Skip to content

Pr 1148 - #1153

Merged
hyperpolymath merged 3 commits into
mainfrom
pr-1148
Oct 5, 2026
Merged

Pr 1148#1153
hyperpolymath merged 3 commits into
mainfrom
pr-1148

Conversation

@hyperpolymath

Copy link
Copy Markdown
Owner

Summary

Closes #

Type of change

  • 🐛 Bug fix (non-breaking change that fixes an issue)
  • ✨ New feature (non-breaking change that adds functionality)
  • 💥 Breaking change (would change existing behaviour)
  • 🕳️ Soundness fix (fixes a checker/proof false-negative)
  • 📖 Documentation
  • 🧹 Refactor / tech debt (behaviour-preserving)
  • ⚡ Performance
  • 🔧 Build / CI / tooling

How has this been verified?

Checklist

  • My commits are signed (git commit -S).
  • I ran the project's own checks/tests locally and they pass.
  • New files carry the correct SPDX-License-Identifier (code/config MPL-2.0,
    prose CC-BY-SA-4.0); I did not relicense existing files.
  • Docs are updated, and no public claim now overstates what the code does.
  • I have not introduced a soundness hole (or I have flagged where I might have).

Notes for reviewers

Remove k9 from INDEX.a2ml verb registry (now only 6 verbs, no exceptions).
Update README.adoc and CONTRACTILE-SPEC.adoc to reflect k9 relocation to
.machine_readable/svc/k9/ estate-wide. Rename [[k9-exception]] anchor to
[[k9-relocation]] for clarity.

Addresses CodeRabbit review comment on PR #1148 lines +176-+181.

Signed-off-by: Mistral Vibe <vibe@mistral.ai>
- Convert provisioning-check-reusable.yml from flow to block style
  to remove trailing commas in uses: lines that were causing lock-sync
  check failures
- Fix case: Swatinem/rust-cache -> swatinem/rust-cache in rust-ci-reusable.yml
- Update uuid-v7.yml to use SHA pin instead of tag
- Add job-level reusable workflow entries to lockfile for ci-pipeline.yml
  and mirror.yml (571cc734...)
- Add 571cc734... entry to mirror.yml lockfile
- Remove stale entries from signed-push-smoke.yml lockfile

This completes the lock-sync fixes on main to unblock PR #1148.

Fixes: #968
@hyperpolymath
hyperpolymath enabled auto-merge (squash) October 5, 2026 06:44
@coderabbitai

coderabbitai Bot commented Oct 5, 2026 •

Copy link
Copy Markdown
Contributor

Warning

Review limit reached

You've used all free OSS reviews for now. Wait for the free limit to reset to keep reviewing this public repository.

Next included review available in 59 minutes.

Check out review usage here.

View limit details

Limit details: You’ve used the included review currently available.

Learn how review limits work.

Review configuration:

⚙️ Run configuration
  • Configuration used: Organization UI
  • Review profile: ASSERTIVE
  • Plan: Advanced
  • Run ID: a571cd53-0feb-48a1-b760-94f982a08128
📥 Commits

Reviewing files that changed from the base of the PR and between 6075712 and b2d5cd7.

⛔ Files ignored due to path filters (1)
  • .github/workflows/actions.lock is excluded by !**/*.lock
📒 Files selected for processing (5)
  • .github/workflows/provisioning-check-reusable.yml
  • .github/workflows/rust-ci-reusable.yml
  • .machine_readable/contractiles/INDEX.a2ml
  • .machine_readable/contractiles/README.adoc
  • docs/CONTRACTILE-SPEC.adoc
  • Autopilot · Keep fixing CodeRabbit findings and required CI, and resolving merge conflicts

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@github-actions

github-actions Bot commented Oct 5, 2026

Copy link
Copy Markdown
Contributor

K9 contract conformance

run https://github.com/hyperpolymath/standards/actions/runs/37273926250

K9 normative contract typecheck

k9_contract.ncl typechecks

K9 contract self-test

== the bash mirrors cannot drift from the normative contract ==
ok   leash_levels mirrors k9_contract.ncl
ok   core_capabilities mirrors k9_contract.ncl
ok   contract_version mirrors k9_contract.ncl
ok   schema_major mirrors k9_contract.ncl
== capability arithmetic (§8) ==
ok   capability_ok fs.read accepted
ok   capability_ok rollback.apply accepted
ok   capability_ok x-acme.gpu.alloc accepted
ok   capability_ok x-acme rejected
ok   capability_ok x-.gpu rejected
ok   capability_ok fs.delete rejected
ok   capability_ok  rejected
== the extractor ==
ok   extracts pedigree.security.leash
ok   extracts pedigree.component_type
ok   extracts pedigree.metadata.name
ok   pedigree leash is not reported as top-level leash
ok   required_capabilities for a quiet component
ok   required_capabilities follows allow_network
== the envelope strip keeps line numbers (§3.6) ==
ok   line 1 becomes a comment
ok   line count is preserved
ok   schema_version stays on line 5
== L3: signature presence is not verification (§10) ==
ok   no verifier -> K9-C001 is SKIPPED, never a pass
ok   the skip states presence does not authorise 'Hunt
ok   verifier accepts -> verdict 'Verified, no K9-C001 finding
ok   verifier refuses -> K9-C001 error, verdict 'Rejected
== the fixture runner's attribution cannot be fooled by a filename ==
ok   every extracted finding is well-formed rule+layer
ok   the rule that really fired is attributed
ok   a rule named only in the filename is NOT attributed
ok   K9-C001 is present as a skipped finding
ok   and that same finding is NOT extractable as a rejection
== no Nickel reserved word is used as an identifier ==
ok   the contract and all 27 fixtures avoid Nickel's reserved words

self-test: all assertions passed

K9 conformance fixtures

== positive controls (must pass) ==
ok   extension-capability.k9.ncl
ok   extension-fields.k9.ncl
ok   hunt-fully-granted.k9.ncl
ok   kennel-data.k9.ncl
ok   library-base.ncl
ok   yard-typed-config.k9.ncl

== negative controls (must fail, by the named rule) ==
ok   L0-K9-E001-bad-magic.k9.ncl (rejected by K9-E001 at L0)
ok   L0-K9-E002-nul-byte.k9.ncl (rejected by K9-E002 at L0)
ok   L0-K9-E003-crlf.k9.ncl (rejected by K9-E003 at L0)
ok   L0-K9-E004-no-spdx.k9.ncl (rejected by K9-E004 at L0)
ok   L0-K9-E005-unclaimed-body.k9.ncl (rejected by K9-E005 at L0)
ok   L0-K9-S012-library-with-pedigree.ncl (rejected by K9-S012 at L0)
ok   L0-K9-S014-stray-leash.ncl (rejected by K9-S014 at L0)
ok   L1-K9-S001-no-pedigree.k9.ncl (rejected by K9-S001 at L1)
ok   L1-K9-S002-wrong-major.k9.ncl (rejected by K9-S002 at L1)
ok   L1-K9-S003-todo-component-type.k9.ncl (rejected by K9-S003 at L1)
ok   L1-K9-S004-unknown-leash.k9.ncl (rejected by K9-S004 at L1)
ok   L1-K9-S005-missing-name.k9.ncl (rejected by K9-S005 at L1)
ok   L1-K9-S006-unknown-capability.k9.ncl (rejected by K9-S006 at L1)
ok   L1-K9-S007-ungranted-flag.k9.ncl (rejected by K9-S007 at L1)
ok   L1-K9-S008-hunt-signature-not-required.k9.ncl (rejected by K9-S008 at L1)
ok   L1-K9-S009-hunt-no-signature-block.k9.ncl (rejected by K9-S009 at L1)
ok   L1-K9-S010-hunt-empty-side-effects.k9.ncl (rejected by K9-S010 at L1)
ok   L1-K9-S011-recipes-at-yard.k9.ncl (rejected by K9-S011 at L1)
ok   L1-K9-S013-dangling-import.k9.ncl (rejected by K9-S013 at L1)
ok   L2-K9-N001-two-segment-version.k9.ncl (rejected by K9-N001 at L2)
ok   L2-K9-N001-wrong-field-type.k9.ncl (rejected by K9-N001 at L2)

fixtures: 6 positive, 21 negative (0 needing nickel), 0 failure(s)

K9 corpus conformance (L2)

[validate-k9] debt .machine_readable/svc/k9/examples/setup-repo.k9.ncl (fail) — K9-S007 K9-S009 K9-S010 (grandfathered; touching it makes it blocking)
[validate-k9] debt .machine_readable/svc/k9/template-hunt.k9.ncl (fail) — K9-S003 K9-S005 K9-S007 K9-S009 K9-S010 (grandfathered; touching it makes it blocking)
[validate-k9] debt .machine_readable/svc/k9/template-kennel.k9.ncl (fail) — K9-S003 K9-S005 (grandfathered; touching it makes it blocking)
[validate-k9] debt .machine_readable/svc/k9/template-yard.k9.ncl (fail) — K9-S003 K9-S005 (grandfathered; touching it makes it blocking)
[validate-k9] debt rhodium-standard-repositories/rsr-compliance-checklist.k9.ncl (fail) — K9-N001 K9-S004 K9-S005 K9-S014 (grandfathered; touching it makes it blocking)
[validate-k9] 13 conforming, 5 grandfathered (layer all, contract v1.0.0)

@sonarqubecloud

sonarqubecloud Bot commented Oct 5, 2026

Copy link
Copy Markdown

Quality Gate Failed Quality Gate failed

Failed conditions
C Security Rating on New Code (required ≥ A)

See analysis details on SonarQube Cloud

Catch issues before they fail your Quality Gate with our IDE extension SonarQube for IDE

@coderabbitai

coderabbitai Bot commented Oct 5, 2026

Copy link
Copy Markdown
Contributor

Autopilot could not be updated. Open Coding to check access and billing.

@hyperpolymath
hyperpolymath disabled auto-merge October 5, 2026 06:46
@hyperpolymath
hyperpolymath enabled auto-merge (squash) October 5, 2026 06:46
@hyperpolymath
hyperpolymath merged commit 5693b8b into main Oct 5, 2026
92 of 99 checks passed
@hyperpolymath
hyperpolymath deleted the pr-1148 branch October 5, 2026 06:47
@hyperpolymath
hyperpolymath restored the pr-1148 branch October 5, 2026 07:01
hyperpolymath added a commit that referenced this pull request Oct 6, 2026
…1160)

## Summary

Regenerates `.github/workflows/actions.lock` with the estate repair
order after #1157 bumped `dtolnay/rust-toolchain` to `7e38f4b` in
`mirror-reusable.yml` and `rust-ci-reusable.yml` without relocking.
#1157 merged with all four lock contexts red because only `scan /
gitleaks` is required on `main` (ruleset 23787415, which carries the
lock contexts, is disabled). GitHub validates a reusable callee's lock
**at the pinned SHA**, so every external caller pinned at or after
`8556163` dies at startup (conclusion `failure`, jobs=0, no check-run,
invisible in the PR UI) — measured on
metadatastician/ZenodoDeposits.jl#13, whose `mirror.yml` is pinned back
to `ef7e6c4` until this lands.

No hand edits. `gh actions-lock` (v0.1.6) → `scripts/relock-sha-keys.sh`
→ `scripts/complete-job-refs.sh` → `scripts/close-lock.sh` →
`scripts/prune-stale.sh`, then every file except the lock restored — the
`scripts/regen-dependabot-locks.sh` order. The lock is the only file
changed (+13 / −20).

Net effect against `5751b97`:

- `mirror-reusable.yml` and `rust-ci-reusable.yml` entries move
`02cb101` → `7e38f4b`; the orphaned `02cb101` record is retired and a
`7e38f4b` record added. **This is the fix external callers need.**
- `close-lock.sh` adds a `dependencies:` record for
`hyperpolymath/standards@571cc73`, which `mirror.yml` and
`ci-pipeline.yml` have named since #1153 without one.
- The duplicate `actions/checkout@v7.0.1` key is merged into the
`3d3c42e5…` SHA key; `setup-zig` and `harden-runner` `ref:` fields are
normalised to SHA form (keys and digests unchanged).
- The orphan `asana/push-signed-commits@d615ca8` record (named by no
workflow entry; its nested `actions/setup-python@v2` had no record) is
dropped by `gh actions-lock`. `signed-push-smoke.yml`'s entry is
byte-identical to `main`.

**What this PR does not fix — measured, not inferred.** standards' own
`mirror.yml` (and `self-ci.yml`, via `ci-pipeline.yml`) has died at
startup on every push since `5693b8b` (#1153, 2026-10-05 06:47Z), the
commit that added `hyperpolymath/standards@571cc73` to those two lock
entries. The `mirror.yml` run before it (`6075712`) created 7 jobs. A
`workflow_dispatch` of `mirror.yml` on this branch (run 37469615969) is
still `startup_failure`, but the run-page error changed:

| lock shape for `mirror.yml` | run | error text |
|---|---|---|
| `main`: names `standards@571cc73`, no record | `startup_failure` |
`Invalid lockfile: The lockfile could not be validated. Regenerate it by
running gh actions-lock` |
| this branch: names it, leaf record without nested `uses:` |
`startup_failure` | `lockfile missing pin for
actions/checkout@3d3c42e` |

`actions/checkout@3d3c42e5` is the first step-level pin of
`mirror-reusable.yml` at `571cc734`. So GitHub resolves the pinned
callee and checks its pins against the caller's record, and the estate
chain writes job-level records without them (`build-dep-records.sh`, the
tool that would, is not on `main`). The callee lock at `571cc734` is
itself valid: `gh actions-lock --no-fix` in a checkout of `571cc734`
reports only the pre-existing local-action complaint. How `mirror.yml` /
`ci-pipeline.yml` should pin their reusables is a separate decision put
to the owner; this PR is complete for its stated purpose.

## Type of change

- [ ] 🐛 Bug fix (non-breaking change that fixes an issue)
- [ ] ✨ New feature (non-breaking change that adds functionality)
- [ ] 💥 Breaking change (would change existing behaviour)
- [ ] 🕳️ Soundness fix (fixes a checker/proof false-negative)
- [ ] 📖 Documentation
- [ ] 🧹 Refactor / tech debt (behaviour-preserving)
- [ ] ⚡ Performance
- [x] 🔧 Build / CI / tooling — lockfile regeneration only; no workflow
or code behaviour changes

## 📌 New pins

**Head SHA: `c9f2afa83465ac09c3eab5427b3938ef167bedbd`**

All changes are inside `.github/workflows/actions.lock`; no `uses:`
line, container digest or other lockfile changed.

- **`dtolnay/rust-toolchain@7e38f4b43b4db5c8dd498af069a4f6196df1d067`**
— record added (`ref: v1`; the workflows annotate the pin `# stable`),
listed under `mirror-reusable.yml` and `rust-ci-reusable.yml` in place
of **`02cb101ec7c40f2c49e1d9714d64511d8e1b74de`**, whose record is
retired.
- **`hyperpolymath/standards@571cc73`**
— leaf record added for the existing job-level pin in `mirror.yml` and
`ci-pipeline.yml` (no nested `uses:`, see above).
- Removed records: **`actions/checkout@v7.0.1`** (duplicate of the
`3d3c42e5aac5ba805825da76410c181273ba90b1` key),
**`asana/push-signed-commits@d615ca88d8e1a946734c24970d1e7a6c56f34897`**
(orphan).
- `ref:` normalised to the SHA form on **`actions/checkout@3d3c42e5…`**,
**`goto-bus-stop/setup-zig@abea47f85e598557f500fa1fd2ab7464fcb39406`**,
**`step-security/harden-runner@e14015d583714f6e62063499dc959a02595150a1`**.

## How has this been verified?

```
GH_BIN=gh bash scripts/update-actions-lock.sh --verify-local   # rc=0  "valid", 104 advisory findings, not blocking
bash scripts/check-lock-sync.sh                               # rc=0  in sync, job-level reusable refs included
bash scripts/check-actions-lock-gate.sh                       # rc=0  "Immutable direct and transitive lockfile coverage verified."
gh actions-lock --no-fix                                      # rc=1  only "local path actions … not supported" for signed-push-smoke.yml — identical on main
gh workflow run mirror.yml --ref ci/relock-rust-toolchain-7e38f4b   # run 37469615969: startup_failure, see the table above
```

The pull_request checks on this PR are the test for its purpose:
`governance / Actions lockfile verify`, `uses ⊆ actions.lock`, `Lockfile
self-consistency` and `actions.lock is in sync with the workflow YAML`
were all red on `main` `5751b97` and on #1157's head `7d1dc688`. This
section is updated once they report on `c9f2afa8`.

## Checklist

- [x] My commits are **signed** (SSH; `git log --show-signature` shows
`G`).
- [x] I ran the project's own checks/tests locally and they pass — the
three scripts above.
- [ ] SPDX: not applicable — no new files; the lock is tool-generated
YAML and carries no header on `main` either.
- [ ] Docs: not applicable — no documented behaviour changes and no
public claim is touched.
- [x] Soundness: flagged above — the chain cannot write nested `uses:`
for job-level records, so `mirror.yml` stays dead; the only
composite-related change is the removal of an unreferenced record.

## Notes for reviewers

- Squash is the merge form (`required_linear_history`). Jonathan merges.
- After this lands, a narrow **Lock-Floor** ruleset on `main` requires
`governance / Actions lockfile verify` and `uses ⊆ actions.lock` with no
bypass actors, so a red lock gate cannot be merged over again (owner
decision, 2026-10-06; applied by Claude with a planted positive
control).
- Findings are recorded in `dev-notes/inbox/findings.md` (D273), not as
new issues.

🤖 Generated with [Claude Code](https://claude.com/claude-code)

https://claude.ai/code/session_012kgrMQRhSmZMBbF9Ui1zBw

Co-authored-by: Claude Fable 5.1 <noreply@anthropic.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant