Pr 1148 - #1153
Pr 1148#1153
Conversation
Remove k9 from INDEX.a2ml verb registry (now only 6 verbs, no exceptions). Update README.adoc and CONTRACTILE-SPEC.adoc to reflect k9 relocation to .machine_readable/svc/k9/ estate-wide. Rename [[k9-exception]] anchor to [[k9-relocation]] for clarity. Addresses CodeRabbit review comment on PR #1148 lines +176-+181. Signed-off-by: Mistral Vibe <vibe@mistral.ai>
- Convert provisioning-check-reusable.yml from flow to block style to remove trailing commas in uses: lines that were causing lock-sync check failures - Fix case: Swatinem/rust-cache -> swatinem/rust-cache in rust-ci-reusable.yml - Update uuid-v7.yml to use SHA pin instead of tag - Add job-level reusable workflow entries to lockfile for ci-pipeline.yml and mirror.yml (571cc734...) - Add 571cc734... entry to mirror.yml lockfile - Remove stale entries from signed-push-smoke.yml lockfile This completes the lock-sync fixes on main to unblock PR #1148. Fixes: #968
|
Warning Review limit reachedYou've used all free OSS reviews for now. Wait for the free limit to reset to keep reviewing this public repository. Next included review available in 59 minutes. View limit detailsLimit details: You’ve used the included review currently available. Review configuration: ⚙️ Run configuration
⛔ Files ignored due to path filters (1)
📒 Files selected for processing (5)
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
K9 contract conformancerun https://github.com/hyperpolymath/standards/actions/runs/37273926250 K9 normative contract typecheckK9 contract self-testK9 conformance fixturesK9 corpus conformance (L2) |
|
|
Autopilot could not be updated. Open Coding to check access and billing. |
…1160) ## Summary Regenerates `.github/workflows/actions.lock` with the estate repair order after #1157 bumped `dtolnay/rust-toolchain` to `7e38f4b` in `mirror-reusable.yml` and `rust-ci-reusable.yml` without relocking. #1157 merged with all four lock contexts red because only `scan / gitleaks` is required on `main` (ruleset 23787415, which carries the lock contexts, is disabled). GitHub validates a reusable callee's lock **at the pinned SHA**, so every external caller pinned at or after `8556163` dies at startup (conclusion `failure`, jobs=0, no check-run, invisible in the PR UI) — measured on metadatastician/ZenodoDeposits.jl#13, whose `mirror.yml` is pinned back to `ef7e6c4` until this lands. No hand edits. `gh actions-lock` (v0.1.6) → `scripts/relock-sha-keys.sh` → `scripts/complete-job-refs.sh` → `scripts/close-lock.sh` → `scripts/prune-stale.sh`, then every file except the lock restored — the `scripts/regen-dependabot-locks.sh` order. The lock is the only file changed (+13 / −20). Net effect against `5751b97`: - `mirror-reusable.yml` and `rust-ci-reusable.yml` entries move `02cb101` → `7e38f4b`; the orphaned `02cb101` record is retired and a `7e38f4b` record added. **This is the fix external callers need.** - `close-lock.sh` adds a `dependencies:` record for `hyperpolymath/standards@571cc73`, which `mirror.yml` and `ci-pipeline.yml` have named since #1153 without one. - The duplicate `actions/checkout@v7.0.1` key is merged into the `3d3c42e5…` SHA key; `setup-zig` and `harden-runner` `ref:` fields are normalised to SHA form (keys and digests unchanged). - The orphan `asana/push-signed-commits@d615ca8` record (named by no workflow entry; its nested `actions/setup-python@v2` had no record) is dropped by `gh actions-lock`. `signed-push-smoke.yml`'s entry is byte-identical to `main`. **What this PR does not fix — measured, not inferred.** standards' own `mirror.yml` (and `self-ci.yml`, via `ci-pipeline.yml`) has died at startup on every push since `5693b8b` (#1153, 2026-10-05 06:47Z), the commit that added `hyperpolymath/standards@571cc73` to those two lock entries. The `mirror.yml` run before it (`6075712`) created 7 jobs. A `workflow_dispatch` of `mirror.yml` on this branch (run 37469615969) is still `startup_failure`, but the run-page error changed: | lock shape for `mirror.yml` | run | error text | |---|---|---| | `main`: names `standards@571cc73`, no record | `startup_failure` | `Invalid lockfile: The lockfile could not be validated. Regenerate it by running gh actions-lock` | | this branch: names it, leaf record without nested `uses:` | `startup_failure` | `lockfile missing pin for actions/checkout@3d3c42e` | `actions/checkout@3d3c42e5` is the first step-level pin of `mirror-reusable.yml` at `571cc734`. So GitHub resolves the pinned callee and checks its pins against the caller's record, and the estate chain writes job-level records without them (`build-dep-records.sh`, the tool that would, is not on `main`). The callee lock at `571cc734` is itself valid: `gh actions-lock --no-fix` in a checkout of `571cc734` reports only the pre-existing local-action complaint. How `mirror.yml` / `ci-pipeline.yml` should pin their reusables is a separate decision put to the owner; this PR is complete for its stated purpose. ## Type of change - [ ] 🐛 Bug fix (non-breaking change that fixes an issue) - [ ] ✨ New feature (non-breaking change that adds functionality) - [ ] 💥 Breaking change (would change existing behaviour) - [ ] 🕳️ Soundness fix (fixes a checker/proof false-negative) - [ ] 📖 Documentation - [ ] 🧹 Refactor / tech debt (behaviour-preserving) - [ ] ⚡ Performance - [x] 🔧 Build / CI / tooling — lockfile regeneration only; no workflow or code behaviour changes ## 📌 New pins **Head SHA: `c9f2afa83465ac09c3eab5427b3938ef167bedbd`** All changes are inside `.github/workflows/actions.lock`; no `uses:` line, container digest or other lockfile changed. - **`dtolnay/rust-toolchain@7e38f4b43b4db5c8dd498af069a4f6196df1d067`** — record added (`ref: v1`; the workflows annotate the pin `# stable`), listed under `mirror-reusable.yml` and `rust-ci-reusable.yml` in place of **`02cb101ec7c40f2c49e1d9714d64511d8e1b74de`**, whose record is retired. - **`hyperpolymath/standards@571cc73`** — leaf record added for the existing job-level pin in `mirror.yml` and `ci-pipeline.yml` (no nested `uses:`, see above). - Removed records: **`actions/checkout@v7.0.1`** (duplicate of the `3d3c42e5aac5ba805825da76410c181273ba90b1` key), **`asana/push-signed-commits@d615ca88d8e1a946734c24970d1e7a6c56f34897`** (orphan). - `ref:` normalised to the SHA form on **`actions/checkout@3d3c42e5…`**, **`goto-bus-stop/setup-zig@abea47f85e598557f500fa1fd2ab7464fcb39406`**, **`step-security/harden-runner@e14015d583714f6e62063499dc959a02595150a1`**. ## How has this been verified? ``` GH_BIN=gh bash scripts/update-actions-lock.sh --verify-local # rc=0 "valid", 104 advisory findings, not blocking bash scripts/check-lock-sync.sh # rc=0 in sync, job-level reusable refs included bash scripts/check-actions-lock-gate.sh # rc=0 "Immutable direct and transitive lockfile coverage verified." gh actions-lock --no-fix # rc=1 only "local path actions … not supported" for signed-push-smoke.yml — identical on main gh workflow run mirror.yml --ref ci/relock-rust-toolchain-7e38f4b # run 37469615969: startup_failure, see the table above ``` The pull_request checks on this PR are the test for its purpose: `governance / Actions lockfile verify`, `uses ⊆ actions.lock`, `Lockfile self-consistency` and `actions.lock is in sync with the workflow YAML` were all red on `main` `5751b97` and on #1157's head `7d1dc688`. This section is updated once they report on `c9f2afa8`. ## Checklist - [x] My commits are **signed** (SSH; `git log --show-signature` shows `G`). - [x] I ran the project's own checks/tests locally and they pass — the three scripts above. - [ ] SPDX: not applicable — no new files; the lock is tool-generated YAML and carries no header on `main` either. - [ ] Docs: not applicable — no documented behaviour changes and no public claim is touched. - [x] Soundness: flagged above — the chain cannot write nested `uses:` for job-level records, so `mirror.yml` stays dead; the only composite-related change is the removal of an unreferenced record. ## Notes for reviewers - Squash is the merge form (`required_linear_history`). Jonathan merges. - After this lands, a narrow **Lock-Floor** ruleset on `main` requires `governance / Actions lockfile verify` and `uses ⊆ actions.lock` with no bypass actors, so a red lock gate cannot be merged over again (owner decision, 2026-10-06; applied by Claude with a planted positive control). - Findings are recorded in `dev-notes/inbox/findings.md` (D273), not as new issues. 🤖 Generated with [Claude Code](https://claude.com/claude-code) https://claude.ai/code/session_012kgrMQRhSmZMBbF9Ui1zBw Co-authored-by: Claude Fable 5.1 <noreply@anthropic.com>




Summary
Closes #
Type of change
How has this been verified?
Checklist
git commit -S).SPDX-License-Identifier(code/configMPL-2.0,prose
CC-BY-SA-4.0); I did not relicense existing files.Notes for reviewers