Skip to content

fix(lock): relock actions.lock after the rust-toolchain bump (#1157) - #1160

Merged
hyperpolymath merged 1 commit into
mainfrom
ci/relock-rust-toolchain-7e38f4b
Oct 6, 2026
Merged

hyperpolymath merged 1 commit into
mainfrom
ci/relock-rust-toolchain-7e38f4b

Conversation

@hyperpolymath

@hyperpolymath hyperpolymath commented Oct 6, 2026 •

Copy link
Copy Markdown
Owner

Summary

Regenerates .github/workflows/actions.lock with the estate repair order after #1157 bumped dtolnay/rust-toolchain to 7e38f4b in mirror-reusable.yml and rust-ci-reusable.yml without relocking. #1157 merged with all four lock contexts red because only scan / gitleaks is required on main (ruleset 23787415, which carries the lock contexts, is disabled). GitHub validates a reusable callee's lock at the pinned SHA, so every external caller pinned at or after 8556163 dies at startup (conclusion failure, jobs=0, no check-run, invisible in the PR UI) — measured on metadatastician/ZenodoDeposits.jl#13, whose mirror.yml is pinned back to ef7e6c4 until this lands.

No hand edits. gh actions-lock (v0.1.6) → scripts/relock-sha-keys.sh → scripts/complete-job-refs.sh → scripts/close-lock.sh → scripts/prune-stale.sh, then every file except the lock restored — the scripts/regen-dependabot-locks.sh order. The lock is the only file changed (+13 / −20).

Net effect against 5751b97:

  • mirror-reusable.yml and rust-ci-reusable.yml entries move 02cb101 → 7e38f4b; the orphaned 02cb101 record is retired and a 7e38f4b record added. This is the fix external callers need.
  • close-lock.sh adds a dependencies: record for hyperpolymath/standards@571cc734, which mirror.yml and ci-pipeline.yml have named since Pr 1148 #1153 without one.
  • The duplicate actions/checkout@v7.0.1 key is merged into the 3d3c42e5… SHA key; setup-zig and harden-runner ref: fields are normalised to SHA form (keys and digests unchanged).
  • The orphan asana/push-signed-commits@d615ca8 record (named by no workflow entry; its nested actions/setup-python@v2 had no record) is dropped by gh actions-lock. signed-push-smoke.yml's entry is byte-identical to main.

What this PR does not fix — measured, not inferred. standards' own mirror.yml (and self-ci.yml, via ci-pipeline.yml) has died at startup on every push since 5693b8b (#1153, 2026-10-05 06:47Z), the commit that added hyperpolymath/standards@571cc734 to those two lock entries. The mirror.yml run before it (6075712) created 7 jobs. A workflow_dispatch of mirror.yml on this branch (run 37469615969) is still startup_failure, but the run-page error changed:

lock shape for mirror.yml run error text
main: names standards@571cc734, no record startup_failure Invalid lockfile: The lockfile could not be validated. Regenerate it by running gh actions-lock
this branch: names it, leaf record without nested uses: startup_failure lockfile missing pin for actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1

actions/checkout@3d3c42e5 is the first step-level pin of mirror-reusable.yml at 571cc734. So GitHub resolves the pinned callee and checks its pins against the caller's record, and the estate chain writes job-level records without them (build-dep-records.sh, the tool that would, is not on main). The callee lock at 571cc734 is itself valid: gh actions-lock --no-fix in a checkout of 571cc734 reports only the pre-existing local-action complaint. How mirror.yml / ci-pipeline.yml should pin their reusables is a separate decision put to the owner; this PR is complete for its stated purpose.

Type of change

  • 🐛 Bug fix (non-breaking change that fixes an issue)
  • ✨ New feature (non-breaking change that adds functionality)
  • 💥 Breaking change (would change existing behaviour)
  • 🕳️ Soundness fix (fixes a checker/proof false-negative)
  • 📖 Documentation
  • 🧹 Refactor / tech debt (behaviour-preserving)
  • ⚡ Performance
  • 🔧 Build / CI / tooling — lockfile regeneration only; no workflow or code behaviour changes

📌 New pins

Head SHA: c9f2afa83465ac09c3eab5427b3938ef167bedbd

All changes are inside .github/workflows/actions.lock; no uses: line, container digest or other lockfile changed.

  • dtolnay/rust-toolchain@7e38f4b43b4db5c8dd498af069a4f6196df1d067 — record added (ref: v1; the workflows annotate the pin # stable), listed under mirror-reusable.yml and rust-ci-reusable.yml in place of 02cb101ec7c40f2c49e1d9714d64511d8e1b74de, whose record is retired.
  • hyperpolymath/standards@571cc734cd69fb846032ec77a662aa8ee4fc32cd — leaf record added for the existing job-level pin in mirror.yml and ci-pipeline.yml (no nested uses:, see above).
  • Removed records: actions/checkout@v7.0.1 (duplicate of the 3d3c42e5aac5ba805825da76410c181273ba90b1 key), asana/push-signed-commits@d615ca88d8e1a946734c24970d1e7a6c56f34897 (orphan).
  • ref: normalised to the SHA form on actions/checkout@3d3c42e5…, goto-bus-stop/setup-zig@abea47f85e598557f500fa1fd2ab7464fcb39406, step-security/harden-runner@e14015d583714f6e62063499dc959a02595150a1.

How has this been verified?

GH_BIN=gh bash scripts/update-actions-lock.sh --verify-local   # rc=0  "valid", 104 advisory findings, not blocking
bash scripts/check-lock-sync.sh                               # rc=0  in sync, job-level reusable refs included
bash scripts/check-actions-lock-gate.sh                       # rc=0  "Immutable direct and transitive lockfile coverage verified."
gh actions-lock --no-fix                                      # rc=1  only "local path actions … not supported" for signed-push-smoke.yml — identical on main
gh workflow run mirror.yml --ref ci/relock-rust-toolchain-7e38f4b   # run 37469615969: startup_failure, see the table above

The pull_request checks on this PR are the test for its purpose: governance / Actions lockfile verify, uses ⊆ actions.lock, Lockfile self-consistency and actions.lock is in sync with the workflow YAML were all red on main 5751b97 and on #1157's head 7d1dc688. This section is updated once they report on c9f2afa8.

Checklist

  • My commits are signed (SSH; git log --show-signature shows G).
  • I ran the project's own checks/tests locally and they pass — the three scripts above.
  • SPDX: not applicable — no new files; the lock is tool-generated YAML and carries no header on main either.
  • Docs: not applicable — no documented behaviour changes and no public claim is touched.
  • Soundness: flagged above — the chain cannot write nested uses: for job-level records, so mirror.yml stays dead; the only composite-related change is the removal of an unreferenced record.

Notes for reviewers

  • Squash is the merge form (required_linear_history). Jonathan merges.
  • After this lands, a narrow Lock-Floor ruleset on main requires governance / Actions lockfile verify and uses ⊆ actions.lock with no bypass actors, so a red lock gate cannot be merged over again (owner decision, 2026-10-06; applied by Claude with a planted positive control).
  • Findings are recorded in dev-notes/inbox/findings.md (D273), not as new issues.

Post-merge note, 2026-10-06. This PR was squash-merged at c9f2afa as ce92a8c. It dropped the asana/push-signed-commits@d615ca88… record, because gh actions-lock does not scan .github/actions/*/action.yml (#1122). That record is not an orphan: .github/actions/signed-push/action.yml:42 needs it. #1163 re-added it, and all four lock contexts are green on main 44a0de4. A follow-up commit, 596ba74, was pushed after the merge and is superseded. It was never part of this PR. Red checks on this PR that it did not cause are tracked in #955, #994, #934 and #1161.

🤖 Generated with Claude Code

https://claude.ai/code/session_012kgrMQRhSmZMBbF9Ui1zBw

#1157 bumped dtolnay/rust-toolchain to 7e38f4b in mirror-reusable.yml and
rust-ci-reusable.yml without regenerating .github/workflows/actions.lock and
merged with all four lock contexts red (only scan / gitleaks is required on
main). GitHub validates a reusable callee's lock at the pinned SHA, so every
caller pinned at or after 8556163 dies at startup (conclusion failure,
jobs=0, no check-run) - measured on metadatastician/ZenodoDeposits.jl#13.

Regenerated with the estate repair order, no hand edits:
  gh actions-lock -> relock-sha-keys.sh -> complete-job-refs.sh ->
  close-lock.sh -> prune-stale.sh, every file except the lock restored.

Net effect against 5751b97:
- mirror-reusable.yml and rust-ci-reusable.yml entries move from 02cb101 to
  7e38f4b; the orphaned 02cb101 record is retired, a 7e38f4b record added.
- close-lock adds the missing dependencies record for
  571cc734, which mirror.yml and ci-pipeline.yml
  named without one. On main mirror.yml dies at startup with "Invalid
  lockfile" and self-ci.yml (which calls ci-pipeline.yml) creates no jobs;
  the mirror.yml dispatch on this branch is the test of that cure.
- The duplicate actions/checkout@v7.0.1 key is merged into the SHA key;
  setup-zig and harden-runner refs are normalised to their SHA form.
- The orphan Asana/push-signed-commits@d615ca8 record (named by no workflow
  entry; its nested actions/setup-python@v2 had no record) is dropped by
  gh actions-lock. signed-push-smoke.yml's entry is unchanged.

Local gates on this lock: update-actions-lock.sh --verify-local rc=0,
check-lock-sync.sh rc=0, check-actions-lock-gate.sh rc=0.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_012kgrMQRhSmZMBbF9Ui1zBw
@coderabbitai

coderabbitai Bot commented Oct 6, 2026 •

Copy link
Copy Markdown
Contributor

Important

Review skipped

Review was skipped due to path filters

⛔ Files ignored due to path filters (1)
  • .github/workflows/actions.lock is excluded by !**/*.lock

CodeRabbit blocks several paths by default. You can override this behavior by explicitly including those paths in the path filters. For example, including **/dist/** will override the default block on the dist directory, by removing the pattern from both the lists.

⚙️ Run configuration
  • Configuration used: Organization UI
  • Review profile: ASSERTIVE
  • Plan: Advanced
  • Run ID: fc5bd741-1238-4537-8ce2-481f68ef2c6c

You can disable this status message by setting the reviews.review_status to false in the CodeRabbit configuration file.

Use the checkbox below for a quick retry:

  • No new commits to review - use @coderabbitai full review for a full pass
  • Autopilot · Keep fixing CodeRabbit findings and required CI, and resolving merge conflicts

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@github-actions

github-actions Bot commented Oct 6, 2026

Copy link
Copy Markdown
Contributor

K9 contract conformance

run https://github.com/hyperpolymath/standards/actions/runs/37470261389

K9 normative contract typecheck

k9_contract.ncl typechecks

K9 contract self-test

== the bash mirrors cannot drift from the normative contract ==
ok   leash_levels mirrors k9_contract.ncl
ok   core_capabilities mirrors k9_contract.ncl
ok   contract_version mirrors k9_contract.ncl
ok   schema_major mirrors k9_contract.ncl
== capability arithmetic (§8) ==
ok   capability_ok fs.read accepted
ok   capability_ok rollback.apply accepted
ok   capability_ok x-acme.gpu.alloc accepted
ok   capability_ok x-acme rejected
ok   capability_ok x-.gpu rejected
ok   capability_ok fs.delete rejected
ok   capability_ok  rejected
== the extractor ==
ok   extracts pedigree.security.leash
ok   extracts pedigree.component_type
ok   extracts pedigree.metadata.name
ok   pedigree leash is not reported as top-level leash
ok   required_capabilities for a quiet component
ok   required_capabilities follows allow_network
== the envelope strip keeps line numbers (§3.6) ==
ok   line 1 becomes a comment
ok   line count is preserved
ok   schema_version stays on line 5
== L3: signature presence is not verification (§10) ==
ok   no verifier -> K9-C001 is SKIPPED, never a pass
ok   the skip states presence does not authorise 'Hunt
ok   verifier accepts -> verdict 'Verified, no K9-C001 finding
ok   verifier refuses -> K9-C001 error, verdict 'Rejected
== the fixture runner's attribution cannot be fooled by a filename ==
ok   every extracted finding is well-formed rule+layer
ok   the rule that really fired is attributed
ok   a rule named only in the filename is NOT attributed
ok   K9-C001 is present as a skipped finding
ok   and that same finding is NOT extractable as a rejection
== no Nickel reserved word is used as an identifier ==
ok   the contract and all 27 fixtures avoid Nickel's reserved words

self-test: all assertions passed

K9 conformance fixtures

== positive controls (must pass) ==
ok   extension-capability.k9.ncl
ERROR   K9-N001 [L2] 1-formats/k9/tools/fixtures/valid/extension-fields.k9.ncl: component violates the K9.Component contract: error: contract broken by a value        extra fields `failure_mode_defenses`, `execution`    ┌─ /home/runner/work/standards/standards/1-formats/k9/tools/fixtures/valid/.k9-validate.9006.25735.driver.ncl:3:1    │  3 │ k9_doc | K9.Component 
FAIL extension-fields.k9.ncl should conform (exit 1)
ok   hunt-fully-granted.k9.ncl
ok   kennel-data.k9.ncl
ok   library-base.ncl
ok   yard-typed-config.k9.ncl

== negative controls (must fail, by the named rule) ==
ok   L0-K9-E001-bad-magic.k9.ncl (rejected by K9-E001 at L0)
ok   L0-K9-E002-nul-byte.k9.ncl (rejected by K9-E002 at L0)
ok   L0-K9-E003-crlf.k9.ncl (rejected by K9-E003 at L0)
ok   L0-K9-E004-no-spdx.k9.ncl (rejected by K9-E004 at L0)
ok   L0-K9-E005-unclaimed-body.k9.ncl (rejected by K9-E005 at L0)
ok   L0-K9-S012-library-with-pedigree.ncl (rejected by K9-S012 at L0)
ok   L0-K9-S014-stray-leash.ncl (rejected by K9-S014 at L0)
ok   L1-K9-S001-no-pedigree.k9.ncl (rejected by K9-S001 at L1)
ok   L1-K9-S002-wrong-major.k9.ncl (rejected by K9-S002 at L1)
ok   L1-K9-S003-todo-component-type.k9.ncl (rejected by K9-S003 at L1)
ok   L1-K9-S004-unknown-leash.k9.ncl (rejected by K9-S004 at L1)
ok   L1-K9-S005-missing-name.k9.ncl (rejected by K9-S005 at L1)
ok   L1-K9-S006-unknown-capability.k9.ncl (rejected by K9-S006 at L1)
ok   L1-K9-S007-ungranted-flag.k9.ncl (rejected by K9-S007 at L1)
ok   L1-K9-S008-hunt-signature-not-required.k9.ncl (rejected by K9-S008 at L1)
ok   L1-K9-S009-hunt-no-signature-block.k9.ncl (rejected by K9-S009 at L1)
ok   L1-K9-S010-hunt-empty-side-effects.k9.ncl (rejected by K9-S010 at L1)
ok   L1-K9-S011-recipes-at-yard.k9.ncl (rejected by K9-S011 at L1)
ok   L1-K9-S013-dangling-import.k9.ncl (rejected by K9-S013 at L1)
ok   L2-K9-N001-two-segment-version.k9.ncl (rejected by K9-N001 at L2)
ok   L2-K9-N001-wrong-field-type.k9.ncl (rejected by K9-N001 at L2)

fixtures: 6 positive, 21 negative (0 needing nickel), 1 failure(s)

@sonarqubecloud

sonarqubecloud Bot commented Oct 6, 2026

Copy link
Copy Markdown

@coderabbitai

coderabbitai Bot commented Oct 6, 2026

Copy link
Copy Markdown
Contributor

Add Carrot credits or activate Agent usage billing to use Autopilot

@hyperpolymath
hyperpolymath merged commit ce92a8c into main Oct 6, 2026
57 of 67 checks passed
@hyperpolymath
hyperpolymath deleted the ci/relock-rust-toolchain-7e38f4b branch October 6, 2026 13:32
@hyperpolymath

Copy link
Copy Markdown
Owner Author

The relock drops a composite-action dependency. uses ⊆ actions.lock is red on c9f2afa for this reason.

  • 5751b97e (main) has asana/push-signed-commits@d615ca88d8e1a946734c24970d1e7a6c56f34897 in actions.lock.
  • c9f2afa8 no longer has it: git diff 5751b97e c9f2afa8 -- .github/workflows/actions.lock.
  • It is still used at .github/actions/signed-push/action.yml:42.
  • .githooks/validate-actions-lock.sh staged mode rejects any commit that touches a workflow on top of this head: ERROR: not in actions.lock: Asana/push-signed-commits@d615ca88….

The likely cause is a regenerate run with --no-migrate-local-actions. With that flag the tool stops descending into .github/actions/*/action.yml, as the validator's header notes. Keeping main's asana/... entry next to the new dtolnay@7e38f4b4 entries should turn the check green. Confirm with gh actions-lock --no-fix --verify.

Found while stacking a fix for a silent bash -e exit in governance R5 (from #1119) on this branch. That fix is waiting for this PR.

🤖 Generated with Claude Code

https://claude.ai/code/session_01P48P9ErT8UFFeDUfEQiYV7

hyperpolymath added a commit that referenced this pull request Oct 6, 2026
…1162)

## Summary

Restores the `Asana/push-signed-commits` entry that the #1160 relock
dropped from `.github/workflows/actions.lock`. The composite action
`.github/actions/signed-push/action.yml:42` still uses it. Since
ce92a8c, `uses ⊆ actions.lock` on main has failed with `not in
actions.lock: Asana/push-signed-commits@d615ca88…`. This is the defect
raised on #1160 in issuecomment-6017428696, which was posted the minute
it merged.

Main has no linked issue for it; the red check on main is the record.

## Type of change

- [x] 🐛 Bug fix: main is red on `uses ⊆ actions.lock`.
- [ ] ✨ New feature: not applicable.
- [ ] 💥 Breaking change: not applicable. The entry existed until
ce92a8c.
- [ ] 🕳️ Soundness fix: not applicable.
- [ ] 📖 Documentation: not applicable.
- [ ] 🧹 Refactor: not applicable.
- [ ] ⚡ Performance: not applicable.
- [x] 🔧 Build / CI / tooling

## 📌 New pins

- Head SHA: **e4641cae27a56264ea3e731d893a07ed5bbbe03b**
- **Asana/push-signed-commits@d615ca88d8e1a946734c24970d1e7a6c56f34897**
(ref **v1.3**, owner_id 1472111, repo_id 772313726, transitive
`actions/setup-python@v2`). This is a restored entry, byte-identical to
the one on 5751b97; it adds no new pin. No workflow YAML is changed.

## How has this been verified?

- `bash .githooks/validate-actions-lock.sh` on ce92a8c: **rc=1**, `1
ref(s) missing from the lockfile` (Asana). With this change: **rc=0**,
`26 SHA-pinned ref(s) found among 26 lockfile keys`.
- `./scripts/check-lock-sync.sh` gives **rc=0**: every `uses:` is
locked, and every entry is referenced.
- `git diff 5751b97 -- .github/workflows/actions.lock` shows no Asana
lines, so the restored block matches the pre-#1160 one exactly.

## Checklist

- [x] My commits are **signed**: `git log --format=%G?` gives `G`.
- [x] I ran the project's own checks locally and they pass (the two lock
scripts above; the pre-commit hook accepted the commit).
- [ ] New files carry the correct SPDX identifier: not applicable, no
new files.
- [ ] Docs are updated: not applicable, no documentation claim is
affected.
- [x] I have not introduced a soundness hole. This adds back a lock
entry; it removes no check.

## Notes for reviewers

Main's other reds on ce92a8c are unrelated to this lock entry and are
not touched here: Repo self-tests, Registry + topology, K9-SVC, Haskell
pipeline, Hypatia scan/baseline, Allowlist Preflight, and SonarCloud.

`gh actions-lock --no-fix --verify` also reports a `local-action` error
for `signed-push-smoke.yml` (`uses: ./…`). That error is pre-existing on
5751b97 and is a tool opinion, not a GitHub validation. It is left
alone.

🤖 Generated with [Claude Code](https://claude.com/claude-code)

https://claude.ai/code/session_01P48P9ErT8UFFeDUfEQiYV7

Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant