Skip to content

fix(lock): restore Asana/push-signed-commits entry dropped by #1160 - #1162

Merged
hyperpolymath merged 2 commits into
mainfrom
fix/lock-restore-asana-20261006
Oct 6, 2026
Merged

hyperpolymath merged 2 commits into
mainfrom
fix/lock-restore-asana-20261006

Conversation

@hyperpolymath

Copy link
Copy Markdown
Owner

Summary

Restores the Asana/push-signed-commits entry that the #1160 relock dropped from .github/workflows/actions.lock. The composite action .github/actions/signed-push/action.yml:42 still uses it. Since ce92a8c, uses ⊆ actions.lock on main has failed with not in actions.lock: Asana/push-signed-commits@d615ca88…. This is the defect raised on #1160 in issuecomment-6017428696, which was posted the minute it merged.

Main has no linked issue for it; the red check on main is the record.

Type of change

  • 🐛 Bug fix: main is red on uses ⊆ actions.lock.
  • ✨ New feature: not applicable.
  • 💥 Breaking change: not applicable. The entry existed until ce92a8c.
  • 🕳️ Soundness fix: not applicable.
  • 📖 Documentation: not applicable.
  • 🧹 Refactor: not applicable.
  • ⚡ Performance: not applicable.
  • 🔧 Build / CI / tooling

📌 New pins

  • Head SHA: e4641ca
  • Asana/push-signed-commits@d615ca8 (ref v1.3, owner_id 1472111, repo_id 772313726, transitive actions/setup-python@v2). This is a restored entry, byte-identical to the one on 5751b97; it adds no new pin. No workflow YAML is changed.

How has this been verified?

  • bash .githooks/validate-actions-lock.sh on ce92a8c: rc=1, 1 ref(s) missing from the lockfile (Asana). With this change: rc=0, 26 SHA-pinned ref(s) found among 26 lockfile keys.
  • ./scripts/check-lock-sync.sh gives rc=0: every uses: is locked, and every entry is referenced.
  • git diff 5751b97e -- .github/workflows/actions.lock shows no Asana lines, so the restored block matches the pre-fix(lock): relock actions.lock after the rust-toolchain bump (#1157) #1160 one exactly.

Checklist

  • My commits are signed: git log --format=%G? gives G.
  • I ran the project's own checks locally and they pass (the two lock scripts above; the pre-commit hook accepted the commit).
  • New files carry the correct SPDX identifier: not applicable, no new files.
  • Docs are updated: not applicable, no documentation claim is affected.
  • I have not introduced a soundness hole. This adds back a lock entry; it removes no check.

Notes for reviewers

Main's other reds on ce92a8c are unrelated to this lock entry and are not touched here: Repo self-tests, Registry + topology, K9-SVC, Haskell pipeline, Hypatia scan/baseline, Allowlist Preflight, and SonarCloud.

gh actions-lock --no-fix --verify also reports a local-action error for signed-push-smoke.yml (uses: ./…). That error is pre-existing on 5751b97 and is a tool opinion, not a GitHub validation. It is left alone.

🤖 Generated with Claude Code

https://claude.ai/code/session_01P48P9ErT8UFFeDUfEQiYV7

The #1160 relock regenerated actions.lock from .github/workflows/ only and
dropped the dependency used by the composite action
.github/actions/signed-push/action.yml:42. `uses ⊆ actions.lock` has been
red on main since ce92a8c ("not in actions.lock:
Asana/push-signed-commits@d615ca88"). This restores the entry byte for
byte as it stood on 5751b97 (ref v1.3, same commit and ids, same
transitive uses).

Verified: .githooks/validate-actions-lock.sh rc=1 before (1 ref missing),
rc=0 after (26/26); scripts/check-lock-sync.sh rc=0.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01P48P9ErT8UFFeDUfEQiYV7
@coderabbitai

coderabbitai Bot commented Oct 6, 2026 •

Copy link
Copy Markdown
Contributor
  • Autopilot · Keep fixing CodeRabbit findings and required CI, and resolving merge conflicts

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@github-actions

github-actions Bot commented Oct 6, 2026

Copy link
Copy Markdown
Contributor

K9 contract conformance

run https://github.com/hyperpolymath/standards/actions/runs/37473363733

K9 normative contract typecheck

k9_contract.ncl typechecks

K9 contract self-test

== the bash mirrors cannot drift from the normative contract ==
ok   leash_levels mirrors k9_contract.ncl
ok   core_capabilities mirrors k9_contract.ncl
ok   contract_version mirrors k9_contract.ncl
ok   schema_major mirrors k9_contract.ncl
== capability arithmetic (§8) ==
ok   capability_ok fs.read accepted
ok   capability_ok rollback.apply accepted
ok   capability_ok x-acme.gpu.alloc accepted
ok   capability_ok x-acme rejected
ok   capability_ok x-.gpu rejected
ok   capability_ok fs.delete rejected
ok   capability_ok  rejected
== the extractor ==
ok   extracts pedigree.security.leash
ok   extracts pedigree.component_type
ok   extracts pedigree.metadata.name
ok   pedigree leash is not reported as top-level leash
ok   required_capabilities for a quiet component
ok   required_capabilities follows allow_network
== the envelope strip keeps line numbers (§3.6) ==
ok   line 1 becomes a comment
ok   line count is preserved
ok   schema_version stays on line 5
== L3: signature presence is not verification (§10) ==
ok   no verifier -> K9-C001 is SKIPPED, never a pass
ok   the skip states presence does not authorise 'Hunt
ok   verifier accepts -> verdict 'Verified, no K9-C001 finding
ok   verifier refuses -> K9-C001 error, verdict 'Rejected
== the fixture runner's attribution cannot be fooled by a filename ==
ok   every extracted finding is well-formed rule+layer
ok   the rule that really fired is attributed
ok   a rule named only in the filename is NOT attributed
ok   K9-C001 is present as a skipped finding
ok   and that same finding is NOT extractable as a rejection
== no Nickel reserved word is used as an identifier ==
ok   the contract and all 27 fixtures avoid Nickel's reserved words

self-test: all assertions passed

K9 conformance fixtures

== positive controls (must pass) ==
ok   extension-capability.k9.ncl
ERROR   K9-N001 [L2] 1-formats/k9/tools/fixtures/valid/extension-fields.k9.ncl: component violates the K9.Component contract: error: contract broken by a value        extra fields `failure_mode_defenses`, `execution`    ┌─ /home/runner/work/standards/standards/1-formats/k9/tools/fixtures/valid/.k9-validate.8759.5007.driver.ncl:3:1    │  3 │ k9_doc | K9.Component 
FAIL extension-fields.k9.ncl should conform (exit 1)
ok   hunt-fully-granted.k9.ncl
ok   kennel-data.k9.ncl
ok   library-base.ncl
ok   yard-typed-config.k9.ncl

== negative controls (must fail, by the named rule) ==
ok   L0-K9-E001-bad-magic.k9.ncl (rejected by K9-E001 at L0)
ok   L0-K9-E002-nul-byte.k9.ncl (rejected by K9-E002 at L0)
ok   L0-K9-E003-crlf.k9.ncl (rejected by K9-E003 at L0)
ok   L0-K9-E004-no-spdx.k9.ncl (rejected by K9-E004 at L0)
ok   L0-K9-E005-unclaimed-body.k9.ncl (rejected by K9-E005 at L0)
ok   L0-K9-S012-library-with-pedigree.ncl (rejected by K9-S012 at L0)
ok   L0-K9-S014-stray-leash.ncl (rejected by K9-S014 at L0)
ok   L1-K9-S001-no-pedigree.k9.ncl (rejected by K9-S001 at L1)
ok   L1-K9-S002-wrong-major.k9.ncl (rejected by K9-S002 at L1)
ok   L1-K9-S003-todo-component-type.k9.ncl (rejected by K9-S003 at L1)
ok   L1-K9-S004-unknown-leash.k9.ncl (rejected by K9-S004 at L1)
ok   L1-K9-S005-missing-name.k9.ncl (rejected by K9-S005 at L1)
ok   L1-K9-S006-unknown-capability.k9.ncl (rejected by K9-S006 at L1)
ok   L1-K9-S007-ungranted-flag.k9.ncl (rejected by K9-S007 at L1)
ok   L1-K9-S008-hunt-signature-not-required.k9.ncl (rejected by K9-S008 at L1)
ok   L1-K9-S009-hunt-no-signature-block.k9.ncl (rejected by K9-S009 at L1)
ok   L1-K9-S010-hunt-empty-side-effects.k9.ncl (rejected by K9-S010 at L1)
ok   L1-K9-S011-recipes-at-yard.k9.ncl (rejected by K9-S011 at L1)
ok   L1-K9-S013-dangling-import.k9.ncl (rejected by K9-S013 at L1)
ok   L2-K9-N001-two-segment-version.k9.ncl (rejected by K9-N001 at L2)
ok   L2-K9-N001-wrong-field-type.k9.ncl (rejected by K9-N001 at L2)

fixtures: 6 positive, 21 negative (0 needing nickel), 1 failure(s)

hyperpolymath added a commit that referenced this pull request Oct 6, 2026
## Summary

The R5 (route-to-canonical) step in
`.github/workflows/governance-reusable.yml` runs under `bash -e`.
`out=$(grep -nE …)` returns 1 when a pattern does not match, and that
killed the step before `rc` was read. So the first clean file ended the
scan with no output, and every later file went unscanned. This PR keeps
the status with `|| rc=$?`.

**Stacked on #1162** (the asana lock restore). Without #1162, the
pre-commit `uses ⊆ actions.lock` hook refuses any commit on main. Once
#1162 merges, this branch will be updated, and the diff will be the R5
commit only.

## Type of change

- [x] 🐛 Bug fix: the R5 scan aborts silently.
- [ ] ✨ New feature: not applicable.
- [ ] 💥 Breaking change: no. Callers that passed before still pass.
Callers with R5 hits after a clean file now see those hits, which is the
intended behaviour.
- [x] 🕳️ Soundness fix: a checker false negative. Hits after the first
clean file were never reported.
- [ ] 📖 Documentation: not applicable.
- [ ] 🧹 Refactor: not applicable.
- [ ] ⚡ Performance: not applicable.
- [x] 🔧 Build / CI / tooling

## 📌 New pins

- Head SHA: **824b98ab5bdc1a68c7c283a70aa61dc18243cd54**
- None. No `uses:` or lock entry is changed by the R5 commit. The base
commit e4641ca (#1162) restores the existing
**Asana/push-signed-commits@d615ca88d8e1a946734c24970d1e7a6c56f34897**
entry.

## How has this been verified?

- `bash tests/test_governance_r5_bash_e.sh`: **RED 3/4** before the fix,
because the no-match case exited early. **GREEN 4/4** after it.
- `.githooks/docstring-scan.sh --staged`: 3/3 functions documented,
coverage 100%.
- The pre-commit hook suite passed: gitleaks, lint, SPDX, SHA-pinning
and lockfile coverage.

## Checklist

- [x] My commits are **signed**.
- [x] I ran the project's own checks locally and they pass (as above).
- [x] The new file `tests/test_governance_r5_bash_e.sh` carries
`SPDX-License-Identifier: MPL-2.0`.
- [ ] Docs are updated: not applicable. No documentation claims R5
behaviour.
- [x] I have not introduced a soundness hole; this PR closes one.

## Notes for reviewers

Every caller pinned to a governance-reusable SHA before this fix keeps
the silent-exit behaviour until it repins. echidna's six standards
callers will be repinned in a follow-up PR once this lands.

🤖 Generated with [Claude Code](https://claude.com/claude-code)

https://claude.ai/code/session_01P48P9ErT8UFFeDUfEQiYV7

---------

Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com>
@hyperpolymath
hyperpolymath enabled auto-merge (squash) October 6, 2026 13:50
@github-actions

github-actions Bot commented Oct 6, 2026

Copy link
Copy Markdown
Contributor

K9 contract conformance

run https://github.com/hyperpolymath/standards/actions/runs/37473959921

K9 normative contract typecheck

k9_contract.ncl typechecks

K9 contract self-test

== the bash mirrors cannot drift from the normative contract ==
ok   leash_levels mirrors k9_contract.ncl
ok   core_capabilities mirrors k9_contract.ncl
ok   contract_version mirrors k9_contract.ncl
ok   schema_major mirrors k9_contract.ncl
== capability arithmetic (§8) ==
ok   capability_ok fs.read accepted
ok   capability_ok rollback.apply accepted
ok   capability_ok x-acme.gpu.alloc accepted
ok   capability_ok x-acme rejected
ok   capability_ok x-.gpu rejected
ok   capability_ok fs.delete rejected
ok   capability_ok  rejected
== the extractor ==
ok   extracts pedigree.security.leash
ok   extracts pedigree.component_type
ok   extracts pedigree.metadata.name
ok   pedigree leash is not reported as top-level leash
ok   required_capabilities for a quiet component
ok   required_capabilities follows allow_network
== the envelope strip keeps line numbers (§3.6) ==
ok   line 1 becomes a comment
ok   line count is preserved
ok   schema_version stays on line 5
== L3: signature presence is not verification (§10) ==
ok   no verifier -> K9-C001 is SKIPPED, never a pass
ok   the skip states presence does not authorise 'Hunt
ok   verifier accepts -> verdict 'Verified, no K9-C001 finding
ok   verifier refuses -> K9-C001 error, verdict 'Rejected
== the fixture runner's attribution cannot be fooled by a filename ==
ok   every extracted finding is well-formed rule+layer
ok   the rule that really fired is attributed
ok   a rule named only in the filename is NOT attributed
ok   K9-C001 is present as a skipped finding
ok   and that same finding is NOT extractable as a rejection
== no Nickel reserved word is used as an identifier ==
ok   the contract and all 27 fixtures avoid Nickel's reserved words

self-test: all assertions passed

K9 conformance fixtures

== positive controls (must pass) ==
ok   extension-capability.k9.ncl
ERROR   K9-N001 [L2] 1-formats/k9/tools/fixtures/valid/extension-fields.k9.ncl: component violates the K9.Component contract: error: contract broken by a value        extra fields `failure_mode_defenses`, `execution`    ┌─ /home/runner/work/standards/standards/1-formats/k9/tools/fixtures/valid/.k9-validate.8812.2420.driver.ncl:3:1    │  3 │ k9_doc | K9.Component 
FAIL extension-fields.k9.ncl should conform (exit 1)
ok   hunt-fully-granted.k9.ncl
ok   kennel-data.k9.ncl
ok   library-base.ncl
ok   yard-typed-config.k9.ncl

== negative controls (must fail, by the named rule) ==
ok   L0-K9-E001-bad-magic.k9.ncl (rejected by K9-E001 at L0)
ok   L0-K9-E002-nul-byte.k9.ncl (rejected by K9-E002 at L0)
ok   L0-K9-E003-crlf.k9.ncl (rejected by K9-E003 at L0)
ok   L0-K9-E004-no-spdx.k9.ncl (rejected by K9-E004 at L0)
ok   L0-K9-E005-unclaimed-body.k9.ncl (rejected by K9-E005 at L0)
ok   L0-K9-S012-library-with-pedigree.ncl (rejected by K9-S012 at L0)
ok   L0-K9-S014-stray-leash.ncl (rejected by K9-S014 at L0)
ok   L1-K9-S001-no-pedigree.k9.ncl (rejected by K9-S001 at L1)
ok   L1-K9-S002-wrong-major.k9.ncl (rejected by K9-S002 at L1)
ok   L1-K9-S003-todo-component-type.k9.ncl (rejected by K9-S003 at L1)
ok   L1-K9-S004-unknown-leash.k9.ncl (rejected by K9-S004 at L1)
ok   L1-K9-S005-missing-name.k9.ncl (rejected by K9-S005 at L1)
ok   L1-K9-S006-unknown-capability.k9.ncl (rejected by K9-S006 at L1)
ok   L1-K9-S007-ungranted-flag.k9.ncl (rejected by K9-S007 at L1)
ok   L1-K9-S008-hunt-signature-not-required.k9.ncl (rejected by K9-S008 at L1)
ok   L1-K9-S009-hunt-no-signature-block.k9.ncl (rejected by K9-S009 at L1)
ok   L1-K9-S010-hunt-empty-side-effects.k9.ncl (rejected by K9-S010 at L1)
ok   L1-K9-S011-recipes-at-yard.k9.ncl (rejected by K9-S011 at L1)
ok   L1-K9-S013-dangling-import.k9.ncl (rejected by K9-S013 at L1)
ok   L2-K9-N001-two-segment-version.k9.ncl (rejected by K9-N001 at L2)
ok   L2-K9-N001-wrong-field-type.k9.ncl (rejected by K9-N001 at L2)

fixtures: 6 positive, 21 negative (0 needing nickel), 1 failure(s)

@coderabbitai

coderabbitai Bot commented Oct 6, 2026

Copy link
Copy Markdown
Contributor

Add Carrot credits or activate Agent usage billing to use Autopilot

@sonarqubecloud

sonarqubecloud Bot commented Oct 6, 2026

Copy link
Copy Markdown

@hyperpolymath
hyperpolymath merged commit cfc3a92 into main Oct 6, 2026
57 of 66 checks passed
@hyperpolymath
hyperpolymath deleted the fix/lock-restore-asana-20261006 branch October 6, 2026 13:51
@hyperpolymath

hyperpolymath commented Oct 6, 2026 •

Copy link
Copy Markdown
Owner Author

Note for the record: this PR's only commit (e4641ca, restoring the Asana/push-signed-commits lock entry) had already landed on main inside the #1163 squash (78a0a61), because #1163 was stacked on it. This PR's own squash (cfc3a92) therefore carries no file changes. Main is green on uses ⊆ actions.lock, governance / Actions lockfile verify, actions.lock is in sync with the workflow YAML and Lockfile self-consistency from 78a0a61 onward. (An earlier version of this comment said the PR was being closed; it had already merged.)

🤖 Generated with Claude Code

https://claude.ai/code/session_01P48P9ErT8UFFeDUfEQiYV7

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant