Repository navigation
fix(ci): sort out the lint-workflows class, the lock re-desync, and the freeze bypass — with the sources cured - #141
Merged
Conversation
… hold bypass Dependabot PR #140 moved github/codeql-action from b96794f0 (v4.38.0) to 2892aa5e (a 2026-09-24 releases/v4 merge, 'update-v4.38.2') in SHA form while copying the inline '# v4.38.0 (4.38.1 blocked estate-wide; nexia-list#100)' comment verbatim — the comment survived the rewrite with its meaning inverted (echo-types: structured loss in a lossy map). That pin is under an estate freeze: nexia-list#100 measured v4.38.1+ refused at workflow startup (tag AND SHA form) and rolled the estate back to the v4.38.0 SHA; nexia-list#104 upgraded the defence to an UNCONDITIONAL dependabot hold — which #140 bypassed anyway (second documented bypass after nexia-list#101's versions-scope failure). hyperpolymath/standards main still pins b96794f0 today. Revert the three workflow files to the held SHA. The inline comment is truthful again. The dependabot.yml comment now records the bypass and points at the gate that will actually enforce the freeze (the next commit's scripts/check-frozen-pins.sh) — an ignore rule is a request to a robot; this repository now asserts the invariant itself. Inverses: git revert this commit restores the bump (do that only after deliberately lifting the freeze in scripts/check-frozen-pins.sh). Co-authored-by: arena-agent <297053741+arena-agent@users.noreply.github.com>
…elf-tests, pin-freeze gate Fixes the two red lint-workflows checks (issue #138). Root cause is a contradiction between two governors over one byte: gh actions-lock INSERTS '# This workflow is managed by gh actions-lock.' at line 1 whenever it mints or refreshes a lockfile, while this workflow's 'Check SPDX headers' step demanded the SPDX identifier on line 1 — so every lock refresh re-failed the check. Measured same-commit: 18 of 19 workflow files failed the line-1 test (including this file, judging itself) while 'governance / Workflow security linter' — the canonical predicate in hyperpolymath/standards governance-reusable.yml since 2026-08-07 — was green on the identical files. The local copy had diverged into a stale, over-strict mutant of the estate's own check. Changes: * scripts/check-workflow-headers.sh — the canonical predicate, byte- faithful to governance-reusable.yml ('Check SPDX headers + permissions'): SPDX anywhere in the leading comment block (tolerating the lock banner and a YAML document marker) plus top-level permissions:. The SPDX and permissions requirements are unchanged; only the line-1 framing, which was wrong and fighting the estate's tool, is gone. * Expected-rejection controls (--self-test): fixtures that must pass (banner+SPDX, line-1 SPDX, doc-marker+SPDX) and fixtures that must be rejected (no SPDX, no permissions). The self-test runs FIRST in the job: a predicate that cannot kill its own mutant is a Certified Null Operation and must not be allowed to judge the tree. This promotes PR #137's manual mutation-testing notes into a control that runs forever. * scripts/check-frozen-pins.sh — the codeql-action freeze as a gate this repo owns, with its own mutants (SHA-form bump and tag-form bump both killed in self-test). Lifting the freeze is a deliberate one-line table edit in its own commit; git revert of that edit restores it. * Job name 'lint-workflows' kept — check contexts must not be renamed casually (standards#994). The check stays blocking; nothing was muted, demoted, or removed from any required set. Determination for issue #138: FIXED (both legs — the second occurrence is the same job on the push event, cleared by the same change). Co-authored-by: arena-agent <297053741+arena-agent@users.noreply.github.com>
…healer PR #140 bumped haskell-actions/setup v2.12.0 -> v2.12.1 in casket-pages.yml without regenerating actions.lock — Dependabot rewrites workflow YAML and never touches the lock — so the tree entered the exact state the actions.lock campaign cured (standards#968): GitHub refuses to start any workflow whose step-level uses: refs are not recorded under its own path. Measured consequences on main today: Lock Sync Gate red, 'governance / Actions lockfile verify' red, CodeQL and GitHub Pages startup_failure (jobs=0), and cflite_batch/cflite_pr poised to die on their next trigger. * actions.lock — bless haskell-actions/setup@v2.12.1 (tag peeled to 0f8e8c99d88aeb3fbfd523f1ef2c6f762d10d64d via the API; owner_id/repo_id unchanged) and onboard the healer below. All four clauses of scripts/check-lock-sync.sh verified against the result, including clause 4 (COVERAGE). Hand-structured to gh actions-lock's format (precedent: PR #137); the healer will re-canonicalise on its first run. * .github/workflows/lock-sync-heal.yml — the source cure. The lockfile's own header names the sanctioned writer (gh actions-lock); this workflow runs it on every workflow change and on a weekly backstop, and when the regenerated lock differs it opens one standing PR whose body carries check-lock-sync.sh's output as a receipt (checked on the regenerated tree BEFORE the PR exists). Audit mode by default on manual dispatch; fail-loud if the generator is unavailable. Inverse: close the PR or revert its commit. A state cure without a source cure is a countdown: the campaign fixed the estate once and the clock re-broke this repo in seven days. This is the fix for the clock. Co-authored-by: arena-agent <297053741+arena-agent@users.noreply.github.com>
Records what the estate's formal-methods repos contribute to the nature of these failures and which lines of the fix each concept changed: pons-asinorum (contradiction/waste taxonomy, negative corpus), absolute- zero (CNO gates, OND residue lists), januskey (inversion metadata, shared-core over divergent copies), echo-types (structured loss; comments that outlive their meaning), epistemic-types (warrant vs knowledge; receipts), choreographic-types (cuts/frontiers), occupancy-types (expected-rejection controls, rung contracts), panic-attack (bug signatures for class-level triage). Includes the three failure signatures and the recommended estate moves. Co-authored-by: arena-agent <297053741+arena-agent@users.noreply.github.com>
arena-ai-coding-agent
Bot
requested a review
from hyperpolymath
as a code owner
September 30, 2026 00:22
Contributor
|
Important Review skippedBot user detected. To trigger a single review, invoke the ⚙️ Run configurationConfiguration used: Organization UI Review profile: ASSERTIVE Plan: Advanced Run ID: You can disable this status message by setting the Use the checkbox below for a quick retry:
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
Co-authored-by: arena-agent <297053741+arena-agent@users.noreply.github.com>
Co-authored-by: arena-agent <297053741+arena-agent@users.noreply.github.com>
hyperpolymath
approved these changes
Sep 30, 2026
Co-authored-by: arena-agent <297053741+arena-agent@users.noreply.github.com>
hyperpolymath
approved these changes
Sep 30, 2026
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
What this sorts out
Closes the acceptance criteria of #138 and goes after the three sources behind today's reds, in one change set. Each cure carries its inverse (januskey); nothing was muted, demoted, or removed from any required set (standards#994 AC5).
1.
lint-workflows×2 (issue #138) — determination: FIXEDTwo governors claimed the same byte:
gh actions-lockinserts# This workflow is managed by gh actions-lock.at line 1 whenever it mints or refreshes a lockfile, while the localCheck SPDX headersstep demanded the SPDX identifier on line 1. Every lock refresh re-failed the check. Measured same-commit (a045f44):lint-workflows(localworkflow-linter.yml)head -1governance / Workflow security linter(canonical,standards@fad242d)The canonical predicate has existed in
hyperpolymath/standardsgovernance-reusable.ymlsince 2026-08-07, with the exact warning recorded: a line-1 test "fights the estate's own tool and re-fails every time a lockfile is refreshed" — it falsely reported 27 hypatia + 13 other workflows and "fixing" it mis-licensed 3 files. The local copy was a stale divergent mutant of the estate's own check.The fix converges the local copy to the canonical form (
scripts/check-workflow-headers.sh, byte-faithful): SPDX anywhere in the leading comment block (banner- and doc-marker-tolerant) + top-levelpermissions:. Same requirements, correct frame. Job namelint-workflowskept; the check stays blocking.Expected-rejection controls (
--self-test, from occupancy-types' gate contract and pons-asinorum's falsifier rule): 3 fixtures that must pass and 2 that must be killed, run first in the job. A predicate that cannot kill its own mutant is a Certified Null Operation (absolute-zero) and is not allowed to judge the tree. This promotes PR #137's manual mutation notes into a permanent control.2. The freeze bypass — determination: FIXED (gate-enforced)
Dependabot #140 moved
github/codeql-actionb96794f0(v4.38.0) →2892aa5e(a 2026-09-24releases/v4merge,update-v4.38.2) in SHA form while copying the# v4.38.0 (4.38.1 blocked estate-wide; nexia-list#100)comment verbatim — the witness of intent survived the rewrite with its meaning inverted. That pin is under an estate freeze (nexia-list#100: v4.38.1+ refused at startup;standardsmain still pinsb96794f0today). This is the second documented bypass of the hold (nexia-list#101: versions-scope; nexia-list#104: unconditional; then this).An ignore rule is a request to a robot; this PR reverts the bump and adds
scripts/check-frozen-pins.sh— the freeze as a check this repo owns, with its own mutants (SHA-form and tag-form bump both killed in self-test). Lifting the freeze becomes a deliberate, reviewable one-line table edit.3. The lock re-desync (standards#968 class) — determination: FIXED, source cured
#140 bumped
haskell-actions/setupv2.12.1 and did not regenerateactions.lock("60 of 60 repos have Dependabot AND a lockfile AND no regeneration step — repos appear to go bad again; nobody broke them, the clock did"). Measured on main today: Lock Sync Gate 🔴,governance / Actions lockfile verify🔴, CodeQL + GitHub Pagesstartup_failure(jobs=0), cflite poised to die. The lock is re-synced (haskell-actions/setup@v2.12.1peeled via API; all fourcheck-lock-sync.shclauses verified), andlock-sync-heal.ymlis the source cure:gh actions-lock(the sanctioned writer) on every workflow change + weekly backstop, opening one standing refresh PR whose body carries the checker's output as a receipt — obtained on the regenerated tree before the PR exists (epistemic-types: transported proof arrives with a sound check of the receiver's claim). Inverse: close the PR.Residue list (honest boundary, echo-types/OND)
Not claimed, not erased — listed with dates:
hypatia / Hypatia Neurosymbolic Analysis— red onmainsince 2026-09-29 (Build Hypatia scanner). Cause not established from here (job logs unreachable from the triage sandbox); candidate classes:hyperpolymath/hypatiaHEAD build-rot or transient hex.pm failure. It is standards#994's class 3; the reusable builds the scanner from a moving HEAD, which is the fragile contract. It is a required context and may block this PR's merge mechanically — per the stopping rule, nothing is required of a branch that its base does not satisfy.mirror / mirror-gitea,mirror / mirror-disroot— red onmain(infrastructure/credentials). Not measured further.Verification
bash -nclean on every script and everyrun:block (extracted and parsed)check-lock-sync.shclauses 1–4 pass on the repaired lock (verified via a clause-faithful port; gawk is not in the triage sandbox — the gate itself runs the real script on ubuntu-latest)lint-workflowsgreen on this PR head (both legs)Theory basis (full map in
docs/ci-guard-cures-2026-09-29.adoc)pons-asinorum (contradiction taxonomy; negative corpus) · absolute-zero (CNO vacuous gates; OND residue lists) · januskey (inversion metadata; shared core over divergent copies) · echo-types (structured loss; comments that outlive their meaning) · epistemic-types (warrant ≠ knowledge; receipts) · choreographic-types (YAML+lock is one cut) · occupancy-types (expected-rejection controls; rung contracts) · panic-attack (signatures:
TWO-GOVERNORS-ONE-INVARIANT,ROBOT-PROMISE-WITHOUT-GATE,STATE-CURE-WITHOUT-SOURCE-CURE).🤖 Generated with Claude Code