Skip to content

fix(parser): replace a Rust doc comment in the Parser module header - #107

Merged
hyperpolymath merged 1 commit into
mainfrom
fix/parser-header-comment
Oct 6, 2026
Merged

hyperpolymath merged 1 commit into
mainfrom
fix/parser-header-comment

Conversation

@hyperpolymath

@hyperpolymath hyperpolymath commented Oct 6, 2026 •

Copy link
Copy Markdown
Owner

Summary

Fixes a one-line defect that stops sanctify-php from compiling at all. Line 6 of src/Sanctify/Parser.hs was //! verified alternatives., a Rust-style doc comment inside the Haskell header comment. GHC reads it as code, so the module header never parses:

Sanctify/Parser.hs:6:1: error: [GHC-58481]
    parse error on input ‘//!’

Under cabal this shows up as File name does not match module name: Saw ‘Main’, Expected ‘Sanctify.Parser’ (GHC-28623). That is how it failed when hyperpolymath/standards built its vendored copy of this repo (hyperpolymath/standards#1185, run 37531109754). The line becomes -- verified alternatives., which continues the comment's sentence.

Closes # (no issue filed. Found while building the standards vendored copy.)

Type of change

  • 🐛 Bug fix (non-breaking change that fixes an issue)
  • ✨ New feature: none.
  • 💥 Breaking change: no. One comment line changes.
  • 🕳️ Soundness fix: not a checker false-negative.
  • 📖 Documentation: no docs change. The fix is to a source comment.
  • 🧹 Refactor: no.
  • ⚡ Performance: no.
  • 🔧 Build / CI / tooling: no CI files change.

📌 New pins

Head SHA: 4317025d5b0a01924ad0457ff3498ddffa8d0844. No pins are added or changed.

How has this been verified?

These checks used local GHC 9.6.6 with the library stanza's flags: -XGHC2021 -XOverloadedStrings -XLambdaCase -XDerivingStrategies -XDeriveGeneric -XDeriveAnyClass.

  • Before (main fa9bd38): ghc -fno-code Sanctify/Parser.hs → Sanctify/Parser.hs:6:1: error: [GHC-58481] parse error on input ‘//!’.
  • After (this branch), the same command:
    • Sanctify.AST typechecks.
    • Sanctify.Parser parses and stops only at Could not find module ‘Text.Megaparsec’. That package is not installed on the machine that ran the check.
  • git grep -nE '^\s*(//|/\*)' -- '*.hs' on main finds this line and no other.

Horizon of this check: it shows that the header and the whole of Parser.hs parse. It does not show that the package builds. No full cabal build ran locally, because neither cabal nor the dependencies were available. This repo's CI has no Haskell build job either: its checks on this PR are governance, scanning and lint only. So nothing has compiled the package end to end yet.

Checklist

  • My commits are signed (git commit -S). git log --format=%G? → G.
  • I ran the project's own checks/tests locally and they pass: no. There is no local cabal, so the tests could not run. Only the GHC parse check above was run.
  • New files carry the correct SPDX-License-Identifier: no new files. The file keeps its MPL-2.0 header.
  • Docs are updated, and no public claim now overstates what the code does. No docs make claims about this.
  • I have not introduced a soundness hole: one comment line changes.

Deferred red checks

Both reds already fail on main (fa9bd38). This PR does not touch either one:

Notes for reviewers

When this lands, hyperpolymath/standards can re-sync its vendored copy under rhodium-standard-repositories/satellites/cccp/satellites/sanctify-php/. Since standards#1184, standards' own CI does not build that copy, because nested-only Haskell is reported as unsupported. So nothing there is red in the meantime.

🤖 Generated with Claude Code

https://claude.ai/code/session_012kgrMQRhSmZMBbF9Ui1zBw

Line 6 of src/Sanctify/Parser.hs was "//! verified alternatives.", a
Rust-style doc comment in the middle of the Haskell header comment. GHC
reads it as code, so the module header never parses:

  Sanctify/Parser.hs:6:1: error: [GHC-58481] parse error on input '//!'

Under cabal this surfaces as "File name does not match module name:
Saw 'Main', Expected 'Sanctify.Parser'" (GHC-28623), which is how it
failed when hyperpolymath/standards built its vendored copy (#1185).

The line becomes "-- verified alternatives.", so it continues the
sentence of the comment above it.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_012kgrMQRhSmZMBbF9Ui1zBw
@coderabbitai

coderabbitai Bot commented Oct 6, 2026 •

Copy link
Copy Markdown
Contributor

Review in Change Stack →

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration
  • Configuration used: Organization UI
  • Review profile: ASSERTIVE
  • Plan: Advanced
  • Run ID: 96bff5d2-cf88-4998-9046-06650e8b3018
📥 Commits

Reviewing files that changed from the base of the PR and between fa9bd38 and 4317025.

📒 Files selected for processing (1)
  • src/Sanctify/Parser.hs

Included review availability: This review used your included allowance. Your plan provides up to 1 included review per hour; 0 remain after this review.

📜 Recent review details
⏰ Context from checks skipped due to timeout. (6)
  • GitHub Check: governance / Validate Hypatia Baseline
  • GitHub Check: Dogfooding compliance summary
  • GitHub Check: governance / Workflow security linter
  • GitHub Check: governance / Language / package anti-pattern policy
  • GitHub Check: hypatia / Hypatia Neurosymbolic Analysis
  • GitHub Check: semgrep-cloud-platform/scan
⚠️ CI failures not shown inline (16)

GitHub Actions: Governance / 1_governance _ Licence consistency.txt: fix(parser): replace a Rust doc comment in the Parser module header

Conclusion: failure

View job details

##[group]Run bash standards/scripts/check-licence-consistency.sh caller
 �[36;1mbash standards/scripts/check-licence-consistency.sh caller�[0m
 shell: /usr/bin/bash -e {0}
 ##[endgroup]
 [OK] LICENSE file found: LICENSE
 [OK] LICENSE has no SPDX header, but its body is verbatim MPL-2.0 text — accepted as a canonical licence file.
 [OK] Manifest licence (./sanctify-php.cabal): LicenseRef-PMPL-1.0-or-later
 [ERROR] Licence-vs-manifest mismatch: licence='MPL-2.0' manifest='LicenseRef-PMPL-1.0-or-later' (./sanctify-php.cabal).
 [OK] No stray retired-estate SPDX headers (PMPL-1.0*/MPL-1.0*/MPL-1.1) in the tree.
 [ERROR] Licence consistency check failed. See messages above.
 ##[error]Process completed with exit code 1.

GitHub Actions: Governance / governance _ Licence consistency: fix(parser): replace a Rust doc comment in the Parser module header

Conclusion: failure

View job details

##[group]Run bash standards/scripts/check-licence-consistency.sh caller
 �[36;1mbash standards/scripts/check-licence-consistency.sh caller�[0m
 shell: /usr/bin/bash -e {0}
 ##[endgroup]
 [OK] LICENSE file found: LICENSE
 [OK] LICENSE has no SPDX header, but its body is verbatim MPL-2.0 text — accepted as a canonical licence file.
 [OK] Manifest licence (./sanctify-php.cabal): LicenseRef-PMPL-1.0-or-later
 [ERROR] Licence-vs-manifest mismatch: licence='MPL-2.0' manifest='LicenseRef-PMPL-1.0-or-later' (./sanctify-php.cabal).
 [OK] No stray retired-estate SPDX headers (PMPL-1.0*/MPL-1.0*/MPL-1.1) in the tree.
 [ERROR] Licence consistency check failed. See messages above.
 ##[error]Process completed with exit code 1.

GitHub Actions: Governance / 3_governance _ Actions lockfile verify.txt: fix(parser): replace a Rust doc comment in the Parser module header

Conclusion: failure

View job details

##[group]Run set -uo pipefail
 �[36;1mset -uo pipefail�[0m
 �[36;1mif [ "$GITHUB_REPOSITORY" = hyperpolymath/standards ]; then�[0m
 �[36;1m  SRC=scripts�[0m
 �[36;1m  echo "Using this repository's own gate + verifier (standards self-lint)."�[0m
 �[36;1melse�[0m
 �[36;1m  SRC=.standards-lock/scripts�[0m
 �[36;1mfi�[0m
 �[36;1mfor f in check-actions-lock-gate.sh update-actions-lock.sh; do�[0m
 �[36;1m  if [ ! -f "$SRC/$f" ]; then�[0m
 �[36;1m    echo "::error::actions-lock gate: $f not found in $SRC (standards checkout at job.workflow_sha failed?)"�[0m

GitHub Actions: Governance / governance _ Actions lockfile verify: fix(parser): replace a Rust doc comment in the Parser module header

Conclusion: failure

View job details

##[group]Run set -uo pipefail
 �[36;1mset -uo pipefail�[0m
 �[36;1mif [ "$GITHUB_REPOSITORY" = hyperpolymath/standards ]; then�[0m
 �[36;1m  SRC=scripts�[0m
 �[36;1m  echo "Using this repository's own gate + verifier (standards self-lint)."�[0m
 �[36;1melse�[0m
 �[36;1m  SRC=.standards-lock/scripts�[0m
 �[36;1mfi�[0m
 �[36;1mfor f in check-actions-lock-gate.sh update-actions-lock.sh; do�[0m
 �[36;1m  if [ ! -f "$SRC/$f" ]; then�[0m
 �[36;1m    echo "::error::actions-lock gate: $f not found in $SRC (standards checkout at job.workflow_sha failed?)"�[0m

GitHub Actions: Governance / 4_governance _ Workflow security linter.txt: fix(parser): replace a Rust doc comment in the Parser module header

Conclusion: failure

View job details

##[group]Run if [ "$GITHUB_REPOSITORY" = hyperpolymath/standards ]; then
 �[36;1mif [ "$GITHUB_REPOSITORY" = hyperpolymath/standards ]; then�[0m
 �[36;1m  SCRIPT="tools/policy/check-workflows-parse.sh"�[0m
 �[36;1m  echo "Using this repository's own copy (standards self-lint)."�[0m
 �[36;1melse�[0m
 �[36;1m  SCRIPT=".standards-dupkey/tools/policy/check-workflows-parse.sh"�[0m
 �[36;1mfi�[0m
 �[36;1mif [ ! -f "$SCRIPT" ]; then�[0m
 �[36;1m  echo "::error::workflow parser gate not found in the pinned Standards revision or locally"�[0m

GitHub Actions: Governance / governance _ Workflow security linter: fix(parser): replace a Rust doc comment in the Parser module header

Conclusion: failure

View job details

##[group]Run if [ "$GITHUB_REPOSITORY" = hyperpolymath/standards ]; then
 �[36;1mif [ "$GITHUB_REPOSITORY" = hyperpolymath/standards ]; then�[0m
 �[36;1m  SCRIPT="tools/policy/check-workflows-parse.sh"�[0m
 �[36;1m  echo "Using this repository's own copy (standards self-lint)."�[0m
 �[36;1melse�[0m
 �[36;1m  SCRIPT=".standards-dupkey/tools/policy/check-workflows-parse.sh"�[0m
 �[36;1mfi�[0m
 �[36;1mif [ ! -f "$SCRIPT" ]; then�[0m
 �[36;1m  echo "::error::workflow parser gate not found in the pinned Standards revision or locally"�[0m

GitHub Actions: Governance / governance _ Workflow security linter: fix(parser): replace a Rust doc comment in the Parser module header

Conclusion: failure

View job details

##[group]Run # GitHub Actions REJECTS a workflow with duplicate keys: the run is
 �[36;1m# GitHub Actions REJECTS a workflow with duplicate keys: the run is�[0m
 �[36;1m# `failure` with no jobs, no log and no check run. Nothing else here�[0m
 �[36;1m# can see it, because yaml.safe_load silently keeps the LAST�[0m
 �[36;1m# duplicate and reports success — so the file "parses" and every�[0m
 �[36;1m# other lint passes. Measured 2026-08-05: nine workflows in hypatia�[0m
 �[36;1m# were dead this way, including a CodeQL workflow with zero�[0m
 �[36;1m# successful runs in its entire lifetime.�[0m
 �[36;1mset -euo pipefail�[0m
 �[36;1m# Standards exercises its pull-request scripts; every consumer uses�[0m
 �[36;1m# the canonical scripts fetched from this workflow's immutable�[0m
 �[36;1m# Standards revision.�[0m
 �[36;1mif [ "$GITHUB_REPOSITORY" = hyperpolymath/standards ]; then�[0m
 �[36;1m  SCRIPT="scripts/check-workflow-duplicate-keys.sh"�[0m
 �[36;1m  echo "Using this repository's own copy (standards self-lint)."�[0m
 �[36;1melse�[0m
 �[36;1m  SCRIPT=".standards-dupkey/scripts/check-workflow-duplicate-keys.sh"�[0m
 �[36;1mfi�[0m
 �[36;1mif [ ! -f "$SCRIPT" ]; then�[0m
 �[36;1m  echo "::error::duplicate-key checker not found — neither fetched from" \�[0m

GitHub Actions: Governance / 6_governance _ Well-Known (RFC 9116 + RSR).txt: fix(parser): replace a Rust doc comment in the Parser module header

Conclusion: failure

View job details

##[group]Run SECTXT=""
 �[36;1mSECTXT=""�[0m
 �[36;1m[ -f ".well-known/security.txt" ] && SECTXT=".well-known/security.txt"�[0m
 �[36;1m[ -f "security.txt" ] && SECTXT="security.txt"�[0m
 �[36;1mif [ -z "$SECTXT" ]; then�[0m
 �[36;1m  echo "::warning::No security.txt found."�[0m
 �[36;1m  exit 0�[0m
 �[36;1mfi�[0m
 �[36;1mgrep -q "^Contact:" "$SECTXT" || { echo "::error::Missing Contact field"; exit 1; }�[0m

GitHub Actions: Governance / governance _ Well-Known (RFC 9116 + RSR): fix(parser): replace a Rust doc comment in the Parser module header

Conclusion: failure

View job details

##[group]Run SECTXT=""
 �[36;1mSECTXT=""�[0m
 �[36;1m[ -f ".well-known/security.txt" ] && SECTXT=".well-known/security.txt"�[0m
 �[36;1m[ -f "security.txt" ] && SECTXT="security.txt"�[0m
 �[36;1mif [ -z "$SECTXT" ]; then�[0m
 �[36;1m  echo "::warning::No security.txt found."�[0m
 �[36;1m  exit 0�[0m
 �[36;1mfi�[0m
 �[36;1mgrep -q "^Contact:" "$SECTXT" || { echo "::error::Missing Contact field"; exit 1; }�[0m

GitHub Actions: Governance / governance _ Well-Known (RFC 9116 + RSR): fix(parser): replace a Rust doc comment in the Parser module header

Conclusion: failure

View job details

##[group]Run MIXED=$(grep -rE 'src="http://|href="http://' --include="*.html" --include="*.htm" . 2>/dev/null | grep -vE 'localhost|127\.0\.0\.1|example\.com|lol/|node_modules/|third-party/|vendor/' | head -5 || true)
 �[36;1mMIXED=$(grep -rE 'src="http://|href="http://' --include="*.html" --include="*.htm" . 2>/dev/null | grep -vE 'localhost|127\.0\.0\.1|example\.com|lol/|node_modules/|third-party/|vendor/' | head -5 || true)�[0m
 �[36;1mif [ -n "$MIXED" ]; then�[0m
 �[36;1m  echo "::error::Mixed content (HTTP in HTML)"�[0m

GitHub Actions: Governance / 7_governance _ Security policy checks.txt: fix(parser): replace a Rust doc comment in the Parser module header

Conclusion: failure

View job details

##[group]Run FAILED=false
 �[36;1mFAILED=false�[0m
 �[36;1mWEAK_CRYPTO=$(grep -rE 'md5\(|sha1\(' --include="*.py" --include="*.rb" --include="*.js" --include="*.ts" --include="*.go" --include="*.rs" . 2>/dev/null | grep -v 'checksum\|cache\|test\|spec' | head -5 || true)�[0m
 �[36;1mif [ -n "$WEAK_CRYPTO" ]; then�[0m
 �[36;1m  echo "::warning::Weak crypto (MD5/SHA1) detected — ADVISORY, does not fail this job. Use SHA256+:"�[0m
 �[36;1m  echo "$WEAK_CRYPTO"�[0m
 �[36;1mfi�[0m
 �[36;1mHTTP_URLS=$(grep -rE 'http://[^l][^o][^c]' --include="*.py" --include="*.js" --include="*.ts" --include="*.go" --include="*.rs" --include="*.yaml" --include="*.yml" . 2>/dev/null | grep -v 'localhost\|127.0.0.1\|example\|test\|spec' | head -5 || true)�[0m
 �[36;1mif [ -n "$HTTP_URLS" ]; then�[0m
 �[36;1m  echo "::warning::HTTP URLs found — ADVISORY, does not fail this job. Use HTTPS:"�[0m
 �[36;1m  echo "$HTTP_URLS"�[0m
 �[36;1mfi�[0m
 �[36;1mSECRETS=$(grep -rEi '(api_key|apikey|secret_key|password)\s*[=:]\s*["\x27][A-Za-z0-9+/=]{20,}' --include="*.py" --include="*.js" --include="*.ts" --include="*.go" --include="*.rs" --include="*.env" . 2>/dev/null | grep -v 'example\|sample\|test\|mock\|placeholder' | head -3 || true)�[0m
 �[36;1mif [ -n "$SECRETS" ]; then�[0m
 �[36;1m  echo "::error::Potential hardcoded secrets detected — this FAILS the job:"�[0m

GitHub Actions: Governance / governance _ Security policy checks: fix(parser): replace a Rust doc comment in the Parser module header

Conclusion: failure

View job details

##[group]Run FAILED=false
 �[36;1mFAILED=false�[0m
 �[36;1mWEAK_CRYPTO=$(grep -rE 'md5\(|sha1\(' --include="*.py" --include="*.rb" --include="*.js" --include="*.ts" --include="*.go" --include="*.rs" . 2>/dev/null | grep -v 'checksum\|cache\|test\|spec' | head -5 || true)�[0m
 �[36;1mif [ -n "$WEAK_CRYPTO" ]; then�[0m
 �[36;1m  echo "::warning::Weak crypto (MD5/SHA1) detected — ADVISORY, does not fail this job. Use SHA256+:"�[0m
 �[36;1m  echo "$WEAK_CRYPTO"�[0m
 �[36;1mfi�[0m
 �[36;1mHTTP_URLS=$(grep -rE 'http://[^l][^o][^c]' --include="*.py" --include="*.js" --include="*.ts" --include="*.go" --include="*.rs" --include="*.yaml" --include="*.yml" . 2>/dev/null | grep -v 'localhost\|127.0.0.1\|example\|test\|spec' | head -5 || true)�[0m
 �[36;1mif [ -n "$HTTP_URLS" ]; then�[0m
 �[36;1m  echo "::warning::HTTP URLs found — ADVISORY, does not fail this job. Use HTTPS:"�[0m
 �[36;1m  echo "$HTTP_URLS"�[0m
 �[36;1mfi�[0m
 �[36;1mSECRETS=$(grep -rEi '(api_key|apikey|secret_key|password)\s*[=:]\s*["\x27][A-Za-z0-9+/=]{20,}' --include="*.py" --include="*.js" --include="*.ts" --include="*.go" --include="*.rs" --include="*.env" . 2>/dev/null | grep -v 'example\|sample\|test\|mock\|placeholder' | head -3 || true)�[0m
 �[36;1mif [ -n "$SECRETS" ]; then�[0m
 �[36;1m  echo "::error::Potential hardcoded secrets detected — this FAILS the job:"�[0m

GitHub Actions: Governance / governance _ Security policy checks: fix(parser): replace a Rust doc comment in the Parser module header

Conclusion: failure

View job details

##[group]Run set -uo pipefail
 �[36;1mset -uo pipefail�[0m
 �[36;1mDIR=.github/canonical-references�[0m
 �[36;1mif [ ! -d "$DIR" ]; then�[0m
 �[36;1m  echo "ℹ️  [R5] no $DIR/ — skipped (repo has not opted in)"�[0m
 �[36;1m  exit 0�[0m
 �[36;1mfi�[0m
 �[36;1mif ! command -v python3 >/dev/null 2>&1; then�[0m
 �[36;1m  echo "❌ [R5] python3 missing on runner — required for YAML rule parsing"�[0m
 �[36;1m  exit 2�[0m
 �[36;1mfi�[0m
 �[36;1mpython3 - <<'PY'�[0m
 �[36;1mimport os, sys, glob, subprocess�[0m
 �[36;1mtry:�[0m
 �[36;1m    import yaml�[0m
 �[36;1mexcept ImportError:�[0m
 �[36;1m    sys.exit("❌ [R5] PyYAML not installed on runner; install python3-yaml")�[0m
 �[36;1m�[0m
 �[36;1mdir_ = ".github/canonical-references"�[0m
 �[36;1mfiles = sorted(glob.glob(f"{dir_}/*.yml") + glob.glob(f"{dir_}/*.yaml"))�[0m
 �[36;1mif not files:�[0m
 �[36;1m    print(f"ℹ️  [R5] {dir_}/ has no .yml/.yaml rules — skipped")�[0m
 �[36;1m    sys.exit(0)�[0m
 �[36;1m�[0m
 �[36;1mtotal = 0�[0m
 �[36;1mfor rf in files:�[0m
 �[36;1m    with open(rf, encoding="utf-8") as fh:�[0m
 �[36;1m        cfg = yaml.safe_load(fh)�[0m
 �[36;1m    if not isinstance(cfg, dict):�[0m
 �[36;1m        print(f"❌ [R5] {rf}: top-level must be a mapping"); total += 1; continue�[0m
 �[36;1m    rid  = cfg.get("id", os.path.basename(rf))�[0m
 �[36;1m    desc = cfg.get("description", "")�[0m
 �[36;1m    pats = cfg.get("patterns") or []�[0m
 �[36;1m    canon = cfg.get("canonical_pointer", "")�[0m
 �[36;1m    scope = (cfg.get("scope") or {})�[0m
 �[36;1m    includes = scope.get("include") or []�[0m
 �[36;1m    if not pats or not includes:�[0m
 �[36;1m        print(f"❌ [R5:{rid}] missing patterns or scope.include in {rf}")�[0m
 �[36;1m        total += 1; continue�[0m
 �[36;1m    # exclude self-references�[0m
 �[36;1m    skip = set(["CHANGELOG.md", "CHANGELOG.adoc", rf])�[0m
 �[36;1m    if canon: skip.add(canon)�[0m
 �[36;1m    rule_hits = 0�[0m
 �[36;1m    for f_ in includes:�[0m
 �[36;1m        if f_ in skip or not os...

GitHub Actions: Governance / 12_governance _ Language _ package anti-pattern policy.txt: fix(parser): replace a Rust doc comment in the Parser module header

Conclusion: failure

View job details

##[group]Run SCRIPT=".standards-checkout/scripts/check-ts-allowlist.sh"
 �[36;1mSCRIPT=".standards-checkout/scripts/check-ts-allowlist.sh"�[0m
 �[36;1mif [ ! -f "$SCRIPT" ] && [ "$GITHUB_REPOSITORY" = "hyperpolymath/standards" ] \�[0m
 �[36;1m   && [ -f scripts/check-ts-allowlist.sh ]; then�[0m
 �[36;1m  SCRIPT="scripts/check-ts-allowlist.sh"�[0m
 �[36;1m  echo "Using this repository's own copy (standards self-check)."�[0m
 �[36;1mfi�[0m
 �[36;1mif [ ! -f "$SCRIPT" ]; then�[0m
 �[36;1m  echo "::error::check-ts-allowlist gate not found in standards@main or locally"�[0m

GitHub Actions: Governance / governance _ Language _ package anti-pattern policy: fix(parser): replace a Rust doc comment in the Parser module header

Conclusion: failure

View job details

##[group]Run SCRIPT=".standards-checkout/scripts/check-ts-allowlist.sh"
 �[36;1mSCRIPT=".standards-checkout/scripts/check-ts-allowlist.sh"�[0m
 �[36;1mif [ ! -f "$SCRIPT" ] && [ "$GITHUB_REPOSITORY" = "hyperpolymath/standards" ] \�[0m
 �[36;1m   && [ -f scripts/check-ts-allowlist.sh ]; then�[0m
 �[36;1m  SCRIPT="scripts/check-ts-allowlist.sh"�[0m
 �[36;1m  echo "Using this repository's own copy (standards self-check)."�[0m
 �[36;1mfi�[0m
 �[36;1mif [ ! -f "$SCRIPT" ]; then�[0m
 �[36;1m  echo "::error::check-ts-allowlist gate not found in standards@main or locally"�[0m

GitHub Actions: Governance / governance _ Language _ package anti-pattern policy: fix(parser): replace a Rust doc comment in the Parser module header

Conclusion: failure

View job details

##[group]Run SCRIPT=".standards-checkout/tools/policy/check-language-policy.sh"
 �[36;1mSCRIPT=".standards-checkout/tools/policy/check-language-policy.sh"�[0m
 �[36;1mif [ ! -f "$SCRIPT" ] && [ -f tools/policy/check-language-policy.sh ]; then�[0m
 �[36;1m  SCRIPT="tools/policy/check-language-policy.sh"�[0m
 �[36;1m  echo "Using this repository's own copy (standards self-check)."�[0m
 �[36;1mfi�[0m
 �[36;1mif [ ! -f "$SCRIPT" ]; then�[0m
 �[36;1m  echo "::error::language-policy gate not found in standards@main or locally"�[0m
🔇 Additional comments (1)
src/Sanctify/Parser.hs (1)

6-6: LGTM!


📝 Summary

Summary by CodeRabbit

  • Documentation
    • Updated the parser’s documentation comment.

Walkthrough

The parser documentation line now uses a Haskell -- comment prefix instead of //!.

Changes

Parser comment update

Layer / File(s) Summary
Update parser comment prefix
src/Sanctify/Parser.hs
The documentation line now uses -- instead of //!.

Priority: ➖ Normal

Estimated code review effort: 1 (Trivial) | ~2 minutes

Change: Bug fix

Suggested reviewers: metadatastician

Merge Risk: ⚪ Minimal · up to 43170

This corrects the parser comment syntax without changing parser behavior, and no additional merge risk is apparent.

Architecture Summary

Architecture risk: 🔵 Low · up to 43170

The change affects 1 system.

Changed systems: src

Architecture concerns
No architecture-level concerns identified.

Review details

Systems and components

  • observed — src (service) was modified; 1 changed file maps to changed impact.

Before / after behavior

  • observed — Modified behavior in src/Sanctify/Parser.hs: The documentation line’s //! prefix was replaced with --.
🚥 Pre-merge checks | ✅ 5
✅ Passed checks (5 passed)
Check name Status Explanation
Docstring Coverage ✅ Passed No functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check. Docstring coverage is scoped to functions touched by this diff. Analyzed 0 functions across 0…
Linked Issues check ✅ Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check ✅ Passed Check skipped because no linked issues were found for this pull request.
Title check ✅ Passed The title clearly describes the change: replacing a Rust-style comment with a Haskell comment in the Parser module header.
Description check ✅ Passed The description explains the parser error, the one-line fix, and the limits of the reported verification. It is directly related to the changeset.
✨ Finishing Touches
🛠️ Fix failing CI checks
  • Commit to this branch
  • Create a new PR
  • Autopilot · Keep fixing CodeRabbit findings and required CI, and resolving merge conflicts

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

A rabbit checks the parser line,
And swaps the prefix, neat and fine.
Two dashes mark the comment clear,
The old slash marks disappear.
The code rests quiet in its burrow.

Comment @coderabbitai help to get the list of available commands.

@coderabbitai

coderabbitai Bot commented Oct 6, 2026

Copy link
Copy Markdown
Contributor

Add Carrot credits or activate Agent usage billing to use Autopilot

@hyperpolymath
hyperpolymath merged commit b0eba0f into main Oct 6, 2026
30 of 32 checks passed
@hyperpolymath
hyperpolymath deleted the fix/parser-header-comment branch October 6, 2026 22:31
@coderabbitai

coderabbitai Bot commented Oct 6, 2026 •

Copy link
Copy Markdown
Contributor

⚠️ Agent ran but produced no code changes.

The CI failures may require manual intervention.

View agent analysis
I made no changes. None of these failures come from this PR, and fixing them means changing infrastructure that I'm not allowed to edit here.

**What the PR touches.** `git diff origin/main..HEAD` came back empty. The only content change is the comment line in `src/Sanctify/Parser.hs`, and no failing check reads Haskell sources.

**Why each check fails:**

1. **Licence consistency (Checks 1–2).** `LICENSE` contains the full MPL-2.0 text, but `sanctify-php.cabal:15` says `license: LicenseRef-PMPL-1.0-or-later`. The checker rejects the mismatch. Fixing it means changing either the build manifest or the licence file. I can't edit the manifest, and choosing the licence is a decision for the owner. It already fails on `main` and is tracked in #109.
2. **Actions lockfile verify (Checks 3–4).** There are stale `actions.lock` entries. That is CI infrastructure, it already fails on `main`, and it's tracked in #108.
3. **The other governance jobs (Checks 5–16).** The log excerpts stop before any error is printed, so the exact cause isn't confirmed. Each job first checks whether a gate script fetched from the pinned `hyperpolymath/standards` revision exists, and stops with an error if it doesn't. The likely cause is that this fetch failed or the pinned revision doesn't have the script. That would have to be fixed in the workflows or in the standards repo. The Well-Known step can't be failing because of a bad `security.txt`, since this repo doesn't have one; in that case the step only warns and exits 0.

To clear these checks, the owner has to decide which licence is correct (#109), someone has to refresh `actions.lock` (#108), and someone has to look into why the standards scripts aren't being fetched in the governance workflow. None of that belongs in this PR.

hyperpolymath added a commit that referenced this pull request Oct 7, 2026
…dabot ecosystems (#111)

## Summary

Dependabot moved three `uses:` lines to new commits, but
`.github/workflows/actions.lock` still named the old ones. GitHub
matches lock entries against the **literal** ref string, so it refused
to start the affected workflows. `Haskell CI` has ended in
`startup_failure` on every run since 2026-10-03, and `governance /
Actions lockfile verify` is red on `main`.

| Action | Old lock entry | Now (matches the workflow) | Workflows |
|---|---|---|---|
| `haskell-actions/setup` | `6037f336` (v2.12.0) | `0f8e8c99` (v2.12.1)
| `haskell.yml`, `casket-pages.yml` |
| `github/codeql-action` | `1c5b6756` (v4.38.1) | `2892aa5e` (v4.38.2) |
`codeql.yml` |

This also corrects the stale version comments beside those pins: the
codeql pins said `# v3` beside a v4.38.2 commit.

A second commit trims `.github/dependabot.yml` to `github-actions` only.
This is a Haskell (cabal) project with no `package.json`, Python
requirements or `Cargo.toml`, so the npm, pip and cargo update jobs
failed on every run (`/package.json not found`). Dependabot has no
Haskell ecosystem.

Closes #108

## Type of change

- [x] 🐛 Bug fix (non-breaking change that fixes an issue)
- [ ] ✨ New feature: none.
- [ ] 💥 Breaking change: no.
- [ ] 🕳️ Soundness fix: not a checker false-negative.
- [ ] 📖 Documentation: no.
- [ ] 🧹 Refactor: no.
- [ ] ⚡ Performance: no.
- [x] 🔧 Build / CI / tooling: `actions.lock`, plus comment-only edits in
two workflows.

## 📌 New pins

Head SHA: **`33dd482f28f3de4f80952615716350d83dcee60c`**

`actions.lock` entries changed. The workflow `uses:` lines are
unchanged; only the lock catches up to them:
- **`haskell-actions/setup@0f8e8c99d88aeb3fbfd523f1ef2c6f762d10d64d`** →
tag `v2.12.1` (also `v2.12`, `v2`), resolved via the GitHub tags API.
- **`github/codeql-action@2892aa5e19bbd11bc0cff5427e3b750a04d9e3c2`** →
tag `v4.38.2` (also `v4`).

## How has this been verified?

- **The lock is hand-edited, deliberately.** `gh actions-lock` in fix
mode was tried first. It rewrote all 19 workflows, turning SHA pins into
tags (e.g. `haskell-actions/setup@v2.12.1`) and re-keying the lock to
match. This repo has `sha_pinning_required: true` (`gh api
repos/hyperpolymath/sanctify-php/actions/permissions`), so that output
would itself stop the workflows from starting. It was discarded.
- **Matched pair** on the unchanged workflow bytes, with `gh
actions-lock --no-fix`:
- old lock: `3 of 19 workflows failed verification` (3 `Unused lockfile
entry` findings), rc 1.
  - new lock: rc 0.
- Every new lock key is the literal `owner/repo@sha` string that the
workflow's `uses:` names.
- `dependabot.yml`: the last runs of `npm_and_yarn` and `pip` both
failed (2026-08-13; npm again on 2026-10-01: `Error during file
fetching; aborting: /package.json not found`). `git ls-files` shows
`sanctify-php.cabal` and no npm, pip or cargo manifest.
- Both actions are on the repo's `selected-actions` allow-list, so the
allow-list is not the cause of the startup failure.

**Horizon of this check:** `gh actions-lock` resolves refs, so its rc 0
alone does not prove GitHub will start the workflows. The literal-string
match does, and this PR's own `Haskell CI` and `CodeQL` runs are the
real proof. If `Haskell CI` now starts and fails, that is a real compile
result, the first since the fix in #107.

## Checklist

- [x] My commits are **signed** (`git commit -S`). `git log
--format=%G?` → `G`.
- [x] I ran the project's own checks locally: `gh actions-lock
--no-fix`, rc 0.
- [ ] New files carry the correct `SPDX-License-Identifier`: no new
files.
- [ ] Docs are updated: no docs are affected.
- [x] I have not introduced a soundness hole: no pin is loosened, and
every `uses:` stays SHA-pinned.

## Notes for reviewers

The owner approved hand-writing this lock delta on 2026-10-07, because
the generator cannot produce a SHA-keyed lock without de-pinning the
workflows.

🤖 Generated with [Claude Code](https://claude.com/claude-code)

https://claude.ai/code/session_012kgrMQRhSmZMBbF9Ui1zBw

---------

Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant