From 2029699dd59fc9b34ca3f6a093132b47dbf671e2 Mon Sep 17 00:00:00 2001 From: "Jonathan D.A. Jewell" <6759885+hyperpolymath@users.noreply.github.com> Date: Fri, 9 Oct 2026 00:15:53 +0100 Subject: [PATCH] fix(governance): make the actions-lock ledger reachable under bash -e The "Check locked or SHA-pinned actions" step runs under the runner's default `bash -e {0}`; `set -uo pipefail` does not clear -e. The bare gate call followed by `rc=$?` therefore never reached the capture: gate exit 3 (missing lock) killed the step before the shrink-only ledger was read. Since 4f7f02ca (#899, 2026-09-22) no ledgered repository has been excused, and since ENFORCE_FROM 2026-10-01 every lockless ledgered caller pinned at or after 4f7f02ca has been red on this job. `rc=0; gate || rc=$?` keeps the exit code, the same idiom this file already uses at the two other exit-status captures that lack `set +e`. Verified locally by running the extracted step script under /usr/bin/bash -e against disposable copies (CI cannot exercise this path here: standards carries a lock, so its own gate exits 0): variant workflows repository rc ledger branch unfixed block hyperpolymath/jaffascript 3 never reached unfixed block (not ledgered) 3 never reached unfixed KYAML hyperpolymath/jaffascript 1 never reached fixed block hyperpolymath/jaffascript 0 ::notice:: LEDGERED fixed block (not ledgered) 3 NOT among them fixed KYAML hyperpolymath/jaffascript 1 NOT among them Co-Authored-By: Claude Opus 5.5 Claude-Session: https://claude.ai/code/session_01GpUzjdhWFi26k6s7AWxYcf --- .github/workflows/governance-reusable.yml | 9 +++++++-- 1 file changed, 7 insertions(+), 2 deletions(-) diff --git a/.github/workflows/governance-reusable.yml b/.github/workflows/governance-reusable.yml index a082badb0..e4c8f0b61 100644 --- a/.github/workflows/governance-reusable.yml +++ b/.github/workflows/governance-reusable.yml @@ -1498,8 +1498,13 @@ jobs: # The gate delegates lockfile verification to the authoritative # verifier, staged into RUNNER_TEMP above. export ACTIONS_LOCK_VERIFIER="$RUNNER_TEMP/update-actions-lock.sh" - bash "$RUNNER_TEMP/check-actions-lock-gate.sh" - rc=$? + # The step runs under the runner's default `bash -e`, which `set -uo + # pipefail` above does not undo. A bare gate call followed by `rc=$?` + # therefore never reaches the capture: exit 3 killed the step before + # the ledger below was read, so no ledgered repository was ever + # excused. `|| rc=$?` keeps the gate's exit code for the ledger. + rc=0 + bash "$RUNNER_TEMP/check-actions-lock-gate.sh" || rc=$? # Shrink-only exemption ledger (.machine_readable/lock-allow.txt in # standards, guarded by scripts/check-exemption-ratchet.sh so it can