FEAT-093 refinement: close the window where main goes red (scry#130) - #175
Merged
Conversation
Operating the gate exposed a hole in the procedure it enforces. Landing a job while its required-checks.txt entry arrives in a SEPARATE PR leaves main AND every open PR red until that follow-up merges. #167 did exactly that: the moment it merged, main failed its own drift gate and #168/#169 went red on a file they could not fix. The fix is structural, not another comment. The gate now FAILS a PR that adds a requirable job which is not in required-checks.txt, so the job and its entry ship together and the window does not exist. VERIFIED ON THE REAL REPO, both directions: job added, no file entry -> exit 1, naming it and quoting the instruction same job WITH its entry -> exit 0 (pending the ruleset update only) restored -> exit 0 Plus two new self-test cases covering exactly those, 7 in total. The procedure in ci.yml is now three steps with no red window: 1. in the SAME PR: add the job AND its required-checks.txt entry 2. after merge: add the context to the ruleset (instant, via the API) 3. rebase every open PR Steps 2 and 3 were each learned by getting them wrong. A required context whose job does not exist deadlocks everything; a job whose context does not exist deadlocks nothing. The asymmetry is why the ordering matters. drift-self-test=0 drift-file=0 gate-coverage=0 trailer-self-test=0 claim-check=0 rivet=0 fmt=0. Claude-Session: https://claude.ai/code/session_01KkNzkNYzPh7366DkNijeNc Co-authored-by: Claude Opus 5 <noreply@anthropic.com>
avrabe
added a commit
that referenced
this pull request
Aug 27, 2026
Both shipped and CI-verified; leaving them proposed understates the release the same way promoting them early would overstate it. FEAT-091 (#167, 13/13 green) -- commit traceability. Its gate's --self-test PASSES and the real check PASSES on main against HEAD~1..HEAD, and the job runs in CI as a REQUIRED check. FEAT-092 (#172, 13/13 green) -- one operator, one name. Its oracle re-run on main just now; the naming-only claim was measured, not argued (every advisory-code count identical on a real module, leaks 2,800 -> 71). NOT promoted, and the reason matters: FEAT-093 -- merged in #167 and green, but #175 is OPEN and adds ACs to it. Promoting now would produce an `accepted` artifact that immediately gains unmet criteria. It goes accepted after #175 lands, not before. FEAT-089 -- filed, not built; its AC#1 demands a test still red by design. FEAT-057 / FEAT-065 / REQ-021 -- unbuilt. FEAT-064 -- AC1 still falsified, so REQ-020 stays blocked. rivet=0 claim-check=0 drift-gate=0 fmt=0. Claude-Session: https://claude.ai/code/session_01KkNzkNYzPh7366DkNijeNc Co-authored-by: Claude Opus 5 <noreply@anthropic.com>
📐 rivet artifact deltaPR: #175 Base SHA: Validationhead — `rivet validate` resultbase — `rivet validate` result (for comparison)Artifact stats
full stats — headDiff (base → head)AADL model — headPosted by the |
avrabe
added a commit
that referenced
this pull request
Aug 27, 2026
Both shipped and CI-verified; leaving them proposed understates the release the same way promoting them early would overstate it. FEAT-091 (#167, 13/13 green) -- commit traceability. Its gate's --self-test PASSES and the real check PASSES on main against HEAD~1..HEAD, and the job runs in CI as a REQUIRED check. FEAT-092 (#172, 13/13 green) -- one operator, one name. Its oracle re-run on main just now; the naming-only claim was measured, not argued (every advisory-code count identical on a real module, leaks 2,800 -> 71). NOT promoted, and the reason matters: FEAT-093 -- merged in #167 and green, but #175 is OPEN and adds ACs to it. Promoting now would produce an `accepted` artifact that immediately gains unmet criteria. It goes accepted after #175 lands, not before. FEAT-089 -- filed, not built; its AC#1 demands a test still red by design. FEAT-057 / FEAT-065 / REQ-021 -- unbuilt. FEAT-064 -- AC1 still falsified, so REQ-020 stays blocked. rivet=0 claim-check=0 drift-gate=0 fmt=0. Claude-Session: https://claude.ai/code/session_01KkNzkNYzPh7366DkNijeNc Co-authored-by: Claude Opus 5 <noreply@anthropic.com>
avrabe
added a commit
that referenced
this pull request
Aug 27, 2026
…mplete FEAT-093 was deliberately held back from the earlier promotion because #175 was OPEN and adding acceptance criteria to it; promoting then would have produced an `accepted` artifact that immediately acquired unmet criteria. #175 has now merged, so the criteria are complete AND met. Evidence re-run on main: the gate's 7-case --self-test passes, file mode passes, and live mode passes with `file agrees: True` -- the ruleset, the checked-in file and the CI jobs are all in agreement. Folded in here rather than opened separately because #176 still had not started CI. Same trade as FEAT-071 a moment ago, and the same reason. rivet=0 claim-check=0 drift-gate=0 fmt=0. Claude-Session: https://claude.ai/code/session_01KkNzkNYzPh7366DkNijeNc Co-authored-by: Claude Opus 5 <noreply@anthropic.com>
avrabe
added a commit
that referenced
this pull request
Aug 27, 2026
…→4 (#176) * Promote FEAT-091 / FEAT-092 to accepted — v3.4.0 not-ready 7 -> 5 Both shipped and CI-verified; leaving them proposed understates the release the same way promoting them early would overstate it. FEAT-091 (#167, 13/13 green) -- commit traceability. Its gate's --self-test PASSES and the real check PASSES on main against HEAD~1..HEAD, and the job runs in CI as a REQUIRED check. FEAT-092 (#172, 13/13 green) -- one operator, one name. Its oracle re-run on main just now; the naming-only claim was measured, not argued (every advisory-code count identical on a real module, leaks 2,800 -> 71). NOT promoted, and the reason matters: FEAT-093 -- merged in #167 and green, but #175 is OPEN and adds ACs to it. Promoting now would produce an `accepted` artifact that immediately gains unmet criteria. It goes accepted after #175 lands, not before. FEAT-089 -- filed, not built; its AC#1 demands a test still red by design. FEAT-057 / FEAT-065 / REQ-021 -- unbuilt. FEAT-064 -- AC1 still falsified, so REQ-020 stays blocked. rivet=0 claim-check=0 drift-gate=0 fmt=0. Claude-Session: https://claude.ai/code/session_01KkNzkNYzPh7366DkNijeNc Co-authored-by: Claude Opus 5 <noreply@anthropic.com> * Also promote FEAT-071 — v3.3.0 not-ready 6 -> 5 #174 landed FEAT-071 with 13/13 green, so it belongs in this pass rather than a follow-up. Its oracle re-run on main just now: the scope manifest reaches the feed as data, and the anti-drift property (every not-proven item present in BOTH the page and the feed) holds. That property was mutation-checked when it landed -- emitting empty strings in the feed while the page kept them kills the test. Folded in here rather than opened separately because #176 had not started CI, so it costs nothing; had it been mid-run the trade would have gone the other way. rivet=0 claim-check=0 drift-gate=0 fmt=0. Claude-Session: https://claude.ai/code/session_01KkNzkNYzPh7366DkNijeNc Co-authored-by: Claude Opus 5 <noreply@anthropic.com> * Also promote FEAT-093 — its refinement landed, so its criteria are complete FEAT-093 was deliberately held back from the earlier promotion because #175 was OPEN and adding acceptance criteria to it; promoting then would have produced an `accepted` artifact that immediately acquired unmet criteria. #175 has now merged, so the criteria are complete AND met. Evidence re-run on main: the gate's 7-case --self-test passes, file mode passes, and live mode passes with `file agrees: True` -- the ruleset, the checked-in file and the CI jobs are all in agreement. Folded in here rather than opened separately because #176 still had not started CI. Same trade as FEAT-071 a moment ago, and the same reason. rivet=0 claim-check=0 drift-gate=0 fmt=0. Claude-Session: https://claude.ai/code/session_01KkNzkNYzPh7366DkNijeNc Co-authored-by: Claude Opus 5 <noreply@anthropic.com> --------- Co-authored-by: Claude Opus 5 <noreply@anthropic.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Operating the drift gate exposed a hole in the procedure it enforces — and the fix is
structural rather than another comment.
The hole
Landing a job while its
required-checks.txtentry arrives in a separate PR leavesmain and every open PR red until that follow-up merges.
#167 did exactly that. The moment it merged, main failed its own drift gate, and
#168/#169 went red on a file they had no way to fix — they were blocked on #170.
The fix
The gate now fails a PR that adds a requirable job which is not in
required-checks.txt, so the job and its entry ship together and the window doesn'texist.
Verified on the real repo, both directions:
Plus two new self-test cases covering exactly those (7 total).
The procedure, now with no red window
required-checks.txtentrySteps 2 and 3 were each learned by getting them wrong.
★ The asymmetry that makes the ordering matter: a required context whose job doesn't
exist deadlocks everything — the check can never report. A job whose context isn't
required deadlocks nothing; it's merely unenforced. So the job must always lead and
the context must always follow, never the reverse.
drift-self-test=0 drift-file=0 gate-coverage=0 trailer-self-test=0 claim-check=0 rivet=0 fmt=0🤖 Generated with Claude Code
https://claude.ai/code/session_01KkNzkNYzPh7366DkNijeNc