Skip to content

fix(gates): pin what reusables fetch; gate packaging on capability - #1120

Merged
hyperpolymath merged 1 commit into
mainfrom
fix/red-gates-pin-and-scope
Oct 1, 2026
Merged

hyperpolymath merged 1 commit into
mainfrom
fix/red-gates-pin-and-scope

Conversation

@hyperpolymath

Copy link
Copy Markdown
Owner

Why

Three checks have been red on most estate PRs: Governance / Actions lockfile verify, Governance / Guix packaging policy (Nix retired), and Hypatia Security Scan / Hypatia Neurosymbolic Analysis. The shared root cause is that pinned reusable workflows pull unpinned things at run time (standards scripts from ref: main, hypatia HEAD, and an unpinned gh-actions-lock). On top of that, the Guix gate demands packaging from repos the canon exempts.

What

  • hypatia-scan-reusable.yml:
    • New hypatia-ref input, defaulting to 51ab6496 (hypatia#895, which maps warn to medium). HEAD is still available as a canary. The value is validated as a 40-hex SHA or HEAD.
  • governance-reusable.yml:
    • Every standards sparse checkout now uses job.workflow_sha (verified in laniakea run 36930093550 to resolve to the reusable's own pinned commit) instead of ref: main.
    • gh-actions-lock is installed with --pin v0.1.6.
    • The package-policy step ships check-rsr-profile.sh and template-capability-gates.toml.
  • check-package-policy.sh:
    • Packaging is required only where rsr-profile declares reproducible-build or container. In rsr-criteria-v2, 1.2.1, 1.2.3 and 8.1.4 are gated criteria, not universal ones.
    • Real packaging passes before the profile is even read.
    • Every Containerfile is tried, and .clusterfuzzlite/ is ignored.
    • A stub guix.scm fails only where the capability is declared.
    • An unresolvable profile is named in a warning and treated as declaring nothing. A missing resolver refuses to run.
    • The Nix ban is unchanged.

Evidence

  • Local census over 325 governance callers: 86 red before, 20 after. All 20 are Nix-only, and the per-repo sweep removes their flakes. 0 repos that were green turn red.
  • governance-gates-505-test.sh: 39/39.
    • Mutant control: forcing REQUIRED="" makes 8 cases fail.
    • New known-answer cases cover: no profile; a profile without the capability; a stub with and without the capability; a declared container with a TODO-only Containerfile; a stub sorting before the real Containerfile; fuzz-only; an unresolvable profile; a missing resolver.
  • governance-reusable-contract-test.sh: PASS.
  • actionlint flags job.workflow_sha as unknown. That is a gap in its schema: main already uses the expression at the staleness job, and the live run shows it resolving.

Follow-ups (separate PRs)

  • A central Dependabot actions.lock regeneration workflow. This needs a GitHub App credential, which is an owner step.
  • Removing stale Nix references (.claude/CLAUDE.md, rsr-audit, the template-capability-gates.toml:60 pattern) and the stub build/guix.scm in rsr-template-repo.
  • A caller sweep to bump pins to this commit.

🤖 Generated with Claude Code

https://claude.ai/code/session_016L7GFo3yGQ2vK9YgKL2wsP

Three checks were red on most estate PRs because pinned reusable workflows
pulled unpinned things at run time, and the Guix gate contradicted the canon.

- hypatia-scan-reusable: new `hypatia-ref` input, default 51ab6496 (the
  hypatia#895 warn->medium fix). "HEAD" keeps a canary path. Value is
  validated as 40-hex or HEAD.
- governance-reusable: every standards sparse checkout uses
  job.workflow_sha (the reusable's own commit) instead of `ref: main`, so a
  caller's pin pins the scripts too. gh-actions-lock installed --pin v0.1.6.
  The package-policy step ships check-rsr-profile.sh and the gates table.
- check-package-policy.sh: packaging is required only where the
  rsr-profile declares reproducible-build or container (rsr-criteria-v2
  1.2.1/1.2.3/8.1.4 are gated, not universal). Real packaging passes before
  the profile is read; every Containerfile is tried; .clusterfuzzlite/ is
  ignored; a stub guix.scm fails only where the capability is declared; an
  unresolvable profile is named in a warning; the Nix ban still fails
  regardless of profile.

Census over 325 local governance callers: 86 red before, 20 after (all
Nix-only, removed by the per-repo sweep); no previously-green repo turns red.
Tests: governance-gates-505 39/39, with a mutant (REQUIRED forced empty)
killed by 8 cases.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_016L7GFo3yGQ2vK9YgKL2wsP
@coderabbitai

coderabbitai Bot commented Oct 1, 2026

Copy link
Copy Markdown
Contributor

Warning

Review limit reached

You've used all free OSS reviews for now. Wait for the free limit to reset to keep reviewing this public repository.

Next included review available in 51 minutes.

Check out review usage here.

View limit details

Limit details: You’ve used the included review currently available.

Learn how review limits work.

Review configuration:

⚙️ Run configuration

Configuration used: Organization UI

Review profile: ASSERTIVE

Plan: Advanced

Run ID: 219baa86-08e5-4e4e-845f-6ed1c94b059e

📥 Commits

Reviewing files that changed from the base of the PR and between 39ee4ec and b162519.

📒 Files selected for processing (4)
  • .github/workflows/governance-reusable.yml
  • .github/workflows/hypatia-scan-reusable.yml
  • scripts/check-package-policy.sh
  • scripts/tests/governance-gates-505-test.sh
  • Autopilot · Keep fixing CodeRabbit findings and required CI, and resolving merge conflicts

Autopilot is currently an internal CodeRabbit preview.


Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@hyperpolymath
hyperpolymath merged commit 10e0b6f into main Oct 1, 2026
47 of 49 checks passed
hyperpolymath added a commit that referenced this pull request Oct 1, 2026
…ate (#1121)

Follow-up to #1120. It clears the two remaining reds on `main`.

**Validate Hypatia Baseline (red on main):**
- hypatia#895 maps severity `warn` to `medium`. Since then, the 20
RE001/RE005 acknowledgements in `.hypatia-baseline.json` (recorded as
`warn`) no longer match, so every caller whose baseline has `warn`
entries breaks.
- `scripts/apply-baseline.sh` now treats `warn` and `medium` as one
tier.
- Measured on the failing run's 20 kept findings: 20 suppressed, 0 kept.
- New tests: warn↔medium matches in both directions, and a different
tier stays unmatched. Main's matcher fails both new positive cases
(mutant).
- The governance-reusable baseline job also floated on hypatia HEAD. It
now pins through a `hypatia-ref` input (default `51ab6496`). `HEAD`
remains accepted as an explicit opt-in for canaries.

**Repo self-tests (red on main):**
- The lock gate staged standards at a hardcoded third pin (`5f82b635`).
That pin was one change behind by construction and went stale again with
#1119.
- It now stages at `${{ job.workflow_sha }}`, the reusable's own commit,
which is exactly what the caller pinned.
- `check-lock-gate-pin-freshness.sh` and both contract tests accept that
expression. They still refuse `github.workflow_sha`/`github.sha`, which
name the caller's commit (planted negatives: all three guards go red).

**Package policy:** a caller pinned before the capability resolver
existed now gets a warning and is treated as undeclared, instead of
failing.

Local: `run-shell-test-suite.sh`, all 69 files pass. `docstring-scan
--check` passes.

🤖 Generated with [Claude Code](https://claude.com/claude-code)

https://claude.ai/code/session_016L7GFo3yGQ2vK9YgKL2wsP

---------

Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com>
hyperpolymath added a commit to hyperpolymath/awesome-haskell that referenced this pull request Oct 3, 2026
…ate (#16)

## Issue

Closes the downstream half of #15 (2 red
checks on the default branch, deferred from #14).

## Diagnosis (both checks, at source)

1. `Governance / governance / Code quality + docs` — `Check
documentation` fails with **`Missing required documentation:
CONTRIBUTING`**. The gate (`hyperpolymath/standards`
`scripts/check-docs-presence.sh`) split README/LICENSE (blocking
immediately) from CONTRIBUTING (warn until 2026-08-21, then blocking).
The cutoff has passed; this repo never carried a CONTRIBUTING, so the
red is genuine and this PR is the whole fix.

2. `Governance / governance / Guix packaging policy (Nix retired)` —
`Package policy violation: no packaging found.` The old script demanded
packaging of **every** repo. The owner ruling of 2026-10-01 (landed
upstream as hyperpolymath/standards#1120 at 22:30Z, **10 h after** the
red run 36863734189 timestamped 12:43Z) retires that: packaging is now
gated on the repo's `rsr-profile` declaring `reproducible-build` or
`container`. This repo is a build-less curated list with no profile ⇒
*not applicable*, deliberately neutral — satisfying acceptance criterion
2's "linked change with its reason". No fake `guix.scm` stub is added;
the script flags stubs as violations. The reasoning is recorded at
source in the new CONTRIBUTING.

## Changes

- Adds `CONTRIBUTING.adoc` at the repo root — AsciiDoc per estate doc
policy, one of the paths the gate accepts and GitHub auto-discovers.
Content mirrors `GOVERNANCE.adoc` (licensing, review rules) and
`MAINTAINERS`, documents the awesome-list entry conventions of
`README.adoc`, the CI contract, and the packaging-policy
non-applicability rationale.
- No workflow, pin, lockfile or README change — `actions.lock`, the SHA
pin of `governance-reusable.yml`, and every other gate are untouched.

## Local pre-run of the exact gate scripts

- `check-docs-presence.sh .` → `✅ Core documentation present (README,
LICENSE, CONTRIBUTING)` (exit 0; was exit 1 before this PR)
- `check-package-policy.sh .` (in the CI's script-only shape, resolver
absent) → `✅ Packaging not applicable` (exit 0)
- `check-licence-consistency.sh .` → exit 0 (unchanged)
- `check-trusted-base.sh .` → exit 0 (unchanged)
- R5b version-string drift scan over root `\*.adoc`/`\*.md`: clean
- Editor hygiene on the new file: LF, no trailing whitespace, final
newline

🤖 Generated with [Claude Code](https://claude.com/claude-code) via Arena
Agent Mode

---------

Co-authored-by: arena-agent <297053741+arena-agent@users.noreply.github.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant