feat(echidnabot): pinned sync from hyperpolymath/echidnabot + drift gate [mass-delete-ok] - #586
Merged
Merged
Conversation
…ate [mass-delete-ok] Owner decision 2026-10-05: standalone hyperpolymath/echidnabot is canon. bots/echidnabot/ becomes a pinned sync of it instead of a hand-maintained fork. - bots/echidnabot/FLEET-SYNC.json pins hyperpolymath/echidnabot@bf2c0ff (JCS-canonical lock) and lists the vendored crate surface (src, tests, proofs fixtures, benches, fuzz, migrations, config, Cargo.*, Containerfile, licences, README). Upstream docs/packaging/wiki stay upstream (thin slot). - scripts/sync-vendored-bot.sh: --check (index vs pinned tree, blob ids and modes) and --sync [--rev SHA]; rev must be 40-hex and reachable from the upstream branch. scripts/tests/sync-vendored-bot.sh: 21 offline assertions with planted controls. - .github/workflows/vendored-bot-drift.yml: runs the tests and the drift check on PRs, pushes to main and weekly; reports pin lag as a notice. - dependabot: drop /bots/echidnabot (bumps land upstream, arrive by pin bump); file converted to KYAML, which also repairs a mis-nested ignore block that sat under the github-actions groups key. - CANONICAL_SOURCE.adoc rewritten for the pinned-sync model; lists the six fleet-only files the switch drops and how to recover them. - actions.lock resynced with gh actions-lock (main carried an unused codeql-action entry; codeql.yml now names v4.38.2, the same SHA it already ran, 2892aa5). - shared-context/findings: repoint dangling echidna/latest.json; drop three byte-identical duplicate echidna scans and two zero-byte non-marker files; drop three misfiled root hypatia-echidnabot-* files (an error log, a log-prefixed partial and a bare array superseded by findings/echidnabot/); echidnabot/latest.json becomes the symlink submit-finding.sh expects. - enroll-hypatia-fleet.sh: discover clones at depth 1-3 (star-list layout); depth 1 found 3 of 406 hyper-repos clones. tests/enroll-discovery-test.sh with a depth-1 planted control, wired into e2e.yml. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Contributor
|
Important Review skippedToo many files! This PR contains 157 files, which is 57 over the limit of 100. To get a review, reduce the PR to 100 files or fewer by splitting it into smaller PRs or changing its base branch. Upgrade to a paid plan to raise the limit. This review couldn't start because sufficient usage credits or metered capacity aren't available. Add credits or update usage-based reviews in the billing tab, then retry. ⚙️ Run configuration
⛔ Files ignored due to path filters (3)
📒 Files selected for processing (157)
You can disable this status message by setting the
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
bots/echidnabot/proofs/ carries deliberate Admitted/sorry stubs that echidnabot's protocol-contract tests must flag. They are test fixtures, not trusted base. Without this file check-trusted-base.sh fails with 2 undocumented escape hatches; with it, both are exempted. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
GitHub rejects a workflow with a duplicate mapping key before any job is created; the Workflow security linter flags it on main too. Keep the 'stable' toolchain block (the earlier 'master' block was overridden anyway). Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
This was referenced Oct 5, 2026
Open
- scripts/tests/dispatch-paths.sh: assert the dispatch quarantine on the production runner (exit 78, BLOCKED, no outcome state) and run the path/outcome contracts against a test-only seam copy with exactly the interlock removed. Planted control: the seam copy must not be refused; the test fails outright once the interlock is gone. Closes #587. - bots/gsbot/Cargo.lock: rustls 0.23.40 -> 0.23.45 (RUSTSEC-2026-0285), rustls-webpki 0.103.13 -> 0.103.15; cargo-deny advisories clean. - .hypatia-baseline.json: baseline four code_safety findings in vendored bots/echidnabot (fix upstream; tracking #588, expires 2027-01-05). Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
Owner decision (2026-10-05): standalone
hyperpolymath/echidnabotis canon.bots/echidnabot/is now a pinned sync of it, with a CI drift check, instead of a hand-maintained fork.bots/echidnabot/FLEET-SYNC.jsonpinshyperpolymath/echidnabot@bf2c0ff(upstreammainhead at time of writing). Only the crate surface is vendored; upstream docs/packaging/wiki stay upstream (bots/slots are thin, CLAUDE.md invariant 6).scripts/sync-vendored-bot.sh(--check/--sync [--rev SHA]) +scripts/tests/sync-vendored-bot.sh(21 offline assertions, planted controls: edited file, extra file, mode change, non-canonical lock, short/error-body rev, side-branch rev, empty include)..github/workflows/vendored-bot-drift.yml: runs on PRs, pushes tomain, weekly; reports how far upstream is ahead of the pin./bots/echidnabot, so the copy is never bumped independently.dependabot.ymlconverted to KYAML (D280, non-workflow YAML). This also repairs anignore:block that was mis-nested under the github-actionsgroupskey.CANONICAL_SOURCE.adocrewritten. It lists the six fleet-only files that the switch drops (recoverable from8a4f983).tests/webhook_e2e_test.rsshould be promoted upstream.actions.lockresynced withgh actions-lock. Onmain,--no-fixreported an unusedcodeql-action@1c5b675entry.codeql.ymlnow namesv4.38.2, which is the SHA it already ran (2892aa5), so CodeQL behaviour is unchanged.shared-context/findingscleanup:echidna/latest.json..processedmarkers are kept.hypatia-echidnabot-*files: an error log, a log-prefixed partial and a bare array, all superseded byfindings/echidnabot/.echidnabot/latest.jsonis now the symlink thatsubmit-finding.shwrites.scripts/enroll-hypatia-fleet.sh: discovery now covers the star-list layout (depth 1–3). At depth 1 it found 3 of 406 clones underhyper-repos/. Newtests/enroll-discovery-test.shwith a depth-1 planted control, wired intoe2e.yml.[mass-delete-ok]: 65 tracked files are deliberately removed, mostly upstream-only docs/packaging dropped from the vendored slot. All of them remain in history.Verification (local)
bash scripts/tests/sync-vendored-bot.sh→ 21 passed, 0 failedbash scripts/sync-vendored-bot.sh echidnabot --check→ matches, 75 entriesbash tests/enroll-discovery-test.sh→ ok (incl. planted control)gh actions-lock --no-fix→ cleankyaml-format.sh --check .github/dependabot.yml→ cleandocstring-scan.sh --staged --check→ 18/18 documentedNot covered by this PR: per-repo
FLEET-ENROLLMENT.a2mldirectives live in the target repos, and those repos' own PRs carry them.CI follow-ups in this PR
Dispatch path and outcome contracts(required, red onmainsince Quarantine fleet mutations pending directive enforcement; audit repository policies #571): the test now asserts the quarantine on the production runner and runs the path/outcome contracts through a test-only seam copy, with planted controls. Closes Required check 'Dispatch path and outcome contracts' fails on main since the automation quarantine (#571) #587.GSBot build, tests and dependency security(required, red onmain):bots/gsbotrustls 0.23.40 → 0.23.45 for RUSTSEC-2026-0285;cargo deny ... check advisoriesis clean locally.governance / Validate Hypatia BaselineandHypatia: the four new findings are in vendored upstream echidnabot code, which the drift gate forbids editing here. They are baselined withtracking_issueandexpires_at.Deferred red checks (AGENTS.md §5c item 3)
Hypatia: deferred to Vendored echidnabot: 4 Hypatia code_safety findings must be fixed upstream (baselined in #586) #588 (vendored echidnabot findings must be fixed upstream; baselined here).governance / Validate Hypatia Baseline: deferred to Vendored echidnabot: 4 Hypatia code_safety findings must be fixed upstream (baselined in #586) #588.scorecard / Run Scorecard PR: deferred to Scorecard reconciliation fails on casket-pages.yml (main and PRs) #589 (pre-existing onmain; reconciler fails oncasket-pages.yml, which this PR does not touch).Codeac analyze results: deferred to Codeac analyze results fails on main: service cannot analyse the repo #590 (pre-existing onmain; external service cannot analyse the repo).🤖 Generated with Claude Code