Skip to content

feat(echidnabot): pinned sync from hyperpolymath/echidnabot + drift gate [mass-delete-ok] - #586

Merged
hyperpolymath merged 4 commits into
mainfrom
firstrun/20261005
Oct 5, 2026
Merged

hyperpolymath merged 4 commits into
mainfrom
firstrun/20261005

Conversation

@hyperpolymath

@hyperpolymath hyperpolymath commented Oct 5, 2026 •

Copy link
Copy Markdown
Owner

Summary

Owner decision (2026-10-05): standalone hyperpolymath/echidnabot is canon. bots/echidnabot/ is now a pinned sync of it, with a CI drift check, instead of a hand-maintained fork.

  • bots/echidnabot/FLEET-SYNC.json pins hyperpolymath/echidnabot@bf2c0ff (upstream main head at time of writing). Only the crate surface is vendored; upstream docs/packaging/wiki stay upstream (bots/ slots are thin, CLAUDE.md invariant 6).
  • scripts/sync-vendored-bot.sh (--check / --sync [--rev SHA]) + scripts/tests/sync-vendored-bot.sh (21 offline assertions, planted controls: edited file, extra file, mode change, non-canonical lock, short/error-body rev, side-branch rev, empty include).
  • .github/workflows/vendored-bot-drift.yml: runs on PRs, pushes to main, weekly; reports how far upstream is ahead of the pin.
  • Dependabot no longer watches /bots/echidnabot, so the copy is never bumped independently. dependabot.yml converted to KYAML (D280, non-workflow YAML). This also repairs an ignore: block that was mis-nested under the github-actions groups key.
  • CANONICAL_SOURCE.adoc rewritten. It lists the six fleet-only files that the switch drops (recoverable from 8a4f983). tests/webhook_e2e_test.rs should be promoted upstream.
  • actions.lock resynced with gh actions-lock. On main, --no-fix reported an unused codeql-action@1c5b675 entry. codeql.yml now names v4.38.2, which is the SHA it already ran (2892aa5), so CodeQL behaviour is unchanged.
  • shared-context/findings cleanup:
    • Repointed the dangling echidna/latest.json.
    • Dropped three byte-identical duplicate echidna scans and two zero-byte non-marker files. The .processed markers are kept.
    • Dropped three misfiled root hypatia-echidnabot-* files: an error log, a log-prefixed partial and a bare array, all superseded by findings/echidnabot/.
    • echidnabot/latest.json is now the symlink that submit-finding.sh writes.
  • scripts/enroll-hypatia-fleet.sh: discovery now covers the star-list layout (depth 1–3). At depth 1 it found 3 of 406 clones under hyper-repos/. New tests/enroll-discovery-test.sh with a depth-1 planted control, wired into e2e.yml.

[mass-delete-ok]: 65 tracked files are deliberately removed, mostly upstream-only docs/packaging dropped from the vendored slot. All of them remain in history.

Verification (local)

  • bash scripts/tests/sync-vendored-bot.sh → 21 passed, 0 failed
  • bash scripts/sync-vendored-bot.sh echidnabot --check → matches, 75 entries
  • bash tests/enroll-discovery-test.sh → ok (incl. planted control)
  • gh actions-lock --no-fix → clean
  • kyaml-format.sh --check .github/dependabot.yml → clean
  • docstring-scan.sh --staged --check → 18/18 documented

Not covered by this PR: per-repo FLEET-ENROLLMENT.a2ml directives live in the target repos, and those repos' own PRs carry them.

CI follow-ups in this PR

Deferred red checks (AGENTS.md §5c item 3)

🤖 Generated with Claude Code

…ate [mass-delete-ok]

Owner decision 2026-10-05: standalone hyperpolymath/echidnabot is canon.
bots/echidnabot/ becomes a pinned sync of it instead of a hand-maintained fork.

- bots/echidnabot/FLEET-SYNC.json pins hyperpolymath/echidnabot@bf2c0ff
  (JCS-canonical lock) and lists the vendored crate surface (src, tests,
  proofs fixtures, benches, fuzz, migrations, config, Cargo.*, Containerfile,
  licences, README). Upstream docs/packaging/wiki stay upstream (thin slot).
- scripts/sync-vendored-bot.sh: --check (index vs pinned tree, blob ids and
  modes) and --sync [--rev SHA]; rev must be 40-hex and reachable from the
  upstream branch. scripts/tests/sync-vendored-bot.sh: 21 offline assertions
  with planted controls.
- .github/workflows/vendored-bot-drift.yml: runs the tests and the drift
  check on PRs, pushes to main and weekly; reports pin lag as a notice.
- dependabot: drop /bots/echidnabot (bumps land upstream, arrive by pin
  bump); file converted to KYAML, which also repairs a mis-nested ignore
  block that sat under the github-actions groups key.
- CANONICAL_SOURCE.adoc rewritten for the pinned-sync model; lists the six
  fleet-only files the switch drops and how to recover them.
- actions.lock resynced with gh actions-lock (main carried an unused
  codeql-action entry; codeql.yml now names v4.38.2, the same SHA it
  already ran, 2892aa5).
- shared-context/findings: repoint dangling echidna/latest.json; drop three
  byte-identical duplicate echidna scans and two zero-byte non-marker files;
  drop three misfiled root hypatia-echidnabot-* files (an error log, a
  log-prefixed partial and a bare array superseded by findings/echidnabot/);
  echidnabot/latest.json becomes the symlink submit-finding.sh expects.
- enroll-hypatia-fleet.sh: discover clones at depth 1-3 (star-list layout);
  depth 1 found 3 of 406 hyper-repos clones. tests/enroll-discovery-test.sh
  with a depth-1 planted control, wired into e2e.yml.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
@coderabbitai

coderabbitai Bot commented Oct 5, 2026 •

Copy link
Copy Markdown
Contributor

Important

Review skipped

Too many files!

This PR contains 157 files, which is 57 over the limit of 100.

To get a review, reduce the PR to 100 files or fewer by splitting it into smaller PRs or changing its base branch.

Upgrade to a paid plan to raise the limit.

This review couldn't start because sufficient usage credits or metered capacity aren't available. Add credits or update usage-based reviews in the billing tab, then retry.

⚙️ Run configuration
  • Configuration used: Repository: hyperpolymath/gitbot-fleet/.coderabbit.yaml
  • Review profile: CHILL
  • Plan: Advanced
  • Run ID: c7f0de05-5bad-48da-a65e-46199512a625
📥 Commits

Reviewing files that changed from the base of the PR and between 8a4f983 and b578cf4.

⛔ Files ignored due to path filters (3)
  • .github/workflows/actions.lock is excluded by !**/*.lock
  • bots/echidnabot/Cargo.lock is excluded by !**/*.lock
  • bots/gsbot/Cargo.lock is excluded by !**/*.lock
📒 Files selected for processing (157)
  • .github/dependabot.yml
  • .github/workflows/codeql.yml
  • .github/workflows/e2e.yml
  • .github/workflows/lock-sync-gate.yml
  • .github/workflows/panicbot-sweep.yml
  • .github/workflows/vendored-bot-drift.yml
  • .hypatia-baseline.json
  • .trusted-base-ignore
  • bots/echidnabot/.cargo/audit.toml
  • bots/echidnabot/BRANDING.adoc
  • bots/echidnabot/CANONICAL_SOURCE.adoc
  • bots/echidnabot/CHANGELOG.adoc
  • bots/echidnabot/CITATION.cff
  • bots/echidnabot/Cargo.toml
  • bots/echidnabot/FLEET-SYNC.json
  • bots/echidnabot/LICENSE
  • bots/echidnabot/LICENSE.txt
  • bots/echidnabot/LICENSES/AGPL-3.0-or-later.txt
  • bots/echidnabot/LICENSES/CC-BY-SA-4.0.txt
  • bots/echidnabot/LICENSES/MPL-2.0.txt
  • bots/echidnabot/Mustfile
  • bots/echidnabot/PALIMPSEST.adoc
  • bots/echidnabot/README.adoc
  • bots/echidnabot/RELEASE_CHECKLIST.adoc
  • bots/echidnabot/ROADMAP.adoc
  • bots/echidnabot/RSR_COMPLIANCE.adoc
  • bots/echidnabot/SESSION_SUMMARY_2026-01-29.adoc
  • bots/echidnabot/SONNET-TASKS.adoc
  • bots/echidnabot/TESTING-REPORT.adoc
  • bots/echidnabot/TESTING-REPORT.scm
  • bots/echidnabot/benches/echidnabot_bench.rs
  • bots/echidnabot/codemeta.json
  • bots/echidnabot/contracts/Token.sol
  • bots/echidnabot/contracts/TokenEchidnaTest.sol
  • bots/echidnabot/docs/CITATIONS.adoc
  • bots/echidnabot/docs/casket.toml
  • bots/echidnabot/docs/content/api.adoc
  • bots/echidnabot/docs/content/configuration.adoc
  • bots/echidnabot/docs/content/getting-started.adoc
  • bots/echidnabot/docs/content/index.adoc
  • bots/echidnabot/docs/templates/default.html
  • bots/echidnabot/echidna/echidna-assertion.yaml
  • bots/echidnabot/echidna/echidna-ci.yaml
  • bots/echidnabot/echidna/echidna-config.yaml
  • bots/echidnabot/echidna/echidna-no-flaky-assertion.yaml
  • bots/echidnabot/echidna/echidna-no-flaky.yaml
  • bots/echidnabot/echidnabot.example.toml
  • bots/echidnabot/echidnabot.toml
  • bots/echidnabot/examples/SafeDOMExample.affine
  • bots/echidnabot/examples/web-project-deno.json
  • bots/echidnabot/fuzz/Cargo.toml
  • bots/echidnabot/fuzz/fuzz_targets/fuzz_config.rs
  • bots/echidnabot/fuzz/fuzz_targets/fuzz_hmac.rs
  • bots/echidnabot/fuzz/fuzz_targets/fuzz_webhook_json.rs
  • bots/echidnabot/guix.scm
  • bots/echidnabot/hooks/pre-commit-tsjs-blocker.sh
  • bots/echidnabot/hooks/validate-codeql.sh
  • bots/echidnabot/hooks/validate-permissions.sh
  • bots/echidnabot/hooks/validate-sha-pins.sh
  • bots/echidnabot/hooks/validate-spdx.sh
  • bots/echidnabot/migrations/20260602000001_initial_schema.sql
  • bots/echidnabot/packaging/arch/PKGBUILD
  • bots/echidnabot/packaging/aur/.SRCINFO
  • bots/echidnabot/packaging/aur/PKGBUILD
  • bots/echidnabot/packaging/chocolatey/echidnabot.nuspec
  • bots/echidnabot/packaging/debian/control
  • bots/echidnabot/packaging/debian/rules
  • bots/echidnabot/packaging/flatpak/dev.hyperpolymath.Echidnabot.yml
  • bots/echidnabot/packaging/macports/Portfile
  • bots/echidnabot/packaging/rpm/echidnabot.spec
  • bots/echidnabot/packaging/scoop/echidnabot.json
  • bots/echidnabot/packaging/winget/echidnabot.yaml
  • bots/echidnabot/proofs/ECHO-TYPES-AUDIT.adoc
  • bots/echidnabot/proofs/coq/admitted_stub.v
  • bots/echidnabot/proofs/coq/trivial_ok.v
  • bots/echidnabot/proofs/lean/sorry_stub.lean
  • bots/echidnabot/proofs/lean/trivial_ok.lean
  • bots/echidnabot/proofs/test_fixtures/trivial_coq.json
  • bots/echidnabot/proofs/test_fixtures/trivial_lean.json
  • bots/echidnabot/scripts/batch_driver.sh
  • bots/echidnabot/scripts/echidna-gen.js
  • bots/echidnabot/src/abi/Foreign.idr
  • bots/echidnabot/src/abi/Layout.idr
  • bots/echidnabot/src/abi/Types.idr
  • bots/echidnabot/src/adapters/bitbucket.rs
  • bots/echidnabot/src/adapters/codeberg.rs
  • bots/echidnabot/src/adapters/github.rs
  • bots/echidnabot/src/adapters/gitlab.rs
  • bots/echidnabot/src/adapters/mod.rs
  • bots/echidnabot/src/api/graphql.rs
  • bots/echidnabot/src/api/mod.rs
  • bots/echidnabot/src/api/rate_limit.rs
  • bots/echidnabot/src/api/webhooks.rs
  • bots/echidnabot/src/config.rs
  • bots/echidnabot/src/dispatcher/echidna_client.rs
  • bots/echidnabot/src/dispatcher/mod.rs
  • bots/echidnabot/src/error.rs
  • bots/echidnabot/src/executor/container.rs
  • bots/echidnabot/src/executor/mod.rs
  • bots/echidnabot/src/feedback/corpus_delta.rs
  • bots/echidnabot/src/feedback/mod.rs
  • bots/echidnabot/src/feedback/reranker.rs
  • bots/echidnabot/src/fleet/mod.rs
  • bots/echidnabot/src/lib.rs
  • bots/echidnabot/src/llm.rs
  • bots/echidnabot/src/main.rs
  • bots/echidnabot/src/modes/directives.rs
  • bots/echidnabot/src/modes/manifest.rs
  • bots/echidnabot/src/modes/mod.rs
  • bots/echidnabot/src/observability.rs
  • bots/echidnabot/src/result_formatter.rs
  • bots/echidnabot/src/scheduler/job_queue.rs
  • bots/echidnabot/src/scheduler/limiter.rs
  • bots/echidnabot/src/scheduler/mod.rs
  • bots/echidnabot/src/scheduler/retry.rs
  • bots/echidnabot/src/shutdown.rs
  • bots/echidnabot/src/store/mod.rs
  • bots/echidnabot/src/store/models.rs
  • bots/echidnabot/src/store/sqlite.rs
  • bots/echidnabot/src/trust/axiom_tracker.rs
  • bots/echidnabot/src/trust/confidence.rs
  • bots/echidnabot/src/trust/migration_scanner.rs
  • bots/echidnabot/src/trust/mod.rs
  • bots/echidnabot/src/trust/solver_integrity.rs
  • bots/echidnabot/tests/fixtures/manifest/ephapax.a2ml
  • bots/echidnabot/tests/fixtures/manifest/valence-shell.a2ml
  • bots/echidnabot/tests/integration_tests.rs
  • bots/echidnabot/tests/lifecycle.rs
  • bots/echidnabot/tests/property_tests.rs
  • bots/echidnabot/tests/protocol_contract.rs
  • bots/echidnabot/tests/regressions/mod.rs
  • bots/echidnabot/tests/seam_test.rs
  • bots/echidnabot/tests/smoke.rs
  • bots/echidnabot/tests/webhook_e2e_test.rs
  • bots/echidnabot/wiki/Architecture.md
  • bots/echidnabot/wiki/FAQ.md
  • bots/echidnabot/wiki/Getting-Started.md
  • bots/echidnabot/wiki/Home.md
  • bots/echidnabot/wiki/Supported-Provers.md
  • docs/AUTOMATION-QUARANTINE.adoc
  • scripts/enroll-hypatia-fleet.sh
  • scripts/sync-vendored-bot.sh
  • scripts/tests/dispatch-paths.sh
  • scripts/tests/sync-vendored-bot.sh
  • shared-context/enrollment/README.adoc
  • shared-context/findings/echidna/20260206-213531.json
  • shared-context/findings/echidna/20260206-213627.json
  • shared-context/findings/echidna/20260206-213643.json
  • shared-context/findings/echidna/20260206-215453.json
  • shared-context/findings/echidna/20260212-153016.json
  • shared-context/findings/echidna/latest.json
  • shared-context/findings/echidnabot/latest.json
  • shared-context/findings/echidnabot/latest.json
  • shared-context/findings/hypatia-echidnabot-20260206-211633.json
  • shared-context/findings/hypatia-echidnabot-20260206-212939.json
  • shared-context/findings/hypatia-echidnabot-20260206-213033.json
  • tests/enroll-discovery-test.sh

You can disable this status message by setting the reviews.review_status to false in the CodeRabbit configuration file.

  • Autopilot · Keep fixing CodeRabbit findings and required CI, and resolving merge conflicts

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

Comment thread bots/echidnabot/fuzz/fuzz_targets/fuzz_hmac.rs
Comment thread bots/echidnabot/src/adapters/mod.rs
Comment thread bots/echidnabot/src/api/rate_limit.rs
Comment thread bots/echidnabot/src/scheduler/job_queue.rs
hyperpolymath and others added 2 commits October 5, 2026 16:54
bots/echidnabot/proofs/ carries deliberate Admitted/sorry stubs that
echidnabot's protocol-contract tests must flag. They are test fixtures,
not trusted base. Without this file check-trusted-base.sh fails with
2 undocumented escape hatches; with it, both are exempted.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
GitHub rejects a workflow with a duplicate mapping key before any job is
created; the Workflow security linter flags it on main too. Keep the
'stable' toolchain block (the earlier 'master' block was overridden anyway).

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
- scripts/tests/dispatch-paths.sh: assert the dispatch quarantine on the
  production runner (exit 78, BLOCKED, no outcome state) and run the
  path/outcome contracts against a test-only seam copy with exactly the
  interlock removed. Planted control: the seam copy must not be refused;
  the test fails outright once the interlock is gone. Closes #587.
- bots/gsbot/Cargo.lock: rustls 0.23.40 -> 0.23.45 (RUSTSEC-2026-0285),
  rustls-webpki 0.103.13 -> 0.103.15; cargo-deny advisories clean.
- .hypatia-baseline.json: baseline four code_safety findings in vendored
  bots/echidnabot (fix upstream; tracking #588, expires 2027-01-05).

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
@hyperpolymath
hyperpolymath enabled auto-merge (squash) October 5, 2026 16:22
@hyperpolymath
hyperpolymath merged commit dcfcdc4 into main Oct 5, 2026
54 of 58 checks passed
@hyperpolymath
hyperpolymath deleted the firstrun/20261005 branch October 5, 2026 16:25
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Required check 'Dispatch path and outcome contracts' fails on main since the automation quarantine (#571)

2 participants