Skip to content

feat(echidnabot): pinned sync from hyperpolymath/echidnabot + drift gate [mass-delete-ok] - #586

Merged
hyperpolymath merged 4 commits into
mainfrom
firstrun/20261005
Oct 5, 2026
Merged

hyperpolymath merged 4 commits into
mainfrom
firstrun/20261005

Conversation

@hyperpolymath

@hyperpolymath hyperpolymath commented Oct 5, 2026 •

Copy link
Copy Markdown
Owner

Summary

Owner decision (2026-10-05): standalone hyperpolymath/echidnabot is canon. bots/echidnabot/ is now a pinned sync of it, with a CI drift check, instead of a hand-maintained fork.

  • bots/echidnabot/FLEET-SYNC.json pins hyperpolymath/echidnabot@bf2c0ff (upstream main head at time of writing). Only the crate surface is vendored; upstream docs/packaging/wiki stay upstream (bots/ slots are thin, CLAUDE.md invariant 6).
  • scripts/sync-vendored-bot.sh (--check / --sync [--rev SHA]) + scripts/tests/sync-vendored-bot.sh (21 offline assertions, planted controls: edited file, extra file, mode change, non-canonical lock, short/error-body rev, side-branch rev, empty include).
  • .github/workflows/vendored-bot-drift.yml: runs on PRs, pushes to main, weekly; reports how far upstream is ahead of the pin.
  • Dependabot no longer watches /bots/echidnabot, so the copy is never bumped independently. dependabot.yml converted to KYAML (D280, non-workflow YAML). This also repairs an ignore: block that was mis-nested under the github-actions groups key.
  • CANONICAL_SOURCE.adoc rewritten. It lists the six fleet-only files that the switch drops (recoverable from 8a4f983). tests/webhook_e2e_test.rs should be promoted upstream.
  • actions.lock resynced with gh actions-lock. On main, --no-fix reported an unused codeql-action@1c5b675 entry. codeql.yml now names v4.38.2, which is the SHA it already ran (2892aa5), so CodeQL behaviour is unchanged.
  • shared-context/findings cleanup:
    • Repointed the dangling echidna/latest.json.
    • Dropped three byte-identical duplicate echidna scans and two zero-byte non-marker files. The .processed markers are kept.
    • Dropped three misfiled root hypatia-echidnabot-* files: an error log, a log-prefixed partial and a bare array, all superseded by findings/echidnabot/.
    • echidnabot/latest.json is now the symlink that submit-finding.sh writes.
  • scripts/enroll-hypatia-fleet.sh: discovery now covers the star-list layout (depth 1–3). At depth 1 it found 3 of 406 clones under hyper-repos/. New tests/enroll-discovery-test.sh with a depth-1 planted control, wired into e2e.yml.

[mass-delete-ok]: 65 tracked files are deliberately removed, mostly upstream-only docs/packaging dropped from the vendored slot. All of them remain in history.

Verification (local)

  • bash scripts/tests/sync-vendored-bot.sh → 21 passed, 0 failed
  • bash scripts/sync-vendored-bot.sh echidnabot --check → matches, 75 entries
  • bash tests/enroll-discovery-test.sh → ok (incl. planted control)
  • gh actions-lock --no-fix → clean
  • kyaml-format.sh --check .github/dependabot.yml → clean
  • docstring-scan.sh --staged --check → 18/18 documented

Not covered by this PR: per-repo FLEET-ENROLLMENT.a2ml directives live in the target repos, and those repos' own PRs carry them.

CI follow-ups in this PR

Deferred red checks (AGENTS.md §5c item 3)

🤖 Generated with Claude Code

…ate [mass-delete-ok]

Owner decision 2026-10-05: standalone hyperpolymath/echidnabot is canon.
bots/echidnabot/ becomes a pinned sync of it instead of a hand-maintained fork.

- bots/echidnabot/FLEET-SYNC.json pins hyperpolymath/echidnabot@bf2c0ff
  (JCS-canonical lock) and lists the vendored crate surface (src, tests,
  proofs fixtures, benches, fuzz, migrations, config, Cargo.*, Containerfile,
  licences, README). Upstream docs/packaging/wiki stay upstream (thin slot).
- scripts/sync-vendored-bot.sh: --check (index vs pinned tree, blob ids and
  modes) and --sync [--rev SHA]; rev must be 40-hex and reachable from the
  upstream branch. scripts/tests/sync-vendored-bot.sh: 21 offline assertions
  with planted controls.
- .github/workflows/vendored-bot-drift.yml: runs the tests and the drift
  check on PRs, pushes to main and weekly; reports pin lag as a notice.
- dependabot: drop /bots/echidnabot (bumps land upstream, arrive by pin
  bump); file converted to KYAML, which also repairs a mis-nested ignore
  block that sat under the github-actions groups key.
- CANONICAL_SOURCE.adoc rewritten for the pinned-sync model; lists the six
  fleet-only files the switch drops and how to recover them.
- actions.lock resynced with gh actions-lock (main carried an unused
  codeql-action entry; codeql.yml now names v4.38.2, the same SHA it
  already ran, 2892aa5).
- shared-context/findings: repoint dangling echidna/latest.json; drop three
  byte-identical duplicate echidna scans and two zero-byte non-marker files;
  drop three misfiled root hypatia-echidnabot-* files (an error log, a
  log-prefixed partial and a bare array superseded by findings/echidnabot/);
  echidnabot/latest.json becomes the symlink submit-finding.sh expects.
- enroll-hypatia-fleet.sh: discover clones at depth 1-3 (star-list layout);
  depth 1 found 3 of 406 hyper-repos clones. tests/enroll-discovery-test.sh
  with a depth-1 planted control, wired into e2e.yml.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
@coderabbitai

coderabbitai Bot commented Oct 5, 2026 •

Copy link
Copy Markdown
Contributor

Important

Review skipped

Too many files!

This PR contains 157 files, which is 57 over the limit of 100.

To get a review, reduce the PR to 100 files or fewer by splitting it into smaller PRs or changing its base branch.

Upgrade to a paid plan to raise the limit.

This review couldn't start because sufficient usage credits or metered capacity aren't available. Add credits or update usage-based reviews in the billing tab, then retry.

⚙️ Run configuration
  • Configuration used: Repository: hyperpolymath/gitbot-fleet/.coderabbit.yaml
  • Review profile: CHILL
  • Plan: Advanced
  • Run ID: c7f0de05-5bad-48da-a65e-46199512a625
📥 Commits

Reviewing files that changed from the base of the PR and between 8a4f983 and b578cf4.

⛔ Files ignored due to path filters (3)
  • .github/workflows/actions.lock is excluded by !**/*.lock
  • bots/echidnabot/Cargo.lock is excluded by !**/*.lock
  • bots/gsbot/Cargo.lock is excluded by !**/*.lock
📒 Files selected for processing (157)
  • .github/dependabot.yml
  • .github/workflows/codeql.yml
  • .github/workflows/e2e.yml
  • .github/workflows/lock-sync-gate.yml
  • .github/workflows/panicbot-sweep.yml
  • .github/workflows/vendored-bot-drift.yml
  • .hypatia-baseline.json
  • .trusted-base-ignore
  • bots/echidnabot/.cargo/audit.toml
  • bots/echidnabot/BRANDING.adoc
  • bots/echidnabot/CANONICAL_SOURCE.adoc
  • bots/echidnabot/CHANGELOG.adoc
  • bots/echidnabot/CITATION.cff
  • bots/echidnabot/Cargo.toml
  • bots/echidnabot/FLEET-SYNC.json
  • bots/echidnabot/LICENSE
  • bots/echidnabot/LICENSE.txt
  • bots/echidnabot/LICENSES/AGPL-3.0-or-later.txt
  • bots/echidnabot/LICENSES/CC-BY-SA-4.0.txt
  • bots/echidnabot/LICENSES/MPL-2.0.txt
  • bots/echidnabot/Mustfile
  • bots/echidnabot/PALIMPSEST.adoc
  • bots/echidnabot/README.adoc
  • bots/echidnabot/RELEASE_CHECKLIST.adoc
  • bots/echidnabot/ROADMAP.adoc
  • bots/echidnabot/RSR_COMPLIANCE.adoc
  • bots/echidnabot/SESSION_SUMMARY_2026-01-29.adoc
  • bots/echidnabot/SONNET-TASKS.adoc
  • bots/echidnabot/TESTING-REPORT.adoc
  • bots/echidnabot/TESTING-REPORT.scm
  • bots/echidnabot/benches/echidnabot_bench.rs
  • bots/echidnabot/codemeta.json
  • bots/echidnabot/contracts/Token.sol
  • bots/echidnabot/contracts/TokenEchidnaTest.sol
  • bots/echidnabot/docs/CITATIONS.adoc
  • bots/echidnabot/docs/casket.toml
  • bots/echidnabot/docs/content/api.adoc
  • bots/echidnabot/docs/content/configuration.adoc
  • bots/echidnabot/docs/content/getting-started.adoc
  • bots/echidnabot/docs/content/index.adoc
  • bots/echidnabot/docs/templates/default.html
  • bots/echidnabot/echidna/echidna-assertion.yaml
  • bots/echidnabot/echidna/echidna-ci.yaml
  • bots/echidnabot/echidna/echidna-config.yaml
  • bots/echidnabot/echidna/echidna-no-flaky-assertion.yaml
  • bots/echidnabot/echidna/echidna-no-flaky.yaml
  • bots/echidnabot/echidnabot.example.toml
  • bots/echidnabot/echidnabot.toml
  • bots/echidnabot/examples/SafeDOMExample.affine
  • bots/echidnabot/examples/web-project-deno.json
  • bots/echidnabot/fuzz/Cargo.toml
  • bots/echidnabot/fuzz/fuzz_targets/fuzz_config.rs
  • bots/echidnabot/fuzz/fuzz_targets/fuzz_hmac.rs
  • bots/echidnabot/fuzz/fuzz_targets/fuzz_webhook_json.rs
  • bots/echidnabot/guix.scm
  • bots/echidnabot/hooks/pre-commit-tsjs-blocker.sh
  • bots/echidnabot/hooks/validate-codeql.sh
  • bots/echidnabot/hooks/validate-permissions.sh
  • bots/echidnabot/hooks/validate-sha-pins.sh
  • bots/echidnabot/hooks/validate-spdx.sh
  • bots/echidnabot/migrations/20260602000001_initial_schema.sql
  • bots/echidnabot/packaging/arch/PKGBUILD
  • bots/echidnabot/packaging/aur/.SRCINFO
  • bots/echidnabot/packaging/aur/PKGBUILD
  • bots/echidnabot/packaging/chocolatey/echidnabot.nuspec
  • bots/echidnabot/packaging/debian/control
  • bots/echidnabot/packaging/debian/rules
  • bots/echidnabot/packaging/flatpak/dev.hyperpolymath.Echidnabot.yml
  • bots/echidnabot/packaging/macports/Portfile
  • bots/echidnabot/packaging/rpm/echidnabot.spec
  • bots/echidnabot/packaging/scoop/echidnabot.json
  • bots/echidnabot/packaging/winget/echidnabot.yaml
  • bots/echidnabot/proofs/ECHO-TYPES-AUDIT.adoc
  • bots/echidnabot/proofs/coq/admitted_stub.v
  • bots/echidnabot/proofs/coq/trivial_ok.v
  • bots/echidnabot/proofs/lean/sorry_stub.lean
  • bots/echidnabot/proofs/lean/trivial_ok.lean
  • bots/echidnabot/proofs/test_fixtures/trivial_coq.json
  • bots/echidnabot/proofs/test_fixtures/trivial_lean.json
  • bots/echidnabot/scripts/batch_driver.sh
  • bots/echidnabot/scripts/echidna-gen.js
  • bots/echidnabot/src/abi/Foreign.idr
  • bots/echidnabot/src/abi/Layout.idr
  • bots/echidnabot/src/abi/Types.idr
  • bots/echidnabot/src/adapters/bitbucket.rs
  • bots/echidnabot/src/adapters/codeberg.rs
  • bots/echidnabot/src/adapters/github.rs
  • bots/echidnabot/src/adapters/gitlab.rs
  • bots/echidnabot/src/adapters/mod.rs
  • bots/echidnabot/src/api/graphql.rs
  • bots/echidnabot/src/api/mod.rs
  • bots/echidnabot/src/api/rate_limit.rs
  • bots/echidnabot/src/api/webhooks.rs
  • bots/echidnabot/src/config.rs
  • bots/echidnabot/src/dispatcher/echidna_client.rs
  • bots/echidnabot/src/dispatcher/mod.rs
  • bots/echidnabot/src/error.rs
  • bots/echidnabot/src/executor/container.rs
  • bots/echidnabot/src/executor/mod.rs
  • bots/echidnabot/src/feedback/corpus_delta.rs
  • bots/echidnabot/src/feedback/mod.rs
  • bots/echidnabot/src/feedback/reranker.rs
  • bots/echidnabot/src/fleet/mod.rs
  • bots/echidnabot/src/lib.rs
  • bots/echidnabot/src/llm.rs
  • bots/echidnabot/src/main.rs
  • bots/echidnabot/src/modes/directives.rs
  • bots/echidnabot/src/modes/manifest.rs
  • bots/echidnabot/src/modes/mod.rs
  • bots/echidnabot/src/observability.rs
  • bots/echidnabot/src/result_formatter.rs
  • bots/echidnabot/src/scheduler/job_queue.rs
  • bots/echidnabot/src/scheduler/limiter.rs
  • bots/echidnabot/src/scheduler/mod.rs
  • bots/echidnabot/src/scheduler/retry.rs
  • bots/echidnabot/src/shutdown.rs
  • bots/echidnabot/src/store/mod.rs
  • bots/echidnabot/src/store/models.rs
  • bots/echidnabot/src/store/sqlite.rs
  • bots/echidnabot/src/trust/axiom_tracker.rs
  • bots/echidnabot/src/trust/confidence.rs
  • bots/echidnabot/src/trust/migration_scanner.rs
  • bots/echidnabot/src/trust/mod.rs
  • bots/echidnabot/src/trust/solver_integrity.rs
  • bots/echidnabot/tests/fixtures/manifest/ephapax.a2ml
  • bots/echidnabot/tests/fixtures/manifest/valence-shell.a2ml
  • bots/echidnabot/tests/integration_tests.rs
  • bots/echidnabot/tests/lifecycle.rs
  • bots/echidnabot/tests/property_tests.rs
  • bots/echidnabot/tests/protocol_contract.rs
  • bots/echidnabot/tests/regressions/mod.rs
  • bots/echidnabot/tests/seam_test.rs
  • bots/echidnabot/tests/smoke.rs
  • bots/echidnabot/tests/webhook_e2e_test.rs
  • bots/echidnabot/wiki/Architecture.md
  • bots/echidnabot/wiki/FAQ.md
  • bots/echidnabot/wiki/Getting-Started.md
  • bots/echidnabot/wiki/Home.md
  • bots/echidnabot/wiki/Supported-Provers.md
  • docs/AUTOMATION-QUARANTINE.adoc
  • scripts/enroll-hypatia-fleet.sh
  • scripts/sync-vendored-bot.sh
  • scripts/tests/dispatch-paths.sh
  • scripts/tests/sync-vendored-bot.sh
  • shared-context/enrollment/README.adoc
  • shared-context/findings/echidna/20260206-213531.json
  • shared-context/findings/echidna/20260206-213627.json
  • shared-context/findings/echidna/20260206-213643.json
  • shared-context/findings/echidna/20260206-215453.json
  • shared-context/findings/echidna/20260212-153016.json
  • shared-context/findings/echidna/latest.json
  • shared-context/findings/echidnabot/latest.json
  • shared-context/findings/echidnabot/latest.json
  • shared-context/findings/hypatia-echidnabot-20260206-211633.json
  • shared-context/findings/hypatia-echidnabot-20260206-212939.json
  • shared-context/findings/hypatia-echidnabot-20260206-213033.json
  • tests/enroll-discovery-test.sh

You can disable this status message by setting the reviews.review_status to false in the CodeRabbit configuration file.

  • Autopilot · Keep fixing CodeRabbit findings and required CI, and resolving merge conflicts

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

Comment thread bots/echidnabot/fuzz/fuzz_targets/fuzz_hmac.rs
Comment thread bots/echidnabot/src/adapters/mod.rs
Comment thread bots/echidnabot/src/api/rate_limit.rs
Comment thread bots/echidnabot/src/scheduler/job_queue.rs
hyperpolymath and others added 2 commits October 5, 2026 16:54
bots/echidnabot/proofs/ carries deliberate Admitted/sorry stubs that
echidnabot's protocol-contract tests must flag. They are test fixtures,
not trusted base. Without this file check-trusted-base.sh fails with
2 undocumented escape hatches; with it, both are exempted.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
GitHub rejects a workflow with a duplicate mapping key before any job is
created; the Workflow security linter flags it on main too. Keep the
'stable' toolchain block (the earlier 'master' block was overridden anyway).

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
- scripts/tests/dispatch-paths.sh: assert the dispatch quarantine on the
  production runner (exit 78, BLOCKED, no outcome state) and run the
  path/outcome contracts against a test-only seam copy with exactly the
  interlock removed. Planted control: the seam copy must not be refused;
  the test fails outright once the interlock is gone. Closes #587.
- bots/gsbot/Cargo.lock: rustls 0.23.40 -> 0.23.45 (RUSTSEC-2026-0285),
  rustls-webpki 0.103.13 -> 0.103.15; cargo-deny advisories clean.
- .hypatia-baseline.json: baseline four code_safety findings in vendored
  bots/echidnabot (fix upstream; tracking #588, expires 2027-01-05).

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
@hyperpolymath
hyperpolymath enabled auto-merge (squash) October 5, 2026 16:22
@hyperpolymath
hyperpolymath merged commit dcfcdc4 into main Oct 5, 2026
54 of 58 checks passed
@hyperpolymath
hyperpolymath deleted the firstrun/20261005 branch October 5, 2026 16:25
hyperpolymath added a commit that referenced this pull request Oct 7, 2026
<!--
SPDX-License-Identifier: CC-BY-SA-4.0
Copyright (c) Jonathan D.A. Jewell <j.d.a.jewell@open.ac.uk>
-->
## Summary

This PR is a rescue of the D37 phase-zero recovery commit `632b54a`
(2026-08-24), rebuilt as the single commit `d19776e` on `main` (the
original commit left the branch so GitGuardian no longer sees its
test-canary password; kept locally in `refs/rescued/pr596/`). `main` had
independently landed most of the original work, so every one of the 33
conflicts resolves to `main`'s version:

- the pin, `actions.lock` and permissions edits (#550–#566, #594);
- the `fixer.rs` restoration. At the old base that file was a 14-line
malformed patch fragment; `76ac79d` onward restored it;
- the `hypatia.rs` `?` refactor;
- the `6a2/` → `descriptiles/` move. A2ML is retired, so it is not
re-homed;
- the echidnabot `api.adoc` deletion (#586).

Net change against `main`, 3 files:

1. **`repo-integrity-guard.yml`**: a new step, *Source files must not be
patch fragments*. It fails when a tracked `*.rs/ex/exs/res/js/ts/py/sh`
file starts with `@@ `, `*** Begin Patch` or `diff --git`. That is
exactly how `fixer.rs` was broken.
2. **`.gitignore`**: ignores `.claude/worktrees/`, so an agent worktree
can't be committed as a gitlink again. That had happened with
`actions-policy`, which `main` has since dropped.
3. **`SECURITY.md`**: adds reporting expectations (acknowledgement
within 48 hours, assessment within 7 days, 90-day coordinated
disclosure), a supported-versions statement and a safe-harbour clause.
It keeps `main`'s pointer to `SECURITY.adoc`, which has none of these.

Closes: none

## Type of change

- [ ] 🐛 Bug fix (non-breaking change that fixes an issue). The breakage
is already fixed on `main`.
- [ ] ✨ New feature (non-breaking change that adds functionality)
- [ ] 💥 Breaking change (would change existing behaviour)
- [x] 🕳️ Soundness fix (fixes a checker/proof false-negative). The
integrity guard did not catch a source file that was a patch fragment.
- [x] 📖 Documentation (`SECURITY.md`)
- [ ] 🧹 Refactor / tech debt (behaviour-preserving)
- [ ] ⚡ Performance
- [x] 🔧 Build / CI / tooling

## 📌 New pins

Head SHA: **`d19776e`**. This PR adds or changes no pins. Every `uses:`
ref and `actions.lock` entry is `main`'s, byte for byte.

## How has this been verified?

- `git diff --stat origin/main d19776e` shows 3 files changed, +41/−10,
and nothing else.
- I ran the new guard's script locally on the merged tree: rc=0, no
findings.
- Positive control: I planted `planted_frag.rs` starting with `@@ -1,2
+1,2 @@` and staged it with intent-to-add. The guard reported `::error
file=planted_frag.rs::Source file begins with patch syntax` with rc=1.
The planted file was then removed.
- `actionlint .github/workflows/repo-integrity-guard.yml` was clean.
- `grep` of `SECURITY.adoc` for hour/day/harbour/disclosure/acknowledge
found nothing, so the `SECURITY.md` additions are not duplicates.

## Checklist

- [x] My commits are **signed** (`git commit -S`). `d19776e` shows `G`.
- [ ] I ran the project's own checks/tests locally and they pass. No
Rust source changed against `main`. The repo's CI on `d19776e` is the
check, and I ran the guard step locally (above).
- [x] New files carry the correct `SPDX-License-Identifier`. There are
no new files; `SECURITY.md` keeps its existing `MPL-2.0` header.
- [x] Docs are updated, and no public claim now overstates what the code
does.
- [x] I have not introduced a soundness hole. The guard only adds a
failure path.

## Notes for reviewers

- The guard checks only the *first non-blank line* of each file. A
fragment that is spliced into the middle of a file is out of its scope.
- The `SECURITY.md` response-time commitments are the owner's text from
`632b54a`, kept verbatim.

🤖 Generated with [Claude Code](https://claude.com/claude-code)

https://claude.ai/code/session_014BxjiTAaTZCHVWn2U5NWhL

Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Required check 'Dispatch path and outcome contracts' fails on main since the automation quarantine (#571)

2 participants