From a22ba4907089447e155b988d06eb3fa7da6ed91c Mon Sep 17 00:00:00 2001 From: "Jonathan D.A. Jewell" <6759885+hyperpolymath@users.noreply.github.com> Date: Tue, 22 Sep 2026 22:39:31 +0100 Subject: [PATCH 1/2] fix(ci): repoint the estate audit at a cicd-suite ref whose gates actually run MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit The audit is the only red left on main. It dies at step 3 of 30, Required Files Gate, and takes 25 downstream gates with it as `skipped`. Measured on run 35786286540 (main, a643534) the step ran for 41ms and produced: shell: /usr/bin/bash --noprofile --norc -e -o pipefail {0} found .editorconfig -> .editorconfig ... all 8 required files found ... ##[error]Process completed with exit code 1. No `::error::` of its own — a silent death immediately after the presence loop. The next thing that script does is judge CODEOWNERS: functional_lines=$(grep -vE '^\s*(#|//|;|$)' "$f" | wc -l) This repo's .github/CODEOWNERS is comment-only by policy (standards CODEOWNERS-POLICY.adoc Rule 1, solo-maintained), so that grep matches nothing and exits 1. The `-e` is supplied by the GitHub composite harness, not by the script, and the script's own `set -uo pipefail` does not clear it. The step therefore dies one line ABOVE the message that declares this exact file valid. The gate was never failing pons on substance. It was failing on being correct. cicd-suite cured this in fa71ac2 (#32) and 0c1bc9f (#34). The old pin predates both: required-files-check at 3b4afafa has 0 of the guards, at 0c1bc9f it has 3. Why the old pin looked safe. Its comment said 3b4afafa was "the head of a green run of that workflow" — true, and useless. Green there meant cicd-suite's own self-test had not run: 3b4afafa is the commit that dropped two composite-reached pins from its lockfile, killing `Gate controls` in `Set up job` at 1 step. A square is not a measurement. The new comment records step counts (14 and 6) so the next re-pin has something falsifiable to check. Expect this to surface NEW reds. Those 25 gates have been skipped, not passing, and several have never executed against this repository at all. Per the standing owner ruling a new scanner finding is an issue with acceptance criteria, not a blocker. Co-Authored-By: Claude Opus 5 Claude-Session: https://claude.ai/code/session_01WRvDivYwLSeVCJUrfjic3f --- .github/workflows/main-estate-audit.yml | 11 ++++++++--- 1 file changed, 8 insertions(+), 3 deletions(-) diff --git a/.github/workflows/main-estate-audit.yml b/.github/workflows/main-estate-audit.yml index 9a16a26..e472aeb 100644 --- a/.github/workflows/main-estate-audit.yml +++ b/.github/workflows/main-estate-audit.yml @@ -22,7 +22,12 @@ jobs: # a snapshot that is already stale (cicd-suite has since replaced # zig-hexadeca-check with zig-unified-api-adapter-check). # - # The SHA below is cicd-suite main as of 2026-09-21 and is the head of a - # green run of that workflow. Re-pin when the gate set changes. + # The SHA below is cicd-suite main as of 2026-09-22: the head of a run whose + # `Gate controls` job executed 14 steps and whose `Composite shell contract` + # job executed 6. Both numbers matter. The PREVIOUS pin (3b4afafa) was also + # "the head of a green run" — but green there meant the self-test never ran, + # and its composites still carried the harness `-e` kill that fails Required + # Files Gate here in 41ms, silently, skipping 25 downstream gates. + # Re-pin on a gate-set change, and check the STEP COUNT, not the square. call-estate-audit: - uses: hyperpolymath/cicd-suite/.github/workflows/main-estate-audit.yml@3b4afafa969103279ee580572626a175ec9dc0d0 + uses: hyperpolymath/cicd-suite/.github/workflows/main-estate-audit.yml@0c1bc9f5aa5857965e50f96021485d5710b6e0ea From f7521ff0dda2d2bdc08c4ff7f96c72e6877b2e1d Mon Sep 17 00:00:00 2001 From: "Jonathan D.A. Jewell" <6759885+hyperpolymath@users.noreply.github.com> Date: Tue, 22 Sep 2026 22:48:57 +0100 Subject: [PATCH 2/2] fix(ci): pin the estate audit at 6cb08dd, where the lock names a cured gate MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit Pinning 0c1bc9f was necessary and not sufficient, and run 35787980954 proved it: Required Files Gate died at 82ms, silently, exit 1, 25 gates skipped — identical to the pin it replaced. The reusable invokes its gates by BRANCH ref (`/actions/@main`). A branch ref is trusted from the lockfile, so the runner executes the commit THE LOCK names, not the branch tip. cicd-suite's lock at 0c1bc9f still pinned cicd-suite@main at 9adb3908 — four commits stale, with 0 of the harness `-e` guards. Which gates this repo runs is chosen by the lock at the pinned SHA, not by the pinned SHA. 6cb08dd is cicd-suite#35, which re-pinned that entry at 0c1bc9f: 3 guards in required-files-check and 1 in spdx-license-check, against 0 and 0 before. The comment now records the rule rather than the symptom, and cicd-suite#35 added tests/lock-transitive-closure.sh so this drift goes red there instead of silently here. Co-Authored-By: Claude Opus 5 Claude-Session: https://claude.ai/code/session_01WRvDivYwLSeVCJUrfjic3f --- .github/workflows/main-estate-audit.yml | 35 +++++++++++++++++++------ 1 file changed, 27 insertions(+), 8 deletions(-) diff --git a/.github/workflows/main-estate-audit.yml b/.github/workflows/main-estate-audit.yml index e472aeb..793d4f0 100644 --- a/.github/workflows/main-estate-audit.yml +++ b/.github/workflows/main-estate-audit.yml @@ -22,12 +22,31 @@ jobs: # a snapshot that is already stale (cicd-suite has since replaced # zig-hexadeca-check with zig-unified-api-adapter-check). # - # The SHA below is cicd-suite main as of 2026-09-22: the head of a run whose - # `Gate controls` job executed 14 steps and whose `Composite shell contract` - # job executed 6. Both numbers matter. The PREVIOUS pin (3b4afafa) was also - # "the head of a green run" — but green there meant the self-test never ran, - # and its composites still carried the harness `-e` kill that fails Required - # Files Gate here in 41ms, silently, skipping 25 downstream gates. - # Re-pin on a gate-set change, and check the STEP COUNT, not the square. + # The SHA below is cicd-suite main as of 2026-09-22. Choosing it is necessary + # and NOT sufficient, and the reason is the whole point of this comment. + # + # That reusable invokes its 26 gates by BRANCH ref: + # + # uses: hyperpolymath/cicd-suite/actions/@main + # + # Under gh-actions-lock a branch ref is trusted from the lockfile, and the + # runner executes THE COMMIT THE LOCKFILE NAMES, not the branch tip. So the + # gates this repo actually runs are chosen by cicd-suite's actions.lock AT + # THE SHA BELOW -- not by the SHA below. + # + # Measured, not assumed. Pinning 0c1bc9f (the head of a run whose `Gate + # controls` job executed 14 steps) left this audit dying EXACTLY as before: + # run 35787980954, Required Files Gate, 82ms, silent exit 1, 25 gates + # skipped. The lock at 0c1bc9f still pinned cicd-suite@main at 9adb3908 -- + # four commits stale, carrying ZERO of the harness `-e` guards. The cure had + # merged and reached nobody. + # + # 6cb08dd is cicd-suite#35, which re-pinned that entry at 0c1bc9f (3 guards + # in required-files-check, 1 in spdx-license-check; 9adb3908 had 0 and 0). + # + # When re-pinning: check the LOCK at the candidate SHA, not the SHA's own + # tree, and check the STEP COUNT, not the square. cicd-suite#35 added + # tests/lock-transitive-closure.sh so that drift goes red there rather than + # silently here. call-estate-audit: - uses: hyperpolymath/cicd-suite/.github/workflows/main-estate-audit.yml@0c1bc9f5aa5857965e50f96021485d5710b6e0ea + uses: hyperpolymath/cicd-suite/.github/workflows/main-estate-audit.yml@6cb08dde98b70d20ad2d506e77dd6a517503eb08