Skip to content

fix: restore standards main to green: lock-gate pin bump, registry regen (closes #1092), uuid-v7 hardening - #1088

Open
hyperpolymath wants to merge 3 commits into
mainfrom
chore/bump-lock-gate-pin
Open

hyperpolymath wants to merge 3 commits into
mainfrom
chore/bump-lock-gate-pin

Conversation

@hyperpolymath

@hyperpolymath hyperpolymath commented Sep 30, 2026 •

Copy link
Copy Markdown
Owner

Restores standards main to green. Three reds on main block each other, and all three cures are in this one PR because no single one can pass CI alone.

What each commit fixes

  1. Lock-gate staging pin bump. The ref: under "Checkout standards for the lock gate" in governance-reusable.yml moves to 5f82b635. scripts/check-lock-gate-pin-freshness.sh returns rc=1 on main and rc=0 on this branch. Each tree's own copy of the script was run; running one tree's copy against another tree reads the wrong workflow and passes vacuously.
  2. Registry source_hash regeneration. Closes main red: REGISTRY source_hash drift after #1072/#1075 reds Registry Verify and Repo self-tests (and skips the lock-gate pin guard) #1092. fix(scripts): replace hardcoded /tmp paths with mktemp (#936) #1072 and fix(scripts): remove eval from rsr-audit and fill-placeholders test (#939) #1075 changed files under the RSR spec home without regenerating .machine_readable/REGISTRY.a2ml, so build-registry.sh --check fails. That failure reds Self-tests, and the pin guard step never runs because it comes after the failing suite. The change is one regenerated hash line. Under D231 it is a regeneration only; migrating off the generated file is a later piece of work.
  3. uuid-v7.yml hardening. It adds timeout-minutes: 10, a concurrency group, and a push trigger bounded to main. These are the three unfiltered Hypatia Baseline findings on main: missing_timeout_minutes, d_burn_double_trigger, and WH006.

Correction

My earlier comment on this PR attributed the Hypatia Baseline red to #1014. That was wrong. #1014 is the estate-wide HYPATIA_PIN rollout. The baseline red on main comes from the uuid-v7.yml findings that commit 3 fixes.

Local verification on 3d5ff2d

check result
bash scripts/run-shell-test-suite.sh 62 of 62 test files passed
check-lock-gate-pin-freshness.sh origin/main PASS
build-registry.sh --check clean

Lands under the fully-green rule only when every check is green.

🤖 Generated with Claude Code

https://claude.ai/code/session_01QYY8Gp4v4x2J7iSNn1vZ57

@coderabbitai

coderabbitai Bot commented Sep 30, 2026 •

Copy link
Copy Markdown
Contributor

Warning

Review limit reached

You've used all free OSS reviews for now. Wait for the free limit to reset to keep reviewing this public repository.

Next included review available in 11 minutes.

Check out review usage here.

View limit details

Limit details: You’ve used the included review currently available.

Learn how review limits work.

Review configuration:

⚙️ Run configuration

Configuration used: Organization UI

Review profile: ASSERTIVE

Plan: Advanced

Run ID: e79e0156-c09e-4aa9-9cc7-790044d5d37c

📥 Commits

Reviewing files that changed from the base of the PR and between 5fb9ad1 and 3d5ff2d.

📒 Files selected for processing (3)
  • .github/workflows/governance-reusable.yml
  • .github/workflows/uuid-v7.yml
  • .machine_readable/REGISTRY.a2ml
  • Autopilot · Keep fixing CodeRabbit findings and required CI, and resolving merge conflicts

Autopilot is currently an internal CodeRabbit preview.


Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@hyperpolymath

Copy link
Copy Markdown
Owner Author

CI does not exercise this PR's purpose. On this PR and on main, the step "Lock-gate pin is not stale" is skipped, because the test step before it fails. That failure is pre-existing registry drift, now tracked in #1092.

So the pin guard was run locally against each tree's own copy of scripts/check-lock-gate-pin-freshness.sh:

tree pin guard result
main 5f82b635 9c256b67 rc=1, scripts/update-actions-lock.sh stale in the pinned tree
this PR aee1111f 5f82b635 rc=0, PASS

The other two reds here also appear on main at the same SHA. They are "Registry + topology in sync" (#1092) and "Validate Hypatia Baseline", which reports 3 unfiltered findings (#1014). This PR is held under the fully-green rule until those are resolved or the owner rules otherwise.

🤖 Generated with Claude Code

https://claude.ai/code/session_01QYY8Gp4v4x2J7iSNn1vZ57

hyperpolymath and others added 3 commits September 30, 2026 16:26
The "Lock-gate pin is not stale" step of Repo self-tests has been red on
every main commit since #1064 changed scripts/update-actions-lock.sh
(a stricter single-object check on the verifier's JSON). The staging pin
in governance-reusable.yml still pointed at 9c256b6, one change behind.
The guard is designed so the next PR owes this bump; this is that PR.

Control: the guard on the old pin exits 1 against main 5f82b63.
Cure: the guard on the new pin exits 0 against the same main.
The guard's own mutant suite passes 10/10.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01QYY8Gp4v4x2J7iSNn1vZ57
…tale

#1072 and #1075 changed files under rhodium-standard-repositories/
without regenerating the registry, so `build-registry.sh --check` exits 1
on main. That reds "Registry + topology in sync" and both
build-registry-test.sh and build-scorecards-test.sh. And because the
test step fails, the "Lock-gate pin is not stale" step is skipped on
every PR. Output of `just registry`, one line.

Owner ruling D231: regenerate now; moving the registry off .a2ml stays
tracked in #1010/#479. Closes #1092.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01QYY8Gp4v4x2J7iSNn1vZ57
The three unfiltered findings that red "Validate Hypatia Baseline" on
main are all in uuid-v7.yml (#1063): no `timeout-minutes` (flagged by
workflow_audit and WH006), and an unscoped `push` beside
`pull_request`, so every PR-branch push ran it twice (D-BURN).

Scope push to main, add the repo's usual concurrency cancel block, and
set `timeout-minutes: 10`. Job name and check name are unchanged.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01QYY8Gp4v4x2J7iSNn1vZ57
@hyperpolymath
hyperpolymath force-pushed the chore/bump-lock-gate-pin branch from aee1111 to 3d5ff2d Compare September 30, 2026 15:29
@hyperpolymath hyperpolymath changed the title chore(governance): bump the lock-gate staging pin to main fix: restore standards main to green: lock-gate pin bump, registry regen (closes #1092), uuid-v7 hardening Sep 30, 2026
@hyperpolymath

Copy link
Copy Markdown
Owner Author

Correction to my earlier comment. I attributed the Hypatia Baseline red to #1014, and that was wrong. The three unfiltered findings on main are all in .github/workflows/uuid-v7.yml: missing_timeout_minutes, d_burn_double_trigger, and WH006. This branch now fixes them in its third commit, alongside the registry regen that closes #1092. The PR body is updated to match.

🤖 Generated with Claude Code

https://claude.ai/code/session_01QYY8Gp4v4x2J7iSNn1vZ57

@hyperpolymath

Copy link
Copy Markdown
Owner Author

CI status at 3d5ff2dd: UNSTABLE, and only on two non-required checks that are red on main itself.

The three reds this PR set out to cure (lock-gate pin freshness, registry --check / #1092, uuid-v7) are green. The two remaining reds are woken by this PR's paths but are not caused by it. Both reproduce on a clean checkout of main at 5fb9ad19:

This PR is held, not merged. The owner's 2026-09-22 rule lands only fully-green PRs, and the D232 hold still needs re-asking after its premise erratum.

🤖 Generated with Claude Code

https://claude.ai/code/session_01QYY8Gp4v4x2J7iSNn1vZ57

@coderabbitai

coderabbitai Bot commented Sep 30, 2026

Copy link
Copy Markdown
Contributor

Autopilot could not be updated. Open Coding to check access and billing.

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

main red: REGISTRY source_hash drift after #1072/#1075 reds Registry Verify and Repo self-tests (and skips the lock-gate pin guard)

1 participant