fix: restore standards main to green: lock-gate pin bump, registry regen (closes #1092), uuid-v7 hardening - #1088
hyperpolymath wants to merge 3 commits into
Conversation
|
Warning Review limit reachedYou've used all free OSS reviews for now. Wait for the free limit to reset to keep reviewing this public repository. Next included review available in 11 minutes. View limit detailsLimit details: You’ve used the included review currently available. Review configuration: ⚙️ Run configurationConfiguration used: Organization UI Review profile: ASSERTIVE Plan: Advanced Run ID: 📒 Files selected for processing (3)
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
|
CI does not exercise this PR's purpose. On this PR and on So the pin guard was run locally against each tree's own copy of
The other two reds here also appear on 🤖 Generated with Claude Code |
The "Lock-gate pin is not stale" step of Repo self-tests has been red on every main commit since #1064 changed scripts/update-actions-lock.sh (a stricter single-object check on the verifier's JSON). The staging pin in governance-reusable.yml still pointed at 9c256b6, one change behind. The guard is designed so the next PR owes this bump; this is that PR. Control: the guard on the old pin exits 1 against main 5f82b63. Cure: the guard on the new pin exits 0 against the same main. The guard's own mutant suite passes 10/10. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01QYY8Gp4v4x2J7iSNn1vZ57
…tale #1072 and #1075 changed files under rhodium-standard-repositories/ without regenerating the registry, so `build-registry.sh --check` exits 1 on main. That reds "Registry + topology in sync" and both build-registry-test.sh and build-scorecards-test.sh. And because the test step fails, the "Lock-gate pin is not stale" step is skipped on every PR. Output of `just registry`, one line. Owner ruling D231: regenerate now; moving the registry off .a2ml stays tracked in #1010/#479. Closes #1092. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01QYY8Gp4v4x2J7iSNn1vZ57
The three unfiltered findings that red "Validate Hypatia Baseline" on main are all in uuid-v7.yml (#1063): no `timeout-minutes` (flagged by workflow_audit and WH006), and an unscoped `push` beside `pull_request`, so every PR-branch push ran it twice (D-BURN). Scope push to main, add the repo's usual concurrency cancel block, and set `timeout-minutes: 10`. Job name and check name are unchanged. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01QYY8Gp4v4x2J7iSNn1vZ57
aee1111 to
3d5ff2d
Compare
|
Correction to my earlier comment. I attributed the Hypatia Baseline red to #1014, and that was wrong. The three unfiltered findings on main are all in 🤖 Generated with Claude Code |
|
CI status at The three reds this PR set out to cure (lock-gate pin freshness, registry
This PR is held, not merged. The owner's 2026-09-22 rule lands only fully-green PRs, and the D232 hold still needs re-asking after its premise erratum. 🤖 Generated with Claude Code |
|
Autopilot could not be updated. Open Coding to check access and billing. |
Restores
standardsmain to green. Three reds on main block each other, and all three cures are in this one PR because no single one can pass CI alone.What each commit fixes
ref:under "Checkout standards for the lock gate" ingovernance-reusable.ymlmoves to5f82b635.scripts/check-lock-gate-pin-freshness.shreturns rc=1 on main and rc=0 on this branch. Each tree's own copy of the script was run; running one tree's copy against another tree reads the wrong workflow and passes vacuously.source_hashregeneration. Closes main red: REGISTRY source_hash drift after #1072/#1075 reds Registry Verify and Repo self-tests (and skips the lock-gate pin guard) #1092. fix(scripts): replace hardcoded /tmp paths with mktemp (#936) #1072 and fix(scripts): remove eval from rsr-audit and fill-placeholders test (#939) #1075 changed files under the RSR spec home without regenerating.machine_readable/REGISTRY.a2ml, sobuild-registry.sh --checkfails. That failure reds Self-tests, and the pin guard step never runs because it comes after the failing suite. The change is one regenerated hash line. Under D231 it is a regeneration only; migrating off the generated file is a later piece of work.uuid-v7.ymlhardening. It addstimeout-minutes: 10, aconcurrencygroup, and apushtrigger bounded tomain. These are the three unfiltered Hypatia Baseline findings on main: missing_timeout_minutes, d_burn_double_trigger, and WH006.Correction
My earlier comment on this PR attributed the Hypatia Baseline red to #1014. That was wrong. #1014 is the estate-wide HYPATIA_PIN rollout. The baseline red on main comes from the
uuid-v7.ymlfindings that commit 3 fixes.Local verification on 3d5ff2d
bash scripts/run-shell-test-suite.shcheck-lock-gate-pin-freshness.sh origin/mainbuild-registry.sh --checkLands under the fully-green rule only when every check is green.
🤖 Generated with Claude Code
https://claude.ai/code/session_01QYY8Gp4v4x2J7iSNn1vZ57