ci: validate pinned paired semantic-memory source - #3
Draft
RecursiveIntell wants to merge 2 commits into
Draft
RecursiveIntell wants to merge 2 commits into
RecursiveIntell wants to merge 2 commits into
Conversation
This was referenced Sep 28, 2026
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Dependency and purpose
Draft, stacked on standalone semantic-memory PR #2 (
fix/mirror-canary-error-20260928, head518a2ad471c4da4f26f53ee615aefb851f9df5a6). This adds a CI proof for the repository's documented paired workspace-root validation model. It does not make a standalone clone build independently, synchronize the other source differences, adopt semantic law, merge either PR, or activate a service.On a
pull_request, the workflow checks out GitHub's exact synthetic base+head merge commit (the revision supplying the workflow file) and verifies the PR head as its second parent. Push/dispatch runs use their event commit. Libraries source is separately pinned to0b099ec416de60f6adafb182f1d1e83795d05c56. The two checkouts are not edited; the script assembles a disposable paired root from those Git objects. Only regular, path-checked mirror files are extracted; duplicate/colliding archive members are rejected, and every assembled mirror path is checked against its Git blob and executable mode. The trusted Libraries archive comes from its pinned Git object, but this script does not independently hash every extracted Libraries file. A scratch lock update is allowed only if its parsed content differs from the pinned Libraries lock by the known removal offib-quant 0.1.0-alpha.1from PolyKV's dependency list. Other lock drift fails.Gates and limits
git show --format=%Phid both parents in Actions' depth-one checkout. I reproduced that failure with a shallow checkout of its exact merge commit7f381d350ae2560176418f0251567609b55620a0, then changed the script to read the rawgit cat-file -pcommit headers. The repaired script assembled that shallow merge source with 172 tracked mirror blobs and verified its PR head as second parent. In the resulting local paired root, the targeted Cargo check, formatting, Clippy and library tests passed: 120 passed, 3 ignored.actionlint v1.7.10returned exit 0 on the revised workflow. The repaired-head hosted run #36385081947 subsequently completed successfully at PR headccc08cd14fbd45eab22c4b6a3179ed501e5660f0(onepaired-rootjob). The first failed run remains failed evidence; the hosted result covers only the workflow's selected lanes, not complete parity or clean standalone packaging.expect, so this PR is deliberately dependent on PR fix(example): forward-sync governed canary issuer error #2. This result was not converted into a green base claim. The standalone-onlycargo metadatafailure due inherited workspace dependencies is unchanged.Rollback / promotion
Revert this three-file CI commit if rejected; scratch source and lock are rebuildable. Do not merge this stacked PR before PR #2 is integrated and its exact approved blob is present on the intended target branch. Before any later full-mirror or release claim, reconcile source and dependency deltas, refresh the pinned owner SHA through review, and run the corresponding broader gates. No live state is touched by this PR.