Skip to content

ci: validate pinned paired semantic-memory source - #3

Draft
RecursiveIntell wants to merge 2 commits into
fix/mirror-canary-error-20260928from
ci/paired-root-proof-20260928
Draft

RecursiveIntell wants to merge 2 commits into
fix/mirror-canary-error-20260928from
ci/paired-root-proof-20260928

Conversation

@RecursiveIntell

@RecursiveIntell RecursiveIntell commented Sep 28, 2026 •

Copy link
Copy Markdown
Owner

Dependency and purpose

Draft, stacked on standalone semantic-memory PR #2 (fix/mirror-canary-error-20260928, head 518a2ad471c4da4f26f53ee615aefb851f9df5a6). This adds a CI proof for the repository's documented paired workspace-root validation model. It does not make a standalone clone build independently, synchronize the other source differences, adopt semantic law, merge either PR, or activate a service.

On a pull_request, the workflow checks out GitHub's exact synthetic base+head merge commit (the revision supplying the workflow file) and verifies the PR head as its second parent. Push/dispatch runs use their event commit. Libraries source is separately pinned to 0b099ec416de60f6adafb182f1d1e83795d05c56. The two checkouts are not edited; the script assembles a disposable paired root from those Git objects. Only regular, path-checked mirror files are extracted; duplicate/colliding archive members are rejected, and every assembled mirror path is checked against its Git blob and executable mode. The trusted Libraries archive comes from its pinned Git object, but this script does not independently hash every extracted Libraries file. A scratch lock update is allowed only if its parsed content differs from the pinned Libraries lock by the known removal of fib-quant 0.1.0-alpha.1 from PolyKV's dependency list. Other lock drift fails.

Gates and limits

  • The workflow runs the pairing script's negative self-tests, formats the package, checks the governed canary example, runs Clippy on package targets, and runs the library tests with the scratch lock pinned after its explicit delta check. Fork PRs are skipped pending separate maintainer admission; a skipped workflow is not passing CI.
  • Local controller validation: seven Python tests passed, including wrong-SHA-before-scratch, shallow Git commit-parent extraction, PR merge-parent, path/mode, archive-collision, real temporary-Git assembly and lock-drift negatives. The first hosted PR run #36384379185 failed before Cargo tests: git show --format=%P hid both parents in Actions' depth-one checkout. I reproduced that failure with a shallow checkout of its exact merge commit 7f381d350ae2560176418f0251567609b55620a0, then changed the script to read the raw git cat-file -p commit headers. The repaired script assembled that shallow merge source with 172 tracked mirror blobs and verified its PR head as second parent. In the resulting local paired root, the targeted Cargo check, formatting, Clippy and library tests passed: 120 passed, 3 ignored. actionlint v1.7.10 returned exit 0 on the revised workflow. The repaired-head hosted run #36385081947 subsequently completed successfully at PR head ccc08cd14fbd45eab22c4b6a3179ed501e5660f0 (one paired-root job). The first failed run remains failed evidence; the hosted result covers only the workflow's selected lanes, not complete parity or clean standalone packaging.
  • A diagnostic branch at standalone main failed Clippy on the old canary expect, so this PR is deliberately dependent on PR fix(example): forward-sync governed canary issuer error #2. This result was not converted into a green base claim. The standalone-only cargo metadata failure due inherited workspace dependencies is unchanged.
  • This is not full mirror parity: the previously recorded denominator at the selected heads has 17 differing shared paths and 118 Libraries-only paths. The pinned Libraries revision may become stale when its main branch advances. This job does not test all features, every example, clean release packaging, invalid-token execution, provider behavior, or live memory authority.

Rollback / promotion

Revert this three-file CI commit if rejected; scratch source and lock are rebuildable. Do not merge this stacked PR before PR #2 is integrated and its exact approved blob is present on the intended target branch. Before any later full-mirror or release claim, reconcile source and dependency deltas, refresh the pinned owner SHA through review, and run the corresponding broader gates. No live state is touched by this PR.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant