Skip to content

Arena/01a0ef85 cicd squabbler - #113

Merged
hyperpolymath merged 5 commits into
mainfrom
arena/01a0ef85-cicd-squabbler
Sep 30, 2026
Merged

hyperpolymath merged 5 commits into
mainfrom
arena/01a0ef85-cicd-squabbler

Conversation

@hyperpolymath

Copy link
Copy Markdown
Owner

Summary

Changes

RSR Quality Checklist

Required

  • Tests pass (just test or equivalent)
  • Code is formatted (just fmt or equivalent)
  • Linter is clean (no new warnings or errors)
  • No banned language patterns (no TypeScript, no npm/bun, no Go/Python)
  • No unsafe blocks without // SAFETY: comments
  • No banned functions (believe_me, unsafeCoerce, Obj.magic, Admitted, sorry)
  • SPDX license headers present on all new/modified source files
  • No secrets, credentials, or .env files included

As Applicable

  • .machine_readable/descriptiles/STATE.a2ml updated (if project state changed)
  • .machine_readable/descriptiles/ECOSYSTEM.a2ml updated (if integrations changed)
  • .machine_readable/descriptiles/META.a2ml updated (if architectural decisions changed)
  • Documentation updated for user-facing changes
  • TOPOLOGY.md updated (if architecture changed)
  • CHANGELOG or release notes updated
  • New dependencies reviewed for license compatibility (MPL-2.0 / MPL-2.0)
  • ABI/FFI changes validated (src/interface/abi/ and src/interface/ffi/ consistent)

Testing

Screenshots

hyperpolymath and others added 5 commits September 29, 2026 23:52
…dabot #111

Dependabot bumped .github/workflows/codeql.yml from github/codeql-action@v4.38.0
to @v4.38.2 (#111) but cannot touch actions.lock, which still pinned v4.38.0.
That is exactly the desync the Lock Sync Gate exists to catch, and it had three
visible symptoms on main @16c9ad0:

  * Lock Sync Gate                       red
  * governance / Actions lockfile verify red
  * CodeQL Security Analysis             startup_failure (zero jobs created)

The lock now lists the v4.38.2 tag for codeql.yml and carries its dependency
record. commit: is the DEREFERENCED commit sha (2892aa5e…), not the annotated tag
object (88585263…); the same lookup reproduces the v4.38.0 sha already in the lock.
Both codeql-action/init and /analyze are 'using: node24' leaves, so the record has
no nested uses:, matching the v4.38.0 record it replaces. The now-orphaned v4.38.0
record is dropped.

Refs #105

Co-authored-by: arena-agent <297053741+arena-agent@users.noreply.github.com>
…F Compliance red

#110's changelog entry about the template-placeholder rendering spelled the
double-brace token out literally. The OpenSSF Compliance gate greps each required
file (CHANGELOG.adoc is one) with  grep -cE '\{\{[A-Z_]+\}\}'  and cannot tell a
quoted example from an unfilled one, so the entry itself tripped it:

  ::error::CHANGELOG.adoc contains 1 unfilled {{PLACEHOLDER}} tokens

Reworded to describe the token without spelling it, with a note saying why, so the
next editor does not reintroduce it. Verified by running the gate's exact regex
over every file the gate checks: CHANGELOG.adoc 1 -> 0, all others already 0.

Refs #105

Co-authored-by: arena-agent <297053741+arena-agent@users.noreply.github.com>
…d before merge)

Runs the estate Rust gates (fmt --check, clippy -D warnings, test --all-targets, same
cargo arguments as standards' rust-ci-reusable.yml) on push to arena/** and publishes the
output as workflow annotations, because the authoring sandbox has no Rust toolchain and
cannot read job logs. Read-only, carries no uses:, and has a [] lock entry (gate clause 4).

#110 merged ~1,800 lines of Rust that were never compiled by their author, and every CI run
on that PR was startup_failure; main's Rust CI has been red on 'Cargo fmt' ever since, which
also SKIPS clippy and every test. This exists to find out what is actually true.

Refs #100 #15

Co-authored-by: arena-agent <297053741+arena-agent@users.noreply.github.com>
Co-authored-by: arena-agent <297053741+arena-agent@users.noreply.github.com>
@coderabbitai

coderabbitai Bot commented Sep 30, 2026

Copy link
Copy Markdown
Contributor

Review in Change Stack →

Navigate logical layers of code changes, visualize relationships, and explore their blast radius.

Note

Currently processing new changes in this PR. This may take a few minutes, please wait...

⚙️ Run configuration

Configuration used: Organization UI

Review profile: ASSERTIVE

Plan: Advanced

Run ID: 5d205c14-287b-4a6b-946d-0c5d2c75aab6

📥 Commits

Reviewing files that changed from the base of the PR and between 16c9ad0 and b49fe04.

⛔ Files ignored due to path filters (1)
  • .github/workflows/actions.lock is excluded by !**/*.lock
📒 Files selected for processing (1)
  • CHANGELOG.adoc
 ________________________________________________________________________________________________________________________
< I've finally learned what 'upward compatible' means. It means we get to keep all our old mistakes. - Dennie van Tassel >
 ------------------------------------------------------------------------------------------------------------------------
  \
   \   \
        \ /\
        ( )
      .( o ).

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@hyperpolymath
hyperpolymath merged commit b12657f into main Sep 30, 2026
47 of 51 checks passed
@hyperpolymath
hyperpolymath deleted the arena/01a0ef85-cicd-squabbler branch September 30, 2026 00:16
hyperpolymath added a commit that referenced this pull request Sep 30, 2026
…116)

## Why

`rust-ci / Cargo check + clippy + fmt` is **red on `main`** (`b12657f`,
#113). The fmt step fails first, so clippy never runs, and `Cargo test`,
`llvm-cov line coverage` and `Cargo audit` are all **skipped** on every
PR, #114 included. Nothing in CI has been testing this workspace.

## What

- `cargo fmt --all` (squabble-fight `lib.rs` + `workflows.rs`,
squabble-cli `fetch.rs`, squabble-core `moves.rs`). Formatting only.
- `clippy::needless_lifetimes`: `workflows.rs` `uses_target` now elides
its lifetimes.
- Removed `fetch::run_with_greens`. It has no caller: `run_bundle`
already returns `.greens`, and that is what `fight` consumes.

## Evidence (local, same commands as the workflow)

| step | rc |
|---|---|
| `cargo check --locked --all-targets` | 0 |
| `cargo fmt --all -- --check` | 0 |
| `cargo clippy --locked --all-targets -- -D warnings` | 0 |
| `cargo test --workspace` | green (41 + 82 + 64 + 12) |

Found by `squabble verify-satisfied` (stacked on #114), which initially
reported #114 as done while this check was red. That was a gap in the
evaluator, and it is fixed in that PR.

Merge before #114, so #114's CI is the first to actually run tests.

🤖 Generated with [Claude Code](https://claude.com/claude-code)

https://claude.ai/code/session_0136eszqrQ53Kj7aBH1D4rXK

Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant