From 8384981abbc27dafcfa643870e7ac6a7cbee3cb6 Mon Sep 17 00:00:00 2001 From: hyperpolymath <6759885+hyperpolymath@users.noreply.github.com> Date: Tue, 29 Sep 2026 23:52:27 +0000 Subject: [PATCH 1/5] =?UTF-8?q?fix(ci):=20lock=20codeql-action=20v4.38.2?= =?UTF-8?q?=20=E2=80=94=20resync=20actions.lock=20after=20Dependabot=20#11?= =?UTF-8?q?1?= MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit Dependabot bumped .github/workflows/codeql.yml from github/codeql-action@v4.38.0 to @v4.38.2 (#111) but cannot touch actions.lock, which still pinned v4.38.0. That is exactly the desync the Lock Sync Gate exists to catch, and it had three visible symptoms on main @16c9ad0: * Lock Sync Gate red * governance / Actions lockfile verify red * CodeQL Security Analysis startup_failure (zero jobs created) The lock now lists the v4.38.2 tag for codeql.yml and carries its dependency record. commit: is the DEREFERENCED commit sha (2892aa5e…), not the annotated tag object (88585263…); the same lookup reproduces the v4.38.0 sha already in the lock. Both codeql-action/init and /analyze are 'using: node24' leaves, so the record has no nested uses:, matching the v4.38.0 record it replaces. The now-orphaned v4.38.0 record is dropped. Refs #105 Co-authored-by: arena-agent <297053741+arena-agent@users.noreply.github.com> --- .github/workflows/actions.lock | 8 ++++---- 1 file changed, 4 insertions(+), 4 deletions(-) diff --git a/.github/workflows/actions.lock b/.github/workflows/actions.lock index c39d3e1..afd1eb2 100644 --- a/.github/workflows/actions.lock +++ b/.github/workflows/actions.lock @@ -5,7 +5,7 @@ version: 'v0.0.2' workflows: '.github/workflows/codeql.yml': - 'actions/checkout@v7.0.1' - - 'github/codeql-action@v4.38.0' + - 'github/codeql-action@v4.38.2' '.github/workflows/container-build.yml': - 'actions/checkout@v7.0.1' '.github/workflows/dependabot-automerge.yml': @@ -167,9 +167,9 @@ dependencies: commit: 'sha1-cdf488f595d80d6e07e03d4674febd5ab45fa938' owner_id: 9919 repo_id: 259445878 - 'github/codeql-action@v4.38.0': - ref: 'v4.38.0' - commit: 'sha1-b96794f015dfd88f77b49b1c93e0fa7110f94c63' + 'github/codeql-action@v4.38.2': + ref: 'v4.38.2' + commit: 'sha1-2892aa5e19bbd11bc0cff5427e3b750a04d9e3c2' owner_id: 9919 repo_id: 259445878 'goto-bus-stop/setup-zig@abea47f85e598557f500fa1fd2ab7464fcb39406': From b5795264685de88cd0e51f419b6841d521749de7 Mon Sep 17 00:00:00 2001 From: hyperpolymath <6759885+hyperpolymath@users.noreply.github.com> Date: Tue, 29 Sep 2026 23:52:35 +0000 Subject: [PATCH 2/5] =?UTF-8?q?fix(changelog):=20stop=20quoting=20the=20pl?= =?UTF-8?q?aceholder=20token=20=E2=80=94=20it=20turned=20OpenSSF=20Complia?= =?UTF-8?q?nce=20red?= MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit #110's changelog entry about the template-placeholder rendering spelled the double-brace token out literally. The OpenSSF Compliance gate greps each required file (CHANGELOG.adoc is one) with grep -cE '\{\{[A-Z_]+\}\}' and cannot tell a quoted example from an unfilled one, so the entry itself tripped it: ::error::CHANGELOG.adoc contains 1 unfilled {{PLACEHOLDER}} tokens Reworded to describe the token without spelling it, with a note saying why, so the next editor does not reintroduce it. Verified by running the gate's exact regex over every file the gate checks: CHANGELOG.adoc 1 -> 0, all others already 0. Refs #105 Co-authored-by: arena-agent <297053741+arena-agent@users.noreply.github.com> --- CHANGELOG.adoc | 10 ++++++---- 1 file changed, 6 insertions(+), 4 deletions(-) diff --git a/CHANGELOG.adoc b/CHANGELOG.adoc index 4c2ee67..841207e 100644 --- a/CHANGELOG.adoc +++ b/CHANGELOG.adoc @@ -53,10 +53,12 @@ https://semver.org/spec/v2.0.0.html[Semantic Versioning]. * All 27 workflow files whose `gh actions-lock` stamp had displaced the SPDX header off line 1 now carry `# SPDX-License-Identifier: MPL-2.0` as byte 1 again — `lint-workflows / Check SPDX Headers` red on `main`, issue #105. -* Unrendered `{{PLACEHOLDER}}` tokens across `.devcontainer/`, `.envrc`, - `.github/SUPPORT`, `.github/.mailmap`, `.github/MAINTAINERS`, - `.github/CODE_OF_CONDUCT.md`, `.github/copilot-instructions.md` and the - `.machine_readable/ai/` rule files. +* Unrendered template placeholder tokens (the double-brace form) across + `.devcontainer/`, `.envrc`, `.github/SUPPORT`, `.github/.mailmap`, + `.github/MAINTAINERS`, `.github/CODE_OF_CONDUCT.md`, + `.github/copilot-instructions.md` and the `.machine_readable/ai/` rule files. + (This entry must not spell the token out: the OpenSSF Compliance gate greps + the changelog for it, and quoting it here turned that gate red on `main`.) ==== Removed From 16bc675def02d55f7821154c82c53b851872c526 Mon Sep 17 00:00:00 2001 From: hyperpolymath <6759885+hyperpolymath@users.noreply.github.com> Date: Tue, 29 Sep 2026 23:52:35 +0000 Subject: [PATCH 3/5] chore(probe): TEMPORARY Rust gate probe for this branch (to be removed before merge) Runs the estate Rust gates (fmt --check, clippy -D warnings, test --all-targets, same cargo arguments as standards' rust-ci-reusable.yml) on push to arena/** and publishes the output as workflow annotations, because the authoring sandbox has no Rust toolchain and cannot read job logs. Read-only, carries no uses:, and has a [] lock entry (gate clause 4). #110 merged ~1,800 lines of Rust that were never compiled by their author, and every CI run on that PR was startup_failure; main's Rust CI has been red on 'Cargo fmt' ever since, which also SKIPS clippy and every test. This exists to find out what is actually true. Refs #100 #15 Co-authored-by: arena-agent <297053741+arena-agent@users.noreply.github.com> --- .github/workflows/actions.lock | 1 + .github/workflows/arena-rust-probe.yml | 226 +++++++++++++++++++++++++ 2 files changed, 227 insertions(+) create mode 100644 .github/workflows/arena-rust-probe.yml diff --git a/.github/workflows/actions.lock b/.github/workflows/actions.lock index afd1eb2..c4c1aca 100644 --- a/.github/workflows/actions.lock +++ b/.github/workflows/actions.lock @@ -3,6 +3,7 @@ # Docs: https://gh.io/actions-lockfile version: 'v0.0.2' workflows: + '.github/workflows/arena-rust-probe.yml': [] '.github/workflows/codeql.yml': - 'actions/checkout@v7.0.1' - 'github/codeql-action@v4.38.2' diff --git a/.github/workflows/arena-rust-probe.yml b/.github/workflows/arena-rust-probe.yml new file mode 100644 index 0000000..5e4241c --- /dev/null +++ b/.github/workflows/arena-rust-probe.yml @@ -0,0 +1,226 @@ +# SPDX-License-Identifier: MPL-2.0 +# ARENA SESSION SCRATCH -- NOT FOR MERGE. Deleted before this branch is proposed. +# +# Why this exists: the authoring sandbox has no Rust toolchain and cannot read job +# logs (they are served from a blob host it cannot reach), so `cargo fmt`, +# `clippy -D warnings` and `cargo test` could not be observed at all. PR #110 merged +# ~1,800 lines of Rust its author never compiled, and every one of that PR's own CI +# runs was `startup_failure`, so nothing ever exercised it. This probe runs the same +# gates, with the same cargo arguments, as standards' rust-ci-reusable.yml and publishes +# their output as workflow annotations -- the one channel the checks API serves +# without the log (the same technique MetaManifold-WebUI's ci.yml already uses). +# +# Read-only (contents: read). Carries NO `uses:`, so the Actions policy cannot refuse it. +name: Arena Rust Probe + +on: + push: + branches: ['arena/**'] + +permissions: + contents: read + +concurrency: + group: arena-rust-probe-${{ github.ref }} + cancel-in-progress: true + +env: + CARGO_TERM_COLOR: never + CARGO_TERM_PROGRESS_WHEN: never + +defaults: + run: + shell: bash + +jobs: + fmt: + name: probe / fmt (emits the rustfmt patch) + runs-on: ubuntu-latest + timeout-minutes: 15 + steps: + - name: Check out without actions/checkout + env: + REPO: ${{ github.repository }} + SHA: ${{ github.sha }} + TOKEN: ${{ github.token }} + run: | + set -euo pipefail + AUTH="AUTHORIZATION: basic $(printf 'x-access-token:%s' "${TOKEN}" | base64 -w0)" + git init -q . + git remote add origin "https://github.com/${REPO}.git" + git -c http.extraheader="${AUTH}" fetch -q --depth 1 origin "${SHA}" + git checkout -q FETCH_HEAD + echo "checked out ${SHA}" + + - name: Install the same toolchain the estate CI installs (stable + rustfmt) + run: | + set -euo pipefail + rustup toolchain install stable --profile minimal --component rustfmt --no-self-update + rustup default stable + echo "::notice title=fmt toolchain::$(rustc --version) | $(cargo --version) | $(rustfmt --version)" + + - name: cargo fmt --all -- --check (exact estate command) + id: check + run: | + set +e + cargo fmt --all -- --check > "$RUNNER_TEMP/fmt-check.log" 2>&1 + rc=$? + echo "rc=$rc" >> "$GITHUB_OUTPUT" + echo "::notice title=fmt check exit code::$rc ($(grep -c '^Diff in' "$RUNNER_TEMP/fmt-check.log") diff hunks)" + exit 0 + + - name: Apply rustfmt and publish the resulting patch (gzip + base64, chunked) + run: | + set +e + emit() { # emit TITLE FILE MODE(text|b64) MAXCHUNKS + local title="$1" file="$2" mode="$3" max="${4:-27}" dir total n f lvl msg + dir="$(mktemp -d)" + if [ "$mode" = b64 ]; then split -b 3000 -d -a 3 "$file" "$dir/c."; else split -C 3000 -d -a 3 "$file" "$dir/c."; fi + total=$(find "$dir" -type f | wc -l); n=0 + for f in "$dir"/c.*; do + n=$((n+1)); [ "$n" -gt "$max" ] && break + if [ "$n" -le 9 ]; then lvl=error; elif [ "$n" -le 18 ]; then lvl=warning; else lvl=notice; fi + msg="$(sed -e 's/%/%25/g' "$f" | sed -e ':a;N;$!ba;s/\r/%0D/g;s/\n/%0A/g')" + echo "::${lvl} title=${title} ${n}/${total}::${msg}" + done + if [ "$total" -gt "$max" ]; then echo "::notice title=${title} TRUNCATED::${total} chunks; only ${max} emitted"; fi + } + cargo fmt --all + git diff --stat > "$RUNNER_TEMP/fmt.stat" + git diff > "$RUNNER_TEMP/fmt.patch" + bytes=$(wc -c < "$RUNNER_TEMP/fmt.patch") + echo "::notice title=fmt patch::$(tail -n 1 "$RUNNER_TEMP/fmt.stat") | patch bytes=${bytes}" + if [ "$bytes" -gt 0 ]; then + echo "::notice title=fmt.stat::$(head -c 3000 "$RUNNER_TEMP/fmt.stat" | sed -e 's/%/%25/g' | sed -e ':a;N;$!ba;s/\n/%0A/g')" + gzip -9 -c "$RUNNER_TEMP/fmt.patch" | base64 -w0 > "$RUNNER_TEMP/fmt.patch.gz.b64" + echo "::notice title=fmt patch b64::$(wc -c < "$RUNNER_TEMP/fmt.patch.gz.b64") base64 bytes (gz)" + emit "fmt.patch.gz.b64" "$RUNNER_TEMP/fmt.patch.gz.b64" b64 22 + fi + + - name: Gate result + env: + RC: ${{ steps.check.outputs.rc }} + run: 'exit "${RC:-1}"' + + clippy: + name: probe / clippy (-D warnings) + runs-on: ubuntu-latest + timeout-minutes: 25 + steps: + - name: Check out without actions/checkout + env: + REPO: ${{ github.repository }} + SHA: ${{ github.sha }} + TOKEN: ${{ github.token }} + run: | + set -euo pipefail + AUTH="AUTHORIZATION: basic $(printf 'x-access-token:%s' "${TOKEN}" | base64 -w0)" + git init -q . + git remote add origin "https://github.com/${REPO}.git" + git -c http.extraheader="${AUTH}" fetch -q --depth 1 origin "${SHA}" + git checkout -q FETCH_HEAD + + - name: Install the same toolchain the estate CI installs (stable + clippy) + run: | + set -euo pipefail + rustup toolchain install stable --profile minimal --component clippy --no-self-update + rustup default stable + echo "::notice title=clippy toolchain::$(rustc --version) | $(cargo clippy --version)" + + - name: cargo clippy --locked --all-targets -- -D warnings (exact estate command, short format) + id: clippy + run: | + set +e + emit() { + local title="$1" file="$2" max="${3:-27}" dir total n f lvl msg + dir="$(mktemp -d)"; split -C 3000 -d -a 3 "$file" "$dir/c." + total=$(find "$dir" -type f | wc -l); n=0 + for f in "$dir"/c.*; do + n=$((n+1)); [ "$n" -gt "$max" ] && break + if [ "$n" -le 9 ]; then lvl=error; elif [ "$n" -le 18 ]; then lvl=warning; else lvl=notice; fi + msg="$(sed -e 's/%/%25/g' "$f" | sed -e ':a;N;$!ba;s/\r/%0D/g;s/\n/%0A/g')" + echo "::${lvl} title=${title} ${n}/${total}::${msg}" + done + if [ "$total" -gt "$max" ]; then echo "::notice title=${title} TRUNCATED::${total} chunks; only ${max} emitted"; fi + } + cargo clippy --locked --all-targets --message-format=short -- -D warnings > "$RUNNER_TEMP/clippy.log" 2>&1 + rc=$? + echo "rc=$rc" >> "$GITHUB_OUTPUT" + echo "::notice title=clippy exit code::$rc | errors=$(grep -c ': error' "$RUNNER_TEMP/clippy.log") warnings=$(grep -c ': warning' "$RUNNER_TEMP/clippy.log")" + grep -E ': (error|warning)|^error|^warning|could not compile' "$RUNNER_TEMP/clippy.log" | grep -v '^warning: unused manifest' > "$RUNNER_TEMP/clippy.short" || true + [ -s "$RUNNER_TEMP/clippy.short" ] || tail -c 20000 "$RUNNER_TEMP/clippy.log" > "$RUNNER_TEMP/clippy.short" + emit "clippy" "$RUNNER_TEMP/clippy.short" 25 + exit 0 + + - name: Gate result + env: + RC: ${{ steps.clippy.outputs.rc }} + run: 'exit "${RC:-1}"' + + test: + name: probe / test (--all-targets, no-fail-fast) + runs-on: ubuntu-latest + timeout-minutes: 25 + steps: + - name: Check out without actions/checkout + env: + REPO: ${{ github.repository }} + SHA: ${{ github.sha }} + TOKEN: ${{ github.token }} + run: | + set -euo pipefail + AUTH="AUTHORIZATION: basic $(printf 'x-access-token:%s' "${TOKEN}" | base64 -w0)" + git init -q . + git remote add origin "https://github.com/${REPO}.git" + git -c http.extraheader="${AUTH}" fetch -q --depth 1 origin "${SHA}" + git checkout -q FETCH_HEAD + + - name: Install the same toolchain the estate CI installs (stable) + run: | + set -euo pipefail + rustup toolchain install stable --profile minimal --no-self-update + rustup default stable + echo "::notice title=test toolchain::$(rustc --version) | $(cargo --version)" + + - name: cargo test --locked --all-targets --no-fail-fast + id: test + run: | + set +e + emit() { + local title="$1" file="$2" max="${3:-27}" dir total n f lvl msg + dir="$(mktemp -d)"; split -C 3000 -d -a 3 "$file" "$dir/c." + total=$(find "$dir" -type f | wc -l); n=0 + for f in "$dir"/c.*; do + n=$((n+1)); [ "$n" -gt "$max" ] && break + if [ "$n" -le 9 ]; then lvl=error; elif [ "$n" -le 18 ]; then lvl=warning; else lvl=notice; fi + msg="$(sed -e 's/%/%25/g' "$f" | sed -e ':a;N;$!ba;s/\r/%0D/g;s/\n/%0A/g')" + echo "::${lvl} title=${title} ${n}/${total}::${msg}" + done + if [ "$total" -gt "$max" ]; then echo "::notice title=${title} TRUNCATED::${total} chunks; only ${max} emitted"; fi + } + cargo test --locked --all-targets --no-fail-fast > "$RUNNER_TEMP/test.log" 2>&1 + rc=$? + echo "rc=$rc" >> "$GITHUB_OUTPUT" + passed=$(grep -c '^test .* \.\.\. ok$' "$RUNNER_TEMP/test.log") + failed=$(grep -c '^test .* \.\.\. FAILED$' "$RUNNER_TEMP/test.log") + echo "::notice title=test exit code::$rc | passed=${passed} failed=${failed}" + grep -E '^test result:' "$RUNNER_TEMP/test.log" | sort | uniq -c | sed 's/^ *//' > "$RUNNER_TEMP/test.results" || true + echo "::notice title=test results::$(sed -e 's/%/%25/g' "$RUNNER_TEMP/test.results" | sed -e ':a;N;$!ba;s/\n/%0A/g')" + awk ' + /^---- .* ----$/ { p = 1 } + /^failures:$/ { p = 1 } + /^test result:/ { print; p = 0; next } + /^error(\[|:)/ { print } + /^test .* FAILED$/ { print } + p { print } + ' "$RUNNER_TEMP/test.log" > "$RUNNER_TEMP/test.fail" + if [ -s "$RUNNER_TEMP/test.fail" ]; then emit "test.fail" "$RUNNER_TEMP/test.fail" 24; fi + if [ "$rc" -ne 0 ] && [ ! -s "$RUNNER_TEMP/test.fail" ]; then + tail -c 20000 "$RUNNER_TEMP/test.log" > "$RUNNER_TEMP/test.tail"; emit "test.tail" "$RUNNER_TEMP/test.tail" 9 + fi + exit 0 + + - name: Gate result + env: + RC: ${{ steps.test.outputs.rc }} + run: 'exit "${RC:-1}"' From 1acd3354040ea4863b82b5cc60a5e2d6ac79375c Mon Sep 17 00:00:00 2001 From: hyperpolymath <6759885+hyperpolymath@users.noreply.github.com> Date: Tue, 29 Sep 2026 23:59:06 +0000 Subject: [PATCH 4/5] Revert "chore(probe): TEMPORARY Rust gate probe for this branch (to be removed before merge)" This reverts commit 16bc675def02d55f7821154c82c53b851872c526. --- .github/workflows/actions.lock | 1 - .github/workflows/arena-rust-probe.yml | 226 ------------------------- 2 files changed, 227 deletions(-) delete mode 100644 .github/workflows/arena-rust-probe.yml diff --git a/.github/workflows/actions.lock b/.github/workflows/actions.lock index c4c1aca..afd1eb2 100644 --- a/.github/workflows/actions.lock +++ b/.github/workflows/actions.lock @@ -3,7 +3,6 @@ # Docs: https://gh.io/actions-lockfile version: 'v0.0.2' workflows: - '.github/workflows/arena-rust-probe.yml': [] '.github/workflows/codeql.yml': - 'actions/checkout@v7.0.1' - 'github/codeql-action@v4.38.2' diff --git a/.github/workflows/arena-rust-probe.yml b/.github/workflows/arena-rust-probe.yml deleted file mode 100644 index 5e4241c..0000000 --- a/.github/workflows/arena-rust-probe.yml +++ /dev/null @@ -1,226 +0,0 @@ -# SPDX-License-Identifier: MPL-2.0 -# ARENA SESSION SCRATCH -- NOT FOR MERGE. Deleted before this branch is proposed. -# -# Why this exists: the authoring sandbox has no Rust toolchain and cannot read job -# logs (they are served from a blob host it cannot reach), so `cargo fmt`, -# `clippy -D warnings` and `cargo test` could not be observed at all. PR #110 merged -# ~1,800 lines of Rust its author never compiled, and every one of that PR's own CI -# runs was `startup_failure`, so nothing ever exercised it. This probe runs the same -# gates, with the same cargo arguments, as standards' rust-ci-reusable.yml and publishes -# their output as workflow annotations -- the one channel the checks API serves -# without the log (the same technique MetaManifold-WebUI's ci.yml already uses). -# -# Read-only (contents: read). Carries NO `uses:`, so the Actions policy cannot refuse it. -name: Arena Rust Probe - -on: - push: - branches: ['arena/**'] - -permissions: - contents: read - -concurrency: - group: arena-rust-probe-${{ github.ref }} - cancel-in-progress: true - -env: - CARGO_TERM_COLOR: never - CARGO_TERM_PROGRESS_WHEN: never - -defaults: - run: - shell: bash - -jobs: - fmt: - name: probe / fmt (emits the rustfmt patch) - runs-on: ubuntu-latest - timeout-minutes: 15 - steps: - - name: Check out without actions/checkout - env: - REPO: ${{ github.repository }} - SHA: ${{ github.sha }} - TOKEN: ${{ github.token }} - run: | - set -euo pipefail - AUTH="AUTHORIZATION: basic $(printf 'x-access-token:%s' "${TOKEN}" | base64 -w0)" - git init -q . - git remote add origin "https://github.com/${REPO}.git" - git -c http.extraheader="${AUTH}" fetch -q --depth 1 origin "${SHA}" - git checkout -q FETCH_HEAD - echo "checked out ${SHA}" - - - name: Install the same toolchain the estate CI installs (stable + rustfmt) - run: | - set -euo pipefail - rustup toolchain install stable --profile minimal --component rustfmt --no-self-update - rustup default stable - echo "::notice title=fmt toolchain::$(rustc --version) | $(cargo --version) | $(rustfmt --version)" - - - name: cargo fmt --all -- --check (exact estate command) - id: check - run: | - set +e - cargo fmt --all -- --check > "$RUNNER_TEMP/fmt-check.log" 2>&1 - rc=$? - echo "rc=$rc" >> "$GITHUB_OUTPUT" - echo "::notice title=fmt check exit code::$rc ($(grep -c '^Diff in' "$RUNNER_TEMP/fmt-check.log") diff hunks)" - exit 0 - - - name: Apply rustfmt and publish the resulting patch (gzip + base64, chunked) - run: | - set +e - emit() { # emit TITLE FILE MODE(text|b64) MAXCHUNKS - local title="$1" file="$2" mode="$3" max="${4:-27}" dir total n f lvl msg - dir="$(mktemp -d)" - if [ "$mode" = b64 ]; then split -b 3000 -d -a 3 "$file" "$dir/c."; else split -C 3000 -d -a 3 "$file" "$dir/c."; fi - total=$(find "$dir" -type f | wc -l); n=0 - for f in "$dir"/c.*; do - n=$((n+1)); [ "$n" -gt "$max" ] && break - if [ "$n" -le 9 ]; then lvl=error; elif [ "$n" -le 18 ]; then lvl=warning; else lvl=notice; fi - msg="$(sed -e 's/%/%25/g' "$f" | sed -e ':a;N;$!ba;s/\r/%0D/g;s/\n/%0A/g')" - echo "::${lvl} title=${title} ${n}/${total}::${msg}" - done - if [ "$total" -gt "$max" ]; then echo "::notice title=${title} TRUNCATED::${total} chunks; only ${max} emitted"; fi - } - cargo fmt --all - git diff --stat > "$RUNNER_TEMP/fmt.stat" - git diff > "$RUNNER_TEMP/fmt.patch" - bytes=$(wc -c < "$RUNNER_TEMP/fmt.patch") - echo "::notice title=fmt patch::$(tail -n 1 "$RUNNER_TEMP/fmt.stat") | patch bytes=${bytes}" - if [ "$bytes" -gt 0 ]; then - echo "::notice title=fmt.stat::$(head -c 3000 "$RUNNER_TEMP/fmt.stat" | sed -e 's/%/%25/g' | sed -e ':a;N;$!ba;s/\n/%0A/g')" - gzip -9 -c "$RUNNER_TEMP/fmt.patch" | base64 -w0 > "$RUNNER_TEMP/fmt.patch.gz.b64" - echo "::notice title=fmt patch b64::$(wc -c < "$RUNNER_TEMP/fmt.patch.gz.b64") base64 bytes (gz)" - emit "fmt.patch.gz.b64" "$RUNNER_TEMP/fmt.patch.gz.b64" b64 22 - fi - - - name: Gate result - env: - RC: ${{ steps.check.outputs.rc }} - run: 'exit "${RC:-1}"' - - clippy: - name: probe / clippy (-D warnings) - runs-on: ubuntu-latest - timeout-minutes: 25 - steps: - - name: Check out without actions/checkout - env: - REPO: ${{ github.repository }} - SHA: ${{ github.sha }} - TOKEN: ${{ github.token }} - run: | - set -euo pipefail - AUTH="AUTHORIZATION: basic $(printf 'x-access-token:%s' "${TOKEN}" | base64 -w0)" - git init -q . - git remote add origin "https://github.com/${REPO}.git" - git -c http.extraheader="${AUTH}" fetch -q --depth 1 origin "${SHA}" - git checkout -q FETCH_HEAD - - - name: Install the same toolchain the estate CI installs (stable + clippy) - run: | - set -euo pipefail - rustup toolchain install stable --profile minimal --component clippy --no-self-update - rustup default stable - echo "::notice title=clippy toolchain::$(rustc --version) | $(cargo clippy --version)" - - - name: cargo clippy --locked --all-targets -- -D warnings (exact estate command, short format) - id: clippy - run: | - set +e - emit() { - local title="$1" file="$2" max="${3:-27}" dir total n f lvl msg - dir="$(mktemp -d)"; split -C 3000 -d -a 3 "$file" "$dir/c." - total=$(find "$dir" -type f | wc -l); n=0 - for f in "$dir"/c.*; do - n=$((n+1)); [ "$n" -gt "$max" ] && break - if [ "$n" -le 9 ]; then lvl=error; elif [ "$n" -le 18 ]; then lvl=warning; else lvl=notice; fi - msg="$(sed -e 's/%/%25/g' "$f" | sed -e ':a;N;$!ba;s/\r/%0D/g;s/\n/%0A/g')" - echo "::${lvl} title=${title} ${n}/${total}::${msg}" - done - if [ "$total" -gt "$max" ]; then echo "::notice title=${title} TRUNCATED::${total} chunks; only ${max} emitted"; fi - } - cargo clippy --locked --all-targets --message-format=short -- -D warnings > "$RUNNER_TEMP/clippy.log" 2>&1 - rc=$? - echo "rc=$rc" >> "$GITHUB_OUTPUT" - echo "::notice title=clippy exit code::$rc | errors=$(grep -c ': error' "$RUNNER_TEMP/clippy.log") warnings=$(grep -c ': warning' "$RUNNER_TEMP/clippy.log")" - grep -E ': (error|warning)|^error|^warning|could not compile' "$RUNNER_TEMP/clippy.log" | grep -v '^warning: unused manifest' > "$RUNNER_TEMP/clippy.short" || true - [ -s "$RUNNER_TEMP/clippy.short" ] || tail -c 20000 "$RUNNER_TEMP/clippy.log" > "$RUNNER_TEMP/clippy.short" - emit "clippy" "$RUNNER_TEMP/clippy.short" 25 - exit 0 - - - name: Gate result - env: - RC: ${{ steps.clippy.outputs.rc }} - run: 'exit "${RC:-1}"' - - test: - name: probe / test (--all-targets, no-fail-fast) - runs-on: ubuntu-latest - timeout-minutes: 25 - steps: - - name: Check out without actions/checkout - env: - REPO: ${{ github.repository }} - SHA: ${{ github.sha }} - TOKEN: ${{ github.token }} - run: | - set -euo pipefail - AUTH="AUTHORIZATION: basic $(printf 'x-access-token:%s' "${TOKEN}" | base64 -w0)" - git init -q . - git remote add origin "https://github.com/${REPO}.git" - git -c http.extraheader="${AUTH}" fetch -q --depth 1 origin "${SHA}" - git checkout -q FETCH_HEAD - - - name: Install the same toolchain the estate CI installs (stable) - run: | - set -euo pipefail - rustup toolchain install stable --profile minimal --no-self-update - rustup default stable - echo "::notice title=test toolchain::$(rustc --version) | $(cargo --version)" - - - name: cargo test --locked --all-targets --no-fail-fast - id: test - run: | - set +e - emit() { - local title="$1" file="$2" max="${3:-27}" dir total n f lvl msg - dir="$(mktemp -d)"; split -C 3000 -d -a 3 "$file" "$dir/c." - total=$(find "$dir" -type f | wc -l); n=0 - for f in "$dir"/c.*; do - n=$((n+1)); [ "$n" -gt "$max" ] && break - if [ "$n" -le 9 ]; then lvl=error; elif [ "$n" -le 18 ]; then lvl=warning; else lvl=notice; fi - msg="$(sed -e 's/%/%25/g' "$f" | sed -e ':a;N;$!ba;s/\r/%0D/g;s/\n/%0A/g')" - echo "::${lvl} title=${title} ${n}/${total}::${msg}" - done - if [ "$total" -gt "$max" ]; then echo "::notice title=${title} TRUNCATED::${total} chunks; only ${max} emitted"; fi - } - cargo test --locked --all-targets --no-fail-fast > "$RUNNER_TEMP/test.log" 2>&1 - rc=$? - echo "rc=$rc" >> "$GITHUB_OUTPUT" - passed=$(grep -c '^test .* \.\.\. ok$' "$RUNNER_TEMP/test.log") - failed=$(grep -c '^test .* \.\.\. FAILED$' "$RUNNER_TEMP/test.log") - echo "::notice title=test exit code::$rc | passed=${passed} failed=${failed}" - grep -E '^test result:' "$RUNNER_TEMP/test.log" | sort | uniq -c | sed 's/^ *//' > "$RUNNER_TEMP/test.results" || true - echo "::notice title=test results::$(sed -e 's/%/%25/g' "$RUNNER_TEMP/test.results" | sed -e ':a;N;$!ba;s/\n/%0A/g')" - awk ' - /^---- .* ----$/ { p = 1 } - /^failures:$/ { p = 1 } - /^test result:/ { print; p = 0; next } - /^error(\[|:)/ { print } - /^test .* FAILED$/ { print } - p { print } - ' "$RUNNER_TEMP/test.log" > "$RUNNER_TEMP/test.fail" - if [ -s "$RUNNER_TEMP/test.fail" ]; then emit "test.fail" "$RUNNER_TEMP/test.fail" 24; fi - if [ "$rc" -ne 0 ] && [ ! -s "$RUNNER_TEMP/test.fail" ]; then - tail -c 20000 "$RUNNER_TEMP/test.log" > "$RUNNER_TEMP/test.tail"; emit "test.tail" "$RUNNER_TEMP/test.tail" 9 - fi - exit 0 - - - name: Gate result - env: - RC: ${{ steps.test.outputs.rc }} - run: 'exit "${RC:-1}"' From b49fe0485815f4aaab424f413ddc1bf1d38aaf8a Mon Sep 17 00:00:00 2001 From: hyperpolymath <6759885+hyperpolymath@users.noreply.github.com> Date: Tue, 29 Sep 2026 23:59:24 +0000 Subject: [PATCH 5/5] docs(changelog): record the codeql-action lock re-sync (issue #105) Co-authored-by: arena-agent <297053741+arena-agent@users.noreply.github.com> --- CHANGELOG.adoc | 4 ++++ 1 file changed, 4 insertions(+) diff --git a/CHANGELOG.adoc b/CHANGELOG.adoc index 841207e..93bc5b4 100644 --- a/CHANGELOG.adoc +++ b/CHANGELOG.adoc @@ -46,6 +46,10 @@ https://semver.org/spec/v2.0.0.html[Semantic Versioning]. `branches/{b}/protection` `required_status_checks` populates the gate identically (contexts unioned when both mechanisms exist), and a 403 there is a hard error, never a no-gate — issue #100. +* `actions.lock` re-synced after Dependabot (#111) bumped `github/codeql-action` + to v4.38.2 in `codeql.yml`; Dependabot cannot edit the lockfile, so the lock + still pinned v4.38.0. Symptoms on `main`: Lock Sync Gate and governance + Actions lockfile verify red, CodeQL `startup_failure` — issue #105. * `actions.lock` desync: `standards-pipeline.yml`'s job-level reusable ref (`hyperpolymath/standards@ed5e3f65…`) was unlisted. Its entry and dependency record (with transitive closure) are now present — Lock Sync