Skip to content

fix(ci): make Rust Build + rust-ci able to go green; unmask clippy/fmt - #144

Merged
hyperpolymath merged 2 commits into
mainfrom
fix/ci-toolchain-fmt
Oct 2, 2026
Merged

hyperpolymath merged 2 commits into
mainfrom
fix/ci-toolchain-fmt

Conversation

@hyperpolymath

@hyperpolymath hyperpolymath commented Oct 2, 2026 •

Copy link
Copy Markdown
Owner

Why

Two Rust jobs are red on main (539e6f9). The claims ledger (ULTRAPLAN P1-0) needs a cargo test that CI actually runs, so these are fixed first.

Check on main First failing cause (from the job log)
Rust Build + Unit Tests error: invalid value 'v1' for '[TOOLCHAIN]...': invalid toolchain name: 'v1' (e2e.yml:24)
rust-ci / Cargo check + clippy + fmt cargo fmt --check diff in attestation.rs, keys_cli.rs. Behind it, a stack of clippy -D warnings errors, each target masking the next

What

  • e2e.yml:
    • toolchain: stable with the clippy and rustfmt components.
    • Removed || true from the Clippy and Format steps, which previously could not fail.
    • Clippy now runs with --all-targets, matching rust-ci.
  • cargo fmt.
  • All clippy --all-targets -D warnings lints cleared:
    • rand 0.9 thread_rng → rng.
    • Needless mut, borrows, parentheses and format!.
    • &PathBuf → &Path (20 sites).
    • Removed the dead KeyManager.root_path field and a dead store in the bench.
  • jk-keys now imports attestation/keys from the lib. It used to compile them as private modules via mod. That made the lib's public methods read as dead code, and it ran 10 unit tests twice.

Evidence (local, Rust 1.97.1)

  • cargo fmt --all --check → clean
  • cargo clippy --locked --workspace --all-targets -- -D warnings → rc 0
  • cargo test --locked --workspace → 107 passed, 0 failed
  • --list diff against main:
    • Before: 117 entries. After: 107.
    • The 10 removed entries are exactly the src/keys_cli.rs copies of attestation::tests::* (6) and keys::tests::* (4).
    • Each was checked to still run under src/lib.rs, so no test was lost.
  • cargo bench --no-run → builds.

Not in this PR

e2e.yml:98 runs python3 (banned estate-wide), behind || true. It is recorded in dev-notes/inbox/findings.md, not changed here.

Second push (e6fee67)

  • e2e.yml: the Criterion, E2E Lifecycle and Panic Attack jobs called dtolnay/rust-toolchain@v1 with no toolchain input. That step failed with "'toolchain' is a required input", so these jobs now pass toolchain: stable.
  • tests/aspect/cross_cutting_test.sh:
    • The repo moved SECURITY, ARCHITECTURE, PROOF-NEEDS and TOPOLOGY to .adoc, but the checks still looked for .md, so 4 of 29 failed.
    • Each check now accepts either extension, as the README check already did. Result: 29/29.
    • Negative control: with TOPOLOGY.adoc removed, the check fails (28/29).
  • attestation.rs: the HMAC key error is now propagated with map_err(std::io::Error::other)? instead of expect(). Hypatia flagged it as expect_in_hot_path, and the function already returns io::Result.

Partly addresses #135 (acceptance items 1 and 2 and Run aspect tests) and #133 (clippy/fmt || true). Neither issue is closed.

Red checks on e6fee67: deferred, not introduced here

Every red below also fails on main 539e6f9. The only required context is scan / gitleaks, which is green.

🤖 Generated with Claude Code

https://claude.ai/code/session_01VxcAoyMQe7CjQwCKL18Mm4

…y/fmt

- e2e.yml: `toolchain: v1` is not a toolchain name (rustup: "invalid
  toolchain name: 'v1'"), so "Rust Build + Unit Tests" died before
  building. Use `stable` with clippy + rustfmt components.
- e2e.yml: drop `|| true` from the Clippy and Format steps; they could
  never fail.
- cargo fmt over attestation.rs / keys_cli.rs (rust-ci's first red step).
- Clear every `clippy --all-targets -D warnings` lint (each target's
  errors masked the next): rand 0.9 thread_rng -> rng, needless mut /
  borrow / parens, &PathBuf -> &Path, dead `root_path` field, dead store
  in the transactions bench.
- jk-keys imported `attestation` and `keys` via `mod`, compiling a second
  private copy of each: the lib's public API read as dead code there and
  10 unit tests ran twice. Import them from the lib crate instead. Unique
  test count is unchanged (107; was 117 listed with the 10 duplicates).

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01VxcAoyMQe7CjQwCKL18Mm4
@coderabbitai

coderabbitai Bot commented Oct 2, 2026 •

Copy link
Copy Markdown
Contributor

Review in Change Stack →

Navigate logical layers of code changes, visualize relationships, and explore their blast radius.

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration

Configuration used: Organization UI

Review profile: ASSERTIVE

Plan: Advanced

Run ID: 289ea8f6-1aee-4f81-80dc-3f6e95f0c610

📥 Commits

Reviewing files that changed from the base of the PR and between 539e6f9 and e6fee67.

📒 Files selected for processing (17)
  • .github/workflows/e2e.yml
  • benches/januskey_benchmarks.rs
  • crates/januskey-cli/src/attestation.rs
  • crates/januskey-cli/src/keys.rs
  • crates/januskey-cli/src/keys_cli.rs
  • crates/januskey-cli/src/lib.rs
  • crates/januskey-cli/src/main.rs
  • crates/januskey-cli/src/obliteration.rs
  • crates/januskey-cli/src/operations.rs
  • crates/januskey-cli/tests/aspect_test.rs
  • crates/januskey-cli/tests/concurrency_test.rs
  • crates/januskey-cli/tests/e2e_test.rs
  • crates/januskey-cli/tests/p2p_test.rs
  • crates/reversible-core/src/manifest.rs
  • crates/reversible-core/src/metadata.rs
  • crates/reversible-core/src/transaction.rs
  • tests/aspect/cross_cutting_test.sh

Included review availability: This review used your included allowance. Your plan provides up to 1 included review per hour; 0 remain after this review.

📜 Recent review details
⏰ Context from checks skipped due to timeout. (1)
  • GitHub Check: semgrep-cloud-platform/scan
⚠️ CI failures not shown inline (23)

GitHub Actions: Central Estate CI/CD Audit / 0_estate-audit.txt: fix(ci): make Rust Build + rust-ci able to go green; unmask clippy/fmt

Conclusion: failure

View job details

##[group]Run # Accepted placements widened per owner ruling 2026-09-19: estate
 �[36;1m# Accepted placements widened per owner ruling 2026-09-19: estate�[0m
 �[36;1m# repos legitimately keep governance docs under docs/ (and GitHub�[0m
 �[36;1m# renders under .github/) — rsr-template-repo itself was failing on�[0m
 �[36;1m# layout, not on substance. Root forms still win (first hit).�[0m
 �[36;1m# Template-repo mode: see below.�[0m
 �[36;1m#�[0m
 �[36;1m# Presence-only checking rewards filler. This gate previously demanded�[0m
 �[36;1m# ARCHITECTURE.md / MAINTAINERS.adoc / GOVERNANCE.md and checked only�[0m
 �[36;1m# that the paths existed — so the cheapest way to pass was to commit�[0m
 �[36;1m# template boilerplate. That happened: an estate repo acquired an�[0m
 �[36;1m# ARCHITECTURE.md describing a directory layout it does not have, a�[0m
 �[36;1m# MAINTAINERS naming a different account as owner, and a mise.toml�[0m
 �[36;1m# pinning `zig = "latest"` against that repo's own .tool-versions.�[0m
 �[36;1m# All three would have passed. So: presence, THEN format, THEN substance.�[0m
 �[36;1m#�[0m
 �[36;1m# Format policy (estate):�[0m
 �[36;1m#   .adoc  documentation (default)�[0m
 �[36;1m#   .md    wiki content only — plus a transitional allowance for the�[0m
 �[36;1m#          GitHub-mandated files, which are migrating to berrywiki format�[0m
 �[36;1m#   .txt   licence texts�[0m
 �[36;1m#   fixed  names GitHub or convention dictates (CODEOWNERS, funding.yml,�[0m
 �[36;1m#          NOTICE, AUTHORS, MAINTAINERS) keep their form�[0m
 �[36;1mset -uo pipefail�[0m
 �[36;1mfail=0�[0m
 �[36;1m�[0m
 �[36;1m# --- template-repo mode -------------------------------------------�[0m
 �[36;1m# An un-instantiated template legitimately SHIPS {{OWNER}}/{{AUTHOR}}�[0m
 �[36;1m# placeholders and self-references its own template name; judging it�[0m
 �[36;1m# like an instantiated repo is a category error. Detection is explicit�[0m
 �[36;1m# and auditable: the repo name says it is a temp...

GitHub Actions: Central Estate CI/CD Audit / estate-audit: fix(ci): make Rust Build + rust-ci able to go green; unmask clippy/fmt

Conclusion: failure

View job details

##[group]Run # Accepted placements widened per owner ruling 2026-09-19: estate
 �[36;1m# Accepted placements widened per owner ruling 2026-09-19: estate�[0m
 �[36;1m# repos legitimately keep governance docs under docs/ (and GitHub�[0m
 �[36;1m# renders under .github/) — rsr-template-repo itself was failing on�[0m
 �[36;1m# layout, not on substance. Root forms still win (first hit).�[0m
 �[36;1m# Template-repo mode: see below.�[0m
 �[36;1m#�[0m
 �[36;1m# Presence-only checking rewards filler. This gate previously demanded�[0m
 �[36;1m# ARCHITECTURE.md / MAINTAINERS.adoc / GOVERNANCE.md and checked only�[0m
 �[36;1m# that the paths existed — so the cheapest way to pass was to commit�[0m
 �[36;1m# template boilerplate. That happened: an estate repo acquired an�[0m
 �[36;1m# ARCHITECTURE.md describing a directory layout it does not have, a�[0m
 �[36;1m# MAINTAINERS naming a different account as owner, and a mise.toml�[0m
 �[36;1m# pinning `zig = "latest"` against that repo's own .tool-versions.�[0m
 �[36;1m# All three would have passed. So: presence, THEN format, THEN substance.�[0m
 �[36;1m#�[0m
 �[36;1m# Format policy (estate):�[0m
 �[36;1m#   .adoc  documentation (default)�[0m
 �[36;1m#   .md    wiki content only — plus a transitional allowance for the�[0m
 �[36;1m#          GitHub-mandated files, which are migrating to berrywiki format�[0m
 �[36;1m#   .txt   licence texts�[0m
 �[36;1m#   fixed  names GitHub or convention dictates (CODEOWNERS, funding.yml,�[0m
 �[36;1m#          NOTICE, AUTHORS, MAINTAINERS) keep their form�[0m
 �[36;1mset -uo pipefail�[0m
 �[36;1mfail=0�[0m
 �[36;1m�[0m
 �[36;1m# --- template-repo mode -------------------------------------------�[0m
 �[36;1m# An un-instantiated template legitimately SHIPS {{OWNER}}/{{AUTHOR}}�[0m
 �[36;1m# placeholders and self-references its own template name; judging it�[0m
 �[36;1m# like an instantiated repo is a category error. Detection is explicit�[0m
 �[36;1m# and auditable: the repo name says it is a temp...

GitHub Actions: Central Estate CI/CD Audit / estate-audit: fix(ci): make Rust Build + rust-ci able to go green; unmask clippy/fmt

Conclusion: failure

View job details

##[group]Run bash "$GITHUB_ACTION_PATH/check.sh"
 �[36;1mbash "$GITHUB_ACTION_PATH/check.sh"�[0m
 shell: /usr/bin/bash --noprofile --norc -e -o pipefail {0}
 ##[endgroup]
 Scanning implementation source for untracked debt markers...
 ##[error]Untracked debt markers found in implementation source:

GitHub Actions: Idris ABI typecheck / 0_idris-abi (expected red until J1-3).txt: fix(ci): make Rust Build + rust-ci able to go green; unmask clippy/fmt

Conclusion: failure

View job details

##[group]Run idris2 --version
 �[36;1midris2 --version�[0m
 �[36;1midris2 --typecheck src/idris-abi/januskey-abi.ipkg�[0m
 shell: sh -e {0}
 ##[endgroup]
 Idris 2, version 0.8.0-6ca00e72e
 1/4: Building JanusKey.ABI.Types (JanusKey/ABI/Types.idr)
 Error: While processing constructor MkValidPath. Undefined name isInfixOf.
 JanusKey.ABI.Types:63:24--63:33
  59 | record ValidPath where
  60 |   constructor MkValidPath
  61 |   pathStr   : String
  62 |   nonEmpty  : So (length pathStr > 0)
  63 |   noNulls   : So (not (isInfixOf "\0" pathStr))
                              ^^^^^^^^^
 Did you mean any of: isPrefixOf, or isSuffixOf?
 Error: While processing right hand side of ResultOf. Undefined name ObliterationProof.
 JanusKey.ABI.Types:171:23--171:40
  167 | ResultOf Copy       = (ContentHash, FileMetadata)
  168 | ResultOf Move       = (ContentHash, FileMetadata)
  169 | ResultOf Delete     = ContentHash
  170 | ResultOf Modify     = (ContentHash, ContentHash)  -- old hash, new hash
  171 | ResultOf Obliterate = ObliterationProof
                              ^^^^^^^^^^^^^^^^^
 Error: While processing right hand side of acquire. When unifying:
     Handle Available a
 and:
     Handle Locked a
 Mismatch between: Available and Locked.
 JanusKey.ABI.Types:212:31--212:47
  208 |
  209 | ||| Acquire exclusive access — transitions Available -> Locked
  210 | public export
  211 | acquire : Handle Available a -> (Handle Locked a, a)
  212 | acquire (MkHandle tag val) = (MkHandle tag val, val)
                                      ^^^^^^^^^^^^^^^^
 Error: While processing left hand side of release. When unifying:
     Handle Available ?_
 and:
     Handle Locked ?_
 Mismatch between: Available and Locked.
 JanusKey.ABI.Types:217:10--217:24
  213 |
  214 | ||| Release exclusive access — transitions Locked -> Available
  215 | public export
  216 | release : Handle Locked a -> a -> Handle Available a
  217 | release (MkHandle tag _) newVal = MkHandle tag newVal
           ...

GitHub Actions: Idris ABI typecheck / idris-abi (expected red until J1-3): fix(ci): make Rust Build + rust-ci able to go green; unmask clippy/fmt

Conclusion: failure

View job details

##[group]Run idris2 --version
 �[36;1midris2 --version�[0m
 �[36;1midris2 --typecheck src/idris-abi/januskey-abi.ipkg�[0m
 shell: sh -e {0}
 ##[endgroup]
 Idris 2, version 0.8.0-6ca00e72e
 1/4: Building JanusKey.ABI.Types (JanusKey/ABI/Types.idr)
 Error: While processing constructor MkValidPath. Undefined name isInfixOf.
 JanusKey.ABI.Types:63:24--63:33
  59 | record ValidPath where
  60 |   constructor MkValidPath
  61 |   pathStr   : String
  62 |   nonEmpty  : So (length pathStr > 0)
  63 |   noNulls   : So (not (isInfixOf "\0" pathStr))
                              ^^^^^^^^^
 Did you mean any of: isPrefixOf, or isSuffixOf?
 Error: While processing right hand side of ResultOf. Undefined name ObliterationProof.
 JanusKey.ABI.Types:171:23--171:40
  167 | ResultOf Copy       = (ContentHash, FileMetadata)
  168 | ResultOf Move       = (ContentHash, FileMetadata)
  169 | ResultOf Delete     = ContentHash
  170 | ResultOf Modify     = (ContentHash, ContentHash)  -- old hash, new hash
  171 | ResultOf Obliterate = ObliterationProof
                              ^^^^^^^^^^^^^^^^^
 Error: While processing right hand side of acquire. When unifying:
     Handle Available a
 and:
     Handle Locked a
 Mismatch between: Available and Locked.
 JanusKey.ABI.Types:212:31--212:47
  208 |
  209 | ||| Acquire exclusive access — transitions Available -> Locked
  210 | public export
  211 | acquire : Handle Available a -> (Handle Locked a, a)
  212 | acquire (MkHandle tag val) = (MkHandle tag val, val)
                                      ^^^^^^^^^^^^^^^^
 Error: While processing left hand side of release. When unifying:
     Handle Available ?_
 and:
     Handle Locked ?_
 Mismatch between: Available and Locked.
 JanusKey.ABI.Types:217:10--217:24
  213 |
  214 | ||| Release exclusive access — transitions Locked -> Available
  215 | public export
  216 | release : Handle Locked a -> a -> Handle Available a
  217 | release (MkHandle tag _) newVal = MkHandle tag newVal
           ...

GitHub Actions: Workflow Security Linter / 0_lint-workflows.txt: fix(ci): make Rust Build + rust-ci able to go green; unmask clippy/fmt

Conclusion: failure

View job details

##[group]Run errors=0
 �[36;1merrors=0�[0m
 �[36;1mfor f in .github/workflows/*.yml .github/workflows/*.yaml; do�[0m
 �[36;1m  [ -f "$f" ] || continue�[0m
 �[36;1m  if ! head -1 "$f" | grep -q "SPDX-License-Identifier"; then�[0m
 �[36;1m    echo "ERROR: $f missing SPDX header"�[0m
 �[36;1m    errors=$((errors + 1))�[0m
 �[36;1m  fi�[0m
 �[36;1mdone�[0m
 �[36;1mexit $errors�[0m
 shell: /usr/bin/bash -e {0}
 ##[endgroup]
 ERROR: .github/workflows/boj-build.yml missing SPDX header
 ERROR: .github/workflows/cargo-audit.yml missing SPDX header
 ERROR: .github/workflows/casket-pages.yml missing SPDX header
 ERROR: .github/workflows/codeql.yml missing SPDX header
 ERROR: .github/workflows/dashboard-check.yml missing SPDX header
 ERROR: .github/workflows/dependabot-automerge.yml missing SPDX header
 ERROR: .github/workflows/dogfood-gate.yml missing SPDX header
 ERROR: .github/workflows/e2e.yml missing SPDX header
 ERROR: .github/workflows/governance.yml missing SPDX header
 ERROR: .github/workflows/hypatia-scan.yml missing SPDX header
 ERROR: .github/workflows/instant-sync.yml missing SPDX header
 ERROR: .github/workflows/label-triage.yml missing SPDX header
 ERROR: .github/workflows/labels.yml missing SPDX header
 ERROR: .github/workflows/main-estate-audit.yml missing SPDX header
 ERROR: .github/workflows/mirror.yml missing SPDX header
 ERROR: .github/workflows/pages.yml missing SPDX header
 ERROR: .github/workflows/push-email-notify.yml missing SPDX header
 ERROR: .github/workflows/rust-ci.yml missing SPDX header
 ERROR: .github/workflows/scorecard.yml missing SPDX header
 ERROR: .github/workflows/secret-scanner.yml missing SPDX header
 ERROR: .github/workflows/semgrep.yml missing SPDX header
 ERROR: .github/workflows/workflow-linter.yml missing SPDX header
 ##[error]Process completed with exit code 22.

GitHub Actions: Workflow Security Linter / lint-workflows: fix(ci): make Rust Build + rust-ci able to go green; unmask clippy/fmt

Conclusion: failure

View job details

##[group]Run errors=0
 �[36;1merrors=0�[0m
 �[36;1mfor f in .github/workflows/*.yml .github/workflows/*.yaml; do�[0m
 �[36;1m  [ -f "$f" ] || continue�[0m
 �[36;1m  if ! head -1 "$f" | grep -q "SPDX-License-Identifier"; then�[0m
 �[36;1m    echo "ERROR: $f missing SPDX header"�[0m
 �[36;1m    errors=$((errors + 1))�[0m
 �[36;1m  fi�[0m
 �[36;1mdone�[0m
 �[36;1mexit $errors�[0m
 shell: /usr/bin/bash -e {0}
 ##[endgroup]
 ERROR: .github/workflows/boj-build.yml missing SPDX header
 ERROR: .github/workflows/cargo-audit.yml missing SPDX header
 ERROR: .github/workflows/casket-pages.yml missing SPDX header
 ERROR: .github/workflows/codeql.yml missing SPDX header
 ERROR: .github/workflows/dashboard-check.yml missing SPDX header
 ERROR: .github/workflows/dependabot-automerge.yml missing SPDX header
 ERROR: .github/workflows/dogfood-gate.yml missing SPDX header
 ERROR: .github/workflows/e2e.yml missing SPDX header
 ERROR: .github/workflows/governance.yml missing SPDX header
 ERROR: .github/workflows/hypatia-scan.yml missing SPDX header
 ERROR: .github/workflows/instant-sync.yml missing SPDX header
 ERROR: .github/workflows/label-triage.yml missing SPDX header
 ERROR: .github/workflows/labels.yml missing SPDX header
 ERROR: .github/workflows/main-estate-audit.yml missing SPDX header
 ERROR: .github/workflows/mirror.yml missing SPDX header
 ERROR: .github/workflows/pages.yml missing SPDX header
 ERROR: .github/workflows/push-email-notify.yml missing SPDX header
 ERROR: .github/workflows/rust-ci.yml missing SPDX header
 ERROR: .github/workflows/scorecard.yml missing SPDX header
 ERROR: .github/workflows/secret-scanner.yml missing SPDX header
 ERROR: .github/workflows/semgrep.yml missing SPDX header
 ERROR: .github/workflows/workflow-linter.yml missing SPDX header
 ##[error]Process completed with exit code 22.

GitHub Actions: Dogfood Gate / 2_Validate DEED manifests.txt: fix(ci): make Rust Build + rust-ci able to go green; unmask clippy/fmt

Conclusion: failure

View job details

##[group]A2ML Manifest Validation
 Scanning . for .a2ml and .deed files...
 Found 29 .a2ml/.deed file(s)
   Validating: ./.machine_readable/6a2/0-AI-MANIFEST.a2ml
 ##[warning]Missing SPDX-License-Identifier in first 10 lines
   Validating: ./.machine_readable/6a2/AGENTIC.a2ml
   Validating: ./.machine_readable/6a2/ECOSYSTEM.a2ml
   Validating: ./.machine_readable/6a2/META.a2ml
   Validating: ./.machine_readable/6a2/NEUROSYM.a2ml
   Validating: ./.machine_readable/6a2/PLAYBOOK.a2ml
   Validating: ./.machine_readable/6a2/STATE.a2ml
   Validating: ./.machine_readable/6a2/anchor/0-AI-MANIFEST.a2ml
 ##[warning]Missing SPDX-License-Identifier in first 10 lines
   Validating: ./.machine_readable/6a2/anchor/ANCHOR.a2ml
 ##[warning]Missing SPDX-License-Identifier in first 10 lines
   Validating: ./.machine_readable/CLADE.a2ml
   Validating: ./.machine_readable/bot_directives/coverage.a2ml
   Validating: ./.machine_readable/bot_directives/debt.a2ml
   Validating: ./.machine_readable/bot_directives/git-private-farm.a2ml
   Validating: ./.machine_readable/bot_directives/gitbot-fleet.a2ml
   Validating: ./.machine_readable/bot_directives/hypatia.a2ml
   Validating: ./.machine_readable/bot_directives/methodology.a2ml
   Validating: ./.machine_readable/contractiles/Adjustfile.a2ml
   Validating: ./.machine_readable/contractiles/Bustfile.a2ml
   Validating: ./.machine_readable/contractiles/Dustfile.a2ml
   Validating: ./.machine_readable/contractiles/Intentfile.a2ml
   Validating: ./.machine_readable/contractiles/Mustfile.a2ml
   Validating: ./.machine_readable/contractiles/Trustfile.a2ml
   Validating: ./.machine_readable/integrations/feedback-o-tron.a2ml
   Validating: ./.machine_readable/integrations/proven.a2ml
   Validating: ./.machine_readable/integrations/verisimdb.a2ml
   Validating: ./.machine_readable/integrations/vexometer.a2ml
   Validating: ./.machine_readable/threat-model.a2ml
   Validating: ./0-AI-MANIFEST.a2ml
 ##[warning]Missing SPDX-License-Identifier in first ...

GitHub Actions: Dogfood Gate / Validate DEED manifests: fix(ci): make Rust Build + rust-ci able to go green; unmask clippy/fmt

Conclusion: failure

View job details

##[group]A2ML Manifest Validation
 Scanning . for .a2ml and .deed files...
 Found 29 .a2ml/.deed file(s)
   Validating: ./.machine_readable/6a2/0-AI-MANIFEST.a2ml
 ##[warning]Missing SPDX-License-Identifier in first 10 lines
   Validating: ./.machine_readable/6a2/AGENTIC.a2ml
   Validating: ./.machine_readable/6a2/ECOSYSTEM.a2ml
   Validating: ./.machine_readable/6a2/META.a2ml
   Validating: ./.machine_readable/6a2/NEUROSYM.a2ml
   Validating: ./.machine_readable/6a2/PLAYBOOK.a2ml
   Validating: ./.machine_readable/6a2/STATE.a2ml
   Validating: ./.machine_readable/6a2/anchor/0-AI-MANIFEST.a2ml
 ##[warning]Missing SPDX-License-Identifier in first 10 lines
   Validating: ./.machine_readable/6a2/anchor/ANCHOR.a2ml
 ##[warning]Missing SPDX-License-Identifier in first 10 lines
   Validating: ./.machine_readable/CLADE.a2ml
   Validating: ./.machine_readable/bot_directives/coverage.a2ml
   Validating: ./.machine_readable/bot_directives/debt.a2ml
   Validating: ./.machine_readable/bot_directives/git-private-farm.a2ml
   Validating: ./.machine_readable/bot_directives/gitbot-fleet.a2ml
   Validating: ./.machine_readable/bot_directives/hypatia.a2ml
   Validating: ./.machine_readable/bot_directives/methodology.a2ml
   Validating: ./.machine_readable/contractiles/Adjustfile.a2ml
   Validating: ./.machine_readable/contractiles/Bustfile.a2ml
   Validating: ./.machine_readable/contractiles/Dustfile.a2ml
   Validating: ./.machine_readable/contractiles/Intentfile.a2ml
   Validating: ./.machine_readable/contractiles/Mustfile.a2ml
   Validating: ./.machine_readable/contractiles/Trustfile.a2ml
   Validating: ./.machine_readable/integrations/feedback-o-tron.a2ml
   Validating: ./.machine_readable/integrations/proven.a2ml
   Validating: ./.machine_readable/integrations/verisimdb.a2ml
   Validating: ./.machine_readable/integrations/vexometer.a2ml
   Validating: ./.machine_readable/threat-model.a2ml
   Validating: ./0-AI-MANIFEST.a2ml
 ##[warning]Missing SPDX-License-Identifier in first ...

GitHub Actions: Dogfood Gate / 3_Groove manifest check.txt: fix(ci): make Rust Build + rust-ci able to go green; unmask clippy/fmt

Conclusion: failure

View job details

##[group]Run # Check for static or dynamic Groove endpoints
 �[36;1m# Check for static or dynamic Groove endpoints�[0m
 �[36;1mHAS_MANIFEST="false"�[0m
 �[36;1mHAS_GROOVE_CODE="false"�[0m
 �[36;1m�[0m
 �[36;1mif [ -f ".well-known/groove/manifest.json" ]; then�[0m
 �[36;1m  HAS_MANIFEST="true"�[0m
 �[36;1m  # Validate the manifest JSON�[0m
 �[36;1m  if ! jq empty .well-known/groove/manifest.json 2>/dev/null; then�[0m
 �[36;1m    echo "::error file=.well-known/groove/manifest.json::Invalid JSON in Groove manifest"�[0m

GitHub Actions: Dogfood Gate / Groove manifest check: fix(ci): make Rust Build + rust-ci able to go green; unmask clippy/fmt

Conclusion: failure

View job details

##[group]Run # Check for static or dynamic Groove endpoints
 �[36;1m# Check for static or dynamic Groove endpoints�[0m
 �[36;1mHAS_MANIFEST="false"�[0m
 �[36;1mHAS_GROOVE_CODE="false"�[0m
 �[36;1m�[0m
 �[36;1mif [ -f ".well-known/groove/manifest.json" ]; then�[0m
 �[36;1m  HAS_MANIFEST="true"�[0m
 �[36;1m  # Validate the manifest JSON�[0m
 �[36;1m  if ! jq empty .well-known/groove/manifest.json 2>/dev/null; then�[0m
 �[36;1m    echo "::error file=.well-known/groove/manifest.json::Invalid JSON in Groove manifest"�[0m

GitHub Actions: Governance / 2_governance _ Well-Known (RFC 9116 + RSR).txt: fix(ci): make Rust Build + rust-ci able to go green; unmask clippy/fmt

Conclusion: failure

View job details

##[group]Run SECTXT=""
 �[36;1mSECTXT=""�[0m
 �[36;1m[ -f ".well-known/security.txt" ] && SECTXT=".well-known/security.txt"�[0m
 �[36;1m[ -f "security.txt" ] && SECTXT="security.txt"�[0m
 �[36;1mif [ -z "$SECTXT" ]; then�[0m
 �[36;1m  echo "::warning::No security.txt found."�[0m
 �[36;1m  exit 0�[0m
 �[36;1mfi�[0m
 �[36;1mgrep -q "^Contact:" "$SECTXT" || { echo "::error::Missing Contact field"; exit 1; }�[0m

GitHub Actions: Governance / governance _ Well-Known (RFC 9116 + RSR): fix(ci): make Rust Build + rust-ci able to go green; unmask clippy/fmt

Conclusion: failure

View job details

##[group]Run SECTXT=""
 �[36;1mSECTXT=""�[0m
 �[36;1m[ -f ".well-known/security.txt" ] && SECTXT=".well-known/security.txt"�[0m
 �[36;1m[ -f "security.txt" ] && SECTXT="security.txt"�[0m
 �[36;1mif [ -z "$SECTXT" ]; then�[0m
 �[36;1m  echo "::warning::No security.txt found."�[0m
 �[36;1m  exit 0�[0m
 �[36;1mfi�[0m
 �[36;1mgrep -q "^Contact:" "$SECTXT" || { echo "::error::Missing Contact field"; exit 1; }�[0m

GitHub Actions: Governance / governance _ Well-Known (RFC 9116 + RSR): fix(ci): make Rust Build + rust-ci able to go green; unmask clippy/fmt

Conclusion: failure

View job details

##[group]Run MIXED=$(grep -rE 'src="http://|href="http://' --include="*.html" --include="*.htm" . 2>/dev/null | grep -vE 'localhost|127\.0\.0\.1|example\.com|lol/|node_modules/|third-party/|vendor/' | head -5 || true)
 �[36;1mMIXED=$(grep -rE 'src="http://|href="http://' --include="*.html" --include="*.htm" . 2>/dev/null | grep -vE 'localhost|127\.0\.0\.1|example\.com|lol/|node_modules/|third-party/|vendor/' | head -5 || true)�[0m
 �[36;1mif [ -n "$MIXED" ]; then�[0m
 �[36;1m  echo "::error::Mixed content (HTTP in HTML)"�[0m

GitHub Actions: Governance / 6_governance _ Workflow security linter.txt: fix(ci): make Rust Build + rust-ci able to go green; unmask clippy/fmt

Conclusion: failure

View job details

##[group]Run # GitHub Actions REJECTS a workflow with duplicate keys: the run is
 �[36;1m# GitHub Actions REJECTS a workflow with duplicate keys: the run is�[0m
 �[36;1m# `failure` with no jobs, no log and no check run. Nothing else here�[0m
 �[36;1m# can see it, because yaml.safe_load silently keeps the LAST�[0m
 �[36;1m# duplicate and reports success — so the file "parses" and every�[0m
 �[36;1m# other lint passes. Measured 2026-08-05: nine workflows in hypatia�[0m
 �[36;1m# were dead this way, including a CodeQL workflow with zero�[0m
 �[36;1m# successful runs in its entire lifetime.�[0m
 �[36;1mset -euo pipefail�[0m
 �[36;1mSCRIPT=".standards-dupkey/scripts/check-workflow-duplicate-keys.sh"�[0m
 �[36;1m# Self-hosting fallback: when THIS repository is standards, its own�[0m
 �[36;1m# working tree already holds the script, and during a rename that copy�[0m
 �[36;1m# is the only correct one — the pinned main checkout still has the old�[0m
 �[36;1m# name. Preferring the fetched copy keeps every other caller on the�[0m
 �[36;1m# canonical version.�[0m
 �[36;1mif [ ! -f "$SCRIPT" ] && [ -f scripts/check-workflow-duplicate-keys.sh ]; then�[0m
 �[36;1m  SCRIPT="scripts/check-workflow-duplicate-keys.sh"�[0m
 �[36;1m  echo "Using this repository's own copy (standards self-lint)."�[0m
 �[36;1mfi�[0m
 �[36;1mif [ ! -f "$SCRIPT" ]; then�[0m
 �[36;1m  echo "::error::duplicate-key checker not found — neither fetched from" \�[0m

GitHub Actions: Governance / governance _ Workflow security linter: fix(ci): make Rust Build + rust-ci able to go green; unmask clippy/fmt

Conclusion: failure

View job details

##[group]Run # GitHub Actions REJECTS a workflow with duplicate keys: the run is
 �[36;1m# GitHub Actions REJECTS a workflow with duplicate keys: the run is�[0m
 �[36;1m# `failure` with no jobs, no log and no check run. Nothing else here�[0m
 �[36;1m# can see it, because yaml.safe_load silently keeps the LAST�[0m
 �[36;1m# duplicate and reports success — so the file "parses" and every�[0m
 �[36;1m# other lint passes. Measured 2026-08-05: nine workflows in hypatia�[0m
 �[36;1m# were dead this way, including a CodeQL workflow with zero�[0m
 �[36;1m# successful runs in its entire lifetime.�[0m
 �[36;1mset -euo pipefail�[0m
 �[36;1mSCRIPT=".standards-dupkey/scripts/check-workflow-duplicate-keys.sh"�[0m
 �[36;1m# Self-hosting fallback: when THIS repository is standards, its own�[0m
 �[36;1m# working tree already holds the script, and during a rename that copy�[0m
 �[36;1m# is the only correct one — the pinned main checkout still has the old�[0m
 �[36;1m# name. Preferring the fetched copy keeps every other caller on the�[0m
 �[36;1m# canonical version.�[0m
 �[36;1mif [ ! -f "$SCRIPT" ] && [ -f scripts/check-workflow-duplicate-keys.sh ]; then�[0m
 �[36;1m  SCRIPT="scripts/check-workflow-duplicate-keys.sh"�[0m
 �[36;1m  echo "Using this repository's own copy (standards self-lint)."�[0m
 �[36;1mfi�[0m
 �[36;1mif [ ! -f "$SCRIPT" ]; then�[0m
 �[36;1m  echo "::error::duplicate-key checker not found — neither fetched from" \�[0m

GitHub Actions: Governance / governance _ Workflow security linter: fix(ci): make Rust Build + rust-ci able to go green; unmask clippy/fmt

Conclusion: failure

View job details

##[group]Run failed=0
 �[36;1mfailed=0�[0m
 �[36;1mfor file in .github/workflows/*.yml .github/workflows/*.yaml; do�[0m
 �[36;1m  [ -f "$file" ] || continue�[0m
 �[36;1m  # ⚠ SCAN THE HEADER BLOCK, NOT LINE 1. REUSE places the identifier�[0m
 �[36;1m  # anywhere in a file's leading comment block, and `gh actions-lock`�[0m
 �[36;1m  # INSERTS `# This workflow is managed by gh actions-lock.` at line 1�[0m
 �[36;1m  # whenever it mints a lockfile — so a line-1 test fights the estate's�[0m
 �[36;1m  # own tool and re-fails every time a lockfile is refreshed.�[0m
 �[36;1m  #�[0m
 �[36;1m  # Measured 2026-08-07: it reported 27 hypatia workflows and 13 more�[0m
 �[36;1m  # elsewhere as missing a header they all had, and "fixing" that by�[0m
 �[36;1m  # prepending a default MIS-LICENSED three files (PMPL-1.0-or-later�[0m
 �[36;1m  # shadowed by MPL-2.0) before it was caught.�[0m
 �[36;1m  #�[0m
 �[36;1m  # The leading run of comment lines is read, tolerating a YAML�[0m
 �[36;1m  # document marker. A licence declared there is declared.�[0m
 �[36;1m  if ! awk '/^---[[:space:]]*$/ { next } /^#/ { print; next } { exit }' "$file" \�[0m
 �[36;1m       | grep -q "^# SPDX-License-Identifier:"; then�[0m
 �[36;1m    echo "ERROR: $file has no SPDX-License-Identifier in its header comment block"; failed=1�[0m
 �[36;1m  fi�[0m
 �[36;1m  if ! grep -q "^permissions:" "$file"; then�[0m
 �[36;1m    echo "ERROR: $file missing top-level 'permissions:' declaration"; failed=1�[0m
 �[36;1m  fi�[0m
 �[36;1mdone�[0m
 �[36;1m[ $failed -eq 1 ] && { echo "Add SPDX header + permissions:"; exit 1; }�[0m
 �[36;1mecho "All workflows have SPDX headers + permissions"�[0m
 shell: /usr/bin/bash -e {0}
 ##[endgroup]
 ERROR: .github/workflows/main-estate-audit.yml has no SPDX-License-Identifier in its header comment block
 ERROR: .github/workflows/main-estate-audit.yml missing top-level 'permissions:' declaration
 Add SPDX header + permissions:
 ##[error]Process completed with exit code 1.

GitHub Actions: Governance / 9_governance _ Allowlist Preflight.txt: fix(ci): make Rust Build + rust-ci able to go green; unmask clippy/fmt

Conclusion: failure

View job details

##[group]Run rm -rf .standards-checkout
 �[36;1mrm -rf .standards-checkout�[0m
 �[36;1mbash "$RUNNER_TEMP/check-actions-policy.sh" \�[0m
 �[36;1m  "$GITHUB_REPOSITORY" "$RUNNER_TEMP/allowed-actions.json"�[0m
 shell: /usr/bin/bash -e {0}
 env:
   GH_***REDACTED_SECRET_ASSIGNMENT***
 gh: To use GitHub CLI in a GitHub Actions workflow, set the GH_TOKEN environment variable. Example:
   env:
     GH_***REDACTED_SECRET_ASSIGNMENT*** github.token }}
 ERROR: could not read live Actions permissions for hyperpolymath/januskey
 ##[error]Process completed with exit code 3.

GitHub Actions: Governance / governance _ Allowlist Preflight: fix(ci): make Rust Build + rust-ci able to go green; unmask clippy/fmt

Conclusion: failure

View job details

##[group]Run rm -rf .standards-checkout
 �[36;1mrm -rf .standards-checkout�[0m
 �[36;1mbash "$RUNNER_TEMP/check-actions-policy.sh" \�[0m
 �[36;1m  "$GITHUB_REPOSITORY" "$RUNNER_TEMP/allowed-actions.json"�[0m
 shell: /usr/bin/bash -e {0}
 env:
   GH_***REDACTED_SECRET_ASSIGNMENT***
 gh: To use GitHub CLI in a GitHub Actions workflow, set the GH_TOKEN environment variable. Example:
   env:
     GH_***REDACTED_SECRET_ASSIGNMENT*** github.token }}
 ERROR: could not read live Actions permissions for hyperpolymath/januskey
 ##[error]Process completed with exit code 3.

GitHub Actions: Governance / 11_governance _ Code quality + docs.txt: fix(ci): make Rust Build + rust-ci able to go green; unmask clippy/fmt

Conclusion: failure

View job details

##[group]Run editorconfig-checker/action-editorconfig-checker@840e866d93b8e032123c23bac69dece044d4d84c
 with:
   github-***REDACTED_SECRET_ASSIGNMENT***
   version: latest
 ##[endgroup]
 Find 'latest' release
 ##[error]Error: The binary 'ec-linux-amd64*' not found

GitHub Actions: Governance / governance _ Code quality + docs: fix(ci): make Rust Build + rust-ci able to go green; unmask clippy/fmt

Conclusion: failure

View job details

##[group]Run editorconfig-checker/action-editorconfig-checker@840e866d93b8e032123c23bac69dece044d4d84c
 with:
   github-***REDACTED_SECRET_ASSIGNMENT***
   version: latest
 ##[endgroup]
 Find 'latest' release
 ##[error]Error: The binary 'ec-linux-amd64*' not found

GitHub Actions: Governance / 12_governance _ Security policy checks.txt: fix(ci): make Rust Build + rust-ci able to go green; unmask clippy/fmt

Conclusion: failure

View job details

##[group]Run set -uo pipefail
 �[36;1mset -uo pipefail�[0m
 �[36;1mDIR=.github/canonical-references�[0m
 �[36;1mif [ ! -d "$DIR" ]; then�[0m
 �[36;1m  echo "ℹ️  [R5] no $DIR/ — skipped (repo has not opted in)"�[0m
 �[36;1m  exit 0�[0m
 �[36;1mfi�[0m
 �[36;1mif ! command -v python3 >/dev/null 2>&1; then�[0m
 �[36;1m  echo "❌ [R5] python3 missing on runner — required for YAML rule parsing"�[0m
 �[36;1m  exit 2�[0m
 �[36;1mfi�[0m
 �[36;1mpython3 - <<'PY'�[0m
 �[36;1mimport os, sys, glob, subprocess�[0m
 �[36;1mtry:�[0m
 �[36;1m    import yaml�[0m
 �[36;1mexcept ImportError:�[0m
 �[36;1m    sys.exit("❌ [R5] PyYAML not installed on runner; install python3-yaml")�[0m
 �[36;1m�[0m
 �[36;1mdir_ = ".github/canonical-references"�[0m
 �[36;1mfiles = sorted(glob.glob(f"{dir_}/*.yml") + glob.glob(f"{dir_}/*.yaml"))�[0m
 �[36;1mif not files:�[0m
 �[36;1m    print(f"ℹ️  [R5] {dir_}/ has no .yml/.yaml rules — skipped")�[0m
 �[36;1m    sys.exit(0)�[0m
 �[36;1m�[0m
 �[36;1mtotal = 0�[0m
 �[36;1mfor rf in files:�[0m
 �[36;1m    with open(rf, encoding="utf-8") as fh:�[0m
 �[36;1m        cfg = yaml.safe_load(fh)�[0m
 �[36;1m    if not isinstance(cfg, dict):�[0m
 �[36;1m        print(f"❌ [R5] {rf}: top-level must be a mapping"); total += 1; continue�[0m
 �[36;1m    rid  = cfg.get("id", os.path.basename(rf))�[0m
 �[36;1m    desc = cfg.get("description", "")�[0m
 �[36;1m    pats = cfg.get("patterns") or []�[0m
 �[36;1m    canon = cfg.get("canonical_pointer", "")�[0m
 �[36;1m    scope = (cfg.get("scope") or {})�[0m
 �[36;1m    includes = scope.get("include") or []�[0m
 �[36;1m    if not pats or not includes:�[0m
 �[36;1m        print(f"❌ [R5:{rid}] missing patterns or scope.include in {rf}")�[0m
 �[36;1m        total += 1; continue�[0m
 �[36;1m    # exclude self-references�[0m
 �[36;1m    skip = set(["CHANGELOG.md", "CHANGELOG.adoc", rf])�[0m
 �[36;1m    if canon: skip.add(canon)�[0m
 �[36;1m    rule_hits = 0�[0m
 �[36;1m    for f_ in includes:�[0m
 �[36;1m        if f_ in skip or not os...

GitHub Actions: Governance / governance _ Security policy checks: fix(ci): make Rust Build + rust-ci able to go green; unmask clippy/fmt

Conclusion: failure

View job details

##[group]Run set -uo pipefail
 �[36;1mset -uo pipefail�[0m
 �[36;1mDIR=.github/canonical-references�[0m
 �[36;1mif [ ! -d "$DIR" ]; then�[0m
 �[36;1m  echo "ℹ️  [R5] no $DIR/ — skipped (repo has not opted in)"�[0m
 �[36;1m  exit 0�[0m
 �[36;1mfi�[0m
 �[36;1mif ! command -v python3 >/dev/null 2>&1; then�[0m
 �[36;1m  echo "❌ [R5] python3 missing on runner — required for YAML rule parsing"�[0m
 �[36;1m  exit 2�[0m
 �[36;1mfi�[0m
 �[36;1mpython3 - <<'PY'�[0m
 �[36;1mimport os, sys, glob, subprocess�[0m
 �[36;1mtry:�[0m
 �[36;1m    import yaml�[0m
 �[36;1mexcept ImportError:�[0m
 �[36;1m    sys.exit("❌ [R5] PyYAML not installed on runner; install python3-yaml")�[0m
 �[36;1m�[0m
 �[36;1mdir_ = ".github/canonical-references"�[0m
 �[36;1mfiles = sorted(glob.glob(f"{dir_}/*.yml") + glob.glob(f"{dir_}/*.yaml"))�[0m
 �[36;1mif not files:�[0m
 �[36;1m    print(f"ℹ️  [R5] {dir_}/ has no .yml/.yaml rules — skipped")�[0m
 �[36;1m    sys.exit(0)�[0m
 �[36;1m�[0m
 �[36;1mtotal = 0�[0m
 �[36;1mfor rf in files:�[0m
 �[36;1m    with open(rf, encoding="utf-8") as fh:�[0m
 �[36;1m        cfg = yaml.safe_load(fh)�[0m
 �[36;1m    if not isinstance(cfg, dict):�[0m
 �[36;1m        print(f"❌ [R5] {rf}: top-level must be a mapping"); total += 1; continue�[0m
 �[36;1m    rid  = cfg.get("id", os.path.basename(rf))�[0m
 �[36;1m    desc = cfg.get("description", "")�[0m
 �[36;1m    pats = cfg.get("patterns") or []�[0m
 �[36;1m    canon = cfg.get("canonical_pointer", "")�[0m
 �[36;1m    scope = (cfg.get("scope") or {})�[0m
 �[36;1m    includes = scope.get("include") or []�[0m
 �[36;1m    if not pats or not includes:�[0m
 �[36;1m        print(f"❌ [R5:{rid}] missing patterns or scope.include in {rf}")�[0m
 �[36;1m        total += 1; continue�[0m
 �[36;1m    # exclude self-references�[0m
 �[36;1m    skip = set(["CHANGELOG.md", "CHANGELOG.adoc", rf])�[0m
 �[36;1m    if canon: skip.add(canon)�[0m
 �[36;1m    rule_hits = 0�[0m
 �[36;1m    for f_ in includes:�[0m
 �[36;1m        if f_ in skip or not os...
🧰 Additional context used
🪛 GitHub Actions: Workflow Security Linter / 0_lint-workflows.txt
.github/workflows/e2e.yml

[error] 1-1: SPDX header check failed: missing SPDX-License-Identifier on the first line. The workflow header check exited with code 22.

🪛 GitHub Actions: Workflow Security Linter / lint-workflows
.github/workflows/e2e.yml

[error] 1-1: SPDX header check failed: missing SPDX-License-Identifier on the first line.

🪛 zizmor (1.30.1)
.github/workflows/e2e.yml

[error] 26-26: unpinned action reference (unpinned-uses): action is not pinned to a hash (required by blanket policy)

(unpinned-uses)

🔇 Additional comments (17)
.github/workflows/e2e.yml (1)

24-25: LGTM!

Also applies to: 32-32, 34-34, 43-44, 56-57, 97-98

benches/januskey_benchmarks.rs (1)

121-121: LGTM!

Also applies to: 158-158

crates/reversible-core/src/manifest.rs (1)

44-44: LGTM!

Also applies to: 108-108

crates/januskey-cli/src/attestation.rs (1)

203-203: LGTM!

Also applies to: 212-212

crates/januskey-cli/src/keys.rs (1)

187-187: LGTM!

Also applies to: 231-231, 247-247, 549-549, 608-608

crates/januskey-cli/src/obliteration.rs (1)

76-76: LGTM!

Also applies to: 82-82, 166-166, 345-345

crates/januskey-cli/src/keys_cli.rs (1)

11-11: LGTM!

Also applies to: 15-16, 296-296, 448-448, 568-568, 676-676

crates/januskey-cli/src/main.rs (1)

18-18: LGTM!

Also applies to: 219-219, 241-241, 362-362, 396-396, 482-482, 487-487, 538-538, 594-594, 715-715, 769-769, 788-788, 803-803, 832-832, 845-845, 889-889, 951-951, 967-967, 978-978

crates/januskey-cli/src/lib.rs (1)

79-79: LGTM!

Also applies to: 81-81, 86-86

crates/januskey-cli/src/operations.rs (1)

503-503: LGTM!

Also applies to: 534-534, 551-551

crates/januskey-cli/tests/aspect_test.rs (1)

12-12: LGTM!

Also applies to: 21-21, 29-29, 146-150

crates/januskey-cli/tests/concurrency_test.rs (1)

12-12: LGTM!

Also applies to: 22-22, 63-63, 71-71, 74-75, 131-131, 136-136, 163-163, 392-392

crates/januskey-cli/tests/e2e_test.rs (1)

10-10: LGTM!

Also applies to: 19-19, 88-88, 107-107, 137-137, 176-176, 187-187, 238-238, 241-241, 244-244, 254-254, 376-376

crates/januskey-cli/tests/p2p_test.rs (1)

106-106: LGTM!

Also applies to: 146-146, 198-198

crates/reversible-core/src/metadata.rs (1)

266-266: LGTM!

crates/reversible-core/src/transaction.rs (1)

126-126: LGTM!

tests/aspect/cross_cutting_test.sh (1)

55-58: LGTM!


📝 Summary

Summary by CodeRabbit

  • Bug Fixes

    • Attestation generation now reports an error if its cryptographic setup fails, rather than terminating unexpectedly.
  • Chores

    • Build and test checks now use the stable Rust toolchain, and formatting or linting failures are no longer ignored.
    • Documentation checks now recognise both Markdown and AsciiDoc files.

Walkthrough

The pull request updates Rust workflow checks and makes related changes to CLI key and attestation handling, path arguments, file reads, tests, benchmarks, and core code. It also allows documentation checks to find either Markdown or AsciiDoc files.

Changes

Rust tooling and code updates

Layer / File(s) Summary
Workflow checks
.github/workflows/e2e.yml
The Rust jobs select the stable toolchain. Clippy checks all targets with warnings as errors, and Clippy and formatting failures fail the job.
Key and attestation updates
crates/januskey-cli/src/{keys.rs,attestation.rs,obliteration.rs,keys_cli.rs}
Key and obliteration code uses rand::rng(). HMAC initialisation errors now map to I/O errors. KeyManager no longer stores root_path, and keys_cli.rs imports the modules from januskey.
CLI command interfaces
crates/januskey-cli/src/{keys_cli.rs,main.rs}
CLI command helpers use &Path instead of &PathBuf. The changes also update optional-flag checks, error formatting, and status output.
File reads and test updates
crates/januskey-cli/src/{lib.rs,keys.rs,main.rs,obliteration.rs,operations.rs}, crates/januskey-cli/tests/*, crates/reversible-core/src/{metadata.rs,transaction.rs}, tests/aspect/cross_cutting_test.sh
File reads retain their existing limits and parsing behaviour without mutable file bindings. Test helpers and filters are updated, and documentation checks accept .md or .adoc files.
Benchmark and core call sites
benches/januskey_benchmarks.rs, crates/reversible-core/src/manifest.rs
The benchmark initialises its active flag directly and passes hash buffers by value. The manifest appends its version line as a literal and passes the finalized hash buffer by value.

Priority: ➖ Normal

Estimated code review effort: 2 (Simple) | ~10 minutes

Change: Bug fix

Merge Risk: ⚪ Minimal · up to e6fee

The workflow will now fail on Clippy warnings and formatting errors, while the described code changes preserve existing behavior and return HMAC initialization errors. No merge-blocking regression is identified beyond normal CI validation.

🚥 Pre-merge checks | ✅ 4 | ❌ 1

❌ Failed checks (1 warning)

Check name Status Explanation Resolution
Docstring Coverage ⚠️ Warning Docstring coverage is 60.34% which is insufficient. The required threshold is 80.00%. Docstring coverage is scoped to functions touched by this diff. Analyzed 58 functions across 16 files. (1 skipped:… Write docstrings for the functions missing them to satisfy the coverage threshold.
✅ Passed checks (4 passed)
Check name Status Explanation
Linked Issues check ✅ Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check ✅ Passed Check skipped because no linked issues were found for this pull request.
Description check ✅ Passed The description clearly explains the Rust CI fixes, Clippy and rustfmt changes, test validation, aspect-check updates, and deferred checks. It is directly related to the changeset.
Title check ✅ Passed The title clearly identifies the primary change: fixing Rust CI and enabling Clippy and rustfmt failures to fail correctly. It is concise and related to the changeset.
Full details: Docstring Coverage

Explanation

Docstring coverage is 60.34% which is insufficient. The required threshold is 80.00%. Docstring coverage is scoped to functions touched by this diff. Analyzed 58 functions across 16 files. (1 skipped: 1 unsupported.)

🤖 Coding task started

✨ Finishing Touches 💡 2
📝 Generate docstrings 💡
  • Commit to this branch
  • Create a new PR
🛠️ Fix failing CI checks 💡
  • Commit to this branch
  • Create a new PR
  • Autopilot · Keep fixing CodeRabbit findings and required CI, and resolving merge conflicts

Autopilot is currently an internal CodeRabbit preview.


Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

A rabbit checks the stable build,
Then hops where Rust warnings once were stilled.
Key bytes whirl and hashes flow,
Bounded reads keep files in tow.
Markdown, AsciiDoc both appear,
The rabbit thumps: the checks are clear.

Comment @coderabbitai help to get the list of available commands.

Comment thread crates/januskey-cli/src/attestation.rs Fixed
….adoc

- dtolnay/rust-toolchain@v1 needs a `toolchain` input; the Criterion,
  E2E Lifecycle and Panic Attack jobs had none ("'toolchain' is a required
  input"). Set `stable`.
- tests/aspect: SECURITY/ARCHITECTURE/PROOF-NEEDS/TOPOLOGY were migrated
  to .adoc, so the .md-only existence checks failed 4/29. Accept either,
  as README already did. Negative control: removing TOPOLOGY.adoc makes
  the check FAIL.
- attestation: propagate HMAC new_from_slice's error instead of expect()
  (Hypatia expect_in_hot_path; the fn already returns io::Result).

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01VxcAoyMQe7CjQwCKL18Mm4
@coderabbitai

coderabbitai Bot commented Oct 2, 2026 •

Copy link
Copy Markdown
Contributor

⚠️ Coding task changes are ready, but delivery needs attention

Open the task to resolve the delivery issue or retry.

@coderabbitai

coderabbitai Bot commented Oct 2, 2026

Copy link
Copy Markdown
Contributor

Autopilot could not be updated. Open Coding to check access and billing.

@hyperpolymath
hyperpolymath merged commit 8c4ec63 into main Oct 2, 2026
37 of 45 checks passed
@hyperpolymath
hyperpolymath deleted the fix/ci-toolchain-fmt branch October 2, 2026 13:16
hyperpolymath added a commit that referenced this pull request Oct 2, 2026
…counts (#146)

ULTRAPLAN **P1-0, PR B of three** (B: ledger + counts; C: escape-hatch
counter; D: `workflow_call`).

> **Stacked on #144.** This branch contains #144's commit e6fee67, so
review only **6f31e89** and the docs follow-up. It stays a draft until
#144 merges; then it is rebased onto main and marked ready.

## What it does
`PROOF-NEEDS.adoc` gains a `=== Claims ledger` table. Each row is `claim
| status | artefact | command`, with status PROVEN / TESTED / ASSUMED /
DESIGNED / OPEN, and each row fits on one line. `dashboard-check --check
.` (already run by `dashboard-check.yml`) now does the following:

| Status | Rule |
|---|---|
| TESTED | The artefact `file::test` must exist and name the test. The
command must exit 0, **and** some output line must show that test
passing (`ok`/`PASS`). That rejects `true` and a filter that runs 0
tests. |
| PROVEN | The file must name the theorem, and the checker command must
exit 0. |
| ASSUMED / DESIGNED / OPEN | The command must be `-`. The artefact must
be an existing file or `#N`. |
| any | A wrapped row, an unknown status, or a missing table fails and
names the line. |

**Dashboard counts.** On README / EXPLAINME / TOPOLOGY / READINESS, a
number followed within two words by *test(s)* must equal `cargo test
--workspace --locked -- --list` (lines ending `: test`). A number
followed by *proof(s)/theorem(s)* must equal the number of PROVEN rows.
Percentages are excluded, and so are numbers in another table cell.

**Ledger contents:** 7 TESTED rows (obliteration ×3, execute∘undo,
content-store round-trip, rollback, audit-chain verify) and 2 OPEN rows
(#145). **0 PROVEN**, because the Idris2 ABI does not typecheck.

## Doc corrections the checker forced
| Where | Was | Now |
|---|---|---|
| READINESS:11, :67; TOPOLOGY:82 | 67 tests | 119 tests |
| READINESS:11, :63, :67; TOPOLOGY:80 | 30 (Idris2) proofs, row 16 ✓ | 0
checked (#145), row 16 ✗ |

TOPOLOGY "Last updated" → 2026-10-02.

## Scope limits (stated, not implied)
- **Only test/proof counts are reconciled here.** The OVERALL percentage
is reconciled against STATE as before, but the per-component `N%`
figures on TOPOLOGY are **not** checked.
- **The 119 tests are workspace-wide and include dashboard-check's own
31.** Adding a test anywhere now requires updating the dashboard count
in the same PR. That is the intended ratchet.
- **PROVEN is exercised only by unit tests (fake runner), not by a real
row**, because the repo has none. ASSUMED/DESIGNED have no rows either.
- **Escape-hatch counting** (Axiom/Admitted/sorry/believe_me/postulate)
is PR C, not this one.

## Verification (local, rust 1.97.1)
- `cargo fmt --all -- --check` ✓; `cargo clippy --workspace
--all-targets --locked -- -D warnings` ✓; `cargo test --workspace
--locked`: 119 passed, 0 failed.
- `cargo run -p dashboard-check -- --check .` → rc=0: `✓ 119 tests
measured, 0 PROVEN claims`, all 7 TESTED rows ran and passed.
- **Positive control 1:** on the old docs the checker printed 6
divergences (67 vs 118, 30 vs 0 ×3, plus READINESS:11) with rc=1.
- **Positive control 2:** adding one unit test made it report `claims
118 but there are 119` on three lines with rc=1. It was green again
after the update.
- **Fixtures** (in `claims.rs`): `lying_verifier_fails` (exit 0, no
output), `unchecked_skip_fails` (`running 0 tests`),
`inflated_counts_fail_and_true_counts_pass`, `wrapped_row_is_rejected`,
`proven_row_needs_theorem_and_passing_checker`,
`open_rows_run_nothing_and_need_a_real_artefact`.
- **CI:** dashboard-check run 37010504568 passed in **39 s** (13:03:41Z
to 13:04:20Z), well under the job's 15 min timeout. Its log shows all 7
`✓ Tested` rows, both `✓ Open` rows and `✓ 119 tests measured, 0 PROVEN
claims`.


## Red checks: inherited from #144 (e6fee67), deferred, not introduced
here
The red set on this head equals #144's, which equals main 539e6f9's. The
ledger commit adds none.
- `lint-workflows`: deferred to #135 (acceptance item 5)
- `governance / Workflow security linter`: deferred to #135 (acceptance
item 5)
- `governance / Allowlist Preflight`: deferred to #135 (acceptance item
6, `Check live Actions policy`)
- `Validate DEED manifests`: deferred to #135 (acceptance item 6)
- `estate-audit`: deferred to #135 (acceptance item 6, `Code Hygiene
Gate`)
- `idris-abi (expected red until J1-3)`: expected red by design (#142)
until #145 (ULTRAPLAN J1-3) makes Types.idr typecheck.

**CodeRabbit** posted the status "Review rate limited" on 6f31e89 and
has not reviewed this PR yet. Its review will be read before this PR is
marked ready.

🤖 Generated with [Claude Code](https://claude.com/claude-code)

https://claude.ai/code/session_01VxcAoyMQe7CjQwCKL18Mm4

---------

Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants