Skip to content

fix(ci): satisfy the Actions allow-list so workflows can start (+ provenance probe visibility) - #85

Merged
hyperpolymath merged 4 commits into
mainfrom
arena/01a0de46-metamanifold-webui
Sep 27, 2026
Merged

hyperpolymath merged 4 commits into
mainfrom
arena/01a0de46-metamanifold-webui

Conversation

@arena-ai-coding-agent

Copy link
Copy Markdown

Why

Every workflow run on this repository since 2026-09-25 22:19 UTC has failed with startup_failure and zero jobs — CI has produced no verdict on anything since (the refreshed audit in docs/audit/2026-09-26-memory-numerics-warning-audit.md records the same observation). The run annotations name the cause; two rules, neither reportable by a job that never starts:

The actions julia-actions/setup-julia@…, julia-actions/cache@…, and julia-actions/julia-processcoverage@… are not allowed in hyperpolymath/MetaManifold-WebUI because all actions must be from a repository owned by hyperpolymath, created by GitHub, verified in the GitHub Marketplace, or match the pattern: arena-ai-coding-agent[bot]. All actions must also be pinned to a full-length commit SHA.

  • ci.yml, ui.yml, doi.yml used the three disallowed julia-actions/* actions;
  • proofs.yml used tag refs (@v4/@v5) instead of full SHAs (its annotation from run 36293672919).

Dependabot PR #68 (merged 2026-09-25 22:26) was not the cause — it only changed which ref each disallowed action used; the enforcement itself turned on at 22:19 and broke the arena-branch run five minutes before #68 merged.

What changed (behaviour preserved)

workflow was now
ci/ui/doi julia-actions/setup-julia inline install of official 1.12.5 binaries, verified against the official checksum file before use; JULIA_VERSION keeps the pin cross-checked by test_install_pins
ci/ui/doi julia-actions/cache actions/cache@55cc834 (v6.1.0) over the same depot dirs, keyed on each workflow's own Manifest/Project
ci julia-actions/julia-processcoverage equivalent CoverageTools run step (same default dirs, same lcov.info)
proofs checkout/setup-python/cache/upload-artifact@v4/@v5 same tags' commits — no version change

Plus two guards so this cannot regress silently:

  • test/unit/test_install_pins.jl now locates the Julia pin by step name (JULIA_VERSION= in Set up Julia) and gains a new testset that walks every workflow and fails on any action that is not full-SHA-pinned or not allow-listed — a future dependabot bump to a tag reddens Pkg.test instead of silencing Actions;
  • the provenance probe fallbacks in src/analysis/Execution.jl (the second commit) now @warn before writing version=unknown/hostname=unknown placeholders — the manifest schema and all existing assertions over it are untouched.

Validation done offline

  • YAML parse + duplicate-key scan of all four workflows;
  • policy self-check mirroring the new testset (every uses: full-SHA + allow-listed owner);
  • bash -n on every run: block;
  • JULIA_VERSION regex against config/defaults/tool_versions.yml (1.12.5 = 1.12.5);
  • sha256sum -c and /usr/local/bin/<tool> strings the pin tests assert on are still present.

Known remaining (settings-side, not fixable from workflow files)

A run on this branch also reported Actor is not allowed to trigger Actions workflows (run 36295388349) — the repository's actor allow-list appears to glob arena-ai-coding-agent[bot] (the [bot] read as a character class), so pushes made by the Arena bot may still be refused even with compliant workflow files. An admin needs to fix that pattern; runs triggered by hyperpolymath should proceed once this merges.

hyperpolymath and others added 3 commits September 27, 2026 04:48
main was rewritten to a new root (4c2c79e, PR #83) that shares no history
with the revision this audit was written against (4a848da), and the audited
code moved: Execution.jl +125/-60, estimation.jl +231/-29. ilr_basis.jl,
analysis.jl, provenance.jl and bench/ilr_bases/benchmark.jl are
byte-identical, so their citations are untouched.

Re-verifies all 21 findings against the new tree -- the four headline ones
(M3 dead clr_table, M4 redundant copies, N1 mixed healing scales, W1
is_dangerous not updated on :not_run) by reading the new code rather than
trusting the old line numbers -- and re-locates every citation into the two
files that moved.

Also corrects the catalogue for work that landed after the audit:
glmGamPoi dispersion is now a pure-Julia port (SUPPORTED_DISPERSION gains
"glmgampoi"; only local/mean/pooled remain refused), so
estimation.dispersion_refused no longer says "use parametric" for it. Adds
three entries: the port itself, its unported spline abundance trend, and
its pass-1 fallback; and records in the audit that two pure-Julia kernels
now exist, which bears on question 10 without changing the gate (CI still
has no verdict on any of this code).

Co-authored-by: arena-agent <297053741+arena-agent@users.noreply.github.com>
Every workflow run since 2026-09-25 22:19 UTC failed with
startup_failure and zero jobs. The run annotations name two
enforcement rules, neither of which a running job could ever have
reported:

* actions must be from a repository owned by hyperpolymath, created
  by GitHub, verified in the GitHub Marketplace, or match the
  configured pattern -- julia-actions/setup-julia, julia-actions/cache
  and julia-actions/julia-processcoverage match none of those;
* all actions must be pinned to a full-length commit SHA -- the
  Proofs workflow still used @v4/@v5 tag refs.

Changes, one per violation, with behaviour preserved:

* ci/ui/doi: julia-actions/setup-julia replaced by an inline install
  of the official 1.12.5 binaries, verified against the official
  checksum file before use; JULIA_VERSION keeps the pin that
  test/unit/test_install_pins.jl compares against tool_versions.yml
  and Manifest.toml;
* ci/ui/doi: julia-actions/cache replaced by actions/cache at
  55cc834 (v6.1.0) over the same depot directories, keyed on the
  workflow's own Manifest/Project pair;
* ci: julia-actions/julia-processcoverage replaced by the equivalent
  CoverageTools invocation (same default directories, same lcov.info);
* proofs: checkout/setup-python/cache/upload-artifact pinned to the
  commits their existing tags pointed at, so behaviour is unchanged.

test/unit/test_install_pins.jl locates the Julia pin by step name
now, and a new testset walks every workflow and fails on any action
that is not full-SHA-pinned and allow-listed, so a future dependabot
bump to a tag or an unverified owner reddens Pkg.test instead of
silencing Actions.

Validated offline: YAML parse + duplicate-key scan of all four
workflows, policy self-check mirroring the new testset, bash -n on
every run block, JULIA_VERSION regex against the pin file.

Co-authored-by: arena-agent <297053741+arena-agent@users.noreply.github.com>
The ExecutionManifest constructor swallowed probe_metamanifold and
probe_host failures into OrderedDict(version=>unknown /
hostname=>unknown) with no record of the refusal: a manifest that
looks probed when it was not. Both catch blocks now emit @warn with
the probe name and the error text before writing the placeholder,
which is the audit's rule that every fallback stays visible
(category: dependency_environment). The placeholder values
themselves are unchanged, so the manifest schema and every existing
assertion over it are untouched.

Co-authored-by: arena-agent <297053741+arena-agent@users.noreply.github.com>
@coderabbitai

coderabbitai Bot commented Sep 27, 2026 •

Copy link
Copy Markdown

Important

Review skipped

Bot user detected.

To trigger a single review, invoke the @coderabbitai review command.

⚙️ Run configuration

Configuration used: Organization UI

Review profile: ASSERTIVE

Plan: Advanced

Run ID: 680eea58-175c-4ddc-80d3-1085a16cdc14

You can disable this status message by setting the reviews.review_status to false in the CodeRabbit configuration file.

Use the checkbox below for a quick retry:

  • 🔍 Trigger review

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@hyperpolymath
hyperpolymath merged commit a5deb6c into main Sep 27, 2026
7 of 13 checks passed
@hyperpolymath
hyperpolymath deleted the arena/01a0de46-metamanifold-webui branch September 27, 2026 05:20
arena-ai-coding-agent Bot added a commit that referenced this pull request Sep 27, 2026
)

Follow-up to #85, which restored workflow startup. With CI alive again,
the **Source lint** step (`config/ci/lint_source.jl`) produced its first
verdict in two days and failed on two files it had never been able to
run against — neither of them touched by #85:

1. **`test/doi/fixtures.jl`** uses the suite aliases `B`/`P`, which are
`const` bindings defined in `tests.jl` before `include("fixtures.jl")`.
The lint check is deliberately textual and per-file, so an alias
supplied by the includer is invisible to it. The three call sites
(`B.write_checksums!`, `P.prepare!`, `P.publish!`) now go through
`Target.DOIBundles` / `Target.DOIPublications` — the same bindings at
runtime (tests.jl defines them from `Target`), legible in isolation.

2. **`test/unit/test_zero_replacement.jl:215`** broadcast
`Float64.(parse.(Float64, ...))` — the outer map is an identity (`parse`
with a `Float64` target already yields `Float64`), and the `Float64.(`
spelling matches the lint's `Module.member` pattern over test files.
Removing the outer conversion changes no value.

**Validation:** replayed the lint's textual checks (escaped
interpolation, adjacent docstrings, bare-alias member refs, the
`Float64.( pattern`) over both files — all clean. Julia itself isn't
available in this sandbox, so the definitive gate is the CI Source lint
step on this PR.

**Known-red checks NOT addressed here** (pre-existing, not introduced by
this change): repo-hygiene `tsc --noEmit` (frontend, likely #83-era),
the stale apt-Agda 2.6.4.3 `Proofs (Agda)` job inside ci.yml (proofs.yml
— the real gate — is green), and the DOI contracts job.

Co-authored-by: arena-agent <arena-agent@users.noreply.github.com>
Co-authored-by: arena-agent <297053741+arena-agent@users.noreply.github.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant