Skip to content

fix(ci): clear Dogfood+Governance check failures - #95

Merged
hyperpolymath merged 1 commit into
mainfrom
arena/01a0da6f-aerie
Sep 25, 2026
Merged

hyperpolymath merged 1 commit into
mainfrom
arena/01a0da6f-aerie

Conversation

@arena-ai-coding-agent

Copy link
Copy Markdown
Contributor

What

Two independent reds on main at cb2b475, each reproduced locally with the exact pinned tooling, then fixed:

1. Dogfood Gate — Validate DEED manifests (run 36188043077)

hyperpolymath/deed-ecosystem/validate-action@aa4b836 reported:

::error file=./tests/idris2/depends.a2ml,line=1::Missing required identity field (agent-id, name, or project)
::error file=./tests/idris2/diagnosticity.a2ml,line=1::Missing required identity field (agent-id, name, or project)
A2ML validation failed with 2 error(s)

Both files are corpus metadata docs (tests/idris2/README.adoc, ROADMAP Phase 9) in .a2ml form. Fix: add name + version identity fields. Validator now exits 0 — 0 errors, warnings down 6 → 4 (remaining ones are advisory SPDX/attestation warnings in non-strict mode).

2. Governance — Workflow security linter / Check SPDX headers + permissions (run 36188043851)

.github/workflows/build.yml had neither a SPDX header comment block nor a top-level permissions: declaration — both required by hyperpolymath/standards governance-reusable@092deda. Fix: standard estate header + permissions: contents: read.

Drive-bys in the same (failed) workflow's summary steps

  • Scorecard row and manifest-count line read the never-set A2ML_STATUS / A2ML_COUNT → empty cells; now DEED_STATUS / MANIFEST_COUNT.
  • The empty-K9 branch printed the missing-DEED text; now says K9.

Verification (local, before pushing)

Gate Result
SPDX + permissions scan (linter step, verbatim) ✅ all workflows
validate-a2ml.sh@aa4b836 (job step, verbatim) ✅ 0 errors
check-workflow-duplicate-keys.sh@092deda ✅ 17 clean
check-workflows-parse.sh@092deda ✅ all parse
check-action-pins-resolve.sh@092deda ✅ 20/20 resolve
TOML parse of the two .a2ml files ✅

Not in this PR (owner-token / other sessions)

  • Actions allow-list empty-list zero-jobs failure → Secret Scanner, Label Triage, GitHub Pages, Mirror (owner; commands in docs/REPO-SETTINGS.adoc §3/§9, docs/ESTATE-PROPAGATION.adoc §4–5).
  • SonarQube (Build run) scanner exit 3 — SONAR_TOKEN owner secret.
  • Optimus-Branch enablement + check contexts — only after checks schedule again (REPO-SETTINGS §1).
  • Estate propagation layers A→C — runbook in docs/ESTATE-PROPAGATION.adoc.

Two independent reds on main at cb2b475, both reproduced locally with
the exact pinned tooling before fixing:

- Dogfood Gate "Validate DEED manifests": deed-ecosystem validate-action
  errored on tests/idris2/{depends,diagnosticity}.a2ml — missing
  required identity field. Both are corpus metadata docs (README.adoc);
  add name + version so the validator exits 0 (0 errors, warnings down
  6 → 4, all advisory in non-strict mode).

- Governance "Workflow security linter": .github/workflows/build.yml
  had neither a SPDX header comment block nor a top-level permissions:
  declaration — both required by standards governance-reusable
  (092deda). Add the standard estate header + contents: read.

Drive-bys in the Dogfood summary steps (same failed workflow): the
scorecard row and manifest-count line read the never-set A2ML_STATUS /
A2ML_COUNT instead of DEED_STATUS / MANIFEST_COUNT (empty cells), and
the empty-K9 branch printed the missing-DEED text.

Gates re-run locally after the fix, all green: SPDX+permissions scan,
duplicate-key check (17 workflows clean), workflow parse, action-pin
resolve (20/20 upstream), A2ML validator (0 errors).

Co-authored-by: arena-agent <297053741+arena-agent@users.noreply.github.com>
@coderabbitai

coderabbitai Bot commented Sep 25, 2026

Copy link
Copy Markdown
Contributor

Important

Review skipped

Bot user detected.

To trigger a single review, invoke the @coderabbitai review command.

⚙️ Run configuration

Configuration used: Organization UI

Review profile: ASSERTIVE

Plan: Advanced

Run ID: 044cbac1-dcf6-47c9-baa4-fa2ddc8f3def

You can disable this status message by setting the reviews.review_status to false in the CodeRabbit configuration file.

Use the checkbox below for a quick retry:

  • 🔍 Trigger review

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@hyperpolymath
hyperpolymath merged commit f4e49a7 into main Sep 25, 2026
5 checks passed
@hyperpolymath
hyperpolymath deleted the arena/01a0da6f-aerie branch September 25, 2026 21:30
hyperpolymath added a commit that referenced this pull request Sep 25, 2026
## What

Follow-up to #95. Governance on main (f4e49a7) now passes `Check SPDX
headers + permissions` ✅ but fails one step later:

```
::error::1 of 20 action pin(s) DO NOT EXIST upstream.
  NOT-ANCESTOR    hyperpolymath/standards@892497f  (compare main → diverged)
```

**Root cause (a real, determinate negative — not a flake):** `892497fe`,
the pin on `secret-scanner.yml`'s reusable workflow, is a real commit
object but **not an ancestor of `standards/main`** (orphan —
squash-merge residue / PR-head lineage). GitHub's resolver only accepts
reusable-workflow commits reachable from the default branch, so:

- **every Secret Scanner run** (push *and* PR) fails at graph resolution
with 0 jobs — the "This run likely failed because of a workflow file
issue" rows red on main since at least #93;
- the estate's updated pin gate (standards\@main, now run by
Governance's linter) determinately fails on it.

standards issue #782 documents this class: *four such SHAs (7fdc2705…,
**892497fe**…, 46960521…, 5b1d0022…) account for 61 dead workflow-run
rows with ZERO alive rows* — aerie's secret-scanner pin is literally one
of the named four.

## Fix

Repin to `e13e2ea3dbbc9c7815e39c3749b4480514f555a6` — the newest commit
on `standards/main` touching the reusable (2026-09-19, standards #867):

- **ancestry verified**: `compare/main...e13e2ea3` → `behind` (ancestor)
— the same predicate the gate applies;
- **strict superset** of the orphan's content: estate gitleaks baseline
wiring, full-history gating pass (`fetch-depth: 0` + shallow-assert),
`--verbose` findings, repo-local config resolution.

Per the gate's own guidance: repin to a merge commit **on** the default
branch, never a PR head.

## Verification (local, CI script versions)

| Gate | Result |
|---|---|
| `check-action-pins-resolve.sh` (standards\@main — what CI runs) | ✅
20/20 |
| SPDX + permissions | ✅ |
| duplicate keys | ✅ 17 clean |
| workflow parse | ✅ 25 |

## Expected effect after merge

- **Governance** → green (linter completes: SPDX ✓ → pin-resolve ✓ →
dup-workflows ✓).
- **Secret Scanner** → schedules jobs for the first time (was
unresolvable at graph resolution).

Note: Label Triage / Pages / Mirror / SonarQube remain owner-token items
(allow-list, secrets) — see `docs/REPO-SETTINGS.adoc` §3/§9.

---------

Co-authored-by: hyperpolymath <6759885+hyperpolymath@users.noreply.github.com>
Co-authored-by: arena-agent <297053741+arena-agent@users.noreply.github.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant