From 641caf2addcd3f4913f2e79bba61fe405530996d Mon Sep 17 00:00:00 2001 From: hyperpolymath <6759885+hyperpolymath@users.noreply.github.com> Date: Fri, 25 Sep 2026 21:28:39 +0000 Subject: [PATCH] fix(ci): clear Dogfood+Governance check failures MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit Two independent reds on main at cb2b475, both reproduced locally with the exact pinned tooling before fixing: - Dogfood Gate "Validate DEED manifests": deed-ecosystem validate-action errored on tests/idris2/{depends,diagnosticity}.a2ml — missing required identity field. Both are corpus metadata docs (README.adoc); add name + version so the validator exits 0 (0 errors, warnings down 6 → 4, all advisory in non-strict mode). - Governance "Workflow security linter": .github/workflows/build.yml had neither a SPDX header comment block nor a top-level permissions: declaration — both required by standards governance-reusable (092deda). Add the standard estate header + contents: read. Drive-bys in the Dogfood summary steps (same failed workflow): the scorecard row and manifest-count line read the never-set A2ML_STATUS / A2ML_COUNT instead of DEED_STATUS / MANIFEST_COUNT (empty cells), and the empty-K9 branch printed the missing-DEED text. Gates re-run locally after the fix, all green: SPDX+permissions scan, duplicate-key check (17 workflows clean), workflow parse, action-pin resolve (20/20 upstream), A2ML validator (0 errors). Co-authored-by: arena-agent <297053741+arena-agent@users.noreply.github.com> --- .github/workflows/build.yml | 11 +++++++++++ .github/workflows/dogfood-gate.yml | 6 +++--- tests/idris2/depends.a2ml | 3 +++ tests/idris2/diagnosticity.a2ml | 3 +++ 4 files changed, 20 insertions(+), 3 deletions(-) diff --git a/.github/workflows/build.yml b/.github/workflows/build.yml index e68b148..096c3e3 100644 --- a/.github/workflows/build.yml +++ b/.github/workflows/build.yml @@ -1,10 +1,21 @@ +# SPDX-License-Identifier: MPL-2.0 +# Copyright (c) 2026 Jonathan D.A. Jewell (hyperpolymath) +# +# build.yml — SonarQube analysis on pushes to main and on PRs. +# The top-level permissions block is required by the estate workflow +# security linter (standards governance-reusable: SPDX headers + permissions). name: Build + on: push: branches: - main pull_request: types: [opened, synchronize, reopened] + +permissions: + contents: read + jobs: sonarqube: name: SonarQube diff --git a/.github/workflows/dogfood-gate.yml b/.github/workflows/dogfood-gate.yml index b97489e..b0f3e00 100644 --- a/.github/workflows/dogfood-gate.yml +++ b/.github/workflows/dogfood-gate.yml @@ -58,7 +58,7 @@ jobs: else echo "## DEED Manifest Validation" >> "$GITHUB_STEP_SUMMARY" echo "" >> "$GITHUB_STEP_SUMMARY" - echo "Scanned **${A2ML_COUNT}** manifest file(s) (.deed, or legacy .a2ml). See step output for details." >> "$GITHUB_STEP_SUMMARY" + echo "Scanned **${MANIFEST_COUNT}** manifest file(s) (.deed, or legacy .a2ml). See step output for details." >> "$GITHUB_STEP_SUMMARY" fi # --------------------------------------------------------------------------- @@ -100,7 +100,7 @@ jobs: cat <<'EOF' >> "$GITHUB_STEP_SUMMARY" ## K9 Contract Validation - :warning: **No .a2ml/.deed manifest files found.** Every RSR-compliant repo should have a repo deed (`_chora.deed`) at its root. + :warning: **No K9 contract files found.** Every RSR repo with config files should carry K9 contracts. Generate contracts with: `k9iser generate .` EOF @@ -396,7 +396,7 @@ jobs: | Tool/Format | Status | Notes | |-------------|--------|-------| - | DEED repo deed (`_chora.deed`) | ${A2ML_STATUS} | Required for all RSR repos | + | DEED repo deed (`_chora.deed`) | ${DEED_STATUS} | Required for all RSR repos | | K9 contracts | ${K9_STATUS} | Required for repos with config files | | .editorconfig | ${EC_STATUS} | Required for all repos | | Groove endpoint | ${GROOVE_STATUS} | Required for service repos | diff --git a/tests/idris2/depends.a2ml b/tests/idris2/depends.a2ml index 24f8db5..bc0b870 100644 --- a/tests/idris2/depends.a2ml +++ b/tests/idris2/depends.a2ml @@ -3,6 +3,9 @@ # yields exit 2 (VOID), and VOID propagates: a battery must reclassify any # green downstream of this unit's VOID as VOID. +name = "aerie-idris2-depends" +version = "1.0.0" + [upstream_units] value = "none — self-contained model suite; mirrors src/api/zig/{proof,policy}.zig invariants" diff --git a/tests/idris2/diagnosticity.a2ml b/tests/idris2/diagnosticity.a2ml index e048423..312df0d 100644 --- a/tests/idris2/diagnosticity.a2ml +++ b/tests/idris2/diagnosticity.a2ml @@ -1,6 +1,9 @@ # SPDX-License-Identifier: MPL-2.0 # Diagnosticity contract for the aerie model suite (tests/idris2). +name = "aerie-idris2-diagnosticity" +version = "1.0.0" + [detects] condition = "divergence between the aerie specification models (proof envelope well-formedness, policy-gate monotonicity, longest-prefix route matching) and their stated invariants" defect_class = "spec-model-drift"