From 641caf2addcd3f4913f2e79bba61fe405530996d Mon Sep 17 00:00:00 2001 From: hyperpolymath <6759885+hyperpolymath@users.noreply.github.com> Date: Fri, 25 Sep 2026 21:28:39 +0000 Subject: [PATCH 1/2] fix(ci): clear Dogfood+Governance check failures MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit Two independent reds on main at cb2b475, both reproduced locally with the exact pinned tooling before fixing: - Dogfood Gate "Validate DEED manifests": deed-ecosystem validate-action errored on tests/idris2/{depends,diagnosticity}.a2ml — missing required identity field. Both are corpus metadata docs (README.adoc); add name + version so the validator exits 0 (0 errors, warnings down 6 → 4, all advisory in non-strict mode). - Governance "Workflow security linter": .github/workflows/build.yml had neither a SPDX header comment block nor a top-level permissions: declaration — both required by standards governance-reusable (092deda). Add the standard estate header + contents: read. Drive-bys in the Dogfood summary steps (same failed workflow): the scorecard row and manifest-count line read the never-set A2ML_STATUS / A2ML_COUNT instead of DEED_STATUS / MANIFEST_COUNT (empty cells), and the empty-K9 branch printed the missing-DEED text. Gates re-run locally after the fix, all green: SPDX+permissions scan, duplicate-key check (17 workflows clean), workflow parse, action-pin resolve (20/20 upstream), A2ML validator (0 errors). Co-authored-by: arena-agent <297053741+arena-agent@users.noreply.github.com> --- .github/workflows/build.yml | 11 +++++++++++ .github/workflows/dogfood-gate.yml | 6 +++--- tests/idris2/depends.a2ml | 3 +++ tests/idris2/diagnosticity.a2ml | 3 +++ 4 files changed, 20 insertions(+), 3 deletions(-) diff --git a/.github/workflows/build.yml b/.github/workflows/build.yml index e68b148..096c3e3 100644 --- a/.github/workflows/build.yml +++ b/.github/workflows/build.yml @@ -1,10 +1,21 @@ +# SPDX-License-Identifier: MPL-2.0 +# Copyright (c) 2026 Jonathan D.A. Jewell (hyperpolymath) +# +# build.yml — SonarQube analysis on pushes to main and on PRs. +# The top-level permissions block is required by the estate workflow +# security linter (standards governance-reusable: SPDX headers + permissions). name: Build + on: push: branches: - main pull_request: types: [opened, synchronize, reopened] + +permissions: + contents: read + jobs: sonarqube: name: SonarQube diff --git a/.github/workflows/dogfood-gate.yml b/.github/workflows/dogfood-gate.yml index b97489e..b0f3e00 100644 --- a/.github/workflows/dogfood-gate.yml +++ b/.github/workflows/dogfood-gate.yml @@ -58,7 +58,7 @@ jobs: else echo "## DEED Manifest Validation" >> "$GITHUB_STEP_SUMMARY" echo "" >> "$GITHUB_STEP_SUMMARY" - echo "Scanned **${A2ML_COUNT}** manifest file(s) (.deed, or legacy .a2ml). See step output for details." >> "$GITHUB_STEP_SUMMARY" + echo "Scanned **${MANIFEST_COUNT}** manifest file(s) (.deed, or legacy .a2ml). See step output for details." >> "$GITHUB_STEP_SUMMARY" fi # --------------------------------------------------------------------------- @@ -100,7 +100,7 @@ jobs: cat <<'EOF' >> "$GITHUB_STEP_SUMMARY" ## K9 Contract Validation - :warning: **No .a2ml/.deed manifest files found.** Every RSR-compliant repo should have a repo deed (`_chora.deed`) at its root. + :warning: **No K9 contract files found.** Every RSR repo with config files should carry K9 contracts. Generate contracts with: `k9iser generate .` EOF @@ -396,7 +396,7 @@ jobs: | Tool/Format | Status | Notes | |-------------|--------|-------| - | DEED repo deed (`_chora.deed`) | ${A2ML_STATUS} | Required for all RSR repos | + | DEED repo deed (`_chora.deed`) | ${DEED_STATUS} | Required for all RSR repos | | K9 contracts | ${K9_STATUS} | Required for repos with config files | | .editorconfig | ${EC_STATUS} | Required for all repos | | Groove endpoint | ${GROOVE_STATUS} | Required for service repos | diff --git a/tests/idris2/depends.a2ml b/tests/idris2/depends.a2ml index 24f8db5..bc0b870 100644 --- a/tests/idris2/depends.a2ml +++ b/tests/idris2/depends.a2ml @@ -3,6 +3,9 @@ # yields exit 2 (VOID), and VOID propagates: a battery must reclassify any # green downstream of this unit's VOID as VOID. +name = "aerie-idris2-depends" +version = "1.0.0" + [upstream_units] value = "none — self-contained model suite; mirrors src/api/zig/{proof,policy}.zig invariants" diff --git a/tests/idris2/diagnosticity.a2ml b/tests/idris2/diagnosticity.a2ml index e048423..312df0d 100644 --- a/tests/idris2/diagnosticity.a2ml +++ b/tests/idris2/diagnosticity.a2ml @@ -1,6 +1,9 @@ # SPDX-License-Identifier: MPL-2.0 # Diagnosticity contract for the aerie model suite (tests/idris2). +name = "aerie-idris2-diagnosticity" +version = "1.0.0" + [detects] condition = "divergence between the aerie specification models (proof envelope well-formedness, policy-gate monotonicity, longest-prefix route matching) and their stated invariants" defect_class = "spec-model-drift" From d57a02ad4bfbb890d59ca737665045eb75e096fb Mon Sep 17 00:00:00 2001 From: hyperpolymath <6759885+hyperpolymath@users.noreply.github.com> Date: Fri, 25 Sep 2026 21:37:40 +0000 Subject: [PATCH 2/2] fix(ci): repin secret-scanner off orphan SHA MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit The pinned secret-scanner-reusable.yml@892497fe is a real commit object but NOT an ancestor of hyperpolymath/standards' default branch (compare main -> diverged). The resolver cannot reach it, so every Secret Scanner run fails at graph resolution with zero jobs ("workflow file issue" on both push and PR), and the estate's updated pin gate fails Governance's "Check action pins resolve upstream" on it: 1 of 20 NOT-ANCESTOR (standards issue #782 — 61 dead estate rows traced to four such SHAs, 892497fe among them). Repin to e13e2ea3, the newest commit on standards/main touching the reusable (2026-09-19, standards #867): verified ancestor (compare main...sha = behind) and a strict superset of the orphan's content — estate gitleaks baseline wiring, full-history gating pass, --verbose findings. Gates re-run locally against the CI script versions, all green: pin resolve 20/20 (check-action-pins-resolve.sh from standards@main), SPDX+permissions, duplicate keys (17 clean), workflow parse. Co-authored-by: arena-agent <297053741+arena-agent@users.noreply.github.com> --- .github/workflows/secret-scanner.yml | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/.github/workflows/secret-scanner.yml b/.github/workflows/secret-scanner.yml index 05b8812..0f65b76 100644 --- a/.github/workflows/secret-scanner.yml +++ b/.github/workflows/secret-scanner.yml @@ -16,5 +16,5 @@ permissions: jobs: scan: - uses: hyperpolymath/standards/.github/workflows/secret-scanner-reusable.yml@892497fe373744874316710966b81ae6f0ea9e66 + uses: hyperpolymath/standards/.github/workflows/secret-scanner-reusable.yml@e13e2ea3dbbc9c7815e39c3749b4480514f555a6 secrets: inherit