Skip to content

fix(gates): require .deed, not the deprecated .a2ml - #46

Merged
hyperpolymath merged 2 commits into
mainfrom
fix/deed-gate-grammar
Sep 21, 2026
Merged

hyperpolymath merged 2 commits into
mainfrom
fix/deed-gate-grammar

Conversation

@hyperpolymath

Copy link
Copy Markdown
Owner

What breaks today

dogfood-gate.yml counts .a2ml files and nothing else, so a repo whose only manifest is a
.deed document gets ::warning::No .a2ml manifest files found, and the summary step is
skipped by the same predicate. The gate is checking for a grammar the estate has deprecated.

Authority for the new wording

  • deed-ecosystem/README.adoc: "The DEED format name and .deed extension are final, not A2ML."
  • rsr-template-repo ships rsr-template-repo_chora.deed and bootstraps with just repo-init;
    the removed a2mliser init instruction points at neither.
  • hyperpolymath/accessibility-everywhere already carries this exact migrated form, so this PR
    converges a stale copy rather than introducing a new convention.

Deliberately not touched

  • .machine_readable/*.a2ml and any gate reading a real retained file: their own README scopes
    the rename away from "retained A2ML v1 material". Rewriting those inputs would fail gates that
    currently pass.
  • validate-a2ml.sh hook filenames and the validator's own Validate A2ML Manifests step name
    (names, not grammars).

Part of the estate-wide .deed gate migration, 2026-09-21.

The guard counted `.a2ml` files only, so a repo carrying just a `.deed` document was told it had
no manifest at all:

  - find \. -name '\*\.a2ml' -not -path '\./\.git/\*'
  + find . -type f \( -name '*.a2ml' -o -name '*.deed' \) -not -path './.git/*'

The validator already reads both grammars; the caller's predicate was the bug. Wording follows the
estate's own migrated copy and `deed-ecosystem/README.adoc`: `.deed` is final, `.a2ml` is legacy and
no longer authored, and the template bootstraps with `just repo-init` (so the `a2mliser init`
instruction is removed). Retained `.machine_readable/*.a2ml` inputs are untouched.
@coderabbitai

coderabbitai Bot commented Sep 21, 2026

Copy link
Copy Markdown

Review Change StackReview Change Stack

Note

Currently processing new changes in this PR. This may take a few minutes, please wait...

⚙️ Run configuration

Configuration used: Organization UI

Review profile: ASSERTIVE

Plan: Advanced

Run ID: 0866dc8d-e1f1-45f9-bdd5-d6157c7b8b9f

📥 Commits

Reviewing files that changed from the base of the PR and between 60fc95c and f0958ea.

📒 Files selected for processing (1)
  • .github/workflows/dogfood-gate.yml
 ___________________________________________________________
< Ultimately, we're all just debugging someone else's code. >
 -----------------------------------------------------------
  \
   \   \
        \ /\
        ( )
      .( o ).

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@hyperpolymath
hyperpolymath merged commit 683cca8 into main Sep 21, 2026
@hyperpolymath
hyperpolymath deleted the fix/deed-gate-grammar branch September 21, 2026 11:10
@github-actions

Copy link
Copy Markdown

🔍 Hypatia Security Scan

Findings: 79 issues detected

Severity Count
🔴 Critical 7
🟠 High 17
🟡 Medium 55

⚠️ Action Required: Critical security issues found!

View findings
[
  {
    "reason": "Invalid .github/workflows/actions.lock: {:line, 162, {:repository_id_reused, 1275649586, \"hyperpolymath/a2ml-ecosystem\", \"hyperpolymath/deed-ecosystem\"}}. Regenerate and verify it with gh actions-lock.",
    "type": "invalid_actions_lock",
    "file": "actions.lock",
    "action": "regenerate",
    "rule_module": "workflow_audit",
    "severity": "high"
  },
  {
    "reason": "No permissions declaration -- add permissions: read-all",
    "type": "missing_permissions",
    "file": "main-estate-audit.yml",
    "action": "add_permissions",
    "rule_module": "workflow_audit",
    "severity": "medium"
  },
  {
    "reason": "Job `trigger-boj` in boj-build.yml has no `timeout-minutes:` declaration. Default is 6 hours — a stuck codeload fetch or runner hang can burn budget. Add `timeout-minutes: 10` (or proportional).",
    "type": "missing_timeout_minutes",
    "file": "boj-build.yml",
    "action": "flag",
    "rule_module": "workflow_audit",
    "severity": "medium",
    "recipe_id": "recipe-add-workflow-timeout-minutes",
    "job": "trigger-boj"
  },
  {
    "reason": "Job `build` in casket-pages.yml has no `timeout-minutes:` declaration. Default is 6 hours — a stuck codeload fetch or runner hang can burn budget. Add `timeout-minutes: 10` (or proportional).",
    "type": "missing_timeout_minutes",
    "file": "casket-pages.yml",
    "action": "flag",
    "rule_module": "workflow_audit",
    "severity": "medium",
    "recipe_id": "recipe-add-workflow-timeout-minutes",
    "job": "build"
  },
  {
    "reason": "Job `deploy` in casket-pages.yml has no `timeout-minutes:` declaration. Default is 6 hours — a stuck codeload fetch or runner hang can burn budget. Add `timeout-minutes: 10` (or proportional).",
    "type": "missing_timeout_minutes",
    "file": "casket-pages.yml",
    "action": "flag",
    "rule_module": "workflow_audit",
    "severity": "medium",
    "recipe_id": "recipe-add-workflow-timeout-minutes",
    "job": "deploy"
  },
  {
    "reason": "Job `analyze` in codeql.yml has no `timeout-minutes:` declaration. Default is 6 hours — a stuck codeload fetch or runner hang can burn budget. Add `timeout-minutes: 10` (or proportional).",
    "type": "missing_timeout_minutes",
    "file": "codeql.yml",
    "action": "flag",
    "rule_module": "workflow_audit",
    "severity": "medium",
    "recipe_id": "recipe-add-workflow-timeout-minutes",
    "job": "analyze"
  },
  {
    "reason": "Job `automerge` in dependabot-automerge.yml has no `timeout-minutes:` declaration. Default is 6 hours — a stuck codeload fetch or runner hang can burn budget. Add `timeout-minutes: 10` (or proportional).",
    "type": "missing_timeout_minutes",
    "file": "dependabot-automerge.yml",
    "action": "flag",
    "rule_module": "workflow_audit",
    "severity": "medium",
    "recipe_id": "recipe-add-workflow-timeout-minutes",
    "job": "automerge"
  },
  {
    "reason": "Job `a2ml-validate` in dogfood-gate.yml has no `timeout-minutes:` declaration. Default is 6 hours — a stuck codeload fetch or runner hang can burn budget. Add `timeout-minutes: 10` (or proportional).",
    "type": "missing_timeout_minutes",
    "file": "dogfood-gate.yml",
    "action": "flag",
    "rule_module": "workflow_audit",
    "severity": "medium",
    "recipe_id": "recipe-add-workflow-timeout-minutes",
    "job": "a2ml-validate"
  },
  {
    "reason": "Job `dogfood-summary` in dogfood-gate.yml has no `timeout-minutes:` declaration. Default is 6 hours — a stuck codeload fetch or runner hang can burn budget. Add `timeout-minutes: 10` (or proportional).",
    "type": "missing_timeout_minutes",
    "file": "dogfood-gate.yml",
    "action": "flag",
    "rule_module": "workflow_audit",
    "severity": "medium",
    "recipe_id": "recipe-add-workflow-timeout-minutes",
    "job": "dogfood-summary"
  },
  {
    "reason": "Job `eclexiaiser-validate` in dogfood-gate.yml has no `timeout-minutes:` declaration. Default is 6 hours — a stuck codeload fetch or runner hang can burn budget. Add `timeout-minutes: 10` (or proportional).",
    "type": "missing_timeout_minutes",
    "file": "dogfood-gate.yml",
    "action": "flag",
    "rule_module": "workflow_audit",
    "severity": "medium",
    "recipe_id": "recipe-add-workflow-timeout-minutes",
    "job": "eclexiaiser-validate"
  }
]

Powered by Hypatia Neurosymbolic CI/CD Intelligence

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant