Skip to content

refactor: eradicate ReScript and mechanically port to AffineScript - #362

Merged
hyperpolymath merged 2 commits into
mainfrom
refactor/eradicate-rescript
Aug 23, 2026
Merged

hyperpolymath merged 2 commits into
mainfrom
refactor/eradicate-rescript

Conversation

@hyperpolymath

Copy link
Copy Markdown
Owner

Summary

Closes #

Type of change

  • 🐛 Bug fix (non-breaking change that fixes an issue)
  • ✨ New feature (non-breaking change that adds functionality)
  • 💥 Breaking change (would change existing behaviour)
  • 🕳️ Soundness fix (fixes a checker/proof false-negative)
  • 📖 Documentation
  • 🧹 Refactor / tech debt (behaviour-preserving)
  • ⚡ Performance
  • 🔧 Build / CI / tooling

How has this been verified?

Checklist

  • My commits are signed (git commit -S).
  • I ran the project's own checks/tests locally and they pass.
  • New files carry the correct SPDX-License-Identifier (code/config MPL-2.0,
    prose CC-BY-SA-4.0); I did not relicense existing files.
  • Docs are updated, and no public claim now overstates what the code does.
  • I have not introduced a soundness hole (or I have flagged where I might have).

Notes for reviewers

@gitar-bot

gitar-bot Bot commented Aug 23, 2026 •

Copy link
Copy Markdown

Important

You are using the Gitar free plan. Upgrade to unlock code review, CI analysis, auto-apply, custom automations, and more.

Gitar

@hyperpolymath
hyperpolymath merged commit 3aa12bd into main Aug 23, 2026
2 checks passed
@hyperpolymath
hyperpolymath deleted the refactor/eradicate-rescript branch August 23, 2026 19:39
hyperpolymath added a commit that referenced this pull request Sep 25, 2026
…396)

## Summary

Review all 19 remaining issues without falsely closing roadmap or
upstream-blocked work.

- Repair eight duplicate Rust-toolchain `with:` mappings that GitHub
rejects before creating jobs.
- Fix workflow SPDX preamble validation for `actions-lock` managed
files.
- Add regression checks using the unchanged, pinned standards
duplicate-key scanner.
- Retire 33 obsolete ReScript exemptions after merged #362; add lossless
Hypatia risk routing (runtime, FFI, proof, migration, conservative
test-only review).
- Link proof CI from five metadata siblings and record the currency gaps
and disposition of every open issue in
`docs/reports/2026-09-25-issue-maintenance.adoc`.

Closes #216 (canonical owner header already on main).
Closes #175 (completed informational audit following #166).
Closes #196 (local cancel-token preemption already implemented by #154;
benchmark and transport remain #161/#194).
Closes #240 (legacy source removed by #362; obsolete exemptions removed
here; real UI compilation remains #117/#266).

Refs #239, #252, #314, #310. These remain open: classification is not
expert review, re-arming is not a completed security burn-down, and this
connection cannot rotate the owner-selected secret.

## Validation

- `bash -n scripts/ci/*.sh` — pass
- `bash scripts/ci/test-issue-regressions.sh` — pass, 34 workflows
checked plus positive/negative fixtures
- Checker rejects all eight original broken workflow files and accepts
their repaired versions
- Classifier preserves all original finding fields; tested routing, line
preservation, unknown rules, mixed production/test paths, malformed
input and empty reports
- Archived 148-finding report classifies successfully (not represented
as a fresh scan)
- Vendored checker byte-for-byte compared to
standards@2479cf769ed5f0481ccf64860a2ab954514c2b59
- `git diff --check` — pass
- No `uses:` reference, Actions lock, proof, licence, secret, baseline
severity, or gate strictness changed

## Known limits / pre-existing red checks

Main run 36150127750 already fails baseline validation with 62
unfiltered findings at `info`. The baseline was NOT absent/skipped; it
must not be broadened without evidence. The latest Security Scan has a
pre-existing startup failure. Other main workflows also have failures;
this PR does not claim to resolve all infrastructure.

This sandbox cannot download Debian toolchain packages or GitHub release
assets, so no fresh Hypatia scan or proof compilation is claimed. The
integration returns 403 for Actions secrets/code-scanning alerts and
cannot download Actions log blobs (job/annotation metadata is readable).
Owner's #310 decision was rotate, not delete; no credential change made.

## Merge blocker discovered on this PR

**All GitHub Actions runs are rejected by actor policy**, before
creating any jobs:

> Actor is not allowed to trigger Actions workflows. Workflow file:
'.github/workflows/workflow-linter.yml'.

Evidence:
https://github.com/hyperpolymath/echidna/actions/runs/36185037867 (actor
`arena-ai-coding-agent[bot]`). The main ruleset requires `scan /
gitleaks`, `scan / rust-secrets`, and `scan / shell-secrets`. An
authorized maintainer must permit this actor or trigger validation as an
allowed actor. These checks are not being bypassed. Local test success
must not be confused with CI success.

## Current disposition

Auto-merge (squash) is enabled, but the PR is **not merged** while
required Actions checks cannot run. Attempts to close the three
already-resolved issues #216, #175, and #196 were also rejected with
`Resource not accessible by integration` (confirmed via REST HTTP 403).
**No issue was closed; all 19 remain open.** The closure keywords above
are intended to close the four evidenced resolutions upon merge.
Remaining roadmap, proof, credential and upstream work stays open
intentionally.

The GitHub connection needs Issues write permission to manage closures,
and Actions policy must allow this actor (or validation must be run by
an authorized maintainer). No administrative bypass was attempted.

---------

Co-authored-by: hyperpolymath <6759885+hyperpolymath@users.noreply.github.com>
Co-authored-by: arena-agent <297053741+arena-agent@users.noreply.github.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant