Skip to content

fix(ci): cicd-suite 4c772eb2, rust-ci pin, Justfile and workflow hygiene - #119

Merged
hyperpolymath merged 1 commit into
mainfrom
fix/redci-cleanup
Oct 6, 2026
Merged

hyperpolymath merged 1 commit into
mainfrom
fix/redci-cleanup

Conversation

@hyperpolymath

@hyperpolymath hyperpolymath commented Oct 6, 2026 •

Copy link
Copy Markdown
Owner

Summary

This PR clears the three reds on main (54e02de), plus the reds hidden behind them.

  1. estate-audit printed no reason. cicd-suite 5a10b72e runs functional_lines=$(grep -vE … "$f" | wc -l) in its Required Files Gate. The harness shell is bash -e -o pipefail, and this repo's CODEOWNERS contains only comments, so grep exits 1 and the step aborts without a message. cicd-suite fixed this in fa71ac2a (chore(deps): bump the cargo group with 4 updates #32), and this PR moves every cicd-suite pin to cicd-suite main 4c772eb2. Once that gate ran, it exposed a second, masked failure in the Recipes Set gate: the Justfile did not parse (unknown start of token '-' Justfile:72:12) because lines in its shebang recipes started at column 0. Those lines are now indented.
  2. Workflow security linter. main-estate-audit.yml had no SPDX header and no top-level permissions:. Both are added, with contents: read.
  3. rust-ci. rust-ci-reusable@d135b05b called dtolnay/rust-toolchain, pinned by SHA, without the required toolchain input. This PR bumps it to standards main eafcfbb5, which passes toolchain: stable. That exposed 12 clippy deprecated errors for criterion::black_box, so the bench now imports std::hint::black_box.

Type of change

  • 🐛 Bug fix: no runtime code changed.
  • ✨ New feature: N/A
  • 💥 Breaking change: N/A
  • 🕳️ Soundness fix: N/A
  • 📖 Documentation: N/A
  • 🧹 Refactor / tech debt (behaviour-preserving): the bench import and Justfile indentation.
  • ⚡ Performance: N/A
  • 🔧 Build / CI / tooling

📌 New pins

Head SHA: a87fa8ad5cef7074136beb24f767cbb5c91da0cd

  • hyperpolymath/cicd-suite/actions/*@4c772eb235b04455307d5c03cbbc4f45130f7f0f, all refs in main-estate-audit.yml (was 5a10b72e…). This is cicd-suite main.
  • actions.lock:
    • hyperpolymath/cicd-suite@4c772eb2… replaces the 5a10b72e workflow entry and dependency, with commit: sha1-4c772eb235b04455307d5c03cbbc4f45130f7f0f.
    • The transitive deed-ecosystem@f9d999b6 and k9-ecosystem@2155aa26 entries are unchanged; 4c772eb2 still uses them.
  • hyperpolymath/standards/.github/workflows/rust-ci-reusable.yml@eafcfbb5933dde8b42fdbd61483794bb75fb4c97 (was d135b05b…).
    • This is standards main and a commit.
    • The standards lock at that commit covers dtolnay/rust-toolchain@7e38f4b4.

Reds (decisive log line on main)

Check Decisive line Outcome
estate-audit (job 111187403025) output stops after found toolchain -> .mise.toml, then ##[error]Process completed with exit code 1. Reproduced locally: rc=1 under -e -o pipefail, rc=0 without fixed (central fix, pin bump)
estate-audit / Recipes Set, previously masked Justfile does not parse: error: unknown start of token '-' Justfile:72:12 fixed
Workflow security linter (111187404489) ERROR: .github/workflows/main-estate-audit.yml has no SPDX-License-Identifier; missing top-level 'permissions:' fixed
rust-ci (111187500676) 'toolchain' is a required input fixed (pin bump)
rust-ci clippy, previously masked 12× use of deprecated function 'criterion::black_box' fixed

How has this been verified?

  • cicd-suite composite steps at 4c772eb2, each run under bash -e -o pipefail:
    • All gates rc=0.
    • The deed and k9 validate-actions also rc=0 (No K9 files found).
    • just --list parses and just doctor runs.
  • Rust, with the stable toolchain:
    • cargo fmt --check rc=0.
    • cargo check --locked --all-targets rc=0.
    • cargo clippy --locked --all-targets -- -D warnings rc=0.
    • cargo test --locked --all-targets: all ok.
    • cargo test --features git-integration: ok.
  • gh actions-lock --verify rc=0. Positive control: putting the old SHA back in the lock gives rc=1.
  • Standards gates:
    • Duplicate keys: 14 files clean.
    • SPDX + permissions: OK.
    • Pins resolve: 10.
    • Allowed actions: 40 refs, 0 uncovered.
    • check-actions-lock-gate.sh: verified.
  • actionlint: clean.

Checklist

  • My commits are signed (git commit -S); %G? = G.
  • I ran the project's own checks and tests locally, as listed above, and they pass.
  • New files: none. I added the MPL-2.0 SPDX header to main-estate-audit.yml, which had none; this matches the repo's existing workflow headers. Nothing was relicensed.
  • Docs: no user-facing change.
  • I have not introduced a soundness hole. No gate was weakened: the estate-audit pins moved to the commit that contains the upstream fix.

Notes for reviewers

  • Dependabot chore(deps): bump the actions group with 3 updates #118 will desync actions.lock. It moves codeql.yml from github/codeql-action@b96794f0 to 2892aa5e without touching the lock, which still lists @b96794f0…. The # v3 comment would also go stale. The PR itself was not touched.
  • governance.yml still pins 092dedad. It was not red.

🤖 Generated with Claude Code

https://claude.ai/code/session_01X3hgXxWm6umMgZkjYyHnnm

- main-estate-audit.yml: bump all cicd-suite gate pins 5a10b72e ->
  4c772eb2 (cicd-suite main). At 5a10b72e the Required Files Gate runs
  `functional_lines=$(grep -vE ... | wc -l)` under the harness's
  `bash -e -o pipefail`; on this repo's comment-only CODEOWNERS grep
  exits 1 and the step dies with no message after "found toolchain".
  cicd-suite fa71ac2a (#32) fixed it with `grep -c ... || true`.
  actions.lock entry and dependency record moved to the same SHA.
- main-estate-audit.yml: add the SPDX header and a top-level
  `permissions: contents: read` the governance workflow linter requires.
- Justfile: indent the column-0 shell lines inside the doctor, heal and
  help-me shebang recipes. A column-0 line ends a just recipe, so the
  file did not parse ("unknown start of token '-'" at 72:12) and the
  Recipes Set gate, which the Required Files gate had been masking,
  failed.
- rust-ci.yml: bump rust-ci-reusable d135b05b -> standards main
  eafcfbb5, which passes `toolchain: stable` to the SHA-pinned
  dtolnay/rust-toolchain (it failed: "'toolchain' is a required input").
- benches: use std::hint::black_box; criterion::black_box is deprecated
  and clippy -D warnings rejects it (12 errors).

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01X3hgXxWm6umMgZkjYyHnnm
@coderabbitai

coderabbitai Bot commented Oct 6, 2026 •

Copy link
Copy Markdown

Review in Change Stack →

Note

Currently processing new changes in this PR. This may take a few minutes, please wait...

⚙️ Run configuration
  • Configuration used: Organization UI
  • Review profile: ASSERTIVE
  • Plan: Advanced
  • Run ID: 547af926-ab2b-4908-b477-16a687d25cf5
📥 Commits

Reviewing files that changed from the base of the PR and between 54e02de and a87fa8a.

⛔ Files ignored due to path filters (1)
  • .github/workflows/actions.lock is excluded by !**/*.lock
📒 Files selected for processing (4)
  • .github/workflows/main-estate-audit.yml
  • .github/workflows/rust-ci.yml
  • Justfile
  • benches/git_reticulator_bench.rs
 ________________________________________________
< Squeezing intelligence out of LLMs since 2023. >
 ------------------------------------------------
  \
   \   (\__/)
       (•ㅅ•)
       /   づ
✨ Finishing Touches
📝 Generate docstrings
  • Autopilot · Keep fixing CodeRabbit findings and required CI, and resolving merge conflicts

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@@ -1,3 +1,4 @@
# SPDX-License-Identifier: MPL-2.0
@coderabbitai

coderabbitai Bot commented Oct 6, 2026 •

Copy link
Copy Markdown

@coderabbitai

coderabbitai Bot commented Oct 6, 2026

Copy link
Copy Markdown

Add Carrot credits or activate Agent usage billing to use Autopilot

@hyperpolymath
hyperpolymath merged commit 10819d6 into main Oct 6, 2026
35 checks passed
@hyperpolymath
hyperpolymath deleted the fix/redci-cleanup branch October 6, 2026 21:13
hyperpolymath added a commit that referenced this pull request Oct 6, 2026
…t_minutes) (#120)

## Summary

Hypatia's workflow audit opened a code-scanning thread on #119 (alert
168, `missing_timeout_minutes`): the `estate-audit` job in
`main-estate-audit.yml` declares no `timeout-minutes`, so it inherits
GitHub's 6-hour default. A stuck fetch or a runner hang could burn that
much budget. This PR bounds the job at 10 minutes. The job runs two
quick gates, so 10 minutes is ample.

The fix was made on #119's branch after #119 had already merged at
`a87fa8a`, so it never reached `main`. This PR carries it onto `main`
(`10819d6`) by itself.

## Type of change

- [ ] 🐛 Bug fix: no runtime code changed.
- [ ] ✨ New feature: N/A
- [ ] 💥 Breaking change: N/A
- [ ] 🕳️ Soundness fix: N/A
- [ ] 📖 Documentation: N/A
- [ ] 🧹 Refactor / tech debt: N/A
- [ ] ⚡ Performance: N/A
- [x] 🔧 Build / CI / tooling: one `timeout-minutes` line.

## 📌 New pins

Head SHA: **`a42c00647083691f902d7897b6ca90e9617f2460`**

None. No `uses:` ref, `actions.lock` entry, lockfile or container digest
is added or changed.

## How has this been verified?

- `git diff origin/main --stat`: one file, one line added
(`timeout-minutes: 10` under `estate-audit`).
- `actionlint .github/workflows/main-estate-audit.yml`: rc=0.
- **Not yet verified:** a CI run at this head, and the code-scanning
alert closing. Hypatia re-scans on push, so alert 168 should close once
this lands on `main`.

## Checklist

- [x] My commits are **signed** (`git commit -S`): `a42c006` shows `G`.
- [x] I ran the project's own checks: actionlint, as above. No test
covers this workflow.
- [x] New files: none. The workflow keeps its existing SPDX header.
- [x] Docs: no user-facing change.
- [x] I have not introduced a soundness hole. No gate is weakened: the
job runs the same steps, only with an upper bound on its runtime.

## Notes for reviewers

- The pushed branch `fix/redci-cleanup` (at `ec166e9`) was re-created by
mistake after #119's merge and can be deleted. This PR supersedes it.

🤖 Generated with [Claude Code](https://claude.com/claude-code)

https://claude.ai/code/session_01X3hgXxWm6umMgZkjYyHnnm

Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants