Repository navigation
fix(ci): cicd-suite 4c772eb2, rust-ci pin, Justfile and workflow hygiene - #119
Merged
Merged
Conversation
- main-estate-audit.yml: bump all cicd-suite gate pins 5a10b72e -> 4c772eb2 (cicd-suite main). At 5a10b72e the Required Files Gate runs `functional_lines=$(grep -vE ... | wc -l)` under the harness's `bash -e -o pipefail`; on this repo's comment-only CODEOWNERS grep exits 1 and the step dies with no message after "found toolchain". cicd-suite fa71ac2a (#32) fixed it with `grep -c ... || true`. actions.lock entry and dependency record moved to the same SHA. - main-estate-audit.yml: add the SPDX header and a top-level `permissions: contents: read` the governance workflow linter requires. - Justfile: indent the column-0 shell lines inside the doctor, heal and help-me shebang recipes. A column-0 line ends a just recipe, so the file did not parse ("unknown start of token '-'" at 72:12) and the Recipes Set gate, which the Required Files gate had been masking, failed. - rust-ci.yml: bump rust-ci-reusable d135b05b -> standards main eafcfbb5, which passes `toolchain: stable` to the SHA-pinned dtolnay/rust-toolchain (it failed: "'toolchain' is a required input"). - benches: use std::hint::black_box; criterion::black_box is deprecated and clippy -D warnings rejects it (12 errors). Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01X3hgXxWm6umMgZkjYyHnnm
|
Note Currently processing new changes in this PR. This may take a few minutes, please wait... ⚙️ Run configuration
⛔ Files ignored due to path filters (1)
📒 Files selected for processing (4)
✨ Finishing Touches📝 Generate docstrings
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
| @@ -1,3 +1,4 @@ | |||
| # SPDX-License-Identifier: MPL-2.0 | |||
|
Add Carrot credits or activate Agent usage billing to use Autopilot |
6 of 13 tasks
hyperpolymath
added a commit
that referenced
this pull request
Oct 6, 2026
…t_minutes) (#120) ## Summary Hypatia's workflow audit opened a code-scanning thread on #119 (alert 168, `missing_timeout_minutes`): the `estate-audit` job in `main-estate-audit.yml` declares no `timeout-minutes`, so it inherits GitHub's 6-hour default. A stuck fetch or a runner hang could burn that much budget. This PR bounds the job at 10 minutes. The job runs two quick gates, so 10 minutes is ample. The fix was made on #119's branch after #119 had already merged at `a87fa8a`, so it never reached `main`. This PR carries it onto `main` (`10819d6`) by itself. ## Type of change - [ ] 🐛 Bug fix: no runtime code changed. - [ ] ✨ New feature: N/A - [ ] 💥 Breaking change: N/A - [ ] 🕳️ Soundness fix: N/A - [ ] 📖 Documentation: N/A - [ ] 🧹 Refactor / tech debt: N/A - [ ] ⚡ Performance: N/A - [x] 🔧 Build / CI / tooling: one `timeout-minutes` line. ## 📌 New pins Head SHA: **`a42c00647083691f902d7897b6ca90e9617f2460`** None. No `uses:` ref, `actions.lock` entry, lockfile or container digest is added or changed. ## How has this been verified? - `git diff origin/main --stat`: one file, one line added (`timeout-minutes: 10` under `estate-audit`). - `actionlint .github/workflows/main-estate-audit.yml`: rc=0. - **Not yet verified:** a CI run at this head, and the code-scanning alert closing. Hypatia re-scans on push, so alert 168 should close once this lands on `main`. ## Checklist - [x] My commits are **signed** (`git commit -S`): `a42c006` shows `G`. - [x] I ran the project's own checks: actionlint, as above. No test covers this workflow. - [x] New files: none. The workflow keeps its existing SPDX header. - [x] Docs: no user-facing change. - [x] I have not introduced a soundness hole. No gate is weakened: the job runs the same steps, only with an upper bound on its runtime. ## Notes for reviewers - The pushed branch `fix/redci-cleanup` (at `ec166e9`) was re-created by mistake after #119's merge and can be deleted. This PR supersedes it. 🤖 Generated with [Claude Code](https://claude.com/claude-code) https://claude.ai/code/session_01X3hgXxWm6umMgZkjYyHnnm Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
This PR clears the three reds on
main(54e02de), plus the reds hidden behind them.5a10b72erunsfunctional_lines=$(grep -vE … "$f" | wc -l)in its Required Files Gate. The harness shell isbash -e -o pipefail, and this repo's CODEOWNERS contains only comments, sogrepexits 1 and the step aborts without a message. cicd-suite fixed this infa71ac2a(chore(deps): bump the cargo group with 4 updates #32), and this PR moves every cicd-suite pin to cicd-suite main4c772eb2. Once that gate ran, it exposed a second, masked failure in the Recipes Set gate: theJustfiledid not parse (unknown start of token '-' Justfile:72:12) because lines in its shebang recipes started at column 0. Those lines are now indented.main-estate-audit.ymlhad no SPDX header and no top-levelpermissions:. Both are added, withcontents: read.rust-ci-reusable@d135b05bcalleddtolnay/rust-toolchain, pinned by SHA, without the requiredtoolchaininput. This PR bumps it to standards maineafcfbb5, which passestoolchain: stable. That exposed 12 clippydeprecatederrors forcriterion::black_box, so the bench now importsstd::hint::black_box.Type of change
📌 New pins
Head SHA:
a87fa8ad5cef7074136beb24f767cbb5c91da0cdhyperpolymath/cicd-suite/actions/*@4c772eb235b04455307d5c03cbbc4f45130f7f0f, all refs inmain-estate-audit.yml(was5a10b72e…). This is cicd-suitemain.actions.lock:hyperpolymath/cicd-suite@4c772eb2…replaces the5a10b72eworkflow entry and dependency, withcommit: sha1-4c772eb235b04455307d5c03cbbc4f45130f7f0f.deed-ecosystem@f9d999b6andk9-ecosystem@2155aa26entries are unchanged; 4c772eb2 still uses them.hyperpolymath/standards/.github/workflows/rust-ci-reusable.yml@eafcfbb5933dde8b42fdbd61483794bb75fb4c97(wasd135b05b…).mainand a commit.dtolnay/rust-toolchain@7e38f4b4.Reds (decisive log line on
main)found toolchain -> .mise.toml, then##[error]Process completed with exit code 1.Reproduced locally: rc=1 under-e -o pipefail, rc=0 withoutJustfile does not parse: error: unknown start of token '-' Justfile:72:12ERROR: .github/workflows/main-estate-audit.yml has no SPDX-License-Identifier;missing top-level 'permissions:''toolchain' is a required inputuse of deprecated function 'criterion::black_box'How has this been verified?
4c772eb2, each run underbash -e -o pipefail:No K9 files found).just --listparses andjust doctorruns.stabletoolchain:cargo fmt --checkrc=0.cargo check --locked --all-targetsrc=0.cargo clippy --locked --all-targets -- -D warningsrc=0.cargo test --locked --all-targets: all ok.cargo test --features git-integration: ok.gh actions-lock --verifyrc=0. Positive control: putting the old SHA back in the lock gives rc=1.check-actions-lock-gate.sh: verified.actionlint: clean.Checklist
git commit -S);%G?=G.MPL-2.0SPDX header tomain-estate-audit.yml, which had none; this matches the repo's existing workflow headers. Nothing was relicensed.Notes for reviewers
actions.lock. It movescodeql.ymlfromgithub/codeql-action@b96794f0to2892aa5ewithout touching the lock, which still lists@b96794f0…. The# v3comment would also go stale. The PR itself was not touched.governance.ymlstill pins092dedad. It was not red.🤖 Generated with Claude Code
https://claude.ai/code/session_01X3hgXxWm6umMgZkjYyHnnm