You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
{{ message }}
Repository navigation
Commit d5f3476
Browse filesBrowse the repository at this point in the historyBrowse files
chore(echidnabot): bump vendored copy to faeb280 (#168, #169) (#603)
## Summary
Re-pins the vendored `bots/echidnabot` copy to
`hyperpolymath/echidnabot` `main` @ `faeb2808` (was `bf2c0ffc`, 2
commits behind), using the repo's own `scripts/sync-vendored-bot.sh
echidnabot --sync --rev faeb2808efcf1fc8149afc5811182cb14bf79091`.
It brings in:
- **hyperpolymath/echidnabot#168:** echidna integration, the
prove-result contract, UUID minting (`src/ids.rs`: v7 records, v8
content ids) and a CI repair.
- **hyperpolymath/echidnabot#169:** the `submitProofObligation` GraphQL
mutation. hypatia's FleetDispatcher and LearningScheduler send this
contract (hyperpolymath/hypatia#911). Until this bump lands, a
fleet-deployed echidnabot rejects every hypatia dispatch as an unknown
field.
Scope:
- Only `bots/echidnabot/**` changes (34 files, +2065/−241).
- `FLEET-SYNC.json` changes `rev` only.
- 0 files deleted, so the Repo Integrity Guard needs no
`[mass-delete-ok]`.
- 4 files added: `migrations/20261008000001_proof_obligations.sql`,
`src/dispatcher/prove_result.rs`, `src/ids.rs`, `tests/live_echidna.rs`.
No issue to close. This is the follow-up to
hyperpolymath/echidnabot#169.
## Type of change
- [ ] 🐛 Bug fix — not a fix in this repo; it re-pins vendored upstream
code.
- [ ] ✨ New feature — the feature (`submitProofObligation`) was built
and reviewed upstream in hyperpolymath/echidnabot#169; this PR only
re-vendors it.
- [ ] 💥 Breaking change — no existing fleet behaviour changes. The
upstream GraphQL change is additive.
- [ ] 🕳️ Soundness fix — not applicable.
- [ ] 📖 Documentation — no fleet docs change. The vendored copy carries
no `docs/` (not in `include`).
- [ ] 🧹 Refactor / tech debt — not applicable.
- [ ] ⚡ Performance — not applicable.
- [x] 🔧 Build / CI / tooling — a vendored-dependency pin bump
(`FLEET-SYNC.json` rev plus the synced tree).
## 📌 New pins
- **PR head SHA: `cdfa0b813f44a46be8dd149edd02d32f65cbe1d8`**
- **`bots/echidnabot/FLEET-SYNC.json` `rev`:
`bf2c0ffc9f5faee3c2072b516855a045400ac247` →
`faeb2808efcf1fc8149afc5811182cb14bf79091`** (`hyperpolymath/echidnabot`
`main` head, the signed squash merge of #169).
- Vendored `bots/echidnabot/Cargo.lock` records, as resolved upstream:
- **added `echidna-core-spark` 0.1.0**, git
`https://github.com/hyperpolymath/echidna` **rev
`b761b3a832981be51d4e88076ef1b90fe5037e9c`**
- **added `serde_json_canonicalizer` 0.3.2**
- **added `ryu-js` 1.0.3**
- **`async-trait` 0.1.89 → 0.1.92**
- **`rustls` 0.23.40 → 0.23.45**
- **`rustls-webpki` 0.103.13 → 0.103.15**
- No action `uses:` SHAs, `actions.lock` entries or container digests
change.
## How has this been verified?
All commands were run in the PR worktree at the head above:
- `scripts/sync-vendored-bot.sh echidnabot --check` printed
"bots/echidnabot matches
https://github.com/hyperpolymath/echidnabot@faeb2808… (79 entries)" and
exited **0**.
- `bash scripts/tests/sync-vendored-bot.sh` reported **21 passed, 0
failed**.
- `jq -cS . bots/echidnabot/FLEET-SYNC.json` is byte-identical to the
file, so the lock stays in canonical form.
- `git diff --cached --name-only | grep -v '^bots/echidnabot/'` printed
nothing. `git diff --cached --diff-filter=D` lists 0 files.
- `git log -1 --show-signature` reports a good ED25519 signature, as
`required_signatures` on `main` needs.
- **Not built here.** Fleet CI does not compile `bots/echidnabot`:
`rust.yml` builds robot-repo-automaton, shared-context, dashboard and
rhodibot; CodeQL is `actions` / `build-mode: none`. The build evidence
for this tree is therefore upstream CI on `faeb2808`, which is green
apart from skipped deploy/automerge/coverage jobs. `squabble
verify-satisfied hyperpolymath/echidnabot 169` returned `done: true`.
## Checklist
- [x] My commits are **signed**: SSH ED25519 key, verified locally with
`git log --show-signature`.
- [x] I ran the project's own checks/tests locally and they pass: the
drift `--check` and the sync script's planted-control suite, as above.
- [x] New files carry the correct `SPDX-License-Identifier`: all 4 added
vendored files are `MPL-2.0`, as written upstream. Nothing was
relicensed.
- [x] Docs are updated, and no public claim now overstates what the code
does. No fleet doc describes the vendored version. Upstream's `api.adoc`
says `submitProofObligation` stores an obligation and does not prove it
(`status` is always `PENDING`).
- [x] I have not introduced a soundness hole. This is a byte-for-byte
re-vendor of reviewed upstream code, and the drift gate enforces that.
## Notes for reviewers
- `.github/dependabot.yml` deliberately leaves out `/bots/echidnabot`.
Dependency bumps for it land upstream and arrive here by re-pinning, as
in this PR.
- The new git dependency `echidna-core-spark` is pinned by full rev in
both the vendored `Cargo.toml` and `Cargo.lock`.
### Deferred red checks (none required; all also red on `main` @
`72970698`)
This PR touches no workflow and no `actions.lock`. Each red below fails
identically on `main`:
- `actions.lock is in sync with the workflow YAML`: deferred to #604.
#595 bumped `smtp-notify-action` to v0.5.0 without relocking.
- `governance / Actions lockfile verify`: deferred to #604, same cause.
- `scorecard / Run Scorecard PR`: deferred to #604, same cause.
Reconciliation fails on `push-email-notify.yml`.
- `Codeac analyze results` (legacy status): deferred to #590. The
service cannot analyse the repo.
🤖 Generated with [Claude Code](https://claude.com/claude-code)
https://claude.ai/code/session_015bTuGfwCcvjrmNFejydTML
Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com>
0 commit comments