feat(rsr): detect rule-table drift against the estate - #536
Merged
Merged
Conversation
The RSR rule table in bots/rhodibot/src/rsr.rs is the source of truth for
compliance, and it has rotted twice: once by requiring LICENSE.txt (0 of 269
repositories carried it) and once by holding the .well-known/security.txt
checks advisory after the migration they were waiting on had finished. There
is no deployed rhodibot anywhere in the estate, so nothing was going to catch
either one.
Adds:
* scripts/detect-rsr-drift.sh — parses the rule table from source and measures
it against a census of the estate. Flags DEAD (no repository has the path),
ROT (a Required check almost nothing satisfies) and PENDING-MIGRATION (the
destination of an in-flight, source-declared migration window). Offline via
--trees-dir; can also probe live check runs to establish whether any runner
is attributed to the app.
Parser is defensive: line 365 of rsr.rs is `}, BannedPattern {`, a record
closer and opener sharing a line, and brace counting silently drops the
.well-known/security.txt ban because of it. A self-check compares parsed
record counts against literal openings and fails loudly, and severity tuples
are shape-asserted because they are read positionally downstream.
A census below MIN_CENSUS (50) is treated as a sample: flags are marked
(sample), the migration-window verdict refuses to be drawn, and the run
exits 2 (indeterminate) rather than 1. Concluding "window closed" from a
sample would advise raising severities that most repositories would then
fail.
* scripts/rsr-census.sh — builds the cached census the detector measures
against. One API request per repository, atomic writes, reuse unless
--refresh.
* bots/rhodibot/hooks/validate-rsr-drift.sh — pre-commit hook, runs the
detector when src/rsr.rs changes. Without a census it validates the table
itself and says the estate comparison was skipped.
* Justfile — validate-rsr-drift and refresh-rsr-census recipes.
Shell only: Python is a banned language in this estate.
Contributor
|
Note Currently processing new changes in this PR. This may take a few minutes, please wait... ⚙️ Run configurationConfiguration used: Organization UI Review profile: ASSERTIVE Plan: Advanced Run ID: 📒 Files selected for processing (4)
✨ Finishing Touches📝 Generate docstrings
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
The RSR rule table has rotted twice, and there is no deployed rhodibot to catch it. Adds an offline-first drift detector, a census builder, a pre-commit hook, and two Justfile recipes.
Shell only — Python is a banned language in this estate.
See the commit message for the parser-defensiveness and sample-census rationale.