Skip to content

feat(rsr): detect rule-table drift against the estate - #536

Merged
hyperpolymath merged 1 commit into
mainfrom
chore/rsr-drift-detector
Sep 18, 2026
Merged

hyperpolymath merged 1 commit into
mainfrom
chore/rsr-drift-detector

Conversation

@hyperpolymath

Copy link
Copy Markdown
Owner

The RSR rule table has rotted twice, and there is no deployed rhodibot to catch it. Adds an offline-first drift detector, a census builder, a pre-commit hook, and two Justfile recipes.

Shell only — Python is a banned language in this estate.

See the commit message for the parser-defensiveness and sample-census rationale.

The RSR rule table in bots/rhodibot/src/rsr.rs is the source of truth for
compliance, and it has rotted twice: once by requiring LICENSE.txt (0 of 269
repositories carried it) and once by holding the .well-known/security.txt
checks advisory after the migration they were waiting on had finished. There
is no deployed rhodibot anywhere in the estate, so nothing was going to catch
either one.

Adds:

* scripts/detect-rsr-drift.sh — parses the rule table from source and measures
  it against a census of the estate. Flags DEAD (no repository has the path),
  ROT (a Required check almost nothing satisfies) and PENDING-MIGRATION (the
  destination of an in-flight, source-declared migration window). Offline via
  --trees-dir; can also probe live check runs to establish whether any runner
  is attributed to the app.

  Parser is defensive: line 365 of rsr.rs is `},    BannedPattern {`, a record
  closer and opener sharing a line, and brace counting silently drops the
  .well-known/security.txt ban because of it. A self-check compares parsed
  record counts against literal openings and fails loudly, and severity tuples
  are shape-asserted because they are read positionally downstream.

  A census below MIN_CENSUS (50) is treated as a sample: flags are marked
  (sample), the migration-window verdict refuses to be drawn, and the run
  exits 2 (indeterminate) rather than 1. Concluding "window closed" from a
  sample would advise raising severities that most repositories would then
  fail.

* scripts/rsr-census.sh — builds the cached census the detector measures
  against. One API request per repository, atomic writes, reuse unless
  --refresh.

* bots/rhodibot/hooks/validate-rsr-drift.sh — pre-commit hook, runs the
  detector when src/rsr.rs changes. Without a census it validates the table
  itself and says the estate comparison was skipped.

* Justfile — validate-rsr-drift and refresh-rsr-census recipes.

Shell only: Python is a banned language in this estate.
@hyperpolymath
hyperpolymath merged commit 0ab0fd1 into main Sep 18, 2026
2 of 31 checks passed
@hyperpolymath
hyperpolymath deleted the chore/rsr-drift-detector branch September 18, 2026 15:44
@coderabbitai

coderabbitai Bot commented Sep 18, 2026

Copy link
Copy Markdown
Contributor

Review Change StackReview Change Stack

Note

Currently processing new changes in this PR. This may take a few minutes, please wait...

⚙️ Run configuration

Configuration used: Organization UI

Review profile: ASSERTIVE

Plan: Advanced

Run ID: 3e9efc9a-6e3a-428b-b16f-465cc37b26e2

📥 Commits

Reviewing files that changed from the base of the PR and between 8e741dc and 853105a.

📒 Files selected for processing (4)
  • Justfile
  • bots/rhodibot/hooks/validate-rsr-drift.sh
  • scripts/detect-rsr-drift.sh
  • scripts/rsr-census.sh
 _________________________________________________
< Because, even your code needs a second opinion. >
 -------------------------------------------------
  \
   \   (\__/)
       (•ㅅ•)
       /   づ
✨ Finishing Touches
📝 Generate docstrings
  • Commit to this branch
  • Create a new PR

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant