Skip to content

Arena/01a0dd51 hypatia - #863

Merged
hyperpolymath merged 7 commits into
mainfrom
arena/01a0dd51-hypatia
Sep 26, 2026
Merged

hyperpolymath merged 7 commits into
mainfrom
arena/01a0dd51-hypatia

Conversation

@hyperpolymath

Copy link
Copy Markdown
Owner

Summary

Closes #

Type of change

  • 🐛 Bug fix (non-breaking change that fixes an issue)
  • ✨ New feature (non-breaking change that adds functionality)
  • 💥 Breaking change (would change existing behaviour)
  • 🕳️ Soundness fix (fixes a checker/proof false-negative)
  • 📖 Documentation
  • 🧹 Refactor / tech debt (behaviour-preserving)
  • ⚡ Performance
  • 🔧 Build / CI / tooling

How has this been verified?

Checklist

  • My commits are signed (git commit -S).
  • I ran the project's own checks/tests locally and they pass.
  • New files carry the correct SPDX-License-Identifier (code/config MPL-2.0,
    prose CC-BY-SA-4.0); I did not relicense existing files.
  • Docs are updated, and no public claim now overstates what the code does.
  • I have not introduced a soundness hole (or I have flagged where I might have).

Notes for reviewers

hypatia and others added 5 commits September 26, 2026 14:11
…te sweeps

Two poisoned pins in this repository were left by the 2026-09-22 rollback,
which relabelled the pin without re-pinning it: github/codeql-action@1c5b6756
(annotated `# v4.38.0`) is the commit GitHub rejects at workflow start-up, so
CodeQL and the security scan die with zero jobs wherever it appears.
actions.lock already carries the correct b96794f0 pin; the workflows did not.
This makes the workflows agree with the lock.

Adds the estate machinery the September incident showed was missing:

  lib/rules/pin_integrity.ex     PI001-PI005 + mechanical substitution
  lib/rules/pr_automerge.ex      PA001-PA006 + decision manifests
  test/rules/*.exs               the incident's cases, as tests
  scripts/sweeps/estate-*.sh     pin repair, PR disposition, absence intake,
                                 estate statistics
  pr-automerge-policy.json       the single policy both readers consume
  docs/operations/estate-automerge.adoc   the handoff document

The rule the whole design turns on: pin identity is the SHA, never the inline
comment. A version-string check sees nothing wrong with `1c5b6756 # v4.38.0`,
which is exactly how the poison survived the first rollback and came back in
25 of the estate's 34 open dependabot PRs.

Not a self-approved change: rules, bot directives and this repository are
under the reflexivity guard (NA-005). Review before merge.

Co-authored-by: arena-agent <297053741+arena-agent@users.noreply.github.com>
The signals section could only ever report security weak points, because the
scan store holds panic-attack scans and nothing else. "Which repositories have
no tests at all" and "whose suites are failing" — two of the four things the
dashboard was asked to track — had no source and so reported `unavailable`
forever. They were measurable all along, from the repositories' own workflow
definitions and their runs on the default branch.

  * --checks: two API calls per active repository; a workflow counts as a
    test surface when its name or path matches (test|spec|ci|check|
    conformance|gate|audit|verify). Opt-in: ~9 minutes across 408 repos.
  * A failed call is recorded as unmeasured and excluded from the counts, so
    a rate limit can never read as "this project has no tests".
  * The newest completed run wins, sorted on created_at rather than trusting
    API ordering — this changed the answer for two repositories.
  * New top-level `paging` block: every threshold in stats_thresholds
    evaluated against the measured value, with `unavailable` for the metrics
    that have no producer (benches) instead of a silent `ok`.

Measured on 2026-09-26: 408 repositories, 350 with a test surface, 58 with
none, 120 whose most recent suite failed. Paging: 3 critical (open issues
887, failing tests, coverage empties), 2 warn (PR count, oldest PR age),
2 unavailable (the bench metrics).

Also adds an `estate-rules` CI job: the two new rule test files and a
structure gate over the four sweeps. Targeted rather than `mix test`, because
the repository has known-red test families unrelated to these rules and a
gate that is red on arrival gets ignored.

Co-authored-by: arena-agent <297053741+arena-agent@users.noreply.github.com>
An agent-pushed pull request gets no pull_request workflow runs at all: every
one fails at startup with zero jobs, including workflows the pull request
never touches. That is the same signature as the codeql-action denylist
failure, and the GitHub UI gives both the same explanation.

Established by elimination on #862: 18 of 18 failed, and they still failed
with an empty commit and with the workflow edits removed entirely. The same
wall appears on MetaManifold-WebUI#72 and oikosbot#107, both agent-pushed and
both merged on owner review.

This matters because the whole point of the estate machinery is that a robot
proposes pin repairs — and a robot's repair arrives wearing the costume of the
defect it removes. The rule of thumb, written into the document: if a workflow
the pull request does not touch fails at startup, the cause is not the pull
request's contents.

Co-authored-by: arena-agent <297053741+arena-agent@users.noreply.github.com>
The policy names docs/status/estate-stats.json as the producer path for the
private farm dashboard; this is that file, generated by
scripts/sweeps/estate-stats.sh with --checks, plus a README saying how to
regenerate it and what the headline numbers mean.

The numbers this run establishes, none of which were visible before:

  test surface   350 repositories with, 58 without, 120 whose most recent
                 suite failed (408 measured; a failed API call is recorded
                 as unmeasured and excluded, so a rate limit cannot read as
                 "this project has no tests")
  paging         3 critical (open issues 887, failing suites, coverage
                 empties), 2 warn (PR count 33, oldest PR 7 days),
                 2 unavailable (the bench metrics — no producer exists, and
                 unavailable is not zero)

Co-authored-by: arena-agent <297053741+arena-agent@users.noreply.github.com>
Repairing a pin does not stop the pin coming back, and the measurement says so:
133 poisoned files across 104 repositories; 337 repositories estate-wide carry
the dependabot shape that lets the bump through; of the 104 that already carry
the poison, 102 are exposed, 0 hold the action, and 31 hold it in the form
standards#1037 established is not honoured inside `groups:`.

The evidence that this is not theoretical: nexia-list merged the poisoned bump
in #107 on 2026-09-23 and still carries the poisoned commit today, annotated
with the number of the pull request that was supposed to have rolled it back.

estate-dependabot-hold.sh installs the hold that survives grouping —
`exclude-patterns` on the group, scoped to the action rather than holding the
whole group. Two added lines per file, nothing reordered, nothing reflowed.
Idempotent, and `--verify-only` exits non-zero while anything is still exposed,
so the same script is both the cure and the check that the cure is holding.

Verified against the estate: 102 of 102 patched files parse as YAML and carry
the exclusion; 2 repositories have no wildcard group to hang it on and are
reported for a human rather than edited blind. The sweep now proves a patch
parses before writing it — the first attempt silently emitted a column-0 entry
in one file out of 102, which is exactly the failure mode a sweep must not have.

Co-authored-by: arena-agent <297053741+arena-agent@users.noreply.github.com>
@coderabbitai

coderabbitai Bot commented Sep 26, 2026 •

Copy link
Copy Markdown
Contributor

Review in Change Stack →

Navigate logical layers of code changes, visualize relationships, and explore their blast radius.

Note

Currently processing new changes in this PR. This may take a few minutes, please wait...

⚙️ Run configuration

Configuration used: Organization UI

Review profile: ASSERTIVE

Plan: Advanced

Run ID: bdf48150-209c-4b94-aae0-aa93408d705f

📥 Commits

Reviewing files that changed from the base of the PR and between 4654d7a and 18d3592.

📒 Files selected for processing (3)
  • .github/workflows/tests.yml
  • docs/operations/estate-automerge.adoc
  • scripts/sweeps/estate-dependabot-hold.sh
 ______________________________________________________________________
< If it “compiles on my machine”, I will make your machine my machine. >
 ----------------------------------------------------------------------
  \
   \   (\__/)
       (•ㅅ•)
       /   づ
✨ Finishing Touches
📝 Generate docstrings

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

Signed-off-by: Jonathan D.A. Jewell <6759885+hyperpolymath@users.noreply.github.com>
@coderabbitai

coderabbitai Bot commented Sep 26, 2026 •

Copy link
Copy Markdown
Contributor

🤖 Completed: Generate docstrings for PR #863 — View commit d482553

@hyperpolymath
hyperpolymath merged commit de52a3d into main Sep 26, 2026
43 of 47 checks passed
@hyperpolymath
hyperpolymath deleted the arena/01a0dd51-hypatia branch September 26, 2026 15:33
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant