Arena/01a0dd51 hypatia - #863
Merged
Merged
Conversation
…te sweeps Two poisoned pins in this repository were left by the 2026-09-22 rollback, which relabelled the pin without re-pinning it: github/codeql-action@1c5b6756 (annotated `# v4.38.0`) is the commit GitHub rejects at workflow start-up, so CodeQL and the security scan die with zero jobs wherever it appears. actions.lock already carries the correct b96794f0 pin; the workflows did not. This makes the workflows agree with the lock. Adds the estate machinery the September incident showed was missing: lib/rules/pin_integrity.ex PI001-PI005 + mechanical substitution lib/rules/pr_automerge.ex PA001-PA006 + decision manifests test/rules/*.exs the incident's cases, as tests scripts/sweeps/estate-*.sh pin repair, PR disposition, absence intake, estate statistics pr-automerge-policy.json the single policy both readers consume docs/operations/estate-automerge.adoc the handoff document The rule the whole design turns on: pin identity is the SHA, never the inline comment. A version-string check sees nothing wrong with `1c5b6756 # v4.38.0`, which is exactly how the poison survived the first rollback and came back in 25 of the estate's 34 open dependabot PRs. Not a self-approved change: rules, bot directives and this repository are under the reflexivity guard (NA-005). Review before merge. Co-authored-by: arena-agent <297053741+arena-agent@users.noreply.github.com>
The signals section could only ever report security weak points, because the
scan store holds panic-attack scans and nothing else. "Which repositories have
no tests at all" and "whose suites are failing" — two of the four things the
dashboard was asked to track — had no source and so reported `unavailable`
forever. They were measurable all along, from the repositories' own workflow
definitions and their runs on the default branch.
* --checks: two API calls per active repository; a workflow counts as a
test surface when its name or path matches (test|spec|ci|check|
conformance|gate|audit|verify). Opt-in: ~9 minutes across 408 repos.
* A failed call is recorded as unmeasured and excluded from the counts, so
a rate limit can never read as "this project has no tests".
* The newest completed run wins, sorted on created_at rather than trusting
API ordering — this changed the answer for two repositories.
* New top-level `paging` block: every threshold in stats_thresholds
evaluated against the measured value, with `unavailable` for the metrics
that have no producer (benches) instead of a silent `ok`.
Measured on 2026-09-26: 408 repositories, 350 with a test surface, 58 with
none, 120 whose most recent suite failed. Paging: 3 critical (open issues
887, failing tests, coverage empties), 2 warn (PR count, oldest PR age),
2 unavailable (the bench metrics).
Also adds an `estate-rules` CI job: the two new rule test files and a
structure gate over the four sweeps. Targeted rather than `mix test`, because
the repository has known-red test families unrelated to these rules and a
gate that is red on arrival gets ignored.
Co-authored-by: arena-agent <297053741+arena-agent@users.noreply.github.com>
An agent-pushed pull request gets no pull_request workflow runs at all: every one fails at startup with zero jobs, including workflows the pull request never touches. That is the same signature as the codeql-action denylist failure, and the GitHub UI gives both the same explanation. Established by elimination on #862: 18 of 18 failed, and they still failed with an empty commit and with the workflow edits removed entirely. The same wall appears on MetaManifold-WebUI#72 and oikosbot#107, both agent-pushed and both merged on owner review. This matters because the whole point of the estate machinery is that a robot proposes pin repairs — and a robot's repair arrives wearing the costume of the defect it removes. The rule of thumb, written into the document: if a workflow the pull request does not touch fails at startup, the cause is not the pull request's contents. Co-authored-by: arena-agent <297053741+arena-agent@users.noreply.github.com>
The policy names docs/status/estate-stats.json as the producer path for the
private farm dashboard; this is that file, generated by
scripts/sweeps/estate-stats.sh with --checks, plus a README saying how to
regenerate it and what the headline numbers mean.
The numbers this run establishes, none of which were visible before:
test surface 350 repositories with, 58 without, 120 whose most recent
suite failed (408 measured; a failed API call is recorded
as unmeasured and excluded, so a rate limit cannot read as
"this project has no tests")
paging 3 critical (open issues 887, failing suites, coverage
empties), 2 warn (PR count 33, oldest PR 7 days),
2 unavailable (the bench metrics — no producer exists, and
unavailable is not zero)
Co-authored-by: arena-agent <297053741+arena-agent@users.noreply.github.com>
Repairing a pin does not stop the pin coming back, and the measurement says so: 133 poisoned files across 104 repositories; 337 repositories estate-wide carry the dependabot shape that lets the bump through; of the 104 that already carry the poison, 102 are exposed, 0 hold the action, and 31 hold it in the form standards#1037 established is not honoured inside `groups:`. The evidence that this is not theoretical: nexia-list merged the poisoned bump in #107 on 2026-09-23 and still carries the poisoned commit today, annotated with the number of the pull request that was supposed to have rolled it back. estate-dependabot-hold.sh installs the hold that survives grouping — `exclude-patterns` on the group, scoped to the action rather than holding the whole group. Two added lines per file, nothing reordered, nothing reflowed. Idempotent, and `--verify-only` exits non-zero while anything is still exposed, so the same script is both the cure and the check that the cure is holding. Verified against the estate: 102 of 102 patched files parse as YAML and carry the exclusion; 2 repositories have no wildcard group to hang it on and are reported for a human rather than edited blind. The sweep now proves a patch parses before writing it — the first attempt silently emitted a column-0 entry in one file out of 102, which is exactly the failure mode a sweep must not have. Co-authored-by: arena-agent <297053741+arena-agent@users.noreply.github.com>
Contributor
|
Navigate logical layers of code changes, visualize relationships, and explore their blast radius. Note Currently processing new changes in this PR. This may take a few minutes, please wait... ⚙️ Run configurationConfiguration used: Organization UI Review profile: ASSERTIVE Plan: Advanced Run ID: 📒 Files selected for processing (3)
✨ Finishing Touches📝 Generate docstrings
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
Signed-off-by: Jonathan D.A. Jewell <6759885+hyperpolymath@users.noreply.github.com>
Contributor
|
🤖 Completed: Generate docstrings for PR #863 — View commit |
5 tasks
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
Closes #
Type of change
How has this been verified?
Checklist
git commit -S).SPDX-License-Identifier(code/configMPL-2.0,prose
CC-BY-SA-4.0); I did not relicense existing files.Notes for reviewers