Skip to content

Address the open issue set: CI truth, proof gates, scanner precision, toolchain policy (21 issues fixed, 3 filed) - #867

Merged
hyperpolymath merged 1 commit into
mainfrom
arena/01a0df1a-hypatia
Sep 27, 2026
Merged

hyperpolymath merged 1 commit into
mainfrom
arena/01a0df1a-hypatia

Conversation

@arena-ai-coding-agent

Copy link
Copy Markdown
Contributor

Addresses the open issue set of hyperpolymath/hypatia in line with rsr-template-repo and standards, plus items needing immediate attention. One commit (30e6d14, five logical waves), 21 issues fixed/resolved, 3 new issues filed from findings, everything else triaged below.

Note on issue comments: the GitHub integration used here can create issues but is refused issue comment / issue close (HTTP 403 "Resource not accessible by integration"). Per-issue dispositions live in this body instead; Closes #… keywords below will close the resolved set on merge.

Wave 1 — CI truth

Wave 2 — runtime safety

Wave 3 — proofs

  • verify-proofs.yml installs Idris2 to PREFIX=/usr/local but the binary reads --libdir under ~/.idris2 #820 — verify-proofs.yml + abi-codegen-drift.yml: single-prefix Idris2 bootstrap (make install PREFIX="$HOME/.idris2", no sudo), cache key -3, PATH export, measurement step printing idris2 --prefix/--libdir + support-lib layout. The abi repair step is retained with a sequencing comment: delete it only after a green -3 run prints "support installation already complete".
  • verification/PROOF-STATUS.adoc is stale: wrong path, wrong LOC, wrong proofs #816 — scripts/check-proof-status.sh (new): PROOF-STATUS rows named in docs must exist; Property identifiers must match. Green on tree ("files named 27, identifiers checked 7, mismatches 0"); mutants killed both directions (renamed identifier → red; doc pointing at nonexistent file → red); proof-status job in verify-proofs.yml.
  • docs: AFFIRMATION.adoc overclaims 'zero escape hatches'; proof-debt.md cites a nonexistent script and CI job #831 — scripts/check-trusted-base.sh (new): zero escape hatches outside test/soundness/fixtures/. Tree measured 2026-09-26 (marker files = RuleEngine.idr comments + 6 fixtures; 0 assert_total/postulate/%hint/native_decide/admit in code). Run: "fixture=19 allowed=1 comment=1 debt=0"; mutant killed (believe_me planted in verify/src/PipelineState.idr → DEBT red). docs/proof-debt.adoc counts re-derived (6, obj_magic was missing); AFFIRMATION.adoc claim scoped "outside test/soundness/fixtures/". check-trusted-base job in verify-proofs.yml (5 jobs now: type-check, lake-build, tlc, proof-status, check-trusted-base).

Wave 4 — toolchain & policy

  • build: mise.toml provisions banned runtimes (python, denojs) and a Python-only toolchain #832 — mise.toml no longer provisions python/denojs or the Python-only toolchain (pip/black/isort/ruff/pytest, PYTHON* env); language-blockers.yml now enforces LANGUAGE-POLICY (Deno manifests banned; TS/ReScript sources banned — whole-tree, measured 0; banned runtimes cannot silently return to mise.toml) instead of its inverse ("Use Deno instead"). The old TS gate was structurally broken (depth-1 checkout vs git diff HEAD~1) and inverted (it blocked bun.lockb telling you to use Deno). Checks green; mutant (planted python = "latest") caught.
  • ci(pins): dtolnay/rust-toolchain@v1 is a mutable tag at 22 sites — decide the pinning mechanism, then apply it uniformly #825 — pinning decision recorded in docs/governance/ACTIONS-PINNING.adoc (linked from README): actions.lock is the pinning mechanism for symbolic refs (option (b)) — no partial SHA sweep. Evidence the lock catches a moved ref is in DEBT-REGISTER CI-1's own runner log ("Lockfile pin … does not match ref"). Residual: one deliberate retag-mutant drill.
  • Mirror to Git Forges: 3 of 7 forges broken — Gitea's host variable expands to EMPTY, Disroot/Bitbucket keys rejected #845 — mirror.yml pins standards' mirror-reusable.yml at 2479cf76, past the Gitea empty-host fault (host/fingerprint vars now asserted non-empty and named, SSH host keys fingerprint-verified, per-forge skip notices). New Mirror coverage job reports the denominator (N of 7 configured). Disroot/Bitbucket deploy-key registration remains owner action (legible via skip notices). Residual: verify-a-mirror-landed-by-remote-SHA (AC5) needs per-forge remote read.
  • Also: two broken README links fixed (DEBT-REGISTER.md → .adoc; PALIMPSEST.adoc now points at hyperpolymath/standards where the file lives).

Wave 5 — scanner precision & docs

New issues filed (found during this work, not merge blockers)

Triage of the remaining open set

# disposition
358, 359 panic-attack fact-source / higher-order rules — design work, unchanged; no blocker found this pass
361, 363, 366 #333 cohort detector ideas — additive rules; valid backlog
367 M20 SNIF parser port — blocked on its upstream unlock (hypatia#294), untouched
369 code-scanning→dispatch loop RFC — the security-status aggregator pattern from #847 is a building block
421 reusable_workflow_sha_bump_needs_propagation wiring — real; registry+dispatch wiring still missing
447–449 taxonomy/self-model/planner RFCs — out of scope for this pass
463–466 estate ops queues (billing wall, red CI, licence PRs, PR stewardship) — owner-facing, unchanged
470, 471, 473 ruleset audits — ABI-Codegen-Drift is the only active hypatia ruleset (verified); estate-wide Base ruleset audit still open
483 doc + contractile currency — #636/#695/#864 are slices of it
485 rsr-template↔standards divergence audit — needs owner/consistency-plugin access
486 neural-convergence proofs — needs network+Mathlib; out of pass
519 Hypatia check must report on every PR — related to the #847 aggregator design; still open
520 stale standards reusable pins estate-wide — hypatia's own mirror.yml pin bumped to 2479cf76 in this PR; the estate sweep remains (and check-lockfile-drift.sh mode 4 is the detector)
523, 554, 556 scanner deployment/verification ops — unchanged
567 cicd-squabbler feedback channel — design, unchanged
582 ScorecardReconciler scheduling — unchanged
585 ruleset gate-deadlock (structurally-unsatisfiable required checks) — owner/ruleset-admin action; the accept-or-delete ruling applies
605 B-SHAPIN + actions_policy.ex — valid detection backlog
638 allowlist heal-then-wipe oscillation — ops, unchanged
683 CI-health estate failure-class report — ops cadence, unchanged
676 kept open — hypatia side fixed (see above); the producer-side half is #866
845 kept open — Gitea empty-host fault fixed via pin bump; Disroot/Bitbucket key registration (owner) + remote-SHA verification (AC5) remain

Evidence & limits

  • All new scripts were run green on the tree and mutant-proven both directions (detailed in each commit message). Scanner rule changes ship with both-directions fixtures.
  • No Elixir/Rust toolchain exists in the fix sandbox: mix test / cargo test assertions are written to run in CI on this branch and constitute the test-level acceptance evidence.
  • actions.lock kept set-equal to workflow refs (both third-party action tags are v7.0.1/v4.32.0, matching the lock's recorded resolutions).

Closes #814, closes #816, closes #820, closes #825, closes #831, closes #832, closes #834, closes #841, closes #847, closes #848, closes #849, closes #850, closes #851, closes #853, closes #857, closes #636, closes #695, closes #746, closes #748

…ision, toolchain policy (#814, #816, #820, #825, #831, #832, #834, #841, #845, #847–#851, #853, #857, #636, #676, #695, #746, #748)

WAVE 1 — CI truth (#841, #814, #847–#851)
* --locked passed on every test/check cargo invocation (tests.yml,
  ci.yml, verify-proofs.yml, abi-codegen-drift.yml, batch-security-scan);
  the committed Cargo.lock is the constraint it claims to be.
* #814 real cause of red cargo test --workspace = unsatisfiable
  testcontainers ^0.28 vs testcontainers-modules ^0.15 (not network
  egress); pair made satisfiable and DEBT-REGISTER CI-1 corrected.
* security-policy.yml: one scan tier + security-status aggregator on the
  Fail-on-critical gate; TruffleHog Gates A/B (--only-verified off +
  historical scan); audit jobs report instead of discard; container-scan
  joins the aggregator; scanner image pinned (no :latest). Decision
  record + per-step manifest at the top of the workflow.

WAVE 2 — runtime safety (#857, #853)
* RateLimiter tests own named instances via start_supervised! (no
  sleeps); drain crasher (finding.type KeyError on string-keyed maps)
  cannot take the limiter down; check_internal/2 mirrors the full check
  incl. burst; crash-isolation regression test. compose tier deleted.

WAVE 3 — proofs (#820, #816, #831)
* Single-prefix Idris2 bootstrap (make install PREFIX=~/.idris2), cache
  -3, PATH export, measurement step; abi repair step retained with
  sequencing comment until one green run prints the support marker.
* scripts/check-proof-status.sh + proof-status job: doc rows vs real
  identifiers, green on tree, mutants killed both directions.
* scripts/check-trusted-base.sh + check-trusted-base job: zero escape
  hatches outside test/soundness/fixtures/; tree re-measured 2026-09-26;
  mutant killed; docs/proof-debt.adoc counts re-derived (6);
  AFFIRMATION.adoc claim scoped. verify-proofs.yml now 5 jobs.

WAVE 4 — toolchain & policy (#832, #825, #845)
* mise.toml no longer provisions python/denojs or the Python-only
  toolchain; language-blockers.yml enforces LANGUAGE-POLICY (Deno
  manifests banned, TS/ReScript sources banned — whole-tree, measured 0,
  banned runtimes cannot silently return to mise.toml) instead of its
  inverted predecessor. Checks green; planted-python mutant caught.
* docs/governance/ACTIONS-PINNING.adoc records the pinning decision
  (actions.lock is the mechanism, option (b)); README links it and two
  broken README links are fixed.
* mirror.yml pins standards' mirror-reusable at 2479cf76 past the Gitea
  empty-host fault (host/fingerprint asserted, fingerprints verified,
  per-forge skip notices); Mirror-coverage job reports the denominator.

WAVE 5 — scanner precision & docs (#834, #676, #746/#748, #636, #695)
* Zig comment stripping; scan_content reports real lines (SARIF startLine
  no longer 1); inline hypatia:ignore / hypatia: allow directives honoured
  per line; main.zig opaque-handle casts carry reviewed pragmas (cast
  unchanged); RE005 strips YAML comments and honours
  hypatia:ignore RE005 -- reason. Both directions fixtured.
* Deterministic language resolution shared by all readers (count desc,
  fixed priority, lexical); discriminating tie-break test.
* Secret findings dispositioned: placeholder shapes and whole-line
  comments demote to medium/report with reason; uncommented real-looking
  values stay critical/revoke_rotate_and_purge.
* Logtalk category-A purge (ci.yml header, ROADMAP, poc-scanner.sh,
  guides, NEURAL-ARCHITECTURE); PROOF-STATUS annotated with reason;
  B/C/D untouched (owner-gated contractile filed as #864).
* PMPL headers fixed (3 workflows); SPDX added where missing
  (fixture main.rs deliberately headerless, recorded in new .reuse/dep5);
  AGPL dead weight removed; CITATION.cff added; stale TEST_CI artifact
  deleted per its own instruction; mix hypatia.rsr_score finds its SSOT
  without --ssot.

New issues filed from findings: #864 (owner-gated contractile), #865
(harvested-registry secret carve-out), #866 (scan-writer determinism
boundary — producer lives outside this repo). Mutants and measurements
as recorded per issue; mix/cargo evidence runs in CI on this branch.

Co-authored-by: arena-agent <297053741+arena-agent@users.noreply.github.com>
@coderabbitai

coderabbitai Bot commented Sep 27, 2026

Copy link
Copy Markdown
Contributor

Important

Review skipped

Bot user detected.

To trigger a single review, invoke the @coderabbitai review command.

⚙️ Run configuration

Configuration used: Organization UI

Review profile: ASSERTIVE

Plan: Advanced

Run ID: f8ffe867-58c0-4eee-882b-33d177d959af

You can disable this status message by setting the reviews.review_status to false in the CodeRabbit configuration file.

Use the checkbox below for a quick retry:

  • 🔍 Trigger review

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@gitguardian

gitguardian Bot commented Sep 27, 2026

Copy link
Copy Markdown

⚠️ GitGuardian has uncovered 1 secret following the scan of your pull request.

Please consider investigating the findings and remediating the incidents. Failure to do so may lead to compromising the associated services or software components.

🔎 Detected hardcoded secret in your pull request
GitGuardian id GitGuardian status Secret Commit Filename
37657201 Triggered Generic High Entropy Secret 30e6d14 test/scanner_suppression_test.exs View secret
🛠 Guidelines to remediate hardcoded secrets
  1. Understand the implications of revoking this secret by investigating where it is used in your code.
  2. Replace and store your secret safely. Learn here the best practices.
  3. Revoke and rotate this secret.
  4. If possible, rewrite git history. Rewriting git history is not a trivial act. You might completely break other contributing developers' workflow and you risk accidentally deleting legitimate data.

To avoid such incidents in the future consider


🦉 GitGuardian detects secrets in your source code to help developers and security teams secure the modern development process. You are seeing this because you or someone else with access to this repository has authorized GitGuardian to scan your pull request.

@arena-ai-coding-agent
arena-ai-coding-agent Bot enabled auto-merge (squash) September 27, 2026 01:49
@hyperpolymath
hyperpolymath merged commit 43124f0 into main Sep 27, 2026
4 of 5 checks passed
@hyperpolymath
hyperpolymath deleted the arena/01a0df1a-hypatia branch September 27, 2026 01:50
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment