Skip to content

Fix/pin integrity latent logic - #899

Merged
hyperpolymath merged 4 commits into
mainfrom
fix/pin-integrity-latent-logic
Oct 3, 2026
Merged

hyperpolymath merged 4 commits into
mainfrom
fix/pin-integrity-latent-logic

Conversation

@hyperpolymath

Copy link
Copy Markdown
Owner

Summary

Closes #

Type of change

  • 🐛 Bug fix (non-breaking change that fixes an issue)
  • ✨ New feature (non-breaking change that adds functionality)
  • 💥 Breaking change (would change existing behaviour)
  • 🕳️ Soundness fix (fixes a checker/proof false-negative)
  • 📖 Documentation
  • 🧹 Refactor / tech debt (behaviour-preserving)
  • ⚡ Performance
  • 🔧 Build / CI / tooling

How has this been verified?

Checklist

  • My commits are signed (git commit -S).
  • I ran the project's own checks/tests locally and they pass.
  • New files carry the correct SPDX-License-Identifier (code/config MPL-2.0,
    prose CC-BY-SA-4.0); I did not relicense existing files.
  • Docs are updated, and no public claim now overstates what the code does.
  • I have not introduced a soundness hole (or I have flagged where I might have).

Notes for reviewers

hyperpolymath and others added 3 commits September 30, 2026 10:46
#862 put an unescaped `/` inside a character class in three `~r/.../`
sigils (pin_integrity.ex @uses_regex and locked_refs/1, pr_automerge.ex
@pin_re). In a `~r/` sigil that `/` terminates the sigil, so
`mix compile` fails with MismatchedDelimiterError. Every estate Hypatia
scan (hypatia-scan-reusable.yml resolves hypatia@main) has failed since.

`\/` inside a character class matches the same byte set as `/`; this
change is semantics-preserving and only restores compilation.

The two modules' own tests (17) now run for the first time and fail on
latent logic bugs in #862; nothing outside test/ calls either module.
Those are fixed in a follow-up PR, kept separate so this outage fix
stays three characters.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_0136eszqrQ53Kj7aBH1D4rXK
PinIntegrity and PrAutomerge never compiled on main, so their 17 tests
had never run. With #876 they run; this fixes what they found.

PinIntegrity
- claimed_version/1: Regex.run drops trailing unmatched groups, so a
  `v`-led match returned a 1-element list neither clause matched -> nil.
  That cascaded into pi002 and pi005 never firing.
- relabel_line/2 prepended `#` to relabel/2's already-`#`-led result
  (`##`). Now mirrors estate-pin-integrity.sh: head without `#`, comment
  handed over with it.
- relabel/2 restores `# ` for the `#`-stripped comment pin_sites/1
  emits; `#v3` and "" keep the shell mirror's byte-identical output.

PrAutomerge
- pin_deltas/3 returned a bare map from a flat_map callback, so every
  delta was flattened into {key, value} tuples.
- verdict/3 dropped the scan, so decisions lacked deltas/licence_touch.
- SAFETY: close_poison_only went through accept/4, i.e. a pin-only PR
  onto a DENYLISTED pin was classified safety=arm_auto. Now reject/4.
  Mutant control: reverting this alone turns exactly that test red.
- decision_manifest/2 vetoes use string keys like the rest of the
  manifest (the schema-shaped output).

Test fixture: "a patch that also edits a permissions block" carried
the permissions lines as diff CONTEXT (leading space) under a mismatched
hunk header, so it asserted an edit the diff did not contain. The code
was right; the fixture now makes the edit real (-/+ lines).

mix test: 1673 tests, 0 failures. mix compile --warnings-as-errors: clean.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_0136eszqrQ53Kj7aBH1D4rXK
Escript packaging soundness compiles with --warnings-as-errors and has
been red on this since #862. Every field delta/6 needs is read from the
parsed pins by its callers; nothing downstream reads a ref off a delta.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_0136eszqrQ53Kj7aBH1D4rXK
@coderabbitai

coderabbitai Bot commented Oct 3, 2026 •

Copy link
Copy Markdown
Contributor

Warning

Review limit reached

You've used all free OSS reviews for now. Wait for the free limit to reset to keep reviewing this public repository.

Next included review available in 59 minutes.

Check out review usage here.

View limit details

Limit details: You’ve used the included review currently available.

Learn how review limits work.

Review configuration:

⚙️ Run configuration
  • Configuration used: Organization UI
  • Review profile: ASSERTIVE
  • Plan: Advanced
  • Run ID: f542f9fc-e909-4e7c-ac52-525ff15431dc
📥 Commits

Reviewing files that changed from the base of the PR and between d6eade9 and 76b8c89.

📒 Files selected for processing (3)
  • lib/rules/pin_integrity.ex
  • lib/rules/pr_automerge.ex
  • test/rules/pr_automerge_test.exs
  • Autopilot · Keep fixing CodeRabbit findings and required CI, and resolving merge conflicts

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@coderabbitai

coderabbitai Bot commented Oct 3, 2026

Copy link
Copy Markdown
Contributor

Autopilot could not be updated. Open Coding to check access and billing.

Signed-off-by: Jonathan D.A. Jewell <6759885+hyperpolymath@users.noreply.github.com>
@hyperpolymath
hyperpolymath merged commit aed409d into main Oct 3, 2026
42 of 46 checks passed
@hyperpolymath
hyperpolymath deleted the fix/pin-integrity-latent-logic branch October 3, 2026 09:51
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant