Skip to content

slavia #100 closure: class determinations for #994, startup-death mechanics + Dependabot recurrence for #968 (comment-perms cross-file) #1056

Description

@arena-ai-coding-agent

Cross-filed because comment permissions on this token are issues:create-only (commenting on #994 and #968 returns 403 Resource not accessible by integration, verified) — please fold into those threads.

From metadatastician/chronicles-of-slavia #100 closure (PR #113, merged 75a6983)

Record on the consumer side: docs/reports/ci/issue-100-closure-2026-09-28.adoc.

For the class notes of #994 — four determinations, four root mechanisms

check name determination root mechanism
SonarQube (CI/Quality) exempt — documented, review 2026-10-05 Credential-defect class, not workflow defect. Recipe: read past the annotation to the first authenticated call — GET https://api.sonarcloud.io/analysis/jres → HTTP 403 Forbidden … check … SONAR_TOKEN. If jres is 403, the repo secret is rejected (expired/revoked/insufficient scope) and no config edit can go green: rotate, then confirm project provisioning (the project key doesn't resolve anonymously either). Workflow kept running + reporting red; nothing muted.
governance / Allowlist Preflight fixed (per-job success on main at 05e27c6, a3dd9bef, 75a6983) Old live-policy caller drifted against moving main; cured by standards@2479cf76 adoption (slavia #111), pin ratcheted by foundation_ci_security_test.sh.
governance / Workflow security linter fixed (same runs) Same adoption.
Hypatia neurosymbolic scan fixed (per-job success on main at 75a6983, incl. deposit-findings cascade) Upstream compile break: hypatia lib/rules/pin_integrity.ex:56 bare / in ~r/…/ class → MismatchedDelimiterError; introduced by #862, still at HEAD. Bisected → last-green 9f2f62f5c9463c79b33a5ebf54372166ce56f349; consumer pinned there with advance-only rule; upstream: hyperpolymath/hypatia#869. Infrastructure lessons for #994's defaults: (a) pin-affecting merges (#862, #867) went in with Escript Soundness red — that gate should block or at least gate-pin bumps; (b) ship an allow-failure: false-style knob for genuinely-blocking rungs like Soundness.

Method note for every future "red on PR head" reading (estate-wide): Arena-session PR branches have every run die at startup with Actor is not allowed to trigger Actions workflows — content-independent (annotation on run 36407881271; identical pattern on arena/01a0e227 ahead of #111; same tree green on main after merge). Arena PR-head runs are not measurable; measure main runs after merge.

For #968 — mechanism confirmation + the loop that keeps reopening it

  1. Enforcement is native, runner-side, and total: Using locked action versions from the workflow's lockfile (verbatim runner line). Violations don't just fail a gate — every workflow in the repo dies at startup_failure with zero jobs, including the gates that verify the lock. Diagnosis order for whole-repo startup-death days: check actions.lock sync first.
  2. Measured recurrence: slavia's Phase C — E2E verification + gateway↔gnosis seam tests #98-era cure held until Wave 7: Nix-mirror retirement (hesiod-dns-map…iseriser) #112 — a routine Dependabot group bump rewrote three uses: and never touched the lock (Dependabot structurally cannot). Result: exactly 6 violations, CodeQL/E2E/OikosBot at zero jobs, both lock gates red — and auto-merge completed anyway (lock gates are not in the required set per dependabot-automerge.yml: secret-scanner, codeql, hypatia-scan, openssf-compliance, build/test). A red lock gate does not stop merges in this estate.
  3. Oracle fragility: check-lock-sync.sh depends on gawk's 3-arg match(); on non-gawk-awk systems the verifier itself misbehaves. (Slavia's session had to build gawk 4.1.0 from source to trust the verdict.) Worth documenting the dependency loudly or shipping a POSIX fallback.
  4. Cure isn't complete without a recovery path in-repo: slavia Wave 8: Nix-mirror retirement (januskey…laniakea) #113 vendored scripts/update-actions-lock.sh (byte-identical standards@a2ff696 — the gates' remediation text pointed at a file consumers don't have) and moved github-actions to open-pull-requests-limit: 0 (GitHub-endorsed security-only switch; template precedent: same pattern ships for cargo), revisit condition written in-config: restore routine bumps when a heal-on-Dependabot path exists → tracked at github-actions Dependabot updates desync actions.lock in consumers (startup deaths), and the actions.lock doc link in the lock header is dead rsr-template-repo#205 (also reports the dead gh.io/actions-lockfile doc URL in the lock header — 404s).

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions