Skip to content

Feat/kyaml pilot provisioning convert - #1133

Merged
hyperpolymath merged 7 commits into
mainfrom
feat/kyaml-pilot-provisioning-convert
Oct 2, 2026
Merged

hyperpolymath merged 7 commits into
mainfrom
feat/kyaml-pilot-provisioning-convert

Conversation

@hyperpolymath

Copy link
Copy Markdown
Owner

Summary

Closes #

Type of change

  • 🐛 Bug fix (non-breaking change that fixes an issue)
  • ✨ New feature (non-breaking change that adds functionality)
  • 💥 Breaking change (would change existing behaviour)
  • 🕳️ Soundness fix (fixes a checker/proof false-negative)
  • 📖 Documentation
  • 🧹 Refactor / tech debt (behaviour-preserving)
  • ⚡ Performance
  • 🔧 Build / CI / tooling

How has this been verified?

Checklist

  • My commits are signed (git commit -S).
  • I ran the project's own checks/tests locally and they pass.
  • New files carry the correct SPDX-License-Identifier (code/config MPL-2.0,
    prose CC-BY-SA-4.0); I did not relicense existing files.
  • Docs are updated, and no public claim now overstates what the code does.
  • I have not introduced a soundness hole (or I have flagged where I might have).

Notes for reviewers

hyperpolymath and others added 3 commits October 1, 2026 18:54
YAML-POLICY Y-1: a verdict about a workflow must come from a parser.
Each of these gates read `uses:`/`permissions:` by line grep, which only
sees block style. On a KYAML workflow they either falsely failed (the
quote and comma were captured into the ref) or went blind (a pin inside
`{ uses: ... }` was never seen):

- validate-actions-lock.sh, lock-selfcheck.sh, check-action-pins-resolve.sh,
  update-actions-lock.sh: refs come from yq; an unparseable file fails
  closed instead of contributing zero refs.
- check-workflow-duplicate-keys.sh: flow documents are normalised with
  yq -P before the line scanner runs (yq keeps duplicates, so the
  scanner still sees them).
- governance-reusable.yml: top-level permissions via yq has("permissions"),
  with a warned grep fallback on a runner without yq.
- Mustfile actions-sha-pinned: optional quote/comma in the pattern.
- lock-selfcheck.sh: its existing MPL-2.0 SPDX line moves from line 41
  to line 2 so the staged SPDX hook sees it (identifier unchanged).

Known answers on main's block-style tree: identical ref sets for
validate-actions-lock (29) and lock-selfcheck (111 pairs);
check-action-pins-resolve drops exactly two `# uses:` comment examples
that never execute. New KYAML cases and mutants fail against the old
scripts and pass against the new ones.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01W5CoaksP2Bg21HpDCgFgwS
The pre-commit/pre-push permissions hook grepped `^permissions:`, which
never matches a KYAML workflow (every key sits inside `{ ... }`), so a
KYAML file that does declare permissions was rejected. Ask yq
has("permissions") instead; an unparseable file is an error, not a
pass. Without yq the grep is kept with a warning -- it can only
false-fail KYAML, never false-pass.

Known answer: identical output to the old hook on all 58 of main's
workflows. scripts/tests/validate-permissions-test.sh: 6/6; the old
hook fails its KYAML positive case.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01W5CoaksP2Bg21HpDCgFgwS
Single-file pilot of YAML-POLICY Y-3, produced verbatim by
`yq -p yaml -o kyaml '.'` (yq v4.53.3). Not the #1023 scope ruling.

Verified locally:
- data-equal: sort_keys JSON of block and KYAML forms cmp-identical
- idempotent: re-emitting the KYAML is byte-identical
- tools/yaml-comment-proof (#1021): kyaml arm PASS, 26/26 comments
  preserved, 0 moved, 0 dropped; 8 blank lines lost (cosmetic)
- the gates fixed in the previous commits read it correctly
  (validate-actions-lock, validate-permissions, duplicate keys,
  governance permissions check, Mustfile pin pattern)

Not proven: GitHub's runtime parse of this reusable needs a caller run.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01W5CoaksP2Bg21HpDCgFgwS
@coderabbitai

coderabbitai Bot commented Oct 2, 2026 •

Copy link
Copy Markdown
Contributor

Warning

Review limit reached

You've used all free OSS reviews for now. Wait for the free limit to reset to keep reviewing this public repository.

Next included review available in 1 minute.

Check out review usage here.

View limit details

Limit details: You’ve used the included review currently available.

Learn how review limits work.

Review configuration:

⚙️ Run configuration

Configuration used: Organization UI

Review profile: ASSERTIVE

Plan: Advanced

Run ID: 4be85938-33fa-4325-aeaf-d1524a52612e

📥 Commits

Reviewing files that changed from the base of the PR and between 804b780 and 2602452.

📒 Files selected for processing (1)
  • .github/workflows/provisioning-check-reusable.yml
  • Autopilot · Keep fixing CodeRabbit findings and required CI, and resolving merge conflicts

Autopilot is currently an internal CodeRabbit preview.


Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@hyperpolymath
hyperpolymath enabled auto-merge (squash) October 2, 2026 01:22
@coderabbitai

coderabbitai Bot commented Oct 2, 2026

Copy link
Copy Markdown
Contributor

Autopilot could not be updated. Open Coding to check access and billing.

@hyperpolymath
hyperpolymath disabled auto-merge October 2, 2026 01:23
@hyperpolymath
hyperpolymath enabled auto-merge (squash) October 2, 2026 01:24
@hyperpolymath
hyperpolymath disabled auto-merge October 2, 2026 01:29
@hyperpolymath
hyperpolymath enabled auto-merge (squash) October 2, 2026 01:29
@hyperpolymath
hyperpolymath disabled auto-merge October 2, 2026 01:30
@hyperpolymath
hyperpolymath enabled auto-merge (squash) October 2, 2026 01:30
@hyperpolymath
hyperpolymath disabled auto-merge October 2, 2026 01:59
@hyperpolymath
hyperpolymath enabled auto-merge (squash) October 2, 2026 02:05
@hyperpolymath
hyperpolymath disabled auto-merge October 2, 2026 02:05
@hyperpolymath
hyperpolymath merged commit c550314 into main Oct 2, 2026
42 of 45 checks passed
@hyperpolymath
hyperpolymath deleted the feat/kyaml-pilot-provisioning-convert branch October 2, 2026 02:05
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant