Fix CI and clarify project build status - #71
Merged
Merged
Conversation
Co-authored-by: arena-agent <297053741+arena-agent@users.noreply.github.com>
Contributor
|
Important Review skippedBot user detected. To trigger a single review, invoke the ⚙️ Run configurationConfiguration used: Organization UI Review profile: ASSERTIVE Plan: Advanced Run ID: You can disable this status message by setting the Use the checkbox below for a quick retry:
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
hyperpolymath
added a commit
that referenced
this pull request
Sep 27, 2026
…s with a written determination (#67) (#72) Closes #67. ## What #67 asked, and the answers | Check | Determination | Red on `main` too? | |---|---|---| | `core-fill-tests` | **Retired** | Yes — since #43 (2026-08-24) deleted `deno.json`, a month before #66. Its task was `cargo test … fill_blocks_`, a strict subset of the `rust-core` job. | | `extension-build` | **Retired** | Yes — same #43 deletion; the bundle toolchain is not in the checkout at all. Comes back under a new name when the frontend has a pipeline. | Neither was in a required-check set (the repo's rulesets have no `required_status_checks` rule). Nothing was muted: no `continue-on-error`, no demotion, and the full ledger with a review date is in `docs/ci/CHECK-DETERMINATIONS.adoc`. ## The larger thing underneath it At `main` = d50a857, **all nine** push-triggered workflows were `startup_failure`, jobs=0 — including the Lock Sync Gate and the CI workflow that would run any check at all. Four consecutive merges after #66 rewrote `uses:` refs without touching `actions.lock`: - #69 (Dependabot) bumped codeql-action to `1c5b675` (= **v4.38.1**, the held version) → killed `codeql.yml`, `hypatia-scan.yml`. It got through the hold because the ignore was `github/codeql-action`, which does not match the `/init`, `/analyze`, `/upload-sarif` subpath names Dependabot tracks. Merged with the gate red. - #70 (Dependabot) bumped haskell-actions/setup → killed `casket-pages.yml`. Merged with the gate red. - #71 replaced the `ci.yml` jobs, leaving stale `setup-deno`/`wasm-pack-action` lock entries → killed `ci.yml`. By then the gate was already dead from #69/#70, so nothing could flag it. ## Changes - **`actions.lock`** resynchronised and transitively closed — `scripts/check-lock-sync.sh` exits 0 on all four clauses. - **`codeql.yml` / `hypatia-scan.yml`**: re-pinned to `b96794f` (true v4.38.0), restoring the hold #64 set and #68 re-asserted. The `# v4.38.0` comment Dependabot left next to the 4.38.1 SHA was false; it is now true. - **`dependabot.yml`**: ignore glob `github/codeql-action*` (estate-canonical form from `hyperpolymath/standards`), weekly cadence, `open-pull-requests-limit: 2`, header explaining the lock contract. - **`ci.yml`**: `rust-core` kept; the duplicate `workflow-lock` job dropped — it ran inside a workflow GitHub refuses to start on exactly the fault it checked, so it could never report. `lock-sync-gate.yml` (no `uses:`) is the authoritative gate. - **`docs/ci/CHECK-DETERMINATIONS.adoc`**: the ledger, root-cause table, standing rules, review date 2026-12-27. - `TEST-NEEDS.adoc`, `TOPOLOGY.adoc`, `CHANGELOG.adoc`: stop describing a Deno/Jest pipeline that does not exist. ## Verification - `scripts/check-lock-sync.sh` → `actions.lock is in sync and transitively closed` (run locally with gawk). - All workflow YAML parses. - `rust-core` has **never** had a run that reached execution (every prior `ci.yml` run was a Deno failure or a startup failure), and this sandbox cannot reach crates.io, so **this PR's checks are the first real run**. If `rust-core` is red here, that is a genuine finding about the crate and I will fix it in this PR rather than merge over it. ## Owner action that this PR cannot do (needs admin) Add `actions.lock is in sync with the workflow YAML` and `Rust core (tests, formatting, lint)` as **required status checks** on `main`. #69 and #70 were merged by hand with the gate red; without a required-check rule the standing rule "never merge over a red gate" is a convention, not an enforcement. This is the piece that makes the fix permanent. --------- Co-authored-by: hyperpolymath <6759885+hyperpolymath@users.noreply.github.com> Co-authored-by: arena-agent <297053741+arena-agent@users.noreply.github.com>
hyperpolymath
added a commit
that referenced
this pull request
Sep 27, 2026
…s and ecosystem recon (#73) Two logically separate pieces of work on one branch, because this session is pinned to a single branch. **Part 1** finishes the tail end of #67. **Part 2** is a recon pass that found the repository's documentation describing a project it is not, and fixes that. Part 2 is the larger half; Part 1 is two lines. --- # Part 1 — `fix(rust)`: clear the rust-core Clippy gate At `main` = `e1b6225` the `Rust core (tests, formatting, lint)` job passed `cargo fmt` and `cargo test` (6/6) and failed at Clippy with exactly two lints, both in `rust/pdftool_core/src/lib.rs`. ```diff fn resolve_object(doc: &Document, obj: &Object) -> Result<Object, lopdf::Error> { match obj { - Object::Reference(id) => doc.get_object(*id).map(Clone::clone), + Object::Reference(id) => doc.get_object(*id).cloned(), _ => Ok(obj.clone()), } } fn object_to_number(obj: &Object) -> Option<f32> { match obj { Object::Integer(v) => Some(*v as f32), - Object::Real(v) => Some(*v as f32), + Object::Real(v) => Some(*v), _ => None, } } ``` 1. `clippy::map_clone` → `.cloned()`. lopdf 0.34's `Document::get_object(&self, id) -> Result<&Object>` [^1], and `Result<&T, E>::cloned() -> Result<T, E> where T: Clone` is stable since Rust 1.59.0 [^2]. `Object` derives `Clone`, so the declared return type `Result<Object, lopdf::Error>` is unchanged. 2. `clippy::unnecessary_cast` → `Some(*v)`. `Object::Real(f32)` [^3], so `v` is `&f32` and the cast was an identity cast. The adjacent `Object::Integer(v) => Some(*v as f32)` is **deliberately left alone**: `v` is `&i64` there and that `i64` → `f32` cast is real. Clippy did not flag it. ## Local verification **There is no Rust toolchain in this sandbox and no crates.io access, so `cargo fmt --check`, `cargo test --locked` and `cargo clippy` were not run here.** `cargo` and `rustc` are absent, `~/.cargo` and `~/.rustup` do not exist, and `static.rust-lang.org`, `sh.rustup.rs`, `crates.io` and `docs.rs` are all network-blocked (`SSL_ERROR_SYSCALL`); only `github.com` / `api.github.com` are reachable. The two edits were verified by reading the upstream source of the exact pinned dependency: - `lopdf` 0.34.0 (the `Cargo.lock` version): `get_object` returns `Result<&Object>`, and `Object` is `#[derive(Clone, PartialEq)]` with `Real(f32)` — fetched from the `v0.34.0` tag via the GitHub API. - `std`: `impl<T, E> Result<&T, E> { pub fn cloned(self) -> Result<T, E> where T: Clone }`, `#[stable(feature = "result_cloned", since = "1.59.0")]` — the doc example is literally `Result<&i32, i32>::cloned() -> Result<i32, i32>`. - `rust-clippy` master, `clippy_lints/src/methods/map_clone.rs`: for a non-`Copy` `T` the suggestion is `cloned()` (vs `copied()` for `Copy`), and the diagnostic is `Applicability::MachineApplicable`. Against run 36296845297 (push, `e1b6225`, actor `hyperpolymath`), job `Rust core (tests, formatting, lint)`, conclusion `failure`, the step-level results were: | Step | Result | | --- | --- | | Check formatting (`cargo fmt --manifest-path rust/pdftool_core/Cargo.toml -- --check`) | success | | Run unit tests (`cargo test --manifest-path rust/pdftool_core/Cargo.toml --locked`) | success | | Run Clippy (`cargo clippy --manifest-path rust/pdftool_core/Cargo.toml --locked --all-targets -- -D warnings`) | failure | `rust/pdftool_core/src/lib.rs` is the crate's only `.rs` file, and `grep -rn "map(Clone::clone)" rust/` now returns nothing, so `--all-targets` has no other file to fail on. `docs/ci/CHECK-DETERMINATIONS.adoc` — the `rust-core` row said the job had never executed. It has: run 36296845297 reached its third step. The row now records fmt+tests green, the two lints, and this repair, and stays open pending one owner-triggered green run on `main`. It is **not** marked plain "Fixed", because no such run exists yet. --- # Part 2 — recon: the docs were describing a different project ## What was wrong Six documents were materially out of date, in the way that makes a reviewer say *"oh, wait"*: | File | What it said | What is true | | --- | --- | --- | | `.github/CONTRIBUTING.md` | Cloned `hyperpolymath/language-bridges`; documented a `lib/` + `extensions/` + `plugins/` + `tools/` layout; told readers to run `just check`, `mix compile`, `guix develop`; referenced an issue template that did not exist | None of that exists here. Repo uses `Justfile`, `.adoc` docs, one Rust crate and an AffineScript prototype | | `TOPOLOGY.adoc` | "Deno-first scripts"; Popup UI 100% "stateful forms stable"; overall "~90% Production-ready extension" | `deno.json` deleted by #43; the frontend is a prototype with no build pipeline | | `EXPLAINME.adoc` | Listed **Deno** as a technology choice; mapped a `lib/` directory | Deno is gone; the core is Rust + lopdf | | `www/.well-known/humans.txt` | "Components: Idris2 ABI, Zig FFI", dated 2026-03-28 | Rust/WASM + AffineScript prototype | | `REQUIRES_INITIALISATION.adoc` | "10 substitution tokens across 3 files" | 8 live tokens in 2 files; the 2 said to be in `CODE_OF_CONDUCT.md` were already resolved | | `docs/tech-debt-2026-05-26.adoc` | "CHANGELOG.md is missing", "CONTRIBUTING.md Y" | `CHANGELOG.adoc` exists; `CONTRIBUTING.md` existed and was wrong | Plus three structural gaps: **no issue templates at all**, **no PR template**, and **no wiki** (the wiki feature is enabled but `.wiki.git` had never been initialised). ## What changed **Corrected** — `CONTRIBUTING.md` (rewritten against this repo), `TOPOLOGY.adoc` (dashboard, missing "Last updated" date, and a rule-of-honesty note that a bar describes working verified code rather than files on disk), `EXPLAINME.adoc` (real dependency set plus a claims-and-where-they-are-checked table), `www/.well-known/humans.txt` and `ai.txt` (the latter pointed at an `AI.a2ml` that does not exist), `TEST-NEEDS.adoc` (14 workflows not 15, stale header), `CHANGELOG.adoc` (the `[Unreleased]` section was a mangled commit dump with a duplicated line and an inline `-Authored-By:` trailer), and a new status-as-of-2026-09-27 section on the tech-debt snapshot so it cannot be mistaken for current state. **Added** — `docs/ecosystem/ECOSYSTEM.adoc`, the suite boundary statement; an *Ecosystem position* section in `README.adoc`; `.github/ISSUE_TEMPLATE/` (`bug_report.yml`, `feature_request.yml`, `documentation.yml`, `config.yml` in the estate's YAML form style); `.github/PULL_REQUEST_TEMPLATE.md`; and `wiki/` plus the live wiki. **Machine-readable state** — `INTENT.contractile`'s eight outstanding tokens filled from evidence, along with its empty `architectural-invariants` and `ask-before-touching` placeholders; `methodology.a2ml`'s `unique-strength`, `divergent-invariants` and `known-constraints` filled; `STATE.a2ml` given `verified` / `not-implemented` / `known-red-on-main` / `open-decisions` sections (its `completion-percentage` had read `0` since the 2026-03-15 conversion); `debt.a2ml` populated with the eleven things this recon found and deliberately did not fix; `0-AI-MANIFEST.a2ml` given a read-in-this- order list and a "three things that will surprise you" section. Nothing was invented. Every token value is traceable to a file in this repository or to docmatrix#71, and `REQUIRES_INITIALISATION.adoc` — rewritten as a resolution record rather than deleted — says which is which. ## The wiki Seeded in **BerryWiki** format, the design taken from the metadatastician estate: a hidden `<!-- berrywiki … -->` metadata block carrying `id`, `parent`, `position`, `kind` and `tags`; hierarchy from the `parent` id chain rather than filenames; a generated `_Sidebar.md`; plain Markdown that renders natively in GitHub's wiki reader with or without BerryWiki; zero JavaScript. Eight pages: Home, Architecture, Rust-Core, CI-and-Gates, Ecosystem, Contributing, Contributing--Dev-Setup, Glossary. Structure validated programmatically — 8 pages, unique ids, every `parent` resolves, sibling positions distinct, no broken `[[WikiLinks]]`, every `_Sidebar` link resolves. The source lives in `wiki/` so it is versioned and reviewable; the published mirror has been pushed to `hyperpolymath/blocky-writer.wiki.git` (commit `59b17bd`, replacing the placeholder "Welcome to the blocky-writer wiki!" page). `wiki/README.adoc` documents the format, the three rules that make it work, the publish step, and how to add a page. --- # Owner actions 1. **Merge as yourself, not via the bot.** Every Actions run triggered by `arena-ai-coding-agent[bot]` in this org is refused at startup with `Actor is not allowed to trigger Actions workflows`, so this PR will show **no repository checks at all** — not red, absent — because a startup failure creates no check run. That is expected and is not a signal about this branch; it is the same org-side policy recorded in `docs/ci/CHECK-DETERMINATIONS.adoc` (<<actor>>) that stopped #71's runs. Nothing was weakened to work around it: no `continue-on-error`, no `if: false`, no demotion. 2. **Once CI is green on `main`, add two required status checks to the `Branch-Floor` ruleset** (id 23869449, target `~DEFAULT_BRANCH`, currently carrying only `deletion` and `non_fast_forward` — verified via the API, it has no `required_status_checks` rule): - `actions.lock is in sync with the workflow YAML` - `Rust core (tests, formatting, lint)` 3. **Tick "require branches to be up to date"** on that ruleset. Until step 2 lands, rule 2 of the standing rules in `docs/ci/CHECK-DETERMINATIONS.adoc` ("a red Lock Sync Gate is never merged over") is a convention rather than an enforcement. Note the intended interaction with the actor refusal: a required check that never runs blocks every bot-authored PR from merging, which is the correct outcome — it turns "CI-silent merge" into "cannot merge until an allowed actor triggers CI". Optional, and cheap: update the repository **description and topics** to match the boundary statement. The topics are currently `automation, cli-tool, developer-tools, epistemic-computing, epistemic-infrastructure, equivalence-aware-computing, hyperpolymath, open-source, rust, typed-provenance, veridical-computing` — none of which say pdf, firefox-extension, wasm, affinescript or document-suite. --- # Cross-repo issues — filed Eleven short issues, one per neighbour. Each says where blocky-writer is, what they can now progress with, and what they might use from here. None proposes an integration; that was deliberate — the ask was for parallel communication, not a remarkable integration exercise. | Repo | Issue | Gist | | --- | --- | --- | | `docmatrix` | [#79](hyperpolymath/docmatrix#79) | **#71 acceptance criterion 1 is met on our side** — README boundary statement + `docs/ecosystem/ECOSYSTEM.adoc`. Asks them to confirm the wording and to decide whether the GitHub *description* also needs it. | | `formatrix-docs` | [#61](hyperpolymath/formatrix-docs#61) | Boundary declared: viewer/editor stays theirs, placement stays ours. Notes the `detect_blocks` rectangle+label shape as a possible seam, and offers our `.a2ml` files as parser test material. | | `affinescript` | [#771](hyperpolymath/affinescript#771) | **A real consumer exists and is blocked on the on-ramp.** Eight `.affine` files, none compilable — no compiler config, no bundle pipeline. Asks for the smallest thing that makes them build. | | `docudactyl` | [#84](hyperpolymath/docudactyl#84) | Field labels are our weak spot; forms with no `/T` get a meaningless `field_<page>_<index>`. OCR is the obvious fix. Offers our widget rectangles in return. | | `dotmatrix-fileprinter` | [#83](hyperpolymath/dotmatrix-fileprinter#83) | Sibling check-in. No seam identified; asks them to confirm either way so it is recorded rather than rediscovered. | | `presswerk` | [#118](hyperpolymath/presswerk#118) | A filled application form is a print job. Notes that nothing currently distinguishes a machine-filled form from a hand-filled one, and asks whether that should be deliberate. | | `universal-language-server-plugin` | [#96](hyperpolymath/universal-language-server-plugin#96) | Flags a possible conversion-boundary overlap with docmatrix rather than letting it be resolved by whoever writes code first. | | `recon-silly-ation` | [#68](hyperpolymath/recon-silly-ation#68) | Clause 4 (never silently normalise) is the invariant we are most likely to break. Asks where reconciliation ends and silent normalisation begins. | | `berrywiki` | [#61](metadatastician/berrywiki#61) | **A real wiki now runs the format.** Includes the honest caveat that `berrywiki check` could not be run here (no Rust toolchain), so our seed is validated by our own script, not theirs. | | `gv-clade-index` | [#96](hyperpolymath/gv-clade-index#96) | `CLADE.a2ml` entry check. Phase `active` is correct but may overstate the project; asks whether a "core works, product incomplete" bucket exists. | | `rsr-template-repo` | [#200](hyperpolymath/rsr-template-repo#200) | **Template bug:** the shipped `CONTRIBUTING.md` told readers to clone `hyperpolymath/language-bridges`. Plus the stale token count in `REQUIRES_INITIALISATION.adoc`. | Not filed, deliberately: `standards` and `deed-ecosystem`. The actor-refusal signature is already recorded estate-wide (the determinations doc cites `wordpress-tools#96` and `statistikles#112`), so a third report would add noise rather than signal. --- # Follow-ups noted, not fixed * **Two workflows build the Pages site under one concurrency group.** `pages.yml` (Ddraig SSG, Idris 2) and `casket-pages.yml` (casket-ssg, Haskell) both build and deploy to `github-pages`, so they cancel each other. `pages.yml` also looks for `README.md`, which does not exist here — it would publish a bare `# hyperpolymath/blocky-writer` index. `casket-pages.yml` handles `README.adoc` correctly. **Which one is canonical is undecided, and it is an owner call.** Any fix needs the matching `actions.lock` change in the same commit. * **Two other checks are red on `main` at `e1b6225`, unrelated to this PR.** Neither touches the Rust crate and neither has a row in the determinations ledger, so both need one before anything is done about them: - `Hypatia Security Scan` (run 36296845360) — the `Hypatia Neurosymbolic Analysis` job fails at `Build Hypatia scanner (if needed)` and `Upload SARIF to GitHub code scanning`. - `Mirror to Git Forges` (run 36296845635) — 4 of 7 mirror jobs fail (`mirror-disroot`, `mirror-gitea`, `mirror-codeberg`, `mirror-bitbucket`); `mirror-gitlab`, `mirror-sourcehut` and `mirror-radicle` are green, so this looks like per-forge credential or host reachability rather than a workflow defect. - Both were already red at `a94b5b5`, i.e. before this branch existed. * **Orphaned build leftovers.** A ~90 KB `deno.lock` sits in the root although #43 deleted `deno.json`; `webpack.config.cjs` configures a bundle pipeline that does not exist. Both are the most likely things to make a reviewer think this is a Deno project. Deleting them is safe but it is an owner call — an estate tool outside this checkout may reference them. * **`Justfile` reads a file that does not exist.** The `crg-grade` and `crg-badge` recipes parse `READINESS.md`; the CRG grade actually lives in `TEST-NEEDS.adoc`. Both silently fall back to grade `X`. * **The product gap.** Ruled-line, per-character-cell and baseline detection are not implemented. `detect_blocks` reports widget annotation rectangles only. This is the "hand spacing" case the project is named for — the real thing to build next, and deliberately left alone here. * The `rust-core` row in `docs/ci/CHECK-DETERMINATIONS.adoc` should be re-marked *Fixed* once an owner-triggered green run on `main` exists. * The `ubuntu-latest` label migrates to Ubuntu 26 on 2026-10-19 (runner-images issue 14748), per the notice on run 36296845297. [^1]: `lopdf` v0.34.0, `src/document.rs`: `pub fn get_object(&self, id: ObjectId) -> Result<&Object>`. [^2]: `rust-lang/rust`, `library/core/src/result.rs`: `impl<T, E> Result<&T, E>`, stable since 1.59.0. [^3]: `lopdf` v0.34.0, `src/object.rs`: `#[derive(Clone, PartialEq)] pub enum Object { ... Real(f32), ... }`. --------- Co-authored-by: hyperpolymath <6759885+hyperpolymath@users.noreply.github.com> Co-authored-by: arena-agent <297053741+arena-agent@users.noreply.github.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary\n- Replace CI steps that invoke undefined Deno tasks with Rust formatting, unit-test, and Clippy checks.\n- Add a workflow lockfile verification job (including its GNU awk prerequisite).\n- Correct the README and Rust core documentation to match implemented behavior and clearly identify the unfinished extension frontend.\n\n## Validation\n-
git diff --checkpassed.\n- Rust checks were not run locally because Cargo is unavailable in the environment.\n- Workflow lock verification could not run locally because GNU awk is unavailable; CI installs it before running the check.