Skip to content

fix(ci): resync actions.lock, restore codeql hold, retire dead CI jobs with a written determination (#67) - #72

Merged
hyperpolymath merged 2 commits into
mainfrom
arena/01a0e12e-blocky-writer
Sep 27, 2026
Merged

hyperpolymath merged 2 commits into
mainfrom
arena/01a0e12e-blocky-writer

Conversation

@arena-ai-coding-agent

Copy link
Copy Markdown
Contributor

Closes #67.

What #67 asked, and the answers

Check Determination Red on main too?
core-fill-tests Retired Yes — since #43 (2026-08-24) deleted deno.json, a month before #66. Its task was cargo test … fill_blocks_, a strict subset of the rust-core job.
extension-build Retired Yes — same #43 deletion; the bundle toolchain is not in the checkout at all. Comes back under a new name when the frontend has a pipeline.

Neither was in a required-check set (the repo's rulesets have no required_status_checks rule). Nothing was muted: no continue-on-error, no demotion, and the full ledger with a review date is in docs/ci/CHECK-DETERMINATIONS.adoc.

The larger thing underneath it

At main = d50a857, all nine push-triggered workflows were startup_failure, jobs=0 — including the Lock Sync Gate and the CI workflow that would run any check at all. Four consecutive merges after #66 rewrote uses: refs without touching actions.lock:

Changes

  • actions.lock resynchronised and transitively closed — scripts/check-lock-sync.sh exits 0 on all four clauses.
  • codeql.yml / hypatia-scan.yml: re-pinned to b96794f (true v4.38.0), restoring the hold fix(ci): codeql-action v4.38.1 -> v4.38.0 SHA pin + dependabot hold (estate-wide startup_failure) #64 set and ci: re-pin codeql-action to the true v4.38.0 commit #68 re-asserted. The # v4.38.0 comment Dependabot left next to the 4.38.1 SHA was false; it is now true.
  • dependabot.yml: ignore glob github/codeql-action* (estate-canonical form from hyperpolymath/standards), weekly cadence, open-pull-requests-limit: 2, header explaining the lock contract.
  • ci.yml: rust-core kept; the duplicate workflow-lock job dropped — it ran inside a workflow GitHub refuses to start on exactly the fault it checked, so it could never report. lock-sync-gate.yml (no uses:) is the authoritative gate.
  • docs/ci/CHECK-DETERMINATIONS.adoc: the ledger, root-cause table, standing rules, review date 2026-12-27.
  • TEST-NEEDS.adoc, TOPOLOGY.adoc, CHANGELOG.adoc: stop describing a Deno/Jest pipeline that does not exist.

Verification

  • scripts/check-lock-sync.sh → actions.lock is in sync and transitively closed (run locally with gawk).
  • All workflow YAML parses.
  • rust-core has never had a run that reached execution (every prior ci.yml run was a Deno failure or a startup failure), and this sandbox cannot reach crates.io, so this PR's checks are the first real run. If rust-core is red here, that is a genuine finding about the crate and I will fix it in this PR rather than merge over it.

Owner action that this PR cannot do (needs admin)

Add actions.lock is in sync with the workflow YAML and Rust core (tests, formatting, lint) as required status checks on main. #69 and #70 were merged by hand with the gate red; without a required-check rule the standing rule "never merge over a red gate" is a convention, not an enforcement. This is the piece that makes the fix permanent.

…s with a written determination (#67)

Root cause of the outage this issue sits on top of: four consecutive merges
after #66 (#68, #69, #70, #71) rewrote uses: refs without touching
.github/workflows/actions.lock. At main=d50a857 every push-triggered
workflow was startup_failure with zero jobs, including the Lock Sync Gate
itself and the CI workflow that would have run the two checks in #67.

Changes:
- actions.lock: resynchronised and transitively closed (check-lock-sync.sh
  exit 0). ci.yml entries pruned to what it uses; haskell-actions/setup
  v2.12.1 recorded; unreferenced alias records pruned.
- codeql.yml, hypatia-scan.yml: codeql-action re-pinned to b96794f (true
  v4.38.0), restoring the estate hold #64 set and #68 re-asserted. The
  '# v4.38.0' comment Dependabot left beside the 4.38.1 SHA was false.
- dependabot.yml: ignore glob corrected to 'github/codeql-action*'. The bare
  name never matched the /init, /analyze, /upload-sarif subpath dependency
  names Dependabot tracks, which is how #69 bumped straight through the
  hold. Weekly cadence + open-PR limit per estate DEPENDABOT-POLICY.
- ci.yml: keep rust-core; drop the duplicate workflow-lock job, which ran
  from inside a workflow GitHub refuses to start on exactly the fault it
  checked. lock-sync-gate.yml (no uses:) is the authoritative gate.
- docs/ci/CHECK-DETERMINATIONS.adoc: ledger. core-fill-tests and
  extension-build are RETIRED (their deno tasks were deleted by #43 a month
  before #66; red on main since; coverage subsumed by rust-core). Nothing
  was muted. Review date 2026-12-27.
- TEST-NEEDS.adoc, TOPOLOGY.adoc, CHANGELOG.adoc: stop describing a
  Deno/Jest pipeline that does not exist.

Closes #67

Co-authored-by: arena-agent <297053741+arena-agent@users.noreply.github.com>
@coderabbitai

coderabbitai Bot commented Sep 27, 2026 •

Copy link
Copy Markdown
Contributor

Important

Review skipped

Bot user detected.

To trigger a single review, invoke the @coderabbitai review command.

⚙️ Run configuration

Configuration used: Organization UI

Review profile: ASSERTIVE

Plan: Advanced

Run ID: 6a965bc3-4984-445d-96db-b9287c8681fd

You can disable this status message by setting the reviews.review_status to false in the CodeRabbit configuration file.

Use the checkbox below for a quick retry:

  • 🔍 Trigger review

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

…used triggering actor

Run annotations (web page only; not in REST) separate the two classes:
  'Invalid lockfile ... could not be validated'  -> lock drift (fixed here)
  'Actor is not allowed to trigger Actions workflows' -> every run whose
  triggering actor is arena-ai-coding-agent[bot], including a workflow with
  no uses: and a verified-clean lock (run 36295605950).

All 9 push runs at d50a857 and all 6 PR runs on this branch are the second
class; the 3 startup failures at a0e8674 (actor hyperpolymath) are the first.
Owner-side; same signature as wordpress-tools#96 and statistikles#112.

rust-core's row is downgraded to 'fixed -- verification pending an
owner-actor run': it has never executed, and it is not green until it has.

Co-authored-by: arena-agent <297053741+arena-agent@users.noreply.github.com>
@hyperpolymath
hyperpolymath merged commit a94b5b5 into main Sep 27, 2026
5 checks passed
@hyperpolymath
hyperpolymath deleted the arena/01a0e12e-blocky-writer branch September 27, 2026 05:02
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Triage: 2 pre-existing red checks surfaced by the actions.lock cure (PR #66)

1 participant