Skip to content

CI: regen upstream of ci (build→regen→ci→deploy) + heal auto-fixes drift on PRs - #7126

Merged
briansrls merged 40 commits into
mainfrom
session/sleek-crane-70
Jul 23, 2026
Merged

briansrls merged 40 commits into
mainfrom
session/sleek-crane-70

Conversation

@gunbai-bot

@gunbai-bot gunbai-bot Bot commented Jul 23, 2026

Copy link
Copy Markdown
Contributor

Completes the regen-upstream restructure and makes the generated-artifact heal a general convenience (operator-directed 2026-07-23).

What changed

Verified locally (direct binary)

  • `ci.yml` regenerated: build → regen(needs build) → ci(needs build,regen) → deploy; heal on pull_request||push with branch checkout + branch push + guarded add.
  • Drift gate `ExitSuccess` (ci.yml at fixed point); heal witness `true` (5 discriminating controls: enrollment, needs-build-not-ci, pr_and_push guard, scoped write, artifact-only + existence-guarded + branch-aware push); fixed-point loop-safety witness `true`.

Known caveat

The drift gate still lives inside `ci`, so the first run that observes drift shows `ci` red on its pre-heal snapshot (a GITHUB_TOKEN push doesn't re-trigger CI); the branch is auto-fixed and main is green. Making even that first run green means moving drift out of the ci floor (a merge-admission change) — left as a follow-up.

🤖 Generated with Claude Code

Brian Searls and others added 30 commits July 22, 2026 22:00
…+ roadmap row

Splits every floor gate by remedy KIND (gunbc.ci_remedy): RemedyDerivation
(pure projection of the tree — pipeline may chore-commit) vs RemedyJudgment
(fail-closed default — detect + refuse, never fix). Derivation is grounded on
existing authorities, not hand-listed: the GeneratedArtifactRegen channel heals
exactly committed_generated_artifacts() (the registry the drift gate guards),
walled by ci_remedy_witness_test with two RED controls.

P0 (byte-idempotent regen) measured ALREADY-SATISFIED: main_wet yields zero diff
on a clean tree, twice. Executable fixed-point leg added to
generated_artifact_drift_test (reads real committed bytes; RED control perturbs).

ROADMAP row ts-loop-selfheal regenerated from authority.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
…41703)

Address cursor review 41703 REQUEST_CHANGES on #7112:
- ci_heal_shell_lines now stages EXACTLY committed_generated_artifact_paths()
  (git add over the registry, then git diff --cached --quiet) instead of git add -A,
  so an unattended push to main can never sweep incidental runner dirt — artifact-only
  by construction (DESIGN §5 no-silent-widen).
- Add ci_heal_commit_push_shell_emit_scaffold (Disposition = Scaffold) + dissolution
  trigger for the hand-authored git transport, matching the sibling CI-shell scaffolds;
  dissolves when shell→intent models git commit/push as typed host effects.
- New heal_commit_scope_is_artifact_only witness pins the scope (contains scoped git add
  + --cached, no git add -A) as a discriminating control.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
…cile regen-job extraction with main's GithubActionsCiRegenJob gate lane

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
Brian Searls and others added 3 commits July 23, 2026 16:27
…arded add, branch-aware push (5 discriminating controls)

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
…branch-head checkout witness control

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
@gunbai-bot

gunbai-bot Bot commented Jul 23, 2026

Copy link
Copy Markdown
Contributor Author

Addressed both findings from cursor review 41904 (both valid):

  1. roadmap_authority.dag ts-loop-selfheal row updated — it now describes the PR+push heal, the branch-head checkout, the branch-aware push, and the existence-guarded git add; ROADMAP.md regenerated to match.
  2. Added heal_checks_out_triggering_branch() to the witness suite — it folds the heal job's steps and reds unless one checks out ci_heal_branch_ref_expr (github.head_ref || github.ref_name), so a regression to the default merge ref is now caught. Witness green by execution (6 discriminating controls).
    Landed in 04ec0ae. — sent from sleek-crane-70

Brian Searls and others added 2 commits July 23, 2026 16:47
…board auto-committed the conflicted marker)

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
Brian Searls and others added 2 commits July 23, 2026 17:09
…ch-aware / own-regen-job wiring (review 41924)

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
@gunbai-bot

gunbai-bot Bot commented Jul 23, 2026

Copy link
Copy Markdown
Contributor Author

review 41924 — both stale strings fixed and ci.yml regenerated (drift gate ExitSuccess):

  • ci_workflow.dag heal commit-push step name: "…to main…" → "…to the triggering branch…"
  • ci_spec.dag regen notice title: "…folded into ci job" → "…own regen job upstream of ci"

Pushed as 7872b56. These are telemetry-only, no behavior change.

— sent from sleek-crane-70

Brian Searls and others added 3 commits July 23, 2026 17:47
…uto-pushing

main is protected by a ruleset requiring the 'ci' check, so a heal push to
main is rejected (GH013). Operator-directed: don't auto-heal main — on main
the ci job's own drift gate reds if regen ever drifts, which is correct since
a change reaching main should already be green from its PR heal. ci_regen_heal_if
drops the 'push' arm; witness heal_job_runs_on_pr_only reds if it returns.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
@briansrls
briansrls merged commit 3cec679 into main Jul 23, 2026
5 checks passed
@briansrls
briansrls deleted the session/sleek-crane-70 branch July 23, 2026 20:05
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant