Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
10 changes: 7 additions & 3 deletions .github/workflows/catalog-freshness.yml
Original file line number Diff line number Diff line change
Expand Up @@ -2,7 +2,10 @@ name: Catalog freshness (report-only)

on:
schedule:
- cron: '17 6 * * *'
# Daily at 06:17 UTC; github.event.schedule identifies Monday proposals.
# https://github.com/github/docs/blob/2bd66de8cea336061c9ea060c9b37385136e6ab3/data/reusables/repositories/actions-scheduled-workflow-example.md#L34-L51
- cron: '17 6 * * 1'
- cron: '17 6 * * 0,2-6'
workflow_dispatch:
inputs:
max_repos:
Expand Down Expand Up @@ -180,7 +183,7 @@ jobs:
# registration -- it never selects, evaluates, or writes catalogs/sota-convergence/*,
# catalogs/landscape/*.json, manifests/stack.json, or layer-verdicts* (owned by the
# separate SOTA-convergence lane review). Off by default: it only runs from an explicit
# manual `open_pr: true` dispatch, or from a schedule when the repository variable
# manual `open_pr: true` dispatch, or from Monday's schedule when the repository variable
# CATALOG_FRESHNESS_PROPOSE is set to 'true' -- and, either way, only when this run's own
# freshness fetch was unbounded and free of both full fetch errors and partial errors (a
# releases/tags/commit sub-fetch that failed and fell back, e.g. a 503 on releases papered
Expand All @@ -192,7 +195,8 @@ jobs:
github.ref == 'refs/heads/main' && needs.freshness.outputs.drift == 'true' &&
(inputs.max_repos || 0) == 0 && needs.freshness.outputs.upstream_errors == '0' &&
needs.freshness.outputs.partial_errors == '0' &&
(inputs.open_pr == true || (github.event_name == 'schedule' && vars.CATALOG_FRESHNESS_PROPOSE == 'true'))
(inputs.open_pr == true || (github.event_name == 'schedule' &&
github.event.schedule == '17 6 * * 1' && vars.CATALOG_FRESHNESS_PROPOSE == 'true'))
runs-on: ubuntu-24.04
timeout-minutes: 20
concurrency:
Expand Down
7 changes: 4 additions & 3 deletions .github/workflows/practice-references-freshness.yml
Original file line number Diff line number Diff line change
Expand Up @@ -13,9 +13,10 @@ on:
# Thursday 06:41 UTC. Off the top of the hour, which GitHub names as a high-load time
# when scheduled runs can be delayed or dropped
# (https://docs.github.com/en/actions/reference/workflows-and-actions/events-that-trigger-workflows#schedule),
# and on a day without the Monday lanes: GITHUB_TOKEN's REST budget is 1,000 requests per
# hour per repository (https://docs.github.com/en/rest/using-the-rest-api/rate-limits-for-the-rest-api),
# and catalog-freshness.yml's Monday fetch alone covers about 480 repositories.
# with the repository's GITHUB_TOKEN REST budget shared across these workflows
# (https://docs.github.com/en/rest/using-the-rest-api/rate-limits-for-the-rest-api).
# The daily catalog report is scheduled 24 minutes earlier; this timing does not prove
# that their execution or API use cannot overlap. No quota impact is measured here.
- cron: '41 6 * * 4'
workflow_dispatch:

Expand Down
2 changes: 1 addition & 1 deletion .github/workflows/security-scan.yml
Original file line number Diff line number Diff line change
Expand Up @@ -21,7 +21,7 @@ on:
push:
branches: [main]
schedule:
- cron: '37 5 * * 3' # Weekly Wednesday 05:37 UTC, between the Monday lanes
- cron: '37 5 * * 3' # Weekly Wednesday 05:37 UTC, 40 minutes before the daily catalog report
workflow_dispatch:

permissions:
Expand Down
4 changes: 2 additions & 2 deletions catalogs/foundation/automation.json
Original file line number Diff line number Diff line change
Expand Up @@ -214,8 +214,8 @@
{
"workflow": ".github/workflows/catalog-freshness.yml",
"job": "freshness",
"schedule": "17 6 * * 1",
"purpose": "Reruns extract_layers.py + github_freshness.py, rebuilds a manifest with build_manifest.py against an empty lanes.json (skips interactive lane review, still recomputes the real pin/upstream baseline), diffs it against catalogs/sota-convergence/manifest-20260922.json, and appends a fixed-tool pin-drift table to the job summary. Writes and commits nothing; uploads a 30-day artifact.",
"schedule": ["17 6 * * 1", "17 6 * * 0,2-6"],
"purpose": "Reports daily at 06:17 UTC through disjoint Monday and other-day triggers. Reruns extract_layers.py + github_freshness.py, rebuilds a manifest with build_manifest.py against an empty lanes.json (skips interactive lane review, still recomputes the real pin/upstream baseline), diffs it against catalogs/sota-convergence/manifest-20260922.json, and appends a fixed-tool pin-drift table to the job summary. This freshness job writes and commits nothing; it uploads a 30-day artifact. The separate guarded proposal job is eligible on Monday with CATALOG_FRESHNESS_PROPOSE=true, or by explicit manual open_pr=true dispatch.",
"required_check": false
},
{
Expand Down
13 changes: 9 additions & 4 deletions docs/decisions/2026-09-26-stack-agents-role-dispatch.md
Original file line number Diff line number Diff line change
Expand Up @@ -253,10 +253,15 @@ Codex parity is a template only, not applied by any installer; B1 applies no Cod
B1 is the host-apply unit that follows this change.
`adoption/templates/codex.hooks.template.json` holds the one group that would run the same script under Codex, and
it can only be used by hand-appending that group after ai-memory's one SessionStart group in the user `hooks.json`.
The config template ships no trust entry for it: Codex keys a hand-appended group by its position
(`session_start:1:0` after ai-memory's one SessionStart group, `session_start:2:0` or later after more), and at
every position the handler stays untrusted, and is skipped, until it is reviewed in `/hooks` (Codex's trust rule
for hooks; the keys were measured for the second and third positions with Codex 0.157.1 and 0.159.2; see Sources).
Codex's persisted key includes the discovered source path and the group/handler indexes:
`<source-path>:session_start:G:H`. The suffix is `session_start:1:0` after ai-memory's one SessionStart group,
or `session_start:2:0` after two groups. The second and third positions were measured with Codex 0.157.1 and
0.159.2 (see Sources). The current template handler is not trusted at any position: an absent trust entry is
untrusted, while the different hash at position zero is modified. Both are skipped until reviewed in native
`/hooks`; no trust setting is changed here. The full key and trust states follow
[key construction](https://github.com/openai/codex/blob/a956835d020762cb2b570053af06f643a11c0ecc/codex-rs/hooks/src/lib.rs#L113)
and [discovery](https://github.com/openai/codex/blob/a956835d020762cb2b570053af06f643a11c0ecc/codex-rs/hooks/src/engine/discovery.rs#L795)
at the destination-selected Codex 0.160.0 source; the repository stack pin remains separately recorded.

The hook prints only `summary_line`, and prints nothing for a missing or stale (over 8 days) due-file. It also
prints nothing for a malformed or unreadable file, one more than a day ahead, one that is not a regular file, or one
Expand Down
6 changes: 3 additions & 3 deletions docs/decisions/2026-09-30-session-currency-notice.md
Original file line number Diff line number Diff line change
Expand Up @@ -151,9 +151,9 @@ only. See the [current behavior and bounded schedule decision](2026-10-02-daily-
3. **The startup rule.** Item 4 of `docs/token-practice.md` now allows exactly one read-only SessionStart line from
that file, printed fail-open; the checks never run at startup. `AGENTS.md:28` still reads "Do not rerun the full
audit or model trials at startup", which this design keeps. Any change to that wording is unit F1's.
4. **The historical proposed contract for the hook in unit F2, which this change does not contain:**
The correction above identifies the implemented age limit and output format; this list preserves the original
proposal and its unmeasured acceptance gate.
4. **The historical proposed contract for the hook in unit F2, which this change does not contain:**
The correction above identifies the implemented age limit and output format; this list preserves the original
proposal and its unmeasured acceptance gate.
- Read only that file and print its `summary_line` as plain stdout. Exit 0 in every case.
- Print nothing when the file is missing, unreadable or not a JSON object, when `summary_line` is not one line
of at most 160 characters, or when `generated_at` is more than 48 hours old, because a failing timer leaves
Expand Down
33 changes: 31 additions & 2 deletions docs/decisions/2026-10-02-daily-catalog-currency.md
Original file line number Diff line number Diff line change
Expand Up @@ -44,15 +44,20 @@ explicit adoption uses native `/hooks` to inspect and review the actual hook.
The command, matcher, timeout and shipped trust configuration are unchanged;
this change registers or trusts no hook.

**Review correction (2026-10-02):** the earlier unpublished template wording
**Review correction (2026-10-02):** the template wording already published at
`18eea2c1de992b46c266d79ef0cc40f93c9fb943`
called bare `session_start:G:H` examples keys. They are suffixes; the full
persisted key is `<source-path>:session_start:G:H`. The selected Codex 0.160.0
persisted key is `<source-path>:session_start:G:H`. The destination-selected Codex 0.160.0
source at `a956835d020762cb2b570053af06f643a11c0ecc` builds that key from
`key_source`, event, group and handler, and discovery assigns `key_source` from
the actual source path. The corrected template directs review to the actual
native `/hooks` entry without guessing its namespace. This is a wording repair
only, with no registration or trust change.

The repository stack pin at the correction base remains Codex 0.159.3. The
destination's 0.160.0 selection and its source review do not silently update
that pin or establish an execution on either host.

## Verification boundary and overturn condition

Use the pinned native actionlint binary for the changed workflow, the existing
Expand Down Expand Up @@ -101,6 +106,30 @@ review and local integration receipts remain historical evidence. Neither the
rebase nor a passing source regression check is a new scheduled Actions run,
hosted bot proposal, target installation or provider acceptance.

## 2026-10-03 residual correction

The daily schedule above also made scheduled proposals eligible every day when
`CATALOG_FRESHNESS_PROPOSE=true`. The selected nonsecret repository variable
was observed as `true`; that established eligibility, not an observed proposal
run. Keep daily reports at 06:17 UTC using disjoint Monday (`17 6 * * 1`) and
other-day (`17 6 * * 0,2-6`) events. Require the exact Monday event for a
scheduled proposal, alongside the existing variable and safety gates. Explicit
manual `open_pr=true` remains available. This uses GitHub's
[multiple-schedule/event.schedule reference](https://github.com/github/docs/blob/2bd66de8cea336061c9ea060c9b37385136e6ab3/data/reusables/repositories/actions-scheduled-workflow-example.md#L34),
not a new scheduler or a change to catalog selections.

The automation inventory and neighboring workflow comments now describe the
daily report. Thursday's practice check is scheduled 24 minutes later, and
Wednesday's security scan 40 minutes earlier; neither offset proves execution
or API-budget isolation. No quota or hosted cadence outcome is claimed. The
practice checker itself stays weekly.

The hook-key correction above concerns already-published wording. Position zero
can be **modified** because its stored hash differs; positions with no entry
are **untrusted**. Both states are skipped. The remaining client-template and
handbook wording belongs to the Claude lane and is handed off separately;
this change activates or trusts no hook.

## Sources

- Existing workflow and its guarded proposal job:
Expand Down
Original file line number Diff line number Diff line change
@@ -0,0 +1,79 @@
# Catalog freshness residual corrections

`pr613-source-review.json` is the original retained, already-sanitized review
checkpoint for PR #613 head `26f09b021e5da36f15cb15ada9032d69d26a238c`, copied
byte-for-byte. Its SHA-256 is
`ca7cc90d94684da52b3b952ecb84c2c15565dcf3ba832a1e09f36bcc7021febc`, matching
the locator previously recorded in that PR's description. It is a bounded
structural/source review of the main reconciliation, not a new run or evidence
that the later eight residual findings were closed. Its original limitations,
failed rebase and worker-observation distinctions remain intact.

The residual implementation follows GitHub's pinned
[multiple-schedule/event.schedule example](https://github.com/github/docs/blob/2bd66de8cea336061c9ea060c9b37385136e6ab3/data/reusables/repositories/actions-scheduled-workflow-example.md#L34)
and the existing workflow at base `56473e4b840f0e6940c031801d866e7e9bf29baf`.
Daily reports use separate Monday/other-day triggers; scheduled proposals keep
the existing opt-in and safety gates and add Monday selection. Manual proposals
remain available. Source and local checks do not prove a future scheduled run.

Correction during preparation: the shared working directory was at
`5cfa2400e3ebb4aefb8419135345c1fa92b05409`, despite its `origin/main` ref naming
the intended base. Its weekly workflow and missing newer files were not current
main. No edit used those stale reads; all edits use an isolated checkout at the
exact base above. The source intake also guessed `scripts/practice_references.py`;
the actual source is `tools/sota-convergence/practice_references.py`, found by
`rg --files` and read before editing. Failed path lookups are not absence claims.

## Actual bounded checks on the integration checkout

Base `56473e4b840f0e6940c031801d866e7e9bf29baf`; the coordinator applied the
worker's retained two-file patch to the separate integration checkout. Its
workflow and test bytes matched the worker snapshot, respectively SHA256
`5c05254b9697920813e84203e58a8e690a8fc1022d67b48ebb9206e19e3a94df`
and `8b47c2850f86d2ac3d6fbf6f83aff5679d8f185011065c0b3f18579a92417229`.
The worker's checkout was not edited. Registration uses the repository's
`scripts/host_receipts.py:register_file`, with only existing changed bindings
and new evidence files selected through `docs/lanes.md`'s protocol.

Native kjanat/actionlint **1.17.0** ran on catalog-freshness,
practice-references-freshness and security-scan: exit0, empty stdout/stderr.
The scoped official Linux amd64 archive matched the release's full SHA256
`620abd485a12b6ab1125b844a876414e1d5bd2af8a3125b27f82b01d0d9d6e5a`.
Version output named1.17.0, go1.27.1 and linux/amd64. The earlier PATH probe
returned1; this proves no global absence. No production installation changed.

Coordinator-observed original commands, each with
`PYTHONDONTWRITEBYTECODE=1` for unittest:

```text
python3 -m unittest tests.test_catalog_freshness_propose tests.test_catalog_freshness_pins tests.test_catalog_freshness_trading
exit0;128tests/OK;57.592s
python3 -m unittest tests.test_adoption_docs_consistency tests.test_github_automation_practice tests.test_practice_references
exit0;79tests/OK;1skip;14.201s
python3 scripts/validate.py
exit0;69components/9319hashedfiles/4profiles/186receipts
git diff --check
exit0
```

These are repository source-contract, synthetic integration and structural
checks. They are not unchanged upstream suites, native GitHub expression
execution, a scheduled Actions run, new provider trials or host acceptance.
The public integration/docs output files retain the exact original native
stdout/stderr bytes; lint output was empty. Registry validation is repeated
after this evidence publication changes its inputs.

The worker's earlier RED had26tests/two source-contract failures; its later
128-test attempt exited1 on publication validation while registration was
outside its ownership; its35-test workflow subset exited0. The initial gh
source fetch returned4 before pinned public curl fetch returned0; actionlint
lookup1, scoped filename discovery2 with inaccessible directories, and Git
commit128 from read-only shared Git metadata remain retained failures. No
tests or evidence were weakened. Original worker outputs remain private with
their recorded hashes; its terminal completion/usage is not inferred from
the delivered patch or a handoff file.

Claude owns the template/position-zero distinction, handbook cadence and
anti-pattern row correction. The coordinator's PR608 handoff requests those
in the pin-move PR. This bounded source change closes the owned residuals;
closure of all eight requires those owner edits and the corrected PR613 body.
Original file line number Diff line number Diff line change
@@ -0,0 +1,5 @@
..................s............................................................
----------------------------------------------------------------------
Ran 79 tests in 14.201s

OK (skipped=1)
Original file line number Diff line number Diff line change
@@ -0,0 +1,5 @@
................................................................................................................................
----------------------------------------------------------------------
Ran 128 tests in 57.592s

OK
Loading
Loading