Repository navigation
macOS CI scope: validate-macos stays required, running the full suite for Mac-relevant changes, only changed test modules for test-only changes, and skipping otherwise (decision record, receipt, tests) - #677
Conversation
… pull requests Implements docs/decisions/2026-10-03-macos-ci-scope.md (draft sha256 3a5eba0772ed82cf...). - .github/workflows/adoption-bootstrap.yml: the changes job writes macos and macos_tests from the record's 89-entry MACOS_PATTERNS (outputs grouped, macos written last, every failure path calls fail_safe). validate-macos stays required and gains needs: changes, a fail-safe job-level if: (a skipped job reports success) and VALIDATE_MACOS_MODE; its 15 full-mode steps are guarded and a changed-tests step runs only the changed top-level test modules, with empty-selection and zero-test guards. bootstrap-macos and bootstrap-macos-brew run on a pull request only in full mode (B+). Push, schedule and dispatch runs stay full; the push paths keep manifests/evidence.json as the post-merge net. - tests/test_workflow_hardening.py: the D9 expectation changes, plus MacosPatternsTests (coverage, drift guard, D8), PushNetTests (D11), ValidateMacosModeTests, and runs of the changes script and the changed-tests step against scratch repositories, each guard with a mutation control. tests/test_adoption_bootstrap_macos.py: comments only. - docs: the decision record; docs/github-automation.md; a dated note on the closure record; adoption/platforms/macos-arm64.md. - evidence/artifacts/macos-ci-scope-20261003: the replay inputs the record cites, its saved outputs, and replay.py, which reproduces the record's tables from them (exit 0; output retained). .gitignore gains a narrow exception for the receipt's one .jsonl input, as for earlier receipts. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Hot-file protocol (docs/lanes.md): the base's manifests/evidence.json (6112d14) with the branch's 7 changed and 26 new files registered through host_receipts.register_file; component_matrix.py --write and new_host_grand_list.py --write left their reports unchanged. python3 scripts/validate.py passes (9589 hashed files). Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Codex Review SummaryThis comment shows the latest Codex review activity on this pull request.
ℹ️ About Codex in GitHubYour team has set up Codex to review pull requests in this repo. Reviews are triggered when you
Codex reacts with 👀 while any review is running, comments if it has suggestions, and reacts with 👍 once all reviews finish with no findings. |
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: 0eceddab0c
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
|
FINDINGS / HOLD for #677 head
Root independently rehashed all 42 present owned head/base bodies and 15 pinned primary originals against their Git identities and checked all 33 owned payload registry bindings; all non-files registry fields remain exact. The frozen packet distinguishes 34 exact PR-owned paths from 110 raw main-to-head paths carrying foreign branch differences. Prospective merge preservation remains unqualified; raw gaps are not proof of eventual deletion. The fixed selector intentionally skips unknown well-formed unlisted paths. Its textual drift guard is not dependency-graph discovery. The cited PyTorch EditedByPR establishes prioritization, not exclusive test gating. Keep those limits explicit. Retained historical replay, simulation and model outcomes remain owner reports, including the unretained simulation code; they are not new root executions or native upstream acceptance. Repairs belong to the Claude owner. No root workflow/manifest edit, hosted dispatch, test execution, merge, active client/configuration read or credential/auth access occurred. The root parser's initial dictionary assumption for a list-shaped source map failed; the corrected type-aware verifier checked the exact retained bodies successfully, and the processing failure is preserved. |
…fail-safe Repair round for the Codex root's source review of head 0ecedda and the P2 review thread on the decision record. - validate-macos: the gate adds needs.changes.result != 'success' and the mode's changed-tests branch adds needs.changes.result == 'success', so a changes job that did not succeed runs the full job whatever outputs it wrote (root finding 2). - The changed-tests step counts each selected module's test cases before unittest runs and fails naming a module that loads none; the aggregate "Ran N tests" guard stays for a selection that loads tests but runs none (root finding 1). - Tests: the gate and mode are evaluated over every event, changes result and output value against the record's table, with 0ecedda's outputs-only gate and mode as the negative control; a module with no test beside one with tests fails, and without the per-module guard the aggregate check passes it. - Decision record: precise fail-safe and zero-test wording; EditedByPR as prioritization, not exclusive gating; the textual drift guard; the fixed selector, owner reports and unobserved failed-job outputs as residuals; section 3.5 and 5 use sim_r2.json's saved (b2)+B+ figures (339.9 slot-hours, p90 1.7 min); disposition and pinned sources. - Receipt: replay.py checks every simulated figure the record states against sim_r2.json; replay-output.txt re-run (exit 0); README updated. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
The workflow, the hardening tests, the decision record and the receipt's README, replay.py and replay-output.txt, through host_receipts.register_file (docs/lanes.md, hot-file protocol). The component matrix and new-host grand list check unchanged. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
|
SOURCE ACCEPT WITH LIMITS — exact head The two source findings close:
I independently checked all 34 owned payloads, 33 registrations, six commit originals and all 20 pinned upstream originals, including the five newly acquired references. Full foreign preservation is exact against both the prior reviewed head and actual construction base Well-formed unlisted paths intentionally skip; this is a fixed textual selector, not a dependency graph. Historical replay, prior failure and warning evidence remain historical. The hosted failed- |
|
Actual merged-source carry ACCEPT WITH LIMITS — landing Root independently rehashed all 182 frozen bindings and 112 original streams from 56 native commands0, reconstructed all three complete Git trees against their full commit originals, and rederived the actual 34-path roster. All 33 payload modes/types/OIDs and full registration rows match the ACE source verdict. All 10,269 ordered foreign Git tuples and 9,563 ordered foreign full registration rows remain exact against the prior main. All 9,570 prior registration positions survive projection; the 26 new rows belong to the reviewed payload. Every non-files field, all 193 receipts and all 29 convergence records remain exact. Root explicitly joined every map membership to its complete captured tree: 76 present body joins, including all three registries, plus 26 verified absent prior scopes; zero mismatches. Frozen manifest113099B/SHA256 One root processing failure is retained: the absent-scope schema omits |
… protocol: main's rows plus the owned bindings) Only manifests/evidence.json conflicted. It is main's copy plus register_file for the 76 PR-owned paths (72 new rows, 4 updated); the three-way merge helper produced byte-identical output. #677's hunks in tests/test_workflow_hardening.py (two imports, then from line 1235) and docs/decisions/2026-09-22-github-automation-closure.md (line 1421) are region-disjoint from this PR's and merged cleanly; their registry rows bind the merged bytes. Both generator --check commands exit 0, so no --write ran. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
…(hot-file protocol) Reapplies the merge commit's registry: main's copy plus register_file for the 76 PR-owned paths. The two files #677 also changed, tests/test_workflow_hardening.py and docs/decisions/2026-09-22-github-automation-closure.md, are bound at their merged bytes. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
…utation runs in manifests/evidence.json Hot-file protocol (docs/lanes.md): this is the branch's last commit, on main e0c329a (#677), and takes main's manifests/evidence.json. It re-registers the closure record, the receipt and docs/harness-defaults.md, and the 71 files under evidence/artifacts/frozen-variant-guard-mutations-20261003/. component_matrix --write and new_host_grand_list --write changed nothing else. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…ant) (#635) * Record and guard the Dependabot alert 16 dismissal on the frozen macOS variant The closure record notes the dismissal of Dependabot alert 16 (GHSA-vcvr-r3jv-pc5j) as not_used on the frozen macOS variant's package.json, with its API readback receipt, evidence/receipts/dependabot-alert-16-dismissal-20261003.json. tests/test_frozen_macos_variant_no_use.py, a tripwire in the required validate job, fails when: - a scanned file names the frozen artifact directory beyond its pinned lines; - the directory gains a file; - the lock or its next pin changes; - the frozen OSV exception's date or keys change. The guard's mutation driver is kept under evidence/artifacts/frozen-variant-guard-mutations-20261003/. The anti-pattern log gains two 2026-10-03 rows. This commit replaces the branch's earlier content commits (review rounds 1-7), rebuilt on main 4ced292, so that no commit on the branch quotes a user message. Its tree equals round 7's first content commit 8f547913, apart from main's changes since 9b0b8d6. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com> * Retain the guard's mutation runs and disclose the retained driver's assembled name The mutation driver's returned results are kept under evidence/artifacts/frozen-variant-guard-mutations-20261003/: - round 8's final run: all 45 rows against the content commit a447a51, every row as expected; - round 7's three runs of the new rows against the round-3, round-4 and round-5 modules. Each gap row passes there, so each of these runs exits 1 by design. runs.json gives the argument vectors, times, exit codes, clone heads and hashes. Clone roots, the output directory and the Python prefix are replaced with placeholders. The receipt's table equals the retained output (45 rows, 0 mismatches) and binds the driver and runs.json by sha256. Its limitations now say: - the retained driver assembles the artifact name from fragments, a stated blind spot of the guard, and installs, builds or serves nothing; - configuration names inside an excluded class that differ only in letter case are not read. The closure note says "ASCII letter case", since the module folds ASCII letters only. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com> * Keep the control runs' modules, rebuild the controls on main and record the indirect-route decision This commit answers the Codex review at 06c90df. Control runs: - The three earlier modules the control runs used are kept byte for byte, as .txt files, under evidence/artifacts/frozen-variant-guard-mutations-20261003/controls/. The guard does not read .txt files under evidence/**, and the receipt says so. - The control runs were re-run on main's d2777ee with each kept module committed in a scratch clone, so anyone can rebuild them from the repository. Their outcomes, failing tests and messages equal round 7's runs, which they replace. runs.json records each control's base commit and module file. Indirect routes: the receipt gains indirect_routes, a dated decision. The dismissal stands, and the indirect routes stay stated limits. The record names: - the alternatives declined: pinning the 43 lines that read the inventory, pinning the 297 package-manager lines, resolving each command's target, reopening the alert, and keeping the frozen manifest under names that tools don't parse; - the precedent; - the dated backstop of the OSV exception: it lapses on 2026-12-24, can be renewed at most 90 days ahead, and each renewal fails the review-date test. The closure note points to the decision. Round 8 review fixes: - runs.json defines <repo> without tying it to the final run's clone head. - runs.json describes the commits after the content commit accurately. - The receipt states X15's correction as a deduction from the module. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com> * Correct the alert-16 backstop and precedent, record the convergence decision and log the tripwire scope miss This commit answers the round-9 review and the Codex review at 9faa5c4. Backstop: once the frozen exception lapses, the required osv-scanner job fails in its unittest preflight (FrozenScanTests) before OSV-Scanner runs, and validate's full suite fails IgnorePolicyTests, both through ignore_entry_problems. A renewal that also edits REVIEW_DATE passes, and the receipt now says so. Precedent: the dismissal of alerts 7-15 that this record cites was superseded on 2026-09-25 by renaming the fixture (#224). The authorization, reasoning.precedent and indirect_routes now say so. Convergence decision: indirect_routes records the same day's convergence round. It ran Claude and GPT-6 research, two GPT-6 Astra and two Claude Opus votes, and took the GitHub/CI lane session's input. It chose to rename both frozen variant files to .frozen and stop scanning them in a follow-up pull request. The dismissal and the tripwire stand until then. The overturn and the closure note carry the new conditions. Other fixes: - The two counts now record their exact git grep commands. - The statement that the guard does not read the .txt control modules names the recogniser's conditions. - docs/harness-defaults.md gains a row for scoping a tripwire by expected file kinds, proven by controls N1, N4-N6, N7 and X13. - The branch is rebased onto main 59f8a1e (#653). Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com> * Qualify the tripwire-scope anti-pattern row to the guard's actual reach The Codex review at 47da9f8 found that the new row's rule said the guard reads JSON launch configurations inside the record classes. The guard deliberately leaves `evidence/**/launch.json` unread: it is stated limit L5, and its control passes. The rule now scans every file outside the record classes, reads each recognised runnable or configuring kind inside them, and names every kind left unread as a stated limit with a passing control. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com> * Register the alert-16 receipt, the changed records and the retained mutation runs in manifests/evidence.json Hot-file protocol (docs/lanes.md): this is the branch's last commit, on main e0c329a (#677), and takes main's manifests/evidence.json. It re-registers the closure record, the receipt and docs/harness-defaults.md, and the 71 files under evidence/artifacts/frozen-variant-guard-mutations-20261003/. component_matrix --write and new_host_grand_list --write changed nothing else. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com> --------- Co-authored-by: Scout <scout@local> Co-authored-by: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…673) * fix(ci): port OSV split-scan policy and mutation hardening Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> * chore(evidence): register OSV split-hardening port artifacts Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> * Review repair: exact override keys, overturn clause, neutral wording Independent Opus review of 48bbe5c (verdict repair, 0 blocking, 2 should-fix, 5 minor), one repair round: - override_problems rejects [[PackageOverrides]] keys outside the PackageOverrideEntry toml tags at OSV-Scanner v2.6.0 (internal/config/config.go:38-49, nested :83-89); main's next/braces name assertion is restored beside it; two case-aliased mutation cases and three unit cases are added. - The closure record's first overturn trigger again ends with "; or OSV lists an advisory ...", followed by the removal procedure. - Coordinator-owned steps are worded neutrally, the helper's "sum check: 0 == 53" line is quoted verbatim, and the overwritten first component-matrix output is recorded. - The receipt gains a repair_round with the discriminating controls, whose script and output are retained as artifacts. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> * Register the review-repair files in the evidence manifest Re-registers the four changed port files and the two new repair-round artifacts with scripts.host_receipts.register_file on top of the PR's registry; foreign rows are unchanged. component_matrix.py --check and new_host_grand_list.py --check pass, so no generator --write was run. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> * Re-check minors: discriminating advisory mutation, review status, retained repair controls - tests/test_osv_lockfile_coverage.py: the 'advisory' mutation now adds a well-formed exception (reason, ignoreUntil 30 days out) and asserts that ignore_entry_problems accepts it, so only the frozen-id check can reject it. - Receipt: independent_review.status states the review and re-check verdicts; the override-key-function and three-module-unittest repair controls gain retained re-runs; recheck_round records the discriminating control. - Artifacts: recheck-advisory-mutation-control.{py,stdout}.txt, repair-round-override-key-function.{py,stdout}.txt and repair-round-three-module-unittest.{stdout,stderr}.txt. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> * Register the re-check minors files in the evidence manifest register_file for the test module, the receipt and the six new control artifacts on top of the branch registry (9628 -> 9634 rows). Both generator --check commands passed, so no --write ran. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> * Hot-file protocol: restore main's copy of manifests/evidence.json before this PR's last commit The merge commit carries the resolved registry; this commit returns it to main e0c329a's copy so that the next, last commit carries the PR's registry rows. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> * Shared hot file last: this PR's evidence registry rows on main e0c329a (hot-file protocol) Reapplies the merge commit's registry: main's copy plus register_file for the 76 PR-owned paths. The two files #677 also changed, tests/test_workflow_hardening.py and docs/decisions/2026-09-22-github-automation-closure.md, are bound at their merged bytes. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> * Hot-file protocol: reset manifests/evidence.json to the merge base before the final registry commit Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> * Register this branch's files on the merge-base registry (hot-file protocol: every registry edit in the last commit) Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> * Pin #673's two check-only references to the frozen macOS lock; record the alert-16 recheck After main merged in, CI's full unittest run failed the alert-16 tripwire (tests/test_frozen_macos_variant_no_use.py) on two lines this port adds that name the frozen lock: the FROZEN constant of its retained split-scan control copy, and tests/test_osv_lockfile_coverage.py's copy of the workflow's assignment check used by the split-scan mutants. Both only scan or check the lock; nothing builds, runs or serves from it. Per the tripwire's own rule, both are pinned in PINNED_LINES after review, under the hashes of their already-pinned originals (the 2026-09-30 relock control's FROZEN constant and SCAN_ASSIGNMENT); pins only, no recogniser, scope rule or excluded class changes. The closure record's alert-16 section gains the dated recheck its overturn asks for when the tripwire fails. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> * Hot-file protocol: reset manifests/evidence.json to the merge base before the final registry commit Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> * Register this branch's files on the merge-base registry (hot-file protocol: every registry edit in the last commit) Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> * Hot-file protocol: reset manifests/evidence.json to the merge base before the final registry commit Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> * Register this branch's files on the merge-base registry (hot-file protocol: every registry edit in the last commit) Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> * Hot-file protocol: reset manifests/evidence.json to the merge base before the final hot-file commit Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> * Reapply this branch's manifests/evidence.json edits on the merge base (hot-file protocol: every hot-file edit in the last commit) Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> --------- Co-authored-by: Scout <scout@local> Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com>
…ify the six cache calls' batch timestamps in the receipt (review 632 P1, P2) Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
…d five anti-patterns (#632) * Record the macOS full-suite coverage decision, the CI measurements and five anti-patterns The 2026-10-03 GitHub CI review measured the required test jobs: both run the whole suite (about 9,500 tests) serially, Linux validate in 1,727-1,828 s against a 2,400 s limit and macOS validate-macos in 1,932-2,394 s, and 30 of 1,025 pull-request head SHAs (2.9%) failed only on macOS in 8 days. The decision record keeps full macOS coverage on every pull request (O4), pre-registers a fallback that gates only the full-suite step (O2, not adopted, with a prospective shadow phase, a frozen escape bound and a derived INERT list), rejects gating the whole job (O1, forbidden by tests/test_workflow_hardening.py:1247-1255) and running the suite only after merge (O3), and lists reductions R1 to R6 for their owners. The measurements are kept as a durable receipt because Actions run ids expire with the new retention period; the itemized failing runs carry their head SHAs. Five proven mistakes join the anti-pattern log. Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com> * Publish the CI measurement input and later reads; reconcile the receipt Answer the review threads on the receipt with published evidence: - Publish the compiled measurement input byte-identical (evidence/artifacts/github-ci-measurements-20261003/input.json, sha256 d01f9b63...) and the read-only GET calls of 2026-10-03 that check the receipt (later-reads-20261003.json: 218 calls with argument vectors, times, exit codes and payload hashes; payloads withheld because they carry commit author emails). - Add a queries section: request forms reconstructed from the measurement plan, not a transcript, and what was not retained. The receipt is a recorded summary that can be re-derived only while the run records exist; durability wording in scope and limitations is replaced. - Caches: record 130 (likely the usage endpoint) and 131 (the by-prefix sum) with the byte reconciliation; the difference stays unreconciled, and two later paired reads show the same one-cache gap. - Failure anatomy: the 80 of 88 Validate runs are the failed runs no later same-SHA run turned green (reproduced exactly); the 8 omitted are sota-sources-only failures (21 of 94 instances over all 88). Other workflows: 10 of 76 classified, 66 not. - Self-audit fixes: the 17-entry failing-test key and limits string, the composition of the 11 non-pull-request cancelled runs, the 96 and 87 denominators, the sampled failed-job seconds and the suite-shape definitions. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> * Run the O2 phase as a dry run and qualify R3 and R5 by anatomy coverage - O2's prospective phase becomes a dry run: the required validate-macos job keeps running the full suite on every pull request, the gate only reports what it would skip, E_G is read from the required job on the would-skip pull requests, and skipping starts only after the preregistered thresholds pass in a later reviewed change. The thresholds are unchanged. - R3 and R5 state the failure anatomy's coverage (80 classified of Validate's 88 failed pull-request runs, all 75 of Adoption's, 10 of 76 other-workflow failures) and what the 8 omitted runs change (sota-sources 21 of 94 over all 88); R5 names the steps behind 18 and 15. - The measured findings and evidence class say the receipt is a recorded summary that can be re-derived only while the run records exist, and point to the published input and the later reads. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> * State the anatomy selection, cache bytes and query forms as strong as the data Second review of the receipt and the record (R1-R5): - R1: the reclassification of all 88 failed Validate runs forces each of the 8 runs the anatomy left out to have failed only in sota-sources (94 - 86 = 8 instances, 21 - 13 = 8 of them sota-sources), but any 8 of the 19 sota-sources-only failures reproduce the counts. The 8 that a later same-SHA run turned green are consistent with the input's tally of 8 of 96, not established as the 8 left out: 96 covers all events and the 6 push and 2 workflow_dispatch failures were not checked. The record says once that R3 and R5 do not depend on which 8. The receipt's coverage keys become selection and runs_with_a_later_success. - R2: the byte total equals the by-prefix sum to 0.1 MiB but does not indicate which cache count is right; the later listing's total_count of 129 is stated. - R3: the measuring agent's request forms give the path only (client flags not retained); the GET statement is scoped to the input and a GH_DEBUG check that was not retained; the suite-shape figures are not covered by the plan; the queue-seconds definition is marked inferred; the two-endpoint cross-check is relayed as the input's statement. - R5: largest_file reads 632 'def test' occurrences (624 test definitions) in 8,441 lines, listed in source.changes_from_input. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> * Drop the unpublished creation timestamp and say policy_gate rises by the same 8 in the anatomy selection text Delta review findings on the CI measurements receipt: the later-success creation time is in no published artifact, so the sentence now points at the run ids in the later-reads artifact; the reclassification of all 88 runs keeps every other by_step cell equal but policy_gate rises by the same 8 because it counts sota-sources. Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com> * Register the CI measurement receipt, its artifacts, the record and the anti-pattern log (hot-file protocol; last commit) One registration on main's manifest at 4ced292: the receipt, the decision record, input.json, later-reads-20261003.json and docs/harness-defaults.md (five rows). It is the branch's last commit, so a later rebase takes main's manifest and registers again (docs/lanes.md). Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com> * Mark the record's coverage policy as superseded in part by #677; qualify the six cache calls' batch timestamps in the receipt (review 632 P1, P2) Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> * Hot-file protocol: reset manifests/evidence.json to the merge base before the final hot-file commit Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> * Reapply this branch's manifests/evidence.json edits on the merge base (hot-file protocol: every hot-file edit in the last commit) Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> * Hot-file protocol: reset manifests/evidence.json to the merge base before the final hot-file commit Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> * Reapply this branch's manifests/evidence.json edits on the merge base (hot-file protocol: every hot-file edit in the last commit) Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> --------- Co-authored-by: seathatflowsinourveins <seathatflowsinourveins@users.noreply.github.com> Co-authored-by: Claude Sonnet 5.5 <noreply@anthropic.com> Co-authored-by: Scout <scout@local>
Skip validate-macos, bootstrap-macos and bootstrap-macos-brew on every pull_request; retain full runs on filtered main pushes and manual dispatch, and move the weekly bootstrap schedule to nightly 06:47 UTC. Match the committed ruleset and dated automation catalog to the coordinator's seven required contexts, including the merge guard's documented count. Keep the Linux PR detector working and label the retained macOS selector as historical. Record the user's 2026-10-05 advisory decision, #699's portability catch, the fix-forward path and overturn rules. Sources: GitHub Actions workflow-syntax#jobsjob_idif and events-that-trigger-workflows#schedule, github/docs at 2bd66de8cea336061c9ea060c9b37385136e6ab3; #677's retained measurements; #699 (landed as 5df0e0e). Validation: the final PR-event test fails the original workflow with 133 failing subtests across all three macOS jobs (exit 1), and passes the new workflow (exit 0); 388 selected unittest tests (36 skipped), including the merge-guard stale-count red/green control; git diff --check. actionlint is not on PATH. validate.py exits 1 for evidence registry drift only. Evidence registration remains with the coordinator. The count-only docs/lanes.md correction follows that file's lane:shared integration policy. Built by GPT bounded job 064 (GPT-6.1 Sol at max); committed by the coordinator, who re-pointed the #699 citation from its branch-local head to the landed main commit. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Skip validate-macos, bootstrap-macos and bootstrap-macos-brew on every pull_request; retain full runs on filtered main pushes and manual dispatch, and move the weekly bootstrap schedule to nightly 06:47 UTC. Match the committed ruleset and dated automation catalog to the coordinator's seven required contexts, including the merge guard's documented count. Keep the Linux PR detector working and label the retained macOS selector as historical. Record the user's 2026-10-05 advisory decision, #699's portability catch, the fix-forward path and overturn rules. Sources: GitHub Actions workflow-syntax#jobsjob_idif and events-that-trigger-workflows#schedule, github/docs at 2bd66de8cea336061c9ea060c9b37385136e6ab3; #677's retained measurements; Validation: the final PR-event test fails the original workflow with 133 failing subtests across all three macOS jobs (exit 1), and passes the new workflow (exit 0); 388 selected unittest tests (36 skipped), including the merge-guard stale-count red/green control; git diff --check. actionlint is not on PATH. validate.py exits 1 for evidence registry drift only. Evidence registration remains with the coordinator. The count-only docs/lanes.md correction follows that file's lane:shared integration policy. Built by GPT bounded job 064 (GPT-6.1 Sol at max); committed by the coordinator, who re-pointed the #699 citation from its branch-local head to the landed main commit. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
…pushes, no PR runs; the user's 2026-10-05 decision) (#711) ### Scope - What this PR changes: it makes macOS CI advisory. `validate-macos`, `bootstrap-macos` and `bootstrap-macos-brew` no longer run on pull requests, and they leave the required checks. They still run nightly (06:47 UTC), on filtered main pushes and on manual dispatch, so a macOS regression is fixed forward. This follows the user's decision of 2026-10-05 (~01:50Z, an AskUserQuestion answer): "Advisory only". - Base commit: `5df0e0ede` - Lane: `lane:shared`. docs/lanes.md's required-context count goes from eight to seven, so the trading-custody owner must ACK. - Owned paths touched: - `.github/workflows/adoption-bootstrap.yml`; - `.github/main-ruleset.json` (the committed target); - `catalogs/foundation/automation.json`, `docs/github-automation.md`, `docs/lanes.md`, `adoption/platforms/macos-arm64.md`; - five test modules; - the decision record. The live ruleset 23739774 was already changed by the coordinator on 2026-10-05, with an API read-back: `validate-macos` is no longer required. This PR brings the committed target and the docs into line with it. ### SOTA sources - GitHub Actions workflow syntax, `jobs.<job_id>.if`: https://docs.github.com/en/actions/writing-workflows/workflow-syntax-for-github-actions#jobsjob_idif (github/docs at 2bd66de8cea336061c9ea060c9b37385136e6ab3) - Events that trigger workflows, `schedule`: https://docs.github.com/en/actions/writing-workflows/choosing-when-your-workflow-runs/events-that-trigger-workflows#schedule (same pin) - Rulesets, required status checks: https://docs.github.com/en/repositories/configuring-branches-and-merges-in-your-repository/managing-rulesets/available-rules-for-rulesets#require-status-checks-to-pass-before-merging - #677's retained macOS measurements, and #699's macOS catch (landed as 5df0e0e), which shows why the nightly runs stay. ### Evidence-class table | Claim | Evidence class | Command / receipt | | --- | --- | --- | | The new workflow skips all three macOS jobs on `pull_request`, and the old one runs them | local_integration | The PR-event test fails the original workflow (133 failing subtests, exit 1) and passes the new one (exit 0) | | The committed ruleset target equals the live seven-context ruleset | source_review | `.github/main-ruleset.json`; live read-back from `gh api repos/.../rulesets/23739774` on 2026-10-05 | | The workflow has no security findings | local_integration | `zizmor --offline .github/workflows/adoption-bootstrap.yml`: no findings (5 suppressed) | ### Local commands run ``` $ python3 -m unittest tests.test_workflow_hardening tests.test_adoption_bootstrap_macos tests.test_github_automation_practice tests.test_codex_broker_reaper tests.test_shell_parser_ci tests.test_merge_guard_doc 388 tests OK (36 skipped) [GPT builder job 064] $ zizmor --offline .github/workflows/adoption-bootstrap.yml No findings to report (5 suppressed) [coordinator] $ python3 scripts/validate.py status passed (10,044 hashed files) [coordinator, after the registry commit] $ python3 merge_tree_landing_check.py origin/main HEAD LANDABLE ``` actionlint was not on PATH in the builder's sandbox; zizmor ran instead. ### Decision record `docs/decisions/2026-10-05-macos-ci-advisory.md`: the user's decision, #699's portability catch, the fix-forward path and the overturn rules. Built by GPT bounded job 064 (GPT-6.1 Sol at max). Review chain: - Claude read: 4 P2 and 6 P3, all fixed by the GPT repair round (5f6eb31). - Claude delta read: all ten confirmed fixed; three new P3s, fixed by the coordinator (7e4d69f), along with a fresh ruleset read-back (enforcement active, strict false, merge methods squash only). - Registry last (331d008). This PR lands after the v2026.10.05 re-pin, because adoption/** is on the release window's hold list. 🤖 Generated with [Claude Code](https://claude.com/claude-code)
Scope
validate-macosstays required, but on a pull request it now runsthe full macOS suite only when a macOS-relevant path changes, runs only the changed top-level test modules when
nothing else relevant changed, and is skipped otherwise; the two macOS bootstrap jobs run on a pull request only in
full mode, and push, schedule and dispatch runs stay full. This implements
docs/decisions/2026-10-03-macos-ci-scope.md, adds its receipt, and updates the hardening tests and docs.6112d14d40f741855f0b961124d98939daaad00e(headace6dd766;origin/mainhas since moved tob29036f05, which touches none of these paths except the sharedmanifests/evidence.json, andgit merge-tree --write-tree HEAD origin/mainis clean).lane:foundation..github/workflows/adoption-bootstrap.ymltests/test_workflow_hardening.py,tests/test_adoption_bootstrap_macos.py(comments only)docs/decisions/2026-10-03-macos-ci-scope.md(new),docs/decisions/2026-09-22-github-automation-closure.md(a dated note),
docs/github-automation.md,adoption/platforms/macos-arm64.mdevidence/artifacts/macos-ci-scope-20261003/(new receipt),.gitignore(one narrow exception for its.jsonlinput)
manifests/evidence.json(registration only, the last commit)How the three modes work:
changeswritesvalidate-macosbootstrap-macos,-brewMACOS_PATTERNS(the record's 89, §6.2), or anytests/path that is not a top-leveltests/test_*.pymacos=truebootstrapgate)tests/test_*.pymodules (still present), plus unlisted pathsmacos=false,macos_tests=<modules>macos=false,macos_tests=if:(reports success to the required check; recorded as untested)changescannot decide (missing SHA, failedgit diff)fail_safe:macos=truechangesstops before writingmacosmacosoutput!= 'false', never== 'true')changesfails after writing its outputsneeds.changes.result != 'success')In changed-tests mode, a selected module from which unittest loads no test case fails the step before any test runs,
and the step names it; a selection that loads tests but runs none also fails. Skipped tests are not failures; the step
summary gives their count.
Repair round at
ace6dd766For the Codex root's exact-head source review of
0eceddab(the FINDINGS / HOLD comment) and the review thread "Usethe retained simulation result". Commits:
27b7c8300(content) andace6dd766(registry, last).(
.github/workflows/adoption-bootstrap.yml:995-1005) loads each selected module on its own withunittest.defaultTestLoader.loadTestsFromNamebefore unittest runs, and fails naming the module whencountTestCases()is 0; the exit code decides, so import-time output cannot fool it. The aggregate guard(
:1013-1017) stays for a selection that loads tests but runs none.tests/test_workflow_hardening.py,ChangedTestsStepRunTests):test_a_module_with_no_test_beside_a_module_with_tests_fails_naming_it(both orders: exit 1, the error namestests.test_zz_empty, unittest never starts) andtest_a_module_with_no_test_fails_before_unittest_runs.test_control_without_the_per_module_guard_the_aggregate_check_passes_the_mixed_selection.With the guard line neutralized, which leaves
0eceddab's logic,tests.test_zz_pass tests.test_zz_emptyexits 0 with "ran 1 tests".
test_a_selection_that_loads_tests_but_runs_none_fails_as_untestedkeeps the aggregate guard's own case with areal interpreter: a class that skips in
setUpClass(Ran 0, OK (skipped=1), exit 0).ValidateMacosModeTestspins the guard's text and its place before the run; its control drops either guard.:812) addsneeds.changes.result != 'success', and the mode(
:820) addsneeds.changes.result == 'success'to its changed-tests branch. Achangesjob that does notsucceed now runs the full job, whatever outputs it wrote.
ValidateMacosGateEvaluationTestsevaluates both expressions with a test-local evaluator of thedocumented operator subset (
!,==,!=,&&,||, parentheses, strings, property paths,cancelled();anything else raises). It covers 96 inputs (4 events × 4
changesresults × 3macosvalues × 2 module lists)against the record's §2 table, and includes
test_a_changes_job_that_failed_after_writing_macos_false_runs_in_full. The oracle has its own test of thecited semantics.
test_control_the_outputs_only_gate_and_mode_scope_or_skip_a_failed_changes_job.0eceddab'sgate and mode, byte-identical to
git show 0eceddab:.github/workflows/adoption-bootstrap.yml, disagree with thetable on exactly the 6 inputs (pull_request, failure|cancelled|skipped,
macos=false, either module list). Theygive changed-tests with modules and a skip without.
test_the_pre_fix_condition_text_fails_this_tests_own_assertions(the resultterm dropped from the gate, or from the mode).
0eceddab's workflow, 10gate/mode subtests and all 3 changed-tests cases fail.
EditedByPRestablishes prioritization, not exclusive gating. pytorch@dd5cbc42 runs only the top 25% withtarget determination on, and its default leaves that off on macOS.
classifications are owner reports. Failed-job output retention was not observed on a hosted run. Skips pass.
PRRT_kwDOUg_LrM6osJBK(P2). §3.5 (L396) and §5 (L501-504) now usesim_r2.json: (b2) with B+is 339.9 slot-hours and p90 1.7 min, and B+ saves 27.8 slot-hours, not 48.
replay.pychecks every simulatedfigure the record states against
sim_r2.json(9 checks, all OK; compared, not re-run, since the simulation codewas not retained). The (a-mac) and (b1) simulated figures are labelled as having no saved output.
host_receipts.register_filein the lastcommit.
component_matrix.py --checkandnew_host_grand_list.py --checkare unchanged. Againstorigin/mainatb29036f05,git merge-tree --write-treeexits 0, and the registry is the only shared path. No merge commit wasneeded, so no patch-id comparison applies. Pushed fast-forward
0eceddab0..ace6dd766;git ls-remotereadsace6dd76663951526406446d65f2acbb4c6825b1.SOTA sources
GitHub documentation (the load-bearing behavior), re-read 2026-10-03T21:09Z:
https://docs.github.com/en/pull-requests/collaborating-with-pull-requests/collaborating-on-repositories-with-code-quality-features/troubleshooting-required-status-checks:
"A job is skipped by a conditional | The job reports 'Success'"; "A workflow is skipped by path filtering ...
Associated checks stay in a 'Pending' state and block merging"; "Use
always()withneedsfor required checksthat depend on other jobs".
will report its status as 'Success'. It will not prevent a pull request from merging, even if it is a required
check."
content/actions/reference/workflows-and-actions/contexts.md:97, :100, :110:jobs.<job_id>.envmay readneeds;jobs.<job_id>.ifmay readneedsand callcancelled();jobs.<job_id>.steps.ifmay readenv.events-that-trigger-workflows#pull_request, the macOS concurrency limit, managing-a-merge-queue.
Repair round, re-read 2026-10-03 at fixed commits:
content/actions/reference/workflows-and-actions/:contexts.md:777-779(needs.<job_id>.outputs, andneeds.<job_id>.resultwithsuccess,failure,cancelledor
skipped);expressions.md:30(falsy values),:52-68(operators; strings compare ignoring case),:322(astatus check function replaces the default
success()).src/Sdk/DTExpressions2/Expressions2/Sdk/Operators/And.cs:33-49andOr.cs:33-49:&&and||return anoperand's value, which the
cond && 'changed-tests' || 'full'mode relies on.Lib/unittest/:loader.py:203-208(named modules mergedinto one suite),
runner.py:254-256(one aggregate "Ran N tests" line),main.py:283-288(exit status 5 onlywhen no test ran and none was skipped),
suite.py:117-119and:241-243(a class that skips insetUpClassrunsno test).
tools/testing/target_determination/heuristics/edited_by_pr.py:29-37(edited test files get the top score);
test/run_test.py:1698-1712(the--enable-tddefault, off on macOS) and:2452-2458(the top 25% with target determination, else all tests).The decision and its precedents:
docs/decisions/2026-10-03-macos-ci-scope.md(from the draft with sha2563a5eba0772ed82cf86e0688809788241f676e79072333a0416b75f3371e2b83f), and its receiptevidence/artifacts/macos-ci-scope-20261003/.EditedByPR(pinned above). It is prioritization, not exclusivegating, and the record says so (§5.4). Memon et al., "Taming Google-Scale Continuous Testing", ICSE-SEIP 2017
(pre-submit affected targets, post-submit runs, culprit rollback).
(
Tools/build/compute-changes.py), denoland/deno@b4f08f12 (ci.ts:253-254,:558-591), astral-sh/uv@46b84fd0,astral-sh/ruff@127e77ef, rust-lang/rust@db8f076d.
Linters, at the versions the repository pins:
actionlint_1.17.0_linux_amd64.tar.gz, sha256620abd485a12b6ab1125b844a876414e1d5bd2af8a3125b27f82b01d0d9d6e5a(.github/workflows/validate.yml:89-92).manifests/stack.json), assetshellcheck-v0.11.0.linux.x86_64.tar.xz, verifiedagainst GitHub's asset digest
sha256:8c3be12b05d5c177a04c29e3c78ce89ac86f1595681cab149b65b97c4e227198. Its SC2129is why the output writes are grouped, as
.github/workflows/catalog-freshness.yml:114already does.Evidence-class table
changesscript gives full for a listed path, changed-tests for top-level test modules only, skip for neither or a deletion only, and full on a missing or unknown SHA; each guard has a mutation controllocal_integrationChangesModeComputationTests(bash against scratch git repositories)validate-macos's gate and mode give the record's mode for all 96 event ×changesresult × output inputs, and achangesjob that failed after writingmacos=falseruns in full;0eceddab's outputs-only expressions disagree on exactly those 6 inputslocal_integration(a test-local evaluator of the documented operator subset, not GitHub's evaluator)ValidateMacosGateEvaluationTestslocal_integrationChangedTestsStepRunTestsPATTERNSequal to the push paths,MACOS_PATTERNScoverage and drift guard (27 files: 21 listed, 6 excluded), the D11 push-path pinlocal_integrationtests.test_workflow_hardening(109 tests)if:reports success to a required checksource_reviewsim_r2.jsonlocal_integration(artifact measurement over historical API reads; the simulation is compared, not re-run)evidence/artifacts/macos-ci-scope-20261003/replay.py, exit 0,replay-output.txtlocal_integrationLocal commands run
Repair round, at
nice -n 19withTMPDIR=/var/tmp/c5-macos, one module per run, on the committed tree atace6dd766unless noted.Also at
ace6dd766:tests.test_github_automation_practice(exit 0, Ran 8, OK) andtests.test_adoption_launchd(exit 0, Ran 70, OK (skipped=1)). Not re-run:
tests.test_gitleaks_config(37 OK in the first round, 87 s). Itshistory scan now also covers this round's two commits; the scans above cover their content, and
validate.yml'ssecret-scanjob runs the module with the pinned gitleaks on this head (.github/workflows/validate.yml:363-372).Not available on this host: a bash 3.2 binary (
BASH32_BINARY), so the 3.2 compatibility of thechangesscript andof the changed-tests step rests on construction and on this PR's own macOS run.
Decision record
docs/decisions/2026-10-03-macos-ci-scope.md. Where the implementation goes beyond the record's §6.1 sketch is its§6.8. The first round added:
macoswritten last; grouped output writes (SC2129); an empty-selection guard;LC_ALL=Cfor the module regex; a safe spelling of paths in the step summary; the drift-guard expression; actionlint1.17.0. The repair round added the
changesresult in the gate and mode, and the per-module zero-test guard. T1 staysa process rule (§8.1): the record names no in-repository mechanism, so nothing automates it. One figure does not
reproduce from the record's own saved outputs, and its §10 says so: "52 of 1,211" (51 among pull-request runs; 52
counts one
workflow_dispatchrun). The decision does not rest on it. The simulated (b2) with B+ figures now are thesaved ones (339.9 slot-hours, p90 1.7 min).
Host evidence
Not applicable: no file under
evidence/hosts/changes.Integration notes
manifests/evidence.jsonwas registered against the base's copy plus this branch's rows. At merge, follow thehot-file protocol (
docs/lanes.md): takemain's copy and re-register the 33 filesgit diff --name-only --diff-filter=AM origin/main...HEADlists, thencomponent_matrix.py --write,new_host_grand_list.py --writeandvalidate.py. The textual merge againstb29036f05is clean today; the merged registry was not validated here.pull_requestevent (a push, or close and reopen) to get the newworkflow; a re-run reuses the old SHA and workflow file (record §6.6).
Decision and Alternatives (superseded in part by this record).
re-measurements (§6.6, §6.7).
Checklist
version comment (no floating tags). No action was added or re-pinned.
permissions: contents: read(or a narrower, explicitly justified addition). Unchanged.
added without a documented owner.
moved or overwritten).
🤖 Generated with Claude Code