Skip to content

macOS CI scope: validate-macos stays required, running the full suite for Mac-relevant changes, only changed test modules for test-only changes, and skipping otherwise (decision record, receipt, tests) - #677

Merged
seathatflowsinourveins merged 4 commits into
mainfrom
c5/macos-ci-scope
Oct 4, 2026
Merged

seathatflowsinourveins merged 4 commits into
mainfrom
c5/macos-ci-scope

Conversation

@seathatflowsinourveins

@seathatflowsinourveins seathatflowsinourveins commented Oct 3, 2026 •

Copy link
Copy Markdown
Owner

Scope

  • What this PR changes, in one or two sentences: validate-macos stays required, but on a pull request it now runs
    the full macOS suite only when a macOS-relevant path changes, runs only the changed top-level test modules when
    nothing else relevant changed, and is skipped otherwise; the two macOS bootstrap jobs run on a pull request only in
    full mode, and push, schedule and dispatch runs stay full. This implements
    docs/decisions/2026-10-03-macos-ci-scope.md, adds its receipt, and updates the hardening tests and docs.
  • Base commit: 6112d14d40f741855f0b961124d98939daaad00e (head ace6dd766; origin/main has since moved to
    b29036f05, which touches none of these paths except the shared manifests/evidence.json, and
    git merge-tree --write-tree HEAD origin/main is clean).
  • Lane: lane:foundation.
  • Owned paths touched:
    • .github/workflows/adoption-bootstrap.yml
    • tests/test_workflow_hardening.py, tests/test_adoption_bootstrap_macos.py (comments only)
    • docs/decisions/2026-10-03-macos-ci-scope.md (new), docs/decisions/2026-09-22-github-automation-closure.md
      (a dated note), docs/github-automation.md, adoption/platforms/macos-arm64.md
    • evidence/artifacts/macos-ci-scope-20261003/ (new receipt), .gitignore (one narrow exception for its .jsonl
      input)
    • manifests/evidence.json (registration only, the last commit)

How the three modes work:

Pull request changes changes writes validate-macos bootstrap-macos, -brew
A path in MACOS_PATTERNS (the record's 89, §6.2), or any tests/ path that is not a top-level tests/test_*.py macos=true full suite as before (bootstrap gate)
Only top-level tests/test_*.py modules (still present), plus unlisted paths macos=false, macos_tests=<modules> only those modules (scoped result, not a full-suite pass) skipped
Neither macos=false, macos_tests= skipped by its job-level if: (reports success to the required check; recorded as untested) skipped
changes cannot decide (missing SHA, failed git diff) fail_safe: macos=true full suite as before
changes stops before writing macos no macos output full suite (!= 'false', never == 'true') as before
changes fails after writing its outputs whatever it wrote full suite (needs.changes.result != 'success') as its outputs say
The run is cancelled (a newer push) — cancelled, never skipped (record §1) cancelled

In changed-tests mode, a selected module from which unittest loads no test case fails the step before any test runs,
and the step names it; a selection that loads tests but runs none also fails. Skipped tests are not failures; the step
summary gives their count.

Repair round at ace6dd766

For the Codex root's exact-head source review of 0eceddab (the FINDINGS / HOLD comment) and the review thread "Use
the retained simulation result". Commits: 27b7c8300 (content) and ace6dd766 (registry, last).

  1. Per-module zero-test guarantee (root finding 1). The changed-tests step
    (.github/workflows/adoption-bootstrap.yml:995-1005) loads each selected module on its own with
    unittest.defaultTestLoader.loadTestsFromName before unittest runs, and fails naming the module when
    countTestCases() is 0; the exit code decides, so import-time output cannot fool it. The aggregate guard
    (:1013-1017) stays for a selection that loads tests but runs none.
    • Tests (tests/test_workflow_hardening.py, ChangedTestsStepRunTests):
      test_a_module_with_no_test_beside_a_module_with_tests_fails_naming_it (both orders: exit 1, the error names
      tests.test_zz_empty, unittest never starts) and test_a_module_with_no_test_fails_before_unittest_runs.
    • Negative control: test_control_without_the_per_module_guard_the_aggregate_check_passes_the_mixed_selection.
      With the guard line neutralized, which leaves 0eceddab's logic, tests.test_zz_pass tests.test_zz_empty
      exits 0 with "ran 1 tests".
    • test_a_selection_that_loads_tests_but_runs_none_fails_as_untested keeps the aggregate guard's own case with a
      real interpreter: a class that skips in setUpClass (Ran 0, OK (skipped=1), exit 0).
    • ValidateMacosModeTests pins the guard's text and its place before the run; its control drops either guard.
  2. Failure fallback (root finding 2). The gate (:812) adds needs.changes.result != 'success', and the mode
    (:820) adds needs.changes.result == 'success' to its changed-tests branch. A changes job that does not
    succeed now runs the full job, whatever outputs it wrote.
    • Tests: ValidateMacosGateEvaluationTests evaluates both expressions with a test-local evaluator of the
      documented operator subset (!, ==, !=, &&, ||, parentheses, strings, property paths, cancelled();
      anything else raises). It covers 96 inputs (4 events × 4 changes results × 3 macos values × 2 module lists)
      against the record's §2 table, and includes
      test_a_changes_job_that_failed_after_writing_macos_false_runs_in_full. The oracle has its own test of the
      cited semantics.
    • Negative control: test_control_the_outputs_only_gate_and_mode_scope_or_skip_a_failed_changes_job. 0eceddab's
      gate and mode, byte-identical to git show 0eceddab:.github/workflows/adoption-bootstrap.yml, disagree with the
      table on exactly the 6 inputs (pull_request, failure|cancelled|skipped, macos=false, either module list). They
      give changed-tests with modules and a skip without.
    • Text pins: two more mutations in test_the_pre_fix_condition_text_fails_this_tests_own_assertions (the result
      term dropped from the gate, or from the mode).
    • Discrimination check, run once and not committed: with the new tests pointed at 0eceddab's workflow, 10
      gate/mode subtests and all 3 changed-tests cases fail.
  3. Limits kept explicit (decision record). The status line lists this round's edits.
    • §5.4: EditedByPR establishes prioritization, not exclusive gating. pytorch@dd5cbc42 runs only the top 25% with
      target determination on, and its default leaves that off on macOS.
    • §6.2: the drift guard is textual; C6's closure was computed once.
    • §9: the fixed selector reads an unknown ordinary path as not Mac-relevant by design. The replay, simulation and
      classifications are owner reports. Failed-job output retention was not observed on a hosted run. Skips pass.
    • §6.5: the receipt bullet no longer claims the simulation code.
    • §6.7: control (f′), not run. §6.8: implementation notes. §11: disposition.
  4. Review thread PRRT_kwDOUg_LrM6osJBK (P2). §3.5 (L396) and §5 (L501-504) now use sim_r2.json: (b2) with B+
    is 339.9 slot-hours and p90 1.7 min, and B+ saves 27.8 slot-hours, not 48. replay.py checks every simulated
    figure the record states against sim_r2.json (9 checks, all OK; compared, not re-run, since the simulation code
    was not retained). The (a-mac) and (b1) simulated figures are labelled as having no saved output.
  5. Hot-file protocol. The six changed files are re-registered with host_receipts.register_file in the last
    commit. component_matrix.py --check and new_host_grand_list.py --check are unchanged. Against origin/main at
    b29036f05, git merge-tree --write-tree exits 0, and the registry is the only shared path. No merge commit was
    needed, so no patch-id comparison applies. Pushed fast-forward 0eceddab0..ace6dd766; git ls-remote reads
    ace6dd76663951526406446d65f2acbb4c6825b1.

SOTA sources

GitHub documentation (the load-bearing behavior), re-read 2026-10-03T21:09Z:

Repair round, re-read 2026-10-03 at fixed commits:

  • github/docs@2bd66de, content/actions/reference/workflows-and-actions/:
    contexts.md:777-779 (needs.<job_id>.outputs, and needs.<job_id>.result with success, failure, cancelled
    or skipped); expressions.md:30 (falsy values), :52-68 (operators; strings compare ignoring case), :322 (a
    status check function replaces the default success()).
  • actions/runner@d7bc179,
    src/Sdk/DTExpressions2/Expressions2/Sdk/Operators/And.cs:33-49 and Or.cs:33-49: && and || return an
    operand's value, which the cond && 'changed-tests' || 'full' mode relies on.
  • python/cpython@f6650f9, Lib/unittest/: loader.py:203-208 (named modules merged
    into one suite), runner.py:254-256 (one aggregate "Ran N tests" line), main.py:283-288 (exit status 5 only
    when no test ran and none was skipped), suite.py:117-119 and :241-243 (a class that skips in setUpClass runs
    no test).
  • pytorch/pytorch@dd5cbc4: tools/testing/target_determination/heuristics/edited_by_pr.py:29-37
    (edited test files get the top score); test/run_test.py:1698-1712 (the --enable-td default, off on macOS) and
    :2452-2458 (the top 25% with target determination, else all tests).

The decision and its precedents:

  • The decision record, docs/decisions/2026-10-03-macos-ci-scope.md (from the draft with sha256
    3a5eba0772ed82cf86e0688809788241f676e79072333a0416b75f3371e2b83f), and its receipt
    evidence/artifacts/macos-ci-scope-20261003/.
  • Prioritizing the tests a change edits: PyTorch EditedByPR (pinned above). It is prioritization, not exclusive
    gating, and the record says so (§5.4). Memon et al., "Taming Google-Scale Continuous Testing", ICSE-SEIP 2017
    (pre-submit affected targets, post-submit runs, culprit rollback).
  • Change-based gating of platform jobs on pull requests, as the record cites: python/cpython@83b40d06
    (Tools/build/compute-changes.py), denoland/deno@b4f08f12 (ci.ts:253-254, :558-591), astral-sh/uv@46b84fd0,
    astral-sh/ruff@127e77ef, rust-lang/rust@db8f076d.

Linters, at the versions the repository pins:

  • kjanat/actionlint v1.17.0, actionlint_1.17.0_linux_amd64.tar.gz, sha256
    620abd485a12b6ab1125b844a876414e1d5bd2af8a3125b27f82b01d0d9d6e5a (.github/workflows/validate.yml:89-92).
  • koalaman/shellcheck v0.11.0 (manifests/stack.json), asset shellcheck-v0.11.0.linux.x86_64.tar.xz, verified
    against GitHub's asset digest sha256:8c3be12b05d5c177a04c29e3c78ce89ac86f1595681cab149b65b97c4e227198. Its SC2129
    is why the output writes are grouped, as .github/workflows/catalog-freshness.yml:114 already does.
  • zizmor 1.30.1 (the repository's offline strict pass).

Evidence-class table

Claim Evidence class Command / receipt
The changes script gives full for a listed path, changed-tests for top-level test modules only, skip for neither or a deletion only, and full on a missing or unknown SHA; each guard has a mutation control local_integration ChangesModeComputationTests (bash against scratch git repositories)
validate-macos's gate and mode give the record's mode for all 96 event × changes result × output inputs, and a changes job that failed after writing macos=false runs in full; 0eceddab's outputs-only expressions disagree on exactly those 6 inputs local_integration (a test-local evaluator of the documented operator subset, not GitHub's evaluator) ValidateMacosGateEvaluationTests
The changed-tests step passes a scoped run; it fails a failing selection, a module with no test (alone or beside one with tests, before unittest runs), a selection that loads tests but runs none, and an empty or malformed selection; without the per-module guard the mixed selection passes; the aggregate guard is what fails a "Ran 0 tests" exit 0 local_integration ChangedTestsStepRunTests
Gate text (with the result terms), B+, fail-safe outputs, step guards, PATTERNS equal to the push paths, MACOS_PATTERNS coverage and drift guard (27 files: 21 listed, 6 excluded), the D11 push-path pin local_integration tests.test_workflow_hardening (109 tests)
A job skipped by its own if: reports success to a required check source_review the GitHub docs above; hosted control (b) of the record's §6.7 has not run
The shipped 89-pattern list reproduces the record's tables (B0, B′, (a-mac), (a-all), (b2); D1; 30-run table; main exposure; coverage), and the record's simulated figures equal sim_r2.json local_integration (artifact measurement over historical API reads; the simulation is compared, not re-run) evidence/artifacts/macos-ci-scope-20261003/replay.py, exit 0, replay-output.txt
The workflow lints clean local_integration actionlint 1.17.0 with shellcheck 0.11.0; zizmor 1.30.1 offline
Behavior on GitHub-hosted runners (all three modes, required-check reporting, macOS bash, whether a failed job keeps its outputs) not yet observed this PR's own run is control (a); controls (b) to (g) and (f′) are pending

Local commands run

Repair round, at nice -n 19 with TMPDIR=/var/tmp/c5-macos, one module per run, on the committed tree at
ace6dd766 unless noted.

$ python3 -m unittest tests.test_workflow_hardening
exit 0: Ran 109 tests in 4.541s / OK (skipped=2)   # PyYAML absent; the hash-frozen list is empty
$ uv run --no-project --with pyyaml==6.0.3 python3 -m unittest tests.test_workflow_hardening
exit 0: Ran 109 tests in 4.728s / OK (skipped=1)   # the YAML parser cross-check executes
$ python3 -m unittest tests.test_adoption_bootstrap_macos
exit 0: Ran 161 tests in 40.427s / OK (skipped=32)
$ python3 -m unittest tests.test_shell_parser_ci           # at 27b7c8300's content (the registry commit changes neither input)
exit 0: Ran 37 tests in 2.527s / OK (skipped=1)
$ python3 -m unittest tests.test_workflow_security_coverage  # same
exit 0: Ran 10 tests in 0.686s / OK
$ python3 -m unittest tests.test_codex_broker_reaper        # same
exit 0: Ran 60 tests in 6.220s / OK
$ python3 -m unittest tests.test_landscape_sweep_skills     # same
exit 0: Ran 110 tests in 7.248s / OK (skipped=40)
$ python3 -m unittest tests.test_adoption_bootstrap         # same
exit 0: Ran 80 tests in 15.458s / OK
$ python3 -m unittest tests.test_adoption_docs_consistency
exit 0: Ran 39 tests in 13.055s / OK (skipped=1)
$ actionlint -color .github/workflows/adoption-bootstrap.yml   # kjanat 1.17.0 and shellcheck 0.11.0, sha256-verified, deleted afterwards
exit 0, no output (repo-wide `actionlint -color`, as validate.yml runs it: exit 0, no output)
$ zizmor --offline --no-config --no-ignores --no-progress --persona regular --strict-collection --format json .github/workflows/adoption-bootstrap.yml
exit 0, 0 findings (the same over `.`: exit 0, 0 findings)
$ python3 scripts/validate.py
exit 0: {"components": 69, "hashed_files": 9589, "profiles": 4, "receipts": 193, "status": "passed"}
$ python3 evidence/artifacts/macos-ci-scope-20261003/replay.py
exit 0 (4 s): 41 OK, PASS: 0 mismatch(es); its output is the committed replay-output.txt
$ python3 scripts/host_receipts.py validate; component_matrix.py --check; new_host_grand_list.py --check; build_ecosystem.py --check; validate_foundation.py --root . --json; validate_catalogs.py; landscape.py --root .; validate_convergence.py --all-recorded --root . --json; build_verdicts.py --check
exit 0 each
$ python3 scripts/validate.py --scan-file <each of the 6 changed files>; gitleaks dir <copies of the same files> --config .gitleaks.toml --redact
exit 0: {"scanned_files": 6, "status": "passed"}; no leaks found (the pre-commit gitleaks hook also passed both commits)

Also at ace6dd766: tests.test_github_automation_practice (exit 0, Ran 8, OK) and tests.test_adoption_launchd
(exit 0, Ran 70, OK (skipped=1)). Not re-run: tests.test_gitleaks_config (37 OK in the first round, 87 s). Its
history scan now also covers this round's two commits; the scans above cover their content, and validate.yml's
secret-scan job runs the module with the pinned gitleaks on this head (.github/workflows/validate.yml:363-372).

Not available on this host: a bash 3.2 binary (BASH32_BINARY), so the 3.2 compatibility of the changes script and
of the changed-tests step rests on construction and on this PR's own macOS run.

Decision record

docs/decisions/2026-10-03-macos-ci-scope.md. Where the implementation goes beyond the record's §6.1 sketch is its
§6.8. The first round added: macos written last; grouped output writes (SC2129); an empty-selection guard;
LC_ALL=C for the module regex; a safe spelling of paths in the step summary; the drift-guard expression; actionlint
1.17.0. The repair round added the changes result in the gate and mode, and the per-module zero-test guard. T1 stays
a process rule (§8.1): the record names no in-repository mechanism, so nothing automates it. One figure does not
reproduce from the record's own saved outputs, and its §10 says so: "52 of 1,211" (51 among pull-request runs; 52
counts one workflow_dispatch run). The decision does not rest on it. The simulated (b2) with B+ figures now are the
saved ones (339.9 slot-hours, p90 1.7 min).

Host evidence

Not applicable: no file under evidence/hosts/ changes.

Integration notes

  • manifests/evidence.json was registered against the base's copy plus this branch's rows. At merge, follow the
    hot-file protocol (docs/lanes.md): take main's copy and re-register the 33 files git diff --name-only --diff-filter=AM origin/main...HEAD lists, then component_matrix.py --write, new_host_grand_list.py --write and
    validate.py. The textual merge against b29036f05 is clean today; the merged registry was not validated here.
  • After merge, each open pull request needs a new pull_request event (a push, or close and reopen) to get the new
    workflow; a re-run reuses the old SHA and workflow file (record §6.6).
  • Owner decisions, not made here: cancelling queued pull-request runs by recorded ID (§6.6), and PR Record the macOS full-suite coverage decision, the CI measurements and five anti-patterns #632's
    Decision and Alternatives (superseded in part by this record).
  • Pending: the record's hosted controls (b) to (g) and (f′) on throwaway pull requests, and the 24-hour and 7-day
    re-measurements (§6.6, §6.7).

Checklist

  • New/changed GitHub Actions are pinned to a full commit SHA with a
    version comment (no floating tags). No action was added or re-pinned.
  • New/changed workflows declare top-level permissions: contents: read
    (or a narrower, explicitly justified addition). Unchanged.
  • No secrets are printed, logged or committed; no new required secret was
    added without a documented owner.
  • No new paid hosting, subscription or billing surface was introduced.
  • Peer-owned untracked files and worktrees were preserved (not deleted,
    moved or overwritten).

🤖 Generated with Claude Code

Scout and others added 2 commits October 3, 2026 17:47
… pull requests

Implements docs/decisions/2026-10-03-macos-ci-scope.md (draft sha256 3a5eba0772ed82cf...).

- .github/workflows/adoption-bootstrap.yml: the changes job writes macos and
  macos_tests from the record's 89-entry MACOS_PATTERNS (outputs grouped,
  macos written last, every failure path calls fail_safe). validate-macos stays
  required and gains needs: changes, a fail-safe job-level if: (a skipped job
  reports success) and VALIDATE_MACOS_MODE; its 15 full-mode steps are guarded
  and a changed-tests step runs only the changed top-level test modules, with
  empty-selection and zero-test guards. bootstrap-macos and bootstrap-macos-brew
  run on a pull request only in full mode (B+). Push, schedule and dispatch
  runs stay full; the push paths keep manifests/evidence.json as the
  post-merge net.
- tests/test_workflow_hardening.py: the D9 expectation changes, plus
  MacosPatternsTests (coverage, drift guard, D8), PushNetTests (D11),
  ValidateMacosModeTests, and runs of the changes script and the changed-tests
  step against scratch repositories, each guard with a mutation control.
  tests/test_adoption_bootstrap_macos.py: comments only.
- docs: the decision record; docs/github-automation.md; a dated note on the
  closure record; adoption/platforms/macos-arm64.md.
- evidence/artifacts/macos-ci-scope-20261003: the replay inputs the record
  cites, its saved outputs, and replay.py, which reproduces the record's
  tables from them (exit 0; output retained). .gitignore gains a narrow
  exception for the receipt's one .jsonl input, as for earlier receipts.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Hot-file protocol (docs/lanes.md): the base's manifests/evidence.json
(6112d14) with the branch's 7 changed and 26 new files registered through
host_receipts.register_file; component_matrix.py --write and
new_host_grand_list.py --write left their reports unchanged.
python3 scripts/validate.py passes (9589 hashed files).

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
@seathatflowsinourveins seathatflowsinourveins added the lane:foundation Foundation lane: Claude/Codex setup, hosts, memory, RAG, research, workers label Oct 3, 2026
@chatgpt-codex-connector

chatgpt-codex-connector Bot commented Oct 3, 2026 •

Copy link
Copy Markdown

Codex Review Summary

This comment shows the latest Codex review activity on this pull request.

Review Status Commit Review trigger
📝 Code Review ✅ Completed 2026-10-03T22:08:06.761898Z 0ecedda PR opened
ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review" or "@codex security review".

Codex reacts with 👀 while any review is running, comments if it has suggestions, and reacts with 👍 once all reviews finish with no findings.

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: 0eceddab0c

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment thread docs/decisions/2026-10-03-macos-ci-scope.md Outdated
@seathatflowsinourveins

Copy link
Copy Markdown
Owner Author

FINDINGS / HOLD for #677 head 0eceddab0cec33d8ff4f55233a097093cf4e5ac1. This is an exact-head source review; no hosted control or native fixture was executed by root.

  1. The per-module zero-test guarantee is not implemented. The decision says a selected module with zero tests fails. The oracle invokes all selected modules together and rejects only an aggregate zero count. Pinned CPython combines named suites and prints aggregate testsRun. An otherwise passing nonempty module alongside an empty module therefore escapes this guard. The existing single-empty-module fixture does not cover that mixed selection. Please enforce the declared per-module contract and retain a mixed-selection check, or narrow the decision and acceptance claim explicitly.

  2. Failure fallback needs its own result condition or a narrower claim. The decision promises full validation if changes fails. The job gate and mode inspect outputs without needs.changes.result; outputs are written before the final summary write. For a failed changes job with populated macos=false, a nonempty module list selects changed-tests and an empty list skips the job. Empty outputs correctly select full mode. GitHub documents outputs and result separately. This is a conditional source counterexample; failed-job output retention was not exercised on a hosted run here. Qualify that case or use the dependency result for the stated fail-safe guarantee. !cancelled() already overrides the implicit success condition under official status semantics; that is not the defect.

Root independently rehashed all 42 present owned head/base bodies and 15 pinned primary originals against their Git identities and checked all 33 owned payload registry bindings; all non-files registry fields remain exact. The frozen packet distinguishes 34 exact PR-owned paths from 110 raw main-to-head paths carrying foreign branch differences. Prospective merge preservation remains unqualified; raw gaps are not proof of eventual deletion.

The fixed selector intentionally skips unknown well-formed unlisted paths. Its textual drift guard is not dependency-graph discovery. The cited PyTorch EditedByPR establishes prioritization, not exclusive test gating. Keep those limits explicit. Retained historical replay, simulation and model outcomes remain owner reports, including the unretained simulation code; they are not new root executions or native upstream acceptance.

Repairs belong to the Claude owner. No root workflow/manifest edit, hosted dispatch, test execution, merge, active client/configuration read or credential/auth access occurred. The root parser's initial dictionary assumption for a list-shaped source map failed; the corrected type-aware verifier checked the exact retained bodies successfully, and the processing failure is preserved.

Scout and others added 2 commits October 3, 2026 19:03
…fail-safe

Repair round for the Codex root's source review of head 0ecedda and the
P2 review thread on the decision record.

- validate-macos: the gate adds needs.changes.result != 'success' and the
  mode's changed-tests branch adds needs.changes.result == 'success', so a
  changes job that did not succeed runs the full job whatever outputs it
  wrote (root finding 2).
- The changed-tests step counts each selected module's test cases before
  unittest runs and fails naming a module that loads none; the aggregate
  "Ran N tests" guard stays for a selection that loads tests but runs none
  (root finding 1).
- Tests: the gate and mode are evaluated over every event, changes result
  and output value against the record's table, with 0ecedda's
  outputs-only gate and mode as the negative control; a module with no
  test beside one with tests fails, and without the per-module guard the
  aggregate check passes it.
- Decision record: precise fail-safe and zero-test wording; EditedByPR as
  prioritization, not exclusive gating; the textual drift guard; the fixed
  selector, owner reports and unobserved failed-job outputs as residuals;
  section 3.5 and 5 use sim_r2.json's saved (b2)+B+ figures (339.9
  slot-hours, p90 1.7 min); disposition and pinned sources.
- Receipt: replay.py checks every simulated figure the record states
  against sim_r2.json; replay-output.txt re-run (exit 0); README updated.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
The workflow, the hardening tests, the decision record and the receipt's
README, replay.py and replay-output.txt, through
host_receipts.register_file (docs/lanes.md, hot-file protocol). The
component matrix and new-host grand list check unchanged.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
@seathatflowsinourveins

Copy link
Copy Markdown
Owner Author

SOURCE ACCEPT WITH LIMITS — exact head ace6dd76663951526406446d65f2acbb4c6825b1, replacing my findings on 0eceddab0cec33d8ff4f55233a097093cf4e5ac1 in #677 (comment).

The two source findings close:

  1. Every selected module now receives a loadTestsFromName(...).countTestCases() preflight; a zero-case module fails independently of a nonempty module and its order. The combined run retains its aggregate zero-tests guard. This guarantees positive loaded-case count per selected module, with skipped tests allowed; it does not guarantee positive executed-case count for every module. Workflow at this head, declared skip/count scope, CPython recursive loaded-case count at f6650f9.
  2. An uncancelled failed changes job explicitly selects macOS and cannot enter changed-tests mode even when a retained output is false; mode falls back to full. This closes the unsuccessful-needs/output interaction in the source. Job condition, mode expression, runner short-circuit operand semantics at d7bc179.

I independently checked all 34 owned payloads, 33 registrations, six commit originals and all 20 pinned upstream originals, including the five newly acquired references. Full foreign preservation is exact against both the prior reviewed head and actual construction base 6112d14d40f741855f0b961124d98939daaad00e: 10,257 Git tuples and 9,556 ordered full evidence rows, plus non-file state. Acquisition handles all closed successfully; this was source inspection, with no fixture, upstream test or hosted control rerun.

Well-formed unlisted paths intentionally skip; this is a fixed textual selector, not a dependency graph. Historical replay, prior failure and warning evidence remain historical. The hosted failed-changes control and prospective merge acceptance remain unverified. The inherited differences against observed main b29036f05905f75df934603eb8f1d2248a01c543 are not attributed to this repair; source acceptance does not certify that prospective merged tree or runtime acceptance.

@seathatflowsinourveins

Copy link
Copy Markdown
Owner Author

Actual merged-source carry ACCEPT WITH LIMITS — landing e0c329ae98efb6ac5e11a49220b69ec6eddbb658, reviewed head ace6dd76663951526406446d65f2acbb4c6825b1, sole parent 7d0174168d478d8e3a01602db2138905b6130f8a. GitHub reports #677 merged at 2026-10-04T00:35:21Z.

Root independently rehashed all 182 frozen bindings and 112 original streams from 56 native commands0, reconstructed all three complete Git trees against their full commit originals, and rederived the actual 34-path roster. All 33 payload modes/types/OIDs and full registration rows match the ACE source verdict.

All 10,269 ordered foreign Git tuples and 9,563 ordered foreign full registration rows remain exact against the prior main. All 9,570 prior registration positions survive projection; the 26 new rows belong to the reviewed payload. Every non-files field, all 193 receipts and all 29 convergence records remain exact. Root explicitly joined every map membership to its complete captured tree: 76 present body joins, including all three registries, plus 26 verified absent prior scopes; zero mismatches.

Frozen manifest113099B/SHA256 60a17275ad39c4cdf591c23eb5d6599fac1ea0a4b5eb99f6038b08552194274d. This is an actual landing observation, extending the earlier prospective source review. The positive LOADED per-module case remains a source case; it was not executed per module here. Skip behavior and the uncancelled full fallback retain their original reviewed scope. This establishes no fresh hosted CI, destination installation, model run, role qualification or GPU acceptance.

One root processing failure is retained: the absent-scope schema omits body_map_claimed_membership; the initial observer incorrectly required the key and exited1 with KeyError. The bounded repair accepts omitted/null claims only for a path independently absent from the complete tree; the rerun exited0. No gate, source payload, registry or upstream test changed. Object derivation follows Git v2.43.0 commit 564d0252ca632e0264ed670534a51d18a689ef5d, Documentation/git-cat-file.txt and Documentation/git-ls-tree.txt, with explicit source-map joins supplementing the frozen root observer.

seathatflowsinourveins pushed a commit that referenced this pull request Oct 4, 2026
… protocol: main's rows plus the owned bindings)

Only manifests/evidence.json conflicted. It is main's copy plus register_file for the 76 PR-owned paths (72 new rows, 4 updated); the three-way merge helper produced byte-identical output. #677's hunks in tests/test_workflow_hardening.py (two imports, then from line 1235) and docs/decisions/2026-09-22-github-automation-closure.md (line 1421) are region-disjoint from this PR's and merged cleanly; their registry rows bind the merged bytes. Both generator --check commands exit 0, so no --write ran.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
seathatflowsinourveins pushed a commit that referenced this pull request Oct 4, 2026
…(hot-file protocol)

Reapplies the merge commit's registry: main's copy plus register_file for the 76 PR-owned paths. The two files #677 also changed, tests/test_workflow_hardening.py and docs/decisions/2026-09-22-github-automation-closure.md, are bound at their merged bytes.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
seathatflowsinourveins pushed a commit that referenced this pull request Oct 4, 2026
…utation runs in manifests/evidence.json

Hot-file protocol (docs/lanes.md): this is the branch's last commit, on main e0c329a (#677), and takes main's
manifests/evidence.json. It re-registers the closure record, the receipt and docs/harness-defaults.md, and the 71
files under evidence/artifacts/frozen-variant-guard-mutations-20261003/. component_matrix --write and
new_host_grand_list --write changed nothing else.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
seathatflowsinourveins added a commit that referenced this pull request Oct 4, 2026
…ant) (#635)

* Record and guard the Dependabot alert 16 dismissal on the frozen macOS variant

The closure record notes the dismissal of Dependabot alert 16 (GHSA-vcvr-r3jv-pc5j) as not_used on the frozen
macOS variant's package.json, with its API readback receipt,
evidence/receipts/dependabot-alert-16-dismissal-20261003.json. tests/test_frozen_macos_variant_no_use.py, a
tripwire in the required validate job, fails when:
- a scanned file names the frozen artifact directory beyond its pinned lines;
- the directory gains a file;
- the lock or its next pin changes;
- the frozen OSV exception's date or keys change.

The guard's mutation driver is kept under evidence/artifacts/frozen-variant-guard-mutations-20261003/. The
anti-pattern log gains two 2026-10-03 rows.

This commit replaces the branch's earlier content commits (review rounds 1-7), rebuilt on main 4ced292, so that
no commit on the branch quotes a user message. Its tree equals round 7's first content commit 8f547913, apart from
main's changes since 9b0b8d6.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* Retain the guard's mutation runs and disclose the retained driver's assembled name

The mutation driver's returned results are kept under
evidence/artifacts/frozen-variant-guard-mutations-20261003/:
- round 8's final run: all 45 rows against the content commit a447a51, every row as expected;
- round 7's three runs of the new rows against the round-3, round-4 and round-5 modules. Each gap row passes
  there, so each of these runs exits 1 by design.

runs.json gives the argument vectors, times, exit codes, clone heads and hashes. Clone roots, the output directory
and the Python prefix are replaced with placeholders.

The receipt's table equals the retained output (45 rows, 0 mismatches) and binds the driver and runs.json by
sha256. Its limitations now say:
- the retained driver assembles the artifact name from fragments, a stated blind spot of the guard, and
  installs, builds or serves nothing;
- configuration names inside an excluded class that differ only in letter case are not read.

The closure note says "ASCII letter case", since the module folds ASCII letters only.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* Keep the control runs' modules, rebuild the controls on main and record the indirect-route decision

This commit answers the Codex review at 06c90df.

Control runs:
- The three earlier modules the control runs used are kept byte for byte, as .txt files, under
  evidence/artifacts/frozen-variant-guard-mutations-20261003/controls/. The guard does not read .txt files under
  evidence/**, and the receipt says so.
- The control runs were re-run on main's d2777ee with each kept module committed in a scratch clone, so anyone can
  rebuild them from the repository. Their outcomes, failing tests and messages equal round 7's runs, which they
  replace. runs.json records each control's base commit and module file.

Indirect routes: the receipt gains indirect_routes, a dated decision. The dismissal stands, and the indirect routes
stay stated limits. The record names:
- the alternatives declined: pinning the 43 lines that read the inventory, pinning the 297 package-manager lines,
  resolving each command's target, reopening the alert, and keeping the frozen manifest under names that tools
  don't parse;
- the precedent;
- the dated backstop of the OSV exception: it lapses on 2026-12-24, can be renewed at most 90 days ahead, and each
  renewal fails the review-date test.
The closure note points to the decision.

Round 8 review fixes:
- runs.json defines <repo> without tying it to the final run's clone head.
- runs.json describes the commits after the content commit accurately.
- The receipt states X15's correction as a deduction from the module.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* Correct the alert-16 backstop and precedent, record the convergence decision and log the tripwire scope miss

This commit answers the round-9 review and the Codex review at 9faa5c4.

Backstop: once the frozen exception lapses, the required osv-scanner job fails in its unittest preflight
(FrozenScanTests) before OSV-Scanner runs, and validate's full suite fails IgnorePolicyTests, both through
ignore_entry_problems. A renewal that also edits REVIEW_DATE passes, and the receipt now says so.

Precedent: the dismissal of alerts 7-15 that this record cites was superseded on 2026-09-25 by renaming the fixture
(#224). The authorization, reasoning.precedent and indirect_routes now say so.

Convergence decision: indirect_routes records the same day's convergence round. It ran Claude and GPT-6 research,
two GPT-6 Astra and two Claude Opus votes, and took the GitHub/CI lane session's input. It chose to rename both
frozen variant files to .frozen and stop scanning them in a follow-up pull request. The dismissal and the tripwire
stand until then. The overturn and the closure note carry the new conditions.

Other fixes:
- The two counts now record their exact git grep commands.
- The statement that the guard does not read the .txt control modules names the recogniser's conditions.
- docs/harness-defaults.md gains a row for scoping a tripwire by expected file kinds, proven by controls N1, N4-N6,
  N7 and X13.
- The branch is rebased onto main 59f8a1e (#653).

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* Qualify the tripwire-scope anti-pattern row to the guard's actual reach

The Codex review at 47da9f8 found that the new row's rule said the guard reads JSON launch configurations inside
the record classes. The guard deliberately leaves `evidence/**/launch.json` unread: it is stated limit L5, and its
control passes. The rule now scans every file outside the record classes, reads each recognised runnable or
configuring kind inside them, and names every kind left unread as a stated limit with a passing control.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

* Register the alert-16 receipt, the changed records and the retained mutation runs in manifests/evidence.json

Hot-file protocol (docs/lanes.md): this is the branch's last commit, on main e0c329a (#677), and takes main's
manifests/evidence.json. It re-registers the closure record, the receipt and docs/harness-defaults.md, and the 71
files under evidence/artifacts/frozen-variant-guard-mutations-20261003/. component_matrix --write and
new_host_grand_list --write changed nothing else.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

---------

Co-authored-by: Scout <scout@local>
Co-authored-by: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
seathatflowsinourveins added a commit that referenced this pull request Oct 4, 2026
…673)

* fix(ci): port OSV split-scan policy and mutation hardening

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>

* chore(evidence): register OSV split-hardening port artifacts

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>

* Review repair: exact override keys, overturn clause, neutral wording

Independent Opus review of 48bbe5c (verdict repair, 0 blocking,
2 should-fix, 5 minor), one repair round:

- override_problems rejects [[PackageOverrides]] keys outside the
  PackageOverrideEntry toml tags at OSV-Scanner v2.6.0
  (internal/config/config.go:38-49, nested :83-89); main's next/braces
  name assertion is restored beside it; two case-aliased mutation cases
  and three unit cases are added.
- The closure record's first overturn trigger again ends with
  "; or OSV lists an advisory ...", followed by the removal procedure.
- Coordinator-owned steps are worded neutrally, the helper's
  "sum check: 0 == 53" line is quoted verbatim, and the overwritten
  first component-matrix output is recorded.
- The receipt gains a repair_round with the discriminating controls,
  whose script and output are retained as artifacts.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>

* Register the review-repair files in the evidence manifest

Re-registers the four changed port files and the two new repair-round
artifacts with scripts.host_receipts.register_file on top of the PR's
registry; foreign rows are unchanged. component_matrix.py --check and
new_host_grand_list.py --check pass, so no generator --write was run.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>

* Re-check minors: discriminating advisory mutation, review status, retained repair controls

- tests/test_osv_lockfile_coverage.py: the 'advisory' mutation now adds a
  well-formed exception (reason, ignoreUntil 30 days out) and asserts that
  ignore_entry_problems accepts it, so only the frozen-id check can reject it.
- Receipt: independent_review.status states the review and re-check verdicts;
  the override-key-function and three-module-unittest repair controls gain
  retained re-runs; recheck_round records the discriminating control.
- Artifacts: recheck-advisory-mutation-control.{py,stdout}.txt,
  repair-round-override-key-function.{py,stdout}.txt and
  repair-round-three-module-unittest.{stdout,stderr}.txt.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>

* Register the re-check minors files in the evidence manifest

register_file for the test module, the receipt and the six new control
artifacts on top of the branch registry (9628 -> 9634 rows). Both generator
--check commands passed, so no --write ran.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>

* Hot-file protocol: restore main's copy of manifests/evidence.json before this PR's last commit

The merge commit carries the resolved registry; this commit returns it to main e0c329a's copy so that the next, last commit carries the PR's registry rows.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>

* Shared hot file last: this PR's evidence registry rows on main e0c329a (hot-file protocol)

Reapplies the merge commit's registry: main's copy plus register_file for the 76 PR-owned paths. The two files #677 also changed, tests/test_workflow_hardening.py and docs/decisions/2026-09-22-github-automation-closure.md, are bound at their merged bytes.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>

* Hot-file protocol: reset manifests/evidence.json to the merge base before the final registry commit

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>

* Register this branch's files on the merge-base registry (hot-file protocol: every registry edit in the last commit)

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>

* Pin #673's two check-only references to the frozen macOS lock; record the alert-16 recheck

After main merged in, CI's full unittest run failed the alert-16 tripwire (tests/test_frozen_macos_variant_no_use.py)
on two lines this port adds that name the frozen lock: the FROZEN constant of its retained split-scan control copy,
and tests/test_osv_lockfile_coverage.py's copy of the workflow's assignment check used by the split-scan mutants.
Both only scan or check the lock; nothing builds, runs or serves from it. Per the tripwire's own rule, both are
pinned in PINNED_LINES after review, under the hashes of their already-pinned originals (the 2026-09-30 relock
control's FROZEN constant and SCAN_ASSIGNMENT); pins only, no recogniser, scope rule or excluded class changes.
The closure record's alert-16 section gains the dated recheck its overturn asks for when the tripwire fails.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>

* Hot-file protocol: reset manifests/evidence.json to the merge base before the final registry commit

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>

* Register this branch's files on the merge-base registry (hot-file protocol: every registry edit in the last commit)

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>

* Hot-file protocol: reset manifests/evidence.json to the merge base before the final registry commit

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>

* Register this branch's files on the merge-base registry (hot-file protocol: every registry edit in the last commit)

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>

* Hot-file protocol: reset manifests/evidence.json to the merge base before the final hot-file commit

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>

* Reapply this branch's manifests/evidence.json edits on the merge base (hot-file protocol: every hot-file edit in the last commit)

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>

---------

Co-authored-by: Scout <scout@local>
Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com>
seathatflowsinourveins pushed a commit that referenced this pull request Oct 4, 2026
…ify the six cache calls' batch timestamps in the receipt (review 632 P1, P2)

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
seathatflowsinourveins added a commit that referenced this pull request Oct 4, 2026
…d five anti-patterns (#632)

* Record the macOS full-suite coverage decision, the CI measurements and five anti-patterns

The 2026-10-03 GitHub CI review measured the required test jobs: both run the
whole suite (about 9,500 tests) serially, Linux validate in 1,727-1,828 s
against a 2,400 s limit and macOS validate-macos in 1,932-2,394 s, and 30 of
1,025 pull-request head SHAs (2.9%) failed only on macOS in 8 days. The decision
record keeps full macOS coverage on every pull request (O4), pre-registers a
fallback that gates only the full-suite step (O2, not adopted, with a prospective
shadow phase, a frozen escape bound and a derived INERT list), rejects gating the
whole job (O1, forbidden by tests/test_workflow_hardening.py:1247-1255) and
running the suite only after merge (O3), and lists reductions R1 to R6 for their
owners. The measurements are kept as a durable receipt because Actions run ids
expire with the new retention period; the itemized failing runs carry their head
SHAs. Five proven mistakes join the anti-pattern log.

Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>

* Publish the CI measurement input and later reads; reconcile the receipt

Answer the review threads on the receipt with published evidence:

- Publish the compiled measurement input byte-identical
  (evidence/artifacts/github-ci-measurements-20261003/input.json, sha256
  d01f9b63...) and the read-only GET calls of 2026-10-03 that check the
  receipt (later-reads-20261003.json: 218 calls with argument vectors,
  times, exit codes and payload hashes; payloads withheld because they
  carry commit author emails).
- Add a queries section: request forms reconstructed from the measurement
  plan, not a transcript, and what was not retained. The receipt is a
  recorded summary that can be re-derived only while the run records
  exist; durability wording in scope and limitations is replaced.
- Caches: record 130 (likely the usage endpoint) and 131 (the by-prefix
  sum) with the byte reconciliation; the difference stays unreconciled,
  and two later paired reads show the same one-cache gap.
- Failure anatomy: the 80 of 88 Validate runs are the failed runs no
  later same-SHA run turned green (reproduced exactly); the 8 omitted are
  sota-sources-only failures (21 of 94 instances over all 88). Other
  workflows: 10 of 76 classified, 66 not.
- Self-audit fixes: the 17-entry failing-test key and limits string, the
  composition of the 11 non-pull-request cancelled runs, the 96 and 87
  denominators, the sampled failed-job seconds and the suite-shape
  definitions.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>

* Run the O2 phase as a dry run and qualify R3 and R5 by anatomy coverage

- O2's prospective phase becomes a dry run: the required validate-macos
  job keeps running the full suite on every pull request, the gate only
  reports what it would skip, E_G is read from the required job on the
  would-skip pull requests, and skipping starts only after the
  preregistered thresholds pass in a later reviewed change. The
  thresholds are unchanged.
- R3 and R5 state the failure anatomy's coverage (80 classified of
  Validate's 88 failed pull-request runs, all 75 of Adoption's, 10 of 76
  other-workflow failures) and what the 8 omitted runs change (sota-sources
  21 of 94 over all 88); R5 names the steps behind 18 and 15.
- The measured findings and evidence class say the receipt is a recorded
  summary that can be re-derived only while the run records exist, and
  point to the published input and the later reads.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>

* State the anatomy selection, cache bytes and query forms as strong as the data

Second review of the receipt and the record (R1-R5):

- R1: the reclassification of all 88 failed Validate runs forces each of
  the 8 runs the anatomy left out to have failed only in sota-sources
  (94 - 86 = 8 instances, 21 - 13 = 8 of them sota-sources), but any 8 of
  the 19 sota-sources-only failures reproduce the counts. The 8 that a
  later same-SHA run turned green are consistent with the input's tally
  of 8 of 96, not established as the 8 left out: 96 covers all events and
  the 6 push and 2 workflow_dispatch failures were not checked. The
  record says once that R3 and R5 do not depend on which 8. The receipt's
  coverage keys become selection and runs_with_a_later_success.
- R2: the byte total equals the by-prefix sum to 0.1 MiB but does not
  indicate which cache count is right; the later listing's total_count
  of 129 is stated.
- R3: the measuring agent's request forms give the path only (client
  flags not retained); the GET statement is scoped to the input and a
  GH_DEBUG check that was not retained; the suite-shape figures are not
  covered by the plan; the queue-seconds definition is marked inferred;
  the two-endpoint cross-check is relayed as the input's statement.
- R5: largest_file reads 632 'def test' occurrences (624 test
  definitions) in 8,441 lines, listed in source.changes_from_input.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>

* Drop the unpublished creation timestamp and say policy_gate rises by the same 8 in the anatomy selection text

Delta review findings on the CI measurements receipt: the later-success creation time is in no published artifact, so the sentence now points at the run ids in the later-reads artifact; the reclassification of all 88 runs keeps every other by_step cell equal but policy_gate rises by the same 8 because it counts sota-sources.

Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>

* Register the CI measurement receipt, its artifacts, the record and the anti-pattern log (hot-file protocol; last commit)

One registration on main's manifest at 4ced292: the receipt, the decision record, input.json, later-reads-20261003.json and docs/harness-defaults.md (five rows). It is the branch's last commit, so a later rebase takes main's manifest and registers again (docs/lanes.md).

Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>

* Mark the record's coverage policy as superseded in part by #677; qualify the six cache calls' batch timestamps in the receipt (review 632 P1, P2)

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>

* Hot-file protocol: reset manifests/evidence.json to the merge base before the final hot-file commit

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>

* Reapply this branch's manifests/evidence.json edits on the merge base (hot-file protocol: every hot-file edit in the last commit)

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>

* Hot-file protocol: reset manifests/evidence.json to the merge base before the final hot-file commit

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>

* Reapply this branch's manifests/evidence.json edits on the merge base (hot-file protocol: every hot-file edit in the last commit)

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>

---------

Co-authored-by: seathatflowsinourveins <seathatflowsinourveins@users.noreply.github.com>
Co-authored-by: Claude Sonnet 5.5 <noreply@anthropic.com>
Co-authored-by: Scout <scout@local>
seathatflowsinourveins pushed a commit that referenced this pull request Oct 5, 2026
Skip validate-macos, bootstrap-macos and bootstrap-macos-brew on every
pull_request; retain full runs on filtered main pushes and manual dispatch,
and move the weekly bootstrap schedule to nightly 06:47 UTC.

Match the committed ruleset and dated automation catalog to the coordinator's
seven required contexts, including the merge guard's documented count. Keep
the Linux PR detector working and label the
retained macOS selector as historical. Record the user's 2026-10-05 advisory
decision, #699's portability catch, the fix-forward path and overturn rules.

Sources: GitHub Actions workflow-syntax#jobsjob_idif and
events-that-trigger-workflows#schedule, github/docs at
2bd66de8cea336061c9ea060c9b37385136e6ab3; #677's retained measurements;
#699 (landed as 5df0e0e).

Validation: the final PR-event test fails the original workflow with 133
failing subtests across all three macOS jobs (exit 1), and passes the new
workflow (exit 0); 388 selected unittest tests (36 skipped), including the
merge-guard stale-count red/green control; git diff --check.
actionlint is not on PATH. validate.py exits 1 for evidence registry drift
only. Evidence registration remains with the coordinator. The count-only
docs/lanes.md correction follows that file's lane:shared integration policy.

Built by GPT bounded job 064 (GPT-6.1 Sol at max); committed by the coordinator, who re-pointed
the #699 citation from its branch-local head to the landed main commit.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
seathatflowsinourveins pushed a commit that referenced this pull request Oct 5, 2026
Skip validate-macos, bootstrap-macos and bootstrap-macos-brew on every
pull_request; retain full runs on filtered main pushes and manual dispatch,
and move the weekly bootstrap schedule to nightly 06:47 UTC.

Match the committed ruleset and dated automation catalog to the coordinator's
seven required contexts, including the merge guard's documented count. Keep
the Linux PR detector working and label the
retained macOS selector as historical. Record the user's 2026-10-05 advisory
decision, #699's portability catch, the fix-forward path and overturn rules.

Sources: GitHub Actions workflow-syntax#jobsjob_idif and
events-that-trigger-workflows#schedule, github/docs at
2bd66de8cea336061c9ea060c9b37385136e6ab3; #677's retained measurements;

Validation: the final PR-event test fails the original workflow with 133
failing subtests across all three macOS jobs (exit 1), and passes the new
workflow (exit 0); 388 selected unittest tests (36 skipped), including the
merge-guard stale-count red/green control; git diff --check.
actionlint is not on PATH. validate.py exits 1 for evidence registry drift
only. Evidence registration remains with the coordinator. The count-only
docs/lanes.md correction follows that file's lane:shared integration policy.

Built by GPT bounded job 064 (GPT-6.1 Sol at max); committed by the coordinator, who re-pointed
the #699 citation from its branch-local head to the landed main commit.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
seathatflowsinourveins added a commit that referenced this pull request Oct 5, 2026
…pushes, no PR runs; the user's 2026-10-05 decision) (#711)

### Scope

- What this PR changes: it makes macOS CI advisory. `validate-macos`, `bootstrap-macos` and `bootstrap-macos-brew` no longer run on pull requests, and they leave the required checks. They still run nightly (06:47 UTC), on filtered main pushes and on manual dispatch, so a macOS regression is fixed forward. This follows the user's decision of 2026-10-05 (~01:50Z, an AskUserQuestion answer): "Advisory only".
- Base commit: `5df0e0ede`
- Lane: `lane:shared`. docs/lanes.md's required-context count goes from eight to seven, so the trading-custody owner must ACK.
- Owned paths touched:
  - `.github/workflows/adoption-bootstrap.yml`;
  - `.github/main-ruleset.json` (the committed target);
  - `catalogs/foundation/automation.json`, `docs/github-automation.md`, `docs/lanes.md`, `adoption/platforms/macos-arm64.md`;
  - five test modules;
  - the decision record.

The live ruleset 23739774 was already changed by the coordinator on 2026-10-05, with an API read-back: `validate-macos` is no longer required. This PR brings the committed target and the docs into line with it.

### SOTA sources

- GitHub Actions workflow syntax, `jobs.<job_id>.if`: https://docs.github.com/en/actions/writing-workflows/workflow-syntax-for-github-actions#jobsjob_idif (github/docs at 2bd66de8cea336061c9ea060c9b37385136e6ab3)
- Events that trigger workflows, `schedule`: https://docs.github.com/en/actions/writing-workflows/choosing-when-your-workflow-runs/events-that-trigger-workflows#schedule (same pin)
- Rulesets, required status checks: https://docs.github.com/en/repositories/configuring-branches-and-merges-in-your-repository/managing-rulesets/available-rules-for-rulesets#require-status-checks-to-pass-before-merging
- #677's retained macOS measurements, and #699's macOS catch (landed as 5df0e0e), which shows why the nightly runs stay.

### Evidence-class table

| Claim | Evidence class | Command / receipt |
| --- | --- | --- |
| The new workflow skips all three macOS jobs on `pull_request`, and the old one runs them | local_integration | The PR-event test fails the original workflow (133 failing subtests, exit 1) and passes the new one (exit 0) |
| The committed ruleset target equals the live seven-context ruleset | source_review | `.github/main-ruleset.json`; live read-back from `gh api repos/.../rulesets/23739774` on 2026-10-05 |
| The workflow has no security findings | local_integration | `zizmor --offline .github/workflows/adoption-bootstrap.yml`: no findings (5 suppressed) |

### Local commands run

```
$ python3 -m unittest tests.test_workflow_hardening tests.test_adoption_bootstrap_macos tests.test_github_automation_practice tests.test_codex_broker_reaper tests.test_shell_parser_ci tests.test_merge_guard_doc
388 tests OK (36 skipped)  [GPT builder job 064]
$ zizmor --offline .github/workflows/adoption-bootstrap.yml
No findings to report (5 suppressed)  [coordinator]
$ python3 scripts/validate.py
status passed (10,044 hashed files)  [coordinator, after the registry commit]
$ python3 merge_tree_landing_check.py origin/main HEAD
LANDABLE
```

actionlint was not on PATH in the builder's sandbox; zizmor ran instead.

### Decision record

`docs/decisions/2026-10-05-macos-ci-advisory.md`: the user's decision, #699's portability catch, the fix-forward path and the overturn rules.

Built by GPT bounded job 064 (GPT-6.1 Sol at max). Review chain:
- Claude read: 4 P2 and 6 P3, all fixed by the GPT repair round (5f6eb31).
- Claude delta read: all ten confirmed fixed; three new P3s, fixed by the coordinator (7e4d69f), along with a fresh ruleset read-back (enforcement active, strict false, merge methods squash only).
- Registry last (331d008).

This PR lands after the v2026.10.05 re-pin, because adoption/** is on the release window's hold list.

🤖 Generated with [Claude Code](https://claude.com/claude-code)
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

lane:foundation Foundation lane: Claude/Codex setup, hosts, memory, RAG, research, workers

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant