Skip to content

PR-metadata gates in their own workflow, reading the current PR; suite counts in the validate summary (G-1, G-6) - #706

Merged
seathatflowsinourveins merged 9 commits into
mainfrom
foundation/pr-metadata-workflow-20261004
Oct 10, 2026
Merged

seathatflowsinourveins merged 9 commits into
mainfrom
foundation/pr-metadata-workflow-20261004

Conversation

@seathatflowsinourveins

@seathatflowsinourveins seathatflowsinourveins commented Oct 5, 2026 •

Copy link
Copy Markdown
Owner

Scope

Move sota-sources and verdict-review-gate into a dedicated PR metadata workflow so description edits rerun those gates using the current PR. Add unittest ran/skipped counts to validate's step summary without changing the suite result.

  • Base commit: 3b8f9c8a1b938358d65bf422f61592dc3b89407d
  • Lane: lane:foundation; apply the matching PR label.
  • Owned paths touched: the new metadata workflow, validate and reusable SOTA workflows, scaffold caller, workflow tests, scoped automation documentation and evidence registrations.

SOTA sources

Evidence-class table

Claim Evidence class Command / receipt
SOTA judges the current body and fails on rejected REST retrieval synthetic Executed script fixtures in tests.test_sota_sources_gate
Workflow triggers, permissions, job parity and current-base checks satisfy the implementation contract local_integration Named acceptance modules; 303 tests, 2 skipped
Summary reporting handles complete, failed, missing and interrupted logs, plus an unwritable destination local_integration Executed shell fixtures in tests.test_workflow_hardening
Changed artifacts are intact and registered local_integration scripts/validate.py and final scripts/evidence_manifest.py --check
Changed workflows pass local offline zizmor analysis local_integration zizmor 1.30.1, regular persona, exit 0
Async failure handling, concurrency and unittest output formats follow maintained sources source_review Sources linked above

Hosted PR traces remain pending; no hosted acceptance is claimed.

Local commands run

Commands were launched with rtk nice -n 19 env TMPDIR="$PWD/.tmp-build".

$ python3 -m unittest tests.test_sota_sources_gate tests.test_workflow_hardening tests.test_verdict_review_gate tests.test_merge_guard_doc
exit 0; Ran 303 tests in 30.340s; OK (skipped=2)

$ python3 scripts/validate.py
exit 0; 69 components, 9962 hashed files, 4 profiles, 199 receipts

$ python3 scripts/evidence_manifest.py --check
exit 0; 9962 files; repeated successfully after registration

$ git diff --check
exit 0; repeated successfully after registration

$ zizmor --offline --no-config --no-ignores --persona regular --strict-collection .github/workflows/pr-metadata.yml .github/workflows/sota-sources-gate.yml .github/workflows/validate.yml
exit 0; zizmor 1.30.1; no regular-persona findings; 9 suppressed

Pinned kjanat/actionlint v1.17.0: nv locally because it is absent from PATH. All nine changed artifacts were registered last through scripts.host_receipts.register_file, exit 0. The earlier full-suite attempt returned 1 without a complete summary during disk exhaustion; it was not rerun under the final instruction. CI runs the full suite and online workflow checks.

Decision record

Implementation follows the reconciled unit-G record, implementation units G-1 and G-6, and the slot-3 ruling. The coordinator owns the forthcoming docs/decisions/2026-10-04-github-convergence-workflow.md; finalize its link before merge.

The selected behavior isolates description-edit gates, queues runs and reads current metadata. Hosted acceptance should confirm stable required contexts and fresh gate results across active-run edits and retargets.

Host evidence

Not applicable: no host receipt files changed. Evidence-manifest changes register repository artifacts.

Checklist

  • New/changed GitHub Actions retain full commit SHA pins and version comments.
  • The new workflow declares top-level permissions: {} and grants job-local read permissions; the reusable caller grants pull-requests: read.
  • No secrets were printed, logged or committed, and no required secret was added.
  • No paid hosting, subscription or billing surface was introduced.
  • Peer-owned files and protected parallel-PR regions were preserved.

Review chain

  • Claude Opus first read: FINDINGS (1 p1, 3 p2).
  • GPT-6.1 Sol repair round through the packaged SDK worker; the coordinator committed it.
  • Claude Opus delta read of the repair: ACCEPT at 700c82483b0f (0 p1, 0 p2).

Recorded residuals (bounded review, 2026-10-05)

The Claude Opus delta read of follow-up t2 at 929ba811f9ca returned ACCEPT with no p1. Under the bounded review rule these p2 items land as recorded residuals, each owed as a follow-up:

  • tests/test_verdict_review_gate.py:1698-1707 : The wrapper derivation ignores job-level uses: edges, so it is incomplete when the gate runs through a reusable workflow.

🤖 Generated with Claude Code

@seathatflowsinourveins seathatflowsinourveins added the lane:foundation Foundation lane: Claude/Codex setup, hosts, memory, RAG, research, workers label Oct 5, 2026
@chatgpt-codex-connector

chatgpt-codex-connector Bot commented Oct 5, 2026 •

Copy link
Copy Markdown

Codex Review Summary

This comment shows the latest Codex review activity on this pull request.

Review Status Commit Review trigger
📝 Code Review ✅ Completed 2026-10-05T02:33:38.970270Z 700c824 PR opened
ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review" or "@codex security review".

Codex reacts with 👀 while any review is running, comments if it has suggestions, and reacts with 👍 once all reviews finish with no findings.

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: 700c82483b

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment thread .github/workflows/pr-metadata.yml
@socket-security

socket-security Bot commented Oct 5, 2026 •

Copy link
Copy Markdown

Dependency limit exceeded — report not shown.

This pull request scan exceeded the 10,000-dependency limit applied to this scan, so the results are incomplete and may be inaccurate. To avoid reporting false positives, Socket has not posted a report.

Upgrade your plan to raise the dependency limit and get complete reports, or view the partial scan in the dashboard.

Socket is always free for open source. If this is a non-commercial open source project, contact us to request a free Team account.

seathatflowsinourveins pushed a commit that referenced this pull request Oct 5, 2026
…rom the workflows (delta-read p2s)

- New TrustPathDerivationTests.test_workflow_wrappers_match_the_workflow_trust_paths. It uses
  the repository's workflow-policy YAML loader and file enumerator to collect every workflow
  that defines a verdict-review-gate job or runs scripts/verdict_review_gate.py, and requires
  that set to equal the .github/workflows/ entries of TRUST_PATHS. It fails with the obsolete
  validate.yml entry and passes with pr-metadata.yml, so this drift class is now caught by a
  test. docs/github-automation.md and the test docstring describe the derivation.
- The 2026-09-22 closure record's accepted-residual bullet names pr-metadata.yml and keeps the
  note that validate.yml owned the job before PR #706.

Built by GPT-6.1 Sol through the packaged SDK worker (round gh-prmeta-t2); committed by the
coordinator.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
seathatflowsinourveins added a commit that referenced this pull request Oct 7, 2026
### Scope

Route catalog lookup through QMD's lexical queries and bounded document retrieval; use SocratiCode for semantic catalog search at the main checkout's projectPath. Keep reranking available and prohibit qmd embed/pull. Update current maintenance recipes and native instruction carriers through the repository renderers.

Existing Serena consumers read its manual before navigation, and jCodeMunch consumers obtain the current guide before a typed route with the actual caller model and execution off. Four existing Claude roles gain only Serena's manual tool. Reviewer/builder keep their no-menu boundary, and a focused read of a known path and line remains valid.

This landing repair appends the preregistration's Amendment4 to bind the deliberately changed role bodies and compacts lane-authored RTK explanations within the unchanged compact and startup budgets. The entire composed pre-RTK prefix, upstream awareness, owner's blocks, exact SKILL line, seven exceptions, models and effort are preserved. Prior amendment rows, observations, seals and RUNBOOK bytes remain unchanged.

The canonical code-graph rename is prepared as a separate patch and is excluded from this head under command-center ruling081016Z. Main's existing names remain in both templates, the map, fixtures and carriers. The protected lane token requires the owner's word before the rename can land. Until that follow-up, this host's Claude code-graph access is through the vendor's hook channel only; the stale MCP carrier id is a recorded limitation and is not claimed fixed.

- Base commit: `c44993b379da25fae923dbbe70188978af5104aa` (verified native source; #803 already landed).
- Lane: `lane:foundation`; draft.
- Head: `9985e468fa4997d22630714b2fa6a76666e3cda9`. Native bytes: compact 8076 <8192, rendered 9142, three-file startup 20101 <=20103; full Claude block 4087 <=4100. These are byte gates, not token-use measurements.
- Owned paths: token-lane carriers and their paired handbook text, minimal manual grants and mirrors, Codex template/rendered copies, native loader/routing/sequence tests, current recipes and generated handbook, append-only decisions/preregistration amendment, follow-up receipts and checksum/registry projections.
- ROLE-CARRIER-GAPS and ROLE-GRANTS are separate future work and stay out of this change.

Landing path: explicit command-center cue070358Z and fallback ruling081016Z permit one pushed rebase/content repair onto then-current main while #802/#813/#830 land. The co-op performs the new-head delta read with its CI result; the command center ACKs; 5f lands. A further pushed rebase requires the separate dated landing-conflict cue. Host configuration, cutover and fresh-session/working-day acceptance belong to their owners.

## SOTA sources

- [QMD v2.8.3 lexical query](https://github.com/tobi/qmd/blob/v2.8.3/src/mcp/server.ts#L294), [typed searches/rerank](https://github.com/tobi/qmd/blob/v2.8.3/src/mcp/server.ts#L321) and [document retrieval](https://github.com/tobi/qmd/blob/v2.8.3/src/mcp/server.ts#L412): native lexical subqueries, retrieval and optional rerank. Rerank defaults true (:334-335). [README maintenance syntax:1033-1037](https://github.com/tobi/qmd/blob/v2.8.3/README.md#L1033-L1037) supplies bounded commands.
- [SocratiCode v1.15.0 codebase_search](https://github.com/giancarloerra/SocratiCode/blob/v1.15.0/src/index.ts#L138): semantic search at an absolute projectPath. Owner ruling224125Z selects the routing and preserves rerank-on acceptance; this PR performs no host cutover.
- [Serena c6fbd1c5 manual order](https://github.com/oraios/serena/blob/c6fbd1c5932df2494ffa0020af5a9fbe80b82143/src/serena/resources/config/prompt_templates/system_prompt.yml#L5-L6), [manual tool:28-40](https://github.com/oraios/serena/blob/c6fbd1c5932df2494ffa0020af5a9fbe80b82143/src/serena/tools/workflow_tools.py#L28-L40) and [project/session binding:44-49](https://github.com/oraios/serena/blob/c6fbd1c5932df2494ffa0020af5a9fbe80b82143/src/serena/tools/config_tools.py#L44-L49): manual first, active cwd project and returned session id for switches.
- [jCodeMunch 1.108.330, 28803366, typed route:446-463](https://github.com/jgravelle/jcodemunch-mcp/blob/288033668f0425ab0547f420dd647c14bd186c7f/src/jcodemunch_mcp/server.py#L446-L463), [guide:4743-4752](https://github.com/jgravelle/jcodemunch-mcp/blob/288033668f0425ab0547f420dd647c14bd186c7f/src/jcodemunch_mcp/server.py#L4743-L4752) and [policy:101-128](https://github.com/jgravelle/jcodemunch-mcp/blob/288033668f0425ab0547f420dd647c14bd186c7f/src/jcodemunch_mcp/cli/policy.py#L101-L128): guide-first and typed task/model route. These files are unchanged at target1.108.331/d94049d0. The executable schema corrects the guide's query example; no new adaptive-tier setting or upstream rebuild.
- `native-agent-stack@c44993b:tests/test_token_e2e_preregistration.py:637-663,905-909`: later dated role-pin amendment and sealed RUNBOOK contracts. Amendment4 preserves every earlier row/seal and extends the current-row selector. The command center records merge chronology at landing; this is a structural repair and authorizes no run.
- [DeusData/codebase-memory-mcp v0.11.0 release](https://github.com/DeusData/codebase-memory-mcp/releases/tag/v0.11.0), the repository's pinned component, and the command center's native-client read-back identify the canonical server name. Its proposed client-key/wire-id/owner-token correction is kept in the separate patch, preserving every payload and strict fixture. Ruling081016Z explicitly keeps main's names in this publication while the owner's instruction-token decision remains open.
- RTK explanation provenance: `native-agent-stack@2d849ba` (#726) and `@50b9579` (#389), `adoption/templates/codex.AGENTS.template.md` after its exceptions marker. The eight explanations shorten while all facts and protected bytes remain. Command-center064832Z accepted their class and scoped wording.
- Native helpers at `native-agent-stack@c44993b`: `tools/adoption/managed_block.py:169` (`codex_block`), `tools/adoption/codex_roles.py:287` (`f4_block`), `scripts/host_receipts.py:710` (`register_file`), `docs/lanes.md:94-128`. Current generated inventory/handbook and checksum bindings use those repository tools; historical receipts and the frozen catalog passage are preserved.

### Evidence-class table

| Claim | Evidence class | Command / receipt |
| --- | --- | --- |
| Documented native routing/manual/guide interfaces | source_review | Pinned upstream files above |
| Carrier rendering, protected bytes, new body pins and tool ids | local_integration | Existing native helpers, hashes and required modules |
| Permission/sequence/byte-mutant/frozen-row controls | synthetic | Existing tests with assertions preserved |
| Deployed use and token savings | Pending owner evidence | No model, host apply or working-day measurement in this repair |

### Local commands run

```text
$ CI=true nice -n 19 ionice -c3 python3 -B -m unittest tests.test_token_lanes_session_start tests.test_token_lanes_subagent_start tests.test_scaffold_repo tests.test_new_wsl_handbook tests.test_adoption_docs_consistency tests.test_codex_agents tests.test_codex_roles tests.test_codex_worker_lane tests.test_token_e2e_preregistration tests.test_new_wsl_client_config.RecordTests tests.test_install_claude_profile tests.test_managed_block tests.test_task_model_routing tests.test_new_wsl_client_config.MapTests tests.test_new_wsl_client_config.AgentGapTests tests.test_new_wsl_client_config.RenderTests tests.test_new_wsl_client_config.ApplyTests.test_the_first_run_writes_what_the_wired_pieces_name_and_nothing_else
exit 0; Ran 595 tests in 109.929s; OK (skipped=14)

$ CI=true nice -n 19 ionice -c3 python3 -B -m unittest tests.test_install_claude_profile tests.test_adoption_docs_consistency tests.test_new_wsl_client_config.RecordTests
exit 0; Ran 150 tests in 16.306s; OK (skipped=2)

$ CI=true nice -n 19 ionice -c3 node examples/claude-native/workflows/test-envelope.mjs
exit 0; SUMMARY passed=254 failed=0 total=254

$ CI=true nice -n 19 ionice -c3 python3 -B tools/adoption/new_wsl_client_config.py --check --markdown
exit 0

$ CI=true nice -n 19 ionice -c3 python3 -B scripts/build_new_wsl_handbook.py --check
exit 0
```

The passing 595-test run is retained on unchanged source/assertion inputs from the pre-window checkpoint; the 150-test run checks the concrete relocation-fixture and workflows-README changes in the new main base. Their counts overlap and are not added. The fresh Node run passes 254/254. Strict checksums in both Codex directories and the Claude hook directory, plus `git diff --check`, exit 0. All three Amendment-4 role digests were re-derived in both copies and are unchanged from the previous published head.

```text
$ CI=true nice -n 19 ionice -c3 python3 -B scripts/validate.py
exit 0; 69 components, 10,482 hashed files, 4 profiles, 224 receipts, status passed
```

The earlier landing composition used source `630b6ece8485a7710ea51321682d5a12e364e25c` and hot commit `5703ef1061b982078038425fada888fd35153868`; its native checks and source-critic result are retained. The authorized locator follow-up changes only `catalogs/foundation/upstream-surface-dispositions.json` and that file's registry row: the `otel.environment` citation now points to the command at `examples/codex-native/README.md:214`. Source commit `2b36cfee` is followed by registry-last commit `9985e468fa4997d22630714b2fa6a76666e3cda9`, with no further rebase. Claude/Codex instruction bytes, role hashes, historical records, namespace and byte budgets remain unchanged.

The registry starts from exact main `c44993b379da25fae923dbbe70188978af5104aa`, registers the same 67 changed-file rows through the native producer, and preserves main's receipt and convergence arrays. The two-file correction passed the 114-test citation module, the two exact failing methods and a second native validator run. The worktree is clean; the shifted-citation scan found no other current target to repair. Historical before/after references remain intact.

```text
$ CI=true nice -n 19 ionice -c3 python3 -B -m unittest tests.test_upstream_surface_watch
exit 0; 114 tests, 6 skipped

$ CI=true nice -n 19 ionice -c3 python3 -B -m unittest tests.test_upstream_surface_watch.DispositionCitationTests.test_every_cited_line_names_the_key tests.test_upstream_surface_watch.DispositionCitationTests.test_a_dotted_key_has_its_parent_near_the_citation
exit 0; 2 tests

$ CI=true nice -n 19 ionice -c3 python3 -B scripts/validate.py
exit 0; integrity and scope passed
```

The hosted run at5703 returned two failures in11,495 tests because the documentation locator moved. A reviewed locator still gates when its repository test fails. This follow-up closes that exact contract; it adds no assertion waiver or namespace change.

Read-only overlap metadata checked all 47 open PRs, including full file pagination where needed. Source overlaps: #645, #706, #709, #754, #769, #770, #775, #776, #795, #810, #821, #826, #829. Shared registry/checksum paths use the hot-file protocol; no peer branch is changed.

Earlier failed CI at3ba ran11,381tests and failed six role-body-pin subcases; its complete failed log is retained privately. The failed 560-test and earlier 595-test preparation runs also remain retained. This repair uses a dated amendment, preserves the older source evidence and strict current-body comparison, and performs no full-suite or provider acceptance run. Validator results are integrity and scope evidence only.

### Decision record

`docs/decisions/2026-10-06-qmd-lexical-catalog-instructions.md` and `docs/decisions/2026-10-07-serena-jcodemunch-native-navigation-wiring.md`, with appended clarifications and the new landing follow-up, explain the behavior and limits. The preregistration README gains Amendment4 only; its RUNBOOK and earlier sealed records stay byte-identical. No prior result is recast as a new run.

### Host evidence

Repository-only change. No live instruction file, MCP registration, hook trust, client setting, gateway setting/key or model session changed. Source/render checks and synthetic fixtures remain distinct from the configuration owner's read-back and organic-use acceptance.

### Checklist

- [x] No GitHub Actions or paid service change.
- [x] No credentials, raw conversations or live client configuration committed.
- [x] Models, effort, owner's blocks and historical observations preserved.
- [x] Peer-owned worktrees and source preserved.
- [x] Native validation passed; changed checksums/registry committed last at the final head.
seathatflowsinourveins added a commit that referenced this pull request Oct 8, 2026
…heck (#838)

### Scope

The required Linux test job runs serially and blocks each landing for roughly half an hour. This change runs native unittest discovery as eight module shards and keeps one final required check named `validate`, which fails on any unsuccessful dependency or incomplete module coverage.

- Base commit: `b16cb8cf7cb8e37bf0d0edb9924502beb3e6a276`.
- Lane: `lane:shared`; the command center requests trading acknowledgement for the one promotion workflow-contract method.
- Owned paths: validate workflow, shard helper/weights, its fixtures, declared workflow-contract tests, the decision/receipt and the final registry commit.
- Landing path: exact-head co-op cross-family read after the draft's hosted timing run; command-center ACK; 5f lands after #833/#836 and before #820/#829/#776, per GO-RELAUNCH230713Z and RULING203309Z. The draft stays draft until that read. Critical-path cap allowance confirmed by item191739Z; all25kind3rows accepted by name in203309Z subject to their stronger-assertion condition.
- #706 relation: this final summary supersedes G-6 (serial suite counts); G-1 (PR-metadata workflow work) stays in #706 for its rank38 turn.

## SOTA sources

- [GitHub matrix strategies and failure handling](https://docs.github.com/en/actions/how-tos/write-workflows/choose-what-workflows-do/run-job-variations), read 2026-10-07.
- [GitHub needs result](https://docs.github.com/en/actions/reference/workflows-and-actions/contexts#needs-context) and [always](https://docs.github.com/en/actions/reference/workflows-and-actions/expressions#always), read 2026-10-07.
- [Skipped jobs](https://docs.github.com/en/actions/how-tos/write-workflows/choose-when-workflows-run/control-jobs-with-conditions) report success even when required; [required status checks](https://docs.github.com/en/repositories/configuring-branches-and-merges-in-your-repository/managing-protected-branches/about-protected-branches#require-status-checks-before-merging) accept skipped statuses. This final job always runs and explicitly rejects skipped/cancelled/failed dependencies.
- [CPython v3.12.3 native discovery](https://github.com/python/cpython/blob/v3.12.3/Lib/unittest/loader.py#L109), [load_tests protocol](https://docs.python.org/3.12/library/unittest.html#load-tests-protocol) and [TextTestRunner](https://docs.python.org/3.12/library/unittest.html#unittest.TextTestRunner). The helper supplies assignment and receipt glue; unittest runs the tests.
- `native-agent-stack@b16cb8c:.github/workflows/validate.yml:147-250`: the unchanged provisioners and diagnostics.
- Same pin, `docs/decisions/2026-10-03-suite-parallelism-trial-outcome.md:24-27`: the superseded Linux serial instruction; failed pool-trial evidence and macOS instruction preserved.
- Existing pinned download/upload artifact actions are reused; no requirement file or other workflow job changes.

### Evidence-class table

| Claim | Evidence class | Command / receipt |
| --- | --- | --- |
| Historical timing weights | source_review of retained native output | run37653671981/job112905135751, log SHA b1d2d43e; 17 failures retained |
| Native discovery and assignment | local_integration | Current tree discovery-only sample:272owners/11607cases, no bodies; predates final fixture set |
| Focused contracts and fixtures | local_integration; synthetic fixtures remain synthetic | 368tests/95.067s with one retained serial-binding failure; its authorized class delta3tests/0.874s passes; final new-module13tests/3.383s passes |
| Syntax/integrity | local_integration | actionlint0; offlinezizmor0/findings[]; py_compile0; diff--check0; validate.py0 |
| Hosted timing and exact module/count union | pending | The draft's actual run supplies this; historical estimates are not acceptance |

Expected first-run limitation: this branch is still based on b16cb8c, while main28327acc carries #837's new frozen-lock exceptions. The first osv-scanner check is expected red for that base; it is refreshed only at the command-center landing cue's single rebase. No exception or requirement change is added here, and a local check never substitutes for the landing head's hosted result.

### Local commands run

```text
nice -n 19 ionice -c3 actionlint -color .github/workflows/validate.yml
exit0

nice -n 19 ionice -c3 zizmor --offline --no-config --no-ignores --format json .github/workflows/validate.yml
exit0, []

python3 -I -B -X pycache_prefix=<ignored-owned-path> -m py_compile <helper and five touched test modules>
exit0

nice -n 19 ionice -c3 <activated Python3.12.3> -I -B -X faulthandler <stdlib unittest bootstrap> -q --durations 50
selected: test_validate_shards, test_workflow_hardening, test_shell_parser_ci,
test_landscape_sweep_skills, test_workflow_security_coverage, test_promotion_gate,
test_adoption_docs_consistency
exit1, 368ran/95.067s/onefailure/fiveskips (retained)
Only failure: the promotion class's serial-command binding.
Authorized delta: that class exit0, 3ran/0.874s; other36method ASTs and surrounding bytes preserved.
New fixture deltas:12ran/3.407s and13ran/3.383s, both exit0.
No full-suite phase or hidden baseline waiver.

nice -n 19 ionice -c3 <activated Python3.12.3> -I -B scripts/validate.py
exit0, components69/hashed_files10559/profiles4/receipts226.
git diff --check
exit0
```

The local environment has Python3.12.3/PyYAML6.0.3 and real Node24.21.0/npm11.19.0 bins before generic PATH. It is a focused environment, not full hosted-image parity. Every hosted cell keeps the current installer and promotion/parser/NodeYAML provisioners; non-test checks execute once in cell zero.

### Contract changes

Each listed existing test deliberately replaces the serial whole-suite binding with complete module-shard coverage under `docs/decisions/2026-10-07-validate-module-shards.md` (kind3). Provisioning, history, timeout/faulthandler and native failure controls remain. The one promotion method additionally runs the tiny native aggregate fixture; neighboring and numeric assertions remain byte-identical.

The trading lane's conditional acknowledgement, ledger row `report-native-agent-stack-5f-20261007T200005-shardack`, binds that promotion method to three conditions:

1. Every shard runs the promotion provisioner with `--require-hashes` on `blueprints/us-equities/data/requirements.lock` and exports `REQUIRE_PROMOTION_GATE_VENV=1` before testing, including the shard assigned this module.
2. Module coverage comes from live native discovery, with each module's executed suite exactly once. Weights are scheduling estimates, not a separate test inventory.
3. Final `validate` runs under `if: always()` and passes only on successful shards; cancellation, skipping and timeout fail the gate. The trading lane checks these again on this PR before merge.

| Test ID | Kind | Record |
| --- | --- | --- |
| `tests.test_workflow_hardening.WholeSuiteJobsCheckOutFullHistory.test_whole_suite_jobs_set_fetch_depth_zero` | 3 | docs/decisions/2026-10-07-validate-module-shards.md |
| `tests.test_workflow_hardening.WholeSuiteHeadroomAndDiagnostics.test_every_whole_suite_job_names_its_suite_step` | 3 | docs/decisions/2026-10-07-validate-module-shards.md |
| `tests.test_workflow_hardening.WholeSuiteHeadroomAndDiagnostics.test_each_suite_lists_its_50_slowest_tests_with_faulthandler_on` | 3 | docs/decisions/2026-10-07-validate-module-shards.md |
| `tests.test_workflow_hardening.WholeSuiteHeadroomAndDiagnostics.test_linux_suites_abort_five_minutes_before_the_job_limit` | 3 | docs/decisions/2026-10-07-validate-module-shards.md |
| `tests.test_workflow_hardening.WholeSuiteHeadroomAndDiagnostics.test_validate_uploads_its_verbose_log_even_when_the_suite_fails` | 3 | docs/decisions/2026-10-07-validate-module-shards.md |
| `tests.test_workflow_hardening.ValidateSuiteStepTracesAHang.test_a_hang_prints_the_hung_test_traceback_and_fails_the_step` | 3 | docs/decisions/2026-10-07-validate-module-shards.md |
| `tests.test_workflow_hardening.ValidateSuiteStepTracesAHang.test_control_without_faulthandler_the_hang_leaves_no_traceback` | 3 | docs/decisions/2026-10-07-validate-module-shards.md |
| `tests.test_shell_parser_ci.ProvisioningStepTests.test_provisioning_step_exists_in_the_validate_job` | 3 | docs/decisions/2026-10-07-validate-module-shards.md |
| `tests.test_shell_parser_ci.ProvisioningStepTests.test_provisioning_step_precedes_the_unittest_step` | 3 | docs/decisions/2026-10-07-validate-module-shards.md |
| `tests.test_shell_parser_ci.ProvisioningStepTests.test_step_command_is_derived_from_the_pin_file` | 3 | docs/decisions/2026-10-07-validate-module-shards.md |
| `tests.test_shell_parser_ci.ProvisioningStepTests.test_step_exports_the_directory_through_github_env` | 3 | docs/decisions/2026-10-07-validate-module-shards.md |
| `tests.test_shell_parser_ci.ProvisioningStepTests.test_step_cannot_be_skipped_or_ignored` | 3 | docs/decisions/2026-10-07-validate-module-shards.md |
| `tests.test_shell_parser_ci.ProvisioningStepTests.test_the_provisioning_job_is_the_job_that_runs_the_suite` | 3 | docs/decisions/2026-10-07-validate-module-shards.md |
| `tests.test_shell_parser_ci.ProvisioningStepTests.test_every_whole_suite_job_provisions_the_parser_or_is_a_recorded_gap` | 3 | docs/decisions/2026-10-07-validate-module-shards.md |
| `tests.test_shell_parser_ci.ProvisioningControls.test_each_mutant_is_reported_in_its_category` | 3 | docs/decisions/2026-10-07-validate-module-shards.md |
| `tests.test_shell_parser_ci.ProvisioningControls.test_a_scratch_copy_of_the_workflow_without_the_step_fails_the_structure_tests` | 3 | docs/decisions/2026-10-07-validate-module-shards.md |
| `tests.test_shell_parser_ci.RealRatchetControls.test_the_real_workflows_pass` | 3 | docs/decisions/2026-10-07-validate-module-shards.md |
| `tests.test_shell_parser_ci.RealRatchetControls.test_a_new_whole_suite_job_in_a_real_workflow_is_reported` | 3 | docs/decisions/2026-10-07-validate-module-shards.md |
| `tests.test_shell_parser_ci.RealRatchetControls.test_provisioning_a_recorded_gap_job_is_cleared_by_deleting_its_entry` | 3 | docs/decisions/2026-10-07-validate-module-shards.md |
| `tests.test_shell_parser_ci.RealRatchetControls.test_a_step_that_only_names_the_pin_file_is_judged_by_the_structure_checks` | 3 | docs/decisions/2026-10-07-validate-module-shards.md |
| `tests.test_landscape_sweep_skills.SkillsYamlProvisioningTests.test_the_validate_job_provisions_the_yaml_pin_before_the_suite` | 3 | docs/decisions/2026-10-07-validate-module-shards.md |
| `tests.test_landscape_sweep_skills.SkillsYamlProvisioningTests.test_every_whole_suite_job_provisions_the_yaml_pin_or_is_a_recorded_gap` | 3 | docs/decisions/2026-10-07-validate-module-shards.md |
| `tests.test_landscape_sweep_skills.SkillsYamlProvisioningControls.test_each_mutant_is_reported_in_its_category` | 3 | docs/decisions/2026-10-07-validate-module-shards.md |
| `tests.test_landscape_sweep_skills.SkillsYamlProvisioningControls.test_the_ratchet_reports_a_new_whole_suite_job_and_a_gap_that_now_provisions` | 3 | docs/decisions/2026-10-07-validate-module-shards.md |
| `tests.test_promotion_gate.WorkflowProvisioningContract.test_unittest_step_runs_the_full_suite` | 3 | docs/decisions/2026-10-07-validate-module-shards.md |

### Failed attempts and limits

The failed unittest-parallel trial remains unchanged. The historical weighting run failed17 tests. Worker fixture-authoring attempts (one missing-helper error; then one failure/one error among12cases) remain disclosed separately; later root runs do not replace them. An early validate returned1 for pending registry hashes, and an incorrect register_file CLI probe returned2 before the documented Python API was used.

The source critic's two fixture gaps (global zero discovery and a package hook invoking nested discovery) are covered by the passing native delta fixtures. Shared fixture origins trigger an explicit serial fallback; that preserves native semantics and must be reported as a performance constraint. Actual hosted latency, skips and complete module coverage remain pending.

### Decision record

`docs/decisions/2026-10-07-validate-module-shards.md`; scoped observations in `evidence/artifacts/validate-module-shards-20261007/preparation.json`. The final commit changes only `manifests/evidence.json`.

### Host evidence

No host receipt, platform-status change, install or setting change.

### Checklist

- [x] Changed actions pinned to full SHAs with version comments.
- [x] Top-level permissions empty; each job grants contents:read only.
- [x] No credential value or new secret.
- [x] No new billing surface.
- [x] Peer worktrees preserved.
- [ ] Trading acknowledgement before merge (command center requests it).
- [ ] Hosted timing/coverage receipt and exact-head cross-family read.
seathatflowsinourveins pushed a commit that referenced this pull request Oct 9, 2026
…rom the workflows (delta-read p2s)

- New TrustPathDerivationTests.test_workflow_wrappers_match_the_workflow_trust_paths. It uses
  the repository's workflow-policy YAML loader and file enumerator to collect every workflow
  that defines a verdict-review-gate job or runs scripts/verdict_review_gate.py, and requires
  that set to equal the .github/workflows/ entries of TRUST_PATHS. It fails with the obsolete
  validate.yml entry and passes with pr-metadata.yml, so this drift class is now caught by a
  test. docs/github-automation.md and the test docstring describe the derivation.
- The 2026-09-22 closure record's accepted-residual bullet names pr-metadata.yml and keeps the
  note that validate.yml owned the job before PR #706.

Built by GPT-6.1 Sol through the packaged SDK worker (round gh-prmeta-t2); committed by the
coordinator.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
@seathatflowsinourveins
seathatflowsinourveins force-pushed the foundation/pr-metadata-workflow-20261004 branch from 929ba81 to 71d1a19 Compare October 9, 2026 22:34
@seathatflowsinourveins

Copy link
Copy Markdown
Owner Author

PR706-REBASE-HEAD 71d1a19

Rebased onto current main 3c01bdddc66896f8e36f9f21d452710808a9557e; published head 71d1a1928052b6623f5059a212da0f10479c8968. The exact expected-head lease was 929ba811f9ca9fa037bf840ed55e56459da3e7ec, and the push completed with repository hooks enabled.

The dedicated PR-metadata workflow retains both gates, current PR REST reads, permissions and queue behavior. Validation retains all eight shards, the native runner, final aggregate, uploads and secret scanners. Description edits rerun metadata gates. The original nonfatal count reporter remains; the shard failure guard was adapted to reject job-level and actual suite-step suppression while permitting that reporter. The current workflow passed and three suppression mutations were rejected.

Generated manifests/evidence.json was rebuilt from current main through scripts.host_receipts.register_file for all fifteen replayed source paths, then scripts/evidence_manifest.py --write. Four registrations were added and eleven refreshed; no registrations were removed, and the other top-level manifest sections were retained unchanged.

Validation at the final content:

  • kjanat/actionlint 1.17.0, actionlint -color: exit 0 for the full workflow collection.
  • zizmor 1.30.1, zizmor --no-config --no-ignores --persona regular --strict-collection .: exit 0; no regular-persona findings, 54 suppressed. The installed tool ran in offline mode; online audits remain CI evidence.
  • FULL python3 scripts/validate.py: exit 0, 70 components, 11287 hashed files, 4 profiles, 239 receipts.
  • Manifest check and git diff --check: exit 0.
  • Gate, hardening, verdict, resolver, security coverage, shard and merge-doc regression modules: exit 0, 488 tests, 1 existing skip.
  • Actual pre-push committed-tip host/private-name scan, pushed history and commit identities: source=host, 12055 files, zero matching locations. All three registry checks passed without skips. No --no-verify was used.

Native host/tool invocation issues were resolved without repository scanner changes: the existing Gitleaks 8.30.1 executable was selected through task-scoped PATH; the omitted WSL distro label was restored after native WSL, uname and launcher-source verification; history scan arguments use full object IDs. Earlier failed attempts remain recorded in the lane receipt.

Sources: the existing PR's pinned actions/github-script@3a2844b7e9c422d3c10d287c895573f7108da1b3, GitHub pull_request event documentation, current queue:max syntax, Git 2.53.0 explicit lease contract, and the repository's current-main generation and hook implementations.

The preserved event split also sends base-branch retarget edits through metadata only; the current-base guard remains fail-closed. Hosted edit/retarget/queue behavior is not claimed by these local results. The previously recorded bounded-review residual remains for its follow-up. The CC owns the Claude read at this full head and landing. Monday receipts remain queued after this item.

seathatflowsinourveins pushed a commit that referenced this pull request Oct 10, 2026
…rom the workflows (delta-read p2s)

- New TrustPathDerivationTests.test_workflow_wrappers_match_the_workflow_trust_paths. It uses
  the repository's workflow-policy YAML loader and file enumerator to collect every workflow
  that defines a verdict-review-gate job or runs scripts/verdict_review_gate.py, and requires
  that set to equal the .github/workflows/ entries of TRUST_PATHS. It fails with the obsolete
  validate.yml entry and passes with pr-metadata.yml, so this drift class is now caught by a
  test. docs/github-automation.md and the test docstring describe the derivation.
- The 2026-09-22 closure record's accepted-residual bullet names pr-metadata.yml and keeps the
  note that validate.yml owned the job before PR #706.

Built by GPT-6.1 Sol through the packaged SDK worker (round gh-prmeta-t2); committed by the
coordinator.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
@seathatflowsinourveins
seathatflowsinourveins force-pushed the foundation/pr-metadata-workflow-20261004 branch from adb83b4 to a5eba47 Compare October 10, 2026 03:44
Scout and others added 9 commits October 10, 2026 02:30
…e counts in the validate summary (G-1, G-6)

sota-sources and verdict-review-gate move from validate.yml into .github/workflows/pr-metadata.yml (job IDs and
pins unchanged) on opened/synchronize/reopened/edited, push to main and workflow_dispatch, with queue: max and no
cancel-in-progress. sota-sources reads the current PR body through the pinned actions/github-script
(pulls.get, pull-requests: read) and fails on a retrieval error; verdict-review-gate also fails closed when the
current base differs from the event's. The reusable gate changes identically, and the scaffold caller grants
pull-requests: read. validate.yml drops edited, so a description edit no longer cancels the full suite, and appends
the ran/skipped counts to its job summary. Native traces (description edits, retarget) follow on the open PR.
GPT-6.1 Sol build gh-prmeta through the packaged SDK worker; the coordinator commits.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
…x; base-ref fail-closed; stale bootstrap text; summary skipped=0 (Opus p1 + p2s)

GPT-6.1 Sol repair round gh-prmeta-r1 (answers the Claude Opus batch-7 read) through the packaged SDK worker; the
coordinator commits.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
…ST_PATHS (review thread)

The verdict-review gate moved into .github/workflows/pr-metadata.yml in this PR, but
scripts/verdict_review_gate.py still listed validate.yml in TRUST_PATHS. As a result,
trust_paths_changed() missed changes to pr-metadata.yml, and a change to the gate wrapper
could land together with the verdict data it judges. validate.yml no longer executes or
wraps any part of the gate, so pr-metadata.yml replaces it.

- New regression test TrustBaseTests.test_metadata_workflow_change_with_a_verdict_row_change_fails:
  red before the fix (the combined change passed), green after.
- The gate docstring and the trust-path lists in docs/github-automation.md and the
  2026-09-22 closure record are updated.

Built by GPT-6.1 Sol through the packaged SDK worker (round gh-prmeta-t1); committed by the
coordinator.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
…rom the workflows (delta-read p2s)

- New TrustPathDerivationTests.test_workflow_wrappers_match_the_workflow_trust_paths. It uses
  the repository's workflow-policy YAML loader and file enumerator to collect every workflow
  that defines a verdict-review-gate job or runs scripts/verdict_review_gate.py, and requires
  that set to equal the .github/workflows/ entries of TRUST_PATHS. It fails with the obsolete
  validate.yml entry and passes with pr-metadata.yml, so this drift class is now caught by a
  test. docs/github-automation.md and the test docstring describe the derivation.
- The 2026-09-22 closure record's accepted-residual bullet names pr-metadata.yml and keeps the
  note that validate.yml owned the job before PR #706.

Built by GPT-6.1 Sol through the packaged SDK worker (round gh-prmeta-t2); committed by the
coordinator.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
…dence

Add the native proposal's repo-root pr-metadata.yml grant and increase the
inventory control from 90 to 91. Cite the measured hosted validator passes
and timeout plus Python 3.12 subprocess.run(timeout=); 300 seconds is the
repository's chosen budget.

The grants proposal was read at rebased head
8296982. That pin is metadata-only:
no committed field stores it, and no source-pin or ancestry field changed.
Regenerate changed evidence registrations with repository tooling.

The current-main fleet regression source already matches this checkout;
refresh its inherited stale evidence hash/byte registration with the same
repository helper so FULL validation covers main's actual source bytes.
…ntory

Complete the cued native landing rebase onto main f6ae0de.
The installed inventory_paths derivation reproduces exactly 92 repository grants,
including the landed Claude practice skill and the reviewed metadata workflow.
Preserve the native-union policy bytes and all reviewed PR source edits; update
only the inventory test's hard count from 91 to the measured 92.

Regenerate evidence registrations from main's baseline through
scripts.host_receipts.register_file for all 21 PR source paths and
scripts/evidence_manifest.py --write. No generated manifest hand merge.

Source: scripts/local_pages_policy_grants.py:inventory_paths and
scripts/host_receipts.py:register_file at landed main f6ae0de;
installed Git 2.53.0 native rebase/ls-files metadata and git merge-file -p.
Existing inventory regression fails before the count correction (92 != 91).
Snapshot and comparison SHAs are metadata evidence, not runtime dependency pins.
@seathatflowsinourveins
seathatflowsinourveins force-pushed the foundation/pr-metadata-workflow-20261004 branch from a5eba47 to b616f62 Compare October 10, 2026 06:44
@seathatflowsinourveins
seathatflowsinourveins merged commit 4d34526 into main Oct 10, 2026
36 checks passed
@seathatflowsinourveins
seathatflowsinourveins deleted the foundation/pr-metadata-workflow-20261004 branch October 10, 2026 07:09
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

lane:foundation Foundation lane: Claude/Codex setup, hosts, memory, RAG, research, workers

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant