Skip to content

ci: prepare prospective decision metadata with pinned PyYAML - #745

Closed
seathatflowsinourveins wants to merge 2 commits into
mainfrom
codex/ns2604-ci-r5-20261005
Closed

seathatflowsinourveins wants to merge 2 commits into
mainfrom
codex/ns2604-ci-r5-20261005

Conversation

@seathatflowsinourveins

@seathatflowsinourveins seathatflowsinourveins commented Oct 5, 2026 •

Copy link
Copy Markdown
Owner

Scope

Prepare prospective MADR metadata validation for decision paths introduced after R5's actual main landing tree, a deterministic index, and advisory review-date reporting. Add PyYAML 6.0.3 through the existing Linux CI binary-only, hash-locked requirements installer after #735 landed.

Partial draft: the validate.yml caller remains #706-owned. The decision documents the one-line opt-in and full-history prerequisite after R5 lands. Default integrity and arbitrary-file scanning remain stdlib-only. This draft changes no workflow and claims no hosted metadata enforcement. It stays draft for the command center's Claude read.

SOTA sources

Evidence-class table

Claim Evidence class Command / receipt
Required fields, date bounds, concurrent-main arrivals, backdated additions, stale indexes and pending/unknown states obey the policy synthetic / local_integration 196 touched tests passed after rebase
Default/scan validation, currency report shape/notices and final coverage-row position remain compatible local_integration Existing currency, notice and validator tests in those 196
Combined CI lock resolves binary wheels with verified hashes on CP313; a wrong PyYAML hash is rejected local_integration / synthetic control, reused Earlier native pip dry-run 0, 11 candidates; zeroed-hash fixture exit 1 as expected; lock/include/installer bytes unchanged
Existing analyzer pin/hash and OSV calendar include remain consistent local_integration Three targeted lock-policy tests passed
Selected PyYAML parser passed its unchanged upstream harness on the reviewed CP313 wheel native_proven, reused 2,608 upstream tests, one unchanged-source warning; not a new R5/CI312 acceptance
Registry references/hashes are consistent local_integration python3 scripts/validate.py exit 0; integrity/scope only
SDK constructor completed unknown / unfinished Native 25-minute timeout, no report/edits, requests/usage UNKNOWN; source-backed coordinator recovery has separate evidence
Hosted metadata enforcement / native CP312 parser acceptance unknown #706 caller held; no workflow rerun or new hosted acceptance claim

Local commands run

Private paths are sanitized; actual commands/results are retained in the lane record and compact receipt. The 199 local tests and integrity check are fresh on main1796303f. Pip and unchanged upstream parser evidence are reused from the prior receipt with matching input hashes; no repeat install or parser execution.

env TMPDIR=<private-cache> PYTHONDONTWRITEBYTECODE=1 <accepted-parser-venv>/bin/python -m unittest tests.test_decision_metadata tests.test_currency_due tests.test_currency_due_notice tests.test_validate
Ran 196 tests in 30.514s on main1796303f; OK; exit 0
python -m unittest tests.test_workflow_policy.ZizmorConfigurationTests.test_the_analyzer_stays_pinned_by_hash tests.test_catalog_freshness_pins.CatalogFreshnessPinTableTests.test_zizmor_pin_matches_requirements_lock tests.test_osv_lockfile_coverage.IgnorePolicyTests.test_repo_wide_ignores_hide_nothing_outside_their_allowed_lock
Ran 3 tests in 0.214s on main1796303f; OK; exit 0
python -m pip install --isolated --dry-run --ignore-installed --only-binary=:all: --require-hashes --index-url https://pypi.org/simple -r .github/requirements-ci.txt --report <private-native-report>
exit 0; 11 binary candidates; PyYAML6.0.3 CP313 SHA2560f29edc4...
same native pip command with deliberately zeroed PyYAML expected hash
exit 1; expected hash mismatch
python3 scripts/validate.py
exit 0; 69 components, 4 profiles, 204 receipts, 10189 hashes
python3 scripts/component_matrix.py --write
exit 0; 32 rows, 0 flip-rule violations
python3 scripts/new_host_grand_list.py --write
exit 0; 32 layers, 66 winners
git diff --check
exit 0

Failed attempts

The native OpenHands SDK builder job ns2604-ci-r5-write-20261005 started at 2026-10-05T14:03:00Z and ended at 2026-10-05T14:28:00Z after its 1,500-second (25-minute) limit. Preparation exited 0; the native start/wait command exited 1, and independent service observation reported Result=timeout. The attempt is UNFINISHED: no run report, no repository edits, and requests and usage UNKNOWN. ExecMainStatus=0 does not establish completion. Native journal and frozen source inputs remain retained privately. No SDK retry.

The lane root's cited-source implementation and later tests are separate integration/synthetic evidence and do not stand in for the failed SDK attempt or unchanged upstream tests. This follows the acceptance evidence policy and user A18. Exact structured attempt metadata and earlier failed test conditions/corrections remain in evidence/artifacts/github-ci-r5-20261005.json. The earlier #735 rebase conflicted only in the registry; the current-main rebase was clean. Main's registry copy was taken and this branch's evidence re-registered both times, without a hand merge.

Decision record

docs/decisions/2026-10-05-ci-decision-metadata.md names the alternatives, actual-landing baseline, non-success pending/unknown states, owner wiring, source correction and overturn conditions. Receipt: evidence/artifacts/github-ci-r5-20261005.json.

Host evidence

No evidence/hosts or platform-status change. Native pip performed a dry-run only; parser upstream acceptance is reused historical evidence with matching inputs.

Checklist

@seathatflowsinourveins seathatflowsinourveins added the lane:foundation Foundation lane: Claude/Codex setup, hosts, memory, RAG, research, workers label Oct 5, 2026
@seathatflowsinourveins seathatflowsinourveins changed the title ci: prepare decision metadata for records after R5 lands ci: prepare prospective decision metadata with pinned PyYAML Oct 5, 2026
@seathatflowsinourveins
seathatflowsinourveins force-pushed the codex/ns2604-ci-r5-20261005 branch from 664c428 to 2579f7c Compare October 5, 2026 15:24
@socket-security

socket-security Bot commented Oct 5, 2026 •

Copy link
Copy Markdown

Dependency limit exceeded — report not shown.

This pull request scan exceeded the 10,000-dependency limit applied to this scan, so the results are incomplete and may be inaccurate. To avoid reporting false positives, Socket has not posted a report.

Upgrade your plan to raise the dependency limit and get complete reports, or view the partial scan in the dashboard.

Socket is always free for open source. If this is a non-commercial open source project, contact us to request a free Team account.

@seathatflowsinourveins
seathatflowsinourveins force-pushed the codex/ns2604-ci-r5-20261005 branch from 2579f7c to bb3832b Compare October 5, 2026 16:11
@seathatflowsinourveins

Copy link
Copy Markdown
Owner Author

Closed with a record by the PR triage of 2026-10-07 (the command center's ruling, item review-ns2604-coop-20261007T023012Z (the command center's PR-triage ruling of 2026-10-07; proposal by github-ci-finalize, triage-20261007.json)). Not merged; the branch codex/ns2604-ci-r5-20261005 stays on origin at bb3832b.

What it holds: docs/decisions/2026-10-05-ci-decision-metadata.md; docs/decisions/decision-metadata-index.json; scripts/decision_metadata.py with tests/test_decision_metadata.py; evidence/artifacts/github-ci-r5-20261005.json; scripts/validate.py and scripts/currency_due.py (modified); .github/requirements-ci.txt (PyYAML 6.0.3, hash-pinned)

Superseded by: not superseded; unprioritized under the 2026-10-07 PR triage (confidence: high that nothing supersedes it: scripts/decision_metadata.py and the index are absent on main, and validate.py, currency_due.py and requirements-ci.txt are unchanged since its base)

Reopen trigger: The repository adopts machine-readable MADR metadata for new decision records. Reopen with gh pr reopen 745.

@seathatflowsinourveins
seathatflowsinourveins deleted the codex/ns2604-ci-r5-20261005 branch October 8, 2026 17:05
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

lane:foundation Foundation lane: Claude/Codex setup, hosts, memory, RAG, research, workers

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant