Skip to content

Pin conformance authority to merge commits on main - #327

Merged
BunsDev merged 2 commits into
mainfrom
feat/authority-freshness-guard
Sep 20, 2026
Merged

BunsDev merged 2 commits into
mainfrom
feat/authority-freshness-guard

Conversation

@BunsDev

@BunsDev BunsDev commented Sep 19, 2026 •

Copy link
Copy Markdown
Member

The lock verifier checks an immutable authority checkout, so governed files can drift on main while its tests remain green. This adds a main-push freshness gate and separates content changes from their subsequent authority repin.

The guard requires an immutable authority revision that is a merge commit on the checked ref's first-parent history. It compares governed harness files, production deltas, and its own source blob. Git calls use the existing hardened environment, disabling replacement objects and inherited Git configuration.

CI extracts and executes the guard and its imports from the pinned authority. Changing the working-tree guard to return success cannot bypass the gate. Fixture tests exercise the actual CI shell, including a neutered current guard, replacement refs, environment overrides, nested feature merges, and symlinked temporary paths.

Merge this PR with a merge commit. It deliberately leaves the lock unchanged; the first main run will fail because the old authority has no guard. A follow-up repin PR will bind this merge commit and refresh all lock digests and their test/prose copies. That follow-up and green final-main CI are part of delivery.

Validation:

  • Freshness tests: 12 passed, with regression failures observed before fixes.
  • Authority lock tests: 95 passed, 1 skipped.
  • Typecheck and lint passed (four existing informational lint suggestions).
  • Full normal suite, serial: 1,346 passed, 63 skipped. The initial parallel run hit one existing 5-second PowerShell timeout; limits were unchanged.
  • Independent review completed; its first-parent finding is fixed and reverified.

Refs #324.

harnessAuthority.revision named a commit on the branch that introduced
the change. That is why every pair of conformance branches collided:
each wrote a different revision into the same file, so whichever merged
second had to be rebuilt, and whichever merged last left a pin
describing a tree that no longer matched what shipped. Three branches
needed that rebuild in a single afternoon.

The authority now names a merge commit already on main, which a pull
request cannot do in one step: a merge commit's SHA does not exist until
the merge happens, so the lock inside the merged tree cannot name it.
Landing a governed change therefore takes a content PR that leaves the
lock alone, then a repin PR that advances the revision and every digest
together against a commit that already exists. Only the repin PR writes
the lock, and it runs serially on main, so content branches cannot
conflict over it. A content PR may now be squashed, since it pins
nothing.

Between the two merges the authority lags, and the lock cannot see it:
the lock test compares digests against a detached checkout of the
authority, which stays self-consistent however far main moves on. That
is how #322 moved Cargo.toml, Cargo.lock and keyring.rs without a repin
and stayed green for three more merges, with the drift only surfacing
when a later change advanced the authority and had to reconcile all
three at once.

phase1-authority-freshness.mjs closes that gap. It asserts the pin is
reachable, is a merge commit rather than a branch tip, and that no
governed file or production delta has moved since it was pinned. CI runs
it on main pushes only, because a pull request is allowed to lag by
construction. A regression test pins it to the #322 merge, where it
reports both the branch-tip pin and all three drifted files.

Refs #324

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🟡 Changes recommended

Critical authority-coverage and Git-hardening gaps remain, along with missing regression and workflow assertions.

Get a fresh assessment by requesting another Copilot review.

Review effort: Lite
Findings: 2 High severity · 1 Low severity

Open (3)
What changed in this PR

Adds a main-push freshness guard ensuring conformance authority remains a reachable merge commit synchronized with governed files.

Changes:

  • Implements freshness validation and regression tests.
  • Documents the two-stage content/repin workflow.
  • Runs enforcement only on pushes to main.
File Summary
src/​phase1-authority-freshness.test.ts Tests authority freshness scenarios; unreachable revisions need coverage.
scripts/​phase1-authority-freshness.mjs Validates reachability, ancestry, and file drift; needs hardened Git execution and immutable authority coverage.
scripts/​phase1-authority-freshness.d.mts Declares freshness-check result types.
docs/​phase1-conformance.md Documents the content/repin protocol; workflow behavior needs clarification.
.github/​workflows/​ci.yml Runs freshness enforcement on main pushes; its presence and scope need a specification guard.

💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

Comment thread scripts/phase1-authority-freshness.mjs
Comment thread scripts/phase1-authority-freshness.mjs Outdated
Comment thread docs/phase1-conformance.md Outdated
@BunsDev
BunsDev merged commit 8c3d735 into main Sep 20, 2026
10 checks passed
BunsDev added a commit that referenced this pull request Sep 20, 2026
Bind the signed guard merge and refresh its workflow digest, test expectations, and documentation. All required PR checks passed.
@BunsDev
BunsDev deleted the feat/authority-freshness-guard branch September 21, 2026 21:19
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants