Repository navigation
Pin conformance authority to merge commits on main - #327
Merged
Merged
Conversation
harnessAuthority.revision named a commit on the branch that introduced the change. That is why every pair of conformance branches collided: each wrote a different revision into the same file, so whichever merged second had to be rebuilt, and whichever merged last left a pin describing a tree that no longer matched what shipped. Three branches needed that rebuild in a single afternoon. The authority now names a merge commit already on main, which a pull request cannot do in one step: a merge commit's SHA does not exist until the merge happens, so the lock inside the merged tree cannot name it. Landing a governed change therefore takes a content PR that leaves the lock alone, then a repin PR that advances the revision and every digest together against a commit that already exists. Only the repin PR writes the lock, and it runs serially on main, so content branches cannot conflict over it. A content PR may now be squashed, since it pins nothing. Between the two merges the authority lags, and the lock cannot see it: the lock test compares digests against a detached checkout of the authority, which stays self-consistent however far main moves on. That is how #322 moved Cargo.toml, Cargo.lock and keyring.rs without a repin and stayed green for three more merges, with the drift only surfacing when a later change advanced the authority and had to reconcile all three at once. phase1-authority-freshness.mjs closes that gap. It asserts the pin is reachable, is a merge commit rather than a branch tip, and that no governed file or production delta has moved since it was pinned. CI runs it on main pushes only, because a pull request is allowed to lag by construction. A regression test pins it to the #322 merge, where it reports both the branch-tip pin and all three drifted files. Refs #324
9 tasks
Contributor
There was a problem hiding this comment.
Copilot review overview
🟡 Changes recommended
Critical authority-coverage and Git-hardening gaps remain, along with missing regression and workflow assertions.
Get a fresh assessment by requesting another Copilot review.
Review effort: Lite
Findings: 2
Open (3)
What changed in this PR
Adds a main-push freshness guard ensuring conformance authority remains a reachable merge commit synchronized with governed files.
Changes:
- Implements freshness validation and regression tests.
- Documents the two-stage content/repin workflow.
- Runs enforcement only on pushes to
main.
| File | Summary |
|---|---|
src/phase1-authority-freshness.test.ts |
Tests authority freshness scenarios; unreachable revisions need coverage. |
scripts/phase1-authority-freshness.mjs |
Validates reachability, ancestry, and file drift; needs hardened Git execution and immutable authority coverage. |
scripts/phase1-authority-freshness.d.mts |
Declares freshness-check result types. |
docs/phase1-conformance.md |
Documents the content/repin protocol; workflow behavior needs clarification. |
.github/workflows/ci.yml |
Runs freshness enforcement on main pushes; its presence and scope need a specification guard. |
💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.
BunsDev
added a commit
that referenced
this pull request
Sep 20, 2026
Bind the signed guard merge and refresh its workflow digest, test expectations, and documentation. All required PR checks passed.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.


The lock verifier checks an immutable authority checkout, so governed files can drift on main while its tests remain green. This adds a main-push freshness gate and separates content changes from their subsequent authority repin.
The guard requires an immutable authority revision that is a merge commit on the checked ref's first-parent history. It compares governed harness files, production deltas, and its own source blob. Git calls use the existing hardened environment, disabling replacement objects and inherited Git configuration.
CI extracts and executes the guard and its imports from the pinned authority. Changing the working-tree guard to return success cannot bypass the gate. Fixture tests exercise the actual CI shell, including a neutered current guard, replacement refs, environment overrides, nested feature merges, and symlinked temporary paths.
Merge this PR with a merge commit. It deliberately leaves the lock unchanged; the first main run will fail because the old authority has no guard. A follow-up repin PR will bind this merge commit and refresh all lock digests and their test/prose copies. That follow-up and green final-main CI are part of delivery.
Validation:
Refs #324.