Skip to content

re-pin layer 3 of 3: this repository's 4 malf-toolchain references mo… - #13

Merged
coderoast-dev merged 1 commit into
mainfrom
claude/coderoast-claude-md-malf-p80u1w
Sep 18, 2026
Merged

coderoast-dev merged 1 commit into
mainfrom
claude/coderoast-claude-md-malf-p80u1w

Conversation

@coderoast-dev

Copy link
Copy Markdown
Collaborator

…ve onto da2abf63

Layer 3 (the last) of the malf-toolchain re-pin that unblocks the next CodeRoast release tag.

THE DEFECT. The workspace pinned malf-toolchain at b5e15eee5e2cc9a2709309850f845b28ba8d9e58. The malf driver at that revision does local pin="$MALF_WORKSPACE_ROOT/scripts/pin_coherence.py" followed by [[ -f "$pin" ]] || return 1, in both cut-verify and bump. That superproject script no longer exists: the check became the Pharos check module scripts/pharos/checks/pin_coherence.py and its two producer verbs (released and bump X.Y.Z) moved to scripts/version_line.py. So the next v* tag would run .github/workflows/cut-verify.yml, which checks malf-toolchain out at the pinned revision and runs that checkout's malf cut-verify, which exits 1 on the missing file -- and every release job declaring needs: [cut-verify, ...] would be skipped. Measured: git show b5e15eee:malf | grep -c pin_coherence returns 6; git show da2abf63:malf | grep -c pin_coherence returns 2, and both survivors are correct (one comment and one python3 "$pharos" check --module pin_coherence invocation).

THE TARGET IS NOT THE TOOLCHAIN'S main. origin/main is b62485cde9e1d5438b2c4ebabe86189a0ea7f028 and its count is also 6 -- main does not carry the fix. The target is
da2abf639f64e1c1bca382aa7a973e9cc2f00412, the head of malf-toolchain's claude/coderoast-claude-md-malf-p80u1w branch, which is a strict fast-forward of main (7 commits ahead, 0 behind). That branch must be merged, not squashed, or every reference below would name a commit that no longer exists.

WHY da2abf63 IS A LEGAL TARGET FOR EXTERNAL REFERENCES. The re-pin is layered because a commit may only pin edges whose TARGET it does not touch. Layer 1 (390108f5) moved malf-toolchain's 9 action->action refs onto the content head 5081176 and touched only 6 files under .github/actions/, none of them a target of those refs. Layer 2 (da2abf63) moved the 10 workflow->action refs onto layer 1 and touched only .github/workflows/, so all 10 target actions have identical bytes at layer 1 and at da2abf63. This layer touches no malf-toolchain file at all, so every workflow and every action a consumer executes has, at da2abf63, exactly the bytes it has at the revision this workspace pins. INV-17 (d) verifies that chain independently: each pinned SHA must be an ancestor of its successor differing by nothing but uses: lines.

IN THIS REPOSITORY. 4 references move from b5e15eee to da2abf63: 4 uses: step(s) and no actions/checkout of the toolchain.

Verified: every changed line is either a
uses: CodeRoasted/malf-toolchain/...@<40-hex> step or the ref: of an actions/checkout whose repository: is CodeRoasted/malf-toolchain; every changed file parses under
python3 -c "import yaml; yaml.safe_load(open(f))".

Claude-Session: https://claude.ai/code/session_01DgF1dGH16hPwX7aaaKguWw

…ve onto da2abf63

Layer 3 (the last) of the malf-toolchain re-pin that unblocks the next
CodeRoast release tag.

THE DEFECT. The workspace pinned malf-toolchain at
b5e15eee5e2cc9a2709309850f845b28ba8d9e58. The `malf` driver at that revision
does `local pin="$MALF_WORKSPACE_ROOT/scripts/pin_coherence.py"` followed by
`[[ -f "$pin" ]] || return 1`, in both `cut-verify` and `bump`. That
superproject script no longer exists: the check became the Pharos check module
`scripts/pharos/checks/pin_coherence.py` and its two producer verbs (`released`
and `bump X.Y.Z`) moved to `scripts/version_line.py`. So the next `v*` tag
would run `.github/workflows/cut-verify.yml`, which checks malf-toolchain out
at the pinned revision and runs that checkout's `malf cut-verify`, which exits
1 on the missing file -- and every release job declaring
`needs: [cut-verify, ...]` would be skipped. Measured:
`git show b5e15eee:malf | grep -c pin_coherence` returns 6;
`git show da2abf63:malf | grep -c pin_coherence` returns 2, and both survivors
are correct (one comment and one `python3 "$pharos" check --module
pin_coherence` invocation).

THE TARGET IS NOT THE TOOLCHAIN'S main. `origin/main` is
b62485cde9e1d5438b2c4ebabe86189a0ea7f028 and its count is also 6 -- main does
not carry the fix. The target is
da2abf639f64e1c1bca382aa7a973e9cc2f00412, the head of malf-toolchain's
`claude/coderoast-claude-md-malf-p80u1w` branch, which is a strict
fast-forward of main (7 commits ahead, 0 behind). That branch must be merged,
not squashed, or every reference below would name a commit that no longer
exists.

WHY da2abf63 IS A LEGAL TARGET FOR EXTERNAL REFERENCES. The re-pin is layered
because a commit may only pin edges whose TARGET it does not touch. Layer 1
(390108f5) moved malf-toolchain's 9 action->action refs onto the content head
5081176 and touched only 6 files under `.github/actions/`, none of them a
target of those refs. Layer 2 (da2abf63) moved the 10 workflow->action refs
onto layer 1 and touched only `.github/workflows/`, so all 10 target actions
have identical bytes at layer 1 and at da2abf63. This layer touches no
malf-toolchain file at all, so every workflow and every action a consumer
executes has, at da2abf63, exactly the bytes it has at the revision this
workspace pins. INV-17 (d) verifies that chain independently: each pinned SHA
must be an ancestor of its successor differing by nothing but `uses:` lines.

IN THIS REPOSITORY. 4 references move from b5e15eee to da2abf63: 4 `uses:`
step(s) and no `actions/checkout` of the toolchain.

Verified: every changed line is either a
`uses: CodeRoasted/malf-toolchain/...@<40-hex>` step or the `ref:` of an
`actions/checkout` whose `repository:` is `CodeRoasted/malf-toolchain`; every
changed file parses under
`python3 -c "import yaml; yaml.safe_load(open(f))"`.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01DgF1dGH16hPwX7aaaKguWw
@coderoast-dev
coderoast-dev merged commit 4454042 into main Sep 18, 2026
2 checks passed
@coderoast-dev
coderoast-dev deleted the claude/coderoast-claude-md-malf-p80u1w branch September 19, 2026 08:03
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants