From 16a957c1d8acf27f67eca7a313ee17bddf0c0b3f Mon Sep 17 00:00:00 2001 From: Claude Date: Thu, 17 Sep 2026 15:10:58 +0000 Subject: [PATCH] re-pin layer 3 of 3: this repository's 4 malf-toolchain references move onto da2abf63 Layer 3 (the last) of the malf-toolchain re-pin that unblocks the next CodeRoast release tag. THE DEFECT. The workspace pinned malf-toolchain at b5e15eee5e2cc9a2709309850f845b28ba8d9e58. The `malf` driver at that revision does `local pin="$MALF_WORKSPACE_ROOT/scripts/pin_coherence.py"` followed by `[[ -f "$pin" ]] || return 1`, in both `cut-verify` and `bump`. That superproject script no longer exists: the check became the Pharos check module `scripts/pharos/checks/pin_coherence.py` and its two producer verbs (`released` and `bump X.Y.Z`) moved to `scripts/version_line.py`. So the next `v*` tag would run `.github/workflows/cut-verify.yml`, which checks malf-toolchain out at the pinned revision and runs that checkout's `malf cut-verify`, which exits 1 on the missing file -- and every release job declaring `needs: [cut-verify, ...]` would be skipped. Measured: `git show b5e15eee:malf | grep -c pin_coherence` returns 6; `git show da2abf63:malf | grep -c pin_coherence` returns 2, and both survivors are correct (one comment and one `python3 "$pharos" check --module pin_coherence` invocation). THE TARGET IS NOT THE TOOLCHAIN'S main. `origin/main` is b62485cde9e1d5438b2c4ebabe86189a0ea7f028 and its count is also 6 -- main does not carry the fix. The target is da2abf639f64e1c1bca382aa7a973e9cc2f00412, the head of malf-toolchain's `claude/coderoast-claude-md-malf-p80u1w` branch, which is a strict fast-forward of main (7 commits ahead, 0 behind). That branch must be merged, not squashed, or every reference below would name a commit that no longer exists. WHY da2abf63 IS A LEGAL TARGET FOR EXTERNAL REFERENCES. The re-pin is layered because a commit may only pin edges whose TARGET it does not touch. Layer 1 (390108f5) moved malf-toolchain's 9 action->action refs onto the content head 5081176 and touched only 6 files under `.github/actions/`, none of them a target of those refs. Layer 2 (da2abf63) moved the 10 workflow->action refs onto layer 1 and touched only `.github/workflows/`, so all 10 target actions have identical bytes at layer 1 and at da2abf63. This layer touches no malf-toolchain file at all, so every workflow and every action a consumer executes has, at da2abf63, exactly the bytes it has at the revision this workspace pins. INV-17 (d) verifies that chain independently: each pinned SHA must be an ancestor of its successor differing by nothing but `uses:` lines. IN THIS REPOSITORY. 4 references move from b5e15eee to da2abf63: 4 `uses:` step(s) and no `actions/checkout` of the toolchain. Verified: every changed line is either a `uses: CodeRoasted/malf-toolchain/...@<40-hex>` step or the `ref:` of an `actions/checkout` whose `repository:` is `CodeRoasted/malf-toolchain`; every changed file parses under `python3 -c "import yaml; yaml.safe_load(open(f))"`. Co-Authored-By: Claude Opus 5 Claude-Session: https://claude.ai/code/session_01DgF1dGH16hPwX7aaaKguWw --- .github/workflows/ci.yml | 4 ++-- .github/workflows/lint.yml | 2 +- .github/workflows/release.yaml | 2 +- 3 files changed, 4 insertions(+), 4 deletions(-) diff --git a/.github/workflows/ci.yml b/.github/workflows/ci.yml index 033698c..865e265 100644 --- a/.github/workflows/ci.yml +++ b/.github/workflows/ci.yml @@ -11,7 +11,7 @@ jobs: permissions: contents: read actions: read - uses: CodeRoasted/malf-toolchain/.github/workflows/coderoast-ci.yml@b5e15eee5e2cc9a2709309850f845b28ba8d9e58 + uses: CodeRoasted/malf-toolchain/.github/workflows/coderoast-ci.yml@da2abf639f64e1c1bca382aa7a973e9cc2f00412 with: # ipc is a tower root (no first-party deps to vendor). Root meta-package first, then the three # sub-packages; each gates its unit tests behind a -D flag, passed as trailing cmake-args. @@ -35,7 +35,7 @@ jobs: permissions: pull-requests: write actions: read - uses: CodeRoasted/malf-toolchain/.github/workflows/coderoast-sift-post.yml@b5e15eee5e2cc9a2709309850f845b28ba8d9e58 + uses: CodeRoasted/malf-toolchain/.github/workflows/coderoast-sift-post.yml@da2abf639f64e1c1bca382aa7a973e9cc2f00412 with: run-id: ${{ github.run_id }} secrets: inherit diff --git a/.github/workflows/lint.yml b/.github/workflows/lint.yml index 9ce4025..92d9564 100644 --- a/.github/workflows/lint.yml +++ b/.github/workflows/lint.yml @@ -8,4 +8,4 @@ on: jobs: lint: - uses: CodeRoasted/malf-toolchain/.github/workflows/coderoast-lint.yml@b5e15eee5e2cc9a2709309850f845b28ba8d9e58 + uses: CodeRoasted/malf-toolchain/.github/workflows/coderoast-lint.yml@da2abf639f64e1c1bca382aa7a973e9cc2f00412 diff --git a/.github/workflows/release.yaml b/.github/workflows/release.yaml index 39756f2..36d0683 100644 --- a/.github/workflows/release.yaml +++ b/.github/workflows/release.yaml @@ -25,7 +25,7 @@ jobs: secrets: inherit release: needs: ci - uses: CodeRoasted/malf-toolchain/.github/workflows/coderoast-release.yml@b5e15eee5e2cc9a2709309850f845b28ba8d9e58 + uses: CodeRoasted/malf-toolchain/.github/workflows/coderoast-release.yml@da2abf639f64e1c1bca382aa7a973e9cc2f00412 with: tag: ${{ github.event.inputs.tag || github.ref_name }} packages: |