Skip to content

fix(publish): one door to cargo publish — the recorded clean-room run must be green on the tag (PMAT-4687) - #4869

Open
noahgift wants to merge 2 commits into
mainfrom
PMAT-4687-publish-strict-pinned-cleanroom
Open

noahgift wants to merge 2 commits into
mainfrom
PMAT-4687-publish-strict-pinned-cleanroom

Conversation

@noahgift

@noahgift noahgift commented Oct 6, 2026 •

Copy link
Copy Markdown
Contributor

What

publish_strict.sh is the one door to cargo publish. It used to accept any non-empty cleanroom-run-id file. It now reads the recorded run back and judges it with the cascade's own clean_room_gate, pinned to that one run. A run id that is missing, empty, non-numeric, unreadable, red, from another workflow, or green on another commit stops the cascade before any upload. --plan is unchanged.

clean_room_gate gains an optional third argument, a recorded run id. In pinned mode it reads exactly that run through the runs API and never lists runs, so a green run elsewhere cannot stand in for a red recorded one.

Proof

Before (main 645dc34) After (this head)
scripts/check_publish_strict_cleanroom.sh (runs the real publish_strict.sh with stub gh/cargo) 8 of 9 checks FAIL: non-numeric, red, other-commit and unreadable ids all pass the door 9 of 9 hold
scripts/check_cascade_clean_room_gate.sh no pinned rows every row holds, including 10 pinned rows
pv validate contracts/publish-workspace-v1.yaml — 0 errors (adds PW-DOOR-005, FALSIFY-PUB-008)

The green row passes the clean-room door and then stops on the next precondition, so no row reaches an upload; the stub cargo fails the table if it is ever called.

A planted review round on 1b52a42 returned YES; both lanes caught the plant. 56a84f3 adds only CI follow-ups (ontology glyphs in the new formal: line, a comment reworded so the new guard runs in guard-tree, the regenerated roadmap), and the round is re-run on it. This is a gate change, so it needs two non-author reviews before merge.

Refs #4687

keep-open: #4687 is a multi-row issue and this PR delivers only its row T10; the issue closes when its remaining rows land.

🤖 Generated with Claude Code

… must be green on the tag (PMAT-4687)

publish_strict.sh accepted any non-empty cleanroom-run-id file. It now reads
the recorded run back and judges it with the cascade's own clean_room_gate,
pinned to that one run: a missing, empty, non-numeric, unreadable, red or
other-commit run id stops the cascade before any upload. --plan is unchanged.

clean_room_gate gains an optional third argument, a recorded run id. Pinned
mode reads exactly that run through the runs API, refuses a run of another
workflow, and never lists runs, so a green run elsewhere cannot stand in for
a red recorded one.

Falsifier: scripts/check_publish_strict_cleanroom.sh runs the real
publish_strict.sh against a fixture tag checkout and stub gh/cargo. On
origin/main 645dc34 it fails 8 of 9 checks; here 9 of 9 hold.
check_cascade_clean_room_gate.sh gains 10 pinned rows. Contract:
PW-DOOR-005 + FALSIFY-PUB-008 (pv validate: 0 errors).

Agent: aprender-cd
Refs: #4687
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
@github-actions

github-actions Bot commented Oct 6, 2026 •

Copy link
Copy Markdown

§13.11 rung 1 — quorum shadow verdict

S13-SHADOW pr=4869 head=56a84f3e03baac4ab915d0754ce6853bbd3aff34 verdict=REFUSE class=Q1 arm_rc=1

Shadow mode: this records a verdict and merges nothing. A refusal
to arm is not a block (§13 adds zero rows to §7) — the pull request is
exactly as green as it was.

…d wiring, roadmap aggregate (PMAT-4687)

- PW-DOOR-005's formal: line now uses symbols the ontology declares
  (⇒ ≠ ∅ ∧), so formal_prose stays at the 1464 baseline instead of rising
  to 1465 (PV-ONT-004, shrink-only).
- check_publish_strict_cleanroom.sh carried a bare cargo token in a comment,
  so the textual classifier filed it as a cargo guard that no workflow runs.
  The comment is reworded; the guard invokes no build tool and now runs in
  guard-tree (check_guards_are_wired.sh: PASS, unwired stays 3).
- docs/roadmaps/roadmap.yaml regenerated from the new fragment.

Agent: aprender-cd
Refs: #4687
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant