ci(half-state-patrol): call objectstack's composite action pinned to a sha, with the no-anchor opt-in (objectui#11174) - #11332
Merged
objectstack-fleet[bot] merged 3 commits intoOct 1, 2026
Conversation
…a sha, with the no-anchor opt-in (objectui#11174) The patrol no longer checks out objectstack `main` unpinned and runs the sweeper from it. It calls objectstack-ai/objectstack/.github/actions/half-state-patrol at a 40-character objectstack commit sha (objectstack main's tip as read at implementation time, which contains 79114850f where `anchor-optional` was declared), passing `github-token`, an empty `anchor-issue` beside `anchor-optional: true` (this board's supported no-anchor configuration, objectui#8740), and `closed-floor: '2026-08-28'`. Trigger, schedule, permissions, concurrency and the job name are unchanged. The header prose adopted from upstream is gone; what remains is this board's own: the pin and how to bump it, the no-anchor decision, and the closed-card floor. Every pin of the old shape moves with it: - the Half-State Patrol section of content/docs/guide/ci-cd-pipeline.md; - ci-cd-pipeline-doc.test.ts: the objectui#8043 block now compares the section against the patrol step's parsed `with:` inputs instead of `PM_SWEEP_*` env keys, and holds the sha shape of the ref; the sweeper path the section names is declared as a non-run command (the job has no `run:` step any more); - the sha spelling is a declared exception in check-action-ref-convention.mjs, and that gate's non-vacuity tests append their synthetic entries to the real table instead of replacing it. Claude-Session: https://claude.ai/code/session_01TdiauJaVCHuj45EzZGUxHh Co-authored-by: Claude <noreply@anthropic.com>
…i#11174) The no-anchor paragraph quoted the maintainer's Chinese closing words on objectui#7852; AGENTS.md rule #-1 keeps code comments English, so the header now names the closure instead of quoting it. Claude-Session: https://claude.ai/code/session_01TdiauJaVCHuj45EzZGUxHh Co-authored-by: Claude <noreply@anthropic.com>
This was referenced Oct 1, 2026
Contributor
Author
|
CI red that is not this PR's:
|
This was referenced Oct 1, 2026
objectstack-fleet
Bot
deleted the
claude/issue-11174-half-state-patrol-composite-action-r2
branch
October 1, 2026 07:39
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Fixes #11174
Clause-②: no. CI wiring only; no published contract or accept set moves.
objectui's half of objectstack-ai/objectstack#18471 (ruling 只做②). The half-state patrol stops checking out objectstack
mainunpinned and running the sweeper from it. It now calls objectstack's composite action at a pinned 40-character sha, using the no-anchor opt-in that objectstack-ai/objectstack#20793 (decision A) declared for this board. Dispatched bydomain:devxseat 2, sessionhttps://claude.ai/code/session_01TdiauJaVCHuj45EzZGUxHh, claim comment 5924897388.What changed
.github/workflows/half-state-patrol.yml. These steps are gone: the objectstack checkout (noref:, somain), thenode objectstack-tooling/scripts/pm/check-half-states.mjsstep, the inline resolve-anchor, update-anchor, summary and fail steps, and theANCHOR_ISSUEenv.uses: objectstack-ai/objectstack/.github/actions/half-state-patrol@0c5a71b0942d54e56ad365f0b2a173fd84c1c5e1.github-token: secrets.GITHUB_TOKEN,anchor-issue: '',anchor-optional: trueandclosed-floor: '2026-08-28'.actions/checkoutandactions/setup-node(node'22') stay in the caller. The action needs both: the checkout is the swept subject, and the action has no Node pin of its own.scripts/dependabot-merge-gate.mjsclassifies. To confirm, both versions were parsed withyamlandon,permissions,concurrency,jobs.patrol.name,runs-onandtimeout-minutesall compare SAME.content/docs/guide/ci-cd-pipeline.md, Half-State Patrol section. It now describes the action call, the pin and how to bump it, the four inputs, the no-anchor configuration and its accepted cost, the PR-run blind spot, the floor, and a hand-run recipe. The recipe gainsPM_SWEEP_CLOSED_FLOOR=2026-08-28and a note to check out the pinned sha to reproduce a run.scripts/__tests__/ci-cd-pipeline-doc.test.ts.PM_SWEEP_*env keys, and the workflow no longer sets any. It now compares the section against the patrol step's parsedwith:inputs (viayaml), in both directions. It also holds the floor value, the anchor configuration (emptyanchor-issue+anchor-optional: true), and the 40-hex shape of the ref.SWEEP_DECLARED_NON_RUN_COMMANDSentry is added, forhalf-state-patrol.yml: scripts/pm/check-half-states.mjs. The section names objectstack's sweeper, and the job now has norun:step at all. This is the same dual-eligible shape as the existingcheck-links.ymlentry.scripts/check-action-ref-convention.mjsand its test (see the surface note below).DECLARED_EXCEPTIONSentry with its reason and issue.The pin
0c5a71b0942d54e56ad365f0b2a173fd84c1c5e1. This is objectstackorigin/main's tip, read at 2026-10-01T04:46:15Z withgit -C /home/user/objectstack fetch origin mainand thengit rev-parse origin/main. Its commit date is 2026-10-01T03:32:30Z (fix(metadata-protocol): a packaged action or permission set's refusal names its own sanctioned path (ADR-0126 Regime C rows) objectstack#21026).git merge-base --is-ancestor 79114850f0f559dcb4fb432f5bcfc12947a03de6 0c5a71b0942d54e56ad365f0b2a173fd84c1c5e1gives exit 0. An "is an ancestor" answer proves itself even on the shallow objectstack clone, so no control leg is owed.git rev-list --countbetween them gives 127 commits.main's tip, as the Q2 ruling requires. At the pin, bothaction.yml(blob2df36034) andscripts/pm/check-half-states.mjs(blobfa35f635) are byte-identical to what 79114850f landed. So today the two choices run the same code. The tip rule is what keeps that true on the next bump.action.ymlat the pin:anchor-issue,anchor-optional,closed-floor,github-token;anchor-optionalcomes from ci(half-state-patrol): a declaredanchor-optionalinput lets a board with no anchor issue run summary-only (default off) objectstack#20812.Acceptance evidence: what this PR's own run can and cannot show
pull_requestrun of Half-State Patrol exercises the pin, the inputs and the transport on a real runner. The action'sLocate the patrol sourcesstep judgesgithub-tokenand theanchor-optionalspelling on every event,pull_requestincluded, and the sweep runs.37 1,7,13,19 * * *) orworkflow_dispatchrun after this lands. The expected result:Resolve the anchor issuewritesconfigured=falseand emits the::notice::naminganchor-optional: true;Update the pinned anchor issueis skipped;Tests
Every check below was run on head
ec0c6e49, except where a line namesa13f4e5f. That earlier head differs only by the header-comment edit in the second commit.actionlint -shellcheck= -pyflakes= .github/workflows/half-state-patrol.ymlgives exit 0.permissions:misspelled gives exit 1,unexpected key "permissionz".action.ymlread under The pin.vitest run scripts/__tests__/(throughos-verify-lock,--maxWorkers=2) onec0c6e49: 177 files passed and 2 skipped (179); 5374 tests passed and 2 skipped (5376);VERDICT command-exit 0. The same result ona13f4e5f.pnpm exec vitest run scripts/__tests__/ci-cd-pipeline-doc.test.ts scripts/__tests__/check-action-ref-convention.test.tsgives 2 files and 104 tests passed. On the base it gave 101.tsc -p tsconfig.scripts.json --listFilesona13f4e5fgives exit 0, and both edited test files are in the program.ec0c6e49changes only the workflow YAML, which is outside that program and outside the lint population below.pnpm check:doc-fences,pnpm docs:check-links,pnpm check:control-bytes,pnpm check:action-ref-convention,pnpm check:new-line-citations(0 new citations),pnpm check:test-path-rootsandnode scripts/check-shell-escape-residue.mjs;node scripts/check-changeset-presence.mjs: "no changeset is owed". Nothing under a released package's source or contract moves, so no changeset is added and no label is applied;node scripts/check-governed-queue-guard.mjs --testover the five paths: NOT GOVERNED.eslint --format jsonover the three lintable files reports 3 files, 0 errors and 0 warnings. The YAML and the Markdown are not in the lint population.lint:root, which iseslint .minuspackages/,examples/,apps/anddocs/. The three files sit inside it.eslint.config.jshas noparserOptionsorprojectService, so the linting is not type-aware;eslint-rules/*.jsread no files (readFileSync/existsSync/readdirSyncgive zero hits);Ablations (one-shot; nothing kept)
Each ablation ran through objectstack's
scripts/ablation-replace.mjsin WRAP mode on committed heada13f4e5f. In each, the anchor hit once, the blob changed, and the file was restored with blob == HEAD andgit diff HEADempty.@0c5a71b0…changed to@main: exactly 1 red, "pins the action to a 40-character sha … never a branch".check-action-ref-convention.test.tsstayed green, which is the hole that pin covers: the exception matches by workflow and action, not by spelling.anchor-issue: ''changed to'9857': exactly 1 red, "describes the anchor configuration the step actually passes".closed-floordeleted: 2 red, "names only inputs the workflow actually passes" and "quotes the closure floor".github-tokenbullet stripped of its name: 1 red, "names every input the workflow passes".scan(root, { exceptions: [] })with no file mutated: 1 offender,half-state-patrol.yml … [sha].Surface note for the seat
The claim's surface lists the workflow, the doc section,
ci-cd-pipeline-doc.test.tsand "any othergit grep half-state-patrolhit whose assertion moves". This PR also editsscripts/check-action-ref-convention.mjsandscripts/__tests__/check-action-ref-convention.test.ts.DECLARED_EXCEPTIONSentry.Acceptance notes (noted, not filed)
merge-queue-head-patrol.yml's header still sayshalf-state-patrol.yml"fails when its anchor variable is unset". That has been false since objectui#8740. Its env comment cites "the reasonhalf-state-patrol.ymlstates"; the new header keeps that sentence, so the citation still resolves.changeset-guard.yml,performance-budget.yml,lockfile-dedupe.ymland the docblock ofrender-budget-comment.test.tssay this workflow listsscripts/invoked-as.mjsin its paths. That has been false since objectui#10208, not because of this PR.github-actionsecosystem runs monthly here. Whether it proposes bumps for a sha-pinned ref to a non-tagged action path inside a monorepo is NOT MEASURED. If it does, the bump arrives as a PR touching this file, which runs the patrol, so it is a reviewed moment in any case.Generated by Claude Code