PR #1284 at df74ef1 was reviewed against git diff origin/main...HEAD.
Two coverage gaps block the supplied review bar:
-
The sole roadmap caller now depends on the labels audit succeeding. .github/workflows/issue-triage.yml:241 has no step if, so GitHub applies success(). If any open issue lacks labels, the earlier labels audit exits 1 and the roadmap contract, selftest and live arms are skipped, including on a PR editing ROADMAP.md or either gate. The old suite ran these gates independently; after this PR it cannot provide that coverage. Run the roadmap step with a status condition such as ${{ !cancelled() }}, or put the two audits in independent jobs. Keep their failures advisory. The ordinary PR run did succeed: https://github.com/InauguralSystems/EigenScript/actions/runs/35922007325 . This finding concerns the first-step-failure path, not an observed failure of that run. GitHub's default status condition: https://docs.github.com/en/actions/reference/workflows-and-actions/expressions#status-check-functions .
-
tests/run_all_tests.sh:7081-7084 checks only the selftest exit status. The deleted caller also pinned its counts. In a disposable copy, add return 0 immediately after selftest() { in tools/workflow_yaml_check.sh; execute the actual extracted [99zd] section, including the runner's bash accounting wrapper. It prints RESULTS: TOTAL=1 PASS=1 FAIL=0 although --selftest emits nothing. Likewise, add return 0 at the start of st_case() and the section passes over SELFTEST: 0 case(s) run, 0 passed, 0 failed, 0 skipped. Disabling only selftest loader runs produces 8 case(s) run, 6 passed, 0 failed, 2 skipped on a host where import yaml succeeds, and the section still passes. Restore the small caller-owned summary check: eight total, eight passed/zero skipped with PyYAML, six passed/two skipped without it. Control is green; whole-gate exit-0, exit-1, disabled live loader, and malformed workflow plants are all red.
Dangling claims to repair with the above:
- issue-triage.yml:226-233 still says the dev image carries gh, Linux gcc exports its token, and contrasts this job with the former suite caller.
- docs/CI.md:337-340 and tools/workflow_yaml_check.sh:53-54,77-81 claim selftest/contract pins that the new caller does not enforce.
- tools/gh_probe.sh:32 refers to deleted CI.md text, “What the caller can and cannot prove”.
- CHANGELOG.md:1441 says “see below” for the new change, which is above at line 1389.
Validation (one heavy command at a time; no full-suite rerun):
- make: exit 0, EigenScript 0.43.0 built. Binary: 952K
- make precheck: 19 passed, 0 failed, 0 skipped in 89s
- section_plan.sh --skip-audit: 25 emitting lines (floor 20), 25 routed skips (floor 25), 25 reviewed reasons, unaccounted=0
- child_exit_check.sh: 122 child sites (floor 122), no bypasses, 8 environment-selectable children
- docs_claims_check.sh: NUMBERS 36 (history-deferred=0), PATHS 248, FLAGS 43, MAKE TARGETS 36, NAMES 463 (families 12), DOC ENROLMENT 12
- ci_tier_check.sh: 22 jobs (16 required, 6 workers), 19 required names, 25 jobs on required paths
- yaml.safe_load of all 9 workflow files: exit 0, no output
- Both lowered floors are exact: child sites 126 -> 122 (-4); docs/CI.md paths 68 -> 65 (-3).
- The live Protection ruleset lists exactly the 19 required checks in .github/required-checks.txt and excludes issue-triage.
Out of scope (pre-existing): workflow_yaml_check.sh:227 checks only whether jobs exists, not whether it is a mapping. A file containing name: lane, on: workflow_dispatch, jobs: [] is accepted with workflow-yaml: OK (examined=1 file(s), 1 name(s), loader=pyyaml), despite the tool header claiming a jobs mapping. This is not introduced by #1284.
PR #1284 at df74ef1 was reviewed against
git diff origin/main...HEAD.Two coverage gaps block the supplied review bar:
The sole roadmap caller now depends on the labels audit succeeding.
.github/workflows/issue-triage.yml:241has no stepif, so GitHub appliessuccess(). If any open issue lacks labels, the earlier labels audit exits 1 and the roadmap contract, selftest and live arms are skipped, including on a PR editing ROADMAP.md or either gate. The old suite ran these gates independently; after this PR it cannot provide that coverage. Run the roadmap step with a status condition such as${{ !cancelled() }}, or put the two audits in independent jobs. Keep their failures advisory. The ordinary PR run did succeed: https://github.com/InauguralSystems/EigenScript/actions/runs/35922007325 . This finding concerns the first-step-failure path, not an observed failure of that run. GitHub's default status condition: https://docs.github.com/en/actions/reference/workflows-and-actions/expressions#status-check-functions .tests/run_all_tests.sh:7081-7084checks only the selftest exit status. The deleted caller also pinned its counts. In a disposable copy, addreturn 0immediately afterselftest() {intools/workflow_yaml_check.sh; execute the actual extracted[99zd]section, including the runner's bash accounting wrapper. It printsRESULTS: TOTAL=1 PASS=1 FAIL=0although--selftestemits nothing. Likewise, addreturn 0at the start ofst_case()and the section passes overSELFTEST: 0 case(s) run, 0 passed, 0 failed, 0 skipped. Disabling only selftest loader runs produces8 case(s) run, 6 passed, 0 failed, 2 skippedon a host whereimport yamlsucceeds, and the section still passes. Restore the small caller-owned summary check: eight total, eight passed/zero skipped with PyYAML, six passed/two skipped without it. Control is green; whole-gate exit-0, exit-1, disabled live loader, and malformed workflow plants are all red.Dangling claims to repair with the above:
Validation (one heavy command at a time; no full-suite rerun):
Out of scope (pre-existing): workflow_yaml_check.sh:227 checks only whether
jobsexists, not whether it is a mapping. A file containingname: lane,on: workflow_dispatch,jobs: []is accepted withworkflow-yaml: OK (examined=1 file(s), 1 name(s), loader=pyyaml), despite the tool header claiming a jobs mapping. This is not introduced by #1284.