fix(ci): untrusted-input checks the corpus figure against its anchor, not anywhere in the doc (Closes #5799) - #5801
Merged
Conversation
…nywhere in the doc Untrusted Input Gate's re-take guard required today's spec count to appear anywhere in docs/theory/IGLA-FORMAL-RESULTS.md (`str(walked) in doc`). It was red on master (1166 appears nowhere), red on every PR that adds a spec merely for adding it, and green at 1156 only because T444 enumerates 1156 alphabets. The figure is now one generated, marked block: <!-- corpus-count anchor=<40-hex> -->1146<!-- /corpus-count --> written by `test_retaken_propositions_still_match.py --write`, and the check is the relation it states: the block equals the .t27 count (outside any scratch dir) in the tree of the anchor commit, fetched by SHA when the depth-1 CI checkout lacks it. The block must also match its RE-TAKEN AT heading and the re-take's total row. No number outside the marker is read. A live count regenerated by every spec PR was rejected: five spec merges landed inside 90 s on 2026-10-03, and two branches that each write N+1 merge cleanly into a wrong master. Closes #5799 Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Contributor
Contributor
|
📓 NotebookLM Notebook linked to this PR
This notebook contains session context, decisions, and artifacts for this work. |
This was referenced Oct 3, 2026
Closed
gHashTag
added a commit
that referenced
this pull request
Oct 4, 2026
…5891) P17's catalog figure is now one generated block, <!-- catalog-count anchor=<40-hex> -->N<!-- /catalog-count -->. It is checked against the CATALOG: lines in specs/numeric/formats_catalog.t27 at the anchor, the RE-TAKEN AT heading and the mandatory-field row. Nothing outside the marker is read. The marker, fetch-by-SHA and --write move into scripts/ci/anchored_count.py, which both gates share; the #5801 corpus gate's output is byte-identical on the doc. --self-check runs four controls in CI: correct block gives 0; wrong block, wrong block with the number planted elsewhere, and marker removed each give 1. Closes #5881
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Closes #5799
What
untrusted-inputrequired, and why that was wrongStep "Every re-taken proposition is still anchored" runs
scripts/ci/test_retaken_propositions_still_match.py. For the corpus it checkedstr(walked) in doc: today's count of.t27files underspecs/(outsidescratch) had to appear anywhere in the 27k-linedocs/theory/IGLA-FORMAL-RESULTS.md. The intent (#3086) was "the re-takes must not quote a corpus that has moved". In practice:188884e89it fails:1166 appears nowhere -- the re-takes quote a corpus that has moved again. The re-take says 1146, anchored at4f65684d.Mechanism
The figure lives in one generated, marked block inside the
4f65684dre-take:python3 scripts/ci/test_retaken_propositions_still_match.py --write(--anchor <rev>moves it). The hand copies of 1146 in the heading and prose are gone.RE-TAKEN ATheading and the re-take'stotalrow. Moving the anchor without re-takingt27c impl-statusis red.Who updates it: nobody, per spec PR. I chose the stated relation over "every spec PR regenerates a live count":
Controls, from output
CI-shaped run: in a fresh
git clone --depth 1 https://github.com/gHashTag/t27, the anchor was absent (Not a valid object name). The script fetched it in 9 s (.git60M to 62M), countedspecs at 4f65684dff: 1146, and returned rc=0.Siblings unchanged and passing locally:
check_untrusted_shell_interp,check_untrusted_javascript_interp,check_pr_branch_filters,test_catalog_table_matches_the_gate,test_status_tables_name_paths_that_exist.Not done here
test_catalog_table_matches_the_gate.pyhas the same substring shape (**{records}**anywhere in the doc). It is green today and only moves with the catalog, so it is not fixed here.spec-guards(ring-096 vsspecs/numeric/formats.t27) is a pre-existing red on master and is left alone.🤖 Generated with Claude Code