diff --git a/.github/workflows/ci.yml b/.github/workflows/ci.yml index d9e2318..7e0eb16 100644 --- a/.github/workflows/ci.yml +++ b/.github/workflows/ci.yml @@ -11,7 +11,7 @@ jobs: permissions: contents: read actions: read - uses: CodeRoasted/malf-toolchain/.github/workflows/coderoast-ci.yml@b5e15eee5e2cc9a2709309850f845b28ba8d9e58 + uses: CodeRoasted/malf-toolchain/.github/workflows/coderoast-ci.yml@da2abf639f64e1c1bca382aa7a973e9cc2f00412 with: # metalog vendors insight_canon from its PUBLIC release, then builds the single root package # (test=true runs the full gtest suite; create=true verifies packaging + test_package). @@ -38,7 +38,7 @@ jobs: permissions: pull-requests: write actions: read - uses: CodeRoasted/malf-toolchain/.github/workflows/coderoast-sift-post.yml@b5e15eee5e2cc9a2709309850f845b28ba8d9e58 + uses: CodeRoasted/malf-toolchain/.github/workflows/coderoast-sift-post.yml@da2abf639f64e1c1bca382aa7a973e9cc2f00412 with: run-id: ${{ github.run_id }} secrets: inherit diff --git a/.github/workflows/golden.yaml b/.github/workflows/golden.yaml index 4d669b0..390699c 100644 --- a/.github/workflows/golden.yaml +++ b/.github/workflows/golden.yaml @@ -135,7 +135,7 @@ jobs: uses: actions/checkout@v5 with: repository: CodeRoasted/malf-toolchain - ref: b5e15eee5e2cc9a2709309850f845b28ba8d9e58 + ref: da2abf639f64e1c1bca382aa7a973e9cc2f00412 path: malf fetch-depth: 1 persist-credentials: false @@ -151,11 +151,11 @@ jobs: - name: Provision gcc-16.2 toolchain (OUR OWN published asset; arm64 auto-picked by uname -m) if: matrix.leg == 'gcc' - uses: CodeRoasted/malf-toolchain/.github/actions/setup-gcc@b5e15eee5e2cc9a2709309850f845b28ba8d9e58 + uses: CodeRoasted/malf-toolchain/.github/actions/setup-gcc@da2abf639f64e1c1bca382aa7a973e9cc2f00412 - name: Provision clang-21 + libc++-21 if: matrix.leg == 'clang' - uses: CodeRoasted/malf-toolchain/.github/actions/setup-clang21-libcxx@b5e15eee5e2cc9a2709309850f845b28ba8d9e58 + uses: CodeRoasted/malf-toolchain/.github/actions/setup-clang21-libcxx@da2abf639f64e1c1bca382aa7a973e9cc2f00412 - name: Base — ninja + CMake 4.3.x (+ gcc-16.2 /opt wiring on the gcc leg) run: | @@ -264,7 +264,7 @@ jobs: uses: actions/checkout@v5 with: repository: CodeRoasted/malf-toolchain - ref: b5e15eee5e2cc9a2709309850f845b28ba8d9e58 + ref: da2abf639f64e1c1bca382aa7a973e9cc2f00412 path: malf fetch-depth: 1 persist-credentials: false @@ -278,7 +278,7 @@ jobs: persist-credentials: false - name: Install + activate MSVC 14.52 (the C++23-modules fix floor; not pre-installed) - uses: CodeRoasted/malf-toolchain/.github/actions/setup-msvc1452@b5e15eee5e2cc9a2709309850f845b28ba8d9e58 + uses: CodeRoasted/malf-toolchain/.github/actions/setup-msvc1452@da2abf639f64e1c1bca382aa7a973e9cc2f00412 - name: Verify the active toolset is MSVC 14.52, not a fallback shell: pwsh @@ -475,7 +475,7 @@ jobs: pattern: golden-digest-* - name: Compare + validate the golden (all 5 legs must be byte-identical) - uses: CodeRoasted/malf-toolchain/.github/actions/coderoast-golden-compare@b5e15eee5e2cc9a2709309850f845b28ba8d9e58 + uses: CodeRoasted/malf-toolchain/.github/actions/coderoast-golden-compare@da2abf639f64e1c1bca382aa7a973e9cc2f00412 with: digests-dir: digests min-legs: '5' diff --git a/.github/workflows/lint.yml b/.github/workflows/lint.yml index 2d43d6d..cd6c45b 100644 --- a/.github/workflows/lint.yml +++ b/.github/workflows/lint.yml @@ -8,10 +8,11 @@ on: jobs: lint: - uses: CodeRoasted/malf-toolchain/.github/workflows/coderoast-lint.yml@b5e15eee5e2cc9a2709309850f845b28ba8d9e58 + uses: CodeRoasted/malf-toolchain/.github/workflows/coderoast-lint.yml@da2abf639f64e1c1bca382aa7a973e9cc2f00412 # PUBLIC repo: no runs-on passthrough and no checkout token — a fork PR runs this job. with: # clang-tidy runs (the default), over a clang-21 source build of this repo's whole first-party # closure. These are the repos that closure reaches, held to packages.yml by the superproject's - # pin_coherence.py INV-13. A private one would fail its clone loudly, never be skipped. + # pin_coherence check module's INV-13. A private one would fail its clone loudly, never be + # skipped. lint-siblings: insight-canon diff --git a/.github/workflows/release.yaml b/.github/workflows/release.yaml index 580854f..9e98bdd 100644 --- a/.github/workflows/release.yaml +++ b/.github/workflows/release.yaml @@ -38,7 +38,7 @@ jobs: release: needs: golden - uses: CodeRoasted/malf-toolchain/.github/workflows/coderoast-release.yml@b5e15eee5e2cc9a2709309850f845b28ba8d9e58 + uses: CodeRoasted/malf-toolchain/.github/workflows/coderoast-release.yml@da2abf639f64e1c1bca382aa7a973e9cc2f00412 with: tag: ${{ github.event.inputs.tag || github.ref_name }} packages: 'insight_metalog:.' diff --git a/technical_docs/operations/ccc_migration.md b/technical_docs/operations/ccc_migration.md index c3d151a..aa71f78 100644 --- a/technical_docs/operations/ccc_migration.md +++ b/technical_docs/operations/ccc_migration.md @@ -505,7 +505,7 @@ wrote was found INCOMPLETE and repaired before the commit.** | Q | unit | verdict | what the agent found | |---|---|---|---| -| Q1 | 5 | recovered, high — **and it found an enforcement this lane had not** | the rule is mechanically gated by `scripts/json_write_closure_lint.py`, run in `lint.yml`'s `pin-coherence` job, with every list derived rather than hand-kept and an exit 2 on an empty derivation. Two limits it read off the tree: the gate proves LOCATION only, and `lint.yml` has no `push:` trigger, so it fires on pull request, dispatch and the release tag, never on a main push | +| Q1 | 5 | recovered, high — **and it found an enforcement this lane had not** | the rule is mechanically gated by the `json_write_closure` check module (`scripts/json_write_closure_lint.py` then), run in `lint.yml`'s `pin-coherence` job, with every list derived rather than hand-kept and an exit 2 on an empty derivation. Two limits it read off the tree: the gate proves LOCATION only, and `lint.yml` has no `push:` trigger, so it fires on pull request, dispatch and the release tag, never on a main push | | Q2 | 5 | recovered, high | `DN-65.O4` in full: the opts-spelling rule was written first and falsified the same day — 5 true positives, 9 false positives, 2 false negatives as a grep, and it missed the live defect | | Q3 | 5 | recovered, high | `opt_true` assigns the member when the caller's type carries it and derives a new type when it does not, so `prettify`/`skip_null_members` survive and no caller can spell the escape false. It added a "cannot" specific to this file: metalog's wrapper exposes only `to_string`, with no `write(value, buffer)` overload, so a metalog caller cannot recover Glaze's error context — sift's twin offers both | | Q4 | 5 | recovered, high | the 5/27 split with a third, independent source this lane had not used: a measurement recorded in the release history that reverted this very wrapper to a raw `glz::write`, rebuilt, and redded on 27 of 32 C0 bytes with the survivors *"exactly `0x08 0x09 0x0a 0x0c 0x0d`"*. It also bounded the claim: nothing in the tree covers bytes at or above 0x20 | @@ -1244,8 +1244,8 @@ one questionnaire over 200 blocks is two interrogations pretending to be one. **Census (`OPS-8.S4`), derived rather than taken from the written list.** The gates that read a comment token in this repo were enumerated first: `malf/comment_contract_lint.py` (the CCC tool forms), clang-tidy (`NOLINT` in all spellings, `/*name*/`, `/*name=*/`), clang-format -(`clang-format off`/`on`, the namespace closer), `scripts/wallclock_lint.py` and -`scripts/random_determinism_lint.py` (`DETERMINISM-ALLOW`), `scripts/log_seat_routing_lint.py` +(`clang-format off`/`on`, the namespace closer), the `wallclock` and +`random_determinism` check modules (`DETERMINISM-ALLOW`), the `log_seat_routing` check module (`LOG-SEAT-ALLOW`), `scripts/retired_structure_lint.py` (its `allow` marker, whose regex does not require an HTML comment and can therefore sit in C++), plus `wall-clock:` and `SPDX-License-Identifier:`. Two scope facts fell out of that walk and are recorded because they diff --git a/tests/reservoir/test_reservoir.cpp b/tests/reservoir/test_reservoir.cpp index 4dac828..ccd1599 100644 --- a/tests/reservoir/test_reservoir.cpp +++ b/tests/reservoir/test_reservoir.cpp @@ -89,7 +89,7 @@ TEST(ReservoirTest, RareErrorNotRetainedWithoutReservoir) EXPECT_FALSE(top_k_has(doc, "connection refused to db")) << "the rare error is below top_k by frequency (one occurrence vs the steady benign 100s)"; EXPECT_FALSE(reservoir_has(doc, "connection refused to db")) - << "with the reservoir off the rare severe event is tail dust — retained nowhere (the F1 " + << "with the reservoir off the rare severe event is tail dust — retained nowhere (the FLAW-1 " "recall=0 baseline the salience reservoir flips to 1)"; }