Commit 0392152
fix: aletheia has not compiled since June — repair it, then gate it (#123)
## Summary
A sitrep on this repo turned up something bigger than the CI gap it
started as:
**`aletheia` has not compiled since 2026-06-17.** This branch fixes
that, then adds the
gate that would have caught it, and clears two unrelated reds.
| # | Finding | State |
|---|---|---|
| 1 | `aletheia` fails to build — unclosed delimiter in `src/config.rs`
| **fixed & verified** |
| 2 | `aletheia` has no CI anywhere; its 16 workflows are inert | **root
gate added** |
| 3 | Governance red — `pages.yml` missing SPDX header | **fixed** |
| 4 | `absolute-zero` pinned to a nonexistent commit; Dependabot dead |
**re-pinned — needs your confirmation** |
## 1. The compile break
`Config::load_config` opened three blocks on one collapsed line and
closed two.
Introduced by `b5322c2` *"security: remediate Track C and Track E
findings"* — which
correctly added a 1 MiB read cap against memory exhaustion, then dropped
a brace
collapsing the block. **`main` has been unbuildable for over a month.**
The security intent is preserved exactly; the cap is retained and now
commented.
## 2. Why nothing noticed
`aletheia/` is vendored as **plain tracked files (mode 100644), not a
submodule**.
Actions only reads `.github/workflows/` at the *repository root*, so all
16 files under
`aletheia/.github/workflows/` — `rust-ci`, `codeql`, `cflite_*`, SLSA3,
GHCR — have
**never executed**. There is no standalone `hyperpolymath/aletheia`
running them either;
it was removed from GitHub in early 2026. No root workflow mentioned
cargo, and root
`codeql.yml`'s language matrix excludes Rust. ~962 lines were completely
ungated.
Adds root `.github/workflows/rust-ci.yml`: debug + release build, 26
unit tests,
`cargo fmt --check`, and a zero-dependency check enforcing the RSR
Bronze constraint
from `aletheia/CLAUDE.md`. It uses the runner's preinstalled Rust — **no
new
third-party action**, no added supply-chain surface.
Also adds `aletheia/.github/workflows/README.md` so nobody edits an
inert workflow again.
### What I deliberately did *not* gate
Two things are genuinely red, and a hollow green job is worse than no
job. Neither is
masked with `continue-on-error`; both are documented in the workflow
header:
- **Integration tests: 27 of 29 fail.** They exercise a CLI surface —
`--help`,
`--version`, `--format=`, `--badge`, `--html`, `--init-hook` — that
`src/main.rs`
does not implement. It parses only `--json` and `--sarif`.
- **`clippy -D warnings`: 25 findings**, mostly dead code.
These share one root cause: the crate was split into 5 modules (962
lines) but
`main.rs` is only 117 lines and never wires most of them up.
`glob_match`,
`check_path_security`, `parse_toml`, `TomlValue`, `PathCheckResult` are
all unreachable.
**aletheia is mid-refactor and incomplete** — its 823-line test suite is
closer to a
specification of the intended tool than a description of the current
one.
That is a product decision, not a CI fix, so I have left it to you.
## 4. Submodule re-pin — please confirm
`ad085baa` **does not exist** upstream (API 422), nor on the GitLab or
Codeberg mirrors;
orphaned by a force-push during the Ddraig rollout. Dependabot has
failed since
2026-07-20 with `upload-pack: not our ref`.
Re-pinned to current upstream main `87902bb7`. **This is a semantic
bump, not a
restore** — the old pin's content is unrecoverable, so I cannot verify
`87902bb7` is the
intended CNO state.
It may also not be durable: this repo has already oscillated three times
(#89 → `bef4c92`
→ #117). Worth settling submodule-vs-vendor, or barring force-push on
`absolute-zero`.
## Verification
All run locally from a clean target dir before pushing:
```
build: PASS release: PASS
tests: 26 passed; 0 failed
fmt: PASS zero-dep: PASS
git submodule update --init absolute-zero -> checks out 87902bb7 cleanly
```
## Notes
- `PROOF-NEEDS.md` is **stale**: it claims one `Admitted` in
`y_not_cno`. There are
zero — it is a documented *KEPT AXIOM*. A declared trust assumption, not
an unproven
hole. Worth correcting separately.
- `rustfmt.toml` sets 18 nightly-only options that stable rustfmt
silently ignores.
- `aletheia/Cargo.toml` still points `repository` at the deleted GitHub
repo.
- Untouched: the uncommitted SonarCloud edits in the working copy
(unpinned `@master`),
and the 4 unpushed local commits. Both are yours to decide.
🤖 Generated with [Claude Code](https://claude.com/claude-code)
---------
Co-authored-by: Claude Opus 4.8 <noreply@anthropic.com>1 parent ba29a18 commit 0392152
11 files changed
Lines changed: 239 additions & 63 deletions
File tree
- .github/workflows
- aletheia
- .github/workflows
- benches
- src
- tests
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
| 1 | + | |
| 2 | + | |
| 3 | + | |
| 4 | + | |
1 | 5 | | |
2 | 6 | | |
3 | 7 | | |
| |||
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
| 1 | + | |
| 2 | + | |
| 3 | + | |
| 4 | + | |
| 5 | + | |
| 6 | + | |
| 7 | + | |
| 8 | + | |
| 9 | + | |
| 10 | + | |
| 11 | + | |
| 12 | + | |
| 13 | + | |
| 14 | + | |
| 15 | + | |
| 16 | + | |
| 17 | + | |
| 18 | + | |
| 19 | + | |
| 20 | + | |
| 21 | + | |
| 22 | + | |
| 23 | + | |
| 24 | + | |
| 25 | + | |
| 26 | + | |
| 27 | + | |
| 28 | + | |
| 29 | + | |
| 30 | + | |
| 31 | + | |
| 32 | + | |
| 33 | + | |
| 34 | + | |
| 35 | + | |
| 36 | + | |
| 37 | + | |
| 38 | + | |
| 39 | + | |
| 40 | + | |
| 41 | + | |
| 42 | + | |
| 43 | + | |
| 44 | + | |
| 45 | + | |
| 46 | + | |
| 47 | + | |
| 48 | + | |
| 49 | + | |
| 50 | + | |
| 51 | + | |
| 52 | + | |
| 53 | + | |
| 54 | + | |
| 55 | + | |
| 56 | + | |
| 57 | + | |
| 58 | + | |
| 59 | + | |
| 60 | + | |
| 61 | + | |
| 62 | + | |
| 63 | + | |
| 64 | + | |
| 65 | + | |
| 66 | + | |
| 67 | + | |
| 68 | + | |
| 69 | + | |
| 70 | + | |
| 71 | + | |
| 72 | + | |
| 73 | + | |
| 74 | + | |
| 75 | + | |
| 76 | + | |
| 77 | + | |
| 78 | + | |
| 79 | + | |
| 80 | + | |
| 81 | + | |
| 82 | + | |
| 83 | + | |
| 84 | + | |
| 85 | + | |
| 86 | + | |
| 87 | + | |
| 88 | + | |
| 89 | + | |
| 90 | + | |
| 91 | + | |
| 92 | + | |
| 93 | + | |
| 94 | + | |
| 95 | + | |
| 96 | + | |
| 97 | + | |
| 98 | + | |
| 99 | + | |
| 100 | + | |
| 101 | + | |
| 102 | + | |
| 103 | + | |
| 104 | + | |
Submodule absolute-zero updated from ad085ba to 87902bb
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
| 1 | + | |
| 2 | + | |
| 3 | + | |
| 4 | + | |
| 5 | + | |
| 6 | + | |
| 7 | + | |
| 8 | + | |
| 9 | + | |
| 10 | + | |
| 11 | + | |
| 12 | + | |
| 13 | + | |
| 14 | + | |
| 15 | + | |
| 16 | + | |
| 17 | + | |
| 18 | + | |
| 19 | + | |
| 20 | + | |
| 21 | + | |
| 22 | + | |
| 23 | + | |
| 24 | + | |
| 25 | + | |
| 26 | + | |
| 27 | + | |
| 28 | + | |
| 29 | + | |
| 30 | + | |
| 31 | + | |
| 32 | + | |
| 33 | + | |
| 34 | + | |
| 35 | + | |
| 36 | + | |
| 37 | + | |
| 38 | + | |
| 39 | + | |
| 40 | + | |
| 41 | + | |
| 42 | + | |
| 43 | + | |
| 44 | + | |
| 45 | + | |
| 46 | + | |
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
238 | 238 | | |
239 | 239 | | |
240 | 240 | | |
241 | | - | |
| 241 | + | |
| 242 | + | |
| 243 | + | |
| 244 | + | |
242 | 245 | | |
243 | 246 | | |
244 | 247 | | |
| |||
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
2 | 2 | | |
3 | 3 | | |
4 | 4 | | |
5 | | - | |
6 | | - | |
| 5 | + | |
| 6 | + | |
7 | 7 | | |
8 | 8 | | |
9 | 9 | | |
| |||
20 | 20 | | |
21 | 21 | | |
22 | 22 | | |
23 | | - | |
| 23 | + | |
24 | 24 | | |
25 | 25 | | |
26 | 26 | | |
| |||
29 | 29 | | |
30 | 30 | | |
31 | 31 | | |
32 | | - | |
| 32 | + | |
| 33 | + | |
| 34 | + | |
| 35 | + | |
33 | 36 | | |
34 | 37 | | |
35 | 38 | | |
36 | 39 | | |
37 | 40 | | |
38 | | - | |
| 41 | + | |
| 42 | + | |
| 43 | + | |
| 44 | + | |
| 45 | + | |
| 46 | + | |
| 47 | + | |
39 | 48 | | |
40 | 49 | | |
41 | 50 | | |
42 | | - | |
43 | | - | |
44 | | - | |
| 51 | + | |
| 52 | + | |
| 53 | + | |
| 54 | + | |
| 55 | + | |
| 56 | + | |
| 57 | + | |
| 58 | + | |
| 59 | + | |
| 60 | + | |
| 61 | + | |
45 | 62 | | |
46 | 63 | | |
47 | 64 | | |
| |||
85 | 102 | | |
86 | 103 | | |
87 | 104 | | |
88 | | - | |
89 | | - | |
90 | | - | |
91 | | - | |
92 | | - | |
| 105 | + | |
| 106 | + | |
93 | 107 | | |
94 | 108 | | |
95 | 109 | | |
| |||
121 | 135 | | |
122 | 136 | | |
123 | 137 | | |
124 | | - | |
| 138 | + | |
| 139 | + | |
| 140 | + | |
| 141 | + | |
125 | 142 | | |
126 | 143 | | |
127 | 144 | | |
| |||
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
73 | 73 | | |
74 | 74 | | |
75 | 75 | | |
76 | | - | |
77 | | - | |
| 76 | + | |
| 77 | + | |
| 78 | + | |
| 79 | + | |
| 80 | + | |
| 81 | + | |
| 82 | + | |
78 | 83 | | |
79 | 84 | | |
80 | 85 | | |
| |||
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
2 | 2 | | |
3 | 3 | | |
4 | 4 | | |
5 | | - | |
6 | | - | |
7 | | - | |
| 5 | + | |
| 6 | + | |
| 7 | + | |
8 | 8 | | |
9 | 9 | | |
10 | 10 | | |
| |||
70 | 70 | | |
71 | 71 | | |
72 | 72 | | |
73 | | - | |
| 73 | + | |
74 | 74 | | |
75 | 75 | | |
76 | 76 | | |
| |||
93 | 93 | | |
94 | 94 | | |
95 | 95 | | |
96 | | - | |
| 96 | + | |
| 97 | + | |
| 98 | + | |
| 99 | + | |
| 100 | + | |
97 | 101 | | |
98 | 102 | | |
99 | 103 | | |
| |||
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
2 | 2 | | |
3 | 3 | | |
4 | 4 | | |
5 | | - | |
6 | | - | |
| 5 | + | |
| 6 | + | |
7 | 7 | | |
8 | 8 | | |
9 | | - | |
10 | | - | |
| 9 | + | |
| 10 | + | |
11 | 11 | | |
12 | 12 | | |
13 | | - | |
14 | 13 | | |
| 14 | + | |
15 | 15 | | |
16 | 16 | | |
17 | 17 | | |
18 | 18 | | |
19 | 19 | | |
20 | 20 | | |
21 | | - | |
| 21 | + | |
22 | 22 | | |
23 | | - | |
| 23 | + | |
24 | 24 | | |
25 | 25 | | |
26 | 26 | | |
| |||
40 | 40 | | |
41 | 41 | | |
42 | 42 | | |
43 | | - | |
| 43 | + | |
44 | 44 | | |
45 | 45 | | |
46 | 46 | | |
| |||
137 | 137 | | |
138 | 138 | | |
139 | 139 | | |
140 | | - | |
141 | | - | |
| 140 | + | |
| 141 | + | |
| 142 | + | |
| 143 | + | |
| 144 | + | |
| 145 | + | |
| 146 | + | |
| 147 | + | |
142 | 148 | | |
143 | 149 | | |
144 | 150 | | |
145 | 151 | | |
146 | 152 | | |
147 | 153 | | |
148 | 154 | | |
149 | | - | |
| 155 | + | |
| 156 | + | |
| 157 | + | |
| 158 | + | |
150 | 159 | | |
151 | 160 | | |
152 | 161 | | |
| |||
0 commit comments