Skip to content

feat(fleet): enforce per-module required-minimum pin floors - #47

Merged
hseshadr merged 2 commits into
mainfrom
feat/fleet-minimum-pin
Sep 27, 2026
Merged

hseshadr merged 2 commits into
mainfrom
feat/fleet-minimum-pin

Conversation

@hseshadr

Copy link
Copy Markdown
Owner

Claim touched: every consumer runs a release gate at least as new as its last mandatory fix.

Why

Fleet policy checked that each central Dagger module pin was a well-formed exact SHA, but not that it was new enough. Consumers could stay pinned below a mandatory fix (dd19871, #46, the greenMain rerun created_at skew fix) without anyone noticing. That blocked aml-filter's release on 2026-09-24, and 7 more repos were later found below the fix.

What

  • REQUIRED_MINIMUM in .dagger/src/ci/fleet_policy.py maps each central module to a floor commit. It starts with portfolio-foundation -> dd19871486588b1582e432b7bc1f2cfffb296340. No other module gets a floor: cloudflare-pages and python-package load foundation from their own revision, so the foundation floor already covers their pins, and no other change on main is mandatory for every consumer.
  • The existing GitHub reader (github_fleet.read_source_evidence, the same path dagger call fleet uses) now compares every floored module revision in the resolved Dagger graph using compare/<floor>...<pin> and compare/<pin>...main on hseshadr/ci. A 404, meaning no common history, is recorded as unrelated. Any other non-200 response fails the scan.
  • Policy: both comparisons must return ahead or identical. Anything else, including missing evidence, produces pin-below-required-minimum, which fails the check.
  • Docs: docs/dagger-modules.md#required-minimum-pins covers the rule. When you ship a mandatory fix, raise the floor in the same PR.

Evidence

Check Result
RED (stubbed API, no logic) 9 failed / 224 passed: older pin, off-main ×3, missing evidence, repo-contract integration, 3 reader tests
GREEN 233 passed; uv run poe gate exit 0 (ruff, mypy strict, xenon A, cov 96%, branchrate)
Floor literal pinned test_should_floor_foundation_at_rerun_skew_fix_when_reviewed asserts {"portfolio-foundation": "dd19871486588b1582e432b7bc1f2cfffb296340"}
M1: invert the ancestor check (return not ...) 9 tests red, including test_should_reject_pin_when_older_than_floor
M2: treat behind as a descendant 2 red (the older-pin test and the repo-contract test)
M3: ignore pin...main 1 red (the off-main pin test)
M4: accept missing evidence (fail open) 1 red (the absent-evidence test)

Live read-only scan_fleet(include_central=True) run today, pin-below-required-minimum findings only:

Repo Pin Finding Open bump PR
almamesh cd28585 behind #165
assay 8d9e0c0 behind #73
edge-proc 95c7257 behind #75
edge-reco 068c3c0 behind #126
edgeproc-core 95c7257 behind #58
privacy-core 068c3c0 behind #47
aml-filter dd19871 none n/a
ci 9d49185 none n/a

agentic-saga and agentic-context-service are not in repository_expectations, so the fleet scan does not cover them yet. That gap predates this PR.

🤖 Generated with Claude Code

https://claude.ai/code/session_015oBArfm762nN1r4F4Fst5a

Consumers pin central Dagger modules at exact SHAs, and fleet policy
checked that each pin was well-formed but not that it was new enough.
Repos could stay pinned below a mandatory fix (dd19871, #46)
without anyone noticing, which blocked the aml-filter release.

REQUIRED_MINIMUM in fleet_policy.py holds a reviewed floor per central
module, starting with portfolio-foundation -> dd19871. The GitHub reader
compares every floored module revision in a consumer's resolved Dagger
graph against the floor (compare/<floor>...<pin>) and against central
main (compare/<pin>...main). Both must be ahead or identical. Otherwise,
including when there is no common history or the evidence is missing,
the scan reports pin-below-required-minimum and fails.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_015oBArfm762nN1r4F4Fst5a
hseshadr added a commit that referenced this pull request Sep 26, 2026
Brings in #47 -> #48 -> #50 -> #52 so this PR merges last without
conflicts. Their README lines move to the new layout: the consumer list
(now with agentic-context-service and agentic-saga), the uncovered-consumer
failure and the required-minimum pin floor go to docs/ARCHITECTURE.md
"What dagger call fleet checks", with plain one-line versions in the README
intro. Publisher lineage and the dagger-args-expression rule are noted there too.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_015oBArfm762nN1r4F4Fst5a
@hseshadr
hseshadr merged commit 14df981 into main Sep 27, 2026
3 checks passed
@hseshadr
hseshadr deleted the feat/fleet-minimum-pin branch September 27, 2026 21:59
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant