feat(fleet): enforce per-module required-minimum pin floors - #47
Merged
Merged
Conversation
Consumers pin central Dagger modules at exact SHAs, and fleet policy checked that each pin was well-formed but not that it was new enough. Repos could stay pinned below a mandatory fix (dd19871, #46) without anyone noticing, which blocked the aml-filter release. REQUIRED_MINIMUM in fleet_policy.py holds a reviewed floor per central module, starting with portfolio-foundation -> dd19871. The GitHub reader compares every floored module revision in a consumer's resolved Dagger graph against the floor (compare/<floor>...<pin>) and against central main (compare/<pin>...main). Both must be ahead or identical. Otherwise, including when there is no common history or the evidence is missing, the scan reports pin-below-required-minimum and fails. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_015oBArfm762nN1r4F4Fst5a
This was referenced Sep 25, 2026
hseshadr
added a commit
that referenced
this pull request
Sep 26, 2026
Brings in #47 -> #48 -> #50 -> #52 so this PR merges last without conflicts. Their README lines move to the new layout: the consumer list (now with agentic-context-service and agentic-saga), the uncovered-consumer failure and the required-minimum pin floor go to docs/ARCHITECTURE.md "What dagger call fleet checks", with plain one-line versions in the README intro. Publisher lineage and the dagger-args-expression rule are noted there too. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_015oBArfm762nN1r4F4Fst5a
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Claim touched: every consumer runs a release gate at least as new as its last mandatory fix.
Why
Fleet policy checked that each central Dagger module pin was a well-formed exact SHA, but not that it was new enough. Consumers could stay pinned below a mandatory fix (dd19871, #46, the
greenMainreruncreated_atskew fix) without anyone noticing. That blocked aml-filter's release on 2026-09-24, and 7 more repos were later found below the fix.What
REQUIRED_MINIMUMin.dagger/src/ci/fleet_policy.pymaps each central module to a floor commit. It starts withportfolio-foundation -> dd19871486588b1582e432b7bc1f2cfffb296340. No other module gets a floor:cloudflare-pagesandpython-packageload foundation from their own revision, so the foundation floor already covers their pins, and no other change on main is mandatory for every consumer.github_fleet.read_source_evidence, the same pathdagger call fleetuses) now compares every floored module revision in the resolved Dagger graph usingcompare/<floor>...<pin>andcompare/<pin>...mainon hseshadr/ci. A 404, meaning no common history, is recorded asunrelated. Any other non-200 response fails the scan.aheadoridentical. Anything else, including missing evidence, producespin-below-required-minimum, which fails the check.docs/dagger-modules.md#required-minimum-pinscovers the rule. When you ship a mandatory fix, raise the floor in the same PR.Evidence
uv run poe gateexit 0 (ruff, mypy strict, xenon A, cov 96%, branchrate)test_should_floor_foundation_at_rerun_skew_fix_when_reviewedasserts{"portfolio-foundation": "dd19871486588b1582e432b7bc1f2cfffb296340"}return not ...)test_should_reject_pin_when_older_than_floorbehindas a descendantpin...mainLive read-only
scan_fleet(include_central=True)run today,pin-below-required-minimumfindings only:agentic-saga and agentic-context-service are not in
repository_expectations, so the fleet scan does not cover them yet. That gap predates this PR.🤖 Generated with Claude Code
https://claude.ai/code/session_015oBArfm762nN1r4F4Fst5a