Skip to content

CI test integrity batch 181A: controls that can fail, RE-DERIVE escalation, cp1252 roots, tests mypy ratchet (BACKLOG #1971, #1842, #1866, #1030, #1799) - #1825

Merged
wshallwshall merged 43 commits into
mainfrom
batch/181a-ci-integrity
Oct 1, 2026
Merged

wshallwshall merged 43 commits into
mainfrom
batch/181a-ci-integrity

Conversation

@wshallwshall

Copy link
Copy Markdown
Collaborator

Batch 181 (ci-workflows), wave PR A. Five items, one merge commit each, built on origin/main 0f5ae18a8a. Batch head 51abf88624.

Landing order: this PR lands BEFORE batch 181 PR B. Branch b181-2093 conflicts with b181-1799 (in this PR) in tests/test_log_write_guard.py, so #2093 is held back and gets re-merged onto main once this PR lands.

Checks the Manager ran on the combined tree

  • ruff check . passed. ruff format --check . reported 1583 files already formatted.
  • mypy messagefoundry messagefoundry_webconsole --exclude messagefoundry/tray/: no issues, 322 files.
  • mypy --explicit-package-bases tests --platform linux: no issues, 1025 files.
  • python scripts/ci/mypy_ratchet_check.py: all 28 listed modules still report errors on linux and win32.
  • python scripts/hooks/ledger_check.py --ci: exit 0.
  • pytest -n 6 over all 163 changed test files: 4955 passed, 414 skipped (Postgres and SQL Server environment skips).
  • Not run locally: the full suite. The hosted legs are the reading.

BACKLOG #1971: the AD local-account conflict test can fail again

  • Source b181-1971 @ 3910a8b59f980602e6e1df13fab447aa4b597082
  • The test used to post an AD password login, which _dispatch_login refuses up front, so the conflict branch was never reached. It now drives POST /auth/negotiate (Windows SSO) into _complete_ad_login. It asserts:
    • a 401;
    • the directory was called;
    • exactly one auth.login_failed row with reason local_account_conflict;
    • no success row;
    • the local account unchanged.
  • Mutation. With the conflict branch disabled, the test fails on ['directory_identity_conflict'] == ['local_account_conflict']. The old test passed under the same mutation.
  • Checks: ruff, both mypy, tests/test_auth_hardening.py 29 passed, code-review at xhigh (one round).
  • Known, not fixed:
  • Proposed banner: SHIPPED -- the M4 conflict test drives Windows SSO into _complete_ad_login and pins the local_account_conflict audit row; red with the branch removed.

BACKLOG #1842 (option 2): RE-DERIVE escalates, and the web console rows re-derived a third time

  • Source b181-1842 @ 1b0e05ad408e0d4795987263977e0d8b77981ba8
  • Annotations. A success run over an uncensored baseline row now emits a GitHub ::warning annotation, and a summary banner, in two grades:
    • RE-DERIVE: the run is over the record, but the cap in force still holds.
    • RE-SIZE: the sizing rule gives a larger cap, or the gate reddened the run.
  • Exit code unchanged. It is still set by the margin alone, so a slightly-over run does not eject a pull request.
  • One copy of the sizing rule. SIZING_MULTIPLE, SIZING_FLOOR_MINUTES and sized_cap_minutes() now live only in step_margin.py.
  • Live control. self_check gained RE-DERIVE and RE-SIZE arms, each paired with a run under the record, and each pair must exit alike.
  • Re-measured caps. Pool: 782 ci.yml merge_group/pull_request runs, 2026-09-26T02:16Z to 2026-09-29T20:38Z.
    • Maxima: ubuntu 3:44, windows-2022 5:05, windows-2025 5:43.
    • Caps: 6 (was 5), 7 (was 6), 8 (unchanged).
  • Checks: ruff, both mypy, mypy --strict scripts/ci/step_margin.py, tests/test_ci_step_margin.py 53 passed, 387 across ci tests, code-review at xhigh (two rounds).
  • Unread leg: the first windows-2022 web console run after merge, to see the annotation render.
  • Known:
    • The lead time is set by the sizing rule, about 18 s above the windows-2022 row. The rot is tail variance, not suite growth, so a percentile-plus-pad rule is a filing candidate.
    • The ubuntu engine Tests (pytest) row is stale at 16:08, so engine runs will now draw RE-DERIVE, which is correct.
    • The workflow-command escaper is duplicated in three scripts.
  • Proposed banner: BUILT 2026-09-29 -- option 2 shipped: RE-DERIVE / RE-SIZE now raise a warning annotation and never red a leg; the web console rows re-derived to 3:44 / 5:05 / 5:43 and caps to 6 / 7 / 8. Open: the lead time is set by the sizing rule, a few percent.

BACKLOG #1866 (remainder 1): the connscale red was the stranding budget, pinned

  • Source b181-1866 @ 26736badf51a3119b71087ac3c7bb7d49b15eb52 (main merged in to clear an additive CHANGELOG conflict; the item commit is 963f6ed3c1)
  • The 2026-09-21 connscale red was the stranding budget, not a real intake shortfall.
    • Counters: 18 sent, 3 acked, 15 unconfirmed, backlog 0.
    • The per-message audit read missing_accepted=0.
  • Already answered by fix(webconsole): apply the api/validation.py rules to the console GET and control routes (BACKLOG #1740, Limb A) #1292 (PRs 1532 and 1537). 0 of 341 merge_group runs since have failed the test.
  • What this adds:
    • a regression pin, test_connscale_reconcile_the_2026_09_21_reds_were_the_stranding_budget;
    • two corrected comments ("clamped rather than zeroed" was false);
    • a CHANGELOG correction.
  • Loss construction. Dropping K accept-ACKed messages at ingress:
    • connscale smoke: K=0 green, K=1 red, K=3 red;
    • current load test: K=1 red;
    • pre-PR-1407 load test (arm 2): K=1 red.
  • Checks: ruff, both mypy, 17 plus 125 targeted tests passed, code-review at xhigh (two rounds).
  • Unread legs: test (windows-2025, py3.14), repo harness tests (windows-2025).
  • Still open, owner question: whether the intake floor that PR 1407 retired stays retired.
  • Proposed banner: PARTIAL -- remainder (1) answered by #1292, pinned here; arm 2 shown. Intake floor stays an owner question.

BACKLOG #1030 (remainder): the cp1252 gate covers every root holding Python

  • Source b181-1030 @ 624cf81d719d2d61e8dc69eedce064841eb6dc89
  • Seven more roots are gated: webconsole, packaging, samples, tee, fuzz, docker, docs.
    • fuzz/ was missing from the ledger's list.
    • A census test fails on any new root.
    • Each row pins a top-level file and a nested file.
    • Planting U+2192 into one real file per new root reddened all 7 rows.
  • One git-listed walk, _files_under, now serves every surface. The engine wrappers are folded into the parametrization.
  • argparse, pytest-reason and __doc__ text is gated: 18 planted shapes fire and 7 never-printed shapes do not.
  • Already done on main: AST hardening detection (Batch 184 engine wave: rule 3c stops reading quoted heredoc data bodies, and usage headroom names why a root reads UNKNOWN (BACKLOG #1072, #1459) #1875).
  • Checks: ruff, both mypy, tests/test_cp1252_console_safety.py 84 passed, code-review at xhigh (two rounds).
  • Still open:
    • the decode direction: 371 subprocess calls pass text=True with no encoding;
    • tee/ cannot call the shared console fix, so it needs its own vendored copy;
    • tee/__main__.py prints runtime values unhardened (review-reported).
  • Proposed banner: PARTIAL -- the reach gate walks every top-level directory holding Python with a census test; one git-listed walk; engine wrappers folded; argparse/pytest-reason/__doc__ text gated. Remains: the decode direction (371 subprocess text=True sites with no encoding, measured 2026-09-29), a tee/ remedy (vendor the chokepoint), and tee/__main__.py runtime prints.

BACKLOG #1799 (remainder): the tests mypy ratchet goes from 177 to 28, and a clean entry now fails CI

  • Source b181-1799 @ d19182cbaec61638edd98acaf8a317326666c83c
  • New dead-entry check. scripts/ci/mypy_ratchet_check.py runs as a new ci.yml step. It fails on any listed module that is already clean on linux and win32, and it refuses to pass on a flip that did not take.
  • 149 modules fixed off the list. Errors with the exemption off, same method before and after:
Platform Before After
linux 1559 568
win32 1551 569
  • Real test defects fixed, assertions unchanged:
    • test_mllp_tls started sources with a sync lambda handler;
    • fake sinks lacked enforced=;
    • fake stores lacked list_active_alert_instances;
    • a 2-tuple was seeded into a 3-tuple map;
    • several return and fixture annotations were wrong.
  • Found, not fixed: test_adr0157_demote_teardown::test_a_shutdown_teardown_calls_no_demotion_helper never drives _teardown_unsafe, so its named mutation would not fail it. A targeted ignore with a note keeps mypy's signal visible.
  • Checks: ruff, mypy engine and tests on linux and native, 159 changed modules 4708 passed, code-review at xhigh (one round).
  • Unread leg: the new ubuntu step "Type-check (mypy, tests ratchet has no dead entries)".
  • Open questions:
    1. The ratchet list is the union of the linux and win32 results (no module has that shape today).
    2. Three Windows-only test bodies are type-checked only natively.
    3. ConnScaleRecord ack_p*_ms=None against a float type in test_connscale_empty_claims_per_msg.
  • Proposed banner: PARTIAL -- a CI step now fails on a listed module that is already clean; the ignore_errors list is down from 177 to 28 modules (568 errors on linux, 569 on win32 with the exemption off).

Claims held by the Builders' worktrees (release after merge)

#1971, #1842, #1866, #1030, #1799.

wshallwshall added 30 commits September 29, 2026 15:41
…1030)

Brings messagefoundry_webconsole/, packaging/, samples/, tee/, fuzz/,
docker/ and docs/ into the reach gate as parametrized rows, and folds
the engine's three hand-written wrapper tests into the same rows.

fuzz/ was not named in the ledger's list of six; a tracked-file census
found it. All seven measured zero console-bound hits, so no source file
changes. A planted U+2192 in one real file per new root turned all
seven gate rows red, and a new per-root control plants the glyph in
each pinned file's real text to prove every zero is the detector
looking.

Each row now pins a top-level and a nested file wherever the root has
both shapes, and the coverage test checks that it does.
…#1799)

scripts/ci/mypy_ratchet_check.py re-runs mypy over the ignore_errors list with
the exemption flipped off, on linux and win32, and fails on a module clean on
both. A ci.yml step runs it after the tests mypy pass. tests/test_mypy_tests_scope.py
pins the step and plants a clean and a dirty module against the parser and
verdict. Live control: planting tests.test_mypy_tests_scope on the list made
the script exit 1 naming it.
Every surface in the cp1252 gate now walks `git ls-files` output
through one cached helper, `_files_under(root, suffix)`. The scripts
.py walk, the scripts .ps1 walk and the reach walk were three separate
rglob expressions. A filesystem walk also read untracked scratch and
build output, so two checkouts of one commit could disagree.

The full list is read once and filtered in Python, never through a
`<root>/**/*.py` pathspec, which drops top-level files. A git failure
raises rather than returning an empty list.

New census test: every top-level directory holding a tracked .py file
must be a reach row or scripts/. Removing the fuzz/ row makes it fire.
…it can fail (BACKLOG #1971)

test_ad_login_conflicting_with_local_account_is_rejected posted /auth/login
with provider="ad". Directory password sign-in is retired, so _dispatch_login
refused it before any directory work and the conflict branch in
_complete_ad_login was never reached.

The test now drives POST /auth/negotiate (Windows SSO), a live leg into
_complete_ad_login. It asserts the 401, that the directory was consulted,
exactly one auth.login_failed row with reason local_account_conflict, no
success row, and the local account unchanged. The dead provider parameter
on the _login helper is gone.

Mutation: with the conflict branch disabled the test goes red. A later
check still refuses as directory_identity_conflict, so only the audit
reason catches it. The old test stayed green under the same mutation.

Proposed PR title: test(auth): the AD local-account conflict test can fail again (BACKLOG #1971)
Proposed ledger banner: SHIPPED -- the M4 conflict test drives Windows SSO into _complete_ad_login and pins the local_account_conflict audit row; red with the branch removed.
Closes the first of #1030's two named detector gaps. The reach
detector saw only print, std-stream writes and loggers, so a
non-cp1252 character in argparse help=/description=/epilog= (printed
to stdout on --help) or a pytest skip/xfail reason (printed under -rs)
was invisible. PR 1403 had to fix one such site by hand.

Only the printed arguments are walked. A default=, choices= or a
skipif condition is compared or evaluated, never printed, and does not
fire. Measured over every reach root: zero hits, so this is a ratchet
at zero and changes no source file. Thirteen planted shapes must fire
and seven never-printed shapes must not.
…1799)

Each module is off the ignore_errors list and clean on linux and win32.
Real test defects mypy found:
- test_secret_rotation: the fake sink lacked the enforced= keyword the
  runner passes on the enforced path, so that path would raise TypeError.
- test_session_rotation_primitive: seeded a 2-tuple into a map whose
  entries are (count, first_seen, user_id).
- test_transform_concurrency: a wrapper annotated -> None returned the
  handoff's bool.
- test_uploads_cross_process_quota: key annotated bytes, passed a str.
- test_security_cli: patched json.loads through cli.json, an unexported
  name; it now patches the same module object directly.
…KLOG #1799)

Each module is off the ignore_errors list and clean on linux and win32.
Two Windows-only tests gain a platform skip mypy can read; the existing
skipif marks already skip them elsewhere. Fakes now subclass the connector
ABCs they stand in for, and unused or mis-coded ignores are gone.
…KLOG #1799)

Each module is off the ignore_errors list and clean on linux and win32.
Handlers registered on a Registry now take the Payload the registry
declares and narrow to Message, which the runner hands them by default.
Real test defect: test_pooled_rider's three fakes and test_pooled_runner's
collector overrode DestinationConnector.send without its metadata keyword.
Argparse arm: walk every argument of an argparse call. argparse prints
metavar=, version=, choices=, option strings, subcommand names and
positional group titles, which the keyword allow-list missed. A
`__doc__` in a console-bound argument now resolves to the module
docstring, because `description=__doc__` is how this tree spells it.

Pytest arm dropped. Pytest's TerminalWriter.write_raw catches
UnicodeEncodeError and writes the text unicode-escaped, so a reason
never aborts. A test re-derives that premise. The PR 1403 comment that
said it aborted carries a dated correction.

tee/ may not import the engine, so under the reach gate it accepts the
direct sys.stdout.reconfigure form. A test re-derives that tee imports
nothing from messagefoundry.

The walk now lists tracked plus untracked-not-ignored files, so a
Builder's unstaged new file is scanned. An unstaged glyph file under
fuzz/ turned the gate red. git failure or an empty listing fails with
git's stderr. The census derives gated roots from row paths, not
labels. Verdict kinds are a typed Literal. Stale comments fixed.
…KLOG #1799)

Each module is off the ignore_errors list and clean on linux and win32.
Also strips 188 type: ignore comments that mypy reports unused on both
platforms from modules still on the list, each where that was the line's
only error; comment-only, so no test behaviour changes.
Covers BACKLOG #1866, cited in the body because the claim gate holds
the subject to a claim this worktree does not hold (as PR 1407 did).

The connscale red was the stranding budget, not the exact shortfall.
15 of 18 unconfirmed is over max(12, 13), so the excusal clamps to 0.
The audit on run 35638437724 read missing_accepted=0.

Remainder (1) looks answered by BACKLOG #1292 (PRs 1532, 1537): 0 of
341 merge_group runs since 2026-09-25T19:17Z red this test. Reconcile
unchanged. Loss arms (not committed): K=0 green, K=1 and K=3 red.

PR title: test(harness): the connscale #1866 red was the stranding budget
Banner: PARTIAL -- remainder (1) answered by #1292, pinned here; arm 2
shown. Intake floor stays an owner question.
…KLOG #1799)

Each module is off the ignore_errors list and clean on linux and win32.
Also, in modules still listed: ConnectorType now comes from config.models
(wiring does not export it), and fake responses' __exit__ returns None.
test_anon_parity now hands the vendored tee copy its own DEFAULT_RULES
rather than the engine's, which is what a parity check should compare.
…KLOG #1842)

RE-DERIVE left the step log. A success run over an uncensored row now
raises a ::warning annotation, graded RE-DERIVE or RE-SIZE, with no
change to the exit code. The self-check gained two record arms.

Third re-derivation, 2026-09-29: rows 3:44 / 5:05 / 5:43 over
merge_group and pull_request runs to 2026-09-29T20:38Z. Caps move to
6 / 7 / 8 by ceil_minute(1.35x).

Proposed PR title: CI step margin: escalate a rotting record, and
re-derive the web console rows a third time (BACKLOG #1842)

Proposed banner: BUILT 2026-09-29 -- option 2 shipped: RE-DERIVE /
RE-SIZE now raise a warning annotation and never red a leg; the web
console rows re-derived to 3:44 / 5:05 / 5:43 and caps to 6 / 7 / 8.
Open: the lead time is set by the sizing rule, a few percent.
The tee/ second remedy is withdrawn. It accepted a stdout reconfigure
anywhere in a file, the position-free check the chokepoint rule exists
to refuse. tee/ stays gated with no remedy but ASCII until it vendors
the chokepoint. That is recorded as open.

Pytest reasons are an arm again. They are corrupted rather than
aborted, the same failure the gate already refuses on stderr. The
argparse arm skips default=, type=, nargs= and similar, which argparse
does not print, and walks dest=. main.__doc__ resolves, and a bare
__doc__ inside a class body no longer resolves to the module's.

The planted control now passes repo-relative paths and requires the
planted line among the hits. The census reads tracked files only and
names a repo-root .py plainly. scripts/ pins a top-level file. A git
binary missing from PATH fails with a message.

Proposed PR title: cp1252 gate covers every root holding Python,
walks git's file list, and sees argparse and pytest text (BACKLOG
#1030)

Proposed banner: PARTIAL. The reach gate now walks every top-level
directory holding Python (a census test fails on a new one), through
one git-listed walk. The engine wrappers are folded into the
parametrization, and argparse, pytest-reason and __doc__ text is
gated. Remaining: the DECODE direction, unbuilt (2026-09-29: 371
subprocess calls pass text=True with no encoding, 348 under tests/;
ruff PLW1514, preview-only, finds 4 file reads with no encoding); a
remedy for tee/ (vendor the chokepoint); and tee/__main__.py printing
runtime values unhardened.
…LOG #1799)

Each module is off the ignore_errors list and clean on linux and win32.
Also None-checks one-line reads of an Optional row across modules still
listed. Real test defects: test_tls_policy's yield fixture was annotated
as returning a tuple; test_alert_failover's fake store lacked a method
the sink's protocol requires; test_asvs_phase0 now builds a real
WebSocket over a hand-made scope instead of a namespace duck.
#1799)

Each module is off the ignore_errors list and clean on linux and win32.
A cursor row and a message dict no longer share one local name in the
None-checked reads. Real test defect: test_retry_cap_default annotated
the inbound connection its graph helper returns as object.
#1799)

Each module is off the ignore_errors list and clean on linux and win32.
test_store_once_deliver_many became clean from the None-checked reads
alone, the dead-entry case the new CI check exists to catch. Also
None-checks more Optional row reads in modules still listed.
…#1799)

Each module is off the ignore_errors list and clean on linux and win32.
The store, retention, staging and encryption suites now None-check their
Optional reads, and their fake coordinator and alert sink subclass the
real null implementations instead of standing in as partial ducks.
…#1799)

Each module is off the ignore_errors list and clean on linux and win32.
The ADR 0075 suites swap store.sqlserver's uuid4 through one harness helper
instead of assigning an unexported module name under ignores. Real test
defect: test_alert_state's fake store lacked a method the sink's store
protocol requires.
…#1799)

Each module is off the ignore_errors list and clean on linux and win32.
Fakes subclass the real connector and sink bases, helpers declare the
real return types, and raw SQL reads narrow the engine store to the SQLite
store they rely on. test_adr0075_batch_error_attribution imports its
harness package-qualified, so mypy sees it rather than Any.
…#1799)

Each module is off the ignore_errors list and clean on linux and win32.
Real test defect: test_mllp_tls started three MLLP sources with a plain
lambda as the inbound handler. MLLPSource awaits its handler, so the
first message any of them received would have raised TypeError; the
tests only probed the handshake, so none ever did. They now share an
async _ack_aa. test_log_write_guard's legacy-key refusals go through
model_validate, which is the typed way to hand pydantic unknown keys.
…#1799)

Each module is off the ignore_errors list and clean on linux and win32.
Real test defects: test_cert_expiry's fake sink lacked the enforced=
keyword the secret-rotation runner passes; test_fifo_index_migration's
helper was annotated list[str] but returns positions. Inputs outside a
declared Literal set, kept on purpose because the refusal is the subject,
carry a targeted ignore that says so.
… (BACKLOG #1799)

test_crl_held_copies borrows test_cert_expiry's _RecordingSink, which is
now a LoggingAlertSink, so its arg-type ignore became unused and the tests
mypy pass would have failed on it. Caught by a whole-directory run.
…#1799)

Each module is off the ignore_errors list and clean on linux and win32,
checked by a whole-directory run on both platforms. Module-global patches
(sys.platform, subprocess.run) now name the module they patch directly;
they were always patching that same global object.
…1799)

The dead-entry check flips only an ignore_errors line inside a mypy
override, so coverage.py's key of the same spelling cannot redden it; a
planted control pins that. Every ADR 0075 suite imports its harness
package-qualified. test_adr0157_demote_teardown keeps mypy's
comparison-overlap signal with a note: that guard never drives
_teardown_unsafe.

Proposed PR title: CI fails on a clean tests-ratchet entry; 149 test
modules type-fixed off it (BACKLOG #1799)
Proposed banner: PARTIAL -- a CI step now fails on a listed module that
is already clean; the ignore_errors list is down from 177 to 28 modules
(568 errors on linux, 569 on win32 with the exemption off).
One conflict, tests/test_security_cli.py: main patched json.loads through
cli_common.json after the CLI extraction; this branch patches the json
module directly, which is the same object and type-checks. Kept this
branch's side. Whole-directory mypy over tests is clean on linux and
win32 after the merge, and the dead-entry check passes.

Proposed PR title: CI fails on a clean tests-ratchet entry; 149 test
modules type-fixed off it (BACKLOG #1799)
Proposed banner: PARTIAL -- a CI step now fails on a listed module that
is already clean; the ignore_errors list is down from 177 to 28 modules
(568 errors on linux, 569 on win32 with the exemption off).
@wshallwshall

Copy link
Copy Markdown
Collaborator Author

QA: main merged in after PR 1828 landed. New head 40db5fc4c9, a fast-forward from 5267e98122 (merge 09ad8d77c9, review fixes 3bf18bb356 and 40db5fc4c9). Not enqueued.

Resolved as the Lander directed:

  • Step margin (ci.yml, step_margin_baseline.toml, test_ci_step_margin.py) against PR 1859: main's 2026-09-30 re-pool wins, with caps 6 / 8 / 8 and a windows-2022 kill of 11. The baseline file now matches main, apart from one note about the new annotation. This branch's 2026-09-29 "third re-derivation" note and its SUPERSEDED line are retired, so ci.yml carries one third note. The record_escalation annotation paragraphs stay, re-pointed at main's numbers.
  • test_cp1252_console_safety.py against PR 1828: this branch's deletion of the two engine-gate wrappers stands.
  • test_cluster_lease.py against PR 1876: its deletion of the two handicapped-sibling tests stands.
  • The BACKLOG Corepoint import: a MsgSend of a non-subject handle raises instead of sending msg (BACKLOG #313 step 1) #1866 entry moved from CHANGELOG.md to changelog.d/1866.fixed.md. CHANGELOG.md now matches main.

Also resolved:

  • test_db_lookup.py: main's login_timeout parameter, without the ignore this branch removed.
  • test_hl7_raw_separators.py: main dropped import hl7; this branch's typing.Any stays.
  • Two errors appeared under this branch's stricter mypy profile for tests: an unused ignore in PR 1876's fake lease DB (removed), and PR 1832's abstract loop stand-in in test_mllp_tls.py (now ignore[abstract]).

Checks:

  • The vacuous-absence lint over the whole tree, test_tooling_partition, the from-None lint and the name-run lint all pass. No new site needed a guard.
  • mypy --explicit-package-bases tests and mypy messagefoundry are clean, and mypy_ratchet_check.py passes.
  • ruff check and ruff format are clean over the repo.
  • changelog_fragments.py check passes.
  • pytest over this branch's test files, the conflicted files, PR 1876's two new cluster files, test_ci_step_margin and the named lints: 5661 passed, 414 skipped. The full suite was not run.

Review: code-review at xhigh, two rounds. It found no correctness bug in the resolution. The prose findings are fixed, except one: main's own "6:10 or longer" in the third re-derivation note. The true red line is 6:09.2, and that sentence is main's to fix.

Before flipping the #1842 ledger row: this PR's body and its proposed #1842 banner still say this PR re-derived the web console caps to 6 / 7 / 8 (rows 3:44 / 5:05 / 5:43). After this merge it re-derives nothing. The caps and rows are main's PR 1859 values: 6 / 8 / 8 over 4:15 / 5:40 / 5:43. What this PR adds for #1842 is the ::warning annotation from record_escalation. Correct the banner text before using it.

@wshallwshall
wshallwshall enabled auto-merge October 1, 2026 04:54
@wshallwshall
wshallwshall added this pull request to the merge queue Oct 1, 2026
@github-merge-queue
github-merge-queue Bot removed this pull request from the merge queue due to failed status checks Oct 1, 2026
@github-actions

github-actions Bot commented Oct 1, 2026

Copy link
Copy Markdown

CI failed in test (ubuntu-latest, py3.14) / Type-check (mypy, tests — linux platform) while this pull request was in the merge queue, so the queue ejected it.

Its own head can still be green: the queue revalidates the merge, and the path gates that skip on a pull request run there. Read the run before retrying.

https://github.com/MEFORORG/MessageFoundry/actions/runs/36819562275

@wshallwshall
wshallwshall added this pull request to the merge queue Oct 1, 2026
@github-actions

github-actions Bot commented Oct 1, 2026

Copy link
Copy Markdown

CI failed in test (ubuntu-latest, py3.14) / Type-check (mypy, tests — linux platform) while this pull request was in the merge queue, so the queue ejected it.

Its own head can still be green: the queue revalidates the merge, and the path gates that skip on a pull request run there. Read the run before retrying.

https://github.com/MEFORORG/MessageFoundry/actions/runs/36822096585

@github-merge-queue
github-merge-queue Bot removed this pull request from the merge queue due to failed status checks Oct 1, 2026
@wshallwshall
wshallwshall added this pull request to the merge queue Oct 1, 2026
@github-merge-queue
github-merge-queue Bot removed this pull request from the merge queue due to failed status checks Oct 1, 2026
@github-actions

github-actions Bot commented Oct 1, 2026

Copy link
Copy Markdown

CI failed in test (ubuntu-latest, py3.14) / Type-check (mypy, tests — linux platform) while this pull request was in the merge queue, so the queue ejected it.

Its own head can still be green: the queue revalidates the merge, and the path gates that skip on a pull request run there. Read the run before retrying.

https://github.com/MEFORORG/MessageFoundry/actions/runs/36826480887

@wshallwshall
wshallwshall added this pull request to the merge queue Oct 1, 2026
@github-merge-queue
github-merge-queue Bot removed this pull request from the merge queue due to failed status checks Oct 1, 2026
@github-actions

github-actions Bot commented Oct 1, 2026

Copy link
Copy Markdown

Security failed in semgrep (project SAST rules) / Run the MessageFoundry rules while this pull request was in the merge queue, so the queue ejected it.

Its own head can still be green: the queue revalidates the merge, and the path gates that skip on a pull request run there. Read the run before retrying.

https://github.com/MEFORORG/MessageFoundry/actions/runs/36832387843

@wshallwshall
wshallwshall added this pull request to the merge queue Oct 1, 2026
@github-merge-queue
github-merge-queue Bot removed this pull request from the merge queue due to failed status checks Oct 1, 2026
@wshallwshall
wshallwshall added this pull request to the merge queue Oct 1, 2026
@wshallwshall
wshallwshall removed this pull request from the merge queue due to a manual request Oct 1, 2026
wshallwshall added 2 commits October 1, 2026 03:21
No textual conflict. Semantic: PR 1843 added two functools.partial
calls in tests/test_docs_security_pathways.py that pass a SimpleNamespace
stand-in as AuthService's self. This branch's stricter tests mypy
profile covers that file, so "Type-check (mypy, tests)" failed in six
merge-group runs. Both calls now carry the per-argument
`# type: ignore[arg-type]` the file already uses for the same stand-in
on the same AuthService methods (the partial and calls in the sibling
helpers above). mypy over the whole tests tree is clean on win32 and
linux, and the ratchet check finds no dead entries.
…view)

Two comments said auth_provider is the one field _mfa_required_for reads off a user. It reads none (BACKLOG #1144). Comment only.
@wshallwshall

Copy link
Copy Markdown
Collaborator Author

QA: main merged at e47a879479. New head d9e053b9ac, a fast-forward from 40db5fc4c9 (merge a20973f830, comment fix d9e053b9ac). Not enqueued.

Fixed the cause of the six red merge-group runs. "Type-check (mypy, tests)" failed at tests/test_docs_security_pathways.py:2329 and :2331 [arg-type].

  • PR 1843 added two functools.partial calls that pass a SimpleNamespace stand-in as AuthService's self. This branch's stricter tests mypy profile covers that file.
  • Each call now carries the per-argument # type: ignore[arg-type] the file already uses for the same stand-in on the same methods (the owes helper, around lines 1924-1933). The file has no cast.
  • Review found that types.MethodType would type-check with no ignore. It is only worth switching if every helper switches together.

Comment fix (branch side). Two comments said auth_provider is the one field _mfa_required_for reads off a user. It reads none (BACKLOG #1144). Both now say the user is a placeholder.

Checks:

  • mypy --explicit-package-bases tests over the whole tree: clean on win32 and --platform linux, 1053 files. mypy messagefoundry clean.
  • mypy_ratchet_check.py: all 28 listed modules still report errors, so no dead entries.
  • The vacuous-absence lint over the whole tree passes, as do tooling-partition, the from-None and name-run lints, mypy-scope and changelog-fragment tests.
  • ruff is clean over the repo. pytest over main's newly changed test files plus cp1252 and step-margin: 781 passed, 89 skipped.

Review: code-review at xhigh, one round. No correctness bug in the merge's lines. Its notes on this branch's other content, left as they are:

  • The helper near line 1387 now asserts isinstance(..., int) instead of coercing with int().
  • Three helpers build the AuthService stand-in by hand.
  • Structural: main keeps adding code to modules that main's ratchet still exempts and this branch takes off it. Each such addition passes on main and goes red only at merge, until this PR lands.

@wshallwshall
wshallwshall enabled auto-merge October 1, 2026 08:29
@github-actions

github-actions Bot commented Oct 1, 2026

Copy link
Copy Markdown

CI failed in test (ubuntu-latest, py3.14) / Type-check (mypy, tests — linux platform) while this pull request was in the merge queue, so the queue ejected it.

Its own head can still be green: the queue revalidates the merge, and the path gates that skip on a pull request run there. Read the run before retrying.

https://github.com/MEFORORG/MessageFoundry/actions/runs/36835249856

@wshallwshall
wshallwshall added this pull request to the merge queue Oct 1, 2026
@github-merge-queue
github-merge-queue Bot removed this pull request from the merge queue due to failed status checks Oct 1, 2026
@github-actions

github-actions Bot commented Oct 1, 2026

Copy link
Copy Markdown

CI failed in test (windows-2022, py3.14) / Tests (pytest) while this pull request was in the merge queue, so the queue ejected it.

Its own head can still be green: the queue revalidates the merge, and the path gates that skip on a pull request run there. Read the run before retrying.

https://github.com/MEFORORG/MessageFoundry/actions/runs/36840329310

@wshallwshall
wshallwshall added this pull request to the merge queue Oct 1, 2026
Merged via the queue into main with commit 8a72702 Oct 1, 2026
49 of 51 checks passed
@wshallwshall
wshallwshall deleted the batch/181a-ci-integrity branch October 1, 2026 10:32
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

ci-red A required check went red. Attribute it before retrying. qa Builder QA record posted; not a merge gate

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant