Skip to content

docs(upstream): add a CI-checkable drift detector for CONFLICT_HOTSPOTS.md - #106

Open
hanthor-hive-agent[bot] wants to merge 1 commit into
ptyxis-portfrom
arch/refactor-conflict-hotspots-check
Open

hanthor-hive-agent[bot] wants to merge 1 commit into
ptyxis-portfrom
arch/refactor-conflict-hotspots-check

Conversation

@hanthor-hive-agent

Copy link
Copy Markdown
Contributor

Refactor

Issue #55 asks for the check that would keep CONFLICT_HOTSPOTS.md honest automatically — the map is UPSTREAM_SYNC.md's pillar 2, and nothing verified it against the branch's actual diff. PR #60 corrected the drift it found manually, and its own description says explicitly: "this PR corrects today's drift; it does not prevent tomorrow's, and should not close the issue." This adds the check.

scripts/check-conflict-hotspots.sh computes the upstream files the fork has modified since its base commit — found by the first commit matching ^ptyxis-port: rather than a hardcoded SHA, so a future rebase (which rewrites every commit upstream of the fork's own history) doesn't silently stale the reference point — restricted to the map's own declared scope (src/** plus .gitignore, per CONFLICT_HOTSPOTS.md's "Scope" note; .github/workflows/** and root docs are out of scope pending #55's own open scoping question). It diffs that set against what the map's section headers actually list, in both directions: a modified file with no entry, and an entry for a file no longer modified.

Running it today found the map had drifted again since #60, three weeks later: src/build/docker/debian/Dockerfile and src/build/docker/lib-c-docs/Dockerfile both carry real fork security patches (blueshell#41's checksum-verified Zig toolchain download, blueshell#28's digest-pinned archlinux base image) with no map entry. This PR adds both entries in the map's existing format, and the script passes cleanly against HEAD after that fix — which is itself the point: manual updates keep falling behind, so only the automated check catches this reliably going forward.

Verified against dash (Ubuntu's /bin/sh, what upstream-sync.yml's runs-on: ubuntu-latest actually invokes), not only bash — the first draft used a bashism (comm <(...)) that would have silently failed on the actual CI runner.

What this does not do: wire the script into upstream-sync.yml as a CI step. That file is under .github/workflows/**, which this agent's GitHub App token cannot push regardless of what the installation grants — filed as a follow-up issue with the exact step to add.

Refs #55 (needs-human: the workflow-wiring half lives in .github/workflows/upstream-sync.yml, which this agent's token cannot push — see the follow-up issue for the exact YAML)


Filed by architect agent (ACMM L6 — full mode)

— hive: agent=architect backend=pi model=kiro-api-key/claude-sonnet-5:high pi=0.87.1

…TS.md

Refs #55 — that issue asks for the check that would keep this file
honest automatically; PR #60 corrected the drift it found manually but
explicitly deferred the automation. This adds it.

scripts/check-conflict-hotspots.sh computes the upstream files the fork
has modified since its base commit (found by the first commit matching
'^ptyxis-port:', not a hardcoded SHA, so a future rebase does not stale
it), restricted to the map's own declared scope (src/** plus
.gitignore), and diffs that set against what CONFLICT_HOTSPOTS.md's
section headers list. It reports both directions: a modified file with
no entry, and an entry for a file no longer modified.

Running it today found the map had drifted again since #60:
src/build/docker/debian/Dockerfile and src/build/docker/lib-c-docs/Dockerfile
both carry real fork patches (blueshell#41's checksum-verified Zig
download, blueshell#28's digest-pinned archlinux base) with no map entry.
This adds both entries, verified against the actual diff, and the script
now passes cleanly against HEAD.

POSIX sh, verified against dash (Ubuntu's /bin/sh, what upstream-sync.yml's
runs-on: ubuntu-latest actually invokes) rather than only bash.

Wiring this into upstream-sync.yml as a CI step is a separate change: it
touches .github/workflows/**, which this agent's GitHub App token cannot
push regardless of what the installation grants. Filed as a follow-up
issue with the exact step to add.

Signed-off-by: hanthor <hanthor@users.noreply.github.com>
@hanthor-hive-agent

Copy link
Copy Markdown
Contributor Author

Important

Held for human sign-off on the direction, not on the code.

This PR's only tracked rationale is #55, which the hive filed itself — issue #55 was filed by hanthor-hive-agent[bot] and no human has acknowledged it. An agent-filed issue does not, on its own, establish that anyone agreed to the direction (hivecommons/hive#5117).

The change may well be right; nothing here is a review of it. To release the hold, acknowledge the direction on that issue — comment on it, assign yourself, or add the approved-direction label — and remove the hold label here.

@hanthor-hive-agent

Copy link
Copy Markdown
Contributor Author
4340f7a

⚠️ Sentinel alert — maintainer review required

Hive flagged this PR (author @hanthor-hive-agent[bot], head 4340f7a6bdfc) because it matches behaviors that can override security controls, escalate privileges or damage the codebase. This is a heuristic, not an accusation — a maintainer should confirm the change is intended before it merges.

  • ci_gate_weakening — CI configuration is deleted, softened or has gate checks removed (Disables or softens CI gates (continue-on-error, || true, removed checks))
    • scripts/check-conflict-hotspots.sh

Hive added the sentinel-alert label. While it is present, Hive will not approve this PR, apply LGTM/approval labels, or merge it through any auto-merge lane. Remove the label once reviewed; Hive will not re-apply it unless new commits are pushed. Tune paths and behaviors under sentinel in hive.yaml or the dashboard Security tab.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant