From 4e9a6831cd41e2bf4ab7aa223d5a6fddd6052b14 Mon Sep 17 00:00:00 2001 From: Ralf Anton Beier Date: Sat, 5 Sep 2026 00:44:06 +0200 Subject: [PATCH] ci: require the two gates I built today and then did not require MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit Both new jobs in kill-criteria.yml — the composed-graph env sweep (#346) and the MPU enforcement oracle (#349) — were running on every PR and gating nothing. Every other job in that workflow is a required context; these two were not, because I added them to the workflow and never to branch protection. That is the gale#294 defect class, reintroduced by me, in the workflow built to hold that line, on the day I closed #294 saying the invariant was now watched. The check-required-contexts gate did not catch it, and correctly so: it asserts that every REQUIRED context can report, not that every gate worth requiring IS required. Those are different properties and I had only built the first. Worth stating plainly because "we have a gate for that" was exactly the reasoning that let this through. Added to protection only after confirming both complete `success` on main (kill-criteria run, all six jobs green) — requiring a context not proven producible is the deadlock #340 was about, and doing it twice would be careless. Adding them to protection first made the committed list lag at 20 against 22, and the gate's own --protection direction reported it: NOT_LISTED a denied write really faults (REQ-OS-MPU-001 kill-criterion) NOT_LISTED no raw env import survives in the composed graph FAIL: 2 required context(s) may not be produced on a PR exit 1 Second time that direction has caught real drift rather than a planted one. This commit closes it: 22 contexts, list and protection matching exactly. Co-Authored-By: Claude Opus 5 Claude-Session: https://claude.ai/code/session_011QG86sovTbfnPNY9SfhSmo --- .github/required-contexts.txt | 2 ++ 1 file changed, 2 insertions(+) diff --git a/.github/required-contexts.txt b/.github/required-contexts.txt index ca4a55c5..71c95021 100644 --- a/.github/required-contexts.txt +++ b/.github/required-contexts.txt @@ -18,3 +18,5 @@ Lean Proofs V-closure needed? no requirement lags its closed V every required context can actually report +no raw env import survives in the composed graph +a denied write really faults (REQ-OS-MPU-001 kill-criterion)