Four corrections from @codex-reviewer-andresmgsl on 9c17a9e:
- changelog.d/202.md keeps !207's merged Added section (my cat > had deleted
64 lines of unreleased release notes) with the drills appended under Changed;
- run 1 and run 4 link their own probe issues — run 4 is the clean repeat
after the redaction incident and deserves its own citation;
- the #205 record links the evidence per identity and drops the pseudo-JSON,
claiming only what the cited runs measured;
- the security lesson states the real invariant: report content must never
contain a credential expression OR value — variables are not laundering.
Refs #202
3.6 KiB
Added
-
docs/RUNNER-PROBES.mddocuments the standing runner-probe venue,heavy-duty/ceremony-runner-probe— the place runner-only facts are measured on demand, ruled as option A by the operator (#202). -
drills/README.mdcross-links it beside the disposal rule, so the exception is visible where the dangerous habit lives (#202). -
The runbook states that the drill disposal rule does not apply to it. Archiving it defeats its purpose, and that is exactly how the three existing drill repos each became unavailable (#202).
-
It records that a probe must run as an Actions job under the workflow token: the same call answers 500 there and 204 under a PAT, so a probe run any other way produces a confident wrong answer (#202).
-
Creating the repo is recorded as the operator's step, measured rather than assumed: a fleet identity gets 403 on org repo creation and 201 in its own namespace (#202).
-
It carries an executable two-layer arming procedure: an immutable candidate code SHA and an armed workflow commit on top of it. A single layer is self-referential — rewriting a workflow makes a new commit, and a commit cannot contain its own object ID (#202).
-
Callers are pinned by layer: composite actions to the candidate code SHA, reusable workflows to the armed SHA, which is the only revision whose inner checkout points at the fork (#202).
-
The arming gate asserts what each carrier IS, not only that the old literal is gone: every
repository:equals the fork, everyCEREMONY_SELF_REFvalue equal the candidate code SHA, and callers match the layer they belong to (#202). -
It enumerates the carriers from the tree rather than encoding a count, and distinguishes ceremony's internal self-checkouts from the consumer checkouts that must stay
${{ github.repository }}(#202). -
Both published snippets are ShellCheck-clean when extracted and linted directly, not merely as part of the repository sweep (#202).
-
The checker validates the MANIFEST against the target it was given, so a manifest that describes a wrong arming consistently — wrong fork, or the armed SHA where the candidate belongs — refuses instead of matching a tree rewritten to the same wrong value (#202).
-
The manifest is generated from the PRE-arming tree, which is the only order that enumerates the carriers that must change (#202).
-
Both published snippets were driven against a constructed candidate/probe pair: deletion, both role swaps, wrong owner, wrong SHA, wrong path, a deleted caller class and an extra carrier all refuse, and the armed control passes (#202).
-
The manifest records complete caller coordinates, so a path swapped under the right owner and SHA is caught (#202).
-
Generator and checker share one domain — ceremony callers — so a third-party
actions/checkoutis neither manifested nor reported as unrecognised (#202). -
Probe results are written to an issue in the probe repo and carried to the ceremony issue by a human, so the probe holds no path that can write to the live board (#202).
Changed
-
docs/RUNNER-PROBES.mdrecords the venue's first delivered drills — the #192 asymmetry re-observed on demand under the workflow token, the dispatch route's 204 under both identities, and #215's boundary finding — each with the probe-issue URL it is recorded in (#202). -
Two venue lessons join the runbook where the next probe author will look: findings must be written to issues because the venue's log route 404s for non-admin reads, and report content sent to the forge must never contain a credential expression or value (#202).