R-428: the gate that hunts label-matching was matching a label (and CI proved it)
gates / gates (push) Successful in 20s

decoy_coverage_gate.py identified a repository by os.path.basename(root), looked up in a RUNNERS
map. Gitea's act-runner checks the repo out into a directory called `hostexecutor`, so on its FIRST
CI run the gate reported "unknown repo 'hostexecutor'" and went INCONCLUSIVE - correctly refusing to
pass, and blind.

A NAME standing in for a FACT, in the first ten lines of the main loop of the gate written that same
morning to catch exactly that, by a session with the four shapes on screen. That is the point of
R-428 and why it is recorded rather than quietly patched: this class is not carelessness.

FIXED: the repo is now identified by which registered runner FILE exists under the root. Verified
under a renamed directory - 14 gates found where the name-based version found none.

CI also now fetches app-catalog-felhom.eu. The meta-gate walks all four runners, and a gate that
cannot see part of its subject must not report a pass on it - the same reasoning, and the same fix,
as the two sibling fetches already in the workflow.

NOTE ON THE OTHER THREE RED RUNS, all mine and all ordering: felhom-agent and felhom-controller cite
R-421, and I pushed them BEFORE felhom.eu carried that row, so instructions_gate correctly convicted
"cites R-421, which appears in neither register". The register lives in felhom.eu; any repo citing a
new row must be pushed after it. Re-run below.
This commit is contained in:
2026-09-01 12:45:42 +02:00
parent 94555614ab
commit 2d88776227
3 changed files with 30 additions and 7 deletions
+13
View File
@@ -92,6 +92,19 @@ jobs:
git checkout -q FETCH_HEAD
echo "controller CHANGELOG at $(git rev-parse --short=12 HEAD): $(head -1 CHANGELOG.md)"
- name: Fetch the app catalog (decoy-coverage reads all four runners)
# R-421's meta-gate walks every registered gate across all four repos, so it needs all four
# present. Without this it reports the catalog's runner as missing — and a gate that cannot
# see part of its subject must not report a pass on it. Same reasoning, and the same fix, as
# the two sibling fetches above: give the gate what it needs rather than let it skip.
run: |
git init -q ../app-catalog-felhom.eu
cd ../app-catalog-felhom.eu
git remote add origin http://gitea.gitea-system.svc.cluster.local:3000/admin/app-catalog-felhom.eu.git
git fetch -q --depth 1 origin main
git checkout -q FETCH_HEAD
echo "catalog at $(git rev-parse --short=12 HEAD)"
- name: Classify the push - code or documents (R-404)
# ONE RULE, NOT TWO. The pre-push hook exempts a golden-currency CONVICTION on a
# documents-only push; if CI did not do the same, a drill night would still produce red CI