Skip to content

ADR-2784: Move the praetor pin to 3a766f2d56ad, take its REUSE workflow and declare the build-warnings lanes it cannot read

  • Status: Accepted
  • Date: 2026-10-08
  • Deciders: lusoris
  • Tags: ci, governance, standards, license

Context

PRAETOR_REF pinned 7458a220e1c9 (ADR-2440). Praetor main at 3a766f2d56ad59ac757826a76bb37d0fbbc87bf3 (2026-10-08) is 13 commits later; seven are breaking. The new engine's audit, run on an untouched clean clone of master a6d8d22b4, fails first on a managed workflow that holds an earlier praetor text. With the engine-written files refreshed it fails one more gate, the build-warnings gate (HISS-10). Every other change passes or does not apply here.

Praetor change Finding on master Resolution here
#902: every emitted gate takes the hosted gate draft shape; the draft step names shell: bash praetor-api.yml and praetor-docs.yml hold an earlier text regenerated by adopt (an unedited earlier rendering refreshes without --force)
#866: locked assets pass adopter linters (gofumpt gate, tools/apicompat/gate/placeholder.go, ruff-clean MkDocs hook, 80-column README and VENDOR.md) the four files hold earlier texts, the placeholder is missing regenerated by adopt; adopt also adds the placeholder to the praetor-owned list of renovate.json. The ruff, black and SPDX exceptions of tools/figures/mkdocs_hook.py stay: this repository's ruff still reports two lazy imports (PLC0415)
#892 and #898: REUSE licensing gates. adopt writes .github/workflows/reuse.yml and a lefthook reuse-lint job; audit checks the order of REUSE.toml annotations and that LICENSE is the declared licence's text order: none of the 48 annotations is shadowed; root licence: LICENSE equals LICENSES/EUPL-1.2.txt, and NOTICE is not named like a licence; reuse.yml is new and pins actions/checkout@v7 and fsfe/reuse-action@v6 by tag (cordanaLLM/praetor#899) see Decision
#868: audit fails a CI lane that compiles C, C++, Rust or Go without warnings as errors 47 lanes in 16 workflows see Decision
#861: audit warns about workflow triggers that start wasted runs 136 findings in 28 of 50 workflows, reported and not enforced; they ask for the hosted gate shape where ADR-2169 skips a draft at job level and the aggregator fails it. Three are false positives (jobs whose if: excludes pull_request) none; false positives filed as cordanaLLM/praetor#922
#854: backlog caps as policy, an optional kind on bug rows, HISS coverage titles from the catalog no cap is declared (profile, facets and lock are unchanged); praetorctl state status reads the ledger; hiss coverage --verify passes with no stale title none
#859: the rendered ruleset requires a proven merge gate; planning reconcile adoption.decline lists branch-ruleset; no planning sync runs here none
#864, #865, #863, #895, #869: lock-source refusal outside Git, HISS-02 Go shapes, radar, Makefile includes, ruff 0.16.10 none (the lock source is a Git clone at the pin; the HISS scan stays at 0) none

The DevContainer bundle changes with the engine source and was regenerated by adopt --force in a throwaway copy.

The gate of #868 reads the warnings-as-errors switch only as a literal on the build command (mesonWerror() in praetor's internal/forge/build_warnings_toolchains.go). ADR-2170 gates a leg through scripts/ci/werror-args.sh, called as $(...), through a step output or a matrix value, so the gate reads those legs as ungated. The 47 lanes are: 11 legs gated that way (all 14 rows of the Linux and macOS build matrix count as one lane); 23 Meson builds that are not gated yet (analysis, coverage, golden, DNN, sanitizer, nightly, fuzz, SYCL parity, the consumer comparison, Windows MSVC+SYCL, the Linux and macOS legs of build.yml); 5 builds of the third-party Level Zero loader with CMake defaults; the static pkg-config link probe (${CC:-cc}); 2 cgo steps without -Werror in CGO_CFLAGS; 5 cargo steps that deny warnings only through the clippy lane.

Decision

Move PRAETOR_REF in .github/workflows/standards-gate.yml to 3a766f2d56ad59ac757826a76bb37d0fbbc87bf3 under ADR-1351's conditions: engine-written files come from the engine in a throwaway copy (adopt --lock-source-root <praetor clone at the pin>, and --force for the DevContainer bundle), and only the files audit reports stale, plus the REUSE workflow below, are copied back. The agent settings, .gemini/settings.json, .config/lefthook/python.sh and the JetBrains files adopt writes are not.

REUSE. Take reuse.yml and make its REUSE lint job the one CI run of reuse lint:

  • both actions pinned to commits (actions/checkout v7.0.1, fsfe/reuse-action v6.0.0), as every other workflow here; praetor keeps an edited reuse.yml, --force included;
  • the Pre-Commit job skips its reuse-lint hook and the make lint-reuse step of lint-and-format.yml goes; the commit hook and make lint keep it locally;
  • REUSE lint joins the aggregator's required and strictMustReport lists and always in .github/ci-tier.json (it has no path filter and no tier gate); its marker sits in standards-gate.yml;
  • the job stays in praetor's hosted gate shape, so it is an untiered_jobs entry and joins PRAETOR_MANAGED in the routing contract.

The lefthook reuse-lint job is not taken: .pre-commit-config.yaml already runs reuse lint at every commit from the hash lock (reuse 6.2.0, the version the action's image runs).

HISS-10. Declare each of the 16 workflows in .config/lint-exceptions.d/HISS-10.toml, one file, one reason and expiry 2027-01-04 each, rendered into .standards.yaml by scripts/ci/praetor_tidy_coverage.py (PRAETOR_RULES gains HISS-10). The work is RC4 WP14 (#2438): spell the switch where the gate reads it, gate the remaining legs, then remove each entry as its workflow passes (T-CI-PRAETOR-HISS10-LANES-2026-10-08).

Alternatives considered

Option Pros Cons Why not chosen
REUSE: decline reuse-gate and keep make lint-reuse in the Pre-Commit job no new workflow, no tag pins a declined fleet gate is an exception by another name; the next adopt reports it every time the fleet's managed gate replaces the local step (HISS-19); a decline would keep a local copy of it
REUSE: take reuse.yml and keep the local CI step no change to lint-and-format.yml reuse lint runs three times in CI (hook, step, workflow) one behaviour, one implementation
REUSE: take reuse.yml as rendered no local edit two actions pinned by tag, the only ones here pinned to commits until praetor#899 lands
HISS-10: spell -Dwerror=true, CGO_CFLAGS and RUSTFLAGS on every lane now fewer exceptions RC4 WP14 work inside a pin move (ADR-1341: no leak across phases); 23 legs are not at zero warnings yet; every workflow also holds a lane that stays ungated, so no entry could go in this change the entries carry the work to RC4 with a due date
HISS-10: ask praetor to read $(script) output or step outputs no workflow change the gate deliberately reads only what the file shows; a script's output is not visible to it not a defect of the gate
Hold the pin no exceptions Pelorus and golusoris bumps wait on this one (Q-311)

Consequences

  • Positive: reuse lint is one required job that a planted missing licence fails; the build-warnings debt is declared per workflow with a date instead of passing unseen.
  • Negative: 16 HISS-10 entries until RC4 removes them; the REUSE job starts on a draft and reports a red check, like the other two praetor jobs (cordanaLLM/praetor#857).
  • Neutral / follow-ups: every hook engine moves with the merge, and a branch rebases onto the merged pin first. An older engine refuses a bug ledger whose rows carry a kind (praetor#792), so no state bug add --kind until every engine reading the shared ledger is at this pin. The HISS-13 baseline stays at 0.

Supply-chain impact

  • Build-time fetches: go install github.com/cordanaLLM/praetor/cmd/standardsctl@3a766f2d56ad... in the gate jobs, pinned by commit; fsfe/reuse-action@676e2d560c9a (its image is fsfe/reuse:6, reuse 6.2.0 when measured).
  • CVE surface delta: none.

References

  • Q-311: praetor first; the Pelorus and golusoris bumps follow after this one lands (orchestrator ledger, 2026-10-08).
  • Q-061: warnings are errors in every language (ADR-2342, RC4 WP14, #2438).
  • req (paraphrased): make the tree pass the REUSE gates without blanket exceptions; any exception names one file, one rule, a reason and an expiry (coordinator brief, 2026-10-08).
  • 2580: REUSE compliance issue closed by this change.

  • ADR-2440, ADR-2321, ADR-1351: earlier pin moves.