ADR-2784: Move the praetor pin to 3a766f2d56ad, take its REUSE workflow and declare the build-warnings lanes it cannot read¶
- Status: Accepted
- Date: 2026-10-08
- Deciders: lusoris
- Tags: ci, governance, standards, license
Context¶
PRAETOR_REF pinned 7458a220e1c9 (ADR-2440). Praetor main at 3a766f2d56ad59ac757826a76bb37d0fbbc87bf3 (2026-10-08) is 13 commits later; seven are breaking. The new engine's audit, run on an untouched clean clone of master a6d8d22b4, fails first on a managed workflow that holds an earlier praetor text. With the engine-written files refreshed it fails one more gate, the build-warnings gate (HISS-10). Every other change passes or does not apply here.
| Praetor change | Finding on master | Resolution here |
|---|---|---|
#902: every emitted gate takes the hosted gate draft shape; the draft step names shell: bash | praetor-api.yml and praetor-docs.yml hold an earlier text | regenerated by adopt (an unedited earlier rendering refreshes without --force) |
#866: locked assets pass adopter linters (gofumpt gate, tools/apicompat/gate/placeholder.go, ruff-clean MkDocs hook, 80-column README and VENDOR.md) | the four files hold earlier texts, the placeholder is missing | regenerated by adopt; adopt also adds the placeholder to the praetor-owned list of renovate.json. The ruff, black and SPDX exceptions of tools/figures/mkdocs_hook.py stay: this repository's ruff still reports two lazy imports (PLC0415) |
#892 and #898: REUSE licensing gates. adopt writes .github/workflows/reuse.yml and a lefthook reuse-lint job; audit checks the order of REUSE.toml annotations and that LICENSE is the declared licence's text | order: none of the 48 annotations is shadowed; root licence: LICENSE equals LICENSES/EUPL-1.2.txt, and NOTICE is not named like a licence; reuse.yml is new and pins actions/checkout@v7 and fsfe/reuse-action@v6 by tag (cordanaLLM/praetor#899) | see Decision |
| #868: audit fails a CI lane that compiles C, C++, Rust or Go without warnings as errors | 47 lanes in 16 workflows | see Decision |
| #861: audit warns about workflow triggers that start wasted runs | 136 findings in 28 of 50 workflows, reported and not enforced; they ask for the hosted gate shape where ADR-2169 skips a draft at job level and the aggregator fails it. Three are false positives (jobs whose if: excludes pull_request) | none; false positives filed as cordanaLLM/praetor#922 |
| #854: backlog caps as policy, an optional kind on bug rows, HISS coverage titles from the catalog | no cap is declared (profile, facets and lock are unchanged); praetorctl state status reads the ledger; hiss coverage --verify passes with no stale title | none |
| #859: the rendered ruleset requires a proven merge gate; planning reconcile | adoption.decline lists branch-ruleset; no planning sync runs here | none |
| #864, #865, #863, #895, #869: lock-source refusal outside Git, HISS-02 Go shapes, radar, Makefile includes, ruff 0.16.10 | none (the lock source is a Git clone at the pin; the HISS scan stays at 0) | none |
The DevContainer bundle changes with the engine source and was regenerated by adopt --force in a throwaway copy.
The gate of #868 reads the warnings-as-errors switch only as a literal on the build command (mesonWerror() in praetor's internal/forge/build_warnings_toolchains.go). ADR-2170 gates a leg through scripts/ci/werror-args.sh, called as $(...), through a step output or a matrix value, so the gate reads those legs as ungated. The 47 lanes are: 11 legs gated that way (all 14 rows of the Linux and macOS build matrix count as one lane); 23 Meson builds that are not gated yet (analysis, coverage, golden, DNN, sanitizer, nightly, fuzz, SYCL parity, the consumer comparison, Windows MSVC+SYCL, the Linux and macOS legs of build.yml); 5 builds of the third-party Level Zero loader with CMake defaults; the static pkg-config link probe (${CC:-cc}); 2 cgo steps without -Werror in CGO_CFLAGS; 5 cargo steps that deny warnings only through the clippy lane.
Decision¶
Move PRAETOR_REF in .github/workflows/standards-gate.yml to 3a766f2d56ad59ac757826a76bb37d0fbbc87bf3 under ADR-1351's conditions: engine-written files come from the engine in a throwaway copy (adopt --lock-source-root <praetor clone at the pin>, and --force for the DevContainer bundle), and only the files audit reports stale, plus the REUSE workflow below, are copied back. The agent settings, .gemini/settings.json, .config/lefthook/python.sh and the JetBrains files adopt writes are not.
REUSE. Take reuse.yml and make its REUSE lint job the one CI run of reuse lint:
- both actions pinned to commits (
actions/checkoutv7.0.1,fsfe/reuse-actionv6.0.0), as every other workflow here; praetor keeps an editedreuse.yml,--forceincluded; - the Pre-Commit job skips its
reuse-linthook and themake lint-reusestep oflint-and-format.ymlgoes; the commit hook andmake lintkeep it locally; REUSE lintjoins the aggregator'srequiredandstrictMustReportlists andalwaysin.github/ci-tier.json(it has no path filter and no tier gate); its marker sits instandards-gate.yml;- the job stays in praetor's hosted gate shape, so it is an
untiered_jobsentry and joinsPRAETOR_MANAGEDin the routing contract.
The lefthook reuse-lint job is not taken: .pre-commit-config.yaml already runs reuse lint at every commit from the hash lock (reuse 6.2.0, the version the action's image runs).
HISS-10. Declare each of the 16 workflows in .config/lint-exceptions.d/HISS-10.toml, one file, one reason and expiry 2027-01-04 each, rendered into .standards.yaml by scripts/ci/praetor_tidy_coverage.py (PRAETOR_RULES gains HISS-10). The work is RC4 WP14 (#2438): spell the switch where the gate reads it, gate the remaining legs, then remove each entry as its workflow passes (T-CI-PRAETOR-HISS10-LANES-2026-10-08).
Alternatives considered¶
| Option | Pros | Cons | Why not chosen |
|---|---|---|---|
REUSE: decline reuse-gate and keep make lint-reuse in the Pre-Commit job | no new workflow, no tag pins | a declined fleet gate is an exception by another name; the next adopt reports it every time | the fleet's managed gate replaces the local step (HISS-19); a decline would keep a local copy of it |
REUSE: take reuse.yml and keep the local CI step | no change to lint-and-format.yml | reuse lint runs three times in CI (hook, step, workflow) | one behaviour, one implementation |
REUSE: take reuse.yml as rendered | no local edit | two actions pinned by tag, the only ones here | pinned to commits until praetor#899 lands |
HISS-10: spell -Dwerror=true, CGO_CFLAGS and RUSTFLAGS on every lane now | fewer exceptions | RC4 WP14 work inside a pin move (ADR-1341: no leak across phases); 23 legs are not at zero warnings yet; every workflow also holds a lane that stays ungated, so no entry could go in this change | the entries carry the work to RC4 with a due date |
HISS-10: ask praetor to read $(script) output or step outputs | no workflow change | the gate deliberately reads only what the file shows; a script's output is not visible to it | not a defect of the gate |
| Hold the pin | no exceptions | Pelorus and golusoris bumps wait on this one (Q-311) |
Consequences¶
- Positive:
reuse lintis one required job that a planted missing licence fails; the build-warnings debt is declared per workflow with a date instead of passing unseen. - Negative: 16 HISS-10 entries until RC4 removes them; the REUSE job starts on a draft and reports a red check, like the other two praetor jobs (cordanaLLM/praetor#857).
- Neutral / follow-ups: every hook engine moves with the merge, and a branch rebases onto the merged pin first. An older engine refuses a bug ledger whose rows carry a kind (praetor#792), so no
state bug add --kinduntil every engine reading the shared ledger is at this pin. The HISS-13 baseline stays at 0.
Supply-chain impact¶
- Build-time fetches:
go install github.com/cordanaLLM/praetor/cmd/standardsctl@3a766f2d56ad...in the gate jobs, pinned by commit;fsfe/reuse-action@676e2d560c9a(its image isfsfe/reuse:6, reuse 6.2.0 when measured). - CVE surface delta: none.
References¶
- Q-311: praetor first; the Pelorus and golusoris bumps follow after this one lands (orchestrator ledger, 2026-10-08).
- Q-061: warnings are errors in every language (ADR-2342, RC4 WP14, #2438).
- req (paraphrased): make the tree pass the REUSE gates without blanket exceptions; any exception names one file, one rule, a reason and an expiry (coordinator brief, 2026-10-08).
-
2580: REUSE compliance issue closed by this change.¶
- ADR-2440, ADR-2321, ADR-1351: earlier pin moves.