chore(bootstrap): pin 7ee3d5cc6416 and re-record digests - #89
Merged
Conversation
By hand again, for #88, because the `pin` job still cannot push its bump branch (#87 — the App installation lacks `contents: write`). Second hand-bump in one afternoon. The pin only goes stale when a fetched file changes, so this is not noise: it is the designed hand-off running with its automated half broken, and every PR touching `.claude/` will need this until #87 is fixed.
This was referenced Aug 3, 2026
bdelanghe
added a commit
that referenced
this pull request
Aug 3, 2026
Two changes, one cause (#87). 1. Point at `front-desk-pin`, not `front-desk`. The fan-in entry carries no `contents`, so it could never push the bump branch, and it cannot be given any: it is deliberately unpinned and `contents` is privileged, so the broker would refuse the entry outright and take every other consumer with it. The separate pinned entry is bounded-systems/infra#172. 2. Do not use the token when the mint step FAILED. `require: contents, pull_requests` (#93) worked exactly as designed on the merge of #97 — it reported `contents(granted: absent)` and named both places the gap could live. Then `continue-on-error: true` swallowed the verdict, the job used the token anyway, and died on the very push the assertion had just said would fail. An assertion whose verdict nothing consumes is decoration. The fallback is not a downgrade: github.token holds contents:write here and pushed this branch fine before the broker was wired in (#79). So on a scope gap the branch now LANDS with the correct pin and only opening the PR is lost — a click, versus the full hand-regenerate it costs today (#79, #86, #89, #98). A third annotation separates "broker reachable, scopes insufficient" from "broker unreachable", since the two are fixed in different systems.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
The bump #88 needs. By hand again, because the
pinjob still can't push its branch — #87, the App installation lackscontents: write.SUM_session_start_dispatch_mjsmoves; the other two are unchanged, as expected — #88 touched only the dispatcher.Generated with
node .claude/gen-bootstrap-pin.mjs 7ee3d5cc6416ecf9a5c37bce3b66fae62ac2599d, not hand-edited. Verified withGITHUB_EVENT_NAME=push, the setting that assertsFRESHNESS— i.e. under the condition that is currently red on main, not just the PR-mode one.This is the second hand-bump today
Worth stating plainly rather than letting it look like routine noise: the pin goes stale only when a fetched file changes, so this isn't churn — it's the designed hand-off running with its automated half broken. Every PR touching
.claude/will need a follow-up like this until #87 is fixed, and if one is forgotten,mainstays red and sessions without.githubattached are served stale files from the fallback path. That is the failurebootstrap-pin.test.mjswas written to catch, and it catches it correctly; nothing is acting on the catch.Generated by Claude Code