Skip to content

pin_integrity.ex:56 bare / inside ~r/…/ character class breaks compilation — HEAD unbuildable, all consumer Hypatia lanes red #869

Description

@arena-ai-coding-agent

Summary

lib/rules/pin_integrity.ex does not compile. Every consumer that builds the scanner from source — this repo's own Escript Soundness, metadatastician/chronicles-of-slavia's Hypatia neurosymbolic scan (a required check) and scan / Hypatia Neurosymbolic Analysis (standards reusable), and every other estate lane that resolves HEAD — fails at mix compile with the identical error.

Error (verbatim, both toolchains)

== Compilation error in file lib/rules/pin_integrity.ex ==
** (MismatchedDelimiterError) mismatched delimiter found on lib/rules/pin_integrity.ex:56:76:
    error: unexpected token: ]
  56 │   @uses_regex ~r/^\s*-?\s*uses:\s*(?<action>[A-Za-z0-9_.-]+\/[A-Za-z0-9_./-]*?)@(?<ref>[^\s#]+)\s*(?:#\s*(?<comment>.*?))?\s*$/
    │                                                                            └ mismatched closing delimiter (expected "end")
    └─ lib/rules/pin_integrity.ex:56:76

Reproduced under elixir 1.17.3/OTP 27 (this repo's Escript Soundness container) and elixir 1.19.4/OTP 28 (chronicles-of-slavia's setup-beam job): not a toolchain issue, a source issue.

Root cause

The char class [A-Za-z0-9_./-] in the ~r/…/ sigil contains a bare /. Elixir's sigil lexer does not understand regex character classes; the bare / closes the sigil early, and the trailing ] becomes a stray token one level up. The path separator earlier in the same regex is escaped (+\/[); the one inside the class is not.

Fix (one character): [A-Za-z0-9_./-] → [A-Za-z0-9_.\/-] (or switch the sigil delimiter, e.g. ~r{…}).

Bisect

commit date Escript Soundness
9f2f62f5c9463c79b33a5ebf54372166ce56f349 (#861) 2026-09-25T21:50Z ✅ success (last green)
4654d7a3d4… (#862) 2026-09-26T14:56Z ❌ failure — introduces lib/rules/pin_integrity.ex, the only commit that has ever touched it
43124f025af26dadc9d268460410a205cfccefe8 (HEAD, #867) 2026-09-27T01:50Z ❌ failure

First failing run: https://github.com/hyperpolymath/hypatia/actions — Escript Soundness on 4654d7a3d4, "Compile" step, 2026-09-26T14:56Z. Every run since is red at the same step; HEAD is still 43124f02 (no commits since 2026-09-27T01:50Z).

Evidence links

Process note (why this stayed invisible)

#862 landed while this repo's own CI was mostly startup_failure (the codeql-action v4.38.1 class, cf. nexia-list#100), and #867 merged the next day with Escript Soundness already red. A visible red was merged over. Estate lesson (feeds standards#994 / #968): a compile gate that is startup-dead provides no merge protection — restore startup before landing source changes.

Consumer status while this is open

🤖 Generated with Claude Code

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions