Repository navigation
rivet externals are declared against a volume that does not exist — the federated half of the trace graph is never validated #1012
Description
Activity
- added 14 commits that reference this issue
on Aug 25, 2026 Fix up as PR #1060.
Verified the diagnosis by counting:
FAIL (50 errors, 192 warnings, 0 broken cross-refs)as committed →FAIL (12, 192, 12)with the deadpath:lines removed →PASS (192 warnings)after triage (backlinks 1032, so resolution demonstrably ran).- 9 of the 12 exposed dangling refs were GitHub issue/PR numbers written as artifact ids (
gale:209/354/359/369×2/372/374/382,witness:130) — links deleted per the convention VCR-DEC-003's own in-file comment states (and violated one line below); every number was already in the artifact's title/tags/description. - 1 (
kiln:FR-P3-ASYNC-BUILTINS) targets an id kiln's store never contained — deleted with an in-file comment rather than retargeted. - 2 (
jess:TEST-PIX-013) were REAL —jessis now declared as a git-only external and both resolve.witnessdeliberately not declared (its only ref was a PR number; nothing would resolve). rivet.lockcommitted (7 pins);rivet lockworks once the dead paths are gone.- CI: required
Rivet Validationuntouched; new NON-requiredRivet Federated Graph (advisory)job runsrivet sync+ full-graph validate + a non-vacuity guard that reds whenCross-repo backlinksis 0/absent — i.e. the exact "0 broken cross-refs beside 50 errors" signature of this issue can never again read as success. Red-first proven on real CI in the PR's own history (red run 32920387620, green run 32920637704).
Upstream friction filed: pulseengine/rivet#853 (
syncignoresrivet.lock— why the federated job stays advisory) and pulseengine/rivet#854 (a deadpath:poisons resolution with nogit:fallback and the misleading counter).- 9 of the 12 exposed dangling refs were GitHub issue/PR numbers written as artifact ids (
8 remaining items
- added a commit that references this issue
on Aug 26, 2026 Closed by v0.59.0. synth's rivet trace graph resolves for the first time:
rivet validatewent FAIL (50 errors, 0 broken cross-refs) -> PASS, exit 0, 1032 cross-repo backlinks.The diagnostic is the reusable part:
0 broken cross-refsbeside 50 link errors never meant the graph was clean — it meant resolution never ran. Nine of the twelve genuine dangling refs it exposed were GitHub issue/PR numbers written where an artifact id belongs.The federated CI job is deliberately advisory, not required: a required check that cannot run deadlocks every merge, and
rivet synchas no--lockedmode. It carries a non-vacuity guard that reds when the backlink count is 0, so this issue's exact signature can never again read as success.- added 11 commits that reference this issue
on Aug 26, 2026 - added a commit that references this issue
on Oct 8, 2026
Summary
rivet.yamldeclares six externals (kiln,meld,sigil,loom,gale,scry) each with apath:under/Volumes/Home/git/pulseengine/— a volume that does not exist on at least one maintainer machine. That deadpath:takes precedence over thegit:fallback, so external resolution silently fails and rivet never resolves cross-repotraces-tolinks at all.The tell is the counter, not the total:
path:present)FAIL (50 errors, 188 warnings, **0 broken cross-refs**)path:lines strippedFAIL (12 errors, 188 warnings, **12 broken cross-refs**)0 broken cross-refsalongside 50 link errors is the signature: rivet was not resolving the federated graph, it was failing to load it. Remove the dead paths and it resolves — 38 of the 50 errors were config rot, and 12 are genuine dangling references that had been invisible behind them.Evidence
rivet syncworks (git fallback): all 6 synced to.rivet/repos/.rivet lockfails:error: IO error: git rev-parse: No such file or directory (os error 2)— it runs git inside the declaredpath:.kiln:REQ_FUNC_014is defined at.rivet/repos/kiln/safety/requirements/functional-requirements/REQ_FUNC_014.yaml:2, andgale:SWREQ-KILN-001at.rivet/repos/gale/artifacts/phase2_kiln_integration.yaml:86. rivet still reported both as "does not exist" while the dead paths were in play.rivet.lockin the repo, so externals are unpinned even in principle.Two further gaps found alongside
jessandwitnessare referenced bytraces-tolinks but are not declared as externals at all (2 and 1 references respectively). Those can never resolve, sync or no sync.rivet syncorrivet lock(no match in.github/workflows/). So the requiredRivet Validationcheck validates only synth-local artifacts and skips every cross-repo link. Combined with the above, the federated half of the traceability graph is unvalidated in CI — a check that passes because it is not looking.CI also pins rivet v0.23.0 while current is 0.32.0; the pin is deliberate (#229 — an unpinned rivet drifted the gate when 0.15.0 promoted a WARN to an ERROR), but nine minor versions is worth a look on its own.
Why this matters
This is the checkers were the defects class one level up, and it lands on traceability specifically — which v0.58 just started relying on, since release readiness is now a query over rivet statuses. A trace graph whose federated half is silently unresolved cannot support that.
Suggested shape
path:entries, or make them conditional/optional so a missing local checkout falls back togit:instead of poisoning resolution.rivet.lockso externals are pinned.jessandwitness, or remove the links that reference them.rivet syncin theRivet Validationjob so the federated links are actually checked — and red-first: show the job failing on a deliberately dangling cross-repo ref before trusting it.Found while planning v0.59 (#1011). Not scoped into that release yet — filing so it is not lost.