forked from heavy-duty/ceremony
@codex-reviewer-andresmgsl's blocker 1 is right and the filename exemption was
the wrong shape. It exempted the whole FILE — any later `gh` call anywhere in
labels.yml would have ridden in free — and it let the merge ship a step that
dies with `command not found` on every sweep on this forge, which #197's bar
does not permit.
The declaration mechanism already existed; a workflow simply could not reach
it. It can: `CEREMONY_FORGE_CLIENT: gh` in the step's env is the same
declaration actions/refs-not-closing carries, and the refusal that a script
gets from forge_preflight is inline here because a workflow has no shell to
call it from. The dispatch now warns by name, cites #205, and exits 0 rather
than reddening every sweep for a known gap.
So the guard needs no exemption list at all. It now requires the pair —
declared AND refusing — and reports a declaration that carries no refusal,
which is a permission slip for `command not found`.
That predicate was wrong on its first write, and its mutation test caught it:
`refuses_when_unavailable` matched the word `forge_preflight` inside
labels.yml's own comment explaining that it has NO forge_preflight to call. A
guard reading prose as evidence is the blind sweep again, in the guard written
to forbid it. Comments are stripped now, as gh_calls already stripped them.
Blocker 4: the nudge strips a trailing slash from the server URL. Reverting the
strip reds two cases.
Blockers 2 and 3 were already fixed in 97e63ac, before either review landed.
test/run.sh 28 files 0 failed under CI's env; shellcheck 0.10.0 (CI's pin),
actionlint, self-ref, marker, vendored and changelog-armed all clean, with
every file tracked this time.
Refs #198
48 lines
2.2 KiB
Markdown
48 lines
2.2 KiB
Markdown
### Added
|
|
|
|
- This tree carries upstream ceremony through `8c3a4d1` (upstream `0.6.0`):
|
|
`lib/attention.sh`, `lib/read.sh`, `actions/refs-not-closing`, the guarded
|
|
reads, and the ruling and window rules (#198).
|
|
|
|
- `test/no-runtime-gh.test.sh` — the forge-portability guard: no runtime `gh`
|
|
outside `lib/forge-github.sh` unless the file declares
|
|
`CEREMONY_FORGE_CLIENT=gh` (#198).
|
|
|
|
- `CHANGELOG.md` names the upstream commit this tree carries, so a drill
|
|
record can say which `0.6.0` it exercised (#197, #198).
|
|
|
|
### Fixed
|
|
|
|
- Eight runtime `gh` call sites arrived with the merge outside every conflict
|
|
hunk, in functions upstream added to files this tree already owned. Seven
|
|
are ported onto the shim; the eighth is named with its reason (#198).
|
|
|
|
- The open-PR gather reads `Refs`, not only closing keywords. Reading one side
|
|
for closing links and the other for `Refs` is what released a live claim in
|
|
crew#321, and this tree carried that shape (#198).
|
|
|
|
- The merged record gains `merged_at`, so `post_merge_pr_for_issue` answers
|
|
the PR that merged last rather than the highest-numbered one. Without the
|
|
column every sort key ties and the old order returns silently (#198).
|
|
|
|
- The open gather feeds `open_pr_issues` one record per physical body line. A
|
|
whole decoded body as one record loses every declaration including the
|
|
first, and reclaims a claim a live PR was holding (#198).
|
|
|
|
- The post-merge nudge links the issue on the forge in play rather than a
|
|
hard-coded `github.com` (#198).
|
|
|
|
- `actions/refs-not-closing` reports and skips on a forge it cannot speak,
|
|
naming the client and #199, instead of standing red on every PR. It reaches
|
|
the forge zero times, so no verdict is produced either way (#198).
|
|
|
|
- `.github/workflows/labels.yml`'s sweep dispatch declares the client it
|
|
speaks and refuses by name on a runner without it, instead of dying with
|
|
`command not found` on every sweep. #205 ports it to REST (#198).
|
|
|
|
- The post-merge nudge strips a trailing slash from the server URL, so a forge
|
|
URL carrying one does not render `//owner/repo` (#198).
|
|
|
|
- `.github/scripts/release-path.sh` names `lib/forge.sh`: #191 put the shim on
|
|
the release doors' executable path here, so a doors-unchanged record that
|
|
omitted it was measuring the wrong set (#198).
|