Skip to content

ci: install the register check for this repository's own text - #7

Draft
odenrider wants to merge 4 commits into
mainfrom
guard/register-checker
Draft

odenrider wants to merge 4 commits into
mainfrom
guard/register-checker

Conversation

@odenrider

Copy link
Copy Markdown
Contributor

Installs the register check, which reads this repository's own published text: the pull request title and body, our comments, the commit messages in the pull request, and the changed file names. It runs on the platform, so it also covers a body edited in the web interface and a comment posted from a phone.

What is here

file what it is
.github/workflows/register.yml the check
.github/workflows/register-corpora.yml the two head-side corpora
.github/scripts/register-lint.py the checker
.github/scripts/register-lint-selftest.py 70 fixtures
.github/scripts/register-pin-selftest.py 42 patterns, each pinned by a fixture
.github/scripts/register-crossrun-selftest.py 14 cases for the cross-run step

The scripts and register.yml are byte-identical to the soqucoin-sdk copies, so the guard is one file in every repository and the next copy is a copy. register-corpora.yml is the one addition: the SDK runs those two corpora inside its existing test workflow, and this repository's CI is shaped differently.

How it works

register.yml takes the checker from the base of a pull request, so a pull request does not supply the checker that judges it. A second step runs the base's corpus against the checker a pull request ships, so the check reads on the checker as well as on the text.

The check is red on this pull request, and that is the expected result

The base of this pull request carries no checker, so there is no trusted copy to run and the step fails closed. That is the designed behaviour for the change that installs it, and it clears on the next pull request.

For the same reason, register should be made a required check only after this has merged. Requiring it first leaves this pull request unmergeable.

The check reads the pull request title and body, our comments, the commit messages in the pull request and the changed file names, using the checker taken from the base of a pull request. A second step runs the base corpus against the checker a pull request ships.

The four scripts and register.yml are copies of the soqucoin-sdk files, so the guard is one file in every repository. register-corpora.yml runs the two head-side corpora, which the SDK runs inside its own test workflow.

The check fails on this pull request by design: its base carries no checker, so there is no trusted copy to run. Make it required after this merges.
…ss-run job

The shared files are copied from soqucoin-sdk, where the corpora run, and verified here by
blob hash. register.yml fires on pull_request_target and the three comment events and loads
the repository default branch on every trigger. The cross-run step, which runs the checker a
pull request ships, moves to register-crossrun.yml on pull_request and stays advisory.
register-lint.py follows the Link header, so a pull request longer than one page is read to
the end.
@odenrider

Copy link
Copy Markdown
Contributor Author

The register check splits into two jobs, and this repository carries the change by copy.

register.yml holds the required job: it fires on pull_request_target and the three comment
events, takes no ref so every trigger loads the repository default branch, carries
contents: read with pull-requests: read, and runs nothing a pull request ships. The
cross-run step, which does run the checker a pull request ships, is now
register-crossrun.yml on pull_request and is advisory. They are two files because a job
skipped by an if publishes a passing check. register-lint.py also follows the Link header
now, so a pull request longer than one page is read to the end.

The six shared files are byte-identical to soqucoin-sdk, where the corpora run, verified here
by blob hash: register-lint.py af2483ed5cd8, register-lint-selftest.py 94baa673803b,
register-pin-selftest.py 14d307cd74e5, register-crossrun-selftest.py 411932b2f0fd,
register.yml 29225a1b7558, register-crossrun.yml 8b33f6288796. corpora is green here:
42 patterns pinned, 23 workflow cases.

crossrun is red on this pull request and is expected to be, once: the step needs a corpus on
the base to run the checker against, and the base of the change that installs the corpus does
not carry one. The message it prints says so. The required job does not run on this pull
request either, because register.yml is not on the default branch yet. Both start working on
the pull request after this one merges.

Reasoning and the two open items are on soqucoin-labs/soqucoin-sdk#63.

…the runner's own

The step runs the checker a pull request ships. A run step is handed no repository token
unless the workflow puts one in its environment and this one does not, so the check is
against a later edit that adds one. The runner's cache and id-token service tokens are in
every step, so the child process drops them.

Two cases hold it: the step stops before any head code runs when a token is present, and the
checker reads the runner token as absent. Removing the scrub makes the second read the value.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant