REPORT: the CI step is MEASURED, not assumed - job 481 shows the payload works
gates / gates (push) Successful in 12s

Gitea's act-runner does populate GITHUB_EVENT_PATH with a commits array carrying per-file lists.
Job 481 read 3 commits / 12 distinct paths, classified CODE (5 document, 7 code), and ran the gates
with --scope=code. Green.

Still not observed: the docs branch in CI, and an advisory in a CI log - the second additionally
needs a golden debt to exist at that moment. Neither is being arranged artificially.
This commit is contained in:
2026-09-01 12:03:28 +02:00
parent 13dd00bcff
commit 3db62fc6b2
+21 -5
View File
@@ -186,11 +186,27 @@ empty array, an absent classifier. So this step can only make CI as strict as it
looser — **the untested direction is the safe one**, which is why shipping it before observing it is
defensible.
**NOT VALIDATED: CI's actual behaviour, until a real push lands.** I have not confirmed that Gitea's
act-runner populates `GITHUB_EVENT_PATH` with a `commits` array carrying per-file lists. If it does
not, CI silently stays exactly as strict as it is now and the advisory never appears there. **The
first push after this one is the observation**, and the workflow prints the paths it found and the
scope it chose so the answer is readable in the log.
**MEASURED after the push, so this is no longer an assumption.** CI job **481** (`1e6c387a`,
felhom.eu) ran the new step and its log reads:
```
3 commit(s), 12 distinct path(s) in the payload
--- paths the push event reported ---
scripts/push_scope.py
scripts/test_push_scope.py
push_scope: CODE (12 file(s): 5 document, 7 code)
scope: code
::group::Run python3 scripts/repo_gates.py --fast --scope="${PUSH_SCOPE:-code}"
```
So Gitea's act-runner **does** populate `GITHUB_EVENT_PATH` with a `commits` array carrying per-file
lists; the classifier ran on it and returned `code` for a push that genuinely touched `scripts/`.
Job 481 is green.
**STILL NOT OBSERVED: the `docs` branch in CI, and an advisory in a CI log.** The code path is proven;
a documents-only CI run has not happened yet, and an ADVISORY there additionally needs a golden debt
to exist at that moment. Neither is arranged artificially — the next documents-only push shows the
first, and the next release-without-a-bake shows the second.
The compensating controls that make a green documents-only CI run honest are named in the workflow
itself: the advisory block in the run's own log, `STATUS.md`, and the controller-side notice.