#!/usr/bin/env python3 # -*- coding: utf-8 -*- """test_golden_notice.py — the notice REPORTS and never REFUSES (R-404). N1 IS THE LOAD-BEARING CASE. The notice's value depends entirely on it being harmless: it fires at the moment a release is committed, when the golden legitimately cannot exist yet. A notice that blocked there would refuse the very commit that starts the process, and would be disabled within a day. Its red-proof is written out below and was run. Run from `controller/`: python3 scripts/test_golden_notice.py Exit 0 all pass · 1 a case failed. """ import io import os import shutil import subprocess import sys import tempfile HERE = os.path.dirname(os.path.abspath(__file__)) CTRL = os.path.dirname(HERE) REPO = os.path.dirname(CTRL) NOTICE = os.path.join(HERE, "golden_notice.py") SHA = "9287f7cef5f13166276e8406005e3f28004004510c5184f1c1c7377f7aafad2e" def run(repo_root): p = subprocess.run([sys.executable, NOTICE, repo_root], capture_output=True, text=True) return p.returncode, p.stdout + p.stderr def fake_workspace(tmp, released, baked): """A miniature workspace: /felhom-controller + /felhom.eu, only what the gate reads.""" ctrl = os.path.join(tmp, "felhom-controller") eu = os.path.join(tmp, "felhom.eu") os.makedirs(ctrl) os.makedirs(os.path.join(eu, "scripts")) tests = os.path.join(eu, "documentation", "tests") os.makedirs(tests) with io.open(os.path.join(ctrl, "CHANGELOG.md"), "w", encoding="utf-8") as fh: fh.write(u"# changelog\n\n## v%s — a release\n\nstuff\n" % released) # the real gate, copied in so the notice imports a genuine one shutil.copy(os.path.join(os.path.dirname(REPO), "felhom.eu", "scripts", "golden_currency_gate.py"), os.path.join(eu, "scripts", "golden_currency_gate.py")) if baked: d = os.path.join(tests, "golden-%s-2026-01-01" % baked) os.makedirs(d) with io.open(os.path.join(d, "bake.log"), "w", encoding="utf-8") as fh: fh.write(u"[golden] upload OK\nGOLDEN_VERSION=%s\nGOLDEN_SHA256=%s\n" % (baked, SHA)) return ctrl def main(): fails = [] # --- N1: a version with no golden -> the notice PRINTS, exit code UNCHANGED (0) ----------- # RED-PROOF (run 2026-09-01, recorded in REPORT.md): changing the debt branch's `return 0` to # `return 1` makes this fail — and in production would refuse the commit that starts a release. tmp = tempfile.mkdtemp(prefix="gnotice-") try: ctrl = fake_workspace(tmp, "0.240.0", "0.230.0") rc, out = run(ctrl) if rc != 0: fails.append("N1: a debt must NOT change the exit code — the notice fires when the " "golden cannot exist yet, so blocking there refuses the commit that " "starts the release. Got exit %d" % rc) elif "0.240.0" not in out or "OWES A GOLDEN" not in out: fails.append("N1: the notice must NAME the version that owes a golden; got:\n%s" % out) elif "0.230.0" not in out: fails.append("N1: the notice must also say which golden IS current; got:\n%s" % out) else: print("N1 ok: debt named (0.240.0 owes; newest bake 0.230.0), exit 0 - never blocks") finally: shutil.rmtree(tmp, ignore_errors=True) # --- N2: sibling clone absent -> INCONCLUSIVE, silent about currency, still non-blocking --- tmp = tempfile.mkdtemp(prefix="gnotice-") try: lonely = os.path.join(tmp, "felhom-controller") os.makedirs(lonely) rc, out = run(lonely) if rc != 2: fails.append("N2: an absent sibling must be INCONCLUSIVE (exit 2), never a pass and " "never a conviction; got %d" % rc) elif "OWES A GOLDEN" in out or "OK —" in out: fails.append("N2: with no sibling it must stay SILENT about currency; got:\n%s" % out) elif "INCONCLUSIVE" not in out: fails.append("N2: it must say INCONCLUSIVE out loud; got:\n%s" % out) else: print("N2 ok: absent sibling -> INCONCLUSIVE, silent about currency, exit 2") # and exit 2 must still not fail the runner, because the gate is registered non-blocking import importlib.util spec = importlib.util.spec_from_file_location( "cg", os.path.join(HERE, "controller_gates.py")) cg = importlib.util.module_from_spec(spec) spec.loader.exec_module(cg) row = [g for g in cg.GATES if g[0] == "golden-notice"] if not row: fails.append("N2: golden-notice is not registered in controller_gates.py at all") elif row[0][4] is not False: fails.append("N2: golden-notice must be registered NON-BLOCKING (5th field False); " "got %r" % (row[0][4],)) else: print("N2 ok: registered non-blocking, so exit 2 cannot fail the runner") # POSITIVE CONTROL: every OTHER gate must still be blocking, or this proves nothing. nonblocking = [g[0] for g in cg.GATES if g[4] is False] if nonblocking != ["golden-notice"]: fails.append("N2 CONTROL: exactly ONE gate may be non-blocking; got %r" % nonblocking) else: print("N2 ok (control): golden-notice is the ONLY non-blocking gate") finally: shutil.rmtree(tmp, ignore_errors=True) # --- N3: currency fine -> nothing beyond the ordinary line -------------------------------- tmp = tempfile.mkdtemp(prefix="gnotice-") try: ctrl = fake_workspace(tmp, "0.230.0", "0.230.0") rc, out = run(ctrl) if rc != 0: fails.append("N3: a current golden must exit 0; got %d" % rc) elif "OWES A GOLDEN" in out: fails.append("N3: it must not cry wolf when the golden is current; got:\n%s" % out) elif len([l for l in out.splitlines() if l.strip()]) != 1: fails.append("N3: a healthy check must be ONE line — a gate that prints a paragraph " "every run is one people stop reading; got:\n%s" % out) else: print("N3 ok: current golden -> one quiet line, exit 0") # NEGATIVE CONTROL: a string that cannot be there. if "ZZZ-NOT-IN-THE-OUTPUT" in out: fails.append("N3: negative control matched — the search is not discriminating") finally: shutil.rmtree(tmp, ignore_errors=True) # --- N4: a golden AHEAD of the record is not reported as a debt ---------------------------- tmp = tempfile.mkdtemp(prefix="gnotice-") try: ctrl = fake_workspace(tmp, "0.230.0", "0.240.0") rc, out = run(ctrl) if "OWES A GOLDEN" in out: fails.append("N4: a golden AHEAD of the newest release is not a missing golden; that " "is R-385's direction and belongs to the felhom.eu gate, not here") else: print("N4 ok: a golden ahead of the record is not reported here as a debt") finally: shutil.rmtree(tmp, ignore_errors=True) if fails: print() for f in fails: print("FAIL: %s" % f) return 1 print("\ngolden-notice tests OK — it reports, it never refuses") return 0 sys.exit(main())