a4444088ad
gates / gates (push) Successful in 12s
No version heading on purpose. No Go code, no image, no version bump; giving this one would create the exact golden debt the change is about. Until today this repo - where a release actually happens - had NO golden-currency check at all, while felhom.eu ran one on every push including documents-only ones that can neither create the debt nor clear it. The person who could act heard nothing; the person who could not act was blocked, thirteen --no-verify uses' worth. golden_notice.py is ADVISORY IN EVERY CASE, and that is the only correct behaviour rather than timidity: at the moment a release is committed the golden legitimately does not exist yet, so blocking there would refuse the commit that STARTS the process - and blocking later is the mistake being undone. NO SECOND IMPLEMENTATION: it IMPORTS felhom.eu/scripts/golden_currency_gate.py and calls that gate's own released_versions()/newest_baked(), so it is the same comparison read in the other direction. Cross-repo shape copied from instructions_gate.py; never a copy of the script, because a copy recreates the drift these gates exist to detect. An absent sibling clone is INCONCLUSIVE and silent about currency - it never guesses. controller_gates.py GAINED A FIFTH `blocking` FIELD. It could not express a reporting-only gate at all before: every registered gate's non-zero exit failed the run, so the only way to add a notice was to give it the power to refuse a push. The capability was added rather than the notice compromised (R-420). False for exactly one gate, and test_golden_notice.py asserts it stays one. Tests N1-N4 with a positive control that every other gate is still blocking. RED-PROOF RUN: making the debt branch return 1 fails N1 - in production that would refuse the commit that starts a release.
158 lines
7.2 KiB
Python
158 lines
7.2 KiB
Python
#!/usr/bin/env python3
|
|
# -*- coding: utf-8 -*-
|
|
"""test_golden_notice.py — the notice REPORTS and never REFUSES (R-404).
|
|
|
|
N1 IS THE LOAD-BEARING CASE. The notice's value depends entirely on it being harmless: it fires at
|
|
the moment a release is committed, when the golden legitimately cannot exist yet. A notice that
|
|
blocked there would refuse the very commit that starts the process, and would be disabled within a
|
|
day. Its red-proof is written out below and was run.
|
|
|
|
Run from `controller/`: python3 scripts/test_golden_notice.py
|
|
Exit 0 all pass · 1 a case failed.
|
|
"""
|
|
import io
|
|
import os
|
|
import shutil
|
|
import subprocess
|
|
import sys
|
|
import tempfile
|
|
|
|
HERE = os.path.dirname(os.path.abspath(__file__))
|
|
CTRL = os.path.dirname(HERE)
|
|
REPO = os.path.dirname(CTRL)
|
|
NOTICE = os.path.join(HERE, "golden_notice.py")
|
|
SHA = "9287f7cef5f13166276e8406005e3f28004004510c5184f1c1c7377f7aafad2e"
|
|
|
|
|
|
def run(repo_root):
|
|
p = subprocess.run([sys.executable, NOTICE, repo_root], capture_output=True, text=True)
|
|
return p.returncode, p.stdout + p.stderr
|
|
|
|
|
|
def fake_workspace(tmp, released, baked):
|
|
"""A miniature workspace: <tmp>/felhom-controller + <tmp>/felhom.eu, only what the gate reads."""
|
|
ctrl = os.path.join(tmp, "felhom-controller")
|
|
eu = os.path.join(tmp, "felhom.eu")
|
|
os.makedirs(ctrl)
|
|
os.makedirs(os.path.join(eu, "scripts"))
|
|
tests = os.path.join(eu, "documentation", "tests")
|
|
os.makedirs(tests)
|
|
with io.open(os.path.join(ctrl, "CHANGELOG.md"), "w", encoding="utf-8") as fh:
|
|
fh.write(u"# changelog\n\n## v%s — a release\n\nstuff\n" % released)
|
|
# the real gate, copied in so the notice imports a genuine one
|
|
shutil.copy(os.path.join(os.path.dirname(REPO), "felhom.eu", "scripts",
|
|
"golden_currency_gate.py"),
|
|
os.path.join(eu, "scripts", "golden_currency_gate.py"))
|
|
if baked:
|
|
d = os.path.join(tests, "golden-%s-2026-01-01" % baked)
|
|
os.makedirs(d)
|
|
with io.open(os.path.join(d, "bake.log"), "w", encoding="utf-8") as fh:
|
|
fh.write(u"[golden] upload OK\nGOLDEN_VERSION=%s\nGOLDEN_SHA256=%s\n" % (baked, SHA))
|
|
return ctrl
|
|
|
|
|
|
def main():
|
|
fails = []
|
|
|
|
# --- N1: a version with no golden -> the notice PRINTS, exit code UNCHANGED (0) -----------
|
|
# RED-PROOF (run 2026-09-01, recorded in REPORT.md): changing the debt branch's `return 0` to
|
|
# `return 1` makes this fail — and in production would refuse the commit that starts a release.
|
|
tmp = tempfile.mkdtemp(prefix="gnotice-")
|
|
try:
|
|
ctrl = fake_workspace(tmp, "0.240.0", "0.230.0")
|
|
rc, out = run(ctrl)
|
|
if rc != 0:
|
|
fails.append("N1: a debt must NOT change the exit code — the notice fires when the "
|
|
"golden cannot exist yet, so blocking there refuses the commit that "
|
|
"starts the release. Got exit %d" % rc)
|
|
elif "0.240.0" not in out or "OWES A GOLDEN" not in out:
|
|
fails.append("N1: the notice must NAME the version that owes a golden; got:\n%s" % out)
|
|
elif "0.230.0" not in out:
|
|
fails.append("N1: the notice must also say which golden IS current; got:\n%s" % out)
|
|
else:
|
|
print("N1 ok: debt named (0.240.0 owes; newest bake 0.230.0), exit 0 - never blocks")
|
|
finally:
|
|
shutil.rmtree(tmp, ignore_errors=True)
|
|
|
|
# --- N2: sibling clone absent -> INCONCLUSIVE, silent about currency, still non-blocking ---
|
|
tmp = tempfile.mkdtemp(prefix="gnotice-")
|
|
try:
|
|
lonely = os.path.join(tmp, "felhom-controller")
|
|
os.makedirs(lonely)
|
|
rc, out = run(lonely)
|
|
if rc != 2:
|
|
fails.append("N2: an absent sibling must be INCONCLUSIVE (exit 2), never a pass and "
|
|
"never a conviction; got %d" % rc)
|
|
elif "OWES A GOLDEN" in out or "OK —" in out:
|
|
fails.append("N2: with no sibling it must stay SILENT about currency; got:\n%s" % out)
|
|
elif "INCONCLUSIVE" not in out:
|
|
fails.append("N2: it must say INCONCLUSIVE out loud; got:\n%s" % out)
|
|
else:
|
|
print("N2 ok: absent sibling -> INCONCLUSIVE, silent about currency, exit 2")
|
|
# and exit 2 must still not fail the runner, because the gate is registered non-blocking
|
|
import importlib.util
|
|
spec = importlib.util.spec_from_file_location(
|
|
"cg", os.path.join(HERE, "controller_gates.py"))
|
|
cg = importlib.util.module_from_spec(spec)
|
|
spec.loader.exec_module(cg)
|
|
row = [g for g in cg.GATES if g[0] == "golden-notice"]
|
|
if not row:
|
|
fails.append("N2: golden-notice is not registered in controller_gates.py at all")
|
|
elif row[0][4] is not False:
|
|
fails.append("N2: golden-notice must be registered NON-BLOCKING (5th field False); "
|
|
"got %r" % (row[0][4],))
|
|
else:
|
|
print("N2 ok: registered non-blocking, so exit 2 cannot fail the runner")
|
|
# POSITIVE CONTROL: every OTHER gate must still be blocking, or this proves nothing.
|
|
nonblocking = [g[0] for g in cg.GATES if g[4] is False]
|
|
if nonblocking != ["golden-notice"]:
|
|
fails.append("N2 CONTROL: exactly ONE gate may be non-blocking; got %r" % nonblocking)
|
|
else:
|
|
print("N2 ok (control): golden-notice is the ONLY non-blocking gate")
|
|
finally:
|
|
shutil.rmtree(tmp, ignore_errors=True)
|
|
|
|
# --- N3: currency fine -> nothing beyond the ordinary line --------------------------------
|
|
tmp = tempfile.mkdtemp(prefix="gnotice-")
|
|
try:
|
|
ctrl = fake_workspace(tmp, "0.230.0", "0.230.0")
|
|
rc, out = run(ctrl)
|
|
if rc != 0:
|
|
fails.append("N3: a current golden must exit 0; got %d" % rc)
|
|
elif "OWES A GOLDEN" in out:
|
|
fails.append("N3: it must not cry wolf when the golden is current; got:\n%s" % out)
|
|
elif len([l for l in out.splitlines() if l.strip()]) != 1:
|
|
fails.append("N3: a healthy check must be ONE line — a gate that prints a paragraph "
|
|
"every run is one people stop reading; got:\n%s" % out)
|
|
else:
|
|
print("N3 ok: current golden -> one quiet line, exit 0")
|
|
# NEGATIVE CONTROL: a string that cannot be there.
|
|
if "ZZZ-NOT-IN-THE-OUTPUT" in out:
|
|
fails.append("N3: negative control matched — the search is not discriminating")
|
|
finally:
|
|
shutil.rmtree(tmp, ignore_errors=True)
|
|
|
|
# --- N4: a golden AHEAD of the record is not reported as a debt ----------------------------
|
|
tmp = tempfile.mkdtemp(prefix="gnotice-")
|
|
try:
|
|
ctrl = fake_workspace(tmp, "0.230.0", "0.240.0")
|
|
rc, out = run(ctrl)
|
|
if "OWES A GOLDEN" in out:
|
|
fails.append("N4: a golden AHEAD of the newest release is not a missing golden; that "
|
|
"is R-385's direction and belongs to the felhom.eu gate, not here")
|
|
else:
|
|
print("N4 ok: a golden ahead of the record is not reported here as a debt")
|
|
finally:
|
|
shutil.rmtree(tmp, ignore_errors=True)
|
|
|
|
if fails:
|
|
print()
|
|
for f in fails:
|
|
print("FAIL: %s" % f)
|
|
return 1
|
|
print("\ngolden-notice tests OK — it reports, it never refuses")
|
|
return 0
|
|
|
|
|
|
sys.exit(main())
|