a4444088ad
gates / gates (push) Successful in 12s
No version heading on purpose. No Go code, no image, no version bump; giving this one would create the exact golden debt the change is about. Until today this repo - where a release actually happens - had NO golden-currency check at all, while felhom.eu ran one on every push including documents-only ones that can neither create the debt nor clear it. The person who could act heard nothing; the person who could not act was blocked, thirteen --no-verify uses' worth. golden_notice.py is ADVISORY IN EVERY CASE, and that is the only correct behaviour rather than timidity: at the moment a release is committed the golden legitimately does not exist yet, so blocking there would refuse the commit that STARTS the process - and blocking later is the mistake being undone. NO SECOND IMPLEMENTATION: it IMPORTS felhom.eu/scripts/golden_currency_gate.py and calls that gate's own released_versions()/newest_baked(), so it is the same comparison read in the other direction. Cross-repo shape copied from instructions_gate.py; never a copy of the script, because a copy recreates the drift these gates exist to detect. An absent sibling clone is INCONCLUSIVE and silent about currency - it never guesses. controller_gates.py GAINED A FIFTH `blocking` FIELD. It could not express a reporting-only gate at all before: every registered gate's non-zero exit failed the run, so the only way to add a notice was to give it the power to refuse a push. The capability was added rather than the notice compromised (R-420). False for exactly one gate, and test_golden_notice.py asserts it stays one. Tests N1-N4 with a positive control that every other gate is still blocking. RED-PROOF RUN: making the debt branch return 1 fails N1 - in production that would refuse the commit that starts a release.
116 lines
5.5 KiB
Python
116 lines
5.5 KiB
Python
#!/usr/bin/env python3
|
|
# -*- coding: utf-8 -*-
|
|
"""golden_notice.py — tell the repo that CREATES the golden debt, at the moment it creates it.
|
|
|
|
Usage: python3 scripts/golden_notice.py <repo-root>
|
|
Exit ALWAYS 0 when it can answer, 2 when it cannot. **NEVER 1. It cannot refuse a push.**
|
|
|
|
WHY THIS EXISTS (R-404, 2026-09-01).
|
|
|
|
The golden-currency check was pointed at the wrong repository. `felhom.eu` — which holds the bake
|
|
evidence, the register and the architecture — ran it on every push, including pushes that touch only
|
|
documents and therefore can neither create the debt nor clear it. `felhom-controller` — where a
|
|
release actually happens — **never checked at all.** So the person who could act heard nothing and
|
|
the person who could not act was blocked, and `--no-verify` was reached for thirteen times.
|
|
|
|
This is the other half of that correction: the notice belongs where the debt is born.
|
|
|
|
⚠ IT IS ADVISORY IN EVERY CASE, AND THAT IS NOT TIMIDITY — IT IS THE ONLY CORRECT BEHAVIOUR.
|
|
At the moment a release is committed the golden legitimately does NOT exist yet: you cannot bake a
|
|
golden for a version you have not pushed. Blocking here would refuse the very commit that starts the
|
|
process. And blocking LATER is the mistake this whole change is undoing. So it prints, and the
|
|
runner's exit code is untouched. `controller_gates.py` gained a `blocking` field to express that;
|
|
before this, that runner could not describe a gate that reports without refusing.
|
|
|
|
⚠ IT NEVER GUESSES. With no `felhom.eu` sibling clone it says INCONCLUSIVE and stays silent about
|
|
currency — an absent input is "I do not know", never "fine".
|
|
|
|
NO SECOND IMPLEMENTATION. It IMPORTS `felhom.eu/scripts/golden_currency_gate.py` and calls that
|
|
gate's own `released_versions()` and `newest_baked()`, so the comparison here is the SAME
|
|
comparison, read in the other direction. A private copy of "which version owes a golden" is a second
|
|
thing that can be wrong, and the two would drift. This follows `instructions_gate.py`'s cross-repo
|
|
pattern: the shared script lives in ONE repo and is invoked across the workspace, never copied.
|
|
"""
|
|
import importlib.util
|
|
import os
|
|
import sys
|
|
|
|
HERE = os.path.dirname(os.path.abspath(__file__))
|
|
CTRL = os.path.dirname(HERE)
|
|
REPO_DEFAULT = os.path.dirname(CTRL)
|
|
|
|
|
|
def load_gate(repo_root):
|
|
"""Import the sibling felhom.eu gate. Returns (module, tried_path) or (None, tried_path)."""
|
|
path = os.path.join(os.path.dirname(repo_root), "felhom.eu", "scripts",
|
|
"golden_currency_gate.py")
|
|
if not os.path.isfile(path):
|
|
return None, path
|
|
try:
|
|
spec = importlib.util.spec_from_file_location("golden_currency_gate", path)
|
|
mod = importlib.util.module_from_spec(spec)
|
|
spec.loader.exec_module(mod)
|
|
return mod, path
|
|
except Exception as e:
|
|
sys.stdout.write("golden-notice: the sibling gate could not be imported: %s\n" % e)
|
|
return None, path
|
|
|
|
|
|
def main(argv):
|
|
repo_root = os.path.abspath(argv[1]) if len(argv) > 1 else REPO_DEFAULT
|
|
gate, tried = load_gate(repo_root)
|
|
if gate is None:
|
|
print("golden-notice: INCONCLUSIVE — no felhom.eu sibling clone.")
|
|
print(" tried: %s" % tried)
|
|
print(" Nothing is claimed about golden currency. An absent input is 'I do not know',")
|
|
print(" never 'fine'. This is still NOT a refusal — it never blocks a push.")
|
|
return 2
|
|
|
|
try:
|
|
released = gate.released_versions()
|
|
baked = gate.newest_baked()
|
|
except Exception as e:
|
|
print("golden-notice: INCONCLUSIVE — the sibling gate raised %s" % e)
|
|
return 2
|
|
|
|
# `released_versions()` returns newest-first; `newest_baked()` returns the newest bake.
|
|
newest_rel = released[0] if released else None
|
|
newest_bake = baked[0] if isinstance(baked, tuple) else baked
|
|
if newest_rel is None:
|
|
print("golden-notice: INCONCLUSIVE — could not read a released version from CHANGELOG.md.")
|
|
return 2
|
|
|
|
rel_s = gate.vstr(newest_rel)
|
|
bake_s = gate.vstr(newest_bake) if newest_bake else "none"
|
|
|
|
if newest_bake and tuple(newest_bake) >= tuple(newest_rel):
|
|
print("golden-notice: OK — v%s is released and a golden carries it (newest bake %s)."
|
|
% (rel_s, bake_s))
|
|
return 0
|
|
|
|
# The debt exists. Say so plainly, and say what clears it.
|
|
print("=" * 78)
|
|
print("NOTICE — v%s OWES A GOLDEN. (this NEVER blocks; see the docstring)" % rel_s)
|
|
print("=" * 78)
|
|
print(" newest released controller : %s (this repo's CHANGELOG.md)" % rel_s)
|
|
print(" newest golden baked : %s (felhom.eu documentation/tests/)" % bake_s)
|
|
print("")
|
|
print(" A machine installed right now would receive %s, not %s." % (bake_s, rel_s))
|
|
print("")
|
|
print(" This is a REMINDER AT THE ONE MOMENT IT IS USEFUL — you are in the repo where the")
|
|
print(" release happens. It does not block, and must not: at the moment a release is")
|
|
print(" committed the golden cannot exist yet.")
|
|
print("")
|
|
print(" WHAT CLEARS IT: bake a golden (felhom.eu documentation/runbooks/RUNBOOK-manual-build.md")
|
|
print(" section 4.1), then vouch it — a THREE-field change: golden_version + agent_version +")
|
|
print(" min_agent. The bake record lands in felhom.eu documentation/tests/golden-<ver>-<date>/.")
|
|
print("")
|
|
print(" If this release deliberately needs no golden, record a waiver row in")
|
|
print(" felhom.eu documentation/backlog/OPEN-ITEMS.md — never a habit of bypassing.")
|
|
print("=" * 78)
|
|
return 0
|
|
|
|
|
|
if __name__ == "__main__":
|
|
sys.exit(main(sys.argv))
|