diff --git a/.forgejo/workflows/ci.yml b/.forgejo/workflows/ci.yml index a2b83696..0f941457 100644 --- a/.forgejo/workflows/ci.yml +++ b/.forgejo/workflows/ci.yml @@ -10,15 +10,22 @@ jobs: runs-on: [hive-ci] steps: - uses: actions/checkout@v3 - - name: lint tracker tags - # Fast pre-check: flags hash-number tracker tags in source - # (hive convention is prose, not tags — /knowledge/hive-rules.md). - # Phase 1 is warn-only while the legacy backlog is cleaned up; - # flip the arg to `deny` for a hard gate once the tree is clean. - # See scripts/check-issue-refs.sh. - run: sh scripts/check-issue-refs.sh warn - name: check # Runs all flake checks: formatting (treefmt+rustfmt), cargo test, # cargo clippy, and module evaluation. No --no-build: the checks # derivations are the canonical source of truth. run: nix flake check + + tracker-tags: + name: tracker-tag lint + runs-on: [hive-ci] + steps: + - uses: actions/checkout@v3 + - name: lint + # Flags hash-number tracker tags in source (hive convention is + # prose, not tags — /knowledge/hive-rules.md). Runs as its own + # job, kept out of the required checks while the legacy backlog + # is cleaned up: a hit fails this check (red) without blocking + # merge. Promote to a required check once the tree is clean. + # See scripts/check-issue-refs.sh. + run: sh scripts/check-issue-refs.sh diff --git a/scripts/check-issue-refs.sh b/scripts/check-issue-refs.sh index fcae50a6..6b8cdbf5 100755 --- a/scripts/check-issue-refs.sh +++ b/scripts/check-issue-refs.sh @@ -4,12 +4,12 @@ # code (see /knowledge/hive-rules.md) — tags rot, they point at moving # targets and leak tracker coupling into the source tree. # -# Usage: check-issue-refs.sh [warn|deny] -# warn (default): emit a CI warning annotation per hit, exit 0. -# deny: same annotations, but exit 1 if any hit is found. -# -# Rollout: starts in `warn` while the legacy backlog is cleaned up, -# then flips to `deny` for a hard gate (the clippy-stricter playbook). +# Emits a CI error annotation per hit and exits 1 if any tag is found, +# 0 otherwise. It runs as its own CI job, deliberately kept OUT of the +# required checks while the legacy backlog is cleaned up: a hit turns +# the job red (a visible, non-blocking signal on the PR) without +# blocking merge. Promote it to a required check once the tree is clean +# to make it a hard gate — no code change, just branch-protection. # # Scope: tracked *.rs *.nix *.js *.ts *.css *.html. Markdown is exempt # (prose docs may legitimately cite the tracker). The pattern matches a @@ -19,15 +19,6 @@ # identical digits) trips it — write the six-digit form to dodge. set -eu -mode="${1:-warn}" -case "$mode" in - warn | deny) ;; - *) - echo "usage: $0 [warn|deny]" >&2 - exit 2 - ;; -esac - pattern='#[0-9]{2,5}([^0-9a-fA-F]|$)' # `/dev/null` forces grep to always print a filename prefix, even when @@ -40,10 +31,10 @@ hits="$( if [ -n "$hits" ]; then echo "$hits" | while IFS=: read -r file lineno _; do - printf '::warning file=%s,line=%s::tracker tag in source — write prose, not a hash-number tag (see /knowledge/hive-rules.md)\n' "$file" "$lineno" + printf '::error file=%s,line=%s::tracker tag in source — write prose, not a hash-number tag (see /knowledge/hive-rules.md)\n' "$file" "$lineno" done count="$(printf '%s\n' "$hits" | wc -l | tr -d ' ')" printf 'check-issue-refs: %s tracker tag(s) found in source\n' "$count" >&2 - [ "$mode" = deny ] && exit 1 + exit 1 fi exit 0