From 029a8b51a3595a56b1e12b608c1dfd03a922eda0 Mon Sep 17 00:00:00 2001 From: atlas Date: Tue, 9 Jun 2026 11:18:48 +0200 Subject: [PATCH] ci: make the tracker-tag lint its own non-blocking check MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit Per operator guidance: the required-status-checks config gates merge on the nix flake check only, not this lint. So drop the warn|deny mode — the lint just fails (exit 1, error annotations) when it finds tracker tags, and runs as its own CI job so that failure shows red on the PR without failing the required nix flake check job or blocking merge. Once the legacy backlog is cleaned up, promoting this job to a required check flips it to a hard gate — no code change. --- .forgejo/workflows/ci.yml | 21 ++++++++++++++------- scripts/check-issue-refs.sh | 25 ++++++++----------------- 2 files changed, 22 insertions(+), 24 deletions(-) diff --git a/.forgejo/workflows/ci.yml b/.forgejo/workflows/ci.yml index a2b83696..0f941457 100644 --- a/.forgejo/workflows/ci.yml +++ b/.forgejo/workflows/ci.yml @@ -10,15 +10,22 @@ jobs: runs-on: [hive-ci] steps: - uses: actions/checkout@v3 - - name: lint tracker tags - # Fast pre-check: flags hash-number tracker tags in source - # (hive convention is prose, not tags — /knowledge/hive-rules.md). - # Phase 1 is warn-only while the legacy backlog is cleaned up; - # flip the arg to `deny` for a hard gate once the tree is clean. - # See scripts/check-issue-refs.sh. - run: sh scripts/check-issue-refs.sh warn - name: check # Runs all flake checks: formatting (treefmt+rustfmt), cargo test, # cargo clippy, and module evaluation. No --no-build: the checks # derivations are the canonical source of truth. run: nix flake check + + tracker-tags: + name: tracker-tag lint + runs-on: [hive-ci] + steps: + - uses: actions/checkout@v3 + - name: lint + # Flags hash-number tracker tags in source (hive convention is + # prose, not tags — /knowledge/hive-rules.md). Runs as its own + # job, kept out of the required checks while the legacy backlog + # is cleaned up: a hit fails this check (red) without blocking + # merge. Promote to a required check once the tree is clean. + # See scripts/check-issue-refs.sh. + run: sh scripts/check-issue-refs.sh diff --git a/scripts/check-issue-refs.sh b/scripts/check-issue-refs.sh index fcae50a6..6b8cdbf5 100755 --- a/scripts/check-issue-refs.sh +++ b/scripts/check-issue-refs.sh @@ -4,12 +4,12 @@ # code (see /knowledge/hive-rules.md) — tags rot, they point at moving # targets and leak tracker coupling into the source tree. # -# Usage: check-issue-refs.sh [warn|deny] -# warn (default): emit a CI warning annotation per hit, exit 0. -# deny: same annotations, but exit 1 if any hit is found. -# -# Rollout: starts in `warn` while the legacy backlog is cleaned up, -# then flips to `deny` for a hard gate (the clippy-stricter playbook). +# Emits a CI error annotation per hit and exits 1 if any tag is found, +# 0 otherwise. It runs as its own CI job, deliberately kept OUT of the +# required checks while the legacy backlog is cleaned up: a hit turns +# the job red (a visible, non-blocking signal on the PR) without +# blocking merge. Promote it to a required check once the tree is clean +# to make it a hard gate — no code change, just branch-protection. # # Scope: tracked *.rs *.nix *.js *.ts *.css *.html. Markdown is exempt # (prose docs may legitimately cite the tracker). The pattern matches a @@ -19,15 +19,6 @@ # identical digits) trips it — write the six-digit form to dodge. set -eu -mode="${1:-warn}" -case "$mode" in - warn | deny) ;; - *) - echo "usage: $0 [warn|deny]" >&2 - exit 2 - ;; -esac - pattern='#[0-9]{2,5}([^0-9a-fA-F]|$)' # `/dev/null` forces grep to always print a filename prefix, even when @@ -40,10 +31,10 @@ hits="$( if [ -n "$hits" ]; then echo "$hits" | while IFS=: read -r file lineno _; do - printf '::warning file=%s,line=%s::tracker tag in source — write prose, not a hash-number tag (see /knowledge/hive-rules.md)\n' "$file" "$lineno" + printf '::error file=%s,line=%s::tracker tag in source — write prose, not a hash-number tag (see /knowledge/hive-rules.md)\n' "$file" "$lineno" done count="$(printf '%s\n' "$hits" | wc -l | tr -d ' ')" printf 'check-issue-refs: %s tracker tag(s) found in source\n' "$count" >&2 - [ "$mode" = deny ] && exit 1 + exit 1 fi exit 0