ci: make the tracker-tag lint its own non-blocking check

Per operator guidance: the required-status-checks config gates merge
on the nix flake check only, not this lint. So drop the warn|deny
mode — the lint just fails (exit 1, error annotations) when it finds
tracker tags, and runs as its own CI job so that failure shows red on
the PR without failing the required nix flake check job or blocking
merge. Once the legacy backlog is cleaned up, promoting this job to a
required check flips it to a hard gate — no code change.
This commit is contained in:
atlas 2026-06-09 11:18:48 +02:00 committed by mara
commit 029a8b51a3
2 changed files with 22 additions and 24 deletions

View file

@ -4,12 +4,12 @@
# code (see /knowledge/hive-rules.md) — tags rot, they point at moving
# targets and leak tracker coupling into the source tree.
#
# Usage: check-issue-refs.sh [warn|deny]
# warn (default): emit a CI warning annotation per hit, exit 0.
# deny: same annotations, but exit 1 if any hit is found.
#
# Rollout: starts in `warn` while the legacy backlog is cleaned up,
# then flips to `deny` for a hard gate (the clippy-stricter playbook).
# Emits a CI error annotation per hit and exits 1 if any tag is found,
# 0 otherwise. It runs as its own CI job, deliberately kept OUT of the
# required checks while the legacy backlog is cleaned up: a hit turns
# the job red (a visible, non-blocking signal on the PR) without
# blocking merge. Promote it to a required check once the tree is clean
# to make it a hard gate — no code change, just branch-protection.
#
# Scope: tracked *.rs *.nix *.js *.ts *.css *.html. Markdown is exempt
# (prose docs may legitimately cite the tracker). The pattern matches a
@ -19,15 +19,6 @@
# identical digits) trips it — write the six-digit form to dodge.
set -eu
mode="${1:-warn}"
case "$mode" in
warn | deny) ;;
*)
echo "usage: $0 [warn|deny]" >&2
exit 2
;;
esac
pattern='#[0-9]{2,5}([^0-9a-fA-F]|$)'
# `/dev/null` forces grep to always print a filename prefix, even when
@ -40,10 +31,10 @@ hits="$(
if [ -n "$hits" ]; then
echo "$hits" | while IFS=: read -r file lineno _; do
printf '::warning file=%s,line=%s::tracker tag in source — write prose, not a hash-number tag (see /knowledge/hive-rules.md)\n' "$file" "$lineno"
printf '::error file=%s,line=%s::tracker tag in source — write prose, not a hash-number tag (see /knowledge/hive-rules.md)\n' "$file" "$lineno"
done
count="$(printf '%s\n' "$hits" | wc -l | tr -d ' ')"
printf 'check-issue-refs: %s tracker tag(s) found in source\n' "$count" >&2
[ "$mode" = deny ] && exit 1
exit 1
fi
exit 0