hyperhive/scripts/check-issue-refs.sh
iris 3c6c2ed272 ci: add .mjs to check-comment-blocks.sh + check-issue-refs.sh's scope
mara: "add mjs to the lint and fix it in this pr". Both lints scope their
git ls-files scan to a fixed extension list that never included .mjs, so
all three frontend build.mjs files (swarm-ui, dashboard, agent) were
completely invisible to both -- not merely under the limits, outside the
scan entirely.

check-comment-blocks.sh: added '*.mjs' to the ls-files glob and to the
mode_of regex (same slash-comment treatment .js/.ts/.tsx already get --
.mjs is the same comment syntax, argus's exact proposed fix). check-issue-refs.sh:
added '*.mjs' to its glob list, no regex change needed.

Fixing the scope immediately surfaced real, pre-existing violations in
the other two build.mjs files (swarm-ui's own is already handled by this
PR's earlier commits):
- dashboard/build.mjs: 49-line comment block (trimmed to 15 -- redundant
  per-file output-layout table cut, the code below already names every
  output path) plus three bare tracker tags (#448 x2, #453) in the
  stream-worker comment, reworded to prose
- agent/build.mjs: two bare tracker tags (hyperhive#3685 x2), reworded

No logic changes anywhere -- comment-only edits plus the two lint
scripts. Closes #4300 and (independently filed, consolidated into that
one) #4299.
2026-09-12 13:04:01 +02:00

50 lines
2.5 KiB
Shell
Executable file

#!/bin/sh
# CI lint: flags tracker references — a `#N` tag or a full `.../issues/N`
# forge URL — anywhere in tracked text, source or docs. Prose, not tracker
# references: in code because tags rot; in markdown because the forge's
# public mirror carries no issue/PR data at all, so bare/qualified/glued
# `#N` and a full link are equally dead weight for a public reader — a
# full URL is the same problem spelled out longer, not a safer swap for a
# short tag. No markdown exemption: one used to exist, dropped once that
# read as still allowing exactly this.
#
# Emits a CI error annotation per hit, exits 1 if any hit is found. Its own
# required CI job (branch protection) — a hit blocks merge.
#
# Scope: every tracked `*.rs *.nix *.js *.mjs *.ts *.tsx *.css *.html *.md
# *.yml *.yaml`. CI workflow files (`.forgejo/workflows/*.yml`) are explicitly in
# scope: a step comment is still a comment. The pattern matches a hash,
# 2-5 digits, then a non-alphanumeric char or end-of-line (skips
# letter-bearing hex colours and digit-runs-then-letter, e.g. `#24h`;
# residual: a pure-numeric short hex trips it, write the six-digit form to
# dodge); or an `/issues/N` path segment, catching a full link via
# `$HIVE_FORGE_URL` or a literal domain alike.
#
# Escape hatch: a line with the marker `lint:allow` is exempt. Reserve it
# for a genuine non-tag hit (a `#123` heading example, test-input data) and
# keep a short reason next to it — not for a real reference of either
# form; rewrite those to prose that stands on its own instead.
set -eu
pattern='#[0-9]{2,5}([^0-9a-zA-Z]|$)|/issues/[0-9]+([^0-9a-zA-Z]|$)'
# `/dev/null` forces grep to always print a filename prefix, even when
# xargs hands it a single file. `-r`/`-0` keep it robust to odd paths and
# an empty file list. Lines carrying the `lint:allow` marker are dropped
# (legitimate non-tracker hit; see the header).
hits="$(
git ls-files -z '*.rs' '*.nix' '*.js' '*.mjs' '*.ts' '*.tsx' '*.css' '*.html' '*.md' \
'*.yml' '*.yaml' \
| xargs -0 -r grep -nE "$pattern" /dev/null 2>/dev/null \
| grep -v 'lint:allow' || true
)"
if [ -n "$hits" ]; then
echo "$hits" | while IFS=: read -r file lineno _; do
printf '::error file=%s,line=%s::tracker reference — write prose that stands on its own, not a hash-number tag or a full issue URL (see /knowledge/hive-rules.md)\n' "$file" "$lineno"
done
count="$(printf '%s\n' "$hits" | wc -l | tr -d ' ')"
printf 'check-issue-refs: %s tracker reference(s) found\n' "$count" >&2
exit 1
fi
exit 0