ci(gate): add sea-ref-gate to forbid regrown SEA-NNN issue refs (RIG-2804) - #717
Open
rigel-mintaka wants to merge 2 commits into
Open
ci(gate): add sea-ref-gate to forbid regrown SEA-NNN issue refs (RIG-2804)#717rigel-mintaka wants to merge 2 commits into
rigel-mintaka wants to merge 2 commits into
Conversation
…2804)
A fail-closed CI check that the compass tree carries no retired `SEA-NNN` issue
reference, keeping the RIG-2804 P1 flip from silently re-rotting — the same
pattern as orion-ref-gate and design-ledger-gate.
A sibling to orion-ref-gate, not an extension of it: that gate is deliberately
single-token ("SCOPE: orion ONLY... does not double as a general brand-token
gate"), so the SEA boundary gets its own gate rather than bloating it.
The gate matches the UPPERCASE-NUMERIC `SEA-<digits>` whole-word token —
exactly what the P1 codemod flipped, so the two are symmetric: the gate goes
green precisely when the flip is complete. It does NOT match lowercase
`sea-<n>` branch slugs or `SEA-nnn` placeholders, mirroring the codemod.
Carve-outs mirror orion-ref-gate: forks/** vendored subtrees (but not
first-party forks/README.md), the gate's own source, generated eng-docs copies,
and bun.lock. Wired into `moon run :ci` via the `ci` aggregate; never cached
(the subject is the live tracked tree).
Verified: 22 unit tests over the pure core (token match, carve-outs, grep-hit
parsing, runner exit codes); the gate runs clean on the flipped tree and trips
red (exit 1) on an injected `SEA-9999`.
Refs RIG-2804.
Co-authored-by: Matt Wilkinson <matt@rigel.build>
|
Compass engineering docs preview: https://compass-repo-rig-2804-sea-re.compass-eng-docs.pages.dev Deployed from |
… (RIG-2804) Both sea-ref-gate and orion-ref-gate scanned via `git grep ….nothrow()`, which swallowed every non-zero git exit and returned empty output — so a genuine scan malfunction (e.g. not a git work tree, git exit 128) was reported as clean/exit 0. That is fail-OPEN: the exact false-green a fail-closed gate exists to stop, and it contradicted each gate's own docstring/package.json claim of "exit 2 on scan error" (whose exit-2 branch was previously reachable only from the injected-throw unit test, never from the real scanner). Fix: inspect the git exit code. `git grep` exits 0 with matches, 1 on no match (a legitimately clean empty result), and >=2 on a real error; exit >=2 now throws, so runOnce's existing catch returns exit 2. Exit 1 stays clean. Applied identically to both sibling gates so they do not diverge (the review of the sea-ref-gate PR surfaced this as an inherited pattern from the merged orion-ref-gate; Matt ruled fix both together). Verified: both gates stay clean/exit 0 on the valid tree; run outside a git tree now exits 2 with the "cannot scan the tree" diagnosis (was exit 0 before). Both test suites green (sea 22, orion 23). Refs RIG-2804. Co-authored-by: Matt Wilkinson <matt@rigel.build>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
This PR is part of a stack containing 2 PRs:
mainA fail-closed CI check that the compass tree carries no retired
SEA-NNNissuereference, keeping the RIG-2804 P1 flip from silently re-rotting — the same
pattern as orion-ref-gate and design-ledger-gate.
A sibling to orion-ref-gate, not an extension of it: that gate is deliberately
single-token ("SCOPE: orion ONLY... does not double as a general brand-token
gate"), so the SEA boundary gets its own gate rather than bloating it.
The gate matches the UPPERCASE-NUMERIC
SEA-<digits>whole-word token —exactly what the P1 codemod flipped, so the two are symmetric: the gate goes
green precisely when the flip is complete. It does NOT match lowercase
sea-<n>branch slugs orSEA-nnnplaceholders, mirroring the codemod.Carve-outs mirror orion-ref-gate: forks/** vendored subtrees (but not
first-party forks/README.md), the gate's own source, generated eng-docs copies,
and bun.lock. Wired into
moon run :civia theciaggregate; never cached(the subject is the live tracked tree).
Verified: 22 unit tests over the pure core (token match, carve-outs, grep-hit
parsing, runner exit codes); the gate runs clean on the flipped tree and trips
red (exit 1) on an injected
SEA-9999.Refs RIG-2804.
Co-authored-by: Matt Wilkinson matt@rigel.build