The controller now decides what a pull request's check runs from the mesh's module graph, so the announcement carries the changed directories that hold a module at the head and whether the head has a merge-check.sh. A verdict sets mesh/merge-gate (the gate, with the modules it judged) and mesh/repo-check (the repository's own tests). gitea_branch_protection_get/set let the operator's agent make those statuses required. The catalogue's merge-check.sh leaves the gate to the build seat and keeps its own layer: every manifest through module check, and the touched Go modules' tests.
50 lines
2.3 KiB
Bash
Executable File
50 lines
2.3 KiB
Bash
Executable File
#!/bin/sh
|
|
# mesh-check-toolchain: go
|
|
#
|
|
# The catalogue's own check (novox/hq ADR 0237 as amended): the second layer of a pull request's merge
|
|
# check, `mesh/repo-check`, run by the build seat in the mesh's Go toolchain.
|
|
#
|
|
# The gate — the manifests the change touches through the running controller's module check, every machine
|
|
# of the facts snapshot composed with them and validated by the node-engine's own validator, the replays
|
|
# against this tree — is the build seat's first layer (`mesh/merge-gate`), run because the mesh's module
|
|
# graph builds these modules from here. It is not repeated here. This is the repository's own:
|
|
#
|
|
# 1. every manifest through the controller's module check, so one module's change cannot leave another
|
|
# it shares a rule with refused (MESH_GATE is the controller the mesh runs);
|
|
# 2. the Go tests of every module the change touches that has them, under the race detector when the
|
|
# toolchain has a C compiler — and a module whose dependencies cannot be fetched here, or that is
|
|
# written in TypeScript, is said as not tested, never passed silently.
|
|
set -eu
|
|
|
|
if [ -n "${MESH_GATE:-}" ]; then
|
|
"$MESH_GATE" module check modules/*/module.json > /dev/null
|
|
else
|
|
echo "NOT CHECKED: no controller was built beside this check, so the manifests were not read by one"
|
|
fi
|
|
|
|
race=""
|
|
if command -v gcc >/dev/null 2>&1; then race="-race"; else echo "NOT RACE-CHECKED: the toolchain holds no C compiler"; fi
|
|
|
|
touched=$(printf '%s\n' "${MESH_CHECK_CHANGED:-}" | tr ',' '\n' | sed -n 's#^modules/\([^/]*\)/.*#\1#p' | sort -u)
|
|
for m in $touched; do
|
|
[ -d "modules/$m" ] || continue
|
|
if [ ! -f "modules/$m/go.mod" ]; then
|
|
[ -f "modules/$m/package.json" ] && echo "NOT TESTED HERE: modules/$m is TypeScript; the gate judges its manifest"
|
|
continue
|
|
fi
|
|
if ! (cd "modules/$m" && GOPRIVATE=git.novox.be go mod download >/dev/null 2>&1); then
|
|
echo "NOT TESTED: modules/$m — its dependencies cannot be fetched by the build seat"
|
|
continue
|
|
fi
|
|
echo "testing modules/$m"
|
|
unformatted=$(cd "modules/$m" && gofmt -l .)
|
|
if [ -n "$unformatted" ]; then
|
|
echo "modules/$m is not gofmt'd: $unformatted"
|
|
exit 1
|
|
fi
|
|
cgo=0
|
|
[ -n "$race" ] && cgo=1
|
|
(cd "modules/$m" && CGO_ENABLED=$cgo GOPRIVATE=git.novox.be go vet ./... &&
|
|
CGO_ENABLED=$cgo GOPRIVATE=git.novox.be go test $race -count=1 ./...)
|
|
done
|