Files
mesh-controller/merge-check.sh
T
jochen 9c714f00d6 Judge every pull request against the mesh that runs, before it merges (hq ADR 0237, to-be 45 §9)
Every check the mesh had ran after a merge, on a machine: a manifest the node-engine refused
(236), an identity a real machine's name made too long (263). merge-gate raises the mesh as the
facts snapshot says it is and the mesh with the change, each in a throwaway store through the
controller's own records, composes every machine twice and validates it with the node-engine's
validator, and fails what the change breaks, naming the machine's roles and the module - plus a
manifest the judging controller cannot read, a consumer left out of its grant, a module removed
while a machine runs it, a new module the node-engine would refuse; it warns on a wide rebuild.

The forge's new head of a pull request becomes a check the controller asks of the build seat:
the head and, beside it, the controller the mesh runs, the catalogue, the host and the lab; a
throwaway store and bus of the versions the mesh runs; the repository's merge-check.sh in the
mesh's Go toolchain with no container runtime socket; then mesh-lab's replays. The verdict is
said as checked, an error never a pass, and nothing is recorded or registered.
2026-10-06 21:11:26 +02:00

36 lines
1.6 KiB
Bash
Executable File

#!/bin/sh
# The merge check of the controller (novox/hq to-be 45 §9), run by the build seat on every pull request
# before it merges — and by hand: `MESH_FACTS=facts.json MESH_GATE_POSTGRES=… MESH_TEST_POSTGRES=…
# MESH_TEST_NATS=… sh merge-check.sh`.
#
# The build seat clones this repository with the catalogue and the host beside it (the tests read them
# there), reads the facts snapshot the controller keeps, and raises a throwaway store and bus of the
# versions the mesh runs; this says what is judged with them:
#
# 1. formatted and vetted;
# 2. the merge gate, judged by THIS change's controller: every machine of the snapshot composed with
# it and validated by the node-engine's own validator, against the mesh as it is;
# 3. the whole suite, the replays among it, against that store and that bus, one package at a time
# because the live tests share one bus's fixed names.
#
# Fails on the first that fails. The gate's verdict is written where MESH_CHECK_VERDICT says, so the
# pull request is told the gate's own words.
set -eu
export GOFLAGS=-mod=vendor GOPROXY=off CGO_ENABLED=0
unformatted=$(gofmt -l cmd internal examples)
if [ -n "$unformatted" ]; then
echo "not gofmt'd:"
echo "$unformatted"
exit 1
fi
go vet ./...
judge="${MESH_CHECK_BESIDE:-${TMPDIR:-/tmp}}/bin/judge"
go build -o "$judge" ./cmd/mesh-controller
"$judge" merge-gate --facts "$MESH_FACTS" --store "$MESH_GATE_POSTGRES" \
--repository "${MESH_CHECK_REPOSITORY:-novox/mesh-controller}" --tree . \
--changed "${MESH_CHECK_CHANGED:-}" --json > "${MESH_CHECK_VERDICT:-/dev/null}"
go test -p 1 -timeout 25m ./...