Merge pull request 'Leave the gate to the build seat; merge-check.sh checks the node-engine's own code (hq ADR 0238)' (#43) from feat/the-graph-decides-what-is-checked into main
mesh/delivery delivered

This commit was merged in pull request #43.
This commit is contained in:
2026-10-06 21:00:35 +00:00
+19 -24
View File
@@ -1,34 +1,29 @@
#!/bin/sh
# The merge check of the node-engine (novox/hq to-be 45 §9), run by the build seat on every pull request
# before it merges, beside the controller the mesh runs and the facts snapshot the controller keeps.
# mesh-check-toolchain: go
#
# 1. formatted, vetted, and the whole suite;
# 2. the merge gate **with this change's validator**: the controller the mesh runs is built with the
# validator from this tree in place of the one it vendors, and every machine of the snapshot is
# composed and validated by it. A change to the node-engine that would refuse what the mesh sends
# today fails here, naming the machine — not on the first machine it reaches.
# The node-engine's own check (novox/hq ADR 0237 as amended): the second layer of a pull request's merge
# check, `mesh/repo-check`, run by the build seat in the mesh's Go toolchain — and by hand.
#
# The gate — the controller the mesh runs, built with THIS change's validator in place of the one it
# vendors, composing and validating every machine of the facts snapshot — is the build seat's first layer
# (`mesh/merge-gate`), run because the mesh's module graph builds `mesh-host` from this repository and
# judged so because it does. It is not repeated here. This is the code's own quality and its suite:
# formatted, vetted, and every test, under the race detector when the toolchain has a C compiler.
#
# Exit 0 is a pass; anything else fails `mesh/repo-check` with the last line printed.
set -eu
unformatted=$(gofmt -l .)
if [ -n "$unformatted" ]; then
echo "not gofmt'd:"
echo "$unformatted"
exit 1
fi
go vet ./...
go test -count=1 ./...
CGO_ENABLED=0 go vet ./...
beside="${MESH_CHECK_BESIDE:?the controller the mesh runs is cloned beside this check}"
judge_tree="$beside/mesh-controller"
[ -f "$judge_tree/cmd/mesh-controller/merge_gate.go" ] || judge_tree="$beside/mesh-controller-main"
vendored="$judge_tree/vendor/github.com/novox/mesh-host"
for pkg in validate internal/declaration; do
rm -f "$vendored/$pkg"/*.go
for f in "$pkg"/*.go; do
case "$f" in *_test.go) ;; *) cp "$f" "$vendored/$pkg/" ;; esac
done
done
judge="$beside/bin/judge-with-this-validator"
(cd "$judge_tree" && CGO_ENABLED=0 GOFLAGS=-mod=vendor GOPROXY=off go build -o "$judge" ./cmd/mesh-controller)
"$judge" merge-gate --facts "$MESH_FACTS" --store "$MESH_GATE_POSTGRES" \
--repository "${MESH_CHECK_REPOSITORY:-novox/mesh-host}" --tree . \
--changed "${MESH_CHECK_CHANGED:-}" --json > "${MESH_CHECK_VERDICT:-/dev/null}"
if command -v gcc >/dev/null 2>&1; then
CGO_ENABLED=1 go test -race -count=1 ./...
else
echo "NOT RACE-CHECKED: the toolchain holds no C compiler; the suite runs without the race detector"
CGO_ENABLED=0 go test -count=1 ./...
fi