Check the lab's own code before it merges (hq ADR 0237)

A merge-check.sh, the repository's layer of the mesh's merge check (mesh/repo-check), in
the TypeScript toolchain: install from the lock file, type-check, the unit suite. The
integration suite and the replays need a lab and the container runtime, which unapproved
code is not given: said as not run, never passed silently.
This commit is contained in:
jochen
2026-10-06 22:06:35 +02:00
parent 8962454530
commit 6b44d7c414
+28
View File
@@ -0,0 +1,28 @@
#!/bin/sh
# mesh-check-toolchain: typescript
#
# The lab's own check (novox/hq ADR 0237 as amended): the second layer of a pull request's merge check,
# `mesh/repo-check`, run by the build seat in the mesh's TypeScript toolchain — and by hand.
#
# The mesh builds no module from the lab, so no gate runs for its pull requests (`mesh/merge-gate` says the
# change touches no module of the graph); this is all that is checked before a change to it merges:
#
# 1. installed from the lock file, and type-checked, sources and tests;
# 2. the unit suite.
#
# **Said, never passed silently**: the integration suite raises a lab on a workstation, and the replays
# (replays/, Go) raise containers through the container runtime — neither is given to code nobody has
# approved, and this toolchain holds no Go compiler. The replays run from the lab's main, reviewed, in every
# gate of a core change; a change to them is proven by `go run ./replays/cmd/prove` by hand before it merges.
set -eu
npm ci --no-audit --no-fund --loglevel=error
npm run typecheck
npm test
if command -v go >/dev/null 2>&1; then
(cd replays && test -z "$(gofmt -l .)" && go vet ./...)
else
echo "NOT CHECKED HERE: replays/ (Go) — the TypeScript toolchain holds no Go compiler"
fi
echo "NOT RUN HERE: the integration suite and the replays — they need a lab and the container runtime"