diff --git a/merge-check.sh b/merge-check.sh index 22a189c..c6e04de 100644 --- a/merge-check.sh +++ b/merge-check.sh @@ -1,28 +1,33 @@ #!/bin/sh # mesh-check-toolchain: typescript +# mesh-check-also: go replays/merge-check.sh # # The lab's own check (novox/hq ADR 0237 as amended): the second layer of a pull request's merge check, -# `mesh/repo-check`, run by the build seat in the mesh's TypeScript toolchain — and by hand. +# `mesh/repo-check`, run by the build seat — and by hand. # # The mesh builds no module from the lab, so no gate runs for its pull requests (`mesh/merge-gate` says the -# change touches no module of the graph); this is all that is checked before a change to it merges: +# change touches no module of the graph); this is all that is checked before a change to it merges. The lab +# is in two languages, and each part runs in its own toolchain's container (novox/hq issue 302): # -# 1. installed from the lock file, and type-checked, sources and tests; -# 2. the unit suite. +# - this script, in the TypeScript toolchain: installed from the lock file, type-checked, sources and +# tests, and the unit suite; +# - replays/merge-check.sh, in the Go toolchain, declared on the line above: the replays register and its +# prover formatted, vetted and compiled, and the register's own tests. # # **Said, never passed silently**: the integration suite raises a lab on a workstation, and the replays -# (replays/, Go) raise containers through the container runtime — neither is given to code nobody has -# approved, and this toolchain holds no Go compiler. The replays run from the lab's main, reviewed, in every -# gate of a core change; a change to them is proven by `go run ./replays/cmd/prove` by hand before it merges. +# raise containers through the container runtime — neither is given to code nobody has approved. The +# replays run from the lab's main, reviewed, in every gate of a core change; a change to them is proven by +# `go run ./replays/cmd/prove` by hand before it merges. set -eu npm ci --no-audit --no-fund --loglevel=error npm run typecheck npm test +# By hand, with Go at hand, the Go part runs here too; on the build seat it runs in the Go toolchain. if command -v go >/dev/null 2>&1; then - (cd replays && test -z "$(gofmt -l .)" && go vet ./...) + sh replays/merge-check.sh else - echo "NOT CHECKED HERE: replays/ (Go) — the TypeScript toolchain holds no Go compiler" + echo "replays/ (Go) is checked by replays/merge-check.sh, which the build seat runs in the Go toolchain" fi echo "NOT RUN HERE: the integration suite and the replays — they need a lab and the container runtime" diff --git a/replays/merge-check.sh b/replays/merge-check.sh new file mode 100644 index 0000000..fe63253 --- /dev/null +++ b/replays/merge-check.sh @@ -0,0 +1,28 @@ +#!/bin/sh +# mesh-check-toolchain: go +# +# The Go part of the lab's own check (novox/hq issue 302): the replays register and its prover, run by the +# build seat in the mesh's Go toolchain, its own container, because the lab's merge-check.sh declares it +# (`# mesh-check-also: go replays/merge-check.sh`) — and by hand, from anywhere: +# `sh replays/merge-check.sh`. +# +# 1. formatted and vetted — the register, the replays and the prover compile, tests included; +# 2. the tests that need nothing but Go and git: every replay registered whole (TestEveryReplayIsWhole), +# and the bed's reading of what a change touches. +# +# **Said, never passed silently**: the replays themselves raise containers and a bus of the release the mesh +# runs; this container holds no container runtime, so they are not run here. They run from the lab's main, +# reviewed, in the gate of every core change, and a change to one is proven by `go run ./cmd/prove` before +# it merges. +set -eu +cd "$(dirname "$0")" + +unformatted=$(gofmt -l .) +if [ -n "$unformatted" ]; then + echo "not gofmt'd:" + echo "$unformatted" + exit 1 +fi +go vet ./... +go test -count=1 -run '^(TestEveryReplayIsWhole|TestTheBedProvesWhatTheChangeTouches)$' . +echo "NOT RUN HERE: the replays themselves — they raise containers, and this container holds no container runtime" diff --git a/replays/register.go b/replays/register.go index 32a6c41..e868ebb 100644 --- a/replays/register.go +++ b/replays/register.go @@ -114,6 +114,24 @@ var Register = []Replay{ Asserts: "a merge adding a module asks the build seat for it, at the branch merged into, and opens no plan", Package: "./cmd/mesh-controller", Test: "TestReplay300", Files: []string{"cmd/mesh-controller/replays_test.go"}, Home: "mesh-controller", HomeRef: "7597294ff86383c171b8bec3920b5472fbce00e9"}, + // The push a recorded build waits for, counted as a repair (2026-10-07): a test in the controller, in + // the fix's own commit, recording two such pushes as the seat's push records them. + {ID: "R301", Issue: 301, Kind: InRepository, Repository: "mesh-controller", Fix: "e92a3fe", + What: "the operator's pushes of new builds whose upgrade policy is record — the resolver, the network " + + "managers, the packet filter — were counted as repairs, and S15 wanted a healer for each cause", + Asserts: "a push that moves only recorded builds, recorded as the push records it, wants no healer " + + "however often its cause is given", + Package: "./cmd/mesh-controller", Test: "TestReplay301", Files: []string{"cmd/mesh-controller/replays_test.go"}}, + // The lab's Go replays never compiled before a lab merge (2026-10-07): the build agent ran a repository's + // check in one toolchain. Before the fix there was no part to run, so the commit before is held to fail + // by not having it. + {ID: "R302", Issue: 302, Kind: Gate, Repository: "mesh-controller", Fix: "98ef7ba", + What: "mesh-lab's replays register merged with NOT CHECKED HERE: its check ran in the TypeScript " + + "toolchain, which holds no Go compiler", + Asserts: "a repository in two languages has each declared part of its own check run in that part's " + + "toolchain, and the layer passes only when every part does", + Package: "./internal/builder", Test: "TestARepositoryInTwoLanguagesIsCheckedInBoth", + Files: []string{"internal/builder/check_test.go"}}, // Not a core incident, and the first of its kind: a module's. The crash loop was found by a person // reading the agent server's log for another reason (issue 268); research 032 measured it, and ADR // 0240 makes the node-engine judge it and the gate fail it.