Commit d9f7431
authored
docs: realign branch-protection sources of truth with live protection (#163)
* docs: realign branch-protection sources of truth with live protection
PR #161 made `contract schema (L2)`, `curl|bash smoke`, and `old-cli
compat` run on pull_request and added them to branch protection on main,
but left the in-repo files describing the previous three-check world.
Live protection requires six contexts; the repo claimed three.
The maintainer confirmed the six-check state is intended, so the in-repo
files catch up to protection rather than the reverse. Live protection is
unchanged by this commit.
- .github/required-checks.txt: add the three missing contexts, so the
file matches `.required_status_checks.contexts` exactly.
- docs/MERGE_POLICY.md: drop the pre-merge/post-merge split, which no
longer describes anything real — every job in test.yml fires on push,
pull_request, and both dispatch events with no job-level `if:`, and
vm-e2e on push and pull_request. "Why these three" becomes "Why these
six". Adds the external-state trade-off these required checks carry,
and notes the drift sensor's blind spot: it compares the file against
workflow job names only, never against live protection, which is how
this drift went unnoticed.
- docs/HARNESS.md: the curl|bash smoke row said "push to main / dispatch"
and the L2 contract row said "CI"; both now say "every PR".
* docs: correct CI claims found by review fact-check
A fact-check of the previous commit against the actual workflows found
three wrong claims in the new text. All verified by reading the files.
- `vm-e2e` does not run on push to `main`. vm-e2e-spike.yml scopes its
push trigger to the `test/vm-e2e-speed` spike branch, so the claim
"all six run on every PR and again on push to main" was false. It is
PR-only, now stated as such.
- `curl|bash smoke` never executes `scripts/install.sh`. The job curls
`localhost:18888/testuser/test-config/install`, which mock-server.py
serves as a synthetic stub that execs the freshly built binary in
dry-run mode; no workflow references scripts/install.sh at all. The
real installer is covered in L1 by install_script_test.go, which pipes
it through `/bin/bash -s`. Both the table row (pre-existing error) and
the new "no Go test exercises it end to end" bullet were wrong.
- The network-dependency section said "three" but named two, and claimed
a GitHub API blip or yanked asset blocks all PRs. `old-cli compat`
ends its lookup with `|| true` and gates every later step on a
non-empty version, so it passes green having tested nothing. Rewritten
to name the real asymmetry: L2 blocks, cli-compat fails open.
Also corrects "fails on PRs" for the drift sensor, which is
continue-on-error, and notes its second blind spot: it only checks that
listed checks have jobs, never that required contexts are listed.1 parent b47d976 commit d9f7431
3 files changed
Lines changed: 58 additions & 25 deletions
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
10 | 10 | | |
11 | 11 | | |
12 | 12 | | |
| 13 | + | |
| 14 | + | |
| 15 | + | |
13 | 16 | | |
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
49 | 49 | | |
50 | 50 | | |
51 | 51 | | |
52 | | - | |
| 52 | + | |
53 | 53 | | |
54 | 54 | | |
55 | 55 | | |
56 | 56 | | |
57 | | - | |
| 57 | + | |
58 | 58 | | |
59 | 59 | | |
60 | 60 | | |
| |||
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
9 | 9 | | |
10 | 10 | | |
11 | 11 | | |
12 | | - | |
| 12 | + | |
13 | 13 | | |
14 | | - | |
| 14 | + | |
| 15 | + | |
| 16 | + | |
| 17 | + | |
15 | 18 | | |
16 | | - | |
17 | | - | |
18 | | - | |
| 19 | + | |
| 20 | + | |
| 21 | + | |
19 | 22 | | |
20 | 23 | | |
21 | 24 | | |
22 | 25 | | |
23 | 26 | | |
| 27 | + | |
| 28 | + | |
| 29 | + | |
24 | 30 | | |
25 | 31 | | |
26 | | - | |
27 | | - | |
28 | | - | |
29 | | - | |
30 | | - | |
31 | | - | |
32 | | - | |
33 | | - | |
34 | | - | |
35 | | - | |
36 | | - | |
37 | | - | |
38 | 32 | | |
39 | 33 | | |
40 | 34 | | |
| |||
56 | 50 | | |
57 | 51 | | |
58 | 52 | | |
59 | | - | |
| 53 | + | |
60 | 54 | | |
61 | 55 | | |
62 | 56 | | |
| |||
65 | 59 | | |
66 | 60 | | |
67 | 61 | | |
| 62 | + | |
| 63 | + | |
| 64 | + | |
| 65 | + | |
| 66 | + | |
| 67 | + | |
| 68 | + | |
| 69 | + | |
| 70 | + | |
68 | 71 | | |
69 | 72 | | |
70 | 73 | | |
71 | 74 | | |
72 | | - | |
73 | | - | |
74 | | - | |
75 | | - | |
| 75 | + | |
| 76 | + | |
| 77 | + | |
| 78 | + | |
| 79 | + | |
| 80 | + | |
| 81 | + | |
| 82 | + | |
| 83 | + | |
| 84 | + | |
| 85 | + | |
| 86 | + | |
| 87 | + | |
| 88 | + | |
| 89 | + | |
| 90 | + | |
| 91 | + | |
| 92 | + | |
| 93 | + | |
| 94 | + | |
| 95 | + | |
| 96 | + | |
| 97 | + | |
| 98 | + | |
76 | 99 | | |
77 | 100 | | |
78 | 101 | | |
79 | 102 | | |
80 | 103 | | |
81 | 104 | | |
82 | 105 | | |
83 | | - | |
| 106 | + | |
| 107 | + | |
| 108 | + | |
| 109 | + | |
| 110 | + | |
| 111 | + | |
| 112 | + | |
| 113 | + | |
84 | 114 | | |
85 | 115 | | |
86 | 116 | | |
| |||
0 commit comments