diff --git a/tools/ci/pre-push.sh b/tools/ci/pre-push.sh index 1dbc47624..d401750cb 100755 --- a/tools/ci/pre-push.sh +++ b/tools/ci/pre-push.sh @@ -80,6 +80,9 @@ never_push_checks() { # A secret or an identity leak must not reach the remote on any branch; together about 20 s on the Mac. run "identity grep of the public export list and the served site" bash tools/ci/identity-check.sh run "no secret file names and no 64-hex secrets in the tree" bash -c 'bash tools/ci/no-secrets-check.sh --self-test && bash tools/ci/no-secrets-check.sh' + # the third never-push class (7 October 2026, 20:5x UK): a founder name on ANY branch, because every branch went to the public host's + # mirror and a branch green-stamped before the check existed carried one onto master through the deferred merge + run "no founder name, personal login, earlier business or personal address in any tracked text file (the pre-public scrub; self-test first, encoded list)" bash -c 'bash tools/ci/founder-strings-check.sh --self-test && bash tools/ci/founder-strings-check.sh' } tree_checks() { @@ -138,7 +141,6 @@ tree_checks() { run "hash-origin report: a known-finished day and a known-failed day" node --test tools/observer/hash-origin.test.mjs run "harness summaries never carry a raw 64-hex key (the writer's own redaction and check)" node infra/fast-time/lib/redact-keys.mjs --self-test run "docs-only pushes skip the compile-or-compute CI jobs (the changes job's classifier)" bash tools/ci/docs-only-check.sh --self-test - run "no founder name, personal login, earlier business or personal address in any tracked text file (the pre-public scrub; self-test first, encoded list)" bash -c 'bash tools/ci/founder-strings-check.sh --self-test && bash tools/ci/founder-strings-check.sh' run "the public ledger (docs/ledger-public.md) is what docs/fud-ledger.md generates: one row per item, no commit ids, times or team names (self-test first)" bash -c 'node tools/ledger/export-public.mjs --self-test && node tools/ledger/export-public.mjs --check' run "every workflow job carries timeout-minutes (site 15, changes 10, pow 60, sims 45; the hung-job class of 7 October 2026)" bash tools/ci/workflow-timeouts-check.sh --self-test run "a box or network check gets one retry before it is red (retry-once self-test)" bash tools/ci/retry-once.sh --self-test @@ -228,6 +230,7 @@ case "$MODE" in # the light gate carries the two never-push classes beside the structural checks, and the full gate runs them too declare -f never_push_checks | grep -q 'tools/ci/no-secrets-check.sh' || { echo "self-test failed: the never-push checks do not run the no-secrets check"; fails=1; } declare -f never_push_checks | grep -q 'tools/ci/identity-check.sh' || { echo "self-test failed: the never-push checks do not run the identity grep"; fails=1; } + declare -f never_push_checks | grep -q 'tools/ci/founder-strings-check.sh' || { echo "self-test failed: the never-push checks do not run the founder-strings check"; fails=1; } grep -qE '^\s+structural_checks; never_push_checks; finish "feature branch"' "$0" || { echo "self-test failed: the hook's light gate does not run the never-push checks"; fails=1; } # the green stamp and the deferral, in a fixture repository: a merge of a stamped branch onto the remote tip defers; an # unstamped branch, a stale stamp, a merge onto an older tip and a plain commit all take the full gate diff --git a/tools/ci/scroll-width-check.mjs b/tools/ci/scroll-width-check.mjs index ae0944899..00b75e928 100644 --- a/tools/ci/scroll-width-check.mjs +++ b/tools/ci/scroll-width-check.mjs @@ -1,5 +1,5 @@ #!/usr/bin/env node -// Lateral scroll (the project lead, 7 October 2026: "the website big container also has some lateral scroll movement that needs fixing"). +// Lateral scroll (the founder, 7 October 2026: "the website big container also has some lateral scroll movement that needs fixing"). // Renders every route at five widths in both themes and fails when document.documentElement.scrollWidth exceeds clientWidth: // the page itself must never scroll sideways; only a table, code or diagram may scroll inside its own overflow-x container. // On a failure it names the widest elements that run past the viewport, so the cause is fixed rather than the body clipped.