From 46a8ff39d19a58aa0a7f95dcdd5257d0263c834c Mon Sep 17 00:00:00 2001 From: igneum-labs <337424239+igneum-labs@users.noreply.github.com> Date: Wed, 7 Oct 2026 18:49:47 +0000 Subject: [PATCH] Hook: the CI rule binds a GitHub remote; a box mirror remote or a declared IGNEUM_MASTER_EXCEPTION takes the local gate, printed with the push (main's ruling, 7 October 2026, 19:5x UK: the account suspended, lanes landing on the mirror's master) Co-Authored-By: Claude Fable 5.1 --- tools/ci/pre-push.sh | 27 ++++++++++++++++++++++----- 1 file changed, 22 insertions(+), 5 deletions(-) diff --git a/tools/ci/pre-push.sh b/tools/ci/pre-push.sh index 3549091f2..7c8ddfda9 100755 --- a/tools/ci/pre-push.sh +++ b/tools/ci/pre-push.sh @@ -189,6 +189,12 @@ master_ci_ok() { # -> 0 and a line, or 1 and the reas echo " Use tools/ci/merge-to-master.sh (it pushes the branch for a run when there is none, waits for a queued run and refuses a red)." >&2 return 1 } +master_rule_binds() { # : 0 when the CI rule applies to this push (a GitHub remote, no declared exception), 1 with a printed line otherwise + local url="${1:-}" + if [ -n "${IGNEUM_MASTER_EXCEPTION:-}" ]; then echo " EXCEPTION to the CI rule for this push, declared by main: $IGNEUM_MASTER_EXCEPTION (the local gate is the verdict)"; return 1; fi + case "$url" in *github.com*) return 0 ;; esac + echo " the remote ${url:-?} is not GitHub (a mirror): the CI rule binds GitHub's master; the local gate is the verdict here"; return 1 +} branch_red_line() { # : the branch's newest completed ci run, when red, printed before the light gate (nothing on green or no gh) local line; line=$(node "$GATE_ROOT/tools/ci/ci-state.mjs" --branch-red "$1" 2>/dev/null) || return 0 case "$line" in previous\ CI\ red*) echo " $line" ;; esac @@ -261,7 +267,12 @@ FAKEGH ( cd "$fx" && PATH="$fakebin:$PATH" master_ci_ok "$M" "$B" >/dev/null 2>&1 ) && { echo "self-test failed: a merge onto another tip (its own run queued) was let through"; fails=1; } ( cd "$fx" && PATH="$fakebin:$PATH" master_ci_ok "$A" "$A" >/dev/null 2>&1 ) && { echo "self-test failed: a commit with no ci run was let through to master"; fails=1; } rm -rf "$fx" "$fakebin" - [ "$fails" = 0 ] && echo "self-test passed: a failing check is RED and fails the gate, a passing one is ok; master and release-* select the full gate, other refs the light one; a merge of a green-stamped branch onto the remote tip defers to CI, every other shape takes the full gate; master takes only a commit (or a merge's branch parent) whose own ci run is green, and refuses red, queued and unrun ones; a feature-branch push prints the branch's previous red first; a --ci site build outside GitHub Actions leaves the tree unchanged (structural checks, no-secrets, identity grep)" + # the CI rule binds a GitHub remote; a mirror remote and a declared exception take the local gate, each with a printed line + master_rule_binds https://github.com/igneum-network/igneum.git >/dev/null || { echo "self-test failed: the CI rule did not bind a GitHub remote"; fails=1; } + master_rule_binds build@188.40.146.49:/srv/igneum.git >/dev/null && { echo "self-test failed: the CI rule bound a box mirror remote"; fails=1; } + ( IGNEUM_MASTER_EXCEPTION="main, 7 Oct 2026 19:5x UK: GitHub suspended" master_rule_binds https://github.com/x/y.git >/dev/null ) && { echo "self-test failed: a declared exception did not lift the CI rule"; fails=1; } + out=$(IGNEUM_MASTER_EXCEPTION="ruling text" master_rule_binds https://github.com/x/y.git); case "$out" in *"EXCEPTION"*"ruling text"*) ;; *) echo "self-test failed: the exception was not printed with its ruling: $out"; fails=1 ;; esac + [ "$fails" = 0 ] && echo "self-test passed: a failing check is RED and fails the gate, a passing one is ok; master and release-* select the full gate, other refs the light one; a merge of a green-stamped branch onto the remote tip defers to CI, every other shape takes the full gate; master takes only a commit (or a merge's branch parent) whose own ci run is green, and refuses red, queued and unrun ones (GitHub remotes; a mirror remote or a declared exception takes the local gate, printed); a feature-branch push prints the branch's previous red first; a --ci site build outside GitHub Actions leaves the tree unchanged (structural checks, no-secrets, identity grep)" exit $fails ;; list) grep -E '^\s+run "' "$0" | sed -E 's/^\s+run "([^"]+)".*/\1/' ;; @@ -270,10 +281,16 @@ FAKEGH if [ "$which" = full ]; then # a merge of a green-stamped branch onto the exact remote tip goes through on the light gate (CI runs the full one) verdict=""; while read -r lref lsha rref rsha; do case "$rref" in refs/heads/master|refs/heads/release-*) verdict=$(deferred_merge "$lsha" "$rsha"); break ;; esac; done <<<"$REFS" - # a push to master: the pushed commit (or its branch parent) must already have a green ci run on that exact commit - while read -r lref lsha rref rsha; do - if [ "$rref" = refs/heads/master ] && [ "$lsha" != 0000000000000000000000000000000000000000 ]; then master_ci_ok "$lsha" "$rsha" || exit 1; fi - done <<<"$REFS" + # a push to master: the pushed commit (or its branch parent) must already have a green ci run on that exact commit. CI runs on + # GitHub, so the rule binds a push whose remote is github.com; a push of master to a box mirror (build@:/srv/igneum.git) + # takes the local gate as before. IGNEUM_MASTER_EXCEPTION="" lifts the CI rule for one push and is printed with + # the push (7 October 2026, 19:5x UK: the GitHub account suspended, lanes landing on the box mirror's master by main's ruling, + # the box gate stamp as the verdict; GitHub gets the fast-forward when it answers again). + if master_rule_binds "${2:-}"; then + while read -r lref lsha rref rsha; do + if [ "$rref" = refs/heads/master ] && [ "$lsha" != 0000000000000000000000000000000000000000 ]; then master_ci_ok "$lsha" "$rsha" || exit 1; fi + done <<<"$REFS" + fi case "$verdict" in defer*) echo "pre-push gate: a merge of green-stamped ${verdict#defer } onto the remote tip: the light gate here, the full gate in CI on landing:" structural_checks; never_push_checks; finish "merge of a green branch (full gate deferred to CI)" ;;