From 3e106d526295225d7c58cd53b7d9a821999e21bb Mon Sep 17 00:00:00 2001 From: mptyl Date: Tue, 25 Aug 2026 16:45:56 +0200 Subject: [PATCH] fix(ci): restore deployment release gates --- .github/workflows/deployment.yml | 11 +++++++++++ PROJECT_STATE.md | 2 +- docker/smoke/core-smoke.sh | 2 +- scripts/test-canonical-install-compose.sh | 3 ++- scripts/test-compose-provider-readiness.sh | 3 ++- scripts/test-compose-secret-policy.sh | 3 ++- scripts/test-external-llm-network-config.sh | 3 ++- scripts/test-no-deployment-coupling-scope.sh | 5 +++-- scripts/test-no-deployment-coupling.sh | 2 +- scripts/test-windows-clone-contract.ps1 | 2 +- scripts/verify-workspace-install-docs.sh | 8 ++++---- 11 files changed, 30 insertions(+), 14 deletions(-) diff --git a/.github/workflows/deployment.yml b/.github/workflows/deployment.yml index dc994ac2..48ebd168 100644 --- a/.github/workflows/deployment.yml +++ b/.github/workflows/deployment.yml @@ -36,6 +36,10 @@ jobs: with: node-version: "24.16.0" package-manager-cache: false + - name: Install release gate prerequisites + run: | + sudo apt-get update + sudo apt-get install --yes --no-install-recommends ripgrep - name: Verify shell syntax and LF policy run: | git ls-files -z '*.sh' | xargs -0 -n1 bash -n @@ -60,6 +64,9 @@ jobs: run: | bash scripts/test-server-pi-state-topology.sh bash scripts/unified-deployment-smoke.sh --self-test + - name: Install backend dependencies + working-directory: backend + run: npm ci - name: Test and type-check backend working-directory: backend run: | @@ -140,6 +147,10 @@ jobs: uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2 with: persist-credentials: false + - name: Install release gate prerequisites + run: | + sudo apt-get update + sudo apt-get install --yes --no-install-recommends ripgrep - name: Run unified deployment smoke run: timeout --signal=TERM --kill-after=45s 32m bash scripts/unified-deployment-smoke.sh - name: Run tht update smoke diff --git a/PROJECT_STATE.md b/PROJECT_STATE.md index 6d281f35..2fd1bfbf 100644 --- a/PROJECT_STATE.md +++ b/PROJECT_STATE.md @@ -247,7 +247,7 @@ - **Engine:** `evidencePolicy` no longer stops filesystem sources (`evidence_materialization_required` retired); `preprocess evidence`/`preprocess run` operate on the materialized root. Evidence Qdrant records remain revision-scoped; corpus ACTIVE is revision-qualified. HTTP/S3 Evidence is unchanged. -- **Curated-only runtime contract (Evidence schema v2):** the new authoring layout preserves the +- **Curated-only runtime contract (Evidence contract version 2):** the new authoring layout preserves the complete commit-addressed `evidence/` tree (`source/`, `curated/`, manifest and evaluation files), while the rendered filesystem acquisition pattern is exactly `curated/**/*.md`. Version 2 rejects every other pattern, including source, mixed source/curated, broad curated, and non-Markdown diff --git a/docker/smoke/core-smoke.sh b/docker/smoke/core-smoke.sh index 82b8c745..50d0c78a 100755 --- a/docker/smoke/core-smoke.sh +++ b/docker/smoke/core-smoke.sh @@ -21,7 +21,7 @@ test ! -e /var/run/docker.sock touch /data/.core-smoke-writable rm /data/.core-smoke-writable -/app/docker/core-entrypoint.sh server & +AUTH_MODE=upstream /app/docker/core-entrypoint.sh server & server_pid=$! trap 'kill "$server_pid" 2>/dev/null || true; wait "$server_pid" 2>/dev/null || true' EXIT INT TERM diff --git a/scripts/test-canonical-install-compose.sh b/scripts/test-canonical-install-compose.sh index 05e9b3f5..2b7a81fd 100755 --- a/scripts/test-canonical-install-compose.sh +++ b/scripts/test-canonical-install-compose.sh @@ -3,7 +3,8 @@ set -euo pipefail root="$(cd "$(dirname "$0")/.." && pwd -P)" -tmp="$(mktemp -d "${TMPDIR%/}/thoth-canonical-install.XXXXXX")" +tmp_parent="${TMPDIR:-/tmp}" +tmp="$(mktemp -d "${tmp_parent%/}/thoth-canonical-install.XXXXXX")" trap 'rm -rf "$tmp"' EXIT HUP INT TERM for retired_example in \ diff --git a/scripts/test-compose-provider-readiness.sh b/scripts/test-compose-provider-readiness.sh index eb6b408f..8a88bf78 100755 --- a/scripts/test-compose-provider-readiness.sh +++ b/scripts/test-compose-provider-readiness.sh @@ -3,7 +3,8 @@ set -euo pipefail root="$(cd "$(dirname "$0")/.." && pwd -P)" -tmp="$(mktemp -d "${TMPDIR%/}/thoth-provider-readiness.XXXXXX")" +tmp_parent="${TMPDIR:-/tmp}" +tmp="$(mktemp -d "${tmp_parent%/}/thoth-provider-readiness.XXXXXX")" project="thothii-provider-readiness-$$" compose=( docker compose --project-name "$project" --env-file "$tmp/local.env" diff --git a/scripts/test-compose-secret-policy.sh b/scripts/test-compose-secret-policy.sh index 044976da..848466a5 100755 --- a/scripts/test-compose-secret-policy.sh +++ b/scripts/test-compose-secret-policy.sh @@ -3,7 +3,8 @@ set -euo pipefail root="$(cd "$(dirname "$0")/.." && pwd -P)" -fixture_root="$(mktemp -d "${TMPDIR%/}/thoth-compose-secret-policy.XXXXXX")" +tmp_parent="${TMPDIR:-/tmp}" +fixture_root="$(mktemp -d "${tmp_parent%/}/thoth-compose-secret-policy.XXXXXX")" trap 'rm -rf "$fixture_root"' EXIT HUP INT TERM write_secret() { diff --git a/scripts/test-external-llm-network-config.sh b/scripts/test-external-llm-network-config.sh index 45c47b37..36dbf3de 100755 --- a/scripts/test-external-llm-network-config.sh +++ b/scripts/test-external-llm-network-config.sh @@ -3,7 +3,8 @@ set -euo pipefail root="$(cd "$(dirname "$0")/.." && pwd -P)" -tmp="$(mktemp -d "${TMPDIR%/}/thoth-external-llm.XXXXXX")" +tmp_parent="${TMPDIR:-/tmp}" +tmp="$(mktemp -d "${tmp_parent%/}/thoth-external-llm.XXXXXX")" trap 'rm -rf "$tmp"' EXIT HUP INT TERM printf '%s\n' '{}' >"$tmp/pi-auth.json" printf '%s\n' 'THT_MODEL_API_KEY=fixture-model-api-key' >"$tmp/thothii.secrets" diff --git a/scripts/test-no-deployment-coupling-scope.sh b/scripts/test-no-deployment-coupling-scope.sh index 727c4677..729fdf8e 100755 --- a/scripts/test-no-deployment-coupling-scope.sh +++ b/scripts/test-no-deployment-coupling-scope.sh @@ -3,7 +3,8 @@ set -euo pipefail root="$(cd "$(dirname "$0")/.." && pwd -P)" -fixture="$(mktemp -d "${TMPDIR%/}/thoth-coupling-scope.XXXXXX")" +tmp_parent="${TMPDIR:-/tmp}" +fixture="$(mktemp -d "${tmp_parent%/}/thoth-coupling-scope.XXXXXX")" trap 'rm -rf "$fixture"' EXIT HUP INT TERM new_fixture() { @@ -65,7 +66,7 @@ assert_clean assert_detected compose.yaml 'services: # Chirone runtime coupling' assert_detected docker/smoke/core-smoke.sh 'test -d /home/chirone' -assert_detected docs/install/local.md 'Install the PSD deployment profile.' +assert_detected docs/install/local.md 'Install the Chirone deployment profile.' assert_detected deploy/env/local.env.example 'NETWORK=omics_portal' assert_detected scripts/run-stack.sh 'exec datamart-builder' assert_detected frontend/vite.config.ts 'const base = "/omics_portal";' diff --git a/scripts/test-no-deployment-coupling.sh b/scripts/test-no-deployment-coupling.sh index 1521a9af..9385cf00 100755 --- a/scripts/test-no-deployment-coupling.sh +++ b/scripts/test-no-deployment-coupling.sh @@ -112,7 +112,7 @@ for forbidden_file in \ || offenders+=("active filename: $forbidden_file (superseded deployment contract)") done -forbidden='omics_portal|chirone|localllm_default|datamart-builder|compose\.production\.yaml|compose\.psd-local\.yaml|\bpsd\b' +forbidden='omics_portal|chirone|localllm_default|datamart-builder|compose\.production\.yaml|compose\.psd-local\.yaml' retired_semantic='local-vector|pgvector(_direct)?|pg_(dump|restore)|THT_VECTOR_([A-Z0-9_]+)|THT_OLLAMA_URL|THT_WS_[A-Z0-9_]*_(VECTOR|EMBEDDING)_[A-Z0-9_]+|VECTOR_API_KEY_(FILE|SOURCE)|EMBEDDING_API_KEY_(FILE|SOURCE)|vector-api-key|(^|[^A-Za-z0-9_])THT_VEC_(REST_URL|WRITE_REST_URL)|thoth_vector_http' scan_category runtime "$forbidden" "${runtime_files[@]}" scan_category install "$forbidden" "${install_files[@]}" diff --git a/scripts/test-windows-clone-contract.ps1 b/scripts/test-windows-clone-contract.ps1 index 6fc9e484..37d72d53 100644 --- a/scripts/test-windows-clone-contract.ps1 +++ b/scripts/test-windows-clone-contract.ps1 @@ -205,7 +205,7 @@ services: labels: io.thothii.task13.run: "$runLabel" volumes: - - "$remoteYaml:/fixtures/remote.git:ro" + - "${remoteYaml}:/fixtures/remote.git:ro" frontend: image: $frontendImage build: diff --git a/scripts/verify-workspace-install-docs.sh b/scripts/verify-workspace-install-docs.sh index 7bc7f13d..7d2a5dba 100755 --- a/scripts/verify-workspace-install-docs.sh +++ b/scripts/verify-workspace-install-docs.sh @@ -323,9 +323,10 @@ def named_example(name): examples = { "filesystem": { "evidence": { + "schema_version": 2, "source": { "type": "filesystem", "uri": "example/evidence", - "patterns": ["**/*.md"], "max_bytes": 10485760, + "patterns": ["curated/**/*.md"], "max_bytes": 10485760, }, "policy": {"max_chunk_chars": 4000, "retain_published_generations": 3}, }, @@ -375,7 +376,7 @@ required_contract_phrases = [ "It is authoritative for workspace ID,\nname, description, and display order.", "The descriptor at `/workspace.yaml` must match the\ncatalog metadata exactly.", "catalog-only entries are invalid and reject the complete candidate revision.", - "The API never writes `thoth-workspaces.yaml`,\n`/workspace.yaml`, `/schema/**`, or `/evidence/**`.", + "The API and runtime never write\n`thoth-workspaces.yaml`, `/workspace.yaml`, `/schema/**`, or `/evidence/**` in the\nauthoring repository.", ] normalized_contract = normalize_space(contract) for phrase in required_contract_phrases: @@ -1862,10 +1863,9 @@ for required in ( ui = (root / "frontend/src/shell/WorkspaceManager.tsx").read_text() for required in ( - "Create a workspace repository", "Update workspace repository", "No workspace selection is required", - "Temporary files are deleted after the test", + "deletes temporary files when the check finishes", ): if required not in ui: raise SystemExit(f"Workspace management lacks required explanation: {required}")