feat: unify installation model catalog
This commit is contained in:
@@ -1,5 +1,5 @@
|
||||
#!/usr/bin/env bash
|
||||
# Fail-closed absence gate for the supported schema-v3-only workspace runtime.
|
||||
# Fail-closed absence gate for the supported schema-v4-only workspace runtime.
|
||||
set -euo pipefail
|
||||
shopt -s nocasematch
|
||||
|
||||
@@ -31,7 +31,7 @@ Release trust anchor and order (durable entry point):
|
||||
checkout and performs an inline clean-checkout assertion before the wrapper.
|
||||
scripts/verify-schema-v3-only-release.sh then runs npm ci --ignore-scripts from the trusted
|
||||
backend/package-lock.json; clean build; npm Node verifier test; Bash regression;
|
||||
and the full schema-v3-only gate, which repeats trust checks.
|
||||
and the full schema-v4-only gate, which repeats trust checks.
|
||||
EOF
|
||||
}
|
||||
|
||||
@@ -54,7 +54,7 @@ if ! root="$(cd "$root_argument" 2>/dev/null && pwd -P)"; then
|
||||
fi
|
||||
[[ $runtime_only -eq 1 || $bootstrap_trust_only -eq 1 || "$root" == "$script_root" ]] || { echo "full mode is restricted to the canonical repository" >&2; exit 2; }
|
||||
|
||||
tmp="$(mktemp -d "${TMPDIR:-/tmp}/thoth-v3-gate.XXXXXX")"
|
||||
tmp="$(mktemp -d "${TMPDIR:-/tmp}/thoth-v4-gate.XXXXXX")"
|
||||
trap 'rm -rf "$tmp"' EXIT HUP INT TERM
|
||||
|
||||
if git_top="$(git -C "$root" rev-parse --show-toplevel 2>"$tmp/rev-parse")"; then :; else
|
||||
@@ -88,6 +88,7 @@ is_allowed_match() {
|
||||
legacy-workspace:scripts/verify-schema-v3-only.sh|legacy-workspace:scripts/test-verify-schema-v3-only.sh|legacy-workspace:backend/scripts/verify-workspace-descriptor-files.mjs|legacy-workspace:backend/scripts/verify-workspace-descriptor-files.test.mjs|legacy-workspace:backend/scripts/revision-state-policy.mjs|legacy-workspace:backend/scripts/revision-state-policy.test.mjs|legacy-workspace:backend/scripts/bash-heredoc.mjs|legacy-workspace:backend/scripts/revision_state_policy.py|legacy-workspace:backend/scripts/test_revision_state_policy.py) return 0 ;;
|
||||
migration-marker:scripts/verify-schema-v3-only.sh|migration-marker:scripts/test-verify-schema-v3-only.sh|migration-marker:backend/scripts/verify-workspace-descriptor-files.mjs|migration-marker:backend/scripts/verify-workspace-descriptor-files.test.mjs|migration-marker:backend/scripts/revision-state-policy.mjs|migration-marker:backend/scripts/revision-state-policy.test.mjs|migration-marker:backend/scripts/bash-heredoc.mjs|migration-marker:backend/scripts/revision_state_policy.py|migration-marker:backend/scripts/test_revision_state_policy.py) return 0 ;;
|
||||
migration-marker:scripts/workspace_descriptor_doc_contract.py|migration-marker:scripts/test_workspace_descriptor_doc_contract.py) return 0 ;;
|
||||
migration-marker:backend/src/workspaces/schema.ts) return 0 ;;
|
||||
migration-marker:backend/scripts/clean-dist.test.mjs) return 0 ;;
|
||||
*) return 1 ;;
|
||||
esac
|
||||
@@ -204,7 +205,7 @@ bootstrap_files=(
|
||||
)
|
||||
if [[ $bootstrap_trust_only -eq 1 ]]; then
|
||||
require_trusted_files_at "$root" "${bootstrap_files[@]}"
|
||||
echo "schema-v3-only bootstrap trust passed"
|
||||
echo "schema-v4-only bootstrap trust passed"
|
||||
exit 0
|
||||
fi
|
||||
|
||||
@@ -272,4 +273,4 @@ if [[ $runtime_only -eq 0 ]]; then
|
||||
--document "$root/docs/operations/workspaces.md"
|
||||
fi
|
||||
|
||||
echo "schema-v3-only absence gate passed"
|
||||
echo "schema-v4-only absence gate passed"
|
||||
|
||||
Reference in New Issue
Block a user