Skip to content

feat(ci): make check, mirrored on GitHub Actions - #14

Merged
fredericrous merged 8 commits into
mainfrom
feat/ci
Sep 29, 2026
Merged

fredericrous merged 8 commits into
mainfrom
feat/ci

Conversation

@fredericrous

Copy link
Copy Markdown
Owner

What

The CI ADR-0017 requires, and the first live implementation-review cycle (Phase 4 of the implementation-review plan). Plan: docs/plans/2026-09-30-dotfiles-ci.md.

  • make check = tools render lint private-refs: chezmoi v2.72.1 and shellcheck v0.11.0 as release assets verified against SHA-256s in tools.env, into .tools/, never PATH; every template rendered against ci/chezmoi.toml placeholders into a temp home (run_once templates on their own, the config template too, state file kept out of the tree); shellcheck over every tracked shell script; private-refs --tree over every tracked plaintext file — names only, <path withheld> when the path matches, PRIVATE_REFS_REQUIRE_TERMS for CI, an invalid regex is a failure.
  • .github/workflows/ci.yaml: ubuntu + macos, contents: read, checkout pinned by commit, the PRIVATE_TERMS secret through env: into $RUNNER_TEMP, required on pushes and same-repo PRs, four steps named after the targets.
  • amont.conf: make check at pre-push (warm 9–10 s). README badge and paragraph. Six git helper scripts fixed (two real bugs: literal backslash-quotes to git commit, ${2:REMOVED} meant as a default).

Implementation review (F4b, live)

Round 1 approve-with-changes (52k tokens, 78 s): six findings, the first real — an invalid regex in the terms file made grep -E exit 2, read as "no match", a silent pass. All fixed; Delta approve-with-changes (31k, 30 s); one low item deliberate. The push of this branch: the hook silent, journal unconfirmed reviewed, pass file written for tree 19bd0a5e4c1d.

Verification (input → expected → actual)

  • make check on this Mac → green → green, cold 15 s, warm 9–10 s.
  • Falsifications (each restored from a copy): wrong tool version, one checksum digit, broken run_once template, broken ordinary template, unquoted-loop script, README word as a term, no terms file, REQUIRE_TERMS with no / comments-only / [unclosed file, a term only in the Application Support template (space in the path), a term matching a path → each behaved as the plan says; details in the plan's Verification.
  • git status --porcelain after make check → only intended files; chezmoi managed lists none of Makefile, tools.env, ci.
  • CI on ubuntu and macos → both green → recorded below once the runs finish; Phase 3 ticked then.

🤖 Generated with Claude Code

fredericrous and others added 8 commits September 30, 2026 00:43
The approved plan, landed as the branch's first commit
(work.plan-lives-in-the-repo). Panel: backend, platform; body-sha
f5d3133cd045.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
What shellcheck 0.11.0 finds in the tracked shell scripts, ahead of
make lint: literal backslash-quotes handed to git commit --author and
-m (the quotes ended up in the commit), a -z test on a literal that was
always false, ${2:REMOVED} that meant a default value, bashisms under a
sh shebang, and unquoted expansions. Usage text says <name> rather than
$name.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
One check target, what the workflow will run (ADR-0017,
ci.mirrors-the-local-check): tools (chezmoi v2.72.1, shellcheck v0.11.0
as release assets verified against SHA-256s in tools.env, into .tools/,
never PATH), render (every template against ci/chezmoi.toml placeholders
into a temp home, run_once templates on their own, the config template),
lint (shellcheck over every tracked shell script, NUL-safe),
private-refs
(--tree: every tracked plaintext file, names only, path withheld when it
matches, PRIVATE_REFS_REQUIRE_TERMS for CI). Makefile, tools.env and ci/
are repository machinery and join .chezmoiignore.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
.github/workflows/ci.yaml runs make check on ubuntu and macos for every
push to main and every pull request: contents: read, checkout pinned by
commit, the PRIVATE_TERMS secret through env: into $RUNNER_TEMP,
required
on a push or a same-repository pull request and left to the loud pass on
a fork's. amont.conf runs make check at pre-push (warm 10 s on this Mac,
under the 20 s ceiling). The README carries the badge and one paragraph.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
An invalid regex in the terms file made grep exit 2, which the check
read as no match: now a failure naming the file. The workflow runs the
four targets as four steps, so a red step is the target to run at home.
Status lines go to stderr; the helper scripts' usage goes there too and
exits 2; lint no longer hides a read error behind || true.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
@fredericrous
fredericrous merged commit 35f1e06 into main Sep 29, 2026
2 checks passed
@fredericrous
fredericrous deleted the feat/ci branch September 29, 2026 23:04
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant