feat(ci): make check, mirrored on GitHub Actions - #14
Merged
Merged
Conversation
The approved plan, landed as the branch's first commit (work.plan-lives-in-the-repo). Panel: backend, platform; body-sha f5d3133cd045. Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
What shellcheck 0.11.0 finds in the tracked shell scripts, ahead of
make lint: literal backslash-quotes handed to git commit --author and
-m (the quotes ended up in the commit), a -z test on a literal that was
always false, ${2:REMOVED} that meant a default value, bashisms under a
sh shebang, and unquoted expansions. Usage text says <name> rather than
$name.
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
One check target, what the workflow will run (ADR-0017, ci.mirrors-the-local-check): tools (chezmoi v2.72.1, shellcheck v0.11.0 as release assets verified against SHA-256s in tools.env, into .tools/, never PATH), render (every template against ci/chezmoi.toml placeholders into a temp home, run_once templates on their own, the config template), lint (shellcheck over every tracked shell script, NUL-safe), private-refs (--tree: every tracked plaintext file, names only, path withheld when it matches, PRIVATE_REFS_REQUIRE_TERMS for CI). Makefile, tools.env and ci/ are repository machinery and join .chezmoiignore. Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
.github/workflows/ci.yaml runs make check on ubuntu and macos for every push to main and every pull request: contents: read, checkout pinned by commit, the PRIVATE_TERMS secret through env: into $RUNNER_TEMP, required on a push or a same-repository pull request and left to the loud pass on a fork's. amont.conf runs make check at pre-push (warm 10 s on this Mac, under the 20 s ceiling). The README carries the badge and one paragraph. Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
An invalid regex in the terms file made grep exit 2, which the check read as no match: now a failure naming the file. The workflow runs the four targets as four steps, so a red step is the target to run at home. Status lines go to stderr; the helper scripts' usage goes there too and exits 2; lint no longer hides a read error behind || true. Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
What
The CI ADR-0017 requires, and the first live implementation-review cycle (Phase 4 of the implementation-review plan). Plan:
docs/plans/2026-09-30-dotfiles-ci.md.make check=tools render lint private-refs: chezmoi v2.72.1 and shellcheck v0.11.0 as release assets verified against SHA-256s intools.env, into.tools/, never PATH; every template rendered againstci/chezmoi.tomlplaceholders into a temp home (run_once templates on their own, the config template too, state file kept out of the tree); shellcheck over every tracked shell script;private-refs --treeover every tracked plaintext file — names only,<path withheld>when the path matches,PRIVATE_REFS_REQUIRE_TERMSfor CI, an invalid regex is a failure..github/workflows/ci.yaml: ubuntu + macos,contents: read, checkout pinned by commit, thePRIVATE_TERMSsecret throughenv:into$RUNNER_TEMP, required on pushes and same-repo PRs, four steps named after the targets.amont.conf:make checkat pre-push (warm 9–10 s). README badge and paragraph. Six git helper scripts fixed (two real bugs: literal backslash-quotes togit commit,${2:REMOVED}meant as a default).Implementation review (F4b, live)
Round 1 approve-with-changes (52k tokens, 78 s): six findings, the first real — an invalid regex in the terms file made
grep -Eexit 2, read as "no match", a silent pass. All fixed; Delta approve-with-changes (31k, 30 s); one low item deliberate. The push of this branch: the hook silent, journalunconfirmed reviewed, pass file written for tree19bd0a5e4c1d.Verification (input → expected → actual)
make checkon this Mac → green → green, cold 15 s, warm 9–10 s.run_oncetemplate, broken ordinary template, unquoted-loop script, README word as a term, no terms file,REQUIRE_TERMSwith no / comments-only /[unclosedfile, a term only in theApplication Supporttemplate (space in the path), a term matching a path → each behaved as the plan says; details in the plan's Verification.git status --porcelainaftermake check→ only intended files;chezmoi managedlists none ofMakefile,tools.env,ci.🤖 Generated with Claude Code