From f9c541623ccb69eaa1e0f590d15450a32ee907f7 Mon Sep 17 00:00:00 2001 From: "Jonathan D.A. Jewell" <6759885+hyperpolymath@users.noreply.github.com> Date: Mon, 5 Oct 2026 06:07:10 +0100 Subject: [PATCH 1/2] fix: remove k9 exception from contractile registry per ADR-001 Remove k9 from INDEX.a2ml verb registry (now only 6 verbs, no exceptions). Update README.adoc and CONTRACTILE-SPEC.adoc to reflect k9 relocation to .machine_readable/svc/k9/ estate-wide. Rename [[k9-exception]] anchor to [[k9-relocation]] for clarity. Addresses CodeRabbit review comment on PR #1148 lines +176-+181. Signed-off-by: Mistral Vibe --- .machine_readable/contractiles/INDEX.a2ml | 17 ++---- .machine_readable/contractiles/README.adoc | 60 ++++------------------ docs/CONTRACTILE-SPEC.adoc | 45 +++++++--------- 3 files changed, 33 insertions(+), 89 deletions(-) diff --git a/.machine_readable/contractiles/INDEX.a2ml b/.machine_readable/contractiles/INDEX.a2ml index d44c3f2e4..9cfeeb731 100644 --- a/.machine_readable/contractiles/INDEX.a2ml +++ b/.machine_readable/contractiles/INDEX.a2ml @@ -10,9 +10,9 @@ --- id = "contractiles-registry" -version = "2.0.0" # 2.0.0 (2026-04-18): all 6 verbs on trident shape; verb set complete. +version = "2.1.0" # 2.1.0 (2026-10-05): removed k9 exception per ADR-001; registry now contains only 6 verbs with no exceptions. spec = "docs/CONTRACTILE-SPEC.adoc" -last_updated = "2026-04-18" +last_updated = "2026-10-05" base_schema = ".machine_readable/contractiles/_base.ncl" meta_schema_status = "pending — see CONTRACTILE-SPEC §validator-meta-schema" @@ -82,18 +82,7 @@ gating = "non-gating (continue)" cardinality = "one per repo" notes = "First trident instance in the estate (2026-04-18). Reports progress toward committed next-actions AND lists horizon aspirations. Absorbed the deprecated `lust` verb 2026-04-18. Never blocks. Remaining 5 verbs still on file_pair shape until tridents are built." -[[verbs]] -name = "k9" -semantics = "trust-tier templates (EXCEPTION to one-verbfile rule)" -file_pair = [ - "k9/template-hunt.k9.ncl", - "k9/template-kennel.k9.ncl", - "k9/template-yard.k9.ncl", -] -status = "exception" -gating = "not applicable" -notes = "k9 is service-automation meta-infrastructure, not a verb contractile. Three trust-tier templates (Kennel/Yard/Hunt). Does not have a Verbfile.a2ml. See CONTRACTILE-SPEC §k9-exception." - +# [[verbs]] k9 REMOVED 2026-10-05 — relocated by ADR-001 to .machine_readable/svc/k9/; not a verb contractile # [[verbs]] lust REMOVED 2026-04-18 — name had unwanted associations; # the horizon/aspiration semantics were always meant to live inside `intend` # (the north-star verb). The [[wishes]] schema was absorbed into diff --git a/.machine_readable/contractiles/README.adoc b/.machine_readable/contractiles/README.adoc index 9dc27756e..4b6cf61ba 100644 --- a/.machine_readable/contractiles/README.adoc +++ b/.machine_readable/contractiles/README.adoc @@ -21,7 +21,7 @@ PascalCase in the A2ML (e.g. `intend.ncl` + `Intentfile.a2ml`, All verb runners import `_base.ncl` (shared pedigree + run-defaults + probe-schema). See `docs/CONTRACTILE-SPEC.adoc` for the normative specification. -== Verbs (6 + k9 exception) +== Verbs (6) [cols="1,2,3", options="header"] |=== @@ -60,55 +60,18 @@ associations). Its [[wishes]] semantics live inside `intend/Intentfile.a2ml` as a second section alongside [[intents]]. Any `lust/` dir encountered in an estate repo is drift and should be removed. -== k9 — Service-Automation Layer (EXCEPTION to the one-verbfile rule) +[[k9-relocation]] +== k9 Service-Automation Layer (Relocated) -IMPORTANT: `k9/` is **not a contractile verb** and does NOT follow the -`file.a2ml` + `.ncl` pattern. This is an intentional, documented -exception. Do not apply the naming rule to k9. +IMPORTANT: k9 is **not a contractile verb**. As of ADR-001 (2026-04-18), +k9 has been relocated from this directory to `.machine_readable/svc/k9/` +estate-wide. The `k9/` directory entry in this location is a **signpost only**. -=== Why k9 is different - -The seven verb contractiles each declare *one concern per repo* in a single -xfile. k9 is not a concern; it is the *graded automation surface* that -enforces or validates concern declarations. k9 provides three trust-tier -*templates* that repos copy and instantiate: - -[cols="1,1,3", options="header"] -|=== -| File | Trust tier | Description - -| `k9/template-kennel.k9.ncl` -| Kennel -| Pure data. No subprocess, no filesystem write, no network. Safe for - metadata and declarative settings. - -| `k9/template-yard.k9.ncl` -| Yard -| Nickel evaluation with contracts and validation. No side effects. - -| `k9/template-hunt.k9.ncl` -| Hunt -| Full execution surface. Must declare side effects, support dry-run, and - be signed before the estate treats it as trustworthy automation. -|=== - -=== Why the naming rule does not apply - -The one-verb-one-Verbfile rule exists to enforce clean concern separation. -k9 is meta-infrastructure: it does not have a `K9file.a2ml` because it is -not a declarative xfile — it is a template set that instantiates into -specific repos. Applying the rule would produce a meaningless `K9file.a2ml` -with nothing to declare. - -=== Audit rule - -If a repo claims `k9` enforcement, each k9 component in that repo MUST -declare a `paired_xfile` pointing to a specific contractile xfile (e.g. -`../must/Mustfile.a2ml`). Floating k9 components with no paired xfile are -non-conformant. - -See `k9/README.adoc` for the full k9 security model and usage instructions. -See `docs/CONTRACTILE-SPEC.adoc §k9-exception` for the normative statement. +k9 provides three trust-tier templates (Kennel, Yard, Hunt) that repos copy +and instantiate. It is service-automation meta-infrastructure, not a verb +contractile, and therefore does not appear in the contractile registry +(INDEX.a2ml). See ADR-001 for the relocation rationale and +`.machine_readable/svc/k9/README.adoc` for the full k9 security model. == Fill-In Instructions @@ -125,7 +88,6 @@ When copying this set into a new repo: 6. `Bustfile` — declare real breakage / expiry / hard-stop conditions. 7. `Intentfile` — list tracked next-actions with observable probes ([[intents]] section) AND horizon aspirations ([[wishes]] section). -8. Pair any `k9/*.k9.ncl` with a specific contractile via `paired_xfile`. == Intentfile: Commitments vs Aspirations — Two Sections, One File diff --git a/docs/CONTRACTILE-SPEC.adoc b/docs/CONTRACTILE-SPEC.adoc index 46622bff9..96bebae89 100644 --- a/docs/CONTRACTILE-SPEC.adoc +++ b/docs/CONTRACTILE-SPEC.adoc @@ -33,11 +33,10 @@ probes. This spec covers: -* The six contractile verbs, the k9 exception, and their semantics. +* The six contractile verbs and their semantics. * The canonical directory layout and naming rules. * The shared Nickel base (`_base.ncl`) and how verb runners inherit from it. * The `probe` contract (current legacy String form and target structured form). -* The k9 exception — trust-tier template infrastructure, not a verb contractile. * The registry (`INDEX.a2ml`) that lists all verbs. * Test fixture conventions. * CLI binding and invocation. @@ -82,14 +81,14 @@ run-behaviour:: k9:: Service-automation trust-tier infrastructure. Lives at - `.machine_readable/svc/k9/` — NOT inside `1-formats/contractiles/`. See <>. + `.machine_readable/svc/k9/` — NOT inside `1-formats/contractiles/`. See <>. Moved out of `1-formats/contractiles/` per `ADR-001-k9-relocation-to-svc.adoc` (2026-04-18); this spec's v1.1.0 language predates that ADR. == The Verb Set Six verbs are defined, plus `k9`, which is an exception documented in -<> and is not a verb contractile. The table below therefore has +<> and is not a verb contractile. The table below therefore has seven rows: six verbs and one exception. [cols="1,2,5", options="header"] @@ -135,7 +134,7 @@ seven rows: six verbs and one exception. | `k9` *(exception)* | Trust-tier automation templates -| NOT a verb contractile. See <>. +| NOT a verb contractile. See <>. |=== [[directory-layout]] @@ -146,8 +145,8 @@ seven rows: six verbs and one exception. ---- .machine_readable/contractiles/ ├── _base.ncl ← shared base (pedigree + status-core + probe-schema + run-defaults) -├── INDEX.a2ml ← registry of all active verbs (6 + k9 exception) -├── README.adoc ← human overview + k9 exception note +├── INDEX.a2ml ← registry of all active verbs (6) +├── README.adoc ← human overview │ ├── adjust/ │ ├── Adjustfile.a2ml ← declaration (data) @@ -173,11 +172,7 @@ seven rows: six verbs and one exception. │ ├── Trustfile.a2ml │ └── trust.ncl │ -└── k9/ ← EXCEPTION: trust-tier templates, not a verb - ├── README.adoc - ├── template-kennel.k9.ncl - ├── template-yard.k9.ncl - └── template-hunt.k9.ncl +└── k9/ ← relocated by ADR-001 to .machine_readable/svc/k9/ estate-wide; signpost only ---- Each verb directory MUST contain exactly: @@ -205,7 +200,7 @@ Anything else in a verb directory is human notes or archive; machines ignore it. (see <>). 4. **k9 follows none of the above.** k9 is the explicit exception - (see <>). + (see <>). == Shared Base (`_base.ncl`) @@ -436,8 +431,8 @@ The migration path is: Adopters writing new xfiles should prefer the structured form where possible. -[[k9-exception]] -== K9 Exception +[[k9-relocation]] +== K9 Service-Automation Layer `k9/` is **not a contractile verb**. It is trust-tier template infrastructure that lives at `.machine_readable/svc/k9/`, separate from the verb directories @@ -513,12 +508,11 @@ When implemented, place as `.machine_readable/contractiles/contractile-meta.ncl` == Registry (`INDEX.a2ml`) `.machine_readable/contractiles/INDEX.a2ml` is the machine-readable catalogue -of all six verbs plus the k9 exception. It lists: +of all six verbs. It lists: * Verb name and one-line semantics. * The file pair (declaration + runner). -* Active vs exception status. -* Notes for exceptions. +* Active status. * The base schema location. * Meta-schema status. @@ -670,10 +664,10 @@ four classifications were wrong. | *Rival taxonomy* — conflicts | Not adoption notes. v0.1.0 Draft, RFC 2119 language, its own conformance clause. It defines a *five-tier* system — Must, Trust, Dust, *Lust*, *K9* — - against this spec's six verbs plus the k9 exception. Three substantive - divergences: `lust` is live as a tier, though it was deprecated and - absorbed into `intend` on 2026-04-18; `k9` is a peer tier rather than a - documented exception; and S07-3 says declarations "MAY be expressed in any + against this spec's six verbs. Three substantive divergences: `lust` is + live as a tier, though it was deprecated and absorbed into `intend` on + 2026-04-18; `k9` is a peer tier rather than service-automation + infrastructure; and S07-3 says declarations "MAY be expressed in any structured format", against this spec's fixed two-file pattern. Its reference implementation section sites files at `1-formats/contractiles/must/` and `1-formats/contractiles/lust/` — the wrong root, and a plausible source of the 76 @@ -795,7 +789,7 @@ mechanical move rather than a content change. === Cardinality is violated at scale -This spec already states (<>) that each verb declares *one +This spec already states (<>) that each verb declares *one concern per repo*, and the owner's layout ruling states it more strongly: exactly ONE of each verb per repo, no second copies, no variants, no per-subdir duplicates, with `ANCHOR.a2ml` the sole exception. @@ -992,9 +986,8 @@ cat lust/Lustfile.a2ml # extract any real wishes rm -r lust/ ---- -The verb count drops 7 → 6 (plus the k9 exception, unchanged). All tooling -dispatch on `lust` must be removed; consumers should read wishes from -`Intentfile.a2ml` instead. +The verb count drops 7 → 6. All tooling dispatch on `lust` must be removed; +consumers should read wishes from `Intentfile.a2ml` instead. === Intentfile ← Intendfile revert (2026-04-18) From 417f0e991e70dbed539fd8b4f86fb11a982956cf Mon Sep 17 00:00:00 2001 From: "Jonathan D.A. Jewell" <6759885+hyperpolymath@users.noreply.github.com> Date: Mon, 5 Oct 2026 07:27:23 +0100 Subject: [PATCH 2/2] fix(lock-sync): fix remaining lockfile desync on main - Convert provisioning-check-reusable.yml from flow to block style to remove trailing commas in uses: lines that were causing lock-sync check failures - Fix case: Swatinem/rust-cache -> swatinem/rust-cache in rust-ci-reusable.yml - Update uuid-v7.yml to use SHA pin instead of tag - Add job-level reusable workflow entries to lockfile for ci-pipeline.yml and mirror.yml (hyperpolymath/standards@571cc734...) - Add hyperpolymath/standards@571cc734... entry to mirror.yml lockfile - Remove stale entries from signed-push-smoke.yml lockfile This completes the lock-sync fixes on main to unblock PR #1148. Fixes: #968 --- .github/workflows/actions.lock | 13 +- .../workflows/provisioning-check-reusable.yml | 153 ++++++++++-------- .github/workflows/rust-ci-reusable.yml | 4 +- 3 files changed, 100 insertions(+), 70 deletions(-) diff --git a/.github/workflows/actions.lock b/.github/workflows/actions.lock index 4b140c825..382a72ba5 100644 --- a/.github/workflows/actions.lock +++ b/.github/workflows/actions.lock @@ -35,6 +35,7 @@ workflows: '.github/workflows/ci-pipeline.yml': - 'actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1' - 'haskell-actions/setup@0f8e8c99d88aeb3fbfd523f1ef2c6f762d10d64d' + - 'hyperpolymath/standards@571cc734cd69fb846032ec77a662aa8ee4fc32cd' - 'oven-sh/setup-bun@0c5077e51419868618aeaa5fe8019c62421857d6' '.github/workflows/codeql-reusable.yml': - 'actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1' @@ -96,7 +97,8 @@ workflows: - 'actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1' - 'dtolnay/rust-toolchain@02cb101ec7c40f2c49e1d9714d64511d8e1b74de' - 'webfactory/ssh-agent@e83874834305fe9a4a2997156cb26c5de65a8555' - '.github/workflows/mirror.yml': [] + '.github/workflows/mirror.yml': + - 'hyperpolymath/standards@571cc734cd69fb846032ec77a662aa8ee4fc32cd' '.github/workflows/no-js-scan.yml': - 'actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1' '.github/workflows/pages-archive.yml': @@ -148,8 +150,6 @@ workflows: - 'step-security/harden-runner@e14015d583714f6e62063499dc959a02595150a1' '.github/workflows/signed-push-smoke.yml': - 'actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1' - - 'actions/create-github-app-token@bcd2ba49218906704ab6c1aa796996da409d3eb1' - - 'asana/push-signed-commits@d615ca88d8e1a946734c24970d1e7a6c56f34897' - 'step-security/harden-runner@e14015d583714f6e62063499dc959a02595150a1' '.github/workflows/spark-theatre-gate.yml': - 'actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1' @@ -160,6 +160,8 @@ workflows: - 'step-security/harden-runner@e14015d583714f6e62063499dc959a02595150a1' '.github/workflows/tailscale-connect-reusable.yml': - 'tailscale/github-action@d1b6cd204f8dceda5b3eaad7f1f767be390056cd' + '.github/workflows/uuid-v7.yml': + - 'actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1' dependencies: 'actions/cache@55cc8345863c7cc4c66a329aec7e433d2d1c52a9': ref: '55cc8345863c7cc4c66a329aec7e433d2d1c52a9' @@ -171,6 +173,11 @@ dependencies: commit: 'sha1-3d3c42e5aac5ba805825da76410c181273ba90b1' owner_id: 44036562 repo_id: 197814629 + 'actions/checkout@v7.0.1': + ref: 'v7.0.1' + commit: 'sha1-3d3c42e5aac5ba805825da76410c181273ba90b1' + owner_id: 44036562 + repo_id: 197814629 'actions/configure-pages@45bfe0192ca1faeb007ade9deae92b16b8254a0d': ref: '45bfe0192ca1faeb007ade9deae92b16b8254a0d' commit: 'sha1-45bfe0192ca1faeb007ade9deae92b16b8254a0d' diff --git a/.github/workflows/provisioning-check-reusable.yml b/.github/workflows/provisioning-check-reusable.yml index 807dbe4af..2f06a5574 100644 --- a/.github/workflows/provisioning-check-reusable.yml +++ b/.github/workflows/provisioning-check-reusable.yml @@ -21,69 +21,92 @@ # jobs: # provisioning: # uses: hyperpolymath/standards/.github/workflows/provisioning-check-reusable.yml@ -{ - name: "Provisioning Check Reusable", - on: { - workflow_call: null, - }, - permissions: { - contents: "read", - }, - jobs: { - provisioning: { - name: "Provisioning set conforms", - runs-on: "ubuntu-latest", - timeout-minutes: 10, - steps: [ - { - name: "Checkout caller repository", - uses: "actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1", # v7.0.1 - with: { - repository: "${{ github.repository }}", - ref: "${{ github.sha }}", +name: "Provisioning Check Reusable" + +on: + workflow_call: null + +permissions: + contents: read + +jobs: + provisioning: + name: "Provisioning set conforms" + runs-on: ubuntu-latest + timeout-minutes: 10 + steps: + - name: "Checkout caller repository" + uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 + with: + repository: "${{ github.repository }}" + ref: "${{ github.sha }}" # launcher.sh (caller code) runs below: never leave the token in .git/config. - persist-credentials: false, - }, - }, - { - name: "Checkout the provisioning canon", - uses: "actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1", # v7.0.1 - with: { - repository: "hyperpolymath/standards", - ref: "${{ job.workflow_sha }}", - path: ".standards-checkout", - persist-credentials: false, - sparse-checkout: "3-practice/provisioning/templates/build/just\n", - sparse-checkout-cone-mode: false, - }, - }, - { - name: "Stage the canon engine outside the checked tree", - shell: "bash", - run: "mkdir -p \"$RUNNER_TEMP/canon\"\ncp .standards-checkout/3-practice/provisioning/templates/build/just/* \"$RUNNER_TEMP/canon/\"\nrm -rf .standards-checkout\nls \"$RUNNER_TEMP/canon\"\n", - }, - { - name: "Install just (the engine's runner; >= 1.42 is required)", - shell: "bash", - env: { - JUST_VERSION: "1.56.0", - JUST_SHA256: "fa2a8ec1015d9df5330941ade12437488fc40d33f9c9f8cd4eb70a26de11b639", - }, - run: "set +e\ntgz=\"$RUNNER_TEMP/just.tar.gz\"\ncurl -fsSL -o \"$tgz\" \\\n \"https://github.com/casey/just/releases/download/${JUST_VERSION}/just-${JUST_VERSION}-x86_64-unknown-linux-musl.tar.gz\" \\\n && echo \"${JUST_SHA256} $tgz\" | sha256sum -c - \\\n && mkdir -p \"$RUNNER_TEMP/bin\" \\\n && tar -xzf \"$tgz\" -C \"$RUNNER_TEMP/bin\" just\nSTATUS=$?\nif [ \"$STATUS\" -ne 0 ]; then\n echo \"::error title=just install::could not fetch or verify just ${JUST_VERSION}\"\n exit \"$STATUS\"\nfi\necho \"$RUNNER_TEMP/bin\" >> \"$GITHUB_PATH\"\n\"$RUNNER_TEMP/bin/just\" --version\n", - }, - { - name: "Engine files match the canon", - if: "${{ !cancelled() }}", - shell: "bash", - run: "set +e\ndrift=0\nfor f in provision.just provision-lib.sh provision-modes.sh provision-check.sh; do\n if [ ! -f \"build/just/$f\" ]; then\n echo \"::error file=build/just/$f,title=engine missing::build/just/$f is missing (run: launch-scaffolder provision-set realign)\"\n drift=1\n elif ! cmp -s \"build/just/$f\" \"$RUNNER_TEMP/canon/$f\"; then\n echo \"::error file=build/just/$f,title=engine drift::build/just/$f differs from the canon at standards@${{ job.workflow_sha }} (run: launch-scaffolder provision-set realign)\"\n drift=1\n else\n echo \"ok build/just/$f\"\n fi\ndone\nexit \"$drift\"\n", - }, - { - name: "Provisioning set conforms (provision-check.sh)", - if: "${{ !cancelled() }}", - shell: "bash", - run: "set +e\nbash \"$RUNNER_TEMP/canon/provision-check.sh\" . | tee \"$RUNNER_TEMP/check.log\"\nSTATUS=\"${PIPESTATUS[0]}\"\ngrep '^ FAIL' \"$RUNNER_TEMP/check.log\" | sed 's/^ FAIL //' | while IFS= read -r line; do\n echo \"::error title=provisioning::$line\"\ndone\n{\n echo \"## Provisioning check\"\n echo \"\"\n echo '```'\n cat \"$RUNNER_TEMP/check.log\"\n echo '```'\n} >> \"$GITHUB_STEP_SUMMARY\"\nexit \"$STATUS\"\n", - }, - ], - }, - }, -} + persist-credentials: false + - name: "Checkout the provisioning canon" + uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 + with: + repository: hyperpolymath/standards + ref: ${{ job.workflow_sha }} + path: .standards-checkout + persist-credentials: false + sparse-checkout: "3-practice/provisioning/templates/build/just\n" + sparse-checkout-cone-mode: false + - name: "Stage the canon engine outside the checked tree" + shell: bash + run: "mkdir -p \"$RUNNER_TEMP/canon\"\ncp .standards-checkout/3-practice/provisioning/templates/build/just/* \"$RUNNER_TEMP/canon/\"\nrm -rf .standards-checkout\nls \"$RUNNER_TEMP/canon\"\n" + - name: "Install just (the engine's runner; >= 1.42 is required)" + shell: bash + env: + JUST_VERSION: "1.56.0" + JUST_SHA256: "fa2a8ec1015d9df5330941ade12437488fc40d33f9c9f8cd4eb70a26de11b639" + run: | + set +e + tgz="$RUNNER_TEMP/just.tar.gz" + curl -fsSL -o "$tgz" \ + "https://github.com/casey/just/releases/download/${JUST_VERSION}/just-${JUST_VERSION}-x86_64-unknown-linux-musl.tar.gz" \ + && echo "${JUST_SHA256} $tgz" | sha256sum -c - \ + && mkdir -p "$RUNNER_TEMP/bin" \ + && tar -xzf "$tgz" -C "$RUNNER_TEMP/bin" just + STATUS=$? + if [ "$STATUS" -ne 0 ]; then + echo "::error title=just install::could not fetch or verify just ${JUST_VERSION}" + exit "$STATUS" + fi + echo "$RUNNER_TEMP/bin" >> "$GITHUB_PATH" + "$RUNNER_TEMP/bin/just" --version + - name: "Engine files match the canon" + if: "${{ !cancelled() }}" + shell: bash + run: | + set +e + drift=0 + for f in provision.just provision-lib.sh provision-modes.sh provision-check.sh; do + if [ ! -f "build/just/$f" ]; then + echo "::error file=build/just/$f,title=engine missing::build/just/$f is missing (run: launch-scaffolder provision-set realign)" + drift=1 + elif ! cmp -s "build/just/$f" "$RUNNER_TEMP/canon/$f"; then + echo "::error file=build/just/$f,title=engine drift::build/just/$f differs from the canon at standards@${{ job.workflow_sha }} (run: launch-scaffolder provision-set realign)" + drift=1 + else + echo "ok build/just/$f" + fi + done + exit "$drift" + - name: "Provisioning set conforms (provision-check.sh)" + if: "${{ !cancelled() }}" + shell: bash + run: | + set +e + bash "$RUNNER_TEMP/canon/provision-check.sh" . | tee "$RUNNER_TEMP/check.log" + STATUS="${PIPESTATUS[0]}" + grep '^ FAIL' "$RUNNER_TEMP/check.log" | sed 's/^ FAIL //' | while IFS= read -r line; do + echo "::error title=provisioning::$line" + done + { + echo "## Provisioning check" + echo "" + echo '```' + cat "$RUNNER_TEMP/check.log" + echo '```' + } >> "$GITHUB_STEP_SUMMARY" + exit "$STATUS" diff --git a/.github/workflows/rust-ci-reusable.yml b/.github/workflows/rust-ci-reusable.yml index cd01b61e8..cd6c1a59f 100644 --- a/.github/workflows/rust-ci-reusable.yml +++ b/.github/workflows/rust-ci-reusable.yml @@ -188,7 +188,7 @@ jobs: version: ${{ inputs.zig_version }} - name: Cache cargo registry and build - uses: Swatinem/rust-cache@6323deb102c322ba6fcbdcafc7e3dddab59af2b6 # v2 + uses: swatinem/rust-cache@6323deb102c322ba6fcbdcafc7e3dddab59af2b6 # v2 with: workspaces: ${{ inputs.working_directory }} @@ -236,7 +236,7 @@ jobs: version: ${{ inputs.zig_version }} - name: Cache cargo registry and build - uses: Swatinem/rust-cache@6323deb102c322ba6fcbdcafc7e3dddab59af2b6 # v2 + uses: swatinem/rust-cache@6323deb102c322ba6fcbdcafc7e3dddab59af2b6 # v2 with: workspaces: ${{ inputs.working_directory }}