Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
7 changes: 7 additions & 0 deletions .github/workflows/actions.lock
Original file line number Diff line number Diff line change
Expand Up @@ -215,6 +215,13 @@ dependencies:
repo_id: 496012378
uses:
- 'actions/upload-artifact@bbbca2ddaa5d8feaa63e36b76fdaad77386f024f'
'asana/push-signed-commits@d615ca88d8e1a946734c24970d1e7a6c56f34897':
ref: 'v1.3'
commit: 'sha1-d615ca88d8e1a946734c24970d1e7a6c56f34897'
owner_id: 1472111
repo_id: 772313726
uses:
- 'actions/setup-python@v2'
'dtolnay/rust-toolchain@7e38f4b43b4db5c8dd498af069a4f6196df1d067':
ref: 'v1'
commit: 'sha1-7e38f4b43b4db5c8dd498af069a4f6196df1d067'
Expand Down
6 changes: 5 additions & 1 deletion .github/workflows/governance-reusable.yml
Original file line number Diff line number Diff line change
Expand Up @@ -977,7 +977,11 @@ jobs:
if [ -n "$canon" ] && [ "$f_" = "$canon" ]; then continue; fi
[ -f "$f_" ] || continue
for pat in "${pats[@]}"; do
out=$(grep -nE -e "$pat" -- "$f_" 2>"$err"); rc=$?
# The step runs under `bash -e`: a bare `out=$(grep …)` that matches nothing
# returns 1 and kills the step silently before rc is read. `|| rc=$?` keeps
# the status without tripping -e.
rc=0
out=$(grep -nE -e "$pat" -- "$f_" 2>"$err") || rc=$?
if [ "$rc" -eq 0 ]; then
while IFS= read -r line; do
echo "::error file=$f_,line=${line%%:*}::[R5:$rid] ${line#*:} → route to ${canon:-drop or move to a canonical source}"
Expand Down
80 changes: 80 additions & 0 deletions tests/test_governance_r5_bash_e.sh
Original file line number Diff line number Diff line change
@@ -0,0 +1,80 @@
#!/usr/bin/env bash
# SPDX-License-Identifier: MPL-2.0
# SPDX-FileCopyrightText: 2026 Jonathan D.A. Jewell
#
# test_governance_r5_bash_e.sh — runs the R5 canonical-reference drift step of
# .github/workflows/governance-reusable.yml exactly as a runner does: the step's
# `run:` text, extracted with yq, under `bash -e` (a step with no `shell:` runs
# as `bash -e {0}` on ubuntu runners).
#
# Regression: under `-e`, `out=$(grep …)` on an include file with no match
# returned 1 and aborted the step before `rc=$?` — exit 1, no output, no
# annotation. echidna#410 went red on clean content. The planted-hit cases are
# the positive control: a real drift must still fail and name the line.
#
# Run: bash tests/test_governance_r5_bash_e.sh
set -uo pipefail
ROOT="$(cd "$(dirname "$0")/.." && pwd)"
F="$ROOT/.github/workflows/governance-reusable.yml"
STEP='Canonical-reference drift (R5 generic)'
WORK="$(mktemp -d)"
trap 'rm -rf "$WORK"' EXIT
pass=0; fail=0

# Print the R5 step's run: text; fail the suite if the step cannot be found.
extract_step() {

Check warning on line 25 in tests/test_governance_r5_bash_e.sh

View check run for this annotation

SonarQubeCloud / SonarCloud Code Analysis

Add an explicit return statement at the end of the function.

See more on https://sonarcloud.io/project/issues?id=hyperpolymath_standards&issues=AaERd-yMEqfx0cnctt4X&open=AaERd-yMEqfx0cnctt4X&pullRequest=1163
yq -r ".jobs.\"security-policy\".steps[] | select(.name == \"$STEP\") | .run" "$F"
}

# Build a fixture repo in $1 with one rule over the given include files.
# Remaining args are "path:content" pairs written into the fixture.
make_fixture() {

Check warning on line 31 in tests/test_governance_r5_bash_e.sh

View check run for this annotation

SonarQubeCloud / SonarCloud Code Analysis

Add an explicit return statement at the end of the function.

See more on https://sonarcloud.io/project/issues?id=hyperpolymath_standards&issues=AaERd-yMEqfx0cnctt4Y&open=AaERd-yMEqfx0cnctt4Y&pullRequest=1163
local dir="$1"; shift
mkdir -p "$dir/.github/canonical-references"
cat > "$dir/.github/canonical-references/drift.yml" <<'RULE'
id: test-drift
description: planted drift marker
canonical_pointer: CANON.md
patterns:
- "DRIFT_MARKER_[0-9]+"
scope:
include: [a.md, b.md]
RULE
local pair
for pair in "$@"; do printf '%s\n' "${pair#*:}" > "$dir/${pair%%:*}"; done
}

# assert <label> <want-exit> <needle> <fixture-dir>: run the step under bash -e.
assert() {
local label="$1" want="$2" needle="$3" dir="$4" out status
out="$(cd "$dir" && bash -e "$WORK/r5.sh" 2>&1)"; status=$?
if [ "$status" != "$want" ]; then

Check failure on line 51 in tests/test_governance_r5_bash_e.sh

View check run for this annotation

SonarQubeCloud / SonarCloud Code Analysis

Use '[[' instead of '[' for conditional tests. The '[[' construct is safer and more feature-rich.

See more on https://sonarcloud.io/project/issues?id=hyperpolymath_standards&issues=AaERd-yMEqfx0cnctt4Z&open=AaERd-yMEqfx0cnctt4Z&pullRequest=1163
echo "FAIL: $label — expected exit $want, got $status; output: $(printf '%s' "$out" | head -3 | tr '\n' '|')"
fail=$((fail + 1)); return
fi
if ! printf '%s' "$out" | grep -qF -- "$needle"; then
echo "FAIL: $label — output lacks '$needle'; output: $(printf '%s' "$out" | head -3 | tr '\n' '|')"
fail=$((fail + 1)); return
fi
echo "PASS: $label"; pass=$((pass + 1))
}

extract_step > "$WORK/r5.sh"
if [ ! -s "$WORK/r5.sh" ] || [ "$(head -c 4 "$WORK/r5.sh")" = "null" ]; then

Check failure on line 63 in tests/test_governance_r5_bash_e.sh

View check run for this annotation

SonarQubeCloud / SonarCloud Code Analysis

Use '[[' instead of '[' for conditional tests. The '[[' construct is safer and more feature-rich.

See more on https://sonarcloud.io/project/issues?id=hyperpolymath_standards&issues=AaERd-yMEqfx0cnctt4a&open=AaERd-yMEqfx0cnctt4a&pullRequest=1163

Check failure on line 63 in tests/test_governance_r5_bash_e.sh

View check run for this annotation

SonarQubeCloud / SonarCloud Code Analysis

Use '[[' instead of '[' for conditional tests. The '[[' construct is safer and more feature-rich.

See more on https://sonarcloud.io/project/issues?id=hyperpolymath_standards&issues=AaERd-yMEqfx0cnctt4b&open=AaERd-yMEqfx0cnctt4b&pullRequest=1163
echo "FAIL: step '$STEP' not found in security-policy"; exit 1
fi

make_fixture "$WORK/clean" "a.md:nothing to see" "b.md:still nothing"
assert "no match in any include file passes" 0 "clean across 1 rule(s)" "$WORK/clean"

make_fixture "$WORK/hit" "a.md:nothing here" "b.md:see DRIFT_MARKER_42 here"
assert "hit after a no-match file still fails" 1 "::error file=b.md,line=1::[R5:test-drift]" "$WORK/hit"

make_fixture "$WORK/first" "a.md:DRIFT_MARKER_7 first" "b.md:nothing"
assert "hit in the first file fails" 1 "❌ [R5] 1 canonical-reference drift hit(s)" "$WORK/first"

mkdir -p "$WORK/optout"
assert "repo without the directory is skipped" 0 "skipped (repo has not opted in)" "$WORK/optout"

echo "R5 bash -e: $pass passed, $fail failed"
[ "$fail" -eq 0 ]

Check failure on line 80 in tests/test_governance_r5_bash_e.sh

View check run for this annotation

SonarQubeCloud / SonarCloud Code Analysis

Use '[[' instead of '[' for conditional tests. The '[[' construct is safer and more feature-rich.

See more on https://sonarcloud.io/project/issues?id=hyperpolymath_standards&issues=AaERd-yMEqfx0cnctt4c&open=AaERd-yMEqfx0cnctt4c&pullRequest=1163
Loading