From 047482382f9d48ee0f9fae86dc3c383f549f76b0 Mon Sep 17 00:00:00 2001 From: Nils Lehnen <30603423+iderex@users.noreply.github.com> Date: Sun, 6 Sep 2026 00:03:30 +0200 Subject: [PATCH] Say that the required checks are in force, where four files put them ahead Five sites in four files reasoned from a ruleset that requires no status check and pointed at #48 for the day one would arrive. #48 closed as completed on 2026-08-24 and the ruleset requires nineteen contexts, every gate leg among them, so each sentence told a reader the opposite of the state it was describing. The one that cost the most is the comment on the dependency-review job. It said nothing depended on the job id today and that adding a `name:` would break something only after required checks arrived. That day has passed: `dependency-review` is a required context, so a `name:` there renames the check run and leaves every pull request on this board blocked with no verdict for it. The comment now says so, and the count and the names are derived by a command rather than written down where they would drift again. gate-parity.md keeps its dated readings and its derivation commands and stops calling the widening unsettled; what is genuinely unsettled there is restated, which is that nothing in this tree reads a ruleset, so neither that file nor any check here notices the day the two disagree again. Closes #169. Signed-off-by: Nils Lehnen <30603423+iderex@users.noreply.github.com> --- .github/workflows/dependency-review.yml | 20 +++++++++++++++----- .github/workflows/gate.yml | 5 +++-- decisions/gate-parity.md | 20 +++++++++++++------- internal/gate/gate.go | 4 +++- 4 files changed, 34 insertions(+), 15 deletions(-) diff --git a/.github/workflows/dependency-review.yml b/.github/workflows/dependency-review.yml index 31d132b..724bd28 100644 --- a/.github/workflows/dependency-review.yml +++ b/.github/workflows/dependency-review.yml @@ -14,11 +14,21 @@ concurrency: jobs: # No `name:` on this job, so the check run is called by the job id - # ("dependency-review"). Nothing depends on that spelling today: the one ruleset - # on this repository is called "gate" and requires no status check of any kind. - # #48 is where required checks arrive. After that, adding a `name:` here renames - # the check run and silently breaks whatever names it, and this comment becomes - # the warning it currently only looks like. + # ("dependency-review"), and that spelling is the required context on main. + # Adding a `name:` here renames the check run, the required context is then + # reported by nothing, and every pull request on this board sits blocked + # carrying no verdict for it rather than a red one - which is the same silence + # the catalogue request sits in and takes just as long to recognise. + # + # THIS COMMENT SAID THE OPPOSITE UNTIL THE REQUIREMENT ARRIVED. It said the + # ruleset required no status check of any kind, that #48 was where required + # checks would arrive, and that this paragraph was a warning only in + # appearance. #48 closed as completed on 2026-08-24 and the requirement is in + # force, so the paragraph is the warning it used to describe. The count and + # the names move, so they are derived rather than written here: + # + # gh api repos/Flowfin/hub/rules/branches/main # --jq '.[] | select(.type=="required_status_checks") + # | .parameters.required_status_checks[].context' dependency-review: runs-on: ubuntu-latest timeout-minutes: 10 diff --git a/.github/workflows/gate.yml b/.github/workflows/gate.yml index e672a1a..a1f6adf 100644 --- a/.github/workflows/gate.yml +++ b/.github/workflows/gate.yml @@ -6,8 +6,9 @@ # step below is `go run . gate `, so what the job checks and what the shell # checks cannot drift apart. # -# The job names are what a pull request shows and what the ruleset in #48 would -# require, so they carry a prefix. The bare words build, deploy and +# The job names are what a pull request shows and what the ruleset on main +# requires - every leg here is a required context today - so they carry a +# prefix. The bare words build, deploy and # report-build-status are already in use on main by the Pages deployment, which # has no file in this tree. internal/gate.JobNamePrefix holds the prefix and the # suite refuses a leg with no job here and a job here with no leg. diff --git a/decisions/gate-parity.md b/decisions/gate-parity.md index 839a9a0..5a4ed0c 100644 --- a/decisions/gate-parity.md +++ b/decisions/gate-parity.md @@ -67,8 +67,12 @@ side does: The left side is the workflow's job names, and it cannot disagree with the leg list: `internal/gate`'s suite refuses a leg with no job and a job with no leg. -Widening the required set is #48 and is not done here; recording that the gap -exists is. +Widening the required set was #48, which closed as completed on 2026-08-24, and +the command above printed nothing on 2026-09-05: every leg this workflow declares +is a required name today. That is a reading of one day and not a property of the +tree, because nothing here adds a name to a ruleset and nothing here reads one +back, so a leg landing tomorrow reopens the gap in silence. Run the command +rather than trusting this paragraph. ## The legs, one line each @@ -266,8 +270,10 @@ gate's own report says on every run that none of them ran. ## What is not settled here -Which of these becomes a required name on `main` is #48. This document says what -each leg is; a ruleset is what makes one block, and nothing in this tree can read -a ruleset. The list above was derived by running the commands at the top on -2026-08-09. Run them again the next time somebody needs the list; what they -print then is the answer. +Which of these becomes a required name on `main` was #48 and is answered: on +2026-09-05 every leg was required. What is not settled is the half that outlasts +the answer. This document says what each leg is; a ruleset is what makes one +block, and nothing in this tree can read a ruleset, so neither this file nor any +check here notices the day the two disagree again. The list above was derived by +running the commands at the top on 2026-08-09. Run them again the next time +somebody needs the list; what they print then is the answer. diff --git a/internal/gate/gate.go b/internal/gate/gate.go index b7ce7e6..ca4374b 100644 --- a/internal/gate/gate.go +++ b/internal/gate/gate.go @@ -63,7 +63,9 @@ type Leg struct { // gh api repos/Flowfin/hub/actions/workflows --jq '.workflows[] | "\(.name)\t\(.path)"' // // A leg named build would therefore report under a name this tree does not -// control, and the ruleset in #48 would require that one instead of this one. +// control, and the ruleset on main would require that one instead of this one. +// That ruleset requires every leg here by its prefixed name, so the collision +// is a live one rather than one waiting for a requirement to arrive. const JobNamePrefix = "Gate: " // CheckRunName is the name the leg's job reports under.