From abfaba4615636249df6f48720af13aab120b231f Mon Sep 17 00:00:00 2001 From: SimonTaurus Date: Mon, 24 Aug 2026 05:29:40 +0200 Subject: [PATCH] ci: validate with oold-python against this working tree - make validate runs oold validate + oold compliance with --meta . - --meta . reads the meta-schemas and catalogue from the checkout, so a rule added in a branch is enforced by the run that introduces it; a released version cannot see it - scripts/validate.mjs is frozen, not deleted: still runnable via make validate-reference, and still the target of oold-python's parity suite - node is no longer installed in CI --- .github/workflows/main.yml | 11 ++++++----- Makefile | 19 ++++++++++++++++--- 2 files changed, 22 insertions(+), 8 deletions(-) diff --git a/.github/workflows/main.yml b/.github/workflows/main.yml index 64ef01b..0653e51 100644 --- a/.github/workflows/main.yml +++ b/.github/workflows/main.yml @@ -20,12 +20,13 @@ jobs: - uses: actions/checkout@v4 with: fetch-depth: 0 # full history + tags so render_spec.py can derive the spec version - - uses: actions/setup-node@v4 - with: - node-version: "20" - uses: astral-sh/setup-uv@v6 - - run: npm install - - run: npm run validate + # Validation runs on oold-python. --meta . reads the meta-schemas and the rule + # catalogue from THIS checkout, so a rule added in this branch is enforced by the + # run that introduces it; a released version could not see it. Node is no longer + # installed here: scripts/validate.mjs is frozen as the reference oold-python is + # compared against, and is run by that comparison rather than by this workflow. + - run: make validate # Re-render the spec and fail if the committed docs/spec/index.html is stale # (drift guard), then lint its structure. Renderer deps are pinned inline # via PEP 723, so `uv run` stays reproducible. diff --git a/Makefile b/Makefile index 2bb24ac..6d2b3e2 100644 --- a/Makefile +++ b/Makefile @@ -9,8 +9,16 @@ ZENSICAL := uvx --with pyyaml==6.0.2 zensical@$(ZENSICAL_VERSION) # pinned inline in the script (PEP 723), so `uv run` needs no extra flags and the # generated HTML stays reproducible (the CI drift guard compares byte-for-byte). -# Node runs only the schema validator. Override when `node` is not on PATH -# (e.g. WSL with only a Windows install): make validate NODE="/c/.../node.exe" +# Validation runs on oold-python, the reference implementation this specification is +# developed against. Pinned so a validator release cannot change what CI means without a +# commit here. --meta . points it at THIS working tree rather than a released tag, so a +# rule added in a branch is enforced by the run that introduces it. +OOLD_VERSION ?= 0.18.0 +OOLD := uv run --with "oold[validation]==$(OOLD_VERSION)" oold + +# scripts/validate.mjs is frozen: kept runnable as the reference the Python port is +# compared against (oold-python's parity suite), but no longer what CI runs. Override +# when `node` is not on PATH: make validate-reference NODE="/c/.../node.exe" NODE ?= node .PHONY: install @@ -18,7 +26,12 @@ install: ## Install the Node dependencies (schema validation) @npm install .PHONY: validate -validate: ## Validate example schemas + instances (meta-schema, formats, JSON-LD) +validate: ## Validate example schemas + instances against this working tree's meta-schemas + @$(OOLD) validate examples --meta . --offline + @$(OOLD) compliance examples/compliance --meta . --offline + +.PHONY: validate-reference +validate-reference: ## Run the frozen JS reference validator (not run by CI) @"$(NODE)" scripts/validate.mjs .PHONY: spec