Skip to content

Commit a780179

Browse files
claude[bot]claude
andauthored
fix(ci): ask cut-rc whether the objectui pin is ON main, instead of whether the object exists (#10494)
`cut-rc.yml`'s objectui clone step asserted that the pin "is not reachable from main (unmerged branch, or main was rewritten)" on the strength of `git cat-file -e` — an object-presence test that cannot see either case it named. A full `--no-tags` clone fetches every branch head, so presence is satisfied by any commit on any objectui branch: measured 2026-08-21, 291 commits across 118 branch tips are present and not reachable from main, and the old guard passed every one of them. Presence stays as its own question and keeps its own message, and the reachability question it was standing in for is now asked directly with `merge-base --is-ancestor` against origin/main. A third exit covers a clone with no origin/main, so "cannot be answered" can never print as "the pin left main". The success line states what the two tests established and nothing more. The full clone is what OPENS this gap rather than closing it, and that, plus bump-objectui.sh pinning `git rev-parse HEAD` without asking which branch that is, is recorded in the block itself. Claude-Session: https://claude.ai/code/session_01DdCnBGcHeufjrq7drTD3wt Co-authored-by: Claude <noreply@anthropic.com>
1 parent 7f8b360 commit a780179

1 file changed

Lines changed: 37 additions & 8 deletions

File tree

‎.github/workflows/cut-rc.yml‎

Lines changed: 37 additions & 8 deletions
Original file line numberDiff line numberDiff line change
@@ -272,9 +272,11 @@ jobs:
272272
OBJECTUI_ROOT="${RUNNER_TEMP}/objectui"
273273
# FULL clone, not shallow, and still a measured requirement rather than
274274
# caution. Two reasons, both surviving #10134:
275-
# - the check below asks whether the PIN is a real, reachable commit
276-
# of objectui main; a tip-only shallow clone cannot answer that and
277-
# would answer "no" for every pin older than the tip;
275+
# - the check below asks whether the PIN is reachable from objectui
276+
# main; a tip-only shallow clone cannot answer that and would answer
277+
# "no" for every pin older than the tip. Necessary, not sufficient:
278+
# a full clone carries every branch, main's and otherwise, so it
279+
# makes the question answerable without answering it;
278280
# - build-console.sh builds from THIS clone (it honours
279281
# $OBJECTUI_ROOT) by adding a worktree at the pin, which needs the
280282
# pin's tree present.
@@ -284,14 +286,41 @@ jobs:
284286
git clone --no-tags https://github.com/objectstack-ai/objectui.git "$OBJECTUI_ROOT"
285287
echo "OBJECTUI_ROOT=${OBJECTUI_ROOT}" >> "$GITHUB_ENV"
286288
287-
# The pin must be IN the clone. Still a real failure mode, and the only
288-
# objectui-side one left: a pin taken from a branch that never merged,
289-
# or a main that was rewritten, names a revision nobody can resolve
290-
# later — and the cut would publish a console built from it.
289+
# THE PIN MUST BE ON objectui MAIN — WHICH IS NOT WHAT OBJECT PRESENCE
290+
# ANSWERS (#9450). This was one `cat-file -e`, and the sentence it
291+
# printed on failure — "not reachable from main (unmerged branch, or
292+
# main was rewritten)" — named a case the test cannot see. Measured on
293+
# a fresh `--no-tags` clone of objectui, 2026-08-21: 291 commits across
294+
# 118 branch tips are present and NOT reachable from main, and
295+
# `cat-file -e` says yes to every one of them — including the "branch
296+
# that never merged" the message claimed to catch. The clone being FULL
297+
# is what OPENS that gap rather than closing it: `git clone` fetches
298+
# every branch head, so the more complete the clone, the more non-main
299+
# revisions it can vouch for.
300+
#
301+
# Nothing upstream closes it either — bump-objectui.sh pins
302+
# `git rev-parse HEAD` of a local objectui checkout without asking which
303+
# branch that is. "The operator happened to be on main" is the whole of
304+
# the protection, so ask the question here rather than assume it.
305+
#
306+
# Three questions, three exits, in this order because the later ones
307+
# cannot be asked until the earlier ones hold: `merge-base --is-ancestor`
308+
# exits 128 on an absent object — an error, not a verdict — and with no
309+
# origin/main it would report "the pin left main", which is this block's
310+
# own overclaim wearing a new message.
311+
if ! git -C "$OBJECTUI_ROOT" rev-parse --verify --quiet origin/main >/dev/null; then
312+
echo "::error::the objectui clone has no origin/main ref, so \"is the pin on main\" cannot be answered in it. Refusing to cut rather than assuming the answer."
313+
exit 1
314+
fi
291315
if ! git -C "$OBJECTUI_ROOT" cat-file -e "${OBJECTUI_SHA}^{commit}" 2>/dev/null; then
292-
echo "::error::the committed pin ${OBJECTUI_SHA} is not present in a fresh full clone of objectui main. It names a revision that is not reachable from main (unmerged branch, or main was rewritten). Fix .objectui-sha in its own PR; do not cut against it."
316+
echo "::error::the committed pin ${OBJECTUI_SHA} is not present in a fresh full clone of objectui at all — no branch carries it. It was never pushed, its branch was deleted, or main was rewritten. Fix .objectui-sha in its own PR; do not cut against it."
317+
exit 1
318+
fi
319+
if ! git -C "$OBJECTUI_ROOT" merge-base --is-ancestor "$OBJECTUI_SHA" origin/main; then
320+
echo "::error::the committed pin ${OBJECTUI_SHA} exists in objectui but is NOT reachable from objectui main — it names a revision on a branch that never merged. Cutting against it would publish @objectstack/console built from code that is not on main. Fix .objectui-sha in its own PR; do not cut against it."
293321
exit 1
294322
fi
323+
echo "objectui pin ${OBJECTUI_SHA:0:12}: present in the clone, and reachable from objectui main."
295324
296325
# Detach the clone AT THE PIN so nothing downstream can accidentally
297326
# read a working tree that is objectui main. build-console.sh builds

0 commit comments

Comments
 (0)