Skip to content

ci: file an issue when the ruleset-drift gate detects drift - #443

Merged
rubenhensen merged 2 commits into
mainfrom
dobby/422-ruleset-drift-report
Sep 22, 2026
Merged

rubenhensen merged 2 commits into
mainfrom
dobby/422-ruleset-drift-report

Conversation

@dobby-coder

@dobby-coder dobby-coder Bot commented Sep 10, 2026 •

Copy link
Copy Markdown
Contributor

Part of #422 (superseded body from the 2026-09-10 "Pre-flight amendment 2" comment, which is the spec this PR follows).

CI on this branch cannot be made green from here. Test workspace (pg-core) fails on exactly the three tests named in "Why three tests are RED" below, and only on those -- confirmed against the 2026-09-10 11:35 UTC run. The cause is the missing build.yml half, which the dobby-coder App cannot push (no workflows: write); that patch is already posted as a comment on #422, waiting on a maintainer to apply it. Test workspace (pg-pkg) shows red in the same run only because the matrix's default fail-fast cancels it once pg-core fails -- its own tests (85 passed, 0 failed, across all four of its test binaries) ran to completion before the cancellation. The repo's actual required merge gate, Wire compat, passes. Nothing further to fix on the code side until the patch lands.

What this does

build.yml's ruleset-drift job reddens on drift and files nothing -- a red job has gone unread for 15 days in this fleet without anyone noticing. This adds the reporting half, in the extracted-script shape #429 established for changelog-coverage:

  • scripts/ruleset-drift-report.sh -- drives scripts/ruleset-drift.sh (unchanged), reads the checker's exit code deliberately, and files a ruleset-drift-labelled issue on real drift, only on a push to main, deduped against any already-open issue with the exact title. 2 still dominates 1: a dedupe-read failure or a failed gh issue create reports 2, never 1.
  • scripts/ruleset-drift-report-test.sh -- offline self-test, stubbing gh on PATH and the checker via RULESET_DRIFT_CHECKER (a PATH stub doesn't work here since the checker is invoked by a relative path after cd to the repo root).
  • pg-core/tests/ci_wiring.rs -- pins the reporter's presence in build.yml's ruleset-drift job, that issues: write is declared, that the filing loop hasn't crept back into the YAML, and that the reporter's self-test runs in CI. Renamed CHANGELOG_COVERAGE_LOOP_MARKERS to REPORTING_LOOP_MARKERS since it now guards two jobs instead of one.

scripts/ruleset-drift.sh and scripts/ruleset-drift-test.sh are untouched -- only the reporting changes.

Why three tests are RED on this branch

The dobby-coder App has no workflows: write, so the build.yml patch that wires the reporter in is posted as a comment on #422 for a maintainer to apply, not pushed here. Left red on purpose -- a patch that's posted and never applied has already merged silently twice on this repo:

  • the_registry_gate_still_reads_the_ruleset_back
  • the_ruleset_drift_gate_files_what_it_finds
  • the_ruleset_drift_reporters_self_test_runs_in_ci

Do not weaken, #[ignore], or delete any of these to get CI green before the patch lands.

Verification

  1. cargo test --manifest-path pg-core/Cargo.toml --features test,rust,stream -- exactly the three failures above, nothing else.
  2. cargo fmt --manifest-path pg-core/Cargo.toml --all -- --check -- passes.
  3. cargo clippy --manifest-path pg-core/Cargo.toml --all-targets --features test,rust,stream -- -D warnings -- passes.
  4. scripts/ruleset-drift-report-test.sh passes offline, no network, no GH_TOKEN; scripts/ruleset-drift-test.sh, scripts/changelog-coverage-test.sh, scripts/changelog-coverage-report-test.sh and scripts/wasm-package-check-test.sh all still pass.
  5. Applied the posted build.yml patch locally (never committed) and confirmed all five required outcomes:
    • all three failures above clear, nothing else breaks (18/18 pass)
    • deleting issues: write reds only the_ruleset_drift_gate_files_what_it_finds
    • reverting the reporter step's run: to scripts/ruleset-drift.sh reds the_registry_gate_still_reads_the_ruleset_back and the_ruleset_drift_gate_files_what_it_finds
    • deleting the Test the ruleset-drift reporter step reds only the_ruleset_drift_reporters_self_test_runs_in_ci
    • pasting a gh issue create line into the reporter step's run: reds the_ruleset_drift_gate_files_what_it_finds
    • reverted the local build.yml edit entirely afterward
  6. git diff --name-only origin/main...HEAD -- .github/workflows/ prints nothing.
  7. git diff --name-only origin/main...HEAD names only pg-core/tests/ci_wiring.rs, scripts/ruleset-drift-report.sh, scripts/ruleset-drift-report-test.sh.

Follow-up needed from a maintainer

The build.yml patch is posted as a comment on #422 -- applying it clears the three red tests above.

Closes #422.

build.yml's ruleset-drift job has reddened on drift with nothing filed
for 15 days without anyone noticing. Add scripts/ruleset-drift-report.sh
(and its offline self-test) as the reporting half, mirroring the
extracted-script shape #429 established for changelog-coverage, and pin
the wiring in pg-core/tests/ci_wiring.rs.

The build.yml patch that wires the reporter in cannot be committed here
(the dobby-coder App has no workflows: write) and is posted on the issue
instead, so three ci_wiring assertions are RED on this branch until a
maintainer applies it.
The dobby-coder App has no `workflows: write`, so this half of #422 was
posted as a diff on the issue for a maintainer to apply. Applying it here
clears the three assertions the branch deliberately left red:
the_registry_gate_still_reads_the_ruleset_back,
the_ruleset_drift_gate_files_what_it_finds and
the_ruleset_drift_reporters_self_test_runs_in_ci.

pg-core's ci_wiring suite goes 15 passed/3 failed -> 18 passed/0 failed
with this applied, and scripts/ruleset-drift-report-test.sh passes offline.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

postguard's ruleset-drift job reds on drift and files nothing, so the gate says nothing to anyone

1 participant