ci: file an issue when the ruleset-drift gate detects drift - #443
Merged
Merged
Conversation
build.yml's ruleset-drift job has reddened on drift with nothing filed for 15 days without anyone noticing. Add scripts/ruleset-drift-report.sh (and its offline self-test) as the reporting half, mirroring the extracted-script shape #429 established for changelog-coverage, and pin the wiring in pg-core/tests/ci_wiring.rs. The build.yml patch that wires the reporter in cannot be committed here (the dobby-coder App has no workflows: write) and is posted on the issue instead, so three ci_wiring assertions are RED on this branch until a maintainer applies it.
The dobby-coder App has no `workflows: write`, so this half of #422 was posted as a diff on the issue for a maintainer to apply. Applying it here clears the three assertions the branch deliberately left red: the_registry_gate_still_reads_the_ruleset_back, the_ruleset_drift_gate_files_what_it_finds and the_ruleset_drift_reporters_self_test_runs_in_ci. pg-core's ci_wiring suite goes 15 passed/3 failed -> 18 passed/0 failed with this applied, and scripts/ruleset-drift-report-test.sh passes offline.
rubenhensen
approved these changes
Sep 22, 2026
Merged
This was referenced Sep 22, 2026
Closed
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Part of #422 (superseded body from the 2026-09-10 "Pre-flight amendment 2" comment, which is the spec this PR follows).
What this does
build.yml'sruleset-driftjob reddens on drift and files nothing -- a red job has gone unread for 15 days in this fleet without anyone noticing. This adds the reporting half, in the extracted-script shape #429 established forchangelog-coverage:scripts/ruleset-drift-report.sh-- drivesscripts/ruleset-drift.sh(unchanged), reads the checker's exit code deliberately, and files aruleset-drift-labelled issue on real drift, only on apushtomain, deduped against any already-open issue with the exact title.2still dominates1: a dedupe-read failure or a failedgh issue createreports2, never1.scripts/ruleset-drift-report-test.sh-- offline self-test, stubbingghonPATHand the checker viaRULESET_DRIFT_CHECKER(aPATHstub doesn't work here since the checker is invoked by a relative path aftercdto the repo root).pg-core/tests/ci_wiring.rs-- pins the reporter's presence inbuild.yml'sruleset-driftjob, thatissues: writeis declared, that the filing loop hasn't crept back into the YAML, and that the reporter's self-test runs in CI. RenamedCHANGELOG_COVERAGE_LOOP_MARKERStoREPORTING_LOOP_MARKERSsince it now guards two jobs instead of one.scripts/ruleset-drift.shandscripts/ruleset-drift-test.share untouched -- only the reporting changes.Why three tests are RED on this branch
The
dobby-coderApp has noworkflows: write, so thebuild.ymlpatch that wires the reporter in is posted as a comment on #422 for a maintainer to apply, not pushed here. Left red on purpose -- a patch that's posted and never applied has already merged silently twice on this repo:the_registry_gate_still_reads_the_ruleset_backthe_ruleset_drift_gate_files_what_it_findsthe_ruleset_drift_reporters_self_test_runs_in_ciDo not weaken,
#[ignore], or delete any of these to get CI green before the patch lands.Verification
cargo test --manifest-path pg-core/Cargo.toml --features test,rust,stream-- exactly the three failures above, nothing else.cargo fmt --manifest-path pg-core/Cargo.toml --all -- --check-- passes.cargo clippy --manifest-path pg-core/Cargo.toml --all-targets --features test,rust,stream -- -D warnings-- passes.scripts/ruleset-drift-report-test.shpasses offline, no network, noGH_TOKEN;scripts/ruleset-drift-test.sh,scripts/changelog-coverage-test.sh,scripts/changelog-coverage-report-test.shandscripts/wasm-package-check-test.shall still pass.build.ymlpatch locally (never committed) and confirmed all five required outcomes:issues: writereds onlythe_ruleset_drift_gate_files_what_it_findsrun:toscripts/ruleset-drift.shredsthe_registry_gate_still_reads_the_ruleset_backandthe_ruleset_drift_gate_files_what_it_findsTest the ruleset-drift reporterstep reds onlythe_ruleset_drift_reporters_self_test_runs_in_cigh issue createline into the reporter step'srun:redsthe_ruleset_drift_gate_files_what_it_findsbuild.ymledit entirely afterwardgit diff --name-only origin/main...HEAD -- .github/workflows/prints nothing.git diff --name-only origin/main...HEADnames onlypg-core/tests/ci_wiring.rs,scripts/ruleset-drift-report.sh,scripts/ruleset-drift-report-test.sh.Follow-up needed from a maintainer
The
build.ymlpatch is posted as a comment on #422 -- applying it clears the three red tests above.Closes #422.