feat: add postguard's renovate.json, pin-ignore pg-compat's readers - #457
Conversation
renovate.json extends github>encryption4all/renovate-config, the fleet preset settled in #254, plus one repo-level packageRules entry that disables pg-core on pg-compat/Cargo.toml: those `=`-exact pins are the wire-compat gate's published readers, and the preset's fleet-wide first-party rule is belt and braces rather than sole coverage here. pg-core/tests/renovate_config.rs pins the shape: extends the preset, keeps the pg-compat ignore rule, and never sets automerge: true anywhere in the tree. Part of #247. Graduated from #254. Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
There was a problem hiding this comment.
Verdict: approve. (Posted as COMMENT, not APPROVE — GitHub rejects an approval from the same bot identity that authored this PR: dobby-coder[bot] is both. No blocking findings, so this stands in for an approve per the review process.)
Rule check (5 binding rules): no violations.
atomic-commits— single commit, well-described (rationale for the renovate rule, the test it adds, and links to #448/#254/#247).code-comments—pg-core/tests/renovate_config.rsmatches the comment density of its modelled-on neighbourrelease_config.rs: a module doc explaining why the test exists (Renovate is hosted, not self-run, so this is the only backstop), and per-test doc comments giving the WHY (wire-compat gate readers, no-automerge-because-bot-can't-review) rather than restating the assertions.draft-pull-requests— PR is open as a draft.no-summary-issues— the release-plz lockfile measurement the issue also asked for was posted as a comment on #448, not filed as a new issue.test-suite-before-submit— fullpg-coresuite reported passing (31 tests + 6 doctests incl. the 3 new ones), independently re-verified by the previous review step, along withcargo fmt --checkand the 3 fail-open proofs (each reverted after).
No findings carried over from the prior review step either (empty set).
Content-wise: matchFileNames/matchPackageNames line up with pg-compat/Cargo.toml's actual aliased pg-core pins, the new test is auto-picked-up by pg-core's existing CI job, and the pre-existing cargo clippy --all-targets compile failure on clean main (missing test feature) is correctly flagged as out of scope rather than silently ignored or papered over.
Approving.
What
renovate.json: extendsgithub>encryption4all/renovate-config(the fleet preset settled in adopt Renovate org-wide (grouped weekly, auto-merge patch/minor on green CI) #254), plus one repo-levelpackageRulesentry that disablespg-coreonpg-compat/Cargo.toml. Those=-exact pins (pg-core-0-6-5,pg-core-0-5-10) are the wire-compat gate's published readers, moved deliberately underpg-compat/tests/support_window.rs'sno_two_pinned_readers_share_a_minor_line;postguard-e2e'scheck-reader-rows.mjswatches their currency separately. The preset already disablespg-corefleet-wide, so this rule is belt and braces, not sole coverage.pg-core/tests/renovate_config.rs, modelled onrelease_config.rs: readsrenovate.jsonwithserde_json(already apg-coredependency, so no new dependency added) and pins three things: the file still extends the preset, thepg-compat/Cargo.toml+pg-core+enabled: falserule is still present, and no rule anywhere setsautomerge: true.No
rangeStrategyoverride (every published crate here is a library or ships fromCargo.lock, so the preset'supdate-lockfileis right), noonboardingkey, and no automerge anywhere:postguardrequires one human review, which a bot cannot give.Closes #448.
Fail-open proof (each reverted after)
pg-compat/pg-coreignore rule →pg_compat_cargo_toml_disables_pg_corefailed. Restored."automerge": trueat the top level →automerge_never_turns_onfailed. Restored.extendsentry →extends_the_fleet_presetfailed. Restored.Verification
cargo test --manifest-path pg-core/Cargo.toml --features test,rust,stream: passes (31 tests + 6 doctests, including the 3 new ones).cargo fmt --manifest-path pg-core/Cargo.toml --all -- --check: passes.cargo clippy --manifest-path pg-core/Cargo.toml --all-targets -- -D warnings: this exact command, as given in the issue's acceptance criteria, already fails to compile on a cleanmainbefore this PR's changes.pg-core/src/lib.rs'stestmodule is#[cfg(feature = "test")]-gated, and several#[cfg(test)]unit-test modulesuse crate::test::TestSetup, which needs that feature;--all-targetsalone doesn't enable it. With the same--features test,rust,streamthecargo testcriterion uses,cargo clippy --manifest-path pg-core/Cargo.toml --all-targets --features test,rust,stream -- -D warningsis clean. Flagging rather than fixing, since it's pre-existing and outside this ticket's file scope.npx --yes --package renovate@44 -- renovate-config-validator --strict renovate.json: exits 0 (ran on the container's Node 22;renovate@44logs anEBADENGINEwarning for its declared^24.11.0but validates successfully anyway).git diff --name-only origin/main...HEAD -- .github/workflows/: empty.renovate.jsonand the one new test file.release-plz lockfile measurement
Requested separately by the issue, not acted on here: posted as a comment on #448. Short version: a
Cargo.lock-only change bumpspg-pkg/cryptifywhen the touched dependency is in their real graph (actix-web, rocket_cors) and leavespg-core/pg-cli/pg-ffialone otherwise; it's not a fixed yes/no per binary crate. No branch from that measurement is committed or pushed.