gui-dod (per-PR: scroll-60fps + unhappy-path) and gui-dod-nightly (rss-flat, schedule/workflow_dispatch) are live in ci.yml, driving GUI's newly-landed gui/tests/dod/run.sh + gui-dod-harness. No Xvfb step: run.sh already runs QT_QPA_PLATFORM=offscreen itself. Each gate forced red once before being trusted (tests/integration/README.md has the transcripts): VELOX_DOD_FRAME_BUDGET_MS=0.01 for scroll-60fps, VELOX_DOD_RSS_SLACK_KIB=-999999999 for rss-flat, and — since run.sh always starts a working mockd — a direct gui-dod-harness invocation against an unreachable socket for unhappy-path, which hit the harness's own 75s watchdog exactly as documented. Recorded GUI's live finding (gui/docs/proto-requests-m1.md) that mockd --drop-connection is a no-op over the UDS transport, so unhappy-path's drop-connection phase can't yet exercise a real drop — coordinating with PROTO on the fix rather than working around it locally. gui-dod stays required regardless: its other two phases and the crash/hang/watchdog paths still catch real regressions. Added gui-dod to BRANCH_PROTECTION.md's required-checks table. ADR 0019: the live-veloxd conformance runner (run.sh step 3b, already unconditional inside the already-required conformance job) stays required as PROTO's xfail list shrinks (18 entries now, down from 34; 57/57 fixtures passing on main). No CI change needed — it was already inside a required check; this records the decision not to carve out an exception for it. Co-Authored-By: Claude Sonnet 5 <[email protected]> Claude-Session: https://claude.ai/code/session_01RBPR7iM3YPyxrjWsVtZDPJ
2.8 KiB
Branch protection for main
CI defines the checks; branch protection is a repo setting (Settings → Branches → Add rule) and has to be configured once by an admin. This file records the intended policy so it can be re-applied or audited.
Rule: main
-
Require a pull request before merging. No direct pushes.
-
Require status checks to pass before merging, and require branches to be up to date first. Required checks:
Check (job name in ci.yml)Required from clang-formatnow testservernow bootstrap-scriptnow (validates package names against the 24.04 runner archive) bootstrap-script-2604now — real --with-clanginstall in a 26.04 container; the release the project ships onbuild (gcc)/build (clang)now — core, daemon and gui have merged sanitizers (dev)/sanitizers (tsan)now — core, daemon and gui have merged conformancenow — tests/conformance/has landed; this is the M0 exit gate. Includes the live-veloxdrunner (step 3b ofrun.sh), unconditional in the script — seedocs/adr/0019-live-veloxd-conformance-is-required.md.extension-lintnow — extension/has merged (MV3 manifest + esbuild build)gui-dodnow — gui/tests/dod/has landed (GUI M1 DoD gates R3:scroll-60fps,unhappy-path); seetests/integration/README.md#gui-m1-definition-of-done-gates-r3.gui-dod-nightly(rss-flat) is schedule-only and cannot be a required PR check.clang-tidyis intentionally not required through M1 (continue-on-error: true,.clang-tidyhasWarningsAsErrors: ''). Make it required at M2. -
Require linear history (matches CLAUDE.md §6: rebase onto
main, no merge commits). -
Require conversation resolution before merging.
-
Do not allow force pushes or deletions.
-
Apply the rule to administrators too, except for the initial scaffolding period.
Note on the "skipped" job steps
extension-lint and clang-tidy short-circuit to a "skipped" echo when their lane
hasn't landed. They still report success, so they can be marked required now without
blocking — they start doing real work automatically on the commit that adds the lane.
Their guards fail loudly (non-zero) once the lane is half-present — e.g. an
extension/manifest.json with no lintable package.json. A guard keyed to a single
filename is how a required check ends up green over nothing; the skip branch is only for
a lane that is genuinely absent.
conformance has no skip branch. It runs ctest -L conformance (see
docs/adr/0014-conformance-runs-through-ctest.md); the dev test preset's
noTestsAction: error fails the job if that label ever matches nothing, so a deleted or
renamed registration goes red instead of passing vacuously.