--check verified outcomes — binaries on PATH, pkg-config modules — on a box that already installed everything. It never looked at the APT_* names, which is the only part that breaks on a clean machine of the wrong release, as R1 just showed. Add a loop over the assembled PKGS array that fails on any name with no installable candidate (apt-cache policy; no root, no network). All-missing is treated as stale lists (warn), not 36 bad names. The bootstrap-script job runs on a 24.04 runner, where the bad name still resolves, so name validation there checks the wrong archive. Add bootstrap-script-2604: a real --with-clang install in an ubuntu:26.04 container — the release the project ships on, and the first time the fuzz-toolchain half of bootstrap is exercised anywhere (CORE had been running clang++-21 directly). Also pass --with-clang/--packaging to the 24.04 --check so the optional and M6 names can't rot unnoticed. BRANCH_PROTECTION.md gains the 2604 row and the stale "when X merges" rows are corrected to "now". gui/docs/pkg-qa-requests-m1.md R2 + the --with-clang note. Co-Authored-By: Claude Sonnet 5 <[email protected]> Claude-Session: https://claude.ai/code/session_0143aKiohmDiyefJBwHDJJqw
45 lines
2.3 KiB
Markdown
45 lines
2.3 KiB
Markdown
# Branch protection for `main`
|
|
|
|
CI defines the checks; **branch protection is a repo setting** (Settings → Branches →
|
|
Add rule) and has to be configured once by an admin. This file records the intended
|
|
policy so it can be re-applied or audited.
|
|
|
|
## Rule: `main`
|
|
|
|
- **Require a pull request before merging.** No direct pushes.
|
|
- **Require status checks to pass before merging**, and require branches to be up to date
|
|
first. Required checks:
|
|
|
|
| Check (job name in `ci.yml`) | Required from |
|
|
|---|---|
|
|
| `clang-format` | now |
|
|
| `testserver` | now |
|
|
| `bootstrap-script` | now (validates package names against the 24.04 runner archive) |
|
|
| `bootstrap-script-2604` | now — real `--with-clang` install in a 26.04 container; the release the project ships on |
|
|
| `build (gcc)` / `build (clang)` | now — core, daemon and gui have merged |
|
|
| `sanitizers (dev)` / `sanitizers (tsan)` | now — core, daemon and gui have merged |
|
|
| `conformance` | **now — `tests/conformance/` has landed; this is the M0 exit gate** |
|
|
| `extension-lint` | now — `extension/` has merged (MV3 manifest + esbuild build) |
|
|
|
|
`clang-tidy` is intentionally **not** required through M1 (`continue-on-error: true`,
|
|
`.clang-tidy` has `WarningsAsErrors: ''`). Make it required at M2.
|
|
|
|
- **Require linear history** (matches CLAUDE.md §6: rebase onto `main`, no merge commits).
|
|
- **Require conversation resolution before merging.**
|
|
- Do **not** allow force pushes or deletions.
|
|
- Apply the rule to administrators too, except for the initial scaffolding period.
|
|
|
|
## Note on the "skipped" job steps
|
|
|
|
`extension-lint` and `clang-tidy` short-circuit to a "skipped" echo when their lane
|
|
hasn't landed. They still report **success**, so they can be marked required now without
|
|
blocking — they start doing real work automatically on the commit that adds the lane.
|
|
|
|
Their guards fail **loudly** (non-zero) once the lane is half-present — e.g. an
|
|
`extension/manifest.json` with no lintable `package.json`. A guard keyed to a single
|
|
filename is how a required check ends up green over nothing; the skip branch is only for
|
|
a lane that is genuinely absent.
|
|
|
|
`conformance` no longer has a skip branch. The suite (`tests/conformance/run.sh`) has
|
|
landed, so the job runs it unconditionally and fails if the entrypoint is missing.
|