--check verified outcomes — binaries on PATH, pkg-config modules — on a box that already installed everything. It never looked at the APT_* names, which is the only part that breaks on a clean machine of the wrong release, as R1 just showed. Add a loop over the assembled PKGS array that fails on any name with no installable candidate (apt-cache policy; no root, no network). All-missing is treated as stale lists (warn), not 36 bad names. The bootstrap-script job runs on a 24.04 runner, where the bad name still resolves, so name validation there checks the wrong archive. Add bootstrap-script-2604: a real --with-clang install in an ubuntu:26.04 container — the release the project ships on, and the first time the fuzz-toolchain half of bootstrap is exercised anywhere (CORE had been running clang++-21 directly). Also pass --with-clang/--packaging to the 24.04 --check so the optional and M6 names can't rot unnoticed. BRANCH_PROTECTION.md gains the 2604 row and the stale "when X merges" rows are corrected to "now". gui/docs/pkg-qa-requests-m1.md R2 + the --with-clang note. Co-Authored-By: Claude Sonnet 5 <[email protected]> Claude-Session: https://claude.ai/code/session_0143aKiohmDiyefJBwHDJJqw
2.3 KiB
Branch protection for main
CI defines the checks; branch protection is a repo setting (Settings → Branches → Add rule) and has to be configured once by an admin. This file records the intended policy so it can be re-applied or audited.
Rule: main
-
Require a pull request before merging. No direct pushes.
-
Require status checks to pass before merging, and require branches to be up to date first. Required checks:
Check (job name in ci.yml)Required from clang-formatnow testservernow bootstrap-scriptnow (validates package names against the 24.04 runner archive) bootstrap-script-2604now — real --with-clanginstall in a 26.04 container; the release the project ships onbuild (gcc)/build (clang)now — core, daemon and gui have merged sanitizers (dev)/sanitizers (tsan)now — core, daemon and gui have merged conformancenow — tests/conformance/has landed; this is the M0 exit gateextension-lintnow — extension/has merged (MV3 manifest + esbuild build)clang-tidyis intentionally not required through M1 (continue-on-error: true,.clang-tidyhasWarningsAsErrors: ''). Make it required at M2. -
Require linear history (matches CLAUDE.md §6: rebase onto
main, no merge commits). -
Require conversation resolution before merging.
-
Do not allow force pushes or deletions.
-
Apply the rule to administrators too, except for the initial scaffolding period.
Note on the "skipped" job steps
extension-lint and clang-tidy short-circuit to a "skipped" echo when their lane
hasn't landed. They still report success, so they can be marked required now without
blocking — they start doing real work automatically on the commit that adds the lane.
Their guards fail loudly (non-zero) once the lane is half-present — e.g. an
extension/manifest.json with no lintable package.json. A guard keyed to a single
filename is how a required check ends up green over nothing; the skip branch is only for
a lane that is genuinely absent.
conformance no longer has a skip branch. The suite (tests/conformance/run.sh) has
landed, so the job runs it unconditionally and fails if the entrypoint is missing.