Files
vdm/.github/BRANCH_PROTECTION.md
T
samiandClaude Sonnet 5 82a2f11d7a pkg: make bootstrap --check validate apt names, and run it on 26.04
--check verified outcomes — binaries on PATH, pkg-config modules — on a box
that already installed everything. It never looked at the APT_* names, which
is the only part that breaks on a clean machine of the wrong release, as R1
just showed. Add a loop over the assembled PKGS array that fails on any name
with no installable candidate (apt-cache policy; no root, no network).
All-missing is treated as stale lists (warn), not 36 bad names.

The bootstrap-script job runs on a 24.04 runner, where the bad name still
resolves, so name validation there checks the wrong archive. Add
bootstrap-script-2604: a real --with-clang install in an ubuntu:26.04
container — the release the project ships on, and the first time the
fuzz-toolchain half of bootstrap is exercised anywhere (CORE had been running
clang++-21 directly). Also pass --with-clang/--packaging to the 24.04 --check
so the optional and M6 names can't rot unnoticed. BRANCH_PROTECTION.md gains
the 2604 row and the stale "when X merges" rows are corrected to "now".

gui/docs/pkg-qa-requests-m1.md R2 + the --with-clang note.

Co-Authored-By: Claude Sonnet 5 <[email protected]>
Claude-Session: https://claude.ai/code/session_0143aKiohmDiyefJBwHDJJqw
2026-09-10 14:58:10 +04:00

2.3 KiB

Branch protection for main

CI defines the checks; branch protection is a repo setting (Settings → Branches → Add rule) and has to be configured once by an admin. This file records the intended policy so it can be re-applied or audited.

Rule: main

  • Require a pull request before merging. No direct pushes.

  • Require status checks to pass before merging, and require branches to be up to date first. Required checks:

    Check (job name in ci.yml) Required from
    clang-format now
    testserver now
    bootstrap-script now (validates package names against the 24.04 runner archive)
    bootstrap-script-2604 now — real --with-clang install in a 26.04 container; the release the project ships on
    build (gcc) / build (clang) now — core, daemon and gui have merged
    sanitizers (dev) / sanitizers (tsan) now — core, daemon and gui have merged
    conformance now — tests/conformance/ has landed; this is the M0 exit gate
    extension-lint now — extension/ has merged (MV3 manifest + esbuild build)

    clang-tidy is intentionally not required through M1 (continue-on-error: true, .clang-tidy has WarningsAsErrors: ''). Make it required at M2.

  • Require linear history (matches CLAUDE.md §6: rebase onto main, no merge commits).

  • Require conversation resolution before merging.

  • Do not allow force pushes or deletions.

  • Apply the rule to administrators too, except for the initial scaffolding period.

Note on the "skipped" job steps

extension-lint and clang-tidy short-circuit to a "skipped" echo when their lane hasn't landed. They still report success, so they can be marked required now without blocking — they start doing real work automatically on the commit that adds the lane.

Their guards fail loudly (non-zero) once the lane is half-present — e.g. an extension/manifest.json with no lintable package.json. A guard keyed to a single filename is how a required check ends up green over nothing; the skip branch is only for a lane that is genuinely absent.

conformance no longer has a skip branch. The suite (tests/conformance/run.sh) has landed, so the job runs it unconditionally and fails if the entrypoint is missing.