From f7a0281ca267aea82e231dbc874dce66fbe8f493 Mon Sep 17 00:00:00 2001 From: Mathias Date: Mon, 20 Jul 2026 12:10:25 +0200 Subject: [PATCH] feat(ci): wire var-go/oath gate into CI (#1) MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit Adds an oath job to cd.yml: on pull_request, checks out swedsl (the vargo-gate source — its oath submodule isn't go-installable, module path isn't a real import path) and runs cmd/vargo-gate against this repo's linked issue, posting a var-go/oath commit status. Deliberately NOT required by branch protection: vargo-gate's candidate is still a hardcoded toy self-test registry (swedsl's own #9 fixture), not a real PR-diff checker, so it fails closed against any real oath until swedsl ships an Executor (swedsl#27). Requiring it now would permanently block every cad-atlas PR. Disclosed in the CI config comment, PROJECT.md, and docs/INCEPTION-OATH.md (honest-stub discipline). Co-Authored-By: Claude Sonnet 5 --- .context/PROJECT.md | 10 +++++++--- .gitea/workflows/cd.yml | 44 +++++++++++++++++++++++++++++++++++++++++ docs/INCEPTION-OATH.md | 7 ++++--- 3 files changed, 55 insertions(+), 6 deletions(-) diff --git a/.context/PROJECT.md b/.context/PROJECT.md index 4017e9e..cb84d7d 100644 --- a/.context/PROJECT.md +++ b/.context/PROJECT.md @@ -54,9 +54,13 @@ assessor-loop ledger) → `06 PR → CI` (go test/vet/lint/govulncheck + **var-g This repo is built *through* the workflow it depicts. It is `dispatch-allow`-enabled, and its own build increments are governed by a **var-go Oath** embedded in their spec issues (see the -Stage-03 tracking issue). Bootstrapping honesty (per swedsl honest-stub discipline): the Oath is -**defined** but `cmd/vargo-gate` is **not yet wired** into this repo's CI — until it is, the Oath -is advisory here. Wiring it is a first tracked task; disclosed in code, this doc, and CI config. +Stage-03 tracking issue). Bootstrapping honesty (per swedsl honest-stub discipline): `cmd/vargo-gate` +is wired into `.gitea/workflows/cd.yml`'s `oath` job (issue #1) — it runs on every pull_request, +fetches the linked issue's oath, and posts a `var-go/oath` commit status. But its candidate is +still a hardcoded toy self-test registry, not a real PR-diff checker (swedsl's Executor question, +swedsl#27, is unbuilt) — it fails closed against any real oath. The status is **not** required by +branch protection, so it can't block merges yet; enabling that waits on the real-diff Executor. +Disclosed in the CI config comment, this doc, and `docs/INCEPTION-OATH.md`. ## Brain references (source of truth — `brain_get `) diff --git a/.gitea/workflows/cd.yml b/.gitea/workflows/cd.yml index f12fefe..7ececc2 100644 --- a/.gitea/workflows/cd.yml +++ b/.gitea/workflows/cd.yml @@ -53,6 +53,50 @@ jobs: - name: Run checks run: task check + oath: + name: var-go/oath + needs: guard + # Only a real pull_request event carries a linked-issue oath to gate (mirrors + # swedsl's own oath job, .gitea/workflows/ci.yml). v1 simplification (swedsl#30): + # the oath issue number is the PR's OWN number. + # + # DISCLOSED LIMITATION (honest-stub discipline, see docs/INCEPTION-OATH.md S3 and + # knowledge/swedsl-vargo-sprint1-enforcement-teeth-verdict.md): cmd/vargo-gate's + # candidate is a hardcoded toy self-test registry (swedsl's own #9 fixture + # vocabulary), not a real PR-diff checker. It will fail closed against any oath + # that isn't that toy vocabulary — which is every real oath, including this repo's + # own #1. A red or green "var-go/oath" status here currently proves the WIRING + # (fetch issue -> gate -> post commit status) runs end-to-end on a real PR, not + # that the PR satisfies its linked issue's oath. Deliberately NOT required by + # branch protection until swedsl ships a real-diff Executor (swedsl#27) — making + # it required now would permanently block every cad-atlas PR. + if: needs.guard.outputs.is_template != 'true' && github.event_name == 'pull_request' + runs-on: self-hosted + steps: + - name: Checkout swedsl (var-go source — not go-installable, module path isn't a real import path) + uses: actions/checkout@v4 + with: + repository: mathias/swedsl + path: swedsl + token: ${{ secrets.DMABE_GITEA_API_TOKEN }} + + - uses: actions/setup-go@v5 + with: + go-version-file: swedsl/oath/go.mod + cache: false + + - name: Run vargo-gate (fetch -> gate -> post status against this PR) + working-directory: swedsl/oath + env: + VARGO_GITEA_BASEURL: ${{ github.server_url }} + VARGO_GITEA_OWNER: ${{ github.repository_owner }} + VARGO_GITEA_REPO: cad-atlas + VARGO_GITEA_ISSUE: ${{ github.event.pull_request.number }} + VARGO_GITEA_SHA: ${{ github.event.pull_request.head.sha }} + run: | + export DMABE_GITEA_API_TOKEN='${{ secrets.DMABE_GITEA_API_TOKEN }}' + go run ./cmd/vargo-gate + build: name: Build & Import needs: [guard, check] diff --git a/docs/INCEPTION-OATH.md b/docs/INCEPTION-OATH.md index 68e8e59..846ec24 100644 --- a/docs/INCEPTION-OATH.md +++ b/docs/INCEPTION-OATH.md @@ -3,8 +3,9 @@ The acceptance contract for standing up cad-atlas. The sprint is finalized only when this Oath holds. Methodology: brain `wiki/homelab/decisions/inception-sprint-and-oath.md`. -> **Status of enforcement:** this Oath is currently **advisory** (human-verified). Machine -> enforcement via `var-go/oath` is deferred — see the honesty rule below and issue #1. +> **Status of enforcement:** this Oath is currently **advisory** (human-verified). `var-go/oath` +> is wired (issue #1) and runs on every PR, but its candidate is a toy self-test — it fails closed +> against any real oath and is not required by branch protection. See the honesty rule below. ## General clauses (any inception sprint) @@ -24,7 +25,7 @@ Oath holds. Methodology: brain `wiki/homelab/decisions/inception-sprint-and-oath |---|--------|--------|----------| | S1 | Atlas served at `/`, renders all 9 stages signal→pod | ✅ | `internal/web/handler.go` + `static/cad-atlas.html` | | S2 | Oath covered in the viz (stages 03 + 06) | ✅ | var-go Oath nodes in the atlas | -| S3 | `var-go/oath` enforces cad-atlas's own PRs | ⏸ **deferred → #1** | var-go v1 candidate is a toy self-test; module not cross-repo consumable. See honesty rule. | +| S3 | `var-go/oath` enforces cad-atlas's own PRs | ⏸ **wired, not enforcing → #1** | `oath` job runs + posts status (#1). Not branch-protection-required: candidate is still a toy self-test, fails closed on every real oath until swedsl's Executor (swedsl#27) exists. See honesty rule. | ## Deployment