Skip to content

fix(tri): gates preview asks the contexts the ruleset requires, parse-ratchet among them (Closes #5725) - #5732

Open
dmitrii-f-t27 wants to merge 1 commit into
masterfrom
fix/preview-required-contexts
Open

dmitrii-f-t27 wants to merge 1 commit into
masterfrom
fix/preview-required-contexts

Conversation

@dmitrii-f-t27

Copy link
Copy Markdown
Collaborator

Closes #5725

tri gates preview asked four contexts it called "the four that can block a merge" (check, check-now-freshness, validate, check-linked-issue), which was the ruleset of 2026-09-06. The ruleset's last edit (2026-09-19 15:06 UTC, 21 s after #4277 merged the parse ratchet) leaves validate, check-linked-issue and parse-ratchet (gh api repos/gHashTag/t27/rules/branches/master; classic protection is off: branches/master reports protection.enabled: false). So two rows that cannot block a merge decided the exit code (an empty branch always exited 1), and parse-ratchet was never asked.

What changes

  • The set is read, not written down. Every run asks the ruleset (required_contexts, the reader tri gates required already used). If it can't be read, the set comes from .github/required-contexts.txt, a ledger that tri gates required --write regenerates (it writes only when the set changes, so the date never moves by itself). Both commands print drift between the ledger and the ruleset. If neither can be read, the preview says the set is unknown, asks every reader anyway, and exits 1.
  • A required context with no reader prints UNAVAILABLE, instead of being left out. A reader is used only when exactly its own workflow posts the context. GitHub matches a required check by name, so a renamed job or a second workflow taking the name turns the row UNAVAILABLE.
  • parse-ratchet runs its job's own steps. The steps are read out of spec-parse-ratchet.yml on every run: --self-test, then cargo build --release -p t27c (the checker gets the executable cargo reports, so CARGO_TARGET_DIR can't hand it a stale binary), then check_specs_still_parse.py over base..HEAD. Exit codes are the checker's: 0 PASS, 1 FAIL (the row names the specs), 2 UNAVAILABLE. validate works the same way, so it now also runs the --self-check it used to skip. If a job's steps differ from what its reader runs, the row reads UNAVAILABLE. This takes the idea behind the_pattern_is_read_out_of_the_gate_that_enforces_it and applies it to whole jobs.
  • check and check-now-freshness print under "NOT REQUIRED BY THE RULESET" and no longer decide the exit code. The NOW-gate scratch control (test_now_gate_writes_nothing.py --tri) still sees the preview reach the NOW gate's pass.
  • The documents that copied the set:
    • docs/BRANCH-PROTECTION.md now states the ruleset as read. It used to list five required workflows; two of them were.
    • spec-parse-ratchet.yml moves into MERGE_CRITICAL; it had been excluded with the reason "not a required check".
    • LOOP-RULES, verify.sh, the Makefile, the pre-push hook and two workflow headers now point at the ledger instead of naming "the four required checks".
    • tri gates required goes from 6 claims / 4 hollow / 1 unclaimed to 5 / 2 / 0. The two left are the docs/now workflows that MERGE_CRITICAL still lists (see below).
  • Help text. tri gates --help showed required's description against preview and unmeasured's against tests; each now sits on its own variant.
  • Census. fetches moves gates.rs:3651 -> 3668 (fn unmeasured), re-blessed in the same commit. This is a line shift from the doc comments added above it; the population is unchanged.

Verified locally

  • cargo build -p tri --all-targets (no new warnings); cargo test -p tri: 834 passed, 0 failed (13 in gates::preview_tests, 10 of them new).
  • Mutation: 7 hand-written mutants of the new code, each killed by a named test over the full 13-test sample.
  • Probes in a throwaway worktree:
    • a commit breaking specs/tools/tri/gates.t27 gives FAIL parse-ratchet ... specs/tools/tri/gates.t27 and exit 1;
    • an extra job step, a removed self-test, or a renamed validate job each give UNAVAILABLE with the reason;
    • an unreadable ruleset falls back to the ledger, and the reason is printed;
    • a ledger with a line removed gives LEDGER DRIFT from both commands;
    • with neither source readable: "THE REQUIRED SET COULD NOT BE READ" and exit 1.
  • tri skill check, tri census pin --gate, tri gates tests --gate, check_pr_branch_filters.py (and --self-test), test_now_gate_writes_nothing.py --tri, check_now_entry_shape.py, check_fix_carries_source.py: all pass. The shared .git/config hash is unchanged across runs.

Not decided here

Whether check and check-now-freshness should be required again is the owner's call. Only an admin can edit the ruleset. Until that's decided they stay in MERGE_CRITICAL, so their pull_request trigger stays unfiltered, and tri gates required reports them as claimed but not required.

🤖 Generated with Claude Code

…-ratchet among them (Closes #5725)

`tri gates preview` asked four contexts it called "the four that can block a
merge": check, check-now-freshness, validate, check-linked-issue -- the
ruleset of 2026-09-06. Since the ruleset's last edit (2026-09-19 15:06 UTC,
21 s after #4277 merged the parse ratchet) it requires validate,
check-linked-issue and parse-ratchet. So two rows that cannot block a merge
decided the exit code (an empty branch always exited 1), and the one new
required context was never asked.

- The set is read from the ruleset on every run (`required_contexts`), else
  from .github/required-contexts.txt, a ledger `tri gates required --write`
  regenerates only when the set changes. Both commands print drift. With
  neither readable the preview asks every reader and exits 1.
- A required context with no reader prints UNAVAILABLE instead of being left
  out. A reader is used only when exactly its own workflow posts the context.
- parse-ratchet runs its job's own steps, read out of spec-parse-ratchet.yml
  on every run: --self-test, `cargo build --release -p t27c` (the executable
  cargo reports), check_specs_still_parse.py over base..HEAD. validate does
  the same with its two steps, so it now runs its --self-check too. A job
  whose steps differ from its reader's reads UNAVAILABLE.
- check and check-now-freshness print under "NOT REQUIRED BY THE RULESET" and
  no longer decide the exit code.
- docs/BRANCH-PROTECTION.md states the ruleset as read; it listed five
  required workflows, two of which were. spec-parse-ratchet.yml joins
  MERGE_CRITICAL (its exclusion reason was "not a required check").
  LOOP-RULES, verify.sh, the Makefile, the pre-push hook and two workflow
  headers point at the ledger instead of naming "the four required checks".
- `tri gates --help` showed required's description on preview and
  unmeasured's on tests; each now sits on its own variant.

Census: `fetches` moves gates.rs:3651 -> 3668 (fn unmeasured). A line shift
from the doc comments added to GatesCmd above it; the population is unchanged.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
@github-actions

github-actions Bot commented Oct 3, 2026

Copy link
Copy Markdown
Contributor

PR Dashboard

Generated at: 2026-10-03 10:16:55 UTC

Summary

Status Count
Total Open PRs 42
PRs with Failing Checks 37
PRs with All Checks Green 5
READY 1
FAILING 37
PENDING 0
NO CHECKS YET 0

These columns do not partition: 1 + 37 + 0 + 0 = 38, and there are 42 open PRs. A PR is being counted twice or not at all.

Seal Status

  • ⚠️ STALE -- sha256(compiler.rs)=b45a356c2eb6 != manifest seal=87e5cbd3ad94.
    The committed NMSE numbers were certified against an older compiler.rs.
    Run scripts/reseal-check.sh locally for the two-step reseal command (advisory; not a merge gate).

@github-actions

github-actions Bot commented Oct 3, 2026

Copy link
Copy Markdown
Contributor

📓 NotebookLM Notebook linked to this PR

This notebook contains session context, decisions, and artifacts for this work.

This was referenced Oct 3, 2026
This was referenced Oct 3, 2026

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

tri gates preview asks four contexts; the ruleset requires validate, check-linked-issue and parse-ratchet

1 participant