Feature 05: Checks & statuses — internal/checks #11
Labels
No labels
actions
bug
cli
duplicate
enhancement
fork
forum
git storage
help wanted
insights
invalid
issues
moderation
oidc
ownership transfer
packages
pr/merge protection rules
projects
pull requests
question
releases
sponsorships
tags
webhooks
wiki
wontfix
No project
No assignees
1 participant
Notifications
Due date
No due date set.
Dependencies
No dependencies set
Reference
crueber/walhub#11
Loading…
Reference in a new issue
No description provided.
Delete branch "%!s()"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
Feature 05: Checks & statuses —
internal/checksSpec:
docs/features/05_checks_statuses.md(normative) + P1/P4–P8 indocs/features/README.md.Rollout: Wave B class in
docs/features/09_rollout.md§3 (parallel with issues/notify core trays). Depends on 01 (roles), 03 (merge task, open-PR index).Recommended implementation (verified against the doc)
internal/checks: oneapi.RouteProvider(Seam 1, both lanes viaapi.Lanes), oneauth.Providerclaiming thewct_prefix (Seam 2 — startup-validated no overlap), zero new policy effects (§6 extends the existingprotecteffect withrequire_checks), one task kindchecks-index-compact(Seam 5). v1 is statuses-only; check-runs/suites deferred (§1 seam note, no migration needed later).repos/<o>/<r>/checks/):checks/<sha>/<context>.json(Create first report, CAS Update after; last-write-wins; never deleted),checks/index.json(P4 CAS'd hot-window projection, newest 500 shas, 256 KiB cap),meta/ci_tokens/<id>.json(CAS'd; only sha256 hash stored; revoked records retained).wct_<id>.<secret>shown once; provider resolves unprivilegedci:<id>principal (frozenPrincipalNOT extended); handler checkschecks:writescope +revoked_at(mismatch/revoked = 401, valid-but-scopeless = 403). Repowriterole may also report.RepoView.Commit, else 404) → Create-or-CAS status → CAS index upsert → SSEcheckpacket + failure/error notification enqueue, all synchronously post-CAS (P8). Bounded CAS retries (≤5, then 503).error > failure > pending > success; zero contexts ⇒pendingwith zero counts. GETs are no-store (sha-addressed but mutable — never immutable class).require_checks: [1–32 validated contexts]insideprotect; union across matching rules; evaluated by 03's merge task at merge time only (wire into the existing merge gate next to the 04 required-reviews check; refusal message verbatimmerge refused: required checks not green for <sha>: …). No bypass list. Direct pushes NOT gated.failure/errorwhere sha is an open PR head (bounded lookup via sharedissues/index.json), enqueue 06'scheck_reportedsynchronously. Success/pending emit nothing.web/sdk/src/checks.js. Dark + light themes.Acceptance criteria
ndefault 50, max 200).make cover≥ 95% oninternal/checks;-raceclean; table-driven httptest per handler.Starting Feature 05 (checks & statuses) implementation on branch feat/checks (transplant from origin/main to protect the dirty worktree). Plan: new internal/checks (statuses, index+compact, wct_ tokens, combined view, require_checks gate via pulls ChecksGate seam), policy require_checks extension, server TokenHook seam, SDK + UI pages, EVIDENCE E6. Will link the PR here when ready.
Feature 05 implementation complete: PR crueber/walhub#16 (feat/checks, one commit on top of origin/main). Done per the issue plan: internal/checks (statuses, index+compact, wct_ tokens + Seam 2 hook, combined view, merge-time gate via pulls ChecksGate seam without forking merge logic), require_checks in protect (union, push-ignored), nil-safe 06-shaped fan-out, UI pages + web/sdk/src/checks.js (dark+light via existing dark: variants). Acceptance: endpoints+P6 gates with plain-text errors and paged index; verbatim refusal proven e2e (unit pulls e2e test + live stack: failure, merge refused verbatim, success, merge lands); internal/checks 96.4% cover with -race clean and table-driven httptest per handler; EVIDENCE.md E6 with measured budgets. Deviations noted in 05 Decisions + 14 Decisions: discovery absent (01/02/03/C2 rule), open-PR lookup via bounded pr.json scan (cards lack head_sha), bypass applies per-rule (03 step 4), 409 on bad state, index-exhaustion answers 200 (02 parity), live SSE rows deferred to the 06/08 stream endpoint. Gaps: make cover internal/git pre-existing float-boundary failure (untouched files); no real-browser drive available here (vite build + live shell serving verified instead). Do NOT merge — awaiting review.
PR #16 review (feat/checks, commit
d26f196) — verified in scratch worktree /tmp/walhub-checks, main worktree untouched, nothing committed.VERDICTS
TESTS (scratch worktree, -race)
No fixes needed — I pushed nothing. Findings: none blocking; two recorded-and-accepted doc deltas (discovery Name() absent like all sibling waves; SSE packet implemented but stream unwired until 06/08 lands).
MERGE RECOMMENDATION: ready to merge.
Feature 05 complete: PR #16 reviewed with no blocking defects, merged as
64e79c7. internal/checks 96.4% coverage, -race clean. Closing.