Skip to content

Release gate 2 — add Python, Node, Rust, and docs checks behind ci-required #94

Description

@M9nx

1. Problem / evidence

On main (f1cd131), .github/workflows/ci.yml runs the 6-job Python test matrix plus a lint job that only executes python -m py_compile semantic_code_intelligence/__init__.py. Nothing in the required ci-required aggregate exercises:

  • Python coverage threshold or mypy;
  • vscode-extension install / compile / lint / audit (and npm ci currently fails — see Release gate 3);
  • codexa-core Rust fmt / clippy / test / audit;
  • the VitePress docs build (npm run docs:build).

Consequence: Node, Rust, and docs PRs (e.g. Dependabot #82, #85, #87–#91, and #92) show green ci-required on Python-only evidence.

Ruleset ci-required (id 24007391) is active on refs/heads/main, strict, requiring context ci-required.

2. Outcome

A green ci-required means every component touched by the PR passed its relevant checks, while the full Ubuntu/Windows × 3.11/3.12/3.13 Python matrix stays required.

3. Scope

  • .github/workflows/ci.yml (change detection, component jobs, aggregate)
  • possibly a small script + tests for path classification and aggregate logic
  • pyproject.toml coverage/mypy configuration (baseline only)

4. Non-goals

  • No change to ruleset / required-context policy; ci-required name stays.
  • No reduction of the Python matrix (that is Release gate 6 + separate policy approval).
  • No test marker reclassification, no moving tests to nightly.

5. Dependencies

  • Node job can only become aggregate-relevant after Release gate 3 makes npm ci pass.
  • Rust job aggregate-relevance after Release gate 4 rustfmt baseline.

6. PR breakdown

  1. ci: add always-running change detection and aggregate contract tests — change detection always runs; representative-path classification tests; aggregate uses if: always() and needs.*.result.
  2. ci: add Python quality shadow checks — real coverage run with configured threshold; scoped mypy with documented baseline; informational until green.
  3. ci: add VS Code extension validation — npm ci, compile, ESLint, audit policy; shadow until gate 3 lands.
  4. ci: add Rust core validation — cargo fmt --check, clippy (warnings policy), tests, cargo audit; safe cache keys.
  5. ci: validate documentation build on pull requests — lockfile install + docs:build.
  6. ci: connect proven component jobs to ci-required — explicit skipped/success/failure semantics with tested condition matrix.

Each PR rolls back by revert; none changes required-check names.

7. Acceptance criteria

  • Change detection always runs; a failed/skipped detector cannot produce a green aggregate.
  • Node/Rust/docs changes cannot merge on Python-only evidence.
  • The six-job Python matrix remains intact and required.
  • fail-fast: false, explicit timeouts, concurrency cancellation, JUnit output, durations, environment evidence preserved.
  • Workflow permissions, shell portability, timeouts, artifact retention, and fork safety reviewed.
  • Evidence from representative docs-only, Node-only, Rust-only, and Python-only PR commits attached.

8. Risks and rollback

Risk of false red (blocking merges) or false green (detector bug). Mitigated by contract tests and shadow period. Rollback: revert the connecting PR (6) to return to Python-only aggregate.

9. Evidence to attach

Workflow run URLs per representative change type, aggregate condition test output, CI minute comparison.

10. Labels, milestone, estimate

Labels: github_actions, enhancement. Milestone: CI & Test Architecture Restructure. Estimate: 4–5 days.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    enhancementNew feature or requestgithub_actionsPull requests that update GitHub Actions code

    Projects

    No projects

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions