diff --git a/.github/workflows/release-check.yml b/.github/workflows/release-check.yml index 2d09a16..55dc2bd 100644 --- a/.github/workflows/release-check.yml +++ b/.github/workflows/release-check.yml @@ -3,6 +3,10 @@ name: release-check on: push: branches: [master] + # Tag pushes fire the tag-integrity job (below): the tag push itself + # is the green proof after a release, so no empty-commit re-trigger + # on master is needed. + tags: ['v*'] jobs: tag-current: @@ -25,3 +29,27 @@ jobs: echo "::error:: git push origin --tags" exit 1 fi + + tag-integrity: + # Tag push is the green proof after a release. tag-current above only + # proves the tag EXISTs on origin; this proves the tag's CONTENT: the + # VERSION in the tagged tree must equal the tag name minus the leading + # v. Runs on tag pushes only. + if: startsWith(github.ref, "refs/tags/v") + runs-on: ubuntu-latest + steps: + - uses: actions/checkout@v4 + with: + # The tag ref itself (github.ref_name is the tag name on a tag + # push). We only read the checked-out tree, so no fetch-depth: 0. + ref: ${{ github.ref_name }} + + - name: Tagged tree VERSION must equal the tag name + run: | + TAG=${GITHUB_REF_NAME#v} + VERSION=$(cat VERSION) + if [ "$VERSION" != "$TAG" ]; then + echo "::error::tag ${GITHUB_REF_NAME} points at a tree with VERSION=${VERSION}, tag name says ${TAG}" + echo "::error::re-tag on the right commit or fix VERSION before pushing" + exit 1 + fi diff --git a/AGENTS.md b/AGENTS.md index 7ba185a..561236d 100644 --- a/AGENTS.md +++ b/AGENTS.md @@ -17,11 +17,12 @@ Three files move together, as one unit, in the PR that ships a release: **Why the tag is not optional:** `.github/workflows/release-check.yml` runs `tag-current` on every push to master and fails the build with -`VERSION=X but tag vX is not on origin` if the tag is missing. The -workflow only triggers on push — pushing the tag alone does NOT -re-run it. If you add the tag after merging, push an empty commit to -master (`git commit --allow-empty`) to re-trigger `release-check` and -turn the red X green. +`VERSION=X but tag vX is not on origin` if the tag is missing. Pushing +the tag ALSO fires the workflow: the `tag-integrity` job runs on tag +pushes, checks out the tagged tree, and fails if that tree's `VERSION` +does not equal the tag name (leading `v` stripped). So the tag push +itself is the green proof after a release — no empty commit, no direct +push to master. `skills/box-audit/SKILL.md` carries a `version:` in its frontmatter, kept in sync **by hand** with `VERSION` (see the comment in that file) @@ -84,7 +85,8 @@ follow: file/line citations. Reviewers never merge. 3. **Maintainer release-tail card** (created only after an approving verdict) merges, tags `v$VERSION` on the merge commit, and pushes - the empty commit to re-trigger `release-check`. + the tag — the tag push fires release-check (tag-integrity) which + is the green proof. No empty commit. No agent merges without an approving review verdict on the PR — not the coder that opened it, not a steered mid-run instruction, not