diff --git a/.castiron.stats.yml b/.castiron.stats.yml index 5994185c6c..fa3eec61a5 100644 --- a/.castiron.stats.yml +++ b/.castiron.stats.yml @@ -1,8 +1,8 @@ schema_version: 1 -generation_id: e6e3b1ee-91de-48d6-8b7e-8021df4212ea +generation_id: 63ac4032-0941-40e4-83ee-ae3cde830f2b openapi_spec_hash: 8aa23d19137079c724365bd6cadd0858 openapi_transformed_spec_hash: d591fedadfdd68837534b2574782bf81 config_hash: 70e6e763ed8ac8c4038de193a96c771d -codegen_sha: b56a245c7ab1a741a95e6ee6bd7357f9ca4b6e52 -codegen_hash: 6e391d7d5910f75be379f99a0ac4529af9a70461a6f2c7ad0a6f5d77cf00d639 -public_codegen_sha: 8bef4a806756c8b3db141bd6a1235fcc7148e854 +codegen_sha: e3fd8becca14771332e4d595da08776af0d652cb +codegen_hash: 4cb3a4a438d6e8d094e5706b634fb67ebd763b682c54876704645012544862a3 +public_codegen_sha: bd28123c82f56c293b4b5f48f369c5f404d98f09 diff --git a/scripts/castiron/CUSTOM_CODE.md b/scripts/castiron/CUSTOM_CODE.md index 936a1b88c4..ce02af9647 100644 --- a/scripts/castiron/CUSTOM_CODE.md +++ b/scripts/castiron/CUSTOM_CODE.md @@ -1,3 +1,5 @@ + + # Custom code The custom-code reporter measures the SDK's remaining customization of generated @@ -77,8 +79,10 @@ The trusted run summary reports additions, deletions, total, mixed-file count, headroom, largest patches, and exact policy/candidate/generated revisions. The existing custom-code comment remains unchanged, including when the budget fails. The trusted compute job reuses its own report, never the candidate's artifacts. -The checker, policy, and workflows are maintained in the SDK and preserved -through the normal three-way merge during generation. +The checker, workflows, and offline tests are generated from shared Castiron +templates. The budget policy remains repository-owned and is never generated. +Repository-specific customizations are preserved through the normal three-way +merge during generation. ## Local verification diff --git a/scripts/castiron/README.md b/scripts/castiron/README.md index 70e2412382..c445a641b3 100644 --- a/scripts/castiron/README.md +++ b/scripts/castiron/README.md @@ -7,7 +7,9 @@ for cross-SDK improvements; repository-specific customizations use the normal three-way merge and are allowed. The reporter uses Python 3.10+, Git, and `gh`; it does not import SDK code. -Run `python3 scripts/castiron/test_custom_code_report.py` for focused tests. +Run `python3 -m unittest discover -s scripts/castiron -p 'test_custom_code*.py'` +for the offline suite. Install Node.js to exercise the workflow publishers too. +See [CUSTOM_CODE.md](CUSTOM_CODE.md) for budget policy and activation. The report comment includes commands to inspect the exact custom-code patch. Public reporting uses only public snapshots and needs no private repository access. @@ -17,8 +19,8 @@ Its hash format is documented in the reporter. Only `.github/actions/` and The read-only pull-request workflow runs on every branch, including drafts and forks. A separate read-only `workflow_run` job computes the authoritative report from -current, GitHub-associated base/head Git objects using the trusted workflow -revision. It fetches those objects into a new bare repository and never checks +the captured main checkout and GitHub-associated PR head. Merge groups are +checked independently against current main. It fetches those objects into a new bare repository and never checks out or executes PR code. The comment-writing job consumes only the artifact from that trusted job, rechecks freshness, and links to its report and patch. PR-produced reports are advisory run output, not the published assessment. The diff --git a/scripts/castiron/custom_code_budget.py b/scripts/castiron/custom_code_budget.py index b43976062c..87767d0271 100644 --- a/scripts/castiron/custom_code_budget.py +++ b/scripts/castiron/custom_code_budget.py @@ -1,8 +1,9 @@ #!/usr/bin/env python3 +# File generated from our OpenAPI spec by Castiron. See CONTRIBUTING.md for details. """SDK custom-code budget gate. Run only from a trusted checkout, never PR code. Reuses Castiron's vendored snapshot verifier and generated-file accounting. This -file and its workflow are maintained in the SDK repository. +file and its workflows are generated from shared Castiron templates. """ from __future__ import annotations diff --git a/scripts/castiron/custom_code_test_support.py b/scripts/castiron/custom_code_test_support.py index ea6328ad96..7c9404b022 100644 --- a/scripts/castiron/custom_code_test_support.py +++ b/scripts/castiron/custom_code_test_support.py @@ -1,3 +1,4 @@ +# File generated from our OpenAPI spec by Castiron. See CONTRIBUTING.md for details. """Small Git/checkpoint fixture shared by the offline Castiron tests.""" from __future__ import annotations diff --git a/scripts/castiron/fixtures/github_publisher.cjs b/scripts/castiron/fixtures/github_publisher.cjs index 3c5d256630..569421ba10 100644 --- a/scripts/castiron/fixtures/github_publisher.cjs +++ b/scripts/castiron/fixtures/github_publisher.cjs @@ -1,21 +1,22 @@ +// File generated from our OpenAPI spec by Castiron. See CONTRIBUTING.md for details. // Execute the real workflow script with an offline GitHub API and capture writes. const fs = require('node:fs'); const data = JSON.parse(fs.readFileSync(0, 'utf8')); const writes = []; const github = { rest: { - actions: {getWorkflowRun: async () => ({data: data.run})}, - pulls: {get: async () => ({data: data.current}), list: 'pulls'}, - git: {getRef: async () => ({data: {object: {sha: data.current.base.sha}}})}, + actions: { getWorkflowRun: async () => ({ data: data.run }) }, + pulls: { get: async () => ({ data: data.current }), list: 'pulls' }, + git: { getRef: async () => ({ data: { object: { sha: data.current.base.sha } } }) }, repos: { - createCommitStatus: async value => writes.push(value), + createCommitStatus: async (value) => writes.push(value), listCommitStatusesForRef: 'statuses', listPullRequestsAssociatedWithCommit: 'associations', }, issues: { listComments: 'comments', - createComment: async value => writes.push({operation: 'create', ...value}), - updateComment: async value => writes.push({operation: 'update', ...value}), + createComment: async (value) => writes.push({ operation: 'create', ...value }), + updateComment: async (value) => writes.push({ operation: 'update', ...value }), }, }, paginate: async (method, params) => { @@ -28,7 +29,10 @@ const github = { throw new Error(`Unexpected GitHub lookup: ${method}`); }, }; -const AsyncFunction = Object.getPrototypeOf(async function() {}).constructor; -new AsyncFunction('github', 'context', 'process', data.script)(github, data.context, {env: data.env || {}}) +const AsyncFunction = Object.getPrototypeOf(async function () {}).constructor; +new AsyncFunction('github', 'context', 'process', data.script)(github, data.context, { env: data.env || {} }) .then(() => process.stdout.write(JSON.stringify(writes))) - .catch(error => { console.error(error); process.exitCode = 1; }); + .catch((error) => { + console.error(error); + process.exitCode = 1; + }); diff --git a/scripts/castiron/test_custom_code_budget.py b/scripts/castiron/test_custom_code_budget.py index ddf07b6775..3e6e2a0ba3 100644 --- a/scripts/castiron/test_custom_code_budget.py +++ b/scripts/castiron/test_custom_code_budget.py @@ -1,3 +1,4 @@ +# File generated from our OpenAPI spec by Castiron. See CONTRIBUTING.md for details. # Regression tests for the custom-code budget. from __future__ import annotations diff --git a/scripts/castiron/test_custom_code_github.py b/scripts/castiron/test_custom_code_github.py index 33bd73e4e0..8dece12109 100644 --- a/scripts/castiron/test_custom_code_github.py +++ b/scripts/castiron/test_custom_code_github.py @@ -1,3 +1,4 @@ +# File generated from our OpenAPI spec by Castiron. See CONTRIBUTING.md for details. """Trusted GitHub evaluation with real local Git objects and an offline API.""" from __future__ import annotations diff --git a/scripts/castiron/test_custom_code_publication.py b/scripts/castiron/test_custom_code_publication.py index 5290bfbf2f..6ed1a877dd 100644 --- a/scripts/castiron/test_custom_code_publication.py +++ b/scripts/castiron/test_custom_code_publication.py @@ -1,3 +1,4 @@ +# File generated from our OpenAPI spec by Castiron. See CONTRIBUTING.md for details. """Run the trusted publishers against offline GitHub state.""" from __future__ import annotations