Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
8 changes: 4 additions & 4 deletions .castiron.stats.yml
Original file line number Diff line number Diff line change
@@ -1,8 +1,8 @@
schema_version: 1
generation_id: e6e3b1ee-91de-48d6-8b7e-8021df4212ea
generation_id: 63ac4032-0941-40e4-83ee-ae3cde830f2b
openapi_spec_hash: 8aa23d19137079c724365bd6cadd0858
openapi_transformed_spec_hash: d591fedadfdd68837534b2574782bf81
config_hash: 70e6e763ed8ac8c4038de193a96c771d
codegen_sha: b56a245c7ab1a741a95e6ee6bd7357f9ca4b6e52
codegen_hash: 6e391d7d5910f75be379f99a0ac4529af9a70461a6f2c7ad0a6f5d77cf00d639
public_codegen_sha: 8bef4a806756c8b3db141bd6a1235fcc7148e854
codegen_sha: e3fd8becca14771332e4d595da08776af0d652cb
codegen_hash: 4cb3a4a438d6e8d094e5706b634fb67ebd763b682c54876704645012544862a3
public_codegen_sha: bd28123c82f56c293b4b5f48f369c5f404d98f09
8 changes: 6 additions & 2 deletions scripts/castiron/CUSTOM_CODE.md
Original file line number Diff line number Diff line change
@@ -1,3 +1,5 @@
<!-- File generated from our OpenAPI spec by Castiron. See CONTRIBUTING.md for details. -->

# Custom code

The custom-code reporter measures the SDK's remaining customization of generated
Expand Down Expand Up @@ -77,8 +79,10 @@ The trusted run summary reports additions, deletions, total, mixed-file count,
headroom, largest patches, and exact policy/candidate/generated revisions. The
existing custom-code comment remains unchanged, including when the budget fails.
The trusted compute job reuses its own report, never the candidate's artifacts.
The checker, policy, and workflows are maintained in the SDK and preserved
through the normal three-way merge during generation.
The checker, workflows, and offline tests are generated from shared Castiron
templates. The budget policy remains repository-owned and is never generated.
Repository-specific customizations are preserved through the normal three-way
merge during generation.

## Local verification

Expand Down
8 changes: 5 additions & 3 deletions scripts/castiron/README.md
Original file line number Diff line number Diff line change
Expand Up @@ -7,7 +7,9 @@ for cross-SDK improvements; repository-specific customizations use the normal
three-way merge and are allowed.
The reporter uses Python 3.10+, Git, and `gh`; it does not import SDK code.

Run `python3 scripts/castiron/test_custom_code_report.py` for focused tests.
Run `python3 -m unittest discover -s scripts/castiron -p 'test_custom_code*.py'`
for the offline suite. Install Node.js to exercise the workflow publishers too.
See [CUSTOM_CODE.md](CUSTOM_CODE.md) for budget policy and activation.
The report comment includes commands to inspect the exact custom-code patch.
Public reporting uses only public snapshots and needs no private repository access.

Expand All @@ -17,8 +19,8 @@ Its hash format is documented in the reporter. Only `.github/actions/` and

The read-only pull-request workflow runs on every branch, including drafts and
forks. A separate read-only `workflow_run` job computes the authoritative report from
current, GitHub-associated base/head Git objects using the trusted workflow
revision. It fetches those objects into a new bare repository and never checks
the captured main checkout and GitHub-associated PR head. Merge groups are
checked independently against current main. It fetches those objects into a new bare repository and never checks
out or executes PR code. The comment-writing job consumes only the artifact
from that trusted job, rechecks freshness, and links to its report and patch.
PR-produced reports are advisory run output, not the published assessment. The
Expand Down
3 changes: 2 additions & 1 deletion scripts/castiron/custom_code_budget.py
Original file line number Diff line number Diff line change
@@ -1,8 +1,9 @@
#!/usr/bin/env python3
# File generated from our OpenAPI spec by Castiron. See CONTRIBUTING.md for details.
"""SDK custom-code budget gate. Run only from a trusted checkout, never PR code.

Reuses Castiron's vendored snapshot verifier and generated-file accounting. This
file and its workflow are maintained in the SDK repository.
file and its workflows are generated from shared Castiron templates.
"""

from __future__ import annotations
Expand Down
1 change: 1 addition & 0 deletions scripts/castiron/custom_code_test_support.py
Original file line number Diff line number Diff line change
@@ -1,3 +1,4 @@
# File generated from our OpenAPI spec by Castiron. See CONTRIBUTING.md for details.
"""Small Git/checkpoint fixture shared by the offline Castiron tests."""

from __future__ import annotations
Expand Down
22 changes: 13 additions & 9 deletions scripts/castiron/fixtures/github_publisher.cjs
Original file line number Diff line number Diff line change
@@ -1,21 +1,22 @@
// File generated from our OpenAPI spec by Castiron. See CONTRIBUTING.md for details.
// Execute the real workflow script with an offline GitHub API and capture writes.
const fs = require('node:fs');
const data = JSON.parse(fs.readFileSync(0, 'utf8'));
const writes = [];
const github = {
rest: {
actions: {getWorkflowRun: async () => ({data: data.run})},
pulls: {get: async () => ({data: data.current}), list: 'pulls'},
git: {getRef: async () => ({data: {object: {sha: data.current.base.sha}}})},
actions: { getWorkflowRun: async () => ({ data: data.run }) },
pulls: { get: async () => ({ data: data.current }), list: 'pulls' },
git: { getRef: async () => ({ data: { object: { sha: data.current.base.sha } } }) },
repos: {
createCommitStatus: async value => writes.push(value),
createCommitStatus: async (value) => writes.push(value),
listCommitStatusesForRef: 'statuses',
listPullRequestsAssociatedWithCommit: 'associations',
},
issues: {
listComments: 'comments',
createComment: async value => writes.push({operation: 'create', ...value}),
updateComment: async value => writes.push({operation: 'update', ...value}),
createComment: async (value) => writes.push({ operation: 'create', ...value }),
updateComment: async (value) => writes.push({ operation: 'update', ...value }),
},
},
paginate: async (method, params) => {
Expand All @@ -28,7 +29,10 @@ const github = {
throw new Error(`Unexpected GitHub lookup: ${method}`);
},
};
const AsyncFunction = Object.getPrototypeOf(async function() {}).constructor;
new AsyncFunction('github', 'context', 'process', data.script)(github, data.context, {env: data.env || {}})
const AsyncFunction = Object.getPrototypeOf(async function () {}).constructor;
new AsyncFunction('github', 'context', 'process', data.script)(github, data.context, { env: data.env || {} })
.then(() => process.stdout.write(JSON.stringify(writes)))
.catch(error => { console.error(error); process.exitCode = 1; });
.catch((error) => {
console.error(error);
process.exitCode = 1;
});
1 change: 1 addition & 0 deletions scripts/castiron/test_custom_code_budget.py
Original file line number Diff line number Diff line change
@@ -1,3 +1,4 @@
# File generated from our OpenAPI spec by Castiron. See CONTRIBUTING.md for details.
# Regression tests for the custom-code budget.
from __future__ import annotations

Expand Down
1 change: 1 addition & 0 deletions scripts/castiron/test_custom_code_github.py
Original file line number Diff line number Diff line change
@@ -1,3 +1,4 @@
# File generated from our OpenAPI spec by Castiron. See CONTRIBUTING.md for details.
"""Trusted GitHub evaluation with real local Git objects and an offline API."""

from __future__ import annotations
Expand Down
1 change: 1 addition & 0 deletions scripts/castiron/test_custom_code_publication.py
Original file line number Diff line number Diff line change
@@ -1,3 +1,4 @@
# File generated from our OpenAPI spec by Castiron. See CONTRIBUTING.md for details.
"""Run the trusted publishers against offline GitHub state."""

from __future__ import annotations
Expand Down
Loading