feat: PowerShell 7 preflight and launcher - preflight.ps1, wikitool.ps1, doctor policy and Mark of the Web checks, pwsh CI job (#151, B)
CI / verify (push) Successful in 2m16s
CI / pwsh (push) Successful in 1m24s
Release / release (push) Successful in 37s

Files changed:
- .gitea/workflows/ci.yml
- CHANGES.md
- INSTALL.md
- README.md
- VERSION
- docs/why-gates-are-code.md
- instructions/bootstrap.md
- instructions/bug-report.md
- instructions/preflight.md
- instructions/setup-instance.md
- instructions/upgrade-instance.md
- tools/CONTRACT.md
- tools/README.md
- tools/bugreport.py
- tools/chemenu/cli.py
- tools/chemenu/commands/dist_cmd.py
- tools/chemenu/commands/doctor.py
- tools/chemenu/prerequisites.py
- tools/chemenu/tests/conftest.py
- tools/chemenu/tests/test_bugreport.py
- tools/chemenu/tests/test_doctor.py
- tools/chemenu/tests/test_preflight.py
- tools/chemenu/tests/test_preflight_pwsh.py
- tools/chemenu/toolpaths.py
- tools/preflight.ps1
- tools/wikitool
- tools/wikitool.ps1
This commit is contained in:
torben committed 2026-10-01 09:52:05 +02:00
1 parent 4035b1ba12
commit 210e0c8286
27 files changed
+1513 -32

No files matched your search

+36 -2
View File
@@ -59,7 +59,7 @@ concern - readable here, never shipped as something to parse.
---
## 8.0.0-beta.14 - 2026-09-30 - Preflight: prerequisites checked and tool paths recorded before wikitool runs (#151, POSIX half)
## 8.0.0-beta.15 - 2026-10-01 - PowerShell 7 preflight and launcher: tools/preflight.ps1, tools/wikitool.ps1, doctor checks for execution policy and Mark of the Web
**Author:** Torben Nehmer
@@ -67,7 +67,7 @@ concern - readable here, never shipped as something to parse.
- Page titles must form valid, unique file names on Windows and macOS: new and rename refuse forbidden characters, reserved names (including INDEX and COLLECTION), a trailing dot or space, and titles that collide with another page by case or Unicode normalization; lint reports existing violations as hard errors - rename each affected page with tools/wikitool rename
- publish without --no-push now exits 1 before committing when the remote is unreachable or not configured, where it used to commit locally and fail at the push - an offline session or a local-only instance must pass --no-push
- new, rename, move and raw accept refuse a target whose path below the instance root is over 160 characters (UTF-16 code units); lint reports existing files over it as Long Paths (advisory) - rename each affected page with tools/wikitool rename, and shorten an incoming/ file name before raw accept
- tools/wikitool now refuses to start (exit 42) until tools/preflight.sh has passed in the checkout - after updating, run tools/preflight.sh once: it checks Python, git and ripgrep, records their paths in .wikitool-tools.json and sets up tools/.venv
- tools/wikitool now refuses to start (exit 42) until tools/preflight.sh (PowerShell 7: tools/preflight.ps1) has passed in the checkout - after updating, run it once: it checks Python, git and ripgrep, records their paths in .wikitool-tools.json and sets up tools/.venv
**Migration:** none required - No page format changes; the rule only refuses titles, and each affected page is renamed individually with tools/wikitool rename
@@ -89,6 +89,7 @@ concern - readable here, never shipped as something to parse.
- Bug-report collector can pseudonymise identities, in two stages
- publish: the gate lists the staged state; a missing or unreachable remote stops before the commit
- Path budget: a file's path stays at 160 characters or fewer so a Windows checkout works without long paths (#163)
- PowerShell 7 preflight and launcher: tools/preflight.ps1, tools/wikitool.ps1, doctor checks for execution policy and Mark of the Web
**Low impact**
- version bump no longer points at version release in its output
@@ -125,6 +126,39 @@ concern - readable here, never shipped as something to parse.
- raw/CONTRACT.md points at the path budget for a name accepted from incoming/
<!-- /wikitool:bumps -->
### PowerShell 7 preflight and launcher: tools/preflight.ps1, tools/wikitool.ps1, doctor checks for execution policy and Mark of the Web
The PowerShell half of #151. Harnesses that run in PowerShell 7 on Windows (GitHub Copilot CLI,
for one) resolve `tools/wikitool` to `tools/wikitool.ps1` before the sh launcher, so without it
the call ended silently. `tools/wikitool.ps1` does what the sh launcher does: it stops with
exit 42 until the preflight has written a complete `.wikitool-tools.json`, accepts either venv
layout, and passes the CLI's exit code through. There is deliberately no `.cmd`.
`tools/preflight.ps1` (`#Requires -Version 7`) answers the same questions as `preflight.sh`
from the same `tools/prerequisites.txt` and writes the same file, byte for byte - CI compares
the two. It is always started as
`pwsh -NoProfile -ExecutionPolicy Bypass -File tools/preflight.ps1`: the bypass holds for that
one process, changes no setting, and lets the script report a Mark of the Web on itself. On
Windows it also reads the machine's `PATH` from the registry, so a session that inherited an
old one still finds a tool installed since, and it never runs or records the Microsoft Store
alias. What only it checks: the effective execution policy (`Restricted` or `AllSigned` is a
stop; when a group policy sets it, the output says that only the administrator can change it
and points at Git Bash) and any `*.ps1` under `tools/` carrying a Mark of the Web from the
internet zone, with the `Unblock-File` line that fixes it.
`doctor` gains `execution-policy` and `script-marks` (Windows only, `OK` elsewhere). The
launcher's STOP text, `toolpaths.PREFLIGHT`, `doctor`'s fix line, the missing-dependency message
and `dist export`'s summary name the PowerShell call beside the sh one. `bugreport.py` starts
`wikitool.ps1` with the same bypass, so a blocking policy shows up as a `doctor` finding instead
of stopping the report. `instructions/preflight.md` carries both calls, the `--set` form and the
two new decision points; `INSTALL.md` has the Windows prerequisite and troubleshooting for the
policy and the Mark of the Web.
The tests run against the same stub machine as the sh ones and skip without `pwsh`. CI gets a
`pwsh` job in the new image `chemenu-ci-pwsh` (`.gitea/pwsh-ci/`, built by
`pwsh-ci-image.yml`, monthly and on change): PSScriptAnalyzer over `tools/*.ps1`, both
preflights compared, `tools/wikitool` started from pwsh, and the PowerShell tests.
### Preflight: prerequisites checked and tool paths recorded before wikitool runs (#151, POSIX half)
The Windows install that prompted this found Python missing, then `rg`, and the agent worked