feat!: installation only from a release, into an empty folder; upstream merge/verify and private-instance.md removed, dist adopt, shell-neutral instructions (#153)
CI / verify (push) Successful in 5m19s
CI / pwsh (push) Successful in 1m55s
Release / release (push) Successful in 36s

Files changed:
- .gitea/workflows/ci.yml
- .gitea/workflows/release.yml
- AGENTS.md
- CHANGES.md
- DEVELOPMENT.md
- EVALS.md
- INSTALL.md
- README.md
- VERSION
- docs/ownership-and-templates.md
- instructions/CONTRACT.md
- instructions/bootstrap.md
- instructions/dev/dev-setup.md
- instructions/dev/stack-dev/SKILL.md
- instructions/gates.md
- instructions/ingest-large-tree.md
- instructions/kb-profiles.md
- instructions/mcp-read-server.md
- instructions/migrations/3.0.0-authoring-conventions.md
- instructions/preflight.md
- instructions/private-instance.md
- instructions/session-setup.md
- instructions/setup-instance.md
- instructions/upgrade-instance.md
- tools/CONTRACT.md
- tools/README.md
- tools/chemenu/cli.py
- tools/chemenu/cli_contract.py
- tools/chemenu/commands/dist_cmd.py
- tools/chemenu/commands/docs_verify.py
- tools/chemenu/commands/doctor.py
- tools/chemenu/commands/git_publish.py
- tools/chemenu/commands/upstream_cmd.py
- tools/chemenu/commands/work_cmd.py
- tools/chemenu/config.py
- tools/chemenu/ownership.py
- tools/chemenu/tests/test_cli.py
- tools/chemenu/tests/test_dist_cmd.py
- tools/chemenu/tests/test_instructions_shell.py
- tools/chemenu/tests/test_preflight.py
- tools/chemenu/tests/test_preflight_pwsh.py
- tools/chemenu/tests/test_run_budget.py
- tools/chemenu/tests/test_upstream_cmd.py
- tools/chemenu/toc.py
- tools/preflight.ps1
- tools/preflight.sh
This commit is contained in:
torben committed 2026-10-01 22:12:09 +02:00
1 parent d0f08d1fba
commit a6d07f97c4
46 files changed
+1314 -1936

No files matched your search

+27 -22
View File
@@ -75,7 +75,8 @@ jobs:
# working tree stays clean for the ignore-rule checks.
WIKITOOL_SESSION_ID: ci-${{ github.run_id }}
WIKI_TRACE_DIR: /tmp/wikitool-trace
DIST_DIR: /tmp/dist
BUILD_DIR: /tmp/build
INSTANCE_DIR: /tmp/instance
steps:
- name: System dependencies
@@ -235,15 +236,24 @@ jobs:
echo 'Then `docs verify` holds VERSION and CHANGES.md together.'
exit 1
- name: Export the distribution
run: tools/wikitool dist export "$DIST_DIR"
- name: Build a release tarball
# The same form release.yml builds - a `dist export` tree under exactly one
# top-level folder, plus its .sha256 - so the replay below starts where a
# user starts: from the archive, not from an exported tree.
run: |
set -eu
name=chemenu-stack-ci
mkdir -p "$BUILD_DIR"
tools/wikitool dist export "${BUILD_DIR}/${name}"
tar -czf "${BUILD_DIR}/${name}.tar.gz" -C "$BUILD_DIR" "$name"
( cd "$BUILD_DIR" && sha256sum "${name}.tar.gz" > "${name}.tar.gz.sha256" )
- name: The distribution works as a fresh instance
# Replays instructions/setup-instance.md end to end, minus its four
# interactive decision points. What this tests is the release artifact
# as an artifact: the documented path from an unpacked export to a
# verified instance. Running one `instructions verify` against the
# export would only have re-checked the file it just copied.
# Replays instructions/setup-instance.md end to end, minus its interactive
# decision points. What this tests is the release artifact as an
# artifact: the documented path from the preflight asset in an empty
# folder to a verified instance. Step 0 runs the asset with --archive
# instead of a download, which is the one difference from a real install.
#
# Personalization is stubbed the same way the identity is: the real
# step interviews the user, so CI substitutes a fixed answer - here,
@@ -253,7 +263,13 @@ jobs:
# what a person would write into them.
run: |
set -eu
cd "$DIST_DIR"
mkdir -p "$INSTANCE_DIR"
cp tools/preflight.sh "$INSTANCE_DIR/preflight.sh"
cd "$INSTANCE_DIR"
sh preflight.sh --archive "${BUILD_DIR}/chemenu-stack-ci.tar.gz"
# Installed in place: the asset is gone, the tree is here.
test ! -e preflight.sh
test -f tools/preflight.sh
git init -q -b main
git config user.name "CI Instance"
git config user.email "ci@example.invalid"
@@ -267,18 +283,7 @@ jobs:
# contracts are adopted verbatim - the shipped text is a working
# default, unlike a personalization file.
grep -v 'wikitool:template-unfilled' kb/CONVENTIONS.md.template > kb/CONVENTIONS.md
for template in kb/*/COLLECTION.md.template types/*.template; do
cp "$template" "${template%.template}"
done
# A fresh instance refuses to run before its preflight (exit 42), so
# this proves both halves: the refusal, then the setup that ends it.
set +e
tools/wikitool doctor > /tmp/before-preflight.txt 2>&1
refused=$?
set -e
test "$refused" -eq 42
grep -q 'tools/preflight.sh' /tmp/before-preflight.txt
tools/preflight.sh
tools/wikitool dist adopt
tools/wikitool instructions sync
tools/wikitool index rebuild
tools/wikitool sources rebuild-index
@@ -306,7 +311,7 @@ jobs:
# The unit tests cover what it collects; this covers that it arrives.
run: |
set -eu
cd "$DIST_DIR"
cd "$INSTANCE_DIR"
python3 tools/bugreport.py --no-trace
bundle=$(ls -d reports/bugreport-*/ | head -n 1)
test -f "$bundle/MANIFEST.md"
+10 -2
View File
@@ -5,7 +5,9 @@
# working wiki instance - no checkout of this repo required. CI already proved
# that path works before this workflow ever runs. Beside it the release carries
# tools/preflight.sh and tools/preflight.ps1 as assets, which download and unpack
# that tarball themselves.
# that tarball themselves, and the two instructions an agent reads before there is
# a tree to read them in: setup-instance.md, which the installation sentence in
# INSTALL.md points at, and the preflight.md its first step leads to.
#
# The tag is created here, by CI, and never by an agent: AGENTS.md invariant 5
# ("never call raw git commit/push") stays intact because nothing in a session
@@ -173,6 +175,12 @@ jobs:
grep -qF "ReleaseChecksumUrl = '${download}/${name}.tar.gz.sha256'" "${BUILD_DIR}/preflight.ps1"
chmod +x "${BUILD_DIR}/preflight.sh"
# The two instructions as the tarball carries them (dist export has already
# stripped them), not as this checkout holds them.
for doc in setup-instance.md preflight.md; do
cp "${BUILD_DIR}/${name}/instructions/${doc}" "${BUILD_DIR}/${doc}"
done
- name: Publish the release
if: steps.version.outputs.skip != 'true'
env:
@@ -198,7 +206,7 @@ jobs:
id="$(printf '%s' "$release" | jq -r '.id')"
echo "Created release ${TAG} (id ${id})."
for asset in "${NAME}.tar.gz" "${NAME}.tar.gz.sha256" preflight.sh preflight.ps1; do
for asset in "${NAME}.tar.gz" "${NAME}.tar.gz.sha256" preflight.sh preflight.ps1 setup-instance.md preflight.md; do
curl -sS -f -X POST "${API}/releases/${id}/assets?name=${asset}" \
-H "Authorization: token ${TOKEN}" \
-F "attachment=@${BUILD_DIR}/${asset}" > /dev/null