Files changed: - .claude/settings.json - .gitea/workflows/ci.yml - .gitea/workflows/nightly.yml - .gitea/workflows/release.yml - .gitea/workflows/tracker-live.yml - .github/hooks/wiki-trace.json - .gitignore - .vibe/hooks.toml - AGENTS.md - CHANGES.md - EVALS.md - INSTALL.md - README.md - VERSION - instructions/bootstrap.md - instructions/preflight.md - instructions/setup-instance.md - instructions/upgrade-instance.md - tools/CONTRACT.md - tools/README.md - tools/chemenu/cli.py - tools/chemenu/commands/dist_cmd.py - tools/chemenu/commands/docs_verify.py - tools/chemenu/commands/doctor.py - tools/chemenu/commands/git_publish.py - tools/chemenu/commands/migrate_cmd.py - tools/chemenu/config.py - tools/chemenu/corpus_cache.py - tools/chemenu/prerequisites.py - tools/chemenu/search/ripgrep.py - tools/chemenu/tests/conftest.py - tools/chemenu/tests/test_dist_upgrade.py - tools/chemenu/tests/test_doctor.py - tools/chemenu/tests/test_preflight.py - tools/chemenu/toolpaths.py - tools/preflight.sh - tools/prerequisites.txt - tools/run_wikitool.py - tools/trace-hook - tools/wikitool
103 lines
4.3 KiB
YAML
103 lines
4.3 KiB
YAML
# Nightly drift check.
|
|
#
|
|
# CI (`ci.yml`) runs on push and deliberately ignores content paths, because
|
|
# `publish` touches kb/, raw/ and work/ on every ingest and running the suite
|
|
# for that is noise. That exclusion is observed to work (Gitea #11), which is
|
|
# exactly why this file exists: since it landed, `lint --fail-on-error` no
|
|
# longer runs when the *corpus* changes. A wiki that drifts into inconsistency
|
|
# over a run of publishes would be seen by nobody.
|
|
#
|
|
# There is also drift that happens with no commit at all. `sources coverage`
|
|
# starts reporting the moment a file appears under `raw/` without a source page
|
|
# claiming it, and `migrate status` only answers when something asks.
|
|
#
|
|
# So: the same checks CI runs against the tree, on a clock instead of a push.
|
|
# `lint --fail-on-error` is the reason; the rest costs seconds.
|
|
#
|
|
# Deliberately absent: `migrate verify --from <rev>`. It needs a comparison
|
|
# revision that means something, and "yesterday" is not one - the invariant
|
|
# diff answers "did *this migration* lose anything", not "did anything change
|
|
# since yesterday". In normal operation a changed page is the desired outcome,
|
|
# not a finding.
|
|
#
|
|
# Runner shape: identical to ci.yml, and for the same reason - `nodejs` is what
|
|
# act_runner needs to execute the JavaScript `checkout` action *inside* the job
|
|
# container, so it is installed before the checkout or the job dies with exit
|
|
# 127. Do not re-derive this; see the header of ci.yml.
|
|
#
|
|
# Failure is meant to be visible without opening the Actions page. That is
|
|
# Gitea's own run notification, not something this workflow builds: a job that
|
|
# files its own issue needs an Actions token with issue-write and a dedup rule,
|
|
# which is more machinery than a red run already carries.
|
|
|
|
name: Nightly
|
|
|
|
on:
|
|
schedule:
|
|
# 03:17 UTC. Gitea evaluates cron in UTC and only for workflows on the
|
|
# default branch, so this file has to live on `main` to fire at all - a
|
|
# test branch proves nothing about it.
|
|
- cron: '17 3 * * *'
|
|
workflow_dispatch:
|
|
|
|
jobs:
|
|
drift:
|
|
runs-on: linux-docker
|
|
container:
|
|
image: debian:trixie-slim
|
|
env:
|
|
# Scope the Iteration Budget Gate to this run instead of letting it fall
|
|
# back to the parent PID, and keep the trace out of the checkout so the
|
|
# working tree stays clean.
|
|
WIKITOOL_SESSION_ID: nightly-${{ github.run_id }}
|
|
WIKI_TRACE_DIR: /tmp/wikitool-trace
|
|
|
|
steps:
|
|
- name: System dependencies
|
|
run: |
|
|
set -eu
|
|
apt-get update -qq
|
|
apt-get install -y --no-install-recommends \
|
|
python3 python3-venv git nodejs ripgrep ca-certificates
|
|
rm -rf /var/lib/apt/lists/*
|
|
|
|
- uses: actions/checkout@v7
|
|
|
|
- name: Tool environment
|
|
# More than `ci.yml`'s equivalent, because this job runs `doctor` and
|
|
# `ci.yml` does not. `doctor` asks whether a *working instance* is
|
|
# correctly configured, and a bare checkout is not one yet - it is the
|
|
# fresh clone instructions/bootstrap.md describes. Two of its checks
|
|
# answered for the container instead of for the repository on the first
|
|
# run (#9): `git-identity` found no `user.name`, and `skills` found
|
|
# nothing published, because `.agents/skills/` and `.claude/skills/`
|
|
# are generated and deliberately not committed. So the bootstrap runs
|
|
# first, and `doctor` then reports on an instance rather than on a
|
|
# tarball. `instructions verify` needs the same, for the same reason.
|
|
run: |
|
|
set -eu
|
|
git config --global --add safe.directory "$GITHUB_WORKSPACE"
|
|
git config --global user.name "Nightly"
|
|
git config --global user.email "nightly@example.invalid"
|
|
tools/preflight.sh
|
|
tools/wikitool instructions sync
|
|
|
|
- name: The instance is still correctly configured
|
|
run: tools/wikitool doctor
|
|
|
|
- name: The stack still describes itself
|
|
run: |
|
|
set -eu
|
|
tools/wikitool docs verify
|
|
tools/wikitool instructions verify
|
|
|
|
- name: The corpus is still structurally sound
|
|
# The one check push-driven CI no longer performs on a content commit.
|
|
run: tools/wikitool lint --fail-on-error
|
|
|
|
- name: Every raw file is still claimed, and the content shape declared
|
|
run: |
|
|
set -eu
|
|
tools/wikitool sources coverage
|
|
tools/wikitool migrate status
|