Skip to content

Scope CI and deployment to affected files - #42

Merged
dskvr merged 3 commits into
masterfrom
ci/41-scope-workflows
Sep 5, 2026
Merged

dskvr merged 3 commits into
masterfrom
ci/41-scope-workflows

Conversation

@dskvr

@dskvr dskvr commented Sep 5, 2026 •

Copy link
Copy Markdown
Member

The main CI workflow currently runs native workspace checks and both Arch source-package builds on every PR. This change scopes validation to affected inputs and gives web/docs and workflow contracts their own lightweight workflows.

  • Website, documentation and README changes avoid Tauri/AUR builds. Planning notes and screenshot proofs trigger no automatic validation.
  • AUR PR checks follow the recipes/tools they actually consume; default-branch pushes also cover rolling-package application inputs.
  • A shared-lockfile check compares reachable pnpm dependencies. Replaying the real changes from Give the landing page a minimal identity and reactive signal background #40 produces application run=false, AUR run=false, web run=true.
  • Native proof freshness uses the same application dependency comparison. Website-only lockfile edits preserve the recorded evidence; changed or unverifiable native inputs still invalidate it. Snapshot checks, ancestry, non-lock critical paths and recorded VM evidence are preserved.
  • Docs deployment has explicit web/build/deploy paths. Its shared-lockfile trigger remains conservative, and production concurrency, manual/tag runs and protected environment are preserved.
  • Release auditing requires the successful workspace job and check step, so scope-only workflow success cannot masquerade as full CI evidence. Legacy successful CI remains accepted.

Closes #41.

Scope

CI/platform automation and developer documentation. Existing native/AUR execution steps and the full local pnpm check command are preserved. Three packaging README prose assertions move into docs validation. No new actions or project dependencies; the helper uses Ruby/YAML already required by workflow verification. Branch protection and rulesets are unchanged.

Validation

  • pnpm verify:workflows: 38 Git/lockfile integration scenarios, 84 workflow path/event cases, 27 native-proof/strict-mode regressions, and job/deployment wiring checks passed.
  • pnpm verify:scripts: all existing automation fixtures plus 10 release-audit evidence modes passed. Scope-only success was reproduced as a failure before the audit fix.
  • The new guard accepted actual job metadata from legacy CI run 33961080924.
  • Actionlint 1.7.12, Ruby/Bash syntax, requirements/docs verification, 11 GitHub setup tests, lint/typecheck, all 295 workspace tests, and the web lane's type/test/build/static-site commands passed.
  • The native proof checker reproduced the inherited GSAP-only failure from run 33964723801. pnpm verify:packaging now passes, including native fixture builds and the original four-target snapshot. Strict comparison tests reject changed/unknown inputs and verify no workflow-output writes.
  • Review caught an omitted website requirements check; a failing regression was added, the web lane corrected, and re-review approved. A pre-existing folded deployment condition was corrected to remove its always-true trailing newline.

Boundaries

This PR changes native/AUR workflow definitions, so those checks are expected for this PR. Native fixture packaging checks passed locally. The full local pnpm check passed, including all 295 workspace tests, native/Rust gates, packaging, types and production builds. The fresh hosted CI run passed on 76b224d, including the Validate workspace job and its Run workspace checks step. No new four-VM proof execution or AUR build was performed locally. Manual, scheduled and release-tag entrypoints remain deliberate overrides. GitHub path-diff limits still apply; path-filtered checks should not be made universally required without an appropriate always-reporting aggregate. No deployment or release was performed.

Detailed file inventory and evidence.

Scope workflow events by the inputs they validate and separate AUR, web/docs
and automation contracts. Refine shared lockfile changes using reachable pnpm
dependency projections so website-only dependencies do not start native jobs.
Keep the existing native commands, manual/release entrypoints and production
serialization, while moving packaging README checks into docs validation.

Selective workflow success is no longer sufficient release evidence: require
the executed workspace job and check step, with an explicit full-CI override
when a release ref was filtered. Preserve successful legacy CI evidence.

Constraint: Shared pnpm lockfiles require dependency-aware decisions; unknown data runs validation conservatively
Rejected: Ignore lockfile changes | would miss application and transitive dependency regressions
Confidence: high
Scope-risk: moderate
Directive: Keep workflow path policies aligned with actual inputs and preserve release job/step evidence checks
Directive: Do not globally require path-filtered status checks without an always-reporting aggregate
Tested: 38 Git/lockfile scenarios, 80 workflow path/event cases and 10 release-audit job/step modes
Tested: Actual PR40 replay skips native and AUR work; real legacy CI job metadata passes the new audit guard
Tested: Actionlint 1.7.12, workflow/requirements/docs/script gates, GitHub setup fixtures, lint/typecheck, 295 tests and web builds
Not-tested: Unchanged native/AUR builds were not rerun locally; hosted workflow execution awaits the PR
Related: #41
Record workflow ownership, dependency-aware selection, actual PR40 replay,
release-evidence protection and the intentional limits of path-based checks.

Confidence: high
Scope-risk: narrow
Tested: Recorded outcomes checked against routing tests, actionlint and script validation results
Related: #41
The recorded native snapshot was rejected after the homepage added GSAP to the
shared lockfile, even though application dependency inputs were unchanged.
Reuse the existing application projection for lockfile freshness and retain
the snapshot, ancestry and other critical input checks. The explicit proof
mode rejects uncertain comparisons instead of using CI's run-more fallback.

Constraint: Preserve the original four-target VM evidence and tested commit
Rejected: Ignore lockfile changes | native and shared dependencies must still invalidate proof
Confidence: high
Scope-risk: narrow
Directive: Strict lockfile verification must reject uncertainty and never write workflow outputs
Tested: Original snapshot failure reproduced, then all four recorded targets verified
Tested: 27 proof regressions, 38 impact cases, 84 workflow path/event cases
Tested: Packaging smoke including native fixture builds, Node/Ruby syntax, actionlint, whitespace
Not-tested: Full workspace and hosted validation still running at commit time
@dskvr
dskvr merged commit 42d2466 into master Sep 5, 2026
7 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Scope CI and deployment to the files they validate

1 participant