core/scripts/hooks/pre-push
Claude 68e68589a2
feat(tests): curated-suite membership ratchet — and PR-4's parity pin withdrawn (PR-4, G-7, N-9)
N-9 is the finding, and it PREVENTS work rather than re-scoping it.

WHAT THE PLAN GOT WRONG. N-3 concluded the 23-vs-13 smoke delta was unintended
drift, on two in-repo comments asserting parity, and called that "the strongest
evidence available that the drift was never intended". H-12 repeated it; R-14
built three options on it recommending "raise CI, +46s measured"; PR-4
specified a bidirectional parity pin as deliverable one.

A third artifact answers all of it, and none of them read it.
tests/test_cli_test_suites.py::test_cli_smoke_suite_covers_ci_smoke_gate has
pinned smoke.yml SUBSET-OF TEST_SUITES["smoke"] since before this assessment —
which is why every measurement finds CI-only == 0; a pin, not luck — beneath a
comment headed "DELIBERATELY ONE-DIRECTIONAL — do not 'complete' this by also
asserting local_paths <= ci_paths". Its history is 50fa287d (2026-07-25):
"revert(tests): drop the local-to-CI smoke parity assertion — CI is not a
gate." An earlier agent read the same comment, drew the same inference, made
the assertion symmetric, and reverted it hours later: "That was wrong, and
AGENTS.md says so in a line I had already read."

AGENTS.md:280 — GitHub is "a mirror only; its Actions are billing-locked and
produce dead signals — never chase them." §277 — the workflows are "secondary
observability only." So the local suite is the SOURCE and is deliberately
broader; the delta is the design.

  - PR-4 pin 1: WITHDRAWN. It exists, in the direction that protects something.
  - R-14: premise corrected in the packet. Option A spends 46s on a workflow
    that does not gate; option B would delete real protection for a fiction;
    option C's live half is a two-line comment fix, done here.
  - N-3's exposure claim was too GENEROUS to CI: for a push that skipped the
    local gate there is no automatic check at all. Larger than stated, and not
    closable by editing smoke.yml.

WHAT LANDED. Measured: 749 of 877 test files are in no curated suite. The
plan's mechanism ("assign every orphan, or 749 exclusion reasons") is hollow at
that scale — glob topic-suites ("adr": tests/test_adr_*.py absorbs 172) satisfy
the assertion while changing nothing about what executes, which is precisely the
Third-Door objection the plan levels at G-7's own first formulation. All four
demonstrated incidents (#113, #136, negation-survives-articulation,
speculative-subject-lifecycle) were caused by a NEWLY LANDED orphan; none by a
legacy one.

So: a ratchet. tests/test_suite_membership.py + tests/full_only_baseline.txt.
New orphans fail. The baseline is enforced in BOTH directions — a promoted or
deleted file must leave it, so the list can only shrink — and its count is
pinned so bulk movement is a reviewed decision, in the discipline
test_volume_honesty.py uses.

Also: the gate-guarding pin now runs on the gate. test_cli_test_suites.py lived
in `fast`; the pre-push gate runs smoke + deductive. The pin guarding the gate
did not run on the gate.

Three sabotages, each OBSERVED RED: a new unregistered test file, a stale
baseline entry, the parity pin demoted out of smoke.

Note on the delta: now 12 (local 27, CI 15) because this session added three
pins locally. Under the corrected reading that is the design, not widening
drift — the invariant is CI-only == 0, and that is pinned. The registers now
say so; "ten files" was a measurement, never a target.

Process note: `git checkout --` during sabotage cleanup destroyed uncommitted
edits to core/cli_test.py, which were redone. Backups, not checkout, on files
with unstaged work.

Registers: G-7 CLOSED, H-12 amended, R-14 dissolved in the packet, PR-4
re-specified, N-9 added to plan §0.

Co-Authored-By: Claude <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01Wcw2pnMBwyvmNyQg4uPEt4
2026-07-28 04:03:51 +00:00

81 lines
3.7 KiB
Bash
Executable file

#!/bin/sh
# CORE local-first pre-push gate (weekly-audit T13, 2026-07-22).
#
# Automates the AGENTS.md §Local-First CI Validation Protocol "Pre-Push Gate":
# (1) the `smoke` suite — the merge bar itself, and a SUPERSET of the
# paths smoke.yml names (corrected 2026-07-28, N-9: this line used to
# read "exact CI-gate parity", which has never been true and is not the
# goal. AGENTS.md §277/§280 make the workflows secondary observability
# and GitHub Actions billing-locked dead signals, so this suite is the
# source and is deliberately broader. The invariant that IS enforced —
# smoke.yml never names a path this suite lacks — is pinned by
# tests/test_cli_test_suites.py::test_cli_smoke_suite_covers_ci_smoke_gate),
# (2) the warmed_session consistency lane pin — catches the T13
# telemetry-consistency regression class, which `smoke` does NOT cover
# (the #96 fail-closed resolve + #97 morph override escaped smoke and
# surfaced only in the warmed_session lane), and
# (3) the `deductive` suite — added 2026-07-25.
#
# On (3): this suite was an ASYNC CI concern while deduction serving was a
# capability under development. ADR-0256 ratified the flag ON by default, which
# makes it a regression suite for a LIVE serving path — a push that breaks
# deduction serving would otherwise clear this gate and sit broken on main for
# the window between push and CI. The register-axis regression (red on main for
# the 2026-07-22..24 window, masked by an unrelated flake label) is the direct
# precedent for that failure mode.
#
# It was added WHOLE rather than as a subset because the cost measurement said
# it could be: 285 tests in ~29s, against smoke's 216 in ~62s. There is no
# coverage trade recorded here because none was needed.
#
# The full ~12k fast-lane stays an ASYNC CI concern by design — this gate is
# deliberately targeted so it prevents the regression class without gridlocking
# the push cycle.
#
# Install (per clone): scripts/hooks/install.sh (sets core.hooksPath).
# Emergency bypass: git push --no-verify (defeats the gate — avoid).
set -u
z40="0000000000000000000000000000000000000000"
read_any=0
only_deletes=1
while read -r _local_ref local_sha _remote_ref _remote_sha; do
read_any=1
if [ "${local_sha}" != "${z40}" ] && [ -n "${local_sha}" ]; then
only_deletes=0
fi
done
# Fail-closed: run the gate unless we positively identified a deletion-only push.
if [ "${read_any}" -eq 1 ] && [ "${only_deletes}" -eq 1 ]; then
echo "[pre-push] deletion-only push — nothing to validate."
exit 0
fi
echo "[pre-push] CORE local-first gate: smoke + warmed_session lane pin + deductive"
echo "[pre-push] (1/3) smoke suite (core test --suite smoke) ..."
if ! uv run core test --suite smoke -q; then
echo "[pre-push] BLOCKED: smoke suite failed. Fix before pushing." >&2
echo "[pre-push] (emergency bypass, discouraged: git push --no-verify)" >&2
exit 1
fi
echo "[pre-push] (2/3) warmed_session consistency lane ..."
if ! uv run python -m pytest tests/test_warmed_session_lane.py -q; then
echo "[pre-push] BLOCKED: warmed_session lane failed (T13 regression class)." >&2
echo "[pre-push] (emergency bypass, discouraged: git push --no-verify)" >&2
exit 1
fi
echo "[pre-push] (3/3) deductive suite (core test --suite deductive) ..."
if ! uv run core test --suite deductive -q; then
echo "[pre-push] BLOCKED: deductive suite failed — deduction serving is a" >&2
echo "[pre-push] LIVE capability (ADR-0256), not an experiment." >&2
echo "[pre-push] (emergency bypass, discouraged: git push --no-verify)" >&2
exit 1
fi
echo "[pre-push] gate PASSED — push proceeding."
exit 0