diff --git a/.github/workflows/validate.yml b/.github/workflows/validate.yml index 671f9c38..06fe7e5f 100644 --- a/.github/workflows/validate.yml +++ b/.github/workflows/validate.yml @@ -37,8 +37,9 @@ jobs: BEFORE_SHA: ${{ github.event.before }} BASE_SHA: ${{ github.event.pull_request.base.sha }} HEAD_SHA: ${{ github.sha }} - DEFAULT_BRANCH: ${{ github.event.repository.default_branch }} + DEVELOPMENT_BRANCH: dev run: | + git fetch -q origin "refs/heads/$DEVELOPMENT_BRANCH:refs/remotes/origin/$DEVELOPMENT_BRANCH" node scripts/validate-commit-provenance.mjs --check-hook-mode --github-range # Догоняющая проверка процесса (PROCESS.md §10.3). Хуки ловят нарушение на @@ -59,11 +60,12 @@ jobs: BEFORE_SHA: ${{ github.event.before }} BASE_SHA: ${{ github.event.pull_request.base.sha }} HEAD_SHA: ${{ github.sha }} - DEFAULT_BRANCH: ${{ github.event.repository.default_branch }} + DEVELOPMENT_BRANCH: dev TARGET_REF: ${{ github.ref }} # Публичный репозиторий: штатного токена хватает на чтение issue. GH_TOKEN: ${{ github.token }} run: | + git fetch -q origin "refs/heads/$DEVELOPMENT_BRANCH:refs/remotes/origin/$DEVELOPMENT_BRANCH" node scripts/process-gate.mjs --github-range --issues # Классификация изменённых путей: тяжёлые job идут только там, где менялось diff --git a/scripts/process-gate.mjs b/scripts/process-gate.mjs index 8e024840..07cbed88 100644 --- a/scripts/process-gate.mjs +++ b/scripts/process-gate.mjs @@ -425,7 +425,7 @@ function main(argv) { beforeSha: process.env.BEFORE_SHA, baseSha: process.env.BASE_SHA, headSha: process.env.HEAD_SHA, - defaultBranch: process.env.DEFAULT_BRANCH, + developmentBranch: process.env.DEVELOPMENT_BRANCH, }, (args) => git(args, repo).trim()); } if (!range) { diff --git a/scripts/validate-commit-provenance.mjs b/scripts/validate-commit-provenance.mjs index db7ef5d7..f010bba5 100644 --- a/scripts/validate-commit-provenance.mjs +++ b/scripts/validate-commit-provenance.mjs @@ -79,7 +79,7 @@ function gitObjectExists(revision, runner = git) { } export function resolveValidationRange({ - eventName, beforeSha, baseSha, headSha, defaultBranch, + eventName, beforeSha, baseSha, headSha, developmentBranch = 'dev', }, runner = git) { if (!headSha) throw new Error('HEAD_SHA is required'); if (eventName === 'pull_request') { @@ -90,7 +90,11 @@ export function resolveValidationRange({ && gitObjectExists(beforeSha, runner); const comparison = hasBefore ? beforeSha - : `refs/remotes/origin/${defaultBranch || 'main'}`; + // A first push has an all-zero `before`. Issue branches are cut from the + // integration branch, not GitHub's default branch (`main`), so comparing + // with main would pull already-landed dev commits into the validation + // range and judge unrelated/closed issues again (#165). + : `refs/remotes/origin/${developmentBranch || 'dev'}`; return `${runner(['merge-base', comparison, headSha])}..${headSha}`; } @@ -129,7 +133,7 @@ function main(argv) { beforeSha: process.env.BEFORE_SHA, baseSha: process.env.BASE_SHA, headSha: process.env.HEAD_SHA, - defaultBranch: process.env.DEFAULT_BRANCH, + developmentBranch: process.env.DEVELOPMENT_BRANCH, }) : argv[rangeAt + 1]; if (!range) throw new Error('--range requires a git revision range'); diff --git a/test/commit-provenance.test.mjs b/test/commit-provenance.test.mjs index 4248ba4c..5e3f8e39 100644 --- a/test/commit-provenance.test.mjs +++ b/test/commit-provenance.test.mjs @@ -39,7 +39,7 @@ test('hook mode requires the executable index bit', () => { ); }); -test('validation range uses ancestry for PRs, normal pushes and new branches', () => { +test('validation range uses PR ancestry, push before and dev for a new issue branch', () => { const calls = []; const runner = (args) => { calls.push(args); @@ -50,11 +50,13 @@ test('validation range uses ancestry for PRs, normal pushes and new branches', ( }, runner), 'common-base..head'); assert.deepEqual(calls.at(-1), ['merge-base', 'base', 'head']); assert.equal(resolveValidationRange({ - eventName: 'push', beforeSha: '000000', headSha: 'head', defaultBranch: 'main', + // GitHub's default branch is main, but House Plan issue branches start at + // dev. The all-zero first-push SHA must therefore compare with origin/dev. + eventName: 'push', beforeSha: '000000', headSha: 'head', }, runner), 'common-base..head'); - assert.deepEqual(calls.at(-1), ['merge-base', 'refs/remotes/origin/main', 'head']); + assert.deepEqual(calls.at(-1), ['merge-base', 'refs/remotes/origin/dev', 'head']); assert.equal(resolveValidationRange({ - eventName: 'push', beforeSha: 'before', headSha: 'head', defaultBranch: 'main', + eventName: 'push', beforeSha: 'before', headSha: 'head', developmentBranch: 'dev', }, runner), 'common-base..head'); assert.deepEqual(calls.at(-1), ['merge-base', 'before', 'head']); });