ci: make the strict typing gate actually run (#42)

r6 Medium: AC4 was measurable only on a developer's machine — no
workflow invoked mypy, so a typing regression in any of the six
allowlist modules reached dev unnoticed while the issue claimed
measurable backend quality. Coverage and lint had continuous gates;
typing had a text comparison of a committed list.

The backend job now runs mypy right after ruff, from the same pinned
dependency file (mypy==2.3.1 — an unpinned checker would redden on code
that never changed). The step derives its module list from the
pyproject.toml strict allowlist instead of duplicating it, because a
drifted duplicate is a green step checking the wrong modules, and it
refuses an empty list rather than passing silently.

Guarded twice: a contract test pins all three facts (pinned checker,
a step that really invokes it, list read from pyproject) and the new
typing-gate-stops-running mutant reddens when the invocation is
neutered.

User-Visible: no
Issue: #42
This commit is contained in:
Codex
2026-08-30 22:00:52 +03:00
parent 01fbb77f3b
commit dddbbe5522
5 changed files with 65 additions and 1 deletions
+6 -1
View File
@@ -1552,10 +1552,15 @@ their passports; `scripts/config-audit.mjs` treats both as `current`.
- `tests_backend/requirements.txt` is the single source of backend CI
dependencies (validate.yml and mutation-gate.yml install from it; the file
itself was introduced by #392, which also moved the harness to python 3.14
and the current Home Assistant — #42 adds ruff to it for the lint step).
and the current Home Assistant — #42 adds ruff and mypy to it for the lint
and typing steps).
- `pyproject.toml` configures ruff (E/F/B/I, E501 excluded by decision) and
mypy strict for a grow-only allowlist of pure modules; the completeness
guard lives in `tests_backend/test_backend_quality.py`.
- Both linters RUN in the backend CI job: the typing step derives its module
list from the `pyproject.toml` allowlist rather than repeating it, refuses an
empty list, and is itself guarded by a test plus the `typing-gate-stops-
running` mutant — a configured-but-unexecuted gate measures nothing.
- The backend CI job measures branch coverage (pure + HA harness combined),
fails below `scripts/backend-coverage-baseline.txt` and refuses to run when
the HA harness would silently skip.