Compare commits

..
3 Commits
Author SHA1 Message Date
archvillainette 4d38967078 fix(topdata): let pinned TLK ids evict stale state owners (#48)
build-binaries / build-binaries (push) Successful in 2m14s
## Problem

The custom palette taxonomy (#46) pins display strings to fixed TLK ids in `tlk/custom.tlk.yml`, and `registerInlineAtID` demanded each pinned id be free. But `.tlk_state.json` is **gitignored and per-machine** — each dev grows their own copy, and before #46 every ref got its id dynamically (first-come-first-served).

On any machine whose state predates #46, a ref could have already parked on a now-pinned id. That fails the build:

```
topdata validation failed with 1 error(s): error: native topdata buildability check failed:
TLK id 2689 is already reserved by "feat:yuanti/alternate_form.feat"
```

It only passes on machines whose state was regenerated after #46 (pinned window already clean). The `allocateID` reserved-skip that #46 added protects a *fresh* build, but does nothing about a *stale cache*.

## Fix

Make the pin authoritative over the per-machine cache. A stale cached owner sitting on a pinned id is evicted and reallocated a fresh id when next made active; only two pins fighting over the same id in `custom.tlk.yml` is now an error. This self-heals on the next build — no manual `.tlk_state.json` deletion needed.

Caveat: the evicted ref's strref shifts on affected machines. That's unavoidable (something must move off the pinned id), and dynamic strrefs were never stable across machines anyway.

## Tests

Added `TestBuildStandaloneTLKPinEvictsStaleStateOwner` (seeds a pre-#46 state with a feat parked on the pinned id, asserts the build succeeds, the pin owns it, and the feat is reallocated). Full `internal/topdata` suite + `go vet` pass.

🤖 Generated with [Claude Code](https://claude.com/claude-code)Reviewed-on: #48
Reviewed-by: xtul <mpiasecki720@protonmail.com>
Co-authored-by: vickydotbat <vickydotbat@tutamail.com>
2026-07-22 18:17:04 +00:00
archvillainette 7b481ca0c0 custom palette taxonomy (#46)
build-binaries / build-binaries (push) Successful in 2m12s
Implements custom palette taxonomyReviewed-on: #46

Co-authored-by: vickydotbat <vickydotbat@tutamail.com>
2026-07-22 17:03:58 +00:00
archvillainette b058846e16 chore(ci): consolidate Gitea CI (#47)
## Summary

- consolidate vet, tests, lint, smoke, and cross-build into one pull-request-only job
- keep binary releases strictly v-tag-only with release-only write permission
- retain wrapper synchronization only for canonical wrapper changes on main
- pin actions and enforce exact trigger contracts

## Verification

- nix develop --command make check
- trigger mutation contract
- 28-workflow cross-repository actionlint audit

Generated with Claude CodeReviewed-on: #47

Co-authored-by: vickydotbat <vickydotbat@tutamail.com>
2026-07-22 16:54:26 +00:00
11 changed files with 425 additions and 55 deletions
+9 -13
View File
@@ -1,25 +1,22 @@
# Cross-platform Crucible binaries (D7 trigger standard): # Cross-platform Crucible release binaries: a v* tag builds all targets,
# PR / push main -> cross-build ALL targets to prove they compile (no publish) # then uploads them, SHA256SUMS, and the canonical wrappers to its Gitea release.
# tag v* -> build all targets + SHA256SUMS, upload to the Gitea release
# Crucible is pure Go (CGO_ENABLED=0), so cross-compiling is a fast loop. # Crucible is pure Go (CGO_ENABLED=0), so cross-compiling is a fast loop.
name: build-binaries name: build-binaries
on: on:
pull_request:
push: push:
branches: [main]
tags: ['v*'] tags: ['v*']
paths-ignore:
- "docs/**" permissions:
- "README.md" code: read
- "AGENTS.md" releases: write
- "LICENSE"
jobs: jobs:
build-binaries: build-binaries:
runs-on: nix-docker runs-on: nix-docker
timeout-minutes: 30
steps: steps:
- uses: actions/checkout@v4 - uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683 # v4.2.2
with: { fetch-depth: 0 } with: { fetch-depth: 0 }
- name: Cross-build all targets - name: Cross-build all targets
@@ -45,9 +42,8 @@ jobs:
' '
- name: Upload to Gitea release - name: Upload to Gitea release
if: github.event_name == 'push' && startsWith(github.ref, 'refs/tags/v')
env: env:
TOKEN: ${{ secrets.GITHUB_TOKEN }} TOKEN: ${{ secrets.GITEA_TOKEN }}
TAG: ${{ github.ref_name }} TAG: ${{ github.ref_name }}
REPO: ${{ github.repository }} REPO: ${{ github.repository }}
SERVER: ${{ github.server_url }} SERVER: ${{ github.server_url }}
+47
View File
@@ -0,0 +1,47 @@
# Pull-request validation for Crucible. Releases and wrapper synchronization
# have their own narrow workflows because they need tag/main events.
name: ci
on:
pull_request:
permissions: read-all
jobs:
ci:
runs-on: nix-docker
timeout-minutes: 60
steps:
- uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683 # v4.2.2
with:
fetch-depth: 0
- name: vet + test + lint
run: |
nix develop --command bash -c '
set -euo pipefail
go vet ./...
go test ./...
shellcheck scripts/*.sh
yamllint .gitea
'
- name: binary smoke (fail-closed contract)
run: nix develop --command make smoke
- name: Cross-build all targets
run: |
nix develop --command bash -c '
set -euo pipefail
sha="$(git rev-parse --short=12 HEAD)"
ldflags="-s -w -X git.westgate.pw/ShadowsOverWestgate/sow-tools/internal/buildinfo.Version=${sha}"
rm -rf dist && mkdir -p dist
export CGO_ENABLED=0
for target in linux/amd64 linux/arm64 darwin/amd64 darwin/arm64 windows/amd64 windows/arm64; do
os="${target%/*}"; arch="${target#*/}"
ext=""; [ "$os" = windows ] && ext=".exe"
echo "building crucible-${os}-${arch}${ext}"
GOOS="$os" GOARCH="$arch" go build -trimpath -ldflags "$ldflags" \
-o "dist/crucible-${os}-${arch}${ext}" ./cmd/crucible
done
'
+4 -1
View File
@@ -14,11 +14,14 @@ on:
- 'wrappers/crucible.sh' - 'wrappers/crucible.sh'
- 'wrappers/crucible.ps1' - 'wrappers/crucible.ps1'
permissions: read-all
jobs: jobs:
sync: sync:
runs-on: nix-docker runs-on: nix-docker
timeout-minutes: 30
steps: steps:
- uses: actions/checkout@v4 - uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683 # v4.2.2
- name: Open sync PRs to consumers - name: Open sync PRs to consumers
env: env:
-30
View File
@@ -1,30 +0,0 @@
# Lint + unit tests for the Crucible suite. PR-first: PRs + push to main (D7).
name: test
on:
push:
branches: [main]
paths-ignore:
- "docs/**"
- "README.md"
- "AGENTS.md"
- "LICENSE"
pull_request:
jobs:
test:
runs-on: nix-docker
steps:
- uses: actions/checkout@v4
with: { fetch-depth: 0 }
- name: vet + test + lint
run: |
nix develop --command bash -c '
set -euo pipefail
go vet ./...
go test ./...
shellcheck scripts/*.sh
yamllint .gitea
'
- name: binary smoke (fail-closed contract)
run: nix develop --command make smoke
+1
View File
@@ -6,6 +6,7 @@ SHELL := bash
check: vet test check: vet test
shellcheck scripts/*.sh shellcheck scripts/*.sh
yamllint .gitea yamllint .gitea
bash tests/workflow-contract.sh
vet: vet:
go vet ./... go vet ./...
+6 -5
View File
@@ -78,13 +78,14 @@ This retires the old habit of checking in `nwn-tool` / `sow-toolkit`.
## CI ## CI
PR-first (D7): checks run on pull requests and on push to `main`; the only PR-first (D7): checks run once on pull requests; the only publish event is a
publish event is a `v*` tag (see `runbooks/ci-trigger-standard.md` in sow-docs, `v*` tag (see `runbooks/ci-trigger-standard.md` in sow-docs,
https://git.westgate.pw/ShadowsOverWestgate/sow-docs). https://git.westgate.pw/ShadowsOverWestgate/sow-docs).
- `test.yml` — vet, test, shellcheck, yamllint, binary smoke (PR + main). - `ci.yml` — vet, test, shellcheck, yamllint, binary smoke, and cross-build all
- `build-binaries.yml` — cross-build all targets (PR + main); on a `v*` tag, upload targets once per pull request.
the binaries, `SHA256SUMS`, and the wrappers to the Gitea release. - `build-binaries.yml` — on a `v*` tag, cross-build and upload the binaries,
`SHA256SUMS`, and the wrappers to the Gitea release.
- `sync-wrappers.yml` — on a `main` push that touches `wrappers/`, auto-PR the - `sync-wrappers.yml` — on a `main` push that touches `wrappers/`, auto-PR the
canonical wrappers to the consumer repos in `wrappers/consumers.txt`. canonical wrappers to the consumer repos in `wrappers/consumers.txt`.
Consumer drift checks run after those PRs merge to `main`, not on the PRs Consumer drift checks run after those PRs merge to `main`, not on the PRs
+3
View File
@@ -410,6 +410,9 @@ func buildNativeUnchecked(p *project.Project, opts NativeBuildOptions, progress
if err != nil { if err != nil {
return BuildResult{}, err return BuildResult{}, err
} }
if err := loadStandaloneTLKStrings(sourceDir, compiler); err != nil {
return BuildResult{}, err
}
output2DA := compiled2DAOutputDir(p) output2DA := compiled2DAOutputDir(p)
outputTLK := compiledTLKOutputDir(p) outputTLK := compiledTLKOutputDir(p)
+84 -3
View File
@@ -13,6 +13,7 @@ import (
"strings" "strings"
"golang.org/x/text/encoding/charmap" "golang.org/x/text/encoding/charmap"
"gopkg.in/yaml.v3"
) )
const ( const (
@@ -74,6 +75,16 @@ type tlkEntryData struct {
SoundLength float32 SoundLength float32
} }
type standaloneTLKDocument struct {
Schema string `yaml:"schema"`
BaseStrref int `yaml:"base_strref"`
Strings []struct {
Key string `yaml:"key"`
Text string `yaml:"text"`
ID *int `yaml:"id"`
} `yaml:"strings"`
}
type tlkStateDocument struct { type tlkStateDocument struct {
Version int `json:"version"` Version int `json:"version"`
Language string `json:"language"` Language string `json:"language"`
@@ -98,6 +109,7 @@ type tlkCompiler struct {
active map[string]tlkEntryData active map[string]tlkEntryData
activeKeys map[string]struct{} activeKeys map[string]struct{}
reservedByID map[int]string reservedByID map[int]string
pinnedByID map[int]string
nextID int nextID int
} }
@@ -147,6 +159,7 @@ func newTLKCompiler(sourceDir string, legacy *legacyTLKData) (*tlkCompiler, erro
active: map[string]tlkEntryData{}, active: map[string]tlkEntryData{},
activeKeys: map[string]struct{}{}, activeKeys: map[string]struct{}{},
reservedByID: reserved, reservedByID: reserved,
pinnedByID: map[int]string{},
nextID: nextID, nextID: nextID,
} }
if legacy != nil { if legacy != nil {
@@ -157,6 +170,42 @@ func newTLKCompiler(sourceDir string, legacy *legacyTLKData) (*tlkCompiler, erro
return compiler, nil return compiler, nil
} }
func loadStandaloneTLKStrings(sourceDir string, compiler *tlkCompiler) error {
path := filepath.Join(sourceDir, "tlk", "custom.tlk.yml")
raw, err := os.ReadFile(path)
if err != nil {
if os.IsNotExist(err) {
return nil
}
return fmt.Errorf("read %s: %w", path, err)
}
var document standaloneTLKDocument
if err := yaml.Unmarshal(raw, &document); err != nil {
return fmt.Errorf("parse %s: %w", path, err)
}
if document.Schema != "sow-topdata/tlk/v1" {
return fmt.Errorf("%s: unsupported schema %q", path, document.Schema)
}
if document.BaseStrref != customTLKBase {
return fmt.Errorf("%s: base_strref must be %d", path, customTLKBase)
}
seen := map[string]struct{}{}
for index, entry := range document.Strings {
entry.Key = strings.TrimSpace(entry.Key)
if entry.Key == "" || entry.Text == "" || entry.ID == nil {
return fmt.Errorf("%s: strings[%d] requires key, text, and id", path, index)
}
if _, ok := seen[entry.Key]; ok {
return fmt.Errorf("%s: duplicate string key %q", path, entry.Key)
}
seen[entry.Key] = struct{}{}
if err := compiler.registerInlineAtID(entry.Key, *entry.ID, tlkEntryData{Text: entry.Text}); err != nil {
return err
}
}
return nil
}
func loadBaseDialogData(path string) (*legacyTLKData, error) { func loadBaseDialogData(path string) (*legacyTLKData, error) {
if _, err := os.Stat(path); err != nil { if _, err := os.Stat(path); err != nil {
if os.IsNotExist(err) { if os.IsNotExist(err) {
@@ -329,6 +378,33 @@ func (c *tlkCompiler) registerInline(key string, entry tlkEntryData) (tlkCompile
}, nil }, nil
} }
func (c *tlkCompiler) registerInlineAtID(key string, id int, entry tlkEntryData) error {
if id < 0 {
return fmt.Errorf("TLK key %q has negative id %d", key, id)
}
// The pin is authoritative over the per-machine .tlk_state.json cache: a
// stale mapping that dynamically grabbed this id on an older build must
// yield so the pinned key can take it. Only a genuine clash between two
// pins in custom.tlk.yml is an author error.
if owner, ok := c.pinnedByID[id]; ok && owner != key {
return fmt.Errorf("TLK id %d is pinned by both %q and %q", id, owner, key)
}
if mapping, ok := c.state.Entries[key]; ok && mapping.ID != id {
// This key held a different cached id; release it so the pin wins.
if c.reservedByID[mapping.ID] == key {
delete(c.reservedByID, mapping.ID)
}
}
if owner, ok := c.reservedByID[id]; ok && owner != key {
// Evict the stale owner; it gets a fresh id when next made active.
delete(c.state.Entries, owner)
}
c.pinnedByID[id] = key
c.state.Entries[key] = tlkStateMapping{ID: id}
c.reservedByID[id] = key
return c.markActive(key, entry)
}
func (c *tlkCompiler) customStrrefForKey(key string) int { func (c *tlkCompiler) customStrrefForKey(key string) int {
return customTLKBase + c.state.Entries[key].ID return customTLKBase + c.state.Entries[key].ID
} }
@@ -338,6 +414,7 @@ func (c *tlkCompiler) markActive(key string, entry tlkEntryData) error {
if !ok { if !ok {
mapping = tlkStateMapping{ID: c.allocateID(), Retired: false} mapping = tlkStateMapping{ID: c.allocateID(), Retired: false}
c.state.Entries[key] = mapping c.state.Entries[key] = mapping
c.reservedByID[mapping.ID] = key
} }
existing, ok := c.active[key] existing, ok := c.active[key]
if ok && existing != entry { if ok && existing != entry {
@@ -351,9 +428,13 @@ func (c *tlkCompiler) markActive(key string, entry tlkEntryData) error {
} }
func (c *tlkCompiler) allocateID() int { func (c *tlkCompiler) allocateID() int {
id := c.nextID for {
c.nextID++ id := c.nextID
return id c.nextID++
if _, reserved := c.reservedByID[id]; !reserved {
return id
}
}
} }
func (c *tlkCompiler) finish(outputDir, tlkName string) (int, error) { func (c *tlkCompiler) finish(outputDir, tlkName string) (int, error) {
+31 -3
View File
@@ -2,6 +2,7 @@ package topdata
import ( import (
"bytes" "bytes"
"encoding/json"
"errors" "errors"
"fmt" "fmt"
"io" "io"
@@ -13,6 +14,7 @@ import (
"time" "time"
"git.westgate.pw/ShadowsOverWestgate/sow-tools/internal/erf" "git.westgate.pw/ShadowsOverWestgate/sow-tools/internal/erf"
"git.westgate.pw/ShadowsOverWestgate/sow-tools/internal/gff"
"git.westgate.pw/ShadowsOverWestgate/sow-tools/internal/project" "git.westgate.pw/ShadowsOverWestgate/sow-tools/internal/project"
) )
@@ -215,10 +217,15 @@ func collectTopPackageResources(p *project.Project, compiled2DADir string) ([]er
if err != nil { if err != nil {
return err return err
} }
if skipTopPackageAsset(rel) { var resource erf.Resource
return nil if strings.HasSuffix(strings.ToLower(rel), ".itp.json") {
resource, err = topPackageITPResourceFromJSON(path)
} else {
if skipTopPackageAsset(rel) {
return nil
}
resource, err = topPackageResourceFromPath(path)
} }
resource, err := topPackageResourceFromPath(path)
if err != nil { if err != nil {
return err return err
} }
@@ -251,6 +258,27 @@ func collectTopPackageResources(p *project.Project, compiled2DADir string) ([]er
return resources, assetFiles, nil return resources, assetFiles, nil
} }
func topPackageITPResourceFromJSON(path string) (erf.Resource, error) {
raw, err := os.ReadFile(path)
if err != nil {
return erf.Resource{}, fmt.Errorf("read %s: %w", path, err)
}
var document gff.Document
if err := json.Unmarshal(raw, &document); err != nil {
return erf.Resource{}, fmt.Errorf("parse %s: %w", path, err)
}
if document.FileType != "ITP " {
return erf.Resource{}, fmt.Errorf("%s: file_type must be ITP", path)
}
var payload bytes.Buffer
if err := gff.Write(&payload, document); err != nil {
return erf.Resource{}, fmt.Errorf("compile %s: %w", path, err)
}
resourceType, _ := erf.HAKResourceTypeForExtension("itp")
name := strings.TrimSuffix(filepath.Base(path), ".itp.json")
return erf.Resource{Name: strings.ToLower(name), Type: resourceType, Data: payload.Bytes(), Size: int64(payload.Len())}, nil
}
func shouldSkipTopDataSourceDir(path string, skipDirs map[string]struct{}) bool { func shouldSkipTopDataSourceDir(path string, skipDirs map[string]struct{}) bool {
_, ok := skipDirs[filepath.Clean(path)] _, ok := skipDirs[filepath.Clean(path)]
return ok return ok
+156
View File
@@ -15,6 +15,7 @@ import (
"time" "time"
"git.westgate.pw/ShadowsOverWestgate/sow-tools/internal/erf" "git.westgate.pw/ShadowsOverWestgate/sow-tools/internal/erf"
"git.westgate.pw/ShadowsOverWestgate/sow-tools/internal/gff"
"git.westgate.pw/ShadowsOverWestgate/sow-tools/internal/project" "git.westgate.pw/ShadowsOverWestgate/sow-tools/internal/project"
) )
@@ -2396,6 +2397,107 @@ func TestBuildUsesNativeModeForInlineTLKAndWritesState(t *testing.T) {
} }
} }
func TestBuildNativeCompilesStandaloneTLKStrings(t *testing.T) {
root := testProjectRoot(t)
mkdirAll(t, filepath.Join(root, "topdata", "data", "feat"))
mkdirAll(t, filepath.Join(root, "topdata", "tlk"))
writeFile(t, filepath.Join(root, "topdata", "base_dialog.json"), "{}\n")
writeFile(t, filepath.Join(root, "topdata", "data", "feat", "base.json"), `{
"output": "feat.2da",
"columns": ["LABEL", "FEAT", "DESCRIPTION"],
"rows": [{
"id": 0,
"key": "feat:test",
"LABEL": "TEST_LABEL",
"FEAT": {"tlk": {"key": "feat:test.name", "text": "Test Feat"}},
"DESCRIPTION": "****"
}]
}`+"\n")
writeFile(t, filepath.Join(root, "topdata", "tlk", "custom.tlk.yml"), `schema: sow-topdata/tlk/v1
base_strref: 16777216
strings:
- key: palette.creatures.npcs
text: NPCs
id: 50
`)
result, err := BuildNative(testProject(root), nil)
if err != nil {
t.Fatalf("BuildNative failed: %v", err)
}
stateRaw, err := os.ReadFile(filepath.Join(root, "topdata", tlkStateFile))
if err != nil {
t.Fatalf("read tlk state: %v", err)
}
var state tlkStateDocument
if err := json.Unmarshal(stateRaw, &state); err != nil {
t.Fatalf("parse tlk state: %v", err)
}
mapping, ok := state.Entries["palette.creatures.npcs"]
if !ok || mapping.Retired {
t.Fatalf("expected active standalone TLK mapping, got %#v", mapping)
}
if got := state.Entries["feat:test.name"].ID; got != 0 || mapping.ID != 50 {
t.Fatalf("standalone strings must keep pinned ids without shifting dataset refs, got dataset=%d standalone=%d", got, mapping.ID)
}
tlkRaw, err := os.ReadFile(filepath.Join(result.OutputTLKDir, defaultTLKName))
if err != nil {
t.Fatalf("read compiled tlk: %v", err)
}
if !bytes.Contains(tlkRaw, []byte("NPCs")) {
t.Fatalf("compiled TLK does not contain standalone text")
}
}
func TestBuildStandaloneTLKPinEvictsStaleStateOwner(t *testing.T) {
root := testProjectRoot(t)
mkdirAll(t, filepath.Join(root, "topdata", "data", "feat"))
mkdirAll(t, filepath.Join(root, "topdata", "tlk"))
writeFile(t, filepath.Join(root, "topdata", "base_dialog.json"), "{}\n")
writeFile(t, filepath.Join(root, "topdata", "data", "feat", "base.json"), `{
"output": "feat.2da",
"columns": ["LABEL", "FEAT", "DESCRIPTION"],
"rows": [{
"id": 0,
"key": "feat:test",
"LABEL": "TEST_LABEL",
"FEAT": {"tlk": {"key": "feat:test.name", "text": "Test Feat"}},
"DESCRIPTION": "****"
}]
}`+"\n")
writeFile(t, filepath.Join(root, "topdata", "tlk", "custom.tlk.yml"), `schema: sow-topdata/tlk/v1
base_strref: 16777216
strings:
- key: sow.module.name
text: Shadows Over Westgate
id: 50
`)
// Simulate a per-machine state that predates the pinned taxonomy: the feat
// ref dynamically grabbed id 50 on an older build, exactly where the pin
// now lives. The build must self-heal instead of failing.
writeFile(t, filepath.Join(root, "topdata", tlkStateFile),
`{"version":1,"language":"en","entries":{"feat:test.name":{"id":50}}}`+"\n")
if _, err := BuildNative(testProject(root), nil); err != nil {
t.Fatalf("BuildNative failed on stale pin collision: %v", err)
}
stateRaw, err := os.ReadFile(filepath.Join(root, "topdata", tlkStateFile))
if err != nil {
t.Fatalf("read tlk state: %v", err)
}
var state tlkStateDocument
if err := json.Unmarshal(stateRaw, &state); err != nil {
t.Fatalf("parse tlk state: %v", err)
}
if state.Entries["sow.module.name"].ID != 50 {
t.Fatalf("pin must own id 50, got %#v", state.Entries["sow.module.name"])
}
if got := state.Entries["feat:test.name"].ID; got == 50 {
t.Fatalf("stale feat ref should have been reallocated off id 50, got %d", got)
}
}
func TestBuildPreservesTLKStateAcrossTextChanges(t *testing.T) { func TestBuildPreservesTLKStateAcrossTextChanges(t *testing.T) {
root := testProjectRoot(t) root := testProjectRoot(t)
mkdirAll(t, filepath.Join(root, "topdata", "data", "skills")) mkdirAll(t, filepath.Join(root, "topdata", "data", "skills"))
@@ -9354,6 +9456,60 @@ func TestBuildAndPackageIncludesCompiled2DAAndTopAssets(t *testing.T) {
} }
} }
func TestBuildAndPackageCompilesITPJSONAssets(t *testing.T) {
root := testProjectRoot(t)
mkdirAll(t, filepath.Join(root, "topdata", "data", "repadjust"))
mkdirAll(t, filepath.Join(root, "topdata", "assets", "palette"))
writeFile(t, filepath.Join(root, "topdata", "base_dialog.json"), "{}\n")
writeFile(t, filepath.Join(root, "topdata", "data", "repadjust", "base.json"), `{
"output": "repadjust.2da",
"columns": ["Label"],
"rows": [{"id": 0, "Label": "TEST_LABEL"}]
}`+"\n")
writeFile(t, filepath.Join(root, "topdata", "assets", "palette", "creaturepal.itp.json"), `{
"file_type": "ITP ",
"file_version": "V3.2",
"root": {
"struct_type": 4294967295,
"fields": [
{"label": "MAIN", "type": "List", "value": []},
{"label": "RESTYPE", "type": "Word", "value": 2027},
{"label": "NEXT_USEABLE_ID", "type": "Byte", "value": 51}
]
}
}`+"\n")
proj := testProject(root)
proj.Config.TopData.ReferenceBuilder = ""
result, err := BuildAndPackage(proj, nil)
if err != nil {
t.Fatalf("BuildAndPackage failed: %v", err)
}
input, err := os.Open(result.OutputHAKPath)
if err != nil {
t.Fatalf("open hak: %v", err)
}
defer input.Close()
archive, err := erf.Read(input)
if err != nil {
t.Fatalf("read hak: %v", err)
}
for _, resource := range archive.Resources {
if resource.Name != "creaturepal" || resource.Type != 0x07EE {
continue
}
document, err := gff.Read(bytes.NewReader(resource.Data))
if err != nil {
t.Fatalf("read compiled ITP: %v", err)
}
if document.FileType != "ITP " || document.FileVersion != "V3.2" {
t.Fatalf("unexpected compiled ITP header: %#v", document)
}
return
}
t.Fatalf("expected creaturepal.itp in top package")
}
func TestCollectTopPackageResourcesRejectsDuplicateTopAssetKeys(t *testing.T) { func TestCollectTopPackageResourcesRejectsDuplicateTopAssetKeys(t *testing.T) {
root := testProjectRoot(t) root := testProjectRoot(t)
mkdirAll(t, filepath.Join(root, ".cache", "2da")) mkdirAll(t, filepath.Join(root, ".cache", "2da"))
+84
View File
@@ -0,0 +1,84 @@
#!/usr/bin/env bash
set -euo pipefail
contract_script="$(cd "$(dirname "${BASH_SOURCE[0]}")" && pwd)/$(basename "${BASH_SOURCE[0]}")"
default_root="$(cd "$(dirname "${BASH_SOURCE[0]}")/.." && pwd)"
repo_root="${WORKFLOW_ROOT:-$default_root}"
cd "$repo_root"
ci=.gitea/workflows/ci.yml
release=.gitea/workflows/build-binaries.yml
sync=.gitea/workflows/sync-wrappers.yml
checkout='actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683'
assert_exact_events() {
local workflow="$1" expected="$2" actual
actual="$(awk '
/^on:$/ { in_on = 1 }
in_on && /^$/ { next }
in_on && $0 != "on:" && $0 !~ /^[[:space:]]/ { exit }
in_on { print }
' "$workflow")"
[[ "$actual" == "$expected" ]] || {
echo "workflow-contract: unexpected event scope in $workflow" >&2
return 1
}
}
[[ -f "$ci" ]] || { echo "missing consolidated CI workflow" >&2; exit 1; }
[[ ! -e .gitea/workflows/test.yml ]] || { echo "legacy test workflow still present" >&2; exit 1; }
assert_exact_events "$ci" $'on:\n pull_request:'
grep -Fqx 'permissions: read-all' "$ci"
grep -Fqx ' timeout-minutes: 60' "$ci"
[[ "$(grep -Fc "$checkout" "$ci")" -eq 1 ]]
grep -Fqx ' fetch-depth: 0' "$ci"
grep -Fq 'go vet ./...' "$ci"
grep -Fq 'go test ./...' "$ci"
grep -Fq 'shellcheck scripts/*.sh' "$ci"
grep -Fq 'yamllint .gitea' "$ci"
grep -Fq 'make smoke' "$ci"
grep -Fq 'for target in linux/amd64 linux/arm64 darwin/amd64 darwin/arm64 windows/amd64 windows/arm64; do' "$ci"
assert_exact_events "$release" $'on:\n push:\n tags: [\'v*\']'
grep -Fqx ' code: read' "$release"
grep -Fqx ' releases: write' "$release"
grep -Fqx ' timeout-minutes: 30' "$release"
[[ "$(grep -Fc "$checkout" "$release")" -eq 1 ]]
grep -Fq 'secrets.GITEA_TOKEN' "$release"
if grep -Fq 'secrets.GITHUB_TOKEN' "$release"; then
echo "workflow-contract: release uses the GitHub token alias" >&2
exit 1
fi
grep -Fqx 'permissions: read-all' "$sync"
grep -Fqx ' timeout-minutes: 30' "$sync"
[[ "$(grep -Fc "$checkout" "$sync")" -eq 1 ]]
assert_exact_events "$sync" $'on:\n push:\n branches: [main]\n paths:\n - \'wrappers/crucible.sh\'\n - \'wrappers/crucible.ps1\''
expect_mutation_rejected() {
local name="$1" workflow="$2" expression="$3" tmp
tmp="$(mktemp -d)"
mkdir -p "$tmp/.gitea"
cp -R "$default_root/.gitea/workflows" "$tmp/.gitea/workflows"
sed -i "$expression" "$tmp/$workflow"
if WORKFLOW_ROOT="$tmp" WORKFLOW_CONTRACT_MUTATION=1 bash "$contract_script" >/dev/null 2>&1; then
echo "workflow-contract: accepted forbidden mutation: $name" >&2
rm -rf "$tmp"
return 1
fi
rm -rf "$tmp"
}
if [[ "${WORKFLOW_CONTRACT_MUTATION:-0}" != 1 ]]; then
mutations_ok=0
expect_mutation_rejected 'CI workflow_dispatch event' "$ci" '/^ pull_request:$/a\ workflow_dispatch:' || mutations_ok=1
expect_mutation_rejected 'release develop branch' "$release" "/^ tags:/a\\ branches: [develop]" || mutations_ok=1
expect_mutation_rejected 'release schedule event' "$release" "/^ tags:/a\\ schedule:\n - cron: '0 0 * * *'" || mutations_ok=1
expect_mutation_rejected 'release extra tag pattern' "$release" "s/tags: \['v\*'\]/tags: ['v*', 'release-*']/" || mutations_ok=1
expect_mutation_rejected 'wrapper sync pull_request event' "$sync" '/^ push:$/i\ pull_request:' || mutations_ok=1
expect_mutation_rejected 'wrapper sync broad path' "$sync" "/^ - 'wrappers\/crucible.ps1'$/a\\ - 'wrappers/**'" || mutations_ok=1
(( mutations_ok == 0 )) || exit 1
fi
echo "workflow-contract: CI is PR-only; release and wrapper sync retain their narrow triggers"