Skip to content

[ci] Inventory workflow jobs explicitly - #3576

Open
joshlf wants to merge 1 commit into
Gqofuqcjxqt64bw7di2snqyunualoi3htfrom
Ghrxpfppzzenc5ecwz3u273gd42e4psk7
Open

[ci] Inventory workflow jobs explicitly#3576
joshlf wants to merge 1 commit into
Gqofuqcjxqt64bw7di2snqyunualoi3htfrom
Ghrxpfppzzenc5ecwz3u273gd42e4psk7

Conversation

@joshlf

@joshlf joshlf commented Aug 25, 2026

Copy link
Copy Markdown
Member

Add a narrow scanner for every lower-case YAML workflow file and its
canonical top-level job IDs. Compare that live inventory with a sorted,
reviewed registry which assigns each job a plain-language role.

Reject quoted or anchored job declarations, duplicate jobs, unfamiliar
jobs keys, case-variant YAML extensions, unsorted registry rows, unknown
roles, and any missing or unreviewed job. Continue using
action-validator for the complete YAML and GitHub Actions schema rather
than implementing another YAML interpreter in zc.

This commit only establishes the handwritten-workflow inventory
boundary. Its crate-private entry point is temporarily allowed to be
unused outside tests; the all-input boundary removes that allowance when
it begins calling the audit. Later checks use the roles to constrain
generated data and keep required static validation and aggregation jobs
visible.

Tests: CARGO_NET_OFFLINE=true ./ci/check_tools.sh
Tests: ./ci/check_fmt.sh

Authored by an agent, posting via joshlf's account


Latest Update: v3 — Compare vs v2

📚 Full Patch History

Links show the diff between the row version and the column version.

Version v2 v1 Base
v3 vs v2 vs v1 vs Base
v2 vs v1 vs Base
v1 vs Base
⬇️ Download this PR

Branch

git fetch origin refs/heads/Ghrxpfppzzenc5ecwz3u273gd42e4psk7 && git checkout -b pr-Ghrxpfppzzenc5ecwz3u273gd42e4psk7 FETCH_HEAD

Checkout

git fetch origin refs/heads/Ghrxpfppzzenc5ecwz3u273gd42e4psk7 && git checkout FETCH_HEAD

Cherry Pick

git fetch origin refs/heads/Ghrxpfppzzenc5ecwz3u273gd42e4psk7 && git cherry-pick FETCH_HEAD

Pull

git pull origin refs/heads/Ghrxpfppzzenc5ecwz3u273gd42e4psk7

Stacked PRs enabled by GHerrit.

@codecov-commenter

Copy link
Copy Markdown

Codecov Report

✅ All modified and coverable lines are covered by tests.
⚠️ Please upload report for BASE (Gqofuqcjxqt64bw7di2snqyunualoi3ht@4aa8517). Learn more about missing BASE report.

Additional details and impacted files
@@                         Coverage Diff                          @@
##             Gqofuqcjxqt64bw7di2snqyunualoi3ht    #3576   +/-   ##
====================================================================
  Coverage                                     ?   91.85%           
====================================================================
  Files                                        ?       20           
  Lines                                        ?     6093           
  Branches                                     ?        0           
====================================================================
  Hits                                         ?     5597           
  Misses                                       ?      496           
  Partials                                     ?        0           

☔ View full report in Codecov by Harness.
📢 Have feedback on the report? Share it here.

🚀 New features to boost your workflow:
  • ❄️ Test Analytics: Detect flaky tests, report on failures, and find test suite problems.

Add a narrow scanner for every lower-case YAML workflow file and its
canonical top-level job IDs. Compare that live inventory with a sorted,
reviewed registry which assigns each job a plain-language role.

Reject quoted or anchored job declarations, duplicate jobs, unfamiliar
jobs keys, case-variant YAML extensions, unsorted registry rows, unknown
roles, and any missing or unreviewed job. Continue using
action-validator for the complete YAML and GitHub Actions schema rather
than implementing another YAML interpreter in zc.

This commit only establishes the handwritten-workflow inventory
boundary. Its crate-private entry point is temporarily allowed to be
unused outside tests; the all-input boundary removes that allowance when
it begins calling the audit. Later checks use the roles to constrain
generated data and keep required static validation and aggregation jobs
visible.

Tests: CARGO_NET_OFFLINE=true ./ci/check_tools.sh
Tests: ./ci/check_fmt.sh

*Authored by an agent, posting via joshlf's account*

gherrit-pr-id: Ghrxpfppzzenc5ecwz3u273gd42e4psk7
@joshlf
joshlf force-pushed the Gqofuqcjxqt64bw7di2snqyunualoi3ht branch from 4aa8517 to 0c5a889 Compare August 25, 2026 18:32
@joshlf
joshlf force-pushed the Ghrxpfppzzenc5ecwz3u273gd42e4psk7 branch from ca89a5d to 1b5b56e Compare August 25, 2026 18:32
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants