ci: closing-keyword gate, informational wire-exemption verdict, AGENTS.md - #176
Merged
juemerson-at-purestorage merged 10 commits intoSep 28, 2026
Merged
juemerson-at-purestorage merged 10 commits into
juemerson-at-purestorage merged 10 commits into
Conversation
…to Pester Adds the rename, #Requires-edited, '#'-in-here-string and root-module cases, and commits here-string setup on main so the '<#' case can fail for the right reason. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…rdict object Moved from local tooling. Adds -HeadRef, returns one Decision/Files/Basis object with exit codes unchanged, and documents how a gate must recompute the verdict from origin/main rather than trust a pull_request run. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…d tighten test coverage A git failure after revision resolution now yields one Undecided verdict with a path-free Reason and exit 2, instead of an uncaught error that exits 1 and reads as NotExempt. Adds tests for that path, the no-in-scope Exempt object, an inert file record and a base-side-only first executable line, and rewords comments that pointed at material outside the repo. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
test(coverage): pin Test-PfbWireExemption.Tests.ps1 at 40 winps51 skips. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Single implementation of the per-issue closing-keyword rule, transliterated from the local hook with JavaScript's \b, \s and $ semantics spelled out so the two agree; parity checked on every case. Case is spelled out as explicit [Xx] classes rather than IgnoreCase: on pwsh 7 .NET IgnoreCase folds the Kelvin sign into K, so a keyword right after one was missed there while Windows PowerShell 5.1 and JavaScript both find it. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
The wire-exemption workflow was written before main required every remote action to be SHA-pinned; pin its checkout to the same v7.0.1 commit the other workflows use. Also word its no-base-copy notice so it does not assume this is the PR that adds the classifier. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
The closing-keyword Describes and its workflow's Describe are ungated, so both editions require them; the wire-exemption Describes are PS7-gated, so only pwsh 7 does. The header count is recomputed from git ls-files: 24 of 219 files skip on 5.1. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…eletion With git's rename detection on, --name-status reports only the new path of a rename, so a cmdlet moved from Public/ to an out-of-scope folder was never seen and the diff read as exempt. Pass --no-renames so a move arrives as a delete plus an add; the rename branch is now unreachable and is removed. A new case moves a cmdlet out of Public/ and expects exit 1 (it fails with the flag removed). test(coverage): Test-PfbWireExemption.Tests.ps1 now skips 41 on 5.1 (total 550). docs: AGENTS.md says the local scripts run under PowerShell 7. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
Two PR-level checks and a starting-point doc. None of it touches the module:
tools/Test-PfbWireExemption.ps1: decides whether a diff can change what the module sends or parses.Public/,Private/, the.psd1and the.psm1, on both sides of the diff, with the PowerShell tokeniser.Decision,Files,Basis,Reason) that a caller can read instead of parsing text.-BaseRefand-HeadReflet it judge any pair of revisions without a checkout.verify-wire-exemption.ymlruns that classifier on every PR and writes the verdict to the job summary. Informational only: it never fails on the verdict, only if the classifier itself returns nothing.tools/Test-PfbClosingKeywords.ps1finds issue references that a closing keyword does not actually close. InFixes #1, #2, GitHub closes Add demote support to Update-PfbFileSystem (-DiscardNonSnapshottedData, -RequestedPromotionState) #1 only. For each finding it prints the corrected form.verify-closing-keywords.ymlruns it over the PR body and every commit message on the branch, and fails the PR on a finding.AGENTS.md: a tool-neutral entry point that points at the threeCLAUDE.mdfiles and lists what CI checks on a pull request.The two new test files are registered in
Tests/coverage-baseline.psd1:RequiredDescribesgains the new Describes. The closing-keyword ones are required on both editions; the wire-exemption ones on pwsh 7 only, since they are PS7-gated.Test-PfbWireExemption.Tests.ps1is pinned at 41 skips on 5.1.Design notes
tools/Test-PfbWireExemption.ps1from the base revision into a temp folder and runs that.::notice.Undecided(exit 2) with aReason, never as a plain exit 1. That way "not exempt" and "the tool broke" never look the same.--no-renames), so moving a cmdlet out ofPublic/still counts as an in-scope change.git rev-list --no-merges <head> --not <merge-base> origin/<base>, so commits that are already on the base branch, such as a merge frommaininto the branch, are not re-judged.Test-PfbClosingKeywords.ps1is a line-for-line port of an existing JavaScript hook, and the two must give identical results.IgnoreCase. .NET's case-insensitive matching on PowerShell 7 folds the Kelvin sign (U+212A) intoK, which JavaScript and Windows PowerShell 5.1 do not.Fixes #100, #101, #103, #87, and #80, which closed only All three group-quota write cmdlets fail on the wire: New-PfbQuotaGroup puts identity in the body, Update-/Remove-PfbQuotaGroup send an illegal names+file_system_names combination (user siblings fixed in #8) #100.Verification
Wire-exempt: The diff leaves the module source and the manifest entirely untouched, so nothing here can alter a request the module sends or a response it parses.
Expected on this PR's first run:
Verify Wire Exemptionskips with a::notice, because the base has no classifier yet.Verify Closing Keywordspasses on this body and these commits. The incident text above is in backticks, which the checker ignores, so it is not read as a real reference.Both scripts were run locally on this branch:
actionlint 1.7.12 reports 0 findings on both new workflows.
actions/checkoutis pinned to the same v7.0.1 commit as every other workflow.Tests
The scoped run covered every test file this branch touches, plus
CiCoverageGate.Tests.ps1, under both editions (Pester 6.0.1):Test-PfbWireExemption.Tests.ps1. It is gated wholesale because the classifier is PowerShell 7-only tooling.#Requires.#Requiresedit, a git failure, and the Kelvin-sign fold.🤖 Generated with Claude Code