diff --git a/.github/workflows/test.yml b/.github/workflows/test.yml index d092533..d2b548e 100644 --- a/.github/workflows/test.yml +++ b/.github/workflows/test.yml @@ -27,3 +27,15 @@ jobs: - run: cargo clippy --workspace --all-targets --locked -- -D warnings - name: Run tests and require complete source-region coverage run: cargo bake --locked test:coverage --all-targets true + + test-result: + if: always() + needs: [test] + runs-on: ubuntu-latest + timeout-minutes: 5 + steps: + - name: Require successful tests and coverage + env: + JOB_RESULTS: ${{ toJSON(needs) }} + run: | + echo "$JOB_RESULTS" | jq -e 'all(.[]; .result == "success")' diff --git a/Cargo.lock b/Cargo.lock index 4a44222..13490f0 100644 --- a/Cargo.lock +++ b/Cargo.lock @@ -667,7 +667,7 @@ dependencies = [ [[package]] name = "socketry-project" -version = "0.3.6" +version = "0.3.7" dependencies = [ "bake", "bake-agent-context", diff --git a/Cargo.toml b/Cargo.toml index 908ea6b..b6e6329 100644 --- a/Cargo.toml +++ b/Cargo.toml @@ -1,6 +1,6 @@ [package] name = "socketry-project" -version = "0.3.6" +version = "0.3.7" edition = "2024" license = "MIT" repository = "https://github.com/socketry/socketry-project-rust" diff --git a/bake/Cargo.toml b/bake/Cargo.toml index 3c8cf07..fc42ff0 100644 --- a/bake/Cargo.toml +++ b/bake/Cargo.toml @@ -7,4 +7,4 @@ publish = false [dependencies] bake = "0.19.0" bake-markdown = "0.3.0" -socketry-project = { path = "..", version = "0.3.6" } +socketry-project = { path = "..", version = "0.3.7" } diff --git a/context/github-repository.md b/context/github-repository.md index 774c154..f13191e 100644 --- a/context/github-repository.md +++ b/context/github-repository.md @@ -41,7 +41,7 @@ Use the `socketry-project-pull-requests` skill for the full title, commit, descr ## Branch protection -Protect `main` and require pull requests with at least one approval. Allow administrators to bypass these rules for maintenance. Require only stable checks that are needed for safe auto-merge; do not make experimental, informational, or unreliable coverage checks mandatory. +Protect `main` and require pull requests with at least one approval. Allow administrators to bypass these rules for maintenance. Require the publishing workflow's `check` job and the testing workflow's stable `test-result` job. The latter succeeds only when all required test and coverage jobs succeed. Keep experimental or diagnostic jobs outside this gate. ## Apply settings safely diff --git a/context/releasing.md b/context/releasing.md index 66639fd..a6ddec3 100644 --- a/context/releasing.md +++ b/context/releasing.md @@ -28,6 +28,8 @@ Run the project's required tests and coverage checks using the `socketry-project Generate `.github/workflows/publish.yml` with `cargo bake cargo:setup:workflow`. The canonical template is maintained in [`bake-cargo-rust/src/publish.yml`](https://github.com/socketry/bake-cargo-rust/blob/main/src/publish.yml). Keep repository-specific changes limited to the configured branch and update this shared template when the standard workflow changes. +Require both `check` from `publish.yml` and `test-result` from `test.yml` in the branch ruleset. The aggregate test result must depend on every required test and coverage job, including matrix jobs, and run with `if: always()` so failures, cancellations, and skipped prerequisites cannot silently bypass it. Ordinary tests run only on pushes in `publish.yml`; pull requests rely on the required testing workflow. + The check job installs the Bake launcher and runs `cargo:release:detect --base "$BAKE_BEFORE" --sha "$BAKE_SHA"`. That task compares the current workspace version with the base commit, checks the matching `releases.md` heading when the version changed, and writes the `release` and `version` GitHub outputs. Release candidates then run `cargo:release` before the formatting, Clippy, and test checks. After a merge to the configured branch, the `crates-io` environment gates the publish job. `cargo:publish:pending --version "$BAKE_VERSION"` checks which workspace packages still need publishing. GitHub OIDC authentication runs only when packages are pending. `cargo:release:publish --version "$BAKE_VERSION" --sha "$BAKE_SHA"` publishes the remaining packages, then creates and pushes the version tag and creates or updates the matching GitHub Release from `releases.md` using `cargo:releases:github:release`. diff --git a/readme.md b/readme.md index 7c752c3..ea1f24e 100644 --- a/readme.md +++ b/readme.md @@ -18,7 +18,7 @@ cargo bake --regenerate Add this dependency under the existing `[dependencies]` table in `bake/Cargo.toml`: ```toml -socketry-project = ">=0.3.6" +socketry-project = ">=0.3.7" ``` Then run `cargo bake --regenerate` again to link the dependency's tasks. The command keeps generated links separate from task source, so no manual import in `main.rs` is needed. Run `cargo bake --list` to see the available tasks. The open-ended minimum requirement keeps this development dependency eligible for newer releases. `Cargo.lock` records the selected version for reproducible builds; update it deliberately when adopting a newer release. @@ -37,6 +37,11 @@ Prepare a release with `cargo bake cargo:version:patch` (or `minor`, `major`, or See [releases.md](releases.md) for the full release history. +### v0.3.7 + +- Require a stable aggregate test and coverage result alongside publishing checks. +- Clarify merge gates and repository-owned agent guidance in the shared conventions. + ### v0.3.6 - Normalize standard project Markdown files after version bumps. @@ -47,11 +52,6 @@ See [releases.md](releases.md) for the full release history. - Require `bake-test-rust` 0.3.0 or newer for LLVM region coverage and update the shared testing guidance to match. -### v0.3.4 - -- Require Bake 0.18.0 and Bake Cargo 0.4.0 for shared task registration. -- Document a test-only shim pattern for deterministic coverage of difficult I/O failures. - ## Contributing @@ -60,6 +60,6 @@ Please open an issue or pull request on [GitHub](https://github.com/socketry/soc ### Agent Context -Run `cargo bake agent:context:install` to install shared context and skills. Read `.agents/context/index.md` to find relevant guides, follow `agents.md` if present, and apply skills under `.agents/skills/`. See the [Agent Context guide] for guidance on organizing package context and repository-only instructions. +Run `cargo bake agent:context:install` to install shared context and skills. Read `.agents/context/index.md` to find relevant guides, follow `agents.md` if present, and apply skills under `.agents/skills/`. The installer preserves repository-owned `agents.md`; it does not create or regenerate that file. [Agent Context guide]: https://github.com/socketry/bake-agent-context-rust/blob/main/context/agent-context.md diff --git a/releases.md b/releases.md index a749539..39c63bb 100644 --- a/releases.md +++ b/releases.md @@ -1,5 +1,10 @@ # Releases +## v0.3.7 + +- Require a stable aggregate test and coverage result alongside publishing checks. +- Clarify merge gates and repository-owned agent guidance in the shared conventions. + ## v0.3.6 - Normalize standard project Markdown files after version bumps.