test-build-modes.sh (8010B)
1 #!/bin/sh 2 set -eu 3 4 repository_root=$(CDPATH= cd -- "$(dirname -- "$0")/.." && pwd) 5 make_command=$(command -v make) 6 gradle_command=${GRADLE:-./gradlew} 7 fixture=$(mktemp -d "${TMPDIR:-/tmp}/harvestcircle-build-mode.XXXXXX") 8 cleanup() { 9 find "$fixture" -depth -delete 10 } 11 trap cleanup EXIT HUP INT TERM 12 13 printf '%s\n' '#!/bin/sh' 'if [ "${1:-}" = +1.97.1 ]; then shift; fi' 'if [ "${1:-}" = extbuild ]; then printf "%s\n" "cargo-extbuild unavailable" >&2; else printf "%s\n" "cargo must not be invoked in standalone dry-run" >&2; fi' 'exit 93' > "$fixture/cargo" 14 chmod +x "$fixture/cargo" 15 16 standalone_output=$(PATH="$fixture:$PATH" "$make_command" --no-print-directory -n BUILD_MODE=standalone -C "$repository_root" check) 17 if printf '%s\n' "$standalone_output" | grep -q 'cargo extbuild'; then 18 printf '%s\n' 'standalone mode attempted to invoke extbuild' >&2 19 exit 1 20 fi 21 22 for lane in source-check integration-check development-check; do 23 for mode in standalone governed; do 24 lane_output=$(PATH="$fixture:$PATH" "$make_command" --no-print-directory -n BUILD_MODE="$mode" -C "$repository_root" "$lane") 25 build_logic_count=$(printf '%s\n' "$lane_output" | grep -c -- '-p build-logic') 26 if [ "$build_logic_count" -ne 1 ]; then 27 printf '%s\n' "$lane in $mode mode must invoke build-logic verification exactly once" >&2 28 exit 1 29 fi 30 done 31 done 32 33 development_output=$(PATH="$fixture:$PATH" "$make_command" --no-print-directory -n BUILD_MODE=standalone -C "$repository_root" development-check) 34 for forbidden in \ 35 'cargo audit' \ 36 'dependencyCheckAnalyze' \ 37 'verifyHostPackage' \ 38 'releaseReadiness' \ 39 'unsignedReleaseReadiness' \ 40 'signingReadiness' \ 41 'notarizationReadiness' \ 42 'packageDmg' \ 43 'packageDeb' 44 do 45 if printf '%s\n' "$development_output" | grep -q "$forbidden"; then 46 printf '%s\n' "development verification activated deferred integration: $forbidden" >&2 47 exit 1 48 fi 49 done 50 51 for mode in standalone governed; do 52 stability_output=$(PATH="$fixture:$PATH" "$make_command" --no-print-directory -n BUILD_MODE="$mode" -C "$repository_root" build-logic-stability-check) 53 stability_count=$(printf '%s\n' "$stability_output" | grep -c 'test-build-logic-stability.sh') 54 if [ "$stability_count" -ne 1 ]; then 55 printf '%s\n' "build-logic stability in $mode mode must invoke its qualification tool exactly once" >&2 56 exit 1 57 fi 58 59 source_output=$(PATH="$fixture:$PATH" "$make_command" --no-print-directory -n BUILD_MODE="$mode" -C "$repository_root" source-check) 60 if printf '%s\n' "$source_output" | grep -q 'test-build-logic-stability.sh'; then 61 printf '%s\n' "ordinary source-check in $mode mode invoked the nondefault stability lane" >&2 62 exit 1 63 fi 64 65 dev_check_output=$(PATH="$fixture:$PATH" "$make_command" --no-print-directory -n BUILD_MODE="$mode" -C "$repository_root" dev-check) 66 dev_check_count=$(printf '%s\n' "$dev_check_output" | grep -c -- '--configuration-cache --configuration-cache-problems=fail :app:desktop:hotRunArgfile') 67 if [ "$dev_check_count" -ne 1 ]; then 68 printf '%s\n' "development readiness in $mode mode must verify the finite hot-reload argfile exactly once" >&2 69 exit 1 70 fi 71 72 source_dev_check_count=$(printf '%s\n' "$source_output" | grep -c -- '--configuration-cache --configuration-cache-problems=fail :app:desktop:hotRunArgfile') 73 if [ "$source_dev_check_count" -ne 1 ]; then 74 printf '%s\n' "ordinary source-check in $mode mode must include development readiness exactly once" >&2 75 exit 1 76 fi 77 done 78 79 dev_output=$(PATH="$fixture:$PATH" "$make_command" --no-print-directory -n BUILD_MODE=standalone -C "$repository_root" dev) 80 if ! printf '%s\n' "$dev_output" | grep -q ':app:desktop:hotRun'; then 81 printf '%s\n' 'development command must invoke Compose hot reload' >&2 82 exit 1 83 fi 84 if printf '%s\n' "$dev_output" | grep -q -- '--no-configuration-cache'; then 85 printf '%s\n' 'development command disabled the qualified configuration cache' >&2 86 exit 1 87 fi 88 89 for mode in standalone governed; do 90 clean_output=$(PATH="$fixture:$PATH" "$make_command" --no-print-directory -n BUILD_MODE="$mode" -C "$repository_root" clean) 91 build_runner_prefix= 92 if [ "$mode" = governed ]; then 93 build_runner_prefix='cargo extbuild run -- ' 94 fi 95 root_clean_count=$(printf '%s\n' "$clean_output" | grep -Fxc -- "${build_runner_prefix}${gradle_command} --no-daemon clean" || true) 96 included_clean_count=$(printf '%s\n' "$clean_output" | grep -Fxc -- "${build_runner_prefix}${gradle_command} --no-daemon -p build-logic clean" || true) 97 if [ "$root_clean_count" -ne 1 ] || [ "$included_clean_count" -ne 1 ]; then 98 printf '%s\n' "clean in $mode mode must clean the root and included builds exactly once" >&2 99 exit 1 100 fi 101 done 102 103 if "$make_command" --no-print-directory -C "$repository_root" BUILD_MODE=unsupported help > "$fixture/unknown.log" 2>&1; then 104 printf '%s\n' 'unknown build mode was accepted' >&2 105 exit 1 106 fi 107 grep -q "Unknown BUILD_MODE 'unsupported'" "$fixture/unknown.log" 108 109 if PATH="$fixture:$PATH" "$make_command" --no-print-directory -C "$repository_root" governed-doctor > "$fixture/governed.log" 2>&1; then 110 printf '%s\n' 'governed mode succeeded without extbuild' >&2 111 exit 1 112 fi 113 grep -q 'cargo-extbuild unavailable' "$fixture/governed.log" 114 115 if "$make_command" --no-print-directory -C "$repository_root" BUILD_MODE=standalone _release-check > "$fixture/release.log" 2>&1; then 116 printf '%s\n' 'release execution accepted standalone mode' >&2 117 exit 1 118 fi 119 grep -q 'release-check requires governed mode' "$fixture/release.log" 120 121 if "$make_command" --no-print-directory -C "$repository_root" BUILD_MODE=standalone _unsigned-release-check > "$fixture/unsigned-release.log" 2>&1; then 122 printf '%s\n' 'unsigned release execution accepted standalone mode' >&2 123 exit 1 124 fi 125 grep -q 'unsigned-release-check requires governed mode' "$fixture/unsigned-release.log" 126 127 unsigned_release_output=$(PATH="$fixture:$PATH" "$make_command" --no-print-directory -n BUILD_MODE=governed -C "$repository_root" _unsigned-release-check) 128 if ! printf '%s\n' "$unsigned_release_output" | grep -q ':app:desktop:unsignedReleaseReadiness'; then 129 printf '%s\n' 'unsigned release command did not select the unsigned readiness gate' >&2 130 exit 1 131 fi 132 for forbidden in 'cargo audit' 'advisories' ':app:desktop:dependencyCheckAnalyze' ':app:desktop:releaseReadiness' ':app:desktop:signingReadiness' ':app:desktop:notarizationReadiness'; do 133 if printf '%s\n' "$unsigned_release_output" | grep -q "$forbidden"; then 134 printf '%s\n' "unsigned release command activated out-of-scope authority: $forbidden" >&2 135 exit 1 136 fi 137 done 138 139 standalone_package_output=$(PATH="$fixture:$PATH" "$make_command" --no-print-directory -n BUILD_MODE=standalone -C "$repository_root" package-check) 140 standalone_unsigned_gate_count=$(printf '%s\n' "$standalone_package_output" | grep -Fxc -- "$gradle_command --no-daemon --no-parallel --no-configuration-cache :app:desktop:unsignedReleaseReadiness" || true) 141 if [ "$standalone_unsigned_gate_count" -ne 1 ] || printf '%s\n' "$standalone_package_output" | grep -q 'cargo extbuild'; then 142 printf '%s\n' 'standalone package-check must invoke the unsigned gate once without probing extbuild' >&2 143 exit 1 144 fi 145 146 governed_package_output=$(PATH="$fixture:$PATH" "$make_command" --no-print-directory -n BUILD_MODE=standalone -C "$repository_root" governed-package-check) 147 governed_unsigned_gate_count=$(printf '%s\n' "$governed_package_output" | grep -Fxc -- "cargo extbuild run -- $gradle_command --no-daemon --no-parallel --no-configuration-cache :app:desktop:unsignedReleaseReadiness" || true) 148 if [ "$governed_unsigned_gate_count" -ne 1 ]; then 149 printf '%s\n' 'governed-package-check must invoke the extbuild-routed unsigned gate exactly once' >&2 150 exit 1 151 fi 152 153 printf '%s\n' 'harvestcircle.build-mode-contract=pass'