Repository navigation
Add shared-files and build-check infrastructure for cross-repo sync - #165
Merged
Merged
Conversation
…ing-key scripts
Shared with java-llama.cpp, BitcoinAddressFinder, srcmorph and streambuffer (listed in
.github/shared-files.sha256, checked by the new shared-files job, which fails on a copy changed in
one repository alone and warns on a sibling whose copy differs):
- .github/buildcheck/{workflow,releasegate,sharedfiles}.py + unit tests (stdlib-only Python),
check-release-gate.py and check-shared-files.py;
- print-crash-logs.sh (replaces the crash-log steps pasted into every test job) and
verify-signing-key.sh (the body of the verify-signing-key job);
- the files that were already kept identical by hand, now in the manifest.
The release gate: every job of publish.yml gates both publish jobs unless
.github/release-gate-exemptions.txt names it with a reason. It found vmlens gating nothing;
vmlens and shared-files now gate both publish jobs.
Also: java-version literals replaced by env.JAVA_VERSION; CLAUDE.md and CHANGELOG describe the
job. Verified: build-check unit tests, check-release-gate.py, check-shared-files.py, actionlint,
reuse lint.
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01AytmJF9faEiQEVt6eetQS2
…epositories An entry .github/workflows/publish.yml#<job> in .github/shared-files.sha256 hashes one job of the workflow (its header and body, not the comment lines before the next job). startgate, shared-files, verify-signing-key, check-snapshot and check-tag are identical in all four publish.yml files, and verify-signing-key-gradle, github-snapshot and github-release in the three Maven-only ones; they were identical by convention only and are now checked like files, without moving them into a reusable workflow. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01AytmJF9faEiQEVt6eetQS2
…pository
check-versions.py (shared build-check library, run in the shared-files job)
compares every groupId:artifactId the POMs use -- plugins, dependencies,
annotation-processor paths and the Spotless formatter version, ${...}
resolved -- with the default branches of the three sibling repositories
and warns per difference. Dependabot bumps each repository on its own;
this is where the drift now shows instead of in a hand-kept table.
Warnings only: a bump lands in four pull requests. The repositories' own
net.ladenthin artifacts are left out. All 33 coordinates the four
repositories share agree today.
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01AytmJF9faEiQEVt6eetQS2
The shared-files job now parses every run: script of .github/workflows and the composite actions that runs in bash (shell decided as the runner does: step shell, job and workflow defaults, else PowerShell on a Windows runner and bash elsewhere). A broken script -- such as a lost line continuation that leaves a line starting with || -- fails within minutes instead of in the job that runs it. New shared buildcheck module runscripts.py with tests and the check-run-scripts.py CLI, listed in the shared-files manifest of all four repositories. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01AytmJF9faEiQEVt6eetQS2
Every .github file whose only copyright holder is Bernard Ladenthin gets the license header MIT OR Apache-2.0, the same in all four sibling repositories, so a shared file needs no per-repository header. Files with another copyright holder are left unchanged. CODE_OF_CONDUCT.md (and, where the copies are now identical, claude.yml, claude-code-review.yml, scorecard.yml, reuse.yml, osv-scanner.yml and dependabot.yml) joined the shared-files manifest. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01AytmJF9faEiQEVt6eetQS2
Every setup-java reads the JDK from .java-version (java-version-file) instead of a JAVA_VERSION env or a literal 21, as java-llama.cpp already does. .java-version (+ its license file, now MIT OR Apache-2.0) and codeql.yml are byte-identical in all four sibling repositories and listed in the shared-files manifest. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01AytmJF9faEiQEVt6eetQS2
A shared-files entry ending in ?repo is hashed with the repository name
replaced by {repo}, so SUPPORT.md, ISSUE_TEMPLATE/config.yml, CITATION.cff,
sonarqube.yml and the code-style job can be checked although they name
their repository. Newly shared: .editorconfig, .gitattributes (*.gguf
binary everywhere), FUNDING.yml, CODEOWNERS, the license texts,
.mvn/jvm.config and .mvn/settings.xml where identical, and the job
verify-signing-key-gradle, now on Gradle 9.8.0 in all four repositories.
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01AytmJF9faEiQEVt6eetQS2
bernardladenthin
had a problem deploying
to
startgate
October 1, 2026 10:13 — with
GitHub Actions
Error
bernardladenthin
had a problem deploying
to
maven-central
October 1, 2026 10:13 — with
GitHub Actions
Failure
bernardladenthin
had a problem deploying
to
maven-central
October 1, 2026 10:13 — with
GitHub Actions
Failure
|
This branch had an error being deployed
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.


Summary
.github/shared-files.sha256manifest andcheck-shared-files.py. Files kept byte-identical across java-llama.cpp, BitcoinAddressFinder, srcmorph, and streambuffer are verified on every run; failures when local copies diverge, warnings when siblings differ.check-release-gate.pyand.github/release-gate-exemptions.txt. Every job in publish.yml must gate both publish jobs unless explicitly exempted with a documented reason.check-run-scripts.py. All bashrun:scripts in workflows and composite actions are parsed withbash -nto catch syntax errors early (e.g., lost line continuations).check-versions.py. Warns when dependencies and plugins differ between this repository and siblings, making Dependabot drift visible across all four repos.shared-filesjob in publish.yml that runs after startgate, executing all four checks plus the buildcheck test suite..github/verify-signing-key.sh) kept byte-identical across repositories, reducing duplication and improving maintainability.The buildcheck library uses only the standard library (no external dependencies) and is structured to be testable in isolation.
Test plan
python3 -m unittest discover -s .github/buildcheck/tests -t .githubshared-filesjob runs all checks)Related issues / PRs
Implements cross-repository synchronization infrastructure for the four-repository workspace (java-llama.cpp, BitcoinAddressFinder, srcmorph, streambuffer).
Checklist
CONTRIBUTING.mdandCODE_OF_CONDUCT.mdhttps://claude.ai/code/session_01AytmJF9faEiQEVt6eetQS2