Skip to content

Add shared-files and build-check infrastructure for cross-repo sync - #165

Merged
bernardladenthin merged 7 commits into
mainfrom
claude/hopeful-pascal-9jlbqb
Oct 1, 2026
Merged

bernardladenthin merged 7 commits into
mainfrom
claude/hopeful-pascal-9jlbqb

Conversation

@bernardladenthin

Copy link
Copy Markdown
Owner

Summary

  • Adds cross-repository file synchronization checks via .github/shared-files.sha256 manifest and check-shared-files.py. Files kept byte-identical across java-llama.cpp, BitcoinAddressFinder, srcmorph, and streambuffer are verified on every run; failures when local copies diverge, warnings when siblings differ.
  • Introduces release-gate enforcement via check-release-gate.py and .github/release-gate-exemptions.txt. Every job in publish.yml must gate both publish jobs unless explicitly exempted with a documented reason.
  • Adds bash script validation via check-run-scripts.py. All bash run: scripts in workflows and composite actions are parsed with bash -n to catch syntax errors early (e.g., lost line continuations).
  • Adds Maven version drift detection via check-versions.py. Warns when dependencies and plugins differ between this repository and siblings, making Dependabot drift visible across all four repos.
  • Consolidates checks into a new shared-files job in publish.yml that runs after startgate, executing all four checks plus the buildcheck test suite.
  • Extracts GPG signing verification into a shared script (.github/verify-signing-key.sh) kept byte-identical across repositories, reducing duplication and improving maintainability.

The buildcheck library uses only the standard library (no external dependencies) and is structured to be testable in isolation.

Test plan

  • Affected unit tests pass locally: python3 -m unittest discover -s .github/buildcheck/tests -t .github
  • CI is green on this branch (new shared-files job runs all checks)
  • CHANGELOG and CLAUDE.md updated

Related issues / PRs

Implements cross-repository synchronization infrastructure for the four-repository workspace (java-llama.cpp, BitcoinAddressFinder, srcmorph, streambuffer).

Checklist

  • I have read CONTRIBUTING.md and CODE_OF_CONDUCT.md
  • My commits follow Conventional Commits
  • No security-sensitive changes

https://claude.ai/code/session_01AytmJF9faEiQEVt6eetQS2

…ing-key scripts

Shared with java-llama.cpp, BitcoinAddressFinder, srcmorph and streambuffer (listed in
.github/shared-files.sha256, checked by the new shared-files job, which fails on a copy changed in
one repository alone and warns on a sibling whose copy differs):
- .github/buildcheck/{workflow,releasegate,sharedfiles}.py + unit tests (stdlib-only Python),
  check-release-gate.py and check-shared-files.py;
- print-crash-logs.sh (replaces the crash-log steps pasted into every test job) and
  verify-signing-key.sh (the body of the verify-signing-key job);
- the files that were already kept identical by hand, now in the manifest.

The release gate: every job of publish.yml gates both publish jobs unless
.github/release-gate-exemptions.txt names it with a reason. It found vmlens gating nothing;
vmlens and shared-files now gate both publish jobs.

Also: java-version literals replaced by env.JAVA_VERSION; CLAUDE.md and CHANGELOG describe the
job. Verified: build-check unit tests, check-release-gate.py, check-shared-files.py, actionlint,
reuse lint.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01AytmJF9faEiQEVt6eetQS2
…epositories

An entry .github/workflows/publish.yml#<job> in .github/shared-files.sha256
hashes one job of the workflow (its header and body, not the comment lines
before the next job). startgate, shared-files, verify-signing-key,
check-snapshot and check-tag are identical in all four publish.yml files,
and verify-signing-key-gradle, github-snapshot and github-release in the
three Maven-only ones; they were identical by convention only and are now
checked like files, without moving them into a reusable workflow.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01AytmJF9faEiQEVt6eetQS2
…pository

check-versions.py (shared build-check library, run in the shared-files job)
compares every groupId:artifactId the POMs use -- plugins, dependencies,
annotation-processor paths and the Spotless formatter version, ${...}
resolved -- with the default branches of the three sibling repositories
and warns per difference. Dependabot bumps each repository on its own;
this is where the drift now shows instead of in a hand-kept table.
Warnings only: a bump lands in four pull requests. The repositories' own
net.ladenthin artifacts are left out. All 33 coordinates the four
repositories share agree today.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01AytmJF9faEiQEVt6eetQS2
The shared-files job now parses every run: script of .github/workflows
and the composite actions that runs in bash (shell decided as the runner
does: step shell, job and workflow defaults, else PowerShell on a
Windows runner and bash elsewhere). A broken script -- such as a lost
line continuation that leaves a line starting with || -- fails within
minutes instead of in the job that runs it. New shared buildcheck
module runscripts.py with tests and the check-run-scripts.py CLI, listed
in the shared-files manifest of all four repositories.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01AytmJF9faEiQEVt6eetQS2
Every .github file whose only copyright holder is Bernard Ladenthin gets
the license header MIT OR Apache-2.0, the same in all four sibling
repositories, so a shared file needs no per-repository header. Files
with another copyright holder are left unchanged. CODE_OF_CONDUCT.md
(and, where the copies are now identical, claude.yml,
claude-code-review.yml, scorecard.yml, reuse.yml, osv-scanner.yml and
dependabot.yml) joined the shared-files manifest.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01AytmJF9faEiQEVt6eetQS2
Every setup-java reads the JDK from .java-version (java-version-file)
instead of a JAVA_VERSION env or a literal 21, as java-llama.cpp already
does. .java-version (+ its license file, now MIT OR Apache-2.0) and
codeql.yml are byte-identical in all four sibling repositories and
listed in the shared-files manifest.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01AytmJF9faEiQEVt6eetQS2
A shared-files entry ending in ?repo is hashed with the repository name
replaced by {repo}, so SUPPORT.md, ISSUE_TEMPLATE/config.yml, CITATION.cff,
sonarqube.yml and the code-style job can be checked although they name
their repository. Newly shared: .editorconfig, .gitattributes (*.gguf
binary everywhere), FUNDING.yml, CODEOWNERS, the license texts,
.mvn/jvm.config and .mvn/settings.xml where identical, and the job
verify-signing-key-gradle, now on Gradle 9.8.0 in all four repositories.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01AytmJF9faEiQEVt6eetQS2
@bernardladenthin
bernardladenthin merged commit 3faa6b2 into main Oct 1, 2026
14 of 17 checks passed
@bernardladenthin
bernardladenthin deleted the claude/hopeful-pascal-9jlbqb branch October 1, 2026 10:16
@sonarqubecloud

sonarqubecloud Bot commented Oct 1, 2026

Copy link
Copy Markdown

Quality Gate Failed Quality Gate failed

Failed conditions
0.0% Coverage on New Code (required ≥ 80%)

See analysis details on SonarQube Cloud

This branch had an error being deployed

1 failed deployment
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants