ci: export the manifest builder into the preflight harness

Since #161534 the preflight step "Build CI manifest" runs
scripts/ci-build-manifest.mjs from the trusted .ci-harness checkout of the
workflow SHA, but checkout_harness only exported release-context.mjs and
release-version.mjs for the preflight kind. Every pull_request preflight
since then failed with "Cannot find module .ci-harness/scripts/ci-build-manifest.mjs"
before any test ran; main push runs skip preflight, so main stayed green.

Add the manifest builder to a shared preflight_scripts tuple and use it for
both the index export (checkout == workflow SHA) and the sparse fetch
(different-revision dispatch), which previously received no preflight
scripts at all. Regenerated ci.yml with scripts/generate-ci-git-owner.mts.

Proof: node scripts/generate-ci-git-owner.mts --check passes; owner.py
compiles; exporting the preflight pathspecs into .ci-harness/ and running
node .ci-harness/scripts/ci-build-manifest.mjs from the workspace resolves
every static import and reaches "CI release scope: full".
This commit is contained in:
Peter Steinberger 2026-09-29 20:39:32 -07:00
parent 924dd4deff
commit 6c07ebfaf4
No known key found for this signature in database
2 changed files with 18 additions and 2 deletions

View file

@ -464,6 +464,12 @@ def checkout_harness(sha):
evidence_scripts = ("scripts/ios-screenshot-evidence.mjs", "scripts/lib/direct-run.mjs", "scripts/ci-static-step.sh")
platform_scripts = ("scripts/lib/swift-toolchain.sh",)
upgrade_scripts = ("scripts/lib/release-upgrade-baseline.mjs", "scripts/lib/release-version.mjs")
# The manifest builder runs from the harness and imports these siblings by file-relative paths.
preflight_scripts = (
"scripts/ci-build-manifest.mjs",
"scripts/lib/release-context.mjs",
"scripts/lib/release-version.mjs",
)
npm_lock_scripts = (
"scripts/ci-npm-lock-admission.mjs",
"scripts/generate-npm-package-lock.mjs",
@ -490,7 +496,7 @@ def checkout_harness(sha):
if kind in ("platform", "linux-node"):
pathspecs += evidence_scripts
elif kind == "preflight":
pathspecs += ["scripts/lib/release-context.mjs", "scripts/lib/release-version.mjs"]
pathspecs += preflight_scripts
if kind == "platform":
pathspecs += platform_scripts
if kind == "linux-node":
@ -503,6 +509,8 @@ def checkout_harness(sha):
sparse_paths = ["/.github/actions/", *(f"/{path}" for path in node_setup_scripts)]
if kind in ("platform", "linux-node"):
sparse_paths += [f"/{path}" for path in evidence_scripts]
elif kind == "preflight":
sparse_paths += [f"/{path}" for path in preflight_scripts]
if kind == "platform":
sparse_paths += [f"/{path}" for path in platform_scripts]
if kind == "linux-node":

View file

@ -743,6 +743,12 @@ jobs:
evidence_scripts = ("scripts/ios-screenshot-evidence.mjs", "scripts/lib/direct-run.mjs", "scripts/ci-static-step.sh")
platform_scripts = ("scripts/lib/swift-toolchain.sh",)
upgrade_scripts = ("scripts/lib/release-upgrade-baseline.mjs", "scripts/lib/release-version.mjs")
# The manifest builder runs from the harness and imports these siblings by file-relative paths.
preflight_scripts = (
"scripts/ci-build-manifest.mjs",
"scripts/lib/release-context.mjs",
"scripts/lib/release-version.mjs",
)
npm_lock_scripts = (
"scripts/ci-npm-lock-admission.mjs",
"scripts/generate-npm-package-lock.mjs",
@ -769,7 +775,7 @@ jobs:
if kind in ("platform", "linux-node"):
pathspecs += evidence_scripts
elif kind == "preflight":
pathspecs += ["scripts/lib/release-context.mjs", "scripts/lib/release-version.mjs"]
pathspecs += preflight_scripts
if kind == "platform":
pathspecs += platform_scripts
if kind == "linux-node":
@ -782,6 +788,8 @@ jobs:
sparse_paths = ["/.github/actions/", *(f"/{path}" for path in node_setup_scripts)]
if kind in ("platform", "linux-node"):
sparse_paths += [f"/{path}" for path in evidence_scripts]
elif kind == "preflight":
sparse_paths += [f"/{path}" for path in preflight_scripts]
if kind == "platform":
sparse_paths += [f"/{path}" for path in platform_scripts]
if kind == "linux-node":