openclaw/scripts/ci-static-step.sh
Peter Steinberger 83fb6a3aa8
ci: tolerate verified main failures in PR gates
Match complete Node assertions and supported static diagnostics against trusted
hourly main evidence. Require untouched failing files and direct subjects,
current evidence, complete selected work, and an attempt-bound monitor receipt.
Keep PR-owned, incomplete, and unknown failures blocking, and annotate inherited
failures as known main red, owned by main.

This only classifies existing CI attempts. It does not dispatch, rerun, or update
branches. Fork observation is read-only; auto-merge PRs are never cancelled.

Validation: focused local regressions and native Testbox evidence; changed lint,
boundary checks, workflow sanity, and all three Knip export scans passed. The
local full typecheck remains limited by an existing TypeScript version and
workspace-declaration mismatch; no task-file errors remain in its output.
2026-09-27 19:28:00 -07:00

32 lines
841 B
Bash

#!/usr/bin/env bash
# Sourced by trusted CI steps; native check owners still run every command.
ci_static_kind="$1"
case "$ci_static_kind" in
tsgo) ci_static_failure=2 ;;
oxlint) ci_static_failure=1 ;;
*) echo "Unsupported static check: $ci_static_kind" >&2; exit 64 ;;
esac
ci_static_groups=0
ci_static_exit=0
run_static_check() {
local child_exit
ci_static_groups=$((ci_static_groups + 1))
if "$@"; then
return 0
else
child_exit=$?
fi
if [ "${OPENCLAW_CI_STATIC_EVIDENCE:-0}" != "1" ] || [ "$child_exit" != "$ci_static_failure" ]; then
exit "$child_exit"
fi
ci_static_exit="$child_exit"
}
finish_static_checks() {
if [ "${OPENCLAW_CI_STATIC_EVIDENCE:-0}" = "1" ]; then
printf '[ci-static:%s:step] {"version":1,"groups":%s}\n' "$ci_static_kind" "$ci_static_groups"
fi
exit "$ci_static_exit"
}