Make the gate structural, and correct what it tells an agent
CI / rust-headless (push) Successful in 6m38s
CI / rust-ui (push) Failing after 6m20s

Three gates in this repository were decorative, and each was discovered by
being wrong rather than by failing.

A crate directory in neither members nor exclude is silently not built, which
is how lumbridge-devices shipped 1,127 lines that had never compiled.
scripts/workspace-guard.sh refuses that state, and asserts the gpui source
and version out of Cargo.lock rather than the manifest, because a manifest
states an intent while the lockfile states what would actually be compiled --
and a caret requirement accepts a version nobody reviewed. It needs no
compiler, so it runs first and in the headless job, which unlike the UI job
is not continue-on-error and can therefore actually fail a push.

deny.toml's source policy had never been executed: ci.sh ran `check
licenses` alone, and `check sources` failed immediately on the rev-pinned
buzz-sdk. The permitted Git sources are now named one by one and the check
runs, so a fourth is a decision rather than an accident.

cargo-deny and cargo-nextest being absent was a warning that let a run report
green having skipped the licence gate DISTRIBUTION.md depends on. Under
LUMBRIDGE_CI_STRICT=1 a missing tool now fails; locally it stays a warning so
a contributor is not blocked.

skills/lumbridge-development/SKILL.md told every agent that GPUI and Floem
live in spikes/ and that no framework may be selected until both pass the
hard gates. Decision 0017 settled that a month ago in the opposite direction.
The entry point an agent is meant to read was the least accurate document in
the repository.

Decision 0023 records where the GPUI dependency actually goes. Published gpui
has not been released since 2025-10-22, Zed's main still declares 0.2.2 with
no bump pending, the platform backends moved to crates that inherit
publish = false, gpui's own x11 and wayland features are now empty markers,
and 0.2.2 has no accesskit dependency at all -- so "published now, migrate
later" was never available. The adapter 0017 promised was never written and
the call sites grew from few to 147 against 20 identities, so the adapter is
written first, on 0.2.2, before the dependency moves.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01SPYebLiN2w4TqnHUYGdECq
This commit is contained in:
Metal Agent
2026-09-01 12:51:25 -07:00
co-authored by Claude Opus 5
parent 28e455f968
commit 9a29e8e335
7 changed files with 337 additions and 20 deletions
+31 -8
View File
@@ -25,20 +25,43 @@ esac
# headless by default rather than silently joining the slow job.
ui_packages=(lumbridge lumbridge-ui-fixture)
# In CI a missing tool is a failure, not a warning. Locally it stays a warning so
# a contributor without cargo-deny is not blocked. The difference matters: the
# licence closure DISTRIBUTION.md depends on was, until this flag existed, being
# skipped on a runner that had never installed cargo-deny -- and reported green.
# Set LUMBRIDGE_CI_STRICT=1 (the workflow does) to require every gate to run.
strict="${LUMBRIDGE_CI_STRICT:-0}"
require_tool() {
command -v "$1" >/dev/null 2>&1 && return 0
if [ "$strict" = 1 ]; then
echo "$1 is required when LUMBRIDGE_CI_STRICT=1 and is not installed" >&2
exit 1
fi
return 1
}
# Structural gates that need no compiler: crate membership, and the pinned UI
# dependency. First, because they cost milliseconds and catch the failure that
# makes every later gate meaningless -- code that is silently not being built.
"$(dirname "$0")/workspace-guard.sh"
cargo fmt --all --check
# The product's licence closure. Graduating GPUI into the workspace made this
# the product's problem rather than a spike's; deny.toml records which licences
# were reviewed and why. Skipped rather than failed when the tool is absent, so
# a contributor without it is not blocked.
if command -v cargo-deny >/dev/null 2>&1; then
cargo deny check licenses
# The product's licence closure and its source allowlist. Graduating GPUI into
# the workspace made both the product's problem rather than a spike's; deny.toml
# records which licences were reviewed and which Git sources are permitted.
#
# `sources` is checked here for the first time. It had been declared in deny.toml
# and never run, which is why nobody noticed it was failing.
if require_tool cargo-deny; then
cargo deny check licenses sources
else
echo "cargo-deny not installed; skipping the licence gate (cargo install cargo-deny)" >&2
echo "cargo-deny not installed; skipping the licence and source gates (cargo install cargo-deny)" >&2
fi
test_runner() {
if command -v cargo-nextest >/dev/null 2>&1; then
if require_tool cargo-nextest; then
cargo nextest run "$@" --all-features --profile "${NEXTEST_PROFILE:-default}"
else
echo "cargo-nextest not installed; using cargo test" >&2