Skip to content

fix(ci): stop the tracked-venv gate from matching basenames that merely start with venv - #1309

Merged
lusoris merged 1 commit into
masterfrom
fix/venv-gate-basename-false-positive
Sep 6, 2026
Merged

lusoris merged 1 commit into
masterfrom
fix/venv-gate-basename-false-positive

Conversation

@lusoris

@lusoris lusoris commented Sep 5, 2026

Copy link
Copy Markdown
Contributor

Summary

scripts/ci/check-no-tracked-venv.sh (the gate from #1280) made the leading dot optional in its pattern, so any tracked basename starting with venv was reported as a tracked virtualenv. The changelog fragment venv-recipe-docs.md on #1282 tripped it and reddened the required Pre-Commit check. The pattern now matches the real shapes only — .venv*, venv, .virtualenv, pyvenv.cfg as the last path segment, or any file inside such a directory — and a test pins seven cases (three look-alikes pass, four real venv paths fail). Wired next to the sibling gate tests in rule-enforcement.yml.

Type

  • fix — CI gate false positive

Checklist

  • Commits follow Conventional Commits.
  • make format && make lint is green locally (pre-commit on every touched file; shfmt/shellcheck; actionlint clean).
  • Unit tests: scripts/ci/tests/test-check-no-tracked-venv.sh (new, 7 cases).
  • Docs — no docs needed: developer gate internals; the script header documents the two shapes.
  • SIMD/GPU, twins, new C sources, breaking change, ADR — all n/a.

Bug-status hygiene (ADR-0165)

  • docs/state.md — T-VENV-GATE-BASENAME-FALSE-POSITIVE-2026-09-05 in Recently closed.

Netflix golden-data gate (ADR-0024)

  • I did not modify any assertAlmostEqual(...) score in the Netflix golden Python tests.

Deep-dive deliverables (ADR-0108)

  • Research digest — no digest needed: trivial. One regex, reproduced on docs(dev): replace the impossible venv recipe with the verified one #1282.
  • Decision matrix — no alternatives: only-one-way fix. The pattern must not match arbitrary basenames.
  • AGENTS.md invariant note — no rebase-sensitive invariants: fork-added script and test.
  • Reproducer / smoke-test command — below.
  • CHANGELOG fragment — changelog.d/fixed/venv-gate-basename-false-positive.md.
  • Rebase note — docs/rebase-notes.md entry.

Reproducer

bash scripts/ci/tests/test-check-no-tracked-venv.sh       # 7 ok lines
git show origin/master:scripts/ci/check-no-tracked-venv.sh > /tmp/old.sh
printf 'changelog.d/fixed/venv-recipe-docs.md\n' | grep -E '(^|/)(\.?venv[^/]*|\.virtualenv|pyvenv\.cfg)$'   # old pattern: matches (the bug)

🤖 Generated with Claude Code

@lusoris lusoris added this to the 1.0.0 — First release milestone Sep 5, 2026
@lusoris
lusoris force-pushed the fix/venv-gate-basename-false-positive branch 4 times, most recently from 1109c0c to 70f1a28 Compare September 5, 2026 21:02
…ly start with venv

The pattern in scripts/ci/check-no-tracked-venv.sh made the leading dot optional, so
changelog.d/fixed/venv-recipe-docs.md on #1282 was reported as a tracked virtualenv and the
required Pre-Commit check went red. Real virtualenv shapes (.venv*, venv, .virtualenv,
pyvenv.cfg, and any file inside such a directory) stay flagged; a test pins both sides.
docs/state.md: T-VENV-GATE-BASENAME-FALSE-POSITIVE-2026-09-05 (Recently closed).
@lusoris
lusoris force-pushed the fix/venv-gate-basename-false-positive branch from 70f1a28 to 2b3d7d5 Compare September 6, 2026 01:08
@lusoris
lusoris marked this pull request as ready for review September 6, 2026 01:08
@lusoris
lusoris merged commit bff0be8 into master Sep 6, 2026
111 of 112 checks passed
@lusoris
lusoris deleted the fix/venv-gate-basename-false-positive branch September 6, 2026 01:33
@lusoris lusoris added the type:bug Something isn't working label Sep 7, 2026
lusoris added a commit that referenced this pull request Oct 1, 2026
…alert #6 (ADR-1389)

- Resolve CodeQL alert #1309 (cpp/include-non-header):
  Replace unity-inclusion of core/src/libvmaf.c in core/test/test_feature_backend_twin.c
  with direct linkage against libvmaf in core/test/meson.build and narrow internal test
  accessors in core/src/libvmaf_priv.h (vmaf_backend_twin_verdict_for_test,
  vmaf_context_fake_backend_for_test, vmaf_context_set_gpumask_for_test,
  vmaf_context_append_registered_feature_extractor_for_test, and
  vmaf_context_resolve_context_fallbacks_for_test) implemented statically in
  core/src/libvmaf.c.
- Add scripts/ci/check-no-non-header-includes.sh and test suite
  scripts/ci/tests/test-check-no-non-header-includes.sh, wired into
  .pre-commit-config.yaml and .github/workflows/rule-enforcement.yml to fail
  closed on non-header source inclusions in core/test/.
- Resolve OpenSSF Scorecard alert #6 (SAST):
  Under ADR-1389, run CodeQL (Actions) unconditionally on every pull request and
  master push in .github/workflows/security-scans.yml, ensuring 100% commit SAST
  coverage across docs-only and non-code PRs with negligible (~15-20s) overhead,
  and enforce it in .github/workflows/required-aggregator.yml.
- Update docs/state.md, changelog fragment, docs/rebase-notes.md, and ADR index.
lusoris added a commit that referenced this pull request Oct 1, 2026
…alert #6 (ADR-1389)

- Resolve CodeQL alert #1309 (cpp/include-non-header):
  Replace unity-inclusion of core/src/libvmaf.c in core/test/test_feature_backend_twin.c
  with direct linkage against libvmaf in core/test/meson.build and narrow internal test
  accessors in core/src/libvmaf_priv.h (vmaf_backend_twin_verdict_for_test,
  vmaf_context_fake_backend_for_test, vmaf_context_set_gpumask_for_test,
  vmaf_context_append_registered_feature_extractor_for_test, and
  vmaf_context_resolve_context_fallbacks_for_test) implemented statically in
  core/src/libvmaf.c.
- Add scripts/ci/check-no-non-header-includes.sh and test suite
  scripts/ci/tests/test-check-no-non-header-includes.sh, wired into
  .pre-commit-config.yaml and .github/workflows/rule-enforcement.yml to fail
  closed on non-header source inclusions in core/test/.
- Resolve OpenSSF Scorecard alert #6 (SAST):
  Under ADR-1389, run CodeQL (Actions) unconditionally on every pull request and
  master push in .github/workflows/security-scans.yml, ensuring 100% commit SAST
  coverage across docs-only and non-code PRs with negligible (~15-20s) overhead,
  and enforce it in .github/workflows/required-aggregator.yml.
- Update docs/state.md, changelog fragment, docs/rebase-notes.md, and ADR index.
lusoris added a commit that referenced this pull request Oct 1, 2026
…alert #6 (ADR-1389) (#1659)

* fix(security): resolve CodeQL include alert #1309 and Scorecard SAST alert #6 (ADR-1389)

- Resolve CodeQL alert #1309 (cpp/include-non-header):
  Replace unity-inclusion of core/src/libvmaf.c in core/test/test_feature_backend_twin.c
  with direct linkage against libvmaf in core/test/meson.build and narrow internal test
  accessors in core/src/libvmaf_priv.h (vmaf_backend_twin_verdict_for_test,
  vmaf_context_fake_backend_for_test, vmaf_context_set_gpumask_for_test,
  vmaf_context_append_registered_feature_extractor_for_test, and
  vmaf_context_resolve_context_fallbacks_for_test) implemented statically in
  core/src/libvmaf.c.
- Add scripts/ci/check-no-non-header-includes.sh and test suite
  scripts/ci/tests/test-check-no-non-header-includes.sh, wired into
  .pre-commit-config.yaml and .github/workflows/rule-enforcement.yml to fail
  closed on non-header source inclusions in core/test/.
- Resolve OpenSSF Scorecard alert #6 (SAST):
  Under ADR-1389, run CodeQL (Actions) unconditionally on every pull request and
  master push in .github/workflows/security-scans.yml, ensuring 100% commit SAST
  coverage across docs-only and non-code PRs with negligible (~15-20s) overhead,
  and enforce it in .github/workflows/required-aggregator.yml.
- Update docs/state.md, changelog fragment, docs/rebase-notes.md, and ADR index.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

type:bug Something isn't working

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant