from __future__ import annotations
import re
import sys
from pathlib import Path
ROOT = Path(__file__).resolve().parents[1]
WORKFLOW_DIR = ROOT / ".github" / "workflows"
PERMANENT_WORKFLOWS = {
"build-and-test.yml",
"dnssd-live.yml",
"llmnr-live.yml",
"mdns-duplex.yml",
"mdns-live.yml",
"mdns-responder-live.yml",
"pin-upstream-resolved.yml",
"replacement-boot-proof.yml",
"replacement-full-certification.yml",
"replacement-readiness-certificate.yml",
"replacement-security-gates.yml",
"replacement-security-proof.yml",
"replacement-upstream-test-75.yml",
"replacement-upstream-test-89-mdns.yml",
"reproducible-release.yml",
"upstream-surface-audit.yml",
"verify-upstream-baseline.yml",
}
OBSOLETE_PREFIXES = ("finalize-", "fix-", "integrate-", "land-", "reconcile-")
TOP_LEVEL_KEYS = ("name", "on", "jobs")
EXACT_SHA_WORKFLOWS = {
"replacement-boot-proof.yml",
"replacement-full-certification.yml",
"replacement-readiness-certificate.yml",
"replacement-security-gates.yml",
"replacement-security-proof.yml",
"replacement-upstream-test-75.yml",
"replacement-upstream-test-89-mdns.yml",
}
def fail(message: str) -> None:
print(f"workflow fleet check failed: {message}", file=sys.stderr)
raise SystemExit(1)
def top_level_key_present(text: str, key: str) -> bool:
return re.search(rf"(?m)^{re.escape(key)}\s*:", text) is not None
def main() -> None:
if not WORKFLOW_DIR.is_dir():
fail(f"missing workflow directory: {WORKFLOW_DIR}")
paths = sorted(WORKFLOW_DIR.glob("*.yml"))
actual = {path.name for path in paths}
missing = sorted(PERMANENT_WORKFLOWS - actual)
unexpected = sorted(actual - PERMANENT_WORKFLOWS)
if missing:
fail("missing permanent workflows: " + ", ".join(missing))
if unexpected:
fail("unexpected workflows: " + ", ".join(unexpected))
obsolete = sorted(name for name in actual if name.startswith(OBSOLETE_PREFIXES))
if obsolete:
fail("obsolete integration launchers remain: " + ", ".join(obsolete))
for path in paths:
text = path.read_text(encoding="utf-8")
if not text.strip():
fail(f"empty workflow: {path.name}")
if "\t" in text:
fail(f"tab indentation in {path.name}")
for key in TOP_LEVEL_KEYS:
if not top_level_key_present(text, key):
fail(f"{path.name} is missing top-level {key!r}")
if "git push origin HEAD:main" in text and path.name != "pin-upstream-resolved.yml":
fail(f"self-mutating permanent workflow: {path.name}")
if re.search(r"cargo build[^\n]*--release[^\n]*--all-features", text):
fail(f"research features enabled in release artifact: {path.name}")
if path.name in EXACT_SHA_WORKFLOWS:
if "source_sha:" not in text:
fail(f"exact-SHA workflow has no source_sha input: {path.name}")
if "run-name:" not in text or "inputs.source_sha || github.sha" not in text:
fail(f"exact-SHA workflow has no bound run name: {path.name}")
checkout_count = text.count("uses: actions/checkout@v4")
bound_checkout_count = text.count(
"ref: ${{ inputs.source_sha || github.sha }}"
)
if checkout_count == 0 or checkout_count != bound_checkout_count:
fail(f"exact-SHA checkout is incomplete: {path.name}")
identity_count = text.count("name: Verify exact source identity")
if identity_count != checkout_count:
fail(f"exact-SHA identity check is incomplete: {path.name}")
orchestrator = (WORKFLOW_DIR / "replacement-full-certification.yml").read_text(
encoding="utf-8"
)
prerequisite_workflows = EXACT_SHA_WORKFLOWS - {
"replacement-full-certification.yml"
}
for workflow in sorted(prerequisite_workflows):
if workflow not in orchestrator:
fail(f"full certification does not dispatch {workflow}")
print(f"workflow fleet check passed: {len(paths)} permanent workflows")
if __name__ == "__main__":
main()