1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
130
//! The tga → trusty-review ticketing artifact (#5405).
//!
//! Why: the sweep synced board data into `work_items` and joined it to
//! `commits` (the [`crate::collect::correlate`] pass), and the due-diligence
//! report read none of it — `src/report/` referenced no board table at all, so
//! a run against a fully configured JIRA/Linear/ADO board produced a report
//! indistinguishable from one against a repository with no tracker. This module
//! is the read side: it reduces the correlation tables to the handful of counts
//! the report states, and serializes them beside the manifest.
//!
//! What: [`TicketingSummary`], [`build_ticketing_summary`] which reads it from
//! an open database, and [`TicketingSummary::to_json`]. Like
//! [`crate::report::dd_manifest`], the builder is pure apart from the database
//! read — the caller writes the file, so the field mapping is provable from
//! unit tests rather than only from a live audit.
//!
//! The file is a sidecar rather than a section of `manifest.toml` because
//! trusty-review resolves it the way it resolves a metrics JSON: a path
//! declared in the manifest, loaded relative to the manifest's directory. It
//! deliberately does NOT travel through `RepositoryEntry.metrics`, whose
//! "declared metrics always win" precedence would block the live `--analyze`
//! fetch for any repository carrying one.
//!
//! Scope: the counts are database-wide, not per repository. tga keeps one
//! SQLite database per engagement and the correlation pass joins across all of
//! it, so a per-repository split would have to key on `commits.repository`
//! matching a manifest entry's name — a match that silently yields zeros when
//! it fails. The figures are stated at the scope they are computed at.
//!
//! Test: `super::ticketing_tests`.
use Connection;
use Serialize;
use crate;
use crateResult;
/// Schema tag written into the artifact.
///
/// Why: trusty-review reads this file across an independent release boundary —
/// the two binaries are installed separately — so the document says what shape
/// it is rather than leaving the reader to infer it from which keys parsed.
/// What: `"v0"`, matching the metrics artifact's own versioning convention.
pub const TICKETING_SCHEMA_VERSION: &str = "v0";
/// The board-correlation figures one audit run produced.
///
/// Why: this is the whole tga→trusty-review ticketing seam, and it is
/// deliberately four counts and a source list. A linkage-quality metric or a
/// grade is a product decision the board-selection axis has not landed yet, and
/// inventing one here would put a number in an acquirer's report that nothing
/// calibrated.
/// What: the commit and work-item totals from [`correlation_counts`], plus the
/// boards those links came from. Every field is a count the database can
/// produce; none is derived, weighted, or scored.
/// Test: `super::ticketing_tests::summary_counts_match_the_database`.
/// Read one run's ticketing figures out of the database.
///
/// Why: the closure condition of #5405 — the report must read a board table.
/// This is the only function that does, and it runs after the sweep's
/// correlation stage so `commit_work_items` is populated.
/// What: [`correlation_counts`] for the totals and [`linked_work_item_sources`]
/// for the board list. Read-only; no clock, no environment, no network, so two
/// calls against an unchanged database return equal values.
/// Test: `super::ticketing_tests::summary_counts_match_the_database`.
///
/// # Errors
///
/// Propagates [`crate::core::errors::TgaError::DbError`] from either query.