diff --git a/scripts/check-package-policy.sh b/scripts/check-package-policy.sh index 952ac1b9..9f6f8dc6 100755 --- a/scripts/check-package-policy.sh +++ b/scripts/check-package-policy.sh @@ -197,7 +197,7 @@ fi CONTAINER="" CONTAINER_STUB="" while IFS= read -r f; do [ -n "$f" ] || continue - if grep -qE '^[[:space:]]*(RUN|ENTRYPOINT|CMD)[[:space:]]' "$f"; then + if grep -qiE '^[[:space:]]*(RUN|ENTRYPOINT|CMD)[[:space:]]' "$f"; then CONTAINER="$f"; break fi CONTAINER_STUB="${CONTAINER_STUB:-$f}" @@ -225,22 +225,6 @@ if printf '%s ' "$CAPS" | grep -xE 'reproducible-build|container' | paste -sd ' ' -)" fi -# Only a stub guix.scm. Before capability gating this passed on presence, and -# ~90 repos rely on that; 8.1.4 is gated on reproducible-build, so the stub -# only fails where that capability (or container) is declared. -if [ -n "$GUIX_STUB" ]; then - if [ -z "$REQUIRED" ]; then - echo "::notice::${GUIX_STUB#"$ROOT"/} is a scaffold stub (criterion 8.1.4)." \ - "Not enforced: this repo declares neither reproducible-build nor container." - echo "✅ Packaging not applicable (no packaging capability declared)." - exit 0 - fi - echo "::error::${GUIX_STUB#"$ROOT"/} is a scaffold stub (placeholder or (source #f))," \ - "and this repo declares: $REQUIRED. A stub builds nothing (criterion 8.1.4)." - echo "Make the guix.scm real, or add a Containerfile with active RUN/CMD steps." - exit 1 -fi - # Nix-only. Under the 2026-05-18 ruling this is NOT compliance — Nix is not a # tier — and the 2026-07-28 ruling removes it from the estate outright. That is # a ban, not a capability, so it applies whatever the profile declares. @@ -273,6 +257,22 @@ if [ -n "$NIX" ]; then exit 1 fi +# Only a stub guix.scm. Before capability gating this passed on presence, and +# ~90 repos rely on that; 8.1.4 is gated on reproducible-build, so the stub +# only fails where that capability (or container) is declared. +if [ -n "$GUIX_STUB" ]; then + if [ -z "$REQUIRED" ]; then + echo "::notice::${GUIX_STUB#"$ROOT"/} is a scaffold stub (criterion 8.1.4)." \ + "Not enforced: this repo declares neither reproducible-build nor container." + echo "✅ Packaging not applicable (no packaging capability declared)." + exit 0 + fi + echo "::error::${GUIX_STUB#"$ROOT"/} is a scaffold stub (placeholder or (source #f))," \ + "and this repo declares: $REQUIRED. A stub builds nothing (criterion 8.1.4)." + echo "Make the guix.scm real, or add a Containerfile with active RUN/CMD steps." + exit 1 +fi + if [ -z "$REQUIRED" ]; then echo "::notice::No packaging, and none required: the repo's rsr-profile declares" \ "neither reproducible-build nor container." \ diff --git a/scripts/tests/governance-gates-505-test.sh b/scripts/tests/governance-gates-505-test.sh index 2dc42aeb..a645b396 100755 --- a/scripts/tests/governance-gates-505-test.sh +++ b/scripts/tests/governance-gates-505-test.sh @@ -183,7 +183,7 @@ assert "declared container + TODO-only Containerfile BLOCKS" 1 "Package policy v r=$(mkrepo pkg-container-multi README.adoc) mkdir -p "$r/.clusterfuzzlite" "$r/build/container" printf 'FROM gcr.io/oss-fuzz-base/base-builder\nRUN echo fuzz\n' > "$r/.clusterfuzzlite/Containerfile" -printf 'FROM x\n# TODO\n' > "$r/a.Containerfile" +printf 'FROM x\n# TODO\n' > "$r/Containerfile.template" printf 'FROM x\nRUN true\n' > "$r/build/container/Containerfile" declare "$r" container assert "active Containerfile found past a stub; .clusterfuzzlite ignored" 0 "build/container/Containerfile" \ @@ -234,6 +234,16 @@ assert "Nix-only packaging BLOCKS after retirement" 1 "Nix-only packaging is not assert "Nix-only packaging warns before retirement" 0 "NOT YET ENFORCED" \ env PKG_TODAY="2026-05-31" "$PKG" "$r" +# A Guix scaffold must not hide Nix-only packaging when no profile is present. +r=$(mkrepo pkg-nix-stub-undeclared flake.nix guix.scm) +stub_guix "$r/guix.scm" +assert "Nix + Guix stub, no profile: warns before retirement" 0 "NOT YET ENFORCED" \ + env PKG_TODAY="2026-05-31" "$PKG" "$r" +assert "Nix + Guix stub, no profile: BLOCKS on retirement cutoff" 1 "Nix-only packaging is not compliant" \ + env PKG_TODAY="2026-06-01" "$PKG" "$r" +assert "Nix + Guix stub, no profile: BLOCKS after retirement" 1 "Nix-only packaging is not compliant" \ + env PKG_TODAY="$AFTER" "$PKG" "$r" + # Same repo, both sides of the cutoff — the self-flipping proof. r=$(mkrepo pkg-none README.adoc) declare "$r" reproducible-build