Skip to content
34 changes: 17 additions & 17 deletions scripts/check-package-policy.sh
Original file line number Diff line number Diff line change
Expand Up @@ -197,7 +197,7 @@ fi
CONTAINER="" CONTAINER_STUB=""
while IFS= read -r f; do
[ -n "$f" ] || continue
if grep -qE '^[[:space:]]*(RUN|ENTRYPOINT|CMD)[[:space:]]' "$f"; then
if grep -qiE '^[[:space:]]*(RUN|ENTRYPOINT|CMD)[[:space:]]' "$f"; then
CONTAINER="$f"; break
fi
CONTAINER_STUB="${CONTAINER_STUB:-$f}"
Expand Down Expand Up @@ -225,22 +225,6 @@ if printf '%s
' "$CAPS" | grep -xE 'reproducible-build|container' | paste -sd ' ' -)"
fi

# Only a stub guix.scm. Before capability gating this passed on presence, and
# ~90 repos rely on that; 8.1.4 is gated on reproducible-build, so the stub
# only fails where that capability (or container) is declared.
if [ -n "$GUIX_STUB" ]; then
if [ -z "$REQUIRED" ]; then
echo "::notice::${GUIX_STUB#"$ROOT"/} is a scaffold stub (criterion 8.1.4)." \
"Not enforced: this repo declares neither reproducible-build nor container."
echo "βœ… Packaging not applicable (no packaging capability declared)."
exit 0
fi
echo "::error::${GUIX_STUB#"$ROOT"/} is a scaffold stub (placeholder or (source #f))," \
"and this repo declares: $REQUIRED. A stub builds nothing (criterion 8.1.4)."
echo "Make the guix.scm real, or add a Containerfile with active RUN/CMD steps."
exit 1
fi

# Nix-only. Under the 2026-05-18 ruling this is NOT compliance β€” Nix is not a
# tier β€” and the 2026-07-28 ruling removes it from the estate outright. That is
# a ban, not a capability, so it applies whatever the profile declares.
Expand Down Expand Up @@ -273,6 +257,22 @@ if [ -n "$NIX" ]; then
exit 1
fi

# Only a stub guix.scm. Before capability gating this passed on presence, and
# ~90 repos rely on that; 8.1.4 is gated on reproducible-build, so the stub
# only fails where that capability (or container) is declared.
if [ -n "$GUIX_STUB" ]; then
if [ -z "$REQUIRED" ]; then
echo "::notice::${GUIX_STUB#"$ROOT"/} is a scaffold stub (criterion 8.1.4)." \
"Not enforced: this repo declares neither reproducible-build nor container."
echo "βœ… Packaging not applicable (no packaging capability declared)."
exit 0
fi
echo "::error::${GUIX_STUB#"$ROOT"/} is a scaffold stub (placeholder or (source #f))," \
"and this repo declares: $REQUIRED. A stub builds nothing (criterion 8.1.4)."
echo "Make the guix.scm real, or add a Containerfile with active RUN/CMD steps."
exit 1
fi

if [ -z "$REQUIRED" ]; then
echo "::notice::No packaging, and none required: the repo's rsr-profile declares" \
"neither reproducible-build nor container." \
Expand Down
12 changes: 11 additions & 1 deletion scripts/tests/governance-gates-505-test.sh
Original file line number Diff line number Diff line change
Expand Up @@ -183,7 +183,7 @@ assert "declared container + TODO-only Containerfile BLOCKS" 1 "Package policy v
r=$(mkrepo pkg-container-multi README.adoc)
mkdir -p "$r/.clusterfuzzlite" "$r/build/container"
printf 'FROM gcr.io/oss-fuzz-base/base-builder\nRUN echo fuzz\n' > "$r/.clusterfuzzlite/Containerfile"
printf 'FROM x\n# TODO\n' > "$r/a.Containerfile"
printf 'FROM x\n# TODO\n' > "$r/Containerfile.template"
printf 'FROM x\nRUN true\n' > "$r/build/container/Containerfile"
declare "$r" container
assert "active Containerfile found past a stub; .clusterfuzzlite ignored" 0 "build/container/Containerfile" \
Expand Down Expand Up @@ -234,6 +234,16 @@ assert "Nix-only packaging BLOCKS after retirement" 1 "Nix-only packaging is not
assert "Nix-only packaging warns before retirement" 0 "NOT YET ENFORCED" \
env PKG_TODAY="2026-05-31" "$PKG" "$r"

# A Guix scaffold must not hide Nix-only packaging when no profile is present.
r=$(mkrepo pkg-nix-stub-undeclared flake.nix guix.scm)
stub_guix "$r/guix.scm"
assert "Nix + Guix stub, no profile: warns before retirement" 0 "NOT YET ENFORCED" \
env PKG_TODAY="2026-05-31" "$PKG" "$r"
assert "Nix + Guix stub, no profile: BLOCKS on retirement cutoff" 1 "Nix-only packaging is not compliant" \
env PKG_TODAY="2026-06-01" "$PKG" "$r"
assert "Nix + Guix stub, no profile: BLOCKS after retirement" 1 "Nix-only packaging is not compliant" \
env PKG_TODAY="$AFTER" "$PKG" "$r"

# Same repo, both sides of the cutoff β€” the self-flipping proof.
r=$(mkrepo pkg-none README.adoc)
declare "$r" reproducible-build
Expand Down
Loading