chore(autoresearch): re-baseline harness on pinned real-risk yardstick

The committed golangci gate now reports 0 issues, so the previous
lint_issues metric was saturated and could no longer measure progress.
Measure debt against an immutable .auto/lint.ref.yaml snapshot that adds
analyzers for genuine defects (panics, error unwrapping, dead stores,
missing enum cases, method ordering, suppression hygiene) while excluding
cosmetic churn (tagliatelle, wrapcheck). Guard enforces build, vet, tests,
the Cordis architecture gate, and anti-cheat floors: the yardstick cannot
be edited, the project gate may only be strengthened, nolint directives may
only shrink, and no test may disappear.
This commit is contained in:
ryan
2026-08-29 07:52:03 +08:00
parent 4f30e2d57b
commit 5971e2a9ed
8 changed files with 404 additions and 20 deletions
+48 -9
View File
@@ -1,11 +1,50 @@
#!/bin/bash
# Correctness gate: build + full tests + Cordis architecture checker (errors only)
set -euo pipefail
cd "$(dirname "$0")/../backend"
# Autoresearch GUARD — hard veto. Every line here protects an invariant that is
# unrelated to the primary metric, plus the anti-cheat red lines.
set -uo pipefail
ROOT="$(cd "$(dirname "$0")/.." && pwd)"
cd "${ROOT}/backend"
STATUS=0
fail() { echo "GUARD FAIL: $1"; STATUS=1; }
go build ./... 2>&1 | head -20
go test ./... 2>&1 | grep -vE '^(ok|---|\?|PASS)' | grep -v 'no test files' | head -40 || true
FAILS=$(go test ./... 2>&1 | grep -cE '^(FAIL|--- FAIL)' || true)
if [ "${FAILS}" != "0" ]; then echo "TESTS FAILED (${FAILS})"; exit 1; fi
"$(dirname "$0")/../scripts/check_cordis_architecture.sh" >/dev/null 2>&1 || { echo "CORDIS ARCH CHECK FAILED"; exit 1; }
echo "CHECKS OK"
source "${ROOT}/.auto/baseline.env"
# --- 1. Correctness -----------------------------------------------------------
go build ./... || fail "go build failed"
go vet ./... || fail "go vet failed"
go test ./... > /tmp/ar_guard_test.txt 2>&1 || true
FAILS=$(grep -cE '^(FAIL|--- FAIL)' /tmp/ar_guard_test.txt || true)
[ "${FAILS}" = "0" ] || { grep -E '^(FAIL|--- FAIL)' /tmp/ar_guard_test.txt | head -20; fail "tests failing (${FAILS})"; }
# --- 2. Cordis architecture gate ---------------------------------------------
"${ROOT}/scripts/check_cordis_architecture.sh" > /dev/null 2>&1 || fail "cordis architecture check failed"
# --- 3. Project lint gate must stay clean ------------------------------------
PROJECT_LINT=$(golangci-lint run 2>&1 | grep -cE '\.go:[0-9]+:[0-9]+: ' || true)
[ "${PROJECT_LINT}" = "0" ] || { fail "project golangci-lint reports ${PROJECT_LINT} issues"; }
# --- 4. Anti-cheat: the yardstick itself is immutable ------------------------
REF_SHA_NOW=$(shasum -a 256 "${ROOT}/.auto/lint.ref.yaml" | awk '{print $1}')
[ "${REF_SHA_NOW}" = "${REF_SHA}" ] || fail "pinned yardstick .auto/lint.ref.yaml was modified"
# --- 5. Anti-cheat: the project gate may only ever be STRENGTHENED ------------
WEAK=$(python3 "${ROOT}/.auto/check_gate_weaken.py" 2>&1) || { echo "${WEAK}"; fail "project gate weakened"; }
# --- 6. Anti-cheat: no new suppressions --------------------------------------
NOLINT=$(rg '//\s*nolint' --glob '*.go' 2>/dev/null | wc -l | tr -d ' ')
[ "${NOLINT}" -le "${BASE_NOLINT}" ] || fail "nolint directives grew (${NOLINT} > ${BASE_NOLINT})"
# --- 7. Anti-cheat: no tests deleted, no packages lost -----------------------
TEST_FUNCS=$(rg -c '^(func Test|func Benchmark)' --glob '*_test.go' 2>/dev/null | awk -F: '{s+=$2} END {print s+0}')
[ "${TEST_FUNCS}" -ge "${BASE_TEST_FUNCS}" ] || fail "test funcs shrank (${TEST_FUNCS} < ${BASE_TEST_FUNCS})"
TEST_FILES=$(rg --files --glob '*_test.go' 2>/dev/null | wc -l | tr -d ' ')
[ "${TEST_FILES}" -ge "${BASE_TEST_FILES}" ] || fail "test files deleted (${TEST_FILES} < ${BASE_TEST_FILES})"
PASSED=$(grep -c '^ok' /tmp/ar_guard_test.txt || true)
[ "${PASSED}" -ge "${BASE_TESTS_PASSED}" ] || fail "passing packages shrank (${PASSED} < ${BASE_TESTS_PASSED})"
# --- 8. License headers on Go sources (CI gate) ------------------------------
"${ROOT}/scripts/update_go_license.sh" --check > /dev/null 2>&1 || fail "license header check failed"
if [ "${STATUS}" = "0" ]; then echo "CHECKS OK"; fi
exit ${STATUS}