tests/project/test_release_gates.py, as it stands after #966, cannot tell
== 'false' from != 'true' on an evidence output. Measured against the module's
own helpers on #966's head e403c9166:
tag: evaluator=0 text=0 (mutant: == 'false' -> != 'true')
pypi: evaluator=0 text=0
conda: evaluator=0 text=0 (unmutated condition also 0/0, as control)
Two reasons it is invisible. text_gate_violations only checks that the evidence
name appears in the condition, never which comparison is made against it. And
every row in gate_rows that holds version_check at success also holds the
evidence outputs at a literal 'true'/'false', so the two spellings agree on
every modelled row.
The spellings diverge only when an output is neither — empty or absent. For a
publishing job that is the dangerous direction: != 'true' runs where
== 'false' skips, so unknown evidence would become a publish attempt.
The two curl-based checks cannot produce that: both default complete=false and
only then set true, under set -euo pipefail. But PCAPKIT_TAG_EXISTS and
PCAPKIT_CONDA_TAG_EXISTS come from mukunku/tag-exists-action@v1.7.0
(create-release.yml:189,201), a third-party output this repo does not control,
and tag's gate reads one of them.
Fix is cheap: add a version_check=success row to gate_rows holding one
evidence output at NULL, and assert the gate skips. Found by the cross-review on
#966; not a gate on it.
tests/project/test_release_gates.py, as it stands after #966, cannot tell== 'false'from!= 'true'on an evidence output. Measured against the module'sown helpers on #966's head
e403c9166:Two reasons it is invisible.
text_gate_violationsonly checks that the evidencename appears in the condition, never which comparison is made against it. And
every row in
gate_rowsthat holdsversion_checkatsuccessalso holds theevidence outputs at a literal
'true'/'false', so the two spellings agree onevery modelled row.
The spellings diverge only when an output is neither — empty or absent. For a
publishing job that is the dangerous direction:
!= 'true'runs where== 'false'skips, so unknown evidence would become a publish attempt.The two curl-based checks cannot produce that: both default
complete=falseandonly then set
true, underset -euo pipefail. ButPCAPKIT_TAG_EXISTSandPCAPKIT_CONDA_TAG_EXISTScome frommukunku/tag-exists-action@v1.7.0(
create-release.yml:189,201), a third-party output this repo does not control,and
tag's gate reads one of them.Fix is cheap: add a
version_check=successrow togate_rowsholding oneevidence output at
NULL, and assert the gate skips. Found by the cross-review on#966; not a gate on it.