Skip to content

test: the release-gate tables cannot tell == 'false' from != 'true' on an evidence output #967

Description

@JarryShaw

tests/project/test_release_gates.py, as it stands after #966, cannot tell
== 'false' from != 'true' on an evidence output. Measured against the module's
own helpers on #966's head e403c9166:

tag:   evaluator=0  text=0      (mutant: == 'false' -> != 'true')
pypi:  evaluator=0  text=0
conda: evaluator=0  text=0      (unmutated condition also 0/0, as control)

Two reasons it is invisible. text_gate_violations only checks that the evidence
name appears in the condition, never which comparison is made against it. And
every row in gate_rows that holds version_check at success also holds the
evidence outputs at a literal 'true'/'false', so the two spellings agree on
every modelled row.

The spellings diverge only when an output is neither — empty or absent. For a
publishing job that is the dangerous direction: != 'true' runs where
== 'false' skips, so unknown evidence would become a publish attempt.

The two curl-based checks cannot produce that: both default complete=false and
only then set true, under set -euo pipefail. But PCAPKIT_TAG_EXISTS and
PCAPKIT_CONDA_TAG_EXISTS come from mukunku/tag-exists-action@v1.7.0
(create-release.yml:189,201), a third-party output this repo does not control,
and tag's gate reads one of them.

Fix is cheap: add a version_check=success row to gate_rows holding one
evidence output at NULL, and assert the gate skips. Found by the cross-review on
#966; not a gate on it.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    enhancementIssues requesting a new capability (set by the feature request template)testPull requests that add or correct tests (test: subject prefix)

    Projects

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions