Author SHA1 Message Date
Tirsvad 5584ddf397 Merge pull request 'MIL-002: GitHub and Gitea steps (dry run, repositories, push mirror) and split into library files' (#25) from mil-002-repositories-and-mirror into main
TirSystem/github-action: Sync GitHub mirror metadata / sync-metadata (push) Successful in 4s
Reviewed-on: #25
2026-10-05 09:33:06 +02:00
41 changed files with 148 additions and 2136 deletions
-4
View File
@@ -12,10 +12,6 @@
# chosen owner and to push to the new one. Prefer a fine-grained token. # chosen owner and to push to the new one. Prefer a fine-grained token.
GITHUB_PAT= GITHUB_PAT=
########################################
# Secrets for workframe
########################################
# GitHub account the token belongs to. It identifies who authenticates; it is # GitHub account the token belongs to. It identifies who authenticates; it is
# only a default suggestion for the owner prompt, because the repository can # only a default suggestion for the owner prompt, because the repository can
# belong to an organization. # belong to an organization.
-1
View File
@@ -187,4 +187,3 @@ repofoundry.*/
!src/lib !src/lib
config.env
+40 -315
View File
@@ -1,225 +1,35 @@
# Repo Foundry # RepoFoundry
RepoFoundry (`src/create-project.sh`) sets up a new project in one run: RepoFoundry (`src/create-project.sh`) sets up a new project: a Gitea
repository, optionally an empty GitHub repository with a push mirror from
Gitea to GitHub, and (in a later phase) a local project with the
SQA-QC-Framework.
- a **Gitea** repository (the source of truth), > **Status: work in progress.** The script can validate its configuration,
- optionally an empty **GitHub** repository that receives everything through a > check both hosts and create the repositories and the mirror. Creating the
**push mirror from Gitea to GitHub**, > local project, and the full installation guide, come in a later phase
- and a **local project** with credential-free remotes and the > (MIL-003). This file so far documents what is needed to run the host steps
[SQA-QC-Framework](https://git.tirsystem.com/TirSystem/SQA-QC-Framework) > safely.
added as a git submodule, with its skills, git hooks (and optionally the plan
gate) and templates installed.
It is a Bash script. It asks for the repository name, description, visibility ## Quick start
and owner (a user or an organization, separately on each host), shows a plan,
and only creates anything after you pass `--apply` and answer yes.
> **Status.** The script is tested with stubbed host APIs and real git against
> local repositories (see [Development](#development)). A first end-to-end run
> on real GitHub and Gitea repositories, with organization owners on both, has
> passed (2026-10-05, review record RC-017). Creating a repository under your
> own Gitea account needs the `write:user` token scope (see
> [Token permissions](#token-permissions)); that path has not been completed
> yet.
## Contents
1. [Installation](#installation)
2. [Configuration](#configuration)
3. [Usage](#usage)
4. [SSH access to Gitea](#ssh-access-to-gitea)
5. [Token permissions](#token-permissions)
6. [Security decisions](#security-decisions)
7. [Error handling and recovery](#error-handling-and-recovery)
8. [Known limitations](#known-limitations)
9. [Code layout](#code-layout)
10. [Development](#development)
11. [Stakeholders](#stakeholders)
12. [License](#license)
## Installation
Requirements:
| Tool | Needed for |
| --- | --- |
| bash 4.4 or later | the script (macOS ships 3.2: install a newer bash first) |
| `git` | the local project and the framework submodule |
| `curl` | the GitHub and Gitea APIs |
| `mktemp` and the usual base tools | temporary files and small helpers |
| `ssh` (optional) | the SSH check; without it the framework steps are skipped |
| `jq` (optional) | JSON parsing; without it a small built-in reader is used |
```bash ```bash
git clone https://git.tirsystem.com/TirSystem-BashScript/RepoFoundry.git cp config.env.example config.env # service addresses, not secret
cd RepoFoundry
src/create-project.sh --help
```
Nothing has to be installed system-wide: the script runs from the checkout and
loads its own files from `src/lib/`.
## Configuration
The script reads two plain files from the project root. They are **parsed,
never executed** (`source` is not used): only `KEY=VALUE` lines with known keys
are accepted, and anything else stops the run with a message that names the key
and the line, never the value.
```bash
cp config.env.example config.env # service addresses, not secret: set GITEA_URL (and GITEA_API_URL)
cp .env.example .env # credentials: keep private cp .env.example .env # credentials: keep private
chmod 600 .env # Linux and macOS chmod 600 .env # Linux and macOS
```
### `config.env` (service addresses)
| Key | Meaning | Default |
| --- | --- | --- |
| `GITHUB_API_URL` | GitHub REST API base URL | `https://api.github.com` |
| `GITHUB_WEB_URL` | GitHub web base URL (links and the mirror address) | `https://github.com` |
| `GITEA_URL` | Gitea base URL (required) | |
| `GITEA_API_URL` | Gitea REST API base URL | `GITEA_URL` + `/api/v1` |
| `GITEA_SSH_PORT` | SSH port of the Gitea server | `10022` |
| `MIRROR_INTERVAL` | how often Gitea pushes to GitHub, e.g. `10m0s` | `10m0s` |
| `FRAMEWORK_REPO` | `OWNER/NAME` of the framework on Gitea | `TirSystem/SQA-QC-Framework` |
Every URL must start with `https://` and must not contain a user name,
password, query string or fragment. A credential key in this file is rejected.
### `config.env` (project details, optional)
Any of the details the script asks for can be set in `config.env` instead.
A detail that is set is used and not asked; the summary marks it with
`(from config.env)`.
| Key | Detail | Accepted value |
| --- | --- | --- |
| `PROJECT_NAME` | repository name | letters, digits, `.`, `_`, `-`; at most 100; not ending in `.git` |
| `PROJECT_DESCRIPTION` | description | at most 350 characters; may be empty |
| `PROJECT_VISIBILITY` | visibility | `private` or `public` |
| `GITEA_OWNER` | Gitea user or organization | letters, digits, `.`, `_`, `-`; at most 39 |
| `USE_GITHUB` | also create a GitHub repository | `yes` or `no` |
| `GITHUB_OWNER` | GitHub user or organization | letters, digits, `-`; used only when GitHub is used |
| `PROJECT_DIRECTORY` | local directory | not empty, not starting with `-` |
| `ENABLE_PLAN_GATE` | enable the plan gate | `yes` or `no` |
- A key that is present counts as set, even when its value is empty. Only
`PROJECT_DESCRIPTION` may be empty (no description); an empty value for any
other key stops the run. Remove the line to be asked instead.
- An invalid value stops the run before any request to a host and names the
key. The script never falls back to asking for it.
- `USE_GITHUB=no` skips the GitHub owner and every GitHub step; a
`GITHUB_OWNER` set at the same time is ignored, with a warning.
- Only these eight details can be set. The confirmations stay questions that
default to no: create now, reusing an existing repository, an existing
directory, `core.hooksPath` and replacing a template file.
- These keys are accepted in `config.env` only, never in `.env`.
- A value is read as plain text: an unquoted ` #` starts a comment and cuts the
value there. Put a description that contains ` #` in double quotes, for
example `PROJECT_DESCRIPTION="Tool for #mirrors"`.
With all eight set, a run asks only the confirmations:
```bash
src/create-project.sh --apply # asks only "Create these now (y/n) [n]"
```
### `.env` (credentials)
| Key | Meaning |
| --- | --- |
| `GITEA_TOKEN` | Gitea access token (required) |
| `GITHUB_PAT` | GitHub personal access token (only when you choose GitHub) |
| `GITHUB_USER` | the GitHub account the token belongs to; only a default for the owner prompt |
`.env` is ignored by git. The script warns if it is readable by other users or
not ignored by git. See [Token permissions](#token-permissions) for what each
token needs.
## Usage
```bash
src/create-project.sh # dry run: reads from the hosts, creates nothing src/create-project.sh # dry run: reads from the hosts, creates nothing
src/create-project.sh --apply # creates everything after a final yes src/create-project.sh --apply # creates the repositories and the mirror
src/create-project.sh --config /path/to/config.env --env /path/to/.env
``` ```
The script asks for, in this order: repository name, description, visibility, Without `--apply` the script only reads from GitHub and Gitea (it checks the
Gitea owner, whether to also create a GitHub repository (and its owner), the tokens, the owners, the name, the license and SSH) and prints a plan. With
local directory and whether to enable the plan gate (a detail set in `--apply` it prints the plan again and asks a final question before it creates
[`config.env`](#configenv-project-details-optional) is not asked). It then checks both hosts anything. Nothing is ever deleted by the script.
with read-only requests and prints a plan:
```text Choosing GitHub also applies the AGPL-3.0 license to the Gitea repository, so
Plan: that repository is not empty. Without GitHub the Gitea repository is created
Gitea repository : create (private) with the AGPL-3.0 license https://git.example.org/Team/my-app empty and has no license.
GitHub repository : create (private), empty https://github.com/acme/my-app
Push mirror : Gitea -> GitHub every 10m0s
Local project : create ./my-app (new directory), git on main, no commit
Local origin : will use SSH (the SSH test passed)
Framework : add ssh://git@git.example.org:10022/Team/SQA-QC-Framework.git as a submodule
Skills and hooks : install once; plan gate no
Templates : AGENTS.md and docs/artifact-registry.md (you are asked before a file is replaced)
```
Without `--apply` that is all that happens. With `--apply` the script asks
"Create these now" (default no) and then creates, in this order:
1. the GitHub repository (empty), if chosen;
2. the Gitea repository (with the AGPL-3.0 license if GitHub was chosen);
3. the push mirror Gitea -> GitHub, and a request for its first sync;
4. the local directory, `git init` on `main`, the `origin` remote (and `github`
if chosen), and, if the Gitea repository holds the license commit, that
history;
5. the framework as the submodule `framework`;
6. the framework's skills and git hooks, and the plan gate if chosen;
7. `AGENTS.md` and `docs/artifact-registry.md` from the framework's templates.
No commit is made in the new project. Work on a branch there: the framework's
hooks refuse commits on `main`.
### Choices
- **GitHub or not.** Choosing GitHub also applies the AGPL-3.0 license to the
Gitea repository (so it is not empty) and sets up the mirror. Without GitHub
the Gitea repository is empty and has no license, and `GITHUB_PAT` is not
needed.
- **Owners.** The Gitea owner and the GitHub owner are chosen separately and
may be a user or an organization. `GITHUB_USER` is only the suggested default
for the GitHub owner prompt; it identifies who authenticates.
- **Plan gate.** If enabled, a commit that changes `src/` or `tests/` in the
new project needs a `Task: MIL-NNN#N` trailer.
### Nothing is overwritten without a yes
The script asks first (default no) before it uses an existing directory, before
it replaces an existing `core.hooksPath`, and before it replaces an existing
`AGENTS.md` or `docs/artifact-registry.md`. It never deletes anything, never
replaces a remote that points somewhere else, and git itself refuses to
overwrite a file when the license history is checked out.
## SSH access to Gitea
The framework submodule is fetched over SSH on port **10022**
(`ssh://git@<gitea host>:10022/TirSystem/SQA-QC-Framework.git`). Before you run
the script:
1. Add your SSH public key to your Gitea account.
2. Connect once by hand so that the server's host key is known (the script
refuses unknown host keys and never answers questions for you):
```bash
ssh -p 10022 -T git@git.tirsystem.com
```
A message that you have successfully authenticated, without shell access,
means it works.
The script runs the same check in its dry run. If it fails, the plan says so
and, with `--apply`, you are asked whether to create the repositories and the
local project **without** the framework steps (they are then reported as
skipped). The default answer is no.
## Token permissions ## Token permissions
@@ -238,7 +48,7 @@ repositories for the chosen owner and to push to the new one.
| Create a private repository | classic token with the `repo` scope | GitHub REST documentation, "Create a repository" | | Create a private repository | classic token with the `repo` scope | GitHub REST documentation, "Create a repository" |
| Create a public repository only | classic token with `public_repo` is enough | same | | Create a public repository only | classic token with `public_repo` is enough | same |
| Push from the Gitea mirror | covered by `repo` | | | Push from the Gitea mirror | covered by `repo` | |
| Check that you belong to the organization owner | worked with a classic token that has `repo` and `admin:org` | `read:org` alone was **not tested**: the GitHub documentation names no scope for this call. If the script says you do not belong to an organization that you do belong to, add `read:org`. | | Check that you belong to the organization owner | probably `read:org` | **Not confirmed**: the GitHub documentation names no scope for this call. If the script says you do not belong to an organization that you do belong to, add `read:org`. |
- **Organization owners:** you must be an active member who is allowed to - **Organization owners:** you must be an active member who is allowed to
create repositories in the organization. Organizations that require SSO or create repositories in the organization. Organizations that require SSO or
@@ -246,80 +56,23 @@ repositories for the chosen owner and to push to the new one.
- **Fine-grained tokens:** the GitHub documentation lists no fine-grained - **Fine-grained tokens:** the GitHub documentation lists no fine-grained
permission for creating a repository, and this has not been tested. permission for creating a repository, and this has not been tested.
Use a classic token until it has been. Use a classic token until it has been.
- **`GITHUB_USER`:** if it differs from the account the token belongs to, the - **`GITHUB_USER`:** names the account the token belongs to. It is only a
script warns and uses the account the token belongs to. default for the owner prompt; the repository may belong to an organization.
If it differs from the account the token belongs to, the script warns and
uses the account the token belongs to.
### Gitea token (`GITEA_TOKEN`) ### Gitea token (`GITEA_TOKEN`)
| Need | Scope | Source | | Need | Scope | Source |
| --- | --- | --- | | --- | --- | --- |
| Read the account the token belongs to | `read:user` | Gitea documentation | | Read the account the token belongs to | `read:user` | Gitea documentation |
| Create a repository **under your own account** | `write:user` | **Confirmed by a real server**: without it Gitea answers `required=[write:user]` | | Create repositories, manage the push mirror | `write:repository` | Gitea documentation |
| Create a repository in an organization, manage its push mirror | `write:organization` and `write:repository` | worked with a token that has both, plus `read:user`; the minimum was not narrowed down | | Look up an organization and your permissions in it | `read:organization` | Gitea documentation |
| Look up an organization and your permissions in it | covered by the scopes above | worked in the end-to-end run | | Create a repository in an organization | probably `write:organization` as well | **Not confirmed**: expected from how the Gitea API groups organization calls; the end-to-end test in MIL-003 will confirm it. |
A missing scope shows up as an HTTP 403 with the server's own message. The A missing scope shows up as an HTTP 403 with the server's own message. The
script stops before it creates anything when a preflight check is refused. script stops before it creates anything when a preflight check is refused.
## Security decisions
- **Tokens never appear** in output, logs, remote URLs, `.git/config`,
`.gitmodules`, command lines or leftover files. They go to `curl` through a
private configuration file that is removed right after the request, and to
`git` (HTTPS fetch only) through a `GIT_ASKPASS` helper and the environment
of that one command. Output is filtered, so even a server message that echoes
a token is shown as `[redacted]`. Tests plant fake tokens and search all
output and every file of the new project for them.
- **No `set -x`.** Tracing would print every secret, so the script switches it
off and says so.
- **Config files are parsed, not sourced,** with a whitelist of keys; values
are validated (URLs must be `https` without credentials, tokens must have a
safe character set) and never executed.
- **Dry run by default.** Creating anything needs `--apply` and a final yes.
- **No destructive commands.** The script never deletes a repository or a
file and never uses a recursive delete; temporary files are removed one by
one.
- **Credential-free remotes.** `origin` is `ssh://git@host:port/owner/name.git`
(or plain HTTPS when SSH is not used) and `github` is a plain HTTPS address.
- **Redirects are not followed,** so a token is only ever sent to the host in
the URL it was meant for. Unknown SSH host keys are refused.
- **Framework scripts run on the new project only.** They are run with
`PROJECT_ROOT` set explicitly, so a `PROJECT_ROOT` in your environment cannot
point them elsewhere. They come from the framework repository you configured:
review what you trust there.
## Error handling and recovery
Every message starts with `error:`, names what failed and what to do, and never
contains a secret. Exit codes: `0` success (or a dry run), `1` a failed check or
step, `2` a usage error.
| What happens | What the script does | What you do |
| --- | --- | --- |
| A tool, a config key or a token is missing or invalid | stops before any request | fix it and run again |
| A token is refused, an owner is unknown, a name is taken, the license is missing | stops in the preflight; nothing was created | fix the cause |
| The host cannot be reached | stops with the host name | try again |
| A repository already exists and is empty (Gitea: or holds only the license and the README Gitea adds) | offers to reuse it (default no) | answer, or choose another name |
| A repository already has content | stops | choose another name or remove it |
| A step fails after another succeeded | stops and prints what exists, what failed and how to continue | fix the cause and run the **same command again with `--apply`**: what was created is offered for reuse |
| The mirror is refused (disabled, interval too short) | keeps the repositories and reports it | change `MIRROR_INTERVAL` or ask the Gitea administrator, then run again |
| The framework submodule cannot be fetched | reports the address and how to test SSH | fix your SSH access, run again |
| `sync_on_commit` was ignored by Gitea | warns; the mirror syncs on its interval | enable it in the repository settings if needed |
A partial run is reported like this:
```text
The run stopped before it finished. This is what exists now:
GitHub repository : created https://github.com/acme/my-app
Gitea repository : FAILED
Push mirror : not attempted
...
To continue: fix the problem named above and run the same command again with --apply.
```
Nothing is deleted automatically. To start over, delete the repositories in the
web interface and the project directory by hand.
## Known limitations ## Known limitations
- **The mirror password is stored on the Gitea server.** Gitea needs the - **The mirror password is stored on the Gitea server.** Gitea needs the
@@ -328,27 +81,25 @@ web interface and the project directory by hand.
this, and revoke it if the Gitea server is ever in doubt. this, and revoke it if the Gitea server is ever in doubt.
- **`sync_on_commit` may be ignored.** When a push mirror is created through - **`sync_on_commit` may be ignored.** When a push mirror is created through
the API, some Gitea versions ignore `sync_on_commit` (upstream issue the API, some Gitea versions ignore `sync_on_commit` (upstream issue
go-gitea/gitea#22990). On Gitea 1.27.3 it was applied: a branch pushed to go-gitea/gitea#22990). The script reads the mirror back and warns if the
Gitea reached GitHub within seconds. The script reads the mirror back and setting was not applied; the mirror then syncs on its interval
warns if the setting was not applied; the mirror then syncs on its interval
(`MIRROR_INTERVAL`, default 10 minutes). The first sync is requested right (`MIRROR_INTERVAL`, default 10 minutes). The first sync is requested right
after the mirror is created. after the mirror is created.
- **The server decides the shortest interval** and whether push mirrors are - **The server decides the shortest interval** and whether push mirrors are
allowed at all. A refused mirror stops the run with the server's message; allowed at all. A refused mirror stops the run with the server's message;
the repositories created so far are kept. the repositories created so far are kept.
- **The license commit.** Gitea adds the license file when the repository is - **The license commit.** Gitea adds the license file when the repository is
created with `auto_init`, and on the real server it also adds a generated created with `auto_init`. The script sends no README, so the repository
`README.md`. Both are mirrored to GitHub and become the first commit of the should hold only `LICENSE`; this is checked in the MIL-003 end-to-end test.
local project. A Gitea repository that holds only these files counts as - **No rollback.** If a step fails, the script reports what exists and how to
content this script created and is offered for reuse; a repository with continue. A repeated run offers to reuse a repository it created earlier
anything else counts as having content and is refused. (empty, or in Gitea's case holding only the license). Delete what you do not
- **No rollback.** See [Error handling and recovery](#error-handling-and-recovery). want in the web interface.
- **Mirror direction is Gitea to GitHub only.** Push to Gitea; GitHub is a - **Mirror direction is Gitea to GitHub only.** Push to Gitea; GitHub is a
copy. copy.
- **The framework needs SSH.** Without SSH access to Gitea the framework steps - **Requirements:** bash 4.4 or later, `git`, `curl` and `mktemp`; `jq` and
can only be skipped. `ssh` are optional. Without `jq` the script reads the few JSON fields it
- **Tested on Windows (Git Bash) only so far.** Running the tests on Linux and needs with a simple built-in reader.
macOS is an open follow-up.
## Code layout ## Code layout
@@ -370,15 +121,12 @@ file. The files are loaded from that directory only, by a fixed path.
| `api.sh` | GitHub and Gitea API calls and reporting a refused call | | `api.sh` | GitHub and Gitea API calls and reporting a refused call |
| `prompts.sh` | interactive questions with validation | | `prompts.sh` | interactive questions with validation |
| `project.sh` | the project details: asking for them and showing them | | `project.sh` | the project details: asking for them and showing them |
| `hosts.sh` | names, links and remote addresses of the repositories | | `hosts.sh` | names and links of the repositories on each host |
| `preflight.sh` | read-only checks of both hosts | | `preflight.sh` | read-only checks of both hosts |
| `steps.sh` | the outcome of each step and the final report | | `steps.sh` | the outcome of each step and the final report |
| `plan.sh` | printing what the script is about to do | | `plan.sh` | printing what the script is about to do |
| `repositories.sh` | creating the GitHub and Gitea repositories | | `repositories.sh` | creating the GitHub and Gitea repositories |
| `mirror.sh` | the Gitea to GitHub push mirror | | `mirror.sh` | the Gitea to GitHub push mirror |
| `git.sh` | running git for the new project without prompts or tokens on a command line |
| `localproject.sh` | the local directory, git repository and remotes |
| `framework.sh` | the framework submodule, skills, hooks and templates |
| `apply.sh` | confirmations and the apply flow; the only code that changes anything | | `apply.sh` | confirmations and the apply flow; the only code that changes anything |
| `cli.sh` | usage text and option parsing | | `cli.sh` | usage text and option parsing |
@@ -391,27 +139,4 @@ when it is loaded.
```bash ```bash
bash tests/run-tests.sh # shellcheck, shfmt and all tests, no network bash tests/run-tests.sh # shellcheck, shfmt and all tests, no network
bash tests/run-tests.sh PATTERN # only tests whose name contains PATTERN
``` ```
The tests stub the two host APIs (a fake `curl` answers from a routes file) and
`ssh`, and run real git against local bare repositories that stand in for
Gitea and the framework (git's `insteadOf` rewrites the remote addresses), with
a private git configuration. Nothing reaches the network and nothing outside
the test directories is changed. Mutation checks show that the tests fail when
a guarantee is removed.
Planning documents, reviews and the traceability matrix are in `docs/`; the
project follows the SQA and QC framework (see `AGENTS.md`).
## Stakeholders
| Who | Role |
| --- | --- |
| [Tirsvad](https://www.linkedin.com/in/tirsvad74) | Product Owner and maintainer |
| [Michael Kragh](https://www.linkedin.com/in/codemikemike/) | DevOps, cybersecurity and maintainer |
| GitHub readers | people who read and may reuse this project |
## License
GNU Affero General Public License v3.0; see [LICENSE](LICENSE).
+2 -23
View File
@@ -17,10 +17,10 @@ GITHUB_API_URL=https://api.github.com
GITHUB_WEB_URL=https://github.com GITHUB_WEB_URL=https://github.com
# Gitea instance base URL. Repository links are derived from it. # Gitea instance base URL. Repository links are derived from it.
GITEA_URL=https://<your gitea instance>/ GITEA_URL=https://git.tirsystem.com/
# Gitea REST API base URL. If you leave this out it is GITEA_URL + /api/v1. # Gitea REST API base URL. If you leave this out it is GITEA_URL + /api/v1.
GITEA_API_URL=https://<your gitea instance>/api/v1 GITEA_API_URL=https://git.tirsystem.com/api/v1
# Optional. SSH port of the Gitea server, used for the SSH check and later # Optional. SSH port of the Gitea server, used for the SSH check and later
# for the framework submodule. Default: 10022. # for the framework submodule. Default: 10022.
@@ -29,24 +29,3 @@ GITEA_API_URL=https://<your gitea instance>/api/v1
# Optional. How often Gitea pushes to GitHub, as a Go duration (10m0s, 8h0m0s). # Optional. How often Gitea pushes to GitHub, as a Go duration (10m0s, 8h0m0s).
# The server may enforce a minimum. Default: 10m0s. # The server may enforce a minimum. Default: 10m0s.
#MIRROR_INTERVAL=10m0s #MIRROR_INTERVAL=10m0s
# Optional. Project details that are set here are not asked. A key that is
# present counts as set, even when empty; only PROJECT_DESCRIPTION may be
# empty. An invalid value stops the run and names the key. Remove or comment
# out a line to be asked for it. The confirmations ("Create these now" and
# the questions about existing repositories, directories and files) are
# always asked. Put a value that contains " #" in double quotes: an unquoted
# " #" starts a comment.
#PROJECT_NAME=my-project
#PROJECT_DESCRIPTION=What the project is for
#PROJECT_VISIBILITY=private # private or public
#GITEA_OWNER=my-organization
#USE_GITHUB=yes # yes or no
#GITHUB_OWNER=my-organization # used only when USE_GITHUB is yes
#PROJECT_DIRECTORY=./my-project
#ENABLE_PLAN_GATE=no # yes or no
# Optional. OWNER/NAME of the SQA-QC-Framework repository on the Gitea server;
# it is added to the new project as a submodule over SSH.
# Default: TirSystem/SQA-QC-Framework.
#FRAMEWORK_REPO=TirSystem/SQA-QC-Framework
+2 -2
View File
@@ -14,7 +14,7 @@ document of a type. `Primary File` may contain a glob (e.g.
| BC | Business Case | docs/business-case.md | 002 | | BC | Business Case | docs/business-case.md | 002 |
| SA | Stakeholder Analysis | docs/stakeholder-analysis.md | 002 | | SA | Stakeholder Analysis | docs/stakeholder-analysis.md | 002 |
| PP | Project Plan | docs/project-plan.md | 002 | | PP | Project Plan | docs/project-plan.md | 002 |
| MIL | Milestone / Gateway | docs/milestones/*.md | 005 | | MIL | Milestone / Gateway | docs/milestones/*.md | 004 |
| US | User Story | docs/user-stories.md | 002 | | US | User Story | docs/user-stories.md | 002 |
| UC | Use Case | docs/uc-*/uc.md | 002 | | UC | Use Case | docs/uc-*/uc.md | 002 |
| SSD | System Sequence Diagram | docs/uc-*/ssd.md | 002 | | SSD | System Sequence Diagram | docs/uc-*/ssd.md | 002 |
@@ -23,7 +23,7 @@ document of a type. `Primary File` may contain a glob (e.g.
| DM | Domain Model | docs/domain-model.md | 003 | | DM | Domain Model | docs/domain-model.md | 003 |
| DICT | Domain Dictionary (PO and IT terms) | docs/dictionary.md | 002 | | DICT | Domain Dictionary (PO and IT terms) | docs/dictionary.md | 002 |
| UCD | Use Case Diagram | docs/use-case-diagram.md | 002 | | UCD | Use Case Diagram | docs/use-case-diagram.md | 002 |
| RC | SQA Review Record | docs/sqa/reviews/rc-*.md | 020 | | RC | SQA Review Record | docs/sqa/reviews/rc-*.md | 017 |
| TM | Traceability Matrix | docs/sqa/traceability-matrix.md | 002 | | TM | Traceability Matrix | docs/sqa/traceability-matrix.md | 002 |
## Languages ## Languages
+3 -5
View File
@@ -9,8 +9,8 @@
## Version History ## Version History
| Date | Status | Author | Reviewer | Change | Commit | | Date | Status | Author | Reviewer | Change | Commit |
| --- | --- | --- | --- | --- | --- | | --- | --- | --- | --- | --- | --- |
| 2026-10-05 | Deprecated | Jens Tirsvad Nielsen | S02 | Initial version | [424f14f] |
| 2026-10-05 | Accepted | Jens Tirsvad Nielsen | S02 | Optional GitHub; choosing GitHub applies the AGPL license to the Gitea repository<br>Cited UCD-001<br>Justified the qualitative cost-benefit; stakeholder roles replaced by interests; success criteria 2 and 3 reworded for optional GitHub<br>Added objective 7 (documentation) and its success criterion | [02875ae] | | 2026-10-05 | Accepted | Jens Tirsvad Nielsen | S02 | Optional GitHub; choosing GitHub applies the AGPL license to the Gitea repository<br>Cited UCD-001<br>Justified the qualitative cost-benefit; stakeholder roles replaced by interests; success criteria 2 and 3 reworded for optional GitHub<br>Added objective 7 (documentation) and its success criterion | [02875ae] |
| 2026-10-05 | Accepted | Jens Tirsvad Nielsen | S02 | Added objective 8 (project details preset in config.env), the matching scope item and success criterion 8 | [2a6bb8e] |
--- ---
@@ -41,7 +41,6 @@ One repeatable, reviewed procedure gives every new project the same secure basel
5. Add the SQA-QC-Framework as the `framework` submodule, install its skills and git hooks, and copy its templates, optionally enabling the plan gate. 5. Add the SQA-QC-Framework as the `framework` submodule, install its skills and git hooks, and copy its templates, optionally enabling the plan gate.
6. Never print or persist a token, and never overwrite existing files or directories without consent. 6. Never print or persist a token, and never overwrite existing files or directories without consent.
7. Document installation, configuration, usage, security decisions and error handling in clear English for GitHub readers. 7. Document installation, configuration, usage, security decisions and error handling in clear English for GitHub readers.
8. Let the Maintainer preset the project details in `config.env`, so that a detail that is set there is not asked again.
## Scope ## Scope
@@ -49,7 +48,7 @@ One repeatable, reviewed procedure gives every new project the same secure basel
- `create-project.sh`, `config.env.example`, `.env.example`, `.gitignore` and `README.md`. - `create-project.sh`, `config.env.example`, `.env.example`, `.gitignore` and `README.md`.
- Safe parsing and validation of `config.env` and `.env` (never `source`d). - Safe parsing and validation of `config.env` and `.env` (never `source`d).
- Prompts for name, description, visibility and owner on each chosen host, and whether to use GitHub (which also applies the AGPL license). Each of these details may be set in `config.env` instead and is then not asked. - Prompts for name, description, visibility and owner on each chosen host, and whether to use GitHub (which also applies the AGPL license).
- Checks for required tools (`git`, `curl`, optional `jq`) before any change. - Checks for required tools (`git`, `curl`, optional `jq`) before any change.
- A check that the project name is not already taken on GitHub. - A check that the project name is not already taken on GitHub.
- Partial-failure reporting with a documented way to continue. - Partial-failure reporting with a documented way to continue.
@@ -90,7 +89,6 @@ Supports developing on self-hosted Gitea while publishing to GitHub, and adoptin
| 5 | No overwrite | An existing directory or file is never replaced without a yes | Run twice in the same location | | 5 | No overwrite | An existing directory or file is never replaced without a yes | Run twice in the same location |
| 6 | Lint | `shellcheck` reports no errors on `create-project.sh` | `shellcheck create-project.sh` | | 6 | Lint | `shellcheck` reports no errors on `create-project.sh` | `shellcheck create-project.sh` |
| 7 | Documentation | `README.md` covers installation, configuration, usage, security decisions, error handling and stakeholders | Review by S02 against MIL-003 Go/No-Go criterion 6 | | 7 | Documentation | `README.md` covers installation, configuration, usage, security decisions, error handling and stakeholders | Review by S02 against MIL-003 Go/No-Go criterion 6 |
| 8 | Preset details | A project detail set in `config.env` is never asked; an invalid one stops the run before any request and names the key | Tests with each key set, absent, empty and invalid |
## Risks ## Risks
@@ -140,5 +138,5 @@ Proceed — the procedure is small, well bounded and removes a repeated, securit
[SA-001]: ./stakeholder-analysis.md [SA-001]: ./stakeholder-analysis.md
[UCD-001]: ./use-case-diagram.md [UCD-001]: ./use-case-diagram.md
[424f14f]: https://git.tirsystem.com/TirSystem-BashScript/repo_foundry/commit/424f14f4f5577bb47fea41c8f3a655dca953e6d8
[02875ae]: https://git.tirsystem.com/TirSystem-BashScript/repo_foundry/commit/02875aee5f2953473924074eea0056eb31af6b7a [02875ae]: https://git.tirsystem.com/TirSystem-BashScript/repo_foundry/commit/02875aee5f2953473924074eea0056eb31af6b7a
[2a6bb8e]: https://git.tirsystem.com/TirSystem-BashScript/repo_foundry/commit/2a6bb8e8afadfe6ca4a621da30e44a372898ca62
+2 -6
View File
@@ -10,7 +10,6 @@
| Date | Status | Author | Reviewer | Change | Commit | | Date | Status | Author | Reviewer | Change | Commit |
| --- | --- | --- | --- | --- | --- | | --- | --- | --- | --- | --- | --- |
| 2026-10-05 | Accepted | Jens Tirsvad Nielsen | S02 | Initial version, created from [DM-001] (UC-001) | [02875ae] | | 2026-10-05 | Accepted | Jens Tirsvad Nielsen | S02 | Initial version, created from [DM-001] (UC-001) | [02875ae] |
| 2026-10-05 | Accepted | Jens Tirsvad Nielsen | S02 | Configuration may hold preset project details (from DM-001, UC-001 step 3) | [2a6bb8e] |
--- ---
@@ -32,9 +31,7 @@ class Project {
description description
visibility visibility
} }
class Configuration { class Configuration
preset project details
}
class "Git Host" as GitHost { class "Git Host" as GitHost {
name name
web address web address
@@ -118,7 +115,7 @@ Summary "1" --> "1" Project : reports on
| --- | --- | --- | --- | | --- | --- | --- | --- |
| Maintainer | The person who creates a new project (S01 or S02) | name | [UC-001] primary actor | | Maintainer | The person who creates a new project (S01 or S02) | name | [UC-001] primary actor |
| Project | The new software project being set up | name, description, visibility | [UC-001] "new project", step 3 | | Project | The new software project being set up | name, description, visibility | [UC-001] "new project", step 3 |
| Configuration | The service addresses and access tokens the Maintainer has set up before starting, and any project details preset in it | preset project details (optional) | [UC-001] precondition, steps 2 and 3 | | Configuration | The service addresses and access tokens the Maintainer has set up before starting | none | [UC-001] precondition, step 2 "configuration and credentials" |
| Git Host | A service that holds repositories: Gitea or GitHub | name, web address, API address | [UC-001] steps 5 to 7 "GitHub", "Gitea" | | Git Host | A service that holds repositories: Gitea or GitHub | name, web address, API address | [UC-001] steps 5 to 7 "GitHub", "Gitea" |
| Access Token | A secret that lets the Maintainer act on a Git Host; it is never part of an address | kind | [UC-001] precondition "Gitea token", "GitHub PAT" | | Access Token | A secret that lets the Maintainer act on a Git Host; it is never part of an address | kind | [UC-001] precondition "Gitea token", "GitHub PAT" |
| Owner | The user or organization on a Git Host that owns repositories | name, kind (user or organization) | [UC-001] step 3 "owner" | | Owner | The user or organization on a Git Host that owns repositories | name, kind (user or organization) | [UC-001] step 3 "owner" |
@@ -173,4 +170,3 @@ Summary "1" --> "1" Project : reports on
[DICT-001]: ./dictionary.md [DICT-001]: ./dictionary.md
[DM-001]: ./uc-001/dm.md [DM-001]: ./uc-001/dm.md
[02875ae]: https://git.tirsystem.com/TirSystem-BashScript/repo_foundry/commit/02875aee5f2953473924074eea0056eb31af6b7a [02875ae]: https://git.tirsystem.com/TirSystem-BashScript/repo_foundry/commit/02875aee5f2953473924074eea0056eb31af6b7a
[2a6bb8e]: https://git.tirsystem.com/TirSystem-BashScript/repo_foundry/commit/2a6bb8e8afadfe6ca4a621da30e44a372898ca62
@@ -9,8 +9,8 @@
## Version History ## Version History
| Date | Status | Author | Reviewer | Change | Commit | | Date | Status | Author | Reviewer | Change | Commit |
| --- | --- | --- | --- | --- | --- | | --- | --- | --- | --- | --- | --- |
| 2026-10-05 | Deprecated | Jens Tirsvad Nielsen | S02 | Initial version | [424f14f] |
| 2026-10-05 | Accepted | Jens Tirsvad Nielsen | S02 | Optional GitHub; choosing GitHub applies the AGPL license to the Gitea repository<br>Cited US-001.02<br>Purpose and criterion 1 reworded for optional GitHub<br>Target date accepted | [02875ae] | | 2026-10-05 | Accepted | Jens Tirsvad Nielsen | S02 | Optional GitHub; choosing GitHub applies the AGPL license to the Gitea repository<br>Cited US-001.02<br>Purpose and criterion 1 reworded for optional GitHub<br>Target date accepted | [02875ae] |
| 2026-10-05 | Proposed | Jens Tirsvad Nielsen | S02 | Criterion 2 corrected after the live run: Gitea also adds a README.md with the license | [613a288] |
--- ---
@@ -27,7 +27,7 @@ Decide whether the script creates the Gitea repository and, if GitHub is chosen,
| # | Criterion (objectively checkable) | Go | No-Go | | # | Criterion (objectively checkable) | Go | No-Go |
| --- | --- | --- | --- | | --- | --- | --- | --- |
| 1 | Repositories are created under the owner chosen at the prompt, for a user owner and for an organization owner, on each host used | Both verified | Any under the wrong owner | | 1 | Repositories are created under the owner chosen at the prompt, for a user owner and for an organization owner, on each host used | Both verified | Any under the wrong owner |
| 2 | The GitHub repository is created empty. The Gitea repository holds only the AGPL license file and the `README.md` that Gitea generates for it when GitHub is chosen, otherwise it is empty. Neither has a `.gitignore` | Verified | Any other file present | | 2 | The GitHub repository is created empty. The Gitea repository holds only the AGPL license file when GitHub is chosen, otherwise it is empty. Neither has a generated README or `.gitignore` | Verified | Any other commit present |
| 3 | When GitHub is chosen, a commit pushed to Gitea (including the license file) appears on GitHub; nothing flows the other way. When GitHub is not chosen, no GitHub call is made | Verified | Wrong direction, no sync, or a GitHub call without the choice | | 3 | When GitHub is chosen, a commit pushed to Gitea (including the license file) appears on GitHub; nothing flows the other way. When GitHub is not chosen, no GitHub call is made | Verified | Wrong direction, no sync, or a GitHub call without the choice |
| 4 | Mirror credentials are never part of a remote URL, log or output | None found | Any found | | 4 | Mirror credentials are never part of a remote URL, log or output | None found | Any found |
| 5 | With an invalid token on one host, the script stops before creating anything or reports exactly what was created and how to continue | Verified | Silent or misleading | | 5 | With an invalid token on one host, the script stops before creating anything or reports exactly what was created and how to continue | Verified | Silent or misleading |
@@ -76,5 +76,5 @@ Decide whether the script creates the Gitea repository and, if GitHub is chosen,
[US-001]: ../user-stories.md [US-001]: ../user-stories.md
[UC-001]: ../uc-001/uc.md [UC-001]: ../uc-001/uc.md
[MIL-001]: ./mil-001-foundation.md [MIL-001]: ./mil-001-foundation.md
[424f14f]: https://git.tirsystem.com/TirSystem-BashScript/repo_foundry/commit/424f14f4f5577bb47fea41c8f3a655dca953e6d8
[02875ae]: https://git.tirsystem.com/TirSystem-BashScript/repo_foundry/commit/02875aee5f2953473924074eea0056eb31af6b7a [02875ae]: https://git.tirsystem.com/TirSystem-BashScript/repo_foundry/commit/02875aee5f2953473924074eea0056eb31af6b7a
[613a288]: https://git.tirsystem.com/TirSystem-BashScript/repo_foundry/commit/613a288dead4c19c00dee6fbb60d46bc3edf8889
@@ -1,91 +0,0 @@
# MIL-004 Configurable Details
## Metadata
| Key | Value |
| --- | --- |
| ID | MIL-004 |
| CrossReference | [BC-001], [US-001], [UC-001] |
## Version History
| Date | Status | Author | Reviewer | Change | Commit |
| --- | --- | --- | --- | --- | --- |
| 2026-10-05 | Accepted | Jens Tirsvad Nielsen | S02 | Initial version | [2a6bb8e] |
---
## Purpose
Decide whether the project details can be preset in `config.env` without weakening the safety questions: a detail that is set there is not asked, an invalid one stops the run, and the confirmations stay interactive.
## Deliverable
`create-project.sh` that reads eight optional keys from `config.env`, checks them with the same rules as the prompts, skips the prompt for each key that is set and marks that value as coming from the configuration in the summary. `config.env.example` and the README document the keys. The tests cover every key.
The keys (a key that is present counts as set, even when empty, but only the description may be empty):
| Key | Detail | Accepted value |
| --- | --- | --- |
| `PROJECT_NAME` | repository name | the repository name rules of the prompt |
| `PROJECT_DESCRIPTION` | description | up to 350 characters, no control characters; may be empty |
| `PROJECT_VISIBILITY` | visibility | `private` or `public` |
| `GITEA_OWNER` | Gitea owner (user or organization) | the Gitea owner rules of the prompt |
| `USE_GITHUB` | also create a GitHub repository | `yes` or `no` |
| `GITHUB_OWNER` | GitHub owner (user or organization) | the GitHub owner rules; used only when GitHub is used |
| `PROJECT_DIRECTORY` | local directory | the directory rules of the prompt |
| `ENABLE_PLAN_GATE` | enable the plan gate | `yes` or `no` |
## Go / No-Go Criteria
| # | Criterion (objectively checkable) | Go | No-Go |
| --- | --- | --- | --- |
| 1 | For each of the eight keys: when it is present its prompt is not shown and its value is used and shown in the summary as coming from `config.env` | Tests pass | Any prompt shown or value ignored |
| 2 | A key that is absent is asked as before; asked and preset details can be mixed | Tests pass | Any asked wrongly |
| 3 | A present but empty value is accepted for `PROJECT_DESCRIPTION` and refused, naming the key, for the other seven | Tests pass | Any other result |
| 4 | An invalid value stops the run before any request to a host, names the key, and never falls back to asking | Tests pass | A request made or a prompt shown |
| 5 | `USE_GITHUB=no` skips the GitHub owner and the GitHub steps; a `GITHUB_OWNER` set while GitHub is not used is ignored with a warning | Tests pass | Any GitHub call or owner prompt |
| 6 | With all eight keys set, the only questions left are the confirmations: create now, reuse of an existing repository, directory, hooks path or file, each still defaulting to no | Tests pass | A confirmation skipped |
| 7 | The new keys are rejected in `.env`, and credentials are still rejected in `config.env` | Tests pass | Any accepted |
| 8 | All acceptance criteria of US-001.04 in [US-001] are met | Verified | Any unmet |
## Dependencies
| Depends on | Reason |
| --- | --- |
| [MIL-003] | Needs the complete prompt and apply flow to change |
## Traceability
| Business Case objective / KPI / user story | Reference |
| --- | --- |
| User story US-001.04 | [US-001] |
| Objective 8 (details preset in `config.env`) | [BC-001] |
| Success criterion 8 | [BC-001] |
## Ownership
| Role | Stakeholder ID (SA) |
| --- | --- |
| Owner | S01 |
| Approving reviewer | S02 |
## Target Date
2026-11-20 — proposed; the Business Case sets no deadline.
## Tasks
| # | Task | Summary | Needs its own Use Case/User Story? | Reference |
| --- | --- | --- | --- | --- |
| 1 | Read and validate the eight optional config keys | Add `PROJECT_NAME`, `PROJECT_DESCRIPTION`, `PROJECT_VISIBILITY`, `GITEA_OWNER`, `USE_GITHUB`, `GITHUB_OWNER`, `PROJECT_DIRECTORY` and `ENABLE_PLAN_GATE` to the `config.env` parser, checked with the validators the prompts use. A present key counts as set; only the description may be empty. Errors name the key. The new keys are rejected in `.env`; credentials stay rejected in `config.env`. | Yes | [UC-001] |
| 2 | Use configured details instead of asking, and show their source | In the step that collects the details, take each configured value instead of asking and mark it `(from config.env)` in the summary. `USE_GITHUB=no` skips the GitHub owner; a `GITHUB_OWNER` set while GitHub is not used is ignored with a warning. Extension 3a of UC-001. | Yes | [UC-001] |
| 3 | Keep the confirmations interactive | Create now, reuse of an existing repository, directory, hooks path and template files stay questions that default to no, even when every detail is configured. Add tests that prove no run creates or replaces anything without them, because this is where a configurable run could weaken the rule never to overwrite without a yes. | No | |
| 4 | Document the keys | Add commented examples to `config.env.example` and a table of the keys to the README, with an example of a run in which only the confirmations are asked, and a note that a key that is present but empty counts as set. | No | |
| 5 | Test every key and case | Each key set, absent, empty and invalid; mixed asked and preset details; the `USE_GITHUB` interplay; the source marking in the summary; no prompt text shown for a preset detail; the existing tests unchanged. | No | |
---
[BC-001]: ../business-case.md
[US-001]: ../user-stories.md
[UC-001]: ../uc-001/uc.md
[MIL-003]: ./mil-003-scaffold-and-release.md
[2a6bb8e]: https://git.tirsystem.com/TirSystem-BashScript/repo_foundry/commit/2a6bb8e8afadfe6ca4a621da30e44a372898ca62
+6 -11
View File
@@ -4,23 +4,23 @@
| Key | Value | | Key | Value |
| --- | --- | | --- | --- |
| ID | PP-001 | | ID | PP-001 |
| CrossReference | [BC-001], [SA-001], [MIL-001], [MIL-002], [MIL-003], [MIL-004], [US-001] | | CrossReference | [BC-001], [SA-001], [MIL-001], [MIL-002], [MIL-003], [US-001] |
## Version History ## Version History
| Date | Status | Author | Reviewer | Change | Commit | | Date | Status | Author | Reviewer | Change | Commit |
| --- | --- | --- | --- | --- | --- | | --- | --- | --- | --- | --- | --- |
| 2026-10-05 | Deprecated | Jens Tirsvad Nielsen | S02 | Initial version | [424f14f] |
| 2026-10-05 | Accepted | Jens Tirsvad Nielsen | S02 | Stories per phase: US-001.01 to US-001.03<br>Dates accepted | [02875ae] | | 2026-10-05 | Accepted | Jens Tirsvad Nielsen | S02 | Stories per phase: US-001.01 to US-001.03<br>Dates accepted | [02875ae] |
| 2026-10-05 | Accepted | Jens Tirsvad Nielsen | S02 | Added phase MIL-004 (proposed dates 2026-11-16 to 2026-11-20) | [2a6bb8e] |
--- ---
## Purpose ## Purpose
Schedule the four phases that deliver RepoFoundry (`create-project.sh` and its documentation) in dependency order. The Business Case sets no deadline, so the dates below are proposals for S01 to confirm. Schedule the three phases that deliver RepoFoundry (`create-project.sh` and its documentation) in dependency order. The Business Case sets no deadline, so the dates below are proposals for S01 to confirm.
## Planning Assumptions ## Planning Assumptions
- Week 1 starts 2026-10-05; the plan ends by 2026-11-20 (the last phase is proposed). - Week 1 starts 2026-10-05; the plan ends by 2026-11-13.
- Phase length: two weeks. - Phase length: two weeks.
- S01 and S02 review each phase through a pull request, as described in [SA-001]. For now one person holds both roles. - S01 and S02 review each phase through a pull request, as described in [SA-001]. For now one person holds both roles.
- The PO language is English, so no translated copies are kept. - The PO language is English, so no translated copies are kept.
@@ -32,7 +32,6 @@ Schedule the four phases that deliver RepoFoundry (`create-project.sh` and its d
| Foundation | [MIL-001] | 2026-10-05 to 2026-10-16 | 2026-10-16 | S01 | US-001.01 | Safe skeleton, config parsing, prompts, tests | [Milestone 43] | | Foundation | [MIL-001] | 2026-10-05 to 2026-10-16 | 2026-10-16 | S01 | US-001.01 | Safe skeleton, config parsing, prompts, tests | [Milestone 43] |
| Repositories and Mirror | [MIL-002] | 2026-10-19 to 2026-10-30 | 2026-10-30 | S02 | US-001.02 | GitHub and Gitea repositories and the push mirror | [Milestone 44] | | Repositories and Mirror | [MIL-002] | 2026-10-19 to 2026-10-30 | 2026-10-30 | S02 | US-001.02 | GitHub and Gitea repositories and the push mirror | [Milestone 44] |
| Scaffold and Release | [MIL-003] | 2026-11-02 to 2026-11-13 | 2026-11-13 | S01 | US-001.03 | Local project, framework, README, final review | [Milestone 45] | | Scaffold and Release | [MIL-003] | 2026-11-02 to 2026-11-13 | 2026-11-13 | S01 | US-001.03 | Local project, framework, README, final review | [Milestone 45] |
| Configurable Details | [MIL-004] | 2026-11-16 to 2026-11-20 | 2026-11-20 | S01 | US-001.04 | Project details preset in config.env | |
```plantuml ```plantuml
@startgantt @startgantt
@@ -43,8 +42,6 @@ Project starts 2026-10-05
[Repositories and Mirror Go/No-Go] happens 2026-10-30 [Repositories and Mirror Go/No-Go] happens 2026-10-30
[Scaffold and Release] starts 2026-11-02 and ends 2026-11-13 [Scaffold and Release] starts 2026-11-02 and ends 2026-11-13
[Scaffold and Release Go/No-Go] happens 2026-11-13 [Scaffold and Release Go/No-Go] happens 2026-11-13
[Configurable Details] starts 2026-11-16 and ends 2026-11-20
[Configurable Details Go/No-Go] happens 2026-11-20
@endgantt @endgantt
``` ```
@@ -58,12 +55,11 @@ Project starts 2026-10-05
| Partial-failure reporting | [MIL-002] | | Partial-failure reporting | [MIL-002] |
| Local directory, remotes, framework submodule, skills, hooks, templates, plan gate | [MIL-003] | | Local directory, remotes, framework submodule, skills, hooks, templates, plan gate | [MIL-003] |
| README and SSH prerequisite documentation | [MIL-003] | | README and SSH prerequisite documentation | [MIL-003] |
| Project details set in `config.env` instead of asked | [MIL-004] |
## Dependencies ## Dependencies
``` ```
MIL-001 → MIL-002 → MIL-003 → MIL-004 MIL-001 → MIL-002 → MIL-003
``` ```
A No-Go moves every later date by the time needed to rework the failed criteria. A No-Go moves every later date by the time needed to rework the failed criteria.
@@ -90,12 +86,11 @@ A No-Go moves every later date by the time needed to rework the failed criteria.
[MIL-001]: ./milestones/mil-001-foundation.md [MIL-001]: ./milestones/mil-001-foundation.md
[MIL-002]: ./milestones/mil-002-repositories-and-mirror.md [MIL-002]: ./milestones/mil-002-repositories-and-mirror.md
[MIL-003]: ./milestones/mil-003-scaffold-and-release.md [MIL-003]: ./milestones/mil-003-scaffold-and-release.md
[MIL-004]: ./milestones/mil-004-configurable-details.md
[US-001]: ./user-stories.md [US-001]: ./user-stories.md
[UC-001]: ./uc-001/uc.md [UC-001]: ./uc-001/uc.md
[SSD-001]: ./uc-001/ssd.md [SSD-001]: ./uc-001/ssd.md
[424f14f]: https://git.tirsystem.com/TirSystem-BashScript/repo_foundry/commit/424f14f4f5577bb47fea41c8f3a655dca953e6d8
[02875ae]: https://git.tirsystem.com/TirSystem-BashScript/repo_foundry/commit/02875aee5f2953473924074eea0056eb31af6b7a [02875ae]: https://git.tirsystem.com/TirSystem-BashScript/repo_foundry/commit/02875aee5f2953473924074eea0056eb31af6b7a
[Milestone 43]: https://git.tirsystem.com/TirSystem-BashScript/RepoFoundry/milestone/43 [Milestone 43]: https://git.tirsystem.com/TirSystem-BashScript/RepoFoundry/milestone/43
[Milestone 44]: https://git.tirsystem.com/TirSystem-BashScript/RepoFoundry/milestone/44 [Milestone 44]: https://git.tirsystem.com/TirSystem-BashScript/RepoFoundry/milestone/44
[Milestone 45]: https://git.tirsystem.com/TirSystem-BashScript/RepoFoundry/milestone/45 [Milestone 45]: https://git.tirsystem.com/TirSystem-BashScript/RepoFoundry/milestone/45
[2a6bb8e]: https://git.tirsystem.com/TirSystem-BashScript/repo_foundry/commit/2a6bb8e8afadfe6ca4a621da30e44a372898ca62
@@ -1,110 +0,0 @@
# SQA Review Record: End-to-end test and final security review (MIL-003)
## Metadata
| Key | Value |
| --- | --- |
| ID | RC-017 |
| CrossReference | [MIL-003], [MIL-002], [RC-016] |
## Version History
| Date | Status | Author | Reviewer | Change | Commit |
| --- | --- | --- | --- | --- | --- |
| 2026-10-05 | Proposed | Jens Tirsvad Nielsen | S02 | Initial version | [613a288] |
| 2026-10-06 | Proposed | Jens Tirsvad Nielsen | S02 | Run A repeated with a `write:user` token: passes; criterion 7 now Pass; only the README review remains | [ef87e73] |
---
## Artifact Under Review
- Instance reviewed: the whole flow of `src/create-project.sh` (branch `mil-003-scaffold-and-release` plus the fixes below), run against real GitHub and Gitea repositories; this is task 6 (issue #20) of [MIL-003] and the live evidence for [MIL-002].
- Checklist used: the Go/No-Go criteria of [MIL-003] and the credential, ownership, mirror, submodule and API items named in its task 6. No QC checklist covers an end-to-end run; the code itself was reviewed in [RC-016].
- Review date: 2026-10-05
- Hosts: Gitea 1.27.3 at `git.tirsystem.com` (SSH on port 10022) and GitHub; real tokens from `.env` (a classic GitHub token with `repo` and `admin:org`; a Gitea token with `write:repository`, `write:organization`, `read:user` and other scopes; it lacked `write:user` until run A2, which used a token that has it).
## End-to-end runs
| Run | Owners | Result |
| --- | --- | --- |
| Dry run | `Tirsvad` on both hosts | All preflight checks passed; nothing created. |
| First `--apply` | `Tirsvad` on both hosts | Stopped before creating anything: **a defect** (see finding F1). |
| A, after the fix | user `Tirsvad` on both hosts | GitHub repository created. Gitea refused: `required=[write:user]`, which the token lacks. The script stopped, reported what existed (GitHub created, Gitea FAILED, the rest not attempted) and how to continue, and deleted nothing. |
| A2 | user `Tirsvad` on both hosts, repeated on 2026-10-06 with a `write:user` token; all eight project details came from `config.env` (MIL-004), so only "Create these now" and the reuse of the empty GitHub repository were asked | Everything created: the Gitea repository under the user account, the mirror, the local project, the framework, skills, hooks and templates; the empty GitHub repository left by run A was reused after confirmation. No warning. |
| B | organization `TirSystem-BashScript` on both hosts, plan gate on | Everything created: both repositories, the mirror, the local project, the framework, skills, hooks, plan gate and templates. No warning. |
After run A2 the following was checked independently of the script's own report: Gitea repository private, owner the user `Tirsvad`, default branch `main`, contents `LICENSE` and `README.md`; push mirror to `https://github.com/Tirsvad/repofoundry-e2e-user.git`, interval `10m0s`, `sync_on_commit` true, `last_error` empty; GitHub repository private with `LICENSE`, `README.md` and the one `Initial commit` that arrived through the mirror; local project on `main` with one commit, `origin` over SSH on port 10022 and `github` over HTTPS, neither with a credential, the framework submodule in place, `core.hooksPath` set and nothing committed by the script; neither token found in the project, its `.git` folder or the run output. The checks below were made after run B and still hold:
- **Gitea:** private, owner the organization, default branch `main`, contents `LICENSE` and `README.md`; push mirror to `https://github.com/TirSystem-BashScript/repofoundry-e2e-org.git`, interval `10m0s`, `sync_on_commit` true, `last_error` empty.
- **GitHub:** private, owner the organization, contents `LICENSE` and `README.md`, one commit `Initial commit` (arrived through the mirror).
- **Local project:** on `main` with that one commit as its whole history, tracking `origin`; `origin` is `ssh://git@git.tirsystem.com:10022/TirSystem-BashScript/repofoundry-e2e-org.git` and `github` is `https://github.com/TirSystem-BashScript/repofoundry-e2e-org.git`; the submodule `framework` comes from `ssh://git@git.tirsystem.com:10022/TirSystem/SQA-QC-Framework.git`; `core.hooksPath` is `framework/githooks` and `planGate.enabled` is true; skills are installed for both harnesses; `AGENTS.md` equals the framework template; no commit was made by the script.
- **Hooks and gate, for real:** a commit on `main` was refused ("refusing to commit directly on 'main'"); a `src/` change without a `Task:` trailer on a branch was refused ("plan-first gate"); a documentation-only commit on a branch was accepted.
- **Mirror direction, for real:** that commit was pushed to Gitea over SSH and the branch `work` appeared on GitHub within seconds, without a manual sync.
## Checklist Results (MIL-003 Go/No-Go)
| # | Criterion | Status | Evidence/Notes |
| --- | --- | --- | --- |
| 1 | `git remote -v` shows `origin` (Gitea) and, when GitHub was chosen, `github`, with no credentials in any URL; with GitHub chosen the local history contains the license commit | Pass | Run B: configured addresses above, credential-free; history is the Gitea license commit. |
| 2 | `framework` is a submodule of `ssh://git@git.tirsystem.com:10022/TirSystem/SQA-QC-Framework.git` and the install scripts have run once, in the documented order | Pass | Run B: `.gitmodules` holds that address; skills, then hooks, then templates; each once. |
| 3 | An existing directory, `AGENTS.md` or `docs/artifact-registry.md` is never overwritten without a yes | Pass | Verified by the automated tests with real git (existing directory, conflicting `LICENSE`, existing templates); not repeated on the real hosts. |
| 4 | With the plan gate enabled, a commit touching `src/` or `tests/` without a `Task: MIL-NNN#N` trailer is refused | Pass | Run B, for real. |
| 5 | An existing `core.hooksPath` is reported and not replaced without consent | Pass | Verified by the automated tests with real git (local and global setting); not repeated on the real hosts. |
| 6 | README covers installation, configuration, usage examples, security decisions, error handling and stakeholders, in clear English | N-A | The sections are written; the review by S02 has not happened yet (action item). |
| 7 | End-to-end run on disposable repositories passes and the final review records no open security finding | Pass | No open security finding. The organization-owner run (B) and the user-owner run (A2, with a `write:user` token) both pass on both hosts. |
| 8 | All acceptance criteria of US-001.03 in [US-001] are met | Pass | Run B: remotes without credentials, framework, skills, hooks, plan gate and templates in place; the "asks first" criterion by the automated tests. |
## Final security review
| Item | Result | Evidence |
| --- | --- | --- |
| Credential handling | No finding | Both tokens were searched for in every file of the new project, including the whole `.git` folder, and in all output of all runs: zero hits. Remote addresses and `.gitmodules` carry no credential. Tokens went to `curl` through a private configuration file and, for an HTTPS fetch, to git through `GIT_ASKPASS` and the environment (covered by tests; the live runs used SSH). |
| Repository ownership | No finding | Created under the owner chosen on both hosts (organization in run B; the user account on both hosts in run A2). `GITHUB_USER` was only a default. |
| Mirror direction | No finding | Gitea is the source: a branch pushed to Gitea reached GitHub on its own. Nothing was pushed from GitHub; that direction was not tested. |
| Submodule setup | No finding | Added over SSH on port 10022 from the configured framework repository; the SSH test and the host key check passed. |
| API limitations | Findings F2 to F4 | `sync_on_commit` was applied on Gitea 1.27.3 (the upstream bug did not occur). Token scopes and the README Gitea adds are covered below. |
| Residual risks | Accepted, documented | The mirror password (the GitHub token) is stored by the Gitea server. The tokens used here are broad (for example `admin:org` on GitHub); tokens limited to what the script needs would reduce the damage of a leak. |
## Findings
| # | Finding | Severity | Status |
| --- | --- | --- | --- |
| F1 | The real `ssh` used for the SSH test reads standard input and swallowed the answers meant for later prompts, so a run that was piped or pasted stopped before creating anything. The test stub did not read stdin, so no test could see it. | Defect (no data lost) | Fixed: stdin is closed for `ssh`, `git`, `curl` and the framework scripts; the test stub now reads stdin like the real tool; a regression test fails without the fix. |
| F2 | Gitea adds a generated `README.md` next to the `LICENSE`. The script, the README and MIL-002 criterion 2 assumed only the license. A repository this script created was therefore counted as "has content" and could not be reused after a partial failure. | Defect | Fixed: `LICENSE` and `LICENSE` + `README.md` count as content created by the script; any other file still counts as content; tests added; README corrected. MIL-002 criterion 2 corrected (new `Proposed` version row, to be accepted). |
| F3 | Creating a repository under one's own Gitea account needs the `write:user` scope, not `write:repository`. | Documentation | Fixed in the README, marked as confirmed by the server. |
| F4 | Documentation had marked two scopes "not confirmed". Result: `write:user` is needed for user-owned Gitea repositories (F3); organization-owned repositories worked with `write:organization`, `write:repository` and `read:user`, and the minimum was not narrowed down; the GitHub membership check worked with `repo` and `admin:org`, `read:org` alone was not tested. | Documentation | README updated with what was observed. |
## Files created and external prerequisites
The script creates, in the new project: `.git`, `.gitmodules`, `framework/` (submodule), `.agents/skills/` and `.claude/skills/`, `AGENTS.md`, `docs/artifact-registry.md`, and (through the Gitea history) `LICENSE` and `README.md`. It never deletes anything.
External prerequisites: bash 4.4 or later, `git`, `curl`, `mktemp`; optional `jq` and `ssh`. An SSH key in the Gitea account and a known host key for `git.tirsystem.com` port 10022 (the script refuses unknown host keys). A GitHub token that can create repositories and push (classic `repo`), only when GitHub is chosen. A Gitea token with `write:repository`, `write:organization` and `read:user`, plus `write:user` for a repository under one's own account. Push mirrors must be enabled on the Gitea server.
## Disposable resources left in place (nothing was deleted)
- Gitea: `TirSystem-BashScript/repofoundry-e2e-org` (private; branches `main` and `work`).
- GitHub: `TirSystem-BashScript/repofoundry-e2e-org` (private; branches `main` and `work`).
- Gitea: `Tirsvad/repofoundry-e2e-user` (private; branch `main`; created by run A2).
- GitHub: `Tirsvad/repofoundry-e2e-user` (private; branch `main`; created by run A, reused by run A2).
- Local temporary directories with the run output and the new projects.
## Overall Verdict
Go-with-conditions — No open security finding, both the organization-owner flow (run B) and the user-owner flow (run A2) work end to end on both hosts, and the two defects the live run found are fixed with regression tests. The one condition left is criterion 6: the README review by S02. Author and reviewer are the same person for now (S01 and S02 are both held by the Maintainer), so the framework independence rule is not met; re-review when a second person takes S02.
## Action Items
| Action | Owner | Due |
| --- | --- | --- |
| Review the README against criterion 6 | S02 | 2026-10-12 |
| Accept the corrected criterion 2 of [MIL-002] (version row `Proposed`) | S02 | 2026-10-12 |
| Delete the disposable repositories listed above in the web interfaces | S01 | 2026-10-12 |
| Run `tests/run-tests.sh` on Linux and macOS (carried over from [RC-016]) | S02 | 2026-10-30 |
| Consider tokens limited to what the script needs, for the Gitea and GitHub accounts used with it | S02 | 2026-10-30 |
---
[MIL-003]: ../../milestones/mil-003-scaffold-and-release.md
[MIL-002]: ../../milestones/mil-002-repositories-and-mirror.md
[RC-016]: ./rc-016-create-project-sh.md
[US-001]: ../../user-stories.md
[613a288]: https://git.tirsystem.com/TirSystem-BashScript/repo_foundry/commit/613a288dead4c19c00dee6fbb60d46bc3edf8889
[ef87e73]: https://git.tirsystem.com/TirSystem-BashScript/repo_foundry/commit/ef87e7395482da9fad854cd5db7f16200bb8c8af
-69
View File
@@ -1,69 +0,0 @@
# SQA Review Record: MIL-004 and the planning change it causes
## Metadata
| Key | Value |
| --- | --- |
| ID | RC-018 |
| CrossReference | [MIL-004], [QC-MIL-001], [US-001], [UC-001] |
## Version History
| Date | Status | Author | Reviewer | Change | Commit |
| --- | --- | --- | --- | --- | --- |
| 2026-10-05 | Proposed | Jens Tirsvad Nielsen | S02 | Initial version | [2a6bb8e] |
---
## Artifact Under Review
- Instance reviewed: [MIL-004], and the changes it causes in [BC-001], [US-001], [UC-001], [SSD-001], [OC-001], [SD-001], [DM-001], [DM-002] and [PP-001].
- Checklist used: [QC-MIL-001] for [MIL-004]. The other artifacts were changed, not created; their change is checked below for consistency with the checklists of their types (user story, use case, SSD, operation contract, sequence diagram, domain model) and with the PP reference.
- Review date: 2026-10-05
## Checklist Results ([MIL-004], QC-MIL-001)
| # | Criterion | Status | Evidence/Notes |
| --- | --- | --- | --- |
| 1 | A concrete deliverable is defined for every gate | Pass | The script reads eight optional keys, skips their prompts and marks the source; the example config and the README document the keys; tests cover each key. |
| 2 | Explicit Go/No-Go criteria are stated for each gate | Pass | Eight criteria, each with an objective Go and No-Go, including all acceptance criteria of US-001.04. |
| 3 | Dependencies on other milestones are explicitly mapped | Pass | Depends on [MIL-003], with the reason. |
| 4 | Each milestone is traceable to a Business Case objective or KPI | Pass | Maps to objective 8 and success criterion 8 of [BC-001], and to US-001.04. |
| 5 | Milestone owner and approving reviewer are identified | Pass | Owner S01, approving reviewer S02. |
| 6 | Milestone has a defined target date consistent with project constraints | Pass | 2026-11-20 matches [PP-001]; the Business Case sets no duration, so nothing conflicts. The date is a proposal and is accepted here. |
## Change checks on the other artifacts
| Artifact | Change | Status | Evidence/Notes |
| --- | --- | --- | --- |
| [BC-001] | Objective 8, scope item, success criterion 8 | Pass | The criterion is measurable (tests with each key set, absent, empty and invalid). |
| [US-001] | US-001.04 with four acceptance criteria | Pass | Given/when/then; traces to [UC-001] step 3 and [MIL-004]; size and INVEST exception recorded. |
| [UC-001] | Precondition, step 3 note, extensions 3a and 3b, business rule | Pass | Extensions name the failure (invalid key) and the outcome (stop before any request, no fallback to asking). |
| [SSD-001] | Parameters of `provideProjectDetails` may come from `config.env` | Pass | The message itself is unchanged, so the diagram is unchanged. |
| [OC-001] | Preset details are part of the Configuration | Pass | Postcondition and rule added; no new operation. |
| [SD-001] | Note that `ConfigLoader` reads and validates the preset details | Pass | The second sequence is unchanged because the arguments are the same whether asked or preset. |
| [DM-001], [DM-002] | `Configuration` may hold preset project details | Pass | Both models changed in the same way and the project model stays consistent with the use-case model, as the project rule requires. Dictionary unchanged: no new term. |
| [PP-001] | Phase [MIL-004], dependency chain and timeline | Pass | Dates agree with [MIL-004]; scope table and Gantt updated. |
## Overall Verdict
Go — [MIL-004] passes every mandatory criterion and the changes to the other artifacts are consistent with each other and with the Business Case. Author and reviewer are the same person for now (S01 and S02 are both held by the Maintainer), so the framework independence rule is not met; re-review when a second person takes S02.
## Action Items
| Action | Owner | Due |
| --- | --- | --- |
| None | - | - |
---
[MIL-004]: ../../milestones/mil-004-configurable-details.md
[BC-001]: ../../business-case.md
[US-001]: ../../user-stories.md
[UC-001]: ../../uc-001/uc.md
[SSD-001]: ../../uc-001/ssd.md
[OC-001]: ../../uc-001/oc.md
[SD-001]: ../../uc-001/sd.md
[DM-001]: ../../uc-001/dm.md
[DM-002]: ../../domain-model.md
[PP-001]: ../../project-plan.md
[QC-MIL-001]: ../../../framework/qc/qc-milestones-gateways.md
[2a6bb8e]: https://git.tirsystem.com/TirSystem-BashScript/repo_foundry/commit/2a6bb8e8afadfe6ca4a621da30e44a372898ca62
-70
View File
@@ -1,70 +0,0 @@
# SQA Review Record: Shell code review of the MIL-004 change
## Metadata
| Key | Value |
| --- | --- |
| ID | RC-019 |
| CrossReference | [MIL-004], [QC-SH-001], [RC-016] |
## Version History
| Date | Status | Author | Reviewer | Change | Commit |
| --- | --- | --- | --- | --- | --- |
| 2026-10-05 | Proposed | Jens Tirsvad Nielsen | S02 | Initial version | [ceaa7d1] |
---
## Artifact Under Review
- Instance reviewed: the MIL-004 change to `src/create-project.sh` and `src/lib/` (`config.sh`, `constants.sh`, `project.sh`), `tests/test-presets.sh`, the README and `config.env.example`, on branch `mil-004-configurable-details` (commit `75e8e91` plus the fixes listed below), tasks 1 to 5 (issues #27 to #31) of [MIL-004].
- Checklist used: [QC-SH-001]. The rest of the code was reviewed in [RC-016].
- Review date: 2026-10-05
- Tool versions: bash 5.2.37, shellcheck 0.11.0, shfmt 3.14.1 (Windows, Git Bash)
## Checklist Results
| # | Criterion | Status | Evidence/Notes |
| --- | --- | --- | --- |
| 1 | Starts with `#!/usr/bin/env bash` and `set -euo pipefail` | Pass | Unchanged. |
| 2 | Every expansion is quoted; lists are arrays; tests use `[[ ]]` and `$(...)` | Pass | `shellcheck` is clean. Values from `config.env` are only ever compared, matched against validators or printed; none reaches `eval`, a command line or a file name before it passed a validator. |
| 3 | Names follow the conventions | Pass | `check_preset`, `preset_detail`, `source_note` and the `HINT_*` constants follow the rules. See finding F4 on the name `PROJECT_NAME`. |
| 4 | Passes `shellcheck` and `bash -n` with no unexplained `disable` comments | Pass | No new `disable`. |
| 5 | Errors go to standard error with an `error:` message and a non-zero exit code | Pass | Every refusal goes through `die`, names the key and the file, never the value. |
| 6 | Temporary files use `mktemp` with a `trap` cleanup | Pass | Not touched. |
| 7 | No secret is written in the script, echoed, or put on a command line | Pass | The new keys carry no credential; they are rejected in `.env`, and credential keys stay rejected in `config.env` (tests). The description is printed in the summary, as it was when asked. |
| 8 | A script that changes state defaults to a dry run | Pass | Unchanged: a preset never skips the dry run or "Create these now". Tests prove that with all eight keys set, an empty or missing answer creates nothing. |
| 9 | A header comment states purpose, usage, options, environment variables and exit codes | Pass | Fixed during this review: the header said only "asks for the project details"; it now says that details set in `config.env` are not asked. |
| 10 | The script implements a task or design it cites; deviations are recorded | Pass | Tasks 1 to 5 of [MIL-004] and extensions 3a and 3b of [UC-001]. Deviations: values are accepted in any case, and `USE_GITHUB`/`ENABLE_PLAN_GATE` take `yes` or `no` only; both are in the README. |
| 11 | Behaviour is tested for success, failure and any disabled or bypass path | Pass | 919 checks in the full suite before the review, 0 failed. New: each key set, absent, empty and invalid; mixed asked and preset; `USE_GITHUB` interplay; the summary marker; no prompt text for a preset; the confirmations. Mutation check: making the preset lookup always fail made the tests fail. |
| 12 | Formatted with `shfmt` | Pass | No difference. |
| 13 | Safe to re-run | Pass | No state is kept. |
| 14 | Bash version and external tools stated | Pass | Unchanged. |
## Findings
| # | Finding | Severity | Status |
| --- | --- | --- | --- |
| F1 | An unquoted `PROJECT_DESCRIPTION` containing ` #` is silently cut at the comment mark (`Tool # for mirrors` becomes `Tool`), with no message. This is how the parser reads every value, but a description is the one free-text key, so it is where it bites. A value with both kinds of quote cannot be set at all (it can still be typed at the prompt). | Low (surprise, no data loss or security effect) | Fixed: the README and `config.env.example` say to put such a value in double quotes; a test pins both behaviours. The both-quotes case is documented as a limit of the parser. |
| F2 | The header of `create-project.sh` and the README sentence "The script asks for, in this order" did not mention that preset details are not asked. | Low (documentation) | Fixed. |
| F3 | The summary marks the source after the value, so a fully preset run reads `my-app (from config.env) (private (from config.env))`. Correct but noisy, and `USE_GITHUB=yes` is not marked on the GitHub line (only the owner is). | Low (readability) | Accepted: the marker is asserted by the tests and the wording is not a requirement; revisit if the Maintainer wants a table layout. |
| F4 | The constant `PROJECT_NAME` (the name of this tool, `RepoFoundry`) and the config key `PROJECT_NAME` (the name of the new project) share a spelling. They never meet in code (the key lives in `CONFIG`), but a reader can confuse them. | Low (maintainability) | Open: renaming the constant is out of scope for this change; a candidate for a later clean-up. |
| F5 | A `config.env` that sets `PROJECT_NAME` and `GITEA_OWNER` makes every run use them. Existing repositories are still detected and need the reuse confirmation, so nothing is overwritten. | Info | Documented in the README (per-project configuration). |
No finding affects credentials, ownership, the mirror direction or the confirmations.
## Overall Verdict
Go — all mandatory criteria pass after the fixes for F1 and F2 (found and fixed during this review; the test for F1 was added; the full suite was rerun afterwards: 923 checks, 0 failed). F3 and F4 are recorded and not blocking. Author and reviewer are the same person for now (S01 and S02 are both held by the Maintainer), so the framework independence rule is not met; re-review when a second person takes S02.
## Action Items
| Action | Owner | Due |
| --- | --- | --- |
| Decide whether to rename the constant `PROJECT_NAME` (F4) and whether to restyle the summary markers (F3) | S02 | 2026-10-30 |
---
[MIL-004]: ../../milestones/mil-004-configurable-details.md
[UC-001]: ../../uc-001/uc.md
[RC-016]: ./rc-016-create-project-sh.md
[QC-SH-001]: ../../../framework/qc/qc-programming-shell.md
[ceaa7d1]: https://git.tirsystem.com/TirSystem-BashScript/repo_foundry/commit/ceaa7d18d8908b4d1e3fb089f238c99b883d71e0
+5 -12
View File
@@ -10,7 +10,6 @@
| Date | Status | Author | Reviewer | Change | Commit | | Date | Status | Author | Reviewer | Change | Commit |
| --- | --- | --- | --- | --- | --- | | --- | --- | --- | --- | --- | --- |
| 2026-10-05 | Proposed | Jens Tirsvad Nielsen | S02 | Initial version, UC-001 artifacts and baseline | [02875ae] | | 2026-10-05 | Proposed | Jens Tirsvad Nielsen | S02 | Initial version, UC-001 artifacts and baseline | [02875ae] |
| 2026-10-05 | Proposed | Jens Tirsvad Nielsen | S02 | Added MIL-004 and RC-018 | [2a6bb8e] |
--- ---
@@ -24,15 +23,14 @@ updated whenever an artifact instance is created or reviewed.
| Artifact Instance | Type | Upstream (Backward Link) | Downstream (Forward Link) | Last Reviewed (RC-ID) | | Artifact Instance | Type | Upstream (Backward Link) | Downstream (Forward Link) | Last Reviewed (RC-ID) |
| --- | --- | --- | --- | --- | | --- | --- | --- | --- | --- |
| [BC-001] | BC | - | [SA-001], [PP-001], [MIL-001], [MIL-002], [MIL-003], [MIL-004], [US-001], [UCD-001] | [RC-010], [RC-018] | | [BC-001] | BC | - | [SA-001], [PP-001], [MIL-001], [MIL-002], [MIL-003], [US-001], [UCD-001] | [RC-010] |
| [SA-001] | SA | [BC-001] | [UCD-001], [UC-001], [DICT-001] | [RC-013] | | [SA-001] | SA | [BC-001] | [UCD-001], [UC-001], [DICT-001] | [RC-013] |
| [PP-001] | PP | [BC-001], [SA-001] | [MIL-001], [MIL-002], [MIL-003], [MIL-004] | [RC-012], [RC-018] | | [PP-001] | PP | [BC-001], [SA-001] | [MIL-001], [MIL-002], [MIL-003] | [RC-012] |
| [MIL-001] | MIL | [BC-001], [PP-001] | [US-001] | [RC-011], [RC-016] | | [MIL-001] | MIL | [BC-001], [PP-001] | [US-001] | [RC-011], [RC-016] |
| [MIL-002] | MIL | [BC-001], [PP-001] | [US-001] | [RC-014], [RC-017] | | [MIL-002] | MIL | [BC-001], [PP-001] | [US-001] | [RC-014] |
| [MIL-003] | MIL | [BC-001], [PP-001] | [US-001] | [RC-015], [RC-017] | | [MIL-003] | MIL | [BC-001], [PP-001] | [US-001] | [RC-015] |
| [MIL-004] | MIL | [BC-001], [PP-001] | [US-001] | [RC-018], [RC-019] |
| [UCD-001] | UCD | [BC-001], [SA-001] | [US-001], [UC-001] | [RC-009] | | [UCD-001] | UCD | [BC-001], [SA-001] | [US-001], [UC-001] | [RC-009] |
| [US-001] | US | [BC-001], [UCD-001], [MIL-001], [MIL-002], [MIL-003], [MIL-004] | [UC-001] | [RC-001] | | [US-001] | US | [BC-001], [UCD-001], [MIL-001], [MIL-002], [MIL-003] | [UC-001] | [RC-001] |
| [UC-001] | UC | [UCD-001], [US-001], [SA-001] | [SSD-001], [DM-001] | [RC-002] | | [UC-001] | UC | [UCD-001], [US-001], [SA-001] | [SSD-001], [DM-001] | [RC-002] |
| [SSD-001] | SSD | [UC-001] | [OC-001] | [RC-003] | | [SSD-001] | SSD | [UC-001] | [OC-001] | [RC-003] |
| [DM-001] | DM | [UC-001], [SSD-001] | [DM-002], [DICT-001], [OC-001] | [RC-004] | | [DM-001] | DM | [UC-001], [SSD-001] | [DM-002], [DICT-001], [OC-001] | [RC-004] |
@@ -54,9 +52,6 @@ updated whenever an artifact instance is created or reviewed.
[MIL-001]: ../milestones/mil-001-foundation.md [MIL-001]: ../milestones/mil-001-foundation.md
[MIL-002]: ../milestones/mil-002-repositories-and-mirror.md [MIL-002]: ../milestones/mil-002-repositories-and-mirror.md
[MIL-003]: ../milestones/mil-003-scaffold-and-release.md [MIL-003]: ../milestones/mil-003-scaffold-and-release.md
[MIL-004]: ../milestones/mil-004-configurable-details.md
[RC-018]: ./reviews/rc-018-mil-004.md
[RC-019]: ./reviews/rc-019-mil-004-code.md
[UCD-001]: ../use-case-diagram.md [UCD-001]: ../use-case-diagram.md
[US-001]: ../user-stories.md [US-001]: ../user-stories.md
[UC-001]: ../uc-001/uc.md [UC-001]: ../uc-001/uc.md
@@ -82,6 +77,4 @@ updated whenever an artifact instance is created or reviewed.
[RC-014]: ./reviews/rc-014-mil-002.md [RC-014]: ./reviews/rc-014-mil-002.md
[RC-015]: ./reviews/rc-015-mil-003.md [RC-015]: ./reviews/rc-015-mil-003.md
[RC-016]: ./reviews/rc-016-create-project-sh.md [RC-016]: ./reviews/rc-016-create-project-sh.md
[RC-017]: ./reviews/rc-017-e2e-security-review.md
[02875ae]: https://git.tirsystem.com/TirSystem-BashScript/repo_foundry/commit/02875aee5f2953473924074eea0056eb31af6b7a [02875ae]: https://git.tirsystem.com/TirSystem-BashScript/repo_foundry/commit/02875aee5f2953473924074eea0056eb31af6b7a
[2a6bb8e]: https://git.tirsystem.com/TirSystem-BashScript/repo_foundry/commit/2a6bb8e8afadfe6ca4a621da30e44a372898ca62
+2 -6
View File
@@ -10,7 +10,6 @@
| Date | Status | Author | Reviewer | Change | Commit | | Date | Status | Author | Reviewer | Change | Commit |
| --- | --- | --- | --- | --- | --- | | --- | --- | --- | --- | --- | --- |
| 2026-10-05 | Accepted | Jens Tirsvad Nielsen | S02 | Initial version | [02875ae] | | 2026-10-05 | Accepted | Jens Tirsvad Nielsen | S02 | Initial version | [02875ae] |
| 2026-10-05 | Accepted | Jens Tirsvad Nielsen | S02 | Configuration may hold preset project details | [2a6bb8e] |
--- ---
@@ -32,9 +31,7 @@ class Project {
description description
visibility visibility
} }
class Configuration { class Configuration
preset project details
}
class "Git Host" as GitHost { class "Git Host" as GitHost {
name name
web address web address
@@ -118,7 +115,7 @@ Summary "1" --> "1" Project : reports on
| --- | --- | --- | --- | | --- | --- | --- | --- |
| Maintainer | The person who creates a new project (S01 or S02) | name | [UC-001] primary actor | | Maintainer | The person who creates a new project (S01 or S02) | name | [UC-001] primary actor |
| Project | The new software project being set up | name, description, visibility | [UC-001] "new project", step 3 | | Project | The new software project being set up | name, description, visibility | [UC-001] "new project", step 3 |
| Configuration | The service addresses and access tokens the Maintainer has set up before starting, and any project details preset in it | preset project details (optional) | [UC-001] precondition, steps 2 and 3 | | Configuration | The service addresses and access tokens the Maintainer has set up before starting | none | [UC-001] precondition, step 2 "configuration and credentials" |
| Git Host | A service that holds repositories: Gitea or GitHub | name, web address, API address | [UC-001] steps 5 to 7 "GitHub", "Gitea" | | Git Host | A service that holds repositories: Gitea or GitHub | name, web address, API address | [UC-001] steps 5 to 7 "GitHub", "Gitea" |
| Access Token | A secret that lets the Maintainer act on a Git Host; it is never part of an address | kind | [UC-001] precondition "Gitea token", "GitHub PAT" | | Access Token | A secret that lets the Maintainer act on a Git Host; it is never part of an address | kind | [UC-001] precondition "Gitea token", "GitHub PAT" |
| Owner | The user or organization on a Git Host that owns repositories | name, kind (user or organization) | [UC-001] step 3 "owner" | | Owner | The user or organization on a Git Host that owns repositories | name, kind (user or organization) | [UC-001] step 3 "owner" |
@@ -173,4 +170,3 @@ Summary "1" --> "1" Project : reports on
[DICT-001]: ../dictionary.md [DICT-001]: ../dictionary.md
[DM-002]: ../domain-model.md [DM-002]: ../domain-model.md
[02875ae]: https://git.tirsystem.com/TirSystem-BashScript/repo_foundry/commit/02875aee5f2953473924074eea0056eb31af6b7a [02875ae]: https://git.tirsystem.com/TirSystem-BashScript/repo_foundry/commit/02875aee5f2953473924074eea0056eb31af6b7a
[2a6bb8e]: https://git.tirsystem.com/TirSystem-BashScript/repo_foundry/commit/2a6bb8e8afadfe6ca4a621da30e44a372898ca62
+3 -6
View File
@@ -10,7 +10,6 @@
| Date | Status | Author | Reviewer | Change | Commit | | Date | Status | Author | Reviewer | Change | Commit |
| --- | --- | --- | --- | --- | --- | | --- | --- | --- | --- | --- | --- |
| 2026-10-05 | Accepted | Jens Tirsvad Nielsen | S02 | Initial version | [02875ae] | | 2026-10-05 | Accepted | Jens Tirsvad Nielsen | S02 | Initial version | [02875ae] |
| 2026-10-05 | Accepted | Jens Tirsvad Nielsen | S02 | Project details may be defined by the Configuration | [2a6bb8e] |
--- ---
@@ -31,7 +30,7 @@ Concepts below use the IT terms of [DICT-001] for the PO concepts of [DM-001]. `
**Postconditions** **Postconditions**
- P1. A `Run` instance was created. - P1. A `Run` instance was created.
- P2. A `Configuration` instance was created from `config.env` and `.env`, with every value validated (including the project details preset in `config.env`) and the credentials held only in memory. - P2. A `Configuration` instance was created from `config.env` and `.env`, with every value validated and the credentials held only in memory.
- P3. A `ToolCheck` instance was created and associated with the `Run`, recording that `git` and `curl` are present and whether `jq` is present. - P3. A `ToolCheck` instance was created and associated with the `Run`, recording that `git` and `curl` are present and whether `jq` is present.
- P4. The `Run` was associated with a `PromptSet` that is returned. - P4. The `Run` was associated with a `PromptSet` that is returned.
@@ -39,7 +38,7 @@ Concepts below use the IT terms of [DICT-001] for the PO concepts of [DM-001]. `
| Condition (failing precondition) | Outcome | | Condition (failing precondition) | Outcome |
| --- | --- | | --- | --- |
| `config.env` or `.env` is missing, or a value is missing or malformed (a preset project detail included) | The `Run` ends with an error naming the key, never its value; nothing was changed | | `config.env` or `.env` is missing, or a value is missing or malformed | The `Run` ends with an error naming the key, never its value; nothing was changed |
| `git` or `curl` is missing | The `Run` ends with an error naming the tool; nothing was changed | | `git` or `curl` is missing | The `Run` ends with an error naming the tool; nothing was changed |
## Contract: provideProjectDetails ## Contract: provideProjectDetails
@@ -54,11 +53,10 @@ Concepts below use the IT terms of [DICT-001] for the PO concepts of [DM-001]. `
- A `Run` exists and its `Configuration` is valid (from `startProjectCreation`). - A `Run` exists and its `Configuration` is valid (from `startProjectCreation`).
- `githubOwner` is present exactly when the Maintainer chose GitHub. - `githubOwner` is present exactly when the Maintainer chose GitHub.
- A detail that the `Configuration` defines is not asked: it is taken from the `Configuration`.
**Postconditions** **Postconditions**
- P1. A `ProjectRequest` instance was created with the attributes given by the Maintainer or defined by the `Configuration`, and associated with the `Run`. - P1. A `ProjectRequest` instance was created with the given attributes and associated with the `Run`.
- P2. A `PreflightResult` instance was created and associated with the `ProjectRequest`, recording that each token needed for the chosen hosts works, that each owner accepts new repositories, that the name is free on the chosen hosts, that `AGPL-3.0` is offered by Gitea when GitHub was chosen, and the outcome of the SSH test to Gitea on port 10022. - P2. A `PreflightResult` instance was created and associated with the `ProjectRequest`, recording that each token needed for the chosen hosts works, that each owner accepts new repositories, that the name is free on the chosen hosts, that `AGPL-3.0` is offered by Gitea when GitHub was chosen, and the outcome of the SSH test to Gitea on port 10022.
- P3. A `GiteaRepository` instance was created under `giteaOwner` with the given name, description and visibility, and associated with the `ProjectRequest`. - P3. A `GiteaRepository` instance was created under `giteaOwner` with the given name, description and visibility, and associated with the `ProjectRequest`.
- P4. If `githubOwner` is present, a `LicenseFile` instance for `AGPL-3.0` was created and associated with the `GiteaRepository`, so that repository is not empty. Otherwise the `GiteaRepository` has no `LicenseFile` and is empty. - P4. If `githubOwner` is present, a `LicenseFile` instance for `AGPL-3.0` was created and associated with the `GiteaRepository`, so that repository is not empty. Otherwise the `GiteaRepository` has no `LicenseFile` and is empty.
@@ -91,4 +89,3 @@ Concepts below use the IT terms of [DICT-001] for the PO concepts of [DM-001]. `
[DICT-001]: ../dictionary.md [DICT-001]: ../dictionary.md
[SD-001]: ./sd.md [SD-001]: ./sd.md
[02875ae]: https://git.tirsystem.com/TirSystem-BashScript/repo_foundry/commit/02875aee5f2953473924074eea0056eb31af6b7a [02875ae]: https://git.tirsystem.com/TirSystem-BashScript/repo_foundry/commit/02875aee5f2953473924074eea0056eb31af6b7a
[2a6bb8e]: https://git.tirsystem.com/TirSystem-BashScript/repo_foundry/commit/2a6bb8e8afadfe6ca4a621da30e44a372898ca62
+1 -3
View File
@@ -10,7 +10,6 @@
| Date | Status | Author | Reviewer | Change | Commit | | Date | Status | Author | Reviewer | Change | Commit |
| --- | --- | --- | --- | --- | --- | | --- | --- | --- | --- | --- | --- |
| 2026-10-05 | Accepted | Jens Tirsvad Nielsen | S02 | Initial version | [02875ae] | | 2026-10-05 | Accepted | Jens Tirsvad Nielsen | S02 | Initial version | [02875ae] |
| 2026-10-05 | Accepted | Jens Tirsvad Nielsen | S02 | Note: preset project details are read by ConfigLoader | [2a6bb8e] |
--- ---
@@ -67,7 +66,7 @@ destroy TC
### Responsibility Check ### Responsibility Check
`ProjectCreator` only sequences two calls; parsing and validation sit in `ConfigLoader`, tool detection in `ToolChecker`. No object receives every message. Project details preset in `config.env` are read and validated by `ConfigLoader` as part of `configuration`; the second sequence is unchanged, because `provideProjectDetails` receives the same arguments whether they were asked or preset. `ProjectCreator` only sequences two calls; parsing and validation sit in `ConfigLoader`, tool detection in `ToolChecker`. No object receives every message.
## Sequence: provideProjectDetails ## Sequence: provideProjectDetails
@@ -189,4 +188,3 @@ destroy SR
[OC-001]: ./oc.md [OC-001]: ./oc.md
[02875ae]: https://git.tirsystem.com/TirSystem-BashScript/repo_foundry/commit/02875aee5f2953473924074eea0056eb31af6b7a [02875ae]: https://git.tirsystem.com/TirSystem-BashScript/repo_foundry/commit/02875aee5f2953473924074eea0056eb31af6b7a
[2a6bb8e]: https://git.tirsystem.com/TirSystem-BashScript/repo_foundry/commit/2a6bb8e8afadfe6ca4a621da30e44a372898ca62
+3 -3
View File
@@ -9,8 +9,8 @@
## Version History ## Version History
| Date | Status | Author | Reviewer | Change | Commit | | Date | Status | Author | Reviewer | Change | Commit |
| --- | --- | --- | --- | --- | --- | | --- | --- | --- | --- | --- | --- |
| 2026-10-05 | Rejected | Jens Tirsvad Nielsen | S02 | Initial version | [424f14f] |
| 2026-10-05 | Accepted | Jens Tirsvad Nielsen | S02 | Optional GitHub; choosing GitHub applies the AGPL license to the Gitea repository<br>Cited OC-001 and DM-001 | [02875ae] | | 2026-10-05 | Accepted | Jens Tirsvad Nielsen | S02 | Optional GitHub; choosing GitHub applies the AGPL license to the Gitea repository<br>Cited OC-001 and DM-001 | [02875ae] |
| 2026-10-05 | Accepted | Jens Tirsvad Nielsen | S02 | Parameters may come from config.env; the message is unchanged | [2a6bb8e] |
--- ---
@@ -37,7 +37,7 @@ S --> A : creation summary
| Step | Message | Parameters | Return | Use case step | | Step | Message | Parameters | Return | Use case step |
| --- | --- | --- | --- | --- | | --- | --- | --- | --- | --- |
| 1 | startProjectCreation | none | prompts for project details (after configuration and tool checks) | 1, 2 | | 1 | startProjectCreation | none | prompts for project details (after configuration and tool checks) | 1, 2 |
| 2 | provideProjectDetails | name, description, visibility, giteaOwner, githubOwner (optional; given means GitHub is chosen and the Gitea repository gets the AGPL license; omitted means no GitHub and no license), directory, enablePlanGate (each of these may come from `config.env` instead of the Maintainer; the message is unchanged) | checks passed, then a creation summary | 3 to 10 | | 2 | provideProjectDetails | name, description, visibility, giteaOwner, githubOwner (optional; given means GitHub is chosen and the Gitea repository gets the AGPL license; omitted means no GitHub and no license), directory, enablePlanGate | checks passed, then a creation summary | 3 to 10 |
Steps 4 to 9 are internal to the system, so one operation covers them. A consent question (step 8a, 9a, 9b) is a prompt from the system and is out of scope for this diagram; failure flows are out of scope here. Steps 4 to 9 are internal to the system, so one operation covers them. A consent question (step 8a, 9a, 9b) is a prompt from the system and is out of scope for this diagram; failure flows are out of scope here.
@@ -50,5 +50,5 @@ The system is one script run. It starts with the first operation and ends after
[UC-001]: ./uc.md [UC-001]: ./uc.md
[DM-001]: ./dm.md [DM-001]: ./dm.md
[OC-001]: ./oc.md [OC-001]: ./oc.md
[424f14f]: https://git.tirsystem.com/TirSystem-BashScript/repo_foundry/commit/424f14f4f5577bb47fea41c8f3a655dca953e6d8
[02875ae]: https://git.tirsystem.com/TirSystem-BashScript/repo_foundry/commit/02875aee5f2953473924074eea0056eb31af6b7a [02875ae]: https://git.tirsystem.com/TirSystem-BashScript/repo_foundry/commit/02875aee5f2953473924074eea0056eb31af6b7a
[2a6bb8e]: https://git.tirsystem.com/TirSystem-BashScript/repo_foundry/commit/2a6bb8e8afadfe6ca4a621da30e44a372898ca62
+3 -9
View File
@@ -9,8 +9,8 @@
## Version History ## Version History
| Date | Status | Author | Reviewer | Change | Commit | | Date | Status | Author | Reviewer | Change | Commit |
| --- | --- | --- | --- | --- | --- | | --- | --- | --- | --- | --- | --- |
| 2026-10-05 | Deprecated | Jens Tirsvad Nielsen | S02 | Initial version | [424f14f] |
| 2026-10-05 | Accepted | Jens Tirsvad Nielsen | S02 | Optional GitHub; choosing GitHub applies the AGPL license to the Gitea repository<br>Cited DM-001 and UCD-001 | [02875ae] | | 2026-10-05 | Accepted | Jens Tirsvad Nielsen | S02 | Optional GitHub; choosing GitHub applies the AGPL license to the Gitea repository<br>Cited DM-001 and UCD-001 | [02875ae] |
| 2026-10-05 | Accepted | Jens Tirsvad Nielsen | S02 | Step 3: details set in config.env are not asked (extensions 3a, 3b) | [2a6bb8e] |
--- ---
@@ -27,7 +27,6 @@
- S03 — the published procedure is documented and reusable - S03 — the published procedure is documented and reusable
- **Preconditions:** - **Preconditions:**
- `config.env` and `.env` exist and are valid. - `config.env` and `.env` exist and are valid.
- `config.env` may preset any of the project details of step 3.
- `git` and `curl` are installed. - `git` and `curl` are installed.
- The Maintainer has a Gitea token, a GitHub PAT (only when GitHub is chosen) and SSH access to Gitea on port 10022. - The Maintainer has a Gitea token, a GitHub PAT (only when GitHub is chosen) and SSH access to Gitea on port 10022.
- **Postconditions (success guarantee):** - **Postconditions (success guarantee):**
@@ -40,7 +39,7 @@
1. The Maintainer starts the project creation. 1. The Maintainer starts the project creation.
2. The system loads and validates the configuration and credentials and checks that the required tools exist. 2. The system loads and validates the configuration and credentials and checks that the required tools exist.
3. The Maintainer provides the repository name, description, visibility, the Gitea owner, whether to also create a GitHub repository (and if so its owner), the local directory, and whether to enable the plan gate. A detail that is set in `config.env` is not asked. 3. The Maintainer provides the repository name, description, visibility, the Gitea owner, whether to also create a GitHub repository (and if so its owner), the local directory, and whether to enable the plan gate.
4. The system checks that the tokens needed for the chosen hosts work, that the owners accept new repositories, that the name is free on those hosts, and whether SSH to Gitea works. 4. The system checks that the tokens needed for the chosen hosts work, that the owners accept new repositories, that the name is free on those hosts, and whether SSH to Gitea works.
5. Optional: if the Maintainer chose GitHub, the system creates the empty GitHub repository. 5. Optional: if the Maintainer chose GitHub, the system creates the empty GitHub repository.
6. The system creates the Gitea repository. If the Maintainer chose GitHub, the repository is created with the AGPL license file and so is not empty; otherwise it is empty and has no license. 6. The system creates the Gitea repository. If the Maintainer chose GitHub, the repository is created with the AGPL license file and so is not empty; otherwise it is empty and has no license.
@@ -53,10 +52,6 @@
- 2a. A required tool is missing, or a configuration value is missing or malformed: - 2a. A required tool is missing, or a configuration value is missing or malformed:
1. The system stops before any change and names the problem without showing a credential. 1. The system stops before any change and names the problem without showing a credential.
- 3a. A project detail is set in `config.env`:
1. The system uses it and does not ask for it; the summary says it came from the configuration.
- 3b. A configured project detail is invalid:
1. The system stops before any request and names the key; it does not ask for the value instead.
- 4a. A token is invalid, an owner does not accept the repository, or the name is taken: - 4a. A token is invalid, an owner does not accept the repository, or the name is taken:
1. The system stops before creating anything and says which check failed. The GitHub token is only checked when GitHub was chosen. 1. The system stops before creating anything and says which check failed. The GitHub token is only checked when GitHub was chosen.
- 4c. GitHub was chosen and the Gitea server does not offer the `AGPL-3.0` license: - 4c. GitHub was chosen and the Gitea server does not offer the `AGPL-3.0` license:
@@ -76,7 +71,6 @@
| --- | --- | | --- | --- |
| 2, 4 | A token never appears in output, logs, command lines, remote URLs or temporary files left behind | | 2, 4 | A token never appears in output, logs, command lines, remote URLs or temporary files left behind |
| 3 | The GitHub owner and the Gitea owner are chosen separately; `GITHUB_USER` is only the authenticating account | | 3 | The GitHub owner and the Gitea owner are chosen separately; `GITHUB_USER` is only the authenticating account |
| 3 | A project detail set in `config.env` (the key is present, even if empty where an empty value is allowed) is not asked; only the confirmations stay interactive |
| 3, 5, 7 | GitHub is optional; without it no GitHub repository, mirror or `github` remote is created and the GitHub credentials are not required | | 3, 5, 7 | GitHub is optional; without it no GitHub repository, mirror or `github` remote is created and the GitHub credentials are not required |
| 6 | Choosing GitHub applies the AGPL license (key `AGPL-3.0`) to the Gitea repository when it is created, so that repository is not empty; without GitHub there is no license and the repository is empty | | 6 | Choosing GitHub applies the AGPL license (key `AGPL-3.0`) to the Gitea repository when it is created, so that repository is not empty; without GitHub there is no license and the repository is empty |
| 7 | The mirror direction is Gitea to GitHub; the GitHub repository stays empty and receives its content from the mirror | | 7 | The mirror direction is Gitea to GitHub; the GitHub repository stays empty and receives its content from the mirror |
@@ -93,5 +87,5 @@
[US-001]: ../user-stories.md [US-001]: ../user-stories.md
[SA-001]: ../stakeholder-analysis.md [SA-001]: ../stakeholder-analysis.md
[DM-001]: ./dm.md [DM-001]: ./dm.md
[424f14f]: https://git.tirsystem.com/TirSystem-BashScript/repo_foundry/commit/424f14f4f5577bb47fea41c8f3a655dca953e6d8
[02875ae]: https://git.tirsystem.com/TirSystem-BashScript/repo_foundry/commit/02875aee5f2953473924074eea0056eb31af6b7a [02875ae]: https://git.tirsystem.com/TirSystem-BashScript/repo_foundry/commit/02875aee5f2953473924074eea0056eb31af6b7a
[2a6bb8e]: https://git.tirsystem.com/TirSystem-BashScript/repo_foundry/commit/2a6bb8e8afadfe6ca4a621da30e44a372898ca62
+5 -21
View File
@@ -4,13 +4,13 @@
| Key | Value | | Key | Value |
| --- | --- | | --- | --- |
| ID | US-001 | | ID | US-001 |
| CrossReference | [BC-001], [UCD-001], [MIL-001], [MIL-002], [MIL-003], [MIL-004] | | CrossReference | [BC-001], [UCD-001], [MIL-001], [MIL-002], [MIL-003] |
## Version History ## Version History
| Date | Status | Author | Reviewer | Change | Commit | | Date | Status | Author | Reviewer | Change | Commit |
| --- | --- | --- | --- | --- | --- | | --- | --- | --- | --- | --- | --- |
| 2026-10-05 | Deprecated | Jens Tirsvad Nielsen | S02 | Initial version | [424f14f] |
| 2026-10-05 | Accepted | Jens Tirsvad Nielsen | S02 | Optional GitHub; choosing GitHub applies the AGPL license to the Gitea repository<br>Cited UCD-001<br>Split the epic into three stories, one per milestone | [02875ae] | | 2026-10-05 | Accepted | Jens Tirsvad Nielsen | S02 | Optional GitHub; choosing GitHub applies the AGPL license to the Gitea repository<br>Cited UCD-001<br>Split the epic into three stories, one per milestone | [02875ae] |
| 2026-10-05 | Accepted | Jens Tirsvad Nielsen | S02 | Added US-001.04: project details preset in config.env | [2a6bb8e] |
--- ---
@@ -18,7 +18,7 @@
One epic: "Create a new project" ([UC-001]), setting up a new project on Gitea, optionally on GitHub, with the SQA-QC-Framework in place. The actor is the Maintainer, as in [UCD-001] (S01 or S02; for now one person holds both roles). One epic: "Create a new project" ([UC-001]), setting up a new project on Gitea, optionally on GitHub, with the SQA-QC-Framework in place. The actor is the Maintainer, as in [UCD-001] (S01 or S02; for now one person holds both roles).
The epic is split into four stories, one per milestone. Each story fits one two-week phase and can be shown working at the end of it. The epic is split into three stories, one per milestone. Each story fits one two-week phase and can be shown working at the end of it.
## Story List ## Story List
@@ -64,24 +64,9 @@ The epic is split into four stories, one per milestone. Each story fits one two-
| --- | --- | --- | | --- | --- | --- |
| [UC-001] steps 8 to 10, [MIL-003] | fits one phase | Independent: needs the repositories of US-001.02 | | [UC-001] steps 8 to 10, [MIL-003] | fits one phase | Independent: needs the repositories of US-001.02 |
### US-001.04 — Create a new project: preset the details
**As a** Maintainer, **I want** to set project details in `config.env`, **so that** the script does not ask for the same answers every time I create a project.
**Acceptance Criteria**
- Given a detail is set in `config.env`, when the script collects the details, then it does not ask for it, and the summary shows the value as coming from the configuration.
- Given a detail is not set in `config.env`, when the script collects the details, then it asks for it as before.
- Given a configured value is invalid, when the script starts, then it stops before any request to a host and names the key; it does not ask for the value instead.
- Given every detail is set, when the script runs, then the only questions left are the confirmations: create now, reuse of an existing repository, directory, hooks path or file.
| Traces to | Size | INVEST exceptions |
| --- | --- | --- |
| [UC-001] step 3, [MIL-004] | fits one phase | Independent: needs the prompts of US-001.01 |
## INVEST Check ## INVEST Check
Valuable, Negotiable, Estimable, Small and Testable hold for each story. Independent holds only in part: the stories are ordered, each using what the one before it delivers, which follows the milestone order in [PP-001]. This is flagged as an exception on US-001.02, US-001.03 and US-001.04. Valuable, Negotiable, Estimable, Small and Testable hold for each story. Independent holds only in part: the stories are ordered, each using what the one before it delivers, which follows the milestone order in [PP-001]. This is flagged as an exception on US-001.02 and US-001.03.
--- ---
@@ -91,7 +76,6 @@ Valuable, Negotiable, Estimable, Small and Testable hold for each story. Indepen
[MIL-001]: ./milestones/mil-001-foundation.md [MIL-001]: ./milestones/mil-001-foundation.md
[MIL-002]: ./milestones/mil-002-repositories-and-mirror.md [MIL-002]: ./milestones/mil-002-repositories-and-mirror.md
[MIL-003]: ./milestones/mil-003-scaffold-and-release.md [MIL-003]: ./milestones/mil-003-scaffold-and-release.md
[MIL-004]: ./milestones/mil-004-configurable-details.md
[PP-001]: ./project-plan.md [PP-001]: ./project-plan.md
[424f14f]: https://git.tirsystem.com/TirSystem-BashScript/repo_foundry/commit/424f14f4f5577bb47fea41c8f3a655dca953e6d8
[02875ae]: https://git.tirsystem.com/TirSystem-BashScript/repo_foundry/commit/02875aee5f2953473924074eea0056eb31af6b7a [02875ae]: https://git.tirsystem.com/TirSystem-BashScript/repo_foundry/commit/02875aee5f2953473924074eea0056eb31af6b7a
[2a6bb8e]: https://git.tirsystem.com/TirSystem-BashScript/repo_foundry/commit/2a6bb8e8afadfe6ca4a621da30e44a372898ca62
+13 -25
View File
@@ -4,14 +4,12 @@
# Purpose # Purpose
# RepoFoundry creates a Gitea repository, optionally an empty GitHub # RepoFoundry creates a Gitea repository, optionally an empty GitHub
# repository with a Gitea -> GitHub push mirror, and a local project with # repository with a Gitea -> GitHub push mirror, and a local project with
# the SQA-QC-Framework. It validates the configuration and credentials, # the SQA-QC-Framework. This version (MIL-002) validates the configuration
# asks for the project details (those set in config.env are not asked), checks both hosts with read-only requests # and credentials, asks for the project details, checks both hosts with
# (tokens, owners, names, license, SSH) and, with --apply, creates the # read-only requests (tokens, owners, names, licence, SSH) and, with
# repositories and the mirror, then the local project: its directory, git # --apply, creates the repositories and the mirror. Choosing GitHub also
# repository, remotes (no credential in any address), the framework as a # applies the AGPL-3.0 license to the Gitea repository. The local project
# submodule, the framework's skills and git hooks (and the plan gate if # is not created yet.
# chosen) and its templates. Choosing GitHub also applies the AGPL-3.0
# license to the Gitea repository. No commit is made in the new project.
# #
# Dry run by default # Dry run by default
# Without --apply the script only reads from GitHub and Gitea (GET # Without --apply the script only reads from GitHub and Gitea (GET
@@ -33,9 +31,8 @@
# #
# Files (parsed, never sourced) # Files (parsed, never sourced)
# config.env GITHUB_API_URL, GITHUB_WEB_URL, GITEA_URL, GITEA_API_URL and # config.env GITHUB_API_URL, GITHUB_WEB_URL, GITEA_URL, GITEA_API_URL and
# the optional GITEA_SSH_PORT (default 10022), MIRROR_INTERVAL # the optional GITEA_SSH_PORT (default 10022) and
# (default 10m0s) and FRAMEWORK_REPO (default # MIRROR_INTERVAL (default 10m0s)
# TirSystem/SQA-QC-Framework, the submodule's OWNER/NAME)
# .env GITHUB_PAT, GITHUB_USER, GITEA_TOKEN # .env GITHUB_PAT, GITHUB_USER, GITEA_TOKEN
# #
# Environment # Environment
@@ -47,15 +44,13 @@
# Requires # Requires
# bash 4.4 or later, git, curl, mktemp; jq and ssh are optional (jq is used # bash 4.4 or later, git, curl, mktemp; jq and ssh are optional (jq is used
# for JSON when present; ssh is used for the Gitea SSH test). # for JSON when present; ssh is used for the Gitea SSH test).
# Also the base tools sed, grep, head, tr, sleep, find, cp, mkdir, chmod, env, rm, # Also the base tools sed, grep, head, tr, sleep, rm, rmdir and uname, and
# rmdir and uname, and
# stat (GNU "stat -c" or BSD "stat -f"; only used outside Windows). # stat (GNU "stat -c" or BSD "stat -f"; only used outside Windows).
# #
# Implements # Implements
# MIL-001 tasks 1 to 6, MIL-002 tasks 1 to 5 and MIL-003 tasks 1 to 4 # MIL-001 tasks 1 to 6 and MIL-002 tasks 1 to 5 (issues #3 to #13), user
# (issues #3 to #13 and #15 to #18), user stories US-001.01 to US-001.03, # stories US-001.01 and US-001.02, UC-001 steps 1 to 7; see docs/. Deviation
# UC-001 steps 1 to 10; see docs/. Deviation from the request: its second # from the request: its second GITEA_URL key is named GITEA_API_URL.
# GITEA_URL key is named GITEA_API_URL.
# #
# Tracing # Tracing
# set -x is switched off while the script runs, because a trace would print # set -x is switched off while the script runs, because a trace would print
@@ -66,8 +61,7 @@
# the files in lib/ next to it (one job per file, see the first lines of # the files in lib/ next to it (one job per file, see the first lines of
# each file): constants, output, temp, util, validate, config, tools, json, # each file): constants, output, temp, util, validate, config, tools, json,
# http, api, prompts, project, hosts, preflight, steps, plan, repositories, # http, api, prompts, project, hosts, preflight, steps, plan, repositories,
# mirror, git, localproject, framework, apply and cli. The files are loaded # mirror, apply and cli. The files are loaded from this directory only.
# from this directory only.
# #
# Exit codes # Exit codes
# 0 success (or a dry run, or a "no" at the final question), 1 a failed # 0 success (or a dry run, or a "no" at the final question), 1 a failed
@@ -135,12 +129,6 @@ source "$SCRIPT_DIR/lib/plan.sh"
source "$SCRIPT_DIR/lib/repositories.sh" source "$SCRIPT_DIR/lib/repositories.sh"
# shellcheck source=lib/mirror.sh # shellcheck source=lib/mirror.sh
source "$SCRIPT_DIR/lib/mirror.sh" source "$SCRIPT_DIR/lib/mirror.sh"
# shellcheck source=lib/git.sh
source "$SCRIPT_DIR/lib/git.sh"
# shellcheck source=lib/localproject.sh
source "$SCRIPT_DIR/lib/localproject.sh"
# shellcheck source=lib/framework.sh
source "$SCRIPT_DIR/lib/framework.sh"
# shellcheck source=lib/apply.sh # shellcheck source=lib/apply.sh
source "$SCRIPT_DIR/lib/apply.sh" source "$SCRIPT_DIR/lib/apply.sh"
# shellcheck source=lib/cli.sh # shellcheck source=lib/cli.sh
+1 -22
View File
@@ -4,7 +4,7 @@
# #
# Part of create-project.sh: sourced by it, never run on its own. # Part of create-project.sh: sourced by it, never run on its own.
# #
# Provides: create_all, confirm_reuse, confirm_framework_access, apply_plan # Provides: create_all, confirm_reuse, apply_plan
create_all() { create_all() {
IS_CREATION_STARTED=1 IS_CREATION_STARTED=1
@@ -15,25 +15,6 @@ create_all() {
if ((PROJECT[has_github])); then if ((PROJECT[has_github])); then
configure_mirror configure_mirror
fi fi
create_local_project
add_framework
install_framework
copy_templates
}
# confirm_framework_access: the framework comes over SSH. Without SSH the
# Maintainer can still go on, without the framework steps, after a yes.
confirm_framework_access() {
if ((${STATE[is_ssh_ok]:-0})); then
STATE[skip_framework]=0
return 0
fi
warn "SSH to Gitea ($(gitea_host) port ${CONFIG[GITEA_SSH_PORT]}) did not work, so the framework cannot be added: ${STATE[ssh_note]}"
prompt_yes_no "Create the repositories and the local project without the framework" n
if ! ((REPLY)); then
die "stopped: set up SSH access to Gitea (see the README) and run again"
fi
STATE[skip_framework]=1
} }
confirm_reuse() { confirm_reuse() {
@@ -61,7 +42,5 @@ apply_plan() {
return 0 return 0
fi fi
confirm_reuse confirm_reuse
confirm_local_directory
confirm_framework_access
create_all create_all
} }
+1 -43
View File
@@ -4,7 +4,7 @@
# #
# Part of create-project.sh: sourced by it, never run on its own. # Part of create-project.sh: sourced by it, never run on its own.
# #
# Provides: unquote_value, parse_env_file, parse_env_entry, validate_config, check_preset, check_preset_choice, validate_project_presets, validate_credentials, require_github_credentials, warn_if_env_unsafe, load_configuration # Provides: unquote_value, parse_env_file, parse_env_entry, validate_config, validate_credentials, require_github_credentials, warn_if_env_unsafe, load_configuration
# unquote_value RAW: strip matching quotes (or a trailing " # comment" on an # unquote_value RAW: strip matching quotes (or a trailing " # comment" on an
# unquoted value) and return the value in REPLY. Fails on unbalanced quotes. # unquoted value) and return the value in REPLY. Fails on unbalanced quotes.
@@ -100,48 +100,6 @@ validate_config() {
CONFIG[MIRROR_INTERVAL]="${CONFIG[MIRROR_INTERVAL]:-$DEFAULT_MIRROR_INTERVAL}" CONFIG[MIRROR_INTERVAL]="${CONFIG[MIRROR_INTERVAL]:-$DEFAULT_MIRROR_INTERVAL}"
is_valid_interval "${CONFIG[MIRROR_INTERVAL]}" || is_valid_interval "${CONFIG[MIRROR_INTERVAL]}" ||
die "MIRROR_INTERVAL in $CONFIG_FILE must look like 10m0s or 8h0m0s" die "MIRROR_INTERVAL in $CONFIG_FILE must look like 10m0s or 8h0m0s"
CONFIG[FRAMEWORK_REPO]="${CONFIG[FRAMEWORK_REPO]:-$DEFAULT_FRAMEWORK_REPO}"
is_valid_framework_repo "${CONFIG[FRAMEWORK_REPO]}" ||
die "FRAMEWORK_REPO in $CONFIG_FILE must look like OWNER/NAME"
validate_project_presets
}
# check_preset KEY VALIDATOR HINT: when KEY is set in config.env its value must
# pass VALIDATOR. A key that is present counts as set; only the description
# may be empty. The message names the key, never the value.
check_preset() {
local key="$1" validator="$2" hint="$3"
[[ -n ${CONFIG[$key]+set} ]] || return 0
if [[ -z ${CONFIG[$key]} && $key != PROJECT_DESCRIPTION ]]; then
die "$key in $CONFIG_FILE is empty; remove the line to be asked, or give a value ($hint)"
fi
"$validator" "${CONFIG[$key]}" ||
die "$key in $CONFIG_FILE is not valid: $hint"
}
# check_preset_choice KEY CHOICE...: like check_preset for a fixed list of
# words; the value is stored in lower case.
check_preset_choice() {
local key="$1"
shift
[[ -n ${CONFIG[$key]+set} ]] || return 0
[[ -n ${CONFIG[$key]} ]] ||
die "$key in $CONFIG_FILE is empty; remove the line to be asked, or give one of: $*"
CONFIG[$key]="${CONFIG[$key],,}"
in_list "${CONFIG[$key]}" "$@" ||
die "$key in $CONFIG_FILE must be one of: $*"
}
# The optional project details that may be preset in config.env.
validate_project_presets() {
check_preset PROJECT_NAME is_valid_repo_name "$HINT_REPO_NAME"
check_preset PROJECT_DESCRIPTION is_valid_description "$HINT_DESCRIPTION"
check_preset_choice PROJECT_VISIBILITY private public
check_preset GITEA_OWNER is_valid_gitea_owner "$HINT_GITEA_OWNER"
check_preset_choice USE_GITHUB yes no
check_preset GITHUB_OWNER is_valid_github_owner "$HINT_GITHUB_OWNER"
check_preset PROJECT_DIRECTORY is_valid_directory "$HINT_DIRECTORY"
check_preset_choice ENABLE_PLAN_GATE yes no
} }
validate_credentials() { validate_credentials() {
+3 -16
View File
@@ -8,7 +8,7 @@
# shellcheck disable=SC2034 # read and written by the other library files # shellcheck disable=SC2034 # read and written by the other library files
readonly PROJECT_NAME="${REPOFOUNDRY_NAME:-RepoFoundry}" readonly PROJECT_NAME="${REPOFOUNDRY_NAME:-RepoFoundry}"
readonly VERSION="0.3.0" readonly VERSION="0.2.0"
readonly EXIT_FAILURE=1 readonly EXIT_FAILURE=1
readonly EXIT_USAGE=2 readonly EXIT_USAGE=2
readonly MAX_VALUE_LENGTH=2048 readonly MAX_VALUE_LENGTH=2048
@@ -16,23 +16,12 @@ readonly MAX_DESCRIPTION_LENGTH=350
readonly HTTP_TIMEOUT_SECONDS=30 readonly HTTP_TIMEOUT_SECONDS=30
readonly DEFAULT_MIRROR_INTERVAL="10m0s" readonly DEFAULT_MIRROR_INTERVAL="10m0s"
readonly DEFAULT_SSH_PORT=10022 readonly DEFAULT_SSH_PORT=10022
readonly DEFAULT_FRAMEWORK_REPO="TirSystem/SQA-QC-Framework"
readonly AGPL_LICENSE_KEY="AGPL-3.0" readonly AGPL_LICENSE_KEY="AGPL-3.0"
readonly DEFAULT_BRANCH="main" readonly DEFAULT_BRANCH="main"
# What the prompts and the preset keys in config.env both tell the Maintainer readonly PLAN_STEPS=("GitHub repository" "Gitea repository" "Push mirror")
# when a value is refused.
readonly HINT_REPO_NAME="use letters, digits, '.', '_' or '-' (at most 100), not ending in .git"
readonly HINT_DESCRIPTION="at most $MAX_DESCRIPTION_LENGTH characters and no control characters"
readonly HINT_GITEA_OWNER="use letters, digits, '.', '_' or '-' (at most 39)"
readonly HINT_GITHUB_OWNER="use letters, digits or '-' (at most 39)"
readonly HINT_DIRECTORY="must not be empty, start with '-' or contain control characters"
readonly PLAN_STEPS=("GitHub repository" "Gitea repository" "Push mirror"
"Local project" "Framework" "Skills and hooks" "Templates")
# shellcheck disable=SC2034 # read through namerefs (parse_env_file) # shellcheck disable=SC2034 # read through namerefs (parse_env_file)
readonly CONFIG_KEYS=(GITHUB_API_URL GITHUB_WEB_URL GITEA_URL GITEA_API_URL readonly CONFIG_KEYS=(GITHUB_API_URL GITHUB_WEB_URL GITEA_URL GITEA_API_URL
GITEA_SSH_PORT MIRROR_INTERVAL FRAMEWORK_REPO GITEA_SSH_PORT MIRROR_INTERVAL)
PROJECT_NAME PROJECT_DESCRIPTION PROJECT_VISIBILITY GITEA_OWNER USE_GITHUB
GITHUB_OWNER PROJECT_DIRECTORY ENABLE_PLAN_GATE)
readonly CREDENTIAL_KEYS=(GITHUB_PAT GITHUB_USER GITEA_TOKEN) readonly CREDENTIAL_KEYS=(GITHUB_PAT GITHUB_USER GITEA_TOKEN)
CONFIG_FILE="$PROJECT_ROOT/config.env" CONFIG_FILE="$PROJECT_ROOT/config.env"
@@ -50,8 +39,6 @@ TEMP_FILES=()
declare -A CONFIG=() declare -A CONFIG=()
declare -A CREDENTIALS=() declare -A CREDENTIALS=()
declare -A PROJECT=() declare -A PROJECT=()
# Project details that came from config.env instead of a prompt (PRESET[name]=1).
declare -A PRESET=()
# Facts found by the preflight checks (logins, owner kinds, repository state). # Facts found by the preflight checks (logins, owner kinds, repository state).
declare -A STATE=() declare -A STATE=()
# Outcome of each step in PLAN_STEPS, for the final report. # Outcome of each step in PLAN_STEPS, for the final report.
-153
View File
@@ -1,153 +0,0 @@
# shellcheck shell=bash
# shellcheck disable=SC2004,SC2034,SC2154 # shared state and arrays are declared in constants.sh
# framework.sh - The SQA-QC-Framework in the new project: submodule, skills, hooks and templates.
#
# Part of create-project.sh: sourced by it, never run on its own.
#
# Provides: is_framework_skipped, add_framework, run_framework_script, install_skills, install_hooks, install_framework, copy_template, copy_templates
# is_framework_skipped: succeed when the framework steps are left out because
# SSH to Gitea is not available (the Maintainer agreed to that).
is_framework_skipped() {
[[ ${STATE[skip_framework]:-0} == 1 ]]
}
# add_framework: git submodule add of the framework as "framework". SSH is
# needed for it; a failure says how to test the access.
add_framework() {
local label="Framework" dir="${PROJECT[directory]}" url err existing
url="$(framework_url)"
if is_framework_skipped; then
finish_step "$label" "skipped" "(no SSH access to Gitea)"
return 0
fi
begin_step "$label"
if [[ -e $dir/framework ]]; then
existing="$(git_project "$dir" config -f .gitmodules --get submodule.framework.url || true)"
if [[ $existing != "$url" ]]; then
die "'framework' already exists in $dir and is not the framework submodule ($url)"
fi
finish_step "$label" "reused" "$url (already a submodule)"
return 0
fi
make_temp_file
err="$REPLY"
if ! git_project "$dir" submodule add -q "$url" framework 2>"$err"; then
die "git could not add the framework from $url. Check the SSH access first: ssh -p ${CONFIG[GITEA_SSH_PORT]} -T git@$(gitea_host). Git said: $(head -n 2 "$err" | tr '\n' ' ')"
fi
finish_step "$label" "created" "$url"
}
# run_framework_script DIR SCRIPT [ARG...]: run one of the framework's own
# scripts inside the project. PROJECT_ROOT is set explicitly so that a
# PROJECT_ROOT in the caller's environment cannot point it elsewhere.
run_framework_script() {
local dir="$1" script="$2" out abs
shift 2
abs="$(cd "$dir" && pwd)"
make_temp_file
out="$REPLY"
if ! (cd "$abs" && env PROJECT_ROOT="$abs" bash "framework/scripts/$script" "$@" </dev/null) >"$out" 2>&1; then
die "the framework script $script failed: $(tail -n 3 "$out" | tr '\n' ' ')"
fi
}
# install_skills DIR: install the framework's skills once. The installer is
# safe to repeat but copies everything again, so a project that already has
# them is left alone.
install_skills() {
local dir="$1"
if [[ -f $dir/.agents/skills/.framework-skills && -f $dir/.claude/skills/.framework-skills ]]; then
STATE[skills_note]="skills already installed"
return 0
fi
run_framework_script "$dir" install-skills.sh
STATE[skills_note]="skills installed"
}
# install_hooks DIR: point core.hooksPath at the framework's hooks, and turn
# on the plan gate if chosen. A different hooks path that is already set is
# only replaced after a yes.
install_hooks() {
local dir="$1" current global gate=() gate_enabled
if ((PROJECT[is_plan_gate_enabled])); then
gate=(--enable-plan-gate)
fi
# Both settings are normally unset; git config exits 1 then.
current="$(git_project "$dir" config --local --get core.hooksPath || true)"
global="$(git_project "$dir" config --global --get core.hooksPath || true)"
gate_enabled="$(git_project "$dir" config --local --get planGate.enabled || true)"
if [[ -z $current && -n $global ]]; then
warn "your global core.hooksPath is '$global'; this project sets its own, which takes precedence here"
fi
if [[ -z $current ]]; then
run_framework_script "$dir" install-git-hooks.sh "${gate[@]}"
STATE[hooks_note]="hooks installed"
elif [[ $current == framework/githooks ]]; then
STATE[hooks_note]="hooks already installed"
if ((PROJECT[is_plan_gate_enabled])) && [[ $gate_enabled != true ]]; then
run_framework_script "$dir" install-git-hooks.sh "${gate[@]}"
fi
else
prompt_yes_no "core.hooksPath is already '$current'. Replace it with framework/githooks" n
if ((REPLY)); then
run_framework_script "$dir" install-git-hooks.sh "${gate[@]}"
STATE[hooks_note]="hooks installed (replaced '$current')"
else
STATE[hooks_note]="kept the existing hooks path '$current'"
if ((PROJECT[is_plan_gate_enabled])); then
warn "the plan gate is not enabled because the framework hooks were not installed"
fi
fi
fi
}
# install_framework: skills, then hooks (and the plan gate). Each is done once.
install_framework() {
local label="Skills and hooks" dir="${PROJECT[directory]}" gate_state="plan gate off"
if is_framework_skipped; then
finish_step "$label" "skipped" "(no SSH access to Gitea)"
return 0
fi
begin_step "$label"
install_skills "$dir"
install_hooks "$dir"
if [[ $(git_project "$dir" config --local --get planGate.enabled || true) == true ]]; then
gate_state="plan gate on"
fi
finish_step "$label" "created" "(${STATE[skills_note]}; ${STATE[hooks_note]}; $gate_state)"
}
# copy_template DIR SOURCE TARGET: copy a framework template. An existing
# target is only replaced after a yes. The result goes to STATE[template_note].
copy_template() {
local dir="$1" source="$2" target="$3"
if [[ ! -f $dir/$source ]]; then
die "the framework has no $source; is the submodule complete?"
fi
if [[ -e $dir/$target ]]; then
prompt_yes_no "$target already exists. Replace it with the framework template" n
if ! ((REPLY)); then
STATE[template_note]="kept existing $target"
return 0
fi
fi
cp -- "$dir/$source" "$dir/$target"
STATE[template_note]="copied $target"
}
# copy_templates: AGENTS.md and docs/artifact-registry.md from the framework.
copy_templates() {
local label="Templates" dir="${PROJECT[directory]}" notes=""
if is_framework_skipped; then
finish_step "$label" "skipped" "(no SSH access to Gitea)"
return 0
fi
begin_step "$label"
mkdir -p -- "$dir/docs"
copy_template "$dir" framework/templates/AGENTS-template.md AGENTS.md
notes="${STATE[template_note]}"
copy_template "$dir" framework/templates/artifact-registry-template.md docs/artifact-registry.md
notes="$notes; ${STATE[template_note]}"
finish_step "$label" "created" "($notes)"
}
-49
View File
@@ -1,49 +0,0 @@
# shellcheck shell=bash
# shellcheck disable=SC2004,SC2034,SC2154 # shared state and arrays are declared in constants.sh
# git.sh - Running git for the new project: no prompts, no token on a command line.
#
# Part of create-project.sh: sourced by it, never run on its own.
#
# Provides: git_project, fetch_origin
# git_project DIR ARGS...: run git in DIR. Prompts are switched off and stdin
# is closed (git must not eat the answers meant for later prompts), so a
# missing credential or SSH key fails at once instead of waiting for input.
git_project() {
local dir="$1"
shift
GIT_TERMINAL_PROMPT=0 GIT_SSH_COMMAND="${GIT_SSH_COMMAND:-ssh} -o BatchMode=yes" \
git -C "$dir" "$@" </dev/null
}
# fetch_origin DIR: fetch the Gitea repository into the project. Over SSH the
# user's key is used. Over HTTPS the token reaches git through a private
# GIT_ASKPASS helper and the environment of this one command: it is never part
# of a URL, of the remote configuration or of a command line.
fetch_origin() {
local dir="$1" url askpass
url="$(git_project "$dir" config --get remote.origin.url)"
if [[ $url != https://* ]]; then
git_project "$dir" fetch -q origin
return
fi
make_temp_file
askpass="$REPLY"
# shellcheck disable=SC2016 # the helper is written out literally: it expands $1 and its environment itself
{
printf '%s\n' '#!/usr/bin/env bash'
printf '%s\n' 'case "$1" in'
printf '%s\n' ' *sername*) printf "%s\n" "$REPOFOUNDRY_ASKPASS_USER" ;;'
printf '%s\n' ' *) printf "%s\n" "$REPOFOUNDRY_ASKPASS_TOKEN" ;;'
printf '%s\n' 'esac'
} >"$askpass"
chmod 700 "$askpass"
# Not "cmd; rm": a failed fetch must still be reported to the caller.
if ! GIT_ASKPASS="$askpass" REPOFOUNDRY_ASKPASS_USER="${STATE[gitea_login]}" \
REPOFOUNDRY_ASKPASS_TOKEN="${CREDENTIALS[GITEA_TOKEN]}" \
git_project "$dir" fetch -q origin; then
rm -f -- "$askpass"
return 1
fi
rm -f -- "$askpass"
}
+1 -38
View File
@@ -4,7 +4,7 @@
# #
# Part of create-project.sh: sourced by it, never run on its own. # Part of create-project.sh: sourced by it, never run on its own.
# #
# Provides: is_reused, repo_owner, repo_url, gitea_host, origin_protocol, origin_url, github_remote_url, framework_url # Provides: is_reused, repo_owner, repo_url
# is_reused HOST: succeed if the existing repository on HOST will be reused. # is_reused HOST: succeed if the existing repository on HOST will be reused.
is_reused() { is_reused() {
@@ -26,40 +26,3 @@ repo_url() {
printf '%s/%s/%s' "${CONFIG[GITHUB_WEB_URL]}" "${PROJECT[github_owner]}" "${PROJECT[name]}" printf '%s/%s/%s' "${CONFIG[GITHUB_WEB_URL]}" "${PROJECT[github_owner]}" "${PROJECT[name]}"
fi fi
} }
# gitea_host: the host name of the Gitea server, from GITEA_URL.
gitea_host() {
local host="${CONFIG[GITEA_URL]#https://}"
host="${host%%/*}"
printf '%s' "${host%%:*}"
}
# origin_protocol: SSH when the SSH test passed, otherwise HTTPS.
origin_protocol() {
if ((${STATE[is_ssh_ok]:-0})); then
printf 'SSH'
else
printf 'HTTPS'
fi
}
# origin_url: the address of the Gitea repository for the origin remote. It
# never holds a credential: "git@" is the SSH user name, not a secret.
origin_url() {
if [[ $(origin_protocol) == SSH ]]; then
printf 'ssh://git@%s:%s/%s/%s.git' "$(gitea_host)" "${CONFIG[GITEA_SSH_PORT]}" \
"${PROJECT[gitea_owner]}" "${PROJECT[name]}"
else
printf '%s/%s/%s.git' "${CONFIG[GITEA_URL]}" "${PROJECT[gitea_owner]}" "${PROJECT[name]}"
fi
}
github_remote_url() {
printf '%s/%s/%s.git' "${CONFIG[GITHUB_WEB_URL]}" "${PROJECT[github_owner]}" "${PROJECT[name]}"
}
# framework_url: where the framework submodule comes from (always SSH).
framework_url() {
printf 'ssh://git@%s:%s/%s.git' "$(gitea_host)" "${CONFIG[GITEA_SSH_PORT]}" \
"${CONFIG[FRAMEWORK_REPO]}"
}
+1 -1
View File
@@ -71,7 +71,7 @@ http_request() {
# that never contains the request. # that never contains the request.
HTTP_STATUS="$(curl --silent --max-time "$HTTP_TIMEOUT_SECONDS" \ HTTP_STATUS="$(curl --silent --max-time "$HTTP_TIMEOUT_SECONDS" \
--connect-timeout 10 --output "$out_file" --write-out '%{http_code}' \ --connect-timeout 10 --output "$out_file" --write-out '%{http_code}' \
--config "$config_file" "${data_args[@]}" </dev/null 2>/dev/null)" || curl_status=$? --config "$config_file" "${data_args[@]}" 2>/dev/null)" || curl_status=$?
# The configuration file holds the token and the body may hold another one # The configuration file holds the token and the body may hold another one
# (the mirror password): remove both now instead of at exit. # (the mirror password): remove both now instead of at exit.
rm -f -- "$config_file" ${body_file:+"$body_file"} rm -f -- "$config_file" ${body_file:+"$body_file"}
-90
View File
@@ -1,90 +0,0 @@
# shellcheck shell=bash
# shellcheck disable=SC2004,SC2034,SC2154 # shared state and arrays are declared in constants.sh
# localproject.sh - The local project: its directory, its git repository and its remotes.
#
# Part of create-project.sh: sourced by it, never run on its own.
#
# Provides: inspect_local_directory, confirm_local_directory, ensure_remote, checkout_gitea_history, create_local_project
# inspect_local_directory: record in STATE[local_dir] whether the project
# directory is missing, empty or not_empty. It creates nothing.
inspect_local_directory() {
local dir="${PROJECT[directory]}"
if [[ ! -e $dir ]]; then
STATE[local_dir]="missing"
elif [[ ! -d $dir ]]; then
die "$dir already exists and is not a directory"
elif [[ -z "$(find "$dir" -mindepth 1 -maxdepth 1 -print -quit)" ]]; then
STATE[local_dir]="empty"
else
STATE[local_dir]="not_empty"
fi
}
# confirm_local_directory: an existing directory is only used after a yes.
confirm_local_directory() {
local dir="${PROJECT[directory]}" what="is empty"
if [[ ${STATE[local_dir]} == missing ]]; then
return 0
fi
if [[ ${STATE[local_dir]} == not_empty ]]; then
what="already has files"
fi
prompt_yes_no "The directory $dir already exists and $what. Use it" n
if ! ((REPLY)); then
die "stopped: choose another directory or remove this one"
fi
}
# ensure_remote DIR NAME URL: add the remote, or accept one that already has
# exactly this address. A different address is never overwritten.
ensure_remote() {
local dir="$1" name="$2" url="$3" existing
# git config exits 1 when the remote is not set; that is the normal case.
existing="$(git_project "$dir" config --get "remote.$name.url" || true)"
if [[ -z $existing ]]; then
git_project "$dir" remote add "$name" "$url"
elif [[ $existing != "$url" ]]; then
die "the remote '$name' in $dir already points to $existing; remove it or choose another directory"
fi
}
# checkout_gitea_history DIR: when the Gitea repository holds the license
# commit, fetch it and start the local branch from it, so the local history
# begins with that commit. Existing files are never overwritten: git refuses.
checkout_gitea_history() {
local dir="$1" err
if ! fetch_origin "$dir" 2>/dev/null; then
die "could not fetch the Gitea repository from $(origin_url); check your SSH key (or, over HTTPS, the token) and run the same command again"
fi
if ! git_project "$dir" rev-parse --verify -q refs/remotes/origin/main >/dev/null; then
return 0
fi
if git_project "$dir" rev-parse --verify -q HEAD >/dev/null 2>&1; then
warn "$dir already has history: the Gitea content was fetched but not checked out"
return 0
fi
make_temp_file
err="$REPLY"
if ! git_project "$dir" checkout -q -b main --track origin/main 2>"$err"; then
die "git would overwrite files in $dir with the Gitea content; move them away and run again. Git said: $(head -n 2 "$err" | tr '\n' ' ')"
fi
}
# create_local_project: the directory, the git repository on main, the
# remotes and, when GitHub is chosen, the license history. No commit is made.
create_local_project() {
local label="Local project" dir="${PROJECT[directory]}"
begin_step "$label"
mkdir -p -- "$dir"
if [[ ! -e $dir/.git ]]; then
git_project "$dir" init -q
git_project "$dir" symbolic-ref HEAD "refs/heads/$DEFAULT_BRANCH"
fi
ensure_remote "$dir" origin "$(origin_url)"
if ((PROJECT[has_github])); then
ensure_remote "$dir" github "$(github_remote_url)"
checkout_gitea_history "$dir"
fi
finish_step "$label" "created" "$dir (origin over $(origin_protocol))"
}
+2 -20
View File
@@ -4,17 +4,7 @@
# #
# Part of create-project.sh: sourced by it, never run on its own. # Part of create-project.sh: sourced by it, never run on its own.
# #
# Provides: local_plan_note, print_plan # Provides: print_plan
# local_plan_note: what will happen to the project directory.
local_plan_note() {
local dir="${PROJECT[directory]}"
case "${STATE[local_dir]}" in
missing) printf 'create %s (new directory), git on %s, no commit' "$dir" "$DEFAULT_BRANCH" ;;
empty) printf 'use the existing empty directory %s (you will be asked)' "$dir" ;;
*) printf 'use the existing directory %s, which has files (you will be asked)' "$dir" ;;
esac
}
print_plan() { print_plan() {
local gitea_action github_action origin_note local gitea_action github_action origin_note
@@ -45,13 +35,5 @@ print_plan() {
else else
origin_note="HTTPS (SSH test: ${STATE[ssh_note]})" origin_note="HTTPS (SSH test: ${STATE[ssh_note]})"
fi fi
say "$(printf ' %-18s: %s' "Local project" "$(local_plan_note)")" say "$(printf ' %-18s: %s' "Local origin" "will use $origin_note, in a later phase")"
say "$(printf ' %-18s: %s' "Local origin" "will use $origin_note")"
if ((STATE[is_ssh_ok])); then
say "$(printf ' %-18s: %s' "Framework" "add $(framework_url) as a submodule")"
say "$(printf ' %-18s: %s' "Skills and hooks" "install once; plan gate $(yes_no "${PROJECT[is_plan_gate_enabled]}")")"
say "$(printf ' %-18s: %s' "Templates" "AGENTS.md and docs/artifact-registry.md (you are asked before a file is replaced)")"
else
say "$(printf ' %-18s: %s' "Framework" "NOT possible without SSH to Gitea; you will be asked whether to go on without it")"
fi
} }
+9 -12
View File
@@ -28,8 +28,7 @@ check_gitea_license() {
} }
# inspect_repository HOST: record in STATE[HOST_repo] whether the repository # inspect_repository HOST: record in STATE[HOST_repo] whether the repository
# is free (does not exist), empty, initial_only (just the LICENSE and the # is free (does not exist), empty, license_only or not_empty.
# README.md Gitea adds) or not_empty.
inspect_repository() { inspect_repository() {
local host="$1" owner name names local host="$1" owner name names
owner="$(repo_owner "$host")" owner="$(repo_owner "$host")"
@@ -46,13 +45,10 @@ inspect_repository() {
return 0 return 0
fi fi
expect_status "cannot read the contents of the $(host_label "$host") repository $owner/$name" 200 expect_status "cannot read the contents of the $(host_label "$host") repository $owner/$name" 200
# Gitea adds a README.md of its own next to the LICENSE when it creates a names="$(json_values "$HTTP_BODY_FILE" name)"
# repository with a license (seen on a real server), so both count as the case "$names" in
# content this script creates.
names="$(json_values "$HTTP_BODY_FILE" name | sort | tr '\n' ' ')"
case "${names% }" in
"") STATE[${host}_repo]="empty" ;; "") STATE[${host}_repo]="empty" ;;
"LICENSE" | "LICENSE README.md") STATE[${host}_repo]="initial_only" ;; LICENSE) STATE[${host}_repo]="license_only" ;;
*) STATE[${host}_repo]="not_empty" ;; *) STATE[${host}_repo]="not_empty" ;;
esac esac
} }
@@ -112,7 +108,9 @@ preflight_github() {
# or without access it is simply "not passed"; it never stops the run. # or without access it is simply "not passed"; it never stops the run.
test_gitea_ssh() { test_gitea_ssh() {
local host port output status=0 local host port output status=0
host="$(gitea_host)" host="${CONFIG[GITEA_URL]#https://}"
host="${host%%/*}"
host="${host%%:*}"
port="${CONFIG[GITEA_SSH_PORT]}" port="${CONFIG[GITEA_SSH_PORT]}"
STATE[is_ssh_ok]=0 STATE[is_ssh_ok]=0
STATE[ssh_note]="failed (check your SSH key and that $host:$port is reachable)" STATE[ssh_note]="failed (check your SSH key and that $host:$port is reachable)"
@@ -121,7 +119,7 @@ test_gitea_ssh() {
return 0 return 0
fi fi
output="$(ssh -p "$port" -o BatchMode=yes -o ConnectTimeout=5 \ output="$(ssh -p "$port" -o BatchMode=yes -o ConnectTimeout=5 \
-o StrictHostKeyChecking=yes -T "git@$host" </dev/null 2>&1)" || status=$? -o StrictHostKeyChecking=yes -T "git@$host" 2>&1)" || status=$?
if ((status == 0)) || [[ $output == *"successfully authenticated"* ]]; then if ((status == 0)) || [[ $output == *"successfully authenticated"* ]]; then
STATE[is_ssh_ok]=1 STATE[is_ssh_ok]=1
STATE[ssh_note]="passed" STATE[ssh_note]="passed"
@@ -142,7 +140,7 @@ decide_existing_repositories() {
case "$state" in case "$state" in
free) ;; free) ;;
empty) STATE[reuse_$host]=1 ;; empty) STATE[reuse_$host]=1 ;;
initial_only) license_only)
if [[ $host == gitea ]] && ((PROJECT[has_github])); then if [[ $host == gitea ]] && ((PROJECT[has_github])); then
STATE[reuse_$host]=1 STATE[reuse_$host]=1
else else
@@ -165,6 +163,5 @@ run_preflight() {
fi fi
test_gitea_ssh test_gitea_ssh
decide_existing_repositories decide_existing_repositories
inspect_local_directory
say "All checks passed." say "All checks passed."
} }
+22 -54
View File
@@ -4,59 +4,34 @@
# #
# Part of create-project.sh: sourced by it, never run on its own. # Part of create-project.sh: sourced by it, never run on its own.
# #
# Provides: preset_detail, collect_project_details, collect_github_details, source_note, yes_no, credential_state, print_summary # Provides: collect_project_details, yes_no, credential_state, print_summary
# preset_detail KEY NAME: a detail set in config.env is used and not asked;
# the value is returned in REPLY and marked in PRESET[NAME].
preset_detail() {
[[ -n ${CONFIG[$1]+set} ]] || return 1
REPLY="${CONFIG[$1]}"
PRESET[$2]=1
}
# Ask for each project detail, except those set in config.env.
collect_project_details() { collect_project_details() {
preset_detail PROJECT_NAME name || prompt_value "Repository name" "" is_valid_repo_name \
prompt_value "Repository name" "" is_valid_repo_name "$HINT_REPO_NAME" "use letters, digits, '.', '_' or '-' (at most 100), not ending in .git"
PROJECT[name]="$REPLY" PROJECT[name]="$REPLY"
preset_detail PROJECT_DESCRIPTION description || prompt_value "Description (optional)" "" is_valid_description \
prompt_value "Description (optional)" "" is_valid_description "$HINT_DESCRIPTION" "at most $MAX_DESCRIPTION_LENGTH characters and no control characters"
PROJECT[description]="$REPLY" PROJECT[description]="$REPLY"
preset_detail PROJECT_VISIBILITY visibility ||
prompt_choice "Visibility" private private public prompt_choice "Visibility" private private public
PROJECT[visibility]="$REPLY" PROJECT[visibility]="$REPLY"
preset_detail GITEA_OWNER gitea_owner || prompt_value "Gitea owner (user or organization)" "" is_valid_gitea_owner \
prompt_value "Gitea owner (user or organization)" "" is_valid_gitea_owner "$HINT_GITEA_OWNER" "use letters, digits, '.', '_' or '-' (at most 39)"
PROJECT[gitea_owner]="$REPLY" PROJECT[gitea_owner]="$REPLY"
collect_github_details
preset_detail PROJECT_DIRECTORY directory ||
prompt_value "Local directory" "./${PROJECT[name]}" is_valid_directory "$HINT_DIRECTORY"
PROJECT[directory]="$REPLY"
if preset_detail ENABLE_PLAN_GATE is_plan_gate_enabled; then
[[ $REPLY == yes ]] && REPLY=1 || REPLY=0
else
prompt_yes_no "Enable the plan gate" n
fi
PROJECT[is_plan_gate_enabled]="$REPLY"
}
# Whether GitHub is used, and its owner. A GITHUB_OWNER set while GitHub is
# not used is ignored, with a warning.
collect_github_details() {
if preset_detail USE_GITHUB has_github; then
[[ $REPLY == yes ]] && REPLY=1 || REPLY=0
else
prompt_yes_no "Also create a GitHub repository (applies the AGPL license)" y prompt_yes_no "Also create a GitHub repository (applies the AGPL license)" y
fi
PROJECT[has_github]="$REPLY" PROJECT[has_github]="$REPLY"
PROJECT[github_owner]="" PROJECT[github_owner]=""
if ((PROJECT[has_github])); then if ((PROJECT[has_github])); then
preset_detail GITHUB_OWNER github_owner || prompt_value "GitHub owner (user or organization)" \
prompt_value "GitHub owner (user or organization)" "${CREDENTIALS[GITHUB_USER]:-}" is_valid_github_owner "$HINT_GITHUB_OWNER" "${CREDENTIALS[GITHUB_USER]:-}" is_valid_github_owner \
"use letters, digits or '-' (at most 39)"
PROJECT[github_owner]="$REPLY" PROJECT[github_owner]="$REPLY"
elif [[ -n ${CONFIG[GITHUB_OWNER]+set} ]]; then
warn "GITHUB_OWNER in $CONFIG_FILE is ignored because GitHub is not used"
fi fi
prompt_value "Local directory" "./${PROJECT[name]}" is_valid_directory \
"must not be empty, start with '-' or contain control characters"
PROJECT[directory]="$REPLY"
prompt_yes_no "Enable the plan gate" n
PROJECT[is_plan_gate_enabled]="$REPLY"
} }
yes_no() { yes_no() {
@@ -75,27 +50,20 @@ credential_state() {
fi fi
} }
# source_note NAME: the marker shown after a value that came from config.env.
source_note() {
if [[ -n ${PRESET[$1]:-} ]]; then
printf ' (from config.env)'
fi
}
print_summary() { print_summary() {
say "" say ""
say "$PROJECT_NAME $VERSION" say "$PROJECT_NAME $VERSION"
say "Collected details:" say "Collected details:"
say " Repository : ${PROJECT[name]}$(source_note name) (${PROJECT[visibility]}$(source_note visibility))" say " Repository : ${PROJECT[name]} (${PROJECT[visibility]})"
say " Description : ${PROJECT[description]:-(none)}$(source_note description)" say " Description : ${PROJECT[description]:-(none)}"
say " Gitea : ${CONFIG[GITEA_URL]}/${PROJECT[gitea_owner]}/${PROJECT[name]}$(source_note gitea_owner)" say " Gitea : ${CONFIG[GITEA_URL]}/${PROJECT[gitea_owner]}/${PROJECT[name]}"
if ((PROJECT[has_github])); then if ((PROJECT[has_github])); then
say " GitHub : ${CONFIG[GITHUB_WEB_URL]}/${PROJECT[github_owner]}/${PROJECT[name]} (AGPL license applied)$(source_note github_owner)" say " GitHub : ${CONFIG[GITHUB_WEB_URL]}/${PROJECT[github_owner]}/${PROJECT[name]} (AGPL license applied)"
else else
say " GitHub : not used$(source_note has_github)" say " GitHub : not used"
fi fi
say " Directory : ${PROJECT[directory]}$(source_note directory)" say " Directory : ${PROJECT[directory]}"
say " Plan gate : $(yes_no "${PROJECT[is_plan_gate_enabled]}")$(source_note is_plan_gate_enabled)" say " Plan gate : $(yes_no "${PROJECT[is_plan_gate_enabled]}")"
say "Credentials : GITEA_TOKEN $(credential_state GITEA_TOKEN)," \ say "Credentials : GITEA_TOKEN $(credential_state GITEA_TOKEN)," \
"GITHUB_PAT $(credential_state GITHUB_PAT)" "GITHUB_PAT $(credential_state GITHUB_PAT)"
} }
+3 -4
View File
@@ -42,11 +42,10 @@ report_outcome() {
say "$(printf ' %-18s: %s' "$label" "${STEP_STATUS[$label]}${STEP_DETAIL[$label]:+ ${STEP_DETAIL[$label]}}")" say "$(printf ' %-18s: %s' "$label" "${STEP_STATUS[$label]}${STEP_DETAIL[$label]:+ ${STEP_DETAIL[$label]}}")"
done done
if ((code == 0)); then if ((code == 0)); then
say "The project is in ${PROJECT[directory]}. Nothing was committed there: review it, then work on a branch." say "The local project with the framework is created by a later phase."
else else
say "To continue: fix the problem named above and run the same command again with --apply." say "To continue: fix the problem named above and run the same command again with --apply."
say "A repository this run created is still empty (or holds only the license and the README Gitea adds), so the next run offers to reuse it." say "A repository this run created is still empty (or holds only the license), so the next run offers to reuse it."
say "A directory, remotes and submodule created so far are used again by the next run; you are asked before an existing directory or file is touched." say "Nothing is deleted automatically. To start over, delete the repositories above in the web interface."
say "Nothing is deleted automatically. To start over, delete the repositories above in the web interface and the project directory by hand."
fi fi
} }
+1 -6
View File
@@ -4,7 +4,7 @@
# #
# Part of create-project.sh: sourced by it, never run on its own. # Part of create-project.sh: sourced by it, never run on its own.
# #
# Provides: is_valid_framework_repo, is_valid_repo_name, is_valid_gitea_owner, is_valid_github_owner, is_valid_description, is_valid_directory, is_valid_base_url, is_valid_request_url, is_valid_token, is_valid_port, is_valid_interval, normalize_url # Provides: is_valid_repo_name, is_valid_gitea_owner, is_valid_github_owner, is_valid_description, is_valid_directory, is_valid_base_url, is_valid_request_url, is_valid_token, is_valid_port, is_valid_interval, normalize_url
is_valid_repo_name() { is_valid_repo_name() {
local name="$1" local name="$1"
@@ -49,11 +49,6 @@ is_valid_token() {
[[ $1 =~ ^[A-Za-z0-9_.~+/=-]{8,255}$ ]] [[ $1 =~ ^[A-Za-z0-9_.~+/=-]{8,255}$ ]]
} }
# OWNER/NAME of the framework repository on Gitea.
is_valid_framework_repo() {
[[ $1 =~ ^[A-Za-z0-9._-]+/[A-Za-z0-9._-]+$ && $1 != */.. && $1 != ../* && $1 != ./* && $1 != */. ]]
}
is_valid_port() { is_valid_port() {
[[ $1 =~ ^[0-9]{1,5}$ ]] && ((10#$1 >= 1 && 10#$1 <= 65535)) [[ $1 =~ ^[0-9]{1,5}$ ]] && ((10#$1 >= 1 && 10#$1 <= 65535))
} }
+6 -68
View File
@@ -23,7 +23,6 @@ readonly FAKE_GITHUB_PAT="ghpFAKEtoken1234567890"
readonly ANSWERS_GITHUB=$'my-app\nA test app\n\nTirSystem\ny\nacme-org\n\nn\n' readonly ANSWERS_GITHUB=$'my-app\nA test app\n\nTirSystem\ny\nacme-org\n\nn\n'
readonly ANSWERS_GITEA_ONLY=$'my-app\n\n\nTirSystem\nn\n\nn\n' readonly ANSWERS_GITEA_ONLY=$'my-app\n\n\nTirSystem\nn\n\nn\n'
SHARED_REMOTES=""
TESTS_RUN=0 TESTS_RUN=0
TESTS_FAILED=0 TESTS_FAILED=0
CURRENT_TEST="" CURRENT_TEST=""
@@ -92,61 +91,6 @@ assert_file_missing() {
new_workdir() { new_workdir() {
WORK="$(mktemp -d "${TMPDIR:-/tmp}/repofoundry-test.XXXXXX")" WORK="$(mktemp -d "${TMPDIR:-/tmp}/repofoundry-test.XXXXXX")"
mkdir -p "$WORK/bin" "$WORK/tmp" mkdir -p "$WORK/bin" "$WORK/tmp"
write_gitconfig
}
# write_gitconfig: the git configuration every test run uses instead of the
# real user's (GIT_CONFIG_GLOBAL), so no test depends on or changes it. The
# remote addresses of Gitea and the framework are redirected to local bare
# repositories (see setup_local_remotes); nothing reaches the network.
write_gitconfig() {
cat >"$WORK/gitconfig" <<EOF
[user]
name = Test User
email = test@example.test
[protocol "file"]
allow = always
[url "file://$WORK/remote/"]
insteadOf = https://git.example.test/
[url "file://$WORK/remote/"]
insteadOf = ssh://git@git.example.test:10022/
EOF
}
# ensure_shared_remotes: build, once per run of the suite, the local bare
# repositories that stand in for Gitea (TirSystem/my-app.git, holding the
# license commit) and for the framework (a copy of the real one).
ensure_shared_remotes() {
if [[ -n $SHARED_REMOTES && -d $SHARED_REMOTES ]]; then
return 0
fi
SHARED_REMOTES="$(mktemp -d "${TMPDIR:-/tmp}/repofoundry-remotes.XXXXXX")"
mkdir -p "$SHARED_REMOTES/TirSystem"
git clone -q --bare "$REPO_ROOT/framework" "$SHARED_REMOTES/TirSystem/SQA-QC-Framework.git"
git init -q --bare "$SHARED_REMOTES/TirSystem/my-app.git"
git init -q "$SHARED_REMOTES/seed"
git -C "$SHARED_REMOTES/seed" symbolic-ref HEAD refs/heads/main
printf 'GNU AFFERO GENERAL PUBLIC LICENSE (test copy)\n' >"$SHARED_REMOTES/seed/LICENSE"
git -C "$SHARED_REMOTES/seed" add LICENSE
git -c user.name=Seed -c user.email=seed@example.test -C "$SHARED_REMOTES/seed" commit -q -m "Initial commit"
git -C "$SHARED_REMOTES/seed" push -q "$SHARED_REMOTES/TirSystem/my-app.git" main
find "$SHARED_REMOTES/seed" \( -type f -o -type l \) -delete
find "$SHARED_REMOTES/seed" -depth -type d -exec rmdir {} +
}
# remove_shared_remotes: delete the shared repositories at the end of the run.
remove_shared_remotes() {
if [[ -n $SHARED_REMOTES && -d $SHARED_REMOTES ]]; then
find "$SHARED_REMOTES" \( -type f -o -type l \) -delete
find "$SHARED_REMOTES" -depth -type d -exec rmdir {} +
fi
SHARED_REMOTES=""
}
# setup_local_remotes: this test's own copy of the local remotes.
setup_local_remotes() {
ensure_shared_remotes
cp -R "$SHARED_REMOTES" "$WORK/remote"
} }
# remove_workdir: delete the work directory without a recursive rm: files # remove_workdir: delete the work directory without a recursive rm: files
@@ -244,9 +188,6 @@ STUB
write_ssh_stub() { write_ssh_stub() {
cat >"$WORK/bin/ssh" <<STUB cat >"$WORK/bin/ssh" <<STUB
#!/usr/bin/env bash #!/usr/bin/env bash
# The real ssh reads standard input until it ends; so does this stub. Whatever
# is left on the caller's stdin (the answers to later prompts) is lost to it.
cat >/dev/null
printf '%s\n' "\$@" >>"\$STUB_DIR/ssh.args" printf '%s\n' "\$@" >>"\$STUB_DIR/ssh.args"
if [[ ${1:-0} == 0 ]]; then if [[ ${1:-0} == 0 ]]; then
echo "Hi there, gitea-user! You've successfully authenticated, but Gitea does not provide shell access." echo "Hi there, gitea-user! You've successfully authenticated, but Gitea does not provide shell access."
@@ -304,7 +245,6 @@ setup_hosts() {
write_curl_stub write_curl_stub
write_ssh_stub 0 write_ssh_stub 0
write_happy_routes write_happy_routes
setup_local_remotes
} }
# calls: the "METHOD URL" lines the stub curl received (empty if none). # calls: the "METHOD URL" lines the stub curl received (empty if none).
@@ -320,11 +260,9 @@ run_cli() {
local input="$1" local input="$1"
shift shift
STATUS=0 STATUS=0
# Run inside the work directory: a relative project directory such as PATH="$WORK/bin:$PATH" STUB_DIR="$WORK" TMPDIR="$WORK/tmp" \
# ./my-app is then created there, never in the repository. REPOFOUNDRY_SYNC_WAIT=0 \
(cd "$WORK" && PATH="$WORK/bin:$PATH" STUB_DIR="$WORK" TMPDIR="$WORK/tmp" \ "$BASH" "$SCRIPT" "$@" <<<"$input" >"$WORK/out.txt" 2>"$WORK/err.txt" ||
REPOFOUNDRY_SYNC_WAIT=0 GIT_CONFIG_GLOBAL="$WORK/gitconfig" GIT_CONFIG_NOSYSTEM=1 \
"$BASH" "$SCRIPT" "$@" <<<"$input" >"$WORK/out.txt" 2>"$WORK/err.txt") ||
STATUS=$? STATUS=$?
OUT="$(cat "$WORK/out.txt")" OUT="$(cat "$WORK/out.txt")"
ERR="$(cat "$WORK/err.txt")" ERR="$(cat "$WORK/err.txt")"
@@ -339,9 +277,9 @@ run_lib() {
printf '#!/usr/bin/env bash\nsource "%s"\n' "$SCRIPT" printf '#!/usr/bin/env bash\nsource "%s"\n' "$SCRIPT"
printf '%s\n' "$2" printf '%s\n' "$2"
} >"$WORK/snippet.sh" } >"$WORK/snippet.sh"
(cd "$WORK" && PATH="$WORK/bin:$PATH" STUB_DIR="$WORK" TMPDIR="$WORK/tmp" \ PATH="$WORK/bin:$PATH" STUB_DIR="$WORK" TMPDIR="$WORK/tmp" \
REPOFOUNDRY_SYNC_WAIT=0 GIT_CONFIG_GLOBAL="$WORK/gitconfig" GIT_CONFIG_NOSYSTEM=1 \ REPOFOUNDRY_SYNC_WAIT=0 \
"$BASH" "$WORK/snippet.sh" <<<"$input" >"$WORK/out.txt" 2>"$WORK/err.txt") || "$BASH" "$WORK/snippet.sh" <<<"$input" >"$WORK/out.txt" 2>"$WORK/err.txt" ||
STATUS=$? STATUS=$?
OUT="$(cat "$WORK/out.txt")" OUT="$(cat "$WORK/out.txt")"
ERR="$(cat "$WORK/err.txt")" ERR="$(cat "$WORK/err.txt")"
-1
View File
@@ -68,7 +68,6 @@ for test_file in "$TEST_DIR"/test-*.sh; do
done < <(declare -F | awk '$3 ~ /^test_/ {print $3}') done < <(declare -F | awk '$3 ~ /^test_/ {print $3}')
done done
remove_shared_remotes
printf '\n%d checks, %d failed, %d static check(s) failed\n' \ printf '\n%d checks, %d failed, %d static check(s) failed\n' \
"$TESTS_RUN" "$TESTS_FAILED" "$failed_checks" "$TESTS_RUN" "$TESTS_FAILED" "$failed_checks"
if ((TESTS_FAILED > 0 || failed_checks > 0)); then if ((TESTS_FAILED > 0 || failed_checks > 0)); then
+1 -12
View File
@@ -158,21 +158,10 @@ test_example_files_hold_placeholders_only() {
fail ".env.example has a value for ${line%%=*}; it must be empty" fail ".env.example has a value for ${line%%=*}; it must be empty"
fi fi
done < <(grep -E '^[A-Z_]+=' "$REPO_ROOT/.env.example") done < <(grep -E '^[A-Z_]+=' "$REPO_ROOT/.env.example")
# The example holds a placeholder for the Gitea address, so it must be
# edited before use: as it is, it is refused with a clear message...
run_lib "" "parse_env_file \"$REPO_ROOT/config.env.example\" CONFIG_KEYS CONFIG run_lib "" "parse_env_file \"$REPO_ROOT/config.env.example\" CONFIG_KEYS CONFIG
validate_config validate_config
echo parsed" echo parsed"
assert_status "placeholder address is refused" 1 "$STATUS" assert_contains "config.env.example is valid" "$OUT" "parsed"
assert_contains "names the key" "$ERR" "GITEA_URL"
# ...and with a real address in its place the rest of the file is valid.
sed -e 's|^GITEA_URL=.*|GITEA_URL=https://git.example.test/|' \
-e 's|^GITEA_API_URL=.*|GITEA_API_URL=https://git.example.test/api/v1|' \
"$REPO_ROOT/config.env.example" >"$WORK/example.env"
run_lib "" "parse_env_file \"$WORK/example.env\" CONFIG_KEYS CONFIG
validate_config
echo parsed"
assert_contains "config.env.example is valid once the address is set" "$OUT" "parsed"
run_lib "" "parse_env_file \"$REPO_ROOT/.env.example\" CREDENTIAL_KEYS CREDENTIALS run_lib "" "parse_env_file \"$REPO_ROOT/.env.example\" CREDENTIAL_KEYS CREDENTIALS
echo parsed" echo parsed"
assert_contains ".env.example parses" "$OUT" "parsed" assert_contains ".env.example parses" "$OUT" "parsed"
-42
View File
@@ -264,9 +264,6 @@ test_apply_declined_creates_nothing() {
test_apply_for_user_owners_uses_the_user_endpoints() { test_apply_for_user_owners_uses_the_user_endpoints() {
setup_hosts setup_hosts
# The Gitea account's own repository (with the license commit) is a copy.
mkdir -p "$WORK/remote/gitea-user"
cp -R "$WORK/remote/TirSystem/my-app.git" "$WORK/remote/gitea-user/my-app.git"
write_routes <<'ROUTES' write_routes <<'ROUTES'
GET|/api/v1/user|200|{"login":"gitea-user"} GET|/api/v1/user|200|{"login":"gitea-user"}
GET|/api/v1/licenses|200|[{"key":"AGPL-3.0"}] GET|/api/v1/licenses|200|[{"key":"AGPL-3.0"}]
@@ -476,42 +473,3 @@ mirror_field '$WORK/m.json' https://github.com/o/b.git sync_on_commit"
assert_eq "the right mirror is chosen with jq" "true" "$OUT" assert_eq "the right mirror is chosen with jq" "true" "$OUT"
fi fi
} }
# ------------------------------------------------- found by the live e2e run
test_a_repository_this_script_created_earlier_can_be_reused() {
# Seen on a real Gitea: creating a repository with a license also adds a
# README.md. After a failed mirror step the next run must still reuse it.
setup_hosts
prepend_route 'GET|/api/v1/repos/TirSystem/my-app|200|{"empty":false}'
prepend_route 'GET|/api/v1/repos/TirSystem/my-app/contents|200|[{"name":"README.md","type":"file"},{"name":"LICENSE","type":"file"}]'
run_apply "$ANSWERS_GITHUB"$'y\ny\n'
assert_status "LICENSE and README.md" 0 "$STATUS"
assert_not_contains "not created again" "$(calls)" "$GITEA_REPO_CALL"
assert_contains "reported" "$OUT" "Gitea repository : reused"
}
test_other_files_still_count_as_content() {
local listing
for listing in '[{"name":"README.md","type":"file"}]' \
'[{"name":"LICENSE","type":"file"},{"name":"README.md","type":"file"},{"name":"main.c","type":"file"}]' \
'[{"name":"LICENSE","type":"file"},{"name":"src","type":"dir"}]'; do
setup_hosts
prepend_route 'GET|/api/v1/repos/TirSystem/my-app|200|{"empty":false}'
prepend_route "GET|/api/v1/repos/TirSystem/my-app/contents|200|$listing"
run_dry "$ANSWERS_GITHUB"
assert_status "content: $listing" 1 "$STATUS"
assert_contains "refused" "$ERR" "already exists and has content"
done
}
test_children_never_eat_the_answers_meant_for_later_prompts() {
# The real ssh reads standard input until it ends; the stub does too. The
# script closes stdin for ssh, git, curl and the framework scripts, so the
# answers that follow the SSH test still reach the later prompts.
setup_hosts
run_apply "$ANSWERS_GITHUB"$'y\n'
assert_status "the final question is still answered" 0 "$STATUS"
assert_contains "created" "$OUT" "Done. This is what exists now:"
assert_not_contains "no lost input" "$ERR" "no input available"
}
-431
View File
@@ -1,431 +0,0 @@
#!/usr/bin/env bash
# test-local.sh - tests for the local project (MIL-003): the directory, the
# git repository and its remotes, the framework submodule, skills, hooks and
# plan gate, and the templates. Real git runs here, against local bare
# repositories that stand in for Gitea and the framework (git rewrites the
# remote addresses, see write_gitconfig); only the two hosts' APIs are stubs.
# Sourced by run-tests.sh.
# shellcheck disable=SC2016 # snippet and fixture text is literal on purpose
# local_answers DIR GITHUB GATE: the prompt answers; the result is in
# LOCAL_ANSWERS (kept in a variable because $(...) would drop the last newline).
local_answers() {
if [[ $2 == y ]]; then
printf -v LOCAL_ANSWERS 'my-app\nA test app\n\nTirSystem\ny\nacme-org\n%s\n%s\n' "$1" "$3"
else
printf -v LOCAL_ANSWERS 'my-app\n\n\nTirSystem\nn\n%s\n%s\n' "$1" "$3"
fi
}
# project_git DIR ARGS...: git in the project with the tests' own config.
project_git() {
local dir="$1"
shift
GIT_CONFIG_GLOBAL="$WORK/gitconfig" GIT_CONFIG_NOSYSTEM=1 git -C "$dir" "$@"
}
# files_with_secret DIR: any file below DIR (the .git folder included) that
# holds one of the fake tokens.
files_with_secret() {
grep -rlF -e "$FAKE_GITEA_TOKEN" -e "$FAKE_GITHUB_PAT" "$1" 2>/dev/null || true
}
readonly SSH_FRAMEWORK_URL="ssh://git@git.example.test:10022/TirSystem/SQA-QC-Framework.git"
# ----------------------------------------------------- directory and remotes
test_local_project_gets_credential_free_remotes_and_the_license_history() {
setup_hosts
local dir="$WORK/project"
local_answers "$dir" y n
run_apply "$LOCAL_ANSWERS"$'y\n'
assert_status "apply" 0 "$STATUS"
assert_file_exists "directory created" "$dir/.git"
assert_eq "branch is main" "main" "$(project_git "$dir" symbolic-ref --short HEAD)"
assert_eq "origin over SSH, no credential" "ssh://git@git.example.test:10022/TirSystem/my-app.git" "$(project_git "$dir" config --get remote.origin.url)"
assert_eq "github remote over HTTPS, no credential" "https://github.com/acme-org/my-app.git" "$(project_git "$dir" config --get remote.github.url)"
assert_eq "the license commit is the whole history" "1" "$(project_git "$dir" rev-list --count HEAD)"
assert_eq "it is the Gitea commit" "Initial commit" "$(project_git "$dir" log -1 --format=%s)"
assert_file_exists "LICENSE from Gitea" "$dir/LICENSE"
assert_eq "branch follows origin" "origin" "$(project_git "$dir" config --get branch.main.remote)"
assert_eq "no token in any file of the project" "" "$(files_with_secret "$dir")"
assert_contains "reported" "$OUT" "Local project : created $dir (origin over SSH)"
}
test_gitea_only_project_has_no_github_remote_and_no_commit() {
setup_hosts
printf 'GITEA_TOKEN=%s\n' "$FAKE_GITEA_TOKEN" >"$WORK/.env"
local dir="$WORK/project"
local_answers "$dir" n n
run_apply "$LOCAL_ANSWERS"$'y\n'
assert_status "apply" 0 "$STATUS"
assert_eq "origin" "ssh://git@git.example.test:10022/TirSystem/my-app.git" "$(project_git "$dir" config --get remote.origin.url)"
assert_eq "no github remote" "" "$(project_git "$dir" config --get remote.github.url || true)"
assert_file_missing "no license file" "$dir/LICENSE"
assert_eq "no commit was made" "0" "$(project_git "$dir" rev-list --all --count)"
assert_eq "no token in any file" "" "$(files_with_secret "$dir")"
}
test_existing_directory_is_used_only_after_a_yes() {
setup_hosts
local dir="$WORK/project"
mkdir -p "$dir"
printf 'mine\n' >"$dir/keep.txt"
local_answers "$dir" y n
run_apply "$LOCAL_ANSWERS"$'y\nn\n'
assert_status "answered no" 1 "$STATUS"
assert_contains "asked" "$ERR" "The directory $dir already exists and already has files. Use it"
assert_contains "stopped" "$ERR" "stopped: choose another directory or remove this one"
assert_file_missing "nothing added to the directory" "$dir/.git"
assert_not_contains "no repository created before the answer" "$(calls)" "POST"
run_apply "$LOCAL_ANSWERS"$'y\ny\n'
assert_status "answered yes" 0 "$STATUS"
assert_eq "the existing file is untouched" "mine" "$(cat "$dir/keep.txt")"
assert_file_exists "project created beside it" "$dir/.git"
}
test_an_empty_existing_directory_is_also_confirmed() {
setup_hosts
local dir="$WORK/project"
mkdir -p "$dir"
local_answers "$dir" y n
run_apply "$LOCAL_ANSWERS"$'y\ny\n'
assert_status "empty directory, yes" 0 "$STATUS"
assert_contains "asked" "$ERR" "already exists and is empty. Use it"
}
test_a_file_that_would_be_overwritten_by_the_license_history_is_kept() {
setup_hosts
local dir="$WORK/project"
mkdir -p "$dir"
printf 'my own license\n' >"$dir/LICENSE"
local_answers "$dir" y n
run_apply "$LOCAL_ANSWERS"$'y\ny\n'
assert_status "git refuses to overwrite" 1 "$STATUS"
assert_contains "says why" "$ERR" "git would overwrite files in $dir"
assert_eq "the file is intact" "my own license" "$(cat "$dir/LICENSE")"
assert_contains "step failed" "$OUT" "Local project : FAILED"
assert_contains "later steps not attempted" "$OUT" "Framework : not attempted"
}
test_a_remote_with_another_address_is_never_replaced() {
setup_hosts
local dir="$WORK/project"
mkdir -p "$dir"
project_git "$dir" init -q
project_git "$dir" remote add origin https://elsewhere.example.test/x/y.git
local_answers "$dir" y n
run_apply "$LOCAL_ANSWERS"$'y\ny\n'
assert_status "different origin" 1 "$STATUS"
assert_contains "says so" "$ERR" "the remote 'origin' in $dir already points to https://elsewhere.example.test/x/y.git"
assert_eq "origin unchanged" "https://elsewhere.example.test/x/y.git" "$(project_git "$dir" config --get remote.origin.url)"
}
# ---------------------------------------------------------------- framework
test_framework_is_a_submodule_and_installed_in_order() {
setup_hosts
local dir="$WORK/project"
local_answers "$dir" y n
run_apply "$LOCAL_ANSWERS"$'y\n'
assert_status "apply" 0 "$STATUS"
assert_eq "submodule address" "$SSH_FRAMEWORK_URL" "$(project_git "$dir" config -f .gitmodules --get submodule.framework.url)"
assert_file_exists "submodule content" "$dir/framework/scripts/install-skills.sh"
assert_file_exists "skills installed" "$dir/.claude/skills/coding-conventions/SKILL.md"
assert_file_exists "skills for the other harness" "$dir/.agents/skills/.framework-skills"
assert_eq "hooks path" "framework/githooks" "$(project_git "$dir" config --local --get core.hooksPath)"
assert_eq "plan gate off" "" "$(project_git "$dir" config --local --get planGate.enabled || true)"
assert_contains "reported" "$OUT" "Framework : created $SSH_FRAMEWORK_URL"
assert_contains "reported once" "$OUT" "Skills and hooks : created (skills installed; hooks installed; plan gate off)"
}
test_skills_and_hooks_are_installed_once() {
setup_hosts
local dir="$WORK/project"
local_answers "$dir" y n
run_apply "$LOCAL_ANSWERS"$'y\n'
assert_status "first run" 0 "$STATUS"
run_lib "" "PROJECT[directory]='$dir'
PROJECT[is_plan_gate_enabled]=0
install_framework
echo \"\${STATE[skills_note]}|\${STATE[hooks_note]}\""
assert_status "second pass" 0 "$STATUS"
assert_eq "nothing installed twice" "skills already installed|hooks already installed" "$OUT"
}
test_the_plan_gate_is_optional_and_refuses_unplanned_commits() {
setup_hosts
local dir="$WORK/project" out
local_answers "$dir" y y
run_apply "$LOCAL_ANSWERS"$'y\n'
assert_status "apply with the plan gate" 0 "$STATUS"
assert_eq "plan gate on" "true" "$(project_git "$dir" config --local --get planGate.enabled)"
assert_contains "reported" "$OUT" "plan gate on)"
# The hooks refuse a commit on main, so work on a branch.
project_git "$dir" checkout -q -b work
mkdir -p "$dir/src"
printf 'x\n' >"$dir/src/x.txt"
project_git "$dir" add src/x.txt
out="$(project_git "$dir" commit -q -m "unplanned change" 2>&1 || true)"
assert_contains "refused without a task trailer" "$out" "plan-first gate: no 'Task: MIL-NNN#N' trailer"
assert_eq "no commit was made" "1" "$(project_git "$dir" rev-list --count HEAD)"
}
test_without_the_plan_gate_the_same_commit_is_allowed() {
setup_hosts
local dir="$WORK/project"
local_answers "$dir" y n
run_apply "$LOCAL_ANSWERS"$'y\n'
project_git "$dir" checkout -q -b work
mkdir -p "$dir/src"
printf 'x\n' >"$dir/src/x.txt"
project_git "$dir" add src/x.txt
project_git "$dir" commit -q -m "change"
assert_eq "commit made" "2" "$(project_git "$dir" rev-list --count HEAD)"
}
test_the_hooks_refuse_a_commit_on_main() {
setup_hosts
local dir="$WORK/project" out
local_answers "$dir" y n
run_apply "$LOCAL_ANSWERS"$'y\n'
printf 'x\n' >"$dir/x.txt"
project_git "$dir" add x.txt
out="$(project_git "$dir" commit -q -m "on main" 2>&1 || true)"
assert_contains "refused on main" "$out" "refusing to commit directly on 'main'"
}
test_an_existing_hooks_path_is_not_replaced_without_a_yes() {
setup_hosts
local dir="$WORK/project"
mkdir -p "$dir"
project_git "$dir" init -q
project_git "$dir" config core.hooksPath .githooks
local_answers "$dir" y y
# create now, use the directory, keep the hooks path
run_apply "$LOCAL_ANSWERS"$'y\ny\nn\n'
assert_status "run continues" 0 "$STATUS"
assert_contains "asked" "$ERR" "core.hooksPath is already '.githooks'. Replace it with framework/githooks"
assert_eq "hooks path kept" ".githooks" "$(project_git "$dir" config --local --get core.hooksPath)"
assert_contains "reported" "$OUT" "kept the existing hooks path '.githooks'"
assert_contains "the plan gate is not on without the hooks" "$ERR" "the plan gate is not enabled because the framework hooks were not installed"
# Answering yes replaces it.
run_apply "$LOCAL_ANSWERS"$'y\ny\ny\n'
assert_eq "hooks path replaced after a yes" "framework/githooks" "$(project_git "$dir" config --local --get core.hooksPath)"
}
test_a_global_hooks_path_is_reported_not_changed() {
setup_hosts
git config --file "$WORK/gitconfig" core.hooksPath global-hooks-dir
local dir="$WORK/project"
local_answers "$dir" y n
run_apply "$LOCAL_ANSWERS"$'y\n'
assert_status "apply" 0 "$STATUS"
assert_contains "warns" "$ERR" "your global core.hooksPath is 'global-hooks-dir'"
assert_eq "the global setting is untouched" "global-hooks-dir" "$(git config --file "$WORK/gitconfig" --get core.hooksPath)"
assert_eq "the project has its own" "framework/githooks" "$(project_git "$dir" config --local --get core.hooksPath)"
}
test_a_project_root_in_the_environment_cannot_redirect_the_framework_scripts() {
setup_hosts
local dir="$WORK/project"
local_answers "$dir" y n
PROJECT_ROOT="$WORK/elsewhere" run_apply "$LOCAL_ANSWERS"$'y\n'
assert_status "apply" 0 "$STATUS"
assert_file_missing "nothing installed where the environment pointed" "$WORK/elsewhere"
assert_file_exists "installed in the project" "$dir/.claude/skills/.framework-skills"
}
# ---------------------------------------------------------------- templates
test_templates_are_copied() {
setup_hosts
local dir="$WORK/project"
local_answers "$dir" y n
run_apply "$LOCAL_ANSWERS"$'y\n'
assert_status "apply" 0 "$STATUS"
assert_eq "AGENTS.md is the template" "$(cat "$dir/framework/templates/AGENTS-template.md")" "$(cat "$dir/AGENTS.md")"
assert_eq "registry is the template" "$(cat "$dir/framework/templates/artifact-registry-template.md")" "$(cat "$dir/docs/artifact-registry.md")"
assert_contains "reported" "$OUT" "Templates : created (copied AGENTS.md; copied docs/artifact-registry.md)"
}
test_existing_template_targets_are_replaced_only_after_a_yes() {
setup_hosts
local dir="$WORK/project"
mkdir -p "$dir/docs"
printf 'my agents file\n' >"$dir/AGENTS.md"
printf 'my registry\n' >"$dir/docs/artifact-registry.md"
local_answers "$dir" y n
# create now, use the directory, keep AGENTS.md, replace the registry
run_apply "$LOCAL_ANSWERS"$'y\ny\nn\ny\n'
assert_status "apply" 0 "$STATUS"
assert_contains "asked about AGENTS.md" "$ERR" "AGENTS.md already exists. Replace it with the framework template"
assert_eq "AGENTS.md kept" "my agents file" "$(cat "$dir/AGENTS.md")"
assert_eq "registry replaced after a yes" "$(cat "$dir/framework/templates/artifact-registry-template.md")" "$(cat "$dir/docs/artifact-registry.md")"
assert_contains "reported" "$OUT" "kept existing AGENTS.md; copied docs/artifact-registry.md"
}
# ----------------------------------------------------------- SSH and errors
test_without_ssh_the_run_stops_unless_the_framework_is_skipped() {
setup_hosts
write_ssh_stub 255
local dir="$WORK/project"
local_answers "$dir" y n
run_apply "$LOCAL_ANSWERS"$'y\nn\n'
assert_status "answered no" 1 "$STATUS"
assert_contains "explains" "$ERR" "SSH to Gitea (git.example.test port 10022) did not work, so the framework cannot be added"
assert_contains "says what to do" "$ERR" "stopped: set up SSH access to Gitea (see the README) and run again"
assert_not_contains "nothing created" "$(calls)" "POST"
assert_file_missing "no directory" "$dir"
}
test_without_ssh_the_framework_steps_are_skipped_after_a_yes() {
setup_hosts
write_ssh_stub 255
local dir="$WORK/project"
local_answers "$dir" y n
run_apply "$LOCAL_ANSWERS"$'y\ny\n'
assert_status "continue without the framework" 0 "$STATUS"
assert_eq "origin over HTTPS, no credential" "https://git.example.test/TirSystem/my-app.git" "$(project_git "$dir" config --get remote.origin.url)"
assert_eq "the license history arrived over HTTPS" "1" "$(project_git "$dir" rev-list --count HEAD)"
assert_eq "no token in any file" "" "$(files_with_secret "$dir")"
assert_eq "no temporary files left" "" "$(find "$WORK/tmp" -mindepth 1)"
assert_contains "framework skipped" "$OUT" "Framework : skipped (no SSH access to Gitea)"
assert_contains "skills and hooks skipped" "$OUT" "Skills and hooks : skipped (no SSH access to Gitea)"
assert_contains "templates skipped" "$OUT" "Templates : skipped (no SSH access to Gitea)"
assert_file_missing "no submodule" "$dir/.gitmodules"
assert_file_missing "no AGENTS.md" "$dir/AGENTS.md"
}
test_a_failed_submodule_gives_an_actionable_message() {
setup_hosts
find "$WORK/remote/TirSystem/SQA-QC-Framework.git" \( -type f -o -type l \) -delete
find "$WORK/remote/TirSystem/SQA-QC-Framework.git" -depth -type d -exec rmdir {} +
local dir="$WORK/project"
local_answers "$dir" y n
run_apply "$LOCAL_ANSWERS"$'y\n'
assert_status "no framework repository" 1 "$STATUS"
assert_contains "names the address" "$ERR" "git could not add the framework from $SSH_FRAMEWORK_URL"
assert_contains "says how to test the access" "$ERR" "ssh -p 10022 -T git@git.example.test"
assert_contains "step failed" "$OUT" "Framework : FAILED"
assert_contains "the rest not attempted" "$OUT" "Skills and hooks : not attempted"
assert_contains "the project itself exists" "$OUT" "Local project : created"
}
test_the_framework_repository_is_configurable() {
setup_hosts
mkdir -p "$WORK/remote/Other"
cp -R "$WORK/remote/TirSystem/SQA-QC-Framework.git" "$WORK/remote/Other/Framework.git"
printf 'FRAMEWORK_REPO=Other/Framework\n' >>"$WORK/config.env"
local dir="$WORK/project"
local_answers "$dir" y n
run_apply "$LOCAL_ANSWERS"$'y\n'
assert_status "apply" 0 "$STATUS"
assert_eq "submodule address" "ssh://git@git.example.test:10022/Other/Framework.git" "$(project_git "$dir" config -f .gitmodules --get submodule.framework.url)"
}
test_framework_repo_must_look_like_owner_and_name() {
local value
for value in "nope" "a/b/c" "../x" "a/.." "a b/c" "/x"; do
printf 'GITEA_URL=https://git.example.test\nFRAMEWORK_REPO=%s\n' "$value" >"$WORK/c.env"
run_lib "" "parse_env_file \"$WORK/c.env\" CONFIG_KEYS CONFIG
validate_config"
assert_status "FRAMEWORK_REPO=$value" 1 "$STATUS"
assert_contains "message" "$ERR" "FRAMEWORK_REPO"
done
}
# --------------------------------------------------------------- the plan
test_the_dry_run_plan_describes_the_local_steps_and_creates_nothing() {
setup_hosts
local dir="$WORK/project"
local_answers "$dir" y y
run_dry "$LOCAL_ANSWERS"
assert_status "dry run" 0 "$STATUS"
assert_contains "project" "$OUT" "Local project : create $dir (new directory), git on main, no commit"
assert_contains "framework" "$OUT" "Framework : add $SSH_FRAMEWORK_URL as a submodule"
assert_contains "skills and hooks" "$OUT" "Skills and hooks : install once; plan gate yes"
assert_contains "templates" "$OUT" "Templates : AGENTS.md and docs/artifact-registry.md (you are asked before a file is replaced)"
assert_file_missing "nothing created" "$dir"
}
test_the_plan_marks_an_existing_directory_and_missing_ssh() {
setup_hosts
local dir="$WORK/project"
mkdir -p "$dir"
printf 'x\n' >"$dir/a.txt"
write_ssh_stub 255
local_answers "$dir" y n
run_dry "$LOCAL_ANSWERS"
assert_contains "existing directory" "$OUT" "use the existing directory $dir, which has files (you will be asked)"
assert_contains "no SSH" "$OUT" "NOT possible without SSH to Gitea; you will be asked whether to go on without it"
assert_contains "HTTPS origin" "$OUT" "will use HTTPS (SSH test: failed"
}
test_a_project_path_that_is_a_file_is_refused_in_the_preflight() {
setup_hosts
local dir="$WORK/project"
printf 'x\n' >"$dir"
local_answers "$dir" y n
run_dry "$LOCAL_ANSWERS"
assert_status "path is a file" 1 "$STATUS"
assert_contains "message" "$ERR" "already exists and is not a directory"
}
# ------------------------------------------------------------------ helpers
test_remote_addresses_are_built_from_the_configuration() {
run_lib "" 'CONFIG[GITEA_URL]=https://git.example.test/sub
CONFIG[GITEA_SSH_PORT]=2222 CONFIG[FRAMEWORK_REPO]=Org/Fw CONFIG[GITHUB_WEB_URL]=https://github.com
PROJECT[gitea_owner]=TirSystem PROJECT[github_owner]=acme PROJECT[name]=my-app
STATE[is_ssh_ok]=1
origin_url; echo
STATE[is_ssh_ok]=0
origin_url; echo
github_remote_url; echo
framework_url; echo
gitea_host; echo'
assert_eq "addresses" $'ssh://git@git.example.test:2222/TirSystem/my-app.git\nhttps://git.example.test/sub/TirSystem/my-app.git\nhttps://github.com/acme/my-app.git\nssh://git@git.example.test:2222/Org/Fw.git\ngit.example.test' "$OUT"
}
test_the_https_fetch_hands_the_token_over_through_the_environment_only() {
# A stub git plays the part of the server asking for credentials: it runs
# the GIT_ASKPASS helper the way git does and records the answers.
local real_git
real_git="$(command -v git)"
write_stub git "
if [[ \$* == *'config --get remote.origin.url'* ]]; then echo https://git.example.test/TirSystem/my-app.git; exit 0; fi
if [[ \$* == *fetch* ]]; then
printf '%s\n' \"\$@\" >>\"\$STUB_DIR/git.args\"
\"\$GIT_ASKPASS\" 'Username for https://git.example.test: ' >>\"\$STUB_DIR/askpass.out\"
\"\$GIT_ASKPASS\" 'Password for https://git.example.test: ' >>\"\$STUB_DIR/askpass.out\"
exit 0
fi
exec '$real_git' \"\$@\""
run_lib "" "setup_temp_dir
STATE[gitea_login]=gitea-user
CREDENTIALS[GITEA_TOKEN]='$FAKE_GITEA_TOKEN'
fetch_origin '$WORK'
cleanup"
assert_status "fetch" 0 "$STATUS"
assert_eq "user name and token reach git" $'gitea-user\n'"$FAKE_GITEA_TOKEN" "$(cat "$WORK/askpass.out")"
assert_not_contains "token not on the git command line" "$(cat "$WORK/git.args")" "$FAKE_GITEA_TOKEN"
assert_eq "the helper is removed" "" "$(find "$WORK/tmp" -mindepth 1)"
}
test_a_failed_https_fetch_is_reported_to_the_caller() {
write_stub git "
if [[ \$* == *'config --get remote.origin.url'* ]]; then echo https://git.example.test/TirSystem/my-app.git; exit 0; fi
if [[ \$* == *fetch* ]]; then exit 128; fi
exit 0"
run_lib "" "setup_temp_dir
STATE[gitea_login]=gitea-user
CREDENTIALS[GITEA_TOKEN]='$FAKE_GITEA_TOKEN'
if fetch_origin '$WORK'; then echo ok; else echo failed; fi
cleanup"
assert_eq "failure passed on" "failed" "$OUT"
assert_eq "the helper is removed" "" "$(find "$WORK/tmp" -mindepth 1)"
}
-275
View File
@@ -1,275 +0,0 @@
#!/usr/bin/env bash
# test-presets.sh - tests for the project details preset in config.env
# (MIL-004): a detail that is set there is not asked, an invalid one stops
# the run, and the confirmations stay interactive. Sourced by run-tests.sh.
# shellcheck disable=SC2016 # snippet and fixture text is literal on purpose
# The eight keys with a value that differs from the answer given when asked.
readonly PRESET_ALL='PROJECT_NAME=preset-app
PROJECT_DESCRIPTION=From the config
PROJECT_VISIBILITY=public
GITEA_OWNER=PresetOrg
USE_GITHUB=yes
GITHUB_OWNER=preset-gh
PROJECT_DIRECTORY=./preset-dir
ENABLE_PLAN_GATE=yes'
# The same details as ANSWERS_GITHUB, so a run with all of them preset is the
# same run with no answers.
readonly PRESET_LIKE_ANSWERS='PROJECT_NAME=my-app
PROJECT_DESCRIPTION=A test app
PROJECT_VISIBILITY=private
GITEA_OWNER=TirSystem
USE_GITHUB=yes
GITHUB_OWNER=acme-org
PROJECT_DIRECTORY=./my-app
ENABLE_PLAN_GATE=no'
# collect_with PRESET_LINES INPUT: parse a config holding the preset lines,
# collect the details and print them one per line.
collect_with() {
printf '%s\n' "$1" >"$WORK/preset.env"
run_lib "$2" 'parse_env_file "'"$WORK"'/preset.env" CONFIG_KEYS CONFIG
validate_project_presets
collect_project_details
for k in name description visibility gitea_owner has_github github_owner directory is_plan_gate_enabled; do
printf "%s=%s\n" "$k" "${PROJECT[$k]}"
done'
}
# Each key, the answers a run gives for the other seven details, and the
# prompt that must not be shown for the key.
test_each_key_is_used_and_not_asked() {
local key value field label line input
local -A answer=([PROJECT_NAME]=asked-app [PROJECT_DESCRIPTION]="Asked description"
[PROJECT_VISIBILITY]=private [GITEA_OWNER]=AskedOrg [USE_GITHUB]=y
[GITHUB_OWNER]=asked-gh [PROJECT_DIRECTORY]=./asked-dir [ENABLE_PLAN_GATE]=n)
local order=(PROJECT_NAME PROJECT_DESCRIPTION PROJECT_VISIBILITY GITEA_OWNER
USE_GITHUB GITHUB_OWNER PROJECT_DIRECTORY ENABLE_PLAN_GATE)
while IFS='|' read -r key value field label; do
input=""
for line in "${order[@]}"; do
if [[ $line != "$key" ]]; then
input+="${answer[$line]}"$'\n'
fi
done
collect_with "$key=$value" "$input"
assert_status "$key preset" 0 "$STATUS"
assert_contains "$key value used" "$OUT" "$field"
assert_not_contains "$key not asked" "$ERR" "$label"
assert_contains "other details still asked" "$OUT" "asked"
done <<'EOF'
PROJECT_NAME|preset-app|name=preset-app|Repository name
PROJECT_DESCRIPTION|From the config|description=From the config|Description
PROJECT_VISIBILITY|public|visibility=public|Visibility
GITEA_OWNER|PresetOrg|gitea_owner=PresetOrg|Gitea owner
USE_GITHUB|yes|has_github=1|Also create a GitHub
GITHUB_OWNER|preset-gh|github_owner=preset-gh|GitHub owner
PROJECT_DIRECTORY|./preset-dir|directory=./preset-dir|Local directory
ENABLE_PLAN_GATE|yes|is_plan_gate_enabled=1|Enable the plan gate
EOF
}
test_all_keys_set_asks_nothing() {
collect_with "$PRESET_ALL" ""
assert_status "no input needed" 0 "$STATUS"
assert_eq "every value from the config" $'name=preset-app\ndescription=From the config\nvisibility=public\ngitea_owner=PresetOrg\nhas_github=1\ngithub_owner=preset-gh\ndirectory=./preset-dir\nis_plan_gate_enabled=1' "$OUT"
assert_eq "no prompt text at all" "" "$ERR"
}
test_absent_keys_are_asked_as_before() {
collect_with "PROJECT_NAME=preset-app" $'\n\nTirSystem\nn\n\nn\n'
assert_status "mixed" 0 "$STATUS"
assert_contains "preset name" "$OUT" "name=preset-app"
assert_contains "default directory from the preset name" "$OUT" "directory=./preset-app"
assert_contains "other details asked" "$ERR" "Gitea owner"
}
test_values_are_taken_in_any_case() {
collect_with $'PROJECT_VISIBILITY=PUBLIC\nUSE_GITHUB=No\nENABLE_PLAN_GATE=YES' $'x-app\n\nTirSystem\n\n'
assert_status "case ignored" 0 "$STATUS"
assert_contains "visibility" "$OUT" "visibility=public"
assert_contains "no GitHub" "$OUT" "has_github=0"
assert_contains "plan gate" "$OUT" "is_plan_gate_enabled=1"
}
# ------------------------------------------------------- empty and invalid
test_empty_value_counts_as_set_only_for_the_description() {
collect_with "PROJECT_DESCRIPTION=" $'my-app\npublic\nTirSystem\nn\n\nn\n'
assert_status "empty description accepted" 0 "$STATUS"
assert_contains "description empty" "$OUT" "description="
assert_not_contains "description not asked" "$ERR" "Description"
local key
for key in PROJECT_NAME PROJECT_VISIBILITY GITEA_OWNER USE_GITHUB GITHUB_OWNER \
PROJECT_DIRECTORY ENABLE_PLAN_GATE; do
printf '%s=\n' "$key" >"$WORK/preset.env"
run_lib "" 'parse_env_file "'"$WORK"'/preset.env" CONFIG_KEYS CONFIG
validate_project_presets'
assert_status "$key empty" 1 "$STATUS"
assert_contains "$key named" "$ERR" "$key in"
assert_contains "$key says empty" "$ERR" "is empty"
done
}
test_invalid_values_are_refused_naming_the_key() {
local key value
while IFS='|' read -r key value; do
printf '%s=%s\n' "$key" "$value" >"$WORK/preset.env"
run_lib "" 'parse_env_file "'"$WORK"'/preset.env" CONFIG_KEYS CONFIG
validate_project_presets'
assert_status "$key=$value" 1 "$STATUS"
assert_contains "$key=$value named" "$ERR" "$key in"
done <<'EOF'
PROJECT_NAME|bad name
PROJECT_NAME|x.git
PROJECT_VISIBILITY|internal
GITEA_OWNER|-lead
USE_GITHUB|maybe
USE_GITHUB|1
GITHUB_OWNER|octo_user
PROJECT_DIRECTORY|-rf
ENABLE_PLAN_GATE|true
EOF
# A description over the limit (350 characters) is refused too.
printf 'PROJECT_DESCRIPTION=%s\n' "$(printf 'a%.0s' $(seq 1 351))" >"$WORK/preset.env"
run_lib "" 'parse_env_file "'"$WORK"'/preset.env" CONFIG_KEYS CONFIG
validate_project_presets'
assert_status "long description" 1 "$STATUS"
assert_contains "named" "$ERR" "PROJECT_DESCRIPTION in"
}
test_invalid_value_stops_before_any_request_and_never_asks() {
setup_hosts
printf 'PROJECT_NAME=bad name\n' >>"$WORK/config.env"
run_apply ""
assert_status "stopped" 1 "$STATUS"
assert_contains "key named" "$ERR" "PROJECT_NAME in"
assert_not_contains "no value asked instead" "$ERR" "Repository name:"
assert_eq "no request made" "" "$(calls)"
}
test_new_keys_are_rejected_in_env_and_credentials_in_config() {
setup_hosts
printf 'PROJECT_NAME=my-app\n' >>"$WORK/.env"
run_dry ""
assert_status ".env with a project key" 1 "$STATUS"
assert_contains "unknown in .env" "$ERR" "unknown key 'PROJECT_NAME'"
setup_hosts
printf 'GITEA_TOKEN=abcdefgh12345\n' >>"$WORK/config.env"
run_dry ""
assert_status "config.env with a credential" 1 "$STATUS"
assert_contains "credential refused" "$ERR" "is a credential"
}
# ------------------------------------------------------------- GitHub
test_use_github_no_skips_the_owner_and_warns_about_a_stray_one() {
collect_with $'USE_GITHUB=no\nGITHUB_OWNER=acme-org' $'my-app\n\n\nTirSystem\n\nn\n'
assert_status "GitHub off" 0 "$STATUS"
assert_contains "no GitHub" "$OUT" "has_github=0"
assert_contains "no owner" "$OUT" "github_owner="
assert_not_contains "owner not asked" "$ERR" "GitHub owner ("
assert_contains "ignored with a warning" "$ERR" "GITHUB_OWNER in"
assert_contains "says why" "$ERR" "ignored because GitHub is not used"
collect_with "USE_GITHUB=no" $'my-app\n\n\nTirSystem\n\nn\n'
assert_not_contains "no warning without the key" "$ERR" "ignored"
}
test_github_owner_preset_is_used_when_github_is_asked_for() {
collect_with "GITHUB_OWNER=preset-gh" $'my-app\n\n\nTirSystem\ny\n\nn\n'
assert_contains "owner from the config" "$OUT" "github_owner=preset-gh"
assert_not_contains "owner not asked" "$ERR" "GitHub owner ("
collect_with "GITHUB_OWNER=preset-gh" $'my-app\n\n\nTirSystem\nn\n\nn\n'
assert_contains "ignored when answered no" "$ERR" "ignored because GitHub is not used"
}
test_use_github_no_makes_no_github_call() {
setup_hosts
printf '%s\n' "$PRESET_LIKE_ANSWERS" | sed 's/^USE_GITHUB=.*/USE_GITHUB=no/' >>"$WORK/config.env"
run_dry ""
assert_status "dry run" 0 "$STATUS"
assert_contains "GitHub not used" "$OUT" "GitHub repository : not used"
assert_not_contains "no GitHub call" "$(calls)" "api.github.com"
assert_not_contains "no GitHub owner asked" "$ERR" "GitHub owner ("
}
# ------------------------------------------------------------ the summary
test_summary_marks_the_values_from_config_env() {
setup_hosts
printf '%s\n' "$PRESET_LIKE_ANSWERS" >>"$WORK/config.env"
run_dry ""
assert_status "all preset" 0 "$STATUS"
assert_contains "name" "$OUT" "Repository : my-app (from config.env) (private (from config.env))"
assert_contains "description" "$OUT" "Description : A test app (from config.env)"
assert_contains "Gitea" "$OUT" "/TirSystem/my-app (from config.env)"
assert_contains "GitHub" "$OUT" "(AGPL license applied) (from config.env)"
assert_contains "directory" "$OUT" "Directory : ./my-app (from config.env)"
assert_contains "plan gate" "$OUT" "Plan gate : no (from config.env)"
}
test_summary_marks_nothing_when_everything_is_asked() {
setup_hosts
run_dry "$ANSWERS_GITHUB"
assert_status "all asked" 0 "$STATUS"
assert_not_contains "no marker" "$OUT" "(from config.env)"
}
# ----------------------------------------------------- the confirmations
test_with_every_detail_set_only_the_confirmations_are_asked() {
setup_hosts
run_apply "$ANSWERS_GITHUB"y$'\n'
local asked_calls
asked_calls="$(calls)"
remove_workdir
new_workdir
setup_hosts
printf '%s\n' "$PRESET_LIKE_ANSWERS" >>"$WORK/config.env"
run_apply $'y\n'
assert_status "run with presets" 0 "$STATUS"
assert_eq "same requests as the run that was asked" "$asked_calls" "$(calls)"
assert_contains "created" "$OUT" "This is what exists now"
}
test_with_every_detail_set_create_now_is_still_asked_and_defaults_to_no() {
setup_hosts
printf '%s\n' "$PRESET_LIKE_ANSWERS" >>"$WORK/config.env"
run_apply $'n\n'
assert_status "declined" 0 "$STATUS"
assert_contains "says so" "$OUT" "Nothing was created."
assert_not_contains "nothing created" "$(calls)" "POST"
setup_hosts
printf '%s\n' "$PRESET_LIKE_ANSWERS" >>"$WORK/config.env"
run_apply $'\n'
assert_contains "empty answer means no" "$OUT" "Nothing was created."
assert_not_contains "no POST on the default" "$(calls)" "POST"
setup_hosts
printf '%s\n' "$PRESET_LIKE_ANSWERS" >>"$WORK/config.env"
run_apply ""
assert_contains "no answer means no" "$OUT" "Nothing was created."
assert_not_contains "nothing created without an answer" "$(calls)" "POST"
}
test_with_every_detail_set_an_existing_directory_is_not_replaced() {
setup_hosts
printf '%s\n' "$PRESET_LIKE_ANSWERS" >>"$WORK/config.env"
mkdir -p "$WORK/my-app"
printf 'keep\n' >"$WORK/my-app/mine.txt"
run_apply $'y\n\n'
assert_file_exists "existing file kept" "$WORK/my-app/mine.txt"
assert_eq "content kept" "keep" "$(cat "$WORK/my-app/mine.txt")"
}
test_a_quoted_description_may_contain_a_hash() {
local answers=$'my-app\npublic\nTirSystem\nn\n\nn\n'
collect_with 'PROJECT_DESCRIPTION="Tool for #mirrors"' "$answers"
assert_status "quoted" 0 "$STATUS"
assert_contains "whole value kept" "$OUT" "description=Tool for #mirrors"
# Unquoted, the same text is cut at the comment mark, as documented.
collect_with 'PROJECT_DESCRIPTION=Tool for #mirrors' "$answers"
assert_contains "cut at the comment" "$OUT" "description=Tool for"
assert_not_contains "comment dropped" "$OUT" "mirrors"
}
+1 -1
View File
@@ -103,7 +103,7 @@ test_usage_errors() {
assert_contains "help shows exit codes" "$OUT" "Exit codes" assert_contains "help shows exit codes" "$OUT" "Exit codes"
run_cli "" --version run_cli "" --version
assert_status "version" 0 "$STATUS" assert_status "version" 0 "$STATUS"
assert_contains "version output" "$OUT" "RepoFoundry 0.3.0" assert_contains "version output" "$OUT" "RepoFoundry 0.2.0"
} }
test_warns_when_env_is_not_ignored_by_git() { test_warns_when_env_is_not_ignored_by_git() {