← Commit history

Release tool: keep the CA bundle out of repo pushes (secret scanner, #79 root cause); runner traces a real net

John Lauer ·08c8817fc6 ·1mo ago ·parent 1e83d4d
3 files changed +22−4
skills/kicad-bridge-test/run_verb_tests.py+10−2
@@ -119,8 +119,8 @@ def matrix(w: dict) -> dict:         "extract_netlist":   dict(phase=2, args={"filePath": S, "includeNodes": False}, timeout=120),         "analyze_connections": dict(phase=2, args={"filePath": S}, timeout=120),         "find_connections":  dict(phase=2, args={"filePath": S, "reference": "U1"}, timeout=120),-        "trace_net":         dict(phase=2, args={"filePath": S, "netName": "GND"}, timeout=120,-                                  note="a net that exists in the rp2040 fixture; a miss is success:false with candidates"),+        "trace_net":         dict(phase=2, args={"__special": "trace_net"}, timeout=120,+                                  note="netName is the first real net kicad_extract_netlist reports for the fixture"),         "run_drc":           dict(phase=2, args={"filePath": B}, timeout=200),         "run_erc":           dict(phase=2, args={"filePath": S}, timeout=200),         "lint_board":        dict(phase=2, args={"filePath": B}, timeout=200),@@ -450,6 +450,14 @@ def main():                 return             args = {"hwnd": v3["hwnd"], "x": 280, "y": 100, "relative": False,                     "reason": "daily verb test: zoom-in toolbar"}+        elif special == "trace_net":+            nl = ab(a.target, "kicad_extract_netlist", {"filePath": w["sch"], "includeNodes": False}, timeout=120)+            names = [n.get("name") if isinstance(n, dict) else n for n in (nl.get("nets") or [])]+            real = next((n for n in names if n and not str(n).startswith("unconnected-")), None)+            if not real:+                results[verb] = {"result": "FAIL", "reason": "extract_netlist reported no nets to trace"}+                return+            args = {"filePath": w["sch"], "netName": real}         elif special == "install_symbol":             import base64 as _b64             args = {"fileName": "ADOM_VERBTEST.kicad_sym",
tools/build_release.py+7−1
@@ -204,8 +204,14 @@ def main() -> int:     # are NOT source: tools/vendor_routing_deps.py rebuilds them from     # requirements-routing.txt, so they stay out of the page repo.     vendored = tuple(d.rstrip("/") + "/" for d in json.load(open("tools/release_files.json")).get("dirs", []))+    # push_exclude: shipped but never pushed. certs/cacert.pem is the public+    # Mozilla CA bundle; the wiki's secret scanner rejects every .pem, and one+    # rejected file fails the whole chunk it rides in (that is how the #79+    # handlers went missing: "certs" sorts right before "handlers").+    excluded = set(json.load(open("tools/release_files.json")).get("push_exclude", []))     push_files = ["BRIDGE_VERSION", "bridge.json"] + ([MANIFEST] if tier_public else []) + [-        f for f in files if os.path.isfile(f) and f != MANIFEST and not f.startswith(vendored)]+        f for f in files if os.path.isfile(f) and f != MANIFEST and not f.startswith(vendored)+        and f not in excluded]     print(f"pushing {len(push_files)} source file(s) to the page repo")     # chunked: a single push of the whole file list can exceed the request cap     CHUNK = 40
tools/release_files.json+5−1
@@ -109,5 +109,9 @@   ],   "dirs": [     "routing_deps"-  ]+  ],+  "push_exclude": [+    "certs/cacert.pem"+  ],+  "_push_exclude_comment": "Shipped in the zip but never pushed to the page repo: the wiki secret scanner rejects any .pem (public Mozilla CA bundle, issue #79 root cause: the chunk carrying it failed silently for twenty releases)." }