ci(openapi): require the pinned server commit to be reachable from server main - #171
Merged
Merged
Conversation
The OpenAPI contract is pinned to an exact Life-USTC/server commit, and
verification only asserted that the server checkout is *at* that commit.
CI checks out exactly the pinned SHA, so that assertion is a tautology.
A pull-request head SHA stays fetchable from the server repository
forever, so the pin could point at a commit that was never on main and
every check still passed: the provenance verified, the checkout matched,
and the vendored spec was byte-identical to the source.
Life-USTC/cli hit this for real. It was pinned at
fea7bb21ead65fa4da1d51d8ef36ef914a647783 ("fix(young): complete release
contracts", 2026-09-15), a pull-request head that is not an ancestor of
server main -- the server squash-merges, so PR heads never land there.
The CLI client was generated from a discarded branch snapshot while CI
reported success.
Add `openapi-contract.sh verify-reachable SERVER_DIR`, which asserts
`git merge-base --is-ancestor <pin> <main>` against the server checkout,
and wire it into CI and the nightly sync through
`make check-openapi-reachability`.
Ancestry needs real history, so the server checkouts now use
`fetch-depth: 0` and fetch `refs/heads/main` explicitly. A shallow
checkout stays shallow even after fetching main, so the script refuses
to run there instead of guessing: a check that cannot be evaluated is
worse than no check. The same refusal covers a missing main ref and a
pin the checkout does not contain.
scripts/openapi-contract.test.sh builds synthetic server histories and
proves the check rejects an unmerged branch head -- including the case
where provenance, HEAD, and the vendored spec all agree -- and accepts
both the main tip and an older commit on main. It runs in CI next to the
deploy-mac smoke test via `make check-scripts`.
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
This was referenced Sep 21, 2026
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Outcome
The Bot cannot silently generate a client from an unmerged server branch.
Refs Life-USTC/server#1101