mirror of
https://github.com/jmcorgan/fips.git
synced 2026-10-06 03:28:24 +00:00
The OpenWrt Package workflow was the only place the package's shell scripts were linted, and it runs on trunk pushes, tags and pull requests but never on a branch push. A shellcheck finding introduced on a topic branch therefore first failed after the branch had landed, which is how all three trunks went red on the gateway init script. testing/check-shellcheck.sh now runs that pass: the scripts the package ships as POSIX sh with the workflow's exclusions, and the nak installer as bash. It also covers the maintainer scripts the workflow's list left out: the postinst and prerm that both the .ipk and the .apk package ship, and the preinst that the SDK feed Makefile ships. It fails when a shell script under the package's files or scripts directory is not on its list, so a new one cannot go unlinted. It exits 2 when shellcheck is missing or cannot read a file, 1 on a finding or a missing script, and 0 when clean. The OpenWrt Package workflow calls the guard in place of its two inline steps, keeping its install-if-missing step, so the runners cannot drift apart. ci-local.sh runs it as a static stage beside the other repository guards, and ci.yml's ci-parity job runs it on every branch push.