From ffb8aed7b632ea9174c56888f977ab7b623a0f0a Mon Sep 17 00:00:00 2001 From: Masaharu Hayashi Date: Sat, 26 Sep 2026 01:44:35 +0000 Subject: [PATCH 1/2] =?UTF-8?q?fix(ci):=20drift=20=E3=83=AF=E3=83=BC?= =?UTF-8?q?=E3=82=AF=E3=83=95=E3=83=AD=E3=83=BC=E3=81=AE=E5=AE=9F=E4=BD=93?= =?UTF-8?q?=E3=81=AB=E3=82=BD=E3=83=BC=E3=82=B9=E7=94=B1=E6=9D=A5=E3=81=AE?= =?UTF-8?q?=E7=B5=8C=E8=B7=AF=E6=A4=9C=E7=9F=A5=E3=82=92=E5=85=A5=E3=82=8C?= =?UTF-8?q?=E3=82=8B?= MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit 原本(tools/api-inventory/ci/)には detect_routes.py --cross-check --gate の段が あったが、GitHub Actions が動かす .github/workflows/ 側に反映されておらず、 config で無効な経路が台帳から落ちても CI で気付けない状態だった。 - 原本を実体にコピーする - 原本と実体の一致を見る test_workflows.py を足す - 実体だけを触った変更でもそのテストが走るよう、tests ワークフローの paths に drift の実体を足す Co-Authored-By: Claude Opus 5.5 --- .github/workflows/api-inventory-drift.yml | 16 ++++++++ .github/workflows/api-inventory-tests.yml | 1 + .../api-inventory/ci/api-inventory-tests.yml | 1 + tools/api-inventory/tests/test_workflows.py | 39 +++++++++++++++++++ 4 files changed, 57 insertions(+) create mode 100644 tools/api-inventory/tests/test_workflows.py diff --git a/.github/workflows/api-inventory-drift.yml b/.github/workflows/api-inventory-drift.yml index 5131b55c6c..9bf2cc580c 100644 --- a/.github/workflows/api-inventory-drift.yml +++ b/.github/workflows/api-inventory-drift.yml @@ -17,6 +17,13 @@ # 個人アカウントに紐づかないため(PAT より事故時の影響が小さい)。 # 未設定なら、このジョブは何もせずスキップする(fork からの PR でも安全)。 # +# 網羅性は二段で見る: +# reconcile.py 実機 url_map ↔ 台帳(この環境で登録されている経路) +# detect_routes.py ソース(AST) ↔ 台帳(config で無効な経路まで含む) +# 前者だけだと、config で無効・プラグイン未導入の経路が台帳から落ちても気付けない。 +# +# ツールそのものの単体テストは api-inventory-tests.yml(Secret も Docker も不要)。 +# # 設置手順: tools/api-inventory/ci/README.md name: API Inventory Drift @@ -209,6 +216,13 @@ jobs: --snapshot /tmp/api_snapshot.new.json \ --summary-only --gate --out /tmp/reconcile.md + # 実機 url_map は「この環境で登録された経路」しか映さない。config で無効・ + # プラグイン未導入・設定値が真のときだけ登録される経路は、API として + # 存在するのに reconcile では見えない。ソースからの検知で二段目を張る。 + python3 $T/detect_routes.py \ + --weko-root "$PWD" --cross-check \ + --summary-only --gate --out /tmp/detect.md + - name: Probe changed endpoints if: always() && steps.cfg.outputs.enabled == 'true' env: @@ -237,6 +251,7 @@ jobs: path: | /tmp/drift.md /tmp/reconcile.md + /tmp/detect.md - name: Comment on PR (counts only) if: always() && steps.cfg.outputs.enabled == 'true' && github.event_name == 'pull_request' @@ -268,6 +283,7 @@ jobs: + '該当箇所はプライベートリポジトリ側の台帳・レポートで確認してください。'; body += read('/tmp/drift.md', 'ベースラインとの差分'); body += read('/tmp/reconcile.md', '台帳との突き合わせ'); + body += read('/tmp/detect.md', 'ソース由来の経路検知'); await github.rest.issues.createComment({ issue_number: context.issue.number, owner: context.repo.owner, diff --git a/.github/workflows/api-inventory-tests.yml b/.github/workflows/api-inventory-tests.yml index 602ee772d4..eaf6ff6260 100644 --- a/.github/workflows/api-inventory-tests.yml +++ b/.github/workflows/api-inventory-tests.yml @@ -19,6 +19,7 @@ on: paths: &paths - 'tools/api-inventory/**' - '.github/workflows/api-inventory-tests.yml' + - '.github/workflows/api-inventory-drift.yml' push: branches: ['**'] paths: *paths diff --git a/tools/api-inventory/ci/api-inventory-tests.yml b/tools/api-inventory/ci/api-inventory-tests.yml index 602ee772d4..eaf6ff6260 100644 --- a/tools/api-inventory/ci/api-inventory-tests.yml +++ b/tools/api-inventory/ci/api-inventory-tests.yml @@ -19,6 +19,7 @@ on: paths: &paths - 'tools/api-inventory/**' - '.github/workflows/api-inventory-tests.yml' + - '.github/workflows/api-inventory-drift.yml' push: branches: ['**'] paths: *paths diff --git a/tools/api-inventory/tests/test_workflows.py b/tools/api-inventory/tests/test_workflows.py new file mode 100644 index 0000000000..9dd1f4fc52 --- /dev/null +++ b/tools/api-inventory/tests/test_workflows.py @@ -0,0 +1,39 @@ +# -*- coding: utf-8 -*- +"""ワークフローの原本(ci/)と実体(.github/workflows/)がずれていないかを検査する。 + +GitHub Actions が動かすのは `.github/workflows/` 側だけで、`ci/` 側は原本に過ぎない。 +片方だけ直すと、手順書と原本を読んだ人は「その検査は回っている」と思い込む。 +実際に `detect_routes.py` の段が原本にだけ入り、実体の drift ワークフローからは +抜けたまま、ソース由来の経路検知が CI で一度も走っていなかった。 +""" +import os + +import pytest + +from conftest import SCRIPTS + +TOOL = os.path.dirname(SCRIPTS) +CI = os.path.join(TOOL, 'ci') +# リポジトリのルート直下にある(ツールだけ取り出した環境には無い)。 +WORKFLOWS = os.path.join(os.path.dirname(os.path.dirname(TOOL)), '.github', 'workflows') + +ORIGINALS = sorted(f for f in os.listdir(CI) if f.endswith('.yml')) + + +def test_原本のワークフローがある(): + assert ORIGINALS, f'{CI} に .yml が無い' + + +@pytest.mark.skipif(not os.path.isdir(WORKFLOWS), + reason='.github/workflows が無い(ツールだけ取り出した環境)') +@pytest.mark.parametrize('name', ORIGINALS) +def test_原本と実体が一致する(name): + actual = os.path.join(WORKFLOWS, name) + assert os.path.isfile(actual), \ + f'.github/workflows/{name} が無い。原本を置いただけでは動かない' + with open(os.path.join(CI, name), encoding='utf-8') as f: + original = f.read() + with open(actual, encoding='utf-8') as f: + assert f.read() == original, \ + f'ci/{name} と .github/workflows/{name} がずれている。' \ + '変更したら両方に反映すること(ci/README.md §2 の 5)' From 01a2a9b7ed82a1e65b8973d8da2fc3a006e58caf Mon Sep 17 00:00:00 2001 From: Masaharu Hayashi Date: Sat, 26 Sep 2026 01:44:53 +0000 Subject: [PATCH 2/2] =?UTF-8?q?style(tools):=20test=5Fworkflows.py=20?= =?UTF-8?q?=E3=81=AE=E8=A1=8C=E9=95=B7=E3=82=92=20flake8=20=E3=81=AB?= =?UTF-8?q?=E5=90=88=E3=82=8F=E3=81=9B=E3=82=8B?= MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit Co-Authored-By: Claude Opus 5.5 --- tools/api-inventory/tests/test_workflows.py | 3 ++- 1 file changed, 2 insertions(+), 1 deletion(-) diff --git a/tools/api-inventory/tests/test_workflows.py b/tools/api-inventory/tests/test_workflows.py index 9dd1f4fc52..8cf35be26e 100644 --- a/tools/api-inventory/tests/test_workflows.py +++ b/tools/api-inventory/tests/test_workflows.py @@ -15,7 +15,8 @@ TOOL = os.path.dirname(SCRIPTS) CI = os.path.join(TOOL, 'ci') # リポジトリのルート直下にある(ツールだけ取り出した環境には無い)。 -WORKFLOWS = os.path.join(os.path.dirname(os.path.dirname(TOOL)), '.github', 'workflows') +ROOT = os.path.dirname(os.path.dirname(TOOL)) +WORKFLOWS = os.path.join(ROOT, '.github', 'workflows') ORIGINALS = sorted(f for f in os.listdir(CI) if f.endswith('.yml'))