Commit Graph
4 Commits
Author SHA1 Message Date
Divarion_D cc212c051b fix(ci): correct check_procedural_use skip path to Infrastructure/Tmdb/lib
The skip list keyed on /Modules/tmdb/lib/, which matches nothing: there is no
src/Modules/tmdb* dir, and the vendored non-namespaced TMDB library lives at
src/Infrastructure/Tmdb/lib/. So the intended skip was dead and that library
was being scanned. Point the skip at the real path. Gate still passes
(411 migrated classes, no violations).
2026-08-07 21:03:57 +03:00
Divarion-D aa7befa375 build: gitignore dev packages under vendor + harden the prod-only gate
Belt-and-suspenders so dev packages can never land in git:

- .gitignore: whitelist the committed production set under src/vendor/ and ignore
  everything else (src/vendor/* + !autoload.php/!chrisyue/!composer/!gemorroj,
  then re-ignore composer/{pcre,semver,xdebug-handler,autoload_files.php}). A
  local `composer install` (for PHPStan/PHP-CS-Fixer) now writes dev packages
  into ignored paths, so `git add` can never stage them. gitignore never
  untracks, so the committed prod files stay tracked and updatable; a NEW prod
  dep just needs a `!` whitelist line.
- check-vendor-prod-only.sh: add a second check on the committed
  vendor/composer/installed.json — it must list no dev package. This covers the
  one thing .gitignore cannot: installed.json is a tracked file that
  `composer install` rewrites with dev entries. Both checks read the git INDEX,
  so a local dev install does not trip the gate, but a committed dev artifact does.

Verified: clean tree passes; a dev `composer install` in the working tree leaves
the gate green (index-based); a fabricated dev installed.json is detected; no dev
dir is stageable after `composer install`.
2026-06-25 21:59:46 +03:00
Divarion-D baf6c8e231 build: ship a production-only vendor; install dev tools via Composer
Switch from "commit vendor with dev deps + strip at release" to the standard
application model: the committed src/vendor/ is PRODUCTION-ONLY, and dev tooling
(PHPStan, PHP-CS-Fixer + ~37 transitive deps) is installed on demand with
"composer install".

- Regenerate the committed src/vendor/ via "composer install --no-dev"
  (34 MB -> ~0.5 MB; only the Composer autoloader + gemorroj/m3u-parser +
  chrisyue/php-m3u8 remain). This also stops PHPStan\PharAutoloader registering
  in production.
- Commit src/composer.lock (un-ignored) — this is an application, so the lock is
  committed to make "composer install" reproducible across dev/CI.
- Revert the release-time strip step (Makefile hooks + tools/build/
  strip-dev-vendor.sh) — no longer needed; the archive ships the prod vendor as-is.
- CI: the phpstan and code-style jobs now run "composer install --working-dir=src"
  (with tools: composer) to obtain the dev tools before running.
- New gate tools/ci/check-vendor-prod-only.sh (+ make check-vendor-prod-only,
  wired into "make gates"): asserts no require-dev package from composer.lock is
  committed under src/vendor/ — guards against accidentally committing a
  dev-bloated vendor. Inspects git-tracked files, so it is correct even in a CI
  job that already ran "composer install".
- Fix verify-lb-archive.sh: LB legitimately ships most of Cli/Commands and
  Cli/CronJobs (edge commands + certbot/cache/cleanup crons), so flag only the
  genuinely privileged dirs + the specific install/root files, not the whole dirs.
- .gitignore / composer.json notes updated.

Verified before pruning: PHPStan no errors, PHPUnit 303, cs + gates green. After
pruning: PHPUnit 303 (prod-only vendor), all three gates green. Local dev tools
restored afterwards with "composer install" (not committed).
2026-06-25 21:51:13 +03:00
Divarion-D e9bc5de0e4 test/ci(psr4): add the missing migration regression gates
Adds the automated gates the PSR-4 plan specified but that were verified only
manually per phase:

PHPUnit (run by the existing test job):
- AutoloadOrderTest      — Composer autoloader registered; the retired
                           XC_Autoloader scanner is NOT in the SPL stack; init()
                           is a no-op; no igbinary class-map cache is written.
- BootstrapPathsTest     — no live require/include points at a lowercase renamed
                           dir (the Фаза-1 grep-gate, as a runtime guard).
- ConsoleDiscoveryTest   — console.php FQCN discovery resolves every Cli command
                           file and the concrete command surface stays stable.

Shell gates (new 'PSR-4 Regression Gates' CI job + 'make gates'):
- tools/ci/check_procedural_use.php — procedural/view files must import every
  migrated class they use, with the `use` ABOVE the usage (PHP imports are
  positional). Runs with short_open_tag=1 so short-tag templates are analysed.
- tools/ci/verify-lb-archive.sh — reproduces the Makefile LB file selection from
  the real LB_* vars and asserts no privileged tree (Admin/Reseller/Player
  controllers, Domain/User|Device, Cli/CronJobs|Commands) ships to an LB node
  (security blocker 1).

Makefile: cs/cs-fix now force short_open_tag=1; new print-%, check-procedural-use,
verify-lb-archive and aggregate `gates` targets.
2026-06-25 20:57:53 +03:00