From 6bdfa35abbde29897ccd5f9458d81a1142012fa6 Mon Sep 17 00:00:00 2001 From: Edwin van den Houdt Date: Thu, 27 Aug 2026 14:31:50 +0200 Subject: [PATCH] build: stop ci-local.sh swallowing the first half of every paired step MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit Under `set -e` bash exempts every command of an AND-OR list except the last, so `npm run gen:api && git diff --exit-code ...` silently swallowed a CRASH in gen:api: the diff never ran and the script sailed on to print "local CI passed". Verified directly — `bash -c 'set -e; false && true; echo hi'` prints hi and exits 0, while `false; true` exits 1. This was not hypothetical. It hid a real gen:api crash introduced by RB-09 (dotnet swagger's design-time host defaults to Production, which that ticket made throw at startup). .github/workflows/ci.yml would have caught it, since it runs each step as its own `- run:` — so the local gate was strictly weaker than the remote one, which is the opposite of its stated purpose. Six steps were affected. The worst was `ng build ssp --localize && ng build behandelportal --localize`: a missing English translation in ssp — the exact thing the second-locale gate exists to catch — could not fail the run. The one `( cd backend && ... )` step is safe as-is and left alone: a subshell propagates its own non-zero status, so errexit sees it. Co-Authored-By: Claude Opus 5 --- scripts/ci-local.sh | 20 ++++++++++++++------ 1 file changed, 14 insertions(+), 6 deletions(-) diff --git a/scripts/ci-local.sh b/scripts/ci-local.sh index 63ecd0c..f5f1eb4 100755 --- a/scripts/ci-local.sh +++ b/scripts/ci-local.sh @@ -9,6 +9,14 @@ set -euo pipefail cd "$(dirname "$0")/.." +# Steps chain with `;`, NOT `&&`. Under `set -e`, bash exempts every command of an +# AND-OR list except the last, so in `gen && git diff --exit-code` a CRASH in `gen` +# is silently swallowed — the diff never runs and the script sails on. That is not +# hypothetical: it hid a real `gen:api` crash (RB-09), which .github/workflows/ci.yml +# would have caught because it runs each step as its own `- run:`. With `;` errexit +# fires on the first failure. The one `( cd backend && ... )` below is safe as-is: +# a subshell propagates its own non-zero status, so errexit sees it. + step() { printf '\n\033[1;36m▶ %s\033[0m\n' "$1"; } step "lint"; npm run lint @@ -18,16 +26,16 @@ step "format:check (prettier)"; npm run format:check step "check:tokens"; npm run check:tokens step "check:seam"; npm run check:seam step "test (vitest + coverage)"; npm run test:coverage -step "build --localize (nl+en)"; npx ng build ssp --localize && npx ng build behandelportal --localize +step "build --localize (nl+en)"; npx ng build ssp --localize; npx ng build behandelportal --localize step "npm audit (shipped deps)"; npm audit --omit=dev step "backend format + tests"; ( cd backend && dotnet format BigRegister.slnx --verify-no-changes && dotnet test BigRegister.slnx --filter "Category!=Integration" ) -step "showcase snippets drift"; npm run gen:snippets && git diff --exit-code apps/ssp/src/app/showcase/snippets.generated.ts -step "behaviour spec drift"; npm run gen:behaviour-spec && git diff --exit-code libs/shared/docs/behaviour-spec.mdx -step "api-client drift"; npm run gen:api && git diff --exit-code libs/shared/src/infrastructure/api-client.ts backend/swagger.json +step "showcase snippets drift"; npm run gen:snippets; git diff --exit-code apps/ssp/src/app/showcase/snippets.generated.ts +step "behaviour spec drift"; npm run gen:behaviour-spec; git diff --exit-code libs/shared/docs/behaviour-spec.mdx +step "api-client drift"; npm run gen:api; git diff --exit-code libs/shared/src/infrastructure/api-client.ts backend/swagger.json if [[ "${1:-}" == "--full" ]]; then - step "storybook build + axe (ssp)"; npm run build-storybook && npm run test-storybook:ci - step "storybook build + axe (behandelportal)"; npm run build-storybook:behandelportal && npm run test-storybook:ci:behandelportal + step "storybook build + axe (ssp)"; npm run build-storybook; npm run test-storybook:ci + step "storybook build + axe (behandelportal)"; npm run build-storybook:behandelportal; npm run test-storybook:ci:behandelportal fi printf '\n\033[1;32m✔ local CI passed\033[0m\n'