name: Check Shared CLAUDE.md Block description: Fails when a repo's shared CLAUDE.md block has drifted from the canonical copy in stat-tackler-infra inputs: TARGET: description: "Path to the CLAUDE.md file to check" default: "CLAUDE.md" CANONICAL_URL: description: "Raw URL of the canonical shared fragment" default: "https://gitea.pixelparasol.com/stat-tackler/stat-tackler-infra/raw/branch/main/docs/CLAUDE.shared.md" GITEA_TOKEN: description: "Gitea token with read access to stat-tackler-infra, if it is private" default: "" runs: using: composite steps: - name: Checkout uses: actions/checkout@v4 - name: Check shared CLAUDE.md block shell: sh env: TARGET: ${{ inputs.TARGET }} CANONICAL_URL: ${{ inputs.CANONICAL_URL }} GITEA_TOKEN: ${{ inputs.GITEA_TOKEN }} run: | set -e if [ ! -f "$TARGET" ]; then echo "::error::$TARGET not found" exit 1 fi extract() { # Everything between the markers, markers included. awk '//{f=0}' "$1" } mine=$(extract "$TARGET") if [ -z "$mine" ]; then echo "::error::$TARGET has no SHARED:BEGIN/SHARED:END block." echo "Copy it from $CANONICAL_URL" exit 1 fi tmp=$(mktemp) if [ -n "$GITEA_TOKEN" ]; then curl -sfSL -H "Authorization: token $GITEA_TOKEN" "$CANONICAL_URL" -o "$tmp" else curl -sfSL "$CANONICAL_URL" -o "$tmp" fi theirs=$(extract "$tmp") if [ -z "$theirs" ]; then echo "::error::Could not read the canonical block from $CANONICAL_URL" exit 1 fi if [ "$mine" = "$theirs" ]; then echo "Shared CLAUDE.md block matches the canonical copy." rm -f "$tmp" exit 0 fi echo "::error::The shared CLAUDE.md block has drifted from the canonical copy." echo "Canonical: $CANONICAL_URL" echo echo "--- canonical" echo "+++ $TARGET" printf '%s\n' "$theirs" > "$tmp.canon" printf '%s\n' "$mine" > "$tmp.mine" diff -u "$tmp.canon" "$tmp.mine" || true rm -f "$tmp" "$tmp.canon" "$tmp.mine" exit 1