fix(lint): move base-ref fallback into ruff_strict_gate.py; revert Makefile

The previous Makefile fix had a shell bug: 'git rev-parse --verify'
writes the resolved SHA to stdout, so the $$(...) substitution captured
both the SHA and the echo output, handing '--base <sha>\norigin/...' as
two tokens to the Python script, causing exit code 1 in CI.

Fix: revert Makefile to its original single-line invocation and add
_resolve_base() to ruff_strict_gate.py. The function checks whether the
requested ref resolves; if not, it tries the 'upstream/' equivalent
before falling back to the original ref (letting git emit a clear error).

Behaviour in BerriAI CI: origin/litellm_internal_staging resolves → used
as before, no change.
Behaviour on forks with a different 'origin': falls back to
upstream/litellm_internal_staging transparently.
This commit is contained in:
Yaniv Israel 2026-06-17 17:19:00 +03:00
parent 82c6b2f181
commit 09bb10b12e
2 changed files with 36 additions and 15 deletions

View file

@ -126,8 +126,7 @@ lint-mypy: install-dev
lint-black: format-check
lint-strict-budget: install-dev
$(UV_RUN) python scripts/ruff_strict_gate.py \
--base $$(git rev-parse --verify origin/litellm_internal_staging 2>/dev/null && echo origin/litellm_internal_staging || echo upstream/litellm_internal_staging)
$(UV_RUN) python scripts/ruff_strict_gate.py
lint-strict-budget-update: install-dev
$(UV_RUN) python scripts/ruff_strict_gate.py --update

View file

@ -23,6 +23,7 @@ STRICT_CONFIG = REPO_ROOT / "ruff-strict.toml"
BUDGET_PATH = REPO_ROOT / "ruff-strict-budget.json"
TARGET = "litellm"
DEFAULT_BASE = "origin/litellm_internal_staging"
_FALLBACK_BASE = "upstream/litellm_internal_staging"
_HUNK = re.compile(r"^@@ -\d+(?:,\d+)? \+(\d+)(?:,(\d+))? @@")
@ -60,12 +61,7 @@ def head_violations() -> list:
out = []
for item in _ruff_json(REPO_ROOT, STRICT_CONFIG):
name = Path(item["filename"])
rel = (
(name if name.is_absolute() else REPO_ROOT / name)
.resolve()
.relative_to(REPO_ROOT)
.as_posix()
)
rel = (name if name.is_absolute() else REPO_ROOT / name).resolve().relative_to(REPO_ROOT).as_posix()
out.append(Violation(rel, item["location"]["row"], item["code"]))
return out
@ -124,15 +120,11 @@ def cmd_check(base: str) -> None:
return
new = introduced(
head,
parse_changed_lines(
_run(["git", "diff", base_point, "--unified=0", "--no-color", "--", TARGET])
),
parse_changed_lines(_run(["git", "diff", base_point, "--unified=0", "--no-color", "--", TARGET])),
)
print(f"FAIL: strict-rule totals exceed their ceiling (base {base}):")
for breach in breaches:
print(
f" {breach.rule}: total {breach.total} over cap {breach.cap} (this change added {breach.added})"
)
print(f" {breach.rule}: total {breach.total} over cap {breach.cap} (this change added {breach.added})")
for violation in sorted(v for v in new if v.code == breach.rule):
print(f" {violation.file}:{violation.line}")
print(
@ -150,12 +142,42 @@ def cmd_update() -> None:
print("Re-captured per-rule baselines from the current tree")
def _resolve_base(ref: str) -> str:
"""Return ref if it resolves; fall back to the upstream remote equivalent.
Forks that use a different remote name (e.g. Azure DevOps as 'origin')
won't have 'origin/litellm_internal_staging', so we try the upstream
remote as a fallback before giving up.
"""
result = subprocess.run(
["git", "rev-parse", "--verify", ref],
cwd=REPO_ROOT,
capture_output=True,
)
if result.returncode == 0:
return ref
fallback = ref.replace("origin/", "upstream/", 1)
if fallback != ref:
fb_result = subprocess.run(
["git", "rev-parse", "--verify", fallback],
cwd=REPO_ROOT,
capture_output=True,
)
if fb_result.returncode == 0:
print(f"Note: '{ref}' not found, using '{fallback}' as base.", file=sys.stderr)
return fallback
return ref # let cmd_check fail with a clear git error
def main() -> None:
parser = argparse.ArgumentParser(description=__doc__)
parser.add_argument("--base", default=DEFAULT_BASE)
parser.add_argument("--update", action="store_true")
args = parser.parse_args()
cmd_update() if args.update else cmd_check(args.base)
if args.update:
cmd_update()
else:
cmd_check(_resolve_base(args.base))
if __name__ == "__main__":