Compare commits
2 Commits
main
...
252e5238ca
| Author | SHA1 | Date | |
|---|---|---|---|
| 252e5238ca | |||
| e0c9e0db94 |
13
.github/workflows/candidate.yml
vendored
13
.github/workflows/candidate.yml
vendored
@@ -18,8 +18,6 @@ jobs:
|
|||||||
- uses: ruby/setup-ruby@003a5c4d8d6321bd302e38f6f0ec593f77f06600 # v1
|
- uses: ruby/setup-ruby@003a5c4d8d6321bd302e38f6f0ec593f77f06600 # v1
|
||||||
with:
|
with:
|
||||||
ruby-version: "3.4"
|
ruby-version: "3.4"
|
||||||
- name: Install standalone test dependency
|
|
||||||
run: gem install minitest --version 6.0.6 --no-document
|
|
||||||
- run: |
|
- run: |
|
||||||
ruby test/repository_test.rb
|
ruby test/repository_test.rb
|
||||||
ruby test/runtime_tuple_promoter_test.rb
|
ruby test/runtime_tuple_promoter_test.rb
|
||||||
@@ -269,12 +267,9 @@ jobs:
|
|||||||
retention-days: 30
|
retention-days: 30
|
||||||
|
|
||||||
exact-image-contract-gitea:
|
exact-image-contract-gitea:
|
||||||
if: >-
|
if: github.server_url != 'https://github.com'
|
||||||
github.server_url != 'https://github.com' &&
|
|
||||||
(github.event_name == 'workflow_dispatch' ||
|
|
||||||
(github.event_name == 'push' && github.ref == 'refs/heads/main'))
|
|
||||||
needs: prepare
|
needs: prepare
|
||||||
runs-on: heyoka-image-build
|
runs-on: ubuntu-latest
|
||||||
name: Gitea full exact image matrix
|
name: Gitea full exact image matrix
|
||||||
steps:
|
steps:
|
||||||
- uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 # v7.0.0
|
- uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 # v7.0.0
|
||||||
@@ -304,7 +299,9 @@ jobs:
|
|||||||
test "$actual_client_sha" = "$EXPECTED_CLIENT_SHA"
|
test "$actual_client_sha" = "$EXPECTED_CLIENT_SHA"
|
||||||
echo "value=$actual_client_sha" >> "$GITHUB_OUTPUT"
|
echo "value=$actual_client_sha" >> "$GITHUB_OUTPUT"
|
||||||
- name: Resolve the private Docker host transport
|
- name: Resolve the private Docker host transport
|
||||||
run: echo "OPENCODE_PROBE_HOST=127.0.0.1" >> "$GITHUB_ENV"
|
run: |
|
||||||
|
probe_host="$(ruby scripts/private_default_gateway.rb)"
|
||||||
|
echo "OPENCODE_PROBE_HOST=$probe_host" >> "$GITHUB_ENV"
|
||||||
- name: Exercise the complete manifest matrix without artifact claims
|
- name: Exercise the complete manifest matrix without artifact claims
|
||||||
env:
|
env:
|
||||||
BUNDLE_GEMFILE: ${{ github.workspace }}/ruby-client/Gemfile
|
BUNDLE_GEMFILE: ${{ github.workspace }}/ruby-client/Gemfile
|
||||||
|
|||||||
1
.github/workflows/watch-upstream.yml
vendored
1
.github/workflows/watch-upstream.yml
vendored
@@ -15,7 +15,6 @@ concurrency:
|
|||||||
|
|
||||||
jobs:
|
jobs:
|
||||||
open-compatibility-pr:
|
open-compatibility-pr:
|
||||||
if: github.server_url == 'https://github.com'
|
|
||||||
runs-on: ubuntu-latest
|
runs-on: ubuntu-latest
|
||||||
steps:
|
steps:
|
||||||
- uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 # v7.0.0
|
- uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 # v7.0.0
|
||||||
|
|||||||
@@ -335,13 +335,6 @@ class RepositoryTest < Minitest::Test
|
|||||||
end
|
end
|
||||||
end
|
end
|
||||||
|
|
||||||
def test_repository_job_installs_its_pinned_standalone_test_dependency
|
|
||||||
workflow = File.read(File.join(ROOT, ".github/workflows/candidate.yml"))
|
|
||||||
repository_job = workflow.split(/^ repository:\n/, 2).fetch(1).split(/^ prepare:\n/, 2).fetch(0)
|
|
||||||
|
|
||||||
assert_includes repository_job, "gem install minitest --version 6.0.6 --no-document"
|
|
||||||
end
|
|
||||||
|
|
||||||
def test_candidate_workflow_verifies_and_preserves_the_lockstep_client_tuple
|
def test_candidate_workflow_verifies_and_preserves_the_lockstep_client_tuple
|
||||||
workflow = File.read(File.join(ROOT, ".github/workflows/candidate.yml"))
|
workflow = File.read(File.join(ROOT, ".github/workflows/candidate.yml"))
|
||||||
|
|
||||||
@@ -381,7 +374,8 @@ class RepositoryTest < Minitest::Test
|
|||||||
assert_includes workflow, "exact-image-contract-gitea:"
|
assert_includes workflow, "exact-image-contract-gitea:"
|
||||||
assert_includes workflow, "if: github.server_url != 'https://github.com'"
|
assert_includes workflow, "if: github.server_url != 'https://github.com'"
|
||||||
assert_includes workflow, "run: scripts/run_image_matrix_contract.sh"
|
assert_includes workflow, "run: scripts/run_image_matrix_contract.sh"
|
||||||
assert_includes workflow, 'echo "OPENCODE_PROBE_HOST=127.0.0.1" >> "$GITHUB_ENV"'
|
assert_includes workflow, 'probe_host="$(ruby scripts/private_default_gateway.rb)"'
|
||||||
|
assert_includes workflow, 'echo "OPENCODE_PROBE_HOST=$probe_host" >> "$GITHUB_ENV"'
|
||||||
assert_operator workflow.scan('BUNDLE_GEMFILE: ${{ github.workspace }}/ruby-client/Gemfile').length, :>=, 2
|
assert_operator workflow.scan('BUNDLE_GEMFILE: ${{ github.workspace }}/ruby-client/Gemfile').length, :>=, 2
|
||||||
assert_operator workflow.scan("generated JSON is transient and is not review evidence").length, :>=, 3
|
assert_operator workflow.scan("generated JSON is transient and is not review evidence").length, :>=, 3
|
||||||
|
|
||||||
@@ -389,20 +383,6 @@ class RepositoryTest < Minitest::Test
|
|||||||
refute_includes gitea_job, "actions/upload-artifact@"
|
refute_includes gitea_job, "actions/upload-artifact@"
|
||||||
end
|
end
|
||||||
|
|
||||||
def test_gitea_exact_image_contract_uses_the_trusted_builder_only_for_main_pushes_or_manual_dispatches
|
|
||||||
workflow = File.read(File.join(ROOT, ".github/workflows/candidate.yml"))
|
|
||||||
ordinary_jobs = workflow.split(/^ exact-image-contract:\n/, 2).fetch(0)
|
|
||||||
github_job, gitea_job = workflow.split(/^ exact-image-contract:\n/, 2).fetch(1)
|
|
||||||
.split(/^ exact-image-contract-gitea:\n/, 2)
|
|
||||||
|
|
||||||
assert_equal 4, ordinary_jobs.scan("runs-on: ubuntu-latest").length
|
|
||||||
assert_includes github_job, "runs-on: ubuntu-latest"
|
|
||||||
assert_includes gitea_job, "runs-on: heyoka-image-build"
|
|
||||||
assert_includes gitea_job, "github.server_url != 'https://github.com'"
|
|
||||||
assert_includes gitea_job, "github.event_name == 'workflow_dispatch'"
|
|
||||||
assert_includes gitea_job, "github.event_name == 'push' && github.ref == 'refs/heads/main'"
|
|
||||||
end
|
|
||||||
|
|
||||||
def test_gitea_matrix_runner_uses_every_generated_entry_without_hardcoded_coordinates
|
def test_gitea_matrix_runner_uses_every_generated_entry_without_hardcoded_coordinates
|
||||||
runner = File.read(File.join(ROOT, "scripts/run_image_matrix_contract.sh"))
|
runner = File.read(File.join(ROOT, "scripts/run_image_matrix_contract.sh"))
|
||||||
|
|
||||||
|
|||||||
@@ -170,10 +170,6 @@ class WatcherTest < Minitest::Test
|
|||||||
def test_workflow_can_only_update_manifests_and_open_a_pr
|
def test_workflow_can_only_update_manifests_and_open_a_pr
|
||||||
workflow = File.read(File.join(ROOT, ".github/workflows/watch-upstream.yml"))
|
workflow = File.read(File.join(ROOT, ".github/workflows/watch-upstream.yml"))
|
||||||
|
|
||||||
assert_match(
|
|
||||||
/\n open-compatibility-pr:\n if: github\.server_url == 'https:\/\/github\.com'\n runs-on:/,
|
|
||||||
workflow
|
|
||||||
)
|
|
||||||
assert_includes workflow, "contents: write"
|
assert_includes workflow, "contents: write"
|
||||||
assert_includes workflow, "pull-requests: write"
|
assert_includes workflow, "pull-requests: write"
|
||||||
assert_includes workflow, "git add manifests/image-matrix.json manifests/upstream.json"
|
assert_includes workflow, "git add manifests/image-matrix.json manifests/upstream.json"
|
||||||
|
|||||||
Reference in New Issue
Block a user