An audit of a full green run's test + build-docs logs (agy scan, spot-
checked) turned up stray output beyond the mkrep git-init hint already
fixed. Two real bugs, plus CI-config cosmetics:
- agents-vault.fish/agents-init.fish: `set -l x (some_fish_function ...)`
command substitutions do not inherit a caller-scoped stderr redirect in
fish (proven with a two-line repro: `outer 2>/dev/null` where outer
does `set -l x (inner)` still leaks inner's stderr to the real
terminal). This let _agents_repo_ensure_symlink's and
_agents_repo_sync's raw internal error messages leak past `--silent`
for real users too, always duplicating the clean summary message each
caller already echoes on failure. Fixed at all 4 call sites by adding
an explicit `2>/dev/null` directly on each command substitution, since
a redirect on the outer call cannot reach it.
- ci.yml: apt-get install missing `apt-utils`, so debconf printed
"delaying package configuration" on every install in both jobs --
installing it first fixes the chicken-and-egg.
- ci.yml: added `NODE_OPTIONS: --no-deprecation` at the build-docs job
level to silence Node's internal punycode-module deprecation notice
(astro's toolchain still pulls it in transitively).
- ci.yml: `npm ci --no-fund` drops the funding nag.
- ci.yml: `gpg --batch --quiet --import` drops gpg's normal-case import
status lines during the bot commit-signing setup.
Deliberately NOT silenced: npm's deprecated-glob warning, its audit
vulnerability summary, and its allow-scripts notice about esbuild's
postinstall -- these are genuine dependency-hygiene signal, not noise,
and no workflow-level flag exists to hide them without also hiding real
future findings. Also not fixable here: a Gitea Actions/act runner
warning ('runs-on' key not defined in CI/test) that traces to neither
workflow YAML in this repo -- both already set runs-on on every job,
confirmed twice; it's runner-internal, like actions/checkout's own
git-init hint in its Checkout-step preamble.
Verified: full suite 730/730 passing ($status 0); the exact mkdir-
collision repro that surfaced the command-substitution bug re-run
clean (rc=1, empty stderr); test-agents-vault.fish standalone,
320/320, zero occurrences of the previously-leaked messages.
179 lines
7.0 KiB
YAML
179 lines
7.0 KiB
YAML
name: CI
|
|
|
|
on:
|
|
push:
|
|
branches:
|
|
- main
|
|
paths:
|
|
- "docs/manual/**"
|
|
- "docs/build-manual.py"
|
|
- "docs/manualtools.py"
|
|
- "docs/verify-manual.py"
|
|
- "docs/site/**"
|
|
- "functions/**"
|
|
- "conf.d/**"
|
|
- "config.fish"
|
|
- "completions/**"
|
|
- "integrations/**"
|
|
- "tests/**"
|
|
workflow_dispatch:
|
|
inputs:
|
|
job:
|
|
description: "Job to run"
|
|
required: false
|
|
default: all
|
|
type: choice
|
|
options:
|
|
- all
|
|
- test
|
|
- build-docs
|
|
|
|
jobs:
|
|
# This workflow file is mirrored to GitHub as-is, but the runner label
|
|
# below (racknerd-mini) only exists on the Gitea instance -- on GitHub
|
|
# the job just sits queued forever with no matching runner, so the
|
|
# mirror never gets a completed status. Gate the real jobs to Gitea and
|
|
# let the github-mirror job below stand in on GitHub instead.
|
|
test:
|
|
if: |
|
|
github.server_url != 'https://github.com' &&
|
|
(github.event_name != 'workflow_dispatch' || github.event.inputs.job == 'all' || github.event.inputs.job == 'test')
|
|
runs-on: racknerd-mini
|
|
steps:
|
|
- name: Checkout
|
|
uses: actions/checkout@v4
|
|
with:
|
|
token: ${{ secrets.GITEA_TOKEN }}
|
|
|
|
- name: Install fish
|
|
run: |
|
|
sudo apt-get -o Acquire::Retries=3 update -qq
|
|
# apt-utils first: its absence is what makes debconf print
|
|
# "delaying package configuration" on every install below.
|
|
sudo DEBIAN_FRONTEND=noninteractive apt-get install --no-install-recommends -y apt-utils software-properties-common
|
|
sudo add-apt-repository -y ppa:fish-shell/release-4
|
|
sudo apt-get -o Acquire::Retries=3 update -qq
|
|
sudo DEBIAN_FRONTEND=noninteractive apt-get install --no-install-recommends -y fish
|
|
|
|
- name: Run fish config tests
|
|
run: fish tests/run-tests.fish
|
|
|
|
build-docs:
|
|
needs: test
|
|
if: |
|
|
github.server_url != 'https://github.com' &&
|
|
always() &&
|
|
(github.event.inputs.job == 'build-docs' ||
|
|
((github.event_name != 'workflow_dispatch' || github.event.inputs.job == 'all') &&
|
|
needs.test.result == 'success'))
|
|
runs-on: racknerd-mini
|
|
env:
|
|
# Silences Node's internal "punycode module is deprecated" notice
|
|
# (astro's toolchain still requires it transitively) on every node
|
|
# invocation in this job, setup-node's own included.
|
|
NODE_OPTIONS: --no-deprecation
|
|
steps:
|
|
- name: Checkout
|
|
uses: actions/checkout@v4
|
|
with:
|
|
token: ${{ secrets.GITEA_TOKEN }}
|
|
|
|
- name: Install dependencies
|
|
run: |
|
|
sudo apt-get -o Acquire::Retries=3 update -qq
|
|
# apt-utils first: its absence is what makes debconf print
|
|
# "delaying package configuration" on every install below.
|
|
sudo DEBIAN_FRONTEND=noninteractive apt-get install --no-install-recommends -y apt-utils software-properties-common
|
|
sudo add-apt-repository -y ppa:fish-shell/release-4
|
|
sudo apt-get -o Acquire::Retries=3 update -qq
|
|
sudo DEBIAN_FRONTEND=noninteractive apt-get install --no-install-recommends -y pandoc python3-yaml fish
|
|
|
|
- name: Generate concatenated markdown
|
|
run: python3 docs/build-manual.py --concat -o docs/fish-config.md
|
|
|
|
# Regeneration MUST run before verification: verify-manual.py's
|
|
# test_concat_roundtrips_original compares a freshly-built concat
|
|
# against docs/fish-config.md on disk. Before this step ran, that
|
|
# file was still the stale pre-push copy, so any ordinary edit under
|
|
# docs/manual/** failed the round-trip check before anything was
|
|
# regenerated. Do not reorder this back — verification still gates
|
|
# pandoc and the auto-commit below, it just no longer requires a
|
|
# contributor to hand-sync the generated file before pushing.
|
|
- name: Verify manual integrity
|
|
run: python3 docs/verify-manual.py
|
|
|
|
- name: Compile man page
|
|
run: |
|
|
pandoc --standalone \
|
|
--from markdown \
|
|
--to man \
|
|
docs/fish-config.md \
|
|
-o docs/fish-config.1
|
|
|
|
- name: Set up Node
|
|
uses: actions/setup-node@v4
|
|
with:
|
|
node-version: "24"
|
|
|
|
- name: Generate site content
|
|
run: python3 docs/build-manual.py --site
|
|
|
|
- name: Build project wiki
|
|
working-directory: docs/site
|
|
run: |
|
|
npm ci --no-fund
|
|
npx astro build
|
|
|
|
- name: Deploy to Cloudflare Pages
|
|
working-directory: docs/site
|
|
env:
|
|
CLOUDFLARE_API_TOKEN: ${{ secrets.CF_API_TOKEN }}
|
|
CLOUDFLARE_ACCOUNT_ID: ${{ secrets.CF_ACCOUNT_ID }}
|
|
run: |
|
|
npx --yes wrangler pages deploy dist/ \
|
|
--project-name=fish-config-docs \
|
|
--branch=main \
|
|
--commit-dirty=true
|
|
|
|
- name: Commit generated docs
|
|
env:
|
|
BOT_GPG_KEY: ${{ secrets.CI_GPG_PRIVATE_KEY }}
|
|
run: |
|
|
# actions@gitea was never a verified email on any account, so
|
|
# these commits could never show as signed/verified regardless
|
|
# of server config. fishconfig-bot is a dedicated Gitea account
|
|
# (verified email, no login) that owns this key; the private
|
|
# key lives only in the CI_GPG_PRIVATE_KEY repo secret.
|
|
#
|
|
# Secret is base64-encoded: a raw multi-line armored key piped
|
|
# through `echo "$VAR" | gpg --import` came out CRC-corrupted
|
|
# ("Invalid keyring") the first time this ran -- something in
|
|
# the secret/env round-trip mangles embedded newlines. Base64
|
|
# collapses it to one line immune to that.
|
|
export GNUPGHOME="$(mktemp -d)"
|
|
chmod 700 "$GNUPGHOME"
|
|
echo "pinentry-mode loopback" > "$GNUPGHOME/gpg.conf"
|
|
echo "allow-loopback-pinentry" > "$GNUPGHOME/gpg-agent.conf"
|
|
command -v gpg >/dev/null || sudo apt-get install -y --no-install-recommends gnupg
|
|
echo "$BOT_GPG_KEY" | base64 -d | gpg --batch --quiet --import
|
|
git config user.name "Gitea Actions Bot"
|
|
git config user.email "fishconfig-bot@git.rootiest.dev"
|
|
git config user.signingkey CAA082C2F3467E1F7217AD492075C120312D23F4
|
|
git config commit.gpgsign true
|
|
git add docs/fish-config.md docs/fish-config.1 conf.d/__fish_config_op_registry.fish
|
|
git diff --cached --quiet && echo "No changes to commit" && exit 0
|
|
git commit -m "chore(docs): regenerate manual, man page, and component registry"
|
|
git push
|
|
|
|
# Stand-in for the GitHub mirror so the commit gets a completed status
|
|
# instead of the real jobs above sitting queued forever for a
|
|
# self-hosted runner that only exists on the Gitea instance.
|
|
github-mirror:
|
|
if: github.server_url == 'https://github.com'
|
|
runs-on: ubuntu-latest
|
|
steps:
|
|
- name: Note that CI runs on Gitea
|
|
run: |
|
|
echo "This repository mirrors from Gitea (git.rootiest.dev), where CI actually runs."
|
|
echo "See the commit's status on the Gitea instance for the real test/build-docs results."
|