Files
fish-config/.github/workflows/ci.yml
T
rootiest af7502d6b1 fix(ci): silence CI/tool noise found auditing the test-job log
An audit of a full green run's test + build-docs logs (agy scan, spot-
checked) turned up stray output beyond the mkrep git-init hint already
fixed. Two real bugs, plus CI-config cosmetics:

- agents-vault.fish/agents-init.fish: `set -l x (some_fish_function ...)`
  command substitutions do not inherit a caller-scoped stderr redirect in
  fish (proven with a two-line repro: `outer 2>/dev/null` where outer
  does `set -l x (inner)` still leaks inner's stderr to the real
  terminal). This let _agents_repo_ensure_symlink's and
  _agents_repo_sync's raw internal error messages leak past `--silent`
  for real users too, always duplicating the clean summary message each
  caller already echoes on failure. Fixed at all 4 call sites by adding
  an explicit `2>/dev/null` directly on each command substitution, since
  a redirect on the outer call cannot reach it.
- ci.yml: apt-get install missing `apt-utils`, so debconf printed
  "delaying package configuration" on every install in both jobs --
  installing it first fixes the chicken-and-egg.
- ci.yml: added `NODE_OPTIONS: --no-deprecation` at the build-docs job
  level to silence Node's internal punycode-module deprecation notice
  (astro's toolchain still pulls it in transitively).
- ci.yml: `npm ci --no-fund` drops the funding nag.
- ci.yml: `gpg --batch --quiet --import` drops gpg's normal-case import
  status lines during the bot commit-signing setup.

Deliberately NOT silenced: npm's deprecated-glob warning, its audit
vulnerability summary, and its allow-scripts notice about esbuild's
postinstall -- these are genuine dependency-hygiene signal, not noise,
and no workflow-level flag exists to hide them without also hiding real
future findings. Also not fixable here: a Gitea Actions/act runner
warning ('runs-on' key not defined in CI/test) that traces to neither
workflow YAML in this repo -- both already set runs-on on every job,
confirmed twice; it's runner-internal, like actions/checkout's own
git-init hint in its Checkout-step preamble.

Verified: full suite 730/730 passing ($status 0); the exact mkdir-
collision repro that surfaced the command-substitution bug re-run
clean (rc=1, empty stderr); test-agents-vault.fish standalone,
320/320, zero occurrences of the previously-leaked messages.
2026-09-22 02:37:42 -04:00

179 lines
7.0 KiB
YAML

name: CI
on:
push:
branches:
- main
paths:
- "docs/manual/**"
- "docs/build-manual.py"
- "docs/manualtools.py"
- "docs/verify-manual.py"
- "docs/site/**"
- "functions/**"
- "conf.d/**"
- "config.fish"
- "completions/**"
- "integrations/**"
- "tests/**"
workflow_dispatch:
inputs:
job:
description: "Job to run"
required: false
default: all
type: choice
options:
- all
- test
- build-docs
jobs:
# This workflow file is mirrored to GitHub as-is, but the runner label
# below (racknerd-mini) only exists on the Gitea instance -- on GitHub
# the job just sits queued forever with no matching runner, so the
# mirror never gets a completed status. Gate the real jobs to Gitea and
# let the github-mirror job below stand in on GitHub instead.
test:
if: |
github.server_url != 'https://github.com' &&
(github.event_name != 'workflow_dispatch' || github.event.inputs.job == 'all' || github.event.inputs.job == 'test')
runs-on: racknerd-mini
steps:
- name: Checkout
uses: actions/checkout@v4
with:
token: ${{ secrets.GITEA_TOKEN }}
- name: Install fish
run: |
sudo apt-get -o Acquire::Retries=3 update -qq
# apt-utils first: its absence is what makes debconf print
# "delaying package configuration" on every install below.
sudo DEBIAN_FRONTEND=noninteractive apt-get install --no-install-recommends -y apt-utils software-properties-common
sudo add-apt-repository -y ppa:fish-shell/release-4
sudo apt-get -o Acquire::Retries=3 update -qq
sudo DEBIAN_FRONTEND=noninteractive apt-get install --no-install-recommends -y fish
- name: Run fish config tests
run: fish tests/run-tests.fish
build-docs:
needs: test
if: |
github.server_url != 'https://github.com' &&
always() &&
(github.event.inputs.job == 'build-docs' ||
((github.event_name != 'workflow_dispatch' || github.event.inputs.job == 'all') &&
needs.test.result == 'success'))
runs-on: racknerd-mini
env:
# Silences Node's internal "punycode module is deprecated" notice
# (astro's toolchain still requires it transitively) on every node
# invocation in this job, setup-node's own included.
NODE_OPTIONS: --no-deprecation
steps:
- name: Checkout
uses: actions/checkout@v4
with:
token: ${{ secrets.GITEA_TOKEN }}
- name: Install dependencies
run: |
sudo apt-get -o Acquire::Retries=3 update -qq
# apt-utils first: its absence is what makes debconf print
# "delaying package configuration" on every install below.
sudo DEBIAN_FRONTEND=noninteractive apt-get install --no-install-recommends -y apt-utils software-properties-common
sudo add-apt-repository -y ppa:fish-shell/release-4
sudo apt-get -o Acquire::Retries=3 update -qq
sudo DEBIAN_FRONTEND=noninteractive apt-get install --no-install-recommends -y pandoc python3-yaml fish
- name: Generate concatenated markdown
run: python3 docs/build-manual.py --concat -o docs/fish-config.md
# Regeneration MUST run before verification: verify-manual.py's
# test_concat_roundtrips_original compares a freshly-built concat
# against docs/fish-config.md on disk. Before this step ran, that
# file was still the stale pre-push copy, so any ordinary edit under
# docs/manual/** failed the round-trip check before anything was
# regenerated. Do not reorder this back — verification still gates
# pandoc and the auto-commit below, it just no longer requires a
# contributor to hand-sync the generated file before pushing.
- name: Verify manual integrity
run: python3 docs/verify-manual.py
- name: Compile man page
run: |
pandoc --standalone \
--from markdown \
--to man \
docs/fish-config.md \
-o docs/fish-config.1
- name: Set up Node
uses: actions/setup-node@v4
with:
node-version: "24"
- name: Generate site content
run: python3 docs/build-manual.py --site
- name: Build project wiki
working-directory: docs/site
run: |
npm ci --no-fund
npx astro build
- name: Deploy to Cloudflare Pages
working-directory: docs/site
env:
CLOUDFLARE_API_TOKEN: ${{ secrets.CF_API_TOKEN }}
CLOUDFLARE_ACCOUNT_ID: ${{ secrets.CF_ACCOUNT_ID }}
run: |
npx --yes wrangler pages deploy dist/ \
--project-name=fish-config-docs \
--branch=main \
--commit-dirty=true
- name: Commit generated docs
env:
BOT_GPG_KEY: ${{ secrets.CI_GPG_PRIVATE_KEY }}
run: |
# actions@gitea was never a verified email on any account, so
# these commits could never show as signed/verified regardless
# of server config. fishconfig-bot is a dedicated Gitea account
# (verified email, no login) that owns this key; the private
# key lives only in the CI_GPG_PRIVATE_KEY repo secret.
#
# Secret is base64-encoded: a raw multi-line armored key piped
# through `echo "$VAR" | gpg --import` came out CRC-corrupted
# ("Invalid keyring") the first time this ran -- something in
# the secret/env round-trip mangles embedded newlines. Base64
# collapses it to one line immune to that.
export GNUPGHOME="$(mktemp -d)"
chmod 700 "$GNUPGHOME"
echo "pinentry-mode loopback" > "$GNUPGHOME/gpg.conf"
echo "allow-loopback-pinentry" > "$GNUPGHOME/gpg-agent.conf"
command -v gpg >/dev/null || sudo apt-get install -y --no-install-recommends gnupg
echo "$BOT_GPG_KEY" | base64 -d | gpg --batch --quiet --import
git config user.name "Gitea Actions Bot"
git config user.email "fishconfig-bot@git.rootiest.dev"
git config user.signingkey CAA082C2F3467E1F7217AD492075C120312D23F4
git config commit.gpgsign true
git add docs/fish-config.md docs/fish-config.1 conf.d/__fish_config_op_registry.fish
git diff --cached --quiet && echo "No changes to commit" && exit 0
git commit -m "chore(docs): regenerate manual, man page, and component registry"
git push
# Stand-in for the GitHub mirror so the commit gets a completed status
# instead of the real jobs above sitting queued forever for a
# self-hosted runner that only exists on the Gitea instance.
github-mirror:
if: github.server_url == 'https://github.com'
runs-on: ubuntu-latest
steps:
- name: Note that CI runs on Gitea
run: |
echo "This repository mirrors from Gitea (git.rootiest.dev), where CI actually runs."
echo "See the commit's status on the Gitea instance for the real test/build-docs results."