-
Notifications
You must be signed in to change notification settings - Fork 0
119 lines (107 loc) · 4.6 KB
/
Copy pathci.yml
File metadata and controls
119 lines (107 loc) · 4.6 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
name: CI
on:
push:
branches: [main]
pull_request:
concurrency:
group: ${{ github.workflow }}-${{ github.ref }}
cancel-in-progress: true
jobs:
lint-shell:
name: ShellCheck + syntax
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@df4cb1c069e1874edd31b4311f1884172cec0e10 # v6
- name: bash -n + shellcheck (same set as `make lint`)
run: |
set -euo pipefail
for f in wsl/*.sh demo/lib/*.sh; do
echo "== $f =="
bash -n "$f"
shellcheck -S warning "$f"
done
echo "All shell scripts clean."
lint-powershell:
name: PSScriptAnalyzer
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@df4cb1c069e1874edd31b4311f1884172cec0e10 # v6
- name: Analyze windows/*.ps1
shell: pwsh
run: |
Install-Module PSScriptAnalyzer -Force -Scope CurrentUser
$warnings = Invoke-ScriptAnalyzer -Path windows -Recurse -Severity Warning
if ($warnings) {
Write-Host "`n--- Warnings (informational) ---"
$warnings | Format-Table RuleName, ScriptName, Line, Message -AutoSize | Out-String | Write-Host
}
$errors = Invoke-ScriptAnalyzer -Path windows -Recurse -Severity Error
if ($errors) {
Write-Host "`n--- Errors (blocking) ---"
$errors | Format-Table RuleName, ScriptName, Line, Message -AutoSize | Out-String | Write-Host
exit 1
}
Write-Host "No PSScriptAnalyzer errors."
windows-powershell:
name: "Windows PowerShell 5.1 parse + non-mutating paths"
runs-on: windows-latest
steps:
- uses: actions/checkout@df4cb1c069e1874edd31b4311f1884172cec0e10 # v6
# User machines run these via powershell.exe (5.1) - parse with THAT
# engine, since PSScriptAnalyzer in the lint job runs on pwsh core.
- name: Parse all scripts with Windows PowerShell 5.1
shell: powershell
run: |
$failed = $false
Get-ChildItem windows -Filter *.ps1 | ForEach-Object {
$tokens = $null; $errors = $null
[System.Management.Automation.Language.Parser]::ParseFile($_.FullName, [ref]$tokens, [ref]$errors) | Out-Null
if ($errors.Count) {
$failed = $true
Write-Host "PARSE ERRORS in $($_.Name):"
$errors | ForEach-Object { Write-Host (" line {0}: {1}" -f $_.Extent.StartLineNumber, $_.Message) }
} else {
Write-Host "[OK] $($_.Name)"
}
}
if ($failed) { exit 1 }
- name: wsl-tools.ps1 help path (touches no WSL state)
shell: powershell
run: .\windows\wsl-tools.ps1 help
smoke-stage2:
name: "stage2 end-to-end: install twice, verify"
runs-on: ubuntu-latest
timeout-minutes: 45
env:
GIT_NAME: CI Smoke
GIT_EMAIL: ci@example.invalid
# stage2's GitHub API lookups (golangci-lint latest tag) honor this -
# unauthenticated api.github.com calls rate-limit hard on shared runner IPs
GITHUB_TOKEN: ${{ github.token }}
steps:
- uses: actions/checkout@df4cb1c069e1874edd31b4311f1884172cec0e10 # v6
# GitHub's runner image ships firefox as a snap-backed deb; `apt upgrade`
# can then stall for minutes on a huge snap download. WSL Ubuntu ships
# neither firefox nor active snapd, so this exercises nothing we ship -
# hold the packages so the smoke test measures the kit, not snap's CDN.
- name: Hold snap-backed packages (runner-only stall source)
run: |
sudo apt-mark hold firefox snapd 2>/dev/null || true
sudo snap refresh --hold 2>/dev/null || true
- name: "Run 1: provision the runner with the CI profile"
run: bash wsl/stage2-ubuntu.sh --profile tests/profiles/ci.conf
- name: Snapshot ~/.bashrc after run 1
run: cp ~/.bashrc /tmp/bashrc.run1
- name: "Run 2: re-run to prove idempotency"
run: bash wsl/stage2-ubuntu.sh --profile tests/profiles/ci.conf
- name: "Assert: managed block written exactly once, byte-identical across runs"
run: |
set -euo pipefail
starts=$(grep -c '^# Development Environment Configuration$' ~/.bashrc)
ends=$(grep -c '^# END Development Environment Configuration$' ~/.bashrc)
echo "start markers: $starts, end markers: $ends"
[ "$starts" -eq 1 ] && [ "$ends" -eq 1 ]
diff /tmp/bashrc.run1 ~/.bashrc && echo "~/.bashrc identical after re-run (idempotent)"
- name: "Assert: health check passes (verify-setup.sh)"
run: |
bash wsl/verify-setup.sh