3da44eed63
jar_id() in redeploy-fleetd.sh called shasum directly, which does not exist on GNU coreutils Linux (Debian/Ubuntu/etc.) — there it silently reported an existing jar as "absent" with exit 0, because the missing command made `cut` succeed on empty input and pipefail's failure was then swallowed by the `|| echo "absent"` fallback. The shell test suite hit the same tool at test-redeploy-fleetd.sh:298-299 and died at exit 127 with zero FAIL lines printed — the same shape as a clean pass on the one channel anyone would check. Adds one hash256() helper (prefer sha256sum, fall back to shasum -a 256, same idiom already used in probe-member-credentials.sh) and points jar_id and the test suite's own reference hash at it. jar_id now has three distinct answers instead of two: absent, a hash, or "unhashable" when neither hasher is on PATH — "absent" is never used for a file that exists. Adds a CI job (shell-tests) that runs scripts/test-redeploy-fleetd.sh on ubuntu-latest, gated on the step's own exit code rather than a FAIL-line count, since a suite that dies before running is exactly what a green run also looks like by that count. New tests: test_jar_id_reports_unhashable_when_no_hasher_on_path (stubbed PATH with neither hasher) and test_no_unguarded_macos_only_hasher_calls (a shape check across every script under scripts/, not named lines — #545 already showed this idiom spreading from two sites to six).
133 lines
6.1 KiB
YAML
133 lines
6.1 KiB
YAML
name: CI
|
|
|
|
on:
|
|
push:
|
|
branches: [main]
|
|
pull_request:
|
|
branches: [main]
|
|
|
|
jobs:
|
|
build:
|
|
runs-on: ubuntu-latest
|
|
steps:
|
|
# The wiki submodule is docs only and is not needed to build — leave it unfetched so CI
|
|
# does not depend on the wiki repo being reachable.
|
|
- uses: actions/checkout@v4
|
|
|
|
# The runner image ships an older default-jdk; fleetd sets maven.compiler.release=25, so
|
|
# provision the JDK explicitly rather than apt-installing whatever "default" means today.
|
|
- name: Set up JDK 25
|
|
uses: actions/setup-java@v4
|
|
with:
|
|
distribution: temurin
|
|
java-version: '25'
|
|
cache: maven
|
|
|
|
# setup-java provisions the JDK only — it does NOT install Maven, and the runner image has
|
|
# no mvn on PATH (a bare `mvn` exits 127). Install it separately. apt pulls a default JRE as
|
|
# a dependency; JAVA_HOME from setup-java still wins, which the version check below proves.
|
|
- name: Install Maven
|
|
run: |
|
|
apt-get update && apt-get install -y --no-install-recommends maven
|
|
mvn -version
|
|
|
|
- name: Build and test
|
|
working-directory: fleetd
|
|
# This IS the mock-socket surface CB-503 asks for: the pom's `default-excludes` profile
|
|
# already sets excludedGroups=contract, so the @Tag("contract") tests — which need a live
|
|
# herdr socket and a RabbitMQ container — are excluded without any flag here. Everything
|
|
# that runs does so against the fake UDS herdr and fake ccs/claude stubs.
|
|
run: mvn -B clean install
|
|
|
|
- name: javadoc reference lint
|
|
working-directory: fleetd
|
|
run: mvn -B -DskipTests javadoc:javadoc -Ddoclint=reference
|
|
|
|
# Deliberately NOT actions/upload-artifact: this Gitea instance presents as GHES, and
|
|
# @actions/artifact v2+ (i.e. upload-artifact@v4) refuses to run there —
|
|
# "GHESNotSupportedError ... not currently supported on GHES", which red-Xes an otherwise
|
|
# green build. Since the artifact could not be retrieved anyway, dump the failing tests into
|
|
# the log instead, where they are actually readable.
|
|
- name: Failing test output
|
|
if: failure()
|
|
working-directory: fleetd
|
|
run: |
|
|
for f in target/surefire-reports/*.txt; do
|
|
[ -f "$f" ] || continue
|
|
grep -qE "Failures: [1-9]|Errors: [1-9]" "$f" && { echo "===== $f ====="; cat "$f"; }
|
|
done
|
|
exit 0
|
|
|
|
# fleetd #550 — nothing ran scripts/test-redeploy-fleetd.sh in CI before this, on any platform,
|
|
# so it had run only on macOS by hand and two Linux-only bugs (this issue's items 1 and 2)
|
|
# survived undetected: shasum is a macOS-only tool (it ships with Perl; GNU coreutils, i.e. every
|
|
# mainstream Linux distro including this runner's ubuntu-latest, does not have it and ships
|
|
# sha256sum instead). The gate here is the step's own exit code, nothing else: a `run:` step in
|
|
# Gitea/GitHub Actions already fails the job on a non-zero exit with no extra scripting needed,
|
|
# so this deliberately does NOT grep the output for a `FAIL:` count. That is the #550 item-2
|
|
# lesson one level up — a suite that dies before it runs a single test prints zero FAIL lines,
|
|
# which is exactly what a clean pass also prints, so counting FAIL lines can never be the gate.
|
|
shell-tests:
|
|
runs-on: ubuntu-latest
|
|
steps:
|
|
- uses: actions/checkout@v4
|
|
|
|
- name: redeploy-fleetd.sh shell suite
|
|
run: bash scripts/test-redeploy-fleetd.sh
|
|
|
|
# CB-521 — actually run the AMQP contract test in CI, against a REAL broker. The broker is a
|
|
# RabbitMQ SERVICE CONTAINER, not Testcontainers-with-Docker: the runner image has no Docker, so
|
|
# AmqpReplyInboxContractTest reads AMQP_URI (set below to the service's network alias) and binds
|
|
# straight to it — no Docker, no skipped tests. This separation (build job hermetic and
|
|
# Docker-free; contract job broker-provided) is deliberate — see the default-excludes/contract
|
|
# profiles in fleetd/pom.xml. `setup-java` provides the JDK only; Maven is installed separately,
|
|
# exactly as in the build job above.
|
|
contract:
|
|
runs-on: ubuntu-latest
|
|
services:
|
|
rabbitmq:
|
|
image: rabbitmq:3.13 # same AMQP 0-9-1 engine the local Testcontainers fixture uses
|
|
env:
|
|
RABBITMQ_DEFAULT_USER: guest
|
|
RABBITMQ_DEFAULT_PASS: guest
|
|
env:
|
|
# Service containers are reachable from the job by their network alias on their internal port.
|
|
AMQP_URI: amqp://guest:guest@rabbitmq:5672
|
|
steps:
|
|
- uses: actions/checkout@v4
|
|
|
|
- name: Set up JDK 25
|
|
uses: actions/setup-java@v4
|
|
with:
|
|
distribution: temurin
|
|
java-version: '25'
|
|
cache: maven
|
|
|
|
- name: Install Maven
|
|
run: |
|
|
apt-get update && apt-get install -y --no-install-recommends maven
|
|
mvn -version
|
|
|
|
# The `contract` profile clears the default-excludes group, so `-Dgroups=contract` runs every
|
|
# @Tag("contract") test and nothing from the unit suite the `build` job already covered — a
|
|
# tag selects the whole group, so a test added to it later runs here automatically. A prior
|
|
# version of this step pinned `-Dtest=AmqpReplyInboxContractTest` by class name instead: that
|
|
# silently excluded every other contract test (including the herdr ones) from CI, and nobody
|
|
# noticed until the herdr protocol drifted out from under a test that never ran here
|
|
# (fleetd #449). If this runner has no herdr socket, the herdr-backed tests in the group
|
|
# skip on their own `assumeTrue` and only the broker-backed ones actually run — check the
|
|
# step output rather than assuming which.
|
|
- name: Contract tests
|
|
working-directory: fleetd
|
|
run: mvn -B -Pcontract test -Dgroups=contract
|
|
|
|
- name: Failing test output
|
|
if: failure()
|
|
working-directory: fleetd
|
|
run: |
|
|
for f in target/surefire-reports/*.txt; do
|
|
[ -f "$f" ] || continue
|
|
grep -qE "Failures: [1-9]|Errors: [1-9]" "$f" && { echo "===== $f ====="; cat "$f"; }
|
|
done
|
|
exit 0
|