135 lines
5.5 KiB
Django/Jinja
135 lines
5.5 KiB
Django/Jinja
name: CI
|
|
on:
|
|
push:
|
|
branches: [main]
|
|
paths-ignore:
|
|
- '**.md'
|
|
|
|
jobs:
|
|
smoke-test:
|
|
runs-on: host
|
|
|
|
# One persistent gc root per subsystem, kept OUTSIDE the per-run workspace.
|
|
#
|
|
# Each build step used to write ./result in the workspace, which act recreates for
|
|
# every run, and each step overwrote the previous one's symlink. So between runs
|
|
# exactly one output stayed rooted -- whichever subsystem happened to run last --
|
|
# and a nix-collect-garbage evicted all the others, making the next run rebuild the
|
|
# whole set from source.
|
|
#
|
|
# Rooting each subsystem separately keeps unchanged subsystems cached across a GC.
|
|
# A run replaces its own symlinks, so at most one closure per subsystem is retained.
|
|
# Deleting this directory is safe: it costs a rebuild, nothing else.
|
|
#
|
|
# Location: the runner's own state dir. It survives between runs, the runner owns
|
|
# it (no root, no fleet-repo provisioning), and the repo-named subdirectory leaves
|
|
# room for other repos to do the same.
|
|
env:
|
|
XO_GCROOTS: /var/lib/forgejo-runner/gcroots/xo-umbrella2
|
|
|
|
steps:
|
|
|
|
- name: debug env
|
|
run:
|
|
env | sort
|
|
|
|
- name: Setup PATH
|
|
run: |
|
|
echo "/nix/var/nix/profiles/default/bin" >> $GITHUB_PATH
|
|
echo "/var/lib/forgejo-runner/.nix-profile/bin" >> $GITHUB_PATH
|
|
|
|
- name: Check PATH
|
|
run:
|
|
echo $PATH
|
|
|
|
- name: Check cwd
|
|
run:
|
|
pwd
|
|
|
|
- name: Check nix version
|
|
run:
|
|
echo $(nix --version)
|
|
|
|
- name: nix store ping
|
|
run:
|
|
nix store info
|
|
|
|
- name: checkout
|
|
run: |
|
|
# 1. actions/checkout@v4 stumbles b/c install is at conybeare.us/git
|
|
# checkout manually instead.
|
|
# 2. could clone from /var/lib/forgejo/gitea-repositories/roland/xo-umbrella2.git
|
|
# 3. instead rely on $GITHUB_SERVER_URL
|
|
|
|
# the run's own commit, $GITHUB_SHA -- NOT a plain clone, which takes
|
|
# whatever main is when the job STARTS: with runs queued, a result
|
|
# then describes a later commit than the one it is labelled with
|
|
# (.xo-backlog/ci/issues/02).
|
|
# the workspace is owned by another user than this job's (the
|
|
# container's): without this, git refuses to work in it ("dubious
|
|
# ownership") once init has made it a repository
|
|
git config --global --add safe.directory "$PWD"
|
|
git init --quiet .
|
|
git remote add origin $GITHUB_SERVER_URL/roland/xo-umbrella2.git
|
|
git fetch --quiet --depth=1 origin "$GITHUB_SHA"
|
|
git checkout --quiet FETCH_HEAD
|
|
echo "checked out $(git rev-parse HEAD)"
|
|
|
|
- name: prepare gc roots
|
|
run: |
|
|
mkdir -p "$XO_GCROOTS"
|
|
# What survived the last gc, and therefore what this run can reuse.
|
|
echo "retained from previous runs: $(ls "$XO_GCROOTS" | wc -l) subsystems"
|
|
|
|
# ---- GENERATED from [[ template_name ]] by xo-gen-ci ----
|
|
# Do not edit these steps by hand. Membership and order come from
|
|
# [[ subsystem_list ]]; regenerate with:
|
|
# cmake --build .build --target xo-gen-ci
|
|
#
|
|
# Generated for the same reason ci-cmake.yaml is: this file was
|
|
# hand-maintained, so a subsystem added to subsystem-list reached the
|
|
# cmake pipeline at the next regeneration and this one only if someone
|
|
# remembered. It had drifted to 61 of 71 while reporting green -- see
|
|
# .xo-backlog/nix-packaging/issues/03.
|
|
#
|
|
# NO exclusions, unlike ci-cmake.yaml: this job runs on `host', which has
|
|
# the OpenGL driver bypass xo-imgui needs, and nix builds xo-cmake as an
|
|
# ordinary derivation rather than bootstrapping it.
|
|
#
|
|
# Steps that are NOT per-subsystem stay outside this block -- see the
|
|
# publish docs step below, whose target is a nix attribute with no entry
|
|
# in subsystem-list.
|
|
|
|
<% for sub in subsystems %>
|
|
- name: build [[ sub ]]
|
|
run: |
|
|
echo nix-build ci.nix -A [[ sub ]] -o "$XO_GCROOTS/[[ sub ]]"
|
|
nix-build ci.nix -A [[ sub ]] -o "$XO_GCROOTS/[[ sub ]]"
|
|
ls -l "$XO_GCROOTS/[[ sub ]]"
|
|
|
|
<% endfor %>
|
|
# Publish subsystem documentation to https://conybeare.us/xo-docs/.
|
|
#
|
|
# Nothing is rendered here: every subsystem with buildDocs = true already
|
|
# installed its html tree during the builds above, and xo-docs-site just gathers
|
|
# them behind stable per-subsystem URLs.
|
|
#
|
|
# -o makes 'current' a gc root, so nix-collect-garbage cannot collect the trees
|
|
# nginx is serving. Replacing the symlink releases the previous revision, so
|
|
# exactly one is retained.
|
|
#
|
|
# /var/www/xo-docs is created, owned by this runner, by the vpn1 fleet repo's
|
|
# activate.sh -- which also carries the matching nginx location.
|
|
- name: publish docs
|
|
run: |
|
|
echo nix-build ci.nix -A xo-docs-site -o /var/www/xo-docs/current
|
|
nix-build ci.nix -A xo-docs-site -o /var/www/xo-docs/current
|
|
ls -l /var/www/xo-docs/current/
|
|
|
|
# Check from outside rather than trusting the build: a site nginx cannot
|
|
# read, or a location block that never got installed, fails silently.
|
|
# --resolve avoids depending on hairpin NAT back to our own public address.
|
|
# This also means an expired TLS cert turns CI red, which is deliberate --
|
|
# vpn1 has no other alerting path yet.
|
|
curl -sS --fail --resolve conybeare.us:443:127.0.0.1 \
|
|
-o /dev/null https://conybeare.us/xo-docs/
|