Add enable-email-notifications: true. This seems to be needed for sending
information about failed runs. Apparently it doesn't make it difference if I
add it to ci/workflows/.github/workflows/test-packaging.yaml.
Signed-off-by: Jan Lindemann <jan@janware.com>
In another attempt at making CI workflow naming more concise:
- Rename standard-tests.yaml to ci.yaml
Currently the contents of this file covers everything CI-related
that happens in the context workflows, so for the time being,
naming it ci.yaml is just fitting. And it's going to be shorter
in commit message summaries. Should a real need arise, we can
always split the file up again.
- Shorten names again, otherwise they don't fit into Forgejo's
check-mark-popup. That should be self-explanatory in context:
name:
Default CI -> CI
jobs.CI.name:
Packaging test - All supported platforms -> Packaging test
Signed-off-by: Jan Lindemann <jan@janware.com>
Running pyright in a minimal docker container gives this error:
$ pyright
/usr/bin/npm-default: No such file or directory
Traceback (most recent call last):
File "/usr/bin/pyright-3.13", line 6, in <module>
sys.exit(entrypoint())
~~~~~~~~~~^^
File "/usr/lib/python3.13/site-packages/pyright/cli.py", line 31, in entrypoint
sys.exit(main(sys.argv[1:]))
~~~~^^^^^^^^^^^^^^
File "/usr/lib/python3.13/site-packages/pyright/cli.py", line 18, in main
return run(*args, **kwargs).returncode
~~~^^^^^^^^^^^^^^^^^
File "/usr/lib/python3.13/site-packages/pyright/cli.py", line 22, in run
pkg_dir = install_pyright(args, quiet=None)
File "/usr/lib/python3.13/site-packages/pyright/_utils.py", line 69, in install_pyright
node.run(
~~~~~~~~^
'npm',
^^^^^^
...<5 lines>...
stderr=subprocess.PIPE if silent else sys.stderr,
^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^
)
^
File "/usr/lib/python3.13/site-packages/pyright/node.py", line 144, in run
subprocess.run(node_args, **kwargs),
~~~~~~~~~~~~~~^^^^^^^^^^^^^^^^^^^^^
File "/usr/lib64/python3.13/subprocess.py", line 577, in run
raise CalledProcessError(retcode, process.args,
output=stdout, stderr=stderr)
subprocess.CalledProcessError: Command '['/usr/bin/npm', 'install', \
'pyright@1.1.409']' returned non-zero exit status 255.
This means that on openSUSE, python3-pyright tries to pull in
packages from the NPM registry. This increases the CI supply chain
attack surface inacceptably, so remove pyright from the release
prerequisites. That should be enough to remove it from the
prerequisites of target check as well and allow it to succeed.
The pyright check machinery itself remains useful, so keep it in
place for developers who install python3-pyright manually.
Signed-off-by: Jan Lindemann <jan@janware.com>
By the time projects-dir.mk is used during onboarding, it's already
cloned, and so is jw-pkg in all its glory. So better use a
ssh-wrapper.sh directly under jw-pkg's version control instead of
plainly generating one with echo some-script-logic > ssh-wrapper.sh.
This has the main benefit of allowing a more elaborate script. The
one added by this commit removes "-l user" from remotes which have a
standard-user@gitserver form, typically because they differentiate
users via their SSH pubkeys only, and which would deny access if both
-l user and standard-user@ were specified.
ssh-wrapper.sh still needs to be a target which is updated by a
recipe, because the version found in jw-pkg can't be trusted to be
executable during bootstrapping, because "make all" has not run, yet.
Signed-off-by: Jan Lindemann <jan@janware.com>
After release, pkg.sh pushes the changes to VERSION and HASH
upstream. Failures are masked, though, propagate them.
Unclear what motivated masking the error. Tracking that down with git
blame leads to build-package.sh, which was inherited from ytools,
where the change was introduced 2014 with the trust-inspiring
comment:
attempted fix for error during commit of version files in
build-package.sh
Signed-off-by: Jan Lindemann <jan@janware.com>
The git-get-pub does not have the same effect as the other git-get-%
targets, and this commit makes it.
The other git-get-% targets run pgit.sh, which rebases the current
branch onto the fetched branch, and git-get-pub doesn't. Since devops
merges contributor forges fast-forward without a merge-commit, the
pub remote's master needs to be the last to be rebased on, because
otherwise it will not allow to force-push the result.
As soon as multiple forges with protected master branches contribute,
fast-forward merging of the master branch will need to be abolished
anyway, and the release machinery will need an overhaul.
Signed-off-by: Jan Lindemann <jan@janware.com>
- Remove package_name and package_path from the prototype of
detect_modules(). They can and should be deduced from
namespace['__name__'] and namespace['__path__'], respectively.
- Make prefix default to None, which signifies "Don't filter by
prefix".
- Add an optional extend_namespace parameter, which will make the
function append the module's __name__ to its __path__. This
defaults to True, thereby adding a side effect to the function.
Which is always wanted in the case for all callers of this
function.
Signed-off-by: Jan Lindemann <jan@janware.com>
pkg.requires.os.release = python3-pyright breaks CI on Kali Linux. It
is present in the janware repos, but using those would cross a line:
jw-pkg must be buildable from the base repositories alone, so don't make
pyright mandatory for Debian, because that pulls it in for Kali, too.
Ironically, the Debian repo provides it. Which makes it obvious that
we will need another entry in the os cascade for Debian proper to
allow pulling in such packages on Debian.
Signed-off-by: Jan Lindemann <jan@janware.com>
Be prepared to not have working pyright. This is necessary, because
the next commit will remove it for Debian.
Signed-off-by: Jan Lindemann <jan@janware.com>
Target all should create all necessary files in topdir. Currently
they're only needed for static file checks, but they might well be
prerequistes for the build to succeed in the future, so make target
all depend on topdir.
Also, place target all before the block of includes, so that the
execution order is defined in topdir.mk rather than the included
snippets.
Signed-off-by: Jan Lindemann <jan@janware.com>
Add two new targets, basically
py-check-annotation-imports:
ruff check --select TC,FA --fix --unsafe-fixes .
py-format-annotation-imports:
ruff format --select TC,FA --fix --unsafe-fixes .
They basically import statements merely used for annotation
only during type checking runs:
if TYPE_CHECKING:
import AirFrobnicator from frobnication
Signed-off-by: Jan Lindemann <jan@janware.com>
This commit reorganizes build-package.yaml in several ways:
- Follow name change of the called workflow
The reusable workflow used by build-package.yaml changed name and
location, and this commit follows the move. It was located at
ci/action-build-package before and has moved to ci/workflows,
because what it provides is semantically more of a workflow than
an action.
- Limit CI runs
The commit also adds safeguards against too many CI runs. It
limits them to PR events opened, re-opened or pushed-to, and to
push events hitting branches master, main and release.
- Rename workflow itself to standard-tests.yaml
That name reflects better what it represents: The entry point to
janware's standard set of CI tests. All of them happen to run in
the context of building and packaging at this point, but that
might not be the only standard test this repo chooses to
subscribe to in the future, and if so, they will be better off in
one file with defined order, so give that file a better umbrella
name.
Signed-off-by: Jan Lindemann <jan@janware.com>
.lib.Result has grown enourmously in size and merits its own module.
For now, reexport it from .lib.base to not break all code containing
"from jw.lib.base import Result"
Signed-off-by: Jan Lindemann <jan@janware.com>
Forgejo versions before 15 didn't support workflow expansion, and
"runs-on" was necessary in callers of reusable workflows. janware.com
now runs Forgejo 15.x, and the requirement is gone, so remove the config
option.
Quoting from https://forgejo.org/docs/latest/user/actions/reference/
runs-on is typically a required field. However, if a job defines
jobs.<job_id>.uses in order to reference a reusable workflow, then it
is optional. See jobs.<job_id>.uses for more information on this
behaviour.
[...]
It is recommended that jobs.<job_id>.runs-on is omitted when using
uses, as this will allow Forgejo to perform workflow expansion.
Workflow expansion results in the target workflow’s jobs appearing in
the UI as separate jobs. This provides an easier to understand
experience for accessing the logs of each job, and permits the jobs to
run on separate runners with their own runs-on fields.
Signed-off-by: Jan Lindemann <jan@janware.com>
Accept if AsyncSSH is missing. The package would be nice to have,
i.e. a good candidate for a "recommends" section, but until there's
support for that, better be able to do without and fall back to
command-line ssh.
Signed-off-by: Jan Lindemann <jan@janware.com>
Accept if argcomplete is missing. The package would be nice to have,
i.e. a good candidate for a "recommends" section, but until there's
support for that, better be able to do without.
Signed-off-by: Jan Lindemann <jan@janware.com>
"make check" fails on Kali Linux, because the machinery lacks pieces:
- Add mypy, yapf3, python3-pyright to project.conf for Debian. The
pyright package is not in upstream Kali, but is now supplied by
the jw-foss repo.
- ifdef ruff out from "make check" in py-topdir.mk, because it's
too much work to get that to work from packages on Kali Linux for
now.
project.conf, py-topdir.mk: Make Kali work
Signed-off-by: Jan Lindemann <jan@janware.com>
All commands that do load_subcommands() should have a default _run()
implementation which calls print_help(), add them.
Signed-off-by: Jan Lindemann <jan@janware.com>
Fix another regression of commit 6db73873e7:
lib.ExecContext.CallContext.__exit__() returns True, which swallows
all exceptions thrown in the context of _run() and _sudo(). Fix that.
Signed-off-by: Jan Lindemann <jan@janware.com>
Allow find_dir() to return None in case it couldn't find a directory,
that's a legal outcome. Add a boolean parameter "throw" to support
throwing an exception if the existence needs to be asserted.
It would probably be nicer for the type checkers to split this up
into a throwing and non-throwing function. Postponed.
Signed-off-by: Jan Lindemann <jan@janware.com>
Updates running in non-interactive mode are passed
--force-resolution
--auto-agree-with-licenses
to get more snakes out of the way, as recently during CI:
# make pkg-install-testbuild-deps
/usr/bin/which: no xdg-open in (/usr/local/sbin:/usr/local/bin:/usr/sbin:/usr/bin:/sbin:/bin)
/usr/bin/python3.13 ./scripts/jw-pkg.py -p ./.. -t .
--topdir-format absolute --interactive=false pkg install "make"
"time" "xdg-utils" "coreutils" "cpio" "git-core" "bash" "python3"
"sudo" "gawk" "pkg-config" "python3-isort" "python3-yapf"
"python3-ruff" "python3-pyright" "rpmbuild" "python3-base"
,---- file://local: Running /usr/bin/zypper --non-interactive --gpg-auto-import-keys --no-gpg-checks install make time xdg-utils coreutils cpio git-core bash python3 sudo gawk pkg-config python3-isort python3-yapf python3-ruff python3-pyright rpmbuild python3-base - >
| Loading repository data...
| Reading installed packages...
| 'sudo' is already installed.
| No update candidate for 'sudo-1.9.17p2-2.2.x86_64'. The highest available version is already installed.
| 'bash' is already installed.
| No update candidate for 'bash-5.3.9-6.4.x86_64'. The highest available version is already installed.
| 'python3' not found in package names. Trying capabilities.
| 'python313' providing 'python3' is already installed.
| 'coreutils' is already installed.
| No update candidate for 'coreutils-9.11-3.1.x86_64'. The highest available version is already installed.
| 'pkg-config' not found in package names. Trying capabilities.
| 'make' is already installed.
| No update candidate for 'make-4.4.1-3.5.x86_64'. The highest available version is already installed.
| 'python3-base' not found in package names. Trying capabilities.
| 'python313-base' providing 'python3-base' is already installed.
| 'rpmbuild' not found in package names. Trying capabilities.
| 'git-core' is already installed.
| No update candidate for 'git-core-2.54.0-2.1.x86_64'. The highest available version is already installed.
| 'python3-pyright' not found in package names. Trying capabilities.
| 'python3-ruff' not found in package names. Trying capabilities.
| 'python3-isort' not found in package names. Trying capabilities.
| 'python3-yapf' not found in package names. Trying capabilities.
| Resolving package dependencies...
|
| Problem: 1: the installed busybox-gawk-1.37.0-41.4.noarch conflicts with 'gawk' provided by the to be installed gawk-5.4.0-1.1.x86_64
| Solution 1: Following actions will be done:
| do not install gawk-5.4.0-1.1.x86_64
| do not ask to install a solvable providing rpmbuild
| Solution 2: deinstallation of busybox-gawk-1.37.0-41.4.noarch
|
| Choose from above solutions by number or cancel [1/2/c/d/?] (c): c
`---- file://local: Running /usr/bin/zypper --non-interactive --gpg-auto-import-keys --no-gpg-checks install make time xdg-utils coreutils cpio git-core bash python3 sudo gawk pkg-config python3-isort python3-yapf python3-ruff python3-pyright rpmbuild python3-base - <
Signed-off-by: Jan Lindemann <jan@janware.com>
Fix a regregression breaking run_curl() / run_curl_into(), introduced
by commit 6db73873e7. A missing indentation raises a non-existing
Error after successful JSON parsing, fix that.
Signed-off-by: Jan Lindemann <jan@janware.com>
The generated code doesn't pass "make check": It would like to see a
newline after the import statement. Add that.
Signed-off-by: Jan Lindemann <jan@janware.com>
App.is_excluded_from_build() uses the wrong function entirely to
query the [build.exclude] section of project.conf
(App.get_project_refs() instead of App.get_value()). This has
obviously never worked. It rose to prominence because commit 6db73873
introduced App.__proj_dir(), which now raises an Exception if passed
garbage, which in turn surfaces as
Exception: No project path found for module "debian"
Use the correct function for that: App.get_value().
Signed-off-by: Jan Lindemann <jan@janware.com>