Add CI gate and auto-merge workflow (warren-ready) - #37
Merged
Merged
Conversation
Wire up the repo so warren PRs auto-merge once CI passes, per docs/project-setup.md. The repo had no CI at all, so auto-merge would have had nothing to wait on and every owner PR would have merged unverified. Two workflows: - auto-merge.yml: verbatim from the warren checklist. Enables squash auto-merge on non-draft PRs authored by the repo owner only, using a GitHub App installation token so the merge commit still triggers downstream workflows. - ci.yml: the gate it waits on. Validates add-on metadata (required HA keys, known arch values, options/schema and ports/description symmetry, version vs CHANGELOG), shellchecks the cont-init script, builds the amd64 image, then boots it and smoke-tests it. The smoke test asserts the things that have actually broken here: compiled filters (rastertokpsl, raster2dymolw/m, rastertogutenprint) and vendored PPDs are present, avahi is up for AirPrint, the generated cupsd.conf keeps the LAN/IPv6 ACLs and is not allow-all, Cancel-Job is authorised in a Policy, and a LAN client gets 200 on the web UI. The job id and name are both `ci` so the branch-protection required check context is exactly `ci`.
CI caught this on the first run: the s6 init shebang (`#!/usr/bin/with-contenv bash`) is not one ShellCheck recognizes, so SC1008 fired as an error before any real check ran.
The avahi assertion sampled the process once, which is racy: avahi-daemon is started with --daemonize, which always returns 0 even if the child exits shortly after (e.g. when D-Bus was not usable yet). Poll for it like we do for cupsd, assert the control socket too, and dump container logs / process list / runtime sockets whenever the smoke test fails so CI output explains itself.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Integrates the warren project-setup checklist into this repo.
Why CI comes first
The checklist assumes the repo already has a PR CI workflow. It doesn't — there was no
.github/directory at all, and no workflow anywhere in history. Enabling auto-merge without CI would mean owner PRs merge immediately and unverified, so this PR adds the gate and the auto-merge flow together.What's added
.github/workflows/ci.ymlThe required check. Single non-matrix job with id and name
ci, so the branch-protection context is exactlyci.Add-on metadata (
.github/scripts/validate_addon.py) — required HA keys, knownarchvalues,options↔schemasymmetry,ports↔ports_descriptionsymmetry,mapentry format, slug matches the add-on directory, andversionmatches the latestCHANGELOG.mdheading.Init scripts —
bash -nplusshellcheck --severity=error.Build —
linux/amd64image with GitHub Actions layer cache.Smoke test (
.github/scripts/smoke_test.sh) — boots the image under its real/initand asserts:HEALTHCHECKhealthyrastertokpsl,raster2dymolw,raster2dymolm,rastertogutenprint.5.3avahi-daemonrunning for AirPrintcupsd.confstill allows@LOCAL+ the RFC1918/fe80::/10/fd00::/8ranges, is not allow-all, and still authorisesCancel-Jobinside aPolicy/,/printers/and/adminThese target the regressions from AirPrint, cancel-job auth, and IPv6 web UI (1.3.2) #35 (IPv6 web UI 403, Cancel-Job
Unauthorized) and 1.3.1 (missing Gutenprint PPDs)..github/workflows/auto-merge.ymlVerbatim from the checklist. Squash auto-merge on non-draft PRs authored by
github.repository_owneronly, using a GitHub App installation token so the merge commit still triggers downstream workflows.auto-merge.ymlwill fail red until the GitHub App credentials exist. That failure is the intended signal (the checklist: "A revoked key or an uninstalled app turns that job red before the merge queue can stall silently"). It is not a required check, so it does not block this PR.Create the App (Settings → Developer settings → GitHub Apps → New GitHub App): Contents Read and write, Pull requests Read and write, webhook off, installed on this repo only. Then:
Repo settings (applied alongside this PR)
allow_auto_merge=truedelete_branch_on_merge=truemainrequiring thecicheck (targets checklist step 5: keep the required status check, no review requirement)Local verification
validate_addon.pypasses, and catches injected faults (bad arch, version/CHANGELOG drift,options/schemamismatch, orphanports_descriptionentry)1againstalpine:latest, so it cannot pass spuriouslyshellcheck --severity=errorclean on the init script and the smoke test