mirror of
https://relay.ngit.dev/npub15qydau2hjma6ngxkl2cyar74wzyjshvl65za5k5rl69264ar2exs5cyejr/ngit-grasp.git
synced 2026-10-05 15:08:24 +00:00
cache-nix-action@v7 reads its token input as required in both restore and save; its github.token default is empty under ngit-ci (no GITHUB_TOKEN is injected), so both phases threw "Input required and not supplied: token" and, hidden by continue-on-error, the Nix store cache never restored or saved. Any non-empty value satisfies the check and is never transmitted while purge (default off) stays disabled. Validation: matches the fix applied to ngit-ci's own workflows and its documented snippet; the next push-triggered run should show the restore/save steps succeeding instead of failing fast.
69 lines
3.1 KiB
YAML
69 lines
3.1 KiB
YAML
# Docs-only pushes are skipped: a push runs only when at least one changed
|
|
# file falls outside the ignore list, so mixed code+docs pushes still run.
|
|
# Tag pushes always run regardless of path filters, and pull_request stays
|
|
# unfiltered because ngit-ci does not evaluate PR path filters yet (filtered
|
|
# PR triggers would run unconditionally anyway).
|
|
on:
|
|
push:
|
|
paths-ignore:
|
|
- "docs/**"
|
|
- "**/*.md"
|
|
- "work/**"
|
|
pull_request:
|
|
|
|
name: Rust CI
|
|
|
|
jobs:
|
|
ci:
|
|
runs-on: ubuntu-latest
|
|
timeout-minutes: 30
|
|
steps:
|
|
- uses: actions/checkout@v5
|
|
- uses: cachix/install-nix-action@v31
|
|
with:
|
|
nix_path: nixpkgs=channel:nixos-unstable
|
|
- name: Restore Nix store cache
|
|
continue-on-error: true
|
|
uses: nix-community/cache-nix-action@v7
|
|
with:
|
|
primary-key: nix-${{ runner.os }}-${{ hashFiles('**/*.nix', 'flake.lock') }}
|
|
restore-prefixes-first-match: nix-${{ runner.os }}-
|
|
# cache-nix-action requires a token even with purge disabled;
|
|
# github.token is empty under ngit-ci, so any non-empty value works.
|
|
token: unused
|
|
- name: Restore Rust build cache
|
|
continue-on-error: true
|
|
uses: actions/cache@v4
|
|
with:
|
|
path: |
|
|
~/.cargo/git
|
|
~/.cargo/registry
|
|
target
|
|
key: rust-${{ runner.os }}-${{ hashFiles('**/Cargo.toml', 'Cargo.lock', 'flake.lock') }}
|
|
restore-keys: |
|
|
rust-${{ runner.os }}-
|
|
# The suite must be hermetic with respect to ambient git configuration,
|
|
# so CI always runs it under a deliberately hostile global config: a
|
|
# failing pre-commit hook delivered via both core.hooksPath and
|
|
# init.templateDir, plus the settings that have bitten before. The
|
|
# settings target test-side git only: the relay never runs `git commit`,
|
|
# so its server-side operations are unaffected except for
|
|
# init.defaultBranch, which is exactly the regression being guarded.
|
|
# (The hermetic helpers make the tests themselves config-blind, so this
|
|
# single run also covers hosts where these settings are unset.)
|
|
- name: Install hostile git configuration
|
|
run: |
|
|
mkdir -p /tmp/hostile-git/hooks /tmp/hostile-git/template/hooks
|
|
printf '#!/bin/sh\necho "hostile hook: ambient git config leaked into a test" >&2\nexit 1\n' \
|
|
| tee /tmp/hostile-git/hooks/pre-commit > /tmp/hostile-git/template/hooks/pre-commit
|
|
chmod +x /tmp/hostile-git/hooks/pre-commit /tmp/hostile-git/template/hooks/pre-commit
|
|
git config --global init.defaultBranch main
|
|
git config --global core.hooksPath /tmp/hostile-git/hooks
|
|
git config --global init.templateDir /tmp/hostile-git/template
|
|
git config --global commit.gpgsign true
|
|
git config --global core.autocrlf true
|
|
- run: nix develop --command cargo fmt --all -- --check
|
|
- run: nix develop --command cargo clippy --workspace --all-targets -- -D warnings
|
|
- run: nix develop --command cargo test --locked
|
|
- run: nix develop --command cargo test -p grasp-audit --locked
|