Restructure the script embedded in the scoped sync workflow into testable functions, fix the invalid `exit 0` (now a successful run with a visible warning when Gitea returns an invalid push mirror list) and report errors as `ERROR: <message>` with exit code 1. Zero, several or malformed GitHub mirrors still fail. Add pytest-based offline tests (workflow YAML, embedded Python, credential and mirror parsing, sync flow against a fake API) that run in a virtual environment, and a validation workflow that runs them on pull requests and pushes to main. Remove the manual tests/test_.ps1 probe and the duplicate src/ copy of the workflow. Update the README and record the decisions for tasks 1 and 3 in MIL-001. Task: MIL-001#1 Task: MIL-001#2 Task: MIL-001#3 Task: MIL-001#4 Task: MIL-001#5 Task: MIL-001#6 Refs #1 Refs #2 Refs #3 Refs #4 Refs #5 Refs #6 Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>
55 lines
1.8 KiB
Python
55 lines
1.8 KiB
Python
"""Static validation of every workflow file in this repository."""
|
|
|
|
import ast
|
|
|
|
import pytest
|
|
import yaml
|
|
|
|
from workflow_source import REPO_ROOT, SYNC_WORKFLOW, embedded_python, workflow_files
|
|
|
|
WORKFLOWS = workflow_files()
|
|
|
|
|
|
def test_workflow_files_exist():
|
|
assert WORKFLOWS, "no workflow files found"
|
|
|
|
|
|
@pytest.mark.parametrize("path", WORKFLOWS, ids=lambda p: p.name)
|
|
class TestEachWorkflow:
|
|
def test_is_valid_yaml_with_name_and_jobs(self, path):
|
|
document = yaml.safe_load(path.read_text(encoding="utf-8"))
|
|
assert isinstance(document, dict)
|
|
assert document.get("name"), "a workflow needs a name"
|
|
assert document.get("jobs"), "a workflow needs at least one job"
|
|
|
|
def test_embedded_python_compiles(self, path):
|
|
for source in embedded_python(path):
|
|
ast.parse(source, filename=str(path))
|
|
|
|
def test_every_job_declares_permissions_and_runner(self, path):
|
|
document = yaml.safe_load(path.read_text(encoding="utf-8"))
|
|
for name, job in document["jobs"].items():
|
|
assert "runs-on" in job, f"job {name} has no runs-on"
|
|
assert "permissions" in job, f"job {name} has no explicit permissions"
|
|
|
|
|
|
def test_sync_workflow_embeds_exactly_one_script():
|
|
assert len(embedded_python(SYNC_WORKFLOW)) == 1
|
|
|
|
|
|
def test_each_workflow_name_has_one_source():
|
|
names = [path.name for path in WORKFLOWS]
|
|
assert len(names) == len(set(names)), "a workflow exists in several directories"
|
|
|
|
|
|
def test_no_workflow_copy_outside_the_workflow_directories():
|
|
stray = [
|
|
path.relative_to(REPO_ROOT)
|
|
for pattern in ("*.yml", "*.yaml")
|
|
for folder in (REPO_ROOT, REPO_ROOT / "src")
|
|
if folder.is_dir()
|
|
for path in folder.glob(pattern)
|
|
if path.name == SYNC_WORKFLOW.name
|
|
]
|
|
assert not stray, f"duplicate workflow copies: {stray}"
|