tests: one run per commit, and nothing from apt - #22
Merged
Merged
Conversation
`push: branches: ['**']` meant every push to a PR branch fired this twice — once as `push`, once as `pull_request` — for one commit and one answer. Sixty push runs against twenty-three PR runs in the last two weeks says how much of that was the duplicate. Main only now; PRs are covered by the `pull_request` trigger they already had. The install step asked apt for three tools and the ubuntu-latest image already had two of them. bats comes from npm (preinstalled, and what haus's shell job uses); shellcheck and jq come from the image, with jq still named — the tier filter IS a jq program — as its own version print, so an image that dropped it fails loudly rather than turning every case into an error. `concurrency` cancels a superseded run on a PR branch. Main is exempt: every push there is a commit whose tick someone may read back. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_011wToFna2AmAJdZzJwqEKQs
The block as first written put every main push in one group with cancelling off, which does not do what its own comment promised: a shared group serializes those runs, and GitHub cancels a *pending* run when a newer one joins it — so a merge followed by a bench ship lock bump inside one build's wall clock leaves the middle commit with no run at all. Line 1 still said "on every push and PR" after line 46 stopped being true. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_011wToFna2AmAJdZzJwqEKQs
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
What
Testsruns once per commit instead of twice, and asks apt for nothing.push: branches: ['**']→branches: [main]sudo npm install -g batsreplacesapt-get update && apt-get install -y bats shellcheck jqprint so an image that dropped it fails loudly
concurrencycancels a superseded run on a PR branch; main is exemptWhy
branches: ['**']fired this workflow twice for every push to a PR branch —once as
push, once aspull_request— for one commit and one answer. Sixtypush runs against twenty-three PR runs over the last two weeks is most of what
that was. PRs keep the coverage they already had, through the trigger they
already had.
The install step asked apt for three tools and the image already shipped two of
them.
apt-get updateis also the step that hangs rather than fails when theAzure mirrors go quiet —
haus'scheck.ymlhas the long account.jq is still named rather than assumed: the tier filter is a jq program and
the config layer is another, so an image that dropped it must fail as a missing
tool rather than turning every case into an error.
The family's four CI rules are now written down in the workshop's
docs/ci.md.Verify
On this PR's run: one
Testsrun, not two.jq --versionprints,shellcheck --versionprints, and
bats test/runs the whole suite under the npm bats.After merge, push a commit to any branch that has no PR — no run should fire.
Open a PR from it — one run should fire.
Watch out
factory tierandfactory shiftdecide what may merge partly from a PR's checks. Those still exist: a PR gets
its run from the
pull_requesttrigger, which is unchanged. What disappearsis the run on a branch with no PR open — which the shift never looks at,
because it works from PRs. Worth confirming on the first night after this
lands that tier 1 still sees green.
What the pre-PR assurance pass changed
A clean-context reviewer read this branch before it had a PR (AGENTS.md Step
2.5) and caught real defects, fixed in the commits above rather than carried:
concurrencyblock as first written was wrong. It put every push tomainin one shared group with cancelling off, which is not what its owncomment promised: a shared group serializes those runs, and GitHub cancels a
pending run outright when a newer one joins the group. A merge followed
closely by a
bench shiplock bump would have left the middle commit with norun at all — the exact tick the rule protects. Only PR runs share a group now;
everything else keys on the commit.
line 46 stopped being true.
factory-tier'sstatusCheckRollupreads the head SHA's checks, which the unfiltered
pull_requesttrigger stillproduces, and
factory-shiftonly ever queries the default branch. Tier-1auto-merge is unaffected.
docs/ci.md, which lands in the workshopPR of the same sweep. Merge that one first (or accept a link that resolves a
few minutes later).
🤖 Generated with Claude Code
https://claude.ai/code/session_011wToFna2AmAJdZzJwqEKQs