diff --git a/.github/workflows/test.yml b/.github/workflows/test.yml index 490c6fb..846f057 100644 --- a/.github/workflows/test.yml +++ b/.github/workflows/test.yml @@ -1,4 +1,4 @@ -# Verify factory on every push and PR. +# Verify factory on every push to main, and on every PR. # # What goes wrong with these scripts is not a crash. `factory shift` runs # unattended and its product is a log read hours later, so its worst output is a @@ -43,9 +43,23 @@ name: Tests on: push: - branches: ['**'] + branches: [main] pull_request: +# A second push to a PR branch makes the first run's answer worthless, and the +# abandoned run still holds a runner — a runner the next PR then waits +# behind. +# +# Only a PR run is ever in a shared group. Everything else keys on the commit, +# so it gets a group of its own: putting main pushes in one group would +# SERIALIZE them even with cancelling off, and GitHub cancels a *pending* run +# when a newer one joins its group — so three merges inside one build would +# leave the middle commit with no run at all. That is the tick this is +# supposed to protect. +concurrency: + group: tests-${{ github.event_name == 'pull_request' && github.ref || github.sha }} + cancel-in-progress: ${{ github.event_name == 'pull_request' }} + jobs: test: name: bats + shellcheck + skill guards @@ -53,11 +67,20 @@ jobs: steps: - uses: actions/checkout@v4 - # jq is named rather than assumed present: the tier filter IS a jq - # program and the config layer is another, so a runner image that dropped - # it would turn every case into an error rather than a failure. - - name: Install bats + shellcheck + jq - run: sudo apt-get update && sudo apt-get install -y bats shellcheck jq + # bats is the one tool of the three the ubuntu-latest image lacks, and + # npm is preinstalled, so it comes from npm rather than apt. shellcheck + # and jq are already on the image; `apt-get update` in front of them + # bought nothing and, on the day the Azure mirrors go quiet, hangs rather + # than fails (haus/check.yml has the long version of that afternoon). + # + # jq is still named rather than assumed: the tier filter IS a jq program + # and the config layer is another, so an image that dropped it would turn + # every case into an error rather than a failure. The version print below + # is what makes that loud instead of confusing. + - name: Install bats + run: sudo npm install -g bats + - name: jq is on this image + run: jq --version # The versions are printed because they are not pinned, and apt's # shellcheck disagrees with a newer one about which checks are on by