fix(ci): make every manual gate default to a value that matches nothing

A manual pipeline creation instantiates every file in .crow/, and a declared
variable default is applied even when the run never passed that variable. So a
gate like target_arch, defaulting to amd64, matched its own amd64 matrix rows on
any manual run of any pipeline. Triggering a weekly-audit-missing run for one
slot started build-all-versions (including its Upload package indexes step) and
process-updates across every row.

#155 fixed the three pipelines that had no gate at all; these six had a gate
whose default was permissive, which left them just as exposed.

- add a 'none' option to each gate variable and default to it, so a manual run
  must name its target explicitly
- record why the default must match nothing, next to the default itself

Cron triggers are unaffected: they match on the cron name, not the variable.
This commit is contained in:
Patrick Schratz 2026-08-09 15:29:31 +00:00
commit 4edd5b43ee
No known key found for this signature in database
GPG key ID: 62050D5BC68AB6DC
6 changed files with 36 additions and 12 deletions

View file

@ -3,12 +3,16 @@
# Variables are declared so the manual-run form exposes them (crow #1165);
# they are merged with build-all-versions' identical declarations.
variables:
# Gates this pipeline. A manual pipeline creation instantiates every file in
# .crow/, and a declared default is applied even when the run never passed
# this variable, so the default must be a value that matches no matrix row.
target_arch:
description: 'Architecture to build.'
description: 'Architecture to build, or "none" to run nothing.'
options:
- none
- amd64
- arm64
default: amd64
default: none
OS:
description: 'Base OS image name.'
options:

View file

@ -4,12 +4,16 @@
# image and cache volume. Placement is via the group label (rpkgs-amd64/rpkgs-arm64).
# Skip list lives in local/excluded-packages.json (read by local/build-all.R).
variables:
# Gates this pipeline. A manual pipeline creation instantiates every file in
# .crow/, and a declared default is applied even when the run never passed
# this variable, so the default must be a value that matches no matrix row.
target_arch:
description: 'Architecture to build.'
description: 'Architecture to build, or "none" to run nothing.'
options:
- none
- amd64
- arm64
default: amd64
default: none
OS:
description: 'Base OS image name.'
options:

View file

@ -7,9 +7,13 @@
# ("all" = every os/arch).
# Arch placement is handled by the group label (rpkgs-amd64, rpkgs-arm64).
variables:
# Gates this pipeline. A manual pipeline creation instantiates every file in
# .crow/, and a declared default is applied even when the run never passed
# this variable, so the default must be a value that matches no matrix row.
process_cran_updates:
description: "Manual run target: a specific <os>-<arch>, or 'all' for every os/arch."
description: "Manual run target: a specific <os>-<arch>, 'all' for every os/arch, or 'none' to run nothing."
options:
- none
- all
- alpine-322-amd64
- alpine-322-arm64
@ -29,7 +33,7 @@ variables:
- ubuntu-2404-arm64
- ubuntu-2604-amd64
- ubuntu-2604-arm64
default: all
default: none
when:
- event: cron

View file

@ -19,12 +19,16 @@
# --var repair_built_stamp=arm64 --var OS=alpine --var OS_VERSION=3.22 \
# --var R_VERSION=4.5.3 --var dry_run=true devxy/build-cran-binaries
variables:
# Gates this pipeline. A manual pipeline creation instantiates every file in
# .crow/, and a declared default is applied even when the run never passed
# this variable, so the default must be a value that matches no matrix row.
repair_built_stamp:
description: 'Architecture of the slot to repair. Also gates this pipeline.'
description: 'Architecture of the slot to repair, or "none" to run nothing.'
options:
- none
- amd64
- arm64
default: arm64
default: none
OS:
description: 'Base OS image name.'
options:

View file

@ -7,9 +7,13 @@
# ("all" = every os/arch).
# Arch placement is via the group label (rpkgs-amd64, rpkgs-arm64).
variables:
# Gates this pipeline. A manual pipeline creation instantiates every file in
# .crow/, and a declared default is applied even when the run never passed
# this variable, so the default must be a value that matches no matrix row.
weekly_audit_missing:
description: "Manual run target: a specific <os>-<arch>, or 'all' for every os/arch."
description: "Manual run target: a specific <os>-<arch>, 'all' for every os/arch, or 'none' to run nothing."
options:
- none
- all
- alpine-322-amd64
- alpine-322-arm64
@ -29,7 +33,7 @@ variables:
- ubuntu-2404-arm64
- ubuntu-2604-amd64
- ubuntu-2604-arm64
default: all
default: none
when:
- event: cron

View file

@ -8,9 +8,13 @@
# single <os>-<arch> to run just one.
# Arch placement is handled by the group label (rpkgs-amd64, rpkgs-arm64).
variables:
# Gates this pipeline. A manual pipeline creation instantiates every file in
# .crow/, and a declared default is applied even when the run never passed
# this variable, so the default must be a value that matches no matrix row.
weekly_rebuild_missing:
description: "Manual run target: a specific <os>-<arch>, or 'all' for every os/arch."
description: "Manual run target: a specific <os>-<arch>, 'all' for every os/arch, or 'none' to run nothing."
options:
- none
- all
- alpine-322-amd64
- alpine-322-arm64
@ -30,7 +34,7 @@ variables:
- ubuntu-2404-arm64
- ubuntu-2604-amd64
- ubuntu-2604-arm64
default: all
default: none
when:
- event: cron