From 4edd5b43ee95e58ac77b6a730118b8926326676e Mon Sep 17 00:00:00 2001 From: pat-s Date: Sun, 9 Aug 2026 15:29:31 +0000 Subject: [PATCH] fix(ci): make every manual gate default to a value that matches nothing A manual pipeline creation instantiates every file in .crow/, and a declared variable default is applied even when the run never passed that variable. So a gate like target_arch, defaulting to amd64, matched its own amd64 matrix rows on any manual run of any pipeline. Triggering a weekly-audit-missing run for one slot started build-all-versions (including its Upload package indexes step) and process-updates across every row. #155 fixed the three pipelines that had no gate at all; these six had a gate whose default was permissive, which left them just as exposed. - add a 'none' option to each gate variable and default to it, so a manual run must name its target explicitly - record why the default must match nothing, next to the default itself Cron triggers are unaffected: they match on the cron name, not the variable. --- .crow/build-all-versions-install-deps.yaml | 8 ++++++-- .crow/build-all-versions.yaml | 8 ++++++-- .crow/process-updates.yaml | 8 ++++++-- .crow/repair-built-stamp.yaml | 8 ++++++-- .crow/weekly-audit-missing.yaml | 8 ++++++-- .crow/weekly-rebuild-missing.yaml | 8 ++++++-- 6 files changed, 36 insertions(+), 12 deletions(-) diff --git a/.crow/build-all-versions-install-deps.yaml b/.crow/build-all-versions-install-deps.yaml index 448cff3..2a6d9c2 100644 --- a/.crow/build-all-versions-install-deps.yaml +++ b/.crow/build-all-versions-install-deps.yaml @@ -3,12 +3,16 @@ # Variables are declared so the manual-run form exposes them (crow #1165); # they are merged with build-all-versions' identical declarations. variables: + # Gates this pipeline. A manual pipeline creation instantiates every file in + # .crow/, and a declared default is applied even when the run never passed + # this variable, so the default must be a value that matches no matrix row. target_arch: - description: 'Architecture to build.' + description: 'Architecture to build, or "none" to run nothing.' options: + - none - amd64 - arm64 - default: amd64 + default: none OS: description: 'Base OS image name.' options: diff --git a/.crow/build-all-versions.yaml b/.crow/build-all-versions.yaml index 9ab888a..fb1229d 100644 --- a/.crow/build-all-versions.yaml +++ b/.crow/build-all-versions.yaml @@ -4,12 +4,16 @@ # image and cache volume. Placement is via the group label (rpkgs-amd64/rpkgs-arm64). # Skip list lives in local/excluded-packages.json (read by local/build-all.R). variables: + # Gates this pipeline. A manual pipeline creation instantiates every file in + # .crow/, and a declared default is applied even when the run never passed + # this variable, so the default must be a value that matches no matrix row. target_arch: - description: 'Architecture to build.' + description: 'Architecture to build, or "none" to run nothing.' options: + - none - amd64 - arm64 - default: amd64 + default: none OS: description: 'Base OS image name.' options: diff --git a/.crow/process-updates.yaml b/.crow/process-updates.yaml index 1e4833c..7600876 100644 --- a/.crow/process-updates.yaml +++ b/.crow/process-updates.yaml @@ -7,9 +7,13 @@ # ("all" = every os/arch). # Arch placement is handled by the group label (rpkgs-amd64, rpkgs-arm64). variables: + # Gates this pipeline. A manual pipeline creation instantiates every file in + # .crow/, and a declared default is applied even when the run never passed + # this variable, so the default must be a value that matches no matrix row. process_cran_updates: - description: "Manual run target: a specific -, or 'all' for every os/arch." + description: "Manual run target: a specific -, 'all' for every os/arch, or 'none' to run nothing." options: + - none - all - alpine-322-amd64 - alpine-322-arm64 @@ -29,7 +33,7 @@ variables: - ubuntu-2404-arm64 - ubuntu-2604-amd64 - ubuntu-2604-arm64 - default: all + default: none when: - event: cron diff --git a/.crow/repair-built-stamp.yaml b/.crow/repair-built-stamp.yaml index 83821e9..e56e1e9 100644 --- a/.crow/repair-built-stamp.yaml +++ b/.crow/repair-built-stamp.yaml @@ -19,12 +19,16 @@ # --var repair_built_stamp=arm64 --var OS=alpine --var OS_VERSION=3.22 \ # --var R_VERSION=4.5.3 --var dry_run=true devxy/build-cran-binaries variables: + # Gates this pipeline. A manual pipeline creation instantiates every file in + # .crow/, and a declared default is applied even when the run never passed + # this variable, so the default must be a value that matches no matrix row. repair_built_stamp: - description: 'Architecture of the slot to repair. Also gates this pipeline.' + description: 'Architecture of the slot to repair, or "none" to run nothing.' options: + - none - amd64 - arm64 - default: arm64 + default: none OS: description: 'Base OS image name.' options: diff --git a/.crow/weekly-audit-missing.yaml b/.crow/weekly-audit-missing.yaml index 4efe409..3a9d98f 100644 --- a/.crow/weekly-audit-missing.yaml +++ b/.crow/weekly-audit-missing.yaml @@ -7,9 +7,13 @@ # ("all" = every os/arch). # Arch placement is via the group label (rpkgs-amd64, rpkgs-arm64). variables: + # Gates this pipeline. A manual pipeline creation instantiates every file in + # .crow/, and a declared default is applied even when the run never passed + # this variable, so the default must be a value that matches no matrix row. weekly_audit_missing: - description: "Manual run target: a specific -, or 'all' for every os/arch." + description: "Manual run target: a specific -, 'all' for every os/arch, or 'none' to run nothing." options: + - none - all - alpine-322-amd64 - alpine-322-arm64 @@ -29,7 +33,7 @@ variables: - ubuntu-2404-arm64 - ubuntu-2604-amd64 - ubuntu-2604-arm64 - default: all + default: none when: - event: cron diff --git a/.crow/weekly-rebuild-missing.yaml b/.crow/weekly-rebuild-missing.yaml index 03a13f9..0353901 100644 --- a/.crow/weekly-rebuild-missing.yaml +++ b/.crow/weekly-rebuild-missing.yaml @@ -8,9 +8,13 @@ # single - to run just one. # Arch placement is handled by the group label (rpkgs-amd64, rpkgs-arm64). variables: + # Gates this pipeline. A manual pipeline creation instantiates every file in + # .crow/, and a declared default is applied even when the run never passed + # this variable, so the default must be a value that matches no matrix row. weekly_rebuild_missing: - description: "Manual run target: a specific -, or 'all' for every os/arch." + description: "Manual run target: a specific -, 'all' for every os/arch, or 'none' to run nothing." options: + - none - all - alpine-322-amd64 - alpine-322-arm64 @@ -30,7 +34,7 @@ variables: - ubuntu-2404-arm64 - ubuntu-2604-amd64 - ubuntu-2604-arm64 - default: all + default: none when: - event: cron