From f8e31af75b3ae418b858dca3d6baeda73e651834 Mon Sep 17 00:00:00 2001 From: pat-s Date: Sun, 9 Aug 2026 15:31:14 +0000 Subject: [PATCH] fix(ci): make every manual gate default to a value that matches nothing (#158) MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit ## Problem A manual `crow pipeline create` instantiates **every** file in `.crow/`, and a declared variable default is applied even when the run never passed that variable. A gate is therefore only a gate if its default matches nothing. #155 fixed the three pipelines that had no manual gate at all. It missed that a *permissive default* leaves a pipeline just as exposed. Demonstrated the expensive way: creating a pipeline with only ``` --var weekly_audit_missing=alpine-324-amd64 ``` also started `build-all-versions` — because its gate `target_arch` defaults to `amd64`, which matches its own amd64 matrix rows — and `process-updates` across every row, because that gate defaults to `all`. The run was killed before any `Upload package indexes` step produced output and both alpine324 indices were verified unchanged, but `build-all-versions` uploads binaries and rewrites indexes, so the next one might not be caught in time. Before: | pipeline | gate | default | fired on an unrelated manual run | | --- | --- | --- | --- | | `build-all-versions` | `target_arch` | `amd64` | amd64 rows — builds and uploads | | `build-all-versions-install-deps` | `target_arch` | `amd64` | amd64 rows | | `weekly-rebuild-missing` | `weekly_rebuild_missing` | `all` | every row | | `weekly-audit-missing` | `weekly_audit_missing` | `all` | every row | | `process-updates` | `process_cran_updates` | `all` | every row | | `repair-built-stamp` | `repair_built_stamp` | `arm64` | arm64 rows | `archive-missed-packages` was the one that behaved, because its gate variable is never declared and so matches nothing. That is the property this restores everywhere. ## What this changes Each of the six gets a `none` option on its gate variable and defaults to it, so a manual run has to name its target explicitly. The reason is recorded next to the default, where someone would go to change it. `none` is used rather than dropping the default so the expression always has a defined value to compare, instead of relying on undefined-variable semantics. Cron triggers are untouched — they match on the `cron:` name, not the variable. ## Verification `crow lint .crow/` reports all ten configs valid. Auditing every pipeline that accepts a manual event: ``` archive-missed-packages.yaml: gate=task default= auto-apply-patches.yaml: gate=auto_apply_patches default='false' build-all-versions-install-deps.yaml gate=target_arch default=none build-all-versions.yaml: gate=target_arch default=none process-updates.yaml: gate=process_cran_updates default=none repair-built-stamp.yaml: gate=repair_built_stamp default=none trial-build-registry.yaml: gate=trial_build_registry default='false' weekly-audit-missing.yaml: gate=weekly_audit_missing default=none weekly-patch-proposals.yaml: gate=weekly_patch_proposals default='false' weekly-rebuild-missing.yaml: gate=weekly_rebuild_missing default=none ``` Every gate now defaults to something that matches no matrix row. Reviewed-on: https://git.devxy.io/devxy/build-cran-binaries/pulls/158 --- .crow/build-all-versions-install-deps.yaml | 8 ++++++-- .crow/build-all-versions.yaml | 8 ++++++-- .crow/process-updates.yaml | 8 ++++++-- .crow/repair-built-stamp.yaml | 8 ++++++-- .crow/weekly-audit-missing.yaml | 8 ++++++-- .crow/weekly-rebuild-missing.yaml | 8 ++++++-- 6 files changed, 36 insertions(+), 12 deletions(-) diff --git a/.crow/build-all-versions-install-deps.yaml b/.crow/build-all-versions-install-deps.yaml index 448cff3..2a6d9c2 100644 --- a/.crow/build-all-versions-install-deps.yaml +++ b/.crow/build-all-versions-install-deps.yaml @@ -3,12 +3,16 @@ # Variables are declared so the manual-run form exposes them (crow #1165); # they are merged with build-all-versions' identical declarations. variables: + # Gates this pipeline. A manual pipeline creation instantiates every file in + # .crow/, and a declared default is applied even when the run never passed + # this variable, so the default must be a value that matches no matrix row. target_arch: - description: 'Architecture to build.' + description: 'Architecture to build, or "none" to run nothing.' options: + - none - amd64 - arm64 - default: amd64 + default: none OS: description: 'Base OS image name.' options: diff --git a/.crow/build-all-versions.yaml b/.crow/build-all-versions.yaml index 9ab888a..fb1229d 100644 --- a/.crow/build-all-versions.yaml +++ b/.crow/build-all-versions.yaml @@ -4,12 +4,16 @@ # image and cache volume. Placement is via the group label (rpkgs-amd64/rpkgs-arm64). # Skip list lives in local/excluded-packages.json (read by local/build-all.R). variables: + # Gates this pipeline. A manual pipeline creation instantiates every file in + # .crow/, and a declared default is applied even when the run never passed + # this variable, so the default must be a value that matches no matrix row. target_arch: - description: 'Architecture to build.' + description: 'Architecture to build, or "none" to run nothing.' options: + - none - amd64 - arm64 - default: amd64 + default: none OS: description: 'Base OS image name.' options: diff --git a/.crow/process-updates.yaml b/.crow/process-updates.yaml index 1e4833c..7600876 100644 --- a/.crow/process-updates.yaml +++ b/.crow/process-updates.yaml @@ -7,9 +7,13 @@ # ("all" = every os/arch). # Arch placement is handled by the group label (rpkgs-amd64, rpkgs-arm64). variables: + # Gates this pipeline. A manual pipeline creation instantiates every file in + # .crow/, and a declared default is applied even when the run never passed + # this variable, so the default must be a value that matches no matrix row. process_cran_updates: - description: "Manual run target: a specific -, or 'all' for every os/arch." + description: "Manual run target: a specific -, 'all' for every os/arch, or 'none' to run nothing." options: + - none - all - alpine-322-amd64 - alpine-322-arm64 @@ -29,7 +33,7 @@ variables: - ubuntu-2404-arm64 - ubuntu-2604-amd64 - ubuntu-2604-arm64 - default: all + default: none when: - event: cron diff --git a/.crow/repair-built-stamp.yaml b/.crow/repair-built-stamp.yaml index 83821e9..e56e1e9 100644 --- a/.crow/repair-built-stamp.yaml +++ b/.crow/repair-built-stamp.yaml @@ -19,12 +19,16 @@ # --var repair_built_stamp=arm64 --var OS=alpine --var OS_VERSION=3.22 \ # --var R_VERSION=4.5.3 --var dry_run=true devxy/build-cran-binaries variables: + # Gates this pipeline. A manual pipeline creation instantiates every file in + # .crow/, and a declared default is applied even when the run never passed + # this variable, so the default must be a value that matches no matrix row. repair_built_stamp: - description: 'Architecture of the slot to repair. Also gates this pipeline.' + description: 'Architecture of the slot to repair, or "none" to run nothing.' options: + - none - amd64 - arm64 - default: arm64 + default: none OS: description: 'Base OS image name.' options: diff --git a/.crow/weekly-audit-missing.yaml b/.crow/weekly-audit-missing.yaml index 4efe409..3a9d98f 100644 --- a/.crow/weekly-audit-missing.yaml +++ b/.crow/weekly-audit-missing.yaml @@ -7,9 +7,13 @@ # ("all" = every os/arch). # Arch placement is via the group label (rpkgs-amd64, rpkgs-arm64). variables: + # Gates this pipeline. A manual pipeline creation instantiates every file in + # .crow/, and a declared default is applied even when the run never passed + # this variable, so the default must be a value that matches no matrix row. weekly_audit_missing: - description: "Manual run target: a specific -, or 'all' for every os/arch." + description: "Manual run target: a specific -, 'all' for every os/arch, or 'none' to run nothing." options: + - none - all - alpine-322-amd64 - alpine-322-arm64 @@ -29,7 +33,7 @@ variables: - ubuntu-2404-arm64 - ubuntu-2604-amd64 - ubuntu-2604-arm64 - default: all + default: none when: - event: cron diff --git a/.crow/weekly-rebuild-missing.yaml b/.crow/weekly-rebuild-missing.yaml index 03a13f9..0353901 100644 --- a/.crow/weekly-rebuild-missing.yaml +++ b/.crow/weekly-rebuild-missing.yaml @@ -8,9 +8,13 @@ # single - to run just one. # Arch placement is handled by the group label (rpkgs-amd64, rpkgs-arm64). variables: + # Gates this pipeline. A manual pipeline creation instantiates every file in + # .crow/, and a declared default is applied even when the run never passed + # this variable, so the default must be a value that matches no matrix row. weekly_rebuild_missing: - description: "Manual run target: a specific -, or 'all' for every os/arch." + description: "Manual run target: a specific -, 'all' for every os/arch, or 'none' to run nothing." options: + - none - all - alpine-322-amd64 - alpine-322-arm64 @@ -30,7 +34,7 @@ variables: - ubuntu-2404-arm64 - ubuntu-2604-amd64 - ubuntu-2604-arm64 - default: all + default: none when: - event: cron