fix(ci): gate the three ungated pipelines on their own variable #155

Merged
pat-s merged 1 commit from fix/gate-manual-pipelines into main 2026-08-09 10:02:06 +00:00
Owner

Problem

A manual crow pipeline create instantiates every pipeline in .crow/, and each one decides for itself whether to run. Three had nothing to decide with — their only manual condition was a bare event: manual:

  • auto-apply-patches — pushes to auto/registry-patch-proposals and opens/updates a PR
  • weekly-patch-proposals — posts and edits two Forgejo issues
  • trial-build-registry — starts a build per matrix row, on both arches

So they fired on any manual trigger in this repo, whatever it was for. That is how they came to run alongside a manual process-updates run for alpine-324-arm64 (#10723), which is also why that pipeline is marked failure.

repair-built-stamp.yaml already documents the rule this breaks:

The gate variable is repair_built_stamp, not target_arch … Every pipeline here gates on a variable named after itself for exactly that reason.

What this changes

Each of the three gets a gate variable named after the pipeline, evaluated on the manual event, defaulting to off:

variables:
  auto_apply_patches:
    description: 'Run the auto-patch proposer. Also gates this pipeline.'
    options: ['true', 'false']
    default: 'false'

when:
  - event: manual
    evaluate: 'auto_apply_patches == "true"'
  - event: cron
    cron: auto-apply-patches

Cron triggers are untouched, so the scheduled runs behave exactly as before.

The run-manually comments in all three headers were also stale: they documented --var task=<name> with woodpecker-cli, and no pipeline evaluates a task variable. They now show the real invocation.

Note on the sibling pipelines

The already-gated pipelines use default: all (e.g. weekly_rebuild_missing). If Crow applies a declared default to a variable that an API-created pipeline never passed, those would match on an unrelated manual run too — weekly-rebuild-missing would be an expensive way to find out. I could not settle that from #10723 because its step logs have since expired, so I left them alone rather than guess. The three fixed here default to 'false', which is safe under either semantics.

Verification

crow lint .crow/ passes. Auditing every pipeline that accepts a manual event now reports a gate on all ten:

build-all-versions-install-deps.yaml: gated
auto-apply-patches.yaml: gated
weekly-patch-proposals.yaml: gated
weekly-audit-missing.yaml: gated
repair-built-stamp.yaml: gated
archive-missed-packages.yaml: gated
weekly-rebuild-missing.yaml: gated
trial-build-registry.yaml: gated
build-all-versions.yaml: gated
process-updates.yaml: gated
## Problem A manual `crow pipeline create` instantiates **every** pipeline in `.crow/`, and each one decides for itself whether to run. Three had nothing to decide with — their only manual condition was a bare `event: manual`: - `auto-apply-patches` — pushes to `auto/registry-patch-proposals` and opens/updates a PR - `weekly-patch-proposals` — posts and edits two Forgejo issues - `trial-build-registry` — starts a build per matrix row, on both arches So they fired on *any* manual trigger in this repo, whatever it was for. That is how they came to run alongside a manual `process-updates` run for `alpine-324-arm64` (#10723), which is also why that pipeline is marked failure. `repair-built-stamp.yaml` already documents the rule this breaks: > The gate variable is `repair_built_stamp`, not `target_arch` … Every pipeline here gates on a variable named after itself for exactly that reason. ## What this changes Each of the three gets a gate variable named after the pipeline, `evaluate`d on the manual event, defaulting to off: ```yaml variables: auto_apply_patches: description: 'Run the auto-patch proposer. Also gates this pipeline.' options: ['true', 'false'] default: 'false' when: - event: manual evaluate: 'auto_apply_patches == "true"' - event: cron cron: auto-apply-patches ``` Cron triggers are untouched, so the scheduled runs behave exactly as before. The run-manually comments in all three headers were also stale: they documented `--var task=<name>` with `woodpecker-cli`, and no pipeline evaluates a `task` variable. They now show the real invocation. ## Note on the sibling pipelines The already-gated pipelines use `default: all` (e.g. `weekly_rebuild_missing`). If Crow applies a declared default to a variable that an API-created pipeline never passed, those would match on an unrelated manual run too — `weekly-rebuild-missing` would be an expensive way to find out. I could not settle that from #10723 because its step logs have since expired, so I left them alone rather than guess. The three fixed here default to `'false'`, which is safe under either semantics. ## Verification `crow lint .crow/` passes. Auditing every pipeline that accepts a manual event now reports a gate on all ten: ``` build-all-versions-install-deps.yaml: gated auto-apply-patches.yaml: gated weekly-patch-proposals.yaml: gated weekly-audit-missing.yaml: gated repair-built-stamp.yaml: gated archive-missed-packages.yaml: gated weekly-rebuild-missing.yaml: gated trial-build-registry.yaml: gated build-all-versions.yaml: gated process-updates.yaml: gated ```
A manual pipeline creation instantiates every pipeline in .crow/, so one whose
only manual condition is a bare `event: manual` fires on any manual trigger in
this repo. auto-apply-patches, weekly-patch-proposals and trial-build-registry
were in that state and all ran unintentionally alongside a manual
process-updates run.

- gate each on a variable named after the pipeline, defaulting to 'false', as
  repair-built-stamp.yaml documents and the other pipelines already do
- refresh the stale run-manually comments, which still referenced a `task`
  variable that no pipeline evaluates
pat-s merged commit 1e843523a0 into main 2026-08-09 10:02:05 +00:00
pat-s deleted branch fix/gate-manual-pipelines 2026-08-09 10:02:06 +00:00
Sign in to join this conversation.
No reviewers
No labels
No milestone
No assignees
1 participant
Notifications
Due date
The due date is invalid or out of range. Please use the format "yyyy-mm-dd".

No due date set.

Dependencies

No dependencies set

Reference
devxy/build-cran-binaries!155
No description provided.