From 70dc82fd9e0d9725ce0c37c7148f5da728e34942 Mon Sep 17 00:00:00 2001 From: pat-s Date: Sun, 9 Aug 2026 09:55:55 +0000 Subject: [PATCH] fix(ci): gate the three ungated pipelines on their own variable A manual pipeline creation instantiates every pipeline in .crow/, so one whose only manual condition is a bare `event: manual` fires on any manual trigger in this repo. auto-apply-patches, weekly-patch-proposals and trial-build-registry were in that state and all ran unintentionally alongside a manual process-updates run. - gate each on a variable named after the pipeline, defaulting to 'false', as repair-built-stamp.yaml documents and the other pipelines already do - refresh the stale run-manually comments, which still referenced a `task` variable that no pipeline evaluates --- .crow/auto-apply-patches.yaml | 15 ++++++++++++++- .crow/trial-build-registry.yaml | 16 ++++++++++++++-- .crow/weekly-patch-proposals.yaml | 18 ++++++++++++++++++ 3 files changed, 46 insertions(+), 3 deletions(-) diff --git a/.crow/auto-apply-patches.yaml b/.crow/auto-apply-patches.yaml index 0076353..7c33c5b 100644 --- a/.crow/auto-apply-patches.yaml +++ b/.crow/auto-apply-patches.yaml @@ -9,14 +9,27 @@ # FORGEJO_TOKEN is used for both the branch push and opening the PR (no separate # write-scoped secret needed). Register the `auto-apply-patches` cron in the crow # UI, or run manually: -# woodpecker-cli pipeline create --var task=auto-apply-patches --branch=main 7 +# crow pipeline create --branch main \ +# --var auto_apply_patches=true devxy/build-cran-binaries +# +# The gate variable is `auto_apply_patches`, named after the pipeline: a manual +# run instantiates every pipeline in `.crow/`, so one without its own gate runs +# on *any* manual trigger in this repo. This one pushes a branch and opens a PR, +# so it must stay off unless it is what was asked for. variables: + auto_apply_patches: + description: 'Run the auto-patch proposer. Also gates this pipeline.' + options: + - 'true' + - 'false' + default: 'false' patch_limit: description: 'Max candidates to propose per run (top by failure volume).' default: '10' when: - event: manual + evaluate: 'auto_apply_patches == "true"' - event: cron cron: auto-apply-patches diff --git a/.crow/trial-build-registry.yaml b/.crow/trial-build-registry.yaml index 73856a1..2195423 100644 --- a/.crow/trial-build-registry.yaml +++ b/.crow/trial-build-registry.yaml @@ -7,15 +7,27 @@ # # The repo uses no `pull_request` triggers, so this runs manually against the # branch (or on a cron); point it at the auto-patch branch via `patch_branch`: -# woodpecker-cli pipeline create --var task=trial-build-registry \ -# --var patch_branch=auto/registry-patch-proposals --branch=main 7 +# crow pipeline create --branch main --var trial_build_registry=true \ +# --var patch_branch=auto/registry-patch-proposals devxy/build-cran-binaries +# +# The gate variable is `trial_build_registry`, named after the pipeline: a +# manual run instantiates every pipeline in `.crow/`, so one without its own +# gate runs on *any* manual trigger in this repo. This one starts a build per +# matrix row on both arches, which is far too expensive to fire by accident. variables: + trial_build_registry: + description: 'Trial-build the branch new registry entries. Also gates this pipeline.' + options: + - 'true' + - 'false' + default: 'false' patch_branch: description: 'Branch whose new registry entries to trial-build.' default: auto/registry-patch-proposals when: - event: manual + evaluate: 'trial_build_registry == "true"' - event: cron cron: trial-build-registry diff --git a/.crow/weekly-patch-proposals.yaml b/.crow/weekly-patch-proposals.yaml index 027d41c..712e87d 100644 --- a/.crow/weekly-patch-proposals.yaml +++ b/.crow/weekly-patch-proposals.yaml @@ -8,8 +8,26 @@ # Global across platforms (the classifier groups over all of single_builds), so # a single job -- no matrix. Clones read-only; the only writes are the two # Forgejo issues via FORGEJO_TOKEN. +# +# Run manually with: +# crow pipeline create --branch main \ +# --var weekly_patch_proposals=true devxy/build-cran-binaries +# +# The gate variable is `weekly_patch_proposals`, named after the pipeline: a +# manual run instantiates every pipeline in `.crow/`, so one without its own +# gate runs on *any* manual trigger in this repo. This one posts and edits +# Forgejo issues, so an unrelated manual run must not fire it. +variables: + weekly_patch_proposals: + description: 'Run the weekly failure triage. Also gates this pipeline.' + options: + - 'true' + - 'false' + default: 'false' + when: - event: manual + evaluate: 'weekly_patch_proposals == "true"' - event: cron cron: weekly-patch-proposals -- 2.54.0