build-cran-binaries/.crow/weekly-audit-missing.yaml
pat-s f8e31af75b
Some checks failed
ci/crow/manual/weekly-audit-missing/6 Pipeline was successful
ci/crow/manual/weekly-audit-missing/5 Pipeline was successful
ci/crow/manual/weekly-rebuild-missing/5 Pipeline was canceled
ci/crow/manual/weekly-rebuild-missing/6 Pipeline was canceled
ci/crow/cron/process-updates/10 Pipeline was successful
ci/crow/cron/process-updates/4 Pipeline was successful
fix(ci): make every manual gate default to a value that matches nothing (#158)
## Problem

A manual `crow pipeline create` instantiates **every** file in `.crow/`, and a declared variable default is applied even when the run never passed that variable. A gate is therefore only a gate if its default matches nothing.

#155 fixed the three pipelines that had no manual gate at all. It missed that a *permissive default* leaves a pipeline just as exposed. Demonstrated the expensive way: creating a pipeline with only

```
--var weekly_audit_missing=alpine-324-amd64
```

also started `build-all-versions` — because its gate `target_arch` defaults to `amd64`, which matches its own amd64 matrix rows — and `process-updates` across every row, because that gate defaults to `all`. The run was killed before any `Upload package indexes` step produced output and both alpine324 indices were verified unchanged, but `build-all-versions` uploads binaries and rewrites indexes, so the next one might not be caught in time.

Before:

| pipeline | gate | default | fired on an unrelated manual run |
| --- | --- | --- | --- |
| `build-all-versions` | `target_arch` | `amd64` | amd64 rows — builds and uploads |
| `build-all-versions-install-deps` | `target_arch` | `amd64` | amd64 rows |
| `weekly-rebuild-missing` | `weekly_rebuild_missing` | `all` | every row |
| `weekly-audit-missing` | `weekly_audit_missing` | `all` | every row |
| `process-updates` | `process_cran_updates` | `all` | every row |
| `repair-built-stamp` | `repair_built_stamp` | `arm64` | arm64 rows |

`archive-missed-packages` was the one that behaved, because its gate variable is never declared and so matches nothing. That is the property this restores everywhere.

## What this changes

Each of the six gets a `none` option on its gate variable and defaults to it, so a manual run has to name its target explicitly. The reason is recorded next to the default, where someone would go to change it.

`none` is used rather than dropping the default so the expression always has a defined value to compare, instead of relying on undefined-variable semantics.

Cron triggers are untouched — they match on the `cron:` name, not the variable.

## Verification

`crow lint .crow/` reports all ten configs valid. Auditing every pipeline that accepts a manual event:

```
archive-missed-packages.yaml:        gate=task                    default=<none>
auto-apply-patches.yaml:             gate=auto_apply_patches      default='false'
build-all-versions-install-deps.yaml gate=target_arch             default=none
build-all-versions.yaml:             gate=target_arch             default=none
process-updates.yaml:                gate=process_cran_updates    default=none
repair-built-stamp.yaml:             gate=repair_built_stamp      default=none
trial-build-registry.yaml:           gate=trial_build_registry    default='false'
weekly-audit-missing.yaml:           gate=weekly_audit_missing    default=none
weekly-patch-proposals.yaml:         gate=weekly_patch_proposals  default='false'
weekly-rebuild-missing.yaml:         gate=weekly_rebuild_missing  default=none
```

Every gate now defaults to something that matches no matrix row.

Reviewed-on: #158
2026-08-09 15:31:14 +00:00

160 lines
4.2 KiB
YAML

# Consolidated weekly-audit-missing pipeline (all platforms, both arches).
# One matrix row per OS/arch replaces the former per-platform files.
# Routing is preserved 1:1:
# - cron: each existing `weekly-audit-missing-<os>-<arch>` cron fires only
# its matching matrix row (via the per-row `cron:` name filter).
# - manual: pick a target from the `weekly_audit_missing` dropdown
# ("all" = every os/arch).
# Arch placement is via the group label (rpkgs-amd64, rpkgs-arm64).
variables:
# Gates this pipeline. A manual pipeline creation instantiates every file in
# .crow/, and a declared default is applied even when the run never passed
# this variable, so the default must be a value that matches no matrix row.
weekly_audit_missing:
description: "Manual run target: a specific <os>-<arch>, 'all' for every os/arch, or 'none' to run nothing."
options:
- none
- all
- alpine-322-amd64
- alpine-322-arm64
- alpine-323-amd64
- alpine-323-arm64
- alpine-324-amd64
- alpine-324-arm64
- redhat-8-amd64
- redhat-8-arm64
- redhat-9-amd64
- redhat-9-arm64
- redhat-10-amd64
- redhat-10-arm64
- ubuntu-2204-amd64
- ubuntu-2204-arm64
- ubuntu-2404-amd64
- ubuntu-2404-arm64
- ubuntu-2604-amd64
- ubuntu-2604-arm64
default: none
when:
- event: cron
cron: weekly-audit-missing-${OS}-${ARCH}
- event: manual
evaluate: 'weekly_audit_missing == "all" || weekly_audit_missing == "${OS}-${ARCH}"'
skip_clone: true
labels:
group: rpkgs-${ARCH}
matrix:
include:
- OS: alpine-322
ARCH: amd64
R_VERSION: 4.5.3
IMG: alpine:3.22
- OS: alpine-322
ARCH: arm64
R_VERSION: 4.5.3
IMG: alpine:3.22
- OS: alpine-323
ARCH: amd64
R_VERSION: 4.5.3
IMG: alpine:3.23
- OS: alpine-323
ARCH: arm64
R_VERSION: 4.5.3
IMG: alpine:3.23
- OS: alpine-324
ARCH: amd64
R_VERSION: 4.5.3
IMG: alpine:3.24
- OS: alpine-324
ARCH: arm64
R_VERSION: 4.5.3
IMG: alpine:3.24
- OS: redhat-8
ARCH: amd64
R_VERSION: 4.4.3
IMG: redhat:8
- OS: redhat-8
ARCH: arm64
R_VERSION: 4.4.3
IMG: redhat:8
- OS: redhat-9
ARCH: amd64
R_VERSION: 4.4.3
IMG: redhat:9
- OS: redhat-9
ARCH: arm64
R_VERSION: 4.4.3
IMG: redhat:9
- OS: redhat-10
ARCH: amd64
R_VERSION: 4.5.3
IMG: redhat:10
- OS: redhat-10
ARCH: arm64
R_VERSION: 4.5.3
IMG: redhat:10
- OS: ubuntu-2204
ARCH: amd64
R_VERSION: 4.4.3
IMG: ubuntu:jammy
- OS: ubuntu-2204
ARCH: arm64
R_VERSION: 4.4.3
IMG: ubuntu:jammy
- OS: ubuntu-2404
ARCH: amd64
R_VERSION: 4.4.3
IMG: ubuntu:noble
- OS: ubuntu-2404
ARCH: arm64
R_VERSION: 4.4.3
IMG: ubuntu:noble
- OS: ubuntu-2604
ARCH: amd64
R_VERSION: 4.5.3
IMG: ubuntu:resolute
- OS: ubuntu-2604
ARCH: arm64
R_VERSION: 4.5.3
IMG: ubuntu:resolute
steps:
- name: 'Audit missing binaries'
image: reg.devxy.io/rpkgs/build-env-${IMG}
pull: true
environment:
B2_S3_ACCESS_KEY:
from_secret: B2_S3_ACCESS_KEY
B2_S3_SECRET_KEY:
from_secret: B2_S3_SECRET_KEY
PGPASS:
from_secret: PGPASS
REPO_RO_TOKEN:
from_secret: REPO_RO_TOKEN
GITHUB_PAT:
from_secret: GITHUB_PAT
FORGEJO_TOKEN:
from_secret: FORGEJO_TOKEN
PLATFORM: ${OS}
ARCH: ${ARCH}
R_LIBS_USER: /mnt/cache/R-pkgs
R_VERSION: ${R_VERSION}
commands:
- git clone -q https://pat-s:$$REPO_RO_TOKEN@git.devxy.io/devxy/build-cran-binaries.git .
- mkdir -p /mnt/cache/packages /mnt/cache/R-pkgs
- rm -rf /mnt/cache/R-pkgs/00LOCK-*
- /opt/R/$R_VERSION/bin/Rscript local/install-bincraft.R
- UVR_R_BIN=/opt/R/$R_VERSION/bin/R local/uvr-install.sh httr2 jsonlite
- /opt/R/$R_VERSION/bin/R -q -e 'source("local/weekly-missing-binaries-audit.R")'
backend_options:
docker:
resources:
requests:
memory: 2Gi
cpu: 2000m
limits:
memory: 4Gi
cpu: 2000m