Skip to content

Commit 10e9552

Browse files
authored
Merge pull request #21 from LibreCodeCoop/feat/failure-recovery-hardening
test: harden workflow update failure recovery
2 parents 2a71b7f + 1c95e0d commit 10e9552

4 files changed

Lines changed: 56 additions & 0 deletions

File tree

‎.github/workflows/publish-workflow-catalog.yml‎

Lines changed: 9 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -22,6 +22,15 @@ jobs:
2222
runs-on: ubuntu-latest
2323
timeout-minutes: 10
2424
steps:
25+
- name: Validate workflow update token
26+
env:
27+
WORKFLOW_UPDATE_TOKEN: ${{ secrets.WORKFLOW_UPDATE_TOKEN }}
28+
run: |
29+
if [ -z "$WORKFLOW_UPDATE_TOKEN" ]; then
30+
echo "::error::WORKFLOW_UPDATE_TOKEN is not configured. It must have access to the target repositories and permission to create/update pull requests."
31+
exit 1
32+
fi
33+
2534
- name: Checkout workflow source
2635
uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
2736
with:

‎.github/workflows/sync-consumers.yml‎

Lines changed: 9 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -26,6 +26,15 @@ jobs:
2626
outputs:
2727
matrix: ${{ steps.matrix.outputs.matrix }}
2828
steps:
29+
- name: Validate workflow update token
30+
env:
31+
WORKFLOW_UPDATE_TOKEN: ${{ secrets.WORKFLOW_UPDATE_TOKEN }}
32+
run: |
33+
if [ -z "$WORKFLOW_UPDATE_TOKEN" ]; then
34+
echo "::error::WORKFLOW_UPDATE_TOKEN is not configured. It must have access to the target repositories and permission to create/update pull requests."
35+
exit 1
36+
fi
37+
2938
- name: Checkout workflow source
3039
uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
3140
with:

‎tests/test_render_upstream.py‎

Lines changed: 18 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -127,6 +127,24 @@ def test_sync_reports_failure_and_continues(self) -> None:
127127
self.assertEqual(failed["name"], "broken")
128128
self.assertIn("failed to apply", failed["error"])
129129

130+
def test_failed_patch_preserves_previous_generated_template(self) -> None:
131+
with tempfile.TemporaryDirectory() as directory:
132+
root, manifest = self.fixture(directory)
133+
source = root / "upstream/vendor/example.yml"
134+
source.write_text("name: Changed upstream\n", encoding="utf-8")
135+
destination = root / "workflow-templates/example.yml"
136+
destination.parent.mkdir(parents=True)
137+
destination.write_text("name: Last known good\n", encoding="utf-8")
138+
139+
report = sync(load_templates(manifest), root)
140+
141+
self.assertFalse(report["ok"])
142+
self.assertEqual(report["failed"], 1)
143+
self.assertEqual(
144+
destination.read_text(encoding="utf-8"),
145+
"name: Last known good\n",
146+
)
147+
130148
def test_write_report(self) -> None:
131149
with tempfile.TemporaryDirectory() as directory:
132150
report_path = Path(directory) / "report.json"

‎tests/test_sync_catalog.py‎

Lines changed: 20 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -104,6 +104,26 @@ def test_requires_custom_svg_icon(self) -> None:
104104
)
105105
collect_publishable(source)
106106

107+
def test_invalid_source_does_not_partially_modify_catalog(self) -> None:
108+
with tempfile.TemporaryDirectory() as directory:
109+
root = Path(directory)
110+
source = root / "source"
111+
target = root / "target"
112+
self.write_template(source)
113+
target.mkdir()
114+
existing = target / "reuse.yml"
115+
existing.write_text("name: Published\n", encoding="utf-8")
116+
117+
(source / "reuse.properties.json").unlink()
118+
119+
with self.assertRaisesRegex(ValueError, "missing template metadata"):
120+
sync_catalog(source, target)
121+
122+
self.assertEqual(
123+
existing.read_text(encoding="utf-8"),
124+
"name: Published\n",
125+
)
126+
107127
def test_check_detects_drift(self) -> None:
108128
with tempfile.TemporaryDirectory() as directory:
109129
root = Path(directory)

0 commit comments

Comments
 (0)