fix: run the suite on both roads into main

validate.yml triggered on pull_request alone, and it holds the only
unittest invocation in the repository: deploy-site.yml stops at
validate_schemas, generation and the freshness diff. Work lands on main
by direct push far more often than by pull request, so 1,318 cases were
guarding the road almost nothing takes.

The suite and the schema check now run on both events. validate-bios and
label-pr read pull request context and carry an event guard. The
concurrency group falls back to the ref, so a push series collapses to
the tip: what stays verified is the head of main.

The path lists are spelled out per event because the workflow parser
reads no YAML anchor, which PyYAML would have accepted in silence. Four
tests hold the wiring: the suite reachable from a push, the two path
lists equal, every job reading pull request context guarded, and no
anchor in any workflow.
This commit is contained in:
Abdessamad Derraz committed 2026-09-04 13:40:11 +02:00
1 parent 60c723a3bf
commit 5587c25675
5 files changed
+119 -19

No files matched your search

+1 -1
View File
@@ -348,7 +348,7 @@ pattern and how to add a test.
| Workflow | File | Trigger | Role |
|----------|------|---------|------|
| Deploy Site | `deploy-site.yml` | push to main (platforms, emulators, wiki, scripts) + manual | validate contracts, generate site, build with MkDocs, validate rendered HTML, deploy to Pages |
| PR Validation | `validate.yml` | pull request on bios/, platforms/, emulators/, schemas/, scripts/, tests/ | validate BIOS hashes, schema check, run the full test suite, auto-label PR |
| Validation | `validate.yml` | pull request and push to main on bios/, platforms/, emulators/, schemas/, scripts/, tests/ | schema check and full test suite on both; BIOS hash validation and auto-label on pull requests |
Releases are not built in CI: the packs are generated and checked on the
maintainer's machine and uploaded with `gh`, see the
+15 -12
View File
@@ -14,7 +14,7 @@ Budget target: ~175 minutes/month on the GitHub free tier.
| Workflow | File | Trigger |
|----------|------|---------|
| Deploy Site | `deploy-site.yml` | Push to main (platforms, emulators, provenance, wiki, scripts, database.json, mkdocs.yml), manual |
| PR Validation | `validate.yml` | PR touching `bios/**`, `platforms/**` or `emulators/**` |
| Validation | `validate.yml` | PR and push to main touching `bios/**`, `platforms/**` or `emulators/**` |
Upstream BIOS lists are not scraped on a schedule. A maintainer runs the
scrapers by hand (see [adding a scraper](adding-a-scraper.md)), reviews the
@@ -70,18 +70,21 @@ The theme version is pinned on both sides: `>=9.7.5` because that is the
release which caps `mkdocs < 2` (MkDocs 2.0 ships without a license), `<10`
so a major theme release cannot change the site without a deliberate bump.
## validate.yml - PR Validation
## validate.yml - Validation
**Trigger.** Pull requests that modify `bios/**`, `platforms/**`,
`emulators/**`, `schemas/**`, `scripts/**`, `tests/**` or `install.py`.
**Trigger.** Pull requests and direct pushes to main that modify `bios/**`,
`platforms/**`, `emulators/**`, `schemas/**`, `scripts/**`, `tests/**` or
`install.py`. The path lists are spelled out once per event because the
workflow parser reads no YAML anchor.
**Concurrency.** Per-PR group, cancel in-progress.
**Concurrency.** Per-PR group on a pull request, per-ref on a push, cancel
in-progress either way: a push series collapses to the tip.
Four parallel jobs:
Four jobs, two of which read pull request context and carry an event guard:
**validate-bios.** Diffs the PR to find changed BIOS files, runs
`validate_pr.py --markdown` on each, and posts the validation report as a PR
comment (hash verification, database match status).
**validate-bios** (pull requests only). Diffs the PR to find changed BIOS
files, runs `validate_pr.py --markdown` on each, and posts the validation
report as a PR comment (hash verification, database match status).
**validate-configs.** Runs `python scripts/validate_schemas.py --source-only`,
which validates every platform YAML against `schemas/platform.schema.json` and
@@ -89,10 +92,10 @@ every emulator profile against `schemas/emulator.schema.json`. Both schemas set
`additionalProperties: false`, so a typo in a field name fails the job instead
of being silently ignored.
**run-tests.** Runs `python -m unittest discover tests -v`. Must pass before
merge.
**run-tests.** Runs `python -m unittest discover tests -v`. Must pass before a
merge, and again on the commit a direct push puts at the head of main.
**label-pr.** Auto-labels the PR based on changed paths:
**label-pr** (pull requests only). Auto-labels the PR based on changed paths:
| Path pattern | Label |
|-------------|-------|
+11 -4
View File
@@ -246,10 +246,17 @@ Ideally, tests, code, and documentation ship together. When profiles and platfor
## CI integration
The `validate.yml` workflow runs `python -m unittest discover tests -v` on every
pull request that touches `bios/`, `platforms/`, `emulators/`, `schemas/`,
`scripts/`, `tests/` or `install.py`. The test job (`run-tests`) runs in parallel
with BIOS validation, schema validation, and auto-labeling.
The `validate.yml` workflow runs `python -m unittest discover tests -v` on both
roads into main: every pull request, and every direct push, that touches
`bios/`, `platforms/`, `emulators/`, `schemas/`, `scripts/`, `tests/` or
`install.py`. Work reaches main by push as often as by pull request, so a suite
wired to pull requests alone would guard the road nobody takes. The test job
(`run-tests`) runs in parallel with schema validation, and on a pull request
with BIOS validation and auto-labeling too; those two read pull request context
and stay behind an event guard.
A push series collapses to the tip, so what a green run states is that the head
of main passes, not every commit under it.
Modules that need real artifacts skip themselves when those artifacts are absent,
so `test_pack_integrity` is a no-op in CI (no `dist/`) and a real check locally.