name: Validation # The same checks on both roads into main. Work lands here by direct push as # often as by pull request, and a test suite reachable only from a PR guards # the road nobody takes. on: pull_request: paths: - "bios/**" - "platforms/**" - "emulators/**" - "schemas/**" - "scripts/**" - "tests/**" # The bootstraps pin install.py's SHA-256 and a test enforces the pin, # so editing one without the other has to fail the PR. - "install.py" - "install.sh" - "install.ps1" # Spelled out twice because the workflow parser reads no YAML anchor; a test # holds the two lists equal. push: branches: [main] paths: - "bios/**" - "platforms/**" - "emulators/**" - "schemas/**" - "scripts/**" - "tests/**" - "install.py" - "install.sh" - "install.ps1" permissions: contents: read pull-requests: write concurrency: # A push series collapses to the tip: what has to stay verified is the head # of main, not every commit that passed under it. group: validate-${{ github.event.pull_request.number || github.ref }} cancel-in-progress: true jobs: validate-bios: runs-on: ubuntu-latest if: github.event_name == 'pull_request' steps: - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7 with: fetch-depth: 0 - uses: actions/setup-python@5fda3b95a4ea91299a34e894583c3862153e4b97 # v7 with: python-version: "3.12" - name: Install dependencies run: pip install pyyaml - name: Get changed BIOS files id: changed env: BASE_SHA: ${{ github.event.pull_request.base.sha }} HEAD_SHA: ${{ github.event.pull_request.head.sha }} run: | # NUL-separated and filtered to added/modified/renamed: a deleted # file has no bytes left to hash, and a path with a space or a # quote must survive the hand-off to validate_pr.py. git diff --name-only --diff-filter=AMR -z "$BASE_SHA"..."$HEAD_SHA" \ -- bios/ > changed_files.zlist - name: Validate BIOS files id: validate run: | if [ -s changed_files.zlist ]; then xargs -0 python scripts/validate_pr.py --markdown -- \ < changed_files.zlist > report.md 2>&1 || true else echo "No BIOS files changed" > report.md fi cat report.md - name: Post validation report if: always() run: | gh pr comment "${{ github.event.pull_request.number }}" --body-file report.md env: GH_TOKEN: ${{ github.token }} validate-configs: runs-on: ubuntu-latest steps: - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7 - uses: actions/setup-python@5fda3b95a4ea91299a34e894583c3862153e4b97 # v7 with: python-version: "3.12" - name: Install dependencies run: pip install pyyaml jsonschema==4.23.0 - name: Validate platform configs and emulator profiles run: python scripts/validate_schemas.py --source-only run-tests: runs-on: ubuntu-latest steps: - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7 - uses: actions/setup-python@5fda3b95a4ea91299a34e894583c3862153e4b97 # v7 with: python-version: "3.12" - name: Install dependencies run: pip install pyyaml jsonschema==4.23.0 - name: Run test suite run: python -m unittest discover tests -v label-pr: runs-on: ubuntu-latest if: github.event_name == 'pull_request' permissions: pull-requests: write steps: - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7 with: fetch-depth: 0 - name: Auto-label PR run: | labels="" files=$(gh pr diff "${{ github.event.pull_request.number }}" --name-only) if echo "$files" | grep -q '^bios/'; then labels="$labels bios" for sys in $(echo "$files" | grep '^bios/' | cut -d/ -f2 | sort -u); do labels="$labels system:$(echo "$sys" | tr '[:upper:]' '[:lower:]')" done fi if echo "$files" | grep -q '^platforms/'; then labels="$labels platform-config" fi if echo "$files" | grep -q '^scripts/'; then labels="$labels automation" fi for label in $labels; do gh pr edit "${{ github.event.pull_request.number }}" --add-label "$label" 2>/dev/null || true done env: GH_TOKEN: ${{ github.token }}