diff --git a/.gitea/workflows/runner-probe.yml b/.gitea/workflows/runner-probe.yml new file mode 100644 index 0000000..ee2ef06 --- /dev/null +++ b/.gitea/workflows/runner-probe.yml @@ -0,0 +1,225 @@ +name: runner-probe + +# Probe-only workflow — answers all runner unknowns before real CI is designed. +# Runs ONLY on the feature branch; never on main. +# All steps that may fail on this runner use continue-on-error: true or || true +# so the probe REPORTS findings instead of red-failing on an expected unknown. +# Do NOT reference any secret in this workflow (T-08-01). +# +# Checks performed: P-01 through P-11 + P-13 +# P-12 (docker login) is deferred to Plan 04 (publish) — DO NOT add it here. + +on: + push: + branches: + - gsd/phase-08-gitea-ci + +jobs: + probe: + name: runner-probe + runs-on: self-hosted + + # P-05: Service container — probe whether it spawns and on which hostname. + # Uses healthcheck.sh --connect --innodb_initialized. + # Note: healthcheck.sh is used because the binary from older clients was + # removed from mariadb:11 (Pitfall 11). + services: + mariadb: + image: mariadb:11 + env: + MARIADB_ROOT_PASSWORD: root + MARIADB_DATABASE: familysync + MARIADB_USER: familysync + MARIADB_PASSWORD: testpass + options: >- + --health-cmd="healthcheck.sh --connect --innodb_initialized" + --health-interval=10s + --health-timeout=5s + --health-retries=10 + --health-start-period=30s + + steps: + # ─── P-07: actions/checkout ────────────────────────────────────────────── + # Must be first real step. Reaching subsequent steps proves it resolves. + - name: P-07 checkout (actions/checkout@v4) + uses: actions/checkout@v4 + + # ─── P-08: actions/setup-node ──────────────────────────────────────────── + - name: P-08 setup-node (actions/setup-node@v4 — pin Node 22) + uses: actions/setup-node@v4 + with: + node-version: '22' + + # ─── P-01: Node.js version ─────────────────────────────────────────────── + - name: P-01 Node.js version + run: | + echo "=== P-01: Node.js version ===" + node --version + echo "Expected: v22.x" + + # ─── P-02: pnpm availability ───────────────────────────────────────────── + - name: P-02 pnpm availability + run: | + echo "=== P-02: pnpm availability ===" + pnpm --version 2>/dev/null || ( + echo "pnpm not found — attempting corepack activation" + corepack enable pnpm + pnpm --version + ) + echo "Expected: pnpm 11.x (from packageManager field in package.json)" + + # ─── P-03: Runner mode — THE critical fork ─────────────────────────────── + # Docker-executor mode: job runs inside a Docker container + # → services: works; DB_HOST=mariadb + # Host-executor mode: job runs directly on the Unraid host + # → services: not supported; must use docker run -d fallback + - name: P-03 runner mode detection (Docker vs host — critical fork) + run: | + echo "=== P-03: Runner mode (critical fork) ===" + echo "--- /proc/1/cgroup (first 5 lines) ---" + cat /proc/1/cgroup 2>/dev/null | head -5 || echo "(not readable)" + echo "--- hostname ---" + hostname + echo "--- /.dockerenv presence ---" + ls -la /.dockerenv 2>&1 + echo "--- Conclusion ---" + if [ -f /.dockerenv ]; then + echo "RUNNER MODE: Docker-executor (job is running inside a Docker container)" + echo " → services: will work; MariaDB hostname = service label name (mariadb)" + echo " → DB_HOST=mariadb in downstream jobs" + else + echo "RUNNER MODE: host-executor (job is running directly on the host)" + echo " → services: NOT supported (nektos/act#2711)" + echo " → Downstream jobs must use: docker run -d mariadb:11 + explicit readiness loop" + echo " → DB_HOST=127.0.0.1 with -p 3306:3306 in docker run" + fi + + # ─── P-04: Docker socket access ────────────────────────────────────────── + - name: P-04 Docker socket access + continue-on-error: true + run: | + echo "=== P-04: Docker socket access ===" + docker info 2>&1 | head -20 + echo "--- docker ps (first few lines) ---" + docker ps 2>&1 | head + + # ─── P-05: Service container spawn check ───────────────────────────────── + - name: P-05 service container spawn (mariadb:11 visible in docker ps?) + continue-on-error: true + run: | + echo "=== P-05: Service container spawn ===" + docker ps 2>&1 | grep -i maria \ + && echo "RESULT: MariaDB service container IS visible in docker ps (Docker-executor mode confirmed)" \ + || echo "RESULT: no mariadb container visible in docker ps (likely host-executor mode — services: not supported)" + + # ─── P-06: MariaDB reachability — try BOTH hostnames ───────────────────── + # Does NOT fail the job: records which hostname resolves. + - name: P-06 MariaDB reachability (hostname=mariadb — Docker mode) + continue-on-error: true + run: | + echo "=== P-06a: MariaDB via hostname 'mariadb' (Docker-executor mode) ===" + mysql -h mariadb -P 3306 -u familysync -ptestpass -e "SELECT 1" 2>&1 | head \ + && echo "P-06a RESULT: mariadb hostname RESOLVES — Docker mode" \ + || echo "P-06a RESULT: mariadb hostname DOES NOT resolve (expected if host-executor mode)" + + - name: P-06 MariaDB reachability (hostname=127.0.0.1 — host mode) + continue-on-error: true + run: | + echo "=== P-06b: MariaDB via 127.0.0.1 (host-executor mode fallback) ===" + mysql -h 127.0.0.1 -P 3306 -u familysync -ptestpass -e "SELECT 1" 2>&1 | head \ + && echo "P-06b RESULT: 127.0.0.1 RESOLVES — host mode" \ + || echo "P-06b RESULT: 127.0.0.1 does not resolve (expected if Docker-executor mode uses 'mariadb' hostname)" + + # ─── P-09: actions/cache ───────────────────────────────────────────────── + # Known issue: cache server runs in runner container; job container on different + # network may cause socket hang-up. continue-on-error so probe reports finding. + - name: P-09 cache action (actions/cache@v4 — may time out in Docker mode) + uses: actions/cache@v4 + continue-on-error: true + with: + path: /tmp/probe-cache-test + key: runner-probe-cache-test-${{ github.sha }} + + - name: P-09 cache result + run: | + echo "=== P-09: Cache action result ===" + echo "If the previous 'cache' step completed without hanging, cache IS usable." + echo "If it timed out or errored, fall back to no-cache in downstream jobs." + + # ─── P-10: Playwright WebKit system deps ──────────────────────────────── + # Confirms WebKit system deps install without sudo/apt failure (Assumption A10). + # Runs from apps/pwa where @playwright/test is installed. + - name: P-10 Playwright WebKit + Chromium system deps + continue-on-error: true + working-directory: apps/pwa + run: | + echo "=== P-10: Playwright browser system deps (webkit + chromium) ===" + npx playwright install --with-deps webkit chromium 2>&1 | tail -30 + echo "--- Exit code: $? ---" + echo "If the above shows installed without 'sudo' or 'apt' errors, WebKit deps are OK." + + # ─── P-11: gitea-upload-artifact fork ─────────────────────────────────── + # The official upload-artifact action is broken on Gitea (detected as GHES, aborts). + # Use ChristopherHX/gitea-upload-artifact@v4 — the confirmed Gitea fix (RESEARCH T-08-SC). + - name: P-11 write dummy artifact for upload test + run: | + echo "=== P-11: Upload artifact test ===" + mkdir -p /tmp/probe-artifact + echo "runner-probe artifact: sha=${GITHUB_SHA}" > /tmp/probe-artifact/probe.txt + cat /tmp/probe-artifact/probe.txt + + - name: P-11 artifact upload (ChristopherHX/gitea-upload-artifact@v4) + uses: https://github.com/ChristopherHX/gitea-upload-artifact@v4 + continue-on-error: true + with: + name: runner-probe-artifact + path: /tmp/probe-artifact/ + retention-days: 3 + + # ─── P-13: GITHUB_SHA short SHA expression ─────────────────────────────── + - name: P-13 short SHA expression (D-04 tag validation) + run: | + echo "=== P-13: GITHUB_SHA short SHA ===" + echo "GITHUB_SHA full = ${GITHUB_SHA}" + echo "short sha = ${GITHUB_SHA:0:7}" + echo "Expected: a 7-character hex string — confirms D-04 tag expression works" + if [ "${#GITHUB_SHA}" -ge 7 ]; then + echo "P-13 RESULT: OK — GITHUB_SHA is available and bash substring works" + else + echo "P-13 RESULT: WARN — GITHUB_SHA is shorter than expected or empty" + fi + + # ─── SUMMARY: one-line verdict per fork ────────────────────────────────── + # Plans 02–04 consume these answers to pick the correct implementation path. + - name: SUMMARY — fork verdicts (record answers for SUMMARY.md) + run: | + echo "========================================================" + echo " RUNNER PROBE SUMMARY — FORK ANSWERS" + echo "========================================================" + echo "" + echo "P-03 Runner mode:" + if [ -f /.dockerenv ]; then + echo " DOCKER-EXECUTOR — job runs in a container" + echo " → services: works; DB_HOST=mariadb" + else + echo " HOST-EXECUTOR — job runs directly on host" + echo " → services: NOT supported; use docker run -d + DB_HOST=127.0.0.1" + fi + echo "" + echo "P-05/P-06 MariaDB service container:" + MARIA_CONTAINER=$(docker ps 2>/dev/null | grep -i maria | head -1 || true) + if [ -n "$MARIA_CONTAINER" ]; then + echo " Service container IS visible — hostname 'mariadb' should resolve" + else + echo " Service container NOT visible — use docker run -d fallback" + fi + echo "" + echo "P-09 Cache: see 'cache' step result above (continue-on-error — pass = usable)" + echo "P-10 WebKit deps: see 'playwright install' step above (continue-on-error)" + echo "P-11 Upload artifact: see 'gitea-upload-artifact' step above (continue-on-error)" + echo "" + echo "P-13 Short SHA: ${GITHUB_SHA:0:7}" + echo "" + echo " SECURITY CHECK: this probe references NO secrets (T-08-01 compliant)" + echo " P-12 (docker login/push) is deferred to Plan 04 — NOT in this probe." + echo "========================================================"