name: runner-probe # Probe-only workflow — answers all runner unknowns before real CI is designed. # Runs ONLY on the feature branch; never on main. # All steps that may fail on this runner use continue-on-error: true or || true # so the probe REPORTS findings instead of red-failing on an expected unknown. # Do NOT reference any secret in this workflow (T-08-01). # # Checks performed: P-01 through P-11 + P-13 # P-12 (docker login) is deferred to Plan 04 (publish) — DO NOT add it here. on: push: branches: - gsd/phase-08-gitea-ci jobs: probe: name: runner-probe runs-on: self-hosted # P-05: Service container — probe whether it spawns and on which hostname. # Uses healthcheck.sh --connect --innodb_initialized. # Note: healthcheck.sh is used because the binary from older clients was # removed from mariadb:11 (Pitfall 11). services: mariadb: image: mariadb:11 env: MARIADB_ROOT_PASSWORD: root MARIADB_DATABASE: familysync MARIADB_USER: familysync MARIADB_PASSWORD: testpass options: >- --health-cmd="healthcheck.sh --connect --innodb_initialized" --health-interval=10s --health-timeout=5s --health-retries=10 --health-start-period=30s steps: # ─── P-07: actions/checkout ────────────────────────────────────────────── # Must be first real step. Reaching subsequent steps proves it resolves. - name: P-07 checkout (actions/checkout@v4) uses: actions/checkout@v4 # ─── P-08: actions/setup-node ──────────────────────────────────────────── - name: P-08 setup-node (actions/setup-node@v4 — pin Node 22) uses: actions/setup-node@v4 with: node-version: '22' # ─── P-01: Node.js version ─────────────────────────────────────────────── - name: P-01 Node.js version run: | echo "=== P-01: Node.js version ===" node --version echo "Expected: v22.x" # ─── P-02: pnpm availability ───────────────────────────────────────────── - name: P-02 pnpm availability run: | echo "=== P-02: pnpm availability ===" pnpm --version 2>/dev/null || ( echo "pnpm not found — attempting corepack activation" corepack enable pnpm pnpm --version ) echo "Expected: pnpm 11.x (from packageManager field in package.json)" # ─── P-03: Runner mode — THE critical fork ─────────────────────────────── # Docker-executor mode: job runs inside a Docker container # → services: works; DB_HOST=mariadb # Host-executor mode: job runs directly on the Unraid host # → services: not supported; must use docker run -d fallback - name: P-03 runner mode detection (Docker vs host — critical fork) run: | echo "=== P-03: Runner mode (critical fork) ===" echo "--- /proc/1/cgroup (first 5 lines) ---" cat /proc/1/cgroup 2>/dev/null | head -5 || echo "(not readable)" echo "--- hostname ---" hostname echo "--- /.dockerenv presence ---" ls -la /.dockerenv 2>&1 echo "--- Conclusion ---" if [ -f /.dockerenv ]; then echo "RUNNER MODE: Docker-executor (job is running inside a Docker container)" echo " → services: will work; MariaDB hostname = service label name (mariadb)" echo " → DB_HOST=mariadb in downstream jobs" else echo "RUNNER MODE: host-executor (job is running directly on the host)" echo " → services: NOT supported (nektos/act#2711)" echo " → Downstream jobs must use: docker run -d mariadb:11 + explicit readiness loop" echo " → DB_HOST=127.0.0.1 with -p 3306:3306 in docker run" fi # ─── P-04: Docker socket access ────────────────────────────────────────── - name: P-04 Docker socket access continue-on-error: true run: | echo "=== P-04: Docker socket access ===" docker info 2>&1 | head -20 echo "--- docker ps (first few lines) ---" docker ps 2>&1 | head # ─── P-05: Service container spawn check ───────────────────────────────── - name: P-05 service container spawn (mariadb:11 visible in docker ps?) continue-on-error: true run: | echo "=== P-05: Service container spawn ===" docker ps 2>&1 | grep -i maria \ && echo "RESULT: MariaDB service container IS visible in docker ps (Docker-executor mode confirmed)" \ || echo "RESULT: no mariadb container visible in docker ps (likely host-executor mode — services: not supported)" # ─── P-06: MariaDB reachability — try BOTH hostnames ───────────────────── # Does NOT fail the job: records which hostname resolves. - name: P-06 MariaDB reachability (hostname=mariadb — Docker mode) continue-on-error: true run: | echo "=== P-06a: MariaDB via hostname 'mariadb' (Docker-executor mode) ===" mysql -h mariadb -P 3306 -u familysync -ptestpass -e "SELECT 1" 2>&1 | head \ && echo "P-06a RESULT: mariadb hostname RESOLVES — Docker mode" \ || echo "P-06a RESULT: mariadb hostname DOES NOT resolve (expected if host-executor mode)" - name: P-06 MariaDB reachability (hostname=127.0.0.1 — host mode) continue-on-error: true run: | echo "=== P-06b: MariaDB via 127.0.0.1 (host-executor mode fallback) ===" mysql -h 127.0.0.1 -P 3306 -u familysync -ptestpass -e "SELECT 1" 2>&1 | head \ && echo "P-06b RESULT: 127.0.0.1 RESOLVES — host mode" \ || echo "P-06b RESULT: 127.0.0.1 does not resolve (expected if Docker-executor mode uses 'mariadb' hostname)" # ─── P-09: actions/cache ───────────────────────────────────────────────── # Known issue: cache server runs in runner container; job container on different # network may cause socket hang-up. continue-on-error so probe reports finding. - name: P-09 cache action (actions/cache@v4 — may time out in Docker mode) uses: actions/cache@v4 continue-on-error: true with: path: /tmp/probe-cache-test key: runner-probe-cache-test-${{ github.sha }} - name: P-09 cache result run: | echo "=== P-09: Cache action result ===" echo "If the previous 'cache' step completed without hanging, cache IS usable." echo "If it timed out or errored, fall back to no-cache in downstream jobs." # ─── P-10: Playwright WebKit system deps ──────────────────────────────── # Confirms WebKit system deps install without sudo/apt failure (Assumption A10). # Runs from apps/pwa where @playwright/test is installed. - name: P-10 Playwright WebKit + Chromium system deps continue-on-error: true working-directory: apps/pwa run: | echo "=== P-10: Playwright browser system deps (webkit + chromium) ===" npx playwright install --with-deps webkit chromium 2>&1 | tail -30 echo "--- Exit code: $? ---" echo "If the above shows installed without 'sudo' or 'apt' errors, WebKit deps are OK." # ─── P-11: gitea-upload-artifact fork ─────────────────────────────────── # The official upload-artifact action is broken on Gitea (detected as GHES, aborts). # Use ChristopherHX/gitea-upload-artifact@v4 — the confirmed Gitea fix (RESEARCH T-08-SC). - name: P-11 write dummy artifact for upload test run: | echo "=== P-11: Upload artifact test ===" mkdir -p /tmp/probe-artifact echo "runner-probe artifact: sha=${GITHUB_SHA}" > /tmp/probe-artifact/probe.txt cat /tmp/probe-artifact/probe.txt - name: P-11 artifact upload (ChristopherHX/gitea-upload-artifact@v4) uses: https://github.com/ChristopherHX/gitea-upload-artifact@v4 continue-on-error: true with: name: runner-probe-artifact path: /tmp/probe-artifact/ retention-days: 3 # ─── P-13: GITHUB_SHA short SHA expression ─────────────────────────────── - name: P-13 short SHA expression (D-04 tag validation) run: | echo "=== P-13: GITHUB_SHA short SHA ===" echo "GITHUB_SHA full = ${GITHUB_SHA}" echo "short sha = ${GITHUB_SHA:0:7}" echo "Expected: a 7-character hex string — confirms D-04 tag expression works" if [ "${#GITHUB_SHA}" -ge 7 ]; then echo "P-13 RESULT: OK — GITHUB_SHA is available and bash substring works" else echo "P-13 RESULT: WARN — GITHUB_SHA is shorter than expected or empty" fi # ─── SUMMARY: one-line verdict per fork ────────────────────────────────── # Plans 02–04 consume these answers to pick the correct implementation path. - name: SUMMARY — fork verdicts (record answers for SUMMARY.md) run: | echo "========================================================" echo " RUNNER PROBE SUMMARY — FORK ANSWERS" echo "========================================================" echo "" echo "P-03 Runner mode:" if [ -f /.dockerenv ]; then echo " DOCKER-EXECUTOR — job runs in a container" echo " → services: works; DB_HOST=mariadb" else echo " HOST-EXECUTOR — job runs directly on host" echo " → services: NOT supported; use docker run -d + DB_HOST=127.0.0.1" fi echo "" echo "P-05/P-06 MariaDB service container:" MARIA_CONTAINER=$(docker ps 2>/dev/null | grep -i maria | head -1 || true) if [ -n "$MARIA_CONTAINER" ]; then echo " Service container IS visible — hostname 'mariadb' should resolve" else echo " Service container NOT visible — use docker run -d fallback" fi echo "" echo "P-09 Cache: see 'cache' step result above (continue-on-error — pass = usable)" echo "P-10 WebKit deps: see 'playwright install' step above (continue-on-error)" echo "P-11 Upload artifact: see 'gitea-upload-artifact' step above (continue-on-error)" echo "" echo "P-13 Short SHA: ${GITHUB_SHA:0:7}" echo "" echo " SECURITY CHECK: this probe references NO secrets (T-08-01 compliant)" echo " P-12 (docker login/push) is deferred to Plan 04 — NOT in this probe." echo "========================================================"