Watch
0
0
Fork
You've already forked hyperhive
0
hyperhive/.forgejo/workflows/coverage.yml
atlas a86379eac5
Some checks were skipped
public bin cache / build + push to preem:grid (push) Has been skipped
ci: internal jobs skip on the public forge instead of waiting for a hive-ci runner
A job-level if: is evaluated by whichever runner picks the job up. The
public forge's copy has only a nixos runner, so a job guarded by
if: vars.PUBLIC_FORGE != 'true' and pinned to runs-on: [hive-ci] never
gets picked up there to evaluate the guard at all - it just sits queued.

runs-on now carries the same PUBLIC_FORGE variable: hive-ci internally,
nixos on the public copy. There the nixos runner picks the job up,
evaluates the existing if:, and skips it immediately. Internally
PUBLIC_FORGE is unset, so runs-on still resolves to hive-ci and nothing
changes.
2026-09-28 19:28:23 +02:00

50 lines
2 KiB
YAML

name: coverage
# Nightly plus manual dispatch. The report is uploaded as an artifact rather
# than printed into the run log, so a scheduled run leaves something to fetch.
#
# ⚠️ The hour is deliberate: at the default job capacity of 1
# (`services.hyperhive.deploy.forgejo.ci.concurrency`) this job holds the
# runner for its whole timeout and everything else queues behind it.
#
# Separate from ci.yml because a `workflow_dispatch` trigger there fires every
# job in that file, and this must not run per pull request.
on:
workflow_dispatch:
schedule:
- cron: "0 2 * * *"
jobs:
coverage:
name: cargo llvm-cov
if: vars.PUBLIC_FORGE != 'true'
runs-on: ${{ vars.PUBLIC_FORGE == 'true' && 'nixos' || 'hive-ci' }}
# Above the 30 min `nix flake check` allows, because instrumented
# builds are slower than the ordinary ones and this starts from a
# cache that the normal jobs never populate.
timeout-minutes: 60
steps:
- uses: actions/checkout@v3
- name: coverage
# No threshold and no `--fail-under-lines`: a coverage gate
# mostly teaches people to write assertion-free tests that
# execute lines. The report is the deliverable; the number is
# for a human to look at.
#
# `--workspace` because the interesting holes are in the crates
# nobody runs directly, and the per-crate default would hide
# exactly those behind a green summary for the one crate someone
# happened to name.
#
# `pipefail` or the step reports `tee`'s status, and a failed run
# uploads an empty report as a success.
run: |
set -o pipefail
nix develop -c cargo llvm-cov --workspace --summary-only | tee coverage-summary.txt
- name: keep the report
# `always()`: a failed run should still leave its partial output.
if: always()
uses: actions/upload-artifact@v3
with:
name: coverage-summary
path: coverage-summary.txt