diff --git a/.gitea/workflows/ci.yml b/.gitea/workflows/ci.yml index 50d563a..6d66c5f 100644 --- a/.gitea/workflows/ci.yml +++ b/.gitea/workflows/ci.yml @@ -33,21 +33,40 @@ jobs: - uses: actions/checkout@v4 with: fetch-depth: 0 + # Implements: REQ-1 (DEVX-176) — docs-only changes skip the heavy + # quality steps. Detection needs only git, so it runs before setup. + - name: Detect docs-only change + id: docs-only + if: github.event_name == 'pull_request' + run: | + HEAD="${{ github.event.pull_request.head.sha || github.sha }}" + DOCS_ONLY=true + while IFS= read -r f; do + case "$f" in + docs/*|*.md|.devin/*) ;; + *) DOCS_ONLY=false; break;; + esac + done < <(git diff --name-only "origin/master...$HEAD") + echo "docs-only=$DOCS_ONLY" >> "$GITHUB_OUTPUT" + echo "docs-only=$DOCS_ONLY" - name: Set up environment env: CI_GITEA_API_TOKEN: ${{ secrets.CI_GITEA_API_TOKEN }} run: make setup-image # --- quality steps --- - name: Lint all + if: steps.docs-only.outputs.docs-only != 'true' run: | . .venv/bin/activate 2>/dev/null || true export PATH="$HOME/.local/bin:$PATH" make lint-all - name: Unit tests with 100% coverage + if: steps.docs-only.outputs.docs-only != 'true' run: | . .venv/bin/activate 2>/dev/null || true make pytest-cov - name: Check unit test speed + if: steps.docs-only.outputs.docs-only != 'true' run: | . .venv/bin/activate 2>/dev/null || true python3 -m devx.tools.check_test_speed --max-seconds 15 --max-single-seconds 0.5 @@ -60,10 +79,12 @@ jobs: export PATH="$HOME/.local/bin:$PATH" make devx-docs-check - name: Translation completeness check + if: steps.docs-only.outputs.docs-only != 'true' run: | . .venv/bin/activate 2>/dev/null || true python3 -m devx.ci.check_translations - name: Dependency security scan + if: steps.docs-only.outputs.docs-only != 'true' run: | . .venv/bin/activate 2>/dev/null || true # Install pip in venv if missing (needed by pip-audit) @@ -71,6 +92,7 @@ jobs: PIPAPI_PYTHON_LOCATION=$PWD/.venv/bin/python \ pip-audit --desc --skip-editable 2>&1 || true - name: Workflow dry-run validation + if: steps.docs-only.outputs.docs-only != 'true' run: | . .venv/bin/activate 2>/dev/null || true export PATH="$HOME/.local/bin:$PATH" @@ -137,19 +159,9 @@ jobs: . .venv/bin/activate 2>/dev/null || true export PATH="$HOME/.local/bin:$PATH" python3 -m devx.ci.release --dry-run - - name: Notify on failure - if: failure() - env: - CI_GITEA_API_TOKEN: ${{ secrets.CI_GITEA_API_TOKEN }} - run: | - . .venv/bin/activate 2>/dev/null || true - export PATH="$HOME/.local/bin:$PATH" - python3 -m devx.ci.notify_failure \ - --repo "${{ github.repository }}" \ - --run-id "${{ github.run_id }}" \ - --workflow "ci/validate" \ - --commit "${{ github.sha }}" \ - --auto-login + # Implements: REQ-2 (DEVX-176) — no failure-issue step in PR CI; + # auto-created issues are for deploy-pipeline failures only + # (post-merge keeps its notification). auto-merge: # Auto-merge runs after validate passes. It reads the task ID diff --git a/.gitea/workflows/post-merge.yml b/.gitea/workflows/post-merge.yml index 8dd596d..5a8190c 100644 --- a/.gitea/workflows/post-merge.yml +++ b/.gitea/workflows/post-merge.yml @@ -24,7 +24,9 @@ on: concurrency: group: post-merge-${{ github.ref }} - cancel-in-progress: true + # Implements: REQ-3 (DEVX-176) — queue instead of killing an in-flight + # release/publish; a cancelled release can leave tag-without-publish. + cancel-in-progress: false env: PIP_BREAK_SYSTEM_PACKAGES: "1" diff --git a/docs/specs/DEVX-176.md b/docs/specs/DEVX-176.md new file mode 100644 index 0000000..ced9997 --- /dev/null +++ b/docs/specs/DEVX-176.md @@ -0,0 +1,43 @@ +# DEVX-176: CI hygiene — docs fast-path, failure-notify scoping, post-merge cancel + +## Problem + +devx CI has the same inefficiencies fixed in infra (OBL-INFRA-613/615/616): +docs-only PRs run the full quality suite (~10 min), CI failures auto-create +issues (noise — the user decided issues are for deploy failures only), and +post-merge `cancel-in-progress: true` can kill a release mid-publish. + +## Approach + +REQ-1: Docs-only PRs skip heavy validate steps (lint-all, unit tests, +test-speed, translation check, security scan, workflow dry-run). Docs gate, +spec validation, PR size, and auto-merge preconditions still run. +Restricted to pull_request events. + +REQ-2: Remove the failure-issue step from `ci.yml` validate job. +Post-merge keeps failure notification (release/publish failures are +deploy-pipeline events). + +REQ-3: post-merge `cancel-in-progress: false` — a new push queues instead +of killing an in-flight release/publish. + +## Test Plan + +- `make workflow-lint` passes. +- Docs-only PR: quality steps skipped, docs gate + spec + size + merge run. +- Non-docs PR: unchanged behavior. + +## Deploy Plan + +Workflow-only change; takes effect on merge. No release needed. + +## Rollback Plan + +Revert the commit. + +## Acceptance Criteria + +- [x] REQ-1 implemented — early docs-only step + step-level `if` gates +- [x] REQ-2 implemented — notify step removed from ci.yml only +- [x] REQ-3 implemented — post-merge concurrency flipped +- [x] `make workflow-lint` passes