Public Access
Compare commits
82
Commits
| Author | SHA1 | Date | |
|---|---|---|---|
|
|
269699fd6f | ||
|
|
b18fef3f33 | ||
|
|
4d0aa326a1 | ||
|
|
a13fbddce6 | ||
|
|
8fddcff237 | ||
|
|
dede38cbe8 | ||
|
|
8f3c483eff | ||
|
|
30389ff3e7 | ||
|
|
dd8e6c69e9 | ||
|
|
ccb7023965 | ||
|
|
7dd15f1461 | ||
|
|
d4e4621fa1 | ||
|
|
a6f814c446 | ||
|
|
04aa5acb1f | ||
|
|
6973f9d851 | ||
|
|
2669a0ea73 | ||
|
|
03f057b55a | ||
|
|
706d6dafe0 | ||
|
|
03ddce427c | ||
|
|
9642d6884c | ||
|
|
b2074d6635 | ||
|
|
a6dddf25e7 | ||
|
|
01130a7385 | ||
|
|
07580c9280 | ||
|
|
6601d90bee | ||
|
|
ef1ff15593 | ||
|
|
0d0580c4fd | ||
|
|
ed3bd75367 | ||
|
|
ed0a282a52 | ||
|
|
e4e0a534ff | ||
|
|
e35ee2d71a | ||
|
|
1d9e505432 | ||
|
|
ddb0f17886 | ||
|
|
a8a8b743f3 | ||
|
|
a487bddb09 | ||
|
|
e3a37c95c1 | ||
|
|
9bb461e12f | ||
|
|
32193a0e6d | ||
|
|
155c4a204a | ||
|
|
491137f944 | ||
|
|
48cd33be22 | ||
|
|
2fae9bc723 | ||
|
|
bfc2ebec81 | ||
|
|
e01c39b4b8 | ||
|
|
aa93e894a6 | ||
|
|
0df79fed53 | ||
|
|
cf8287e683 | ||
|
|
9f1bdc4cf1 | ||
|
|
004b890463 | ||
|
|
587906f518 | ||
|
|
d743ba93eb | ||
|
|
c7351a495a | ||
|
|
4de11bfc18 | ||
|
|
a02bf6d70e | ||
|
|
368c87aabf | ||
|
|
4f982dc3ba | ||
|
|
a7a8637244 | ||
|
|
cdf3408a35 | ||
|
|
8fcac10286 | ||
|
|
c62c560c85 | ||
|
|
08b781f978 | ||
|
|
ea7566fe6b | ||
|
|
d8ceb6c8a1 | ||
|
|
748baf17eb | ||
|
|
f339df3562 | ||
|
|
db38453a54 | ||
|
|
5d78377152 | ||
|
|
b8b21cccd5 | ||
|
|
326eccfd2f | ||
|
|
076b470344 | ||
|
|
53b49ec91c | ||
|
|
2cfc0aca10 | ||
|
|
83ea4496e5 | ||
|
|
adb94bf96f | ||
|
|
32308f2ad8 | ||
|
|
5468a6f4af | ||
|
|
79830b52e7 | ||
|
|
ddfbdec956 | ||
|
|
68f0872134 | ||
|
|
888cc4e3b2 | ||
|
|
f08ff0e7a3 | ||
|
|
772e1b1c6d |
@@ -32,6 +32,11 @@ concurrency:
|
|||||||
jobs:
|
jobs:
|
||||||
build-and-push:
|
build-and-push:
|
||||||
runs-on: docker
|
runs-on: docker
|
||||||
|
container:
|
||||||
|
image: git.oblachno.oblachno.fyi/oblachno-oss/runner-images/ci-full:latest
|
||||||
|
credentials:
|
||||||
|
username: ${{ vars.CI_GITEA_USERNAME }}
|
||||||
|
password: ${{ secrets.CI_GITEA_API_TOKEN }}
|
||||||
timeout-minutes: 30
|
timeout-minutes: 30
|
||||||
outputs:
|
outputs:
|
||||||
is-release: ${{ steps.check.outputs.is-release }}
|
is-release: ${{ steps.check.outputs.is-release }}
|
||||||
@@ -115,6 +120,11 @@ jobs:
|
|||||||
needs: [build-and-push]
|
needs: [build-and-push]
|
||||||
if: always() && needs.build-and-push.result == 'success'
|
if: always() && needs.build-and-push.result == 'success'
|
||||||
runs-on: docker
|
runs-on: docker
|
||||||
|
container:
|
||||||
|
image: git.oblachno.oblachno.fyi/oblachno-oss/runner-images/ci-base:latest
|
||||||
|
credentials:
|
||||||
|
username: ${{ vars.CI_GITEA_USERNAME }}
|
||||||
|
password: ${{ secrets.CI_GITEA_API_TOKEN }}
|
||||||
timeout-minutes: 10
|
timeout-minutes: 10
|
||||||
steps:
|
steps:
|
||||||
- uses: actions/checkout@v4
|
- uses: actions/checkout@v4
|
||||||
|
|||||||
+11
-3
@@ -18,7 +18,11 @@ jobs:
|
|||||||
# Saves ~4x checkout+setup overhead vs 5 separate jobs.
|
# Saves ~4x checkout+setup overhead vs 5 separate jobs.
|
||||||
validate:
|
validate:
|
||||||
runs-on: docker
|
runs-on: docker
|
||||||
container: git.oblachno.oblachno.fyi/oblachno-oss/runner-images/ci-full:latest
|
container:
|
||||||
|
image: git.oblachno.oblachno.fyi/oblachno-oss/runner-images/ci-full:latest
|
||||||
|
credentials:
|
||||||
|
username: ${{ vars.CI_GITEA_USERNAME }}
|
||||||
|
password: ${{ secrets.CI_GITEA_API_TOKEN }}
|
||||||
timeout-minutes: 15
|
timeout-minutes: 15
|
||||||
defaults:
|
defaults:
|
||||||
run:
|
run:
|
||||||
@@ -46,7 +50,7 @@ jobs:
|
|||||||
- name: Check unit test speed
|
- name: Check unit test speed
|
||||||
run: |
|
run: |
|
||||||
. .venv/bin/activate 2>/dev/null || true
|
. .venv/bin/activate 2>/dev/null || true
|
||||||
python3 -m devx.tools.check_test_speed --max-seconds 6 --max-single-seconds 0.5
|
python3 -m devx.tools.check_test_speed --max-seconds 15 --max-single-seconds 0.5
|
||||||
- name: Documentation gate (coverage + stale refs + lint + version refs + prose)
|
- name: Documentation gate (coverage + stale refs + lint + version refs + prose)
|
||||||
env:
|
env:
|
||||||
DEVX_DOC_COVERAGE_STRICT: "1"
|
DEVX_DOC_COVERAGE_STRICT: "1"
|
||||||
@@ -140,7 +144,11 @@ jobs:
|
|||||||
github.event_name == 'pull_request' &&
|
github.event_name == 'pull_request' &&
|
||||||
needs.validate.result == 'success'
|
needs.validate.result == 'success'
|
||||||
runs-on: docker
|
runs-on: docker
|
||||||
container: git.oblachno.oblachno.fyi/oblachno-oss/runner-images/ci-base:latest
|
container:
|
||||||
|
image: git.oblachno.oblachno.fyi/oblachno-oss/runner-images/ci-base:latest
|
||||||
|
credentials:
|
||||||
|
username: ${{ vars.CI_GITEA_USERNAME }}
|
||||||
|
password: ${{ secrets.CI_GITEA_API_TOKEN }}
|
||||||
timeout-minutes: 10
|
timeout-minutes: 10
|
||||||
defaults:
|
defaults:
|
||||||
run:
|
run:
|
||||||
|
|||||||
@@ -35,7 +35,11 @@ env:
|
|||||||
jobs:
|
jobs:
|
||||||
detect-and-configure:
|
detect-and-configure:
|
||||||
runs-on: docker
|
runs-on: docker
|
||||||
container: git.oblachno.oblachno.fyi/oblachno-oss/runner-images/ci-base:latest
|
container:
|
||||||
|
image: git.oblachno.oblachno.fyi/oblachno-oss/runner-images/ci-base:latest
|
||||||
|
credentials:
|
||||||
|
username: ${{ vars.CI_GITEA_USERNAME }}
|
||||||
|
password: ${{ secrets.CI_GITEA_API_TOKEN }}
|
||||||
timeout-minutes: 10
|
timeout-minutes: 10
|
||||||
defaults:
|
defaults:
|
||||||
run:
|
run:
|
||||||
@@ -99,7 +103,11 @@ jobs:
|
|||||||
needs: [detect-and-configure]
|
needs: [detect-and-configure]
|
||||||
if: always() && needs.detect-and-configure.result == 'success'
|
if: always() && needs.detect-and-configure.result == 'success'
|
||||||
runs-on: docker
|
runs-on: docker
|
||||||
container: git.oblachno.oblachno.fyi/oblachno-oss/runner-images/ci-full:latest
|
container:
|
||||||
|
image: git.oblachno.oblachno.fyi/oblachno-oss/runner-images/ci-full:latest
|
||||||
|
credentials:
|
||||||
|
username: ${{ vars.CI_GITEA_USERNAME }}
|
||||||
|
password: ${{ secrets.CI_GITEA_API_TOKEN }}
|
||||||
timeout-minutes: 15
|
timeout-minutes: 15
|
||||||
outputs:
|
outputs:
|
||||||
tag: ${{ steps.release-tag.outputs.tag }}
|
tag: ${{ steps.release-tag.outputs.tag }}
|
||||||
|
|||||||
@@ -59,7 +59,7 @@ repos:
|
|||||||
|
|
||||||
- id: check-test-speed
|
- id: check-test-speed
|
||||||
name: unit test speed check
|
name: unit test speed check
|
||||||
entry: .venv/bin/python -m devx.tools.check_test_speed --max-seconds 6 --max-single-seconds 0.5
|
entry: .venv/bin/python -m devx.tools.check_test_speed --max-seconds 15 --max-single-seconds 0.5
|
||||||
language: system
|
language: system
|
||||||
types: [python]
|
types: [python]
|
||||||
pass_filenames: false
|
pass_filenames: false
|
||||||
|
|||||||
@@ -1,9 +0,0 @@
|
|||||||
extends: existence
|
|
||||||
message: "Use 'AM' or 'PM' (preceded by a space)."
|
|
||||||
link: "https://developers.google.com/style/word-list"
|
|
||||||
level: error
|
|
||||||
nonword: true
|
|
||||||
tokens:
|
|
||||||
- '\d{1,2}[AP]M\b'
|
|
||||||
- '\d{1,2} ?[ap]m\b'
|
|
||||||
- '\d{1,2} ?[aApP]\.[mM]\.'
|
|
||||||
@@ -1,64 +0,0 @@
|
|||||||
extends: conditional
|
|
||||||
message: "Spell out '%s', if it's unfamiliar to the audience."
|
|
||||||
link: 'https://developers.google.com/style/abbreviations'
|
|
||||||
level: suggestion
|
|
||||||
ignorecase: false
|
|
||||||
# Ensures that the existence of 'first' implies the existence of 'second'.
|
|
||||||
first: '\b([A-Z]{3,5})\b'
|
|
||||||
second: '(?:\b[A-Z][a-z]+ )+\(([A-Z]{3,5})\)'
|
|
||||||
# ... with the exception of these:
|
|
||||||
exceptions:
|
|
||||||
- API
|
|
||||||
- ASP
|
|
||||||
- CLI
|
|
||||||
- CPU
|
|
||||||
- CSS
|
|
||||||
- CSV
|
|
||||||
- DEBUG
|
|
||||||
- DOM
|
|
||||||
- DPI
|
|
||||||
- FAQ
|
|
||||||
- GCC
|
|
||||||
- GDB
|
|
||||||
- GET
|
|
||||||
- GPU
|
|
||||||
- GTK
|
|
||||||
- GUI
|
|
||||||
- HTML
|
|
||||||
- HTTP
|
|
||||||
- HTTPS
|
|
||||||
- IDE
|
|
||||||
- JAR
|
|
||||||
- JSON
|
|
||||||
- JSX
|
|
||||||
- LESS
|
|
||||||
- LLDB
|
|
||||||
- NET
|
|
||||||
- NOTE
|
|
||||||
- NVDA
|
|
||||||
- OSS
|
|
||||||
- PATH
|
|
||||||
- PDF
|
|
||||||
- PHP
|
|
||||||
- POST
|
|
||||||
- RAM
|
|
||||||
- REPL
|
|
||||||
- RSA
|
|
||||||
- SCM
|
|
||||||
- SCSS
|
|
||||||
- SDK
|
|
||||||
- SQL
|
|
||||||
- SSH
|
|
||||||
- SSL
|
|
||||||
- SVG
|
|
||||||
- TBD
|
|
||||||
- TCP
|
|
||||||
- TODO
|
|
||||||
- URI
|
|
||||||
- URL
|
|
||||||
- USB
|
|
||||||
- UTF
|
|
||||||
- XML
|
|
||||||
- XSS
|
|
||||||
- YAML
|
|
||||||
- ZIP
|
|
||||||
@@ -1,8 +0,0 @@
|
|||||||
extends: existence
|
|
||||||
message: "'%s' should be in lowercase."
|
|
||||||
link: 'https://developers.google.com/style/colons'
|
|
||||||
nonword: true
|
|
||||||
level: warning
|
|
||||||
scope: sentence
|
|
||||||
tokens:
|
|
||||||
- '(?<!:[^ ]+?):\s[A-Z]'
|
|
||||||
@@ -1,30 +0,0 @@
|
|||||||
extends: substitution
|
|
||||||
message: "Use '%s' instead of '%s'."
|
|
||||||
link: 'https://developers.google.com/style/contractions'
|
|
||||||
level: suggestion
|
|
||||||
ignorecase: true
|
|
||||||
action:
|
|
||||||
name: replace
|
|
||||||
swap:
|
|
||||||
are not: aren't
|
|
||||||
cannot: can't
|
|
||||||
could not: couldn't
|
|
||||||
did not: didn't
|
|
||||||
do not: don't
|
|
||||||
does not: doesn't
|
|
||||||
has not: hasn't
|
|
||||||
have not: haven't
|
|
||||||
how is: how's
|
|
||||||
is not: isn't
|
|
||||||
it is: it's
|
|
||||||
should not: shouldn't
|
|
||||||
that is: that's
|
|
||||||
they are: they're
|
|
||||||
was not: wasn't
|
|
||||||
we are: we're
|
|
||||||
we have: we've
|
|
||||||
were not: weren't
|
|
||||||
what is: what's
|
|
||||||
when is: when's
|
|
||||||
where is: where's
|
|
||||||
will not: won't
|
|
||||||
@@ -1,9 +0,0 @@
|
|||||||
extends: existence
|
|
||||||
message: "Use 'July 31, 2016' format, not '%s'."
|
|
||||||
link: 'https://developers.google.com/style/dates-times'
|
|
||||||
ignorecase: true
|
|
||||||
level: error
|
|
||||||
nonword: true
|
|
||||||
tokens:
|
|
||||||
- '\d{1,2}(?:\.|/)\d{1,2}(?:\.|/)\d{4}'
|
|
||||||
- '\d{1,2} (?:Jan(?:uary)?|Feb(?:ruary)?|Mar(?:ch)?|Apr(?:il)|May|Jun(?:e)|Jul(?:y)|Aug(?:ust)|Sep(?:tember)?|Oct(?:ober)|Nov(?:ember)?|Dec(?:ember)?) \d{4}'
|
|
||||||
@@ -1,9 +0,0 @@
|
|||||||
extends: existence
|
|
||||||
message: "In general, don't use an ellipsis."
|
|
||||||
link: 'https://developers.google.com/style/ellipses'
|
|
||||||
nonword: true
|
|
||||||
level: warning
|
|
||||||
action:
|
|
||||||
name: remove
|
|
||||||
tokens:
|
|
||||||
- '\.\.\.'
|
|
||||||
@@ -1,13 +0,0 @@
|
|||||||
extends: existence
|
|
||||||
message: "Don't put a space before or after a dash."
|
|
||||||
link: "https://developers.google.com/style/dashes"
|
|
||||||
nonword: true
|
|
||||||
level: error
|
|
||||||
action:
|
|
||||||
name: edit
|
|
||||||
params:
|
|
||||||
- trim
|
|
||||||
- " "
|
|
||||||
tokens:
|
|
||||||
- '\s[—–]\s'
|
|
||||||
|
|
||||||
@@ -1,12 +0,0 @@
|
|||||||
extends: existence
|
|
||||||
message: "Don't use exclamation points in text."
|
|
||||||
link: "https://developers.google.com/style/exclamation-points"
|
|
||||||
nonword: true
|
|
||||||
level: error
|
|
||||||
action:
|
|
||||||
name: edit
|
|
||||||
params:
|
|
||||||
- trim_right
|
|
||||||
- "!"
|
|
||||||
tokens:
|
|
||||||
- '\w+!(?:\s|$)'
|
|
||||||
@@ -1,13 +0,0 @@
|
|||||||
extends: existence
|
|
||||||
message: "Avoid first-person pronouns such as '%s'."
|
|
||||||
link: 'https://developers.google.com/style/pronouns#personal-pronouns'
|
|
||||||
ignorecase: true
|
|
||||||
level: warning
|
|
||||||
nonword: true
|
|
||||||
tokens:
|
|
||||||
- (?:^|\s)I\s
|
|
||||||
- (?:^|\s)I,\s
|
|
||||||
- \bI'm\b
|
|
||||||
- \bme\b
|
|
||||||
- \bmy\b
|
|
||||||
- \bmine\b
|
|
||||||
@@ -1,9 +0,0 @@
|
|||||||
extends: existence
|
|
||||||
message: "Don't use '%s' as a gender-neutral pronoun."
|
|
||||||
link: 'https://developers.google.com/style/pronouns#gender-neutral-pronouns'
|
|
||||||
level: error
|
|
||||||
ignorecase: true
|
|
||||||
tokens:
|
|
||||||
- he/she
|
|
||||||
- s/he
|
|
||||||
- \(s\)he
|
|
||||||
@@ -1,43 +0,0 @@
|
|||||||
extends: substitution
|
|
||||||
message: "Consider using '%s' instead of '%s'."
|
|
||||||
ignorecase: true
|
|
||||||
link: "https://developers.google.com/style/inclusive-documentation"
|
|
||||||
level: error
|
|
||||||
action:
|
|
||||||
name: replace
|
|
||||||
swap:
|
|
||||||
(?:alumna|alumnus): graduate
|
|
||||||
(?:alumnae|alumni): graduates
|
|
||||||
air(?:m[ae]n|wom[ae]n): pilot(s)
|
|
||||||
anchor(?:m[ae]n|wom[ae]n): anchor(s)
|
|
||||||
authoress: author
|
|
||||||
camera(?:m[ae]n|wom[ae]n): camera operator(s)
|
|
||||||
door(?:m[ae]|wom[ae]n): concierge(s)
|
|
||||||
draft(?:m[ae]n|wom[ae]n): drafter(s)
|
|
||||||
fire(?:m[ae]n|wom[ae]n): firefighter(s)
|
|
||||||
fisher(?:m[ae]n|wom[ae]n): fisher(s)
|
|
||||||
fresh(?:m[ae]n|wom[ae]n): first-year student(s)
|
|
||||||
garbage(?:m[ae]n|wom[ae]n): waste collector(s)
|
|
||||||
lady lawyer: lawyer
|
|
||||||
ladylike: courteous
|
|
||||||
mail(?:m[ae]n|wom[ae]n): mail carriers
|
|
||||||
man and wife: husband and wife
|
|
||||||
man enough: strong enough
|
|
||||||
mankind: human kind|humanity
|
|
||||||
manmade: manufactured
|
|
||||||
manpower: personnel
|
|
||||||
middle(?:m[ae]n|wom[ae]n): intermediary
|
|
||||||
news(?:m[ae]n|wom[ae]n): journalist(s)
|
|
||||||
ombuds(?:man|woman): ombuds
|
|
||||||
oneupmanship: upstaging
|
|
||||||
poetess: poet
|
|
||||||
police(?:m[ae]n|wom[ae]n): police officer(s)
|
|
||||||
repair(?:m[ae]n|wom[ae]n): technician(s)
|
|
||||||
sales(?:m[ae]n|wom[ae]n): salesperson or sales people
|
|
||||||
service(?:m[ae]n|wom[ae]n): soldier(s)
|
|
||||||
steward(?:ess)?: flight attendant
|
|
||||||
tribes(?:m[ae]n|wom[ae]n): tribe member(s)
|
|
||||||
waitress: waiter
|
|
||||||
woman doctor: doctor
|
|
||||||
woman scientist[s]?: scientist(s)
|
|
||||||
work(?:m[ae]n|wom[ae]n): worker(s)
|
|
||||||
@@ -1,13 +0,0 @@
|
|||||||
extends: existence
|
|
||||||
message: "Don't put a period at the end of a heading."
|
|
||||||
link: "https://developers.google.com/style/capitalization#capitalization-in-titles-and-headings"
|
|
||||||
nonword: true
|
|
||||||
level: warning
|
|
||||||
scope: heading
|
|
||||||
action:
|
|
||||||
name: edit
|
|
||||||
params:
|
|
||||||
- trim_right
|
|
||||||
- "."
|
|
||||||
tokens:
|
|
||||||
- '[a-z0-9][.]\s*$'
|
|
||||||
@@ -1,29 +0,0 @@
|
|||||||
extends: capitalization
|
|
||||||
message: "'%s' should use sentence-style capitalization."
|
|
||||||
link: "https://developers.google.com/style/capitalization#capitalization-in-titles-and-headings"
|
|
||||||
level: warning
|
|
||||||
scope: heading
|
|
||||||
match: $sentence
|
|
||||||
indicators:
|
|
||||||
- ":"
|
|
||||||
exceptions:
|
|
||||||
- Azure
|
|
||||||
- CLI
|
|
||||||
- Cosmos
|
|
||||||
- Docker
|
|
||||||
- Emmet
|
|
||||||
- gRPC
|
|
||||||
- I
|
|
||||||
- Kubernetes
|
|
||||||
- Linux
|
|
||||||
- macOS
|
|
||||||
- Marketplace
|
|
||||||
- MongoDB
|
|
||||||
- REPL
|
|
||||||
- Studio
|
|
||||||
- TypeScript
|
|
||||||
- URLs
|
|
||||||
- Visual
|
|
||||||
- VS
|
|
||||||
- Windows
|
|
||||||
- JSON
|
|
||||||
@@ -1,11 +0,0 @@
|
|||||||
extends: substitution
|
|
||||||
message: "Use '%s' instead of '%s'."
|
|
||||||
link: 'https://developers.google.com/style/abbreviations'
|
|
||||||
ignorecase: true
|
|
||||||
level: error
|
|
||||||
nonword: true
|
|
||||||
action:
|
|
||||||
name: replace
|
|
||||||
swap:
|
|
||||||
'\b(?:eg|e\.g\.)(?=[\s,;])': for example
|
|
||||||
'\b(?:ie|i\.e\.)(?=[\s,;])': that is
|
|
||||||
@@ -1,14 +0,0 @@
|
|||||||
extends: existence
|
|
||||||
message: "'%s' doesn't need a hyphen."
|
|
||||||
link: "https://developers.google.com/style/hyphens"
|
|
||||||
level: error
|
|
||||||
ignorecase: false
|
|
||||||
nonword: true
|
|
||||||
action:
|
|
||||||
name: edit
|
|
||||||
params:
|
|
||||||
- regex
|
|
||||||
- "-"
|
|
||||||
- " "
|
|
||||||
tokens:
|
|
||||||
- '\b[^\s-]+ly-\w+\b'
|
|
||||||
@@ -1,12 +0,0 @@
|
|||||||
extends: existence
|
|
||||||
message: "Don't use plurals in parentheses such as in '%s'."
|
|
||||||
link: "https://developers.google.com/style/plurals-parentheses"
|
|
||||||
level: error
|
|
||||||
nonword: true
|
|
||||||
action:
|
|
||||||
name: edit
|
|
||||||
params:
|
|
||||||
- trim_right
|
|
||||||
- "(s)"
|
|
||||||
tokens:
|
|
||||||
- '\b\w+\(s\)'
|
|
||||||
@@ -1,7 +0,0 @@
|
|||||||
extends: existence
|
|
||||||
message: "Spell out all ordinal numbers ('%s') in text."
|
|
||||||
link: 'https://developers.google.com/style/numbers'
|
|
||||||
level: error
|
|
||||||
nonword: true
|
|
||||||
tokens:
|
|
||||||
- \d+(?:st|nd|rd|th)
|
|
||||||
@@ -1,7 +0,0 @@
|
|||||||
extends: existence
|
|
||||||
message: "Use the Oxford comma in '%s'."
|
|
||||||
link: 'https://developers.google.com/style/commas'
|
|
||||||
scope: sentence
|
|
||||||
level: warning
|
|
||||||
tokens:
|
|
||||||
- '(?:[^,]+,){1,}\s\w+\s(?:and|or)'
|
|
||||||
@@ -1,7 +0,0 @@
|
|||||||
extends: existence
|
|
||||||
message: "Use parentheses judiciously."
|
|
||||||
link: 'https://developers.google.com/style/parentheses'
|
|
||||||
nonword: true
|
|
||||||
level: suggestion
|
|
||||||
tokens:
|
|
||||||
- '\(.+\)'
|
|
||||||
@@ -1,184 +0,0 @@
|
|||||||
extends: existence
|
|
||||||
link: 'https://developers.google.com/style/voice'
|
|
||||||
message: "In general, use active voice instead of passive voice ('%s')."
|
|
||||||
ignorecase: true
|
|
||||||
level: suggestion
|
|
||||||
raw:
|
|
||||||
- \b(am|are|were|being|is|been|was|be)\b\s*
|
|
||||||
tokens:
|
|
||||||
- '[\w]+ed'
|
|
||||||
- awoken
|
|
||||||
- beat
|
|
||||||
- become
|
|
||||||
- been
|
|
||||||
- begun
|
|
||||||
- bent
|
|
||||||
- beset
|
|
||||||
- bet
|
|
||||||
- bid
|
|
||||||
- bidden
|
|
||||||
- bitten
|
|
||||||
- bled
|
|
||||||
- blown
|
|
||||||
- born
|
|
||||||
- bought
|
|
||||||
- bound
|
|
||||||
- bred
|
|
||||||
- broadcast
|
|
||||||
- broken
|
|
||||||
- brought
|
|
||||||
- built
|
|
||||||
- burnt
|
|
||||||
- burst
|
|
||||||
- cast
|
|
||||||
- caught
|
|
||||||
- chosen
|
|
||||||
- clung
|
|
||||||
- come
|
|
||||||
- cost
|
|
||||||
- crept
|
|
||||||
- cut
|
|
||||||
- dealt
|
|
||||||
- dived
|
|
||||||
- done
|
|
||||||
- drawn
|
|
||||||
- dreamt
|
|
||||||
- driven
|
|
||||||
- drunk
|
|
||||||
- dug
|
|
||||||
- eaten
|
|
||||||
- fallen
|
|
||||||
- fed
|
|
||||||
- felt
|
|
||||||
- fit
|
|
||||||
- fled
|
|
||||||
- flown
|
|
||||||
- flung
|
|
||||||
- forbidden
|
|
||||||
- foregone
|
|
||||||
- forgiven
|
|
||||||
- forgotten
|
|
||||||
- forsaken
|
|
||||||
- fought
|
|
||||||
- found
|
|
||||||
- frozen
|
|
||||||
- given
|
|
||||||
- gone
|
|
||||||
- gotten
|
|
||||||
- ground
|
|
||||||
- grown
|
|
||||||
- heard
|
|
||||||
- held
|
|
||||||
- hidden
|
|
||||||
- hit
|
|
||||||
- hung
|
|
||||||
- hurt
|
|
||||||
- kept
|
|
||||||
- knelt
|
|
||||||
- knit
|
|
||||||
- known
|
|
||||||
- laid
|
|
||||||
- lain
|
|
||||||
- leapt
|
|
||||||
- learnt
|
|
||||||
- led
|
|
||||||
- left
|
|
||||||
- lent
|
|
||||||
- let
|
|
||||||
- lighted
|
|
||||||
- lost
|
|
||||||
- made
|
|
||||||
- meant
|
|
||||||
- met
|
|
||||||
- misspelt
|
|
||||||
- mistaken
|
|
||||||
- mown
|
|
||||||
- overcome
|
|
||||||
- overdone
|
|
||||||
- overtaken
|
|
||||||
- overthrown
|
|
||||||
- paid
|
|
||||||
- pled
|
|
||||||
- proven
|
|
||||||
- put
|
|
||||||
- quit
|
|
||||||
- read
|
|
||||||
- rid
|
|
||||||
- ridden
|
|
||||||
- risen
|
|
||||||
- run
|
|
||||||
- rung
|
|
||||||
- said
|
|
||||||
- sat
|
|
||||||
- sawn
|
|
||||||
- seen
|
|
||||||
- sent
|
|
||||||
- set
|
|
||||||
- sewn
|
|
||||||
- shaken
|
|
||||||
- shaven
|
|
||||||
- shed
|
|
||||||
- shod
|
|
||||||
- shone
|
|
||||||
- shorn
|
|
||||||
- shot
|
|
||||||
- shown
|
|
||||||
- shrunk
|
|
||||||
- shut
|
|
||||||
- slain
|
|
||||||
- slept
|
|
||||||
- slid
|
|
||||||
- slit
|
|
||||||
- slung
|
|
||||||
- smitten
|
|
||||||
- sold
|
|
||||||
- sought
|
|
||||||
- sown
|
|
||||||
- sped
|
|
||||||
- spent
|
|
||||||
- spilt
|
|
||||||
- spit
|
|
||||||
- split
|
|
||||||
- spoken
|
|
||||||
- spread
|
|
||||||
- sprung
|
|
||||||
- spun
|
|
||||||
- stolen
|
|
||||||
- stood
|
|
||||||
- stridden
|
|
||||||
- striven
|
|
||||||
- struck
|
|
||||||
- strung
|
|
||||||
- stuck
|
|
||||||
- stung
|
|
||||||
- stunk
|
|
||||||
- sung
|
|
||||||
- sunk
|
|
||||||
- swept
|
|
||||||
- swollen
|
|
||||||
- sworn
|
|
||||||
- swum
|
|
||||||
- swung
|
|
||||||
- taken
|
|
||||||
- taught
|
|
||||||
- thought
|
|
||||||
- thrived
|
|
||||||
- thrown
|
|
||||||
- thrust
|
|
||||||
- told
|
|
||||||
- torn
|
|
||||||
- trodden
|
|
||||||
- understood
|
|
||||||
- upheld
|
|
||||||
- upset
|
|
||||||
- wed
|
|
||||||
- wept
|
|
||||||
- withheld
|
|
||||||
- withstood
|
|
||||||
- woken
|
|
||||||
- won
|
|
||||||
- worn
|
|
||||||
- wound
|
|
||||||
- woven
|
|
||||||
- written
|
|
||||||
- wrung
|
|
||||||
@@ -1,7 +0,0 @@
|
|||||||
extends: existence
|
|
||||||
message: "Don't use periods with acronyms or initialisms such as '%s'."
|
|
||||||
link: 'https://developers.google.com/style/abbreviations'
|
|
||||||
level: error
|
|
||||||
nonword: true
|
|
||||||
tokens:
|
|
||||||
- '\b(?:[A-Z]\.){3,}'
|
|
||||||
@@ -1,7 +0,0 @@
|
|||||||
extends: existence
|
|
||||||
message: "Commas and periods go inside quotation marks."
|
|
||||||
link: 'https://developers.google.com/style/quotation-marks'
|
|
||||||
level: error
|
|
||||||
nonword: true
|
|
||||||
tokens:
|
|
||||||
- '"[^"]+"[.,?]'
|
|
||||||
@@ -1,7 +0,0 @@
|
|||||||
extends: existence
|
|
||||||
message: "Don't add words such as 'from' or 'between' to describe a range of numbers."
|
|
||||||
link: 'https://developers.google.com/style/hyphens'
|
|
||||||
nonword: true
|
|
||||||
level: warning
|
|
||||||
tokens:
|
|
||||||
- '(?:from|between)\s\d+\s?-\s?\d+'
|
|
||||||
@@ -1,8 +0,0 @@
|
|||||||
extends: existence
|
|
||||||
message: "Use semicolons judiciously."
|
|
||||||
link: 'https://developers.google.com/style/semicolons'
|
|
||||||
nonword: true
|
|
||||||
scope: sentence
|
|
||||||
level: suggestion
|
|
||||||
tokens:
|
|
||||||
- ';'
|
|
||||||
@@ -1,11 +0,0 @@
|
|||||||
extends: existence
|
|
||||||
message: "Don't use internet slang abbreviations such as '%s'."
|
|
||||||
link: 'https://developers.google.com/style/abbreviations'
|
|
||||||
ignorecase: true
|
|
||||||
level: error
|
|
||||||
tokens:
|
|
||||||
- 'tl;dr'
|
|
||||||
- ymmv
|
|
||||||
- rtfm
|
|
||||||
- imo
|
|
||||||
- fwiw
|
|
||||||
@@ -1,10 +0,0 @@
|
|||||||
extends: existence
|
|
||||||
message: "'%s' should have one space."
|
|
||||||
link: 'https://developers.google.com/style/sentence-spacing'
|
|
||||||
level: error
|
|
||||||
nonword: true
|
|
||||||
action:
|
|
||||||
name: remove
|
|
||||||
tokens:
|
|
||||||
- '[a-z][.?!] {2,}[A-Z]'
|
|
||||||
- '[a-z][.?!][A-Z]'
|
|
||||||
@@ -1,10 +0,0 @@
|
|||||||
extends: existence
|
|
||||||
message: "In general, use American spelling instead of '%s'."
|
|
||||||
link: 'https://developers.google.com/style/spelling'
|
|
||||||
ignorecase: true
|
|
||||||
level: warning
|
|
||||||
tokens:
|
|
||||||
- '(?:\w+)nised?'
|
|
||||||
- 'colour'
|
|
||||||
- 'labour'
|
|
||||||
- 'centre'
|
|
||||||
@@ -1,8 +0,0 @@
|
|||||||
extends: existence
|
|
||||||
message: "Put a nonbreaking space between the number and the unit in '%s'."
|
|
||||||
link: "https://developers.google.com/style/units-of-measure"
|
|
||||||
nonword: true
|
|
||||||
level: error
|
|
||||||
tokens:
|
|
||||||
- \b\d+(?:B|kB|MB|GB|TB)
|
|
||||||
- \b\d+(?:ns|ms|s|min|h|d)
|
|
||||||
@@ -1,11 +0,0 @@
|
|||||||
extends: existence
|
|
||||||
message: "Try to avoid using first-person plural like '%s'."
|
|
||||||
link: 'https://developers.google.com/style/pronouns#personal-pronouns'
|
|
||||||
level: warning
|
|
||||||
ignorecase: true
|
|
||||||
tokens:
|
|
||||||
- we
|
|
||||||
- we'(?:ve|re)
|
|
||||||
- ours?
|
|
||||||
- us
|
|
||||||
- let's
|
|
||||||
@@ -1,7 +0,0 @@
|
|||||||
extends: existence
|
|
||||||
message: "Avoid using '%s'."
|
|
||||||
link: 'https://developers.google.com/style/tense'
|
|
||||||
ignorecase: true
|
|
||||||
level: warning
|
|
||||||
tokens:
|
|
||||||
- will
|
|
||||||
@@ -1,80 +0,0 @@
|
|||||||
extends: substitution
|
|
||||||
message: "Use '%s' instead of '%s'."
|
|
||||||
link: "https://developers.google.com/style/word-list"
|
|
||||||
level: warning
|
|
||||||
ignorecase: false
|
|
||||||
action:
|
|
||||||
name: replace
|
|
||||||
swap:
|
|
||||||
"(?:API Console|dev|developer) key": API key
|
|
||||||
"(?:cell ?phone|smart ?phone)": phone|mobile phone
|
|
||||||
"(?:dev|developer|APIs) console": API console
|
|
||||||
"(?:e-mail|Email|E-mail)": email
|
|
||||||
"(?:file ?path|path ?name)": path
|
|
||||||
"(?:kill|terminate|abort)": stop|exit|cancel|end
|
|
||||||
"(?:OAuth ?2|Oauth)": OAuth 2.0
|
|
||||||
"(?:ok|Okay)": OK|okay
|
|
||||||
"(?:WiFi|wifi)": Wi-Fi
|
|
||||||
'[\.]+apk': APK
|
|
||||||
'3\-D': 3D
|
|
||||||
'Google (?:I\-O|IO)': Google I/O
|
|
||||||
"tap (?:&|and) hold": touch & hold
|
|
||||||
"un(?:check|select)": clear
|
|
||||||
above: preceding
|
|
||||||
account name: username
|
|
||||||
action bar: app bar
|
|
||||||
admin: administrator
|
|
||||||
Ajax: AJAX
|
|
||||||
a\.k\.a|aka: or|also known as
|
|
||||||
Android device: Android-powered device
|
|
||||||
android: Android
|
|
||||||
API explorer: APIs Explorer
|
|
||||||
application: app
|
|
||||||
approx\.: approximately
|
|
||||||
authN: authentication
|
|
||||||
authZ: authorization
|
|
||||||
autoupdate: automatically update
|
|
||||||
cellular data: mobile data
|
|
||||||
cellular network: mobile network
|
|
||||||
chapter: documents|pages|sections
|
|
||||||
check box: checkbox
|
|
||||||
CLI: command-line tool
|
|
||||||
click on: click|click in
|
|
||||||
Cloud: Google Cloud Platform|GCP
|
|
||||||
Container Engine: Kubernetes Engine
|
|
||||||
content type: media type
|
|
||||||
curated roles: predefined roles
|
|
||||||
data are: data is
|
|
||||||
Developers Console: Google API Console|API Console
|
|
||||||
disabled?: turn off|off
|
|
||||||
ephemeral IP address: ephemeral external IP address
|
|
||||||
fewer data: less data
|
|
||||||
file name: filename
|
|
||||||
firewalls: firewall rules
|
|
||||||
functionality: capability|feature
|
|
||||||
Google account: Google Account
|
|
||||||
Google accounts: Google Accounts
|
|
||||||
Googling: search with Google
|
|
||||||
grayed-out: unavailable
|
|
||||||
HTTPs: HTTPS
|
|
||||||
in order to: to
|
|
||||||
ingest: import|load
|
|
||||||
k8s: Kubernetes
|
|
||||||
long press: touch & hold
|
|
||||||
network IP address: internal IP address
|
|
||||||
omnibox: address bar
|
|
||||||
open-source: open source
|
|
||||||
overview screen: recents screen
|
|
||||||
regex: regular expression
|
|
||||||
SHA1: SHA-1|HAS-SHA1
|
|
||||||
sign into: sign in to
|
|
||||||
sign-?on: single sign-on
|
|
||||||
static IP address: static external IP address
|
|
||||||
stylesheet: style sheet
|
|
||||||
synch: sync
|
|
||||||
tablename: table name
|
|
||||||
tablet: device
|
|
||||||
touch: tap
|
|
||||||
url: URL
|
|
||||||
vs\.: versus
|
|
||||||
World Wide Web: web
|
|
||||||
@@ -1,4 +0,0 @@
|
|||||||
{
|
|
||||||
"feed": "https://github.com/errata-ai/Google/releases.atom",
|
|
||||||
"vale_version": ">=1.0.0"
|
|
||||||
}
|
|
||||||
@@ -28,6 +28,11 @@ make workflow-check # workflow-lint + workflow-dryrun
|
|||||||
make devx-check-doc-versions # Verify docs version refs match __version__
|
make devx-check-doc-versions # Verify docs version refs match __version__
|
||||||
make devx-vale # Run Vale prose linter on docs and README
|
make devx-vale # Run Vale prose linter on docs and README
|
||||||
make clean # Remove caches, build artifacts, coverage data
|
make clean # Remove caches, build artifacts, coverage data
|
||||||
|
make check-workflow-artifact-deps # Verify artifact download jobs depend on upload jobs
|
||||||
|
make check-workflow-tofu-init # Verify tofu-state jobs have a tofu-init step
|
||||||
|
make check-docker-init # Check Docker Compose services with healthchecks have init: true
|
||||||
|
make check-ansible-set-fact-to-json # Check set_fact tasks don't misuse to_json
|
||||||
|
make check-alert-rules # Validate Prometheus alert rules with promtool
|
||||||
```
|
```
|
||||||
|
|
||||||
`make setup` automatically installs all development tools:
|
`make setup` automatically installs all development tools:
|
||||||
@@ -71,7 +76,7 @@ src/devx/
|
|||||||
├── translations.json # Translation strings (en, bg, de, pl, ru, zh)
|
├── translations.json # Translation strings (en, bg, de, pl, ru, zh)
|
||||||
├── ci/ # CI/CD automation modules (run by workflows)
|
├── ci/ # CI/CD automation modules (run by workflows)
|
||||||
│ ├── release.py # Automated versioning, tagging, changelog
|
│ ├── release.py # Automated versioning, tagging, changelog
|
||||||
│ ├── publish.py # Build and publish to Gitea PyPI registry (--skip-build for non-Python repos)
|
│ ├── publish.py # Build, publish to Gitea PyPI registry, create Gitea release (with retry)
|
||||||
│ ├── auto_merge.py # Squash-merge PRs with task ID validation
|
│ ├── auto_merge.py # Squash-merge PRs with task ID validation
|
||||||
│ ├── check_auto_merge_ready.py # Pre-merge validation gate (branch, PR title, Vikunja, behind-master)
|
│ ├── check_auto_merge_ready.py # Pre-merge validation gate (branch, PR title, Vikunja, behind-master)
|
||||||
│ ├── _shared.py # Shared utilities (get_latest_tag)
|
│ ├── _shared.py # Shared utilities (get_latest_tag)
|
||||||
@@ -90,7 +95,10 @@ src/devx/
|
|||||||
│ ├── doc_coverage.py # Documentation coverage check
|
│ ├── doc_coverage.py # Documentation coverage check
|
||||||
│ ├── lint_docs.py # Documentation linter (structure, links, headings, code blocks, orphans)
|
│ ├── lint_docs.py # Documentation linter (structure, links, headings, code blocks, orphans)
|
||||||
│ ├── validate_deploy_ref.py # Validate git tag for deployments (--github-output)
|
│ ├── validate_deploy_ref.py # Validate git tag for deployments (--github-output)
|
||||||
│ └── record_deployed_tag.py # Record deployed tag to Gitea repo variable
|
│ ├── record_deployed_tag.py # Record deployed tag to Gitea repo variable
|
||||||
|
│ ├── cancel_superseded_runs.py # Cancel in-flight CI runs for the same PR branch
|
||||||
|
│ ├── check_workflow_artifact_deps.py # Verify artifact download jobs depend on upload jobs
|
||||||
|
│ └── check_workflow_tofu_init.py # Verify tofu-state jobs have a tofu-init step
|
||||||
├── tools/ # Developer tooling modules (run locally or by CI)
|
├── tools/ # Developer tooling modules (run locally or by CI)
|
||||||
│ ├── setup.py # Environment setup (venv, deps, hooks)
|
│ ├── setup.py # Environment setup (venv, deps, hooks)
|
||||||
│ ├── install_tools.py # Install actionlint, git-cliff, act_runner, tea, hadolint, vale
|
│ ├── install_tools.py # Install actionlint, git-cliff, act_runner, tea, hadolint, vale
|
||||||
@@ -113,10 +121,13 @@ src/devx/
|
|||||||
│ ├── pr_logs.py # Fetch logs for failed CI jobs
|
│ ├── pr_logs.py # Fetch logs for failed CI jobs
|
||||||
│ ├── pr_label.py # Add labels to PRs (idempotent)
|
│ ├── pr_label.py # Add labels to PRs (idempotent)
|
||||||
│ ├── pre_push_check.py # Validate Vikunja task existence before push
|
│ ├── pre_push_check.py # Validate Vikunja task existence before push
|
||||||
|
│ ├── check_docker_init.py # Check Docker Compose services with healthchecks have init: true
|
||||||
|
│ ├── check_ansible_set_fact_to_json.py # Check set_fact tasks don't misuse to_json
|
||||||
|
│ ├── check_alert_rules.py # Validate Prometheus alert rules with promtool
|
||||||
│ └── _shared.py # Shared tool utilities
|
│ └── _shared.py # Shared tool utilities
|
||||||
├── opentofu.py # OpenTofu output helpers (get_tofu_output, get_tofu_vm_ip, get_tofu_vm_field)
|
├── opentofu.py # OpenTofu output helpers (get_tofu_output, get_tofu_vm_ip, get_tofu_vm_field)
|
||||||
├── utils/ # Shared utilities (reusable across projects)
|
├── utils/ # Shared utilities (reusable across projects)
|
||||||
│ ├── api.py # API response helpers (is_truthy, is_falsy)
|
│ ├── api.py # API response helpers (is_truthy, is_falsy) + APIClient base class
|
||||||
│ ├── ssh.py # SSH exec + wait_for_ssh (pure-Python socket check)
|
│ ├── ssh.py # SSH exec + wait_for_ssh (pure-Python socket check)
|
||||||
│ ├── crypto.py # Secret generation (shell-safe passwords)
|
│ ├── crypto.py # Secret generation (shell-safe passwords)
|
||||||
│ ├── vault.py # Ansible vault encrypt/decrypt helpers
|
│ ├── vault.py # Ansible vault encrypt/decrypt helpers
|
||||||
@@ -124,7 +135,9 @@ src/devx/
|
|||||||
│ ├── confirm.py # Typed confirmation validation for destructive ops
|
│ ├── confirm.py # Typed confirmation validation for destructive ops
|
||||||
│ ├── json_registry.py # File-locked JSON registry for local state
|
│ ├── json_registry.py # File-locked JSON registry for local state
|
||||||
│ ├── step_tracker.py # Multi-step operation tracking with reports
|
│ ├── step_tracker.py # Multi-step operation tracking with reports
|
||||||
│ └── logging.py # XDG-compliant logging configuration
|
│ ├── logging.py # XDG-compliant logging configuration
|
||||||
|
│ ├── ui.py # say() — unified click.echo + logging output
|
||||||
|
│ └── jinja.py # Jinja2 environment helpers + Ansible-compatible filters
|
||||||
└── molecule/ # Optional molecule testing helpers (for Ansible projects)
|
└── molecule/ # Optional molecule testing helpers (for Ansible projects)
|
||||||
├── discover_runners.py # Dynamic Gitea runner discovery
|
├── discover_runners.py # Dynamic Gitea runner discovery
|
||||||
├── distribute_molecule.py # Distribute molecule scenarios across runners (LPT scheduling, --roles-root for multi-role)
|
├── distribute_molecule.py # Distribute molecule scenarios across runners (LPT scheduling, --roles-root for multi-role)
|
||||||
@@ -310,6 +323,20 @@ by `python -m devx.tools.install_tools` and configured by
|
|||||||
- `create_pr()` / `merge_pr()` / `review_pr()` — Pull request operations
|
- `create_pr()` / `merge_pr()` / `review_pr()` — Pull request operations
|
||||||
- `create_release()` / `list_releases()` — Release management
|
- `create_release()` / `list_releases()` — Release management
|
||||||
|
|
||||||
|
**`devx.gitea_cli.configure_tea_login()`** — Configures tea login in
|
||||||
|
containerized CI environments where `make setup` was not called. Used by
|
||||||
|
`publish.py` (`--auto-login`) and `notify_failure.py` (`--auto-login`).
|
||||||
|
Raises `TeaCLIError` if login configuration fails — this prevents cryptic
|
||||||
|
"no available login" errors from subsequent tea commands.
|
||||||
|
|
||||||
|
**Error handling**: `TeaCLI._run()` includes both stdout and stderr in
|
||||||
|
`TeaCLIError` messages, because `tea` writes some errors (for example,
|
||||||
|
"no available login") to stdout, not stderr.
|
||||||
|
|
||||||
|
**Release creation retry**: `publish.py` retries Gitea release creation
|
||||||
|
up to 3 times with exponential backoff (2s, 4s) on transient failures.
|
||||||
|
"Already exists" errors are treated as success (idempotent).
|
||||||
|
|
||||||
### git-cliff Commit Preprocessing
|
### git-cliff Commit Preprocessing
|
||||||
|
|
||||||
Merge commits on master have the format `DEVX-N: <conventional commit>`. The
|
Merge commits on master have the format `DEVX-N: <conventional commit>`. The
|
||||||
|
|||||||
+134
@@ -2,6 +2,140 @@
|
|||||||
|
|
||||||
All notable changes to this project will be documented in this file.
|
All notable changes to this project will be documented in this file.
|
||||||
|
|
||||||
|
## [0.49.5] - 2026-08-07
|
||||||
|
|
||||||
|
### Performance
|
||||||
|
|
||||||
|
- Skip dep resolution in setup-image with --no-deps
|
||||||
|
|
||||||
|
## [0.49.4] - 2026-08-07
|
||||||
|
|
||||||
|
### Bug Fixes
|
||||||
|
|
||||||
|
- Add container.credentials for private registry auth
|
||||||
|
|
||||||
|
## [0.49.3] - 2026-08-07
|
||||||
|
|
||||||
|
### Bug Fixes
|
||||||
|
|
||||||
|
- Retry ansible-galaxy collection install on transient timeouts
|
||||||
|
|
||||||
|
## [0.49.2] - 2026-08-07
|
||||||
|
|
||||||
|
### Bug Fixes
|
||||||
|
|
||||||
|
- Add fallback URL for tea download
|
||||||
|
|
||||||
|
## [0.49.1] - 2026-08-07
|
||||||
|
|
||||||
|
### Bug Fixes
|
||||||
|
|
||||||
|
- Add container images to build-images workflow
|
||||||
|
|
||||||
|
## [0.49.0] - 2026-08-07
|
||||||
|
|
||||||
|
### Features
|
||||||
|
|
||||||
|
- Add --include-roles and --exclude-roles to distribute_molecule
|
||||||
|
## [0.48.0] - 2026-07-22
|
||||||
|
|
||||||
|
### Features
|
||||||
|
|
||||||
|
- Extract reusable components from infra and grm into devx
|
||||||
|
|
||||||
|
## [0.48.0] - 2026-07-22
|
||||||
|
|
||||||
|
### Features
|
||||||
|
|
||||||
|
- Extract reusable components from infra and grm into devx
|
||||||
|
|
||||||
|
## [Unreleased]
|
||||||
|
|
||||||
|
### Features
|
||||||
|
|
||||||
|
- Extract reusable components from infra and grm into devx:
|
||||||
|
- `devx.utils.ui.say()` — unified click.echo + logging output
|
||||||
|
- `devx.utils.api.APIClient` — base HTTP API client class with retry logic
|
||||||
|
- `devx.utils.jinja` — Jinja2 environment helpers with Ansible-compatible filters
|
||||||
|
- `devx.i18n.configure_i18n()` — configurable `lang_env_var` and `translations_path_env_var`
|
||||||
|
- `devx.ci.cancel_superseded_runs` — cancel in-flight CI runs for the same PR branch
|
||||||
|
- `devx.ci.check_workflow_artifact_deps` — verify artifact download jobs depend on upload jobs
|
||||||
|
- `devx.ci.check_workflow_tofu_init` — verify tofu-state jobs have a tofu-init step
|
||||||
|
- `devx.tools.check_docker_init` — check Docker Compose services with healthchecks have init: true
|
||||||
|
- `devx.tools.check_ansible_set_fact_to_json` — check set_fact tasks don't misuse to_json
|
||||||
|
- `devx.tools.check_alert_rules` — validate Prometheus alert rules with promtool
|
||||||
|
- Add `jinja2` and `pyyaml` as core dependencies (previously in `deploy` extras only)
|
||||||
|
- Register new CLI commands: `devx ci cancel-superseded-runs`, `devx ci check-workflow-artifact-deps`,
|
||||||
|
`devx ci check-workflow-tofu-init`, `devx tools check-docker-init`,
|
||||||
|
`devx tools check-ansible-set-fact-to-json`, `devx tools check-alert-rules`
|
||||||
|
- Add Makefile targets for all new check tools
|
||||||
|
|
||||||
|
## [0.47.3] - 2026-07-17
|
||||||
|
|
||||||
|
### Bug Fixes
|
||||||
|
|
||||||
|
- Bake promtool into ci-full image, add download timeout, speed up tests
|
||||||
|
|
||||||
|
## [0.47.2] - 2026-07-17
|
||||||
|
|
||||||
|
### Bug Fixes
|
||||||
|
|
||||||
|
- Add retry logic to TeaCLI for transient HTTP errors (502/503/504/429)
|
||||||
|
|
||||||
|
## [0.47.1] - 2026-07-16
|
||||||
|
|
||||||
|
### Bug Fixes
|
||||||
|
|
||||||
|
- Tea CLI login failure handling, error messages, release retry
|
||||||
|
|
||||||
|
## [0.47.0] - 2026-07-14
|
||||||
|
|
||||||
|
### Features
|
||||||
|
|
||||||
|
- Add promtool to install_tools for alert rule validation
|
||||||
|
|
||||||
|
## [0.46.0] - 2026-07-14
|
||||||
|
|
||||||
|
### Features
|
||||||
|
|
||||||
|
- Make check_test_isolation configurable via pyproject.toml
|
||||||
|
|
||||||
|
## [0.45.1] - 2026-07-14
|
||||||
|
|
||||||
|
### Bug Fixes
|
||||||
|
|
||||||
|
- URL-encode package names and versions in clean_images API calls
|
||||||
|
|
||||||
|
## [0.45.0] - 2026-07-14
|
||||||
|
|
||||||
|
### Features
|
||||||
|
|
||||||
|
- Add IO_INTERNAL_CALLS to check_test_isolation
|
||||||
|
|
||||||
|
## [0.44.2] - 2026-07-14
|
||||||
|
|
||||||
|
### Bug Fixes
|
||||||
|
|
||||||
|
- Use legacy Docker builder to avoid Gitea registry 403
|
||||||
|
|
||||||
|
## [0.44.1] - 2026-07-14
|
||||||
|
|
||||||
|
### Bug Fixes
|
||||||
|
|
||||||
|
- Disable Docker buildx provenance attestation
|
||||||
|
|
||||||
|
## [0.44.0] - 2026-07-13
|
||||||
|
|
||||||
|
### Features
|
||||||
|
|
||||||
|
- Add fix_pr_title module and update_pr API method
|
||||||
|
|
||||||
|
## [0.43.0] - 2026-07-13
|
||||||
|
|
||||||
|
### Features
|
||||||
|
|
||||||
|
- Add get_customer_vm_ip and get_observability_vm_ip to I/O check
|
||||||
|
|
||||||
## [0.42.0] - 2026-07-13
|
## [0.42.0] - 2026-07-13
|
||||||
|
|
||||||
### Features
|
### Features
|
||||||
|
|||||||
@@ -1,4 +1,5 @@
|
|||||||
.PHONY: all setup setup-ci setup-quality setup-release setup-image install update lint lint-all lint-dockerfiles test test-unit pytest-cov clean install-tools install-hooks activate-scripts checkmake check-mutable-globals check-dep-docs check-test-speed build-images push-images build-images-dry-run clean-images
|
.PHONY: all setup setup-ci setup-quality setup-release setup-image install update lint lint-all lint-dockerfiles test test-unit pytest-cov clean install-tools install-hooks activate-scripts checkmake check-mutable-globals check-dep-docs check-test-speed build-images push-images build-images-dry-run clean-images
|
||||||
|
.PHONY: check-workflow-artifact-deps check-workflow-tofu-init check-docker-init check-ansible-set-fact-to-json check-alert-rules
|
||||||
|
|
||||||
PYTHON := python3
|
PYTHON := python3
|
||||||
VENV := .venv
|
VENV := .venv
|
||||||
@@ -65,7 +66,7 @@ setup-release: $(VENV)/bin/activate .env
|
|||||||
# an older devx.mak that doesn't yet define devx-setup-image. Consumer repos
|
# an older devx.mak that doesn't yet define devx-setup-image. Consumer repos
|
||||||
# (grm, infra) can safely alias to devx-setup-image since they install devx from PyPI.
|
# (grm, infra) can safely alias to devx-setup-image since they install devx from PyPI.
|
||||||
setup-image:
|
setup-image:
|
||||||
@if [ -d /opt/venv ]; then ln -sf /opt/venv $(VENV); . $(VENV)/bin/activate && pip install --no-cache-dir -e . 2>/dev/null; \
|
@if [ -d /opt/venv ]; then ln -sf /opt/venv $(VENV); . $(VENV)/bin/activate && pip install --no-cache-dir --no-deps -e . 2>/dev/null; \
|
||||||
else echo "[setup-image] /opt/venv not found — falling back to setup-ci"; $(MAKE) setup-ci; fi
|
else echo "[setup-image] /opt/venv not found — falling back to setup-ci"; $(MAKE) setup-ci; fi
|
||||||
|
|
||||||
install-hooks:
|
install-hooks:
|
||||||
@@ -113,6 +114,31 @@ pr-rebase: devx-pr-rebase
|
|||||||
lint-all: lint workflow-lint lint-dockerfiles
|
lint-all: lint workflow-lint lint-dockerfiles
|
||||||
@echo "[lint-all] All linting checks passed."
|
@echo "[lint-all] All linting checks passed."
|
||||||
|
|
||||||
|
# ── Workflow / Ansible / Docker check tools ─────────────────────────────────
|
||||||
|
# Generic check tools ported from infra. These targets are no-ops in devx
|
||||||
|
# itself (no .gitea/workflows or ansible/ directory) but provide the
|
||||||
|
# canonical entry points for consumer repos that include devx.mak.
|
||||||
|
|
||||||
|
check-workflow-artifact-deps:
|
||||||
|
@$(BIN)/python -m devx.ci.check_workflow_artifact_deps || \
|
||||||
|
echo "[check-workflow-artifact-deps] No workflows directory found — skipping."
|
||||||
|
|
||||||
|
check-workflow-tofu-init:
|
||||||
|
@$(BIN)/python -m devx.ci.check_workflow_tofu_init || \
|
||||||
|
echo "[check-workflow-tofu-init] No workflows directory found — skipping."
|
||||||
|
|
||||||
|
check-docker-init:
|
||||||
|
@$(BIN)/python -m devx.tools.check_docker_init || \
|
||||||
|
echo "[check-docker-init] No ansible templates found — skipping."
|
||||||
|
|
||||||
|
check-ansible-set-fact-to-json:
|
||||||
|
@$(BIN)/python -m devx.tools.check_ansible_set_fact_to_json || \
|
||||||
|
echo "[check-ansible-set-fact-to-json] No ansible directory found — skipping."
|
||||||
|
|
||||||
|
check-alert-rules:
|
||||||
|
@$(BIN)/python -m devx.tools.check_alert_rules --template-path ansible/roles/observability/templates || \
|
||||||
|
echo "[check-alert-rules] No alert-rules template found — skipping."
|
||||||
|
|
||||||
# Note: Not aliased to devx-lint-dockerfiles for the same reason as setup-image —
|
# Note: Not aliased to devx-lint-dockerfiles for the same reason as setup-image —
|
||||||
# devx's own CI images may have an older devx.mak. Consumer repos can safely alias.
|
# devx's own CI images may have an older devx.mak. Consumer repos can safely alias.
|
||||||
lint-dockerfiles:
|
lint-dockerfiles:
|
||||||
|
|||||||
@@ -12,16 +12,16 @@ opinionated CI/CD pipeline: conventional commits, automated versioning via
|
|||||||
git-cliff, squash-merge automation, Vikunja task tracking, wiki sync, and
|
git-cliff, squash-merge automation, Vikunja task tracking, wiki sync, and
|
||||||
quality badges.
|
quality badges.
|
||||||
|
|
||||||
> An open-source project from **Oblachno** (облачно means *cloudy* in Bulgarian).
|
> An open source project from **Oblachno** (облачно means *cloudy* in Bulgarian).
|
||||||
|
|
||||||
[](https://git.oblachno.oblachno.fyi/oblachno-oss/devx/actions)
|
[](https://git.oblachno.oblachno.fyi/oblachno-oss/devx/actions)
|
||||||
[](https://git.oblachno.oblachno.fyi/oblachno-oss/devx/src/branch/master/LICENSE)
|
[](https://git.oblachno.oblachno.fyi/oblachno-oss/devx/src/branch/master/LICENSE)
|
||||||
[](https://git.oblachno.oblachno.fyi/oblachno-oss/devx/actions)
|
[](https://git.oblachno.oblachno.fyi/oblachno-oss/devx/actions)
|
||||||
[](https://git.oblachno.oblachno.fyi/oblachno-oss/devx/actions)
|
[](https://git.oblachno.oblachno.fyi/oblachno-oss/devx/actions)
|
||||||
[](https://git.oblachno.oblachno.fyi/oblachno-oss/devx/wiki)
|
[](https://git.oblachno.oblachno.fyi/oblachno-oss/devx/wiki)
|
||||||
[](https://git.oblachno.oblachno.fyi/oblachno-oss/devx/actions)
|
[](https://git.oblachno.oblachno.fyi/oblachno-oss/devx/actions)
|
||||||
[](https://git.oblachno.oblachno.fyi/oblachno-oss/devx/releases)
|
[](https://git.oblachno.oblachno.fyi/oblachno-oss/devx/releases)
|
||||||
[](https://www.python.org/downloads/)
|
[](https://www.python.org/downloads/)
|
||||||
|
|
||||||
## Why devx?
|
## Why devx?
|
||||||
|
|
||||||
@@ -87,7 +87,7 @@ extra index and list devx in your dependencies:
|
|||||||
```toml
|
```toml
|
||||||
[project]
|
[project]
|
||||||
dependencies = [
|
dependencies = [
|
||||||
"devx>=0.42.0",
|
"devx>=0.49.5",
|
||||||
]
|
]
|
||||||
|
|
||||||
[tool.pip]
|
[tool.pip]
|
||||||
@@ -101,8 +101,8 @@ pip install -e .
|
|||||||
```
|
```
|
||||||
|
|
||||||
> **Note:** If your project requires a specific devx version, pin it in
|
> **Note:** If your project requires a specific devx version, pin it in
|
||||||
> `dependencies` (for example, `"devx==0.42.0"`) or use a version constraint
|
> `dependencies` (for example, `"devx==0.49.5"`) or use a version constraint
|
||||||
> (for example, `"devx>=0.42.0,<0.43"`).
|
> (for example, `"devx>=0.49.5,<0.50"`).
|
||||||
|
|
||||||
### Optional extras
|
### Optional extras
|
||||||
|
|
||||||
|
|||||||
@@ -20,5 +20,6 @@ COPY . /tmp/devx
|
|||||||
RUN pip install --no-cache-dir /tmp/devx[release,molecule,deploy] \
|
RUN pip install --no-cache-dir /tmp/devx[release,molecule,deploy] \
|
||||||
&& rm -rf /tmp/devx
|
&& rm -rf /tmp/devx
|
||||||
|
|
||||||
# Install git-cliff (changelog generator for release job) and OpenTofu (for infra deploy jobs)
|
# Install git-cliff (changelog generator for release job), OpenTofu (for infra deploy jobs),
|
||||||
RUN python3 -m devx.tools.install_tools --tool git-cliff --tool tofu
|
# and promtool (Prometheus rule validator — used by every infra CI run for alert validation)
|
||||||
|
RUN python3 -m devx.tools.install_tools --tool git-cliff --tool tofu --tool promtool
|
||||||
|
|||||||
@@ -40,20 +40,30 @@ invocation in any repo with devx installed automatically runs the
|
|||||||
static analysis. No extra Makefile target or CI step needed.
|
static analysis. No extra Makefile target or CI step needed.
|
||||||
|
|
||||||
The plugin (`devx.tools.check_test_isolation`) statically analyzes
|
The plugin (`devx.tools.check_test_isolation`) statically analyzes
|
||||||
test files during `pytest_collection_finish` and emits
|
test files during `pytest_collection_finish` and **fails the test run**
|
||||||
`UserWarning` for violations:
|
on any hard violation:
|
||||||
|
|
||||||
- **unpatched-subprocess**: `subprocess.run/call/Popen/check_call/check_output`
|
- **unpatched-subprocess**: `subprocess.run/call/Popen/check_call/check_output`
|
||||||
called in a test function without `@patch`
|
called in a test function without `@patch` or `with patch(...)`
|
||||||
- **unpatched-sleep**: `time.sleep` called without `@patch`
|
- **unpatched-sleep**: `time.sleep` called without `@patch`
|
||||||
- **unpatched-helper**: known subprocess-spawning helpers
|
- **unpatched-helper**: known subprocess-spawning helpers
|
||||||
(`update_doc_versions`, `run_cmd`, `run_tests`) called without
|
(`update_doc_versions`, `run_cmd`, `run_tests`) called without
|
||||||
`@patch` (and without patching their internal dependencies)
|
`@patch` (and without patching their internal dependencies)
|
||||||
- **excessive-iterations**: `for _ in range(N)` where N > 100
|
- **excessive-iterations**: `for _ in range(N)` where N > 100
|
||||||
|
- **heavy-module-import**: `httpx`, `ansible`, etc. imported at module
|
||||||
|
level in test files, slowing collection for all tests
|
||||||
|
- **reload-without-cleanup**: `importlib.reload()` called an odd number
|
||||||
|
of times, leaving module state modified
|
||||||
|
|
||||||
The plugin recognizes transitive safety: if `run_cmd` is patched,
|
Transitive-subprocess findings (via call-graph analysis) are reported
|
||||||
`run_tests` (which calls `run_cmd`) is safe. This is tracked via
|
as **advisories** — the static analysis can't predict early exits or
|
||||||
`HELPER_INTERNAL_CALLS`.
|
runtime branch conditions, so the runtime audit is authoritative.
|
||||||
|
|
||||||
|
The plugin also wraps `subprocess.run` at runtime to catch real
|
||||||
|
subprocess calls that leak through transitive call paths (for example
|
||||||
|
`CliRunner.invoke(main)` → `main()` → `update_doc_versions()` →
|
||||||
|
`subprocess.run()`). If a test spawns a real subprocess without
|
||||||
|
`@patch`, the test fails.
|
||||||
|
|
||||||
A standalone CLI (`python -m devx.tools.check_test_isolation`) is also
|
A standalone CLI (`python -m devx.tools.check_test_isolation`) is also
|
||||||
provided for CI gates and pre-commit hooks where pytest isn't run.
|
provided for CI gates and pre-commit hooks where pytest isn't run.
|
||||||
@@ -85,16 +95,20 @@ is even created.
|
|||||||
|
|
||||||
- **Automatic enforcement**: The pytest plugin runs on every `pytest`
|
- **Automatic enforcement**: The pytest plugin runs on every `pytest`
|
||||||
invocation across devx, grm, and infra — no per-repo configuration
|
invocation across devx, grm, and infra — no per-repo configuration
|
||||||
needed. New tests with unpatched subprocess calls emit warnings
|
needed. New tests with unpatched subprocess calls fail immediately.
|
||||||
immediately.
|
|
||||||
- **Shift-left**: Translation gaps and test isolation violations are
|
- **Shift-left**: Translation gaps and test isolation violations are
|
||||||
caught locally (pre-commit / `make lint`) instead of in CI.
|
caught locally (pre-commit / `make lint`) instead of in CI.
|
||||||
- **Fast feedback**: Static analysis adds <0.1s to test runs — no
|
- **Fast feedback**: Static analysis adds <0.1s to test runs; runtime
|
||||||
runtime overhead.
|
subprocess audit adds negligible overhead (wrapper checks a
|
||||||
- **No false positives**: The transitive dependency tracking
|
thread-local flag).
|
||||||
(`HELPER_INTERNAL_CALLS`) correctly recognizes that patching
|
- **Transitive detection**: The call-graph BFS traces
|
||||||
`run_cmd` makes `run_tests` safe, and patching `subprocess.run`
|
`CliRunner.invoke(main)` → `main()` → `update_doc_versions()` →
|
||||||
makes all helpers safe.
|
`subprocess.run()`, catching indirect subprocess leaks that direct
|
||||||
|
analysis misses. The runtime audit provides authoritative enforcement.
|
||||||
|
- **No false positives**: The call graph correctly recognizes that
|
||||||
|
patching `run_cmd` makes `run_tests` (which calls `run_cmd`) safe,
|
||||||
|
and class methods are excluded to avoid false positives when classes
|
||||||
|
like `TeaCLI` are patched.
|
||||||
|
|
||||||
### Negative
|
### Negative
|
||||||
|
|
||||||
@@ -103,10 +117,12 @@ is even created.
|
|||||||
definitions) appears uncovered. Mitigated by `-p no:devx_test_isolation`
|
definitions) appears uncovered. Mitigated by `-p no:devx_test_isolation`
|
||||||
in devx's own `pyproject.toml` `addopts` and `# pragma: no cover` on
|
in devx's own `pyproject.toml` `addopts` and `# pragma: no cover` on
|
||||||
plugin hook functions.
|
plugin hook functions.
|
||||||
- **Static analysis limitations**: The plugin only sees direct calls
|
- **Static analysis limitations**: The call-graph BFS can't predict
|
||||||
in test function bodies, not indirect calls through `main()` or
|
runtime branch conditions or early exits — a test that patches
|
||||||
other wrappers. This is acceptable — the `check_test_speed` tool
|
`shutil.which` to return `None` may skip the subprocess path
|
||||||
catches the symptom (slow tests) for indirect cases.
|
entirely, but the static analysis still reports it. Transitive
|
||||||
|
findings are advisories (exit 0) for this reason; the runtime audit
|
||||||
|
is authoritative.
|
||||||
- **Translation burden**: Every new `_()` call in source requires
|
- **Translation burden**: Every new `_()` call in source requires
|
||||||
adding 6 language translations. This is by design (all supported
|
adding 6 language translations. This is by design (all supported
|
||||||
languages must be complete) but adds friction for quick prototypes.
|
languages must be complete) but adds friction for quick prototypes.
|
||||||
@@ -122,21 +138,36 @@ in consumer repos.
|
|||||||
|
|
||||||
### Disabling the Plugin
|
### Disabling the Plugin
|
||||||
|
|
||||||
- `--no-test-isolation` flag: disables analysis for a single run
|
- `--no-test-isolation` flag: disables static analysis and runtime
|
||||||
|
subprocess audit for a single run
|
||||||
- `-p no:devx_test_isolation` in `addopts`: disables for a repo
|
- `-p no:devx_test_isolation` in `addopts`: disables for a repo
|
||||||
(used in devx's own `pyproject.toml` for coverage reasons)
|
(used in devx's own `pyproject.toml` for coverage reasons)
|
||||||
|
|
||||||
### Strict Mode
|
### Call-Graph Analysis
|
||||||
|
|
||||||
- `--strict-test-isolation` flag: promotes warnings to errors and
|
The `CallGraph` class parses all `.py` files under `src/` and builds
|
||||||
prints a summary to stderr
|
a map of function → called functions. When a test calls
|
||||||
- `filterwarnings = ["error:Test isolation:UserWarning"]` in
|
`CliRunner.invoke(target)`, a BFS traces the call graph from `target`
|
||||||
`pyproject.toml`: same effect via pytest's warning filter system
|
to find all reachable functions. Class methods are excluded from the
|
||||||
|
call graph to avoid false positives when classes are patched (for example
|
||||||
|
`@patch("...TeaCLI")` mocks all methods). The BFS respects `@patch`
|
||||||
|
decorators — if a function is patched, traversal stops at that node.
|
||||||
|
|
||||||
|
### Runtime Subprocess Audit
|
||||||
|
|
||||||
|
The `_SubprocessAudit` singleton wraps `subprocess.run`, `call`,
|
||||||
|
`check_call`, `check_output`, and `Popen` with thread-local
|
||||||
|
recording wrappers. During each non-integration test, the wrapper
|
||||||
|
records calls; if any are recorded (that is the test didn't `@patch`
|
||||||
|
subprocess), the test fails. The wrappers check a thread-local flag,
|
||||||
|
so inactive audits have zero overhead beyond the flag check.
|
||||||
|
|
||||||
### Known Subprocess Helpers
|
### Known Subprocess Helpers
|
||||||
|
|
||||||
The `KNOWN_SUBPROCESS_HELPERS` dict maps function names to
|
The `KNOWN_SUBPROCESS_HELPERS` dict maps function names to
|
||||||
descriptions. `HELPER_INTERNAL_CALLS` maps each helper to the
|
descriptions. `HELPER_INTERNAL_CALLS` maps each helper to the
|
||||||
function names it internally calls, enabling transitive safety
|
function names it internally calls, enabling transitive safety
|
||||||
checks. Both are defined in `check_test_isolation.py` and can be
|
checks for direct calls in test functions. The call-graph BFS
|
||||||
extended as new subprocess-spawning helpers are added to devx.
|
handles transitive detection for `CliRunner.invoke` targets. Both
|
||||||
|
are defined in `check_test_isolation.py` and can be extended as
|
||||||
|
new subprocess-spawning helpers are added to devx.
|
||||||
|
|||||||
+9
-9
@@ -8,16 +8,16 @@ parallel test distribution, and more into a single installable package.
|
|||||||
It was extracted from the [GRM](https://git.oblachno.oblachno.fyi/oblachno-oss/grm)
|
It was extracted from the [GRM](https://git.oblachno.oblachno.fyi/oblachno-oss/grm)
|
||||||
project to be reusable across all oblachno-oss repositories.
|
project to be reusable across all oblachno-oss repositories.
|
||||||
|
|
||||||
> An open-source project from **Oblachno** (облачно means *cloudy* in Bulgarian).
|
> An open source project from **Oblachno** (облачно means *cloudy* in Bulgarian).
|
||||||
|
|
||||||
[](https://git.oblachno.oblachno.fyi/oblachno-oss/devx/actions)
|
[](https://git.oblachno.oblachno.fyi/oblachno-oss/devx/actions)
|
||||||
[](https://git.oblachno.oblachno.fyi/oblachno-oss/devx/src/branch/master/LICENSE)
|
[](https://git.oblachno.oblachno.fyi/oblachno-oss/devx/src/branch/master/LICENSE)
|
||||||
[](https://git.oblachno.oblachno.fyi/oblachno-oss/devx/actions)
|
[](https://git.oblachno.oblachno.fyi/oblachno-oss/devx/actions)
|
||||||
[](https://git.oblachno.oblachno.fyi/oblachno-oss/devx/actions)
|
[](https://git.oblachno.oblachno.fyi/oblachno-oss/devx/actions)
|
||||||
[](https://git.oblachno.oblachno.fyi/oblachno-oss/devx/wiki)
|
[](https://git.oblachno.oblachno.fyi/oblachno-oss/devx/wiki)
|
||||||
[](https://git.oblachno.oblachno.fyi/oblachno-oss/devx/actions)
|
[](https://git.oblachno.oblachno.fyi/oblachno-oss/devx/actions)
|
||||||
[](https://git.oblachno.oblachno.fyi/oblachno-oss/devx/releases)
|
[](https://git.oblachno.oblachno.fyi/oblachno-oss/devx/releases)
|
||||||
[](https://www.python.org/downloads/)
|
[](https://www.python.org/downloads/)
|
||||||
|
|
||||||
## Overview
|
## Overview
|
||||||
|
|
||||||
@@ -74,14 +74,14 @@ Add devx to your `pyproject.toml` dependencies and configure the registry:
|
|||||||
```toml
|
```toml
|
||||||
[project]
|
[project]
|
||||||
dependencies = [
|
dependencies = [
|
||||||
"devx>=0.42.0",
|
"devx>=0.49.5",
|
||||||
]
|
]
|
||||||
|
|
||||||
[tool.pip]
|
[tool.pip]
|
||||||
extra-index-url = "https://git.oblachno.oblachno.fyi/api/packages/oblachno-oss/pypi/simple"
|
extra-index-url = "https://git.oblachno.oblachno.fyi/api/packages/oblachno-oss/pypi/simple"
|
||||||
```
|
```
|
||||||
|
|
||||||
Pin a specific version if needed: `"devx==0.42.0"` or `"devx>=0.42.0,<0.43"`.
|
Pin a specific version if needed: `"devx==0.49.5"` or `"devx>=0.49.5,<0.50"`.
|
||||||
|
|
||||||
### Optional extras
|
### Optional extras
|
||||||
|
|
||||||
|
|||||||
@@ -132,7 +132,7 @@ unblocked auto-merge across all three repos.
|
|||||||
### 2. Double-Prefix Detection (MEDIUM impact)
|
### 2. Double-Prefix Detection (MEDIUM impact)
|
||||||
|
|
||||||
`check_auto_merge_ready.py` now detects and rejects Vikunja task titles
|
`check_auto_merge_ready.py` now detects and rejects Vikunja task titles
|
||||||
that include the identifier prefix (for example, "DEVX-127: Fix...").
|
that include the identifier prefix (for example, "DEVX-127: Fix").
|
||||||
The validator adds the prefix automatically, so a double prefix would
|
The validator adds the prefix automatically, so a double prefix would
|
||||||
fail validation.
|
fail validation.
|
||||||
|
|
||||||
|
|||||||
@@ -87,11 +87,11 @@ overridden via environment variables with the `DEVX_` prefix. Provides:
|
|||||||
|
|
||||||
- `GITEA_API_URL` / `VIKUNJA_API_URL` — API endpoints
|
- `GITEA_API_URL` / `VIKUNJA_API_URL` — API endpoints
|
||||||
- `REPO_OWNER` — repository owner (must be set per-project)
|
- `REPO_OWNER` — repository owner (must be set per-project)
|
||||||
- `TASK_PREFIX` / `TASK_ID_RE` — task ID prefix and regex (for example, `DEVX-N`)
|
- `TASK_PREFIX` / `TASK_ID_RE` — task ID prefix and regular expression (for example, `DEVX-N`)
|
||||||
- `VIKUNJA_PROJECT_ID` — Vikunja project for task tracking
|
- `VIKUNJA_PROJECT_ID` — Vikunja project for task tracking
|
||||||
- `DEFAULT_TIMEOUT`, `DEFAULT_PER_PAGE` — HTTP client defaults
|
- `DEFAULT_TIMEOUT`, `DEFAULT_PER_PAGE` — HTTP client defaults
|
||||||
- `MAX_RETRIES`, `RETRY_BACKOFF_BASE`, `RETRY_STATUS_CODES` — retry config
|
- `MAX_RETRIES`, `RETRY_BACKOFF_BASE`, `RETRY_STATUS_CODES` — retry config
|
||||||
- `CONVENTIONAL_RE` — conventional commit format regex
|
- `CONVENTIONAL_RE` — conventional commit format regular expression
|
||||||
|
|
||||||
### `exceptions.py`
|
### `exceptions.py`
|
||||||
|
|
||||||
@@ -109,7 +109,7 @@ wraps user-facing strings for translation.
|
|||||||
|
|
||||||
Projects can extend translations by setting `DEVX_TRANSLATIONS_PATH` to a
|
Projects can extend translations by setting `DEVX_TRANSLATIONS_PATH` to a
|
||||||
custom JSON file. Keys from the project's file are merged on top of devx's
|
custom JSON file. Keys from the project's file are merged on top of devx's
|
||||||
built-in translations, allowing projects to override or add keys without
|
built-in translations, allowing projects to override, or add keys without
|
||||||
modifying the package.
|
modifying the package.
|
||||||
|
|
||||||
### `api_clients.py`
|
### `api_clients.py`
|
||||||
@@ -171,7 +171,7 @@ from `devx.api_clients`, `devx.config`, `devx.gitea_cli`, and `devx.i18n`.
|
|||||||
|
|
||||||
Automated release using git-cliff. Calculates the next semver version from
|
Automated release using git-cliff. Calculates the next semver version from
|
||||||
conventional commits since the last tag, updates `__version__` in
|
conventional commits since the last tag, updates `__version__` in
|
||||||
`__init__.py` and `CHANGELOG.md`, runs lint and tests to verify the release
|
`__init__.py` and `CHANGELOG.md`, runs lint, and tests to verify the release
|
||||||
is healthy, commits with `release: vX.Y.Z [skip ci]`, creates an annotated
|
is healthy, commits with `release: vX.Y.Z [skip ci]`, creates an annotated
|
||||||
tag, and pushes both to master.
|
tag, and pushes both to master.
|
||||||
|
|
||||||
@@ -288,7 +288,7 @@ Click commands from `cli.py` and verifies each has documentation in
|
|||||||
### `discover_runners.py`
|
### `discover_runners.py`
|
||||||
|
|
||||||
Discovers available Gitea Actions runners at three levels: repository,
|
Discovers available Gitea Actions runners at three levels: repository,
|
||||||
organization, and instance (admin). Falls back to the `MOLECULE_RUNNERS` repo
|
organization, and instance (administrator). Falls back to the `MOLECULE_RUNNERS` repo
|
||||||
variable or `DEFAULT_MAX_RUNNERS` (3). Outputs runner count or a JSON index
|
variable or `DEFAULT_MAX_RUNNERS` (3). Outputs runner count or a JSON index
|
||||||
array for use as a dynamic matrix in Gitea Actions.
|
array for use as a dynamic matrix in Gitea Actions.
|
||||||
|
|
||||||
@@ -330,7 +330,7 @@ Supports `--tool` to install specific tools and `--list` to show status.
|
|||||||
Runs unit tests and enforces execution-time budgets. Two quality gates:
|
Runs unit tests and enforces execution-time budgets. Two quality gates:
|
||||||
total suite time must not exceed `--max-seconds` (default: 10s), and no
|
total suite time must not exceed `--max-seconds` (default: 10s), and no
|
||||||
individual test may exceed `--max-single-seconds` (default: 0.5s, 0 to
|
individual test may exceed `--max-single-seconds` (default: 0.5s, 0 to
|
||||||
disable). Runs `make test-unit` with `PYTEST_ADDOPTS=--durations=0`.
|
off). Runs `make test-unit` with `PYTEST_ADDOPTS=--durations=0`.
|
||||||
|
|
||||||
### `check_test_isolation.py`
|
### `check_test_isolation.py`
|
||||||
|
|
||||||
|
|||||||
+119
-10
@@ -85,7 +85,7 @@ devx ci detect-release-commit
|
|||||||
|
|
||||||
Discover available Gitea Actions runners for dynamic job distribution.
|
Discover available Gitea Actions runners for dynamic job distribution.
|
||||||
Queries the Gitea API for registered runners at repository, organization, and
|
Queries the Gitea API for registered runners at repository, organization, and
|
||||||
instance (admin) levels. Falls back to `MOLECULE_RUNNERS` repo variable or
|
instance (administrator) levels. Falls back to `MOLECULE_RUNNERS` repo variable or
|
||||||
`DEFAULT_MAX_RUNNERS` (3).
|
`DEFAULT_MAX_RUNNERS` (3).
|
||||||
|
|
||||||
```bash
|
```bash
|
||||||
@@ -315,6 +315,56 @@ devx ci validate-commit-msg commit-msg.txt --branch master
|
|||||||
Options:
|
Options:
|
||||||
- `--branch <branch>` — override branch detection (for CI use)
|
- `--branch <branch>` — override branch detection (for CI use)
|
||||||
|
|
||||||
|
### `devx ci cancel-superseded-runs`
|
||||||
|
|
||||||
|
Cancel in-flight CI runs for the same PR branch when a new push triggers
|
||||||
|
a new run. Uses the Gitea Actions API to list running pull_request runs
|
||||||
|
and cancel those with a lower run ID on the same branch.
|
||||||
|
|
||||||
|
```bash
|
||||||
|
devx ci cancel-superseded-runs \
|
||||||
|
--repo "$REPOSITORY" \
|
||||||
|
--current-run-id "$GITHUB_RUN_ID" \
|
||||||
|
--head-branch "$HEAD_REF"
|
||||||
|
```
|
||||||
|
|
||||||
|
Options:
|
||||||
|
- `--repo <owner/repo>` — repository (required)
|
||||||
|
- `--current-run-id <id>` — current run ID, not cancelled (required)
|
||||||
|
- `--head-branch <branch>` — PR head branch name (required)
|
||||||
|
- `--dry-run` — list superseded runs without cancelling
|
||||||
|
- `--base-url <url>` — Gitea base URL (default: `GITEA_API_URL` env var)
|
||||||
|
|
||||||
|
### `devx ci check-workflow-artifact-deps`
|
||||||
|
|
||||||
|
Verify that workflow jobs downloading artifacts depend on the uploading
|
||||||
|
job. Prevents the class of bug where a download job runs in parallel
|
||||||
|
with the upload job and fails because the artifact isn't available yet.
|
||||||
|
|
||||||
|
```bash
|
||||||
|
devx ci check-workflow-artifact-deps
|
||||||
|
devx ci check-workflow-artifact-deps --workflow .gitea/workflows/ci.yml
|
||||||
|
```
|
||||||
|
|
||||||
|
Options:
|
||||||
|
- `--workflow <path>` — check a specific workflow file
|
||||||
|
- `--workflows-dir <path>` — override workflows directory
|
||||||
|
|
||||||
|
### `devx ci check-workflow-tofu-init`
|
||||||
|
|
||||||
|
Verify that workflow jobs using tofu state (tofu output/plan/apply or
|
||||||
|
scripts that call them) have a tofu-init step in the same job.
|
||||||
|
|
||||||
|
```bash
|
||||||
|
devx ci check-workflow-tofu-init
|
||||||
|
devx ci check-workflow-tofu-init --workflow .gitea/workflows/deploy.yml
|
||||||
|
```
|
||||||
|
|
||||||
|
Options:
|
||||||
|
- `--workflow <path>` — check a specific workflow file
|
||||||
|
- `--workflows-dir <path>` — override workflows directory
|
||||||
|
- `--state-script <name>` — add a script that uses tofu state (repeatable)
|
||||||
|
|
||||||
## Tools Commands
|
## Tools Commands
|
||||||
|
|
||||||
### `devx tools check-test-speed`
|
### `devx tools check-test-speed`
|
||||||
@@ -323,7 +373,7 @@ Run unit tests and enforce execution-time budgets. Two quality gates:
|
|||||||
|
|
||||||
- **Total suite time** must not exceed `--max-seconds` (default: 10s)
|
- **Total suite time** must not exceed `--max-seconds` (default: 10s)
|
||||||
- **Per-test time** — no individual test may exceed `--max-single-seconds`
|
- **Per-test time** — no individual test may exceed `--max-single-seconds`
|
||||||
(default: 0.5s, 0 to disable)
|
(default: 0.5s, 0 to turn off)
|
||||||
|
|
||||||
Runs `make test-unit` with `PYTEST_ADDOPTS=--durations=0` so pytest emits
|
Runs `make test-unit` with `PYTEST_ADDOPTS=--durations=0` so pytest emits
|
||||||
per-test timing lines.
|
per-test timing lines.
|
||||||
@@ -339,28 +389,37 @@ devx tools check-test-speed --max-seconds 4 --max-single-seconds 0.5
|
|||||||
Statically analyze test files for un-hermetic patterns that cause slow
|
Statically analyze test files for un-hermetic patterns that cause slow
|
||||||
or flaky tests. Also available as a **pytest plugin** (auto-discovered
|
or flaky tests. Also available as a **pytest plugin** (auto-discovered
|
||||||
via the `pytest11` entry point when devx is installed — runs
|
via the `pytest11` entry point when devx is installed — runs
|
||||||
automatically on every `pytest` invocation).
|
automatically on every `pytest` invocation and **fails on violations**).
|
||||||
|
|
||||||
Detected patterns:
|
Detected patterns (hard errors — exit non-zero):
|
||||||
|
|
||||||
- **unpatched-subprocess**: `subprocess.run/call/Popen/check_call/check_output`
|
- **unpatched-subprocess**: `subprocess.run/call/Popen/check_call/check_output`
|
||||||
called in a test function without `@patch`
|
called in a test function without `@patch` or `with patch(...)`
|
||||||
- **unpatched-sleep**: `time.sleep` called without `@patch`
|
- **unpatched-sleep**: `time.sleep` called without `@patch`
|
||||||
- **unpatched-helper**: known subprocess-spawning helpers (`update_doc_versions`,
|
- **unpatched-helper**: known subprocess-spawning helpers (`update_doc_versions`,
|
||||||
`run_cmd`, `run_tests`) called without `@patch` or patching their internal deps
|
`run_cmd`, `run_tests`) called without `@patch` or patching their internal deps
|
||||||
- **excessive-iterations**: `for _ in range(N)` where N > 100
|
- **excessive-iterations**: `for _ in range(N)` where N > 100
|
||||||
|
- **heavy-module-import**: `httpx`, `ansible`, etc. imported at module level
|
||||||
|
- **reload-without-cleanup**: `importlib.reload()` called an odd number of times
|
||||||
|
|
||||||
|
Advisory patterns (exit 0 — runtime audit is authoritative):
|
||||||
|
|
||||||
|
- **transitive-subprocess**: `CliRunner.invoke(target)` where `target`
|
||||||
|
transitively calls `subprocess.run` without being patched. Detected via
|
||||||
|
static call-graph analysis. The runtime subprocess audit catches actual
|
||||||
|
leaks — if a real subprocess runs without `@patch`, the test fails.
|
||||||
|
|
||||||
```bash
|
```bash
|
||||||
devx tools check-test-isolation
|
devx tools check-test-isolation
|
||||||
devx tools check-test-isolation --test-path tests/ --strict
|
devx tools check-test-isolation --test-path tests/
|
||||||
devx tools check-test-isolation --categories unpatched-subprocess,unpatched-sleep
|
devx tools check-test-isolation --categories unpatched-subprocess,transitive-subprocess
|
||||||
devx tools check-test-isolation --max-loop-iterations 50
|
devx tools check-test-isolation --max-loop-iterations 50
|
||||||
|
devx tools check-test-isolation --src-dir src/
|
||||||
```
|
```
|
||||||
|
|
||||||
Pytest plugin options (automatic when devx is installed):
|
Pytest plugin options (automatic when devx is installed):
|
||||||
|
|
||||||
- `--strict-test-isolation` — fail the test run on violations
|
- `--no-test-isolation` — turn off static analysis and runtime subprocess audit
|
||||||
- `--no-test-isolation` — disable analysis for this run
|
|
||||||
- `--test-isolation-max-loop N` — max iterations per loop (default: 100)
|
- `--test-isolation-max-loop N` — max iterations per loop (default: 100)
|
||||||
|
|
||||||
### `devx tools configure-repo`
|
### `devx tools configure-repo`
|
||||||
@@ -405,7 +464,7 @@ devx tools generate-cliff-config --prefix GRM --force # overwrite existing
|
|||||||
Options:
|
Options:
|
||||||
- `--prefix <prefix>` — task ID prefix (default: `DEVX_TASK_PREFIX` env var
|
- `--prefix <prefix>` — task ID prefix (default: `DEVX_TASK_PREFIX` env var
|
||||||
or `DEVX`)
|
or `DEVX`)
|
||||||
- `--output <file>` — output file path (default: `cliff.toml`)
|
- `--output <file>` — output path (default: `cliff.toml`)
|
||||||
- `--force` — overwrite existing file
|
- `--force` — overwrite existing file
|
||||||
|
|
||||||
### `devx tools install-checkmake`
|
### `devx tools install-checkmake`
|
||||||
@@ -479,6 +538,56 @@ devx tools pr-rebase # auto-detect PR from current branch
|
|||||||
Options (pass after `--`):
|
Options (pass after `--`):
|
||||||
- `--pr <N>` — PR number (auto-detected from current branch if omitted)
|
- `--pr <N>` — PR number (auto-detected from current branch if omitted)
|
||||||
|
|
||||||
|
### `devx tools check-docker-init`
|
||||||
|
|
||||||
|
Check that Docker Compose services with healthchecks have `init: true`.
|
||||||
|
Without `init: true`, CMD-SHELL healthchecks spawn child processes that
|
||||||
|
become zombies when PID 1 doesn't reap them.
|
||||||
|
|
||||||
|
```bash
|
||||||
|
devx tools check-docker-init
|
||||||
|
devx tools check-docker-init --path path/to/docker-compose.yml.j2
|
||||||
|
```
|
||||||
|
|
||||||
|
Options:
|
||||||
|
- `--path <path>` — check a specific file or directory
|
||||||
|
- `--templates-dir <path>` — override templates directory (default: `ansible/roles/`)
|
||||||
|
|
||||||
|
### `devx tools check-ansible-set-fact-to-json`
|
||||||
|
|
||||||
|
Check that Ansible `set_fact` tasks don't misuse `| to_json`. Using
|
||||||
|
`to_json` in `set_fact` converts native Python types to JSON strings,
|
||||||
|
causing iteration bugs (for example, iterating over characters instead
|
||||||
|
of list items).
|
||||||
|
|
||||||
|
```bash
|
||||||
|
devx tools check-ansible-set-fact-to-json
|
||||||
|
devx tools check-ansible-set-fact-to-json --path path/to/playbook.yml
|
||||||
|
```
|
||||||
|
|
||||||
|
Options:
|
||||||
|
- `--path <path>` — check a specific file or directory
|
||||||
|
- `--ansible-dir <path>` — override ansible directories (repeatable)
|
||||||
|
|
||||||
|
### `devx tools check-alert-rules`
|
||||||
|
|
||||||
|
Validate rendered Prometheus alert rules with `promtool check rules`.
|
||||||
|
Renders a Jinja2 template with test values and validates the output.
|
||||||
|
Skips (exits 0) if promtool is not on PATH.
|
||||||
|
|
||||||
|
```bash
|
||||||
|
devx tools check-alert-rules \
|
||||||
|
--template-path ansible/roles/observability/templates
|
||||||
|
devx tools check-alert-rules \
|
||||||
|
--template-path ansible/roles/observability/templates \
|
||||||
|
--var grafana_base_url=https://grafana.example.com
|
||||||
|
```
|
||||||
|
|
||||||
|
Options:
|
||||||
|
- `--template-path <path>` — path to templates directory (required)
|
||||||
|
- `--template-name <name>` — template filename (default: `alert-rules.yml.j2`)
|
||||||
|
- `--var key=value` — template variables (repeatable)
|
||||||
|
|
||||||
## Molecule Commands
|
## Molecule Commands
|
||||||
|
|
||||||
Molecule commands require the `molecule` extra (`pip install devx[molecule]`).
|
Molecule commands require the `molecule` extra (`pip install devx[molecule]`).
|
||||||
|
|||||||
@@ -48,12 +48,12 @@ Add devx to your `pyproject.toml`:
|
|||||||
```toml
|
```toml
|
||||||
[project]
|
[project]
|
||||||
dependencies = [
|
dependencies = [
|
||||||
"devx>=0.42.0",
|
"devx>=0.49.5",
|
||||||
]
|
]
|
||||||
|
|
||||||
[project.optional-dependencies]
|
[project.optional-dependencies]
|
||||||
dev = [
|
dev = [
|
||||||
"devx>=0.42.0",
|
"devx>=0.49.5",
|
||||||
]
|
]
|
||||||
```
|
```
|
||||||
|
|
||||||
|
|||||||
+9
-4
@@ -20,6 +20,8 @@ dependencies = [
|
|||||||
"python-dotenv==1.2.2",
|
"python-dotenv==1.2.2",
|
||||||
"click==8.4.2",
|
"click==8.4.2",
|
||||||
"tenacity==9.1.4", # retry logic for GiteaClient/VikunjaClient
|
"tenacity==9.1.4", # retry logic for GiteaClient/VikunjaClient
|
||||||
|
"jinja2==3.1.6", # template rendering (devx.utils.jinja, check_alert_rules)
|
||||||
|
"pyyaml==6.0.3", # YAML parsing (workflow checks, ansible checks)
|
||||||
]
|
]
|
||||||
|
|
||||||
[project.scripts]
|
[project.scripts]
|
||||||
@@ -62,13 +64,16 @@ molecule = [
|
|||||||
"ansible-core==2.21.1",
|
"ansible-core==2.21.1",
|
||||||
]
|
]
|
||||||
# Deploy tools (for infra staging/production deployments)
|
# Deploy tools (for infra staging/production deployments)
|
||||||
|
# Versions aligned with infra's pyproject.toml to avoid reinstalls on every CI job.
|
||||||
|
# bcrypt and PyJWT are infra deps not in devx core — included here so the CI
|
||||||
|
# image has them and setup-image can use --no-deps (skip dep resolution).
|
||||||
deploy = [
|
deploy = [
|
||||||
"ansible-core==2.21.1",
|
"ansible-core==2.21.1",
|
||||||
"boto3==1.43.37",
|
"boto3==1.43.44",
|
||||||
"docker==7.1.0",
|
"docker==7.1.0",
|
||||||
"jinja2==3.1.6",
|
"cryptography==50.0.0",
|
||||||
"pyyaml==6.0.3",
|
"bcrypt==5.0.0",
|
||||||
"cryptography==49.0.0",
|
"PyJWT==2.13.0",
|
||||||
]
|
]
|
||||||
# Full dev environment (local development)
|
# Full dev environment (local development)
|
||||||
dev = [
|
dev = [
|
||||||
|
|||||||
@@ -1,3 +1,3 @@
|
|||||||
"""devx — reusable development and CI/CD tools for oblachno-oss projects."""
|
"""devx — reusable development and CI/CD tools for oblachno-oss projects."""
|
||||||
|
|
||||||
__version__ = "0.42.0"
|
__version__ = "0.49.5"
|
||||||
|
|||||||
@@ -224,6 +224,16 @@ class GiteaClient:
|
|||||||
r = self._request("GET", f"/pulls/{pr_number}")
|
r = self._request("GET", f"/pulls/{pr_number}")
|
||||||
return r.json()
|
return r.json()
|
||||||
|
|
||||||
|
def update_pr(self, pr_number: str | int, fields: dict[str, Any]) -> dict[str, Any]:
|
||||||
|
"""Update a pull request (e.g. title, body, state).
|
||||||
|
|
||||||
|
Args:
|
||||||
|
pr_number: PR number.
|
||||||
|
fields: Dict of fields to update (e.g. {"title": "new title"}).
|
||||||
|
"""
|
||||||
|
r = self._request("PATCH", f"/pulls/{pr_number}", json=fields)
|
||||||
|
return r.json()
|
||||||
|
|
||||||
def create_pr(self, title: str, head: str, base: str = "master", body: str = "") -> dict[str, Any]:
|
def create_pr(self, title: str, head: str, base: str = "master", body: str = "") -> dict[str, Any]:
|
||||||
"""Create a pull request and return the PR dict.
|
"""Create a pull request and return the PR dict.
|
||||||
|
|
||||||
|
|||||||
@@ -0,0 +1,185 @@
|
|||||||
|
"""Cancel superseded CI runs for the same PR.
|
||||||
|
|
||||||
|
When a new push to a PR branch triggers a new CI run, any in-flight
|
||||||
|
runs for the same PR are wasting runner time. This script cancels
|
||||||
|
all but the latest running CI run for each PR branch.
|
||||||
|
|
||||||
|
Uses the Gitea Actions API:
|
||||||
|
GET /repos/{owner}/{repo}/actions/runs?status=in_progress&event=pull_request
|
||||||
|
POST /repos/{owner}/{repo}/actions/runs/{run_id}/cancel
|
||||||
|
|
||||||
|
Usage::
|
||||||
|
|
||||||
|
# CI (cancels superseded runs for the current PR):
|
||||||
|
python -m devx.ci.cancel_superseded_runs \\
|
||||||
|
--repo "$REPOSITORY" \\
|
||||||
|
--current-run-id "$GITHUB_RUN_ID" \\
|
||||||
|
--head-branch "$HEAD_REF"
|
||||||
|
|
||||||
|
# Dry-run (lists what would be cancelled without cancelling):
|
||||||
|
python -m devx.ci.cancel_superseded_runs \\
|
||||||
|
--repo "$REPOSITORY" \\
|
||||||
|
--current-run-id "$GITHUB_RUN_ID" \\
|
||||||
|
--head-branch "$HEAD_REF" \\
|
||||||
|
--dry-run
|
||||||
|
"""
|
||||||
|
|
||||||
|
from __future__ import annotations
|
||||||
|
|
||||||
|
import argparse
|
||||||
|
import json
|
||||||
|
import os
|
||||||
|
import sys
|
||||||
|
import urllib.error
|
||||||
|
import urllib.request
|
||||||
|
|
||||||
|
_HTTP_NO_CONTENT = 204
|
||||||
|
_HTTP_NOT_FOUND = 404
|
||||||
|
_HTTP_BAD_REQUEST = 400
|
||||||
|
_PAGE_SIZE = 50
|
||||||
|
|
||||||
|
|
||||||
|
def _log(msg: str) -> None:
|
||||||
|
"""Log to stderr."""
|
||||||
|
print(f"[cancel-superseded] {msg}", file=sys.stderr, flush=True)
|
||||||
|
|
||||||
|
|
||||||
|
def _api_request(
|
||||||
|
method: str,
|
||||||
|
path: str,
|
||||||
|
token: str,
|
||||||
|
base_url: str,
|
||||||
|
body: dict | None = None,
|
||||||
|
) -> dict | list:
|
||||||
|
"""Make a Gitea API request."""
|
||||||
|
url = f"{base_url}/api/v1{path}"
|
||||||
|
headers = {
|
||||||
|
"Authorization": f"token {token}",
|
||||||
|
"Content-Type": "application/json",
|
||||||
|
"Accept": "application/json",
|
||||||
|
}
|
||||||
|
data = json.dumps(body).encode() if body else None
|
||||||
|
req = urllib.request.Request(url, data=data, headers=headers, method=method)
|
||||||
|
try:
|
||||||
|
with urllib.request.urlopen(req, timeout=30) as resp: # nosec B310 — authenticated API request to known Gitea instance
|
||||||
|
if resp.status == _HTTP_NO_CONTENT:
|
||||||
|
return {}
|
||||||
|
return json.loads(resp.read().decode())
|
||||||
|
except urllib.error.HTTPError as e:
|
||||||
|
_log(f"API error {e.code} on {method} {path}: {e.read().decode()[:200]}")
|
||||||
|
raise
|
||||||
|
except urllib.error.URLError as e:
|
||||||
|
_log(f"URL error on {method} {path}: {e}")
|
||||||
|
raise
|
||||||
|
|
||||||
|
|
||||||
|
def list_running_runs(repo: str, token: str, base_url: str) -> list[dict]:
|
||||||
|
"""List all running CI runs for pull_request events."""
|
||||||
|
runs: list[dict] = []
|
||||||
|
page = 1
|
||||||
|
while True:
|
||||||
|
result = _api_request(
|
||||||
|
"GET",
|
||||||
|
f"/repos/{repo}/actions/runs?status=in_progress&event=pull_request&page={page}&limit=50",
|
||||||
|
token,
|
||||||
|
base_url,
|
||||||
|
)
|
||||||
|
# Gitea returns {"workflow_runs": [...], "total_count": N}
|
||||||
|
page_runs = result["workflow_runs"] if isinstance(result, dict) else result
|
||||||
|
if not page_runs:
|
||||||
|
break
|
||||||
|
runs.extend(page_runs)
|
||||||
|
if len(page_runs) < _PAGE_SIZE:
|
||||||
|
break
|
||||||
|
page += 1
|
||||||
|
return runs
|
||||||
|
|
||||||
|
|
||||||
|
def cancel_run(repo: str, run_id: int, token: str, base_url: str) -> bool:
|
||||||
|
"""Cancel a CI run. Returns True on success."""
|
||||||
|
try:
|
||||||
|
_api_request(
|
||||||
|
"POST",
|
||||||
|
f"/repos/{repo}/actions/runs/{run_id}/cancel",
|
||||||
|
token,
|
||||||
|
base_url,
|
||||||
|
)
|
||||||
|
except (urllib.error.HTTPError, urllib.error.URLError):
|
||||||
|
return False
|
||||||
|
return True
|
||||||
|
|
||||||
|
|
||||||
|
def main() -> int:
|
||||||
|
parser = argparse.ArgumentParser(description="Cancel superseded CI runs for the same PR.")
|
||||||
|
parser.add_argument("--repo", required=True, help="owner/repo")
|
||||||
|
parser.add_argument("--current-run-id", required=True, help="Current run ID (not cancelled)")
|
||||||
|
parser.add_argument("--head-branch", required=True, help="PR head branch name")
|
||||||
|
parser.add_argument("--dry-run", action="store_true", help="List without cancelling")
|
||||||
|
parser.add_argument(
|
||||||
|
"--base-url",
|
||||||
|
default=os.environ.get("GITEA_API_URL", "https://git.oblachno.oblachno.fyi"),
|
||||||
|
help="Gitea base URL",
|
||||||
|
)
|
||||||
|
args = parser.parse_args()
|
||||||
|
|
||||||
|
token = os.environ.get("CI_GITEA_API_TOKEN") or os.environ.get("CI_GITEA_TOKEN")
|
||||||
|
if not token:
|
||||||
|
_log("No CI_GITEA_API_TOKEN or CI_GITEA_TOKEN set — skipping")
|
||||||
|
return 0
|
||||||
|
|
||||||
|
current_run_id = int(args.current_run_id)
|
||||||
|
|
||||||
|
_log(f"Listing running PR runs for {args.repo}...")
|
||||||
|
try:
|
||||||
|
runs = list_running_runs(args.repo, token, args.base_url)
|
||||||
|
except urllib.error.HTTPError as e:
|
||||||
|
if e.code in (_HTTP_NOT_FOUND, _HTTP_BAD_REQUEST):
|
||||||
|
_log(
|
||||||
|
f"Actions runs API not usable (HTTP {e.code}) — "
|
||||||
|
f"Gitea {args.base_url} may not support this endpoint or status filter. "
|
||||||
|
f"Skipping cancel-superseded (non-fatal)."
|
||||||
|
)
|
||||||
|
return 0
|
||||||
|
raise
|
||||||
|
_log(f"Found {len(runs)} running PR runs")
|
||||||
|
|
||||||
|
# Group by head_branch — only cancel runs for the SAME branch
|
||||||
|
# that are older than the current run
|
||||||
|
same_branch_runs = [
|
||||||
|
r
|
||||||
|
for r in runs
|
||||||
|
if r.get("head_branch") == args.head_branch
|
||||||
|
and int(r.get("id", 0)) != current_run_id
|
||||||
|
and int(r.get("id", 0)) < current_run_id
|
||||||
|
]
|
||||||
|
|
||||||
|
if not same_branch_runs:
|
||||||
|
_log(f"No superseded runs for branch {args.head_branch}")
|
||||||
|
return 0
|
||||||
|
|
||||||
|
_log(f"Found {len(same_branch_runs)} superseded run(s) for branch {args.head_branch}:")
|
||||||
|
for r in same_branch_runs:
|
||||||
|
run_id = r.get("id")
|
||||||
|
created = r.get("created_at", "?")
|
||||||
|
_log(f" Run #{run_id} (created: {created})")
|
||||||
|
|
||||||
|
if args.dry_run:
|
||||||
|
_log("[dry-run] Would cancel the above runs")
|
||||||
|
return 0
|
||||||
|
|
||||||
|
cancelled = 0
|
||||||
|
for r in same_branch_runs:
|
||||||
|
run_id = int(r["id"])
|
||||||
|
_log(f"Cancelling run #{run_id}...")
|
||||||
|
if cancel_run(args.repo, run_id, token, args.base_url):
|
||||||
|
cancelled += 1
|
||||||
|
_log(f" Cancelled run #{run_id}")
|
||||||
|
else:
|
||||||
|
_log(f" Failed to cancel run #{run_id}")
|
||||||
|
|
||||||
|
_log(f"Cancelled {cancelled}/{len(same_branch_runs)} superseded runs")
|
||||||
|
return 0
|
||||||
|
|
||||||
|
|
||||||
|
if __name__ == "__main__": # pragma: no cover
|
||||||
|
raise SystemExit(main())
|
||||||
@@ -285,6 +285,26 @@ def cli(
|
|||||||
click.echo("=" * 60, err=True)
|
click.echo("=" * 60, err=True)
|
||||||
for e in errors:
|
for e in errors:
|
||||||
click.echo(f" - {e}", err=True)
|
click.echo(f" - {e}", err=True)
|
||||||
|
|
||||||
|
# Remediation hints for the most common failure: PR title format
|
||||||
|
title_errors = [
|
||||||
|
e for e in errors if "PR title must follow format" in str(e) or "PR title task ID mismatch" in str(e)
|
||||||
|
]
|
||||||
|
if title_errors and pr_number is not None and repo is not None:
|
||||||
|
click.echo("", err=True)
|
||||||
|
click.echo("REMEDIATION:", err=True)
|
||||||
|
click.echo(
|
||||||
|
_(
|
||||||
|
" Fix the PR title with:\n"
|
||||||
|
" python3 -m devx.ci.fix_pr_title --repo {repo} --pr-number {pr}\n"
|
||||||
|
" Or manually set the PR title to: '{expected}'",
|
||||||
|
repo=repo,
|
||||||
|
pr=pr_number,
|
||||||
|
expected=f"{task_id}: <Vikunja task title>",
|
||||||
|
),
|
||||||
|
err=True,
|
||||||
|
)
|
||||||
|
|
||||||
raise click.ClickException(_("Pre-merge validation failed."))
|
raise click.ClickException(_("Pre-merge validation failed."))
|
||||||
|
|
||||||
click.echo("[pre-merge-check] All auto-merge preconditions satisfied.")
|
click.echo("[pre-merge-check] All auto-merge preconditions satisfied.")
|
||||||
|
|||||||
@@ -0,0 +1,163 @@
|
|||||||
|
"""Check that workflow jobs downloading artifacts depend on the uploading job.
|
||||||
|
|
||||||
|
This prevents the class of bug where a job downloads an artifact produced by
|
||||||
|
another job but does not declare that job in its ``needs`` list. When both
|
||||||
|
jobs run in parallel, the download fails because the artifact hasn't been
|
||||||
|
uploaded yet.
|
||||||
|
|
||||||
|
The check scans all workflow YAML files for:
|
||||||
|
- ``gitea-upload-artifact`` / ``actions/upload-artifact`` steps
|
||||||
|
- ``gitea-download-artifact`` / ``actions/download-artifact`` steps
|
||||||
|
|
||||||
|
For each download, it finds the job(s) that upload an artifact with a
|
||||||
|
matching name and verifies that at least one uploading job is in the
|
||||||
|
downloading job's ``needs`` list.
|
||||||
|
|
||||||
|
Artifact names with ``${{ ... }}`` expressions are matched literally
|
||||||
|
(both sides use the same expression, so they resolve to the same value
|
||||||
|
at runtime).
|
||||||
|
|
||||||
|
Usage::
|
||||||
|
|
||||||
|
python -m devx.ci.check_workflow_artifact_deps
|
||||||
|
python -m devx.ci.check_workflow_artifact_deps --workflow .gitea/workflows/ci.yml
|
||||||
|
|
||||||
|
Exit code 0 if all artifact dependencies are satisfied, 1 otherwise.
|
||||||
|
"""
|
||||||
|
|
||||||
|
from __future__ import annotations
|
||||||
|
|
||||||
|
import sys
|
||||||
|
from pathlib import Path
|
||||||
|
|
||||||
|
import click
|
||||||
|
import yaml
|
||||||
|
|
||||||
|
REPO_ROOT = Path.cwd()
|
||||||
|
WORKFLOWS_DIR = REPO_ROOT / ".gitea" / "workflows"
|
||||||
|
|
||||||
|
UPLOAD_ACTIONS = ("upload-artifact",)
|
||||||
|
DOWNLOAD_ACTIONS = ("download-artifact",)
|
||||||
|
|
||||||
|
|
||||||
|
def _is_artifact_action(uses: str, action_types: tuple[str, ...]) -> bool:
|
||||||
|
"""Check if a step's ``uses`` field references an artifact action."""
|
||||||
|
if not uses:
|
||||||
|
return False
|
||||||
|
uses_lower = uses.lower()
|
||||||
|
return any(action in uses_lower for action in action_types)
|
||||||
|
|
||||||
|
|
||||||
|
def _extract_artifact_info(workflow: dict) -> tuple[dict[str, list[str]], list[tuple[str, str, str]]]:
|
||||||
|
"""Extract artifact upload and download info from a workflow.
|
||||||
|
|
||||||
|
Returns:
|
||||||
|
uploads: Mapping of artifact_name → list of job names that upload it.
|
||||||
|
downloads: List of (job_name, artifact_name, step_name) tuples.
|
||||||
|
"""
|
||||||
|
uploads: dict[str, list[str]] = {}
|
||||||
|
downloads: list[tuple[str, str, str]] = []
|
||||||
|
|
||||||
|
jobs = workflow.get("jobs", {})
|
||||||
|
for job_name, job_def in jobs.items():
|
||||||
|
for step in job_def.get("steps", []):
|
||||||
|
uses = step.get("uses", "")
|
||||||
|
with_data = step.get("with", {})
|
||||||
|
artifact_name = with_data.get("name", "")
|
||||||
|
step_name = step.get("name", "")
|
||||||
|
|
||||||
|
if _is_artifact_action(uses, UPLOAD_ACTIONS):
|
||||||
|
if artifact_name:
|
||||||
|
uploads.setdefault(artifact_name, []).append(job_name)
|
||||||
|
elif _is_artifact_action(uses, DOWNLOAD_ACTIONS) and artifact_name:
|
||||||
|
downloads.append((job_name, artifact_name, step_name))
|
||||||
|
|
||||||
|
return uploads, downloads
|
||||||
|
|
||||||
|
|
||||||
|
def _check_workflow(filepath: Path) -> list[str]:
|
||||||
|
"""Check a single workflow file for missing artifact dependencies.
|
||||||
|
|
||||||
|
Returns a list of error messages (empty if all OK).
|
||||||
|
"""
|
||||||
|
errors: list[str] = []
|
||||||
|
content = filepath.read_text(encoding="utf-8")
|
||||||
|
try:
|
||||||
|
workflow = yaml.safe_load(content)
|
||||||
|
except yaml.YAMLError as exc:
|
||||||
|
return [f"{filepath}: cannot parse YAML: {exc}"]
|
||||||
|
|
||||||
|
if not isinstance(workflow, dict):
|
||||||
|
return [f"{filepath}: not a valid workflow (expected dict)"]
|
||||||
|
|
||||||
|
uploads, downloads = _extract_artifact_info(workflow)
|
||||||
|
jobs = workflow.get("jobs", {})
|
||||||
|
|
||||||
|
for dl_job, artifact_name, step_name in downloads:
|
||||||
|
uploading_jobs = uploads.get(artifact_name, [])
|
||||||
|
if not uploading_jobs:
|
||||||
|
# Artifact not uploaded in this workflow — may come from an
|
||||||
|
# external source (e.g., S3). Skip.
|
||||||
|
continue
|
||||||
|
|
||||||
|
dl_job_def = jobs.get(dl_job, {})
|
||||||
|
needs_raw = dl_job_def.get("needs", [])
|
||||||
|
needs = {needs_raw} if isinstance(needs_raw, str) else set(needs_raw or [])
|
||||||
|
|
||||||
|
# Check if any uploading job is in the download job's needs
|
||||||
|
if not any(uploader in needs for uploader in uploading_jobs):
|
||||||
|
# Check if the download step has continue-on-error: true
|
||||||
|
# (valid guard when the uploading job may be skipped due to
|
||||||
|
# Gitea Actions' needs skip behavior — the download will
|
||||||
|
# fail gracefully if the artifact doesn't exist).
|
||||||
|
dl_steps = dl_job_def.get("steps", [])
|
||||||
|
step_def = next((s for s in dl_steps if s.get("name", "") == step_name), {})
|
||||||
|
if step_def.get("continue-on-error") is True:
|
||||||
|
continue
|
||||||
|
|
||||||
|
uploaders_str = ", ".join(sorted(uploading_jobs))
|
||||||
|
errors.append(
|
||||||
|
f"{filepath.name}::{dl_job}: step '{step_name}' downloads "
|
||||||
|
f"artifact '{artifact_name}' produced by job(s) "
|
||||||
|
f"[{uploaders_str}] but none are in its 'needs' list "
|
||||||
|
f"(current needs: {sorted(needs) or 'none'}). "
|
||||||
|
f"Add the uploading job to 'needs' or guard the download "
|
||||||
|
f"with an if: condition checking the upload job's result."
|
||||||
|
)
|
||||||
|
|
||||||
|
return errors
|
||||||
|
|
||||||
|
|
||||||
|
@click.command()
|
||||||
|
@click.option(
|
||||||
|
"--workflow",
|
||||||
|
type=click.Path(exists=True, path_type=Path),
|
||||||
|
help="Check a specific workflow file (default: all in .gitea/workflows/).",
|
||||||
|
)
|
||||||
|
@click.option(
|
||||||
|
"--workflows-dir",
|
||||||
|
type=click.Path(exists=True, path_type=Path),
|
||||||
|
default=None,
|
||||||
|
help="Override the workflows directory (default: .gitea/workflows/).",
|
||||||
|
)
|
||||||
|
def main(workflow: Path | None, workflows_dir: Path | None) -> None:
|
||||||
|
"""Check that artifact download jobs depend on upload jobs."""
|
||||||
|
wdir = workflows_dir or WORKFLOWS_DIR
|
||||||
|
files = [workflow] if workflow else sorted(wdir.glob("*.yml"))
|
||||||
|
|
||||||
|
all_errors: list[str] = []
|
||||||
|
for f in files:
|
||||||
|
errors = _check_workflow(f)
|
||||||
|
all_errors.extend(errors)
|
||||||
|
|
||||||
|
if all_errors:
|
||||||
|
click.echo("[check-workflow-artifact-deps] FAIL: missing artifact dependencies found:")
|
||||||
|
for err in all_errors:
|
||||||
|
click.echo(f" - {err}")
|
||||||
|
sys.exit(1)
|
||||||
|
else:
|
||||||
|
click.echo("[check-workflow-artifact-deps] OK: all artifact downloads have upload jobs in needs.")
|
||||||
|
|
||||||
|
|
||||||
|
if __name__ == "__main__": # pragma: no cover
|
||||||
|
main()
|
||||||
@@ -0,0 +1,145 @@
|
|||||||
|
"""Check that workflow jobs using tofu state have a tofu-init step.
|
||||||
|
|
||||||
|
This prevents the class of bug where a job runs ``tofu output`` or calls
|
||||||
|
a script that uses tofu state without first running ``tofu init``,
|
||||||
|
causing "Required plugins are not installed" errors.
|
||||||
|
|
||||||
|
The check scans all workflow YAML files for jobs that:
|
||||||
|
- Call scripts that use ``tofu output`` (configurable via --state-scripts)
|
||||||
|
- Call ``tofu output`` directly
|
||||||
|
- Call ``tofu plan`` or ``tofu apply`` directly
|
||||||
|
|
||||||
|
For each such job, it verifies the same job has a ``tofu-init`` step,
|
||||||
|
either:
|
||||||
|
- Directly via ``tofu init`` in a step's run command
|
||||||
|
- Via ``create_staging_deployment.py --phase tofu-init``
|
||||||
|
- Via ``create_production_deployment.py --phase tofu-init``
|
||||||
|
|
||||||
|
Usage::
|
||||||
|
|
||||||
|
python -m devx.ci.check_workflow_tofu_init
|
||||||
|
python -m devx.ci.check_workflow_tofu_init --workflow .gitea/workflows/deploy.yml
|
||||||
|
|
||||||
|
Exit code 0 if all jobs have tofu-init, 1 otherwise.
|
||||||
|
"""
|
||||||
|
|
||||||
|
from __future__ import annotations
|
||||||
|
|
||||||
|
import sys
|
||||||
|
from pathlib import Path
|
||||||
|
|
||||||
|
import click
|
||||||
|
import yaml
|
||||||
|
|
||||||
|
REPO_ROOT = Path.cwd()
|
||||||
|
WORKFLOWS_DIR = REPO_ROOT / ".gitea" / "workflows"
|
||||||
|
|
||||||
|
# Scripts that call `tofu output`, `tofu plan`, or `tofu apply` internally.
|
||||||
|
# If a job calls any of these, it must have a tofu-init step.
|
||||||
|
# NOTE: destroy_orphans.py reads terraform.tfstate directly from disk
|
||||||
|
# (does not invoke `tofu output`), so it does NOT need tofu-init.
|
||||||
|
DEFAULT_TOFU_STATE_SCRIPTS: set[str] = {
|
||||||
|
"preflight_deploy.py",
|
||||||
|
}
|
||||||
|
|
||||||
|
# Commands that directly use tofu state (must be preceded by tofu init).
|
||||||
|
TOFU_STATE_COMMANDS = ("tofu output", "tofu plan", "tofu apply", "tofu show")
|
||||||
|
|
||||||
|
# Commands that initialize tofu (counted as tofu-init steps).
|
||||||
|
TOFU_INIT_COMMANDS = (
|
||||||
|
"tofu init",
|
||||||
|
"--phase tofu-init",
|
||||||
|
"tofu-init",
|
||||||
|
)
|
||||||
|
|
||||||
|
|
||||||
|
def _check_workflow(filepath: Path, state_scripts: set[str]) -> list[str]:
|
||||||
|
"""Check a single workflow file for missing tofu-init steps.
|
||||||
|
|
||||||
|
Returns a list of error messages (empty if all OK).
|
||||||
|
"""
|
||||||
|
errors: list[str] = []
|
||||||
|
content = filepath.read_text(encoding="utf-8")
|
||||||
|
try:
|
||||||
|
workflow = yaml.safe_load(content)
|
||||||
|
except yaml.YAMLError as exc:
|
||||||
|
return [f"{filepath}: cannot parse YAML: {exc}"]
|
||||||
|
|
||||||
|
jobs = workflow.get("jobs", {})
|
||||||
|
for job_name, job_def in jobs.items():
|
||||||
|
steps = job_def.get("steps", [])
|
||||||
|
if not steps:
|
||||||
|
continue
|
||||||
|
|
||||||
|
uses_tofu_state = False
|
||||||
|
has_tofu_init = False
|
||||||
|
|
||||||
|
for step in steps:
|
||||||
|
run_cmd = step.get("run", "")
|
||||||
|
if not run_cmd:
|
||||||
|
continue
|
||||||
|
# Check if this step uses tofu state
|
||||||
|
for script in state_scripts:
|
||||||
|
if script in run_cmd:
|
||||||
|
uses_tofu_state = True
|
||||||
|
for cmd in TOFU_STATE_COMMANDS:
|
||||||
|
if cmd in run_cmd:
|
||||||
|
uses_tofu_state = True
|
||||||
|
# Check if this step initializes tofu
|
||||||
|
for cmd in TOFU_INIT_COMMANDS:
|
||||||
|
if cmd in run_cmd:
|
||||||
|
has_tofu_init = True
|
||||||
|
|
||||||
|
if uses_tofu_state and not has_tofu_init:
|
||||||
|
errors.append(
|
||||||
|
f"{filepath.name}::{job_name}: uses tofu state "
|
||||||
|
f"(tofu output/plan/apply or {state_scripts}) "
|
||||||
|
f"but has no tofu-init step. Add a step running "
|
||||||
|
f"'create_*_deployment.py --phase tofu-init' before "
|
||||||
|
f"the first tofu state access."
|
||||||
|
)
|
||||||
|
|
||||||
|
return errors
|
||||||
|
|
||||||
|
|
||||||
|
@click.command()
|
||||||
|
@click.option(
|
||||||
|
"--workflow",
|
||||||
|
type=click.Path(exists=True, path_type=Path),
|
||||||
|
help="Check a specific workflow file (default: all in .gitea/workflows/).",
|
||||||
|
)
|
||||||
|
@click.option(
|
||||||
|
"--workflows-dir",
|
||||||
|
type=click.Path(exists=True, path_type=Path),
|
||||||
|
default=None,
|
||||||
|
help="Override the workflows directory (default: .gitea/workflows/).",
|
||||||
|
)
|
||||||
|
@click.option(
|
||||||
|
"--state-script",
|
||||||
|
"state_scripts",
|
||||||
|
multiple=True,
|
||||||
|
default=None,
|
||||||
|
help="Add a script name that uses tofu state (can be repeated). Overrides the default list if any are specified.",
|
||||||
|
)
|
||||||
|
def main(workflow: Path | None, workflows_dir: Path | None, state_scripts: tuple[str, ...]) -> None:
|
||||||
|
"""Check that workflow jobs using tofu state have a tofu-init step."""
|
||||||
|
scripts = set(state_scripts) if state_scripts else DEFAULT_TOFU_STATE_SCRIPTS
|
||||||
|
wdir = workflows_dir or WORKFLOWS_DIR
|
||||||
|
files = [workflow] if workflow else sorted(wdir.glob("*.yml"))
|
||||||
|
|
||||||
|
all_errors: list[str] = []
|
||||||
|
for f in files:
|
||||||
|
errors = _check_workflow(f, scripts)
|
||||||
|
all_errors.extend(errors)
|
||||||
|
|
||||||
|
if all_errors:
|
||||||
|
click.echo("[check-workflow-tofu-init] FAIL: missing tofu-init steps found:")
|
||||||
|
for err in all_errors:
|
||||||
|
click.echo(f" - {err}")
|
||||||
|
sys.exit(1)
|
||||||
|
else:
|
||||||
|
click.echo("[check-workflow-tofu-init] OK: all tofu-state jobs have tofu-init.")
|
||||||
|
|
||||||
|
|
||||||
|
if __name__ == "__main__": # pragma: no cover
|
||||||
|
main()
|
||||||
@@ -0,0 +1,127 @@
|
|||||||
|
#!/usr/bin/env python3
|
||||||
|
"""Auto-fix PR title to follow the ``{PREFIX}-N: <title>`` convention.
|
||||||
|
|
||||||
|
Reads the task ID from the branch name, fetches the Vikunja task title,
|
||||||
|
and updates the PR title via the Gitea API.
|
||||||
|
|
||||||
|
Exit codes:
|
||||||
|
0 = PR title updated (or already correct)
|
||||||
|
1 = Error (missing token, PR not found, etc.)
|
||||||
|
|
||||||
|
Usage::
|
||||||
|
|
||||||
|
python3 -m devx.ci.fix_pr_title --repo owner/repo --pr-number 123
|
||||||
|
python3 -m devx.ci.fix_pr_title --repo owner/repo --branch DEVX-256-fix-foo --pr-number 123
|
||||||
|
"""
|
||||||
|
|
||||||
|
from __future__ import annotations
|
||||||
|
|
||||||
|
import click
|
||||||
|
from dotenv import load_dotenv # pyright: ignore[reportMissingImports,reportUnknownVariableType]
|
||||||
|
|
||||||
|
from devx.api_clients import GiteaClient
|
||||||
|
from devx.ci.auto_merge import extract_task_id
|
||||||
|
from devx.ci.check_auto_merge_ready import get_vikunja_title_optional
|
||||||
|
from devx.config import (
|
||||||
|
GITEA_API_URL,
|
||||||
|
TASK_PREFIX,
|
||||||
|
)
|
||||||
|
from devx.exceptions import APIError
|
||||||
|
from devx.i18n import _
|
||||||
|
from devx.tokens import get_ci_token
|
||||||
|
|
||||||
|
load_dotenv()
|
||||||
|
|
||||||
|
|
||||||
|
@click.command()
|
||||||
|
@click.option("--repo", required=True, help=_("Repository in owner/name format"))
|
||||||
|
@click.option("--pr-number", type=int, required=True, help=_("PR number to fix"))
|
||||||
|
@click.option("--branch", default=None, help=_("Branch name (auto-fetched from PR if not given)"))
|
||||||
|
@click.option("--dry-run", is_flag=True, help=_("Show what would change without updating"))
|
||||||
|
def cli(repo: str, pr_number: int, branch: str | None, dry_run: bool) -> None:
|
||||||
|
"""Fix PR title to follow the ``{PREFIX}-N: <title>`` convention."""
|
||||||
|
if "/" not in repo:
|
||||||
|
raise click.ClickException(_("Repo must be in 'owner/name' format, got: {repo}", repo=repo))
|
||||||
|
owner, repo_name = repo.split("/", 1)
|
||||||
|
|
||||||
|
# 1. Get CI token
|
||||||
|
try:
|
||||||
|
token = get_ci_token()
|
||||||
|
except click.ClickException as exc:
|
||||||
|
raise click.ClickException(_("CI_GITEA_API_TOKEN not set: {error}", error=str(exc))) from exc
|
||||||
|
|
||||||
|
client = GiteaClient(GITEA_API_URL, token, owner, repo_name)
|
||||||
|
|
||||||
|
# 2. Fetch PR
|
||||||
|
try:
|
||||||
|
pr = client.get_pr(pr_number)
|
||||||
|
except APIError as exc:
|
||||||
|
raise click.ClickException(_("Failed to fetch PR #{pr}: {error}", pr=pr_number, error=str(exc))) from exc
|
||||||
|
|
||||||
|
current_title = str(pr.get("title", ""))
|
||||||
|
if not branch:
|
||||||
|
branch = str(pr.get("head", {}).get("ref", ""))
|
||||||
|
if not branch:
|
||||||
|
raise click.ClickException(_("Could not determine branch name from PR #{pr}", pr=pr_number))
|
||||||
|
|
||||||
|
click.echo(f"[fix-pr-title] Branch: {branch}")
|
||||||
|
click.echo(f"[fix-pr-title] Current PR title: {current_title}")
|
||||||
|
|
||||||
|
# 3. Extract task ID from branch
|
||||||
|
task_id = extract_task_id(branch)
|
||||||
|
if not task_id:
|
||||||
|
raise click.ClickException(
|
||||||
|
_(
|
||||||
|
"No task ID found in branch '{branch}'. Expected format: {prefix}-N-description.",
|
||||||
|
branch=branch,
|
||||||
|
prefix=TASK_PREFIX,
|
||||||
|
)
|
||||||
|
)
|
||||||
|
|
||||||
|
click.echo(f"[fix-pr-title] Task ID: {task_id}")
|
||||||
|
|
||||||
|
# 4. Get Vikunja task title
|
||||||
|
vikunja_title = get_vikunja_title_optional(task_id)
|
||||||
|
if vikunja_title is None:
|
||||||
|
# Fallback: strip common prefixes from current title
|
||||||
|
# (e.g. "fix: ...", "feat: ...", "refactor: ...")
|
||||||
|
import re
|
||||||
|
|
||||||
|
stripped = re.sub(
|
||||||
|
r"^(fix|feat|refactor|chore|docs|test|ci|build|perf|style|revert)(\(.+?\))?!?:\s*", "", current_title
|
||||||
|
)
|
||||||
|
# Also strip any leading task ID prefix
|
||||||
|
stripped = re.sub(rf"^{TASK_PREFIX}-\d+:\s*", "", stripped)
|
||||||
|
vikunja_title = stripped if stripped else current_title
|
||||||
|
click.echo(f"[fix-pr-title] WARNING: Vikunja task not found — using stripped title: {vikunja_title}")
|
||||||
|
else:
|
||||||
|
click.echo(f"[fix-pr-title] Vikunja title: {vikunja_title}")
|
||||||
|
|
||||||
|
# 5. Build new title
|
||||||
|
# Defensive: strip task ID prefix from Vikunja title if present
|
||||||
|
if vikunja_title.startswith(f"{task_id}:"):
|
||||||
|
vikunja_title = vikunja_title[len(f"{task_id}:") :].strip()
|
||||||
|
|
||||||
|
new_title = f"{task_id}: {vikunja_title}"
|
||||||
|
|
||||||
|
if current_title == new_title:
|
||||||
|
click.echo(f"[fix-pr-title] PR title already correct: {new_title}")
|
||||||
|
return
|
||||||
|
|
||||||
|
click.echo(f"[fix-pr-title] New PR title: {new_title}")
|
||||||
|
|
||||||
|
if dry_run:
|
||||||
|
click.echo("[fix-pr-title] Dry run — not updating PR.")
|
||||||
|
return
|
||||||
|
|
||||||
|
# 6. Update PR title
|
||||||
|
try:
|
||||||
|
client.update_pr(pr_number, {"title": new_title})
|
||||||
|
except APIError as exc:
|
||||||
|
raise click.ClickException(_("Failed to update PR #{pr}: {error}", pr=pr_number, error=str(exc))) from exc
|
||||||
|
|
||||||
|
click.echo(f"[fix-pr-title] PR #{pr_number} title updated to: {new_title}")
|
||||||
|
|
||||||
|
|
||||||
|
if __name__ == "__main__": # pragma: no cover
|
||||||
|
cli() # pragma: no cover
|
||||||
+37
-7
@@ -4,6 +4,10 @@
|
|||||||
Uses git-cliff to generate the release notes from conventional commits.
|
Uses git-cliff to generate the release notes from conventional commits.
|
||||||
Uses the ``tea`` Gitea CLI for release creation.
|
Uses the ``tea`` Gitea CLI for release creation.
|
||||||
|
|
||||||
|
Gitea release creation is retried up to 3 times with exponential backoff
|
||||||
|
(2s, 4s) to handle transient failures (network timeouts, 5xx errors).
|
||||||
|
If the release already exists, it is treated as success (idempotent).
|
||||||
|
|
||||||
Publishing destinations (checked in order):
|
Publishing destinations (checked in order):
|
||||||
1. **Gitea PyPI registry** — if ``--registry-url`` is given (or
|
1. **Gitea PyPI registry** — if ``--registry-url`` is given (or
|
||||||
``DEVX_PYPI_REGISTRY_URL`` env var is set, or ``GITEA_API_URL``
|
``DEVX_PYPI_REGISTRY_URL`` env var is set, or ``GITEA_API_URL``
|
||||||
@@ -27,6 +31,7 @@ from pathlib import Path
|
|||||||
|
|
||||||
import click
|
import click
|
||||||
from dotenv import load_dotenv # pyright: ignore[reportMissingImports,reportUnknownVariableType]
|
from dotenv import load_dotenv # pyright: ignore[reportMissingImports,reportUnknownVariableType]
|
||||||
|
from tenacity import retry, retry_if_exception_type, stop_after_attempt, wait_exponential
|
||||||
|
|
||||||
from devx.config import GITEA_API_URL, REPO_OWNER
|
from devx.config import GITEA_API_URL, REPO_OWNER
|
||||||
from devx.gitea_cli import TeaCLI, TeaCLIError, configure_tea_login
|
from devx.gitea_cli import TeaCLI, TeaCLIError, configure_tea_login
|
||||||
@@ -312,13 +317,7 @@ def main(
|
|||||||
|
|
||||||
release_body = generate_release_notes(tag)
|
release_body = generate_release_notes(tag)
|
||||||
|
|
||||||
try:
|
_create_release_with_retry(tea, repo, tag, release_body)
|
||||||
tea.create_release(repo, tag=tag, title=tag, body=release_body)
|
|
||||||
except TeaCLIError as e:
|
|
||||||
if "already" in str(e).lower() and "release" in str(e).lower():
|
|
||||||
click.echo(_("Gitea release {tag} already exists — skipping creation.", tag=tag))
|
|
||||||
return
|
|
||||||
raise click.ClickException(_("Release creation failed: {error}", error=str(e))) from None
|
|
||||||
|
|
||||||
click.echo(
|
click.echo(
|
||||||
_(
|
_(
|
||||||
@@ -328,5 +327,36 @@ def main(
|
|||||||
)
|
)
|
||||||
|
|
||||||
|
|
||||||
|
def _create_release_with_retry(tea: TeaCLI, repo: str, tag: str, release_body: str) -> None:
|
||||||
|
"""Create a Gitea release with retry for transient failures.
|
||||||
|
|
||||||
|
Retries up to 3 times with exponential backoff (2s, 4s) on TeaCLIError
|
||||||
|
unless the error indicates the release already exists (which is treated
|
||||||
|
as success). This handles transient issues like network timeouts, Gitea
|
||||||
|
rate limiting, or temporary 5xx errors that caused CI run #2822 to fail.
|
||||||
|
"""
|
||||||
|
|
||||||
|
@retry(
|
||||||
|
stop=stop_after_attempt(3),
|
||||||
|
wait=wait_exponential(multiplier=2, min=2, max=10),
|
||||||
|
retry=retry_if_exception_type(TeaCLIError),
|
||||||
|
reraise=True,
|
||||||
|
)
|
||||||
|
def _attempt() -> None:
|
||||||
|
try:
|
||||||
|
tea.create_release(repo, tag=tag, title=tag, body=release_body)
|
||||||
|
except TeaCLIError as e:
|
||||||
|
error_str = str(e).lower()
|
||||||
|
if "already" in error_str and "release" in error_str:
|
||||||
|
click.echo(_("Gitea release {tag} already exists — skipping creation.", tag=tag))
|
||||||
|
return
|
||||||
|
raise
|
||||||
|
|
||||||
|
try:
|
||||||
|
_attempt()
|
||||||
|
except TeaCLIError as e:
|
||||||
|
raise click.ClickException(_("Release creation failed: {error}", error=str(e))) from None
|
||||||
|
|
||||||
|
|
||||||
if __name__ == "__main__": # pragma: no cover
|
if __name__ == "__main__": # pragma: no cover
|
||||||
main()
|
main()
|
||||||
|
|||||||
@@ -252,7 +252,7 @@ def commit_and_push(wiki_dir: Path, wiki_url: str, dry_run: bool) -> bool:
|
|||||||
|
|
||||||
# Push
|
# Push
|
||||||
result = subprocess.run( # nosec
|
result = subprocess.run( # nosec
|
||||||
["git", "push", "--force", wiki_url, "HEAD:master"],
|
["git", "push", "--force", wiki_url, "HEAD:main"],
|
||||||
cwd=wiki_dir,
|
cwd=wiki_dir,
|
||||||
capture_output=True,
|
capture_output=True,
|
||||||
text=True,
|
text=True,
|
||||||
|
|||||||
@@ -172,6 +172,27 @@ def ci_integration_guard(args: tuple[str, ...]) -> None:
|
|||||||
_run_module("devx.ci.integration_guard", list(args))
|
_run_module("devx.ci.integration_guard", list(args))
|
||||||
|
|
||||||
|
|
||||||
|
@ci.command("cancel-superseded-runs")
|
||||||
|
@click.argument("args", nargs=-1)
|
||||||
|
def ci_cancel_superseded_runs(args: tuple[str, ...]) -> None:
|
||||||
|
"""Cancel superseded CI runs for the same PR branch."""
|
||||||
|
_run_module("devx.ci.cancel_superseded_runs", list(args))
|
||||||
|
|
||||||
|
|
||||||
|
@ci.command("check-workflow-artifact-deps")
|
||||||
|
@click.argument("args", nargs=-1)
|
||||||
|
def ci_check_workflow_artifact_deps(args: tuple[str, ...]) -> None:
|
||||||
|
"""Check that artifact download jobs depend on upload jobs."""
|
||||||
|
_run_module("devx.ci.check_workflow_artifact_deps", list(args))
|
||||||
|
|
||||||
|
|
||||||
|
@ci.command("check-workflow-tofu-init")
|
||||||
|
@click.argument("args", nargs=-1)
|
||||||
|
def ci_check_workflow_tofu_init(args: tuple[str, ...]) -> None:
|
||||||
|
"""Check that workflow jobs using tofu state have a tofu-init step."""
|
||||||
|
_run_module("devx.ci.check_workflow_tofu_init", list(args))
|
||||||
|
|
||||||
|
|
||||||
@cli.group()
|
@cli.group()
|
||||||
def tools() -> None:
|
def tools() -> None:
|
||||||
"""Development tool commands."""
|
"""Development tool commands."""
|
||||||
@@ -240,6 +261,27 @@ def tools_pr_rebase(args: tuple[str, ...]) -> None:
|
|||||||
_run_module("devx.tools.pr_rebase", list(args))
|
_run_module("devx.tools.pr_rebase", list(args))
|
||||||
|
|
||||||
|
|
||||||
|
@tools.command("check-docker-init")
|
||||||
|
@click.argument("args", nargs=-1)
|
||||||
|
def tools_check_docker_init(args: tuple[str, ...]) -> None:
|
||||||
|
"""Check that Docker Compose services with healthchecks have init: true."""
|
||||||
|
_run_module("devx.tools.check_docker_init", list(args))
|
||||||
|
|
||||||
|
|
||||||
|
@tools.command("check-ansible-set-fact-to-json")
|
||||||
|
@click.argument("args", nargs=-1)
|
||||||
|
def tools_check_ansible_set_fact_to_json(args: tuple[str, ...]) -> None:
|
||||||
|
"""Check that Ansible set_fact tasks don't misuse to_json."""
|
||||||
|
_run_module("devx.tools.check_ansible_set_fact_to_json", list(args))
|
||||||
|
|
||||||
|
|
||||||
|
@tools.command("check-alert-rules")
|
||||||
|
@click.argument("args", nargs=-1)
|
||||||
|
def tools_check_alert_rules(args: tuple[str, ...]) -> None:
|
||||||
|
"""Validate rendered Prometheus alert rules with promtool."""
|
||||||
|
_run_module("devx.tools.check_alert_rules", list(args))
|
||||||
|
|
||||||
|
|
||||||
@cli.group()
|
@cli.group()
|
||||||
def molecule() -> None:
|
def molecule() -> None:
|
||||||
"""Molecule testing commands (requires devx[molecule])."""
|
"""Molecule testing commands (requires devx[molecule])."""
|
||||||
|
|||||||
+78
-17
@@ -40,27 +40,46 @@ Usage::
|
|||||||
from __future__ import annotations
|
from __future__ import annotations
|
||||||
|
|
||||||
import json
|
import json
|
||||||
|
import logging
|
||||||
import shutil
|
import shutil
|
||||||
import subprocess # nosec B404
|
import subprocess # nosec B404
|
||||||
from typing import Any
|
from typing import Any
|
||||||
|
|
||||||
import click
|
import click
|
||||||
|
from tenacity import (
|
||||||
|
before_sleep_log,
|
||||||
|
retry,
|
||||||
|
retry_if_exception_type,
|
||||||
|
stop_after_attempt,
|
||||||
|
wait_exponential,
|
||||||
|
)
|
||||||
|
|
||||||
from devx.config import GITEA_API_URL
|
from devx.config import GITEA_API_URL, MAX_RETRIES, RETRY_BACKOFF_BASE, RETRY_STATUS_CODES
|
||||||
from devx.i18n import _
|
from devx.i18n import _
|
||||||
from devx.tokens import get_ci_token
|
from devx.tokens import get_ci_token
|
||||||
|
|
||||||
|
logger = logging.getLogger("gitea_cli")
|
||||||
|
|
||||||
|
|
||||||
class TeaCLIError(Exception):
|
class TeaCLIError(Exception):
|
||||||
"""Raised when a tea CLI command fails."""
|
"""Raised when a tea CLI command fails."""
|
||||||
|
|
||||||
|
|
||||||
|
class _TransientTeaError(TeaCLIError):
|
||||||
|
"""Tea CLI error caused by a transient HTTP status (502/503/504/429)."""
|
||||||
|
|
||||||
|
|
||||||
def configure_tea_login(login_name: str = "devx") -> None:
|
def configure_tea_login(login_name: str = "devx") -> None:
|
||||||
"""Configure tea CLI login from CI_GITEA_API_TOKEN and DEVX_GITEA_API_URL.
|
"""Configure tea CLI login from CI_GITEA_API_TOKEN and DEVX_GITEA_API_URL.
|
||||||
|
|
||||||
Idempotent: if a login with the same name already exists, it is not re-added.
|
Idempotent: if a login with the same name already exists, it is not re-added.
|
||||||
Skips silently if tea is not installed or no token is set.
|
Skips silently if tea is not installed or no token is set.
|
||||||
|
|
||||||
|
Raises ``TeaCLIError`` if the login add or default command fails. This is
|
||||||
|
critical because subsequent tea commands (e.g. ``releases create``) will
|
||||||
|
fail with a cryptic "no available login" error if the login was not
|
||||||
|
configured successfully.
|
||||||
|
|
||||||
Used by CI scripts (publish, notify_failure) that need tea login but
|
Used by CI scripts (publish, notify_failure) that need tea login but
|
||||||
run in containerized environments where ``make setup`` was not called.
|
run in containerized environments where ``make setup`` was not called.
|
||||||
"""
|
"""
|
||||||
@@ -88,18 +107,31 @@ def configure_tea_login(login_name: str = "devx") -> None:
|
|||||||
return
|
return
|
||||||
|
|
||||||
click.echo(_("Configuring tea login '{name}' for {url}...", name=login_name, url=gitea_url))
|
click.echo(_("Configuring tea login '{name}' for {url}...", name=login_name, url=gitea_url))
|
||||||
subprocess.run( # nosec B603
|
add_result = subprocess.run( # nosec B603
|
||||||
[tea_bin, "login", "add", "--name", login_name, "--url", gitea_url, "--token", token],
|
[tea_bin, "login", "add", "--name", login_name, "--url", gitea_url, "--token", token],
|
||||||
capture_output=True,
|
capture_output=True,
|
||||||
text=True,
|
text=True,
|
||||||
check=False,
|
check=False,
|
||||||
)
|
)
|
||||||
subprocess.run( # nosec B603
|
if add_result.returncode != 0:
|
||||||
|
raise TeaCLIError(
|
||||||
|
f"tea login add failed (rc={add_result.returncode})\n"
|
||||||
|
f"stdout: {add_result.stdout.strip()}\n"
|
||||||
|
f"stderr: {add_result.stderr.strip()}"
|
||||||
|
)
|
||||||
|
|
||||||
|
default_result = subprocess.run( # nosec B603
|
||||||
[tea_bin, "login", "default", login_name],
|
[tea_bin, "login", "default", login_name],
|
||||||
capture_output=True,
|
capture_output=True,
|
||||||
text=True,
|
text=True,
|
||||||
check=False,
|
check=False,
|
||||||
)
|
)
|
||||||
|
if default_result.returncode != 0:
|
||||||
|
raise TeaCLIError(
|
||||||
|
f"tea login default failed (rc={default_result.returncode})\n"
|
||||||
|
f"stdout: {default_result.stdout.strip()}\n"
|
||||||
|
f"stderr: {default_result.stderr.strip()}"
|
||||||
|
)
|
||||||
|
|
||||||
|
|
||||||
class TeaCLI:
|
class TeaCLI:
|
||||||
@@ -122,6 +154,10 @@ class TeaCLI:
|
|||||||
def _run(self, args: list[str], json_output: bool = True) -> str:
|
def _run(self, args: list[str], json_output: bool = True) -> str:
|
||||||
"""Run a tea command and return stdout.
|
"""Run a tea command and return stdout.
|
||||||
|
|
||||||
|
Retries up to ``MAX_RETRIES`` times on transient HTTP errors
|
||||||
|
(502/503/504/429) detected in stderr/stdout, with exponential
|
||||||
|
backoff. Non-transient errors fail immediately.
|
||||||
|
|
||||||
Args:
|
Args:
|
||||||
args: Command arguments (without the leading ``tea``).
|
args: Command arguments (without the leading ``tea``).
|
||||||
json_output: If True, append ``--output json`` to the command.
|
json_output: If True, append ``--output json`` to the command.
|
||||||
@@ -130,25 +166,50 @@ class TeaCLI:
|
|||||||
stdout as a string.
|
stdout as a string.
|
||||||
|
|
||||||
Raises:
|
Raises:
|
||||||
TeaCLIError: If the command fails.
|
TeaCLIError: If the command fails after retries are exhausted.
|
||||||
"""
|
"""
|
||||||
cmd = [self._tea, *args]
|
cmd = [self._tea, *args]
|
||||||
if json_output:
|
if json_output:
|
||||||
cmd.extend(["--output", "json"])
|
cmd.extend(["--output", "json"])
|
||||||
|
|
||||||
|
def _execute() -> str:
|
||||||
|
try:
|
||||||
|
result = subprocess.run( # nosec B603
|
||||||
|
cmd,
|
||||||
|
capture_output=True,
|
||||||
|
text=True,
|
||||||
|
check=False,
|
||||||
|
)
|
||||||
|
except FileNotFoundError as e:
|
||||||
|
raise TeaCLIError(f"tea binary not found ('{self._tea}'). Install tea or add it to PATH.") from e
|
||||||
|
if result.returncode != 0:
|
||||||
|
parts = [
|
||||||
|
f"tea command failed (rc={result.returncode}): {' '.join(args)}",
|
||||||
|
f"stdout: {result.stdout.strip()}" if result.stdout.strip() else "",
|
||||||
|
f"stderr: {result.stderr.strip()}" if result.stderr.strip() else "",
|
||||||
|
]
|
||||||
|
msg = "\n".join(p for p in parts if p)
|
||||||
|
combined = f"{result.stdout} {result.stderr}".lower()
|
||||||
|
if any(str(code) in combined for code in RETRY_STATUS_CODES):
|
||||||
|
raise _TransientTeaError(msg)
|
||||||
|
raise TeaCLIError(msg)
|
||||||
|
return result.stdout.strip()
|
||||||
|
|
||||||
|
retry_decorator = retry(
|
||||||
|
stop=stop_after_attempt(MAX_RETRIES),
|
||||||
|
wait=wait_exponential(
|
||||||
|
multiplier=RETRY_BACKOFF_BASE,
|
||||||
|
min=RETRY_BACKOFF_BASE,
|
||||||
|
max=RETRY_BACKOFF_BASE**MAX_RETRIES,
|
||||||
|
),
|
||||||
|
retry=retry_if_exception_type(_TransientTeaError),
|
||||||
|
before_sleep=before_sleep_log(logger, logging.WARNING),
|
||||||
|
reraise=True,
|
||||||
|
)
|
||||||
try:
|
try:
|
||||||
result = subprocess.run( # nosec B603
|
return retry_decorator(_execute)()
|
||||||
cmd,
|
except _TransientTeaError as e:
|
||||||
capture_output=True,
|
raise TeaCLIError(str(e)) from e
|
||||||
text=True,
|
|
||||||
check=False,
|
|
||||||
)
|
|
||||||
except FileNotFoundError as e:
|
|
||||||
raise TeaCLIError(f"tea binary not found ('{self._tea}'). Install tea or add it to PATH.") from e
|
|
||||||
if result.returncode != 0:
|
|
||||||
raise TeaCLIError(
|
|
||||||
f"tea command failed (rc={result.returncode}): {' '.join(args)}\nstderr: {result.stderr.strip()}"
|
|
||||||
)
|
|
||||||
return result.stdout.strip()
|
|
||||||
|
|
||||||
def _run_raw(self, args: list[str]) -> str:
|
def _run_raw(self, args: list[str]) -> str:
|
||||||
"""Run a tea command without JSON output and return stdout."""
|
"""Run a tea command without JSON output and return stdout."""
|
||||||
|
|||||||
+34
-5
@@ -6,6 +6,10 @@ Supported: en, bg, de, ru, zh, pl.
|
|||||||
Projects can extend translations by setting DEVX_TRANSLATIONS_PATH to a
|
Projects can extend translations by setting DEVX_TRANSLATIONS_PATH to a
|
||||||
JSON file with additional keys. Keys from the project's file are merged
|
JSON file with additional keys. Keys from the project's file are merged
|
||||||
on top of devx's built-in translations.
|
on top of devx's built-in translations.
|
||||||
|
|
||||||
|
Projects that use different env var names (e.g. GRM_LANG instead of
|
||||||
|
DEVX_LANG) can call :func:`configure_i18n` at import time to override
|
||||||
|
the defaults.
|
||||||
"""
|
"""
|
||||||
|
|
||||||
from __future__ import annotations
|
from __future__ import annotations
|
||||||
@@ -14,15 +18,39 @@ import json
|
|||||||
import os
|
import os
|
||||||
from pathlib import Path
|
from pathlib import Path
|
||||||
|
|
||||||
|
# Configurable env var names — projects can override via configure_i18n()
|
||||||
|
_lang_env_var = "DEVX_LANG"
|
||||||
|
_translations_path_env_var = "DEVX_TRANSLATIONS_PATH"
|
||||||
|
|
||||||
# Load built-in translations
|
# Load built-in translations
|
||||||
_BUILTIN_TRANSLATIONS: dict[str, dict[str, str]] = json.loads(
|
_BUILTIN_TRANSLATIONS: dict[str, dict[str, str]] = json.loads(
|
||||||
(Path(__file__).parent / "translations.json").read_text(encoding="utf-8")
|
(Path(__file__).parent / "translations.json").read_text(encoding="utf-8")
|
||||||
)
|
)
|
||||||
|
|
||||||
|
|
||||||
|
def configure_i18n(
|
||||||
|
*,
|
||||||
|
lang_env_var: str = "DEVX_LANG",
|
||||||
|
translations_path_env_var: str = "DEVX_TRANSLATIONS_PATH",
|
||||||
|
) -> None:
|
||||||
|
"""Override the env var names used for language and translations path.
|
||||||
|
|
||||||
|
This allows downstream projects (e.g. grm) to use their own env var
|
||||||
|
names (e.g. ``GRM_LANG``) while still using devx's i18n system.
|
||||||
|
|
||||||
|
Args:
|
||||||
|
lang_env_var: Environment variable name for language selection.
|
||||||
|
translations_path_env_var: Environment variable name for the
|
||||||
|
path to a JSON file with project-specific translations.
|
||||||
|
"""
|
||||||
|
global _lang_env_var, _translations_path_env_var
|
||||||
|
_lang_env_var = lang_env_var
|
||||||
|
_translations_path_env_var = translations_path_env_var
|
||||||
|
|
||||||
|
|
||||||
def _load_project_translations() -> dict[str, dict[str, str]]:
|
def _load_project_translations() -> dict[str, dict[str, str]]:
|
||||||
"""Load project-specific translations from DEVX_TRANSLATIONS_PATH if set."""
|
"""Load project-specific translations from the configured env var if set."""
|
||||||
path = os.getenv("DEVX_TRANSLATIONS_PATH")
|
path = os.getenv(_translations_path_env_var)
|
||||||
if not path:
|
if not path:
|
||||||
return {}
|
return {}
|
||||||
p = Path(path)
|
p = Path(path)
|
||||||
@@ -41,10 +69,11 @@ TRANSLATIONS: dict[str, dict[str, str]] = {**_BUILTIN_TRANSLATIONS, **_load_proj
|
|||||||
def _(key: str, **kwargs: object) -> str:
|
def _(key: str, **kwargs: object) -> str:
|
||||||
"""Return a translated string for the given key.
|
"""Return a translated string for the given key.
|
||||||
|
|
||||||
Translation is opt-in via the ``DEVX_LANG`` environment variable.
|
Translation is opt-in via the configured language environment variable
|
||||||
If unset, English is always returned regardless of system locale.
|
(default ``DEVX_LANG``). If unset, English is always returned regardless
|
||||||
|
of system locale.
|
||||||
"""
|
"""
|
||||||
lang = os.getenv("DEVX_LANG", "en")
|
lang = os.getenv(_lang_env_var, "en")
|
||||||
if lang not in ("en", "bg", "de", "ru", "zh", "pl"):
|
if lang not in ("en", "bg", "de", "ru", "zh", "pl"):
|
||||||
lang = "en"
|
lang = "en"
|
||||||
template = TRANSLATIONS.get(key, {}).get(lang, key)
|
template = TRANSLATIONS.get(key, {}).get(lang, key)
|
||||||
|
|||||||
@@ -309,7 +309,7 @@ devx-lint: devx-lint-ruff devx-lint-format devx-typecheck devx-lint-bandit devx-
|
|||||||
# ── Testing ───────────────────────────────────────────────────────────────────
|
# ── Testing ───────────────────────────────────────────────────────────────────
|
||||||
|
|
||||||
devx-test-unit:
|
devx-test-unit:
|
||||||
@$(DEVX_BIN)/pytest $(DEVX_TEST_PATHS) -q --no-cov
|
@$(DEVX_BIN)/pytest $(DEVX_TEST_PATHS) -q --no-cov -n 8
|
||||||
|
|
||||||
devx-pytest-cov:
|
devx-pytest-cov:
|
||||||
@$(DEVX_BIN)/pytest $(DEVX_TEST_PATHS) -n auto --cov=$(DEVX_COV_PKG) --cov-report=term-missing --cov-fail-under=100
|
@$(DEVX_BIN)/pytest $(DEVX_TEST_PATHS) -n auto --cov=$(DEVX_COV_PKG) --cov-report=term-missing --cov-fail-under=100
|
||||||
|
|||||||
@@ -104,21 +104,36 @@ def discover_scenarios(root: Path | None = None) -> list[str]:
|
|||||||
return sorted(scenarios)
|
return sorted(scenarios)
|
||||||
|
|
||||||
|
|
||||||
def discover_multi_role_scenarios(roles_root: Path | None = None) -> list[tuple[str, str]]:
|
def discover_multi_role_scenarios(
|
||||||
|
roles_root: Path | None = None,
|
||||||
|
include_roles: list[str] | None = None,
|
||||||
|
exclude_roles: list[str] | None = None,
|
||||||
|
) -> list[tuple[str, str]]:
|
||||||
"""Discover (role, scenario) pairs across all roles under *roles_root*.
|
"""Discover (role, scenario) pairs across all roles under *roles_root*.
|
||||||
|
|
||||||
Scans ``roles_root/*/molecule/*/`` for scenario directories, skipping
|
Scans ``roles_root/*/molecule/*/`` for scenario directories, skipping
|
||||||
``common`` and directories starting with ``_``. Returns a sorted list of
|
``common`` and directories starting with ``_``. Returns a sorted list of
|
||||||
``(role_name, scenario_name)`` tuples.
|
``(role_name, scenario_name)`` tuples.
|
||||||
|
|
||||||
|
If *include_roles* is given, only roles whose name is in the list are
|
||||||
|
returned. If *exclude_roles* is given, roles whose name is in the list
|
||||||
|
are skipped. Both filters are case-insensitive.
|
||||||
"""
|
"""
|
||||||
if roles_root is None:
|
if roles_root is None:
|
||||||
roles_root = DEFAULT_ROLES_ROOT
|
roles_root = DEFAULT_ROLES_ROOT
|
||||||
if not roles_root.is_dir():
|
if not roles_root.is_dir():
|
||||||
raise click.ClickException(_("Roles directory not found: {path}", path=str(roles_root)))
|
raise click.ClickException(_("Roles directory not found: {path}", path=str(roles_root)))
|
||||||
|
include_set = {r.lower() for r in include_roles} if include_roles else None
|
||||||
|
exclude_set = {r.lower() for r in exclude_roles} if exclude_roles else None
|
||||||
pairs: list[tuple[str, str]] = []
|
pairs: list[tuple[str, str]] = []
|
||||||
for role_dir in sorted(roles_root.iterdir()):
|
for role_dir in sorted(roles_root.iterdir()):
|
||||||
if not role_dir.is_dir():
|
if not role_dir.is_dir():
|
||||||
continue
|
continue
|
||||||
|
role_name = role_dir.name
|
||||||
|
if include_set is not None and role_name.lower() not in include_set:
|
||||||
|
continue
|
||||||
|
if exclude_set is not None and role_name.lower() in exclude_set:
|
||||||
|
continue
|
||||||
mol_dir = role_dir / "molecule"
|
mol_dir = role_dir / "molecule"
|
||||||
if not mol_dir.is_dir():
|
if not mol_dir.is_dir():
|
||||||
continue
|
continue
|
||||||
@@ -348,6 +363,24 @@ def _write_github_env(key: str, value: str) -> None:
|
|||||||
help="JSON file with custom platform list (each entry: name, image, command). "
|
help="JSON file with custom platform list (each entry: name, image, command). "
|
||||||
"Overrides the default platform matrix. Useful for projects with custom test images.",
|
"Overrides the default platform matrix. Useful for projects with custom test images.",
|
||||||
)
|
)
|
||||||
|
@click.option(
|
||||||
|
"--include-roles",
|
||||||
|
"include_roles",
|
||||||
|
type=str,
|
||||||
|
default=None,
|
||||||
|
help="Comma-separated list of role names to include (multi-role mode only). "
|
||||||
|
"Only scenarios from these roles are distributed. Case-insensitive. "
|
||||||
|
"Example: --include-roles docker_base,crowdsec,disk_cleanup,app_hardening",
|
||||||
|
)
|
||||||
|
@click.option(
|
||||||
|
"--exclude-roles",
|
||||||
|
"exclude_roles",
|
||||||
|
type=str,
|
||||||
|
default=None,
|
||||||
|
help="Comma-separated list of role names to exclude (multi-role mode only). "
|
||||||
|
"Scenarios from these roles are skipped. Case-insensitive. "
|
||||||
|
"Example: --exclude-roles docker_base,crowdsec,disk_cleanup,app_hardening",
|
||||||
|
)
|
||||||
def cli(
|
def cli(
|
||||||
runner_index: int | None,
|
runner_index: int | None,
|
||||||
max_runners: int,
|
max_runners: int,
|
||||||
@@ -358,11 +391,18 @@ def cli(
|
|||||||
molecule_root: Path | None,
|
molecule_root: Path | None,
|
||||||
roles_root: Path | None,
|
roles_root: Path | None,
|
||||||
platforms_file: Path | None,
|
platforms_file: Path | None,
|
||||||
|
include_roles: str | None,
|
||||||
|
exclude_roles: str | None,
|
||||||
) -> None:
|
) -> None:
|
||||||
platforms = load_platforms(platforms_file)
|
platforms = load_platforms(platforms_file)
|
||||||
|
# Parse role filters
|
||||||
|
include_list = [r.strip() for r in include_roles.split(",")] if include_roles else None
|
||||||
|
exclude_list = [r.strip() for r in exclude_roles.split(",")] if exclude_roles else None
|
||||||
# Multi-role mode: discover (role, scenario) pairs across all roles
|
# Multi-role mode: discover (role, scenario) pairs across all roles
|
||||||
if roles_root is not None:
|
if roles_root is not None:
|
||||||
role_scenarios = discover_multi_role_scenarios(roles_root)
|
role_scenarios = discover_multi_role_scenarios(
|
||||||
|
roles_root, include_roles=include_list, exclude_roles=exclude_list
|
||||||
|
)
|
||||||
if list_all:
|
if list_all:
|
||||||
for role, scenario in role_scenarios:
|
for role, scenario in role_scenarios:
|
||||||
click.echo(f"{role}|{scenario}")
|
click.echo(f"{role}|{scenario}")
|
||||||
|
|||||||
@@ -125,6 +125,11 @@ def build_env_for_pair(pair: str, base_env: dict[str, str]) -> dict[str, str]:
|
|||||||
"""Build environment for a single molecule pair."""
|
"""Build environment for a single molecule pair."""
|
||||||
_role, _scenario, platform_name, platform_image, platform_command = parse_pair(pair)
|
_role, _scenario, platform_name, platform_image, platform_command = parse_pair(pair)
|
||||||
env = base_env.copy()
|
env = base_env.copy()
|
||||||
|
# Append runner index to platform name when running in CI matrix to avoid
|
||||||
|
# Docker container name conflicts when multiple runners share the same Docker host.
|
||||||
|
matrix_index = env.get("MATRIX_INDEX")
|
||||||
|
if matrix_index:
|
||||||
|
platform_name = f"{platform_name}-r{matrix_index}"
|
||||||
env["MOLECULE_PLATFORM_NAME"] = platform_name
|
env["MOLECULE_PLATFORM_NAME"] = platform_name
|
||||||
env["MOLECULE_PLATFORM_IMAGE"] = platform_image
|
env["MOLECULE_PLATFORM_IMAGE"] = platform_image
|
||||||
if platform_command:
|
if platform_command:
|
||||||
@@ -246,18 +251,62 @@ def cli(pairs: tuple[str, ...], roles_root: Path | None) -> None:
|
|||||||
with contextlib.suppress(ProcessLookupError):
|
with contextlib.suppress(ProcessLookupError):
|
||||||
os.killpg(os.getpgid(process.pid), signal.SIGKILL)
|
os.killpg(os.getpgid(process.pid), signal.SIGKILL)
|
||||||
process.wait()
|
process.wait()
|
||||||
|
# Clean up containers left behind by the killed test.
|
||||||
|
click.echo(_("Cleaning up: running molecule destroy for {scenario}", scenario=scenario))
|
||||||
|
destroy_cmd = ["molecule", "destroy"]
|
||||||
|
if scenario != "default":
|
||||||
|
destroy_cmd.extend(["-s", scenario])
|
||||||
|
with contextlib.suppress(subprocess.SubprocessError, OSError):
|
||||||
|
subprocess.run( # nosec B603, B607
|
||||||
|
destroy_cmd,
|
||||||
|
cwd=str(cwd),
|
||||||
|
env=env,
|
||||||
|
check=False,
|
||||||
|
capture_output=True,
|
||||||
|
timeout=120,
|
||||||
|
)
|
||||||
sys.exit(1)
|
sys.exit(1)
|
||||||
time.sleep(1)
|
time.sleep(1)
|
||||||
except KeyboardInterrupt:
|
except KeyboardInterrupt:
|
||||||
with contextlib.suppress(ProcessLookupError):
|
with contextlib.suppress(ProcessLookupError):
|
||||||
os.killpg(os.getpgid(process.pid), signal.SIGTERM)
|
os.killpg(os.getpgid(process.pid), signal.SIGTERM)
|
||||||
process.wait()
|
process.wait()
|
||||||
|
# Clean up containers left behind by the interrupted test.
|
||||||
|
click.echo(_("Cleaning up: running molecule destroy for {scenario}", scenario=scenario))
|
||||||
|
destroy_cmd = ["molecule", "destroy"]
|
||||||
|
if scenario != "default":
|
||||||
|
destroy_cmd.extend(["-s", scenario])
|
||||||
|
with contextlib.suppress(subprocess.SubprocessError, OSError):
|
||||||
|
subprocess.run( # nosec B603, B607
|
||||||
|
destroy_cmd,
|
||||||
|
cwd=str(cwd),
|
||||||
|
env=env,
|
||||||
|
check=False,
|
||||||
|
capture_output=True,
|
||||||
|
timeout=120,
|
||||||
|
)
|
||||||
sys.exit(1)
|
sys.exit(1)
|
||||||
|
|
||||||
rc = process.returncode
|
rc = process.returncode
|
||||||
|
|
||||||
if rc != 0:
|
if rc != 0:
|
||||||
click.echo(_("FAILED: {pair} exited with code {code}", pair=pair, code=rc))
|
click.echo(_("FAILED: {pair} exited with code {code}", pair=pair, code=rc))
|
||||||
|
# Run molecule destroy to clean up containers left behind by the
|
||||||
|
# failed test. Without this, containers stay running and accumulate
|
||||||
|
# on the runner, consuming disk/memory and degrading CI performance.
|
||||||
|
click.echo(_("Cleaning up: running molecule destroy for {scenario}", scenario=scenario))
|
||||||
|
destroy_cmd = ["molecule", "destroy"]
|
||||||
|
if scenario != "default":
|
||||||
|
destroy_cmd.extend(["-s", scenario])
|
||||||
|
with contextlib.suppress(subprocess.SubprocessError, OSError):
|
||||||
|
subprocess.run( # nosec B603, B607
|
||||||
|
destroy_cmd,
|
||||||
|
cwd=str(cwd),
|
||||||
|
env=env,
|
||||||
|
check=False,
|
||||||
|
capture_output=True,
|
||||||
|
timeout=120,
|
||||||
|
)
|
||||||
sys.exit(rc)
|
sys.exit(rc)
|
||||||
|
|
||||||
click.echo(_("PASSED: {pair}", pair=pair))
|
click.echo(_("PASSED: {pair}", pair=pair))
|
||||||
|
|||||||
@@ -174,9 +174,12 @@ def build_image(
|
|||||||
return True
|
return True
|
||||||
|
|
||||||
click.echo(f"Building {spec.name} ({len(full_tags)} tag(s))...")
|
click.echo(f"Building {spec.name} ({len(full_tags)} tag(s))...")
|
||||||
|
# Use legacy builder (DOCKER_BUILDKIT=0) to avoid OCI-format manifest
|
||||||
|
# blobs (attestation, config) that the Gitea registry rejects with 403.
|
||||||
result = subprocess.run( # nosec B603
|
result = subprocess.run( # nosec B603
|
||||||
cmd,
|
cmd,
|
||||||
check=False,
|
check=False,
|
||||||
|
env={**os.environ, "DOCKER_BUILDKIT": "0"},
|
||||||
)
|
)
|
||||||
if result.returncode != 0:
|
if result.returncode != 0:
|
||||||
click.echo(_("Build failed for {name}", name=spec.name), err=True)
|
click.echo(_("Build failed for {name}", name=spec.name), err=True)
|
||||||
|
|||||||
@@ -0,0 +1,86 @@
|
|||||||
|
"""Validate Prometheus alert rules with promtool check rules.
|
||||||
|
|
||||||
|
Renders an alert-rules Jinja2 template with test values and validates
|
||||||
|
the output with ``promtool check rules``. Exits 0 if valid, non-zero
|
||||||
|
otherwise. Skips (exits 0) if promtool is not on PATH.
|
||||||
|
|
||||||
|
Usage::
|
||||||
|
|
||||||
|
python -m devx.tools.check_alert_rules \\
|
||||||
|
--template-path ansible/roles/observability/templates \\
|
||||||
|
--template-name alert-rules.yml.j2
|
||||||
|
|
||||||
|
# With extra template variables:
|
||||||
|
python -m devx.tools.check_alert_rules \\
|
||||||
|
--template-path ansible/roles/observability/templates \\
|
||||||
|
--template-name alert-rules.yml.j2 \\
|
||||||
|
--var grafana_base_url=https://grafana.test.example.com
|
||||||
|
"""
|
||||||
|
|
||||||
|
from __future__ import annotations
|
||||||
|
|
||||||
|
import shutil
|
||||||
|
import subprocess # nosec B404 — used to run promtool, a trusted binary
|
||||||
|
import sys
|
||||||
|
import tempfile
|
||||||
|
from pathlib import Path
|
||||||
|
|
||||||
|
import click
|
||||||
|
|
||||||
|
from devx.utils.jinja import make_env, render_template
|
||||||
|
|
||||||
|
|
||||||
|
@click.command()
|
||||||
|
@click.option(
|
||||||
|
"--template-path",
|
||||||
|
type=click.Path(exists=True, path_type=Path),
|
||||||
|
required=True,
|
||||||
|
help="Path to the directory containing the Jinja2 template.",
|
||||||
|
)
|
||||||
|
@click.option(
|
||||||
|
"--template-name",
|
||||||
|
default="alert-rules.yml.j2",
|
||||||
|
help="Name of the Jinja2 template file to render.",
|
||||||
|
)
|
||||||
|
@click.option(
|
||||||
|
"--var",
|
||||||
|
"template_vars",
|
||||||
|
multiple=True,
|
||||||
|
help="Template variables in key=value format (can be repeated). "
|
||||||
|
"Example: --var grafana_base_url=https://grafana.example.com",
|
||||||
|
)
|
||||||
|
def main(template_path: Path, template_name: str, template_vars: tuple[str, ...]) -> None:
|
||||||
|
"""Validate rendered alert rules with promtool."""
|
||||||
|
if not shutil.which("promtool"):
|
||||||
|
click.echo("promtool not found in PATH — skipping alert rules validation")
|
||||||
|
return
|
||||||
|
|
||||||
|
# Parse template variables
|
||||||
|
kwargs: dict[str, str] = {}
|
||||||
|
for v in template_vars:
|
||||||
|
if "=" in v:
|
||||||
|
key, value = v.split("=", 1)
|
||||||
|
kwargs[key] = value
|
||||||
|
|
||||||
|
env = make_env(str(template_path))
|
||||||
|
output = render_template(env, template_name, **kwargs)
|
||||||
|
|
||||||
|
with tempfile.NamedTemporaryFile(mode="w", suffix=".yml", delete=False) as f:
|
||||||
|
f.write(output)
|
||||||
|
tmp_path = f.name
|
||||||
|
|
||||||
|
click.echo("[check-alert-rules] Validating rendered rules with promtool...")
|
||||||
|
result = subprocess.run( # nosec
|
||||||
|
["promtool", "check", "rules", tmp_path],
|
||||||
|
capture_output=True,
|
||||||
|
text=True,
|
||||||
|
check=False,
|
||||||
|
)
|
||||||
|
click.echo(result.stdout, nl=False)
|
||||||
|
if result.returncode != 0:
|
||||||
|
click.echo(result.stderr, nl=False, err=True)
|
||||||
|
sys.exit(result.returncode)
|
||||||
|
|
||||||
|
|
||||||
|
if __name__ == "__main__": # pragma: no cover
|
||||||
|
main()
|
||||||
@@ -0,0 +1,196 @@
|
|||||||
|
"""Check that Ansible ``set_fact`` tasks don't misuse ``| to_json``.
|
||||||
|
|
||||||
|
This prevents the class of bug where ``set_fact`` tasks use
|
||||||
|
``{{ targets | to_json }}`` to store Python lists, but ``to_json``
|
||||||
|
converts native types to JSON strings. Ansible then stored the result
|
||||||
|
as a string, so iterating over the fact yielded individual characters
|
||||||
|
instead of list items, causing ``object of type 'str' has no attribute
|
||||||
|
'ip'`` errors.
|
||||||
|
|
||||||
|
The check scans all Ansible task files (playbooks and role tasks) for
|
||||||
|
``set_fact`` tasks where any value uses ``| to_json`` or ``| to_nice_json``
|
||||||
|
and flags them as potential bugs.
|
||||||
|
|
||||||
|
``| to_json`` is legitimate in Jinja2 templates (e.g., rendering JSON
|
||||||
|
config files) but almost never correct in ``set_fact`` — the fact should
|
||||||
|
store the native Python type so downstream tasks can iterate/index it.
|
||||||
|
|
||||||
|
Usage::
|
||||||
|
|
||||||
|
python -m devx.tools.check_ansible_set_fact_to_json
|
||||||
|
python -m devx.tools.check_ansible_set_fact_to_json --path ansible/playbooks/deploy.yml
|
||||||
|
|
||||||
|
Exit code 0 if no misuses found, 1 otherwise.
|
||||||
|
"""
|
||||||
|
|
||||||
|
from __future__ import annotations
|
||||||
|
|
||||||
|
import sys
|
||||||
|
from pathlib import Path
|
||||||
|
|
||||||
|
import click
|
||||||
|
import yaml
|
||||||
|
|
||||||
|
REPO_ROOT = Path.cwd()
|
||||||
|
DEFAULT_ANSIBLE_DIRS: list[Path] = [
|
||||||
|
REPO_ROOT / "ansible" / "playbooks",
|
||||||
|
REPO_ROOT / "ansible" / "roles",
|
||||||
|
]
|
||||||
|
|
||||||
|
TO_JSON_FILTERS = ("| to_json", "| to_nice_json", "|to_json", "|to_nice_json")
|
||||||
|
|
||||||
|
|
||||||
|
def _find_task_files(base: Path) -> list[Path]:
|
||||||
|
"""Find all YAML task files under a base directory."""
|
||||||
|
if base.is_file() and base.suffix in (".yml", ".yaml"):
|
||||||
|
return [base]
|
||||||
|
if not base.is_dir():
|
||||||
|
return []
|
||||||
|
return sorted(base.rglob("*.yml")) + sorted(base.rglob("*.yaml"))
|
||||||
|
|
||||||
|
|
||||||
|
def _check_file(filepath: Path, repo_root: Path) -> list[str]:
|
||||||
|
"""Check a single YAML file for set_fact + to_json misuse.
|
||||||
|
|
||||||
|
Returns a list of error messages (empty if all OK).
|
||||||
|
"""
|
||||||
|
errors: list[str] = []
|
||||||
|
content = filepath.read_text(encoding="utf-8")
|
||||||
|
|
||||||
|
# Multi-document YAML (--- separators) is common in playbooks
|
||||||
|
try:
|
||||||
|
docs = list(yaml.safe_load_all(content))
|
||||||
|
except yaml.YAMLError as exc:
|
||||||
|
return [f"{filepath}: cannot parse YAML: {exc}"]
|
||||||
|
|
||||||
|
for doc in docs:
|
||||||
|
if isinstance(doc, list):
|
||||||
|
# Could be a playbook (list of plays) or a role tasks file (list of tasks)
|
||||||
|
for item in doc:
|
||||||
|
if isinstance(item, dict):
|
||||||
|
if any(k in item for k in ("tasks", "pre_tasks", "post_tasks", "handlers", "roles")):
|
||||||
|
# It's a play
|
||||||
|
_check_tasks(item, filepath, errors, repo_root)
|
||||||
|
else:
|
||||||
|
# It's a bare task (role tasks file)
|
||||||
|
_check_task(item, filepath, errors, repo_root)
|
||||||
|
block = item.get("block")
|
||||||
|
if isinstance(block, list):
|
||||||
|
_check_task_list(block, filepath, errors, repo_root)
|
||||||
|
elif isinstance(doc, dict):
|
||||||
|
# Role tasks file or single play — _check_tasks handles all task sections
|
||||||
|
_check_tasks(doc, filepath, errors, repo_root)
|
||||||
|
|
||||||
|
return errors
|
||||||
|
|
||||||
|
|
||||||
|
def _check_tasks(doc: dict, filepath: Path, errors: list[str], repo_root: Path) -> None:
|
||||||
|
"""Check top-level tasks and nested task sections in a playbook doc."""
|
||||||
|
tasks = doc.get("tasks")
|
||||||
|
if isinstance(tasks, list):
|
||||||
|
_check_task_list(tasks, filepath, errors, repo_root)
|
||||||
|
for role_key in ("pre_tasks", "post_tasks", "handlers"):
|
||||||
|
section = doc.get(role_key)
|
||||||
|
if isinstance(section, list):
|
||||||
|
_check_task_list(section, filepath, errors, repo_root)
|
||||||
|
# Check tasks in roles imported via `roles:` key
|
||||||
|
roles = doc.get("roles")
|
||||||
|
if isinstance(roles, list):
|
||||||
|
for role_entry in roles:
|
||||||
|
if isinstance(role_entry, dict):
|
||||||
|
role_tasks = role_entry.get("tasks")
|
||||||
|
if isinstance(role_tasks, list):
|
||||||
|
_check_task_list(role_tasks, filepath, errors, repo_root)
|
||||||
|
|
||||||
|
|
||||||
|
def _check_task_list(tasks: list, filepath: Path, errors: list[str], repo_root: Path) -> None:
|
||||||
|
"""Check a list of task definitions for set_fact + to_json."""
|
||||||
|
for task in tasks:
|
||||||
|
if not isinstance(task, dict):
|
||||||
|
continue
|
||||||
|
_check_task(task, filepath, errors, repo_root)
|
||||||
|
# Check nested block tasks
|
||||||
|
block = task.get("block")
|
||||||
|
if isinstance(block, list):
|
||||||
|
_check_task_list(block, filepath, errors, repo_root)
|
||||||
|
|
||||||
|
|
||||||
|
def _check_task(task: dict, filepath: Path, errors: list[str], repo_root: Path) -> None:
|
||||||
|
"""Check a single task for set_fact + to_json misuse."""
|
||||||
|
# Detect set_fact — could be a module name key or ansible.builtin.set_fact
|
||||||
|
has_set_fact = False
|
||||||
|
for key in task:
|
||||||
|
if key in {"set_fact", "ansible.builtin.set_fact"}:
|
||||||
|
has_set_fact = True
|
||||||
|
break
|
||||||
|
|
||||||
|
if not has_set_fact:
|
||||||
|
return
|
||||||
|
|
||||||
|
set_fact_body = task.get("set_fact") or task.get("ansible.builtin.set_fact")
|
||||||
|
if not isinstance(set_fact_body, dict):
|
||||||
|
return
|
||||||
|
|
||||||
|
task_name = task.get("name", "(unnamed)")
|
||||||
|
|
||||||
|
for fact_name, fact_value in set_fact_body.items():
|
||||||
|
if fact_name in ("cacheable",):
|
||||||
|
continue
|
||||||
|
value_str = str(fact_value)
|
||||||
|
for filter_pattern in TO_JSON_FILTERS:
|
||||||
|
if filter_pattern in value_str:
|
||||||
|
try:
|
||||||
|
display_path = filepath.relative_to(repo_root)
|
||||||
|
except ValueError:
|
||||||
|
display_path = filepath
|
||||||
|
errors.append(
|
||||||
|
f"{display_path}: task '{task_name}' "
|
||||||
|
f"sets fact '{fact_name}' with '{filter_pattern.strip()}' "
|
||||||
|
f"— this converts native Python types to JSON strings. "
|
||||||
|
f"Remove the filter to preserve the native type, or use "
|
||||||
|
f"'| from_json' in the consuming task if the string "
|
||||||
|
f"representation is intentional."
|
||||||
|
)
|
||||||
|
break # One error per fact is enough
|
||||||
|
|
||||||
|
|
||||||
|
@click.command()
|
||||||
|
@click.option(
|
||||||
|
"--path",
|
||||||
|
type=click.Path(exists=True, path_type=Path),
|
||||||
|
help="Check a specific file or directory (default: ansible/playbooks + ansible/roles).",
|
||||||
|
)
|
||||||
|
@click.option(
|
||||||
|
"--ansible-dir",
|
||||||
|
"ansible_dirs",
|
||||||
|
type=click.Path(exists=True, path_type=Path),
|
||||||
|
multiple=True,
|
||||||
|
default=None,
|
||||||
|
help="Override the default ansible directories (can be repeated). Defaults to ansible/playbooks and ansible/roles.",
|
||||||
|
)
|
||||||
|
def main(path: Path | None, ansible_dirs: tuple[Path, ...]) -> None:
|
||||||
|
"""Check that set_fact tasks don't misuse to_json."""
|
||||||
|
dirs = list(ansible_dirs) if ansible_dirs else DEFAULT_ANSIBLE_DIRS
|
||||||
|
if path:
|
||||||
|
files = _find_task_files(path)
|
||||||
|
else:
|
||||||
|
files: list[Path] = []
|
||||||
|
for d in dirs:
|
||||||
|
files.extend(_find_task_files(d))
|
||||||
|
|
||||||
|
all_errors: list[str] = []
|
||||||
|
for f in files:
|
||||||
|
errors = _check_file(f, REPO_ROOT)
|
||||||
|
all_errors.extend(errors)
|
||||||
|
|
||||||
|
if all_errors:
|
||||||
|
click.echo("[check-ansible-set-fact-to-json] FAIL: set_fact with to_json found:")
|
||||||
|
for err in all_errors:
|
||||||
|
click.echo(f" - {err}")
|
||||||
|
sys.exit(1)
|
||||||
|
else:
|
||||||
|
click.echo("[check-ansible-set-fact-to-json] OK: no set_fact tasks misuse to_json.")
|
||||||
|
|
||||||
|
|
||||||
|
if __name__ == "__main__": # pragma: no cover
|
||||||
|
main()
|
||||||
@@ -0,0 +1,166 @@
|
|||||||
|
"""Check that Docker Compose services with healthchecks have ``init: true``.
|
||||||
|
|
||||||
|
This prevents zombie process accumulation on production VMs. Without
|
||||||
|
``init: true``, Docker uses the container's PID 1 process to reap
|
||||||
|
child processes. Many images (especially those using CMD-SHELL
|
||||||
|
healthchecks with ``wget``) don't call ``wait()`` on children, causing
|
||||||
|
zombies to accumulate.
|
||||||
|
|
||||||
|
The check scans all Jinja2 docker-compose templates for services that
|
||||||
|
have a ``healthcheck:`` key but no ``init: true`` key. Since the
|
||||||
|
templates use Jinja2 syntax (not pure YAML), the check uses text-based
|
||||||
|
parsing to identify service blocks and their properties.
|
||||||
|
|
||||||
|
Usage::
|
||||||
|
|
||||||
|
python -m devx.tools.check_docker_init
|
||||||
|
python -m devx.tools.check_docker_init --path ansible/roles/observability/templates/docker-compose.yml.j2
|
||||||
|
|
||||||
|
Exit code 0 if all services with healthchecks have init: true, 1 otherwise.
|
||||||
|
"""
|
||||||
|
|
||||||
|
from __future__ import annotations
|
||||||
|
|
||||||
|
import re
|
||||||
|
import sys
|
||||||
|
from pathlib import Path
|
||||||
|
|
||||||
|
import click
|
||||||
|
|
||||||
|
REPO_ROOT = Path.cwd()
|
||||||
|
DEFAULT_TEMPLATES_DIR = REPO_ROOT / "ansible" / "roles"
|
||||||
|
|
||||||
|
|
||||||
|
def _find_compose_templates(base: Path) -> list[Path]:
|
||||||
|
"""Find all Jinja2 docker-compose templates under a base directory."""
|
||||||
|
if base.is_file():
|
||||||
|
return [base]
|
||||||
|
if not base.is_dir():
|
||||||
|
return []
|
||||||
|
results: list[Path] = []
|
||||||
|
for pattern in ("*docker-compose*", "*compose*"):
|
||||||
|
results.extend(base.rglob(f"{pattern}.yml.j2"))
|
||||||
|
results.extend(base.rglob(f"{pattern}.yaml.j2"))
|
||||||
|
# Also check exporters-compose
|
||||||
|
results.extend(base.rglob("exporters-compose*.j2"))
|
||||||
|
# Deduplicate while preserving order
|
||||||
|
seen: set[Path] = set()
|
||||||
|
unique: list[Path] = []
|
||||||
|
for p in sorted(results):
|
||||||
|
if p not in seen:
|
||||||
|
seen.add(p)
|
||||||
|
unique.append(p)
|
||||||
|
return unique
|
||||||
|
|
||||||
|
|
||||||
|
def _parse_services(content: str) -> dict[str, list[str]]:
|
||||||
|
"""Parse service blocks from a docker-compose Jinja2 template.
|
||||||
|
|
||||||
|
Returns a mapping of service_name → list of lines in that service block.
|
||||||
|
"""
|
||||||
|
lines = content.splitlines()
|
||||||
|
in_services = False
|
||||||
|
services: dict[str, list[str]] = {}
|
||||||
|
current_svc: str | None = None
|
||||||
|
current_lines: list[str] = []
|
||||||
|
|
||||||
|
for line in lines:
|
||||||
|
if line.startswith("services:"):
|
||||||
|
in_services = True
|
||||||
|
continue
|
||||||
|
if not in_services:
|
||||||
|
continue
|
||||||
|
# Top-level keys (networks:, volumes:) end the services section
|
||||||
|
if re.match(r"^(networks|volumes):\s*$", line):
|
||||||
|
if current_svc is not None:
|
||||||
|
services[current_svc] = current_lines
|
||||||
|
current_svc = None
|
||||||
|
in_services = False
|
||||||
|
continue
|
||||||
|
# Service definition: exactly 2-space indent, ends with :
|
||||||
|
# Service names can contain Jinja2 variables like {{ app_name }}
|
||||||
|
# or {{ app_name }}-db. Match: 2-space indent + non-whitespace
|
||||||
|
# chars (including {{ }}, -, _, .) + optional spaces inside {{ }} + :
|
||||||
|
m = re.match(r"^ (\{\{.*?\}\}[a-zA-Z0-9_-]*|[a-zA-Z0-9_().-]+):\s*$", line)
|
||||||
|
if m:
|
||||||
|
if current_svc is not None:
|
||||||
|
services[current_svc] = current_lines
|
||||||
|
current_svc = m.group(1)
|
||||||
|
current_lines = []
|
||||||
|
elif current_svc is not None:
|
||||||
|
current_lines.append(line)
|
||||||
|
|
||||||
|
if current_svc is not None:
|
||||||
|
services[current_svc] = current_lines
|
||||||
|
|
||||||
|
return services
|
||||||
|
|
||||||
|
|
||||||
|
def _check_template(filepath: Path, repo_root: Path) -> list[str]:
|
||||||
|
"""Check a single docker-compose template for missing init: true.
|
||||||
|
|
||||||
|
Returns a list of error messages (empty if all OK).
|
||||||
|
"""
|
||||||
|
errors: list[str] = []
|
||||||
|
content = filepath.read_text(encoding="utf-8")
|
||||||
|
|
||||||
|
if "services:" not in content:
|
||||||
|
return errors
|
||||||
|
|
||||||
|
services = _parse_services(content)
|
||||||
|
|
||||||
|
for svc_name, svc_lines in services.items():
|
||||||
|
svc_text = "\n".join(svc_lines)
|
||||||
|
has_init = "init: true" in svc_text
|
||||||
|
has_healthcheck = "healthcheck:" in svc_text
|
||||||
|
# Skip services that are conditionally included (Jinja2 if blocks)
|
||||||
|
# but still check them — the healthcheck is inside the conditional
|
||||||
|
if has_healthcheck and not has_init:
|
||||||
|
try:
|
||||||
|
display_path = filepath.relative_to(repo_root)
|
||||||
|
except ValueError:
|
||||||
|
display_path = filepath
|
||||||
|
errors.append(
|
||||||
|
f"{display_path}: service '{svc_name}' has a healthcheck "
|
||||||
|
f"but no 'init: true'. Without init: true, CMD-SHELL "
|
||||||
|
f"healthchecks (wget, pgrep) spawn children that become "
|
||||||
|
f"zombies when PID 1 doesn't reap them. Add 'init: true' "
|
||||||
|
f"to enable Docker's built-in tini as PID 1."
|
||||||
|
)
|
||||||
|
|
||||||
|
return errors
|
||||||
|
|
||||||
|
|
||||||
|
@click.command()
|
||||||
|
@click.option(
|
||||||
|
"--path",
|
||||||
|
type=click.Path(exists=True, path_type=Path),
|
||||||
|
help="Check a specific file or directory (default: ansible/roles/).",
|
||||||
|
)
|
||||||
|
@click.option(
|
||||||
|
"--templates-dir",
|
||||||
|
type=click.Path(exists=True, path_type=Path),
|
||||||
|
default=None,
|
||||||
|
help="Override the default templates directory (default: ansible/roles/).",
|
||||||
|
)
|
||||||
|
def main(path: Path | None, templates_dir: Path | None) -> None:
|
||||||
|
"""Check that Docker Compose services with healthchecks have init: true."""
|
||||||
|
tdir = templates_dir or DEFAULT_TEMPLATES_DIR
|
||||||
|
files = _find_compose_templates(path) if path else _find_compose_templates(tdir)
|
||||||
|
|
||||||
|
all_errors: list[str] = []
|
||||||
|
for f in files:
|
||||||
|
errors = _check_template(f, tdir)
|
||||||
|
all_errors.extend(errors)
|
||||||
|
|
||||||
|
if all_errors:
|
||||||
|
click.echo("[check-docker-init] FAIL: services with healthchecks missing init: true:")
|
||||||
|
for err in all_errors:
|
||||||
|
click.echo(f" - {err}")
|
||||||
|
sys.exit(1)
|
||||||
|
else:
|
||||||
|
click.echo("[check-docker-init] OK: all services with healthchecks have init: true.")
|
||||||
|
|
||||||
|
|
||||||
|
if __name__ == "__main__": # pragma: no cover
|
||||||
|
main()
|
||||||
@@ -7,25 +7,48 @@ This module is used in two ways:
|
|||||||
When devx is installed, pytest auto-discovers this plugin via the
|
When devx is installed, pytest auto-discovers this plugin via the
|
||||||
``pytest11`` entry point. Every ``pytest`` run statically analyzes
|
``pytest11`` entry point. Every ``pytest`` run statically analyzes
|
||||||
test files for patterns that cause slow, non-deterministic, or
|
test files for patterns that cause slow, non-deterministic, or
|
||||||
non-hermetic tests and reports violations as warnings.
|
non-hermetic tests and **fails the test run** if any violations are found.
|
||||||
|
|
||||||
To promote warnings to errors (fail the test run), add to pyproject.toml::
|
The plugin also wraps ``subprocess.run`` at runtime to catch real
|
||||||
|
subprocess calls that leak through transitive call paths (e.g.
|
||||||
|
``CliRunner.invoke(main)`` → ``main()`` → ``update_doc_versions()``
|
||||||
|
→ ``subprocess.run()``). If a test spawns a real subprocess without
|
||||||
|
``@patch``, the test fails.
|
||||||
|
|
||||||
[tool.pytest.ini_options]
|
To disable for a specific run: ``--no-test-isolation``.
|
||||||
filterwarnings = ["error:Test isolation:UserWarning"]
|
|
||||||
|
|
||||||
Or use the ``--strict-test-isolation`` flag on the command line.
|
|
||||||
|
|
||||||
2. **As a standalone CLI** (for CI gates)::
|
2. **As a standalone CLI** (for CI gates)::
|
||||||
|
|
||||||
python3 -m devx.tools.check_test_isolation [--test-path tests/]
|
python3 -m devx.tools.check_test_isolation [--test-path tests/]
|
||||||
python3 -m devx.tools.check_test_isolation --strict
|
|
||||||
|
Always exits non-zero on any hard violation. Transitive-subprocess
|
||||||
|
findings are reported as advisories (exit 0) since static analysis
|
||||||
|
can't predict early exits — the runtime audit is authoritative.
|
||||||
|
|
||||||
|
Project-Specific Configuration
|
||||||
|
-------------------------------
|
||||||
|
|
||||||
|
Projects can extend the built-in rule sets via ``[tool.devx.check_test_isolation]``
|
||||||
|
in ``pyproject.toml``. Entries are merged on top of the defaults — they
|
||||||
|
add to (not replace) the built-in rules::
|
||||||
|
|
||||||
|
[tool.devx.check_test_isolation]
|
||||||
|
# Functions known to do filesystem or network I/O
|
||||||
|
io_functions = { "my_func" = "reads config from disk", ... }
|
||||||
|
# Functions known to spawn subprocesses
|
||||||
|
subprocess_helpers = { "my_helper" = "calls subprocess.run", ... }
|
||||||
|
# Transitive deps: if a helper calls these, patching any of them is safe
|
||||||
|
helper_internal_calls = { "my_helper" = ["subprocess", "run_cmd"], ... }
|
||||||
|
# I/O function internal deps: patching any of these makes the call safe
|
||||||
|
io_internal_calls = { "my_func" = ["open", "yaml"], ... }
|
||||||
|
# Heavy modules slow to import at module level in test files
|
||||||
|
heavy_module_imports = { "mymodule" = 150.0, ... }
|
||||||
|
|
||||||
Patterns detected:
|
Patterns detected:
|
||||||
|
|
||||||
1. **Unpatched subprocess calls** — test functions that call
|
1. **Unpatched subprocess calls** — test functions that call
|
||||||
``subprocess.run/call/Popen/check_call/check_output`` without a
|
``subprocess.run/call/Popen/check_call/check_output`` without a
|
||||||
corresponding ``@patch`` decorator.
|
corresponding ``@patch`` decorator or ``with patch(...)`` context manager.
|
||||||
2. **Unpatched ``time.sleep``** — test functions that call ``time.sleep``
|
2. **Unpatched ``time.sleep``** — test functions that call ``time.sleep``
|
||||||
without patching it.
|
without patching it.
|
||||||
3. **Unpatched known-subprocess-helpers** — functions known to spawn
|
3. **Unpatched known-subprocess-helpers** — functions known to spawn
|
||||||
@@ -34,27 +57,66 @@ Patterns detected:
|
|||||||
network I/O (e.g. ``get_pat``, ``load_secrets``, ``requests.get``)
|
network I/O (e.g. ``get_pat``, ``load_secrets``, ``requests.get``)
|
||||||
called without patching.
|
called without patching.
|
||||||
5. **Excessive iteration loops** — ``for _ in range(N)`` where N > 100.
|
5. **Excessive iteration loops** — ``for _ in range(N)`` where N > 100.
|
||||||
|
6. **Module-level heavy imports** — importing ``httpx``, ``ansible``,
|
||||||
|
etc. at module level in test files slows collection for all tests.
|
||||||
|
7. **``importlib.reload`` without cleanup** — reloading a module in a
|
||||||
|
test mutates global state. Each reload must be paired with a
|
||||||
|
cleanup reload (or wrapped in try/finally) to restore defaults.
|
||||||
|
8. **Transitive subprocess leaks** — ``CliRunner.invoke(target)`` where
|
||||||
|
``target`` transitively calls ``subprocess.run`` without being patched.
|
||||||
|
Detected via static call-graph analysis (warning) AND runtime audit
|
||||||
|
(authoritative — fails the test if a real subprocess runs).
|
||||||
"""
|
"""
|
||||||
|
|
||||||
from __future__ import annotations
|
from __future__ import annotations
|
||||||
|
|
||||||
import ast
|
import ast
|
||||||
|
import subprocess # nosec B404
|
||||||
import sys
|
import sys
|
||||||
|
import threading
|
||||||
from dataclasses import dataclass, field
|
from dataclasses import dataclass, field
|
||||||
from pathlib import Path
|
from pathlib import Path
|
||||||
|
|
||||||
import click
|
import click
|
||||||
|
|
||||||
|
from devx.config import _load_pyproject_devx
|
||||||
from devx.i18n import _
|
from devx.i18n import _
|
||||||
|
|
||||||
# ── Configuration ─────────────────────────────────────────────────────────────
|
# ── Configuration ─────────────────────────────────────────────────────────────
|
||||||
|
|
||||||
DEFAULT_MAX_LOOP_ITERATIONS = 100
|
DEFAULT_MAX_LOOP_ITERATIONS = 100
|
||||||
|
|
||||||
|
# Heavy modules that are slow to import (>50ms). When imported at module
|
||||||
|
# level in a test file, they slow down test collection for ALL tests.
|
||||||
|
# Maps module name → approximate import time in milliseconds.
|
||||||
|
# NOTE: ``requests`` is excluded because it's a core devx dependency —
|
||||||
|
# it's loaded during collection regardless of whether test files import it.
|
||||||
|
_DEFAULT_HEAVY_MODULE_IMPORTS: dict[str, float] = {
|
||||||
|
"httpx": 80.0,
|
||||||
|
"aiohttp": 120.0,
|
||||||
|
"docker": 90.0,
|
||||||
|
"kubernetes": 200.0,
|
||||||
|
"boto3": 250.0,
|
||||||
|
"botocore": 200.0,
|
||||||
|
"ansible": 300.0,
|
||||||
|
"molecule": 150.0,
|
||||||
|
"cv2": 400.0,
|
||||||
|
"numpy": 100.0,
|
||||||
|
"pandas": 200.0,
|
||||||
|
"matplotlib": 300.0,
|
||||||
|
"PIL": 80.0,
|
||||||
|
"Pillow": 80.0,
|
||||||
|
"sqlalchemy": 150.0,
|
||||||
|
"django": 200.0,
|
||||||
|
"flask": 80.0,
|
||||||
|
"fastapi": 100.0,
|
||||||
|
"pydantic": 60.0,
|
||||||
|
}
|
||||||
|
|
||||||
# Functions known to spawn subprocesses. When a test calls any of these
|
# Functions known to spawn subprocesses. When a test calls any of these
|
||||||
# without patching them, the real subprocess runs.
|
# without patching them, the real subprocess runs.
|
||||||
# Maps function name → human-readable description.
|
# Maps function name → human-readable description.
|
||||||
KNOWN_SUBPROCESS_HELPERS: dict[str, str] = {
|
_DEFAULT_SUBPROCESS_HELPERS: dict[str, str] = {
|
||||||
"update_doc_versions": "calls subprocess.run to run check_doc_versions --fix",
|
"update_doc_versions": "calls subprocess.run to run check_doc_versions --fix",
|
||||||
"run_tests": "calls run_cmd to run make lint-ruff and make pytest-cov",
|
"run_tests": "calls run_cmd to run make lint-ruff and make pytest-cov",
|
||||||
"run_cmd": "calls subprocess.run for shell commands",
|
"run_cmd": "calls subprocess.run for shell commands",
|
||||||
@@ -63,10 +125,12 @@ KNOWN_SUBPROCESS_HELPERS: dict[str, str] = {
|
|||||||
# Functions known to do filesystem or network I/O that should be mocked in tests.
|
# Functions known to do filesystem or network I/O that should be mocked in tests.
|
||||||
# Maps function name → description of what I/O it does.
|
# Maps function name → description of what I/O it does.
|
||||||
# If a test calls one of these without a corresponding @patch, it's a violation.
|
# If a test calls one of these without a corresponding @patch, it's a violation.
|
||||||
KNOWN_IO_FUNCTIONS: dict[str, str] = { # nosec B105 — descriptions, not passwords
|
_DEFAULT_IO_FUNCTIONS: dict[str, str] = { # nosec B105 — descriptions, not passwords
|
||||||
"get_pat": "reads ZITADEL PAT from filesystem/env (ZitadelAuth._iter_sources)",
|
"get_pat": "reads ZITADEL PAT from filesystem/env (ZitadelAuth._iter_sources)",
|
||||||
"load_secrets": "reads YAML config file from disk",
|
"load_secrets": "reads YAML config file from disk",
|
||||||
"get_customer_secret": "reads customer-specific config from disk",
|
"get_customer_secret": "reads customer-specific config from disk",
|
||||||
|
"get_customer_vm_ip": "queries Hetzner Cloud API for VM IP (network I/O)",
|
||||||
|
"get_observability_vm_ip": "queries Hetzner Cloud API for observability VM IP (network I/O)",
|
||||||
"requests.get": "performs HTTP GET to a real server",
|
"requests.get": "performs HTTP GET to a real server",
|
||||||
"requests.post": "performs HTTP POST to a real server",
|
"requests.post": "performs HTTP POST to a real server",
|
||||||
"requests.put": "performs HTTP PUT to a real server",
|
"requests.put": "performs HTTP PUT to a real server",
|
||||||
@@ -80,12 +144,172 @@ KNOWN_IO_FUNCTIONS: dict[str, str] = { # nosec B105 — descriptions, not passw
|
|||||||
# Transitive dependencies: if a helper calls another helper that is patched,
|
# Transitive dependencies: if a helper calls another helper that is patched,
|
||||||
# the call is safe. Maps helper → set of function names it internally calls.
|
# the call is safe. Maps helper → set of function names it internally calls.
|
||||||
# If ANY of these are in the test's patches, the helper call is safe.
|
# If ANY of these are in the test's patches, the helper call is safe.
|
||||||
HELPER_INTERNAL_CALLS: dict[str, set[str]] = {
|
_DEFAULT_HELPER_INTERNAL_CALLS: dict[str, set[str]] = {
|
||||||
"run_tests": {"run_cmd", "subprocess"},
|
"run_tests": {"run_cmd", "subprocess"},
|
||||||
"update_doc_versions": {"subprocess"},
|
"update_doc_versions": {"subprocess"},
|
||||||
"run_cmd": {"subprocess"},
|
"run_cmd": {"subprocess"},
|
||||||
}
|
}
|
||||||
|
|
||||||
|
# I/O function internal dependencies: if a test patches one of these
|
||||||
|
# internal dependencies, the I/O function call is considered safe.
|
||||||
|
# Maps I/O function name → set of internal function/method names it calls.
|
||||||
|
_DEFAULT_IO_INTERNAL_CALLS: dict[str, set[str]] = {
|
||||||
|
"get_customer_vm_ip": {"get_tofu_output", "get_tofu_vm_ip", "subprocess"},
|
||||||
|
"get_observability_vm_ip": {"get_tofu_output", "get_tofu_vm_ip", "subprocess"},
|
||||||
|
"get_pat": {
|
||||||
|
"_iter_sources",
|
||||||
|
"_local_pat_path",
|
||||||
|
"_secrets_path",
|
||||||
|
"_read_secrets_pat",
|
||||||
|
"validate_pat",
|
||||||
|
"ZitadelAuth",
|
||||||
|
"load_secrets",
|
||||||
|
"os.environ",
|
||||||
|
},
|
||||||
|
"load_secrets": {"load_vault_yaml", "REPO_ROOT", "open", "yaml", "safe_load"},
|
||||||
|
"get_customer_secret": {"load_customer_secrets", "load_vault_yaml", "load_secrets", "REPO_ROOT", "open"},
|
||||||
|
}
|
||||||
|
|
||||||
|
|
||||||
|
def _load_test_isolation_config() -> None:
|
||||||
|
"""Merge project-specific rules from ``[tool.devx.check_test_isolation]``.
|
||||||
|
|
||||||
|
Reads from pyproject.toml and merges with defaults. Project-specific
|
||||||
|
entries are added on top of (not replacing) the built-in defaults.
|
||||||
|
|
||||||
|
Supported keys::
|
||||||
|
|
||||||
|
[tool.devx.check_test_isolation]
|
||||||
|
io_functions = { "my_func" = "does network I/O", ... }
|
||||||
|
subprocess_helpers = { "my_helper" = "calls subprocess.run", ... }
|
||||||
|
helper_internal_calls = { "my_helper" = ["subprocess", "run_cmd"], ... }
|
||||||
|
io_internal_calls = { "my_func" = ["open", "yaml"], ... }
|
||||||
|
heavy_module_imports = { "mymodule" = 150.0, ... }
|
||||||
|
"""
|
||||||
|
devx_cfg = _load_pyproject_devx()
|
||||||
|
cfg_raw = devx_cfg.get("check_test_isolation", {})
|
||||||
|
if not isinstance(cfg_raw, dict):
|
||||||
|
return
|
||||||
|
cfg: dict[str, object] = cfg_raw # type: ignore[assignment]
|
||||||
|
|
||||||
|
# io_functions: {name: description}
|
||||||
|
io_extra = cfg.get("io_functions", {})
|
||||||
|
if isinstance(io_extra, dict):
|
||||||
|
for name, desc in io_extra.items():
|
||||||
|
if isinstance(name, str) and isinstance(desc, str):
|
||||||
|
KNOWN_IO_FUNCTIONS[name] = desc
|
||||||
|
|
||||||
|
# subprocess_helpers: {name: description}
|
||||||
|
sp_extra = cfg.get("subprocess_helpers", {})
|
||||||
|
if isinstance(sp_extra, dict):
|
||||||
|
for name, desc in sp_extra.items():
|
||||||
|
if isinstance(name, str) and isinstance(desc, str):
|
||||||
|
KNOWN_SUBPROCESS_HELPERS[name] = desc
|
||||||
|
|
||||||
|
# helper_internal_calls: {name: [deps]}
|
||||||
|
hic_extra = cfg.get("helper_internal_calls", {})
|
||||||
|
if isinstance(hic_extra, dict):
|
||||||
|
for name, deps in hic_extra.items():
|
||||||
|
if isinstance(name, str) and isinstance(deps, list):
|
||||||
|
deps_set = {str(d) for d in deps if isinstance(d, str)}
|
||||||
|
HELPER_INTERNAL_CALLS.setdefault(name, set()).update(deps_set)
|
||||||
|
|
||||||
|
# io_internal_calls: {name: [deps]}
|
||||||
|
iic_extra = cfg.get("io_internal_calls", {})
|
||||||
|
if isinstance(iic_extra, dict):
|
||||||
|
for name, deps in iic_extra.items():
|
||||||
|
if isinstance(name, str) and isinstance(deps, list):
|
||||||
|
deps_set = {str(d) for d in deps if isinstance(d, str)}
|
||||||
|
IO_INTERNAL_CALLS.setdefault(name, set()).update(deps_set)
|
||||||
|
|
||||||
|
# heavy_module_imports: {name: ms}
|
||||||
|
hmi_extra = cfg.get("heavy_module_imports", {})
|
||||||
|
if isinstance(hmi_extra, dict):
|
||||||
|
for name, ms in hmi_extra.items():
|
||||||
|
if isinstance(name, str) and isinstance(ms, (int, float)):
|
||||||
|
HEAVY_MODULE_IMPORTS[name] = float(ms)
|
||||||
|
|
||||||
|
|
||||||
|
# Active rule sets — start with defaults, merged with project config at import.
|
||||||
|
HEAVY_MODULE_IMPORTS: dict[str, float] = dict(_DEFAULT_HEAVY_MODULE_IMPORTS)
|
||||||
|
KNOWN_SUBPROCESS_HELPERS: dict[str, str] = dict(_DEFAULT_SUBPROCESS_HELPERS)
|
||||||
|
KNOWN_IO_FUNCTIONS: dict[str, str] = dict(_DEFAULT_IO_FUNCTIONS)
|
||||||
|
HELPER_INTERNAL_CALLS: dict[str, set[str]] = {k: set(v) for k, v in _DEFAULT_HELPER_INTERNAL_CALLS.items()}
|
||||||
|
IO_INTERNAL_CALLS: dict[str, set[str]] = {k: set(v) for k, v in _DEFAULT_IO_INTERNAL_CALLS.items()}
|
||||||
|
|
||||||
|
# Merge project-specific configuration from pyproject.toml
|
||||||
|
_load_test_isolation_config()
|
||||||
|
|
||||||
|
# subprocess functions that the runtime audit wraps.
|
||||||
|
_SUBPROCESS_FUNCS = ("run", "call", "check_call", "check_output", "Popen")
|
||||||
|
|
||||||
|
|
||||||
|
# ── Runtime subprocess audit ──────────────────────────────────────────────────
|
||||||
|
#
|
||||||
|
# The static AST analyzer can only see direct calls in test functions.
|
||||||
|
# It cannot trace transitive calls through CliRunner.invoke(main, ...)
|
||||||
|
# → main() → update_doc_versions() → subprocess.run().
|
||||||
|
#
|
||||||
|
# The runtime audit wraps subprocess functions during test execution.
|
||||||
|
# If a test does NOT @patch subprocess, the wrapper catches real calls.
|
||||||
|
# If a test DOES @patch subprocess, the patch overrides our wrapper
|
||||||
|
# (correct — the test is mocking it).
|
||||||
|
|
||||||
|
|
||||||
|
class _SubprocessAudit:
|
||||||
|
"""Thread-local audit tracker for real subprocess calls during tests."""
|
||||||
|
|
||||||
|
def __init__(self) -> None:
|
||||||
|
self._local = threading.local()
|
||||||
|
self._installed = False
|
||||||
|
self._originals: dict[str, object] = {}
|
||||||
|
|
||||||
|
def _ensure_installed(self) -> None:
|
||||||
|
"""Install wrappers on subprocess module (once)."""
|
||||||
|
if self._installed:
|
||||||
|
return
|
||||||
|
for name in _SUBPROCESS_FUNCS:
|
||||||
|
original = getattr(subprocess, name, None)
|
||||||
|
if original is None:
|
||||||
|
continue
|
||||||
|
self._originals[name] = original
|
||||||
|
setattr(subprocess, name, self._make_wrapper(name, original))
|
||||||
|
self._installed = True
|
||||||
|
|
||||||
|
def _make_wrapper(self, name: str, original: object) -> object:
|
||||||
|
"""Create a wrapper that records calls when auditing is active."""
|
||||||
|
|
||||||
|
def wrapper(*args: object, **kwargs: object) -> object:
|
||||||
|
calls = getattr(self._local, "calls", None)
|
||||||
|
if calls is not None:
|
||||||
|
# Extract command for diagnostics
|
||||||
|
cmd = args[0] if args else kwargs.get("args", "?")
|
||||||
|
if isinstance(cmd, (list, tuple)) and cmd:
|
||||||
|
cmd_str = " ".join(str(c) for c in cmd[:4])
|
||||||
|
if len(cmd) > 4:
|
||||||
|
cmd_str += " ..."
|
||||||
|
else:
|
||||||
|
cmd_str = str(cmd)
|
||||||
|
calls.append((name, cmd_str))
|
||||||
|
return original(*args, **kwargs) # type: ignore[misc]
|
||||||
|
|
||||||
|
return wrapper
|
||||||
|
|
||||||
|
def start_test(self) -> None:
|
||||||
|
"""Begin auditing subprocess calls for the current test."""
|
||||||
|
self._ensure_installed()
|
||||||
|
self._local.calls = []
|
||||||
|
|
||||||
|
def stop_test(self) -> list[tuple[str, str]]:
|
||||||
|
"""Stop auditing and return recorded calls."""
|
||||||
|
calls = getattr(self._local, "calls", [])
|
||||||
|
self._local.calls = None
|
||||||
|
return calls
|
||||||
|
|
||||||
|
|
||||||
|
# Singleton instance used by the pytest plugin
|
||||||
|
_audit = _SubprocessAudit()
|
||||||
|
|
||||||
|
|
||||||
# ── Data structures ───────────────────────────────────────────────────────────
|
# ── Data structures ───────────────────────────────────────────────────────────
|
||||||
|
|
||||||
@@ -123,22 +347,58 @@ class TestFunctionInfo:
|
|||||||
|
|
||||||
|
|
||||||
def _extract_patch_targets(node: ast.FunctionDef | ast.AsyncFunctionDef | ast.ClassDef) -> set[str]:
|
def _extract_patch_targets(node: ast.FunctionDef | ast.AsyncFunctionDef | ast.ClassDef) -> set[str]:
|
||||||
"""Extract @patch targets from decorators on a function or class."""
|
"""Extract @patch targets from decorators AND ``with patch(...)`` statements.
|
||||||
|
|
||||||
|
Detects:
|
||||||
|
- ``@patch("module.func")`` decorators
|
||||||
|
- ``with patch("module.func")`` context managers
|
||||||
|
- ``with patch.object(module, "func")`` context managers
|
||||||
|
- ``with patch("a"), patch("b")`` multiple patches
|
||||||
|
"""
|
||||||
targets: set[str] = set()
|
targets: set[str] = set()
|
||||||
|
|
||||||
|
def _process_patch_call(call: ast.Call) -> None:
|
||||||
|
"""Extract target from a patch() or patch.object() call."""
|
||||||
|
func = call.func
|
||||||
|
# patch("module.func") — either bare `patch(...)` or `mock.patch(...)`
|
||||||
|
if (isinstance(func, ast.Name) and func.id == "patch") or (
|
||||||
|
isinstance(func, ast.Attribute) and func.attr == "patch"
|
||||||
|
):
|
||||||
|
if call.args and isinstance(call.args[0], ast.Constant) and isinstance(call.args[0].value, str):
|
||||||
|
target = call.args[0].value
|
||||||
|
targets.add(target)
|
||||||
|
targets.add(target.rsplit(".", 1)[-1])
|
||||||
|
# patch.object(module, "func") — extract short name from 2nd arg
|
||||||
|
elif (
|
||||||
|
isinstance(func, ast.Attribute)
|
||||||
|
and func.attr == "object"
|
||||||
|
and isinstance(func.value, ast.Name)
|
||||||
|
and func.value.id == "patch"
|
||||||
|
and len(call.args) >= 2
|
||||||
|
and isinstance(call.args[1], ast.Constant)
|
||||||
|
and isinstance(call.args[1].value, str)
|
||||||
|
and call.args[0]
|
||||||
|
and isinstance(call.args[0], ast.Name)
|
||||||
|
):
|
||||||
|
short = call.args[1].value
|
||||||
|
targets.add(short)
|
||||||
|
# We can't resolve the module alias here, but the short
|
||||||
|
# name is enough for patch matching in the call graph.
|
||||||
|
|
||||||
|
# 1. Extract from decorators
|
||||||
for decorator in node.decorator_list:
|
for decorator in node.decorator_list:
|
||||||
if isinstance(decorator, ast.Call):
|
if isinstance(decorator, ast.Call):
|
||||||
func = decorator.func
|
_process_patch_call(decorator)
|
||||||
is_patch = (
|
|
||||||
isinstance(func, ast.Name)
|
# 2. Extract from `with patch(...)` context managers in the body
|
||||||
and func.id == "patch"
|
if isinstance(node, (ast.FunctionDef, ast.AsyncFunctionDef)):
|
||||||
or isinstance(func, ast.Attribute)
|
for child in ast.walk(node):
|
||||||
and func.attr == "patch"
|
if isinstance(child, ast.With):
|
||||||
)
|
for item in child.items:
|
||||||
if is_patch and decorator.args and isinstance(decorator.args[0], ast.Constant):
|
ctx = item.context_expr
|
||||||
target = decorator.args[0].value
|
if isinstance(ctx, ast.Call):
|
||||||
if isinstance(target, str):
|
_process_patch_call(ctx)
|
||||||
targets.add(target)
|
|
||||||
targets.add(target.rsplit(".", 1)[-1])
|
|
||||||
return targets
|
return targets
|
||||||
|
|
||||||
|
|
||||||
@@ -208,19 +468,303 @@ def _get_range_count(node: ast.Call) -> int | None:
|
|||||||
return None # pragma: no cover
|
return None # pragma: no cover
|
||||||
|
|
||||||
|
|
||||||
|
# ── Call-graph builder ────────────────────────────────────────────────────────
|
||||||
|
#
|
||||||
|
# The static AST analyzer can only see direct calls in test functions.
|
||||||
|
# It cannot trace transitive calls through CliRunner.invoke(main, ...)
|
||||||
|
# → main() → update_doc_versions() → subprocess.run().
|
||||||
|
#
|
||||||
|
# The call-graph builder parses all source files in the package and builds
|
||||||
|
# a map: function_name → set of function_names it calls.
|
||||||
|
# When a test calls runner.invoke(target, ...), we trace the call graph
|
||||||
|
# from target to find all reachable functions, then check if any of them
|
||||||
|
# call subprocess.run (or other dangerous functions) without being patched.
|
||||||
|
|
||||||
|
|
||||||
|
# Dangerous functions that should never run in unit tests.
|
||||||
|
# Maps full call name → description.
|
||||||
|
_DANGEROUS_CALLS: dict[str, str] = {
|
||||||
|
"subprocess.run": "spawns a real subprocess",
|
||||||
|
"subprocess.call": "spawns a real subprocess",
|
||||||
|
"subprocess.check_call": "spawns a real subprocess",
|
||||||
|
"subprocess.check_output": "spawns a real subprocess",
|
||||||
|
"subprocess.Popen": "spawns a real subprocess",
|
||||||
|
}
|
||||||
|
|
||||||
|
|
||||||
|
@dataclass
|
||||||
|
class _FunctionNode:
|
||||||
|
"""AST node for a function with its called names."""
|
||||||
|
|
||||||
|
name: str
|
||||||
|
module: str
|
||||||
|
calls: set[str] # short names of functions called
|
||||||
|
subprocess_calls: set[str] # dangerous subprocess calls made directly
|
||||||
|
io_calls: set[str] # known I/O function calls made directly
|
||||||
|
|
||||||
|
|
||||||
|
class CallGraph:
|
||||||
|
"""Call graph built from source files in a package directory."""
|
||||||
|
|
||||||
|
def __init__(self, src_dir: Path) -> None:
|
||||||
|
self.src_dir = src_dir
|
||||||
|
# Maps "module.func" → _FunctionNode
|
||||||
|
self._nodes: dict[str, _FunctionNode] = {}
|
||||||
|
# Maps short name → list of full names (for resolution)
|
||||||
|
self._by_short: dict[str, list[str]] = {}
|
||||||
|
self._built = False
|
||||||
|
|
||||||
|
def _ensure_built(self) -> None:
|
||||||
|
if self._built:
|
||||||
|
return
|
||||||
|
self._build()
|
||||||
|
self._built = True
|
||||||
|
|
||||||
|
def _build(self) -> None:
|
||||||
|
"""Parse all .py files under src_dir and build the call graph."""
|
||||||
|
for py_file in sorted(self.src_dir.rglob("*.py")):
|
||||||
|
try:
|
||||||
|
source = py_file.read_text()
|
||||||
|
tree = ast.parse(source, filename=str(py_file))
|
||||||
|
except (SyntaxError, UnicodeDecodeError):
|
||||||
|
continue
|
||||||
|
# Derive module name from path relative to src_dir
|
||||||
|
rel = py_file.relative_to(self.src_dir)
|
||||||
|
module_parts = list(rel.with_suffix("").parts)
|
||||||
|
if module_parts and module_parts[-1] == "__init__":
|
||||||
|
module_parts = module_parts[:-1]
|
||||||
|
module = ".".join(module_parts)
|
||||||
|
self._scan_module(tree, module)
|
||||||
|
|
||||||
|
def _scan_module(self, tree: ast.Module, module: str) -> None:
|
||||||
|
"""Scan a module AST and register all top-level functions.
|
||||||
|
|
||||||
|
Methods defined inside classes are NOT registered — they are called
|
||||||
|
via objects (e.g. ``tea.create_issue()``) and resolving them by short
|
||||||
|
name alone causes false positives when the class is patched (e.g.
|
||||||
|
``@patch("...TeaCLI")`` mocks all methods).
|
||||||
|
"""
|
||||||
|
for node in tree.body:
|
||||||
|
self._scan_node(node, module)
|
||||||
|
|
||||||
|
def _scan_node(self, node: ast.AST, module: str) -> None:
|
||||||
|
"""Recursively scan a node, registering non-method functions."""
|
||||||
|
if isinstance(node, (ast.FunctionDef, ast.AsyncFunctionDef)):
|
||||||
|
self._register_function(node, module)
|
||||||
|
# Don't recurse into function bodies — nested functions are
|
||||||
|
# not callable by name from outside.
|
||||||
|
return
|
||||||
|
if isinstance(node, ast.ClassDef):
|
||||||
|
# Skip class body — methods are not registered.
|
||||||
|
return
|
||||||
|
# Recurse into other compound statements (if/for/try/with/etc.)
|
||||||
|
for child in ast.iter_child_nodes(node):
|
||||||
|
self._scan_node(child, module)
|
||||||
|
|
||||||
|
def _register_function(self, node: ast.FunctionDef | ast.AsyncFunctionDef, module: str) -> None:
|
||||||
|
"""Register a function and its direct calls in the call graph."""
|
||||||
|
full_name = f"{module}.{node.name}"
|
||||||
|
calls: set[str] = set()
|
||||||
|
subprocess_calls: set[str] = set()
|
||||||
|
io_calls: set[str] = set()
|
||||||
|
|
||||||
|
for child in ast.walk(node):
|
||||||
|
if isinstance(child, ast.Call):
|
||||||
|
full = _get_full_called_name(child)
|
||||||
|
short = _get_called_name(child)
|
||||||
|
if short:
|
||||||
|
calls.add(short)
|
||||||
|
if full and full in _DANGEROUS_CALLS:
|
||||||
|
subprocess_calls.add(full)
|
||||||
|
if short and short in KNOWN_IO_FUNCTIONS:
|
||||||
|
io_calls.add(short)
|
||||||
|
# KNOWN_SUBPROCESS_HELPERS are intermediate functions (e.g.
|
||||||
|
# run_tests → run_cmd → subprocess.run). They are already
|
||||||
|
# in *calls* so the BFS will traverse into them and find the
|
||||||
|
# actual subprocess call. Adding them to *subprocess_calls*
|
||||||
|
# here would cause false positives when the helper itself is
|
||||||
|
# transitively patched (e.g. run_cmd is patched → run_tests
|
||||||
|
# is safe, but would still be reported).
|
||||||
|
|
||||||
|
fn_node = _FunctionNode(
|
||||||
|
name=node.name,
|
||||||
|
module=module,
|
||||||
|
calls=calls,
|
||||||
|
subprocess_calls=subprocess_calls,
|
||||||
|
io_calls=io_calls,
|
||||||
|
)
|
||||||
|
self._nodes[full_name] = fn_node
|
||||||
|
self._by_short.setdefault(node.name, []).append(full_name)
|
||||||
|
|
||||||
|
def find_reachable_dangerous(
|
||||||
|
self,
|
||||||
|
target_name: str,
|
||||||
|
patches: set[str],
|
||||||
|
max_depth: int = 10,
|
||||||
|
import_map: dict[str, str] | None = None,
|
||||||
|
) -> list[tuple[str, str]]:
|
||||||
|
"""Find all dangerous calls reachable from target_name that aren't patched.
|
||||||
|
|
||||||
|
Returns a list of (function_name, description) tuples for each
|
||||||
|
unpatched dangerous call found in the transitive closure.
|
||||||
|
|
||||||
|
If import_map is provided (mapping short names to fully-qualified
|
||||||
|
module paths), it's used to resolve the target precisely instead
|
||||||
|
of matching by short name alone.
|
||||||
|
"""
|
||||||
|
self._ensure_built()
|
||||||
|
|
||||||
|
# Resolve target to full name(s)
|
||||||
|
# First try precise resolution via import_map
|
||||||
|
candidates: list[str] = []
|
||||||
|
if import_map and target_name in import_map:
|
||||||
|
full = import_map[target_name]
|
||||||
|
candidates = [full] if full in self._nodes else self._by_short.get(target_name, [])
|
||||||
|
elif target_name in self._nodes:
|
||||||
|
# Already a fully-qualified name (e.g. devx.tools.build_image.main)
|
||||||
|
candidates = [target_name]
|
||||||
|
else:
|
||||||
|
# Fall back to short name resolution
|
||||||
|
short = target_name.rsplit(".", 1)[-1]
|
||||||
|
candidates = self._by_short.get(short, [])
|
||||||
|
|
||||||
|
if not candidates:
|
||||||
|
return []
|
||||||
|
|
||||||
|
visited: set[str] = set()
|
||||||
|
dangerous: list[tuple[str, str]] = []
|
||||||
|
queue: list[tuple[str, int]] = [(c, 0) for c in candidates]
|
||||||
|
|
||||||
|
while queue:
|
||||||
|
full_name, depth = queue.pop(0)
|
||||||
|
if full_name in visited or depth > max_depth:
|
||||||
|
continue
|
||||||
|
visited.add(full_name)
|
||||||
|
|
||||||
|
node = self._nodes.get(full_name)
|
||||||
|
if node is None:
|
||||||
|
continue
|
||||||
|
|
||||||
|
# Check direct subprocess calls
|
||||||
|
for sc in node.subprocess_calls:
|
||||||
|
short = sc.rsplit(".", 1)[-1]
|
||||||
|
if not self._is_patched(sc, short, patches):
|
||||||
|
desc = _DANGEROUS_CALLS.get(sc, "")
|
||||||
|
dangerous.append((full_name, desc))
|
||||||
|
|
||||||
|
# Check direct IO calls
|
||||||
|
for io in node.io_calls:
|
||||||
|
if not self._is_patched(io, io, patches):
|
||||||
|
desc = KNOWN_IO_FUNCTIONS.get(io, "")
|
||||||
|
if desc:
|
||||||
|
dangerous.append((full_name, desc))
|
||||||
|
|
||||||
|
# Enqueue called functions — skip if the called function is patched
|
||||||
|
for called_short in node.calls:
|
||||||
|
if self._is_patched(called_short, called_short, patches):
|
||||||
|
continue
|
||||||
|
# Prefer same-module resolution, then fall back to short name
|
||||||
|
# only if there's a single global match (avoids false positives
|
||||||
|
# when multiple modules define functions with the same name).
|
||||||
|
same_module = f"{node.module}.{called_short}"
|
||||||
|
if same_module in self._nodes and same_module not in visited:
|
||||||
|
queue.append((same_module, depth + 1))
|
||||||
|
else:
|
||||||
|
matches = self._by_short.get(called_short, [])
|
||||||
|
if len(matches) == 1 and matches[0] not in visited:
|
||||||
|
queue.append((matches[0], depth + 1))
|
||||||
|
|
||||||
|
return dangerous
|
||||||
|
|
||||||
|
@staticmethod
|
||||||
|
def _is_patched(full: str, short: str, patches: set[str]) -> bool:
|
||||||
|
"""Check if a function is covered by the test's @patch set."""
|
||||||
|
if short in patches or full in patches:
|
||||||
|
return True
|
||||||
|
# Check if any patch entry ends with ".short" (e.g. "subprocess.run"
|
||||||
|
# is patched by "devx.ci.release.subprocess.run"). Use exact
|
||||||
|
# endswith, not substring, to avoid "run" matching "run_cmd".
|
||||||
|
return any(p.endswith(f".{short}") or p == full for p in patches)
|
||||||
|
|
||||||
|
|
||||||
# ── Analyzers ─────────────────────────────────────────────────────────────────
|
# ── Analyzers ─────────────────────────────────────────────────────────────────
|
||||||
|
|
||||||
|
|
||||||
class TestIsolationVisitor(ast.NodeVisitor):
|
class TestIsolationVisitor(ast.NodeVisitor):
|
||||||
"""AST visitor that detects un-hermetic test patterns."""
|
"""AST visitor that detects un-hermetic test patterns."""
|
||||||
|
|
||||||
def __init__(self, file_path: Path, max_loop_iterations: int = DEFAULT_MAX_LOOP_ITERATIONS):
|
def __init__(
|
||||||
|
self,
|
||||||
|
file_path: Path,
|
||||||
|
max_loop_iterations: int = DEFAULT_MAX_LOOP_ITERATIONS,
|
||||||
|
call_graph: CallGraph | None = None,
|
||||||
|
):
|
||||||
self.file_path = file_path
|
self.file_path = file_path
|
||||||
self.max_loop_iterations = max_loop_iterations
|
self.max_loop_iterations = max_loop_iterations
|
||||||
|
self.call_graph = call_graph
|
||||||
self.violations: list[Violation] = []
|
self.violations: list[Violation] = []
|
||||||
self._current_function: TestFunctionInfo | None = None
|
self._current_function: TestFunctionInfo | None = None
|
||||||
self._current_class_patches: set[str] = set()
|
self._current_class_patches: set[str] = set()
|
||||||
self._in_test_class = False
|
self._in_test_class = False
|
||||||
|
self._reload_calls: list[tuple[int, str | None]] = []
|
||||||
|
# Import map: short name → fully-qualified module.func
|
||||||
|
# e.g. {"main": "devx.ci.release.main"} for `from devx.ci.release import main`
|
||||||
|
self._import_map: dict[str, str] = {}
|
||||||
|
|
||||||
|
def visit_Import(self, node: ast.Import) -> None:
|
||||||
|
# Track imports for call-graph resolution
|
||||||
|
if self._current_function is None:
|
||||||
|
for alias in node.names:
|
||||||
|
name = alias.asname or alias.name
|
||||||
|
self._import_map[name] = alias.name
|
||||||
|
# Check for heavy module imports
|
||||||
|
if self._current_function is None:
|
||||||
|
for alias in node.names:
|
||||||
|
mod = alias.name.split(".")[0]
|
||||||
|
if mod in HEAVY_MODULE_IMPORTS:
|
||||||
|
self.violations.append(
|
||||||
|
Violation(
|
||||||
|
file=self.file_path,
|
||||||
|
line=node.lineno,
|
||||||
|
col=node.col_offset,
|
||||||
|
category="heavy-module-import",
|
||||||
|
message=_(
|
||||||
|
"Heavy import '{mod}' (~{ms:.0f}ms) at module level — "
|
||||||
|
"this slows test collection for all tests. "
|
||||||
|
"Move inside test functions or use lazy import.",
|
||||||
|
mod=alias.name,
|
||||||
|
ms=HEAVY_MODULE_IMPORTS[mod],
|
||||||
|
),
|
||||||
|
)
|
||||||
|
)
|
||||||
|
self.generic_visit(node)
|
||||||
|
|
||||||
|
def visit_ImportFrom(self, node: ast.ImportFrom) -> None:
|
||||||
|
# Track imports for call-graph resolution
|
||||||
|
if self._current_function is None and node.module:
|
||||||
|
for alias in node.names:
|
||||||
|
name = alias.asname or alias.name
|
||||||
|
self._import_map[name] = f"{node.module}.{alias.name}"
|
||||||
|
# Check for heavy module imports
|
||||||
|
if self._current_function is None and node.module:
|
||||||
|
mod = node.module.split(".")[0]
|
||||||
|
if mod in HEAVY_MODULE_IMPORTS:
|
||||||
|
self.violations.append(
|
||||||
|
Violation(
|
||||||
|
file=self.file_path,
|
||||||
|
line=node.lineno,
|
||||||
|
col=node.col_offset,
|
||||||
|
category="heavy-module-import",
|
||||||
|
message=_(
|
||||||
|
"Heavy import '{mod}' (~{ms:.0f}ms) at module level — "
|
||||||
|
"this slows test collection for all tests. "
|
||||||
|
"Move inside test functions or use lazy import.",
|
||||||
|
mod=node.module,
|
||||||
|
ms=HEAVY_MODULE_IMPORTS[mod],
|
||||||
|
),
|
||||||
|
)
|
||||||
|
)
|
||||||
|
self.generic_visit(node)
|
||||||
|
|
||||||
def visit_ClassDef(self, node: ast.ClassDef) -> None:
|
def visit_ClassDef(self, node: ast.ClassDef) -> None:
|
||||||
old_class_patches = self._current_class_patches
|
old_class_patches = self._current_class_patches
|
||||||
@@ -256,9 +800,33 @@ class TestIsolationVisitor(ast.NodeVisitor):
|
|||||||
is_test=True,
|
is_test=True,
|
||||||
)
|
)
|
||||||
old_func = self._current_function
|
old_func = self._current_function
|
||||||
|
old_reloads = self._reload_calls
|
||||||
self._current_function = info
|
self._current_function = info
|
||||||
|
self._reload_calls = []
|
||||||
self.generic_visit(node)
|
self.generic_visit(node)
|
||||||
|
# Check 7: importlib.reload without cleanup
|
||||||
|
# Each reload mutates global module state. An odd number of
|
||||||
|
# reloads means the module is left in a modified state.
|
||||||
|
if len(self._reload_calls) % 2 != 0:
|
||||||
|
first_line, mod_name = self._reload_calls[0]
|
||||||
|
self.violations.append(
|
||||||
|
Violation(
|
||||||
|
file=self.file_path,
|
||||||
|
line=first_line,
|
||||||
|
col=0,
|
||||||
|
category="reload-without-cleanup",
|
||||||
|
message=_(
|
||||||
|
"importlib.reload({mod}) called {n} time(s) in test '{test}' — "
|
||||||
|
"odd count leaves module in modified state. "
|
||||||
|
"Add a final reload to restore defaults or wrap in try/finally.",
|
||||||
|
mod=mod_name or "module",
|
||||||
|
n=len(self._reload_calls),
|
||||||
|
test=info.name,
|
||||||
|
),
|
||||||
|
)
|
||||||
|
)
|
||||||
self._current_function = old_func
|
self._current_function = old_func
|
||||||
|
self._reload_calls = old_reloads
|
||||||
|
|
||||||
def visit_Call(self, node: ast.Call) -> None:
|
def visit_Call(self, node: ast.Call) -> None:
|
||||||
if self._current_function is None:
|
if self._current_function is None:
|
||||||
@@ -269,6 +837,16 @@ class TestIsolationVisitor(ast.NodeVisitor):
|
|||||||
short_name = _get_called_name(node)
|
short_name = _get_called_name(node)
|
||||||
all_patches = self._current_function.patches | self._current_function.class_patches
|
all_patches = self._current_function.patches | self._current_function.class_patches
|
||||||
|
|
||||||
|
# Track importlib.reload calls for cleanup check
|
||||||
|
if full_name == "importlib.reload" or (short_name == "reload" and "reload" in all_patches):
|
||||||
|
mod_arg = node.args[0] if node.args else None
|
||||||
|
mod_name = None
|
||||||
|
if isinstance(mod_arg, ast.Name):
|
||||||
|
mod_name = mod_arg.id
|
||||||
|
elif isinstance(mod_arg, ast.Attribute):
|
||||||
|
mod_name = mod_arg.attr
|
||||||
|
self._reload_calls.append((node.lineno, mod_name))
|
||||||
|
|
||||||
# Check 1: subprocess.run / subprocess.call / subprocess.Popen etc.
|
# Check 1: subprocess.run / subprocess.call / subprocess.Popen etc.
|
||||||
if full_name and full_name.startswith("subprocess."):
|
if full_name and full_name.startswith("subprocess."):
|
||||||
method = full_name.split(".", 1)[1]
|
method = full_name.split(".", 1)[1]
|
||||||
@@ -349,6 +927,9 @@ class TestIsolationVisitor(ast.NodeVisitor):
|
|||||||
or sn in all_patches
|
or sn in all_patches
|
||||||
or any(io_key in p or sn in p for p in all_patches)
|
or any(io_key in p or sn in p for p in all_patches)
|
||||||
or any(p.endswith(f".{sn}") for p in all_patches)
|
or any(p.endswith(f".{sn}") for p in all_patches)
|
||||||
|
or any(
|
||||||
|
dep in all_patches or any(dep in p for p in all_patches) for dep in IO_INTERNAL_CALLS.get(io_key, set())
|
||||||
|
)
|
||||||
):
|
):
|
||||||
self.violations.append(
|
self.violations.append(
|
||||||
Violation(
|
Violation(
|
||||||
@@ -366,6 +947,52 @@ class TestIsolationVisitor(ast.NodeVisitor):
|
|||||||
)
|
)
|
||||||
)
|
)
|
||||||
|
|
||||||
|
# Check 8: CliRunner.invoke / runner.invoke — trace call graph
|
||||||
|
# Detect runner.invoke(target, ...) or CliRunner().invoke(target, ...)
|
||||||
|
if short_name == "invoke" and self.call_graph is not None and node.args:
|
||||||
|
target = node.args[0]
|
||||||
|
target_name: str | None = None
|
||||||
|
if isinstance(target, ast.Name):
|
||||||
|
target_name = target.id
|
||||||
|
elif isinstance(target, ast.Attribute):
|
||||||
|
# Handle module.func pattern (e.g. build_image.main)
|
||||||
|
# Resolve module prefix via import_map
|
||||||
|
if isinstance(target.value, ast.Name):
|
||||||
|
mod_short = target.value.id
|
||||||
|
mod_full = self._import_map.get(mod_short)
|
||||||
|
target_name = f"{mod_full}.{target.attr}" if mod_full else target.attr
|
||||||
|
else:
|
||||||
|
target_name = target.attr
|
||||||
|
if target_name:
|
||||||
|
dangerous = self.call_graph.find_reachable_dangerous(
|
||||||
|
target_name, all_patches, import_map=self._import_map
|
||||||
|
)
|
||||||
|
if dangerous:
|
||||||
|
# Deduplicate by function name
|
||||||
|
seen: set[str] = set()
|
||||||
|
unique: list[tuple[str, str]] = []
|
||||||
|
for func, desc in dangerous:
|
||||||
|
if func not in seen:
|
||||||
|
seen.add(func)
|
||||||
|
unique.append((func, desc))
|
||||||
|
funcs_desc = "; ".join(f"{f} ({d})" for f, d in unique[:3])
|
||||||
|
self.violations.append(
|
||||||
|
Violation(
|
||||||
|
file=self.file_path,
|
||||||
|
line=node.lineno,
|
||||||
|
col=node.col_offset,
|
||||||
|
category="transitive-subprocess",
|
||||||
|
message=_(
|
||||||
|
"CliRunner.invoke({target}) in test '{test}' reaches "
|
||||||
|
"unpatched dangerous functions: {funcs}. "
|
||||||
|
"Add @patch for each or patch the calling function.",
|
||||||
|
target=target_name,
|
||||||
|
test=self._current_function.name,
|
||||||
|
funcs=funcs_desc,
|
||||||
|
),
|
||||||
|
)
|
||||||
|
)
|
||||||
|
|
||||||
self.generic_visit(node)
|
self.generic_visit(node)
|
||||||
|
|
||||||
def visit_For(self, node: ast.For) -> None:
|
def visit_For(self, node: ast.For) -> None:
|
||||||
@@ -400,7 +1027,11 @@ def find_test_files(test_path: Path) -> list[Path]:
|
|||||||
return sorted(test_path.rglob("test_*.py"))
|
return sorted(test_path.rglob("test_*.py"))
|
||||||
|
|
||||||
|
|
||||||
def analyze_file(file_path: Path, max_loop_iterations: int = DEFAULT_MAX_LOOP_ITERATIONS) -> list[Violation]:
|
def analyze_file(
|
||||||
|
file_path: Path,
|
||||||
|
max_loop_iterations: int = DEFAULT_MAX_LOOP_ITERATIONS,
|
||||||
|
call_graph: CallGraph | None = None,
|
||||||
|
) -> list[Violation]:
|
||||||
"""Analyze a single test file for isolation violations.
|
"""Analyze a single test file for isolation violations.
|
||||||
|
|
||||||
Files in ``integration/`` directories are skipped — integration tests
|
Files in ``integration/`` directories are skipped — integration tests
|
||||||
@@ -422,7 +1053,7 @@ def analyze_file(file_path: Path, max_loop_iterations: int = DEFAULT_MAX_LOOP_IT
|
|||||||
)
|
)
|
||||||
]
|
]
|
||||||
|
|
||||||
visitor = TestIsolationVisitor(file_path, max_loop_iterations)
|
visitor = TestIsolationVisitor(file_path, max_loop_iterations, call_graph)
|
||||||
visitor.visit(tree)
|
visitor.visit(tree)
|
||||||
return visitor.violations
|
return visitor.violations
|
||||||
|
|
||||||
@@ -431,12 +1062,13 @@ def analyze_test_files(
|
|||||||
test_path: Path,
|
test_path: Path,
|
||||||
max_loop_iterations: int = DEFAULT_MAX_LOOP_ITERATIONS,
|
max_loop_iterations: int = DEFAULT_MAX_LOOP_ITERATIONS,
|
||||||
categories: set[str] | None = None,
|
categories: set[str] | None = None,
|
||||||
|
call_graph: CallGraph | None = None,
|
||||||
) -> list[Violation]:
|
) -> list[Violation]:
|
||||||
"""Analyze all test files under test_path. Returns list of violations."""
|
"""Analyze all test files under test_path. Returns list of violations."""
|
||||||
test_files = find_test_files(test_path)
|
test_files = find_test_files(test_path)
|
||||||
all_violations: list[Violation] = []
|
all_violations: list[Violation] = []
|
||||||
for file_path in test_files:
|
for file_path in test_files:
|
||||||
violations = analyze_file(file_path, max_loop_iterations)
|
violations = analyze_file(file_path, max_loop_iterations, call_graph)
|
||||||
if categories:
|
if categories:
|
||||||
violations = [v for v in violations if v.category in categories]
|
violations = [v for v in violations if v.category in categories]
|
||||||
all_violations.extend(violations)
|
all_violations.extend(violations)
|
||||||
@@ -447,23 +1079,17 @@ def analyze_test_files(
|
|||||||
#
|
#
|
||||||
# When devx is installed, pytest auto-discovers this plugin via the
|
# When devx is installed, pytest auto-discovers this plugin via the
|
||||||
# `pytest11` entry point. The plugin runs static analysis on every
|
# `pytest11` entry point. The plugin runs static analysis on every
|
||||||
# test file during collection and emits warnings for violations.
|
# test file during collection and **fails** on any violation.
|
||||||
# Use --strict-test-isolation to promote warnings to errors.
|
# It also wraps subprocess at runtime to catch transitive leaks.
|
||||||
|
|
||||||
|
|
||||||
def pytest_addoption(parser): # type: ignore[no-untyped-def] # pragma: no cover
|
def pytest_addoption(parser): # type: ignore[no-untyped-def] # pragma: no cover
|
||||||
"""Register pytest command-line options."""
|
"""Register pytest command-line options."""
|
||||||
parser.addoption(
|
|
||||||
"--strict-test-isolation",
|
|
||||||
action="store_true",
|
|
||||||
default=False,
|
|
||||||
help="Fail the test run if any test isolation violations are found.",
|
|
||||||
)
|
|
||||||
parser.addoption(
|
parser.addoption(
|
||||||
"--no-test-isolation",
|
"--no-test-isolation",
|
||||||
action="store_true",
|
action="store_true",
|
||||||
default=False,
|
default=False,
|
||||||
help="Disable test isolation static analysis.",
|
help="Disable test isolation static analysis and runtime subprocess audit.",
|
||||||
)
|
)
|
||||||
parser.addoption(
|
parser.addoption(
|
||||||
"--test-isolation-max-loop",
|
"--test-isolation-max-loop",
|
||||||
@@ -474,46 +1100,129 @@ def pytest_addoption(parser): # type: ignore[no-untyped-def] # pragma: no cove
|
|||||||
|
|
||||||
|
|
||||||
def pytest_collection_finish(session): # type: ignore[no-untyped-def] # pragma: no cover
|
def pytest_collection_finish(session): # type: ignore[no-untyped-def] # pragma: no cover
|
||||||
"""Run static analysis after all test files are collected."""
|
"""Run static analysis after all test files are collected. Always strict."""
|
||||||
if session.config.getoption("--no-test-isolation"):
|
if session.config.getoption("--no-test-isolation"):
|
||||||
return
|
return
|
||||||
|
|
||||||
strict = session.config.getoption("--strict-test-isolation")
|
|
||||||
max_loop = session.config.getoption("--test-isolation-max-loop")
|
max_loop = session.config.getoption("--test-isolation-max-loop")
|
||||||
|
|
||||||
# Analyze all collected test files
|
# Build call graph from source directory for transitive analysis
|
||||||
|
call_graph: CallGraph | None = None
|
||||||
|
for item in session.items:
|
||||||
|
fspath = Path(str(item.fspath))
|
||||||
|
for parent in fspath.parents:
|
||||||
|
src_dir = parent / "src"
|
||||||
|
if src_dir.is_dir():
|
||||||
|
call_graph = CallGraph(src_dir)
|
||||||
|
break
|
||||||
|
if call_graph is not None:
|
||||||
|
break
|
||||||
|
|
||||||
test_files: set[Path] = set()
|
test_files: set[Path] = set()
|
||||||
for item in session.items:
|
for item in session.items:
|
||||||
test_files.add(Path(str(item.fspath)))
|
test_files.add(Path(str(item.fspath)))
|
||||||
|
|
||||||
all_violations: list[Violation] = []
|
all_violations: list[Violation] = []
|
||||||
for file_path in sorted(test_files):
|
for file_path in sorted(test_files):
|
||||||
violations = analyze_file(file_path, max_loop)
|
violations = analyze_file(file_path, max_loop, call_graph)
|
||||||
all_violations.extend(violations)
|
all_violations.extend(violations)
|
||||||
|
|
||||||
if not all_violations:
|
if not all_violations:
|
||||||
return
|
return
|
||||||
|
|
||||||
# Emit warnings
|
# transitive-subprocess is advisory (static can't predict early exits).
|
||||||
import warnings
|
# All other categories are hard errors.
|
||||||
|
errors = [v for v in all_violations if v.category != "transitive-subprocess"]
|
||||||
|
transitive = [v for v in all_violations if v.category == "transitive-subprocess"]
|
||||||
|
|
||||||
for v in sorted(all_violations, key=lambda x: (str(x.file), x.line)):
|
if errors:
|
||||||
msg = f"Test isolation violation: {v.format()}"
|
count = len(errors)
|
||||||
warnings.warn(msg, UserWarning, stacklevel=2)
|
files = len({v.file for v in errors})
|
||||||
|
|
||||||
if strict:
|
|
||||||
count = len(all_violations)
|
|
||||||
files = len({v.file for v in all_violations})
|
|
||||||
click.echo(
|
click.echo(
|
||||||
_(
|
_(
|
||||||
"\nTest isolation check FAILED: {count} violation(s) in {files} file(s).\n"
|
"\nTest isolation check FAILED: {count} violation(s) in {files} file(s).\n",
|
||||||
"Fix: add @patch decorators for subprocess/time.sleep calls, "
|
|
||||||
"or patch the calling function.\n",
|
|
||||||
count=count,
|
count=count,
|
||||||
files=files,
|
files=files,
|
||||||
),
|
),
|
||||||
err=True,
|
err=True,
|
||||||
)
|
)
|
||||||
|
for v in sorted(errors, key=lambda x: (str(x.file), x.line)):
|
||||||
|
click.echo(f" {v.format()}", err=True)
|
||||||
|
click.echo(
|
||||||
|
_(
|
||||||
|
"Fix: add @patch decorators or with patch() context managers "
|
||||||
|
"for subprocess/time.sleep calls, or patch the calling function.\n"
|
||||||
|
),
|
||||||
|
err=True,
|
||||||
|
)
|
||||||
|
import pytest
|
||||||
|
|
||||||
|
pytest.fail(
|
||||||
|
f"Test isolation: {count} violation(s) found. See output above.",
|
||||||
|
pytrace=False,
|
||||||
|
)
|
||||||
|
|
||||||
|
# transitive-subprocess warnings are advisory — runtime audit is authoritative
|
||||||
|
if transitive:
|
||||||
|
import warnings
|
||||||
|
|
||||||
|
for v in sorted(transitive, key=lambda x: (str(x.file), x.line)):
|
||||||
|
msg = f"Test isolation advisory: {v.format()}"
|
||||||
|
warnings.warn(msg, UserWarning, stacklevel=2)
|
||||||
|
|
||||||
|
|
||||||
|
# ── Runtime subprocess audit hooks ────────────────────────────────────────────
|
||||||
|
|
||||||
|
|
||||||
|
def _is_integration_test(item: object) -> bool:
|
||||||
|
"""Check if a test item is an integration test."""
|
||||||
|
markers = getattr(item, "keywords", {})
|
||||||
|
if "integration" in markers:
|
||||||
|
return True
|
||||||
|
fspath = str(getattr(item, "fspath", ""))
|
||||||
|
return "integration" in fspath
|
||||||
|
|
||||||
|
|
||||||
|
def pytest_runtest_setup(item: object) -> None: # type: ignore[no-untyped-def] # pragma: no cover
|
||||||
|
"""Start subprocess audit for non-integration tests."""
|
||||||
|
config = getattr(item, "config", None)
|
||||||
|
if config is None:
|
||||||
|
return
|
||||||
|
if config.getoption("--no-test-isolation"):
|
||||||
|
return
|
||||||
|
if _is_integration_test(item):
|
||||||
|
return
|
||||||
|
_audit.start_test()
|
||||||
|
|
||||||
|
|
||||||
|
def pytest_runtest_teardown(item: object, nextitem: object) -> None: # type: ignore[no-untyped-def] # pragma: no cover
|
||||||
|
"""Fail test if real subprocess calls were made without @patch."""
|
||||||
|
config = getattr(item, "config", None)
|
||||||
|
if config is None:
|
||||||
|
return
|
||||||
|
if config.getoption("--no-test-isolation"):
|
||||||
|
return
|
||||||
|
if _is_integration_test(item):
|
||||||
|
return
|
||||||
|
calls = _audit.stop_test()
|
||||||
|
if not calls:
|
||||||
|
return
|
||||||
|
|
||||||
|
test_name = getattr(item, "name", str(item))
|
||||||
|
lines = [
|
||||||
|
_(
|
||||||
|
"Real subprocess call(s) detected in test '{test}' without @patch:",
|
||||||
|
test=test_name,
|
||||||
|
)
|
||||||
|
]
|
||||||
|
for func_name, cmd in calls:
|
||||||
|
lines.append(f" {func_name}({cmd})")
|
||||||
|
lines.append(_('Add @patch("subprocess.run") or patch the calling function to fix this.'))
|
||||||
|
msg = "\n".join(lines)
|
||||||
|
|
||||||
|
import pytest
|
||||||
|
|
||||||
|
pytest.fail(msg, pytrace=False)
|
||||||
|
|
||||||
|
|
||||||
# ── Standalone CLI ────────────────────────────────────────────────────────────
|
# ── Standalone CLI ────────────────────────────────────────────────────────────
|
||||||
@@ -536,59 +1245,103 @@ def pytest_collection_finish(session): # type: ignore[no-untyped-def] # pragma
|
|||||||
show_default=True,
|
show_default=True,
|
||||||
help="Maximum allowed iterations in a single test loop.",
|
help="Maximum allowed iterations in a single test loop.",
|
||||||
)
|
)
|
||||||
@click.option(
|
|
||||||
"--strict",
|
|
||||||
is_flag=True,
|
|
||||||
default=False,
|
|
||||||
help="Treat warnings as errors (non-zero exit on any violation).",
|
|
||||||
)
|
|
||||||
@click.option(
|
@click.option(
|
||||||
"--categories",
|
"--categories",
|
||||||
type=str,
|
type=str,
|
||||||
default="",
|
default="",
|
||||||
help="Comma-separated list of categories to check (default: all). "
|
help="Comma-separated list of categories to check (default: all). "
|
||||||
"Available: unpatched-subprocess, unpatched-sleep, unpatched-helper, excessive-iterations",
|
"Available: unpatched-subprocess, unpatched-sleep, unpatched-helper, "
|
||||||
|
"excessive-iterations, heavy-module-import, reload-without-cleanup, "
|
||||||
|
"transitive-subprocess",
|
||||||
)
|
)
|
||||||
def cli(test_paths: tuple[Path, ...], max_loop_iterations: int, strict: bool, categories: str) -> None:
|
@click.option(
|
||||||
"""Check test files for un-hermetic patterns that cause slow or flaky tests."""
|
"--src-dir",
|
||||||
|
type=click.Path(exists=True, file_okay=False, path_type=Path),
|
||||||
|
default=None,
|
||||||
|
help="Source directory for call-graph analysis (auto-detected if omitted).",
|
||||||
|
)
|
||||||
|
def cli(
|
||||||
|
test_paths: tuple[Path, ...],
|
||||||
|
max_loop_iterations: int,
|
||||||
|
categories: str,
|
||||||
|
src_dir: Path | None,
|
||||||
|
) -> None:
|
||||||
|
"""Check test files for un-hermetic patterns that cause slow or flaky tests.
|
||||||
|
|
||||||
|
Always exits non-zero on any hard violation. Transitive-subprocess
|
||||||
|
findings are reported as advisories (exit 0) since static analysis
|
||||||
|
can't predict early exits — the runtime audit is authoritative.
|
||||||
|
"""
|
||||||
allowed: set[str] | None = None
|
allowed: set[str] | None = None
|
||||||
if categories:
|
if categories:
|
||||||
allowed = {c.strip() for c in categories.split(",")}
|
allowed = {c.strip() for c in categories.split(",")}
|
||||||
|
|
||||||
|
# Build call graph for transitive subprocess detection
|
||||||
|
call_graph: CallGraph | None = None
|
||||||
|
if src_dir is not None:
|
||||||
|
call_graph = CallGraph(src_dir)
|
||||||
|
else:
|
||||||
|
for tp in test_paths:
|
||||||
|
for parent in Path(tp).resolve().parents:
|
||||||
|
candidate = parent / "src"
|
||||||
|
if candidate.is_dir():
|
||||||
|
call_graph = CallGraph(candidate)
|
||||||
|
break
|
||||||
|
if call_graph is not None:
|
||||||
|
break
|
||||||
|
|
||||||
all_violations: list[Violation] = []
|
all_violations: list[Violation] = []
|
||||||
total_files = 0
|
total_files = 0
|
||||||
for test_path in test_paths:
|
for test_path in test_paths:
|
||||||
violations = analyze_test_files(test_path, max_loop_iterations, allowed)
|
violations = analyze_test_files(test_path, max_loop_iterations, allowed, call_graph)
|
||||||
all_violations.extend(violations)
|
all_violations.extend(violations)
|
||||||
total_files += len(find_test_files(test_path))
|
total_files += len(find_test_files(test_path))
|
||||||
|
|
||||||
if not all_violations:
|
errors = [v for v in all_violations if v.category != "transitive-subprocess"]
|
||||||
|
advisories = [v for v in all_violations if v.category == "transitive-subprocess"]
|
||||||
|
|
||||||
|
if not errors and not advisories:
|
||||||
click.echo(
|
click.echo(
|
||||||
_("Test isolation check passed: {count} test files analyzed, no violations found.", count=total_files)
|
_("Test isolation check passed: {count} test files analyzed, no violations found.", count=total_files)
|
||||||
)
|
)
|
||||||
sys.exit(0)
|
sys.exit(0)
|
||||||
|
|
||||||
click.echo(
|
if errors:
|
||||||
_(
|
click.echo(
|
||||||
"Test isolation check FAILED: {count} violation(s) found in {files} test file(s).",
|
_(
|
||||||
count=len(all_violations),
|
"Test isolation check FAILED: {count} violation(s) in {files} file(s).",
|
||||||
files=len({v.file for v in all_violations}),
|
count=len(errors),
|
||||||
),
|
files=len({v.file for v in errors}),
|
||||||
err=True,
|
),
|
||||||
)
|
err=True,
|
||||||
click.echo("")
|
)
|
||||||
for v in sorted(all_violations, key=lambda x: (str(x.file), x.line)):
|
click.echo("")
|
||||||
click.echo(f" {v.format()}", err=True)
|
for v in sorted(errors, key=lambda x: (str(x.file), x.line)):
|
||||||
|
click.echo(f" {v.format()}", err=True)
|
||||||
|
click.echo("")
|
||||||
|
click.echo(
|
||||||
|
_(
|
||||||
|
"Fix: add @patch decorators or with patch() context managers "
|
||||||
|
"for subprocess/time.sleep calls, or patch the calling function."
|
||||||
|
),
|
||||||
|
err=True,
|
||||||
|
)
|
||||||
|
sys.exit(1)
|
||||||
|
|
||||||
click.echo("")
|
# Advisories only — exit 0 but print them
|
||||||
click.echo(
|
click.echo(
|
||||||
_(
|
_(
|
||||||
"Fix: add @patch decorators for subprocess/time.sleep calls, "
|
"Test isolation check passed with {count} advisory warning(s) in {files} file(s).",
|
||||||
"or patch the calling function. Use property-based testing for statistical tests."
|
count=len(advisories),
|
||||||
),
|
files=len({v.file for v in advisories}),
|
||||||
err=True,
|
)
|
||||||
)
|
)
|
||||||
sys.exit(1)
|
click.echo(_("Transitive-subprocess advisories (runtime audit is authoritative):"))
|
||||||
|
for v in sorted(advisories, key=lambda x: (str(x.file), x.line))[:10]:
|
||||||
|
click.echo(f" {v.format()}")
|
||||||
|
if len(advisories) > 10:
|
||||||
|
click.echo(f" ... and {len(advisories) - 10} more")
|
||||||
|
sys.exit(0)
|
||||||
|
|
||||||
|
|
||||||
if __name__ == "__main__": # pragma: no cover
|
if __name__ == "__main__": # pragma: no cover
|
||||||
|
|||||||
@@ -11,6 +11,18 @@ Usage:
|
|||||||
The module runs ``make test-unit`` with ``PYTEST_ADDOPTS=--durations=0`` so
|
The module runs ``make test-unit`` with ``PYTEST_ADDOPTS=--durations=0`` so
|
||||||
that pytest emits per-test timing lines alongside the summary. Both the
|
that pytest emits per-test timing lines alongside the summary. Both the
|
||||||
total wall-clock time and individual test durations are parsed and validated.
|
total wall-clock time and individual test durations are parsed and validated.
|
||||||
|
|
||||||
|
CI runner scaling
|
||||||
|
-----------------
|
||||||
|
CI runners (Gitea Actions Docker containers) are typically 5-8x slower than
|
||||||
|
local development machines due to shared CPU, fewer cores, and container
|
||||||
|
overhead. When the ``CI`` environment variable is set (standard CI
|
||||||
|
convention), both the total and per-test limits are multiplied by
|
||||||
|
``CI_SCALE_FACTOR`` (default 6) to account for this. This keeps the local
|
||||||
|
budget strict while preventing false failures on slower CI runners.
|
||||||
|
|
||||||
|
The scale factor can be overridden via the ``DEVX_CI_SCALE_FACTOR``
|
||||||
|
environment variable.
|
||||||
"""
|
"""
|
||||||
|
|
||||||
from __future__ import annotations
|
from __future__ import annotations
|
||||||
@@ -27,6 +39,12 @@ DEFAULT_MAX_SECONDS = 10.0
|
|||||||
DEFAULT_MAX_SINGLE_SECONDS = 0.5
|
DEFAULT_MAX_SINGLE_SECONDS = 0.5
|
||||||
TEST_COMMAND = ["make", "test-unit"]
|
TEST_COMMAND = ["make", "test-unit"]
|
||||||
|
|
||||||
|
# CI runners are typically 5-8x slower than local machines (shared CPU,
|
||||||
|
# fewer cores, container overhead). Scale limits up when running on CI
|
||||||
|
# so the gate catches real regressions, not infrastructure slowness.
|
||||||
|
CI_SCALE_FACTOR = float(os.environ.get("DEVX_CI_SCALE_FACTOR", "6"))
|
||||||
|
_IS_CI = bool(os.environ.get("CI") or os.environ.get("GITEA_ACTIONS"))
|
||||||
|
|
||||||
# Matches pytest summary line: "234 passed in 0.70s"
|
# Matches pytest summary line: "234 passed in 0.70s"
|
||||||
_TIMING_RE = re.compile(r"(\d+) passed.* in ([0-9.]+)s")
|
_TIMING_RE = re.compile(r"(\d+) passed.* in ([0-9.]+)s")
|
||||||
|
|
||||||
@@ -38,6 +56,13 @@ _TIMING_RE = re.compile(r"(\d+) passed.* in ([0-9.]+)s")
|
|||||||
_DURATION_LINE_RE = re.compile(r"^(\d+\.?\d*)s\s+call\s+(.+)$")
|
_DURATION_LINE_RE = re.compile(r"^(\d+\.?\d*)s\s+call\s+(.+)$")
|
||||||
|
|
||||||
|
|
||||||
|
def _ci_scale_limit(limit: float) -> float:
|
||||||
|
"""Scale a time limit by the CI factor when running on CI."""
|
||||||
|
if _IS_CI:
|
||||||
|
return limit * CI_SCALE_FACTOR
|
||||||
|
return limit
|
||||||
|
|
||||||
|
|
||||||
def run_tests() -> tuple[str, str]:
|
def run_tests() -> tuple[str, str]:
|
||||||
"""Execute the unit-test suite and return (stdout, stderr).
|
"""Execute the unit-test suite and return (stdout, stderr).
|
||||||
|
|
||||||
@@ -123,21 +148,38 @@ def check_per_test_speed(
|
|||||||
|
|
||||||
def main(max_seconds: float, max_single_seconds: float) -> None:
|
def main(max_seconds: float, max_single_seconds: float) -> None:
|
||||||
"""Run tests, parse timings, and enforce both budgets."""
|
"""Run tests, parse timings, and enforce both budgets."""
|
||||||
|
# Scale limits for CI runners (slower CPU, fewer workers).
|
||||||
|
effective_max = _ci_scale_limit(max_seconds)
|
||||||
|
effective_single = _ci_scale_limit(max_single_seconds)
|
||||||
|
|
||||||
|
if _IS_CI:
|
||||||
|
click.echo(
|
||||||
|
_(
|
||||||
|
"[check-test-speed] CI environment detected — scaling limits by {factor}x "
|
||||||
|
"(total: {orig}s → {eff}s, per-test: {orig_s}s → {eff_s}s)",
|
||||||
|
factor=CI_SCALE_FACTOR,
|
||||||
|
orig=max_seconds,
|
||||||
|
eff=effective_max,
|
||||||
|
orig_s=max_single_seconds,
|
||||||
|
eff_s=effective_single,
|
||||||
|
)
|
||||||
|
)
|
||||||
|
|
||||||
stdout, stderr = run_tests()
|
stdout, stderr = run_tests()
|
||||||
combined = stdout + "\n" + stderr
|
combined = stdout + "\n" + stderr
|
||||||
click.echo(combined, err=False)
|
click.echo(combined, err=False)
|
||||||
|
|
||||||
duration = parse_duration(combined)
|
duration = parse_duration(combined)
|
||||||
check_speed(duration, max_seconds)
|
check_speed(duration, effective_max)
|
||||||
|
|
||||||
if max_single_seconds > 0:
|
if effective_single > 0:
|
||||||
per_test = parse_per_test_durations(combined)
|
per_test = parse_per_test_durations(combined)
|
||||||
violations = check_per_test_speed(per_test, max_single_seconds)
|
violations = check_per_test_speed(per_test, effective_single)
|
||||||
if violations:
|
if violations:
|
||||||
msg = _(
|
msg = _(
|
||||||
"Per-test speed check FAILED: {count} test(s) exceed {limit}s limit.",
|
"Per-test speed check FAILED: {count} test(s) exceed {limit}s limit.",
|
||||||
count=len(violations),
|
count=len(violations),
|
||||||
limit=max_single_seconds,
|
limit=effective_single,
|
||||||
)
|
)
|
||||||
click.echo(f"\n{msg}", err=True)
|
click.echo(f"\n{msg}", err=True)
|
||||||
for v in violations:
|
for v in violations:
|
||||||
@@ -148,8 +190,8 @@ def main(max_seconds: float, max_single_seconds: float) -> None:
|
|||||||
_(
|
_(
|
||||||
"Unit tests passed in {duration:.2f}s (under {max}s limit, all tests under {single}s per-test limit).",
|
"Unit tests passed in {duration:.2f}s (under {max}s limit, all tests under {single}s per-test limit).",
|
||||||
duration=duration,
|
duration=duration,
|
||||||
max=max_seconds,
|
max=effective_max,
|
||||||
single=max_single_seconds,
|
single=effective_single,
|
||||||
)
|
)
|
||||||
)
|
)
|
||||||
|
|
||||||
|
|||||||
@@ -5,6 +5,13 @@ Queries the Gitea API for all versions of a package (container type) and
|
|||||||
deletes all but the most recent N versions. The ``latest`` tag is always
|
deletes all but the most recent N versions. The ``latest`` tag is always
|
||||||
preserved if present.
|
preserved if present.
|
||||||
|
|
||||||
|
.. note::
|
||||||
|
This tool only deletes package versions via the Gitea API. The underlying
|
||||||
|
blob files on the Gitea server's filesystem are NOT removed by this tool
|
||||||
|
(Gitea 1.26.x has no built-in garbage collection). The production VM's
|
||||||
|
daily cleanup script (``cleanup_gitea.py``) handles filesystem blob GC
|
||||||
|
by querying the database for referenced blobs and removing orphaned files.
|
||||||
|
|
||||||
Usage::
|
Usage::
|
||||||
|
|
||||||
# Clean up ci-base images, keep last 2 versions
|
# Clean up ci-base images, keep last 2 versions
|
||||||
@@ -57,7 +64,10 @@ def list_package_versions(
|
|||||||
Returns a list of version dicts, each containing at least ``version``
|
Returns a list of version dicts, each containing at least ``version``
|
||||||
and ``created_at`` fields.
|
and ``created_at`` fields.
|
||||||
"""
|
"""
|
||||||
url = f"{api_url}/packages/{owner}?type=container&name={name}"
|
from urllib.parse import quote
|
||||||
|
|
||||||
|
encoded_name = quote(name, safe="")
|
||||||
|
url = f"{api_url}/packages/{owner}?type=container&name={encoded_name}"
|
||||||
headers = {"Authorization": f"token {token}"}
|
headers = {"Authorization": f"token {token}"}
|
||||||
all_versions: list[dict[str, Any]] = []
|
all_versions: list[dict[str, Any]] = []
|
||||||
page = 1
|
page = 1
|
||||||
@@ -96,7 +106,11 @@ def delete_package_version(
|
|||||||
|
|
||||||
Returns True on success, False on failure.
|
Returns True on success, False on failure.
|
||||||
"""
|
"""
|
||||||
url = f"{api_url}/packages/{owner}/{package_type}/{name}/{version}"
|
from urllib.parse import quote
|
||||||
|
|
||||||
|
encoded_name = quote(name, safe="")
|
||||||
|
encoded_version = quote(version, safe="")
|
||||||
|
url = f"{api_url}/packages/{owner}/{package_type}/{encoded_name}/{encoded_version}"
|
||||||
headers = {"Authorization": f"token {token}"}
|
headers = {"Authorization": f"token {token}"}
|
||||||
for attempt in range(max_retries):
|
for attempt in range(max_retries):
|
||||||
try:
|
try:
|
||||||
|
|||||||
@@ -8,6 +8,7 @@ Handles installation of:
|
|||||||
- tea (Gitea CLI — official command-line tool for Gitea API operations)
|
- tea (Gitea CLI — official command-line tool for Gitea API operations)
|
||||||
- hadolint (Dockerfile linter)
|
- hadolint (Dockerfile linter)
|
||||||
- vale (prose linter for documentation quality)
|
- vale (prose linter for documentation quality)
|
||||||
|
- promtool (Prometheus rule validator)
|
||||||
|
|
||||||
Each tool is installed to ``~/.local/bin`` if not already on PATH.
|
Each tool is installed to ``~/.local/bin`` if not already on PATH.
|
||||||
Idempotent: skips tools that are already available.
|
Idempotent: skips tools that are already available.
|
||||||
@@ -47,6 +48,8 @@ TOFU_VERSION = "1.12.3"
|
|||||||
|
|
||||||
VALE_VERSION = "3.15.1"
|
VALE_VERSION = "3.15.1"
|
||||||
|
|
||||||
|
PROMTOOL_VERSION = "3.5.5"
|
||||||
|
|
||||||
|
|
||||||
def _arch() -> str:
|
def _arch() -> str:
|
||||||
"""Return the architecture string used by release assets (delegates to shared utility)."""
|
"""Return the architecture string used by release assets (delegates to shared utility)."""
|
||||||
@@ -62,8 +65,33 @@ def _ensure_target_dir() -> Path:
|
|||||||
|
|
||||||
|
|
||||||
def _download(url: str, dest: Path) -> None:
|
def _download(url: str, dest: Path) -> None:
|
||||||
"""Download a file from ``url`` to ``dest``."""
|
"""Download a file from ``url`` to ``dest`` with a 60s timeout.
|
||||||
urllib.request.urlretrieve(url, dest) # nosec B310
|
|
||||||
|
A User-Agent header is set because some CDNs (e.g. dl.gitea.com)
|
||||||
|
return 403 to requests with Python's default User-Agent.
|
||||||
|
"""
|
||||||
|
req = urllib.request.Request(url, headers={"User-Agent": "devx/install-tools"})
|
||||||
|
with urllib.request.urlopen(req, timeout=60) as resp, open(dest, "wb") as f: # nosec B310
|
||||||
|
shutil.copyfileobj(resp, f)
|
||||||
|
|
||||||
|
|
||||||
|
def _download_with_fallback(urls: list[str], binary_name: str) -> Path:
|
||||||
|
"""Try downloading a binary from a list of URLs, falling back on failure.
|
||||||
|
|
||||||
|
Returns the path to the installed binary. Raises if all URLs fail.
|
||||||
|
"""
|
||||||
|
target_dir = _ensure_target_dir()
|
||||||
|
dest = target_dir / binary_name
|
||||||
|
errors: list[str] = []
|
||||||
|
for url in urls:
|
||||||
|
try:
|
||||||
|
_download(url, dest)
|
||||||
|
dest.chmod(0o755)
|
||||||
|
return dest
|
||||||
|
except Exception as exc: # noqa: BLE001
|
||||||
|
errors.append(f"{url}: {exc}")
|
||||||
|
click.echo(f" {binary_name}: retrying — {exc}")
|
||||||
|
raise click.ClickException(f"Failed to download {binary_name} from all URLs: {'; '.join(errors)}")
|
||||||
|
|
||||||
|
|
||||||
def _download_and_extract_tarball(url: str, binary_name: str) -> Path:
|
def _download_and_extract_tarball(url: str, binary_name: str) -> Path:
|
||||||
@@ -160,8 +188,13 @@ def install_tea() -> bool:
|
|||||||
click.echo("tea: already installed")
|
click.echo("tea: already installed")
|
||||||
return True
|
return True
|
||||||
arch = _arch()
|
arch = _arch()
|
||||||
url = f"https://dl.gitea.com/tea/{TEA_VERSION}/tea-{TEA_VERSION}-linux-{arch}"
|
# dl.gitea.com is the primary CDN, but it can return 403 from some networks.
|
||||||
dest = _download_binary(url, "tea")
|
# Fall back to the gitea.com release downloads URL.
|
||||||
|
urls = [
|
||||||
|
f"https://dl.gitea.com/tea/{TEA_VERSION}/tea-{TEA_VERSION}-linux-{arch}",
|
||||||
|
f"https://gitea.com/gitea/tea/releases/download/v{TEA_VERSION}/tea-{TEA_VERSION}-linux-{arch}",
|
||||||
|
]
|
||||||
|
dest = _download_with_fallback(urls, "tea")
|
||||||
click.echo(f"tea: installed to {dest}")
|
click.echo(f"tea: installed to {dest}")
|
||||||
return True
|
return True
|
||||||
|
|
||||||
@@ -212,7 +245,26 @@ def install_vale() -> bool:
|
|||||||
return True
|
return True
|
||||||
|
|
||||||
|
|
||||||
TOOL_NAMES = ["actionlint", "git-cliff", "act_runner", "tea", "hadolint", "tofu", "vale"]
|
def install_promtool() -> bool:
|
||||||
|
"""Install promtool (Prometheus rule validator) if not already present.
|
||||||
|
|
||||||
|
Downloads the official Prometheus release tarball from GitHub and
|
||||||
|
extracts the ``promtool`` binary to ``~/.local/bin``.
|
||||||
|
"""
|
||||||
|
if _is_installed("promtool"):
|
||||||
|
click.echo("promtool: already installed")
|
||||||
|
return True
|
||||||
|
arch = _arch()
|
||||||
|
url = (
|
||||||
|
f"https://github.com/prometheus/prometheus/releases/download/"
|
||||||
|
f"v{PROMTOOL_VERSION}/prometheus-{PROMTOOL_VERSION}.linux-{arch}.tar.gz"
|
||||||
|
)
|
||||||
|
dest = _download_and_extract_tarball(url, "promtool")
|
||||||
|
click.echo(f"promtool: installed to {dest}")
|
||||||
|
return True
|
||||||
|
|
||||||
|
|
||||||
|
TOOL_NAMES = ["actionlint", "git-cliff", "act_runner", "tea", "hadolint", "tofu", "vale", "promtool"]
|
||||||
|
|
||||||
|
|
||||||
def _install_tool(name: str) -> bool:
|
def _install_tool(name: str) -> bool:
|
||||||
@@ -231,6 +283,8 @@ def _install_tool(name: str) -> bool:
|
|||||||
return install_tofu()
|
return install_tofu()
|
||||||
if name == "vale":
|
if name == "vale":
|
||||||
return install_vale()
|
return install_vale()
|
||||||
|
if name == "promtool":
|
||||||
|
return install_promtool()
|
||||||
raise click.ClickException(f"Unknown tool: {name}")
|
raise click.ClickException(f"Unknown tool: {name}")
|
||||||
|
|
||||||
|
|
||||||
|
|||||||
+12
-2
@@ -15,6 +15,7 @@ from pathlib import Path
|
|||||||
|
|
||||||
import click
|
import click
|
||||||
from dotenv import load_dotenv # pyright: ignore[reportMissingImports,reportUnknownVariableType]
|
from dotenv import load_dotenv # pyright: ignore[reportMissingImports,reportUnknownVariableType]
|
||||||
|
from tenacity import retry, stop_after_attempt, wait_exponential
|
||||||
|
|
||||||
from devx.tokens import get_developer_token
|
from devx.tokens import get_developer_token
|
||||||
|
|
||||||
@@ -56,13 +57,22 @@ def _install_pre_commit_hooks(bin_dir: str) -> None:
|
|||||||
|
|
||||||
|
|
||||||
def _install_ansible_collections(bin_dir: str) -> None:
|
def _install_ansible_collections(bin_dir: str) -> None:
|
||||||
"""Install required Ansible Galaxy collections if requirements exist."""
|
"""Install required Ansible Galaxy collections if requirements exist.
|
||||||
|
|
||||||
|
Retries up to 3 times with exponential backoff to handle transient
|
||||||
|
network timeouts when contacting galaxy.ansible.com.
|
||||||
|
"""
|
||||||
galaxy = shutil.which("ansible-galaxy") or str(Path(bin_dir) / "ansible-galaxy")
|
galaxy = shutil.which("ansible-galaxy") or str(Path(bin_dir) / "ansible-galaxy")
|
||||||
requirements = Path("ansible/requirements.yml")
|
requirements = Path("ansible/requirements.yml")
|
||||||
if not requirements.exists():
|
if not requirements.exists():
|
||||||
click.echo(" ansible/requirements.yml not found — skipping collections.")
|
click.echo(" ansible/requirements.yml not found — skipping collections.")
|
||||||
return
|
return
|
||||||
_run([galaxy, "collection", "install", "-r", str(requirements)])
|
|
||||||
|
@retry(stop=stop_after_attempt(3), wait=wait_exponential(multiplier=2, min=2, max=10), reraise=True)
|
||||||
|
def _do_install() -> None:
|
||||||
|
_run([galaxy, "collection", "install", "-r", str(requirements)])
|
||||||
|
|
||||||
|
_do_install()
|
||||||
|
|
||||||
|
|
||||||
def _configure_tea_login() -> None:
|
def _configure_tea_login() -> None:
|
||||||
|
|||||||
@@ -64,9 +64,11 @@ def _install_in_image(
|
|||||||
link.symlink_to(opt_venv)
|
link.symlink_to(opt_venv)
|
||||||
|
|
||||||
# Build pip install command
|
# Build pip install command
|
||||||
|
# --no-deps: the CI image already has all dependencies pre-installed.
|
||||||
|
# We only need to install the project itself in editable mode.
|
||||||
spec = f".[{extras}]" if extras else "."
|
spec = f".[{extras}]" if extras else "."
|
||||||
pip_bin = str(Path(venv_link) / "bin" / "pip")
|
pip_bin = str(Path(venv_link) / "bin" / "pip")
|
||||||
cmd = [pip_bin, "install", "--no-cache-dir", "-e", spec]
|
cmd = [pip_bin, "install", "--no-cache-dir", "--no-deps", "-e", spec]
|
||||||
|
|
||||||
env = os.environ.copy()
|
env = os.environ.copy()
|
||||||
try:
|
try:
|
||||||
@@ -81,6 +83,17 @@ def _install_in_image(
|
|||||||
username,
|
username,
|
||||||
token,
|
token,
|
||||||
)
|
)
|
||||||
|
# Configure git URL rewrite so git+https dependencies can authenticate
|
||||||
|
subprocess.run( # nosec B603, B607
|
||||||
|
[
|
||||||
|
"git",
|
||||||
|
"config",
|
||||||
|
"--global",
|
||||||
|
f"url.https://{username}:{token}@{gitea_host}/.insteadOf",
|
||||||
|
f"https://{gitea_host}/",
|
||||||
|
],
|
||||||
|
check=True,
|
||||||
|
)
|
||||||
|
|
||||||
click.echo(f"[setup-image] Linked {opt_venv}" + (f" with [{extras}]" if extras else "") + ".")
|
click.echo(f"[setup-image] Linked {opt_venv}" + (f" with [{extras}]" if extras else "") + ".")
|
||||||
subprocess.run(cmd, check=True, env=env) # nosec B603
|
subprocess.run(cmd, check=True, env=env) # nosec B603
|
||||||
|
|||||||
+176
-24
@@ -183,14 +183,6 @@
|
|||||||
"ru": "\nTag → Commit alignment:",
|
"ru": "\nTag → Commit alignment:",
|
||||||
"zh": "\nTag → Commit alignment:"
|
"zh": "\nTag → Commit alignment:"
|
||||||
},
|
},
|
||||||
"\nTest isolation check FAILED: {count} violation(s) in {files} file(s).\nFix: add @patch decorators for subprocess/time.sleep calls, or patch the calling function.\n": {
|
|
||||||
"bg": "\nПроверката за изолация на тестове НЕ ПРЕМИНА: {count} нарушения в {files} файла.\nРешение: добавете @patch декоратори за subprocess/time.sleep извиквания или patch-нете извикващата функция.\n",
|
|
||||||
"de": "\nTestisolationsprüfung FEHLGESCHLAGEN: {count} Verstoß/Verstöße in {files} Datei(en).\nBehebung: @patch-Dekoratoren für subprocess/time.sleep-Aufrufe hinzufügen oder die aufrufende Funktion patchen.\n",
|
|
||||||
"en": "\nTest isolation check FAILED: {count} violation(s) in {files} file(s).\nFix: add @patch decorators for subprocess/time.sleep calls, or patch the calling function.\n",
|
|
||||||
"pl": "\nSprawdzenie izolacji testów NIE ZALICZONE: {count} naruszeń w {files} plikach.\nNaprawa: dodaj dekoratory @patch dla wywołań subprocess/time.sleep lub patchuj wywołującą funkcję.\n",
|
|
||||||
"ru": "\nПроверка изоляции тестов НЕ ПРОЙДЕНА: {count} нарушений в {files} файлах.\nИсправление: добавьте декораторы @patch для вызовов subprocess/time.sleep или patch вызывающую функцию.\n",
|
|
||||||
"zh": "\n测试隔离检查失败:在 {files} 个文件中有 {count} 个违规。\n修复:为 subprocess/time.sleep 调用添加 @patch 装饰器,或 patch 调用函数。\n"
|
|
||||||
},
|
|
||||||
"\nUntagged release commits:": {
|
"\nUntagged release commits:": {
|
||||||
"bg": "\nUntagged release commits:",
|
"bg": "\nUntagged release commits:",
|
||||||
"de": "\nUntagged release commits:",
|
"de": "\nUntagged release commits:",
|
||||||
@@ -1583,14 +1575,6 @@
|
|||||||
"ru": "Fetching origin/master...",
|
"ru": "Fetching origin/master...",
|
||||||
"zh": "Fetching origin/master..."
|
"zh": "Fetching origin/master..."
|
||||||
},
|
},
|
||||||
"Fix: add @patch decorators for subprocess/time.sleep calls, or patch the calling function. Use property-based testing for statistical tests.": {
|
|
||||||
"bg": "Решение: добавете @patch декоратори за subprocess/time.sleep извиквания или patch-нете извикващата функция. Използвайте property-based тестове за статистически тестове.",
|
|
||||||
"de": "Behebung: @patch-Dekoratoren für subprocess/time.sleep-Aufrufe hinzufügen oder die aufrufende Funktion patchen. Property-based testing für statistische Tests verwenden.",
|
|
||||||
"en": "Fix: add @patch decorators for subprocess/time.sleep calls, or patch the calling function. Use property-based testing for statistical tests.",
|
|
||||||
"pl": "Naprawa: dodaj dekoratory @patch dla wywołań subprocess/time.sleep lub patchuj wywołującą funkcję. Użyj testów opartych na właściwościach dla testów statystycznych.",
|
|
||||||
"ru": "Исправление: добавьте декораторы @patch для вызовов subprocess/time.sleep или patch вызывающую функцию. Используйте property-based тестирование для статистических тестов.",
|
|
||||||
"zh": "修复:为 subprocess/time.sleep 调用添加 @patch 装饰器,或 patch 调用函数。对统计测试使用基于属性的测试。"
|
|
||||||
},
|
|
||||||
"Force-push failed:\n{error}\nThe remote may have unexpected commits. Fetch and try again.": {
|
"Force-push failed:\n{error}\nThe remote may have unexpected commits. Fetch and try again.": {
|
||||||
"bg": "Force-push failed:\n{error}\nThe remote may have unexpected commits. Fetch and try again.",
|
"bg": "Force-push failed:\n{error}\nThe remote may have unexpected commits. Fetch and try again.",
|
||||||
"de": "Force-push failed:\n{error}\nThe remote may have unexpected commits. Fetch and try again.",
|
"de": "Force-push failed:\n{error}\nThe remote may have unexpected commits. Fetch and try again.",
|
||||||
@@ -2903,14 +2887,6 @@
|
|||||||
"ru": "Test '{name}' took {elapsed:.2f}s (limit: {limit}s). Optimise: use lighter fixtures, reduce I/O, or mock external calls.",
|
"ru": "Test '{name}' took {elapsed:.2f}s (limit: {limit}s). Optimise: use lighter fixtures, reduce I/O, or mock external calls.",
|
||||||
"zh": "Test '{name}' took {elapsed:.2f}s (limit: {limit}s). Optimise: use lighter fixtures, reduce I/O, or mock external calls."
|
"zh": "Test '{name}' took {elapsed:.2f}s (limit: {limit}s). Optimise: use lighter fixtures, reduce I/O, or mock external calls."
|
||||||
},
|
},
|
||||||
"Test isolation check FAILED: {count} violation(s) found in {files} test file(s).": {
|
|
||||||
"bg": "Проверката за изолация на тестове НЕ ПРЕМИНА: открити са {count} нарушения в {files} тестови файла.",
|
|
||||||
"de": "Testisolationsprüfung FEHLGESCHLAGEN: {count} Verstoß/Verstöße in {files} Testdatei(en) gefunden.",
|
|
||||||
"en": "Test isolation check FAILED: {count} violation(s) found in {files} test file(s).",
|
|
||||||
"pl": "Sprawdzenie izolacji testów NIE ZALICZONE: znaleziono {count} naruszeń w {files} plikach testowych.",
|
|
||||||
"ru": "Проверка изоляции тестов НЕ ПРОЙДЕНА: найдено {count} нарушений в {files} тестовых файлах.",
|
|
||||||
"zh": "测试隔离检查失败:在 {files} 个测试文件中发现 {count} 个违规。"
|
|
||||||
},
|
|
||||||
"Test isolation check passed: {count} test files analyzed, no violations found.": {
|
"Test isolation check passed: {count} test files analyzed, no violations found.": {
|
||||||
"bg": "Проверката за изолация на тестове премина: анализирани са {count} тестови файла, няма нарушения.",
|
"bg": "Проверката за изолация на тестове премина: анализирани са {count} тестови файла, няма нарушения.",
|
||||||
"de": "Testisolationsprüfung bestanden: {count} Testdateien analysiert, keine Verstöße gefunden.",
|
"de": "Testisolationsprüfung bestanden: {count} Testdateien analysiert, keine Verstöße gefunden.",
|
||||||
@@ -3686,5 +3662,181 @@
|
|||||||
"pl": "{separator}",
|
"pl": "{separator}",
|
||||||
"ru": "{separator}",
|
"ru": "{separator}",
|
||||||
"zh": "{separator}"
|
"zh": "{separator}"
|
||||||
|
},
|
||||||
|
"\nTest isolation check FAILED: {count} violation(s) in {files} file(s).\n": {
|
||||||
|
"bg": "\nTest isolation check FAILED: {count} violation(s) in {files} file(s).\n",
|
||||||
|
"de": "\nTest isolation check FAILED: {count} violation(s) in {files} file(s).\n",
|
||||||
|
"en": "\nTest isolation check FAILED: {count} violation(s) in {files} file(s).\n",
|
||||||
|
"pl": "\nTest isolation check FAILED: {count} violation(s) in {files} file(s).\n",
|
||||||
|
"ru": "\nTest isolation check FAILED: {count} violation(s) in {files} file(s).\n",
|
||||||
|
"zh": "\nTest isolation check FAILED: {count} violation(s) in {files} file(s).\n"
|
||||||
|
},
|
||||||
|
" Fix the PR title with:\n python3 -m devx.ci.fix_pr_title --repo {repo} --pr-number {pr}\n Or manually set the PR title to: '{expected}'": {
|
||||||
|
"bg": " Fix the PR title with:\n python3 -m devx.ci.fix_pr_title --repo {repo} --pr-number {pr}\n Or manually set the PR title to: '{expected}'",
|
||||||
|
"de": " Fix the PR title with:\n python3 -m devx.ci.fix_pr_title --repo {repo} --pr-number {pr}\n Or manually set the PR title to: '{expected}'",
|
||||||
|
"en": " Fix the PR title with:\n python3 -m devx.ci.fix_pr_title --repo {repo} --pr-number {pr}\n Or manually set the PR title to: '{expected}'",
|
||||||
|
"pl": " Fix the PR title with:\n python3 -m devx.ci.fix_pr_title --repo {repo} --pr-number {pr}\n Or manually set the PR title to: '{expected}'",
|
||||||
|
"ru": " Fix the PR title with:\n python3 -m devx.ci.fix_pr_title --repo {repo} --pr-number {pr}\n Or manually set the PR title to: '{expected}'",
|
||||||
|
"zh": " Fix the PR title with:\n python3 -m devx.ci.fix_pr_title --repo {repo} --pr-number {pr}\n Or manually set the PR title to: '{expected}'"
|
||||||
|
},
|
||||||
|
"Add @patch(\"subprocess.run\") or patch the calling function to fix this.": {
|
||||||
|
"bg": "Add @patch(\"subprocess.run\") or patch the calling function to fix this.",
|
||||||
|
"de": "Add @patch(\"subprocess.run\") or patch the calling function to fix this.",
|
||||||
|
"en": "Add @patch(\"subprocess.run\") or patch the calling function to fix this.",
|
||||||
|
"pl": "Add @patch(\"subprocess.run\") or patch the calling function to fix this.",
|
||||||
|
"ru": "Add @patch(\"subprocess.run\") or patch the calling function to fix this.",
|
||||||
|
"zh": "Add @patch(\"subprocess.run\") or patch the calling function to fix this."
|
||||||
|
},
|
||||||
|
"Branch name (auto-fetched from PR if not given)": {
|
||||||
|
"bg": "Branch name (auto-fetched from PR if not given)",
|
||||||
|
"de": "Branch name (auto-fetched from PR if not given)",
|
||||||
|
"en": "Branch name (auto-fetched from PR if not given)",
|
||||||
|
"pl": "Branch name (auto-fetched from PR if not given)",
|
||||||
|
"ru": "Branch name (auto-fetched from PR if not given)",
|
||||||
|
"zh": "Branch name (auto-fetched from PR if not given)"
|
||||||
|
},
|
||||||
|
"CI_GITEA_API_TOKEN not set: {error}": {
|
||||||
|
"bg": "CI_GITEA_API_TOKEN not set: {error}",
|
||||||
|
"de": "CI_GITEA_API_TOKEN not set: {error}",
|
||||||
|
"en": "CI_GITEA_API_TOKEN not set: {error}",
|
||||||
|
"pl": "CI_GITEA_API_TOKEN not set: {error}",
|
||||||
|
"ru": "CI_GITEA_API_TOKEN not set: {error}",
|
||||||
|
"zh": "CI_GITEA_API_TOKEN not set: {error}"
|
||||||
|
},
|
||||||
|
"CliRunner.invoke({target}) in test '{test}' reaches unpatched dangerous functions: {funcs}. Add @patch for each or patch the calling function.": {
|
||||||
|
"bg": "CliRunner.invoke({target}) in test '{test}' reaches unpatched dangerous functions: {funcs}. Add @patch for each or patch the calling function.",
|
||||||
|
"de": "CliRunner.invoke({target}) in test '{test}' reaches unpatched dangerous functions: {funcs}. Add @patch for each or patch the calling function.",
|
||||||
|
"en": "CliRunner.invoke({target}) in test '{test}' reaches unpatched dangerous functions: {funcs}. Add @patch for each or patch the calling function.",
|
||||||
|
"pl": "CliRunner.invoke({target}) in test '{test}' reaches unpatched dangerous functions: {funcs}. Add @patch for each or patch the calling function.",
|
||||||
|
"ru": "CliRunner.invoke({target}) in test '{test}' reaches unpatched dangerous functions: {funcs}. Add @patch for each or patch the calling function.",
|
||||||
|
"zh": "CliRunner.invoke({target}) in test '{test}' reaches unpatched dangerous functions: {funcs}. Add @patch for each or patch the calling function."
|
||||||
|
},
|
||||||
|
"Could not determine branch name from PR #{pr}": {
|
||||||
|
"bg": "Could not determine branch name from PR #{pr}",
|
||||||
|
"de": "Could not determine branch name from PR #{pr}",
|
||||||
|
"en": "Could not determine branch name from PR #{pr}",
|
||||||
|
"pl": "Could not determine branch name from PR #{pr}",
|
||||||
|
"ru": "Could not determine branch name from PR #{pr}",
|
||||||
|
"zh": "Could not determine branch name from PR #{pr}"
|
||||||
|
},
|
||||||
|
"Failed to fetch PR #{pr}: {error}": {
|
||||||
|
"bg": "Failed to fetch PR #{pr}: {error}",
|
||||||
|
"de": "Failed to fetch PR #{pr}: {error}",
|
||||||
|
"en": "Failed to fetch PR #{pr}: {error}",
|
||||||
|
"pl": "Failed to fetch PR #{pr}: {error}",
|
||||||
|
"ru": "Failed to fetch PR #{pr}: {error}",
|
||||||
|
"zh": "Failed to fetch PR #{pr}: {error}"
|
||||||
|
},
|
||||||
|
"Failed to update PR #{pr}: {error}": {
|
||||||
|
"bg": "Failed to update PR #{pr}: {error}",
|
||||||
|
"de": "Failed to update PR #{pr}: {error}",
|
||||||
|
"en": "Failed to update PR #{pr}: {error}",
|
||||||
|
"pl": "Failed to update PR #{pr}: {error}",
|
||||||
|
"ru": "Failed to update PR #{pr}: {error}",
|
||||||
|
"zh": "Failed to update PR #{pr}: {error}"
|
||||||
|
},
|
||||||
|
"Fix: add @patch decorators or with patch() context managers for subprocess/time.sleep calls, or patch the calling function.": {
|
||||||
|
"bg": "Fix: add @patch decorators or with patch() context managers for subprocess/time.sleep calls, or patch the calling function.",
|
||||||
|
"de": "Fix: add @patch decorators or with patch() context managers for subprocess/time.sleep calls, or patch the calling function.",
|
||||||
|
"en": "Fix: add @patch decorators or with patch() context managers for subprocess/time.sleep calls, or patch the calling function.",
|
||||||
|
"pl": "Fix: add @patch decorators or with patch() context managers for subprocess/time.sleep calls, or patch the calling function.",
|
||||||
|
"ru": "Fix: add @patch decorators or with patch() context managers for subprocess/time.sleep calls, or patch the calling function.",
|
||||||
|
"zh": "Fix: add @patch decorators or with patch() context managers for subprocess/time.sleep calls, or patch the calling function."
|
||||||
|
},
|
||||||
|
"Fix: add @patch decorators or with patch() context managers for subprocess/time.sleep calls, or patch the calling function.\n": {
|
||||||
|
"bg": "Fix: add @patch decorators or with patch() context managers for subprocess/time.sleep calls, or patch the calling function.\n",
|
||||||
|
"de": "Fix: add @patch decorators or with patch() context managers for subprocess/time.sleep calls, or patch the calling function.\n",
|
||||||
|
"en": "Fix: add @patch decorators or with patch() context managers for subprocess/time.sleep calls, or patch the calling function.\n",
|
||||||
|
"pl": "Fix: add @patch decorators or with patch() context managers for subprocess/time.sleep calls, or patch the calling function.\n",
|
||||||
|
"ru": "Fix: add @patch decorators or with patch() context managers for subprocess/time.sleep calls, or patch the calling function.\n",
|
||||||
|
"zh": "Fix: add @patch decorators or with patch() context managers for subprocess/time.sleep calls, or patch the calling function.\n"
|
||||||
|
},
|
||||||
|
"Heavy import '{mod}' (~{ms:.0f}ms) at module level — this slows test collection for all tests. Move inside test functions or use lazy import.": {
|
||||||
|
"bg": "Heavy import '{mod}' (~{ms:.0f}ms) at module level — this slows test collection for all tests. Move inside test functions or use lazy import.",
|
||||||
|
"de": "Heavy import '{mod}' (~{ms:.0f}ms) at module level — this slows test collection for all tests. Move inside test functions or use lazy import.",
|
||||||
|
"en": "Heavy import '{mod}' (~{ms:.0f}ms) at module level — this slows test collection for all tests. Move inside test functions or use lazy import.",
|
||||||
|
"pl": "Heavy import '{mod}' (~{ms:.0f}ms) at module level — this slows test collection for all tests. Move inside test functions or use lazy import.",
|
||||||
|
"ru": "Heavy import '{mod}' (~{ms:.0f}ms) at module level — this slows test collection for all tests. Move inside test functions or use lazy import.",
|
||||||
|
"zh": "Heavy import '{mod}' (~{ms:.0f}ms) at module level — this slows test collection for all tests. Move inside test functions or use lazy import."
|
||||||
|
},
|
||||||
|
"No task ID found in branch '{branch}'. Expected format: {prefix}-N-description.": {
|
||||||
|
"bg": "No task ID found in branch '{branch}'. Expected format: {prefix}-N-description.",
|
||||||
|
"de": "No task ID found in branch '{branch}'. Expected format: {prefix}-N-description.",
|
||||||
|
"en": "No task ID found in branch '{branch}'. Expected format: {prefix}-N-description.",
|
||||||
|
"pl": "No task ID found in branch '{branch}'. Expected format: {prefix}-N-description.",
|
||||||
|
"ru": "No task ID found in branch '{branch}'. Expected format: {prefix}-N-description.",
|
||||||
|
"zh": "No task ID found in branch '{branch}'. Expected format: {prefix}-N-description."
|
||||||
|
},
|
||||||
|
"PR number to fix": {
|
||||||
|
"bg": "PR number to fix",
|
||||||
|
"de": "PR number to fix",
|
||||||
|
"en": "PR number to fix",
|
||||||
|
"pl": "PR number to fix",
|
||||||
|
"ru": "PR number to fix",
|
||||||
|
"zh": "PR number to fix"
|
||||||
|
},
|
||||||
|
"Real subprocess call(s) detected in test '{test}' without @patch:": {
|
||||||
|
"bg": "Real subprocess call(s) detected in test '{test}' without @patch:",
|
||||||
|
"de": "Real subprocess call(s) detected in test '{test}' without @patch:",
|
||||||
|
"en": "Real subprocess call(s) detected in test '{test}' without @patch:",
|
||||||
|
"pl": "Real subprocess call(s) detected in test '{test}' without @patch:",
|
||||||
|
"ru": "Real subprocess call(s) detected in test '{test}' without @patch:",
|
||||||
|
"zh": "Real subprocess call(s) detected in test '{test}' without @patch:"
|
||||||
|
},
|
||||||
|
"Show what would change without updating": {
|
||||||
|
"bg": "Show what would change without updating",
|
||||||
|
"de": "Show what would change without updating",
|
||||||
|
"en": "Show what would change without updating",
|
||||||
|
"pl": "Show what would change without updating",
|
||||||
|
"ru": "Show what would change without updating",
|
||||||
|
"zh": "Show what would change without updating"
|
||||||
|
},
|
||||||
|
"Test isolation check FAILED: {count} violation(s) in {files} file(s).": {
|
||||||
|
"bg": "Test isolation check FAILED: {count} violation(s) in {files} file(s).",
|
||||||
|
"de": "Test isolation check FAILED: {count} violation(s) in {files} file(s).",
|
||||||
|
"en": "Test isolation check FAILED: {count} violation(s) in {files} file(s).",
|
||||||
|
"pl": "Test isolation check FAILED: {count} violation(s) in {files} file(s).",
|
||||||
|
"ru": "Test isolation check FAILED: {count} violation(s) in {files} file(s).",
|
||||||
|
"zh": "Test isolation check FAILED: {count} violation(s) in {files} file(s)."
|
||||||
|
},
|
||||||
|
"Test isolation check passed with {count} advisory warning(s) in {files} file(s).": {
|
||||||
|
"bg": "Test isolation check passed with {count} advisory warning(s) in {files} file(s).",
|
||||||
|
"de": "Test isolation check passed with {count} advisory warning(s) in {files} file(s).",
|
||||||
|
"en": "Test isolation check passed with {count} advisory warning(s) in {files} file(s).",
|
||||||
|
"pl": "Test isolation check passed with {count} advisory warning(s) in {files} file(s).",
|
||||||
|
"ru": "Test isolation check passed with {count} advisory warning(s) in {files} file(s).",
|
||||||
|
"zh": "Test isolation check passed with {count} advisory warning(s) in {files} file(s)."
|
||||||
|
},
|
||||||
|
"Transitive-subprocess advisories (runtime audit is authoritative):": {
|
||||||
|
"bg": "Transitive-subprocess advisories (runtime audit is authoritative):",
|
||||||
|
"de": "Transitive-subprocess advisories (runtime audit is authoritative):",
|
||||||
|
"en": "Transitive-subprocess advisories (runtime audit is authoritative):",
|
||||||
|
"pl": "Transitive-subprocess advisories (runtime audit is authoritative):",
|
||||||
|
"ru": "Transitive-subprocess advisories (runtime audit is authoritative):",
|
||||||
|
"zh": "Transitive-subprocess advisories (runtime audit is authoritative):"
|
||||||
|
},
|
||||||
|
"importlib.reload({mod}) called {n} time(s) in test '{test}' — odd count leaves module in modified state. Add a final reload to restore defaults or wrap in try/finally.": {
|
||||||
|
"bg": "importlib.reload({mod}) called {n} time(s) in test '{test}' — odd count leaves module in modified state. Add a final reload to restore defaults or wrap in try/finally.",
|
||||||
|
"de": "importlib.reload({mod}) called {n} time(s) in test '{test}' — odd count leaves module in modified state. Add a final reload to restore defaults or wrap in try/finally.",
|
||||||
|
"en": "importlib.reload({mod}) called {n} time(s) in test '{test}' — odd count leaves module in modified state. Add a final reload to restore defaults or wrap in try/finally.",
|
||||||
|
"pl": "importlib.reload({mod}) called {n} time(s) in test '{test}' — odd count leaves module in modified state. Add a final reload to restore defaults or wrap in try/finally.",
|
||||||
|
"ru": "importlib.reload({mod}) called {n} time(s) in test '{test}' — odd count leaves module in modified state. Add a final reload to restore defaults or wrap in try/finally.",
|
||||||
|
"zh": "importlib.reload({mod}) called {n} time(s) in test '{test}' — odd count leaves module in modified state. Add a final reload to restore defaults or wrap in try/finally."
|
||||||
|
},
|
||||||
|
"[check-test-speed] CI environment detected — scaling limits by {factor}x (total: {orig}s → {eff}s, per-test: {orig_s}s → {eff_s}s)": {
|
||||||
|
"en": "[check-test-speed] CI environment detected — scaling limits by {factor}x (total: {orig}s → {eff}s, per-test: {orig_s}s → {eff_s}s)",
|
||||||
|
"bg": "[check-test-speed] CI environment detected — scaling limits by {factor}x (total: {orig}s → {eff}s, per-test: {orig_s}s → {eff_s}s)",
|
||||||
|
"de": "[check-test-speed] CI environment detected — scaling limits by {factor}x (total: {orig}s → {eff}s, per-test: {orig_s}s → {eff_s}s)",
|
||||||
|
"pl": "[check-test-speed] CI environment detected — scaling limits by {factor}x (total: {orig}s → {eff}s, per-test: {orig_s}s → {eff_s}s)",
|
||||||
|
"ru": "[check-test-speed] CI environment detected — scaling limits by {factor}x (total: {orig}s → {eff}s, per-test: {orig_s}s → {eff_s}s)",
|
||||||
|
"zh": "[check-test-speed] CI environment detected — scaling limits by {factor}x (total: {orig}s → {eff}s, per-test: {orig_s}s → {eff_s}s)"
|
||||||
|
},
|
||||||
|
"Cleaning up: running molecule destroy for {scenario}": {
|
||||||
|
"en": "Cleaning up: running molecule destroy for {scenario}",
|
||||||
|
"bg": "Изчистване: изпълнение на molecule destroy за {scenario}",
|
||||||
|
"de": "Aufräumen: molecule destroy wird ausgeführt für {scenario}",
|
||||||
|
"pl": "Czyszczenie: uruchamianie molecule destroy dla {scenario}",
|
||||||
|
"ru": "Очистка: запуск molecule destroy для {scenario}",
|
||||||
|
"zh": "清理:正在为 {scenario} 运行 molecule destroy"
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|||||||
+94
-6
@@ -1,14 +1,26 @@
|
|||||||
#!/usr/bin/env python3
|
#!/usr/bin/env python3
|
||||||
"""Utilities for handling API response values.
|
"""Utilities for handling API response values and base HTTP API client.
|
||||||
|
|
||||||
Many APIs return boolean values as strings (``"true"``, ``"false"``)
|
This module provides two categories of utilities:
|
||||||
rather than native JSON booleans. The Mattermost ``/api/v4/config/client``
|
|
||||||
endpoint is a notable example. These helpers handle both string and
|
1. **Response helpers** — :func:`is_truthy` and :func:`is_falsy` handle
|
||||||
boolean responses safely.
|
APIs that return boolean values as strings (``"true"``, ``"false"``)
|
||||||
|
rather than native JSON booleans.
|
||||||
|
|
||||||
|
2. **Base API client** — :class:`APIClient` provides a reusable base
|
||||||
|
class for HTTP API clients with consistent timeout handling, header
|
||||||
|
propagation, and automatic raising on 4xx/5xx responses.
|
||||||
|
|
||||||
Usage::
|
Usage::
|
||||||
|
|
||||||
from devx.utils.api import is_truthy, is_falsy
|
from devx.utils.api import APIClient, is_truthy
|
||||||
|
|
||||||
|
class MyClient(APIClient):
|
||||||
|
def __init__(self):
|
||||||
|
super().__init__(
|
||||||
|
base_url="https://api.example.com",
|
||||||
|
headers={"Authorization": "Bearer token"},
|
||||||
|
)
|
||||||
|
|
||||||
if not is_truthy(config.get("EnableOpenServer")):
|
if not is_truthy(config.get("EnableOpenServer")):
|
||||||
raise ValueError("EnableOpenServer not enabled")
|
raise ValueError("EnableOpenServer not enabled")
|
||||||
@@ -16,6 +28,82 @@ Usage::
|
|||||||
|
|
||||||
from __future__ import annotations
|
from __future__ import annotations
|
||||||
|
|
||||||
|
import requests
|
||||||
|
|
||||||
|
|
||||||
|
class APIClient:
|
||||||
|
"""Base class for HTTP API clients.
|
||||||
|
|
||||||
|
Subclasses set ``base_url``, ``headers``, and optionally ``auth`` in
|
||||||
|
their constructor, then use :meth:`_request` or the convenience
|
||||||
|
methods (:meth:`get`, :meth:`post`, etc.) to make requests.
|
||||||
|
|
||||||
|
All requests raise :class:`requests.HTTPError` on 4xx/5xx responses
|
||||||
|
via :meth:`requests.Response.raise_for_status`.
|
||||||
|
"""
|
||||||
|
|
||||||
|
def __init__(
|
||||||
|
self,
|
||||||
|
base_url: str,
|
||||||
|
headers: dict,
|
||||||
|
timeout: int = 30,
|
||||||
|
verify: bool = True,
|
||||||
|
auth: tuple[str, str] | None = None,
|
||||||
|
) -> None:
|
||||||
|
"""Initialize the API client.
|
||||||
|
|
||||||
|
Args:
|
||||||
|
base_url: Base URL for the API (trailing slash stripped).
|
||||||
|
headers: Default headers sent with every request.
|
||||||
|
timeout: Request timeout in seconds.
|
||||||
|
verify: Whether to verify TLS certificates.
|
||||||
|
auth: Optional ``(username, password)`` tuple for basic auth.
|
||||||
|
"""
|
||||||
|
self.base_url = base_url.rstrip("/")
|
||||||
|
self.headers = headers
|
||||||
|
self.timeout = timeout
|
||||||
|
self.verify = verify
|
||||||
|
self.auth = auth
|
||||||
|
|
||||||
|
def _request(self, method: str, path: str, **kwargs) -> requests.Response:
|
||||||
|
"""Execute an HTTP request against the API.
|
||||||
|
|
||||||
|
The URL is constructed as ``{base_url}{path}``. Default timeout,
|
||||||
|
verify, auth, and headers are applied but can be overridden via
|
||||||
|
``kwargs``.
|
||||||
|
|
||||||
|
Raises:
|
||||||
|
requests.HTTPError: On 4xx/5xx response status codes.
|
||||||
|
"""
|
||||||
|
url = f"{self.base_url}{path}"
|
||||||
|
kwargs.setdefault("timeout", self.timeout)
|
||||||
|
kwargs.setdefault("verify", self.verify)
|
||||||
|
if self.auth is not None:
|
||||||
|
kwargs.setdefault("auth", self.auth)
|
||||||
|
resp = requests.request(method, url, headers=self.headers, **kwargs) # noqa: S113
|
||||||
|
resp.raise_for_status()
|
||||||
|
return resp
|
||||||
|
|
||||||
|
def get(self, path: str, **kwargs) -> requests.Response:
|
||||||
|
"""Send a GET request."""
|
||||||
|
return self._request("GET", path, **kwargs)
|
||||||
|
|
||||||
|
def post(self, path: str, **kwargs) -> requests.Response:
|
||||||
|
"""Send a POST request."""
|
||||||
|
return self._request("POST", path, **kwargs)
|
||||||
|
|
||||||
|
def put(self, path: str, **kwargs) -> requests.Response:
|
||||||
|
"""Send a PUT request."""
|
||||||
|
return self._request("PUT", path, **kwargs)
|
||||||
|
|
||||||
|
def delete(self, path: str, **kwargs) -> requests.Response:
|
||||||
|
"""Send a DELETE request."""
|
||||||
|
return self._request("DELETE", path, **kwargs)
|
||||||
|
|
||||||
|
def patch(self, path: str, **kwargs) -> requests.Response:
|
||||||
|
"""Send a PATCH request."""
|
||||||
|
return self._request("PATCH", path, **kwargs)
|
||||||
|
|
||||||
|
|
||||||
def is_truthy(value: str | bool | None) -> bool:
|
def is_truthy(value: str | bool | None) -> bool:
|
||||||
"""Check if an API config value is truthy.
|
"""Check if an API config value is truthy.
|
||||||
|
|||||||
@@ -0,0 +1,133 @@
|
|||||||
|
"""Shared Jinja2 environment helpers for unit tests and template rendering.
|
||||||
|
|
||||||
|
Creating a Jinja2 Environment is expensive (filesystem scanning, template
|
||||||
|
compilation). These helpers create cached environments with
|
||||||
|
``auto_reload=False`` to skip stat() calls on every ``get_template``,
|
||||||
|
which is the single biggest speedup for template-heavy test suites.
|
||||||
|
|
||||||
|
The filters mimic Ansible builtins not available in plain Jinja2,
|
||||||
|
making it possible to render Ansible templates outside of Ansible
|
||||||
|
(e.g. in unit tests or config generation scripts).
|
||||||
|
|
||||||
|
Usage::
|
||||||
|
|
||||||
|
from devx.utils.jinja import make_env, render_template
|
||||||
|
|
||||||
|
env = make_env("/path/to/templates")
|
||||||
|
output = render_template(env, "alert-rules.yml.j2", grafana_base_url="https://grafana.example.com")
|
||||||
|
"""
|
||||||
|
|
||||||
|
from __future__ import annotations
|
||||||
|
|
||||||
|
import functools
|
||||||
|
import json
|
||||||
|
import re
|
||||||
|
|
||||||
|
import jinja2
|
||||||
|
|
||||||
|
# ---------------------------------------------------------------------------
|
||||||
|
# Filters (mimic Ansible builtins not available in plain Jinja2)
|
||||||
|
# ---------------------------------------------------------------------------
|
||||||
|
|
||||||
|
|
||||||
|
def to_json(value) -> str:
|
||||||
|
return json.dumps(value)
|
||||||
|
|
||||||
|
|
||||||
|
def to_bool(value) -> bool:
|
||||||
|
"""Mimic Ansible's |bool filter for plain Jinja2 tests."""
|
||||||
|
if isinstance(value, bool):
|
||||||
|
return value
|
||||||
|
if isinstance(value, str):
|
||||||
|
return value.lower() not in ("", "false", "0", "no", "off", "null", "none")
|
||||||
|
return bool(value)
|
||||||
|
|
||||||
|
|
||||||
|
def regex_replace(value, pattern: str, replacement: str) -> str:
|
||||||
|
"""Mimic Ansible's |regex_replace filter."""
|
||||||
|
return re.sub(pattern, replacement, str(value))
|
||||||
|
|
||||||
|
|
||||||
|
def regex_escape(value) -> str:
|
||||||
|
"""Mimic Ansible's |regex_escape filter."""
|
||||||
|
return re.escape(str(value))
|
||||||
|
|
||||||
|
|
||||||
|
def regex_search(value, pattern: str) -> str | None:
|
||||||
|
"""Mimic Ansible's |regex_search filter.
|
||||||
|
|
||||||
|
Returns the first match (group 0) or None if no match.
|
||||||
|
Ansible returns the full match string or None.
|
||||||
|
"""
|
||||||
|
m = re.search(pattern, str(value))
|
||||||
|
return m.group(0) if m else None
|
||||||
|
|
||||||
|
|
||||||
|
# ---------------------------------------------------------------------------
|
||||||
|
# Environment factory
|
||||||
|
# ---------------------------------------------------------------------------
|
||||||
|
|
||||||
|
_FILTERS = {
|
||||||
|
"to_json": to_json,
|
||||||
|
"bool": to_bool,
|
||||||
|
"regex_replace": regex_replace,
|
||||||
|
"regex_escape": regex_escape,
|
||||||
|
"regex_search": regex_search,
|
||||||
|
}
|
||||||
|
|
||||||
|
|
||||||
|
@functools.cache
|
||||||
|
def make_env(loader_path: str) -> jinja2.Environment:
|
||||||
|
"""Create a cached Jinja2 Environment with standard filters.
|
||||||
|
|
||||||
|
``auto_reload=False`` skips stat() on every get_template call —
|
||||||
|
templates don't change during a test run so this is safe and
|
||||||
|
cuts ~40% off render time.
|
||||||
|
"""
|
||||||
|
env = jinja2.Environment( # nosec B701 — renders YAML/config templates, not HTML
|
||||||
|
loader=jinja2.FileSystemLoader(loader_path),
|
||||||
|
undefined=jinja2.StrictUndefined,
|
||||||
|
auto_reload=False,
|
||||||
|
cache_size=400,
|
||||||
|
)
|
||||||
|
env.filters.update(_FILTERS)
|
||||||
|
return env
|
||||||
|
|
||||||
|
|
||||||
|
@functools.cache
|
||||||
|
def make_value_env() -> jinja2.Environment:
|
||||||
|
"""Cached environment for rendering individual manifest string values."""
|
||||||
|
env = jinja2.Environment( # nosec B701 — renders config values, not HTML
|
||||||
|
undefined=jinja2.ChainableUndefined,
|
||||||
|
auto_reload=False,
|
||||||
|
)
|
||||||
|
env.filters.update(_FILTERS)
|
||||||
|
return env
|
||||||
|
|
||||||
|
|
||||||
|
# ---------------------------------------------------------------------------
|
||||||
|
# Render helpers
|
||||||
|
# ---------------------------------------------------------------------------
|
||||||
|
|
||||||
|
|
||||||
|
def render_template(env: jinja2.Environment, template_name: str, **kwargs) -> str:
|
||||||
|
"""Render a named template from a FileSystemLoader-backed env."""
|
||||||
|
return env.get_template(template_name).render(**kwargs)
|
||||||
|
|
||||||
|
|
||||||
|
def render_value(value, ctx: dict):
|
||||||
|
"""Render a single string value as a Jinja2 template if it contains expressions."""
|
||||||
|
if not isinstance(value, str):
|
||||||
|
return value
|
||||||
|
if "{{" not in value and "{%" not in value:
|
||||||
|
return value
|
||||||
|
return make_value_env().from_string(value).render(**ctx)
|
||||||
|
|
||||||
|
|
||||||
|
def render_manifest_values(obj, ctx: dict):
|
||||||
|
"""Recursively render all Jinja2 expressions in manifest string values."""
|
||||||
|
if isinstance(obj, dict):
|
||||||
|
return {k: render_manifest_values(v, ctx) for k, v in obj.items()}
|
||||||
|
if isinstance(obj, list):
|
||||||
|
return [render_manifest_values(v, ctx) for v in obj]
|
||||||
|
return render_value(obj, ctx)
|
||||||
@@ -0,0 +1,79 @@
|
|||||||
|
"""User-facing output utilities combining console and log output.
|
||||||
|
|
||||||
|
Console messages are colorised via ``click.style`` for visual feedback.
|
||||||
|
The persistent log file always receives plain text (no ANSI codes).
|
||||||
|
|
||||||
|
This is a generalisation of grm's ``ui.say()`` function, extracted so
|
||||||
|
that any CLI tool can use the same pattern. The logger name and
|
||||||
|
console-level env var are configurable.
|
||||||
|
|
||||||
|
Usage::
|
||||||
|
|
||||||
|
from devx.utils.ui import say
|
||||||
|
|
||||||
|
say("Starting deployment...")
|
||||||
|
say("Error occurred", level=logging.ERROR, err=True, color="red")
|
||||||
|
"""
|
||||||
|
|
||||||
|
from __future__ import annotations
|
||||||
|
|
||||||
|
import logging
|
||||||
|
import os
|
||||||
|
|
||||||
|
import click
|
||||||
|
|
||||||
|
# Configurable env var for console verbosity — projects can override
|
||||||
|
# via :func:`configure_ui`.
|
||||||
|
_LOG_LEVEL_ENV_VAR = "DEVX_LOG_LEVEL"
|
||||||
|
_LOGGER_NAME = "devx"
|
||||||
|
|
||||||
|
|
||||||
|
def configure_ui(*, log_level_env_var: str = "DEVX_LOG_LEVEL", logger_name: str = "devx") -> None:
|
||||||
|
"""Override the env var name and logger name used by :func:`say`.
|
||||||
|
|
||||||
|
This allows downstream projects (e.g. grm) to use their own env var
|
||||||
|
names (e.g. ``GRM_LOG_LEVEL``) and logger names while still using
|
||||||
|
devx's ui module.
|
||||||
|
|
||||||
|
Args:
|
||||||
|
log_level_env_var: Environment variable name for console log level.
|
||||||
|
logger_name: Logger name for persistent log file output.
|
||||||
|
"""
|
||||||
|
global _LOG_LEVEL_ENV_VAR, _LOGGER_NAME
|
||||||
|
_LOG_LEVEL_ENV_VAR = log_level_env_var
|
||||||
|
_LOGGER_NAME = logger_name
|
||||||
|
|
||||||
|
|
||||||
|
def _console_level() -> int:
|
||||||
|
"""Return the minimum level for console output from the configured env var."""
|
||||||
|
value = os.getenv(_LOG_LEVEL_ENV_VAR, "INFO")
|
||||||
|
try:
|
||||||
|
return getattr(logging, value.upper())
|
||||||
|
except AttributeError:
|
||||||
|
return logging.INFO
|
||||||
|
|
||||||
|
|
||||||
|
def say(
|
||||||
|
msg: str,
|
||||||
|
level: int = logging.INFO,
|
||||||
|
err: bool = False,
|
||||||
|
color: str | None = None,
|
||||||
|
) -> None:
|
||||||
|
"""Output a message to the user and also log it for auditing.
|
||||||
|
|
||||||
|
Console output goes via ``click.echo`` (handles encoding, CliRunner,
|
||||||
|
Windows colorama) only when *level* is at least the configured
|
||||||
|
console log level (default ``DEVX_LOG_LEVEL``, falls back to INFO).
|
||||||
|
The same message is always sent to the configured logger so it
|
||||||
|
appears in the persistent log file regardless of console verbosity.
|
||||||
|
|
||||||
|
Args:
|
||||||
|
msg: Message to display.
|
||||||
|
level: Logging level (e.g. ``logging.INFO``, ``logging.ERROR``).
|
||||||
|
err: If True, output to stderr instead of stdout.
|
||||||
|
color: Optional ``click.style`` fg color (e.g. ``"green"``, ``"red"``).
|
||||||
|
"""
|
||||||
|
if level >= _console_level():
|
||||||
|
styled = click.style(msg, fg=color) if color else msg
|
||||||
|
click.echo(styled, err=err)
|
||||||
|
logging.getLogger(_LOGGER_NAME).log(level, msg)
|
||||||
@@ -316,6 +316,18 @@ class TestGiteaClient:
|
|||||||
call_kwargs = client._session.request.call_args.kwargs
|
call_kwargs = client._session.request.call_args.kwargs
|
||||||
assert call_kwargs["json"]["base"] == "develop"
|
assert call_kwargs["json"]["base"] == "develop"
|
||||||
|
|
||||||
|
def test_update_pr(self) -> None:
|
||||||
|
client = GiteaClient("https://git.example.com", "tok", "owner", "repo")
|
||||||
|
client._session.request = MagicMock(return_value=_mock_response({"number": 42, "title": "DEVX-99: New title"}))
|
||||||
|
result = client.update_pr(42, {"title": "DEVX-99: New title"})
|
||||||
|
assert result["number"] == 42
|
||||||
|
client._session.request.assert_called_once_with(
|
||||||
|
"PATCH",
|
||||||
|
"https://git.example.com/repos/owner/repo/pulls/42",
|
||||||
|
timeout=DEFAULT_TIMEOUT,
|
||||||
|
json={"title": "DEVX-99: New title"},
|
||||||
|
)
|
||||||
|
|
||||||
def test_get_pr_files(self) -> None:
|
def test_get_pr_files(self) -> None:
|
||||||
client = GiteaClient("https://git.example.com", "tok", "owner", "repo")
|
client = GiteaClient("https://git.example.com", "tok", "owner", "repo")
|
||||||
client._session.request = MagicMock(
|
client._session.request = MagicMock(
|
||||||
|
|||||||
@@ -508,7 +508,8 @@ class TestCLIBuildImage:
|
|||||||
|
|
||||||
def test_missing_dockerfile_and_manifest(self) -> None:
|
def test_missing_dockerfile_and_manifest(self) -> None:
|
||||||
runner = CliRunner()
|
runner = CliRunner()
|
||||||
result = runner.invoke(build_image.main, [])
|
with patch("devx.tools.build_image.subprocess.run"):
|
||||||
|
result = runner.invoke(build_image.main, [])
|
||||||
assert result.exit_code != 0
|
assert result.exit_code != 0
|
||||||
assert "manifest" in result.output.lower() or "dockerfile" in result.output.lower()
|
assert "manifest" in result.output.lower() or "dockerfile" in result.output.lower()
|
||||||
|
|
||||||
@@ -516,10 +517,11 @@ class TestCLIBuildImage:
|
|||||||
dockerfile = tmp_path / "Dockerfile"
|
dockerfile = tmp_path / "Dockerfile"
|
||||||
dockerfile.touch()
|
dockerfile.touch()
|
||||||
runner = CliRunner()
|
runner = CliRunner()
|
||||||
result = runner.invoke(
|
with patch("devx.tools.build_image.subprocess.run"):
|
||||||
build_image.main,
|
result = runner.invoke(
|
||||||
["--dockerfile", str(dockerfile), "--name", "ci-base", "--push"],
|
build_image.main,
|
||||||
)
|
["--dockerfile", str(dockerfile), "--name", "ci-base", "--push"],
|
||||||
|
)
|
||||||
assert result.exit_code != 0
|
assert result.exit_code != 0
|
||||||
assert "registry" in result.output.lower()
|
assert "registry" in result.output.lower()
|
||||||
|
|
||||||
@@ -527,7 +529,7 @@ class TestCLIBuildImage:
|
|||||||
dockerfile = tmp_path / "Dockerfile"
|
dockerfile = tmp_path / "Dockerfile"
|
||||||
dockerfile.touch()
|
dockerfile.touch()
|
||||||
runner = CliRunner()
|
runner = CliRunner()
|
||||||
with patch.dict("os.environ", {}, clear=True):
|
with patch("devx.tools.build_image.subprocess.run"), patch.dict("os.environ", {}, clear=True):
|
||||||
result = runner.invoke(
|
result = runner.invoke(
|
||||||
build_image.main,
|
build_image.main,
|
||||||
["--dockerfile", str(dockerfile), "--name", "ci-base", "--push", "--registry", "git.example.com"],
|
["--dockerfile", str(dockerfile), "--name", "ci-base", "--push", "--registry", "git.example.com"],
|
||||||
|
|||||||
@@ -152,7 +152,10 @@ class TestGetVikunjaTitleOptional:
|
|||||||
class TestCli:
|
class TestCli:
|
||||||
def test_fails_without_task_id(self) -> None:
|
def test_fails_without_task_id(self) -> None:
|
||||||
runner = CliRunner()
|
runner = CliRunner()
|
||||||
with patch.dict("os.environ", {"DEVX_TASK_PREFIX": "DEVX"}, clear=True):
|
with (
|
||||||
|
patch.dict("os.environ", {"DEVX_TASK_PREFIX": "DEVX"}, clear=True),
|
||||||
|
patch("devx.ci.check_auto_merge_ready.is_branch_behind_master", return_value=False),
|
||||||
|
):
|
||||||
result = runner.invoke(cli, ["--branch", "no-task-id-here"])
|
result = runner.invoke(cli, ["--branch", "no-task-id-here"])
|
||||||
assert result.exit_code != 0
|
assert result.exit_code != 0
|
||||||
|
|
||||||
@@ -242,6 +245,7 @@ class TestCli:
|
|||||||
runner = CliRunner()
|
runner = CliRunner()
|
||||||
with (
|
with (
|
||||||
patch.dict("os.environ", {"DEVX_TASK_PREFIX": "DEVX", "VIKUNJA_TOKEN": ""}, clear=True),
|
patch.dict("os.environ", {"DEVX_TASK_PREFIX": "DEVX", "VIKUNJA_TOKEN": ""}, clear=True),
|
||||||
|
patch("devx.ci.check_auto_merge_ready.is_branch_behind_master", return_value=False),
|
||||||
patch("devx.ci.check_auto_merge_ready.get_pr_title_from_gitea", return_value=None),
|
patch("devx.ci.check_auto_merge_ready.get_pr_title_from_gitea", return_value=None),
|
||||||
):
|
):
|
||||||
result = runner.invoke(
|
result = runner.invoke(
|
||||||
|
|||||||
@@ -2,14 +2,26 @@
|
|||||||
|
|
||||||
from __future__ import annotations
|
from __future__ import annotations
|
||||||
|
|
||||||
|
import ast
|
||||||
|
import subprocess
|
||||||
import textwrap
|
import textwrap
|
||||||
from pathlib import Path
|
from pathlib import Path
|
||||||
|
from unittest.mock import MagicMock
|
||||||
|
|
||||||
|
import pytest
|
||||||
from click.testing import CliRunner
|
from click.testing import CliRunner
|
||||||
|
|
||||||
from devx.tools.check_test_isolation import (
|
from devx.tools.check_test_isolation import (
|
||||||
|
HEAVY_MODULE_IMPORTS,
|
||||||
HELPER_INTERNAL_CALLS,
|
HELPER_INTERNAL_CALLS,
|
||||||
|
IO_INTERNAL_CALLS,
|
||||||
|
KNOWN_IO_FUNCTIONS,
|
||||||
KNOWN_SUBPROCESS_HELPERS,
|
KNOWN_SUBPROCESS_HELPERS,
|
||||||
|
CallGraph,
|
||||||
|
_extract_patch_targets,
|
||||||
|
_is_integration_test,
|
||||||
|
_load_test_isolation_config,
|
||||||
|
_SubprocessAudit,
|
||||||
analyze_file,
|
analyze_file,
|
||||||
analyze_test_files,
|
analyze_test_files,
|
||||||
cli,
|
cli,
|
||||||
@@ -502,6 +514,97 @@ class TestAnalyzeFile:
|
|||||||
assert len(violations) == 1
|
assert len(violations) == 1
|
||||||
assert violations[0].category == "syntax-error"
|
assert violations[0].category == "syntax-error"
|
||||||
|
|
||||||
|
def test_heavy_module_import_at_module_level(self, tmp_path: Path) -> None:
|
||||||
|
file = _write_test_file(
|
||||||
|
tmp_path,
|
||||||
|
"""
|
||||||
|
import pandas
|
||||||
|
|
||||||
|
def test_foo() -> None:
|
||||||
|
assert True
|
||||||
|
""",
|
||||||
|
)
|
||||||
|
violations = analyze_file(file)
|
||||||
|
assert len(violations) == 1
|
||||||
|
assert violations[0].category == "heavy-module-import"
|
||||||
|
assert "pandas" in violations[0].message
|
||||||
|
|
||||||
|
def test_heavy_import_inside_function_ok(self, tmp_path: Path) -> None:
|
||||||
|
file = _write_test_file(
|
||||||
|
tmp_path,
|
||||||
|
"""
|
||||||
|
def test_foo() -> None:
|
||||||
|
import pandas
|
||||||
|
assert True
|
||||||
|
""",
|
||||||
|
)
|
||||||
|
violations = analyze_file(file)
|
||||||
|
assert violations == []
|
||||||
|
|
||||||
|
def test_heavy_import_from_at_module_level(self, tmp_path: Path) -> None:
|
||||||
|
file = _write_test_file(
|
||||||
|
tmp_path,
|
||||||
|
"""
|
||||||
|
from matplotlib import pyplot as plt
|
||||||
|
|
||||||
|
def test_foo() -> None:
|
||||||
|
assert True
|
||||||
|
""",
|
||||||
|
)
|
||||||
|
violations = analyze_file(file)
|
||||||
|
assert len(violations) == 1
|
||||||
|
assert violations[0].category == "heavy-module-import"
|
||||||
|
|
||||||
|
def test_reload_without_cleanup_odd_count(self, tmp_path: Path) -> None:
|
||||||
|
file = _write_test_file(
|
||||||
|
tmp_path,
|
||||||
|
"""
|
||||||
|
import importlib
|
||||||
|
import devx.config as cfg
|
||||||
|
|
||||||
|
def test_reload_no_cleanup() -> None:
|
||||||
|
importlib.reload(cfg)
|
||||||
|
assert cfg.TASK_PREFIX == "CUSTOM"
|
||||||
|
""",
|
||||||
|
)
|
||||||
|
violations = analyze_file(file)
|
||||||
|
reload_violations = [v for v in violations if v.category == "reload-without-cleanup"]
|
||||||
|
assert len(reload_violations) == 1
|
||||||
|
assert "1 time(s)" in reload_violations[0].message
|
||||||
|
|
||||||
|
def test_reload_with_cleanup_even_count_ok(self, tmp_path: Path) -> None:
|
||||||
|
file = _write_test_file(
|
||||||
|
tmp_path,
|
||||||
|
"""
|
||||||
|
import importlib
|
||||||
|
import devx.config as cfg
|
||||||
|
|
||||||
|
def test_reload_with_cleanup() -> None:
|
||||||
|
importlib.reload(cfg)
|
||||||
|
assert cfg.TASK_PREFIX == "CUSTOM"
|
||||||
|
importlib.reload(cfg)
|
||||||
|
""",
|
||||||
|
)
|
||||||
|
violations = analyze_file(file)
|
||||||
|
reload_violations = [v for v in violations if v.category == "reload-without-cleanup"]
|
||||||
|
assert reload_violations == []
|
||||||
|
|
||||||
|
def test_reload_attribute_access_detected(self, tmp_path: Path) -> None:
|
||||||
|
file = _write_test_file(
|
||||||
|
tmp_path,
|
||||||
|
"""
|
||||||
|
import importlib
|
||||||
|
import devx.config
|
||||||
|
|
||||||
|
def test_reload_attr() -> None:
|
||||||
|
importlib.reload(devx.config)
|
||||||
|
""",
|
||||||
|
)
|
||||||
|
violations = analyze_file(file)
|
||||||
|
reload_violations = [v for v in violations if v.category == "reload-without-cleanup"]
|
||||||
|
assert len(reload_violations) == 1
|
||||||
|
assert "config" in reload_violations[0].message
|
||||||
|
|
||||||
|
|
||||||
class TestAnalyzeTestFiles:
|
class TestAnalyzeTestFiles:
|
||||||
def test_multiple_files(self, tmp_path: Path) -> None:
|
def test_multiple_files(self, tmp_path: Path) -> None:
|
||||||
@@ -742,7 +845,8 @@ class TestCli:
|
|||||||
assert "FAILED" in result.output
|
assert "FAILED" in result.output
|
||||||
assert "unpatched-subprocess" in result.output
|
assert "unpatched-subprocess" in result.output
|
||||||
|
|
||||||
def test_strict_flag(self, tmp_path: Path) -> None:
|
def test_always_strict(self, tmp_path: Path) -> None:
|
||||||
|
"""CLI is always strict — no --strict flag needed."""
|
||||||
_write_test_file(
|
_write_test_file(
|
||||||
tmp_path,
|
tmp_path,
|
||||||
"""
|
"""
|
||||||
@@ -753,7 +857,7 @@ class TestCli:
|
|||||||
""",
|
""",
|
||||||
)
|
)
|
||||||
runner = CliRunner()
|
runner = CliRunner()
|
||||||
result = runner.invoke(cli, ["--test-path", str(tmp_path), "--strict"])
|
result = runner.invoke(cli, ["--test-path", str(tmp_path)])
|
||||||
assert result.exit_code == 1
|
assert result.exit_code == 1
|
||||||
|
|
||||||
def test_category_filter(self, tmp_path: Path) -> None:
|
def test_category_filter(self, tmp_path: Path) -> None:
|
||||||
@@ -795,22 +899,6 @@ class TestCli:
|
|||||||
assert result.exit_code == 0
|
assert result.exit_code == 0
|
||||||
assert "no violations" in result.output
|
assert "no violations" in result.output
|
||||||
|
|
||||||
def test_strict_clean_directory_exits_zero(self, tmp_path: Path) -> None:
|
|
||||||
"""Strict mode with no violations should still exit 0."""
|
|
||||||
_write_test_file(
|
|
||||||
tmp_path,
|
|
||||||
"""
|
|
||||||
from unittest.mock import patch, MagicMock
|
|
||||||
class TestExample:
|
|
||||||
@patch("subprocess.run")
|
|
||||||
def test_ok(self, mock: MagicMock) -> None:
|
|
||||||
pass
|
|
||||||
""",
|
|
||||||
)
|
|
||||||
runner = CliRunner()
|
|
||||||
result = runner.invoke(cli, ["--test-path", str(tmp_path), "--strict"])
|
|
||||||
assert result.exit_code == 0
|
|
||||||
|
|
||||||
|
|
||||||
class TestPytestPlugin:
|
class TestPytestPlugin:
|
||||||
"""Tests for the pytest plugin hooks.
|
"""Tests for the pytest plugin hooks.
|
||||||
@@ -830,7 +918,7 @@ class TestPytestPlugin:
|
|||||||
pytest_addoption(parser)
|
pytest_addoption(parser)
|
||||||
|
|
||||||
addoption_calls = parser.addoption.call_args_list
|
addoption_calls = parser.addoption.call_args_list
|
||||||
assert len(addoption_calls) >= 3
|
assert len(addoption_calls) >= 2
|
||||||
|
|
||||||
def test_pytest_collection_finish_noop_when_disabled(self) -> None:
|
def test_pytest_collection_finish_noop_when_disabled(self) -> None:
|
||||||
"""Plugin should skip analysis when --no-test-isolation is set."""
|
"""Plugin should skip analysis when --no-test-isolation is set."""
|
||||||
@@ -854,39 +942,10 @@ class TestPytestPlugin:
|
|||||||
pytest_collection_finish(session)
|
pytest_collection_finish(session)
|
||||||
|
|
||||||
def test_pytest_collection_finish_with_violation(self, tmp_path: Path) -> None:
|
def test_pytest_collection_finish_with_violation(self, tmp_path: Path) -> None:
|
||||||
"""Plugin should emit warnings when violations are found."""
|
"""Plugin should fail when hard violations are found (always strict)."""
|
||||||
import warnings
|
|
||||||
from unittest.mock import MagicMock
|
from unittest.mock import MagicMock
|
||||||
|
|
||||||
from devx.tools.check_test_isolation import pytest_collection_finish
|
import pytest
|
||||||
|
|
||||||
test_file = _write_test_file(
|
|
||||||
tmp_path,
|
|
||||||
"""
|
|
||||||
import subprocess
|
|
||||||
class TestExample:
|
|
||||||
def test_bad(self) -> None:
|
|
||||||
subprocess.run(["echo"])
|
|
||||||
""",
|
|
||||||
)
|
|
||||||
|
|
||||||
session = MagicMock()
|
|
||||||
session.config.getoption.side_effect = lambda opt: False
|
|
||||||
item = MagicMock()
|
|
||||||
item.fspath = str(test_file)
|
|
||||||
session.items = [item]
|
|
||||||
|
|
||||||
with warnings.catch_warnings(record=True) as w:
|
|
||||||
warnings.simplefilter("always")
|
|
||||||
pytest_collection_finish(session)
|
|
||||||
|
|
||||||
assert len(w) >= 1
|
|
||||||
assert any("Test isolation violation" in str(warning.message) for warning in w)
|
|
||||||
|
|
||||||
def test_pytest_collection_finish_strict_mode(self, tmp_path: Path) -> None:
|
|
||||||
"""Plugin should emit warnings and print summary in strict mode."""
|
|
||||||
import warnings
|
|
||||||
from unittest.mock import MagicMock
|
|
||||||
|
|
||||||
from devx.tools.check_test_isolation import pytest_collection_finish
|
from devx.tools.check_test_isolation import pytest_collection_finish
|
||||||
|
|
||||||
@@ -903,7 +962,44 @@ class TestPytestPlugin:
|
|||||||
session = MagicMock()
|
session = MagicMock()
|
||||||
session.config.getoption.side_effect = lambda opt: {
|
session.config.getoption.side_effect = lambda opt: {
|
||||||
"--no-test-isolation": False,
|
"--no-test-isolation": False,
|
||||||
"--strict-test-isolation": True,
|
"--test-isolation-max-loop": 100,
|
||||||
|
}.get(opt, False)
|
||||||
|
item = MagicMock()
|
||||||
|
item.fspath = str(test_file)
|
||||||
|
session.items = [item]
|
||||||
|
|
||||||
|
with pytest.raises(pytest.fail.Exception, match="Test isolation"):
|
||||||
|
pytest_collection_finish(session)
|
||||||
|
|
||||||
|
def test_pytest_collection_finish_advisory_only(self, tmp_path: Path) -> None:
|
||||||
|
"""Transitive-subprocess advisories should warn, not fail."""
|
||||||
|
import warnings
|
||||||
|
from unittest.mock import MagicMock
|
||||||
|
|
||||||
|
from devx.tools.check_test_isolation import pytest_collection_finish
|
||||||
|
|
||||||
|
# Create a src/ directory with a module that calls subprocess.run
|
||||||
|
# so the call graph can detect transitive subprocess calls.
|
||||||
|
src_dir = tmp_path / "src" / "mypkg"
|
||||||
|
src_dir.mkdir(parents=True)
|
||||||
|
(src_dir / "__init__.py").write_text("")
|
||||||
|
(src_dir / "cli.py").write_text("import subprocess\ndef main():\n subprocess.run(['echo'])\n")
|
||||||
|
|
||||||
|
test_file = _write_test_file(
|
||||||
|
tmp_path,
|
||||||
|
"""
|
||||||
|
from click.testing import CliRunner
|
||||||
|
from mypkg.cli import main
|
||||||
|
class TestExample:
|
||||||
|
def test_advisory(self) -> None:
|
||||||
|
runner = CliRunner()
|
||||||
|
result = runner.invoke(main, [])
|
||||||
|
""",
|
||||||
|
)
|
||||||
|
|
||||||
|
session = MagicMock()
|
||||||
|
session.config.getoption.side_effect = lambda opt: {
|
||||||
|
"--no-test-isolation": False,
|
||||||
"--test-isolation-max-loop": 100,
|
"--test-isolation-max-loop": 100,
|
||||||
}.get(opt, False)
|
}.get(opt, False)
|
||||||
item = MagicMock()
|
item = MagicMock()
|
||||||
@@ -914,5 +1010,772 @@ class TestPytestPlugin:
|
|||||||
warnings.simplefilter("always")
|
warnings.simplefilter("always")
|
||||||
pytest_collection_finish(session)
|
pytest_collection_finish(session)
|
||||||
|
|
||||||
assert len(w) >= 1
|
# Should only emit advisory warnings, not fail
|
||||||
assert any("Test isolation violation" in str(warning.message) for warning in w)
|
assert any("advisory" in str(warning.message).lower() for warning in w)
|
||||||
|
|
||||||
|
|
||||||
|
class TestSubprocessAudit:
|
||||||
|
"""Tests for the _SubprocessAudit runtime wrapper (lines 157-195)."""
|
||||||
|
|
||||||
|
def test_ensure_installed_wraps_subprocess(self) -> None:
|
||||||
|
audit = _SubprocessAudit()
|
||||||
|
original_run = subprocess.run
|
||||||
|
try:
|
||||||
|
audit._ensure_installed()
|
||||||
|
assert audit._installed is True
|
||||||
|
assert "run" in audit._originals
|
||||||
|
# The subprocess.run should now be a wrapper, not the original
|
||||||
|
assert subprocess.run is not original_run
|
||||||
|
# Calling _ensure_installed again is a no-op (cached return)
|
||||||
|
audit._ensure_installed()
|
||||||
|
finally:
|
||||||
|
# Restore originals
|
||||||
|
for name, orig in audit._originals.items():
|
||||||
|
setattr(subprocess, name, orig)
|
||||||
|
|
||||||
|
def test_make_wrapper_records_calls_when_active(self) -> None:
|
||||||
|
audit = _SubprocessAudit()
|
||||||
|
mock_original = MagicMock(return_value="result")
|
||||||
|
wrapper = audit._make_wrapper("run", mock_original)
|
||||||
|
audit.start_test()
|
||||||
|
result = wrapper(["echo", "hi"], capture_output=True)
|
||||||
|
calls = audit.stop_test()
|
||||||
|
assert result == "result"
|
||||||
|
run_calls = [c for c in calls if c[0] == "run"]
|
||||||
|
assert len(run_calls) == 1
|
||||||
|
assert "echo" in run_calls[0][1]
|
||||||
|
mock_original.assert_called_once_with(["echo", "hi"], capture_output=True)
|
||||||
|
|
||||||
|
def test_make_wrapper_records_list_cmd_truncation(self) -> None:
|
||||||
|
"""Long command lists should be truncated to first 4 elements."""
|
||||||
|
audit = _SubprocessAudit()
|
||||||
|
mock_original = MagicMock(return_value="result")
|
||||||
|
wrapper = audit._make_wrapper("run", mock_original)
|
||||||
|
audit.start_test()
|
||||||
|
wrapper(["echo", "1", "2", "3", "4", "5", "6"], capture_output=True)
|
||||||
|
calls = audit.stop_test()
|
||||||
|
run_calls = [c for c in calls if c[0] == "run"]
|
||||||
|
assert len(run_calls) == 1
|
||||||
|
assert "..." in run_calls[0][1]
|
||||||
|
|
||||||
|
def test_make_wrapper_records_string_cmd(self) -> None:
|
||||||
|
"""A string command (not list) should be recorded as-is."""
|
||||||
|
audit = _SubprocessAudit()
|
||||||
|
mock_original = MagicMock(return_value="result")
|
||||||
|
wrapper = audit._make_wrapper("run", mock_original)
|
||||||
|
audit.start_test()
|
||||||
|
wrapper("echo hi", shell=True, capture_output=True)
|
||||||
|
calls = audit.stop_test()
|
||||||
|
run_calls = [c for c in calls if c[0] == "run"]
|
||||||
|
assert len(run_calls) == 1
|
||||||
|
assert "echo hi" in run_calls[0][1]
|
||||||
|
|
||||||
|
def test_calls_not_recorded_when_inactive(self) -> None:
|
||||||
|
"""When audit is not active, calls should not be recorded."""
|
||||||
|
audit = _SubprocessAudit()
|
||||||
|
mock_original = MagicMock(return_value="result")
|
||||||
|
wrapper = audit._make_wrapper("run", mock_original)
|
||||||
|
# Don't call start_test — audit inactive
|
||||||
|
wrapper(["echo", "hi"], capture_output=True)
|
||||||
|
# stop_test returns empty since no calls recorded
|
||||||
|
calls = audit.stop_test()
|
||||||
|
assert not calls
|
||||||
|
mock_original.assert_called_once_with(["echo", "hi"], capture_output=True)
|
||||||
|
|
||||||
|
def test_start_then_stop_returns_calls(self) -> None:
|
||||||
|
"""start_test initializes calls list, stop_test returns and clears it."""
|
||||||
|
audit = _SubprocessAudit()
|
||||||
|
mock_original = MagicMock(return_value="result")
|
||||||
|
wrapper = audit._make_wrapper("run", mock_original)
|
||||||
|
audit.start_test()
|
||||||
|
wrapper(["echo"], capture_output=True)
|
||||||
|
calls = audit.stop_test()
|
||||||
|
assert len(calls) == 1
|
||||||
|
# After stop, calls is cleared (None or empty)
|
||||||
|
calls2 = audit.stop_test()
|
||||||
|
assert not calls2
|
||||||
|
|
||||||
|
def test_ensure_installed_skips_missing_funcs(self) -> None:
|
||||||
|
"""If a subprocess func is missing (None), it should be skipped (line 162)."""
|
||||||
|
audit = _SubprocessAudit()
|
||||||
|
saved = subprocess.check_output
|
||||||
|
try:
|
||||||
|
# Temporarily make check_output "missing" (None)
|
||||||
|
subprocess.check_output = None # type: ignore[assignment]
|
||||||
|
audit._ensure_installed()
|
||||||
|
# check_output should NOT be in originals (skipped)
|
||||||
|
assert "check_output" not in audit._originals
|
||||||
|
# run should still be wrapped
|
||||||
|
assert "run" in audit._originals
|
||||||
|
finally:
|
||||||
|
subprocess.check_output = saved # type: ignore[assignment]
|
||||||
|
for name, orig in audit._originals.items():
|
||||||
|
setattr(subprocess, name, orig)
|
||||||
|
|
||||||
|
|
||||||
|
class TestExtractPatchTargets:
|
||||||
|
"""Tests for _extract_patch_targets (lines 263-291)."""
|
||||||
|
|
||||||
|
def _parse_func(self, source: str) -> ast.FunctionDef:
|
||||||
|
tree = ast.parse(textwrap.dedent(source))
|
||||||
|
return tree.body[0] # type: ignore[return-value]
|
||||||
|
|
||||||
|
def test_patch_object_extracted(self) -> None:
|
||||||
|
"""patch.object(module, "name") should extract the short name."""
|
||||||
|
node = self._parse_func(
|
||||||
|
"""
|
||||||
|
def test_foo():
|
||||||
|
with patch.object(mymodule, "subprocess"):
|
||||||
|
mymodule.do_thing()
|
||||||
|
"""
|
||||||
|
)
|
||||||
|
targets = _extract_patch_targets(node)
|
||||||
|
assert "subprocess" in targets
|
||||||
|
|
||||||
|
def test_patch_object_with_module_alias(self) -> None:
|
||||||
|
"""patch.object with a module alias Name as first arg."""
|
||||||
|
node = self._parse_func(
|
||||||
|
"""
|
||||||
|
def test_foo():
|
||||||
|
with patch.object(subprocess, "run"):
|
||||||
|
subprocess.run(["echo"])
|
||||||
|
"""
|
||||||
|
)
|
||||||
|
targets = _extract_patch_targets(node)
|
||||||
|
assert "run" in targets
|
||||||
|
|
||||||
|
def test_with_patch_context_manager_extracted(self) -> None:
|
||||||
|
"""with patch("module.func") in function body should be extracted."""
|
||||||
|
node = self._parse_func(
|
||||||
|
"""
|
||||||
|
def test_foo():
|
||||||
|
with patch("mymodule.subprocess.run"):
|
||||||
|
mymodule.do_thing()
|
||||||
|
"""
|
||||||
|
)
|
||||||
|
targets = _extract_patch_targets(node)
|
||||||
|
assert "mymodule.subprocess.run" in targets
|
||||||
|
assert "run" in targets
|
||||||
|
|
||||||
|
def test_with_multiple_patch_context_managers(self) -> None:
|
||||||
|
"""with patch("a"), patch("b") should extract both."""
|
||||||
|
node = self._parse_func(
|
||||||
|
"""
|
||||||
|
def test_foo():
|
||||||
|
with patch("mod.a"), patch("mod.b"):
|
||||||
|
pass
|
||||||
|
"""
|
||||||
|
)
|
||||||
|
targets = _extract_patch_targets(node)
|
||||||
|
assert "mod.a" in targets
|
||||||
|
assert "mod.b" in targets
|
||||||
|
assert "a" in targets
|
||||||
|
assert "b" in targets
|
||||||
|
|
||||||
|
def test_patch_object_non_string_second_arg_ignored(self) -> None:
|
||||||
|
"""patch.object with non-string 2nd arg should not crash."""
|
||||||
|
node = self._parse_func(
|
||||||
|
"""
|
||||||
|
def test_foo():
|
||||||
|
with patch.object(mymodule, some_var):
|
||||||
|
pass
|
||||||
|
"""
|
||||||
|
)
|
||||||
|
targets = _extract_patch_targets(node)
|
||||||
|
assert targets == set()
|
||||||
|
|
||||||
|
|
||||||
|
class TestCallGraph:
|
||||||
|
"""Tests for CallGraph building (lines 409, 419-420, 449, 470)."""
|
||||||
|
|
||||||
|
def _make_src(self, tmp_path: Path, files: dict[str, str]) -> Path:
|
||||||
|
src = tmp_path / "src"
|
||||||
|
src.mkdir()
|
||||||
|
for rel, content in files.items():
|
||||||
|
f = src / rel
|
||||||
|
f.parent.mkdir(parents=True, exist_ok=True)
|
||||||
|
f.write_text(textwrap.dedent(content))
|
||||||
|
return src
|
||||||
|
|
||||||
|
def test_ensure_built_cached(self, tmp_path: Path) -> None:
|
||||||
|
"""_ensure_built should only build once (cached return)."""
|
||||||
|
src = self._make_src(tmp_path, {"pkg/__init__.py": "", "pkg/mod.py": "def foo():\n pass\n"})
|
||||||
|
cg = CallGraph(src)
|
||||||
|
cg._ensure_built()
|
||||||
|
assert cg._built is True
|
||||||
|
nodes_before = dict(cg._nodes)
|
||||||
|
# Second call should be a no-op
|
||||||
|
cg._ensure_built()
|
||||||
|
assert cg._nodes == nodes_before
|
||||||
|
|
||||||
|
def test_build_skips_syntax_error(self, tmp_path: Path) -> None:
|
||||||
|
"""Files with syntax errors should be skipped, not crash."""
|
||||||
|
src = self._make_src(
|
||||||
|
tmp_path,
|
||||||
|
{
|
||||||
|
"pkg/__init__.py": "",
|
||||||
|
"pkg/broken.py": "def test(:\n pass\n",
|
||||||
|
"pkg/good.py": "def foo():\n pass\n",
|
||||||
|
},
|
||||||
|
)
|
||||||
|
cg = CallGraph(src)
|
||||||
|
cg._ensure_built()
|
||||||
|
# good.py's foo should be registered, broken.py skipped
|
||||||
|
assert any("foo" in k for k in cg._nodes)
|
||||||
|
|
||||||
|
def test_build_skips_unicode_decode_error(self, tmp_path: Path) -> None:
|
||||||
|
"""Files with invalid UTF-8 should be skipped."""
|
||||||
|
src = tmp_path / "src"
|
||||||
|
src.mkdir()
|
||||||
|
(src / "pkg").mkdir()
|
||||||
|
(src / "pkg" / "__init__.py").write_text("")
|
||||||
|
(src / "pkg" / "binary.py").write_bytes(b"\xff\xfe\x00\xbad bytes")
|
||||||
|
(src / "pkg" / "good.py").write_text("def foo():\n pass\n")
|
||||||
|
cg = CallGraph(src)
|
||||||
|
cg._ensure_built()
|
||||||
|
assert any("foo" in k for k in cg._nodes)
|
||||||
|
|
||||||
|
def test_scan_node_skips_classdef(self, tmp_path: Path) -> None:
|
||||||
|
"""Methods inside classes should NOT be registered."""
|
||||||
|
src = self._make_src(
|
||||||
|
tmp_path,
|
||||||
|
{
|
||||||
|
"pkg/__init__.py": "",
|
||||||
|
"pkg/mod.py": """
|
||||||
|
class MyClass:
|
||||||
|
def my_method(self):
|
||||||
|
subprocess.run(["echo"])
|
||||||
|
def top_level():
|
||||||
|
pass
|
||||||
|
""",
|
||||||
|
},
|
||||||
|
)
|
||||||
|
cg = CallGraph(src)
|
||||||
|
cg._ensure_built()
|
||||||
|
# top_level should be registered
|
||||||
|
assert "pkg.mod.top_level" in cg._nodes
|
||||||
|
# my_method should NOT be registered (class body skipped)
|
||||||
|
assert "pkg.mod.my_method" not in cg._nodes
|
||||||
|
assert "my_method" not in cg._by_short
|
||||||
|
|
||||||
|
def test_register_function_records_io_calls(self, tmp_path: Path) -> None:
|
||||||
|
"""KNOWN_IO_FUNCTIONS calls should be recorded in io_calls."""
|
||||||
|
src = self._make_src(
|
||||||
|
tmp_path,
|
||||||
|
{
|
||||||
|
"pkg/__init__.py": "",
|
||||||
|
"pkg/mod.py": """
|
||||||
|
def foo():
|
||||||
|
get_pat("staging")
|
||||||
|
load_secrets("prod")
|
||||||
|
""",
|
||||||
|
},
|
||||||
|
)
|
||||||
|
cg = CallGraph(src)
|
||||||
|
cg._ensure_built()
|
||||||
|
node = cg._nodes["pkg.mod.foo"]
|
||||||
|
assert "get_pat" in node.io_calls
|
||||||
|
assert "load_secrets" in node.io_calls
|
||||||
|
|
||||||
|
def test_register_function_records_subprocess_calls(self, tmp_path: Path) -> None:
|
||||||
|
"""subprocess.run calls should be recorded in subprocess_calls."""
|
||||||
|
src = self._make_src(
|
||||||
|
tmp_path,
|
||||||
|
{
|
||||||
|
"pkg/__init__.py": "",
|
||||||
|
"pkg/mod.py": """
|
||||||
|
import subprocess
|
||||||
|
def foo():
|
||||||
|
subprocess.run(["echo"])
|
||||||
|
""",
|
||||||
|
},
|
||||||
|
)
|
||||||
|
cg = CallGraph(src)
|
||||||
|
cg._ensure_built()
|
||||||
|
node = cg._nodes["pkg.mod.foo"]
|
||||||
|
assert "subprocess.run" in node.subprocess_calls
|
||||||
|
|
||||||
|
|
||||||
|
class TestFindReachableDangerous:
|
||||||
|
"""Tests for find_reachable_dangerous (lines 516-580)."""
|
||||||
|
|
||||||
|
def _make_src(self, tmp_path: Path, files: dict[str, str]) -> Path:
|
||||||
|
src = tmp_path / "src"
|
||||||
|
src.mkdir()
|
||||||
|
for rel, content in files.items():
|
||||||
|
f = src / rel
|
||||||
|
f.parent.mkdir(parents=True, exist_ok=True)
|
||||||
|
f.write_text(textwrap.dedent(content))
|
||||||
|
return src
|
||||||
|
|
||||||
|
def test_import_map_resolution(self, tmp_path: Path) -> None:
|
||||||
|
"""import_map should resolve target to a precise full name."""
|
||||||
|
src = self._make_src(
|
||||||
|
tmp_path,
|
||||||
|
{
|
||||||
|
"pkg/__init__.py": "",
|
||||||
|
"pkg/mod.py": """
|
||||||
|
import subprocess
|
||||||
|
def main():
|
||||||
|
subprocess.run(["echo"])
|
||||||
|
""",
|
||||||
|
},
|
||||||
|
)
|
||||||
|
cg = CallGraph(src)
|
||||||
|
dangerous = cg.find_reachable_dangerous("main", set(), import_map={"main": "pkg.mod.main"})
|
||||||
|
assert len(dangerous) == 1
|
||||||
|
assert "subprocess" in dangerous[0][1]
|
||||||
|
|
||||||
|
def test_import_map_falls_back_to_short_name(self, tmp_path: Path) -> None:
|
||||||
|
"""If import_map value not in nodes, fall back to short name (line 516)."""
|
||||||
|
src = self._make_src(
|
||||||
|
tmp_path,
|
||||||
|
{
|
||||||
|
"pkg/__init__.py": "",
|
||||||
|
"pkg/mod.py": """
|
||||||
|
import subprocess
|
||||||
|
def main():
|
||||||
|
subprocess.run(["echo"])
|
||||||
|
""",
|
||||||
|
},
|
||||||
|
)
|
||||||
|
cg = CallGraph(src)
|
||||||
|
# import_map points to a non-existent full name → fallback to by_short
|
||||||
|
dangerous = cg.find_reachable_dangerous("main", set(), import_map={"main": "nonexistent.pkg.main"})
|
||||||
|
assert len(dangerous) == 1
|
||||||
|
|
||||||
|
def test_no_candidates_returns_empty(self, tmp_path: Path) -> None:
|
||||||
|
"""If no candidates found, return empty list (line 526)."""
|
||||||
|
src = self._make_src(tmp_path, {"pkg/__init__.py": ""})
|
||||||
|
cg = CallGraph(src)
|
||||||
|
dangerous = cg.find_reachable_dangerous("nonexistent", set())
|
||||||
|
assert dangerous == []
|
||||||
|
|
||||||
|
def test_fully_qualified_name_candidate(self, tmp_path: Path) -> None:
|
||||||
|
"""A fully-qualified target_name in nodes should be used directly (line 519)."""
|
||||||
|
src = self._make_src(
|
||||||
|
tmp_path,
|
||||||
|
{
|
||||||
|
"pkg/__init__.py": "",
|
||||||
|
"pkg/mod.py": """
|
||||||
|
import subprocess
|
||||||
|
def main():
|
||||||
|
subprocess.run(["echo"])
|
||||||
|
""",
|
||||||
|
},
|
||||||
|
)
|
||||||
|
cg = CallGraph(src)
|
||||||
|
dangerous = cg.find_reachable_dangerous("pkg.mod.main", set())
|
||||||
|
assert len(dangerous) == 1
|
||||||
|
|
||||||
|
def test_short_name_fallback(self, tmp_path: Path) -> None:
|
||||||
|
"""target_name not in nodes falls back to short name (line 522)."""
|
||||||
|
src = self._make_src(
|
||||||
|
tmp_path,
|
||||||
|
{
|
||||||
|
"pkg/__init__.py": "",
|
||||||
|
"pkg/mod.py": """
|
||||||
|
import subprocess
|
||||||
|
def main():
|
||||||
|
subprocess.run(["echo"])
|
||||||
|
""",
|
||||||
|
},
|
||||||
|
)
|
||||||
|
cg = CallGraph(src)
|
||||||
|
# "pkg.main" is not a full name in nodes, so it falls back to "main"
|
||||||
|
dangerous = cg.find_reachable_dangerous("pkg.main", set())
|
||||||
|
assert len(dangerous) == 1
|
||||||
|
|
||||||
|
def test_visited_prevents_infinite_loop(self, tmp_path: Path) -> None:
|
||||||
|
"""Visited set prevents infinite loops (line 535)."""
|
||||||
|
src = self._make_src(
|
||||||
|
tmp_path,
|
||||||
|
{
|
||||||
|
"pkg/__init__.py": "",
|
||||||
|
"pkg/mod.py": """
|
||||||
|
def a():
|
||||||
|
b()
|
||||||
|
def b():
|
||||||
|
a()
|
||||||
|
subprocess.run(["echo"])
|
||||||
|
""",
|
||||||
|
},
|
||||||
|
)
|
||||||
|
cg = CallGraph(src)
|
||||||
|
dangerous = cg.find_reachable_dangerous("a", set())
|
||||||
|
assert len(dangerous) == 1
|
||||||
|
|
||||||
|
def test_depth_limit_stops_traversal(self, tmp_path: Path) -> None:
|
||||||
|
"""max_depth should stop traversal (line 534)."""
|
||||||
|
src = self._make_src(
|
||||||
|
tmp_path,
|
||||||
|
{
|
||||||
|
"pkg/__init__.py": "",
|
||||||
|
"pkg/mod.py": """
|
||||||
|
def a():
|
||||||
|
b()
|
||||||
|
def b():
|
||||||
|
c()
|
||||||
|
def c():
|
||||||
|
subprocess.run(["echo"])
|
||||||
|
""",
|
||||||
|
},
|
||||||
|
)
|
||||||
|
cg = CallGraph(src)
|
||||||
|
# With max_depth=0, only the direct node is visited
|
||||||
|
dangerous = cg.find_reachable_dangerous("a", set(), max_depth=0)
|
||||||
|
assert dangerous == []
|
||||||
|
|
||||||
|
def test_node_not_found_continues(self, tmp_path: Path) -> None:
|
||||||
|
"""If a queued node isn't in _nodes, continue (line 540)."""
|
||||||
|
src = self._make_src(tmp_path, {"pkg/__init__.py": ""})
|
||||||
|
cg = CallGraph(src)
|
||||||
|
# Manually inject a candidate that doesn't exist in nodes
|
||||||
|
cg._by_short["ghost"] = ["pkg.mod.ghost"]
|
||||||
|
dangerous = cg.find_reachable_dangerous("ghost", set())
|
||||||
|
assert dangerous == []
|
||||||
|
|
||||||
|
def test_io_calls_checked(self, tmp_path: Path) -> None:
|
||||||
|
"""IO calls should be reported as dangerous (lines 551-554)."""
|
||||||
|
src = self._make_src(
|
||||||
|
tmp_path,
|
||||||
|
{
|
||||||
|
"pkg/__init__.py": "",
|
||||||
|
"pkg/mod.py": """
|
||||||
|
def main():
|
||||||
|
get_pat("staging")
|
||||||
|
""",
|
||||||
|
},
|
||||||
|
)
|
||||||
|
cg = CallGraph(src)
|
||||||
|
dangerous = cg.find_reachable_dangerous("main", set())
|
||||||
|
assert len(dangerous) == 1
|
||||||
|
assert "PAT" in dangerous[0][1] or "get_pat" in str(dangerous)
|
||||||
|
|
||||||
|
def test_io_calls_patched_skipped(self, tmp_path: Path) -> None:
|
||||||
|
"""Patched IO calls should not be reported."""
|
||||||
|
src = self._make_src(
|
||||||
|
tmp_path,
|
||||||
|
{
|
||||||
|
"pkg/__init__.py": "",
|
||||||
|
"pkg/mod.py": """
|
||||||
|
def main():
|
||||||
|
get_pat("staging")
|
||||||
|
""",
|
||||||
|
},
|
||||||
|
)
|
||||||
|
cg = CallGraph(src)
|
||||||
|
dangerous = cg.find_reachable_dangerous("main", {"get_pat"})
|
||||||
|
assert dangerous == []
|
||||||
|
|
||||||
|
def test_patched_helper_skipped_in_enqueue(self, tmp_path: Path) -> None:
|
||||||
|
"""A patched helper should not be enqueued (lines 559-560)."""
|
||||||
|
src = self._make_src(
|
||||||
|
tmp_path,
|
||||||
|
{
|
||||||
|
"pkg/__init__.py": "",
|
||||||
|
"pkg/mod.py": """
|
||||||
|
def main():
|
||||||
|
run_cmd()
|
||||||
|
def run_cmd():
|
||||||
|
subprocess.run(["echo"])
|
||||||
|
""",
|
||||||
|
},
|
||||||
|
)
|
||||||
|
cg = CallGraph(src)
|
||||||
|
# run_cmd is patched → should not traverse into it
|
||||||
|
dangerous = cg.find_reachable_dangerous("main", {"run_cmd"})
|
||||||
|
assert dangerous == []
|
||||||
|
|
||||||
|
def test_same_module_resolution(self, tmp_path: Path) -> None:
|
||||||
|
"""Calls within the same module should prefer same-module resolution (lines 566-567)."""
|
||||||
|
src = self._make_src(
|
||||||
|
tmp_path,
|
||||||
|
{
|
||||||
|
"pkg/__init__.py": "",
|
||||||
|
"pkg/mod.py": """
|
||||||
|
def main():
|
||||||
|
helper()
|
||||||
|
def helper():
|
||||||
|
subprocess.run(["echo"])
|
||||||
|
""",
|
||||||
|
},
|
||||||
|
)
|
||||||
|
cg = CallGraph(src)
|
||||||
|
dangerous = cg.find_reachable_dangerous("main", set())
|
||||||
|
assert len(dangerous) == 1
|
||||||
|
|
||||||
|
def test_short_name_single_match_resolution(self, tmp_path: Path) -> None:
|
||||||
|
"""A single global match by short name should be resolved (lines 571-572)."""
|
||||||
|
src = self._make_src(
|
||||||
|
tmp_path,
|
||||||
|
{
|
||||||
|
"pkg/__init__.py": "",
|
||||||
|
"pkg/mod.py": """
|
||||||
|
def main():
|
||||||
|
helper()
|
||||||
|
""",
|
||||||
|
"pkg/other.py": """
|
||||||
|
import subprocess
|
||||||
|
def helper():
|
||||||
|
subprocess.run(["echo"])
|
||||||
|
""",
|
||||||
|
},
|
||||||
|
)
|
||||||
|
cg = CallGraph(src)
|
||||||
|
dangerous = cg.find_reachable_dangerous("main", set())
|
||||||
|
assert len(dangerous) == 1
|
||||||
|
|
||||||
|
def test_is_patched_endswith(self, tmp_path: Path) -> None:
|
||||||
|
"""_is_patched should match patches ending with .short (line 580)."""
|
||||||
|
src = self._make_src(
|
||||||
|
tmp_path,
|
||||||
|
{
|
||||||
|
"pkg/__init__.py": "",
|
||||||
|
"pkg/mod.py": """
|
||||||
|
import subprocess
|
||||||
|
def main():
|
||||||
|
subprocess.run(["echo"])
|
||||||
|
""",
|
||||||
|
},
|
||||||
|
)
|
||||||
|
cg = CallGraph(src)
|
||||||
|
# "devx.ci.release.subprocess.run" ends with ".run"
|
||||||
|
dangerous = cg.find_reachable_dangerous("main", {"devx.ci.release.subprocess.run"})
|
||||||
|
assert dangerous == []
|
||||||
|
|
||||||
|
def test_is_patched_full_name_match(self) -> None:
|
||||||
|
"""_is_patched should match exact full name."""
|
||||||
|
assert CallGraph._is_patched("subprocess.run", "run", {"subprocess.run"}) is True
|
||||||
|
|
||||||
|
def test_is_patched_short_name_match(self) -> None:
|
||||||
|
"""_is_patched should match short name in patches."""
|
||||||
|
assert CallGraph._is_patched("subprocess.run", "run", {"run"}) is True
|
||||||
|
|
||||||
|
def test_is_patched_no_match(self) -> None:
|
||||||
|
"""_is_patched should return False when not patched."""
|
||||||
|
assert CallGraph._is_patched("subprocess.run", "run", {"other"}) is False
|
||||||
|
|
||||||
|
def test_is_patched_endswith_no_false_positive(self) -> None:
|
||||||
|
"""endswith should not match substrings (e.g. 'run' vs 'run_cmd')."""
|
||||||
|
assert CallGraph._is_patched("mod.run_cmd", "run_cmd", {"mod.run"}) is False
|
||||||
|
|
||||||
|
|
||||||
|
class TestVisitCallAttributeTarget:
|
||||||
|
"""Tests for visit_Call with ast.Attribute target (lines 851-862)."""
|
||||||
|
|
||||||
|
def test_invoke_with_module_func_attribute(self, tmp_path: Path) -> None:
|
||||||
|
"""runner.invoke(module.func) should resolve via import_map."""
|
||||||
|
src = tmp_path / "src"
|
||||||
|
src.mkdir()
|
||||||
|
(src / "pkg").mkdir()
|
||||||
|
(src / "pkg" / "__init__.py").write_text("")
|
||||||
|
(src / "pkg" / "cli.py").write_text("import subprocess\ndef main():\n subprocess.run(['echo'])\n")
|
||||||
|
|
||||||
|
test_file = tmp_path / "test_example.py"
|
||||||
|
test_file.write_text(
|
||||||
|
textwrap.dedent(
|
||||||
|
"""
|
||||||
|
from click.testing import CliRunner
|
||||||
|
import pkg.cli as cli_mod
|
||||||
|
class TestExample:
|
||||||
|
def test_invoke(self) -> None:
|
||||||
|
runner = CliRunner()
|
||||||
|
result = runner.invoke(cli_mod.main, [])
|
||||||
|
"""
|
||||||
|
)
|
||||||
|
)
|
||||||
|
cg = CallGraph(src)
|
||||||
|
violations = analyze_file(test_file, call_graph=cg)
|
||||||
|
transitive = [v for v in violations if v.category == "transitive-subprocess"]
|
||||||
|
assert len(transitive) == 1
|
||||||
|
|
||||||
|
def test_invoke_with_attribute_no_import_map(self, tmp_path: Path) -> None:
|
||||||
|
"""runner.invoke(mod.func) where mod not in import_map uses attr only (line 860)."""
|
||||||
|
src = tmp_path / "src"
|
||||||
|
src.mkdir()
|
||||||
|
(src / "pkg").mkdir()
|
||||||
|
(src / "pkg" / "__init__.py").write_text("")
|
||||||
|
(src / "pkg" / "cli.py").write_text("import subprocess\ndef main():\n subprocess.run(['echo'])\n")
|
||||||
|
|
||||||
|
test_file = tmp_path / "test_example.py"
|
||||||
|
test_file.write_text(
|
||||||
|
textwrap.dedent(
|
||||||
|
"""
|
||||||
|
from click.testing import CliRunner
|
||||||
|
class TestExample:
|
||||||
|
def test_invoke(self) -> None:
|
||||||
|
runner = CliRunner()
|
||||||
|
# unknown_mod not imported, so falls back to attr name
|
||||||
|
result = runner.invoke(unknown_mod.main, [])
|
||||||
|
"""
|
||||||
|
)
|
||||||
|
)
|
||||||
|
cg = CallGraph(src)
|
||||||
|
violations = analyze_file(test_file, call_graph=cg)
|
||||||
|
transitive = [v for v in violations if v.category == "transitive-subprocess"]
|
||||||
|
assert len(transitive) == 1
|
||||||
|
|
||||||
|
def test_invoke_with_attribute_non_name_value(self, tmp_path: Path) -> None:
|
||||||
|
"""runner.invoke(get_obj().func) — target.value is not a Name (line 862)."""
|
||||||
|
src = tmp_path / "src"
|
||||||
|
src.mkdir()
|
||||||
|
(src / "pkg").mkdir()
|
||||||
|
(src / "pkg" / "__init__.py").write_text("")
|
||||||
|
(src / "pkg" / "cli.py").write_text("import subprocess\ndef main():\n subprocess.run(['echo'])\n")
|
||||||
|
|
||||||
|
test_file = tmp_path / "test_example.py"
|
||||||
|
test_file.write_text(
|
||||||
|
textwrap.dedent(
|
||||||
|
"""
|
||||||
|
from click.testing import CliRunner
|
||||||
|
class TestExample:
|
||||||
|
def test_invoke(self) -> None:
|
||||||
|
runner = CliRunner()
|
||||||
|
result = runner.invoke(CliRunner().main, [])
|
||||||
|
"""
|
||||||
|
)
|
||||||
|
)
|
||||||
|
cg = CallGraph(src)
|
||||||
|
violations = analyze_file(test_file, call_graph=cg)
|
||||||
|
transitive = [v for v in violations if v.category == "transitive-subprocess"]
|
||||||
|
assert len(transitive) == 1
|
||||||
|
|
||||||
|
|
||||||
|
class TestIsIntegrationTest:
|
||||||
|
"""Tests for _is_integration_test (lines 1076-1080)."""
|
||||||
|
|
||||||
|
def test_marker_based_integration(self) -> None:
|
||||||
|
"""A test item with 'integration' in keywords should be detected."""
|
||||||
|
item = MagicMock()
|
||||||
|
item.keywords = {"integration", "test_foo"}
|
||||||
|
item.fspath = "tests/unit/test_foo.py"
|
||||||
|
assert _is_integration_test(item) is True
|
||||||
|
|
||||||
|
def test_path_based_integration(self) -> None:
|
||||||
|
"""A test item in an integration/ directory should be detected."""
|
||||||
|
item = MagicMock()
|
||||||
|
item.keywords = {"test_foo"}
|
||||||
|
item.fspath = "tests/integration/test_foo.py"
|
||||||
|
assert _is_integration_test(item) is True
|
||||||
|
|
||||||
|
def test_not_integration_test(self) -> None:
|
||||||
|
"""A regular test item should not be detected as integration."""
|
||||||
|
item = MagicMock()
|
||||||
|
item.keywords = {"test_foo"}
|
||||||
|
item.fspath = "tests/unit/test_foo.py"
|
||||||
|
assert _is_integration_test(item) is False
|
||||||
|
|
||||||
|
def test_no_keywords_attr(self) -> None:
|
||||||
|
"""An item without keywords attr should use fspath only."""
|
||||||
|
item = MagicMock()
|
||||||
|
item.keywords = {}
|
||||||
|
item.fspath = "tests/unit/test_foo.py"
|
||||||
|
assert _is_integration_test(item) is False
|
||||||
|
|
||||||
|
|
||||||
|
class TestLoadTestIsolationConfig:
|
||||||
|
"""Tests for _load_test_isolation_config — project-specific rule merging."""
|
||||||
|
|
||||||
|
def test_merges_io_functions(self, tmp_path: Path, monkeypatch: pytest.MonkeyPatch) -> None:
|
||||||
|
"""Project-specific io_functions are added to KNOWN_IO_FUNCTIONS."""
|
||||||
|
pyproject = tmp_path / "pyproject.toml"
|
||||||
|
pyproject.write_text(
|
||||||
|
'[tool.devx.check_test_isolation]\nio_functions = { "my_custom_io" = "reads from disk" }\n'
|
||||||
|
)
|
||||||
|
monkeypatch.chdir(tmp_path)
|
||||||
|
_load_test_isolation_config()
|
||||||
|
assert "my_custom_io" in KNOWN_IO_FUNCTIONS
|
||||||
|
assert KNOWN_IO_FUNCTIONS["my_custom_io"] == "reads from disk"
|
||||||
|
|
||||||
|
def test_merges_subprocess_helpers(self, tmp_path: Path, monkeypatch: pytest.MonkeyPatch) -> None:
|
||||||
|
"""Project-specific subprocess_helpers are added."""
|
||||||
|
pyproject = tmp_path / "pyproject.toml"
|
||||||
|
pyproject.write_text(
|
||||||
|
'[tool.devx.check_test_isolation]\nsubprocess_helpers = { "my_sp_helper" = "calls subprocess.run" }\n'
|
||||||
|
)
|
||||||
|
monkeypatch.chdir(tmp_path)
|
||||||
|
_load_test_isolation_config()
|
||||||
|
assert "my_sp_helper" in KNOWN_SUBPROCESS_HELPERS
|
||||||
|
|
||||||
|
def test_merges_helper_internal_calls(self, tmp_path: Path, monkeypatch: pytest.MonkeyPatch) -> None:
|
||||||
|
"""Project-specific helper_internal_calls are merged."""
|
||||||
|
pyproject = tmp_path / "pyproject.toml"
|
||||||
|
pyproject.write_text(
|
||||||
|
'[tool.devx.check_test_isolation]\nhelper_internal_calls = { "my_helper" = ["subprocess", "run_cmd"] }\n'
|
||||||
|
)
|
||||||
|
monkeypatch.chdir(tmp_path)
|
||||||
|
_load_test_isolation_config()
|
||||||
|
assert "my_helper" in HELPER_INTERNAL_CALLS
|
||||||
|
assert HELPER_INTERNAL_CALLS["my_helper"] == {"subprocess", "run_cmd"}
|
||||||
|
|
||||||
|
def test_merges_io_internal_calls(self, tmp_path: Path, monkeypatch: pytest.MonkeyPatch) -> None:
|
||||||
|
"""Project-specific io_internal_calls are merged."""
|
||||||
|
pyproject = tmp_path / "pyproject.toml"
|
||||||
|
pyproject.write_text(
|
||||||
|
'[tool.devx.check_test_isolation]\nio_internal_calls = { "my_io_func" = ["open", "yaml"] }\n'
|
||||||
|
)
|
||||||
|
monkeypatch.chdir(tmp_path)
|
||||||
|
_load_test_isolation_config()
|
||||||
|
assert "my_io_func" in IO_INTERNAL_CALLS
|
||||||
|
assert IO_INTERNAL_CALLS["my_io_func"] == {"open", "yaml"}
|
||||||
|
|
||||||
|
def test_merges_heavy_module_imports(self, tmp_path: Path, monkeypatch: pytest.MonkeyPatch) -> None:
|
||||||
|
"""Project-specific heavy_module_imports are merged."""
|
||||||
|
pyproject = tmp_path / "pyproject.toml"
|
||||||
|
pyproject.write_text('[tool.devx.check_test_isolation]\nheavy_module_imports = { "mymodule" = 150.0 }\n')
|
||||||
|
monkeypatch.chdir(tmp_path)
|
||||||
|
_load_test_isolation_config()
|
||||||
|
assert "mymodule" in HEAVY_MODULE_IMPORTS
|
||||||
|
assert HEAVY_MODULE_IMPORTS["mymodule"] == 150.0
|
||||||
|
|
||||||
|
def test_no_config_section_is_noop(self, tmp_path: Path, monkeypatch: pytest.MonkeyPatch) -> None:
|
||||||
|
"""Missing [tool.devx.check_test_isolation] section is a no-op."""
|
||||||
|
pyproject = tmp_path / "pyproject.toml"
|
||||||
|
pyproject.write_text('[tool.devx]\nother_key = "value"\n')
|
||||||
|
monkeypatch.chdir(tmp_path)
|
||||||
|
before_io = dict(KNOWN_IO_FUNCTIONS)
|
||||||
|
_load_test_isolation_config()
|
||||||
|
assert before_io == KNOWN_IO_FUNCTIONS
|
||||||
|
|
||||||
|
def test_no_pyproject_is_noop(self, tmp_path: Path, monkeypatch: pytest.MonkeyPatch) -> None:
|
||||||
|
"""No pyproject.toml at all is a no-op."""
|
||||||
|
monkeypatch.chdir(tmp_path)
|
||||||
|
before = dict(KNOWN_SUBPROCESS_HELPERS)
|
||||||
|
_load_test_isolation_config()
|
||||||
|
assert before == KNOWN_SUBPROCESS_HELPERS
|
||||||
|
|
||||||
|
def test_non_dict_config_is_noop(self, tmp_path: Path, monkeypatch: pytest.MonkeyPatch) -> None:
|
||||||
|
"""A non-dict check_test_isolation section is a no-op."""
|
||||||
|
pyproject = tmp_path / "pyproject.toml"
|
||||||
|
pyproject.write_text('[tool.devx]\ncheck_test_isolation = "not_a_dict"\n')
|
||||||
|
monkeypatch.chdir(tmp_path)
|
||||||
|
before = dict(HEAVY_MODULE_IMPORTS)
|
||||||
|
_load_test_isolation_config()
|
||||||
|
assert before == HEAVY_MODULE_IMPORTS
|
||||||
|
|
||||||
|
def test_invalid_entry_types_are_skipped(self, tmp_path: Path, monkeypatch: pytest.MonkeyPatch) -> None:
|
||||||
|
"""Entries with wrong types (non-str values) are silently skipped."""
|
||||||
|
pyproject = tmp_path / "pyproject.toml"
|
||||||
|
pyproject.write_text(
|
||||||
|
"[tool.devx.check_test_isolation]\n"
|
||||||
|
'io_functions = { "good_func" = "desc", "bad_func" = 123 }\n'
|
||||||
|
'heavy_module_imports = { "good_mod" = 100.0, "bad_mod" = "fast" }\n'
|
||||||
|
)
|
||||||
|
monkeypatch.chdir(tmp_path)
|
||||||
|
_load_test_isolation_config()
|
||||||
|
assert "good_func" in KNOWN_IO_FUNCTIONS
|
||||||
|
assert "bad_func" not in KNOWN_IO_FUNCTIONS
|
||||||
|
assert "good_mod" in HEAVY_MODULE_IMPORTS
|
||||||
|
assert "bad_mod" not in HEAVY_MODULE_IMPORTS
|
||||||
|
|
||||||
|
def test_extends_without_replacing_defaults(self, tmp_path: Path, monkeypatch: pytest.MonkeyPatch) -> None:
|
||||||
|
"""Project config adds to defaults without removing them."""
|
||||||
|
pyproject = tmp_path / "pyproject.toml"
|
||||||
|
pyproject.write_text('[tool.devx.check_test_isolation]\nio_functions = { "project_func" = "project I/O" }\n')
|
||||||
|
monkeypatch.chdir(tmp_path)
|
||||||
|
_load_test_isolation_config()
|
||||||
|
# Default entries still present
|
||||||
|
assert "get_pat" in KNOWN_IO_FUNCTIONS
|
||||||
|
# Project entry added
|
||||||
|
assert "project_func" in KNOWN_IO_FUNCTIONS
|
||||||
|
|||||||
@@ -10,6 +10,7 @@ from devx.tools.check_test_speed import (
|
|||||||
DEFAULT_MAX_SECONDS,
|
DEFAULT_MAX_SECONDS,
|
||||||
DEFAULT_MAX_SINGLE_SECONDS,
|
DEFAULT_MAX_SINGLE_SECONDS,
|
||||||
TEST_COMMAND,
|
TEST_COMMAND,
|
||||||
|
_ci_scale_limit,
|
||||||
check_per_test_speed,
|
check_per_test_speed,
|
||||||
check_speed,
|
check_speed,
|
||||||
cli,
|
cli,
|
||||||
@@ -144,7 +145,26 @@ def test_main_module_block() -> None:
|
|||||||
mock_cli.assert_called_once_with([])
|
mock_cli.assert_called_once_with([])
|
||||||
|
|
||||||
|
|
||||||
|
class TestCiScaleLimit:
|
||||||
|
def test_no_scaling_when_not_ci(self) -> None:
|
||||||
|
with patch("devx.tools.check_test_speed._IS_CI", False):
|
||||||
|
assert _ci_scale_limit(10.0) == 10.0
|
||||||
|
assert _ci_scale_limit(0.5) == 0.5
|
||||||
|
|
||||||
|
def test_scales_when_ci(self) -> None:
|
||||||
|
with patch("devx.tools.check_test_speed._IS_CI", True):
|
||||||
|
with patch("devx.tools.check_test_speed.CI_SCALE_FACTOR", 4.0):
|
||||||
|
assert _ci_scale_limit(10.0) == 40.0
|
||||||
|
assert _ci_scale_limit(0.5) == 2.0
|
||||||
|
|
||||||
|
def test_custom_scale_factor(self) -> None:
|
||||||
|
with patch("devx.tools.check_test_speed._IS_CI", True):
|
||||||
|
with patch("devx.tools.check_test_speed.CI_SCALE_FACTOR", 2.5):
|
||||||
|
assert _ci_scale_limit(10.0) == 25.0
|
||||||
|
|
||||||
|
|
||||||
class TestMain:
|
class TestMain:
|
||||||
|
@patch("devx.tools.check_test_speed._IS_CI", False)
|
||||||
@patch("devx.tools.check_test_speed.run_tests")
|
@patch("devx.tools.check_test_speed.run_tests")
|
||||||
@patch("devx.tools.check_test_speed.parse_duration")
|
@patch("devx.tools.check_test_speed.parse_duration")
|
||||||
@patch("devx.tools.check_test_speed.check_speed")
|
@patch("devx.tools.check_test_speed.check_speed")
|
||||||
@@ -174,6 +194,7 @@ class TestMain:
|
|||||||
mock_parse_per.assert_called_once()
|
mock_parse_per.assert_called_once()
|
||||||
mock_check_per.assert_called_once_with([], DEFAULT_MAX_SINGLE_SECONDS)
|
mock_check_per.assert_called_once_with([], DEFAULT_MAX_SINGLE_SECONDS)
|
||||||
|
|
||||||
|
@patch("devx.tools.check_test_speed._IS_CI", False)
|
||||||
@patch("devx.tools.check_test_speed.run_tests")
|
@patch("devx.tools.check_test_speed.run_tests")
|
||||||
@patch("devx.tools.check_test_speed.parse_duration")
|
@patch("devx.tools.check_test_speed.parse_duration")
|
||||||
def test_slow_total_exits(
|
def test_slow_total_exits(
|
||||||
@@ -189,6 +210,7 @@ class TestMain:
|
|||||||
assert result.exit_code == 1
|
assert result.exit_code == 1
|
||||||
assert "too slow" in result.output.lower()
|
assert "too slow" in result.output.lower()
|
||||||
|
|
||||||
|
@patch("devx.tools.check_test_speed._IS_CI", False)
|
||||||
@patch("devx.tools.check_test_speed.run_tests")
|
@patch("devx.tools.check_test_speed.run_tests")
|
||||||
@patch("devx.tools.check_test_speed.parse_duration")
|
@patch("devx.tools.check_test_speed.parse_duration")
|
||||||
@patch("devx.tools.check_test_speed.check_speed")
|
@patch("devx.tools.check_test_speed.check_speed")
|
||||||
@@ -213,6 +235,7 @@ class TestMain:
|
|||||||
assert "Per-test speed check FAILED" in result.output
|
assert "Per-test speed check FAILED" in result.output
|
||||||
assert "test_slow" in result.output
|
assert "test_slow" in result.output
|
||||||
|
|
||||||
|
@patch("devx.tools.check_test_speed._IS_CI", False)
|
||||||
@patch("devx.tools.check_test_speed.run_tests")
|
@patch("devx.tools.check_test_speed.run_tests")
|
||||||
def test_parse_failure_exits(
|
def test_parse_failure_exits(
|
||||||
self,
|
self,
|
||||||
@@ -225,6 +248,7 @@ class TestMain:
|
|||||||
assert result.exit_code == 1
|
assert result.exit_code == 1
|
||||||
assert "Could not parse" in result.output
|
assert "Could not parse" in result.output
|
||||||
|
|
||||||
|
@patch("devx.tools.check_test_speed._IS_CI", False)
|
||||||
@patch("devx.tools.check_test_speed.run_tests")
|
@patch("devx.tools.check_test_speed.run_tests")
|
||||||
@patch("devx.tools.check_test_speed.parse_duration")
|
@patch("devx.tools.check_test_speed.parse_duration")
|
||||||
@patch("devx.tools.check_test_speed.check_speed")
|
@patch("devx.tools.check_test_speed.check_speed")
|
||||||
@@ -248,6 +272,7 @@ class TestMain:
|
|||||||
assert result.exit_code == 0
|
assert result.exit_code == 0
|
||||||
mock_check.assert_called_once_with(0.5, 1.5)
|
mock_check.assert_called_once_with(0.5, 1.5)
|
||||||
|
|
||||||
|
@patch("devx.tools.check_test_speed._IS_CI", False)
|
||||||
@patch("devx.tools.check_test_speed.run_tests")
|
@patch("devx.tools.check_test_speed.run_tests")
|
||||||
@patch("devx.tools.check_test_speed.parse_duration")
|
@patch("devx.tools.check_test_speed.parse_duration")
|
||||||
@patch("devx.tools.check_test_speed.check_speed")
|
@patch("devx.tools.check_test_speed.check_speed")
|
||||||
@@ -270,6 +295,7 @@ class TestMain:
|
|||||||
mock_parse_per.assert_not_called()
|
mock_parse_per.assert_not_called()
|
||||||
mock_check_per.assert_not_called()
|
mock_check_per.assert_not_called()
|
||||||
|
|
||||||
|
@patch("devx.tools.check_test_speed._IS_CI", False)
|
||||||
@patch("devx.tools.check_test_speed.run_tests")
|
@patch("devx.tools.check_test_speed.run_tests")
|
||||||
@patch("devx.tools.check_test_speed.parse_duration")
|
@patch("devx.tools.check_test_speed.parse_duration")
|
||||||
@patch("devx.tools.check_test_speed.check_speed")
|
@patch("devx.tools.check_test_speed.check_speed")
|
||||||
@@ -292,3 +318,32 @@ class TestMain:
|
|||||||
result = runner.invoke(cli, ["--max-single-seconds", "1.0"])
|
result = runner.invoke(cli, ["--max-single-seconds", "1.0"])
|
||||||
assert result.exit_code == 0
|
assert result.exit_code == 0
|
||||||
mock_check_per.assert_called_once_with([], 1.0)
|
mock_check_per.assert_called_once_with([], 1.0)
|
||||||
|
|
||||||
|
@patch("devx.tools.check_test_speed._IS_CI", True)
|
||||||
|
@patch("devx.tools.check_test_speed.CI_SCALE_FACTOR", 4.0)
|
||||||
|
@patch("devx.tools.check_test_speed.run_tests")
|
||||||
|
@patch("devx.tools.check_test_speed.parse_duration")
|
||||||
|
@patch("devx.tools.check_test_speed.check_speed")
|
||||||
|
@patch("devx.tools.check_test_speed.parse_per_test_durations")
|
||||||
|
@patch("devx.tools.check_test_speed.check_per_test_speed")
|
||||||
|
def test_ci_scales_limits(
|
||||||
|
self,
|
||||||
|
mock_check_per: MagicMock,
|
||||||
|
mock_parse_per: MagicMock,
|
||||||
|
mock_check: MagicMock,
|
||||||
|
mock_parse: MagicMock,
|
||||||
|
mock_run: MagicMock,
|
||||||
|
) -> None:
|
||||||
|
mock_run.return_value = ("out\n", "err\n")
|
||||||
|
mock_parse.return_value = 30.0 # would fail local (10s) but pass CI (40s)
|
||||||
|
mock_parse_per.return_value = []
|
||||||
|
mock_check_per.return_value = []
|
||||||
|
|
||||||
|
runner = CliRunner()
|
||||||
|
result = runner.invoke(cli, [])
|
||||||
|
assert result.exit_code == 0
|
||||||
|
assert "CI environment detected" in result.output
|
||||||
|
assert "scaling limits by 4.0x" in result.output
|
||||||
|
# check_speed called with scaled limit
|
||||||
|
mock_check.assert_called_once_with(30.0, 40.0)
|
||||||
|
mock_check_per.assert_called_once_with([], 2.0)
|
||||||
|
|||||||
@@ -0,0 +1,172 @@
|
|||||||
|
"""Unit tests for devx.ci.cancel_superseded_runs."""
|
||||||
|
|
||||||
|
from __future__ import annotations
|
||||||
|
|
||||||
|
import json
|
||||||
|
import urllib.error
|
||||||
|
from unittest.mock import MagicMock, patch
|
||||||
|
|
||||||
|
import pytest
|
||||||
|
|
||||||
|
import devx.ci.cancel_superseded_runs as mod
|
||||||
|
from devx.ci.cancel_superseded_runs import _api_request, cancel_run, list_running_runs, main
|
||||||
|
|
||||||
|
_HTTP_NO_CONTENT = mod._HTTP_NO_CONTENT
|
||||||
|
_PAGE_SIZE = mod._PAGE_SIZE
|
||||||
|
|
||||||
|
|
||||||
|
class TestConstants:
|
||||||
|
def test_http_no_content_is_204(self) -> None:
|
||||||
|
assert _HTTP_NO_CONTENT == 204
|
||||||
|
|
||||||
|
def test_page_size_is_50(self) -> None:
|
||||||
|
assert _PAGE_SIZE == 50
|
||||||
|
|
||||||
|
|
||||||
|
class TestApiRequest:
|
||||||
|
def test_returns_empty_for_204(self) -> None:
|
||||||
|
mock_resp = MagicMock()
|
||||||
|
mock_resp.status = _HTTP_NO_CONTENT
|
||||||
|
mock_resp.read.return_value = b""
|
||||||
|
mock_resp.__enter__ = MagicMock(return_value=mock_resp)
|
||||||
|
mock_resp.__exit__ = MagicMock(return_value=None)
|
||||||
|
with patch("urllib.request.urlopen", return_value=mock_resp):
|
||||||
|
result = _api_request("POST", "/repos/test/actions/runs/1/cancel", "tok", "https://x")
|
||||||
|
assert result == {}
|
||||||
|
|
||||||
|
def test_returns_json_for_200(self) -> None:
|
||||||
|
mock_resp = MagicMock()
|
||||||
|
mock_resp.status = 200
|
||||||
|
mock_resp.read.return_value = json.dumps({"id": 1}).encode()
|
||||||
|
mock_resp.__enter__ = MagicMock(return_value=mock_resp)
|
||||||
|
mock_resp.__exit__ = MagicMock(return_value=None)
|
||||||
|
with patch("urllib.request.urlopen", return_value=mock_resp):
|
||||||
|
result = _api_request("GET", "/repos/test/actions/runs", "tok", "https://x")
|
||||||
|
assert result == {"id": 1}
|
||||||
|
|
||||||
|
def test_http_error_raises(self) -> None:
|
||||||
|
err = urllib.error.HTTPError("x", 500, "err", {}, None)
|
||||||
|
err.read = MagicMock(return_value=b"error body")
|
||||||
|
with patch("urllib.request.urlopen", side_effect=err):
|
||||||
|
with pytest.raises(urllib.error.HTTPError):
|
||||||
|
_api_request("GET", "/repos/test/actions/runs", "tok", "https://x")
|
||||||
|
|
||||||
|
def test_url_error_raises(self) -> None:
|
||||||
|
with patch("urllib.request.urlopen", side_effect=urllib.error.URLError("fail")):
|
||||||
|
with pytest.raises(urllib.error.URLError):
|
||||||
|
_api_request("GET", "/repos/test/actions/runs", "tok", "https://x")
|
||||||
|
|
||||||
|
|
||||||
|
class TestListRunningRuns:
|
||||||
|
def test_paginates_until_empty(self) -> None:
|
||||||
|
page1 = {"workflow_runs": [{"id": 1}, {"id": 2}], "total_count": 2}
|
||||||
|
page2 = {"workflow_runs": [], "total_count": 2}
|
||||||
|
responses = iter([page1, page2])
|
||||||
|
with patch.object(mod, "_api_request", side_effect=lambda *a, **k: next(responses)):
|
||||||
|
runs = list_running_runs("owner/repo", "tok", "https://x")
|
||||||
|
assert len(runs) == 2
|
||||||
|
|
||||||
|
def test_empty_first_page(self) -> None:
|
||||||
|
with patch.object(mod, "_api_request", return_value={"workflow_runs": [], "total_count": 0}):
|
||||||
|
runs = list_running_runs("owner/repo", "tok", "https://x")
|
||||||
|
assert runs == []
|
||||||
|
|
||||||
|
def test_stops_at_page_size(self) -> None:
|
||||||
|
full_page = {"workflow_runs": [{"id": i} for i in range(_PAGE_SIZE)], "total_count": _PAGE_SIZE + 1}
|
||||||
|
half_page = {"workflow_runs": [{"id": 99}], "total_count": _PAGE_SIZE + 1}
|
||||||
|
responses = iter([full_page, half_page])
|
||||||
|
with patch.object(mod, "_api_request", side_effect=lambda *a, **k: next(responses)):
|
||||||
|
runs = list_running_runs("owner/repo", "tok", "https://x")
|
||||||
|
assert len(runs) == _PAGE_SIZE + 1
|
||||||
|
|
||||||
|
def test_uses_in_progress_status(self) -> None:
|
||||||
|
with patch.object(mod, "_api_request", return_value={"workflow_runs": [], "total_count": 0}) as mock_req:
|
||||||
|
list_running_runs("owner/repo", "tok", "https://x")
|
||||||
|
path = mock_req.call_args.args[1]
|
||||||
|
assert "status=in_progress" in path
|
||||||
|
assert "status=running" not in path
|
||||||
|
|
||||||
|
def test_accepts_bare_list(self) -> None:
|
||||||
|
with patch.object(mod, "_api_request", return_value=[{"id": 1}, {"id": 2}]):
|
||||||
|
runs = list_running_runs("owner/repo", "tok", "https://x")
|
||||||
|
assert len(runs) == 2
|
||||||
|
|
||||||
|
|
||||||
|
class TestCancelRun:
|
||||||
|
def test_success_returns_true(self) -> None:
|
||||||
|
with patch.object(mod, "_api_request", return_value={}):
|
||||||
|
assert cancel_run("owner/repo", 123, "tok", "https://x") is True
|
||||||
|
|
||||||
|
def test_http_error_returns_false(self) -> None:
|
||||||
|
with patch.object(mod, "_api_request", side_effect=urllib.error.HTTPError("x", 500, "err", {}, None)):
|
||||||
|
assert cancel_run("owner/repo", 123, "tok", "https://x") is False
|
||||||
|
|
||||||
|
|
||||||
|
class TestMain:
|
||||||
|
def test_no_token_exits_zero(self, monkeypatch: pytest.MonkeyPatch) -> None:
|
||||||
|
monkeypatch.delenv("CI_GITEA_API_TOKEN", raising=False)
|
||||||
|
monkeypatch.delenv("CI_GITEA_TOKEN", raising=False)
|
||||||
|
monkeypatch.setattr("sys.argv", ["cancel", "--repo", "o/r", "--current-run-id", "1", "--head-branch", "feat"])
|
||||||
|
assert main() == 0
|
||||||
|
|
||||||
|
def test_no_superseded_runs(self, monkeypatch: pytest.MonkeyPatch) -> None:
|
||||||
|
monkeypatch.setenv("CI_GITEA_API_TOKEN", "tok")
|
||||||
|
monkeypatch.setattr("sys.argv", ["cancel", "--repo", "o/r", "--current-run-id", "10", "--head-branch", "feat"])
|
||||||
|
with patch.object(mod, "list_running_runs", return_value=[]):
|
||||||
|
assert main() == 0
|
||||||
|
|
||||||
|
def test_cancels_superseded(self, monkeypatch: pytest.MonkeyPatch) -> None:
|
||||||
|
monkeypatch.setenv("CI_GITEA_API_TOKEN", "tok")
|
||||||
|
runs = [
|
||||||
|
{"id": 5, "head_branch": "feat"},
|
||||||
|
{"id": 8, "head_branch": "feat"},
|
||||||
|
{"id": 12, "head_branch": "other"},
|
||||||
|
]
|
||||||
|
monkeypatch.setattr("sys.argv", ["cancel", "--repo", "o/r", "--current-run-id", "10", "--head-branch", "feat"])
|
||||||
|
with patch.object(mod, "list_running_runs", return_value=runs):
|
||||||
|
with patch.object(mod, "cancel_run", return_value=True) as mock_cancel:
|
||||||
|
assert main() == 0
|
||||||
|
cancelled_ids = [call.args[1] for call in mock_cancel.call_args_list]
|
||||||
|
assert cancelled_ids == [5, 8]
|
||||||
|
|
||||||
|
def test_dry_run_does_not_cancel(self, monkeypatch: pytest.MonkeyPatch) -> None:
|
||||||
|
monkeypatch.setenv("CI_GITEA_API_TOKEN", "tok")
|
||||||
|
runs = [{"id": 5, "head_branch": "feat"}]
|
||||||
|
monkeypatch.setattr(
|
||||||
|
"sys.argv",
|
||||||
|
["cancel", "--repo", "o/r", "--current-run-id", "10", "--head-branch", "feat", "--dry-run"],
|
||||||
|
)
|
||||||
|
with patch.object(mod, "list_running_runs", return_value=runs):
|
||||||
|
with patch.object(mod, "cancel_run", return_value=True) as mock_cancel:
|
||||||
|
assert main() == 0
|
||||||
|
assert mock_cancel.call_count == 0
|
||||||
|
|
||||||
|
def test_cancel_failure_continues(self, monkeypatch: pytest.MonkeyPatch) -> None:
|
||||||
|
monkeypatch.setenv("CI_GITEA_API_TOKEN", "tok")
|
||||||
|
runs = [{"id": 5, "head_branch": "feat"}, {"id": 8, "head_branch": "feat"}]
|
||||||
|
monkeypatch.setattr("sys.argv", ["cancel", "--repo", "o/r", "--current-run-id", "10", "--head-branch", "feat"])
|
||||||
|
with patch.object(mod, "list_running_runs", return_value=runs):
|
||||||
|
with patch.object(mod, "cancel_run", side_effect=[False, True]):
|
||||||
|
assert main() == 0
|
||||||
|
|
||||||
|
def test_404_returns_zero(self, monkeypatch: pytest.MonkeyPatch) -> None:
|
||||||
|
monkeypatch.setenv("CI_GITEA_API_TOKEN", "tok")
|
||||||
|
monkeypatch.setattr("sys.argv", ["cancel", "--repo", "o/r", "--current-run-id", "10", "--head-branch", "feat"])
|
||||||
|
err = urllib.error.HTTPError("x", 404, "Not Found", {}, None)
|
||||||
|
with patch.object(mod, "list_running_runs", side_effect=err):
|
||||||
|
assert main() == 0
|
||||||
|
|
||||||
|
def test_400_returns_zero(self, monkeypatch: pytest.MonkeyPatch) -> None:
|
||||||
|
monkeypatch.setenv("CI_GITEA_API_TOKEN", "tok")
|
||||||
|
monkeypatch.setattr("sys.argv", ["cancel", "--repo", "o/r", "--current-run-id", "10", "--head-branch", "feat"])
|
||||||
|
err = urllib.error.HTTPError("x", 400, "Bad Request", {}, None)
|
||||||
|
with patch.object(mod, "list_running_runs", side_effect=err):
|
||||||
|
assert main() == 0
|
||||||
|
|
||||||
|
def test_500_raises(self, monkeypatch: pytest.MonkeyPatch) -> None:
|
||||||
|
monkeypatch.setenv("CI_GITEA_API_TOKEN", "tok")
|
||||||
|
monkeypatch.setattr("sys.argv", ["cancel", "--repo", "o/r", "--current-run-id", "10", "--head-branch", "feat"])
|
||||||
|
err = urllib.error.HTTPError("x", 500, "Server Error", {}, None)
|
||||||
|
with patch.object(mod, "list_running_runs", side_effect=err):
|
||||||
|
with pytest.raises(urllib.error.HTTPError):
|
||||||
|
main()
|
||||||
@@ -0,0 +1,419 @@
|
|||||||
|
"""Unit tests for devx.ci.check_workflow_artifact_deps."""
|
||||||
|
|
||||||
|
from __future__ import annotations
|
||||||
|
|
||||||
|
import textwrap
|
||||||
|
from pathlib import Path
|
||||||
|
|
||||||
|
from click.testing import CliRunner
|
||||||
|
|
||||||
|
from devx.ci.check_workflow_artifact_deps import (
|
||||||
|
_check_workflow,
|
||||||
|
_extract_artifact_info,
|
||||||
|
_is_artifact_action,
|
||||||
|
main,
|
||||||
|
)
|
||||||
|
|
||||||
|
|
||||||
|
class TestIsArtifactAction:
|
||||||
|
def test_upload_action_gitea(self):
|
||||||
|
assert _is_artifact_action("christopherhx/gitea-upload-artifact@v4", ("upload-artifact",))
|
||||||
|
|
||||||
|
def test_upload_action_github(self):
|
||||||
|
assert _is_artifact_action("actions/upload-artifact@v4", ("upload-artifact",))
|
||||||
|
|
||||||
|
def test_download_action(self):
|
||||||
|
assert _is_artifact_action("christopherhx/gitea-download-artifact@v4", ("download-artifact",))
|
||||||
|
|
||||||
|
def test_non_artifact_action(self):
|
||||||
|
assert not _is_artifact_action("actions/checkout@v4", ("upload-artifact",))
|
||||||
|
|
||||||
|
def test_empty_string(self):
|
||||||
|
assert not _is_artifact_action("", ("upload-artifact",))
|
||||||
|
|
||||||
|
def test_case_insensitive(self):
|
||||||
|
assert _is_artifact_action("Actions/Upload-Artifact@v4", ("upload-artifact",))
|
||||||
|
|
||||||
|
|
||||||
|
class TestExtractArtifactInfo:
|
||||||
|
def test_uploads_and_downloads(self):
|
||||||
|
import yaml
|
||||||
|
|
||||||
|
workflow_yaml = textwrap.dedent("""
|
||||||
|
jobs:
|
||||||
|
producer:
|
||||||
|
steps:
|
||||||
|
- name: Upload config
|
||||||
|
uses: christopherhx/gitea-upload-artifact@v4
|
||||||
|
with:
|
||||||
|
name: config-${{ github.run_id }}
|
||||||
|
consumer:
|
||||||
|
needs: [producer]
|
||||||
|
steps:
|
||||||
|
- name: Download config
|
||||||
|
uses: christopherhx/gitea-download-artifact@v4
|
||||||
|
with:
|
||||||
|
name: config-${{ github.run_id }}
|
||||||
|
""").strip()
|
||||||
|
wf = yaml.safe_load(workflow_yaml)
|
||||||
|
uploads, downloads = _extract_artifact_info(wf)
|
||||||
|
assert uploads == {"config-${{ github.run_id }}": ["producer"]}
|
||||||
|
assert downloads == [("consumer", "config-${{ github.run_id }}", "Download config")]
|
||||||
|
|
||||||
|
def test_no_artifacts(self):
|
||||||
|
import yaml
|
||||||
|
|
||||||
|
workflow_yaml = textwrap.dedent("""
|
||||||
|
jobs:
|
||||||
|
build:
|
||||||
|
steps:
|
||||||
|
- name: Checkout
|
||||||
|
uses: actions/checkout@v4
|
||||||
|
""").strip()
|
||||||
|
wf = yaml.safe_load(workflow_yaml)
|
||||||
|
uploads, downloads = _extract_artifact_info(wf)
|
||||||
|
assert uploads == {}
|
||||||
|
assert downloads == []
|
||||||
|
|
||||||
|
def test_multiple_uploaders_same_artifact(self):
|
||||||
|
import yaml
|
||||||
|
|
||||||
|
workflow_yaml = textwrap.dedent("""
|
||||||
|
jobs:
|
||||||
|
producer-a:
|
||||||
|
steps:
|
||||||
|
- uses: christopherhx/gitea-upload-artifact@v4
|
||||||
|
with:
|
||||||
|
name: shared
|
||||||
|
producer-b:
|
||||||
|
steps:
|
||||||
|
- uses: christopherhx/gitea-upload-artifact@v4
|
||||||
|
with:
|
||||||
|
name: shared
|
||||||
|
""").strip()
|
||||||
|
wf = yaml.safe_load(workflow_yaml)
|
||||||
|
uploads, downloads = _extract_artifact_info(wf)
|
||||||
|
assert uploads == {"shared": ["producer-a", "producer-b"]}
|
||||||
|
|
||||||
|
def test_step_without_name(self):
|
||||||
|
import yaml
|
||||||
|
|
||||||
|
workflow_yaml = textwrap.dedent("""
|
||||||
|
jobs:
|
||||||
|
producer:
|
||||||
|
steps:
|
||||||
|
- uses: christopherhx/gitea-upload-artifact@v4
|
||||||
|
with:
|
||||||
|
name: data
|
||||||
|
consumer:
|
||||||
|
needs: [producer]
|
||||||
|
steps:
|
||||||
|
- uses: christopherhx/gitea-download-artifact@v4
|
||||||
|
with:
|
||||||
|
name: data
|
||||||
|
""").strip()
|
||||||
|
wf = yaml.safe_load(workflow_yaml)
|
||||||
|
uploads, downloads = _extract_artifact_info(wf)
|
||||||
|
assert downloads == [("consumer", "data", "")]
|
||||||
|
|
||||||
|
def test_upload_without_name_skipped(self):
|
||||||
|
import yaml
|
||||||
|
|
||||||
|
workflow_yaml = textwrap.dedent("""
|
||||||
|
jobs:
|
||||||
|
producer:
|
||||||
|
steps:
|
||||||
|
- uses: christopherhx/gitea-upload-artifact@v4
|
||||||
|
with:
|
||||||
|
path: ./dist
|
||||||
|
""").strip()
|
||||||
|
wf = yaml.safe_load(workflow_yaml)
|
||||||
|
uploads, downloads = _extract_artifact_info(wf)
|
||||||
|
assert uploads == {}
|
||||||
|
|
||||||
|
|
||||||
|
class TestCheckWorkflow:
|
||||||
|
def test_valid_dependency(self, tmp_path: Path):
|
||||||
|
workflow_yaml = textwrap.dedent("""
|
||||||
|
jobs:
|
||||||
|
producer:
|
||||||
|
steps:
|
||||||
|
- name: Upload config
|
||||||
|
uses: christopherhx/gitea-upload-artifact@v4
|
||||||
|
with:
|
||||||
|
name: config
|
||||||
|
consumer:
|
||||||
|
needs: [producer]
|
||||||
|
steps:
|
||||||
|
- name: Download config
|
||||||
|
uses: christopherhx/gitea-download-artifact@v4
|
||||||
|
with:
|
||||||
|
name: config
|
||||||
|
""").strip()
|
||||||
|
f = tmp_path / "test.yml"
|
||||||
|
f.write_text(workflow_yaml)
|
||||||
|
assert _check_workflow(f) == []
|
||||||
|
|
||||||
|
def test_missing_dependency(self, tmp_path: Path):
|
||||||
|
workflow_yaml = textwrap.dedent("""
|
||||||
|
jobs:
|
||||||
|
producer:
|
||||||
|
steps:
|
||||||
|
- name: Upload config
|
||||||
|
uses: christopherhx/gitea-upload-artifact@v4
|
||||||
|
with:
|
||||||
|
name: config
|
||||||
|
consumer:
|
||||||
|
needs: [other-job]
|
||||||
|
steps:
|
||||||
|
- name: Download config
|
||||||
|
uses: christopherhx/gitea-download-artifact@v4
|
||||||
|
with:
|
||||||
|
name: config
|
||||||
|
""").strip()
|
||||||
|
f = tmp_path / "test.yml"
|
||||||
|
f.write_text(workflow_yaml)
|
||||||
|
errors = _check_workflow(f)
|
||||||
|
assert len(errors) == 1
|
||||||
|
assert "consumer" in errors[0]
|
||||||
|
assert "producer" in errors[0]
|
||||||
|
|
||||||
|
def test_no_needs_at_all(self, tmp_path: Path):
|
||||||
|
workflow_yaml = textwrap.dedent("""
|
||||||
|
jobs:
|
||||||
|
producer:
|
||||||
|
steps:
|
||||||
|
- uses: christopherhx/gitea-upload-artifact@v4
|
||||||
|
with:
|
||||||
|
name: data
|
||||||
|
consumer:
|
||||||
|
steps:
|
||||||
|
- uses: christopherhx/gitea-download-artifact@v4
|
||||||
|
with:
|
||||||
|
name: data
|
||||||
|
""").strip()
|
||||||
|
f = tmp_path / "test.yml"
|
||||||
|
f.write_text(workflow_yaml)
|
||||||
|
errors = _check_workflow(f)
|
||||||
|
assert len(errors) == 1
|
||||||
|
assert "consumer" in errors[0]
|
||||||
|
|
||||||
|
def test_artifact_not_uploaded_in_workflow(self, tmp_path: Path):
|
||||||
|
workflow_yaml = textwrap.dedent("""
|
||||||
|
jobs:
|
||||||
|
consumer:
|
||||||
|
steps:
|
||||||
|
- name: Download external
|
||||||
|
uses: christopherhx/gitea-download-artifact@v4
|
||||||
|
with:
|
||||||
|
name: external-artifact
|
||||||
|
""").strip()
|
||||||
|
f = tmp_path / "test.yml"
|
||||||
|
f.write_text(workflow_yaml)
|
||||||
|
assert _check_workflow(f) == []
|
||||||
|
|
||||||
|
def test_multiple_uploaders_one_in_needs(self, tmp_path: Path):
|
||||||
|
workflow_yaml = textwrap.dedent("""
|
||||||
|
jobs:
|
||||||
|
producer-a:
|
||||||
|
steps:
|
||||||
|
- uses: christopherhx/gitea-upload-artifact@v4
|
||||||
|
with:
|
||||||
|
name: shared
|
||||||
|
producer-b:
|
||||||
|
steps:
|
||||||
|
- uses: christopherhx/gitea-upload-artifact@v4
|
||||||
|
with:
|
||||||
|
name: shared
|
||||||
|
consumer:
|
||||||
|
needs: [producer-a, other]
|
||||||
|
steps:
|
||||||
|
- uses: christopherhx/gitea-download-artifact@v4
|
||||||
|
with:
|
||||||
|
name: shared
|
||||||
|
""").strip()
|
||||||
|
f = tmp_path / "test.yml"
|
||||||
|
f.write_text(workflow_yaml)
|
||||||
|
assert _check_workflow(f) == []
|
||||||
|
|
||||||
|
def test_string_needs(self, tmp_path: Path):
|
||||||
|
workflow_yaml = textwrap.dedent("""
|
||||||
|
jobs:
|
||||||
|
producer:
|
||||||
|
steps:
|
||||||
|
- uses: christopherhx/gitea-upload-artifact@v4
|
||||||
|
with:
|
||||||
|
name: data
|
||||||
|
consumer:
|
||||||
|
needs: producer
|
||||||
|
steps:
|
||||||
|
- uses: christopherhx/gitea-download-artifact@v4
|
||||||
|
with:
|
||||||
|
name: data
|
||||||
|
""").strip()
|
||||||
|
f = tmp_path / "test.yml"
|
||||||
|
f.write_text(workflow_yaml)
|
||||||
|
assert _check_workflow(f) == []
|
||||||
|
|
||||||
|
def test_needs_null(self, tmp_path: Path):
|
||||||
|
workflow_yaml = textwrap.dedent("""
|
||||||
|
jobs:
|
||||||
|
producer:
|
||||||
|
steps:
|
||||||
|
- uses: christopherhx/gitea-upload-artifact@v4
|
||||||
|
with:
|
||||||
|
name: data
|
||||||
|
consumer:
|
||||||
|
needs: null
|
||||||
|
steps:
|
||||||
|
- uses: christopherhx/gitea-download-artifact@v4
|
||||||
|
with:
|
||||||
|
name: data
|
||||||
|
""").strip()
|
||||||
|
f = tmp_path / "test.yml"
|
||||||
|
f.write_text(workflow_yaml)
|
||||||
|
errors = _check_workflow(f)
|
||||||
|
assert len(errors) == 1
|
||||||
|
assert "consumer" in errors[0]
|
||||||
|
|
||||||
|
def test_invalid_yaml(self, tmp_path: Path):
|
||||||
|
f = tmp_path / "test.yml"
|
||||||
|
f.write_text("jobs: [invalid yaml: {")
|
||||||
|
errors = _check_workflow(f)
|
||||||
|
assert len(errors) == 1
|
||||||
|
assert "cannot parse YAML" in errors[0]
|
||||||
|
|
||||||
|
def test_not_a_dict(self, tmp_path: Path):
|
||||||
|
f = tmp_path / "test.yml"
|
||||||
|
f.write_text("just a string")
|
||||||
|
errors = _check_workflow(f)
|
||||||
|
assert len(errors) == 1
|
||||||
|
assert "not a valid workflow" in errors[0]
|
||||||
|
|
||||||
|
def test_no_jobs(self, tmp_path: Path):
|
||||||
|
f = tmp_path / "test.yml"
|
||||||
|
f.write_text("name: empty\non: push\n")
|
||||||
|
assert _check_workflow(f) == []
|
||||||
|
|
||||||
|
def test_continue_on_error_guard(self, tmp_path: Path):
|
||||||
|
workflow_yaml = textwrap.dedent("""
|
||||||
|
jobs:
|
||||||
|
producer:
|
||||||
|
steps:
|
||||||
|
- name: Upload config
|
||||||
|
uses: christopherhx/gitea-upload-artifact@v4
|
||||||
|
with:
|
||||||
|
name: config
|
||||||
|
consumer:
|
||||||
|
needs: [other-job]
|
||||||
|
steps:
|
||||||
|
- name: Download config
|
||||||
|
continue-on-error: true
|
||||||
|
uses: christopherhx/gitea-download-artifact@v4
|
||||||
|
with:
|
||||||
|
name: config
|
||||||
|
""").strip()
|
||||||
|
f = tmp_path / "test.yml"
|
||||||
|
f.write_text(workflow_yaml)
|
||||||
|
assert _check_workflow(f) == []
|
||||||
|
|
||||||
|
def test_continue_on_error_false_still_errors(self, tmp_path: Path):
|
||||||
|
workflow_yaml = textwrap.dedent("""
|
||||||
|
jobs:
|
||||||
|
producer:
|
||||||
|
steps:
|
||||||
|
- name: Upload config
|
||||||
|
uses: christopherhx/gitea-upload-artifact@v4
|
||||||
|
with:
|
||||||
|
name: config
|
||||||
|
consumer:
|
||||||
|
needs: [other-job]
|
||||||
|
steps:
|
||||||
|
- name: Download config
|
||||||
|
continue-on-error: false
|
||||||
|
uses: christopherhx/gitea-download-artifact@v4
|
||||||
|
with:
|
||||||
|
name: config
|
||||||
|
""").strip()
|
||||||
|
f = tmp_path / "test.yml"
|
||||||
|
f.write_text(workflow_yaml)
|
||||||
|
errors = _check_workflow(f)
|
||||||
|
assert len(errors) == 1
|
||||||
|
assert "consumer" in errors[0]
|
||||||
|
|
||||||
|
def test_job_with_no_steps(self, tmp_path: Path):
|
||||||
|
workflow_yaml = textwrap.dedent("""
|
||||||
|
jobs:
|
||||||
|
empty:
|
||||||
|
runs-on: docker
|
||||||
|
""").strip()
|
||||||
|
f = tmp_path / "test.yml"
|
||||||
|
f.write_text(workflow_yaml)
|
||||||
|
assert _check_workflow(f) == []
|
||||||
|
|
||||||
|
|
||||||
|
class TestMain:
|
||||||
|
def test_passes_when_valid(self, tmp_path: Path):
|
||||||
|
workflow_yaml = textwrap.dedent("""
|
||||||
|
jobs:
|
||||||
|
producer:
|
||||||
|
steps:
|
||||||
|
- uses: christopherhx/gitea-upload-artifact@v4
|
||||||
|
with:
|
||||||
|
name: data
|
||||||
|
consumer:
|
||||||
|
needs: [producer]
|
||||||
|
steps:
|
||||||
|
- uses: christopherhx/gitea-download-artifact@v4
|
||||||
|
with:
|
||||||
|
name: data
|
||||||
|
""").strip()
|
||||||
|
f = tmp_path / "test.yml"
|
||||||
|
f.write_text(workflow_yaml)
|
||||||
|
runner = CliRunner()
|
||||||
|
result = runner.invoke(main, ["--workflows-dir", str(tmp_path)])
|
||||||
|
assert result.exit_code == 0
|
||||||
|
assert "OK" in result.output
|
||||||
|
|
||||||
|
def test_fails_when_missing_dep(self, tmp_path: Path):
|
||||||
|
workflow_yaml = textwrap.dedent("""
|
||||||
|
jobs:
|
||||||
|
producer:
|
||||||
|
steps:
|
||||||
|
- uses: christopherhx/gitea-upload-artifact@v4
|
||||||
|
with:
|
||||||
|
name: data
|
||||||
|
consumer:
|
||||||
|
steps:
|
||||||
|
- uses: christopherhx/gitea-download-artifact@v4
|
||||||
|
with:
|
||||||
|
name: data
|
||||||
|
""").strip()
|
||||||
|
f = tmp_path / "test.yml"
|
||||||
|
f.write_text(workflow_yaml)
|
||||||
|
runner = CliRunner()
|
||||||
|
result = runner.invoke(main, ["--workflows-dir", str(tmp_path)])
|
||||||
|
assert result.exit_code == 1
|
||||||
|
assert "FAIL" in result.output
|
||||||
|
assert "consumer" in result.output
|
||||||
|
|
||||||
|
def test_specific_workflow_file(self, tmp_path: Path):
|
||||||
|
workflow_yaml = textwrap.dedent("""
|
||||||
|
jobs:
|
||||||
|
producer:
|
||||||
|
steps:
|
||||||
|
- uses: christopherhx/gitea-upload-artifact@v4
|
||||||
|
with:
|
||||||
|
name: data
|
||||||
|
consumer:
|
||||||
|
needs: [producer]
|
||||||
|
steps:
|
||||||
|
- uses: christopherhx/gitea-download-artifact@v4
|
||||||
|
with:
|
||||||
|
name: data
|
||||||
|
""").strip()
|
||||||
|
f = tmp_path / "test.yml"
|
||||||
|
f.write_text(workflow_yaml)
|
||||||
|
runner = CliRunner()
|
||||||
|
result = runner.invoke(main, ["--workflow", str(f)])
|
||||||
|
assert result.exit_code == 0
|
||||||
@@ -0,0 +1,356 @@
|
|||||||
|
"""Unit tests for devx.ci.check_workflow_tofu_init."""
|
||||||
|
|
||||||
|
from __future__ import annotations
|
||||||
|
|
||||||
|
import textwrap
|
||||||
|
from pathlib import Path
|
||||||
|
|
||||||
|
from click.testing import CliRunner
|
||||||
|
|
||||||
|
import devx.ci.check_workflow_tofu_init as mod
|
||||||
|
from devx.ci.check_workflow_tofu_init import _check_workflow, main
|
||||||
|
|
||||||
|
|
||||||
|
def _write_workflow(tmp_path: Path, content: str) -> Path:
|
||||||
|
filepath = tmp_path / "test.yml"
|
||||||
|
filepath.write_text(textwrap.dedent(content), encoding="utf-8")
|
||||||
|
return filepath
|
||||||
|
|
||||||
|
|
||||||
|
class TestCheckWorkflow:
|
||||||
|
def test_passes_when_tofu_init_present(self, tmp_path: Path) -> None:
|
||||||
|
filepath = _write_workflow(
|
||||||
|
tmp_path,
|
||||||
|
"""
|
||||||
|
name: Test
|
||||||
|
on: push
|
||||||
|
jobs:
|
||||||
|
deploy:
|
||||||
|
runs-on: docker
|
||||||
|
steps:
|
||||||
|
- run: python3 scripts/create_production_deployment.py --phase tofu-init
|
||||||
|
- run: python3 scripts/preflight_deploy.py --env production
|
||||||
|
""",
|
||||||
|
)
|
||||||
|
assert _check_workflow(filepath, mod.DEFAULT_TOFU_STATE_SCRIPTS) == []
|
||||||
|
|
||||||
|
def test_fails_when_tofu_init_missing(self, tmp_path: Path) -> None:
|
||||||
|
filepath = _write_workflow(
|
||||||
|
tmp_path,
|
||||||
|
"""
|
||||||
|
name: Test
|
||||||
|
on: push
|
||||||
|
jobs:
|
||||||
|
preflight:
|
||||||
|
runs-on: docker
|
||||||
|
steps:
|
||||||
|
- run: python3 scripts/preflight_deploy.py --env production
|
||||||
|
""",
|
||||||
|
)
|
||||||
|
errors = _check_workflow(filepath, mod.DEFAULT_TOFU_STATE_SCRIPTS)
|
||||||
|
assert len(errors) == 1
|
||||||
|
assert "preflight" in errors[0]
|
||||||
|
assert "tofu-init" in errors[0]
|
||||||
|
|
||||||
|
def test_passes_when_direct_tofu_init(self, tmp_path: Path) -> None:
|
||||||
|
filepath = _write_workflow(
|
||||||
|
tmp_path,
|
||||||
|
"""
|
||||||
|
name: Test
|
||||||
|
on: push
|
||||||
|
jobs:
|
||||||
|
deploy:
|
||||||
|
runs-on: docker
|
||||||
|
steps:
|
||||||
|
- run: tofu init
|
||||||
|
- run: tofu output -json
|
||||||
|
""",
|
||||||
|
)
|
||||||
|
assert _check_workflow(filepath, mod.DEFAULT_TOFU_STATE_SCRIPTS) == []
|
||||||
|
|
||||||
|
def test_fails_when_direct_tofu_output_without_init(self, tmp_path: Path) -> None:
|
||||||
|
filepath = _write_workflow(
|
||||||
|
tmp_path,
|
||||||
|
"""
|
||||||
|
name: Test
|
||||||
|
on: push
|
||||||
|
jobs:
|
||||||
|
check:
|
||||||
|
runs-on: docker
|
||||||
|
steps:
|
||||||
|
- run: tofu output -json
|
||||||
|
""",
|
||||||
|
)
|
||||||
|
errors = _check_workflow(filepath, mod.DEFAULT_TOFU_STATE_SCRIPTS)
|
||||||
|
assert len(errors) == 1
|
||||||
|
assert "check" in errors[0]
|
||||||
|
|
||||||
|
def test_passes_when_no_tofu_usage(self, tmp_path: Path) -> None:
|
||||||
|
filepath = _write_workflow(
|
||||||
|
tmp_path,
|
||||||
|
"""
|
||||||
|
name: Test
|
||||||
|
on: push
|
||||||
|
jobs:
|
||||||
|
lint:
|
||||||
|
runs-on: docker
|
||||||
|
steps:
|
||||||
|
- run: make lint
|
||||||
|
""",
|
||||||
|
)
|
||||||
|
assert _check_workflow(filepath, mod.DEFAULT_TOFU_STATE_SCRIPTS) == []
|
||||||
|
|
||||||
|
def test_passes_with_staging_deployment_tofu_init(self, tmp_path: Path) -> None:
|
||||||
|
filepath = _write_workflow(
|
||||||
|
tmp_path,
|
||||||
|
"""
|
||||||
|
name: Test
|
||||||
|
on: push
|
||||||
|
jobs:
|
||||||
|
deploy:
|
||||||
|
runs-on: docker
|
||||||
|
steps:
|
||||||
|
- run: python3 scripts/create_staging_deployment.py --phase tofu-init
|
||||||
|
- run: python3 scripts/create_staging_deployment.py --phase deploy
|
||||||
|
""",
|
||||||
|
)
|
||||||
|
assert _check_workflow(filepath, mod.DEFAULT_TOFU_STATE_SCRIPTS) == []
|
||||||
|
|
||||||
|
def test_fails_with_tofu_plan_without_init(self, tmp_path: Path) -> None:
|
||||||
|
filepath = _write_workflow(
|
||||||
|
tmp_path,
|
||||||
|
"""
|
||||||
|
name: Test
|
||||||
|
on: push
|
||||||
|
jobs:
|
||||||
|
plan:
|
||||||
|
runs-on: docker
|
||||||
|
steps:
|
||||||
|
- run: tofu plan
|
||||||
|
""",
|
||||||
|
)
|
||||||
|
errors = _check_workflow(filepath, mod.DEFAULT_TOFU_STATE_SCRIPTS)
|
||||||
|
assert len(errors) == 1
|
||||||
|
assert "plan" in errors[0]
|
||||||
|
|
||||||
|
def test_fails_with_tofu_apply_without_init(self, tmp_path: Path) -> None:
|
||||||
|
filepath = _write_workflow(
|
||||||
|
tmp_path,
|
||||||
|
"""
|
||||||
|
name: Test
|
||||||
|
on: push
|
||||||
|
jobs:
|
||||||
|
apply:
|
||||||
|
runs-on: docker
|
||||||
|
steps:
|
||||||
|
- run: tofu apply -auto-approve
|
||||||
|
""",
|
||||||
|
)
|
||||||
|
errors = _check_workflow(filepath, mod.DEFAULT_TOFU_STATE_SCRIPTS)
|
||||||
|
assert len(errors) == 1
|
||||||
|
assert "apply" in errors[0]
|
||||||
|
|
||||||
|
def test_multiple_jobs_one_missing(self, tmp_path: Path) -> None:
|
||||||
|
filepath = _write_workflow(
|
||||||
|
tmp_path,
|
||||||
|
"""
|
||||||
|
name: Test
|
||||||
|
on: push
|
||||||
|
jobs:
|
||||||
|
good:
|
||||||
|
runs-on: docker
|
||||||
|
steps:
|
||||||
|
- run: python3 scripts/create_production_deployment.py --phase tofu-init
|
||||||
|
- run: python3 scripts/preflight_deploy.py --env production
|
||||||
|
bad:
|
||||||
|
runs-on: docker
|
||||||
|
steps:
|
||||||
|
- run: python3 scripts/preflight_deploy.py --env production
|
||||||
|
""",
|
||||||
|
)
|
||||||
|
errors = _check_workflow(filepath, mod.DEFAULT_TOFU_STATE_SCRIPTS)
|
||||||
|
assert len(errors) == 1
|
||||||
|
assert "bad" in errors[0]
|
||||||
|
|
||||||
|
def test_no_steps_passes(self, tmp_path: Path) -> None:
|
||||||
|
filepath = _write_workflow(
|
||||||
|
tmp_path,
|
||||||
|
"""
|
||||||
|
name: Test
|
||||||
|
on: push
|
||||||
|
jobs:
|
||||||
|
empty:
|
||||||
|
runs-on: docker
|
||||||
|
""",
|
||||||
|
)
|
||||||
|
assert _check_workflow(filepath, mod.DEFAULT_TOFU_STATE_SCRIPTS) == []
|
||||||
|
|
||||||
|
def test_destroy_orphans_does_not_require_init(self, tmp_path: Path) -> None:
|
||||||
|
filepath = _write_workflow(
|
||||||
|
tmp_path,
|
||||||
|
"""
|
||||||
|
name: Test
|
||||||
|
on: push
|
||||||
|
jobs:
|
||||||
|
cleanup:
|
||||||
|
runs-on: docker
|
||||||
|
steps:
|
||||||
|
- run: python3 scripts/destroy_orphans.py
|
||||||
|
""",
|
||||||
|
)
|
||||||
|
assert _check_workflow(filepath, mod.DEFAULT_TOFU_STATE_SCRIPTS) == []
|
||||||
|
|
||||||
|
def test_invalid_yaml_returns_error(self, tmp_path: Path) -> None:
|
||||||
|
filepath = tmp_path / "bad.yml"
|
||||||
|
filepath.write_text("jobs: [invalid yaml: {", encoding="utf-8")
|
||||||
|
errors = _check_workflow(filepath, mod.DEFAULT_TOFU_STATE_SCRIPTS)
|
||||||
|
assert len(errors) == 1
|
||||||
|
assert "cannot parse YAML" in errors[0]
|
||||||
|
|
||||||
|
def test_tofu_show_requires_init(self, tmp_path: Path) -> None:
|
||||||
|
filepath = _write_workflow(
|
||||||
|
tmp_path,
|
||||||
|
"""
|
||||||
|
name: Test
|
||||||
|
on: push
|
||||||
|
jobs:
|
||||||
|
show:
|
||||||
|
runs-on: docker
|
||||||
|
steps:
|
||||||
|
- run: tofu show -json
|
||||||
|
""",
|
||||||
|
)
|
||||||
|
errors = _check_workflow(filepath, mod.DEFAULT_TOFU_STATE_SCRIPTS)
|
||||||
|
assert len(errors) == 1
|
||||||
|
assert "show" in errors[0]
|
||||||
|
|
||||||
|
def test_custom_state_scripts(self, tmp_path: Path) -> None:
|
||||||
|
filepath = _write_workflow(
|
||||||
|
tmp_path,
|
||||||
|
"""
|
||||||
|
name: Test
|
||||||
|
on: push
|
||||||
|
jobs:
|
||||||
|
custom:
|
||||||
|
runs-on: docker
|
||||||
|
steps:
|
||||||
|
- run: python3 scripts/my_custom_script.py
|
||||||
|
""",
|
||||||
|
)
|
||||||
|
errors = _check_workflow(filepath, {"my_custom_script.py"})
|
||||||
|
assert len(errors) == 1
|
||||||
|
assert "custom" in errors[0]
|
||||||
|
|
||||||
|
def test_step_with_no_run_skipped(self, tmp_path: Path) -> None:
|
||||||
|
"""A step with no 'run' key should be skipped (line 80 continue)."""
|
||||||
|
filepath = _write_workflow(
|
||||||
|
tmp_path,
|
||||||
|
"""
|
||||||
|
name: Test
|
||||||
|
on: push
|
||||||
|
jobs:
|
||||||
|
deploy:
|
||||||
|
runs-on: docker
|
||||||
|
steps:
|
||||||
|
- name: Checkout
|
||||||
|
uses: actions/checkout@v4
|
||||||
|
- run: tofu init
|
||||||
|
- run: tofu output
|
||||||
|
""",
|
||||||
|
)
|
||||||
|
assert _check_workflow(filepath, mod.DEFAULT_TOFU_STATE_SCRIPTS) == []
|
||||||
|
|
||||||
|
|
||||||
|
class TestCli:
|
||||||
|
def test_passes_with_specific_workflow(self, tmp_path: Path) -> None:
|
||||||
|
filepath = _write_workflow(
|
||||||
|
tmp_path,
|
||||||
|
"""
|
||||||
|
name: Test
|
||||||
|
on: push
|
||||||
|
jobs:
|
||||||
|
deploy:
|
||||||
|
runs-on: docker
|
||||||
|
steps:
|
||||||
|
- run: tofu init
|
||||||
|
- run: tofu output
|
||||||
|
""",
|
||||||
|
)
|
||||||
|
runner = CliRunner()
|
||||||
|
result = runner.invoke(main, ["--workflow", str(filepath)])
|
||||||
|
assert result.exit_code == 0
|
||||||
|
assert "OK" in result.output
|
||||||
|
|
||||||
|
def test_fails_with_missing_tofu_init(self, tmp_path: Path) -> None:
|
||||||
|
filepath = _write_workflow(
|
||||||
|
tmp_path,
|
||||||
|
"""
|
||||||
|
name: Test
|
||||||
|
on: push
|
||||||
|
jobs:
|
||||||
|
preflight:
|
||||||
|
runs-on: docker
|
||||||
|
steps:
|
||||||
|
- run: python3 scripts/preflight_deploy.py --env production
|
||||||
|
""",
|
||||||
|
)
|
||||||
|
runner = CliRunner()
|
||||||
|
result = runner.invoke(main, ["--workflow", str(filepath)])
|
||||||
|
assert result.exit_code == 1
|
||||||
|
assert "FAIL" in result.output
|
||||||
|
assert "preflight" in result.output
|
||||||
|
|
||||||
|
def test_checks_all_workflows_by_default(self, tmp_path: Path) -> None:
|
||||||
|
workflows_dir = tmp_path / "workflows"
|
||||||
|
workflows_dir.mkdir()
|
||||||
|
(workflows_dir / "good.yml").write_text(
|
||||||
|
textwrap.dedent("""
|
||||||
|
name: Good
|
||||||
|
on: push
|
||||||
|
jobs:
|
||||||
|
deploy:
|
||||||
|
runs-on: docker
|
||||||
|
steps:
|
||||||
|
- run: tofu init
|
||||||
|
- run: tofu output
|
||||||
|
"""),
|
||||||
|
encoding="utf-8",
|
||||||
|
)
|
||||||
|
(workflows_dir / "bad.yml").write_text(
|
||||||
|
textwrap.dedent("""
|
||||||
|
name: Bad
|
||||||
|
on: push
|
||||||
|
jobs:
|
||||||
|
check:
|
||||||
|
runs-on: docker
|
||||||
|
steps:
|
||||||
|
- run: tofu output
|
||||||
|
"""),
|
||||||
|
encoding="utf-8",
|
||||||
|
)
|
||||||
|
runner = CliRunner()
|
||||||
|
result = runner.invoke(main, ["--workflows-dir", str(workflows_dir)])
|
||||||
|
assert result.exit_code == 1
|
||||||
|
assert "bad.yml" in result.output
|
||||||
|
assert "check" in result.output
|
||||||
|
|
||||||
|
def test_all_workflows_pass(self, tmp_path: Path) -> None:
|
||||||
|
workflows_dir = tmp_path / "workflows"
|
||||||
|
workflows_dir.mkdir()
|
||||||
|
(workflows_dir / "ok.yml").write_text(
|
||||||
|
textwrap.dedent("""
|
||||||
|
name: OK
|
||||||
|
on: push
|
||||||
|
jobs:
|
||||||
|
deploy:
|
||||||
|
runs-on: docker
|
||||||
|
steps:
|
||||||
|
- run: tofu init
|
||||||
|
- run: tofu plan
|
||||||
|
"""),
|
||||||
|
encoding="utf-8",
|
||||||
|
)
|
||||||
|
runner = CliRunner()
|
||||||
|
result = runner.invoke(main, ["--workflows-dir", str(workflows_dir)])
|
||||||
|
assert result.exit_code == 0
|
||||||
|
assert "OK" in result.output
|
||||||
@@ -481,8 +481,9 @@ class TestRunGit:
|
|||||||
|
|
||||||
|
|
||||||
class TestMain:
|
class TestMain:
|
||||||
|
@patch("devx.ci.classify_changes.get_changed_files", return_value=[])
|
||||||
@patch("devx.ci.classify_changes.get_latest_tag", return_value="")
|
@patch("devx.ci.classify_changes.get_latest_tag", return_value="")
|
||||||
def test_no_tags_outputs_true(self, mock_tag: MagicMock) -> None:
|
def test_no_tags_outputs_true(self, mock_tag: MagicMock, mock_changes: MagicMock) -> None:
|
||||||
runner = CliRunner()
|
runner = CliRunner()
|
||||||
result = runner.invoke(main, ["--quiet"])
|
result = runner.invoke(main, ["--quiet"])
|
||||||
assert result.exit_code == 0
|
assert result.exit_code == 0
|
||||||
@@ -555,8 +556,9 @@ class TestMain:
|
|||||||
# docs tag has no matching files — should not appear
|
# docs tag has no matching files — should not appear
|
||||||
assert "Docs files" not in result.output
|
assert "Docs files" not in result.output
|
||||||
|
|
||||||
|
@patch("devx.ci.classify_changes.get_changed_files", return_value=[])
|
||||||
@patch("devx.ci.classify_changes.get_latest_tag", return_value="")
|
@patch("devx.ci.classify_changes.get_latest_tag", return_value="")
|
||||||
def test_no_tags_non_quiet(self, mock_tag: MagicMock) -> None:
|
def test_no_tags_non_quiet(self, mock_tag: MagicMock, mock_changes: MagicMock) -> None:
|
||||||
runner = CliRunner()
|
runner = CliRunner()
|
||||||
result = runner.invoke(main, [])
|
result = runner.invoke(main, [])
|
||||||
assert result.exit_code == 0
|
assert result.exit_code == 0
|
||||||
@@ -731,7 +733,10 @@ class TestGithubOutput:
|
|||||||
mock_clf.return_value = self._make_classifier_with_ansible()
|
mock_clf.return_value = self._make_classifier_with_ansible()
|
||||||
gh_file = tmp_path / "output.txt"
|
gh_file = tmp_path / "output.txt"
|
||||||
monkeypatch.setenv("GITHUB_OUTPUT", str(gh_file))
|
monkeypatch.setenv("GITHUB_OUTPUT", str(gh_file))
|
||||||
with patch.object(classify_changes_mod, "get_latest_tag", return_value=""):
|
with (
|
||||||
|
patch.object(classify_changes_mod, "get_latest_tag", return_value=""),
|
||||||
|
patch.object(classify_changes_mod, "get_changed_files", return_value=["src/cli.py"]),
|
||||||
|
):
|
||||||
runner = CliRunner()
|
runner = CliRunner()
|
||||||
result = runner.invoke(main, ["--github-output"])
|
result = runner.invoke(main, ["--github-output"])
|
||||||
assert result.exit_code == 0
|
assert result.exit_code == 0
|
||||||
@@ -774,7 +779,10 @@ class TestGithubOutput:
|
|||||||
)
|
)
|
||||||
gh_file = tmp_path / "output.txt"
|
gh_file = tmp_path / "output.txt"
|
||||||
monkeypatch.setenv("GITHUB_OUTPUT", str(gh_file))
|
monkeypatch.setenv("GITHUB_OUTPUT", str(gh_file))
|
||||||
with patch.object(classify_changes_mod, "get_latest_tag", return_value=""):
|
with (
|
||||||
|
patch.object(classify_changes_mod, "get_latest_tag", return_value=""),
|
||||||
|
patch.object(classify_changes_mod, "get_changed_files", return_value=["src/cli.py"]),
|
||||||
|
):
|
||||||
runner = CliRunner()
|
runner = CliRunner()
|
||||||
result = runner.invoke(main, ["--github-output"])
|
result = runner.invoke(main, ["--github-output"])
|
||||||
assert result.exit_code == 0
|
assert result.exit_code == 0
|
||||||
@@ -789,8 +797,9 @@ class TestGithubOutput:
|
|||||||
mock_clf.return_value = self._make_classifier_with_ansible()
|
mock_clf.return_value = self._make_classifier_with_ansible()
|
||||||
gh_file = tmp_path / "output.txt"
|
gh_file = tmp_path / "output.txt"
|
||||||
monkeypatch.setenv("GITHUB_OUTPUT", str(gh_file))
|
monkeypatch.setenv("GITHUB_OUTPUT", str(gh_file))
|
||||||
runner = CliRunner()
|
with patch.object(classify_changes_mod, "get_changed_files", return_value=["src/cli.py"]):
|
||||||
result = runner.invoke(main, ["--github-output", "--force"])
|
runner = CliRunner()
|
||||||
|
result = runner.invoke(main, ["--github-output", "--force"])
|
||||||
assert result.exit_code == 0
|
assert result.exit_code == 0
|
||||||
content = gh_file.read_text()
|
content = gh_file.read_text()
|
||||||
assert "user-facing-changed=true" in content
|
assert "user-facing-changed=true" in content
|
||||||
@@ -822,8 +831,9 @@ class TestGithubOutput:
|
|||||||
)
|
)
|
||||||
gh_file = tmp_path / "output.txt"
|
gh_file = tmp_path / "output.txt"
|
||||||
monkeypatch.setenv("GITHUB_OUTPUT", str(gh_file))
|
monkeypatch.setenv("GITHUB_OUTPUT", str(gh_file))
|
||||||
runner = CliRunner()
|
with patch.object(classify_changes_mod, "get_changed_files", return_value=["src/cli.py"]):
|
||||||
result = runner.invoke(main, ["--github-output", "--force"])
|
runner = CliRunner()
|
||||||
|
result = runner.invoke(main, ["--github-output", "--force"])
|
||||||
assert result.exit_code == 0
|
assert result.exit_code == 0
|
||||||
content = gh_file.read_text()
|
content = gh_file.read_text()
|
||||||
assert "user-facing-changed=true" in content
|
assert "user-facing-changed=true" in content
|
||||||
@@ -836,8 +846,9 @@ class TestGithubOutput:
|
|||||||
gh_file = tmp_path / "output.txt"
|
gh_file = tmp_path / "output.txt"
|
||||||
monkeypatch.setenv("GITHUB_OUTPUT", str(gh_file))
|
monkeypatch.setenv("GITHUB_OUTPUT", str(gh_file))
|
||||||
monkeypatch.setenv("FORCE_DEPLOY", "true")
|
monkeypatch.setenv("FORCE_DEPLOY", "true")
|
||||||
runner = CliRunner()
|
with patch.object(classify_changes_mod, "get_changed_files", return_value=["src/cli.py"]):
|
||||||
result = runner.invoke(main, ["--github-output"])
|
runner = CliRunner()
|
||||||
|
result = runner.invoke(main, ["--github-output"])
|
||||||
assert result.exit_code == 0
|
assert result.exit_code == 0
|
||||||
content = gh_file.read_text()
|
content = gh_file.read_text()
|
||||||
assert "user-facing-changed=true" in content
|
assert "user-facing-changed=true" in content
|
||||||
@@ -869,8 +880,9 @@ class TestGithubOutput:
|
|||||||
gh_file = tmp_path / "output.txt"
|
gh_file = tmp_path / "output.txt"
|
||||||
monkeypatch.setenv("GITHUB_OUTPUT", str(gh_file))
|
monkeypatch.setenv("GITHUB_OUTPUT", str(gh_file))
|
||||||
monkeypatch.setenv("FORCE_DEPLOY", "false")
|
monkeypatch.setenv("FORCE_DEPLOY", "false")
|
||||||
runner = CliRunner()
|
with patch.object(classify_changes_mod, "get_changed_files", return_value=["src/cli.py"]):
|
||||||
result = runner.invoke(main, ["--github-output", "--force"])
|
runner = CliRunner()
|
||||||
|
result = runner.invoke(main, ["--github-output", "--force"])
|
||||||
assert result.exit_code == 0
|
assert result.exit_code == 0
|
||||||
content = gh_file.read_text()
|
content = gh_file.read_text()
|
||||||
assert "user-facing-changed=true" in content
|
assert "user-facing-changed=true" in content
|
||||||
|
|||||||
@@ -144,19 +144,21 @@ class TestCli:
|
|||||||
assert result.exit_code == 0
|
assert result.exit_code == 0
|
||||||
mock_create.assert_called_once_with("DEVX-42-fix", "master", "", "owner", "repo")
|
mock_create.assert_called_once_with("DEVX-42-fix", "master", "", "owner", "repo")
|
||||||
|
|
||||||
|
@patch("devx.tools.create_pr.subprocess.run")
|
||||||
@patch("devx.tools.create_pr.create_pr")
|
@patch("devx.tools.create_pr.create_pr")
|
||||||
@patch("devx.tools.create_pr.REPO_OWNER", "owner")
|
@patch("devx.tools.create_pr.REPO_OWNER", "owner")
|
||||||
@patch("devx.tools.create_pr.get_repo_name", return_value="repo")
|
@patch("devx.tools.create_pr.get_repo_name", return_value="repo")
|
||||||
def test_explicit_branch(self, mock_repo: MagicMock, mock_create: MagicMock) -> None:
|
def test_explicit_branch(self, mock_repo: MagicMock, mock_create: MagicMock, mock_subproc: MagicMock) -> None:
|
||||||
mock_create.return_value = {"number": 1}
|
mock_create.return_value = {"number": 1}
|
||||||
runner = CliRunner()
|
runner = CliRunner()
|
||||||
result = runner.invoke(cli, ["--branch", "DEVX-42-fix"])
|
result = runner.invoke(cli, ["--branch", "DEVX-42-fix"])
|
||||||
assert result.exit_code == 0
|
assert result.exit_code == 0
|
||||||
|
|
||||||
|
@patch("devx.tools.create_pr.subprocess.run")
|
||||||
@patch("devx.tools.create_pr.create_pr")
|
@patch("devx.tools.create_pr.create_pr")
|
||||||
@patch("devx.tools.create_pr.REPO_OWNER", "owner")
|
@patch("devx.tools.create_pr.REPO_OWNER", "owner")
|
||||||
@patch("devx.tools.create_pr.get_repo_name", return_value="repo")
|
@patch("devx.tools.create_pr.get_repo_name", return_value="repo")
|
||||||
def test_body_from_stdin(self, mock_repo: MagicMock, mock_create: MagicMock) -> None:
|
def test_body_from_stdin(self, mock_repo: MagicMock, mock_create: MagicMock, mock_subproc: MagicMock) -> None:
|
||||||
mock_create.return_value = {"number": 1}
|
mock_create.return_value = {"number": 1}
|
||||||
runner = CliRunner()
|
runner = CliRunner()
|
||||||
result = runner.invoke(cli, ["--branch", "DEVX-42-fix", "--body", "-"], input="PR body text")
|
result = runner.invoke(cli, ["--branch", "DEVX-42-fix", "--body", "-"], input="PR body text")
|
||||||
@@ -164,17 +166,19 @@ class TestCli:
|
|||||||
mock_create.assert_called_once()
|
mock_create.assert_called_once()
|
||||||
assert mock_create.call_args.args[2] == "PR body text"
|
assert mock_create.call_args.args[2] == "PR body text"
|
||||||
|
|
||||||
|
@patch("devx.tools.create_pr.subprocess.run")
|
||||||
@patch("devx.tools.create_pr.REPO_OWNER", "")
|
@patch("devx.tools.create_pr.REPO_OWNER", "")
|
||||||
@patch("devx.tools.create_pr.get_repo_name", return_value="repo")
|
@patch("devx.tools.create_pr.get_repo_name", return_value="repo")
|
||||||
def test_missing_owner(self, mock_repo: MagicMock) -> None:
|
def test_missing_owner(self, mock_repo: MagicMock, mock_subproc: MagicMock) -> None:
|
||||||
runner = CliRunner()
|
runner = CliRunner()
|
||||||
result = runner.invoke(cli, ["--branch", "DEVX-42-fix"])
|
result = runner.invoke(cli, ["--branch", "DEVX-42-fix"])
|
||||||
assert result.exit_code != 0
|
assert result.exit_code != 0
|
||||||
assert "owner" in result.output.lower()
|
assert "owner" in result.output.lower()
|
||||||
|
|
||||||
|
@patch("devx.tools.create_pr.subprocess.run")
|
||||||
@patch("devx.tools.create_pr.create_pr")
|
@patch("devx.tools.create_pr.create_pr")
|
||||||
@patch("devx.tools.create_pr.get_repo_name", return_value="repo")
|
@patch("devx.tools.create_pr.get_repo_name", return_value="repo")
|
||||||
def test_explicit_owner(self, mock_repo: MagicMock, mock_create: MagicMock) -> None:
|
def test_explicit_owner(self, mock_repo: MagicMock, mock_create: MagicMock, mock_subproc: MagicMock) -> None:
|
||||||
mock_create.return_value = {"number": 1}
|
mock_create.return_value = {"number": 1}
|
||||||
runner = CliRunner()
|
runner = CliRunner()
|
||||||
result = runner.invoke(cli, ["--branch", "DEVX-42-fix", "--owner", "custom"])
|
result = runner.invoke(cli, ["--branch", "DEVX-42-fix", "--owner", "custom"])
|
||||||
|
|||||||
@@ -311,6 +311,61 @@ class TestDiscoverMultiRole:
|
|||||||
with pytest.raises(click.ClickException):
|
with pytest.raises(click.ClickException):
|
||||||
discover_multi_role_scenarios()
|
discover_multi_role_scenarios()
|
||||||
|
|
||||||
|
def test_include_roles_filters_to_subset(self, tmp_path: Path) -> None:
|
||||||
|
roles = tmp_path / "roles"
|
||||||
|
for scenario in ["default"]:
|
||||||
|
(roles / "docker_base" / "molecule" / scenario).mkdir(parents=True)
|
||||||
|
(roles / "crowdsec" / "molecule" / scenario).mkdir(parents=True)
|
||||||
|
(roles / "app_container" / "molecule" / scenario).mkdir(parents=True)
|
||||||
|
result = discover_multi_role_scenarios(roles, include_roles=["docker_base", "crowdsec"])
|
||||||
|
assert ("docker_base", "default") in result
|
||||||
|
assert ("crowdsec", "default") in result
|
||||||
|
assert ("app_container", "default") not in result
|
||||||
|
assert len(result) == 2
|
||||||
|
|
||||||
|
def test_include_roles_case_insensitive(self, tmp_path: Path) -> None:
|
||||||
|
roles = tmp_path / "roles"
|
||||||
|
(roles / "Docker_Base" / "molecule" / "default").mkdir(parents=True)
|
||||||
|
(roles / "other" / "molecule" / "default").mkdir(parents=True)
|
||||||
|
result = discover_multi_role_scenarios(roles, include_roles=["docker_base"])
|
||||||
|
assert ("Docker_Base", "default") in result
|
||||||
|
assert len(result) == 1
|
||||||
|
|
||||||
|
def test_exclude_roles_skips_subset(self, tmp_path: Path) -> None:
|
||||||
|
roles = tmp_path / "roles"
|
||||||
|
for scenario in ["default"]:
|
||||||
|
(roles / "docker_base" / "molecule" / scenario).mkdir(parents=True)
|
||||||
|
(roles / "crowdsec" / "molecule" / scenario).mkdir(parents=True)
|
||||||
|
(roles / "app_container" / "molecule" / scenario).mkdir(parents=True)
|
||||||
|
result = discover_multi_role_scenarios(roles, exclude_roles=["docker_base", "crowdsec"])
|
||||||
|
assert ("docker_base", "default") not in result
|
||||||
|
assert ("crowdsec", "default") not in result
|
||||||
|
assert ("app_container", "default") in result
|
||||||
|
assert len(result) == 1
|
||||||
|
|
||||||
|
def test_exclude_roles_case_insensitive(self, tmp_path: Path) -> None:
|
||||||
|
roles = tmp_path / "roles"
|
||||||
|
(roles / "Docker_Base" / "molecule" / "default").mkdir(parents=True)
|
||||||
|
(roles / "other" / "molecule" / "default").mkdir(parents=True)
|
||||||
|
result = discover_multi_role_scenarios(roles, exclude_roles=["docker_base"])
|
||||||
|
assert ("Docker_Base", "default") not in result
|
||||||
|
assert ("other", "default") in result
|
||||||
|
assert len(result) == 1
|
||||||
|
|
||||||
|
def test_include_and_exclude_combined(self, tmp_path: Path) -> None:
|
||||||
|
roles = tmp_path / "roles"
|
||||||
|
for scenario in ["default"]:
|
||||||
|
(roles / "docker_base" / "molecule" / scenario).mkdir(parents=True)
|
||||||
|
(roles / "crowdsec" / "molecule" / scenario).mkdir(parents=True)
|
||||||
|
(roles / "app_container" / "molecule" / scenario).mkdir(parents=True)
|
||||||
|
result = discover_multi_role_scenarios(
|
||||||
|
roles, include_roles=["docker_base", "crowdsec", "app_container"], exclude_roles=["crowdsec"]
|
||||||
|
)
|
||||||
|
assert ("docker_base", "default") in result
|
||||||
|
assert ("crowdsec", "default") not in result
|
||||||
|
assert ("app_container", "default") in result
|
||||||
|
assert len(result) == 2
|
||||||
|
|
||||||
def test_default_roles_root_constant(self) -> None:
|
def test_default_roles_root_constant(self) -> None:
|
||||||
assert Path("ansible/roles") == DEFAULT_ROLES_ROOT
|
assert Path("ansible/roles") == DEFAULT_ROLES_ROOT
|
||||||
|
|
||||||
|
|||||||
@@ -90,8 +90,9 @@ class TestCli:
|
|||||||
assert result.exit_code == 0
|
assert result.exit_code == 0
|
||||||
mock_login.assert_called_once_with("reg.io", "emil", "tok", suppress_failure=False)
|
mock_login.assert_called_once_with("reg.io", "emil", "tok", suppress_failure=False)
|
||||||
|
|
||||||
|
@patch("devx.tools.docker_login.docker_login")
|
||||||
@patch.dict("os.environ", {}, clear=True)
|
@patch.dict("os.environ", {}, clear=True)
|
||||||
def test_required_no_token_raises(self) -> None:
|
def test_required_no_token_raises(self, mock_login: MagicMock) -> None:
|
||||||
runner = CliRunner()
|
runner = CliRunner()
|
||||||
result = runner.invoke(
|
result = runner.invoke(
|
||||||
cli,
|
cli,
|
||||||
@@ -99,8 +100,9 @@ class TestCli:
|
|||||||
)
|
)
|
||||||
assert result.exit_code != 0
|
assert result.exit_code != 0
|
||||||
|
|
||||||
|
@patch("devx.tools.docker_login.docker_login")
|
||||||
@patch.dict("os.environ", {}, clear=True)
|
@patch.dict("os.environ", {}, clear=True)
|
||||||
def test_optional_no_token_skips(self) -> None:
|
def test_optional_no_token_skips(self, mock_login: MagicMock) -> None:
|
||||||
runner = CliRunner()
|
runner = CliRunner()
|
||||||
result = runner.invoke(
|
result = runner.invoke(
|
||||||
cli,
|
cli,
|
||||||
|
|||||||
@@ -0,0 +1,195 @@
|
|||||||
|
"""Tests for devx.ci.fix_pr_title."""
|
||||||
|
|
||||||
|
from __future__ import annotations
|
||||||
|
|
||||||
|
from unittest.mock import MagicMock, patch
|
||||||
|
|
||||||
|
import pytest
|
||||||
|
from click.testing import CliRunner
|
||||||
|
|
||||||
|
from devx.ci.fix_pr_title import cli
|
||||||
|
|
||||||
|
|
||||||
|
@pytest.fixture(autouse=True)
|
||||||
|
def _obl_infra_prefix(monkeypatch: pytest.MonkeyPatch) -> None:
|
||||||
|
"""Use OBL-INFRA prefix to match infra repo conventions."""
|
||||||
|
import re
|
||||||
|
|
||||||
|
monkeypatch.setattr("devx.ci.fix_pr_title.TASK_PREFIX", "OBL-INFRA")
|
||||||
|
monkeypatch.setattr("devx.ci.auto_merge.TASK_PREFIX", "OBL-INFRA")
|
||||||
|
monkeypatch.setattr("devx.ci.auto_merge.PR_TITLE_RE", re.compile(r"^OBL-INFRA-\d+:\s+.+"))
|
||||||
|
monkeypatch.setattr("devx.ci.auto_merge._TASK_ID_PREFIX_RE", re.compile(r"^OBL-INFRA-\d+:\s*"))
|
||||||
|
monkeypatch.setattr("devx.ci._shared.TASK_ID_RE", re.compile(r"OBL-INFRA-\d+"))
|
||||||
|
|
||||||
|
|
||||||
|
class TestFixPrTitle:
|
||||||
|
@patch("devx.ci.fix_pr_title.get_ci_token")
|
||||||
|
@patch("devx.ci.fix_pr_title.GiteaClient")
|
||||||
|
@patch("devx.ci.fix_pr_title.get_vikunja_title_optional")
|
||||||
|
def test_fixes_title_with_vikunja(
|
||||||
|
self,
|
||||||
|
mock_vikunja: MagicMock,
|
||||||
|
mock_gitea_cls: MagicMock,
|
||||||
|
mock_ci_token: MagicMock,
|
||||||
|
) -> None:
|
||||||
|
"""PR title is updated to match task ID + Vikunja title."""
|
||||||
|
mock_client = MagicMock()
|
||||||
|
mock_gitea_cls.return_value = mock_client
|
||||||
|
mock_client.get_pr.return_value = {
|
||||||
|
"number": 42,
|
||||||
|
"title": "Fix blackbox exporter",
|
||||||
|
"head": {"ref": "OBL-INFRA-458-blackbox-ipv4"},
|
||||||
|
}
|
||||||
|
mock_vikunja.return_value = "Fix blackbox exporter IPv4 config"
|
||||||
|
mock_ci_token.return_value = "token"
|
||||||
|
|
||||||
|
runner = CliRunner()
|
||||||
|
result = runner.invoke(cli, ["--repo", "oblachno/infra", "--pr-number", "42"])
|
||||||
|
|
||||||
|
assert result.exit_code == 0
|
||||||
|
mock_client.update_pr.assert_called_once_with(42, {"title": "OBL-INFRA-458: Fix blackbox exporter IPv4 config"})
|
||||||
|
|
||||||
|
@patch("devx.ci.fix_pr_title.get_ci_token")
|
||||||
|
@patch("devx.ci.fix_pr_title.GiteaClient")
|
||||||
|
@patch("devx.ci.fix_pr_title.get_vikunja_title_optional")
|
||||||
|
def test_strips_conventional_commit_prefix_when_no_vikunja(
|
||||||
|
self,
|
||||||
|
mock_vikunja: MagicMock,
|
||||||
|
mock_gitea_cls: MagicMock,
|
||||||
|
mock_ci_token: MagicMock,
|
||||||
|
) -> None:
|
||||||
|
"""When Vikunja task not found, strips conventional-commit prefix from current title."""
|
||||||
|
mock_client = MagicMock()
|
||||||
|
mock_gitea_cls.return_value = mock_client
|
||||||
|
mock_client.get_pr.return_value = {
|
||||||
|
"number": 10,
|
||||||
|
"title": "fix: platform self-monitoring and fixes",
|
||||||
|
"head": {"ref": "OBL-INFRA-456-platform-fixes"},
|
||||||
|
}
|
||||||
|
mock_vikunja.return_value = None
|
||||||
|
mock_ci_token.return_value = "token"
|
||||||
|
|
||||||
|
runner = CliRunner()
|
||||||
|
result = runner.invoke(cli, ["--repo", "oblachno/infra", "--pr-number", "10"])
|
||||||
|
|
||||||
|
assert result.exit_code == 0
|
||||||
|
mock_client.update_pr.assert_called_once_with(
|
||||||
|
10, {"title": "OBL-INFRA-456: platform self-monitoring and fixes"}
|
||||||
|
)
|
||||||
|
|
||||||
|
@patch("devx.ci.fix_pr_title.get_ci_token")
|
||||||
|
@patch("devx.ci.fix_pr_title.GiteaClient")
|
||||||
|
@patch("devx.ci.fix_pr_title.get_vikunja_title_optional")
|
||||||
|
def test_already_correct_title_no_update(
|
||||||
|
self,
|
||||||
|
mock_vikunja: MagicMock,
|
||||||
|
mock_gitea_cls: MagicMock,
|
||||||
|
mock_ci_token: MagicMock,
|
||||||
|
) -> None:
|
||||||
|
"""When PR title is already correct, no update is made."""
|
||||||
|
mock_client = MagicMock()
|
||||||
|
mock_gitea_cls.return_value = mock_client
|
||||||
|
mock_client.get_pr.return_value = {
|
||||||
|
"number": 5,
|
||||||
|
"title": "OBL-INFRA-100: Fix bug",
|
||||||
|
"head": {"ref": "OBL-INFRA-100-fix-bug"},
|
||||||
|
}
|
||||||
|
mock_vikunja.return_value = "Fix bug"
|
||||||
|
mock_ci_token.return_value = "token"
|
||||||
|
|
||||||
|
runner = CliRunner()
|
||||||
|
result = runner.invoke(cli, ["--repo", "oblachno/infra", "--pr-number", "5"])
|
||||||
|
|
||||||
|
assert result.exit_code == 0
|
||||||
|
mock_client.update_pr.assert_not_called()
|
||||||
|
|
||||||
|
@patch("devx.ci.fix_pr_title.get_ci_token")
|
||||||
|
@patch("devx.ci.fix_pr_title.GiteaClient")
|
||||||
|
@patch("devx.ci.fix_pr_title.get_vikunja_title_optional")
|
||||||
|
def test_dry_run_no_update(
|
||||||
|
self,
|
||||||
|
mock_vikunja: MagicMock,
|
||||||
|
mock_gitea_cls: MagicMock,
|
||||||
|
mock_ci_token: MagicMock,
|
||||||
|
) -> None:
|
||||||
|
"""Dry run shows what would change without updating."""
|
||||||
|
mock_client = MagicMock()
|
||||||
|
mock_gitea_cls.return_value = mock_client
|
||||||
|
mock_client.get_pr.return_value = {
|
||||||
|
"number": 7,
|
||||||
|
"title": "Fix thing",
|
||||||
|
"head": {"ref": "OBL-INFRA-7-fix-thing"},
|
||||||
|
}
|
||||||
|
mock_vikunja.return_value = "Fix thing"
|
||||||
|
mock_ci_token.return_value = "token"
|
||||||
|
|
||||||
|
runner = CliRunner()
|
||||||
|
result = runner.invoke(cli, ["--repo", "oblachno/infra", "--pr-number", "7", "--dry-run"])
|
||||||
|
|
||||||
|
assert result.exit_code == 0
|
||||||
|
mock_client.update_pr.assert_not_called()
|
||||||
|
|
||||||
|
@patch("devx.ci.fix_pr_title.get_ci_token")
|
||||||
|
@patch("devx.ci.fix_pr_title.GiteaClient")
|
||||||
|
def test_no_task_id_in_branch_exits_error(
|
||||||
|
self,
|
||||||
|
mock_gitea_cls: MagicMock,
|
||||||
|
mock_ci_token: MagicMock,
|
||||||
|
) -> None:
|
||||||
|
"""When branch has no task ID, exits with error."""
|
||||||
|
mock_client = MagicMock()
|
||||||
|
mock_gitea_cls.return_value = mock_client
|
||||||
|
mock_client.get_pr.return_value = {
|
||||||
|
"number": 1,
|
||||||
|
"title": "Some title",
|
||||||
|
"head": {"ref": "just-a-branch"},
|
||||||
|
}
|
||||||
|
mock_ci_token.return_value = "token"
|
||||||
|
|
||||||
|
runner = CliRunner()
|
||||||
|
result = runner.invoke(cli, ["--repo", "oblachno/infra", "--pr-number", "1"])
|
||||||
|
|
||||||
|
assert result.exit_code != 0
|
||||||
|
mock_client.update_pr.assert_not_called()
|
||||||
|
|
||||||
|
@patch("devx.ci.fix_pr_title.get_ci_token")
|
||||||
|
def test_no_token_exits_error(self, mock_ci_token: MagicMock) -> None:
|
||||||
|
"""When CI token is not set, exits with error."""
|
||||||
|
mock_ci_token.side_effect = Exception("no token")
|
||||||
|
|
||||||
|
runner = CliRunner()
|
||||||
|
result = runner.invoke(cli, ["--repo", "oblachno/infra", "--pr-number", "1"])
|
||||||
|
|
||||||
|
assert result.exit_code != 0
|
||||||
|
|
||||||
|
@patch("devx.ci.fix_pr_title.get_ci_token")
|
||||||
|
@patch("devx.ci.fix_pr_title.GiteaClient")
|
||||||
|
@patch("devx.ci.fix_pr_title.get_vikunja_title_optional")
|
||||||
|
def test_strips_task_id_prefix_from_vikunja_title(
|
||||||
|
self,
|
||||||
|
mock_vikunja: MagicMock,
|
||||||
|
mock_gitea_cls: MagicMock,
|
||||||
|
mock_ci_token: MagicMock,
|
||||||
|
) -> None:
|
||||||
|
"""When Vikunja title already has task ID prefix, it's stripped to avoid double prefix."""
|
||||||
|
mock_client = MagicMock()
|
||||||
|
mock_gitea_cls.return_value = mock_client
|
||||||
|
mock_client.get_pr.return_value = {
|
||||||
|
"number": 99,
|
||||||
|
"title": "Fix thing",
|
||||||
|
"head": {"ref": "OBL-INFRA-99-fix-thing"},
|
||||||
|
}
|
||||||
|
mock_vikunja.return_value = "OBL-INFRA-99: Fix thing"
|
||||||
|
mock_ci_token.return_value = "token"
|
||||||
|
|
||||||
|
runner = CliRunner()
|
||||||
|
result = runner.invoke(cli, ["--repo", "oblachno/infra", "--pr-number", "99"])
|
||||||
|
|
||||||
|
assert result.exit_code == 0
|
||||||
|
mock_client.update_pr.assert_called_once_with(99, {"title": "OBL-INFRA-99: Fix thing"})
|
||||||
|
|
||||||
|
def test_invalid_repo_format_exits_error(self) -> None:
|
||||||
|
"""When repo is not in owner/name format, exits with error."""
|
||||||
|
runner = CliRunner()
|
||||||
|
result = runner.invoke(cli, ["--repo", "invalid", "--pr-number", "1"])
|
||||||
|
assert result.exit_code != 0
|
||||||
@@ -1,4 +1,4 @@
|
|||||||
"""Unit tests for scripts/gitea_cli.py."""
|
"""Unit tests for devx/gitea_cli.py."""
|
||||||
|
|
||||||
from __future__ import annotations
|
from __future__ import annotations
|
||||||
|
|
||||||
@@ -7,7 +7,13 @@ from unittest.mock import MagicMock, patch
|
|||||||
|
|
||||||
import pytest
|
import pytest
|
||||||
|
|
||||||
from devx.gitea_cli import TeaCLI, TeaCLIError, _extract_issue_number, _extract_pr_number, configure_tea_login
|
from devx.gitea_cli import (
|
||||||
|
TeaCLI,
|
||||||
|
TeaCLIError,
|
||||||
|
_extract_issue_number,
|
||||||
|
_extract_pr_number,
|
||||||
|
configure_tea_login,
|
||||||
|
)
|
||||||
|
|
||||||
|
|
||||||
class TestExtractIssueNumber:
|
class TestExtractIssueNumber:
|
||||||
@@ -77,6 +83,25 @@ class TestTeaCLIRun:
|
|||||||
with pytest.raises(TeaCLIError, match="auth error"):
|
with pytest.raises(TeaCLIError, match="auth error"):
|
||||||
cli._run(["labels", "list"])
|
cli._run(["labels", "list"])
|
||||||
|
|
||||||
|
def test_run_failure_includes_stdout(self) -> None:
|
||||||
|
"""tea writes some errors to stdout (e.g. 'no available login')."""
|
||||||
|
cli = TeaCLI(tea_bin="/fake/tea")
|
||||||
|
mock_result = MagicMock(returncode=1, stdout="no available login", stderr="")
|
||||||
|
with patch("subprocess.run", return_value=mock_result):
|
||||||
|
with pytest.raises(TeaCLIError, match="no available login"):
|
||||||
|
cli._run(["releases", "create"])
|
||||||
|
|
||||||
|
def test_run_failure_includes_both_stdout_and_stderr(self) -> None:
|
||||||
|
"""When both stdout and stderr have content, both are included."""
|
||||||
|
cli = TeaCLI(tea_bin="/fake/tea")
|
||||||
|
mock_result = MagicMock(returncode=1, stdout="partial error", stderr="auth error")
|
||||||
|
with patch("subprocess.run", return_value=mock_result):
|
||||||
|
with pytest.raises(TeaCLIError, match="partial error"):
|
||||||
|
cli._run(["labels", "list"])
|
||||||
|
with patch("subprocess.run", return_value=mock_result):
|
||||||
|
with pytest.raises(TeaCLIError, match="auth error"):
|
||||||
|
cli._run(["labels", "list"])
|
||||||
|
|
||||||
def test_run_tea_not_found_raises_tea_error(self) -> None:
|
def test_run_tea_not_found_raises_tea_error(self) -> None:
|
||||||
cli = TeaCLI(tea_bin="tea")
|
cli = TeaCLI(tea_bin="tea")
|
||||||
with patch("subprocess.run", side_effect=FileNotFoundError("tea not found")):
|
with patch("subprocess.run", side_effect=FileNotFoundError("tea not found")):
|
||||||
@@ -100,6 +125,46 @@ class TestTeaCLIRun:
|
|||||||
cmd = mock_run.call_args[0][0]
|
cmd = mock_run.call_args[0][0]
|
||||||
assert "--output" not in cmd
|
assert "--output" not in cmd
|
||||||
|
|
||||||
|
def test_run_retries_on_502(self) -> None:
|
||||||
|
"""Transient 502 errors should be retried, then succeed."""
|
||||||
|
cli = TeaCLI(tea_bin="/fake/tea")
|
||||||
|
fail_result = MagicMock(returncode=1, stdout="", stderr="502 Bad Gateway")
|
||||||
|
success_result = MagicMock(returncode=0, stdout='[{"id": 1}]', stderr="")
|
||||||
|
with patch("subprocess.run", side_effect=[fail_result, success_result]) as mock_run:
|
||||||
|
with patch("tenacity.nap.time.sleep"):
|
||||||
|
output = cli._run(["labels", "list"])
|
||||||
|
assert output == '[{"id": 1}]'
|
||||||
|
assert mock_run.call_count == 2
|
||||||
|
|
||||||
|
def test_run_retries_on_503_then_fails(self) -> None:
|
||||||
|
"""If all retries are exhausted on 503, raise TeaCLIError."""
|
||||||
|
cli = TeaCLI(tea_bin="/fake/tea")
|
||||||
|
fail_result = MagicMock(returncode=1, stdout="", stderr="503 Service Unavailable")
|
||||||
|
with patch("subprocess.run", return_value=fail_result):
|
||||||
|
with patch("tenacity.nap.time.sleep"):
|
||||||
|
with pytest.raises(TeaCLIError, match="503"):
|
||||||
|
cli._run(["issues", "create"])
|
||||||
|
# MAX_RETRIES=3, so 3 attempts total
|
||||||
|
|
||||||
|
def test_run_no_retry_on_non_transient_error(self) -> None:
|
||||||
|
"""Non-transient errors (e.g. auth) should fail immediately without retry."""
|
||||||
|
cli = TeaCLI(tea_bin="/fake/tea")
|
||||||
|
fail_result = MagicMock(returncode=1, stdout="", stderr="auth error")
|
||||||
|
with patch("subprocess.run", return_value=fail_result) as mock_run:
|
||||||
|
with pytest.raises(TeaCLIError, match="auth error"):
|
||||||
|
cli._run(["labels", "list"])
|
||||||
|
assert mock_run.call_count == 1
|
||||||
|
|
||||||
|
def test_run_retries_on_429_in_stdout(self) -> None:
|
||||||
|
"""429 rate limit in stdout should trigger retry."""
|
||||||
|
cli = TeaCLI(tea_bin="/fake/tea")
|
||||||
|
fail_result = MagicMock(returncode=1, stdout="429 Too Many Requests", stderr="")
|
||||||
|
success_result = MagicMock(returncode=0, stdout="ok", stderr="")
|
||||||
|
with patch("subprocess.run", side_effect=[fail_result, success_result]):
|
||||||
|
with patch("tenacity.nap.time.sleep"):
|
||||||
|
output = cli._run(["releases", "create"])
|
||||||
|
assert output == "ok"
|
||||||
|
|
||||||
|
|
||||||
class TestRepoArg:
|
class TestRepoArg:
|
||||||
def test_with_repo_arg(self) -> None:
|
def test_with_repo_arg(self) -> None:
|
||||||
@@ -380,9 +445,11 @@ class TestConfigureTeaLogin:
|
|||||||
def test_configures_login_when_not_present(self, mock_subprocess: MagicMock, mock_which: MagicMock) -> None:
|
def test_configures_login_when_not_present(self, mock_subprocess: MagicMock, mock_which: MagicMock) -> None:
|
||||||
"""configure_tea_login adds login when not already configured."""
|
"""configure_tea_login adds login when not already configured."""
|
||||||
mock_list = MagicMock(returncode=0, stdout="")
|
mock_list = MagicMock(returncode=0, stdout="")
|
||||||
mock_subprocess.return_value = mock_list
|
mock_add = MagicMock(returncode=0, stdout="Login successful", stderr="")
|
||||||
|
mock_default = MagicMock(returncode=0, stdout="", stderr="")
|
||||||
|
mock_subprocess.side_effect = [mock_list, mock_add, mock_default]
|
||||||
configure_tea_login()
|
configure_tea_login()
|
||||||
assert mock_subprocess.call_count >= 2 # login list + login add + login default
|
assert mock_subprocess.call_count == 3 # login list + login add + login default
|
||||||
|
|
||||||
@patch.dict("os.environ", {"CI_GITEA_TOKEN": "tok"})
|
@patch.dict("os.environ", {"CI_GITEA_TOKEN": "tok"})
|
||||||
@patch("devx.gitea_cli.shutil.which", return_value="/usr/bin/tea")
|
@patch("devx.gitea_cli.shutil.which", return_value="/usr/bin/tea")
|
||||||
@@ -393,3 +460,37 @@ class TestConfigureTeaLogin:
|
|||||||
mock_subprocess.return_value = mock_list
|
mock_subprocess.return_value = mock_list
|
||||||
configure_tea_login()
|
configure_tea_login()
|
||||||
assert mock_subprocess.call_count == 1 # only login list, no add
|
assert mock_subprocess.call_count == 1 # only login list, no add
|
||||||
|
|
||||||
|
@patch.dict("os.environ", {"CI_GITEA_TOKEN": "tok"})
|
||||||
|
@patch("devx.gitea_cli.shutil.which", return_value="/usr/bin/tea")
|
||||||
|
@patch("devx.gitea_cli.subprocess.run")
|
||||||
|
def test_raises_on_login_add_failure(self, mock_subprocess: MagicMock, mock_which: MagicMock) -> None:
|
||||||
|
"""configure_tea_login raises TeaCLIError if tea login add fails."""
|
||||||
|
mock_list = MagicMock(returncode=0, stdout="")
|
||||||
|
mock_add = MagicMock(returncode=1, stdout="", stderr="invalid token")
|
||||||
|
mock_subprocess.side_effect = [mock_list, mock_add]
|
||||||
|
with pytest.raises(TeaCLIError, match="login add failed"):
|
||||||
|
configure_tea_login()
|
||||||
|
|
||||||
|
@patch.dict("os.environ", {"CI_GITEA_TOKEN": "tok"})
|
||||||
|
@patch("devx.gitea_cli.shutil.which", return_value="/usr/bin/tea")
|
||||||
|
@patch("devx.gitea_cli.subprocess.run")
|
||||||
|
def test_raises_on_login_default_failure(self, mock_subprocess: MagicMock, mock_which: MagicMock) -> None:
|
||||||
|
"""configure_tea_login raises TeaCLIError if tea login default fails."""
|
||||||
|
mock_list = MagicMock(returncode=0, stdout="")
|
||||||
|
mock_add = MagicMock(returncode=0, stdout="Login successful", stderr="")
|
||||||
|
mock_default = MagicMock(returncode=1, stdout="", stderr="login not found")
|
||||||
|
mock_subprocess.side_effect = [mock_list, mock_add, mock_default]
|
||||||
|
with pytest.raises(TeaCLIError, match="login default failed"):
|
||||||
|
configure_tea_login()
|
||||||
|
|
||||||
|
@patch.dict("os.environ", {"CI_GITEA_TOKEN": "tok"})
|
||||||
|
@patch("devx.gitea_cli.shutil.which", return_value="/usr/bin/tea")
|
||||||
|
@patch("devx.gitea_cli.subprocess.run")
|
||||||
|
def test_login_add_failure_includes_stdout(self, mock_subprocess: MagicMock, mock_which: MagicMock) -> None:
|
||||||
|
"""Error message includes stdout when tea writes errors there."""
|
||||||
|
mock_list = MagicMock(returncode=0, stdout="")
|
||||||
|
mock_add = MagicMock(returncode=1, stdout="Error: invalid username", stderr="")
|
||||||
|
mock_subprocess.side_effect = [mock_list, mock_add]
|
||||||
|
with pytest.raises(TeaCLIError, match="invalid username"):
|
||||||
|
configure_tea_login()
|
||||||
|
|||||||
@@ -0,0 +1,100 @@
|
|||||||
|
"""Unit tests for devx.i18n."""
|
||||||
|
|
||||||
|
from __future__ import annotations
|
||||||
|
|
||||||
|
import pytest
|
||||||
|
|
||||||
|
import devx.i18n as i18n_mod
|
||||||
|
from devx.i18n import _, configure_i18n
|
||||||
|
|
||||||
|
|
||||||
|
class TestTranslate:
|
||||||
|
def test_returns_english_by_default(self) -> None:
|
||||||
|
with pytest.MonkeyPatch().context() as mp:
|
||||||
|
mp.delenv("DEVX_LANG", raising=False)
|
||||||
|
assert _("Running tests") == "Running tests"
|
||||||
|
|
||||||
|
def test_returns_key_when_missing(self) -> None:
|
||||||
|
with pytest.MonkeyPatch().context() as mp:
|
||||||
|
mp.delenv("DEVX_LANG", raising=False)
|
||||||
|
assert _("nonexistent.key.xyz") == "nonexistent.key.xyz"
|
||||||
|
|
||||||
|
def test_formats_kwargs(self) -> None:
|
||||||
|
# Find a key with format placeholders
|
||||||
|
for key, translations in i18n_mod.TRANSLATIONS.items():
|
||||||
|
en = translations.get("en", "")
|
||||||
|
if "{" in en:
|
||||||
|
with pytest.MonkeyPatch().context() as mp:
|
||||||
|
mp.delenv("DEVX_LANG", raising=False)
|
||||||
|
result = _(key, **dict.fromkeys(_extract_format_keys(en), "x"))
|
||||||
|
assert "{" not in result
|
||||||
|
return
|
||||||
|
pytest.skip("No key with format placeholders found")
|
||||||
|
|
||||||
|
def test_invalid_lang_falls_back_to_english(self) -> None:
|
||||||
|
with pytest.MonkeyPatch().context() as mp:
|
||||||
|
mp.setenv("DEVX_LANG", "fr")
|
||||||
|
assert _("Running tests") == "Running tests"
|
||||||
|
|
||||||
|
def test_bulgarian_translation(self) -> None:
|
||||||
|
with pytest.MonkeyPatch().context() as mp:
|
||||||
|
mp.setenv("DEVX_LANG", "bg")
|
||||||
|
# Find a key that has a Bulgarian translation
|
||||||
|
for key, translations in i18n_mod.TRANSLATIONS.items():
|
||||||
|
if "bg" in translations:
|
||||||
|
result = _(key)
|
||||||
|
assert result == translations["bg"]
|
||||||
|
return
|
||||||
|
pytest.skip("No Bulgarian translation found")
|
||||||
|
|
||||||
|
|
||||||
|
class TestConfigureI18n:
|
||||||
|
def test_custom_lang_env_var(self) -> None:
|
||||||
|
configure_i18n(lang_env_var="GRM_LANG")
|
||||||
|
try:
|
||||||
|
with pytest.MonkeyPatch().context() as mp:
|
||||||
|
mp.setenv("GRM_LANG", "bg")
|
||||||
|
mp.delenv("DEVX_LANG", raising=False)
|
||||||
|
# Find a key with Bulgarian translation
|
||||||
|
for key, translations in i18n_mod.TRANSLATIONS.items():
|
||||||
|
if "bg" in translations:
|
||||||
|
assert _(key) == translations["bg"]
|
||||||
|
return
|
||||||
|
pytest.skip("No Bulgarian translation found")
|
||||||
|
finally:
|
||||||
|
configure_i18n() # Reset to defaults
|
||||||
|
|
||||||
|
def test_custom_translations_path_env_var(self, tmp_path) -> None:
|
||||||
|
custom_translations = {"custom.key": {"en": "Custom Value", "bg": "Персонализирано"}}
|
||||||
|
custom_file = tmp_path / "custom.json"
|
||||||
|
custom_file.write_text(__import__("json").dumps(custom_translations))
|
||||||
|
|
||||||
|
configure_i18n(translations_path_env_var="GRM_TRANSLATIONS_PATH")
|
||||||
|
try:
|
||||||
|
# Use i18n_mod.TRANSLATIONS (not a stale import) — other tests
|
||||||
|
# may call importlib.reload(devx.i18n), replacing the dict object.
|
||||||
|
translations = i18n_mod.TRANSLATIONS
|
||||||
|
original = dict(translations)
|
||||||
|
translations.update(custom_translations)
|
||||||
|
try:
|
||||||
|
with pytest.MonkeyPatch().context() as mp:
|
||||||
|
mp.setenv("GRM_TRANSLATIONS_PATH", str(custom_file))
|
||||||
|
assert _("custom.key") == "Custom Value"
|
||||||
|
finally:
|
||||||
|
translations.clear()
|
||||||
|
translations.update(original)
|
||||||
|
finally:
|
||||||
|
configure_i18n() # Reset to defaults
|
||||||
|
|
||||||
|
def test_reset_to_defaults(self) -> None:
|
||||||
|
configure_i18n(lang_env_var="GRM_LANG")
|
||||||
|
configure_i18n() # Reset
|
||||||
|
assert i18n_mod._lang_env_var == "DEVX_LANG"
|
||||||
|
assert i18n_mod._translations_path_env_var == "DEVX_TRANSLATIONS_PATH"
|
||||||
|
|
||||||
|
|
||||||
|
def _extract_format_keys(template: str) -> list[str]:
|
||||||
|
"""Extract {key} format placeholders from a template string."""
|
||||||
|
import re
|
||||||
|
|
||||||
|
return re.findall(r"\{(\w+)\}", template)
|
||||||
@@ -66,7 +66,10 @@ class TestMain:
|
|||||||
def test_already_installed(self) -> None:
|
def test_already_installed(self) -> None:
|
||||||
from click.testing import CliRunner
|
from click.testing import CliRunner
|
||||||
|
|
||||||
with patch("shutil.which", return_value="/usr/bin/checkmake"):
|
with (
|
||||||
|
patch("shutil.which", return_value="/usr/bin/checkmake"),
|
||||||
|
patch("devx.tools.install_checkmake._install_with_go"),
|
||||||
|
):
|
||||||
runner = CliRunner()
|
runner = CliRunner()
|
||||||
runner.invoke(install_checkmake.cli, [])
|
runner.invoke(install_checkmake.cli, [])
|
||||||
|
|
||||||
@@ -98,7 +101,10 @@ class TestMain:
|
|||||||
with patch.object(install_checkmake, "TARGET_PATH", target):
|
with patch.object(install_checkmake, "TARGET_PATH", target):
|
||||||
with patch("shutil.which", side_effect=[None, None]):
|
with patch("shutil.which", side_effect=[None, None]):
|
||||||
with patch.object(platform, "machine", return_value="x86_64"):
|
with patch.object(platform, "machine", return_value="x86_64"):
|
||||||
with patch("urllib.request.urlretrieve", side_effect=_write_file) as mock_retrieve:
|
with (
|
||||||
|
patch("urllib.request.urlretrieve", side_effect=_write_file) as mock_retrieve,
|
||||||
|
patch("devx.tools.install_checkmake._install_with_go", return_value=False),
|
||||||
|
):
|
||||||
runner = CliRunner()
|
runner = CliRunner()
|
||||||
runner.invoke(install_checkmake.cli, [])
|
runner.invoke(install_checkmake.cli, [])
|
||||||
mock_retrieve.assert_called_once()
|
mock_retrieve.assert_called_once()
|
||||||
|
|||||||
@@ -1,6 +1,7 @@
|
|||||||
from __future__ import annotations
|
from __future__ import annotations
|
||||||
|
|
||||||
import platform
|
import platform
|
||||||
|
import urllib.request
|
||||||
from pathlib import Path
|
from pathlib import Path
|
||||||
from unittest.mock import patch
|
from unittest.mock import patch
|
||||||
|
|
||||||
@@ -47,13 +48,29 @@ class TestDownload:
|
|||||||
def test_download(self, tmp_path: Path) -> None:
|
def test_download(self, tmp_path: Path) -> None:
|
||||||
dest = tmp_path / "file.bin"
|
dest = tmp_path / "file.bin"
|
||||||
|
|
||||||
def _write_file(url: str, path: Path) -> tuple[str, None]:
|
class _FakeResponse:
|
||||||
Path(path).write_bytes(b"data")
|
def __init__(self) -> None:
|
||||||
return str(path), None
|
self._sent = False
|
||||||
|
|
||||||
with patch("urllib.request.urlretrieve", side_effect=_write_file) as mock_retrieve:
|
def __enter__(self) -> _FakeResponse:
|
||||||
|
return self
|
||||||
|
|
||||||
|
def __exit__(self, *args: object) -> None:
|
||||||
|
pass
|
||||||
|
|
||||||
|
def read(self, n: int = -1) -> bytes:
|
||||||
|
if self._sent:
|
||||||
|
return b""
|
||||||
|
self._sent = True
|
||||||
|
return b"data"
|
||||||
|
|
||||||
|
with patch("urllib.request.urlopen", return_value=_FakeResponse()) as mock_urlopen:
|
||||||
install_tools._download("https://example.com/file", dest)
|
install_tools._download("https://example.com/file", dest)
|
||||||
mock_retrieve.assert_called_once()
|
mock_urlopen.assert_called_once()
|
||||||
|
call_args = mock_urlopen.call_args
|
||||||
|
req = call_args.args[0]
|
||||||
|
assert isinstance(req, urllib.request.Request)
|
||||||
|
assert req.get_header("User-agent") == "devx/install-tools"
|
||||||
assert dest.read_bytes() == b"data"
|
assert dest.read_bytes() == b"data"
|
||||||
|
|
||||||
|
|
||||||
@@ -221,6 +238,33 @@ class TestInstallTea:
|
|||||||
assert install_tools.install_tea() is True
|
assert install_tools.install_tea() is True
|
||||||
assert (tmp_path / "tea").exists()
|
assert (tmp_path / "tea").exists()
|
||||||
|
|
||||||
|
def test_install_fallback_to_second_url(self, tmp_path: Path) -> None:
|
||||||
|
"""First URL fails (403), second URL succeeds."""
|
||||||
|
call_count = [0]
|
||||||
|
|
||||||
|
def _download_side_effect(url: str, dest: Path) -> None:
|
||||||
|
call_count[0] += 1
|
||||||
|
if call_count[0] == 1:
|
||||||
|
raise OSError("HTTP Error 403: Forbidden")
|
||||||
|
Path(dest).write_bytes(b"binary")
|
||||||
|
|
||||||
|
with patch.object(install_tools, "_is_installed", return_value=False):
|
||||||
|
with patch.object(install_tools, "TARGET_DIR", tmp_path):
|
||||||
|
with patch.object(platform, "machine", return_value="x86_64"):
|
||||||
|
with patch.object(install_tools, "_download", side_effect=_download_side_effect):
|
||||||
|
assert install_tools.install_tea() is True
|
||||||
|
assert (tmp_path / "tea").exists()
|
||||||
|
assert call_count[0] == 2
|
||||||
|
|
||||||
|
def test_install_all_urls_fail(self, tmp_path: Path) -> None:
|
||||||
|
"""All URLs fail — should raise ClickException."""
|
||||||
|
with patch.object(install_tools, "_is_installed", return_value=False):
|
||||||
|
with patch.object(install_tools, "TARGET_DIR", tmp_path):
|
||||||
|
with patch.object(platform, "machine", return_value="x86_64"):
|
||||||
|
with patch.object(install_tools, "_download", side_effect=OSError("403 Forbidden")):
|
||||||
|
with pytest.raises(ClickException, match="Failed to download tea"):
|
||||||
|
install_tools.install_tea()
|
||||||
|
|
||||||
|
|
||||||
class TestInstallHadolint:
|
class TestInstallHadolint:
|
||||||
def test_already_installed(self) -> None:
|
def test_already_installed(self) -> None:
|
||||||
@@ -297,6 +341,47 @@ class TestInstallVale:
|
|||||||
assert (tmp_path / "vale").exists()
|
assert (tmp_path / "vale").exists()
|
||||||
|
|
||||||
|
|
||||||
|
class TestInstallPromtool:
|
||||||
|
def test_already_installed(self) -> None:
|
||||||
|
with patch.object(install_tools, "_is_installed", return_value=True):
|
||||||
|
assert install_tools.install_promtool() is True
|
||||||
|
|
||||||
|
def test_install(self, tmp_path: Path) -> None:
|
||||||
|
import io
|
||||||
|
import tarfile
|
||||||
|
|
||||||
|
tarball_path = tmp_path / "archive.tar.gz"
|
||||||
|
binary_content = b"fake promtool"
|
||||||
|
with tarfile.open(tarball_path, "w:gz") as tar:
|
||||||
|
info = tarfile.TarInfo(name="promtool")
|
||||||
|
info.size = len(binary_content)
|
||||||
|
tar.addfile(info, io.BytesIO(binary_content))
|
||||||
|
|
||||||
|
with patch.object(install_tools, "_is_installed", return_value=False):
|
||||||
|
with patch.object(install_tools, "TARGET_DIR", tmp_path):
|
||||||
|
with patch.object(install_tools, "_arch", return_value="amd64"):
|
||||||
|
with patch.object(
|
||||||
|
install_tools,
|
||||||
|
"_download",
|
||||||
|
side_effect=lambda url, dest: Path(dest).write_bytes(tarball_path.read_bytes()),
|
||||||
|
):
|
||||||
|
assert install_tools.install_promtool() is True
|
||||||
|
assert (tmp_path / "promtool").exists()
|
||||||
|
|
||||||
|
def test_url_contains_version(self, tmp_path: Path) -> None:
|
||||||
|
"""Verify the download URL includes the correct promtool version."""
|
||||||
|
captured_url = []
|
||||||
|
|
||||||
|
def fake_extract(url: str, binary_name: str) -> Path:
|
||||||
|
captured_url.append(url)
|
||||||
|
return tmp_path / binary_name
|
||||||
|
|
||||||
|
with patch.object(install_tools, "_is_installed", return_value=False):
|
||||||
|
with patch.object(install_tools, "_download_and_extract_tarball", side_effect=fake_extract):
|
||||||
|
install_tools.install_promtool()
|
||||||
|
assert any(f"v{install_tools.PROMTOOL_VERSION}" in url for url in captured_url)
|
||||||
|
|
||||||
|
|
||||||
class TestListTools:
|
class TestListTools:
|
||||||
def test_list(self, tmp_path: Path) -> None:
|
def test_list(self, tmp_path: Path) -> None:
|
||||||
with patch.object(install_tools, "TARGET_DIR", tmp_path):
|
with patch.object(install_tools, "TARGET_DIR", tmp_path):
|
||||||
@@ -341,6 +426,11 @@ class TestInstallTool:
|
|||||||
assert install_tools._install_tool("vale") is True
|
assert install_tools._install_tool("vale") is True
|
||||||
mock.assert_called_once()
|
mock.assert_called_once()
|
||||||
|
|
||||||
|
def test_promtool(self) -> None:
|
||||||
|
with patch.object(install_tools, "install_promtool", return_value=True) as mock:
|
||||||
|
assert install_tools._install_tool("promtool") is True
|
||||||
|
mock.assert_called_once()
|
||||||
|
|
||||||
def test_unknown_tool(self) -> None:
|
def test_unknown_tool(self) -> None:
|
||||||
with pytest.raises(ClickException, match="Unknown tool"):
|
with pytest.raises(ClickException, match="Unknown tool"):
|
||||||
install_tools._install_tool("unknown")
|
install_tools._install_tool("unknown")
|
||||||
@@ -359,7 +449,7 @@ class TestMain:
|
|||||||
with patch.object(install_tools, "_install_tool", return_value=True) as mock_install:
|
with patch.object(install_tools, "_install_tool", return_value=True) as mock_install:
|
||||||
result = runner.invoke(install_tools.main, [])
|
result = runner.invoke(install_tools.main, [])
|
||||||
assert result.exit_code == 0
|
assert result.exit_code == 0
|
||||||
assert mock_install.call_count == 7
|
assert mock_install.call_count == 8
|
||||||
|
|
||||||
def test_install_specific_tool(self) -> None:
|
def test_install_specific_tool(self) -> None:
|
||||||
runner = CliRunner()
|
runner = CliRunner()
|
||||||
|
|||||||
@@ -1,7 +1,7 @@
|
|||||||
from __future__ import annotations
|
from __future__ import annotations
|
||||||
|
|
||||||
from pathlib import Path
|
from pathlib import Path
|
||||||
from unittest.mock import patch
|
from unittest.mock import MagicMock, patch
|
||||||
|
|
||||||
import pytest
|
import pytest
|
||||||
from click.testing import CliRunner
|
from click.testing import CliRunner
|
||||||
@@ -87,14 +87,16 @@ class TestRunPlatform:
|
|||||||
|
|
||||||
|
|
||||||
class TestMain:
|
class TestMain:
|
||||||
def test_molecule_not_found(self, tmp_path: Path, monkeypatch: pytest.MonkeyPatch) -> None:
|
@patch("devx.molecule.molecule_all._run_molecule")
|
||||||
|
def test_molecule_not_found(self, mock_run: MagicMock, tmp_path: Path, monkeypatch: pytest.MonkeyPatch) -> None:
|
||||||
monkeypatch.chdir(tmp_path)
|
monkeypatch.chdir(tmp_path)
|
||||||
runner = CliRunner()
|
runner = CliRunner()
|
||||||
result = runner.invoke(molecule_all.main, ["--bin", "nonexistent/bin"])
|
result = runner.invoke(molecule_all.main, ["--bin", "nonexistent/bin"])
|
||||||
assert result.exit_code != 0
|
assert result.exit_code != 0
|
||||||
assert "molecule not found" in result.output
|
assert "molecule not found" in result.output
|
||||||
|
|
||||||
def test_role_dir_not_found(self, tmp_path: Path, monkeypatch: pytest.MonkeyPatch) -> None:
|
@patch("devx.molecule.molecule_all._run_molecule")
|
||||||
|
def test_role_dir_not_found(self, mock_run: MagicMock, tmp_path: Path, monkeypatch: pytest.MonkeyPatch) -> None:
|
||||||
monkeypatch.chdir(tmp_path)
|
monkeypatch.chdir(tmp_path)
|
||||||
bin_dir = tmp_path / ".venv" / "bin"
|
bin_dir = tmp_path / ".venv" / "bin"
|
||||||
bin_dir.mkdir(parents=True)
|
bin_dir.mkdir(parents=True)
|
||||||
@@ -104,7 +106,8 @@ class TestMain:
|
|||||||
assert result.exit_code != 0
|
assert result.exit_code != 0
|
||||||
assert "Role directory not found" in result.output
|
assert "Role directory not found" in result.output
|
||||||
|
|
||||||
def test_role_dir_no_molecule(self, tmp_path: Path, monkeypatch: pytest.MonkeyPatch) -> None:
|
@patch("devx.molecule.molecule_all._run_molecule")
|
||||||
|
def test_role_dir_no_molecule(self, mock_run: MagicMock, tmp_path: Path, monkeypatch: pytest.MonkeyPatch) -> None:
|
||||||
"""Roles dir exists but no role has molecule/ — should error."""
|
"""Roles dir exists but no role has molecule/ — should error."""
|
||||||
monkeypatch.chdir(tmp_path)
|
monkeypatch.chdir(tmp_path)
|
||||||
bin_dir = tmp_path / ".venv" / "bin"
|
bin_dir = tmp_path / ".venv" / "bin"
|
||||||
|
|||||||
@@ -102,6 +102,16 @@ class TestBuildEnvForPair:
|
|||||||
env = build_env_for_pair("default|ubuntu-2204|img:latest|", {"MOLECULE_HOME": "/custom/home"})
|
env = build_env_for_pair("default|ubuntu-2204|img:latest|", {"MOLECULE_HOME": "/custom/home"})
|
||||||
assert env["MOLECULE_HOME"] == "/custom/home"
|
assert env["MOLECULE_HOME"] == "/custom/home"
|
||||||
|
|
||||||
|
def test_appends_matrix_index_to_platform_name(self) -> None:
|
||||||
|
"""When MATRIX_INDEX is set, platform name gets a unique suffix."""
|
||||||
|
env = build_env_for_pair("default|ubuntu-2604|img:latest|sleep infinity", {"MATRIX_INDEX": "3"})
|
||||||
|
assert env["MOLECULE_PLATFORM_NAME"] == "ubuntu-2604-r3"
|
||||||
|
|
||||||
|
def test_no_matrix_index_keeps_platform_name(self) -> None:
|
||||||
|
"""Without MATRIX_INDEX, platform name is unchanged."""
|
||||||
|
env = build_env_for_pair("default|ubuntu-2604|img:latest|sleep infinity", {})
|
||||||
|
assert env["MOLECULE_PLATFORM_NAME"] == "ubuntu-2604"
|
||||||
|
|
||||||
|
|
||||||
class TestPollForOtherFailures:
|
class TestPollForOtherFailures:
|
||||||
def test_sets_failed_event_when_other_runner_fails(self) -> None:
|
def test_sets_failed_event_when_other_runner_fails(self) -> None:
|
||||||
@@ -165,6 +175,7 @@ class TestCli:
|
|||||||
|
|
||||||
with (
|
with (
|
||||||
patch("devx.molecule.molecule_ci_guard.subprocess.Popen") as mock_popen,
|
patch("devx.molecule.molecule_ci_guard.subprocess.Popen") as mock_popen,
|
||||||
|
patch("devx.molecule.molecule_ci_guard.subprocess.run"),
|
||||||
patch("devx.molecule.molecule_ci_guard.subprocess.run") as mock_run,
|
patch("devx.molecule.molecule_ci_guard.subprocess.run") as mock_run,
|
||||||
patch("time.sleep"),
|
patch("time.sleep"),
|
||||||
):
|
):
|
||||||
@@ -193,6 +204,7 @@ class TestCli:
|
|||||||
|
|
||||||
with (
|
with (
|
||||||
patch("devx.molecule.molecule_ci_guard.subprocess.Popen") as mock_popen,
|
patch("devx.molecule.molecule_ci_guard.subprocess.Popen") as mock_popen,
|
||||||
|
patch("devx.molecule.molecule_ci_guard.subprocess.run"),
|
||||||
patch("devx.molecule.molecule_ci_guard.subprocess.run") as mock_run,
|
patch("devx.molecule.molecule_ci_guard.subprocess.run") as mock_run,
|
||||||
patch("devx.molecule.molecule_ci_guard.poll_for_other_failures") as mock_poll,
|
patch("devx.molecule.molecule_ci_guard.poll_for_other_failures") as mock_poll,
|
||||||
patch("time.sleep"),
|
patch("time.sleep"),
|
||||||
@@ -212,8 +224,12 @@ class TestCli:
|
|||||||
"""Pair with fewer than 2 parts should raise."""
|
"""Pair with fewer than 2 parts should raise."""
|
||||||
from click.testing import CliRunner
|
from click.testing import CliRunner
|
||||||
|
|
||||||
runner = CliRunner()
|
with (
|
||||||
result = runner.invoke(cli, ["invalid_no_pipe"])
|
patch("devx.molecule.molecule_ci_guard.subprocess.Popen"),
|
||||||
|
patch("devx.molecule.molecule_ci_guard.subprocess.run"),
|
||||||
|
):
|
||||||
|
runner = CliRunner()
|
||||||
|
result = runner.invoke(cli, ["invalid_no_pipe"])
|
||||||
assert result.exit_code != 0
|
assert result.exit_code != 0
|
||||||
assert "Invalid pair format" in result.output
|
assert "Invalid pair format" in result.output
|
||||||
|
|
||||||
@@ -222,6 +238,8 @@ class TestCli:
|
|||||||
|
|
||||||
with (
|
with (
|
||||||
patch("devx.molecule.molecule_ci_guard.subprocess.Popen") as mock_popen,
|
patch("devx.molecule.molecule_ci_guard.subprocess.Popen") as mock_popen,
|
||||||
|
patch("devx.molecule.molecule_ci_guard.subprocess.run"),
|
||||||
|
patch("devx.molecule.molecule_ci_guard.subprocess.run"),
|
||||||
patch("time.sleep"),
|
patch("time.sleep"),
|
||||||
):
|
):
|
||||||
proc = MagicMock()
|
proc = MagicMock()
|
||||||
@@ -253,6 +271,8 @@ class TestCli:
|
|||||||
),
|
),
|
||||||
patch("devx.molecule.molecule_ci_guard.POLL_INTERVAL", 0.01),
|
patch("devx.molecule.molecule_ci_guard.POLL_INTERVAL", 0.01),
|
||||||
patch("devx.molecule.molecule_ci_guard.subprocess.Popen") as mock_popen,
|
patch("devx.molecule.molecule_ci_guard.subprocess.Popen") as mock_popen,
|
||||||
|
patch("devx.molecule.molecule_ci_guard.subprocess.run"),
|
||||||
|
patch("devx.molecule.molecule_ci_guard.subprocess.run"),
|
||||||
patch("devx.molecule.molecule_ci_guard.get_running_jobs") as mock_get_jobs,
|
patch("devx.molecule.molecule_ci_guard.get_running_jobs") as mock_get_jobs,
|
||||||
patch("time.sleep"),
|
patch("time.sleep"),
|
||||||
):
|
):
|
||||||
@@ -275,6 +295,8 @@ class TestCli:
|
|||||||
|
|
||||||
with (
|
with (
|
||||||
patch("devx.molecule.molecule_ci_guard.subprocess.Popen") as mock_popen,
|
patch("devx.molecule.molecule_ci_guard.subprocess.Popen") as mock_popen,
|
||||||
|
patch("devx.molecule.molecule_ci_guard.subprocess.run"),
|
||||||
|
patch("devx.molecule.molecule_ci_guard.subprocess.run"),
|
||||||
patch("time.sleep", side_effect=KeyboardInterrupt),
|
patch("time.sleep", side_effect=KeyboardInterrupt),
|
||||||
patch("os.killpg") as mock_killpg,
|
patch("os.killpg") as mock_killpg,
|
||||||
patch("os.getpgid") as mock_getpgid,
|
patch("os.getpgid") as mock_getpgid,
|
||||||
@@ -321,6 +343,7 @@ class TestCli:
|
|||||||
),
|
),
|
||||||
patch("devx.molecule.molecule_ci_guard.POLL_INTERVAL", 0.01),
|
patch("devx.molecule.molecule_ci_guard.POLL_INTERVAL", 0.01),
|
||||||
patch("devx.molecule.molecule_ci_guard.subprocess.Popen") as mock_popen,
|
patch("devx.molecule.molecule_ci_guard.subprocess.Popen") as mock_popen,
|
||||||
|
patch("devx.molecule.molecule_ci_guard.subprocess.run"),
|
||||||
patch("devx.molecule.molecule_ci_guard.get_running_jobs", side_effect=get_jobs_side_effect),
|
patch("devx.molecule.molecule_ci_guard.get_running_jobs", side_effect=get_jobs_side_effect),
|
||||||
patch("os.killpg") as mock_killpg,
|
patch("os.killpg") as mock_killpg,
|
||||||
patch("os.getpgid") as mock_getpgid,
|
patch("os.getpgid") as mock_getpgid,
|
||||||
@@ -358,6 +381,7 @@ class TestCli:
|
|||||||
),
|
),
|
||||||
patch("devx.molecule.molecule_ci_guard.POLL_INTERVAL", 0.01),
|
patch("devx.molecule.molecule_ci_guard.POLL_INTERVAL", 0.01),
|
||||||
patch("devx.molecule.molecule_ci_guard.subprocess.Popen") as mock_popen,
|
patch("devx.molecule.molecule_ci_guard.subprocess.Popen") as mock_popen,
|
||||||
|
patch("devx.molecule.molecule_ci_guard.subprocess.run"),
|
||||||
patch("devx.molecule.molecule_ci_guard.subprocess.run") as mock_run,
|
patch("devx.molecule.molecule_ci_guard.subprocess.run") as mock_run,
|
||||||
patch("devx.molecule.molecule_ci_guard.get_running_jobs") as mock_get_jobs,
|
patch("devx.molecule.molecule_ci_guard.get_running_jobs") as mock_get_jobs,
|
||||||
patch("time.sleep", side_effect=lambda x: real_sleep(0)),
|
patch("time.sleep", side_effect=lambda x: real_sleep(0)),
|
||||||
@@ -404,6 +428,7 @@ class TestCli:
|
|||||||
),
|
),
|
||||||
patch("devx.molecule.molecule_ci_guard.POLL_INTERVAL", 0.01),
|
patch("devx.molecule.molecule_ci_guard.POLL_INTERVAL", 0.01),
|
||||||
patch("devx.molecule.molecule_ci_guard.subprocess.Popen") as mock_popen,
|
patch("devx.molecule.molecule_ci_guard.subprocess.Popen") as mock_popen,
|
||||||
|
patch("devx.molecule.molecule_ci_guard.subprocess.run"),
|
||||||
patch("devx.molecule.molecule_ci_guard.get_running_jobs", side_effect=get_jobs_side_effect),
|
patch("devx.molecule.molecule_ci_guard.get_running_jobs", side_effect=get_jobs_side_effect),
|
||||||
patch("os.killpg") as mock_killpg,
|
patch("os.killpg") as mock_killpg,
|
||||||
patch("os.getpgid") as mock_getpgid,
|
patch("os.getpgid") as mock_getpgid,
|
||||||
@@ -451,6 +476,7 @@ class TestCli:
|
|||||||
),
|
),
|
||||||
patch("devx.molecule.molecule_ci_guard.POLL_INTERVAL", 0.01),
|
patch("devx.molecule.molecule_ci_guard.POLL_INTERVAL", 0.01),
|
||||||
patch("devx.molecule.molecule_ci_guard.subprocess.Popen") as mock_popen,
|
patch("devx.molecule.molecule_ci_guard.subprocess.Popen") as mock_popen,
|
||||||
|
patch("devx.molecule.molecule_ci_guard.subprocess.run"),
|
||||||
patch("devx.molecule.molecule_ci_guard.get_running_jobs", side_effect=get_jobs_side_effect),
|
patch("devx.molecule.molecule_ci_guard.get_running_jobs", side_effect=get_jobs_side_effect),
|
||||||
patch("os.killpg") as mock_killpg,
|
patch("os.killpg") as mock_killpg,
|
||||||
patch("os.getpgid") as mock_getpgid,
|
patch("os.getpgid") as mock_getpgid,
|
||||||
@@ -546,6 +572,7 @@ class TestCliMultiRole:
|
|||||||
|
|
||||||
with (
|
with (
|
||||||
patch("devx.molecule.molecule_ci_guard.subprocess.Popen") as mock_popen,
|
patch("devx.molecule.molecule_ci_guard.subprocess.Popen") as mock_popen,
|
||||||
|
patch("devx.molecule.molecule_ci_guard.subprocess.run"),
|
||||||
patch("devx.molecule.molecule_ci_guard.subprocess.run") as mock_run,
|
patch("devx.molecule.molecule_ci_guard.subprocess.run") as mock_run,
|
||||||
patch("time.sleep"),
|
patch("time.sleep"),
|
||||||
):
|
):
|
||||||
|
|||||||
@@ -9,9 +9,10 @@ from devx.gitea_cli import TeaCLIError, configure_tea_login
|
|||||||
|
|
||||||
|
|
||||||
class TestNotifyFailure:
|
class TestNotifyFailure:
|
||||||
|
@patch("devx.gitea_cli.configure_tea_login")
|
||||||
@patch.dict("os.environ", {"CI_GITEA_TOKEN": "tok"})
|
@patch.dict("os.environ", {"CI_GITEA_TOKEN": "tok"})
|
||||||
@patch("devx.ci.notify_failure.TeaCLI")
|
@patch("devx.ci.notify_failure.TeaCLI")
|
||||||
def test_creates_issue_with_tea(self, mock_tea_cls: MagicMock) -> None:
|
def test_creates_issue_with_tea(self, mock_tea_cls: MagicMock, mock_login: MagicMock) -> None:
|
||||||
mock_tea = MagicMock()
|
mock_tea = MagicMock()
|
||||||
mock_tea.list_labels.return_value = [{"id": 5, "name": "bug"}]
|
mock_tea.list_labels.return_value = [{"id": 5, "name": "bug"}]
|
||||||
mock_tea.create_issue.return_value = {"index": 42, "title": "test"}
|
mock_tea.create_issue.return_value = {"index": 42, "title": "test"}
|
||||||
@@ -36,9 +37,10 @@ class TestNotifyFailure:
|
|||||||
mock_tea.create_issue.assert_called_once()
|
mock_tea.create_issue.assert_called_once()
|
||||||
mock_tea.add_label.assert_called_once_with("owner/repo", 42, ["bug"])
|
mock_tea.add_label.assert_called_once_with("owner/repo", 42, ["bug"])
|
||||||
|
|
||||||
|
@patch("devx.gitea_cli.configure_tea_login")
|
||||||
@patch.dict("os.environ", {"CI_GITEA_TOKEN": "tok"})
|
@patch.dict("os.environ", {"CI_GITEA_TOKEN": "tok"})
|
||||||
@patch("devx.ci.notify_failure.TeaCLI")
|
@patch("devx.ci.notify_failure.TeaCLI")
|
||||||
def test_tea_creates_issue_without_bug_label(self, mock_tea_cls: MagicMock) -> None:
|
def test_tea_creates_issue_without_bug_label(self, mock_tea_cls: MagicMock, mock_login: MagicMock) -> None:
|
||||||
mock_tea = MagicMock()
|
mock_tea = MagicMock()
|
||||||
mock_tea.list_labels.return_value = [{"id": 1, "name": "enhancement"}]
|
mock_tea.list_labels.return_value = [{"id": 1, "name": "enhancement"}]
|
||||||
mock_tea.create_issue.return_value = {"index": 43, "title": "test"}
|
mock_tea.create_issue.return_value = {"index": 43, "title": "test"}
|
||||||
@@ -53,9 +55,10 @@ class TestNotifyFailure:
|
|||||||
assert "issue #43" in result.output
|
assert "issue #43" in result.output
|
||||||
mock_tea.add_label.assert_not_called()
|
mock_tea.add_label.assert_not_called()
|
||||||
|
|
||||||
|
@patch("devx.gitea_cli.configure_tea_login")
|
||||||
@patch.dict("os.environ", {"CI_GITEA_TOKEN": "tok"})
|
@patch.dict("os.environ", {"CI_GITEA_TOKEN": "tok"})
|
||||||
@patch("devx.ci.notify_failure.TeaCLI")
|
@patch("devx.ci.notify_failure.TeaCLI")
|
||||||
def test_tea_error_raises(self, mock_tea_cls: MagicMock) -> None:
|
def test_tea_error_raises(self, mock_tea_cls: MagicMock, mock_login: MagicMock) -> None:
|
||||||
"""When tea fails, the workflow fails — no fallback."""
|
"""When tea fails, the workflow fails — no fallback."""
|
||||||
mock_tea = MagicMock()
|
mock_tea = MagicMock()
|
||||||
mock_tea.list_labels.side_effect = TeaCLIError("network error")
|
mock_tea.list_labels.side_effect = TeaCLIError("network error")
|
||||||
@@ -70,9 +73,12 @@ class TestNotifyFailure:
|
|||||||
assert result.exit_code != 0
|
assert result.exit_code != 0
|
||||||
assert "tea" in result.output.lower()
|
assert "tea" in result.output.lower()
|
||||||
|
|
||||||
|
@patch("devx.gitea_cli.configure_tea_login")
|
||||||
@patch.dict("os.environ", {"CI_GITEA_TOKEN": "tok"})
|
@patch.dict("os.environ", {"CI_GITEA_TOKEN": "tok"})
|
||||||
@patch("devx.ci.notify_failure.TeaCLI")
|
@patch("devx.ci.notify_failure.TeaCLI")
|
||||||
def test_tea_list_labels_error_continues_without_labels(self, mock_tea_cls: MagicMock) -> None:
|
def test_tea_list_labels_error_continues_without_labels(
|
||||||
|
self, mock_tea_cls: MagicMock, mock_login: MagicMock
|
||||||
|
) -> None:
|
||||||
"""If listing labels fails via tea, issue is still created without labels."""
|
"""If listing labels fails via tea, issue is still created without labels."""
|
||||||
mock_tea = MagicMock()
|
mock_tea = MagicMock()
|
||||||
mock_tea.list_labels.side_effect = TeaCLIError("network error")
|
mock_tea.list_labels.side_effect = TeaCLIError("network error")
|
||||||
@@ -87,9 +93,10 @@ class TestNotifyFailure:
|
|||||||
assert result.exit_code == 0
|
assert result.exit_code == 0
|
||||||
assert "issue #50" in result.output
|
assert "issue #50" in result.output
|
||||||
|
|
||||||
|
@patch("devx.gitea_cli.configure_tea_login")
|
||||||
@patch.dict("os.environ", {"CI_GITEA_TOKEN": "tok"})
|
@patch.dict("os.environ", {"CI_GITEA_TOKEN": "tok"})
|
||||||
@patch("devx.ci.notify_failure.TeaCLI")
|
@patch("devx.ci.notify_failure.TeaCLI")
|
||||||
def test_tea_add_label_error_is_ignored(self, mock_tea_cls: MagicMock) -> None:
|
def test_tea_add_label_error_is_ignored(self, mock_tea_cls: MagicMock, mock_login: MagicMock) -> None:
|
||||||
"""If adding label fails via tea, issue is still reported as created."""
|
"""If adding label fails via tea, issue is still reported as created."""
|
||||||
mock_tea = MagicMock()
|
mock_tea = MagicMock()
|
||||||
mock_tea.list_labels.return_value = [{"id": 5, "name": "bug"}]
|
mock_tea.list_labels.return_value = [{"id": 5, "name": "bug"}]
|
||||||
@@ -105,8 +112,9 @@ class TestNotifyFailure:
|
|||||||
assert result.exit_code == 0
|
assert result.exit_code == 0
|
||||||
assert "issue #51" in result.output
|
assert "issue #51" in result.output
|
||||||
|
|
||||||
|
@patch("devx.gitea_cli.configure_tea_login")
|
||||||
@patch.dict("os.environ", {"CI_GITEA_TOKEN": ""}, clear=True)
|
@patch.dict("os.environ", {"CI_GITEA_TOKEN": ""}, clear=True)
|
||||||
def test_missing_token_exits(self) -> None:
|
def test_missing_token_exits(self, mock_login: MagicMock) -> None:
|
||||||
runner = CliRunner()
|
runner = CliRunner()
|
||||||
result = runner.invoke(
|
result = runner.invoke(
|
||||||
main,
|
main,
|
||||||
@@ -115,10 +123,13 @@ class TestNotifyFailure:
|
|||||||
assert result.exit_code != 0
|
assert result.exit_code != 0
|
||||||
assert "CI_GITEA_TOKEN" in result.output
|
assert "CI_GITEA_TOKEN" in result.output
|
||||||
|
|
||||||
|
@patch("devx.gitea_cli.configure_tea_login")
|
||||||
@patch.dict("os.environ", {"CI_GITEA_TOKEN": "tok"})
|
@patch.dict("os.environ", {"CI_GITEA_TOKEN": "tok"})
|
||||||
@patch("devx.gitea_cli.shutil.which", return_value=None)
|
@patch("devx.gitea_cli.shutil.which", return_value=None)
|
||||||
@patch("devx.ci.notify_failure.TeaCLI")
|
@patch("devx.ci.notify_failure.TeaCLI")
|
||||||
def test_auto_login_no_tea_skips(self, mock_tea_cls: MagicMock, mock_which: MagicMock) -> None:
|
def test_auto_login_no_tea_skips(
|
||||||
|
self, mock_tea_cls: MagicMock, mock_which: MagicMock, mock_login: MagicMock
|
||||||
|
) -> None:
|
||||||
"""--auto-login with tea not installed skips login and still creates issue."""
|
"""--auto-login with tea not installed skips login and still creates issue."""
|
||||||
mock_tea = MagicMock()
|
mock_tea = MagicMock()
|
||||||
mock_tea.list_labels.return_value = []
|
mock_tea.list_labels.return_value = []
|
||||||
@@ -133,10 +144,13 @@ class TestNotifyFailure:
|
|||||||
assert result.exit_code == 0
|
assert result.exit_code == 0
|
||||||
assert "issue #60" in result.output
|
assert "issue #60" in result.output
|
||||||
|
|
||||||
|
@patch("devx.gitea_cli.configure_tea_login")
|
||||||
@patch.dict("os.environ", {"CI_GITEA_TOKEN": ""}, clear=True)
|
@patch.dict("os.environ", {"CI_GITEA_TOKEN": ""}, clear=True)
|
||||||
@patch("devx.gitea_cli.shutil.which", return_value="/usr/bin/tea")
|
@patch("devx.gitea_cli.shutil.which", return_value="/usr/bin/tea")
|
||||||
@patch("devx.ci.notify_failure.TeaCLI")
|
@patch("devx.ci.notify_failure.TeaCLI")
|
||||||
def test_auto_login_no_token_skips_login(self, mock_tea_cls: MagicMock, mock_which: MagicMock) -> None:
|
def test_auto_login_no_token_skips_login(
|
||||||
|
self, mock_tea_cls: MagicMock, mock_which: MagicMock, mock_login: MagicMock
|
||||||
|
) -> None:
|
||||||
"""--auto-login with no CI_GITEA_TOKEN skips login but raises before creating issue."""
|
"""--auto-login with no CI_GITEA_TOKEN skips login but raises before creating issue."""
|
||||||
mock_tea = MagicMock()
|
mock_tea = MagicMock()
|
||||||
mock_tea_cls.return_value = mock_tea
|
mock_tea_cls.return_value = mock_tea
|
||||||
|
|||||||
@@ -91,9 +91,14 @@ class TestResolveTaskId:
|
|||||||
|
|
||||||
|
|
||||||
class TestMain:
|
class TestMain:
|
||||||
|
@patch("devx.ci.post_merge.subprocess.run")
|
||||||
|
@patch("devx.ci.post_merge._get_git_commit_message", return_value="msg")
|
||||||
|
@patch("devx.ci.post_merge._get_git_commit_sha", return_value="sha")
|
||||||
@patch.dict("os.environ", {"VIKUNJA_TOKEN": "tok"})
|
@patch.dict("os.environ", {"VIKUNJA_TOKEN": "tok"})
|
||||||
@patch("devx.ci.post_merge.VikunjaClient")
|
@patch("devx.ci.post_merge.VikunjaClient")
|
||||||
def test_full_flow(self, mock_client_cls: MagicMock) -> None:
|
def test_full_flow(
|
||||||
|
self, mock_client_cls: MagicMock, mock_msg: MagicMock, mock_sha: MagicMock, mock_subproc: MagicMock
|
||||||
|
) -> None:
|
||||||
mock_client = MagicMock()
|
mock_client = MagicMock()
|
||||||
mock_client.list_project_tasks.return_value = [
|
mock_client.list_project_tasks.return_value = [
|
||||||
{"id": 267, "identifier": "DEVX-20"},
|
{"id": 267, "identifier": "DEVX-20"},
|
||||||
@@ -109,9 +114,14 @@ class TestMain:
|
|||||||
mock_client.post_comment.assert_called_once()
|
mock_client.post_comment.assert_called_once()
|
||||||
mock_client.update_task.assert_called_once_with(267, done=True)
|
mock_client.update_task.assert_called_once_with(267, done=True)
|
||||||
|
|
||||||
|
@patch("devx.ci.post_merge.subprocess.run")
|
||||||
|
@patch("devx.ci.post_merge._get_git_commit_message", return_value="msg")
|
||||||
|
@patch("devx.ci.post_merge._get_git_commit_sha", return_value="sha")
|
||||||
@patch.dict("os.environ", {"VIKUNJA_TOKEN": "tok"})
|
@patch.dict("os.environ", {"VIKUNJA_TOKEN": "tok"})
|
||||||
@patch("devx.ci.post_merge.VikunjaClient")
|
@patch("devx.ci.post_merge.VikunjaClient")
|
||||||
def test_no_commit_sha(self, mock_client_cls: MagicMock) -> None:
|
def test_no_commit_sha(
|
||||||
|
self, mock_client_cls: MagicMock, mock_msg: MagicMock, mock_sha: MagicMock, mock_subproc: MagicMock
|
||||||
|
) -> None:
|
||||||
mock_client = MagicMock()
|
mock_client = MagicMock()
|
||||||
mock_client.list_project_tasks.return_value = [
|
mock_client.list_project_tasks.return_value = [
|
||||||
{"id": 267, "identifier": "DEVX-20"},
|
{"id": 267, "identifier": "DEVX-20"},
|
||||||
@@ -124,31 +134,47 @@ class TestMain:
|
|||||||
args, _ = mock_client.post_comment.call_args
|
args, _ = mock_client.post_comment.call_args
|
||||||
assert "unknown" in args[1]
|
assert "unknown" in args[1]
|
||||||
|
|
||||||
|
@patch("devx.ci.post_merge.subprocess.run")
|
||||||
|
@patch("devx.ci.post_merge._get_git_commit_message", return_value="msg")
|
||||||
|
@patch("devx.ci.post_merge._get_git_commit_sha", return_value="sha")
|
||||||
@patch.dict("os.environ", {"VIKUNJA_TOKEN": ""}, clear=True)
|
@patch.dict("os.environ", {"VIKUNJA_TOKEN": ""}, clear=True)
|
||||||
def test_missing_token_exits(self) -> None:
|
def test_missing_token_exits(self, mock_msg: MagicMock, mock_sha: MagicMock, mock_subproc: MagicMock) -> None:
|
||||||
runner = CliRunner()
|
runner = CliRunner()
|
||||||
result = runner.invoke(main, ["DEVX-20: fix: bug"])
|
result = runner.invoke(main, ["DEVX-20: fix: bug"])
|
||||||
assert result.exit_code == 1
|
assert result.exit_code == 1
|
||||||
assert "VIKUNJA_TOKEN" in result.output
|
assert "VIKUNJA_TOKEN" in result.output
|
||||||
|
|
||||||
|
@patch("devx.ci.post_merge.subprocess.run")
|
||||||
|
@patch("devx.ci.post_merge._get_git_commit_message", return_value="msg")
|
||||||
|
@patch("devx.ci.post_merge._get_git_commit_sha", return_value="sha")
|
||||||
@patch.dict("os.environ", {"VIKUNJA_TOKEN": "tok"})
|
@patch.dict("os.environ", {"VIKUNJA_TOKEN": "tok"})
|
||||||
def test_no_task_id_non_release_fails(self) -> None:
|
def test_no_task_id_non_release_fails(
|
||||||
|
self, mock_msg: MagicMock, mock_sha: MagicMock, mock_subproc: MagicMock
|
||||||
|
) -> None:
|
||||||
"""Non-release commits without DEVX-N prefix should fail."""
|
"""Non-release commits without DEVX-N prefix should fail."""
|
||||||
runner = CliRunner()
|
runner = CliRunner()
|
||||||
result = runner.invoke(main, ["fix: resolve bug"])
|
result = runner.invoke(main, ["fix: resolve bug"])
|
||||||
assert result.exit_code != 0
|
assert result.exit_code != 0
|
||||||
assert "No task ID" in result.output
|
assert "No task ID" in result.output
|
||||||
|
|
||||||
|
@patch("devx.ci.post_merge.subprocess.run")
|
||||||
|
@patch("devx.ci.post_merge._get_git_commit_message", return_value="msg")
|
||||||
|
@patch("devx.ci.post_merge._get_git_commit_sha", return_value="sha")
|
||||||
@patch.dict("os.environ", {"VIKUNJA_TOKEN": "tok"})
|
@patch.dict("os.environ", {"VIKUNJA_TOKEN": "tok"})
|
||||||
def test_release_commit_without_task_id_skips(self) -> None:
|
def test_release_commit_without_task_id_skips(
|
||||||
|
self, mock_msg: MagicMock, mock_sha: MagicMock, mock_subproc: MagicMock
|
||||||
|
) -> None:
|
||||||
"""Release commits without DEVX-N prefix should skip gracefully."""
|
"""Release commits without DEVX-N prefix should skip gracefully."""
|
||||||
runner = CliRunner()
|
runner = CliRunner()
|
||||||
result = runner.invoke(main, ["release: v0.3.2"])
|
result = runner.invoke(main, ["release: v0.3.2"])
|
||||||
assert result.exit_code == 0
|
assert result.exit_code == 0
|
||||||
assert "skipping" in result.output
|
assert "skipping" in result.output
|
||||||
|
|
||||||
|
@patch("devx.ci.post_merge.subprocess.run")
|
||||||
|
@patch("devx.ci.post_merge._get_git_commit_message", return_value="msg")
|
||||||
|
@patch("devx.ci.post_merge._get_git_commit_sha", return_value="sha")
|
||||||
@patch.dict("os.environ", {"VIKUNJA_TOKEN": "tok"})
|
@patch.dict("os.environ", {"VIKUNJA_TOKEN": "tok"})
|
||||||
def test_revert_commit_skips(self) -> None:
|
def test_revert_commit_skips(self, mock_msg: MagicMock, mock_sha: MagicMock, mock_subproc: MagicMock) -> None:
|
||||||
"""Revert commits without DEVX-N prefix should skip gracefully."""
|
"""Revert commits without DEVX-N prefix should skip gracefully."""
|
||||||
runner = CliRunner()
|
runner = CliRunner()
|
||||||
result = runner.invoke(main, ["revert: remove v0.6.0 release"])
|
result = runner.invoke(main, ["revert: remove v0.6.0 release"])
|
||||||
@@ -156,17 +182,25 @@ class TestMain:
|
|||||||
assert "Infrastructure commit" in result.output
|
assert "Infrastructure commit" in result.output
|
||||||
assert "skipping" in result.output
|
assert "skipping" in result.output
|
||||||
|
|
||||||
|
@patch("devx.ci.post_merge.subprocess.run")
|
||||||
|
@patch("devx.ci.post_merge._get_git_commit_message", return_value="msg")
|
||||||
|
@patch("devx.ci.post_merge._get_git_commit_sha", return_value="sha")
|
||||||
@patch.dict("os.environ", {"VIKUNJA_TOKEN": "tok"})
|
@patch.dict("os.environ", {"VIKUNJA_TOKEN": "tok"})
|
||||||
def test_merge_commit_skips(self) -> None:
|
def test_merge_commit_skips(self, mock_msg: MagicMock, mock_sha: MagicMock, mock_subproc: MagicMock) -> None:
|
||||||
"""Merge commits without DEVX-N prefix should skip gracefully."""
|
"""Merge commits without DEVX-N prefix should skip gracefully."""
|
||||||
runner = CliRunner()
|
runner = CliRunner()
|
||||||
result = runner.invoke(main, ["Merge pull request #42"])
|
result = runner.invoke(main, ["Merge pull request #42"])
|
||||||
assert result.exit_code == 0
|
assert result.exit_code == 0
|
||||||
assert "Infrastructure commit" in result.output
|
assert "Infrastructure commit" in result.output
|
||||||
|
|
||||||
|
@patch("devx.ci.post_merge.subprocess.run")
|
||||||
|
@patch("devx.ci.post_merge._get_git_commit_message", return_value="msg")
|
||||||
|
@patch("devx.ci.post_merge._get_git_commit_sha", return_value="sha")
|
||||||
@patch.dict("os.environ", {"VIKUNJA_TOKEN": "tok"})
|
@patch.dict("os.environ", {"VIKUNJA_TOKEN": "tok"})
|
||||||
@patch("devx.ci.post_merge.VikunjaClient")
|
@patch("devx.ci.post_merge.VikunjaClient")
|
||||||
def test_resolve_failure_fails(self, mock_client_cls: MagicMock) -> None:
|
def test_resolve_failure_fails(
|
||||||
|
self, mock_client_cls: MagicMock, mock_msg: MagicMock, mock_sha: MagicMock, mock_subproc: MagicMock
|
||||||
|
) -> None:
|
||||||
"""Missing Vikunja task is a fatal error — every PR must have a task."""
|
"""Missing Vikunja task is a fatal error — every PR must have a task."""
|
||||||
mock_client = MagicMock()
|
mock_client = MagicMock()
|
||||||
mock_client.list_project_tasks.return_value = []
|
mock_client.list_project_tasks.return_value = []
|
||||||
@@ -176,9 +210,14 @@ class TestMain:
|
|||||||
assert result.exit_code != 0
|
assert result.exit_code != 0
|
||||||
assert "Could not find" in result.output
|
assert "Could not find" in result.output
|
||||||
|
|
||||||
|
@patch("devx.ci.post_merge.subprocess.run")
|
||||||
|
@patch("devx.ci.post_merge._get_git_commit_message", return_value="msg")
|
||||||
|
@patch("devx.ci.post_merge._get_git_commit_sha", return_value="sha")
|
||||||
@patch.dict("os.environ", {"VIKUNJA_TOKEN": "tok"})
|
@patch.dict("os.environ", {"VIKUNJA_TOKEN": "tok"})
|
||||||
@patch("devx.ci.post_merge.VikunjaClient")
|
@patch("devx.ci.post_merge.VikunjaClient")
|
||||||
def test_post_comment_failure_fails(self, mock_client_cls: MagicMock) -> None:
|
def test_post_comment_failure_fails(
|
||||||
|
self, mock_client_cls: MagicMock, mock_msg: MagicMock, mock_sha: MagicMock, mock_subproc: MagicMock
|
||||||
|
) -> None:
|
||||||
"""Vikunja API errors should fail — the task was not updated."""
|
"""Vikunja API errors should fail — the task was not updated."""
|
||||||
mock_client = MagicMock()
|
mock_client = MagicMock()
|
||||||
mock_client.list_project_tasks.return_value = [
|
mock_client.list_project_tasks.return_value = [
|
||||||
@@ -191,9 +230,14 @@ class TestMain:
|
|||||||
assert result.exit_code != 0
|
assert result.exit_code != 0
|
||||||
assert "Vikunja API error" in result.output
|
assert "Vikunja API error" in result.output
|
||||||
|
|
||||||
|
@patch("devx.ci.post_merge.subprocess.run")
|
||||||
|
@patch("devx.ci.post_merge._get_git_commit_message", return_value="msg")
|
||||||
|
@patch("devx.ci.post_merge._get_git_commit_sha", return_value="sha")
|
||||||
@patch.dict("os.environ", {"VIKUNJA_TOKEN": "tok"})
|
@patch.dict("os.environ", {"VIKUNJA_TOKEN": "tok"})
|
||||||
@patch("devx.ci.post_merge.VikunjaClient")
|
@patch("devx.ci.post_merge.VikunjaClient")
|
||||||
def test_mark_done_failure_fails(self, mock_client_cls: MagicMock) -> None:
|
def test_mark_done_failure_fails(
|
||||||
|
self, mock_client_cls: MagicMock, mock_msg: MagicMock, mock_sha: MagicMock, mock_subproc: MagicMock
|
||||||
|
) -> None:
|
||||||
"""Vikunja API errors should fail — the task was not updated."""
|
"""Vikunja API errors should fail — the task was not updated."""
|
||||||
mock_client = MagicMock()
|
mock_client = MagicMock()
|
||||||
mock_client.list_project_tasks.return_value = [
|
mock_client.list_project_tasks.return_value = [
|
||||||
@@ -235,11 +279,14 @@ class TestGetGitCommitSha:
|
|||||||
|
|
||||||
|
|
||||||
class TestFromGit:
|
class TestFromGit:
|
||||||
|
@patch("devx.ci.post_merge.subprocess.run")
|
||||||
@patch.dict("os.environ", {"VIKUNJA_TOKEN": "tok"})
|
@patch.dict("os.environ", {"VIKUNJA_TOKEN": "tok"})
|
||||||
@patch("devx.ci.post_merge.VikunjaClient")
|
@patch("devx.ci.post_merge.VikunjaClient")
|
||||||
@patch("devx.ci.post_merge._get_git_commit_sha", return_value="abc123")
|
@patch("devx.ci.post_merge._get_git_commit_sha", return_value="abc123")
|
||||||
@patch("devx.ci.post_merge._get_git_commit_message", return_value="DEVX-20: fix: bug")
|
@patch("devx.ci.post_merge._get_git_commit_message", return_value="DEVX-20: fix: bug")
|
||||||
def test_from_git(self, mock_msg: MagicMock, mock_sha: MagicMock, mock_client_cls: MagicMock) -> None:
|
def test_from_git(
|
||||||
|
self, mock_msg: MagicMock, mock_sha: MagicMock, mock_client_cls: MagicMock, mock_subproc: MagicMock
|
||||||
|
) -> None:
|
||||||
mock_client = MagicMock()
|
mock_client = MagicMock()
|
||||||
mock_client.list_project_tasks.return_value = [
|
mock_client.list_project_tasks.return_value = [
|
||||||
{"id": 267, "identifier": "DEVX-20"},
|
{"id": 267, "identifier": "DEVX-20"},
|
||||||
@@ -250,12 +297,13 @@ class TestFromGit:
|
|||||||
assert result.exit_code == 0
|
assert result.exit_code == 0
|
||||||
assert "updated and marked done" in result.output
|
assert "updated and marked done" in result.output
|
||||||
|
|
||||||
|
@patch("devx.ci.post_merge.subprocess.run")
|
||||||
@patch.dict("os.environ", {"VIKUNJA_TOKEN": "tok"})
|
@patch.dict("os.environ", {"VIKUNJA_TOKEN": "tok"})
|
||||||
@patch("devx.ci.post_merge.VikunjaClient")
|
@patch("devx.ci.post_merge.VikunjaClient")
|
||||||
@patch("devx.ci.post_merge._get_git_commit_sha", return_value="abc123")
|
@patch("devx.ci.post_merge._get_git_commit_sha", return_value="abc123")
|
||||||
@patch("devx.ci.post_merge._get_git_commit_message", return_value="DEVX-20: fix: bug")
|
@patch("devx.ci.post_merge._get_git_commit_message", return_value="DEVX-20: fix: bug")
|
||||||
def test_from_git_with_explicit_sha(
|
def test_from_git_with_explicit_sha(
|
||||||
self, mock_msg: MagicMock, mock_sha: MagicMock, mock_client_cls: MagicMock
|
self, mock_msg: MagicMock, mock_sha: MagicMock, mock_client_cls: MagicMock, mock_subproc: MagicMock
|
||||||
) -> None:
|
) -> None:
|
||||||
mock_client = MagicMock()
|
mock_client = MagicMock()
|
||||||
mock_client.list_project_tasks.return_value = [
|
mock_client.list_project_tasks.return_value = [
|
||||||
@@ -266,8 +314,11 @@ class TestFromGit:
|
|||||||
result = runner.invoke(main, ["--from-git", "--commit-sha", "explicit_sha"])
|
result = runner.invoke(main, ["--from-git", "--commit-sha", "explicit_sha"])
|
||||||
assert result.exit_code == 0
|
assert result.exit_code == 0
|
||||||
|
|
||||||
|
@patch("devx.ci.post_merge.subprocess.run")
|
||||||
|
@patch("devx.ci.post_merge._get_git_commit_message", return_value="msg")
|
||||||
|
@patch("devx.ci.post_merge._get_git_commit_sha", return_value="sha")
|
||||||
@patch.dict("os.environ", {"VIKUNJA_TOKEN": "tok"})
|
@patch.dict("os.environ", {"VIKUNJA_TOKEN": "tok"})
|
||||||
def test_no_msg_and_no_from_git(self) -> None:
|
def test_no_msg_and_no_from_git(self, mock_msg: MagicMock, mock_sha: MagicMock, mock_subproc: MagicMock) -> None:
|
||||||
runner = CliRunner()
|
runner = CliRunner()
|
||||||
result = runner.invoke(main, [])
|
result = runner.invoke(main, [])
|
||||||
assert result.exit_code != 0
|
assert result.exit_code != 0
|
||||||
|
|||||||
@@ -11,7 +11,8 @@ from devx.tools.pr_label import cli
|
|||||||
|
|
||||||
|
|
||||||
class TestCli:
|
class TestCli:
|
||||||
def test_no_token_raises(self, monkeypatch: pytest.MonkeyPatch) -> None:
|
@patch("devx.tools.pr_status.subprocess.run")
|
||||||
|
def test_no_token_raises(self, mock_subproc: MagicMock, monkeypatch: pytest.MonkeyPatch) -> None:
|
||||||
for name in ("DEVELOPER_GITEA_API_TOKEN", "CI_GITEA_API_TOKEN", "CI_GITEA_TOKEN"):
|
for name in ("DEVELOPER_GITEA_API_TOKEN", "CI_GITEA_API_TOKEN", "CI_GITEA_TOKEN"):
|
||||||
monkeypatch.delenv(name, raising=False)
|
monkeypatch.delenv(name, raising=False)
|
||||||
runner = CliRunner()
|
runner = CliRunner()
|
||||||
@@ -23,16 +24,20 @@ class TestCli:
|
|||||||
assert result.exit_code != 0
|
assert result.exit_code != 0
|
||||||
assert "CI_GITEA_TOKEN" in result.output
|
assert "CI_GITEA_TOKEN" in result.output
|
||||||
|
|
||||||
|
@patch("devx.tools.pr_status.subprocess.run")
|
||||||
@patch("devx.tools.pr_label.REPO_OWNER", "")
|
@patch("devx.tools.pr_label.REPO_OWNER", "")
|
||||||
def test_no_owner_raises(self, monkeypatch: pytest.MonkeyPatch) -> None:
|
def test_no_owner_raises(self, mock_subproc: MagicMock, monkeypatch: pytest.MonkeyPatch) -> None:
|
||||||
monkeypatch.setenv("CI_GITEA_TOKEN", "tok")
|
monkeypatch.setenv("CI_GITEA_TOKEN", "tok")
|
||||||
runner = CliRunner()
|
runner = CliRunner()
|
||||||
result = runner.invoke(cli, ["--pr", "42", "--label", "ready-to-merge"])
|
result = runner.invoke(cli, ["--pr", "42", "--label", "ready-to-merge"])
|
||||||
assert result.exit_code != 0
|
assert result.exit_code != 0
|
||||||
assert "owner" in result.output.lower()
|
assert "owner" in result.output.lower()
|
||||||
|
|
||||||
|
@patch("devx.tools.pr_status.subprocess.run")
|
||||||
@patch("devx.tools.pr_label.GiteaClient")
|
@patch("devx.tools.pr_label.GiteaClient")
|
||||||
def test_adds_new_label(self, mock_client_cls: MagicMock, monkeypatch: pytest.MonkeyPatch) -> None:
|
def test_adds_new_label(
|
||||||
|
self, mock_client_cls: MagicMock, mock_subproc: MagicMock, monkeypatch: pytest.MonkeyPatch
|
||||||
|
) -> None:
|
||||||
monkeypatch.setenv("CI_GITEA_TOKEN", "tok")
|
monkeypatch.setenv("CI_GITEA_TOKEN", "tok")
|
||||||
monkeypatch.setenv("DEVX_REPO_OWNER", "owner")
|
monkeypatch.setenv("DEVX_REPO_OWNER", "owner")
|
||||||
monkeypatch.setenv("DEVX_REPO_NAME", "repo")
|
monkeypatch.setenv("DEVX_REPO_NAME", "repo")
|
||||||
@@ -44,8 +49,11 @@ class TestCli:
|
|||||||
client.add_pr_label.assert_called_once_with(42, ["ready-to-merge"])
|
client.add_pr_label.assert_called_once_with(42, ["ready-to-merge"])
|
||||||
assert "Added label" in result.output
|
assert "Added label" in result.output
|
||||||
|
|
||||||
|
@patch("devx.tools.pr_status.subprocess.run")
|
||||||
@patch("devx.tools.pr_label.GiteaClient")
|
@patch("devx.tools.pr_label.GiteaClient")
|
||||||
def test_skips_existing_label(self, mock_client_cls: MagicMock, monkeypatch: pytest.MonkeyPatch) -> None:
|
def test_skips_existing_label(
|
||||||
|
self, mock_client_cls: MagicMock, mock_subproc: MagicMock, monkeypatch: pytest.MonkeyPatch
|
||||||
|
) -> None:
|
||||||
monkeypatch.setenv("CI_GITEA_TOKEN", "tok")
|
monkeypatch.setenv("CI_GITEA_TOKEN", "tok")
|
||||||
monkeypatch.setenv("DEVX_REPO_OWNER", "owner")
|
monkeypatch.setenv("DEVX_REPO_OWNER", "owner")
|
||||||
monkeypatch.setenv("DEVX_REPO_NAME", "repo")
|
monkeypatch.setenv("DEVX_REPO_NAME", "repo")
|
||||||
@@ -57,8 +65,11 @@ class TestCli:
|
|||||||
client.add_pr_label.assert_not_called()
|
client.add_pr_label.assert_not_called()
|
||||||
assert "already" in result.output
|
assert "already" in result.output
|
||||||
|
|
||||||
|
@patch("devx.tools.pr_status.subprocess.run")
|
||||||
@patch("devx.tools.pr_label.GiteaClient")
|
@patch("devx.tools.pr_label.GiteaClient")
|
||||||
def test_mixed_new_and_existing(self, mock_client_cls: MagicMock, monkeypatch: pytest.MonkeyPatch) -> None:
|
def test_mixed_new_and_existing(
|
||||||
|
self, mock_client_cls: MagicMock, mock_subproc: MagicMock, monkeypatch: pytest.MonkeyPatch
|
||||||
|
) -> None:
|
||||||
monkeypatch.setenv("CI_GITEA_TOKEN", "tok")
|
monkeypatch.setenv("CI_GITEA_TOKEN", "tok")
|
||||||
monkeypatch.setenv("DEVX_REPO_OWNER", "owner")
|
monkeypatch.setenv("DEVX_REPO_OWNER", "owner")
|
||||||
monkeypatch.setenv("DEVX_REPO_NAME", "repo")
|
monkeypatch.setenv("DEVX_REPO_NAME", "repo")
|
||||||
|
|||||||
Some files were not shown because too many files have changed in this diff Show More
Reference in New Issue
Block a user