feat: PowerShell 7 preflight and launcher - preflight.ps1, wikitool.ps1, doctor policy and Mark of the Web checks, pwsh CI job (#151, B)
CI / verify (push) Successful in 2m16s
CI / pwsh (push) Successful in 1m24s
Release / release (push) Successful in 37s

Files changed:
- .gitea/workflows/ci.yml
- CHANGES.md
- INSTALL.md
- README.md
- VERSION
- docs/why-gates-are-code.md
- instructions/bootstrap.md
- instructions/bug-report.md
- instructions/preflight.md
- instructions/setup-instance.md
- instructions/upgrade-instance.md
- tools/CONTRACT.md
- tools/README.md
- tools/bugreport.py
- tools/chemenu/cli.py
- tools/chemenu/commands/dist_cmd.py
- tools/chemenu/commands/doctor.py
- tools/chemenu/prerequisites.py
- tools/chemenu/tests/conftest.py
- tools/chemenu/tests/test_bugreport.py
- tools/chemenu/tests/test_doctor.py
- tools/chemenu/tests/test_preflight.py
- tools/chemenu/tests/test_preflight_pwsh.py
- tools/chemenu/toolpaths.py
- tools/preflight.ps1
- tools/wikitool
- tools/wikitool.ps1
This commit is contained in:
torben committed 2026-10-01 09:52:05 +02:00
1 parent 4035b1ba12
commit 210e0c8286
27 files changed
+1513 -32

No files matched your search

+65 -3
View File
@@ -1,8 +1,14 @@
# CI for the wiki stack.
#
# One job, stopping at the first failure - the stack has no artifact to build
# and nothing to deploy, so the pipeline's whole job is "does the machinery
# still hold together, and does the distribution it produces still work".
# `verify` is the pipeline: one job, stopping at the first failure - the stack
# has no artifact to build and nothing to deploy, so its whole job is "does the
# machinery still hold together, and does the distribution it produces still
# work". `pwsh` beside it is the PowerShell half of the same question (Gitea
# #151): the same preflight and launcher, under the PowerShell 7 that Windows
# harnesses start them with, in the prebuilt `chemenu-ci-pwsh` image
# (`pwsh-ci-image.yml`). It runs on Linux, so what only a Windows machine can
# answer - the registry, the Store alias, a real Mark of the Web - is covered by
# the environment hooks `tools/preflight.ps1` documents, not by this job.
#
# Runner: `linux-docker` is one of this Gitea instance's three routing labels
# (alongside `container-builder` and `k3s-deploy`). The job image is named
@@ -327,3 +333,59 @@ jobs:
if path.is_file():
assert host not in path.read_text(encoding="utf-8", errors="replace"), path
PY
pwsh:
runs-on: linux-docker
container:
image: gitea.nehmer.net/torben/chemenu-ci-pwsh:latest
env:
WIKITOOL_SESSION_ID: ci-pwsh-${{ github.run_id }}
WIKI_TRACE_DIR: /tmp/wikitool-trace
steps:
- uses: actions/checkout@v7
- name: PSScriptAnalyzer
# Positional arguments are excluded: the rule is written for cmdlets, and the two
# scripts call their own small helpers positionally throughout. Everything else the
# analyzer knows must stay silent, which includes the ASCII-only and approved-verb rules.
run: |
set -eu
pwsh -NoProfile -Command '
$found = foreach ($script in Get-ChildItem tools -Filter *.ps1) {
Invoke-ScriptAnalyzer -Path $script.FullName -ExcludeRule PSAvoidUsingPositionalParameters
}
$found | Format-List RuleName, ScriptName, Line, Message | Out-String -Width 200 | Write-Output
if (@($found).Count -gt 0) { exit 1 }
'
- name: Preflight, twice, against the POSIX one
# The two preflights answer the same questions from the same list and must write the
# same file: that is what keeps a tools/wikitool launched from either shell starting
# the same git, rg and Python. The second run must change nothing.
run: |
set -eu
git config --global --add safe.directory "$GITHUB_WORKSPACE"
pwsh -NoProfile -ExecutionPolicy Bypass -File tools/preflight.ps1
cp .wikitool-tools.json /tmp/tools-pwsh.json
pwsh -NoProfile -ExecutionPolicy Bypass -File tools/preflight.ps1 > /tmp/preflight-second.txt
cmp .wikitool-tools.json /tmp/tools-pwsh.json
rm .wikitool-tools.json
tools/preflight.sh
cmp .wikitool-tools.json /tmp/tools-pwsh.json
tools/.venv/bin/python -m pip install --quiet pytest
- name: The launcher, started from PowerShell
# `tools/wikitool` from pwsh resolves to wikitool.ps1, not the sh launcher - the one
# thing a Linux shell cannot show, so it is asked for by that exact string.
run: |
set -eu
pwsh -NoProfile -Command './tools/wikitool version show'
- name: PowerShell tests
# Skipped everywhere without pwsh, so this is the run that counts. The `verify` job
# runs the rest of the suite.
run: |
set -eu
cd tools
.venv/bin/python -m pytest -q chemenu/tests/test_preflight_pwsh.py chemenu/tests/test_preflight.py chemenu/tests/test_doctor.py