From 1dd0e2f4b9d366d4a977176b2d8ad106d84806ed Mon Sep 17 00:00:00 2001 From: Bernardo Magri Date: Fri, 29 May 2026 21:36:51 +0100 Subject: [PATCH] ci: move workflow to .gitea/workflows so Gitea picks it up Gitea only scans .gitea/workflows and .github/workflows; it does not scan .forgejo/workflows (that path is Forgejo-only). The CI was therefore dormant on a Gitea instance regardless of whether Actions was enabled. git mv to .gitea/workflows/ (scanned by both Gitea and Forgejo). Updated the live references in STRUCTURE.md (Gitea + act_runner), AGENT.md, and today's ROADMAP entry; left the dated historical Shipped entries as the changelog they are. Co-Authored-By: Claude Opus 4.8 --- {.forgejo => .gitea}/workflows/check.yml | 0 docs/AGENT.md | 2 +- docs/ROADMAP.md | 2 +- docs/STRUCTURE.md | 2 +- 4 files changed, 3 insertions(+), 3 deletions(-) rename {.forgejo => .gitea}/workflows/check.yml (100%) diff --git a/.forgejo/workflows/check.yml b/.gitea/workflows/check.yml similarity index 100% rename from .forgejo/workflows/check.yml rename to .gitea/workflows/check.yml diff --git a/docs/AGENT.md b/docs/AGENT.md index ce93bd4..bb36857 100644 --- a/docs/AGENT.md +++ b/docs/AGENT.md @@ -147,7 +147,7 @@ Steps you should follow for any non-trivial change: ```bash ./bin/utils/nomarchy-eval-matrix ``` - When you **add or rename an opt-in `nomarchy.*` option**, add a matching scenario to the `toggleScenarios` attrset in that script — otherwise the new surface is unverified and the next eval-time bug in it ships silently (this is exactly how the impermanence assertion and the vscode option rename reached `main`). The matrix also runs in CI (`.forgejo/workflows/check.yml`). + When you **add or rename an opt-in `nomarchy.*` option**, add a matching scenario to the `toggleScenarios` attrset in that script — otherwise the new surface is unverified and the next eval-time bug in it ships silently (this is exactly how the impermanence assertion and the vscode option rename reached `main`). The matrix also runs in CI (`.gitea/workflows/check.yml`). First clone? Enable the repo's pre-commit hook so `docs/SCRIPTS.md` regenerates whenever you add/modify/remove a `nomarchy-*` script: ```bash git config core.hooksPath .githooks diff --git a/docs/ROADMAP.md b/docs/ROADMAP.md index 6043e38..fd4f507 100644 --- a/docs/ROADMAP.md +++ b/docs/ROADMAP.md @@ -147,7 +147,7 @@ Pillar is **done** when every component has a closed `wave/qa-` PR an (Move items here when they land — keep them brief, link the commit/PR.) -- _2026-05-29_ — **Pillar 7: opt-in toggle eval matrix in CI.** `nix flake check --no-build` only evaluates the four default `nixosConfigurations`/`homeConfigurations`, so any eval-time bug that *only* fires when a `nomarchy.*` toggle is flipped sailed straight through — exactly how the vscode option rename and the impermanence systemd-stage-1 assertion both reached `main` undetected. New `bin/utils/nomarchy-eval-matrix` layers each opt-in scenario (16 toggles: impermanence single/multi, laptop/desktop presets, accessibility, gaming, hybridGPU, hibernation, docker, fwupd, overrides, panel position, keymap variant, toggles-off — plus home + system halves) onto `nixosConfigurations.default` via `extendModules` and forces `system.build.toplevel.drvPath` (which forces the assertion checks); it also forces all 21 palettes through the system-side Plymouth `base00`→RGB-float math that the home-only `allThemeVariants` never reaches, and both standalone `homeConfigurations`. Per-scenario results come from `builtins.tryEval` so one failure doesn't mask the rest — verified the harness goes red on both a failed assertion (re-injected `boot.initrd.postDeviceCommands`) and a nonexistent-option ref, and green on the current tree (all 39 scenarios pass). Wired into `.forgejo/workflows/check.yml` as a step after `flake check`, with `jq` supplied via `nix shell` so it doesn't depend on the runner image. `docs/AGENT.md` §5.5 now instructs: when you add or rename an opt-in `nomarchy.*` option, add a matching scenario to the script's `toggleScenarios` attrset. +- _2026-05-29_ — **Pillar 7: opt-in toggle eval matrix in CI.** `nix flake check --no-build` only evaluates the four default `nixosConfigurations`/`homeConfigurations`, so any eval-time bug that *only* fires when a `nomarchy.*` toggle is flipped sailed straight through — exactly how the vscode option rename and the impermanence systemd-stage-1 assertion both reached `main` undetected. New `bin/utils/nomarchy-eval-matrix` layers each opt-in scenario (16 toggles: impermanence single/multi, laptop/desktop presets, accessibility, gaming, hybridGPU, hibernation, docker, fwupd, overrides, panel position, keymap variant, toggles-off — plus home + system halves) onto `nixosConfigurations.default` via `extendModules` and forces `system.build.toplevel.drvPath` (which forces the assertion checks); it also forces all 21 palettes through the system-side Plymouth `base00`→RGB-float math that the home-only `allThemeVariants` never reaches, and both standalone `homeConfigurations`. Per-scenario results come from `builtins.tryEval` so one failure doesn't mask the rest — verified the harness goes red on both a failed assertion (re-injected `boot.initrd.postDeviceCommands`) and a nonexistent-option ref, and green on the current tree (all 39 scenarios pass). Wired into `.gitea/workflows/check.yml` as a step after `flake check`, with `jq` supplied via `nix shell` so it doesn't depend on the runner image. `docs/AGENT.md` §5.5 now instructs: when you add or rename an opt-in `nomarchy.*` option, add a matching scenario to the script's `toggleScenarios` attrset. - _2026-05-29_ — **Impermanence rollback no longer fails to build.** `core/system/impermanence.nix` implemented the Erase-Your-Darlings root wipe via `boot.initrd.postDeviceCommands`, but `themes/engine/plymouth.nix:63` sets `boot.initrd.systemd.enable = true` distro-wide (Plymouth is imported unconditionally from `core/system/default.nix`), and systemd stage-1 initrd hard-rejects `postDeviceCommands` with a failed assertion. Net effect: **every** install that flipped `nomarchy.system.impermanence.enable = true` — including any user who picked impermanence at the installer prompt — produced a config that wouldn't evaluate, let alone boot. Converted the rollback into a `boot.initrd.systemd.services.nomarchy-rollback` oneshot unit ordered `after = systemd-cryptsetup@${mainLuksName}.service` and `before = sysroot.mount`, with `boot.initrd.systemd.initrdBin` pulling in `btrfs-progs` / `coreutils` / `util-linux` / `findutils` (the systemd initrd doesn't ship them by default, unlike the old scripted initrd). Script body (timestamped `@` → `old_roots` move, 30-day recursive subvolume GC, `root-blank` → `@` snapshot) is unchanged. Verified the assertion is gone and `nixosConfigurations.default` + `impermanence.enable` evaluates fully via `extendModules`. **Runtime-verification caveat:** the boot-time wipe semantics (the `[[ ]]`/function/IFS shell idioms and the cleanup loop under the systemd initrd shell, plus correct ordering vs the LUKS mapping) can only be confirmed by a real wipe-boot cycle on an impermanence install — fold into the Pillar 8 punch-list. `docs/TROUBLESHOOTING.md` persistence-block line reference updated (46-72 → 91-120). diff --git a/docs/STRUCTURE.md b/docs/STRUCTURE.md index 86d9c1e..e715684 100644 --- a/docs/STRUCTURE.md +++ b/docs/STRUCTURE.md @@ -44,7 +44,7 @@ While the system is defined declaratively, Nomarchy uses a small, local state fi - **`SCRIPTS.md`**: Auto-generated `nomarchy-*` script audit. - **`TROUBLESHOOTING.md`**: Common rebuild errors and fixes. - **`creating-themes.md`**: Theme palette authoring guide. -- **`.forgejo/workflows/`**: Forgejo Actions CI. Runs `nix flake check --no-build`, lints every `nomarchy-*` bash script with `bash -n` + `shellcheck --severity=error`, and verifies `docs/SCRIPTS.md` is up to date on every push to `main` and every PR. To activate: enable Actions on the repo in Forgejo and register a `forgejo-runner` (any Docker-capable Linux host works; the workflow uses `ubuntu-latest` and installs Nix itself). +- **`.gitea/workflows/`**: Gitea/Forgejo Actions CI (the `.gitea/` path is scanned by both Gitea and Forgejo; `.forgejo/` is *not* scanned by Gitea). Runs `nix flake check --no-build`, the opt-in toggle eval matrix (`bin/utils/nomarchy-eval-matrix`), lints every `nomarchy-*` bash script with `bash -n` + `shellcheck --severity=error`, and verifies `docs/SCRIPTS.md` is up to date on every push to `main` and every PR. To activate: enable Actions on the repo and register an `act_runner` (any Docker-capable Linux host works — including the Gitea server itself; the workflow uses `ubuntu-latest` and installs Nix itself). - **`.githooks/`**: Optional per-clone git hooks (`pre-commit` lints changed scripts and regenerates `docs/SCRIPTS.md`). Enable with `git config core.hooksPath .githooks`. CI enforces the same invariants tree-wide. ---