feat(ci): checks-on-push workflow (Forgejo Actions, eval tier)

.forgejo/workflows/check.yml runs on every push to main/v1 (+ manual
dispatch): nix flake check --no-build (full module-system eval incl.
the downstream template through mkFlake), py_compile of
nomarchy-theme-sync, and bash -n over tracked .sh files. The always-on
net under direct-to-main pushes — first slice of the ROADMAP lock-bump
CI item.

Scoped to the eval tier deliberately: the instance's runner is an
act_runner docker container (no systemd, no /dev/kvm — established
from the legacy repo's .gitea/workflows/check.yml, which ran 57 times
on it), so the checks.* VM suite and real builds can't run there. A
commented vm-checks job documents the KVM-runner upgrade path; the
legacy workflow's container gotchas (nixbld setup for the single-user
installer, sandbox=false for Stylix IFD, Nix pinned 2.31.5 vs
lazy-trees, no JS actions past node20) are carried over verbatim in
the header. docs/TESTING.md §1b documents what a green run does and
does not mean.

Verified: V0 locally (the same check commands, minus the container
Nix install) + YAML parse. A real green run depends on the runner
still being registered — not API-visible unauthenticated, so that is
queued as [human] BACKLOG item 20.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
This commit is contained in:
Bernardo Magri
2026-07-04 09:20:45 +01:00
parent bc4e8e1410
commit 46af2f0632
5 changed files with 154 additions and 18 deletions

View File

@@ -22,20 +22,16 @@ next, in what order*.
## NOW
### 2. CI: run the check suite on every push (Forgejo Actions)
First slice of ROADMAP § Automated upstream lock bumps, promoted to NOW
because agents now push to `main` autonomously — an always-on net under
that is the single highest-stability lever available. A workflow that
runs `nix flake check` + the `checks.*` VM suite + a
`system.build.toplevel` build on push to `main`. **Why:** pillar 1;
today nothing re-verifies a push. **Done when:** the workflow exists,
is documented (docs/TESTING.md), and a red run is visible/notifiable;
the runner requirements (Linux + KVM for the VM checks, or a documented
no-KVM subset) are written down. **Verify:** V1 locally (the same
commands the workflow runs) + a real green run on the Forgejo instance
— if runner infra doesn't exist yet, deliver the workflow + a `[human]`
note on registering a runner. **Verify the runner half is possible
before promising it.**
### 20. Confirm the Forgejo runner is alive `[human]`
The checks-on-push workflow (`.forgejo/workflows/check.yml`) shipped;
the repo has `has_actions: true` and the legacy `check.yml` ran 57
times on an act_runner, but whether that runner still exists is not
API-visible without auth. Check the first run of the new workflow at
https://git.bemagri.xyz/bernardo/Nomarchy/actions — if it sits queued,
re-register an act_runner (docker, `ubuntu-latest` label). **Stretch:**
a second runner on a NixOS host with `/dev/kvm` (label `nix-kvm`) —
then uncomment the workflow's `vm-checks` job and the VM suite + real
builds run in CI too (that upgrades half of item 14 for free).
### 3. Memory-pressure protection (no more frozen desktops)
New. A workstation that compiles from source *will* hit memory
@@ -154,10 +150,13 @@ Each is a small, self-contained polish item in the existing patterns:
`SUPER+CTRL` bind; pairs naturally with theme work.
### 14. Automated upstream lock bumps (maintainer CI, slices b+c) `[big]`
ROADMAP § Automated upstream lock bumps — the scheduled half, after
NOW#2 lands: weekly job runs `nix flake update` (within pinned release
branches) → full check suite → lands on `main` on green; `v1` promotion
stays human. Plus the fast-lane note for security bumps.
ROADMAP § Automated upstream lock bumps — the scheduled half (the
checks-on-push workflow shipped; see item 20 for the runner status):
weekly job runs `nix flake update` (within pinned release branches) →
full check suite → lands on `main` on green; `v1` promotion stays
human. Plus the fast-lane note for security bumps. Note the current
runner is eval-only (no KVM) — a green bump run guards eval, not the VM
suite, until item 20's stretch runner exists.
### 15. Display profiles — docked/undocked switching
ROADMAP § Display / monitor management, remaining: true profile

View File

@@ -17,6 +17,25 @@ Template:
---
## 2026-07-04 — CI checks-on-push shipped (loop iteration #2)
- **Task:** BACKLOG NOW#2 — Forgejo Actions workflow.
- **Did:** `.forgejo/workflows/check.yml` (push to main/v1 + dispatch):
flake check --no-build, theme-sync py_compile, bash -n over tracked
.sh. Scoped to the **eval tier** deliberately — API probing +
archaeology of the legacy `.gitea/workflows/check.yml` (57 runs on
this instance) showed the runner is an act_runner docker container
(no KVM/systemd), so the VM suite can't run there; a commented
`vm-checks` job documents the KVM-runner upgrade path. Legacy's
hard-won container gotchas (nixbld setup, sandbox=false for Stylix
IFD, Nix 2.31.5 pin) carried over verbatim. TESTING.md §1b added.
- **Verified:** V0 locally (same commands the workflow runs, minus the
container Nix install) + yq YAML parse. The real green run needs the
runner to be alive — **not confirmable from here** (runners API is
401 unauthenticated); watching the run after push.
- **Pending:** new `[human]` item 20 — confirm/re-register the runner;
stretch: a KVM runner unlocks the vm-checks job.
- **Next suggestion:** NOW#3 (memory-pressure protection).
## 2026-07-04 — Opt-in auto-commit shipped (loop iteration #1)
- **Task:** BACKLOG NOW#1 — auto-commit of state mutations (in-flake
state Phase 4). First autonomous /loop iteration.

View File

@@ -7,6 +7,12 @@ here the moment a debugging session teaches you something a future
iteration would otherwise rediscover.
## Testing & VM recipes
- CI (`.forgejo/workflows/check.yml`) is **eval-tier only**: the Forgejo
act_runner is a docker container (no systemd, no /dev/kvm). Container
gotchas are documented in the workflow header (single-user Nix +
nixbld users, `sandbox=false` for Stylix IFD, Nix pinned 2.31.5 vs
lazy-trees, no JS actions past node20) — learned over the legacy
repo's 57 runs; read them before touching the workflow.
- Reusable headless VM harness: `checks.*` via runNixOSTest — existing
examples to crib from: `distro-id` (boots + `switch-to-configuration
dry-activate`), `hardware-toggles` (kernel cmdline/PAM assertions),