navidrome/.github/workflows/coverage-on-pr.yml
Deluan 16b9f60a21 ci: close change-detection gaps found in review
Four changes, three of them gaps in the filters added by the previous commit.

Go tests execute db/migrations/*.sql for real: persistence_suite_test.go calls
db.Init, which runs goose against an in-memory database. `make migration-sql`
produces a .sql-only diff, and six such commits exist in history, so those PRs
would have run zero Go tests. Added ^db/migrations/ to the Go filter.

validate-translations.sh reads ui/src/i18n/en.json as its reference, not
resources/i18n/en.json, which does not exist. A commit that only removes an
English key (dd4802c0c is one) would have skipped the only check that reports
the orphaned keys left in all 36 translations.

The coverage-artifact probe was unpaginated. A full Go pipeline run produces
exactly 30 artifacts, the API default page size, and octocov-pr sorts to index
27 because the test jobs finish first. Run 33503006884 already produced 33 and
pushed all three coverage artifacts off page one. Server-side ?name= filtering
has no count ceiling.

The script also now fails closed if the base ref cannot be resolved. The fetch
itself stays non-fatal: actions/checkout already created the ref, so a failed
refresh is harmless, and making it fatal would turn a transient blip into a red
pipeline.

Also adds workflow_dispatch, so a manual run is possible and gets every flag.
2026-09-05 13:47:20 -04:00

74 lines
2.9 KiB
YAML

name: Report coverage on PR
on:
workflow_run:
workflows: ['Pipeline: Test, Lint, Build']
types: [completed]
jobs:
comment:
name: Comment coverage report
if: github.event.workflow_run.event == 'pull_request' && github.event.workflow_run.conclusion == 'success'
runs-on: ubuntu-latest
permissions:
contents: read
actions: read
pull-requests: write
env:
COVERAGE_COMMENT: 'true'
steps:
# The pipeline skips its coverage steps when a PR touches no Go code.
- name: Check the run produced a coverage artifact
id: artifact
env:
GH_TOKEN: ${{ github.token }}
run: |
count=$(gh api "repos/$GITHUB_REPOSITORY/actions/runs/${{ github.event.workflow_run.id }}/artifacts?name=octocov-pr" \
--jq '.total_count')
echo "count=$count" >> "$GITHUB_OUTPUT"
# Only the config, from the base branch: this job holds a write token, so
# it must never check out the fork.
- name: Check out the octocov config
if: steps.artifact.outputs.count != '0'
uses: actions/checkout@v7
with:
sparse-checkout: .octocov.yml
sparse-checkout-cone-mode: false
persist-credentials: false
# Into a subdirectory. A pull_request run executes the fork's own copy of
# pipeline.yml, so every file in here is attacker-controlled.
- uses: actions/download-artifact@v8
if: steps.artifact.outputs.count != '0'
with:
name: octocov-pr
path: untrusted
run-id: ${{ github.event.workflow_run.id }}
github-token: ${{ github.token }}
- name: Verify the artifact and take the coverage profile
id: pr
if: steps.artifact.outputs.count != '0'
env:
GH_TOKEN: ${{ github.token }}
HEAD_SHA: ${{ github.event.workflow_run.head_sha }}
run: |
number=$(head -c 20 untrusted/pr_number | tr -d '[:space:]')
case "$number" in ''|*[!0-9]*)
echo "::error::artifact pr_number is not a number"; exit 1;;
esac
sha=$(gh api "repos/$GITHUB_REPOSITORY/pulls/$number" --jq .head.sha)
if [ "$sha" != "$HEAD_SHA" ]; then
echo "::error::artifact claims PR #$number, but its head $sha is not $HEAD_SHA"; exit 1
fi
cp untrusted/coverage.out coverage.out
echo "number=$number" >> "$GITHUB_OUTPUT"
- uses: k1LoW/octocov-action@v1
if: steps.artifact.outputs.count != '0'
env:
# A workflow_run job looks like a push to the default branch. Point
# octocov back at the pull request and at the run that produced it.
GITHUB_PULL_REQUEST_NUMBER: ${{ steps.pr.outputs.number }}
OCTOCOV_GITHUB_REF: refs/pull/${{ steps.pr.outputs.number }}/merge
OCTOCOV_GITHUB_SHA: ${{ github.event.workflow_run.head_sha }}
OCTOCOV_GITHUB_RUN_ID: ${{ github.event.workflow_run.id }}