From 01e36155a3cf8ecde7aff5f23234b97cf69c75fb Mon Sep 17 00:00:00 2001 From: Grant Whitmer Date: Fri, 14 Aug 2026 14:41:14 -0400 Subject: [PATCH] ci: remove the service-networking probe; scope the python-pin test MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit The probe's own log was never retrievable through the jobs API, but the question it asked was answered better by a direct comparison of two real workflows on the same runner and image: windy-git gate @postgres:5432 -> passes its migration round-trip eternitas migrations @localhost:5432 -> failed Also scopes test_g73 to workflows that actually run Python. It failed the probe for not pinning a version when the probe only shelled out to psql — the test being wrong rather than the workflow. Co-Authored-By: Claude (Fable 5) --- .gitea/workflows/service-networking-probe.yml | 38 ------------------- api/tests/test_invariants.py | 5 +++ 2 files changed, 5 insertions(+), 38 deletions(-) delete mode 100644 .gitea/workflows/service-networking-probe.yml diff --git a/.gitea/workflows/service-networking-probe.yml b/.gitea/workflows/service-networking-probe.yml deleted file mode 100644 index 6d9ada8..0000000 --- a/.gitea/workflows/service-networking-probe.yml +++ /dev/null @@ -1,38 +0,0 @@ -# One-off experiment: how are service containers reached on THIS runner? -# -# GitHub-hosted runners port-map services to localhost. Gitea Actions runs the -# job inside a container, so `localhost` is the job itself and services are -# reached by their service NAME. Several migrated workflows hardcode -# localhost:5432 — before rewriting any of them, prove which form actually -# works here instead of assuming. -name: service-networking-probe - -on: - workflow_dispatch: - -jobs: - probe: - runs-on: veron-1 - timeout-minutes: 6 - services: - postgres: - image: postgres:16-alpine - env: - POSTGRES_USER: probe - POSTGRES_PASSWORD: probe - POSTGRES_DB: probe - options: >- - --health-cmd "pg_isready -U probe" - --health-interval 5s - --health-retries 10 - steps: - - name: which hostname reaches the service? - run: | - apt-get install -y postgresql-client >/dev/null 2>&1 || true - for host in localhost 127.0.0.1 postgres; do - if PGPASSWORD=probe psql -h "$host" -U probe -d probe -c 'SELECT 1' >/dev/null 2>&1; then - echo "RESULT $host = REACHABLE" - else - echo "RESULT $host = unreachable" - fi - done diff --git a/api/tests/test_invariants.py b/api/tests/test_invariants.py index 9f07111..0ccbf4a 100644 --- a/api/tests/test_invariants.py +++ b/api/tests/test_invariants.py @@ -492,6 +492,11 @@ def test_g73_workflow_pins_a_python_that_satisfies_requires_python(): for wf in ROOT.rglob(".gitea/workflows/*.y*ml"): text = wf.read_text() + # Only workflows that actually RUN Python need to pin it. A workflow + # that shells out to psql or curl does not, and demanding a pin from + # it is the test being wrong rather than the workflow. + if not _re.search(r"\bpython3?\b|pytest|pip ", text): + continue # Either a pinned container image or an explicit setup-python version. pin = _re.search(r"image:\s*python:(\d+)\.(\d+)", text) or _re.search( r'python-version:\s*"?(\d+)\.(\d+)"?', text