G7.3: setup-python on the act image, not a python image
Some checks failed
check / gate (push) Failing after 43s

Trading one wedge for another: running the job in python:3.12-bookworm fixed
the resolver spiral but broke checkout, because actions/checkout is a
JavaScript action and the official Python images carry no node — 'executable
file not found in $PATH'.

setup-python on the act image has both. Test now accepts either a pinned
container image or an explicit setup-python version, and still checks it
against pyproject's requires-python.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
This commit is contained in:
Grant Whitmer
2026-08-12 11:16:00 -04:00
parent 980fc2dddd
commit 8c4bdd2bc2
2 changed files with 24 additions and 15 deletions

View File

@@ -16,17 +16,8 @@ on:
jobs:
gate:
runs-on: veron-1
# Run IN a Python 3.12 image rather than trusting the runner image's
# toolchain. The first real CI run wedged here: catthehacker/ubuntu:act-22.04
# ships Python 3.10.12, this project declares requires-python >=3.12, and pip
# answered that by backtracking through the entire release history of every
# dependency looking for something 3.10-compatible. It churned for 14 minutes
# at 100% CPU with `-q` hiding all of it, and would have churned until the
# runner timeout. A version mismatch presenting as a hang, not an error.
container:
image: python:3.12-bookworm
# And a hard ceiling, so a wedged step is a red check in minutes rather than
# an occupied runner for half an hour.
# A hard ceiling, so a wedged step is a red check in minutes rather than an
# occupied runner for half an hour.
timeout-minutes: 12
services:
postgres:
@@ -42,6 +33,21 @@ jobs:
steps:
- uses: actions/checkout@v4
# The runner image ships Python 3.10.12; this project requires >=3.12.
# The first real CI run wedged for 14 minutes on exactly that: pip
# answered the mismatch by backtracking through the entire release
# history of every dependency looking for something 3.10-compatible, at
# 100% CPU, with `-q` hiding every line of it. A version mismatch
# presenting as a hang rather than an error.
#
# The obvious fix — run the job in a python:3.12 image — trades one wedge
# for another: actions/checkout is a JavaScript action, and the official
# Python images carry no `node`, so checkout dies with "executable file
# not found". Hence setup-python on the act image, which has both.
- uses: actions/setup-python@v5
with:
python-version: "3.12"
- name: install
run: |
python3 --version

View File

@@ -478,10 +478,13 @@ def test_g73_workflow_pins_a_python_that_satisfies_requires_python():
for wf in ROOT.rglob(".gitea/workflows/*.y*ml"):
text = wf.read_text()
img = _re.search(r"image:\s*python:(\d+)\.(\d+)", text)
assert img, f"{wf.name}: job does not pin a python image"
assert (int(img.group(1)), int(img.group(2))) >= (major, minor), (
f"{wf.name}: pins python {img.group(0)} but the project requires "
# Either a pinned container image or an explicit setup-python version.
pin = _re.search(r"image:\s*python:(\d+)\.(\d+)", text) or _re.search(
r'python-version:\s*"?(\d+)\.(\d+)"?', text
)
assert pin, f"{wf.name}: job neither pins a python image nor sets up a version"
assert (int(pin.group(1)), int(pin.group(2))) >= (major, minor), (
f"{wf.name}: pins python {pin.group(0)} but the project requires "
f">={major}.{minor}"
)