From 72fc42217f0d49de8547e3b4ef367a5fd8f99236 Mon Sep 17 00:00:00 2001 From: JakeBreath Date: Tue, 22 Sep 2026 23:12:56 -0500 Subject: [PATCH] Fix CI for the user-scoped runners - ci.yml: connect to the test MariaDB as root so Django creates the test database itself (no client install/grant step), and drop actions/cache (cache: pip/npm): Gitea's cache service hangs the job on restore/save. - publish.yml: prefer the REGISTRY_USER/REGISTRY_TOKEN secrets (as on other repos) and fall back to the automatic Actions token. - AGENTS.md: note the CI layout, the runner labels and the cache caveat. --- .gitea/workflows/ci.yml | 42 +++++++++++------------------------- .gitea/workflows/publish.yml | 6 ++++-- AGENTS.md | 13 ++++++++++- 3 files changed, 28 insertions(+), 33 deletions(-) diff --git a/.gitea/workflows/ci.yml b/.gitea/workflows/ci.yml index 7fef642..ff4b560 100644 --- a/.gitea/workflows/ci.yml +++ b/.gitea/workflows/ci.yml @@ -30,24 +30,25 @@ jobs: MARIADB_USER: j621 MARIADB_PASSWORD: j621 options: >- - --health-cmd "healthcheck.sh --connect --innodb_initialized" - --health-interval 5s - --health-timeout 5s - --health-retries 20 + --health-cmd="healthcheck.sh --connect --innodb_initialized" + --health-interval=5s + --health-timeout=5s + --health-retries=12 redis: image: redis:7-alpine options: >- - --health-cmd "redis-cli ping" - --health-interval 5s - --health-timeout 5s - --health-retries 20 + --health-cmd="redis-cli ping" + --health-interval=5s + --health-timeout=5s + --health-retries=12 env: + # Connect as root so Django can create the test database itself; + # everything else mirrors the development defaults. DB_HOST: mariadb DB_PORT: "3306" DB_NAME: j621 - DB_USER: j621 - DB_PASSWORD: j621 - DB_ROOT_PASSWORD: root + DB_USER: root + DB_PASSWORD: root REDIS_URL: redis://redis:6379/1 steps: - uses: actions/checkout@v4 @@ -55,27 +56,10 @@ jobs: - uses: actions/setup-python@v5 with: python-version: "3.14" - cache: pip - cache-dependency-path: backend/requirements.txt - name: Install backend dependencies run: pip install -r backend/requirements.txt - - name: Install a MariaDB client - run: | - sudo apt-get update - sudo apt-get install -y --no-install-recommends default-mysql-client - - - name: Grant the test database rights - run: | - for i in $(seq 1 30); do - mysql -h "$DB_HOST" -P "$DB_PORT" -u root -p"$DB_ROOT_PASSWORD" \ - -e "SELECT 1" >/dev/null 2>&1 && break - sleep 2 - done - mysql -h "$DB_HOST" -P "$DB_PORT" -u root -p"$DB_ROOT_PASSWORD" \ - -e "GRANT ALL ON \`test_j621\`.* TO 'j621'@'%'; FLUSH PRIVILEGES;" - - name: Django system checks working-directory: backend run: python manage.py check @@ -98,8 +82,6 @@ jobs: - uses: actions/setup-node@v4 with: node-version: "22" - cache: npm - cache-dependency-path: frontend/package-lock.json - name: Install frontend dependencies working-directory: frontend diff --git a/.gitea/workflows/publish.yml b/.gitea/workflows/publish.yml index cefc74d..7b328f7 100644 --- a/.gitea/workflows/publish.yml +++ b/.gitea/workflows/publish.yml @@ -30,8 +30,10 @@ jobs: name: Build & push images runs-on: ubuntu-latest env: - REGISTRY_USER: ${{ github.actor }} - REGISTRY_TOKEN: ${{ secrets.GITHUB_TOKEN }} + # Prefer dedicated registry secrets (as on other repos); fall back to + # the automatic Actions token. + REGISTRY_USER: ${{ secrets.REGISTRY_USER || github.actor }} + REGISTRY_TOKEN: ${{ secrets.REGISTRY_TOKEN || secrets.GITHUB_TOKEN }} PLATFORMS: ${{ inputs.platforms || 'linux/amd64,linux/arm64' }} steps: - uses: actions/checkout@v4 diff --git a/AGENTS.md b/AGENTS.md index 18c81ed..b22bd8e 100644 --- a/AGENTS.md +++ b/AGENTS.md @@ -49,6 +49,12 @@ Project constraints (do not regress): - Periodic commands (follow syncs, similarity cleanup, guest blacklist refresh) run in the composes' `scheduler` service — the backend image with the j621-scheduler entrypoint, intervals via J621_*_EVERY. No host cron. +- CI lives in .gitea/workflows: ci.yml runs on every push/PR (Django checks + + the full backend suite against MariaDB/Redis service containers, frontend + lint/type-check/build); publish.yml is manual and builds/pushes both images + multi-arch. Jobs run on the user-scoped msi-mortar-ci runner (labels + `desktop` + `ubuntu-latest`). Do not add actions/cache (`cache: pip`/`npm`) + to these workflows: Gitea's cache service hangs the job on restore/save. - Security/permission tests live in backend/apps/core/tests and need a one-time grant: GRANT ALL ON `test_j621`.* TO 'j621'@'%'; @@ -85,7 +91,12 @@ Security hardening (do not weaken): SECRET_KEY (apps/accounts/crypto.py); rotating SECRET_KEY invalidates them (and all signed media URLs), so users must re-enter the key. - API throttles live in REST_FRAMEWORK (env-overridable): anon 120/min, - user 600/min, login 5/min, register 20/hour, e621_proxy 60/hour. + user 600/min, login 5/min, register 20/hour, e621_proxy 60/hour. Signed + media URLs (raw/thumbnail/staged-file/similarity-file actions) are exempt + on purpose: /