diff --git a/.gitea/workflows/unit-tests.yml b/.gitea/workflows/unit-tests.yml index 665dfac..f3d3df4 100644 --- a/.gitea/workflows/unit-tests.yml +++ b/.gitea/workflows/unit-tests.yml @@ -78,12 +78,22 @@ jobs: exit 1 } + # Pinned to a version, never `latest`, for the same reason the builder + # image above is: a dump is an input to the tests, so a moving `latest` + # would let a re-upload retroactively change what an earlier green build + # proved. It also removes a credential from this job entirely -- package + # DOWNLOADS are anonymous while the repo is public, and only resolving + # `latest` needs a token (the list-packages endpoint requires auth on this + # instance). `latest` was the sole reason this step wanted GITEA_TOKEN, + # and no such secret is configured, so it could never have resolved. + # + # Bumping the fixtures means uploading a new version with + # scripts/artifacts/push_artifacts.sh replay-fixtures and editing the SHA + # here, in the same commit -- as with the image tag. - name: Fetch replay fixtures - env: - GITEA_TOKEN: ${{ secrets.GITEA_TOKEN }} # bash, not sh: the script declares #!/bin/bash and uses `set -o # pipefail` and arrays, which dash does not have. - run: bash scripts/artifacts/pull_artifacts.sh replay-fixtures latest + run: bash scripts/artifacts/pull_artifacts.sh replay-fixtures ff3b8eb # pull_artifacts.sh warns and continues when a package version is missing, # which is right for a developer pulling one artifact of several and wrong @@ -107,7 +117,9 @@ jobs: echo "Replay fixtures are absent, so the T2 tier cannot run." >&2 echo "They are not in git (tests/fixtures/dumps/.gitignore) -- they" >&2 echo "live in the Gitea generic package registry and are pulled by" >&2 - echo "the step above, which needs GITEA_TOKEN to resolve 'latest'." >&2 + echo "the step above, at the version pinned there. Check that the" >&2 + echo "version still exists in the registry: pull_artifacts.sh warns" >&2 + echo "and continues on a missing one rather than failing." >&2 exit 1 fi