diff --git a/.github/workflows/tests.yml b/.github/workflows/tests.yml index 7be6eaf..1bd4822 100644 --- a/.github/workflows/tests.yml +++ b/.github/workflows/tests.yml @@ -30,13 +30,20 @@ jobs: # https://mirror.keellinux.org/layers, verified, assembled into a scratch # rootfs, booted in LXC and checked by tests/boot-test.sh. Nothing is built # there; the build host publishes the layer (docs/releases-host.md of the - # keel repository). + # keel repository). So what boots is the layer the mirror publishes, never + # this branch: a pull request that changes the recipe is not exercised by + # this check, which is why the reusable job is called + # boot-published-layer. # # test-appliance.yml targets the labels "self-hosted, keel-lxc"; a job aimed # at a label no runner carries stays queued until GitHub cancels it after 24 # hours, so the reusable workflow's contract is that callers gate on the # organization variable KEEL_LXC_RUNNER (docs/ci-cd.md section 5 of the keel - # repository). This job produces the check "appliance / build-and-boot". + # repository). A layer that has never been published fails this job + # instead of passing it; the bootstrap exemption for a repository whose + # first layer does not exist yet is allow_unpublished, and this layer is + # published, so it is not used here. This job produces the check + # "appliance / boot-published-layer". if: vars.KEEL_LXC_RUNNER == 'true' uses: keel-linux/.github/.github/workflows/test-appliance.yml@main with: diff --git a/COVERAGE.md b/COVERAGE.md index 8ca22a6..ed70675 100644 --- a/COVERAGE.md +++ b/COVERAGE.md @@ -74,11 +74,15 @@ never what it was. ## The appliance gate -`appliance / build-and-boot` runs through the organization's +`appliance / boot-published-layer` runs through the organization's `test-appliance.yml` on the self-hosted `keel-lxc` runner, which fetches the published layer from `https://mirror.keellinux.org/layers`, verifies it, assembles it, boots it in LXC and runs `tests/boot-test.sh`. Nothing is built -there. +there, so what boots is the published layer and not this branch: a pull request +that changes the recipe is not exercised by this check, which is why the job is +`boot-published-layer` and not the old `build-and-boot`. A layer that has never +been published fails it rather than passing it (keel-linux/.github pull request +12). ### What the boot test proved against the published layer, 2026-09-27 @@ -168,7 +172,7 @@ never reached a machine, which is the trap docs/traps.md records: ## Plan - Require `tests / coverage`, `package / changelog` and - `appliance / build-and-boot` on `master`. + `appliance / boot-published-layer` on `master`. - Rebuild on the `apache-php` layer when it lands, which changes the parent and the digest and nothing else here. - Measure `conf.d/main`. A build time script that runs inside a chroot as root