CI: define the four pipeline lanes (dev-artifact, fast, slow, tag) — #67 #80
No reviewers
Labels
No labels
area:companion
area:docs
area:shared
area:tooling
area:watchapp
blocker
kind:chore
kind:feature
kind:spike
kind:test
No milestone
No project
No assignees
1 participant
Notifications
Due date
No due date set.
Dependencies
No dependencies set
Reference
robert/PedalPebble!80
Loading…
Reference in a new issue
No description provided.
Delete branch "tooling/ci-pipeline"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
Implements #67: the four CI lanes from PROCESS.md/TESTING.md, as
.forgejo/workflows/*.yml, plusthe three pinned toolchain images they run inside.
This is workflow-definition work, untested by execution. No runner is registered against this
repo, so nothing in this PR has actually run on a live pipeline. It needs an extra-careful human
read, not a green-checkmark skim.
docs/CI.mdis the map from PROCESS.md/TESTING.md onto thesefiles and tags every non-obvious claim
[VERIFIED]/[REASONED]/[UNVERIFIED]— start there.Hard exclusion, on purpose
This PR does not register a runner, does not generate or touch a runner-registration token, and
does not run or configure
act_runner. That's explicitly Robert's step — it needs a token fromthe Forgejo web UI, and a registered runner executes arbitrary workflow code against this repo, a
different trust tier than a code PR. See "What Robert still has to do" below.
Workflow directory:
.forgejo/workflows/, not.gitea/workflows/Verified against https://forgejo.org/docs/latest/user/actions/overview/ (2026-09-04):
.forgejo/workflows/is primary; the only documented fallback is.github/workflows/— Forgejo'sdocs never mention
.gitea/workflows/at all. The original issue text ("Files:.gitea/workflows/ci.yml") was simply wrong; the 2026-09-03 update's.forgejo/workflows/iscorrect and is what this PR uses. Left a comment on #67 with this finding, per its own ask.
What's built
dev-artifact.yml— every push, any branch, ungated. Builds a debug.pbw(all threetargetPlatforms— see the file for why "emery only" wasn't worth it given DEV.md's measured2.171s build time) and a debug
.apk, then publishes both to a single rolling pre-release(tag
dev-latest) that's anonymously downloadable from Robert's phone browser — the repo ispublic, so no login or API token is needed to fetch a release asset. "Structurally untaggable"
per PROCESS.md: the tag
dev-latestcan never matchtag-lane.yml'sv*.*.*filter, andtag-lane.ymlnever downloads a dev-artifact output — it always rebuilds from the tagged commit.fast-lane.yml— push + PR, 120s target / 180s hard fail (timeout-minutes: 3per job).JVM tests (
:companion:core, real),pebble build(real), gitleaks-on-the-diff / ktlint / detekt/ clang-format (real, tool defaults since no project lint config exists yet), a meta-test
asserting the workflow declares NFR-C7's required jobs (real). Host C tests and generated-code
freshness check for their prerequisite (#68, #7/#53) and skip with a named issue reference if
absent — each activates itself the moment its issue lands, no further edit needed here.
slow-lane.yml— push tomain. Relies onfast-lane.ymlre-running on the same mergecommit for the "everything in the fast lane, plus" half (both files trigger on
pushtomain).Adds: JVM coverage via Kover with a real bootstrap-and-ratchet implementation of TESTING.md §3.1
(writes
docs/ci/coverage-floor.jsonon first green run, ratchets it thereafter, commits with[skip ci]),assembleRelease+ an inline NFR-S2 dependency deny-list check (real), a-Werrorbuild attempt (flagged
[UNVERIFIED]— whetherpebble build/waf honours aCFLAGSenv overridewasn't confirmed tonight), an emulator install+screenshot smoke test (flagged
[UNVERIFIED]—whether the docker-executor container gets KVM access for QEMU). Host C coverage and replay
regression skip-guard on #68/#23.
tag-lane.yml— push tagv*.*.*. Self-contained rather than layered on the other three viauses:, because this session couldn't verify Forgejo Actions supportsworkflow_callat all, andthis is the one lane where an unverified YAML feature failing silently is least acceptable. Real,
working checks for G11 (partial), G12 (field-report currency — date math against
docs/field/*.md), G13 (quarantine-marker grep), G15 (TODO-threshold grep in TESTING.md), G9(full-history gitleaks), plus a waiver-sanity check (annotated tag with a non-empty message).
Rebuilds the
.pbw/.apkfresh from the tagged commit and publishes a real (non-prerelease)release — same
[UNVERIFIED]release-API-auth assumption asdev-artifact.yml(see below). Twogates (
host-c-suite,replay-and-emulator-gates) hard-fail today because #68/#23 don'texist — correct behaviour: a release gate with nothing to check is a fail, not a pass (TESTING.md
G15's own point), so this lane cannot produce a release yet, on purpose.
tooling/docker/{pebble-toolchain,android-toolchain,ci-tools})— pebble-tool/SDK 4.33.1 pinned to Python 3.13 with a build-time assertion (D54), JDK 21 + Android
platform 37 + a Gradle cache warmed at image-build time, and gitleaks/ktlint/detekt/clang-format.
Built once, only ever pulled by CI.
tooling/docker/README.mdhas the exact build/push commandsand explains why pushing them is a manual step: the automatic per-run token is confirmed unable to
push to the package registry (unrelated to the runner-token exclusion above — a different,
independently-confirmed limitation, see the README).
is the automatic per-run
secrets.GITHUB_TOKEN/FORGEJO_TOKEN, injected by the platform itself,not something Robert has to create or paste in.
README.md;docs/CI.mdis the full map, written to TESTING.md'sown
[VERIFIED]/[RECALLED]/[REASONED]tagging convention (here[UNVERIFIED]instead of[RECALLED], since nothing was recalled — everything not directly checked tonight is named as anopen gap instead).
What Robert still has to do by hand
tooling/docker/README.md).act_runner— labelpedalpebble, docker executor (required forthe
container:image overrides every job here uses). Not done in this PR, deliberately.dev-artifact.yml/fast-lane.ymlrun for real the first time. Expect atleast two things to need adjusting: the KVM device option on the emulator-smoke jobs, and
confirming (or fixing) the release-asset-upload auth assumption.
docs/CI.md's[UNVERIFIED]tags once the first real run answers them.Assumptions flagged as unverified (full list and reasoning in
docs/CI.md§6)general; confirmed not for package-registry push; release assets sit in neither confirmed
bucket).
pebble buildhonours aCFLAGSenv override for-Werror(slow/tag lane builds)./dev/kvmaccess for the emulator-smoke jobs.workflow_call/reusable workflows aren't used anywhere, specifically because this couldn't beconfirmed as supported.
companion-{debug,release-unsigned}.apk) —reasoned from the module name, not confirmed against a real build.
Claude-Session: https://claude.ai/code/session_01DAoXbRmJUf2uxNYBfdAXPt