Copies .dockerignore, .gitignore, .prettierignore, check.yml and REPO_POLICIES.md from sneak/prompts at dd4027b. The repo's own entries (dist/, release/, yarn files) are kept after the canonical content. The Dockerfile gets separate lint and test phases. Its last stage depends on both, checks the git describe version and runs make build. script/lint, test, check, cibuild and docker are the canonical models. check-censored moves into the lint phase and test-verify-build into the test phase. fmt and fmt-check fall back to the nvm-installed node. The e2e image builds are uncached. Comments that cited the old test caps now say 60 seconds, and comments that named what runs a script now name the Dockerfile phase or stage. Model: opus-5-5
57 lines
2.6 KiB
YAML
57 lines
2.6 KiB
YAML
name: e2e
|
|
on: [push]
|
|
|
|
# The browser end-to-end suites, one job per browser, deliberately kept out
|
|
# of the check workflow: REPO_POLICIES.md caps make test at 60 seconds and
|
|
# script/cibuild runs make check, so folding a browser suite into either
|
|
# would blow that cap and slow the local fast path. Before this workflow
|
|
# every browser-level guarantee in this repo held only when a human
|
|
# remembered to run it.
|
|
#
|
|
# One job per browser rather than two steps in one job, so a Chrome failure
|
|
# does not hide the Firefox result.
|
|
#
|
|
# Each job is one script and nothing else. Both scripts need docker and
|
|
# nothing else — they deliver the repo to the daemon as a build context and
|
|
# build the extension inside the pinned image — which is what makes them
|
|
# runnable here at all: the runner executes the job in a container against
|
|
# the host's docker socket, so a `-v "$PWD:/work"` source path is resolved
|
|
# by the host daemon and mounts an empty directory, and the runner image's
|
|
# node is too old to install this repo's dependencies.
|
|
#
|
|
# These jobs REPORT, they do not gate. Whether a check blocks a merge is
|
|
# Gitea branch protection, which this repo does not configure, so a failure
|
|
# here is a red mark a reviewer has to account for rather than a hard
|
|
# block. Making e2e-chrome a required check is blocked while reports of the
|
|
# Chrome suite failing under load are still open; the "In CI" section of
|
|
# README.md names them. A gate that fails at random teaches people to merge
|
|
# past red.
|
|
#
|
|
# Nothing here may pass vacuously. There is no continue-on-error and no
|
|
# `|| true`. Both scripts exit non-zero when docker is missing, when the
|
|
# image build fails, and when the browser fails to start; the Chrome
|
|
# harness aborts the suite outright if its network interception is not in
|
|
# effect.
|
|
jobs:
|
|
e2e-chrome:
|
|
runs-on: ubuntu-latest
|
|
# Bounds the image build, a cold cache included, and both Chrome
|
|
# programs, so a hung browser frees the shared runner. README.md
|
|
# "In CI" has the measured times.
|
|
timeout-minutes: 20
|
|
steps:
|
|
# actions/checkout v4.2.2, 2026-02-22
|
|
- uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683
|
|
- run: script/test-e2e
|
|
|
|
e2e-firefox:
|
|
runs-on: ubuntu-latest
|
|
# Bounds the image build, a cold cache included, and both Firefox
|
|
# programs, so a hung browser frees the shared runner. README.md
|
|
# "In CI" has the measured times.
|
|
timeout-minutes: 15
|
|
steps:
|
|
# actions/checkout v4.2.2, 2026-02-22
|
|
- uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683
|
|
- run: script/test-e2e-firefox
|