name: CI on: push: branches: [main, "feat/**", "fix/**"] pull_request: workflow_dispatch: permissions: contents: read jobs: shell: name: shell (shellcheck + syntax) runs-on: ubuntu-latest steps: - uses: actions/checkout@v4 - name: bash syntax check run: | fail=0 while IFS= read -r f; do bash -n "$f" || { echo "::error file=$f::bash syntax error"; fail=1; } done < <(find . -name '*.sh' -not -path './.git/*') exit $fail # Pinned to a release tag, not @master: a third-party action on a moving # branch runs whatever that branch contains at the time CI fires. - name: shellcheck uses: ludeeus/action-shellcheck@2.0.0 env: SHELLCHECK_OPTS: -S warning -e SC1091 python: name: python ${{ matrix.python }} runs-on: ubuntu-latest strategy: fail-fast: false matrix: # TrueNAS SCALE middleware runs 3.11+; keep the patch importable across # the versions it may be injected into. python: ["3.11", "3.12", "3.13"] steps: - uses: actions/checkout@v4 # uv-managed interpreters instead of actions/setup-python: the prebuilt-CPython # download path setup-python relies on does not work on the self-hosted Gitea # runner (all three matrix jobs failed at setup there while passing on GitHub); # uv works identically on both. - uses: astral-sh/setup-uv@fac544c07dec837d0ccb6301d7b5580bf5edae39 # v8.2.0 - name: ruff # Pinned: an unpinned ruff means any upstream release can turn main red # with no code change. run: uvx ruff@0.16.1 check patch tests tools - name: pytest run: uvx --python ${{ matrix.python }} pytest tests -v - name: verify injected middleware blocks compile # Belt-and-braces: the *_BLOCK strings are appended into live middlewared # modules. A syntax error there would break the box at boot. run: uvx --python ${{ matrix.python }} pytest tests/test_apply_blocks.py -v