Skip to content

qa: scope shutdown scheduler journey to Windows #196

qa: scope shutdown scheduler journey to Windows

qa: scope shutdown scheduler journey to Windows #196

Workflow file for this run

name: CI
on:
push:
branches: [main]
pull_request:
workflow_dispatch:
workflow_call:
permissions:
contents: read
jobs:
test:
name: build & test (${{ matrix.os }})
strategy:
fail-fast: false
matrix:
os: [ubuntu-latest, macos-latest, windows-latest]
runs-on: ${{ matrix.os }}
env:
# The unit tests + tsc don't need the Electron/Playwright binaries — skip the heavy downloads.
ELECTRON_SKIP_BINARY_DOWNLOAD: '1'
PLAYWRIGHT_SKIP_BROWSER_DOWNLOAD: '1'
steps:
- uses: actions/checkout@v4
- uses: actions/setup-node@v4
with:
node-version: 20
cache: npm
- run: npm ci
- run: npm run build
- run: npm test
# Verify the macOS launcher's generated AppleScript compiles on a real Mac (no GUI needed).
- name: Validate generated AppleScript compiles
if: runner.os == 'macOS'
run: node scripts/check-applescript.mjs
qa:
# The Playwright/axe audit (a11y per view + the IPC surface round-trips) was previously
# manual-only — its gates never ran on a PR. One Linux leg under xvfb keeps it cheap.
name: qa audit (a11y + ipc, linux)
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@v4
- uses: actions/setup-node@v4
with:
node-version: 20
cache: npm
- run: npm ci
- run: npm run build
# ubuntu-24.04 runners restrict unprivileged user namespaces (AppArmor), which kills the
# Electron/Chromium sandbox before a window ever appears — firstWindow() then times out.
- name: Allow unprivileged user namespaces for the Electron sandbox
run: sudo sysctl -w kernel.apparmor_restrict_unprivileged_userns=0
- name: Install a window manager for real maximize and restore journeys
run: sudo apt-get update && sudo apt-get install -y --no-install-recommends openbox
# The audit verifies cockpit.gitInfo resolves the repo's branch. actions/checkout leaves the repo
# in detached HEAD (no current branch), so that check would fail for an environment reason unrelated
# to the app — put the checkout on a real branch first. (Local `npm run qa:audit` is already on one.)
- name: Put the checkout on a branch for the gitInfo check
run: |
git config --global --add safe.directory "$GITHUB_WORKSPACE"
git checkout -B ci-audit
- name: Run the audit under a virtual display
run: xvfb-run -a node qa/audit.mjs
env:
DEBUG: 'pw:browser' # if launch fails again, the electron process's own stderr lands in the log
- name: Run the multilingual user journeys
run: xvfb-run -a sh -c 'openbox --sm-disable >/tmp/devdeck-openbox.log 2>&1 & node qa/screenshot.mjs'
- uses: actions/upload-artifact@v4
if: always()
with:
name: qa-audit-and-journeys
path: qa/shots/
resilience:
name: failure and recovery journeys (${{ matrix.os }})
strategy:
fail-fast: false
matrix:
os: [ubuntu-latest, windows-latest]
runs-on: ${{ matrix.os }}
timeout-minutes: 10
steps:
- uses: actions/checkout@v4
- uses: actions/setup-node@v4
with:
node-version: 20
cache: npm
- run: npm ci
- name: Check dependency advisories
if: runner.os == 'Linux'
run: npm audit --audit-level=high
- run: npm run build
- name: Allow Electron sandbox
if: runner.os == 'Linux'
run: sudo sysctl -w kernel.apparmor_restrict_unprivileged_userns=0
- name: Run Linux failure and recovery journeys
if: runner.os == 'Linux'
run: xvfb-run -a node qa/resilience.mjs
- name: Run Windows failure and recovery journeys
if: runner.os == 'Windows'
run: node qa/resilience.mjs
- uses: actions/upload-artifact@v4
if: always()
with:
name: qa-resilience-${{ matrix.os }}
path: qa/shots/resilience/