-
Notifications
You must be signed in to change notification settings - Fork 1
Release: merge development into beta #691
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Changes from all commits
2c5c409
455fb54
ea787dc
8965d7b
3bc32e9
49ff8c2
bb0e61c
2d445d4
0c65767
9c257c2
7e65e05
0976e54
82af293
f0931d3
7dae235
d9072e3
96470c1
e34b171
664993e
a009f11
c5564c7
11de95c
63dc7df
96b7dab
7493b37
cf2012e
a5e1297
c818ee2
0309fcc
aef04a7
74b633c
fc0005c
cc63def
752277c
7ae3f99
716b8b6
04d3d14
225eada
e097a21
d46a2e4
8504024
3b63d30
7d1f0a7
8fc72f8
cc3b2a0
df89d9a
d24c0c5
b9367ba
0ca3273
6a319c9
d3ae62a
67f8e03
73b3288
5973a2d
0cb6ba6
8422d4c
b21e44c
0cc8f41
74b5733
99302bf
5f871e5
f83d592
a99364f
9def1c2
eb65a4f
d8cceeb
f2e18e0
5f1c552
94b901e
18c05e1
602fa26
e473d97
f0705e9
9bf78f6
7921095
931c81d
771be92
42b874b
7f8e256
c887fd7
fcff1b4
5597579
1777758
4ef90e9
7feb575
d3b0451
dbb9035
168cf68
8e314af
bdbe373
d05b0af
5425a32
fa9c75a
1d865f7
a2f3eb0
2de5622
243c555
f10253b
eb5071b
06f25bf
752d4b3
9b7fe70
1569544
c88ff04
39d7ebd
8f18b05
7bf7122
02a6005
248fc4d
93fc7ad
34d2c9a
b3228a1
3a71a2b
9ee717e
48cea4b
ff7f253
4c214a9
b165a43
58cd98f
b5727e0
2fa085c
124849b
a562c4c
1f53c25
55be44b
26d2484
26b6ee1
5316f77
e9c3b5b
2cfb1e8
9d18a8b
afb30e6
53003aa
f2dc6ab
fb90ffe
3ac559a
45d2d9f
d853836
37e1571
d7787b4
1fbc3e6
a76742f
8b122cd
3cabf5a
08559e4
e443f72
3b1220d
b10c0d9
51b4c2e
c093cd6
4dda591
4aa7aa1
d3a1040
05a9b3a
f4cf3e0
40e9bc0
1472a0a
566ee14
7227dee
d5328c8
5b729df
File filter
Filter by extension
Conversations
Jump to
Diff view
Diff view
There are no files selected for viewing
| Original file line number | Diff line number | Diff line change |
|---|---|---|
|
|
@@ -118,38 +118,52 @@ jobs: | |
| app-name: keepiq | ||
| php-version: "8.3" | ||
| php-test-versions: '["8.3", "8.4"]' | ||
| # Order matters: the PHPUnit matrix uses the whole list, but the E2E | ||
| # (Playwright), Newman and Journeydoc jobs all check out | ||
| # `fromJSON(nextcloud-test-refs)[0]` as their single server. That server | ||
| # has to be one OpenRegister can load, because `additional-apps` below | ||
| # installs it and keepiq's AppHost integration delegates to it — | ||
| # OpenRegister's lib/ContextChat/ContentProvider.php implements | ||
| # `OCP\ContextChat\IContentProvider`, which exists in stable32 and NOT in | ||
| # stable31 (verified: raw.githubusercontent.com returns 404 for the | ||
| # stable31 path). On stable31 every `occ` invocation printed | ||
| # NO `nextcloud-test-refs` HERE, DELIBERATELY. The shared workflow derives | ||
| # the matrix from appinfo/info.xml when this input is unset, and a derived | ||
| # matrix cannot disagree with the declared range. The override that used to | ||
| # sit here is exactly how the two came apart: it read | ||
| # `["stable34", "stable32", "stable33"]` while this branch moved info.xml to | ||
| # `<nextcloud min-version="32" max-version="35"/>`, so NC 35 was advertised | ||
| # to the App Store with no job touching it — not known-broken, unmeasured. | ||
| # gate-65 rule 11 is what caught it. Re-adding stable35 by hand fixes today | ||
| # and leaves the next bump to be remembered in two files; deriving deletes | ||
| # the second file. | ||
| # | ||
| # WHAT THE OVERRIDE WAS PROTECTING, AND WHY IT NO LONGER HAS TO. | ||
| # Its ORDER carried meaning: E2E (Playwright), Newman and journeydoc-capture | ||
| # each ran against `fromJSON(nextcloud-test-refs)[0]`, so stable34 had to | ||
| # lead to keep them off a server OpenRegister cannot load — OpenRegister's | ||
| # lib/ContextChat/ContentProvider.php implements | ||
| # `OCP\ContextChat\IContentProvider`, which does not exist before stable32, | ||
| # and on stable31 every `occ` invocation printed | ||
| # `Interface "OCP\ContextChat\IContentProvider" not found` while loading | ||
| # commands from openregister's info.xml. | ||
| # | ||
| # The earlier reorder fixed the FIRST-entry problem for E2E/Newman/Journeydoc | ||
| # but left "stable31 is still covered by the PHPUnit matrix" — and that leg | ||
| # is broken by the same fact. The phpunit job ALSO installs `additional-apps` | ||
| # (shared quality.yml, "Checkout additional apps" + "Enabling app: …"), and | ||
| # its `occ app:enable openregister` failure is only a ::warning::, so the | ||
| # stable31 leg ran on without OpenRegister loaded. openregister has since | ||
| # made the floor explicit — `<nextcloud min-version="32"/>`, 8d5181f7a — so | ||
| # NC31 is now a configuration this fixture cannot produce at all. | ||
| # Those four jobs no longer read a meaning off a position. The shared | ||
| # workflow computes a `single-server` output — the numerically HIGHEST | ||
| # stable branch in the resolved set, and for the derived path the matrix | ||
| # action's own `branches-max` — and they consume that. The action's | ||
| # `branches` output is OLDEST-first, so a positional read would have moved | ||
| # all four onto stable32 silently. List order is now inert, and the one | ||
| # thing the override bought is structural instead. | ||
| # | ||
| # THIS ADDS A stable35 LEG. It was RED BEFORE IT WAS GREEN, deliberately. | ||
| # `additional-apps` below installs openregister and integriq, and when this | ||
| # branch was opened (2026-09-15) BOTH still declared `max-version="34"` on | ||
| # `development`. The shared workflow aborts the job when `occ app:enable` | ||
| # fails for an additional app — that was once only a ::warning::, which is | ||
| # how a leg previously ran on WITHOUT OpenRegister loaded and reported | ||
| # nothing — so the stable35 legs failed at the fixture, not in the tests. | ||
| # | ||
| # Removing stable31 corrects an impossible configuration; it does not reduce | ||
| # coverage, because nothing was being covered on that leg. | ||
| # RESOLVED 2026-09-24: both dependencies now declare | ||
| # `<nextcloud min-version="32" max-version="35"/>` on `development`, which | ||
| # is the ref this file pins. Verified by parsing each appinfo/info.xml | ||
| # rather than grepping, because both files carry comments that quote OTHER | ||
| # apps' ranges and a grep matches those first. | ||
| # | ||
| # THE LIST IS THE WHOLE DECLARED RANGE. appinfo/info.xml declares | ||
| # <nextcloud min-version="32" max-version="34"/>, so 32, 33 and 34 each get | ||
| # a leg. Adopting NC 34 by REPLACING the list left 32 and 33 advertised to | ||
| # the App Store with no job touching them — the declared floor became the | ||
| # untested end, which is the same drift as never testing 34, reversed. | ||
| # stable34 leads because newman, playwright and journeydoc-capture all read | ||
| # `fromJSON(inputs.nextcloud-test-refs)[0]` as their single server. | ||
| nextcloud-test-refs: '["stable34", "stable32", "stable33"]' | ||
| # The point of deriving the matrix from info.xml stands: the red was the | ||
| # honest state of NC 35 support while the gap existed, and nothing here | ||
| # could hide it. Leave it derived. | ||
| enable-psalm: true | ||
| enable-phpstan: true | ||
| enable-phpmetrics: true | ||
|
|
@@ -172,7 +186,14 @@ jobs: | |
| # which reads as an auth problem rather than a typo. Six fleet repos hit | ||
| # this; in pipelinq it killed all four PHPUnit legs and the E2E job at the | ||
| # clone step, so those gates had never executed a single test. | ||
| additional-apps: '[{"repo":"ConductionNL/openregister","app":"openregister","ref":"development"}]' | ||
| # | ||
| # integriq is here because the Integrations page reads integriq's | ||
| # `app_connection` rows (adopt-connection-registry). Without it the page | ||
| # shows the missing-dependency screen and | ||
| # `tests/e2e/workflows/integrations-page.spec.ts` fails on every run. | ||
| # `app` is `integriq`, verified in its appinfo/info.xml on `development` | ||
| # on 2026-09-15. | ||
| additional-apps: '[{"repo":"ConductionNL/openregister","app":"openregister","ref":"development"},{"repo":"ConductionNL/integriq","app":"integriq","ref":"development"}]' | ||
|
Contributor
There was a problem hiding this comment. Choose a reason for hiding this commentThe reason will be displayed to describe this comment to others. Learn more. 🟡 Concern — This line adds integriq at the mutable Impact: anything merged to integriq's Suggested fix: in the shared workflow, give the jobs that install third-party apps Done when:
Found by the persistence audit; the shared-workflow half was read from a local Introduced by #706 · finding
Contributor
There was a problem hiding this comment. Choose a reason for hiding this commentThe reason will be displayed to describe this comment to others. Learn more. |
||
| enable-sbom: true | ||
|
|
||
| # ── Licensing ──────────────────────────────────────────────────────── | ||
|
|
@@ -234,9 +255,8 @@ jobs: | |
| # formatter failure mode that made the old `.prettierrc` worth deleting. | ||
| # Centralising the config never stopped drift; the gate does. | ||
| # Measured on this tree before enabling: PASSES, 294 of 310 tracked | ||
| # frontend files in scope. This repo has TWO documentation trees and both | ||
| # are excluded by .prettierignore — `docs/` and the separate `docusaurus/` | ||
| # site, which has its own package.json and its own toolchain. | ||
| # frontend files in scope. The documentation site in `docs/` is excluded | ||
| # by .prettierignore: it has its own package.json and its own toolchain. | ||
| # `check:l10n-js` regenerates l10n/<locale>.js from the JSON catalogue and | ||
| # fails when the committed file is stale. Nextcloud serves ONLY the JS half | ||
| # to a browser — raw JSON out of an app directory is a 404 — so a catalogue | ||
|
|
||
| Original file line number | Diff line number | Diff line change |
|---|---|---|
|
|
@@ -36,7 +36,7 @@ Vrij en open source onder de EUPL-1.2-licentie. | |
|
|
||
| **Ondersteuning:** Voor ondersteuning, neem contact op via [email protected]. | ||
| ]]></description> | ||
| <version>0.3.2-unstable.20260910105221</version> | ||
| <version>0.3.4-unstable.20260912202807</version> | ||
| <licence>EUPL-1.2</licence> | ||
| <author mail="[email protected]" homepage="https://www.conduction.nl/">Conduction</author> | ||
| <namespace>Keepiq</namespace> | ||
|
|
@@ -94,17 +94,19 @@ Vrij en open source onder de EUPL-1.2-licentie. | |
| <!-- | ||
| Floor is 32, fleet-wide, so PHP 8.3 is guaranteed by the platform. | ||
|
|
||
| 31 was never actually deliverable: the CI matrix already tests only | ||
| stable32 (see nextcloud-test-refs in .github/workflows/ | ||
| code-quality.yml), because OpenRegister — which this app builds on — | ||
| declares `<nextcloud min-version="32" max-version="34"/>` itself. Advertising 31 in | ||
| the App Store promised a range no test leg covered and no dependency | ||
| could satisfy. | ||
|
|
||
| max-version stays 34, which is the fleet-wide value everywhere | ||
| except openconnector (35). | ||
| 31 was never actually deliverable: the CI matrix is derived from | ||
| this `<nextcloud>` range (no leg below 32), because OpenRegister — | ||
| which this app builds on — declares `min-version="32"` itself. | ||
| Advertising 31 in the App Store promised a range no test leg covered | ||
| and no dependency could satisfy. | ||
|
|
||
| max-version is 35 as of 2026-09-15: verified against Nextcloud 35 | ||
| (35.0.0 dev) on the shared dev instance — keepiq enabled, its DB | ||
| migrations ran cleanly under `occ upgrade`, and the log showed no | ||
| deprecations or errors. Dependencies openregister and integriq also | ||
| declare 35 on development (verified 2026-09-24). | ||
| --> | ||
| <nextcloud min-version="32" max-version="34"/> | ||
| <nextcloud min-version="32" max-version="35"/> | ||
| </dependencies> | ||
|
|
||
| <background-jobs> | ||
|
|
||
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
🟡 Concern — the development → beta promotion runs no CI, so the beta release is cut before Playwright has seen the promoted tree
Risk category: untested code reaching a release channel. Why E2E Tests (Playwright), Hydra Gates (axe), Coverage Baseline and app:check-code were skipped on 5b729df:
development: sharedquality.ymle2e-promotion-onlydefaults to true (2026-09-13), so push/PR traffic ondevelopmentis "NOT RUN (declared)"; the PR-event run of this promotion PR never started, because this file's job-levelif: (github.event_name != 'pull_request' || github.head_ref != 'development')(line 115, bc82eb4, 2026-09-03) skips everydevelopment → betaPRenable-axenot set (default false) andneeds: playwrightif: github.event_name == 'pull_request', and the PR run is skipped by line 115enable-check-codedefault false —occ app:check-codeno longer existsThe shared workflow moved E2E onto "the promotion path" (PRs into
beta/main) one week after line 115 started skipping exactly that PR, so for keepiq the promotion intobetais the one trigger that runs nothing.release.ymlpublishes on push tobeta: itsbetajob ran at 2026-09-29T15:12:52Z on the merge commit 18f594c. The newest E2E evidence at that moment was the nightly dispatch run on fb90ffe, 33 commits behind 5b729df. E2E on the identical tree came only incidentally, from the beta → main PR (run 36589974816: 82 passed, 2 skipped, the three integrations-page tests green), finishing at 15:58 — after the beta artifact was out. This time it was green; nothing structural made it so.The comment added at line 190–193 ("Without it … integrations-page.spec.ts fails on every run") reads as if E2E runs on every run; on
developmentit runs only on the nightly dispatch.Impact: any regression only Playwright catches (the vault-unlock, compromise-recovery and integrations flows this release touched) reaches the App Store beta channel before any check could fail on it.
Suggested fix: let the promotion PR run the heavy tier — narrow line 115 to skip only the duplicate fast tier, or drop it now that
e2e-promotion-onlyalready keeps E2E off ordinarydevelopmenttraffic — or gaterelease.yml'sbetajob on a green E2E for the same SHA. Reword lines 190–193 to say when the spec runs.Done when:
development → betaPR shows a non-skippedquality / E2E Tests (Playwright)check (gh pr checks <N> -R ConductionNL/keepiq | grep E2E)release.yml'sbetajob has aneeds/condition on a green E2E run for its SHAIntroduced by composition: keepiq bc82eb4 (pre-existing, 2026-09-03) + ConductionNL/.github e2e-promotion-only default (2026-09-13); misleading comment from #706 · finding
s2-f2· review of the #691 release promotion at 5b729dfThere was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Tracked as #882 — #691 is already merged, so this is filed against
developmentrather than fixed here.