Repository navigation
ci(elixir): start Postgres + ArangoDB so mix test can run - #211
Merged
Merged
Conversation
`mix test` is aliased to ecto.create + ecto.migrate + arango.setup, and the standards reusable started no database, so every run died with "The database for EvidenceGraph.Repo couldn't be created" before a single test executed. Pins the reusable at the commit that adds opt-in postgres-image / arangodb-image inputs and passes digest-pinned images. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01Vwyfa8Eq6GYCqYnwo4fqGb
Merged
6 of 13 tasks
Contributor
|
Note Currently processing new changes in this PR. This may take a few minutes, please wait... ⚙️ Run configuration
📒 Files selected for processing (1)
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
With databases available the suite runs: 344 tests, 0 failures. `mix test --cover` then failed on Elixir's implicit 90% default threshold (measured 29.73%). Record the real level as a ratchet. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01Vwyfa8Eq6GYCqYnwo4fqGb
|
hyperpolymath
marked this pull request as ready for review
October 7, 2026 07:13
hyperpolymath
added a commit
to hyperpolymath/standards
that referenced
this pull request
Oct 7, 2026
) ## Summary `elixir-ci-reusable.yml` starts no database. Any Ecto app whose `mix test` alias runs `ecto.create` therefore dies before a single test executes. bofig `main` fails this way on every run: `** (Mix) The database for EvidenceGraph.Repo couldn't be created`, after `tcp connect (localhost:5432): connection refused`. This PR adds two **optional** inputs, both defaulting to empty: - `postgres-image`: when set, Postgres runs on `127.0.0.1:5432` with `POSTGRES_HOST_AUTH_METHOD=trust`. - `arangodb-image`: when set, ArangoDB runs on `127.0.0.1:8529` with `ARANGO_NO_AUTH=1`. With auth off, whatever test credentials a repo's `config/test.exs` uses are accepted, and the reusable carries no password literals. A `Wait for opt-in databases` step polls readiness for up to 120 s. If a server never comes up, it fails by name and prints the container logs. **Why `docker run` steps and not a `services:` block:** tma-mark2 calls this reusable with `runs-on: self-hosted`. Service containers need Docker and Linux on the runner, and I have no evidence that a `services:` block with every image empty is harmless there. With step-level `if:` gates, a caller that sets neither input runs exactly the steps it runs today. Image values reach the scripts through `env:` and are never interpolated, so they cannot inject shell. The owner approved a Postgres input. ArangoDB is included because bofig's test alias also runs `arango.setup`, so Postgres alone would still leave its suite unable to run. Closes # — no issue; found while triaging bofig#208 (mint security bump). ## Type of change - [ ] 🐛 Bug fix: not in the strict sense. Existing callers are unchanged; the new inputs are opt-in. - [x] ✨ New feature (non-breaking change that adds functionality) - [ ] 💥 Breaking change: no. Both inputs default to empty and are skipped. - [ ] 🕳️ Soundness fix: no. - [ ] 📖 Documentation: only the header comment and input descriptions in the same file. - [ ] 🧹 Refactor / tech debt: no. - [ ] ⚡ Performance: no. - [x] 🔧 Build / CI / tooling ## 📌 New pins - **Head SHA: `1c62ff84348892e4ee23ccf58576f8d1c728ddbe`** - No new or changed `uses:` pins. `actions.lock` is unchanged. - No container digests are pinned here. Callers pass their own digest-pinned images, e.g. hyperpolymath/bofig#211. ## How has this been verified? - `actionlint .github/workflows/elixir-ci-reusable.yml` reported nothing. - `bunx --bun js-yaml` parsed the file. - `bash scripts/check-lock-sync.sh .github/workflows` reported "actions.lock is in sync", rc=0. - `gh actions-lock --verify` output on this branch is byte-identical to its output on `main` (diffed). - The pre-commit suite passed: gitleaks, SPDX, SHA-pinning, actions-lock coverage, permissions, bot directives. - Caller enumeration covered **local clones only** (`hyper-repos/` + `meta-repos/`): 2 callers besides bofig. One is tma-mark2 on `self-hosted`, which is the reason for the step design. GitHub code search was not used. - **End-to-end: PASSED.** hyperpolymath/bofig#211 pins this head SHA. On bofig head `7bbd50cb` its `elixir-ci / Compile + test` is green (job 112674037440): both containers started, "databases ready", `arango.setup` created collections, **344 tests, 0 failures**. The earlier head `16014635` also ran 344 tests with 0 failures but failed on Elixir's implicit 90% coverage threshold, which bofig now sets explicitly. ## Checklist - [x] My commits are **signed** (`git commit -S`); `%G?` = `G`. - [x] I ran the project's own checks/tests locally and they pass: pre-commit suite, `check-lock-sync.sh`, actionlint. - [ ] New files carry the correct `SPDX-License-Identifier`: n/a, no new files. The existing MPL-2.0 header is kept. - [x] Docs are updated. The header caller example and input descriptions describe the new inputs, and nothing claims more than they do. - [x] I have not introduced a soundness hole. With both inputs empty, every new step is skipped. ## Notes for reviewers - The squash-merge SHA, not this branch head, is what bofig should finally pin. hyperpolymath/bofig#211 will be re-pinned after merge. - `docker exec … pg_isready` runs inside the container, so it needs no client on the runner. The Arango probe is `curl` from the runner against `/_api/version`. 🤖 Generated with [Claude Code](https://claude.com/claude-code) https://claude.ai/code/session_01Vwyfa8Eq6GYCqYnwo4fqGb Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com>
5 of 13 tasks
hyperpolymath
added a commit
that referenced
this pull request
Oct 7, 2026
## Summary bofig#211 pinned `elixir-ci-reusable.yml` to `1c62ff84`, the **pre-squash branch head** of standards#1190. That PR's body flagged the pin as provisional. When the branch was deleted after the squash merge, the SHA stopped resolving. Every `elixir-ci` run since then has failed at startup with **0 jobs**: | Time (UTC) | Event | Head | Conclusion | |---|---|---|---| | 07:13:27 | push | `f5e414f5` (#211 merge) | **success** | | 07:15:54 | pull_request | `d12a9f4e` | failure | | 09:59:28 | pull_request | `7c2b4129` | failure | | 10:02:03 | push | `e59b3f6d` (#207) | failure | | 10:02:07 | pull_request | `1e016a4c` | failure | | 10:03:48 | push | `cc41782a` (#208) | failure (run 37604869992) | This PR re-pins to `d7b85cac`, the squash merge on standards `main`. `git diff 1c62ff84 d7b85cac -- .github/workflows/elixir-ci-reusable.yml` is empty, so the called workflow is byte-identical. The pin is the only change, one line. ## Type of change - [x] 🐛 Bug fix (non-breaking change that fixes an issue): `elixir-ci` cannot start on `main`. - [ ] ✨ New feature: no. - [ ] 💥 Breaking change: no. - [ ] 🕳️ Soundness fix: no. The workflow is unchanged; only the ref changes. - [ ] 📖 Documentation: no. - [ ] 🧹 Refactor / tech debt: no. - [ ] ⚡ Performance: no. - [x] 🔧 Build / CI / tooling ## 📌 New pins - **Head SHA: `e9476eb`** (see the commit list for the full SHA) - **`hyperpolymath/standards/.github/workflows/elixir-ci-reusable.yml@d7b85cac57eb16edf51508d6f30806e86d63c9d3`** (standards#1190 squash merge, an ancestor of standards `main`). Was `@1c62ff84348892e4ee23ccf58576f8d1c728ddbe`, the deleted branch head. - The container digests are unchanged. `actions.lock` is unchanged: it records no reusable-workflow refs, and it held no `elixir-ci.yml` key at `f5e414f5` either, where the run was green. ## How has this been verified? - `git merge-base --is-ancestor d7b85cac origin/main` in the standards clone: true. - `git ls-remote origin ci/elixir-reusable-db-services`: empty, so the old pin's branch is gone. - `git diff 1c62ff84 d7b85cac -- .github/workflows/elixir-ci-reusable.yml`: empty. - `actionlint .github/workflows/elixir-ci.yml`: rc=0, no output. - The run on this PR is the end-to-end test. It should reproduce #211's result: 344 tests, 0 failures, 21 excluded. ## Checklist - [x] My commits are **signed** (`git commit -S`); `%G?` = `G`. - [ ] I ran the project's own checks/tests locally and they pass: no. This machine has no BEAM toolchain; CI is the test. - [ ] New files carry the correct `SPDX-License-Identifier`: n/a, no new files. - [x] Docs are updated, and no public claim now overstates what the code does: no docs are affected. - [x] I have not introduced a soundness hole. ## Notes for reviewers Lesson for the estate, recorded in dev-notes: never merge a caller pinned to a reusable's PR-branch head. Re-pin to the squash SHA **before** the callee's branch is deleted, or the caller breaks silently with a 0-job startup failure that check-run listings do not show. 🤖 Generated with [Claude Code](https://claude.com/claude-code) https://claude.ai/code/session_01Vwyfa8Eq6GYCqYnwo4fqGb Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.



Summary
elixir-ci / Compile + testis red onmain(7363608) and has never run a test. Themix testalias isecto.create --quiet,ecto.migrate --quiet,arango.setup,test, and the standards reusable started no database. Every run therefore dies at** (Mix) The database for EvidenceGraph.Repo couldn't be created.This PR does two things:
postgres-imageandarangodb-imageinputs.config/test.exs:localhost:5432andhttp://localhost:8529.It unblocks #208 (mint 1.11.0 security bump). That PR compiles identically to
main, but no test has run on either.Draft until standards#1190 merges. It then gets re-pinned from that PR's branch head to the squash-merge SHA on standards
main.Closes # — no issue.
Type of change
mix.exsgains a coverage ratchet at the measured 29% floor. Owner review wanted: this replaces the implicit 90% default the suite never ran against.📌 New pins
7bbd50cb4d291b9230aec3250566357c9616c225hyperpolymath/standards/.github/workflows/elixir-ci-reusable.yml@1c62ff84348892e4ee23ccf58576f8d1c728ddbe(standards#1190 branch head; was@8f2ee50841e216cd8c192eeb68953118190f105c). Provisional, to be replaced by the squash SHA.postgres:16@sha256:65b16a8b326e0cfbdf33fa7e783f2a0cb352a61448616ccccfd616ef42aa0f65(Docker Hublibrary/postgres:16index digest, resolved 2026-10-07)arangodb:3.12@sha256:4bc086d5050ca7ea11c6d00a36d8b910c838bb54ad553f8c1b715769d3499bcf(Docker Hublibrary/arangodb:3.12index digest, resolved 2026-10-07)actions.lockis unchanged. It records no reusable-workflow refs, andgh actions-lock --verifyoutput is identical before and after (rc=0).How has this been verified?
actionlint .github/workflows/elixir-ci.ymlreported nothing.gh actions-lock --verifywas diffed before and after: identical, rc=0.mise.toml.16014635: databases ready, 344 tests, 0 failures, 21 excluded, then exit 3 on Elixir's implicit 90% coverage threshold (measured 29.73%).7bbd50cb(addstest_coverage: [summary: [threshold: 29]]tomix.exsas a ratchet):elixir-ci / Compile + testsuccess (job 112674037440).Checklist
git commit -S);%G?=G.SPDX-License-Identifier: n/a, no new files.Notes for reviewers
The tests have never run in CI, so genuine failures may surface here. Any that do are pre-existing on
main, not caused by this PR or #208.🤖 Generated with Claude Code
https://claude.ai/code/session_01Vwyfa8Eq6GYCqYnwo4fqGb