Skip to content

Commit 25d1568

Browse files
authored
ci: run tests on Blacksmith with the latest WFL nightly (#14)
Run all five Scriptorium suites and the pinned Scribe suite in the freshly pulled WFL nightly Docker image. Record its resolved digest and runtime/source revisions, preserve test failure propagation, and move Linux tooling checks to Blacksmith. Verified 138 runtime tests and 36 tooling tests; an intentional failing assertion also confirmed that GitHub Actions rejects test failures. Update CI and contributor documentation. Closes #13.
1 parent 64edc96 commit 25d1568

7 files changed

Lines changed: 143 additions & 26 deletions

File tree

‎.github/workflows/governance.yml‎

Lines changed: 6 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -20,8 +20,12 @@ jobs:
2020
strategy:
2121
fail-fast: false
2222
matrix:
23-
os: [ubuntu-latest, windows-latest]
24-
runs-on: ${{ matrix.os }}
23+
include:
24+
- os: ubuntu-latest
25+
runner: blacksmith-2vcpu-ubuntu-2404
26+
- os: windows-latest
27+
runner: windows-latest
28+
runs-on: ${{ matrix.runner }}
2529
timeout-minutes: 10
2630
steps:
2731
- uses: actions/checkout@v4

‎.github/workflows/update-scribe.yml‎

Lines changed: 7 additions & 6 deletions
Original file line numberDiff line numberDiff line change
@@ -7,10 +7,11 @@
77
# Scribe commits in the body, so the bump is reviewed rather than silent.
88
#
99
# Note on CI: GITHUB_TOKEN-created PR runs may require Maintainer approval.
10-
# Approve the pending Governance run, or use Run workflow on the PR branch;
11-
# verify that the successful run covers the current revision before merging.
12-
# Runtime tests also need recorded results; see testing.md. No extra token is
13-
# needed for the manual Governance workflow.
10+
# Approve pending Governance and WFL tests runs, or use Run workflow for both
11+
# workflows on the PR branch. Verify that successful runs cover the current
12+
# revision before merging.
13+
# Link both checks, including the nightly image digest; see testing.md. No extra
14+
# token is needed for manual workflow dispatch.
1415
# https://docs.github.com/en/actions/concepts/security/github_token
1516
#
1617
# To bump by hand instead, run scripts/update-scribe.sh.
@@ -135,12 +136,12 @@ jobs:
135136
echo
136137
echo '| Check or exact command | Result and evidence |'
137138
echo '|---|---|'
138-
echo '| `python scripts/run_tests.py --include-scribe` | Not run — this workflow prepares the dependency bump. Record the local and upstream suite results, including failures. |'
139+
echo '| `python3 scripts/run_tests.py --include-scribe` | Pending — this workflow prepares the dependency bump. Link WFL tests results for the current revision, including the nightly image digest and runtime version; record failures. |'
139140
echo '| `python -m unittest discover -s tests/tooling -v` | Pending — Governance results are not verified by this workflow. Link results for the current revision. |'
140141
echo '| `python scripts/check_repo_hygiene.py` | Pending — Governance results are not verified by this workflow. Link results for the current revision. |'
141142
echo '| Affected HTTP/UI rendering journeys | Not run — upstream diff review is needed to identify affected paths. Record setup, expected/actual outcome, and evidence. |'
142143
echo
143-
echo 'Approve any pending Governance run, or run Governance manually on this branch. Verify that successful checks cover the current revision before merging.'
144+
echo 'Approve any pending Governance and WFL tests runs, or run both workflows manually on this branch. Verify that successful checks cover the current revision before merging.'
144145
echo
145146
echo '## Checklist'
146147
echo

‎.github/workflows/wfl-tests.yml‎

Lines changed: 76 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,76 @@
1+
name: WFL tests
2+
3+
on:
4+
push:
5+
branches: [main]
6+
pull_request:
7+
branches: [main]
8+
workflow_dispatch:
9+
10+
permissions:
11+
contents: read
12+
13+
concurrency:
14+
group: wfl-tests-${{ github.ref }}
15+
cancel-in-progress: true
16+
17+
jobs:
18+
wfl-tests:
19+
name: WFL nightly (Blacksmith)
20+
runs-on: blacksmith-2vcpu-ubuntu-2404
21+
timeout-minutes: 15
22+
env:
23+
WFL_IMAGE: bsbyrdwfl/wfl:nightly
24+
TEST_CONTAINER: scriptorium-tests-${{ github.run_id }}-${{ github.run_attempt }}
25+
steps:
26+
- uses: actions/checkout@v4
27+
with:
28+
persist-credentials: false
29+
submodules: recursive
30+
31+
- name: Pull latest WFL nightly and record runtime
32+
id: runtime
33+
shell: bash
34+
run: |
35+
docker pull "$WFL_IMAGE"
36+
image="$(docker image inspect --format '{{index .RepoDigests 0}}' "$WFL_IMAGE")"
37+
echo "image=$image" >> "$GITHUB_OUTPUT"
38+
version="$(docker run --rm --network none "$image" --version)"
39+
{
40+
echo '### WFL nightly test environment'
41+
echo
42+
echo "- Image: $image"
43+
echo "- Runtime: $version"
44+
echo "- Scriptorium: $(git rev-parse HEAD)"
45+
echo "- Scribe: $(git -C lib/scribe rev-parse HEAD)"
46+
echo '- Runner: blacksmith-2vcpu-ubuntu-2404 (Linux x64)'
47+
echo '- Command: python3 scripts/run_tests.py --include-scribe'
48+
} | tee -a "$GITHUB_STEP_SUMMARY"
49+
50+
- name: Run Scriptorium and pinned Scribe suites
51+
shell: bash
52+
env:
53+
RESOLVED_IMAGE: ${{ steps.runtime.outputs.image }}
54+
run: |
55+
# The published image is a minimal runtime with a WFL entrypoint.
56+
# Install Python only in this disposable container. Scribe fixtures
57+
# go to its temporary directory; the checkout stays read-only.
58+
docker run --rm --init --name "$TEST_CONTAINER" \
59+
--user 0:0 --entrypoint /bin/sh \
60+
--mount "type=bind,source=$GITHUB_WORKSPACE,target=/work,readonly" \
61+
--workdir /work "$RESOLVED_IMAGE" -ec '
62+
apt-get update
63+
apt-get install --yes --no-install-recommends python3
64+
python3 --version
65+
wfl --version
66+
python3 scripts/run_tests.py --include-scribe
67+
'
68+
69+
- name: Clean up test container
70+
if: always()
71+
shell: bash
72+
run: |
73+
# Killing a Docker client on cancellation may leave its container up.
74+
if docker container inspect "$TEST_CONTAINER" >/dev/null 2>&1; then
75+
docker container rm --force "$TEST_CONTAINER"
76+
fi

‎CLAUDE.md‎

Lines changed: 5 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -79,8 +79,11 @@ violate the standard.
7979
`python -m unittest discover -s tests/tooling -v` and
8080
`python scripts/check_repo_hygiene.py` for repository tooling and hygiene.
8181
Python 3.11+ is needed for tooling; `wfl` is needed for application tests.
82-
The Governance workflow runs tooling tests and hygiene on Linux and Windows;
83-
WFL runtime suites currently require recorded local results. See
82+
The Governance workflow runs tooling tests and hygiene on Blacksmith Linux
83+
and GitHub-hosted Windows. The WFL tests workflow runs the application and
84+
pinned Scribe suites on Blacksmith using a freshly pulled `bsbyrdwfl/wfl:nightly` image;
85+
its summary records the resolved image digest, runtime version, and source
86+
revisions. See
8487
[testing.md](testing.md) for commands, coverage limits, and merge evidence.
8588
- **`data_dir` is an application convention, not a WFL runtime feature.**
8689
`main.wfl` reads `.wflcfg` itself at boot and parses the key via

‎CONTRIBUTING.md‎

Lines changed: 9 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -121,14 +121,21 @@ write fixtures. Follow [testing.md](testing.md) for HTTP, UI, security, migratio
121121
and recovery checks triggered by the change. Prose-only changes need relevant
122122
link, command, and hygiene checks; they do not need invented application tests.
123123

124+
The WFL tests workflow runs both application and pinned Scribe suites on
125+
Blacksmith Linux using a freshly pulled `bsbyrdwfl/wfl:nightly` Docker image.
126+
Its summary records the resolved image digest, WFL version, and tested source
127+
revisions. Link the current revision's run as CI runtime evidence; retain any
128+
local regression or boundary evidence needed for the change. Governance checks
129+
repository tooling and hygiene on Blacksmith Linux and GitHub-hosted Windows.
130+
124131
Keep PRs focused and use conventional commit subjects such as `fix:`, `feat:`,
125132
`docs:`, `test:`, `refactor:`, and `chore:`. Follow the PR format below.
126133

127134
Do not include passwords, session cookies, tokens, user databases, or personal
128135
content in logs or fixtures. A review must resolve blocking findings before
129136
merge. A bot-created dependency PR needs the same evidence as a human-authored
130-
PR; approve any pending workflow run or run the Governance workflow manually on
131-
the proposed branch, then verify the tested revision and runtime results.
137+
PR; approve any pending workflow runs or run both Governance and WFL tests
138+
manually on the proposed branch, then verify the tested revision and results.
132139

133140
GitHub review and branch-protection settings are maintained on the repository
134141
host. Adding these documents or workflows does not configure those settings.

‎README.md‎

Lines changed: 10 additions & 4 deletions
Original file line numberDiff line numberDiff line change
@@ -217,8 +217,13 @@ python scripts/check_repo_hygiene.py
217217
```
218218

219219
Individual suites still run with `wfl --test TestPrograms/<name>.test.wfl`.
220-
The Governance workflow checks tooling and repository hygiene on Linux and
221-
Windows. Runtime test results must currently be recorded on the PR. See
220+
The [WFL tests workflow](.github/workflows/wfl-tests.yml) runs all five
221+
Scriptorium suites and the pinned Scribe suite on Blacksmith Linux using the
222+
latest `bsbyrdwfl/wfl:nightly` Docker image. It pulls the nightly tag on each run
223+
and records the resolved image digest, runtime version, and tested source
224+
revisions in the job summary. The Governance workflow checks tooling and
225+
repository hygiene on Blacksmith Linux and GitHub-hosted Windows. Link results
226+
for the current revision on the PR. See
222227
[testing.md](testing.md) for coverage, commands, and checks for changes to
223228
HTTP routes, security, themes, or stored data.
224229

@@ -244,8 +249,9 @@ git commit -m "chore(scribe): update lib/scribe"
244249

245250
`.github/workflows/update-scribe.yml` does the same thing on a weekly schedule
246251
(and on demand via *Run workflow*), opening a PR with the Scribe commits it
247-
picked up. Maintainers must verify Governance checks for the current revision
248-
and record runtime test results before merging; see [testing.md](testing.md).
252+
picked up. Maintainers must verify Governance and WFL tests results for the
253+
current revision before merging; bot-created PRs may need both workflows
254+
dispatched manually on their branch. See [testing.md](testing.md).
249255
Delete that file if you would rather bump by hand only.
250256

251257
Working on Scribe itself? `lib/scribe` is a normal git checkout — commit and

‎testing.md‎

Lines changed: 30 additions & 10 deletions
Original file line numberDiff line numberDiff line change
@@ -6,7 +6,7 @@ limits of the tooling that exists today. It does not claim that the repository
66
already implements every gate required for a release.
77

88
- Policy and profile version: 1.0.
9-
- Adopted and reviewed: 2026-09-12.
9+
- Adopted: 2026-09-12; CI profile updated: 2026-09-20.
1010
- Test-suite and infrastructure owner: the Maintainer named in
1111
[GOVERNANCE.md](GOVERNANCE.md).
1212
- Next adoption-gap review: 2026-10-12, or before the next affected behavioral
@@ -194,19 +194,33 @@ keyboard behavior, or data integrity.
194194

195195
## CI, merge, and release gates
196196

197-
[.github/workflows/governance.yml](.github/workflows/governance.yml) runs the
198-
repository hygiene and tooling checks. The application suites still require a
199-
local WFL run; there is no pinned-runtime application-test CI job or automated
200-
HTTP/browser journey suite in this repository. The scheduled Scribe updater
201-
proposes dependency changes; it is not runtime test evidence.
197+
[Governance](.github/workflows/governance.yml) runs repository hygiene and tooling
198+
checks on Blacksmith Linux and GitHub-hosted Windows.
199+
[WFL tests](.github/workflows/wfl-tests.yml) runs the five application suites and the pinned Scribe suite via
200+
`python3 scripts/run_tests.py --include-scribe` on
201+
`blacksmith-2vcpu-ubuntu-2404`. Both workflows run for pushes and pull requests to
202+
`main` and support manual dispatch.
203+
204+
WFL tests pulls `bsbyrdwfl/wfl:nightly` from Docker Hub for every run, resolves
205+
the image digest, and uses that immutable image for that run's runtime checks.
206+
Python is installed in the disposable test container and the source checkout is
207+
mounted read-only. The job summary records the resolved image digest,
208+
`wfl --version`, and tested Scriptorium and Scribe revisions. The nightly tag is
209+
moving: retain the run URL and digest with PR evidence so a later nightly does
210+
not obscure which runtime was tested. The nightly workflow is not a declaration
211+
that every nightly, platform, or production configuration is supported.
212+
213+
There is no automated HTTP/browser journey suite in this repository. The
214+
scheduled Scribe updater only proposes dependency changes; its successful run
215+
alone is not runtime test evidence.
202216

203217
Before merge, required checks MUST pass on the final proposed revision, evidence
204218
MUST cover the affected behavior and risk, and blocking reviews MUST be resolved.
205219
Recheck after changes that invalidate prior results. Maintainers configure
206220
required status checks and review protections on GitHub; repository files alone
207221
do not activate host settings. Bot PRs follow the same review and test rules;
208-
approve pending workflow runs or manually dispatch Governance on the proposed
209-
branch and verify that its revision matches the proposal.
222+
approve pending workflow runs or manually dispatch both Governance and WFL tests
223+
on the proposed branch and verify that their revisions match the proposal.
210224

211225
Before a production release, the Maintainer MUST identify the immutable
212226
Scriptorium and Scribe revisions, runtime version, deployed configuration, and
@@ -222,12 +236,18 @@ measurement and passing criteria before making such a claim.
222236

223237
## Adoption gaps and follow-through
224238

225-
The Maintainer owns this dated register as of 2026-09-12. Each item requires an
239+
The Maintainer owns this dated register as of 2026-09-20. Each item requires an
226240
owned issue before implementation and a link here when that issue exists.
227241

242+
WFL application-test automation is implemented by the WFL tests workflow under
243+
[issue #13](https://github.com/WebFirstLanguage/Scriptorium/issues/13), owned by
244+
Brad. [PR #14](https://github.com/WebFirstLanguage/Scriptorium/pull/14) retains
245+
the Blacksmith runtime evidence, including an intentional assertion failure
246+
used to verify that failures reach GitHub Actions. Host protection settings
247+
remain a separate adoption item below.
248+
228249
| Gap | Required next step and trigger |
229250
|---|---|
230-
| WFL application suites are manual | Pin and provision a runtime in CI; evaluate before the next behavioral PR. Until then attach exact local results to every affected PR. |
231251
| No router/HTTP or browser automation | Add real-boundary regression coverage with each affected behavior change; plan coverage of all critical journeys before the next production release. |
232252
| No declared compatibility matrix or release-candidate workflow | Define supported runtime/platform/configuration tuples and retain candidate results before the next production release. |
233253
| No coverage measurement, performance budgets, or scheduled extended tests | Establish baselines and risk-based targets before claiming those properties; review at the next profile review. |

0 commit comments

Comments
 (0)