From 702dd71f4cb49c6378d20ec99c8bbcd76ae1f1a2 Mon Sep 17 00:00:00 2001 From: Joakim Persson Date: Sun, 6 Sep 2026 23:40:26 +0200 Subject: [PATCH] ci: declare workflow_dispatch input types so Gitea renders the dispatch form Gitea (1.26.2) builds the "Run workflow" dialog from each input's `type:`. With no type declared, the form renders a branch selector and NO input fields, so a manual run silently takes every default -- and for release_tag: '' that means env.RELEASE_TAG resolves EMPTY, the variant tag list becomes `:`, and the run dies on an invalid docker reference only AFTER paying the full base + smoke cost (~70 min). Net effect: the `smoke_only` escape hatch documented in this file's own header has been unreachable from the UI for its entire existence. Found 2026-09-06 while trying to use it to validate three new smoke assertions before cutting v1.8.13. Typed as `string`, deliberately, even though promote_latest/smoke_only read as booleans: all six consumption sites compare strings against 'true' (inputs.smoke_only != 'true' at both build-variant gates, inputs.promote_latest == 'true' at both promote gates) or interpolate into env.PROMOTE_LATEST. A boolean-typed input yields a real boolean, so `!= 'true'` would compare across types and could invert a publish gate silently rather than fail loudly. This keeps the change a pure rendering fix with zero semantic delta; switching to boolean would require re-auditing all six call sites. Validated locally with CI's own pinned tools before pushing, because lint is the only gate on this file: actionlint 1.7.7 exit 0 (clean baseline before the edit, clean after), shellcheck 0.10.0 -S error exit 0 across all 17 shell files, and a pyyaml structural check confirming the three inputs still carry string defaults, the `v*` tag trigger is intact, and all 9 jobs still parse. --- .gitea/workflows/docker-publish.yml | 23 ++++++++++++++++++++++- 1 file changed, 22 insertions(+), 1 deletion(-) diff --git a/.gitea/workflows/docker-publish.yml b/.gitea/workflows/docker-publish.yml index 83e87da..ff65090 100644 --- a/.gitea/workflows/docker-publish.yml +++ b/.gitea/workflows/docker-publish.yml @@ -33,18 +33,39 @@ on: - 'v*' workflow_dispatch: inputs: + # `type:` is REQUIRED for Gitea to render these fields in the "Run + # workflow" dialog. Without it (Gitea 1.26.2) the dispatch form shows a + # branch selector and NO inputs at all, so a manual run silently uses + # every default — which for `release_tag: ''` means RELEASE_TAG resolves + # empty, the variant tag list becomes `:`, and the run dies on an + # invalid reference AFTER paying the full base + smoke cost (~70 min). + # That made the documented `smoke_only` escape hatch below unreachable + # from the UI for its whole existence; found 2026-09-06 trying to use it. + # + # Deliberately `string` and not `boolean`, even though these two read as + # flags: every consumption is a STRING comparison against 'true' + # (`inputs.smoke_only != 'true'` at the build-variant gates, + # `inputs.promote_latest == 'true'` at the promote gates) plus string + # interpolation into env.PROMOTE_LATEST. A boolean-typed input yields a + # real boolean, so `!= 'true'` would compare across types and could + # invert a publish gate rather than fail loudly. Changing the type here + # would mean re-auditing all six call sites; keeping it string is a + # rendering fix with provably zero semantic change. release_tag: description: 'Release tag to publish (e.g. v1.0.0). Used only for workflow_dispatch runs.' required: false default: '' + type: string promote_latest: description: 'Update latest aliases (default true for tag-push, false for manual test runs)' required: false default: 'false' + type: string smoke_only: - description: 'Build base + run both smoke jobs against HEAD, then stop. Publishes nothing. Use to validate smoke assertions without cutting a tag.' + description: 'Build base + run both smoke jobs against HEAD, then stop. Publishes nothing. Use to validate smoke assertions without cutting a tag. Set to the literal string true.' required: false default: 'false' + type: string concurrency: group: ${{ github.workflow }}-${{ github.ref }}