Files
noitu/.github/workflows/proto.yml
T
tiennm99 8223f40b16 feat(server): counters, readiness, drain mode and a version stamp
expvar counters for connections, rooms, games, submissions by rejection
reason, eliminations, chat, joins and bot moves, served on a separate
debug address so they never sit on the public mux, plus one structured
word_rejected log line per refused word carrying the normalized word and
its link. GET /readyz flips to 503 while draining; SIGTERM stops new
rooms, waits up to NOITU_DRAIN_TIMEOUT for live games, then shuts down.
GET /version and the startup log carry the build's git describe.

Fuzz targets for the frame decoder, the text sanitizer and Vietnamese
normalization; the last one found that composing before lowercasing
could leave a non-NFC result, now recomposed after lowering.

CI runs on dev as well as main, gates gofmt and golangci-lint, tracks the
buf major instead of an exact pin, and dependabot watches every
ecosystem. The lint findings that had been hidden by the default
per-issue cap are fixed.
2026-09-21 01:17:52 +07:00

65 lines
2.1 KiB
YAML

# Guards the WebSocket wire contract: the schema is well-formed, it has not
# broken compatibility, and the committed generated code matches it.
#
# The suites that decode the cross-language fixtures run in ci.yml, where the
# rest of the tests are. Nothing here downloads the upstream wordlist.
name: proto
on:
push:
branches: [main, dev]
pull_request:
permissions:
contents: read
jobs:
contract:
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@v4
with:
# buf breaking compares against main, which needs real history.
fetch-depth: 0
# A moving version rather than an exact pin, per house rule: updates
# arrive on the next run, and a breaking major would surface here before
# it could surprise a contributor's own machine.
- uses: bufbuild/buf-setup-action@v1
with:
version: latest
- uses: actions/setup-go@v5
with:
go-version-file: server/go.mod
cache-dependency-path: server/go.sum
- uses: actions/setup-node@v4
with:
node-version: 24
cache: npm
cache-dependency-path: web/package-lock.json
- run: npm ci
working-directory: web
- name: Lint the schema
run: buf lint
# ref=origin/main, not branch=main: a pull_request checkout is a detached
# HEAD with no local main, and branch=main fails there with a git clone
# error rather than a breaking-change report.
- name: Reject breaking changes
run: buf breaking --against '.git#ref=origin/main'
# A committed generated tree that no longer matches the schema is worse
# than no generated tree at all: it compiles, and it is wrong.
# --intent-to-add first: git diff ignores untracked files, so without it
# a plugin that starts emitting a new file passes this check while the
# committed tree is incomplete.
- name: Verify the committed generated code is in sync
run: |
buf generate
git add --intent-to-add -- server/gen web/src/lib/proto
git diff --exit-code -- server/gen web/src/lib/proto