Commit Graph
18 Commits
Author SHA1 Message Date
Divarion_D 734f4751c9 chore(tests): move phpunit.phar into tests/ and repoint references
The committed PHPUnit runner lived at tools/.bin/phpunit.phar, away from
the suite it runs. Move it next to the tests it drives —
tests/phpunit.phar — and update every invocation to
`php tests/phpunit.phar -c tests/phpunit.xml.dist`:

- CI workflows (ci, build-release, build_pre-release) + the ci.yml header,
- CLAUDE.md, CONTRIBUTING.md, tools/README.md, the qa-lead-reviewer agent,
- docs/en (dev-workflow, updates_checklist, phpunit-phar, refactoring).

docs/ru is generated from docs/en (make docs-translate) and is left for
the next regeneration, per the docs workflow.
2026-09-13 22:04:10 +03:00
Divarion_D 9dd2ac2a48 chore(cs): replace PHP-CS-Fixer with phpcs + Slevomat Coding Standard
PHP-CS-Fixer's `no_unused_imports` is conservative — it treats a class name that
merely appears in a PHPDoc *description* as "used", so genuinely-dead imports
(e.g. `use ...Request;` next to a "Request IP" doc description) were never
flagged. Slevomat's UnusedUses is precise: it parses annotation *types*
(@param/@return/@var), so it keeps docblock-typed imports but removes truly
unused ones — matching what Intelephense (P1003) reports.

- Swap require-dev: friendsofphp/php-cs-fixer -> squizlabs/php_codesniffer +
  slevomat/coding-standard (+ phpcodesniffer-composer-installer, allow-listed).
- New narrow ruleset build/phpcs.xml.dist (import/namespace hygiene only, NOT
  full PSR-12): UnusedUses (searchAnnotations=true), UseFromSameNamespace,
  UseDoesNotStartWithBackslash, AlphabeticallySortedUses, UseSpacing,
  NamespaceSpacing. View templates stay excluded.
- Makefile: `make cs` -> phpcs, `make cs-fix` -> phpcbf (same target names).
- CI code-style job, CLAUDE.md, CONTRIBUTING.md, docs, .gitignore updated;
  build/.php-cs-fixer.dist.php removed. Committed vendor stays production-only.
2026-08-21 17:55:24 +03:00
Divarion_D 7f3812e165 chore(build): move phpstan / php-cs-fixer config out of the repo root
Relocate the dev-tooling config into build/ so the project root only holds
source and first-class project files:
- phpstan.dist.neon        -> build/phpstan.dist.neon
- phpstan-baseline.neon    -> build/phpstan-baseline.neon
- .php-cs-fixer.dist.php    -> build/.php-cs-fixer.dist.php
- .php-cs-fixer.cache       -> build/ (regenerated there; gitignored)

Because neon/CS-Fixer resolve relative paths against the config file's own
directory, the internal references are re-anchored one level up (src/ ->
../src/, tools/ -> ../tools/, Finder in(__DIR__.'/../src'); the baseline's
path: entries likewise). The Makefile now points PHPStan at the config with
-c build/phpstan.dist.neon (it previously relied on root auto-discovery),
generates the baseline into build/, and passes --config=build/... to CS-Fixer;
the CS-Fixer cache is pinned to build/ via setCacheFile and re-gitignored.

No behaviour change. Verified: make phpstan (No errors), make cs (0 fixable),
make gates. CI runs through these make targets, so it is covered.
2026-08-09 19:37:11 +03:00
Divarion_D 904ea4859c Update Github CI 2026-08-07 21:39:59 +03:00
Divarion_D b83cb86fbb ci: run CI once per change (scope push to main, add concurrency) 2026-08-06 21:31:46 +03:00
Divarion-D 8d39f90902 chore(tools): remove php_syntax_check.sh — covered by PHPStan/CS/PHPUnit
`php -l` syntax checking is redundant with the real linters/validators (PHPStan
  parses the code, PHP-CS-Fixer and the PHPUnit bootstrap also fail on parse
  errors). Remove the script and every reference to it:

  - Makefile: drop the `syntax_check` target and its .PHONY entry.
  - CI (ci.yml): drop the dedicated `lint` (PHP Syntax Check) job.
  - Release workflows (build-release, build_pre-release): drop the "Check syntax"
    step from the Quality Gate (PHPUnit remains).
  - CONTRIBUTING.md: replace the syntax-check pre-commit guidance with the real
    checks (make dev-tools / phpstan / cs / gates / phpunit).
  - updates_checklist (en/ru): replace `make syntax_check` with the quality-check
    suite and drop the stale "Security scan" snippet that referenced the removed
    script and a non-existent tools/run_scan.sh (Semgrep runs automatically in CI).
2026-06-26 19:00:10 +03:00
Divarion-D baf6c8e231 build: ship a production-only vendor; install dev tools via Composer
Switch from "commit vendor with dev deps + strip at release" to the standard
application model: the committed src/vendor/ is PRODUCTION-ONLY, and dev tooling
(PHPStan, PHP-CS-Fixer + ~37 transitive deps) is installed on demand with
"composer install".

- Regenerate the committed src/vendor/ via "composer install --no-dev"
  (34 MB -> ~0.5 MB; only the Composer autoloader + gemorroj/m3u-parser +
  chrisyue/php-m3u8 remain). This also stops PHPStan\PharAutoloader registering
  in production.
- Commit src/composer.lock (un-ignored) — this is an application, so the lock is
  committed to make "composer install" reproducible across dev/CI.
- Revert the release-time strip step (Makefile hooks + tools/build/
  strip-dev-vendor.sh) — no longer needed; the archive ships the prod vendor as-is.
- CI: the phpstan and code-style jobs now run "composer install --working-dir=src"
  (with tools: composer) to obtain the dev tools before running.
- New gate tools/ci/check-vendor-prod-only.sh (+ make check-vendor-prod-only,
  wired into "make gates"): asserts no require-dev package from composer.lock is
  committed under src/vendor/ — guards against accidentally committing a
  dev-bloated vendor. Inspects git-tracked files, so it is correct even in a CI
  job that already ran "composer install".
- Fix verify-lb-archive.sh: LB legitimately ships most of Cli/Commands and
  Cli/CronJobs (edge commands + certbot/cache/cleanup crons), so flag only the
  genuinely privileged dirs + the specific install/root files, not the whole dirs.
- .gitignore / composer.json notes updated.

Verified before pruning: PHPStan no errors, PHPUnit 303, cs + gates green. After
pruning: PHPUnit 303 (prod-only vendor), all three gates green. Local dev tools
restored afterwards with "composer install" (not committed).
2026-06-25 21:51:13 +03:00
Divarion-D fd35f00c4d fix(views): import migrated classes at top of 5 admin view templates
enigma, episode, episodes, process_monitor and stream_view referenced migrated
classes (UserRepository, BouquetService, StreamRepository, RequestManager,
SettingsManager, ...) by short name with either no `use` or a `use` placed
*below* the first usage. PHP imports outside the top scope are positional, so the
short name resolved to a now-nonexistent global class — a runtime fatal on those
admin pages (php -l passes; not covered by PHPStan/PHPUnit). The migration's
automated `use` insertion missed them due to the interleaved HTML / short-tag
(<? , <?=) structure, and the later php-cs-fixer pass stripped some as 'unused'
because it could not see usage inside short-tag blocks.

- Consolidate every needed `use XcVm\...;` into a single top-of-file PHP block.
- Exclude Public/Views and Modules/*/views from php-cs-fixer (no_unused_imports
  is unreliable on short-tag templates); their import correctness is enforced by
  the new check_procedural_use gate instead.

Verified: php -l (short_open_tag=1) clean; PHPStan no errors; PHPUnit green.
2026-06-25 20:57:37 +03:00
Divarion-D 1a0ad5667a chore(cs): add PHP-CS-Fixer (import/namespace hygiene only)
Add friendsofphp/php-cs-fixer as a committed Composer dev dependency (src/vendor/,
same model as PHPStan — no composer install on deploy).

- .php-cs-fixer.dist.php: deliberately NARROW ruleset — no_unused_imports,
  ordered_imports, no_leading_import_slash, single_line_after_imports,
  blank_line_after_namespace, no_extra_blank_lines[use]. NO @PSR12 / indentation
  rules: the codebase is tab-indented legacy and a full reformat would be
  unreviewable. Indent forced to tabs, LF endings. Excludes vendor, the bundled
  Modules/tmdb/lib, tmp/, backups/.
- Makefile: 'make cs' (dry-run, fails on diff — CI) and 'make cs-fix' (apply).
- CI: new 'Code Style (PHP-CS-Fixer)' job running 'make cs' on PHP 8.3.
- .gitignore: ignore .php-cs-fixer.cache.
2026-06-25 20:24:34 +03:00
Divarion-D db9b8ea7fc chore(deps): migrate M3uParser to Composer (gemorroj/m3u-parser 6.0.1)
- add gemorroj/m3u-parser 6.0.1 to committed vendor/ (PHP >=8.0.2;
  upstream 6.1.0 requires PHP 8.2, incompatible with the 8.1 target)
- remove vendored Core/Parsing/M3uParser snapshot and manual bootstraps
- autoload \M3uParser\ from committed vendor/ instead of a path mapping
- stop tracking composer.lock (already gitignored); CI now audits the
  committed vendor/composer/installed.json without --locked
2026-06-25 19:36:18 +03:00
Divarion-D 7572b9b4d0 chore(ci): enhance Composer audit step to skip when no packages are found 2026-06-25 18:47:24 +03:00
Divarion-D 64e37eb05e chore(ci): update Composer audit command to use --locked option 2026-06-24 22:28:39 +03:00
Divarion-D 7e5732cdcb chore(psr4): phase 0 — Composer PSR-4 autoloader foundation
Introduce a committed Composer PSR-4 autoloader without changing class
resolution behavior, as the foundation for the incremental PSR-4 migration.

- src/composer.json: PSR-4 (XcVm\ -> ./, M3uParser\, Chrisyue\PhpM3u8\),
  platform php 8.1.33 (deploy runtime), optimize-autoloader/classmap-authoritative
  false (live path resolution, no class-map cache). autoload.files left empty:
  global functions are still loaded by existing require glue; moving them is
  deferred until that glue is removed.
- src/vendor/ + src/composer.lock: committed (deploy path has no Composer);
  generated with 'composer update' from src/. Regenerate with dump-autoload.
- src/bootstrap.php, tests/bootstrap.php: require vendor/autoload.php first,
  then the legacy autoload.php.
- src/autoload.php: drop the igbinary disk cache (enableFileCache/saveCache/
  shutdown handler/root-chown + bottom call); register at the END of the SPL
  queue (prepend=false) so Composer wins for XcVm\* and only still-global
  classes fall through to the in-memory scanner.
- Makefile: add vendor to LB_DIRS so load-balancer archives ship the loader.
- phpstan.dist.neon: exclude src/vendor/* from analysis.
- .gitignore: document that src/vendor/ is intentionally tracked.
- ci.yml: add composer-audit job (no-op until real require deps exist).

Verified: php -l clean; Composer first / XC_Autoloader last in the SPL stack;
tmp/cache/autoload_map no longer written; PHPUnit 292/292; PHPStan no errors.
2026-06-24 19:07:37 +03:00
Divarion-D 93da607626 ci(phpstan): add static-analysis job with frozen baseline
- .github/workflows/ci.yml: new `phpstan` job (PHP 8.3, no Composer) running
  `make phpstan` on every push/PR.
- phpstan.dist.neon: include phpstan-baseline.neon so the gate is green on the
  ~446 pre-existing (mostly false-positive/cosmetic) findings and fails only on
  NEW issues. Shrink the baseline over time via `make phpstan-baseline`.
2026-06-23 22:05:42 +03:00
DanilandGitHub 881c9b9ffb Merge pull request #123 from Vateron-Media/dependabot/github_actions/actions/checkout-7
ci: bump actions/checkout from 6 to 7
2026-06-21 22:28:41 +03:00
dependabot[bot]andGitHub 38f1be67bb ci: bump actions/upload-artifact from 4 to 7
Bumps [actions/upload-artifact](https://github.com/actions/upload-artifact) from 4 to 7.
- [Release notes](https://github.com/actions/upload-artifact/releases)
- [Commits](https://github.com/actions/upload-artifact/compare/v4...v7)

---
updated-dependencies:
- dependency-name: actions/upload-artifact
  dependency-version: '7'
  dependency-type: direct:production
  update-type: version-update:semver-major
...

Signed-off-by: dependabot[bot] <support@github.com>
2026-06-21 19:17:51 +00:00
dependabot[bot]andGitHub 9dff052fbd ci: bump actions/checkout from 6 to 7
Bumps [actions/checkout](https://github.com/actions/checkout) from 6 to 7.
- [Release notes](https://github.com/actions/checkout/releases)
- [Changelog](https://github.com/actions/checkout/blob/main/CHANGELOG.md)
- [Commits](https://github.com/actions/checkout/compare/v6...v7)

---
updated-dependencies:
- dependency-name: actions/checkout
  dependency-version: '7'
  dependency-type: direct:production
  update-type: version-update:semver-major
...

Signed-off-by: dependabot[bot] <support@github.com>
2026-06-21 19:17:46 +00:00
Divarion-D 484a758ca0 chore: add Git LFS tracking, CODEOWNERS, SECURITY.md, and CI workflows 2026-06-21 22:11:49 +03:00