Files
XC_VM/.github/workflows/ci.yml
T
Divarion-D fd35f00c4d fix(views): import migrated classes at top of 5 admin view templates
enigma, episode, episodes, process_monitor and stream_view referenced migrated
classes (UserRepository, BouquetService, StreamRepository, RequestManager,
SettingsManager, ...) by short name with either no `use` or a `use` placed
*below* the first usage. PHP imports outside the top scope are positional, so the
short name resolved to a now-nonexistent global class — a runtime fatal on those
admin pages (php -l passes; not covered by PHPStan/PHPUnit). The migration's
automated `use` insertion missed them due to the interleaved HTML / short-tag
(<? , <?=) structure, and the later php-cs-fixer pass stripped some as 'unused'
because it could not see usage inside short-tag blocks.

- Consolidate every needed `use XcVm\...;` into a single top-of-file PHP block.
- Exclude Public/Views and Modules/*/views from php-cs-fixer (no_unused_imports
  is unreliable on short-tag templates); their import correctness is enforced by
  the new check_procedural_use gate instead.

Verified: php -l (short_open_tag=1) clean; PHPStan no errors; PHPUnit green.
2026-06-25 20:57:37 +03:00

152 lines
4.5 KiB
YAML

name: CI
# Quality gate: runs on every push and pull request.
# Tests run via the committed PHAR (tools/.bin/phpunit.phar). Class loading uses
# the committed Composer PSR-4 autoloader (src/vendor/) first, with the legacy
# src/autoload.php scanner as an end-of-queue fallback. The deploy path ships
# vendor/ as-is and never runs `composer install`.
on:
push:
branches: ['**']
pull_request:
permissions:
contents: read
jobs:
lint:
name: PHP Syntax Check
runs-on: ubuntu-latest
steps:
- name: Checkout
uses: actions/checkout@v7
- name: Setup PHP
uses: shivammathur/setup-php@v2
with:
php-version: '8.1'
coverage: none
- name: Check syntax
run: bash tools/php_syntax_check.sh
phpstan:
name: PHPStan (static analysis)
runs-on: ubuntu-latest
steps:
- name: Checkout
uses: actions/checkout@v7
- name: Setup PHP
uses: shivammathur/setup-php@v2
with:
# Matches phpVersion (80300) the analysis targets.
php-version: '8.3'
coverage: none
# Downloads the pinned PHPStan PHAR (no Composer) and analyses against the
# committed baseline — fails only on NEW issues introduced by the change.
- name: Run PHPStan
run: make phpstan
code-style:
name: Code Style (PHP-CS-Fixer)
runs-on: ubuntu-latest
steps:
- name: Checkout
uses: actions/checkout@v7
- name: Setup PHP
uses: shivammathur/setup-php@v2
with:
php-version: '8.3'
coverage: none
# PHP-CS-Fixer ships via the committed src/vendor/ (Composer dev dep), like
# PHPStan — no download, no `composer install`. Narrow ruleset: import /
# namespace hygiene only (see .php-cs-fixer.dist.php). Dry-run fails on diff.
- name: Run PHP-CS-Fixer
run: make cs
psr4-gates:
name: PSR-4 Regression Gates
runs-on: ubuntu-latest
steps:
- name: Checkout
# Full history not needed, but git ls-files requires the working tree.
uses: actions/checkout@v7
- name: Setup PHP
uses: shivammathur/setup-php@v2
with:
php-version: '8.3'
coverage: none
# check-procedural-use: procedural/view files must import every migrated
# class they use (top-of-file `use`; PHP imports are positional).
# verify-lb-archive: the LoadBalancer archive must exclude privileged code
# (security blocker 1 — silent rm misses after the PascalCase rename).
- name: Run PSR-4 gates
run: make gates
composer-audit:
name: Composer Security Audit
runs-on: ubuntu-latest
steps:
- name: Checkout
uses: actions/checkout@v7
- name: Setup PHP
uses: shivammathur/setup-php@v2
with:
php-version: '8.1'
coverage: none
tools: composer:v2
# Audits the committed install set (src/vendor/composer/installed.json)
# against the Packagist advisory database. Does NOT run `composer install`
# (vendor/ is committed and shipped) and does NOT use --locked
# (composer.lock is gitignored, never committed). A no-op while every
# dependency is path-mapped/vendored without metadata, but gates real
# installed packages the moment any are added.
- name: Composer audit
run: |
count=$(php -r '$f="src/vendor/composer/installed.json";$d=is_file($f)?json_decode(file_get_contents($f),true):[];echo is_array($d["packages"]??null)?count($d["packages"]):0;')
if [ "$count" -eq 0 ]; then
echo "No installed Composer packages — nothing to audit."
else
composer audit --no-interaction --working-dir=src
fi
test:
name: PHPUnit
runs-on: ubuntu-latest
steps:
- name: Checkout
uses: actions/checkout@v7
- name: Setup PHP
uses: shivammathur/setup-php@v2
with:
php-version: '8.1'
coverage: pcov
- name: Run unit tests
run: php tools/.bin/phpunit.phar -c tests/phpunit.xml.dist
- name: Coverage report
run: |
php tools/.bin/phpunit.phar -c tests/phpunit.xml.dist \
--coverage-text \
--coverage-clover coverage.xml
continue-on-error: true
- name: Upload coverage artifact
if: always()
uses: actions/upload-artifact@v7
with:
name: coverage
path: coverage.xml
if-no-files-found: ignore