Files
Codex 98028a3093 ci: the backend gate now checks exactly what it promises (#399)
Three claims a green backend used to make, each slightly wider than the
truth — and #392 happened in exactly that gap.

The frontend pin said 20260826.1 next to homeassistant==2026.8.3, whose
package_constraints.txt requires 20260729.7: a combination that exists
in no HA release. It was never derived from anything — someone once
picked it. It is now taken from the constraints, the source is named in
the file, and a test holds both numbers together so raising HA cannot
quietly desync them.

ruff's include declared three trees while CI linted one. Narrowed the
declaration rather than widening CI: the debt in scripts/ and
tests_backend/ (56 findings, mostly E402/I001, plus 7 B023 and 5 B017)
has its own cost and its own decisions, and belongs in its own task, not
in a visibility fix. test/lint-scope.test.mjs now compares the two, so
they can only move together.

The pin check skipped a workflow when it found neither the package name
nor the requirements path — and both vanish together the moment someone
returns to Defaulting to user installation because normal site-packages is not writeable, i.e. the gate switched itself off
under precisely the change it exists to catch. It now walks the whole
.github/workflows directory and decides per file by a positive sign: if
a file installs python packages, it must install them from the pins
file. Verified by dropping a rogue workflow into the directory — it
reddens without touching any list.

Three mutants registered and each run by hand.

User-Visible: no
Issue: #399
2026-08-31 04:35:56 +03:00

45 lines
3.7 KiB
Plaintext
Raw Permalink Blame History

This file contains ambiguous Unicode characters
This file contains Unicode characters that might be confused with other characters. If you think that this is intentional, you can safely ignore this warning. Use the Escape button to reveal them.
# Зависимости HA-харнесса, закреплённые точно (issue #392).
#
# Было так: `pip install pytest voluptuous pytest-homeassistant-custom-component
# home-assistant-frontend` без единой версии. Резолвер выбирал набор сам, и
# выбор зависел не от нашего коммита, а от того, что в этот день лежит на PyPI.
# По SHA нельзя было сказать, чем его проверяли.
#
# Хуже того, выбирал он молча и неудачно. Все релизы phcc начиная с 0.13.348
# (25.07.2026) требуют Python >= 3.14, а job стоял на 3.13 — резолвер уезжал на
# 0.13.316, а та тянет homeassistant 2026.2.3. Интеграция полгода проверялась
# против февральского Home Assistant, и никакой гейт об этом не сообщал.
#
# Переход на актуальный HA оказался бесплатным: замер на ветке
# experiment/392-py314 дал `450 passed, 2 skipped` — ровно то же, что на старом
# наборе. Полугодовой дрейф API нашей интеграции не задел.
#
# Почему 0.13.357, а не последняя. Она — последняя, которая пинует стабильный
# homeassistant 2026.8.3; начиная с 0.13.358 пинуются беты (2026.9.0bN).
# Гейт на бете держать нельзя: её могут перевыпустить под тем же номером, и
# «зелёный» перестанет быть воспроизводимым.
#
# pytest не закреплён намеренно: phcc сам задаёт совместимый диапазон, а жёсткий
# пин с ним конфликтует (проверено — ResolutionImpossible на 9.0.0).
#
# Менять версии здесь можно, но только вместе с прогоном полного набора: это не
# косметика, а смена того, что означает зелёный backend.
# Версия фронтенда НЕ выбирается, а берётся из констрейнтов закреплённого
# Home Assistant: homeassistant/package_constraints.txt тега 2026.8.3 требует
# ровно 20260729.7 (#399). До этого здесь стояла 20260826.1 — набор, которого
# нет ни в одном релизе HA: phcc фронтенд не объявляет, и версию однажды
# назначили руками. Поднимая HA, обновлять эту строку из того же файла.
voluptuous==0.15.2
pytest-homeassistant-custom-component==0.13.357
home-assistant-frontend==20260729.7
# Ставится транзитивно из phcc; закреплён явно, чтобы версия была видна тому,
# кто читает этот файл, а не только тому, кто читает лог.
homeassistant==2026.8.3
# #42: линт бэкенда (шаг «Линт бэкенда» в validate.yml ставится отсюда же).
ruff==0.16.5
# #42: строгая типизация allowlist-модулей (шаг «Типы бэкенда»). Без пина
# гейт типизации был бы не воспроизводим по SHA — ровно то, от чего этот
# файл и заведён: новая версия mypy добавляет проверки и краснеет на коде,
# который не менялся.
mypy==2.3.1