Exclude dir - #4

Draft
samuelburnham wants to merge 10 commits into
devfrom
exclude-dir
Draft

Exclude dir#4
samuelburnham wants to merge 10 commits into
devfrom
exclude-dir

Conversation

@samuelburnham

Copy link
Copy Markdown
Member

Adds a ! prefix to the lake_package_directory arg which will exclude the given pattern from the paths that lean-update runs over.

Also bumps flake.lock for lean4-nix v4.33.1

A `/**` sweep takes every package under a directory, which is the wrong
granularity when one package in the tree must not move — a benchmark
pinned to an old toolchain on purpose, say. Without a way to carve it
back out, the whole glob has to be abandoned for an explicit list that
goes stale as packages are added.
An entry prefixed with `!` now subtracts: it names a directory and drops
that directory together with everything beneath it, so
`benchmarks/** !benchmarks/pinned` covers the tree and spares the one
package.
Exclusions live in `lake_package_directory` rather than in an input of
their own so that no step invoking the action needs a second environment
variable kept in sync with the first.
Matching compares path components, not string prefixes, so
`!benchmarks/slow` cannot swallow `benchmarks/slowfixture`, while
trailing slashes and `./` prefixes still name the same directory. An
exclusion carrying a glob is rejected, since it already reaches its whole
subtree, and one matching nothing is reported: a typo there silently
updates the package it was meant to protect.
Comment thread.github/workflows/e2e_test.yml Fixed
Without a `permissions` block the jobs run with whatever the repository
grants by default, which on many repositories is write access to
contents, issues, and pull requests. The E2E jobs update fixtures only
inside the runner's own checkout and never write back, and the action's
`gh` calls read the public list of Lean releases, so `contents: read`
covers everything they do.
Neither workflow writes to the repository: both build and assert inside
the runner's own checkout, and the `gh` calls underneath read public
data. Without a `permissions` block they ran with whatever the
repository grants by default, which is commonly write access to
contents, issues, and pull requests.
The App token existed only to work around GitHub's guard against a
workflow triggering itself, which leaves a GITHUB_TOKEN pull request
with no CI runs until a maintainer releases them. Trading that back for
one fewer credential to install and rotate means the self-update PR
opens with checks pending until someone pushes to the branch or closes
and reopens it.
The job needs contents and pull-requests write to open the PR, and
issues write for the default `on_update_fails: issue` path.
Opening a pull request with `github.token` carries two constraints that
are documented in peter-evans/create-pull-request but nowhere here, so
they surface as a 403 or a PR with no checks: the repository must allow
GitHub Actions to create pull requests, and such a PR does not trigger
workflow runs.
The README examples already carried the write scopes, attributed to
private repositories. The default token has been read-only regardless of
visibility since February 2023, so the note said the right thing for the
wrong reason.
Also note that a `!` exclusion has to be quoted in YAML, since a scalar
opening with `!` is read as a tag.
A `!` with no path after it resolves to the workspace root, which is at
or above every target, so the whole expansion is filtered away and the
run fails reporting that no package directory was found — true, but not
where the reader would start looking. Name the actual mistake.
The jobs set `on_update_succeeds: silent` but left the failure path at
its default, so a fixture that stopped building would have the action
open an issue. The workflow now runs with a read-only token, which turns
that into a 403 on top of the failure it is reporting. A red check is
the signal a test workflow owes its reader.
The prefetch delegated to leanprover/lean-action, which takes one
directory and uses it as the working directory of its every step. A list,
a glob, or an exclusion is not a directory, so the step could not start,
and `continue-on-error` turned that into a red mark nobody read. Anyone
globbing a tree of Mathlib packages then built them from source.
Validation already walks each target package, so fetch the cache there:
one manifest check, then `lake exe cache get` for the packages that want
it. Every package root has its own `.lake/packages/mathlib` and needs its
own unpack, while the downloads pool in one per-user directory, so the
extra directories cost no extra network.
Elan is installed by this action's own step, so nothing else was keeping
lean-action here.
Falling back to a source build is not a smaller version of using the
cache: Mathlib takes hours to compile and the run usually dies on the job
timeout, so the warning scrolls past and the answer never arrives. Stop
instead, before the build starts, and report the directory along with
what `lake exe cache get` printed.
`mathlib_cache: optional` restores the old behaviour for anyone who would
rather have a slow answer than none.
The failure travels as a build error rather than an exception because
`createIssue` re-runs validation to compose the issue body; raising here
would leave the notification path with nothing to report.
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants

@samuelburnham@github-advanced-security
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Add copy buttons to all
 blocks\n(function() {\n function addCopyButtons() {\n document.querySelectorAll('pre code').forEach(function(codeBlock) {\n if (codeBlock.parentElement.hasAttribute('data-copy-added')) return;\n codeBlock.parentElement.setAttribute('data-copy-added', 'true');\n \n var btn = document.createElement('button');\n btn.textContent = 'Copy';\n btn.style.cssText = 'position:absolute;top:4px;right:4px;padding:2px 8px;font-size:11px;background:#4ecdc4;border:none;border-radius:4px;color:#1a1a2e;cursor:pointer;opacity:0.7;transition:opacity 0.2s;';\n btn.onmouseover = function() { this.style.opacity = '1'; };\n btn.onmouseout = function() { this.style.opacity = '0.7'; };\n btn.onclick = function() {\n navigator.clipboard.writeText(codeBlock.textContent).then(function() {\n btn.textContent = 'Copied!';\n setTimeout(function() { btn.textContent = 'Copy'; }, 1500);\n });\n };\n codeBlock.parentElement.style.position = 'relative';\n codeBlock.parentElement.appendChild(btn);\n });\n }\n \n addCopyButtons();\n \n // Re-run on dynamic content\n var observer = new MutationObserver(addCopyButtons);\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Add Copy Buttons to Code Blocks");
}
} catch(__e) { console.warn('[Userscript:Add Copy Buttons to Code Blocks]', __e); }
})();
(function(){
try {
var __m = "github.com";
var __re = new RegExp('^' + "github\\.com" + '
Skip to content

Exclude dir - #4

Draft
samuelburnham wants to merge 10 commits into
devfrom
exclude-dir
Draft

Exclude dir#4
samuelburnham wants to merge 10 commits into
devfrom
exclude-dir

Conversation

@samuelburnham

Copy link
Copy Markdown
Member

Adds a ! prefix to the lake_package_directory arg which will exclude the given pattern from the paths that lean-update runs over.

Also bumps flake.lock for lean4-nix v4.33.1

A `/**` sweep takes every package under a directory, which is the wrong
granularity when one package in the tree must not move — a benchmark
pinned to an old toolchain on purpose, say. Without a way to carve it
back out, the whole glob has to be abandoned for an explicit list that
goes stale as packages are added.
An entry prefixed with `!` now subtracts: it names a directory and drops
that directory together with everything beneath it, so
`benchmarks/** !benchmarks/pinned` covers the tree and spares the one
package.
Exclusions live in `lake_package_directory` rather than in an input of
their own so that no step invoking the action needs a second environment
variable kept in sync with the first.
Matching compares path components, not string prefixes, so
`!benchmarks/slow` cannot swallow `benchmarks/slowfixture`, while
trailing slashes and `./` prefixes still name the same directory. An
exclusion carrying a glob is rejected, since it already reaches its whole
subtree, and one matching nothing is reported: a typo there silently
updates the package it was meant to protect.
Comment thread.github/workflows/e2e_test.yml Fixed
Without a `permissions` block the jobs run with whatever the repository
grants by default, which on many repositories is write access to
contents, issues, and pull requests. The E2E jobs update fixtures only
inside the runner's own checkout and never write back, and the action's
`gh` calls read the public list of Lean releases, so `contents: read`
covers everything they do.
Neither workflow writes to the repository: both build and assert inside
the runner's own checkout, and the `gh` calls underneath read public
data. Without a `permissions` block they ran with whatever the
repository grants by default, which is commonly write access to
contents, issues, and pull requests.
The App token existed only to work around GitHub's guard against a
workflow triggering itself, which leaves a GITHUB_TOKEN pull request
with no CI runs until a maintainer releases them. Trading that back for
one fewer credential to install and rotate means the self-update PR
opens with checks pending until someone pushes to the branch or closes
and reopens it.
The job needs contents and pull-requests write to open the PR, and
issues write for the default `on_update_fails: issue` path.
Opening a pull request with `github.token` carries two constraints that
are documented in peter-evans/create-pull-request but nowhere here, so
they surface as a 403 or a PR with no checks: the repository must allow
GitHub Actions to create pull requests, and such a PR does not trigger
workflow runs.
The README examples already carried the write scopes, attributed to
private repositories. The default token has been read-only regardless of
visibility since February 2023, so the note said the right thing for the
wrong reason.
Also note that a `!` exclusion has to be quoted in YAML, since a scalar
opening with `!` is read as a tag.
A `!` with no path after it resolves to the workspace root, which is at
or above every target, so the whole expansion is filtered away and the
run fails reporting that no package directory was found — true, but not
where the reader would start looking. Name the actual mistake.
The jobs set `on_update_succeeds: silent` but left the failure path at
its default, so a fixture that stopped building would have the action
open an issue. The workflow now runs with a read-only token, which turns
that into a 403 on top of the failure it is reporting. A red check is
the signal a test workflow owes its reader.
The prefetch delegated to leanprover/lean-action, which takes one
directory and uses it as the working directory of its every step. A list,
a glob, or an exclusion is not a directory, so the step could not start,
and `continue-on-error` turned that into a red mark nobody read. Anyone
globbing a tree of Mathlib packages then built them from source.
Validation already walks each target package, so fetch the cache there:
one manifest check, then `lake exe cache get` for the packages that want
it. Every package root has its own `.lake/packages/mathlib` and needs its
own unpack, while the downloads pool in one per-user directory, so the
extra directories cost no extra network.
Elan is installed by this action's own step, so nothing else was keeping
lean-action here.
Falling back to a source build is not a smaller version of using the
cache: Mathlib takes hours to compile and the run usually dies on the job
timeout, so the warning scrolls past and the answer never arrives. Stop
instead, before the build starts, and report the directory along with
what `lake exe cache get` printed.
`mathlib_cache: optional` restores the old behaviour for anyone who would
rather have a slow answer than none.
The failure travels as a build error rather than an exception because
`createIssue` re-runs validation to compose the issue body; raising here
would leave the notification path with nothing to report.
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants

@samuelburnham@github-advanced-security
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Force GitHub README to respect dark mode\n(function() {\n var style = document.createElement('style');\n style.textContent = '\n .markdown-body {\n color-scheme: dark light;\n }\n .markdown-body pre { background: #161b22 !important; }\n .markdown-body code { background: rgba(110, 118, 129, 0.4) !important; }\n .markdown-body table th, .markdown-body table td { border-color: #30363d !important; }\n .markdown-body img { background: #0d1117; }\n .markdown-body blockquote { border-left-color: #8b949e; }\n .markdown-body hr { border-color: #30363d; }\n ';\n document.head.appendChild(style);\n})();", "GitHub Dark Mode README Fix"); } } catch(__e) { console.warn('[Userscript:GitHub Dark Mode README Fix]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

Exclude dir - #4

Draft
samuelburnham wants to merge 10 commits into
devfrom
exclude-dir
Draft

Exclude dir#4
samuelburnham wants to merge 10 commits into
devfrom
exclude-dir

Conversation

@samuelburnham

Copy link
Copy Markdown
Member

Adds a ! prefix to the lake_package_directory arg which will exclude the given pattern from the paths that lean-update runs over.

Also bumps flake.lock for lean4-nix v4.33.1

A `/**` sweep takes every package under a directory, which is the wrong
granularity when one package in the tree must not move — a benchmark
pinned to an old toolchain on purpose, say. Without a way to carve it
back out, the whole glob has to be abandoned for an explicit list that
goes stale as packages are added.
An entry prefixed with `!` now subtracts: it names a directory and drops
that directory together with everything beneath it, so
`benchmarks/** !benchmarks/pinned` covers the tree and spares the one
package.
Exclusions live in `lake_package_directory` rather than in an input of
their own so that no step invoking the action needs a second environment
variable kept in sync with the first.
Matching compares path components, not string prefixes, so
`!benchmarks/slow` cannot swallow `benchmarks/slowfixture`, while
trailing slashes and `./` prefixes still name the same directory. An
exclusion carrying a glob is rejected, since it already reaches its whole
subtree, and one matching nothing is reported: a typo there silently
updates the package it was meant to protect.
Comment thread.github/workflows/e2e_test.yml Fixed
Without a `permissions` block the jobs run with whatever the repository
grants by default, which on many repositories is write access to
contents, issues, and pull requests. The E2E jobs update fixtures only
inside the runner's own checkout and never write back, and the action's
`gh` calls read the public list of Lean releases, so `contents: read`
covers everything they do.
Neither workflow writes to the repository: both build and assert inside
the runner's own checkout, and the `gh` calls underneath read public
data. Without a `permissions` block they ran with whatever the
repository grants by default, which is commonly write access to
contents, issues, and pull requests.
The App token existed only to work around GitHub's guard against a
workflow triggering itself, which leaves a GITHUB_TOKEN pull request
with no CI runs until a maintainer releases them. Trading that back for
one fewer credential to install and rotate means the self-update PR
opens with checks pending until someone pushes to the branch or closes
and reopens it.
The job needs contents and pull-requests write to open the PR, and
issues write for the default `on_update_fails: issue` path.
Opening a pull request with `github.token` carries two constraints that
are documented in peter-evans/create-pull-request but nowhere here, so
they surface as a 403 or a PR with no checks: the repository must allow
GitHub Actions to create pull requests, and such a PR does not trigger
workflow runs.
The README examples already carried the write scopes, attributed to
private repositories. The default token has been read-only regardless of
visibility since February 2023, so the note said the right thing for the
wrong reason.
Also note that a `!` exclusion has to be quoted in YAML, since a scalar
opening with `!` is read as a tag.
A `!` with no path after it resolves to the workspace root, which is at
or above every target, so the whole expansion is filtered away and the
run fails reporting that no package directory was found — true, but not
where the reader would start looking. Name the actual mistake.
The jobs set `on_update_succeeds: silent` but left the failure path at
its default, so a fixture that stopped building would have the action
open an issue. The workflow now runs with a read-only token, which turns
that into a 403 on top of the failure it is reporting. A red check is
the signal a test workflow owes its reader.
The prefetch delegated to leanprover/lean-action, which takes one
directory and uses it as the working directory of its every step. A list,
a glob, or an exclusion is not a directory, so the step could not start,
and `continue-on-error` turned that into a red mark nobody read. Anyone
globbing a tree of Mathlib packages then built them from source.
Validation already walks each target package, so fetch the cache there:
one manifest check, then `lake exe cache get` for the packages that want
it. Every package root has its own `.lake/packages/mathlib` and needs its
own unpack, while the downloads pool in one per-user directory, so the
extra directories cost no extra network.
Elan is installed by this action's own step, so nothing else was keeping
lean-action here.
Falling back to a source build is not a smaller version of using the
cache: Mathlib takes hours to compile and the run usually dies on the job
timeout, so the warning scrolls past and the answer never arrives. Stop
instead, before the build starts, and report the directory along with
what `lake exe cache get` printed.
`mathlib_cache: optional` restores the old behaviour for anyone who would
rather have a slow answer than none.
The failure travels as a build error rather than an exception because
`createIssue` re-runs validation to compose the issue body; raising here
would leave the notification path with nothing to report.
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants

@samuelburnham@github-advanced-security
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Highlight search terms from Google/DuckDuckGo/Bing referrer\n(function() {\n var ref = document.referrer;\n var terms = [];\n \n if (ref.includes('google.com') || ref.includes('duckduckgo.com') || ref.includes('bing.com')) {\n var url = new URL(ref);\n var q = url.searchParams.get('q') || url.searchParams.get('p');\n if (q) {\n terms = q.split(/\\s+/).filter(function(t) { return t.length > 2; });\n }\n }\n \n if (terms.length === 0) return;\n \n var style = document.createElement('style');\n style.textContent = '.userscript-highlight { background: #fbbf24; color: #1a1a2e; padding: 1px 3px; border-radius: 2px; }';\n document.head.appendChild(style);\n \n function highlight(node) {\n if (node.nodeType === 3) { // text node\n var text = node.textContent;\n var found = false;\n terms.forEach(function(term) {\n var regex = new RegExp('(' + term.replace(/[.*+?^${}()|[\\]\\\\]/g, '\\\\') + ')', 'gi');\n if (regex.test(text)) {\n found = true;\n var frag = document.createDocumentFragment();\n var parts = text.split(regex);\n parts.forEach(function(part, i) {\n if (i % 2 === 0) {\n frag.appendChild(document.createTextNode(part));\n } else {\n var span = document.createElement('span');\n span.className = 'userscript-highlight';\n span.textContent = part;\n frag.appendChild(span);\n }\n });\n node.parentNode.replaceChild(frag, node);\n }\n });\n } else if (node.nodeType === 1 && node.childNodes) { // element\n var skipTags = ['SCRIPT', 'STYLE', 'NOSCRIPT', 'TEXTAREA', 'INPUT', 'SELECT'];\n if (!skipTags.includes(node.tagName)) {\n Array.from(node.childNodes).forEach(highlight);\n }\n }\n }\n \n highlight(document.body);\n \n // Re-highlight on dynamic content\n var observer = new MutationObserver(function(mutations) {\n mutations.forEach(function(m) {\n m.addedNodes.forEach(function(node) {\n if (node.nodeType === 1 || node.nodeType === 3) highlight(node);\n });\n });\n });\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Highlight Search Terms"); } } catch(__e) { console.warn('[Userscript:Highlight Search Terms]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

Exclude dir - #4

Draft
samuelburnham wants to merge 10 commits into
devfrom
exclude-dir
Draft

Exclude dir#4
samuelburnham wants to merge 10 commits into
devfrom
exclude-dir

Conversation

@samuelburnham

Copy link
Copy Markdown
Member

Adds a ! prefix to the lake_package_directory arg which will exclude the given pattern from the paths that lean-update runs over.

Also bumps flake.lock for lean4-nix v4.33.1

A `/**` sweep takes every package under a directory, which is the wrong
granularity when one package in the tree must not move — a benchmark
pinned to an old toolchain on purpose, say. Without a way to carve it
back out, the whole glob has to be abandoned for an explicit list that
goes stale as packages are added.
An entry prefixed with `!` now subtracts: it names a directory and drops
that directory together with everything beneath it, so
`benchmarks/** !benchmarks/pinned` covers the tree and spares the one
package.
Exclusions live in `lake_package_directory` rather than in an input of
their own so that no step invoking the action needs a second environment
variable kept in sync with the first.
Matching compares path components, not string prefixes, so
`!benchmarks/slow` cannot swallow `benchmarks/slowfixture`, while
trailing slashes and `./` prefixes still name the same directory. An
exclusion carrying a glob is rejected, since it already reaches its whole
subtree, and one matching nothing is reported: a typo there silently
updates the package it was meant to protect.
Comment thread.github/workflows/e2e_test.yml Fixed
Without a `permissions` block the jobs run with whatever the repository
grants by default, which on many repositories is write access to
contents, issues, and pull requests. The E2E jobs update fixtures only
inside the runner's own checkout and never write back, and the action's
`gh` calls read the public list of Lean releases, so `contents: read`
covers everything they do.
Neither workflow writes to the repository: both build and assert inside
the runner's own checkout, and the `gh` calls underneath read public
data. Without a `permissions` block they ran with whatever the
repository grants by default, which is commonly write access to
contents, issues, and pull requests.
The App token existed only to work around GitHub's guard against a
workflow triggering itself, which leaves a GITHUB_TOKEN pull request
with no CI runs until a maintainer releases them. Trading that back for
one fewer credential to install and rotate means the self-update PR
opens with checks pending until someone pushes to the branch or closes
and reopens it.
The job needs contents and pull-requests write to open the PR, and
issues write for the default `on_update_fails: issue` path.
Opening a pull request with `github.token` carries two constraints that
are documented in peter-evans/create-pull-request but nowhere here, so
they surface as a 403 or a PR with no checks: the repository must allow
GitHub Actions to create pull requests, and such a PR does not trigger
workflow runs.
The README examples already carried the write scopes, attributed to
private repositories. The default token has been read-only regardless of
visibility since February 2023, so the note said the right thing for the
wrong reason.
Also note that a `!` exclusion has to be quoted in YAML, since a scalar
opening with `!` is read as a tag.
A `!` with no path after it resolves to the workspace root, which is at
or above every target, so the whole expansion is filtered away and the
run fails reporting that no package directory was found — true, but not
where the reader would start looking. Name the actual mistake.
The jobs set `on_update_succeeds: silent` but left the failure path at
its default, so a fixture that stopped building would have the action
open an issue. The workflow now runs with a read-only token, which turns
that into a 403 on top of the failure it is reporting. A red check is
the signal a test workflow owes its reader.
The prefetch delegated to leanprover/lean-action, which takes one
directory and uses it as the working directory of its every step. A list,
a glob, or an exclusion is not a directory, so the step could not start,
and `continue-on-error` turned that into a red mark nobody read. Anyone
globbing a tree of Mathlib packages then built them from source.
Validation already walks each target package, so fetch the cache there:
one manifest check, then `lake exe cache get` for the packages that want
it. Every package root has its own `.lake/packages/mathlib` and needs its
own unpack, while the downloads pool in one per-user directory, so the
extra directories cost no extra network.
Elan is installed by this action's own step, so nothing else was keeping
lean-action here.
Falling back to a source build is not a smaller version of using the
cache: Mathlib takes hours to compile and the run usually dies on the job
timeout, so the warning scrolls past and the answer never arrives. Stop
instead, before the build starts, and report the directory along with
what `lake exe cache get` printed.
`mathlib_cache: optional` restores the old behaviour for anyone who would
rather have a slow answer than none.
The failure travels as a build error rather than an exception because
`createIssue` re-runs validation to compose the issue body; raising here
would leave the notification path with nothing to report.
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants

@samuelburnham@github-advanced-security
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Strip utm_, fbclid, gclid, etc. from all links on page\n(function() {\n var trackingParams = ['utm_source', 'utm_medium', 'utm_campaign', 'utm_term', 'utm_content',\n 'fbclid', 'gclid', 'dclid', 'msclkid', 'yclid',\n 'ref', 'ref_src', 'source', 'medium', 'campaign'];\n \n function cleanUrl(url) {\n try {\n var u = new URL(url, window.location.origin);\n var changed = false;\n trackingParams.forEach(function(p) {\n if (u.searchParams.has(p)) {\n u.searchParams.delete(p);\n changed = true;\n }\n });\n return changed ? u.toString() : url;\n } catch (e) {\n return url;\n }\n }\n \n function cleanLinks() {\n document.querySelectorAll('a[href]').forEach(function(a) {\n var clean = cleanUrl(a.href);\n if (clean !== a.href) a.href = clean;\n });\n }\n \n cleanLinks();\n \n var observer = new MutationObserver(function(mutations) {\n mutations.forEach(function(m) {\n m.addedNodes.forEach(function(node) {\n if (node.nodeType === 1) {\n if (node.tagName === 'A') cleanLinks();\n node.querySelectorAll('a[href]').forEach(function(a) {\n var clean = cleanUrl(a.href);\n if (clean !== a.href) a.href = clean;\n });\n }\n });\n });\n });\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Remove Tracking Parameters from Links"); } } catch(__e) { console.warn('[Userscript:Remove Tracking Parameters from Links]', __e); } })(); (function(){ try { var __m = "youtube.com"; var __re = new RegExp('^' + "youtube\\.com" + '
Skip to content

Exclude dir - #4

Draft
samuelburnham wants to merge 10 commits into
devfrom
exclude-dir
Draft

Exclude dir#4
samuelburnham wants to merge 10 commits into
devfrom
exclude-dir

Conversation

@samuelburnham

Copy link
Copy Markdown
Member

Adds a ! prefix to the lake_package_directory arg which will exclude the given pattern from the paths that lean-update runs over.

Also bumps flake.lock for lean4-nix v4.33.1

A `/**` sweep takes every package under a directory, which is the wrong
granularity when one package in the tree must not move — a benchmark
pinned to an old toolchain on purpose, say. Without a way to carve it
back out, the whole glob has to be abandoned for an explicit list that
goes stale as packages are added.
An entry prefixed with `!` now subtracts: it names a directory and drops
that directory together with everything beneath it, so
`benchmarks/** !benchmarks/pinned` covers the tree and spares the one
package.
Exclusions live in `lake_package_directory` rather than in an input of
their own so that no step invoking the action needs a second environment
variable kept in sync with the first.
Matching compares path components, not string prefixes, so
`!benchmarks/slow` cannot swallow `benchmarks/slowfixture`, while
trailing slashes and `./` prefixes still name the same directory. An
exclusion carrying a glob is rejected, since it already reaches its whole
subtree, and one matching nothing is reported: a typo there silently
updates the package it was meant to protect.
Comment thread.github/workflows/e2e_test.yml Fixed
Without a `permissions` block the jobs run with whatever the repository
grants by default, which on many repositories is write access to
contents, issues, and pull requests. The E2E jobs update fixtures only
inside the runner's own checkout and never write back, and the action's
`gh` calls read the public list of Lean releases, so `contents: read`
covers everything they do.
Neither workflow writes to the repository: both build and assert inside
the runner's own checkout, and the `gh` calls underneath read public
data. Without a `permissions` block they ran with whatever the
repository grants by default, which is commonly write access to
contents, issues, and pull requests.
The App token existed only to work around GitHub's guard against a
workflow triggering itself, which leaves a GITHUB_TOKEN pull request
with no CI runs until a maintainer releases them. Trading that back for
one fewer credential to install and rotate means the self-update PR
opens with checks pending until someone pushes to the branch or closes
and reopens it.
The job needs contents and pull-requests write to open the PR, and
issues write for the default `on_update_fails: issue` path.
Opening a pull request with `github.token` carries two constraints that
are documented in peter-evans/create-pull-request but nowhere here, so
they surface as a 403 or a PR with no checks: the repository must allow
GitHub Actions to create pull requests, and such a PR does not trigger
workflow runs.
The README examples already carried the write scopes, attributed to
private repositories. The default token has been read-only regardless of
visibility since February 2023, so the note said the right thing for the
wrong reason.
Also note that a `!` exclusion has to be quoted in YAML, since a scalar
opening with `!` is read as a tag.
A `!` with no path after it resolves to the workspace root, which is at
or above every target, so the whole expansion is filtered away and the
run fails reporting that no package directory was found — true, but not
where the reader would start looking. Name the actual mistake.
The jobs set `on_update_succeeds: silent` but left the failure path at
its default, so a fixture that stopped building would have the action
open an issue. The workflow now runs with a read-only token, which turns
that into a 403 on top of the failure it is reporting. A red check is
the signal a test workflow owes its reader.
The prefetch delegated to leanprover/lean-action, which takes one
directory and uses it as the working directory of its every step. A list,
a glob, or an exclusion is not a directory, so the step could not start,
and `continue-on-error` turned that into a red mark nobody read. Anyone
globbing a tree of Mathlib packages then built them from source.
Validation already walks each target package, so fetch the cache there:
one manifest check, then `lake exe cache get` for the packages that want
it. Every package root has its own `.lake/packages/mathlib` and needs its
own unpack, while the downloads pool in one per-user directory, so the
extra directories cost no extra network.
Elan is installed by this action's own step, so nothing else was keeping
lean-action here.
Falling back to a source build is not a smaller version of using the
cache: Mathlib takes hours to compile and the run usually dies on the job
timeout, so the warning scrolls past and the answer never arrives. Stop
instead, before the build starts, and report the directory along with
what `lake exe cache get` printed.
`mathlib_cache: optional` restores the old behaviour for anyone who would
rather have a slow answer than none.
The failure travels as a build error rather than an exception because
`createIssue` re-runs validation to compose the issue body; raising here
would leave the notification path with nothing to report.
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants

@samuelburnham@github-advanced-security
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Auto-enable theater mode on YouTube\n(function() {\n function tryTheater() {\n var btn = document.querySelector('button[aria-label=\"Theater mode\"], ytd-player #player button[title=\"Theater mode\"]');\n if (btn && !btn.classList.contains('activated')) {\n btn.click();\n }\n }\n \n // Try immediately\n tryTheater();\n \n // Try after navigation (SPA)\n var lastUrl = location.href;\n setInterval(function() {\n if (location.href !== lastUrl) {\n lastUrl = location.href;\n setTimeout(tryTheater, 500);\n }\n }, 1000);\n \n // Also try on player load\n var observer = new MutationObserver(tryTheater);\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "YouTube Theater Mode Default"); } } catch(__e) { console.warn('[Userscript:YouTube Theater Mode Default]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

Exclude dir - #4

Draft
samuelburnham wants to merge 10 commits into
devfrom
exclude-dir
Draft

Exclude dir#4
samuelburnham wants to merge 10 commits into
devfrom
exclude-dir

Conversation

@samuelburnham

Copy link
Copy Markdown
Member

Adds a ! prefix to the lake_package_directory arg which will exclude the given pattern from the paths that lean-update runs over.

Also bumps flake.lock for lean4-nix v4.33.1

A `/**` sweep takes every package under a directory, which is the wrong
granularity when one package in the tree must not move — a benchmark
pinned to an old toolchain on purpose, say. Without a way to carve it
back out, the whole glob has to be abandoned for an explicit list that
goes stale as packages are added.
An entry prefixed with `!` now subtracts: it names a directory and drops
that directory together with everything beneath it, so
`benchmarks/** !benchmarks/pinned` covers the tree and spares the one
package.
Exclusions live in `lake_package_directory` rather than in an input of
their own so that no step invoking the action needs a second environment
variable kept in sync with the first.
Matching compares path components, not string prefixes, so
`!benchmarks/slow` cannot swallow `benchmarks/slowfixture`, while
trailing slashes and `./` prefixes still name the same directory. An
exclusion carrying a glob is rejected, since it already reaches its whole
subtree, and one matching nothing is reported: a typo there silently
updates the package it was meant to protect.
Comment thread.github/workflows/e2e_test.yml Fixed
Without a `permissions` block the jobs run with whatever the repository
grants by default, which on many repositories is write access to
contents, issues, and pull requests. The E2E jobs update fixtures only
inside the runner's own checkout and never write back, and the action's
`gh` calls read the public list of Lean releases, so `contents: read`
covers everything they do.
Neither workflow writes to the repository: both build and assert inside
the runner's own checkout, and the `gh` calls underneath read public
data. Without a `permissions` block they ran with whatever the
repository grants by default, which is commonly write access to
contents, issues, and pull requests.
The App token existed only to work around GitHub's guard against a
workflow triggering itself, which leaves a GITHUB_TOKEN pull request
with no CI runs until a maintainer releases them. Trading that back for
one fewer credential to install and rotate means the self-update PR
opens with checks pending until someone pushes to the branch or closes
and reopens it.
The job needs contents and pull-requests write to open the PR, and
issues write for the default `on_update_fails: issue` path.
Opening a pull request with `github.token` carries two constraints that
are documented in peter-evans/create-pull-request but nowhere here, so
they surface as a 403 or a PR with no checks: the repository must allow
GitHub Actions to create pull requests, and such a PR does not trigger
workflow runs.
The README examples already carried the write scopes, attributed to
private repositories. The default token has been read-only regardless of
visibility since February 2023, so the note said the right thing for the
wrong reason.
Also note that a `!` exclusion has to be quoted in YAML, since a scalar
opening with `!` is read as a tag.
A `!` with no path after it resolves to the workspace root, which is at
or above every target, so the whole expansion is filtered away and the
run fails reporting that no package directory was found — true, but not
where the reader would start looking. Name the actual mistake.
The jobs set `on_update_succeeds: silent` but left the failure path at
its default, so a fixture that stopped building would have the action
open an issue. The workflow now runs with a read-only token, which turns
that into a 403 on top of the failure it is reporting. A red check is
the signal a test workflow owes its reader.
The prefetch delegated to leanprover/lean-action, which takes one
directory and uses it as the working directory of its every step. A list,
a glob, or an exclusion is not a directory, so the step could not start,
and `continue-on-error` turned that into a red mark nobody read. Anyone
globbing a tree of Mathlib packages then built them from source.
Validation already walks each target package, so fetch the cache there:
one manifest check, then `lake exe cache get` for the packages that want
it. Every package root has its own `.lake/packages/mathlib` and needs its
own unpack, while the downloads pool in one per-user directory, so the
extra directories cost no extra network.
Elan is installed by this action's own step, so nothing else was keeping
lean-action here.
Falling back to a source build is not a smaller version of using the
cache: Mathlib takes hours to compile and the run usually dies on the job
timeout, so the warning scrolls past and the answer never arrives. Stop
instead, before the build starts, and report the directory along with
what `lake exe cache get` printed.
`mathlib_cache: optional` restores the old behaviour for anyone who would
rather have a slow answer than none.
The failure travels as a build error rather than an exception because
`createIssue` re-runs validation to compose the issue body; raising here
would leave the notification path with nothing to report.
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants

@samuelburnham@github-advanced-security
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Remove or un-stick sticky/fixed headers that block content\n(function() {\n function unstick() {\n document.querySelectorAll('header, nav, [role=\"banner\"], .header, .navbar, .sticky, .fixed-top, [style*=\"position: fixed\"], [style*=\"position:sticky\"]').forEach(function(el) {\n if (el.style.position === 'fixed' || el.style.position === 'sticky' || \n getComputedStyle(el).position === 'fixed' || getComputedStyle(el).position === 'sticky') {\n el.style.position = 'static';\n el.style.top = 'auto';\n el.style.zIndex = 'auto';\n }\n });\n }\n \n unstick();\n \n var observer = new MutationObserver(unstick);\n observer.observe(document.body, { childList: true, subtree: true, attributes: true, attributeFilter: ['style', 'class'] });\n})();", "Kill Sticky Headers"); } } catch(__e) { console.warn('[Userscript:Kill Sticky Headers]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

Exclude dir - #4

Draft
samuelburnham wants to merge 10 commits into
devfrom
exclude-dir
Draft

Exclude dir#4
samuelburnham wants to merge 10 commits into
devfrom
exclude-dir

Conversation

@samuelburnham

Copy link
Copy Markdown
Member

Adds a ! prefix to the lake_package_directory arg which will exclude the given pattern from the paths that lean-update runs over.

Also bumps flake.lock for lean4-nix v4.33.1

A `/**` sweep takes every package under a directory, which is the wrong
granularity when one package in the tree must not move — a benchmark
pinned to an old toolchain on purpose, say. Without a way to carve it
back out, the whole glob has to be abandoned for an explicit list that
goes stale as packages are added.
An entry prefixed with `!` now subtracts: it names a directory and drops
that directory together with everything beneath it, so
`benchmarks/** !benchmarks/pinned` covers the tree and spares the one
package.
Exclusions live in `lake_package_directory` rather than in an input of
their own so that no step invoking the action needs a second environment
variable kept in sync with the first.
Matching compares path components, not string prefixes, so
`!benchmarks/slow` cannot swallow `benchmarks/slowfixture`, while
trailing slashes and `./` prefixes still name the same directory. An
exclusion carrying a glob is rejected, since it already reaches its whole
subtree, and one matching nothing is reported: a typo there silently
updates the package it was meant to protect.
Comment thread.github/workflows/e2e_test.yml Fixed
Without a `permissions` block the jobs run with whatever the repository
grants by default, which on many repositories is write access to
contents, issues, and pull requests. The E2E jobs update fixtures only
inside the runner's own checkout and never write back, and the action's
`gh` calls read the public list of Lean releases, so `contents: read`
covers everything they do.
Neither workflow writes to the repository: both build and assert inside
the runner's own checkout, and the `gh` calls underneath read public
data. Without a `permissions` block they ran with whatever the
repository grants by default, which is commonly write access to
contents, issues, and pull requests.
The App token existed only to work around GitHub's guard against a
workflow triggering itself, which leaves a GITHUB_TOKEN pull request
with no CI runs until a maintainer releases them. Trading that back for
one fewer credential to install and rotate means the self-update PR
opens with checks pending until someone pushes to the branch or closes
and reopens it.
The job needs contents and pull-requests write to open the PR, and
issues write for the default `on_update_fails: issue` path.
Opening a pull request with `github.token` carries two constraints that
are documented in peter-evans/create-pull-request but nowhere here, so
they surface as a 403 or a PR with no checks: the repository must allow
GitHub Actions to create pull requests, and such a PR does not trigger
workflow runs.
The README examples already carried the write scopes, attributed to
private repositories. The default token has been read-only regardless of
visibility since February 2023, so the note said the right thing for the
wrong reason.
Also note that a `!` exclusion has to be quoted in YAML, since a scalar
opening with `!` is read as a tag.
A `!` with no path after it resolves to the workspace root, which is at
or above every target, so the whole expansion is filtered away and the
run fails reporting that no package directory was found — true, but not
where the reader would start looking. Name the actual mistake.
The jobs set `on_update_succeeds: silent` but left the failure path at
its default, so a fixture that stopped building would have the action
open an issue. The workflow now runs with a read-only token, which turns
that into a 403 on top of the failure it is reporting. A red check is
the signal a test workflow owes its reader.
The prefetch delegated to leanprover/lean-action, which takes one
directory and uses it as the working directory of its every step. A list,
a glob, or an exclusion is not a directory, so the step could not start,
and `continue-on-error` turned that into a red mark nobody read. Anyone
globbing a tree of Mathlib packages then built them from source.
Validation already walks each target package, so fetch the cache there:
one manifest check, then `lake exe cache get` for the packages that want
it. Every package root has its own `.lake/packages/mathlib` and needs its
own unpack, while the downloads pool in one per-user directory, so the
extra directories cost no extra network.
Elan is installed by this action's own step, so nothing else was keeping
lean-action here.
Falling back to a source build is not a smaller version of using the
cache: Mathlib takes hours to compile and the run usually dies on the job
timeout, so the warning scrolls past and the answer never arrives. Stop
instead, before the build starts, and report the directory along with
what `lake exe cache get` printed.
`mathlib_cache: optional` restores the old behaviour for anyone who would
rather have a slow answer than none.
The failure travels as a build error rather than an exception because
`createIssue` re-runs validation to compose the issue body; raising here
would leave the notification path with nothing to report.
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants

@samuelburnham@github-advanced-security
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Universal Dark Mode - works on any site\n(function() {\n var enabled = true;\n \n function applyDarkMode() {\n if (!enabled) return;\n \n // Create style element if it doesn't exist\n var style = document.getElementById('universal-dark-mode-style');\n if (!style) {\n style = document.createElement('style');\n style.id = 'universal-dark-mode-style';\n document.head.appendChild(style);\n }\n \n // Dark mode CSS - inverts colors but preserves images/video\n style.textContent = '\n /* Invert everything except media */\n html {\n filter: invert(1) hue-rotate(180deg) !important;\n background: #1a1a2e !important;\n }\n \n /* Restore images, videos, iframes, canvas */\n img, video, iframe, canvas, svg, picture, [style*=\"background-image\"] {\n filter: invert(1) hue-rotate(180deg) !important;\n }\n \n /* Preserve specific elements that should not be inverted */\n .no-dark-mode, .no-dark-mode *,\n [data-theme=\"light\"], [data-theme=\"light\"],\n .ace_editor, .ace_editor *,\n .CodeMirror, .CodeMirror *,\n .monaco-editor, .monaco-editor *,\n .markdown-body pre, .markdown-body pre *,\n .highlight, .highlight *,\n pre code, pre code * {\n filter: none !important;\n }\n \n /* Fix common UI elements */\n .modal, .popup, .dropdown-menu, .tooltip, .popover {\n filter: invert(1) hue-rotate(180deg) !important;\n background: #2d2d44 !important;\n border-color: #444 !important;\n }\n \n /* Scrollbars */\n ::-webkit-scrollbar { background: #1a1a2e !important; }\n ::-webkit-scrollbar-thumb { background: #444 !important; }\n ::-webkit-scrollbar-thumb:hover { background: #555 !important; }\n \n /* Selection */\n ::selection { background: #4ecdc4 !important; color: #1a1a2e !important; }\n ::-moz-selection { background: #4ecdc4 !important; color: #1a1a2e !important; }\n ';\n }\n \n function removeDarkMode() {\n var style = document.getElementById('universal-dark-mode-style');\n if (style) style.remove();\n }\n \n // Toggle with Alt+Shift+D\n document.addEventListener('keydown', function(e) {\n if (e.altKey && e.shiftKey && e.key === 'D') {\n e.preventDefault();\n enabled = !enabled;\n if (enabled) {\n applyDarkMode();\n console.log('[Universal Dark Mode] Enabled');\n } else {\n removeDarkMode();\n console.log('[Universal Dark Mode] Disabled');\n }\n }\n });\n \n // Apply on load\n applyDarkMode();\n \n // Re-apply on dynamic content\n var observer = new MutationObserver(function(mutations) {\n if (enabled && !document.getElementById('universal-dark-mode-style')) {\n applyDarkMode();\n }\n });\n observer.observe(document.head, { childList: true });\n \n console.log('[Universal Dark Mode] Loaded - Press Alt+Shift+D to toggle');\n})();", "Universal Dark Mode"); } } catch(__e) { console.warn('[Userscript:Universal Dark Mode]', __e); } })(); })();
Skip to content

Exclude dir - #4

Draft
samuelburnham wants to merge 10 commits into
devfrom
exclude-dir
Draft

Exclude dir#4
samuelburnham wants to merge 10 commits into
devfrom
exclude-dir

Conversation

@samuelburnham

Copy link
Copy Markdown
Member

Adds a ! prefix to the lake_package_directory arg which will exclude the given pattern from the paths that lean-update runs over.

Also bumps flake.lock for lean4-nix v4.33.1

A `/**` sweep takes every package under a directory, which is the wrong
granularity when one package in the tree must not move — a benchmark
pinned to an old toolchain on purpose, say. Without a way to carve it
back out, the whole glob has to be abandoned for an explicit list that
goes stale as packages are added.
An entry prefixed with `!` now subtracts: it names a directory and drops
that directory together with everything beneath it, so
`benchmarks/** !benchmarks/pinned` covers the tree and spares the one
package.
Exclusions live in `lake_package_directory` rather than in an input of
their own so that no step invoking the action needs a second environment
variable kept in sync with the first.
Matching compares path components, not string prefixes, so
`!benchmarks/slow` cannot swallow `benchmarks/slowfixture`, while
trailing slashes and `./` prefixes still name the same directory. An
exclusion carrying a glob is rejected, since it already reaches its whole
subtree, and one matching nothing is reported: a typo there silently
updates the package it was meant to protect.
Comment thread.github/workflows/e2e_test.yml Fixed
Without a `permissions` block the jobs run with whatever the repository
grants by default, which on many repositories is write access to
contents, issues, and pull requests. The E2E jobs update fixtures only
inside the runner's own checkout and never write back, and the action's
`gh` calls read the public list of Lean releases, so `contents: read`
covers everything they do.
Neither workflow writes to the repository: both build and assert inside
the runner's own checkout, and the `gh` calls underneath read public
data. Without a `permissions` block they ran with whatever the
repository grants by default, which is commonly write access to
contents, issues, and pull requests.
The App token existed only to work around GitHub's guard against a
workflow triggering itself, which leaves a GITHUB_TOKEN pull request
with no CI runs until a maintainer releases them. Trading that back for
one fewer credential to install and rotate means the self-update PR
opens with checks pending until someone pushes to the branch or closes
and reopens it.
The job needs contents and pull-requests write to open the PR, and
issues write for the default `on_update_fails: issue` path.
Opening a pull request with `github.token` carries two constraints that
are documented in peter-evans/create-pull-request but nowhere here, so
they surface as a 403 or a PR with no checks: the repository must allow
GitHub Actions to create pull requests, and such a PR does not trigger
workflow runs.
The README examples already carried the write scopes, attributed to
private repositories. The default token has been read-only regardless of
visibility since February 2023, so the note said the right thing for the
wrong reason.
Also note that a `!` exclusion has to be quoted in YAML, since a scalar
opening with `!` is read as a tag.
A `!` with no path after it resolves to the workspace root, which is at
or above every target, so the whole expansion is filtered away and the
run fails reporting that no package directory was found — true, but not
where the reader would start looking. Name the actual mistake.
The jobs set `on_update_succeeds: silent` but left the failure path at
its default, so a fixture that stopped building would have the action
open an issue. The workflow now runs with a read-only token, which turns
that into a 403 on top of the failure it is reporting. A red check is
the signal a test workflow owes its reader.
The prefetch delegated to leanprover/lean-action, which takes one
directory and uses it as the working directory of its every step. A list,
a glob, or an exclusion is not a directory, so the step could not start,
and `continue-on-error` turned that into a red mark nobody read. Anyone
globbing a tree of Mathlib packages then built them from source.
Validation already walks each target package, so fetch the cache there:
one manifest check, then `lake exe cache get` for the packages that want
it. Every package root has its own `.lake/packages/mathlib` and needs its
own unpack, while the downloads pool in one per-user directory, so the
extra directories cost no extra network.
Elan is installed by this action's own step, so nothing else was keeping
lean-action here.
Falling back to a source build is not a smaller version of using the
cache: Mathlib takes hours to compile and the run usually dies on the job
timeout, so the warning scrolls past and the answer never arrives. Stop
instead, before the build starts, and report the directory along with
what `lake exe cache get` printed.
`mathlib_cache: optional` restores the old behaviour for anyone who would
rather have a slow answer than none.
The failure travels as a build error rather than an exception because
`createIssue` re-runs validation to compose the issue body; raising here
would leave the notification path with nothing to report.
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants

@samuelburnham@github-advanced-security