diff --git a/.github/workflows/ci.yml b/.github/workflows/ci.yml
index 36807a6..f050cf1 100644
--- a/.github/workflows/ci.yml
+++ b/.github/workflows/ci.yml
@@ -138,6 +138,12 @@ jobs:
tar -xJf shellcheck.tar.xz
./shellcheck-v0.11.0/shellcheck -S warning $(git ls-files '*.sh')
+ # An exit status is 8 bits, so `exit "$fails"` reads 256 failures as a pass. The suites
+ # exit 1 on any failure; this keeps the next one from carrying its count out.
+ - name: No script exits with its failure count
+ run: |
+ if git grep -nE 'exit +"?\$\{?[a-z_]*fail[a-z_]*\}?"?[[:space:]]*$' -- '*.sh'; then exit 1; fi
+
- run: sh deploy/bootstrap_test.sh
- run: sh deploy/uninstall_test.sh
- run: bash deploy/e2e_release_test.sh
diff --git a/deploy/bootstrap_test.sh b/deploy/bootstrap_test.sh
index 5b2466e..ee9f9c2 100644
--- a/deploy/bootstrap_test.sh
+++ b/deploy/bootstrap_test.sh
@@ -1414,9 +1414,13 @@ expect "and pushed to exactly that endpoint, with the platform login" "DOCKER --
out="$(run_push registry.felis.svc:50000/felis/felis:demo)"
expect "a ref outside the registry is refused with a warning" "WARN: not mirroring" "$out"
-case "$out" in
- *"DOCKER push"*) echo "FAIL: a non-registry ref must not be pushed"; fails=$((fails + 1)) ;;
-esac
+# The push runs with the platform login, `docker --config
push`, so any docker line
+# with a push in it counts.
+if printf '%s\n' "$out" | grep -q '^DOCKER .*push '; then
+ echo "FAIL a ref outside the registry was pushed: $out"; fails=$((fails + 1))
+else
+ echo "PASS a ref outside the registry is not pushed"
+fi
out="$(run_push registry.felis.svc:5000/felis/felis:demo 1)"
expect "a failed push fails the install loudly" "DIE: could not mirror" "$out"
@@ -4605,5 +4609,5 @@ if [ "$fails" -eq 0 ]; then
echo "ALL PASS"
else
echo "$fails FAILED"
+ exit 1
fi
-exit "$fails"
diff --git a/deploy/e2e_check.sh b/deploy/e2e_check.sh
index 6af2e0a..0af309a 100644
--- a/deploy/e2e_check.sh
+++ b/deploy/e2e_check.sh
@@ -240,5 +240,5 @@ if [ "$fails" -eq 0 ]; then
echo "ALL PASS (${phase})"
else
echo "${fails} FAILED (${phase})"
+ exit 1
fi
-exit "$fails"
diff --git a/deploy/e2e_release.sh b/deploy/e2e_release.sh
index b9f21f0..e47e46c 100644
--- a/deploy/e2e_release.sh
+++ b/deploy/e2e_release.sh
@@ -109,4 +109,4 @@ case "${1:-}" in
exit 2
;;
esac
-exit "$fails"
+[ "$fails" -eq 0 ] || exit 1
diff --git a/deploy/e2e_release_test.sh b/deploy/e2e_release_test.sh
index fdc48b2..dcc13e1 100644
--- a/deploy/e2e_release_test.sh
+++ b/deploy/e2e_release_test.sh
@@ -184,5 +184,4 @@ same " and says so" "::error::gh release view answered without a tag" "$out"
same " and writes no outputs" "" "$(cat "$root/out")"
echo
-if [ "$fails" -eq 0 ]; then echo "ALL PASS"; else echo "${fails} FAILED"; fi
-exit "$fails"
+if [ "$fails" -eq 0 ]; then echo "ALL PASS"; else echo "${fails} FAILED"; exit 1; fi
diff --git a/deploy/uninstall_test.sh b/deploy/uninstall_test.sh
index b155565..0117630 100644
--- a/deploy/uninstall_test.sh
+++ b/deploy/uninstall_test.sh
@@ -387,5 +387,5 @@ if [ "$fails" -eq 0 ]; then
echo "ALL PASS"
else
echo "$fails FAILED"
+ exit 1
fi
-exit "$fails"