-
Notifications
You must be signed in to change notification settings - Fork 130
753 lines (645 loc) · 29.2 KB
/
Copy pathci.yml
File metadata and controls
753 lines (645 loc) · 29.2 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
130
131
132
133
134
135
136
137
138
139
140
141
142
143
144
145
146
147
148
149
150
151
152
153
154
155
156
157
158
159
160
161
162
163
164
165
166
167
168
169
170
171
172
173
174
175
176
177
178
179
180
181
182
183
184
185
186
187
188
189
190
191
192
193
194
195
196
197
198
199
200
201
202
203
204
205
206
207
208
209
210
211
212
213
214
215
216
217
218
219
220
221
222
223
224
225
226
227
228
229
230
231
232
233
234
235
236
237
238
239
240
241
242
243
244
245
246
247
248
249
250
251
252
253
254
255
256
257
258
259
260
261
262
263
264
265
266
267
268
269
270
271
272
273
274
275
276
277
278
279
280
281
282
283
284
285
286
287
288
289
290
291
292
293
294
295
296
297
298
299
300
301
302
303
304
305
306
307
308
309
310
311
312
313
314
315
316
317
318
319
320
321
322
323
324
325
326
327
328
329
330
331
332
333
334
335
336
337
338
339
340
341
342
343
344
345
346
347
348
349
350
351
352
353
354
355
356
357
358
359
360
361
362
363
364
365
366
367
368
369
370
371
372
373
374
375
376
377
378
379
380
381
382
383
384
385
386
387
388
389
390
391
392
393
394
395
396
397
398
399
400
401
402
403
404
405
406
407
408
409
410
411
412
413
414
415
416
417
418
419
420
421
422
423
424
425
426
427
428
429
430
431
432
433
434
435
436
437
438
439
440
441
442
443
444
445
446
447
448
449
450
451
452
453
454
455
456
457
458
459
460
461
462
463
464
465
466
467
468
469
470
471
472
473
474
475
476
477
478
479
480
481
482
483
484
485
486
487
488
489
490
491
492
493
494
495
496
497
498
499
500
501
502
503
504
505
506
507
508
509
510
511
512
513
514
515
516
517
518
519
520
521
522
523
524
525
526
527
528
529
530
531
532
533
534
535
536
537
538
539
540
541
542
543
544
545
546
547
548
549
550
551
552
553
554
555
556
557
558
559
560
561
562
563
564
565
566
567
568
569
570
571
572
573
574
575
576
577
578
579
580
581
582
583
584
585
586
587
588
589
590
591
592
593
594
595
596
597
598
599
600
601
602
603
604
605
606
607
608
609
610
611
612
613
614
615
616
617
618
619
620
621
622
623
624
625
626
627
628
629
630
631
632
633
634
635
636
637
638
639
640
641
642
643
644
645
646
647
648
649
650
651
652
653
654
655
656
657
658
659
660
661
662
663
664
665
666
667
668
669
670
671
672
673
674
675
676
677
678
679
680
681
682
683
684
685
686
687
688
689
690
691
692
693
694
695
696
697
698
699
700
701
702
703
704
705
706
707
708
709
710
711
712
713
714
715
716
717
718
719
720
721
722
723
724
725
726
727
728
729
730
731
732
733
734
735
736
737
738
739
740
741
742
743
744
745
746
747
748
749
750
751
752
753
name: CI
on:
push:
# train/** runs the same checks on a train branch before it is fast-forwarded
# onto master; required status checks on master are satisfied by that run.
branches: [master, main, "train/**"]
# The nightly run checks sibling repositories at their default-branch heads;
# workflow_dispatch remains available for an operator-triggered run.
schedule:
- cron: "17 3 * * *"
workflow_dispatch:
env:
FORCE_JAVASCRIPT_ACTIONS_TO_NODE24: true
# Pipeline shape on every push to master/main:
#
# check-plugin, check-pi-plugin (unit tests + lint + typecheck, parallel)
# ↓
# e2e-opencode, e2e-opencode2, e2e-pi, e2e-omp (Docker install + smoke, parallel — gated by unit)
# e2e-host-opencode, e2e-host-opencode2, e2e-host-pi, e2e-host-omp (host-behavior lanes from the mode manifest)
# ↓
#
# Two e2e layers cover different concerns:
# - Docker e2e: fresh-install smoke (plugin loads, doctor clean, one mock turn writes DB rows
# under cortexkit path with right harness). Catches packaging / install-flow regressions.
# - Host e2e: behavior suite with byte-level wire assertions, multi-turn cache stability,
# historian publish behavior, tag-owner collision, synthetic todowrite, cross-harness memory,
# etc. Spawns real `opencode serve` / Pi subprocesses against an embedded mock provider.
# Catches cache-stability + correctness regressions that the smoke layer cannot see.
#
# Docker e2e was previously in a separate workflow (e2e-docker.yml). Folding it here means
# every master/main push exercises the full unit → Docker → host gauntlet. The
# Rust jobs run on every push and scheduled run, checking the current public sibling sources:
#
# rust-crates cargo fmt / clippy --all-targets / cargo test, including every
# integration target under crates/*/tests
# e2e-rust-hermetic-build → e2e-rust-hermetic (4 shards)
#
# Both check out ../commons and ../subconscious from their public default branches.
jobs:
check-plugin:
name: Check (plugin)
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@v5
- uses: oven-sh/setup-bun@v2
with:
bun-version: latest
# node:sqlite (the Pi / OpenCode-Desktop SQLite backend) is only reachable
# under Node, not Bun. Node 24 also strips the smoke script's inline TS.
- uses: actions/setup-node@v4
with:
node-version: "24"
- name: Install dependencies
run: bun install --frozen-lockfile
- name: TypeScript typecheck
run: bun run typecheck
- name: Lint
run: bun run lint
- name: Build
run: bun run build
- name: Check compiled TUI freshness
run: bun run --cwd packages/plugin check:tui-compiled
# The historian prompt golden is the byte-parity contract between the
# TypeScript historian renderer and the Rust mc-module port. The Rust
# golden test pins the committed file from the Rust side, but only this
# regeneration check catches a TypeScript renderer change whose golden
# was never regenerated.
- name: Historian prompt golden drift check
run: bun crates/mc-module/gen/gen-historian-prompt-golden.ts --check
- name: Test
run: bun run test
# Exercise the node:sqlite branch of shared/sqlite.ts under REAL Node —
# bun test only covers the bun:sqlite branch, so the transaction() shim,
# readonly→readOnly mapping, and the array-bind normalization (#151) would
# otherwise ship unverified on Pi/Desktop.
- name: Smoke (node:sqlite backend)
run: node packages/plugin/scripts/smoke-node-sqlite.ts
# The smart-note QuickJS sandbox loads a ~1MB WASM. `bun test` runs it from
# src (wasm resolves via node_modules), so it cannot catch a BUNDLING break
# where the wasm isn't embedded in dist. This bundles sandbox-runner exactly
# like the package build and runs a real check against the bundle.
- name: Smoke (smart-note wasm bundle)
run: bun packages/plugin/scripts/smoke-smartnote-wasm.ts
# The raw-TSX ./tui entry imports @opentui/solid's JSX runtime. `bun test`
# never imports it, so a missing/mismatched OpenTUI or Solid dep (as broke
# on OpenCode 1.17.10's OpenTUI 0.4.2 bump) ships a TUI that won't load.
# Import the entry the way OpenCode loads the ./tui export to catch it.
- name: Smoke (TUI entry import)
run: bun packages/plugin/scripts/smoke-tui-import.ts
# The dev-path import above cannot catch packaging breaks: OpenTUI's Solid
# transform skips node_modules sources, so only a packed PROD install
# exercises the resolution path OpenCode's plugin cache uses (v0.31.1
# shipped without runtime deps and passed every dev-path check).
- name: Smoke (TUI packaged install import)
run: bun packages/plugin/scripts/smoke-tui-pack-install.ts
# Tokenizer loading is lazy, so an import-only smoke misses resolution
# failures. Pack + npm-install prod deps, then exercise an estimate from a
# compiled Bun host matching OpenCode's /$bunfs/root runtime.
- name: Smoke (tokenizer packaged install estimate)
run: bun packages/plugin/scripts/smoke-tokenizer-pack-install.ts
check-pi-plugin:
name: Check (pi-plugin)
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@v5
- uses: oven-sh/setup-bun@v2
with:
bun-version: latest
- name: Install dependencies
run: bun install --frozen-lockfile
- name: TypeScript typecheck
run: bun run --cwd packages/pi-plugin typecheck
- name: Lint
run: bun run --cwd packages/pi-plugin lint
- name: Build
run: bun run --cwd packages/pi-plugin build
- name: Test
run: bun run --cwd packages/pi-plugin test
check-dashboard:
name: Check (dashboard)
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@v5
- uses: oven-sh/setup-bun@v2
with:
bun-version: latest
- name: Install dependencies
run: bun install --frozen-lockfile
# Frontend-only checks (no Rust/Tauri needed). The key gate is the test
# step, which runs config-parity.test.ts — it fails the build if the
# plugin config schema gains/renames/removes a field the dashboard's
# ConfigEditor coverage manifest doesn't account for, so the form can't
# silently drift out of sync with the schema again.
- name: TypeScript typecheck
run: bun run --cwd packages/dashboard typecheck
- name: Lint
run: bun run --cwd packages/dashboard lint
- name: Test
run: bun run --cwd packages/dashboard test
- name: Build (frontend)
run: bun run --cwd packages/dashboard build
e2e-opencode:
name: E2E (OpenCode, Docker)
runs-on: ubuntu-latest
needs: [check-plugin]
timeout-minutes: 25
steps:
- uses: actions/checkout@v5
- uses: oven-sh/setup-bun@v2
with:
bun-version: latest
- name: Install workspace deps
run: bun install --frozen-lockfile
- name: Build OpenCode plugin
run: bun run --cwd packages/plugin build
- name: Build CLI
# The CLI is its own package (@cortexkit/magic-context) since
# v0.16.1; Dockerfile.opencode COPYs packages/cli/dist/ in.
run: bun run --cwd packages/cli build
- name: Build E2E image
run: |
docker build \
--platform linux/amd64 \
-f tests/docker/Dockerfile.opencode \
-t mc-e2e-opencode \
.
- name: Run E2E
run: docker run --rm --platform linux/amd64 mc-e2e-opencode
e2e-opencode2:
name: E2E (OpenCode 2.0.22, Docker)
runs-on: ubuntu-latest
needs: [check-plugin]
timeout-minutes: 30
steps:
- uses: actions/checkout@v5
- uses: oven-sh/setup-bun@v2
with:
bun-version: latest
- name: Install workspace dependencies
run: bun install --frozen-lockfile
# The wrapper is the single local/CI entrypoint. It builds the publishable
# plugin, fails if Docker or opencode2 is missing, and runs the exact-pinned
# GA host through a real transform, host fold, database check, and TUI boot.
- name: Run pinned OpenCode 2 container lane
run: tests/docker/opencode2/run.sh
e2e-pi:
name: E2E (Pi, Docker)
runs-on: ubuntu-latest
needs: [check-pi-plugin]
timeout-minutes: 25
steps:
- uses: actions/checkout@v5
- uses: oven-sh/setup-bun@v2
with:
bun-version: latest
- name: Install workspace deps
run: bun install --frozen-lockfile
- name: Build Pi plugin
run: bun run --cwd packages/pi-plugin build
- name: Build CLI
# The CLI moved to its own package (@cortexkit/magic-context) in
# v0.16.1. Dockerfile.pi COPYs packages/cli/dist/ in for the
# `magic-context doctor --harness pi` test invocation.
run: bun run --cwd packages/cli build
- name: Build E2E image
# The Pi Dockerfile installs runtime deps fresh inside the image
# (better-sqlite3 builds against linux/amd64), so no host-side
# `npm install` is needed.
run: |
docker build \
--platform linux/amd64 \
-f tests/docker/Dockerfile.pi \
-t mc-e2e-pi \
.
- name: Run E2E
run: docker run --rm --platform linux/amd64 mc-e2e-pi
e2e-omp:
name: E2E (Oh My Pi, real Docker)
runs-on: ubuntu-latest
needs: [check-pi-plugin]
timeout-minutes: 25
steps:
- uses: actions/checkout@v5
- uses: oven-sh/setup-bun@v2
with:
bun-version: latest
- name: Install workspace deps
run: bun install --frozen-lockfile
- name: Build Pi-compatible plugin and OMP argv renderer
run: |
bun run --cwd packages/pi-plugin build
bun run --cwd packages/pi-plugin build:e2e-argv
- name: Build CLI
run: bun run --cwd packages/cli build
- name: Build real OMP E2E image
run: |
docker build \
--platform linux/amd64 \
-f tests/docker/Dockerfile.omp \
-t mc-e2e-omp \
.
- name: Run real OMP install and session smoke
run: docker run --rm --platform linux/amd64 mc-e2e-omp
e2e-host-opencode:
name: E2E (OpenCode, host behavior)
runs-on: ubuntu-latest
# Gated on Docker e2e: no point exercising the deep behavior suite if
# the simpler install+smoke path is broken.
needs: [e2e-opencode]
timeout-minutes: 40
steps:
- uses: actions/checkout@v5
- uses: oven-sh/setup-bun@v2
with:
bun-version: latest
- name: Install workspace deps
run: bun install --frozen-lockfile
# Install opencode the same way the Docker image does — the host
# suite spawns `opencode serve` from PATH.
- name: Install opencode
# Float to LATEST (no --version) so CI exercises the opencode version
# users actually run and catches upstream breakage as it ships — not at
# our release time. (A fixed pin previously hid opencode 1.16's
# post-overflow change, commit 7e09660c3, until release; the
# overflow-recovery host test is now version-agnostic.) Trade-off: a
# known-bad upstream release can turn CI red for unrelated PRs — if that
# happens, temporarily re-pin with `--version X.Y.Z` here until it's
# resolved upstream.
run: |
OPENCODE_VERSION=latest bash tests/docker/install-opencode.sh
echo "$HOME/.opencode/bin" >> "$GITHUB_PATH"
- name: Verify opencode on PATH
run: opencode --version
- name: Build OpenCode plugin
# Host tests spawn `opencode serve` with a file:// plugin
# specifier pointing at packages/plugin/, so dist must exist.
run: bun run --cwd packages/plugin build
# Strip inherited NODE_ENV=test so the spawned opencode subprocess
# gets the same logging + runtime behavior as a normal local run
# (documented in CONTRIBUTING / project memory).
#
# Per-test (and per-hook) timeout bumped to 300s: the first test file
# Bun loads on a cold GitHub-hosted runner pays the dependency-resolution
# + opencode-binary cold-start cost in its `beforeAll(TestHarness.create)`,
# which can exceed Bun's 120s default. Subsequent files run in 5-10s.
- name: Run host e2e suite (OpenCode tests only)
env:
NODE_ENV: ""
MC_E2E_MODE: ts
MC_E2E_HOST: opencode
run: |
# The mode validator independently checks tests/**/*.test.ts and
# derives this OpenCode list. Rust coverage runs in the dedicated crate
# and hermetic jobs below, including on pushes.
cd packages/e2e-tests
# A validator failure must fail the job, never fall through to an empty
# list: `bun test` with no files runs every file in the package.
set -o pipefail
files=$(bun scripts/validate-mode-manifest.ts --mode ts --harness opencode | tr '\n' ' ')
if [ -z "${files// /}" ]; then echo 'mode manifest selected no files'; exit 1; fi
echo "Running OpenCode host tests from mode manifest: $files"
# shellcheck disable=SC2086 # The repository-controlled file list must expand into Bun arguments.
bun test --timeout 600000 $files
# This oracle is outside the manifest's tests/**/*.test.ts inventory.
bun test --timeout 600000 src/cache-analysis.test.ts
e2e-host-pi:
name: E2E (Pi, host behavior)
runs-on: ubuntu-latest
needs: [e2e-pi]
timeout-minutes: 40
steps:
- uses: actions/checkout@v5
- uses: oven-sh/setup-bun@v2
with:
bun-version: latest
# Pi tests resolve the Pi binary via createRequire against
# @earendil-works/pi-coding-agent, which is a workspace dep of
# packages/pi-plugin. `bun install` brings it in.
- name: Install workspace deps
run: bun install --frozen-lockfile
# pi-cross-harness.test.ts spawns BOTH a Pi runner and an OpenCode
# serve to verify cross-harness memory sharing, so this job needs
# opencode on PATH too. Float to LATEST like the OpenCode host job
# (see that step for the rationale + re-pin escape hatch).
- name: Install opencode
run: |
OPENCODE_VERSION=latest bash tests/docker/install-opencode.sh
echo "$HOME/.opencode/bin" >> "$GITHUB_PATH"
- name: Verify opencode on PATH
run: opencode --version
- name: Build Pi plugin
run: bun run --cwd packages/pi-plugin build
# pi-cross-harness also instantiates the OpenCode harness, which
# spawns `opencode serve` with a file:// plugin specifier pointing
# at packages/plugin/. That dist must exist.
- name: Build OpenCode plugin
run: bun run --cwd packages/plugin build
# Per-test timeout bumped to 300s for the same cold-start reason as
# the OpenCode host job. Pi historian publish path also crosses an
# HTTP boundary into the mock provider, which is slower on shared
# runners than on local hardware.
- name: Run host e2e suite (Pi tests from mode manifest)
env:
NODE_ENV: ""
MC_E2E_MODE: ts
MC_E2E_HOST: pi
run: |
cd packages/e2e-tests
# A validator failure must fail the job, never fall through to an empty
# list: `bun test` with no files runs every file in the package.
set -o pipefail
files=$(bun scripts/validate-mode-manifest.ts --mode ts --harness pi | tr '\n' ' ')
if [ -z "${files// /}" ]; then echo 'mode manifest selected no files'; exit 1; fi
echo "Running Pi host tests from mode manifest: $files"
# shellcheck disable=SC2086 # The repository-controlled file list must expand into Bun arguments.
bun test --timeout 600000 $files
e2e-host-opencode2:
name: E2E (OpenCode 2.0.22, host behavior)
runs-on: ubuntu-latest
needs: [e2e-opencode2]
timeout-minutes: 40
steps:
- uses: actions/checkout@v5
- uses: oven-sh/setup-bun@v2
with:
bun-version: latest
# The OpenCode 2 harness spawns the real GA host from @opencode/cli, a
# workspace dev dependency whose postinstall unpacks the platform binary
# (trustedDependencies at the workspace root lets bun run it).
- name: Install workspace deps
run: bun install --frozen-lockfile
# The conversion regression boots both generations and doctor probes the
# v1 CLI on PATH; the v2 binary comes from the pinned workspace dependency.
# The installer one-liner resolves "latest" through the rate-limited GitHub API
# and can exit 0 without installing; the repo's installer pins, retries and
# asserts the binary runs.
- name: Install OpenCode 1 for conversion coverage
run: |
OPENCODE_VERSION=1.18.31 bash tests/docker/install-opencode.sh
echo "$HOME/.opencode/bin" >> "$GITHUB_PATH"
- name: Verify the GA host binary
run: bun -e "const { CLI } = await import('./packages/e2e-tests/src/opencode2-runner/spawn.ts'); const { execFileSync } = await import('node:child_process'); const version = execFileSync(CLI, ['--version']).toString().trim(); console.log(CLI, version); if (version !== 'opencode v2.0.22') throw new Error('OpenCode 2 host lane requires 2.0.22')"
- name: Build OpenCode plugin (v1 + v2 entries)
run: bun run --cwd packages/plugin build
- name: Run host e2e suite (OpenCode 2 tests from mode manifest)
env:
NODE_ENV: ""
MC_E2E_MODE: ts
MC_E2E_HOST: opencode2
run: |
cd packages/e2e-tests
set -o pipefail
files=$(bun scripts/validate-mode-manifest.ts --mode ts --harness opencode2 | tr '\n' ' ')
if [ -z "${files// /}" ]; then echo 'mode manifest selected no files'; exit 1; fi
echo "Running OpenCode 2 host tests from mode manifest: $files"
# shellcheck disable=SC2086 # The repository-controlled file list must expand into Bun arguments.
bun test --timeout 600000 $files
# These long-lived dual-host fixtures manipulate separate throwaway stores,
# but run sequentially to avoid contending with one another's live hosts.
- name: Run OC2 conversion and marker regressions
env:
NODE_ENV: ""
MC_E2E_MODE: ts
MC_E2E_HOST: opencode2
run: |
cd packages/e2e-tests
bun test --timeout 600000 tests/opencode2/store-generation-conversion.test.ts
bun test --timeout 600000 tests/opencode2/marker-s3-runtime.test.ts
e2e-host-omp:
name: E2E (Oh My Pi, host behavior)
runs-on: ubuntu-latest
needs: [e2e-omp]
timeout-minutes: 40
steps:
- uses: actions/checkout@v5
- uses: oven-sh/setup-bun@v2
with:
bun-version: latest
# OMP runs the same Pi plugin through Pi's extension API; the harness
# resolves @oh-my-pi/pi-coding-agent (a workspace dev dependency) when
# MC_E2E_HOST=omp.
- name: Install workspace deps
run: bun install --frozen-lockfile
- name: Install opencode
run: |
OPENCODE_VERSION=latest bash tests/docker/install-opencode.sh
echo "$HOME/.opencode/bin" >> "$GITHUB_PATH"
- name: Build Pi plugin
run: bun run --cwd packages/pi-plugin build
- name: Build OpenCode plugin
run: bun run --cwd packages/plugin build
- name: Run host e2e suite (OMP tests from mode manifest)
env:
NODE_ENV: ""
MC_E2E_MODE: ts
MC_E2E_HOST: omp
run: |
cd packages/e2e-tests
set -o pipefail
files=$(bun scripts/validate-mode-manifest.ts --mode ts --harness omp | tr '\n' ' ')
if [ -z "${files// /}" ]; then echo 'mode manifest selected no files'; exit 1; fi
echo "Running OMP host tests from mode manifest: $files"
# shellcheck disable=SC2086 # The repository-controlled file list must expand into Bun arguments.
bun test --timeout 600000 $files
rust-crates:
name: Rust (crates)
# Public sibling workspaces are checked out at their default-branch heads,
# so each push validates the crates against the current shared sources.
#
# It exists because NOTHING ran `cargo test` in this workflow: the drift leg
# below builds the crates only as a side effect of the hermetic harness, so an
# integration test under crates/*/tests could fail unobserved. It depends on the
# no other suite, so a Rust regression is reported even
# when an unrelated host suite is red.
runs-on: ubuntu-latest
timeout-minutes: 45
permissions:
contents: read
steps:
- uses: actions/checkout@v5
- uses: dtolnay/rust-toolchain@stable
with:
components: clippy, rustfmt
# The hostless-store integration test provisions context.db through the CLI.
- uses: oven-sh/setup-bun@v2
with:
bun-version: latest
- name: Install CLI dependencies
run: bun install --frozen-lockfile
- name: Check out commons
uses: actions/checkout@v5
with:
repository: cortexkit/commons
path: .siblings/commons
- name: Check out subconscious
uses: actions/checkout@v5
with:
repository: cortexkit/subconscious
path: .siblings/subconscious
# real_daemon checks that the launch-nonce prerequisite is in history.
fetch-depth: 0
# actions/checkout refuses a path outside $GITHUB_WORKSPACE, so the siblings
# land inside the workspace and are linked to the ../ paths the Rust workspace
# expects. Same shape as the hermetic leg below.
- name: Link siblings at the expected relative paths
shell: bash
run: |
set -euo pipefail
ln -sfn "$GITHUB_WORKSPACE/.siblings/commons" "$GITHUB_WORKSPACE/../commons"
ln -sfn "$GITHUB_WORKSPACE/.siblings/subconscious" "$GITHUB_WORKSPACE/../subconscious"
test -f "$GITHUB_WORKSPACE/../commons/Cargo.toml"
test -f "$GITHUB_WORKSPACE/../subconscious/Cargo.lock"
- name: Record public sibling revisions
shell: bash
run: |
set -euo pipefail
commons_sha="$(git -C "$GITHUB_WORKSPACE/../commons" rev-parse HEAD)"
subconscious_sha="$(git -C "$GITHUB_WORKSPACE/../subconscious" rev-parse HEAD)"
summary="Rust crate checks against commons=${commons_sha}; subconscious=${subconscious_sha}"
echo "$summary"
echo "$summary" >> "$GITHUB_STEP_SUMMARY"
- name: Format check
run: cargo fmt --check
# --all-targets puts the integration tests under crates/*/tests through clippy
# too; a lib-only lint cannot see them.
- name: Clippy
run: cargo clippy --workspace --all-targets -- -D warnings
# `cargo test -p mc-module` runs the lib unit tests AND every integration test
# target under crates/mc-module/tests, which is where cold_flip_adversarial and
# the other cross-crate behaviour proofs live. Naming the package (not --lib)
# is the whole point of this step.
- name: Test mc-module (lib + integration targets)
run: cargo test -p mc-module
- name: Test the remaining workspace crates
run: cargo test --workspace --exclude mc-module
e2e-rust-hermetic-build:
name: E2E (Rust hermetic drift build)
# Public sibling workspaces are checked out at their default-branch heads.
runs-on: ubuntu-latest
timeout-minutes: 120
permissions:
contents: read
steps:
- uses: actions/checkout@v5
- uses: dtolnay/rust-toolchain@stable
- uses: oven-sh/setup-bun@v2
with:
bun-version: latest
# actions/checkout requires sibling checkouts inside $GITHUB_WORKSPACE, so they land
# inside the workspace and are
# linked to the ../ paths the Rust workspace and the hermetic harness expect.
# Same shape as release.yml.
- name: Check out commons
uses: actions/checkout@v5
with:
repository: cortexkit/commons
path: .siblings/commons
- name: Check out subconscious
uses: actions/checkout@v5
with:
repository: cortexkit/subconscious
path: .siblings/subconscious
- name: Link siblings at the expected relative paths
shell: bash
run: |
set -euo pipefail
ln -sfn "$GITHUB_WORKSPACE/.siblings/commons" "$GITHUB_WORKSPACE/../commons"
ln -sfn "$GITHUB_WORKSPACE/.siblings/subconscious" "$GITHUB_WORKSPACE/../subconscious"
test -f "$GITHUB_WORKSPACE/../commons/Cargo.toml"
test -f "$GITHUB_WORKSPACE/../subconscious/Cargo.lock"
- name: Record public sibling revisions
shell: bash
run: |
set -euo pipefail
commons_sha="$(git -C "$GITHUB_WORKSPACE/../commons" rev-parse HEAD)"
subconscious_sha="$(git -C "$GITHUB_WORKSPACE/../subconscious" rev-parse HEAD)"
summary="Rust hermetic sibling checkouts: commons=${commons_sha}; subconscious=${subconscious_sha}"
echo "$summary"
echo "$summary" >> "$GITHUB_STEP_SUMMARY"
- name: Derive hermetic Cargo cache key
id: cargo-cache-key
shell: bash
run: |
set -euo pipefail
# commons is a library workspace with no committed Cargo.lock; key on its
# Cargo.toml instead (release.yml does the same).
digest="$(sha256sum Cargo.lock ../commons/Cargo.toml ../subconscious/Cargo.lock | sha256sum | awk '{print $1}')"
echo "key=rust-hermetic-${RUNNER_OS}-${RUNNER_ARCH}-${digest}" >> "$GITHUB_OUTPUT"
- name: Restore ck-subc and ckdev-mc-e2e Cargo target cache
uses: actions/cache@v4
with:
path: packages/e2e-tests/.cache/rust-e2e-cargo-target
key: ${{ steps.cargo-cache-key.outputs.key }}
- name: Install workspace dependencies
run: bun install --frozen-lockfile
- name: Build hermetic binary pair (including fault-injection variant)
shell: bash
run: |
set -euo pipefail
target="$GITHUB_WORKSPACE/packages/e2e-tests/.cache/rust-e2e-cargo-target"
mkdir -p "$target/prebuilt"
CARGO_TARGET_DIR="$target" cargo build --release -p mc-module
cp "$target/release/ck-mc" "$target/prebuilt/ckdev-mc-e2e"
CARGO_TARGET_DIR="$target" cargo build --release -p mc-module --features drive-fault
cp "$target/release/ck-mc" "$target/prebuilt/ckdev-mc-e2e-drive-fault"
(cd ../subconscious && CARGO_TARGET_DIR="$target" cargo build --release -p subc-core --bins)
cp "$target/release/ck-subc" "$target/prebuilt/ck-subc"
- uses: actions/upload-artifact@v4
with:
name: rust-hermetic-binaries
path: packages/e2e-tests/.cache/rust-e2e-cargo-target/prebuilt/
if-no-files-found: error
retention-days: 1
e2e-rust-hermetic:
name: E2E (Rust hermetic drift ${{ matrix.shard }}/4)
runs-on: ubuntu-latest
needs: [e2e-rust-hermetic-build]
timeout-minutes: 60
strategy:
fail-fast: false
matrix:
shard: [0, 1, 2, 3]
permissions:
contents: read
steps:
- uses: actions/checkout@v5
- uses: dtolnay/rust-toolchain@stable
- uses: oven-sh/setup-bun@v2
with:
bun-version: latest
- uses: actions/checkout@v5
with:
repository: cortexkit/commons
path: .siblings/commons
- uses: actions/checkout@v5
with:
repository: cortexkit/subconscious
path: .siblings/subconscious
- name: Link sibling workspaces
run: |
ln -sfn "$GITHUB_WORKSPACE/.siblings/commons" "$GITHUB_WORKSPACE/../commons"
ln -sfn "$GITHUB_WORKSPACE/.siblings/subconscious" "$GITHUB_WORKSPACE/../subconscious"
- name: Install workspace dependencies
run: bun install --frozen-lockfile
- uses: actions/download-artifact@v4
with:
name: rust-hermetic-binaries
path: packages/e2e-tests/.cache/prebuilt
- name: Make downloaded binaries executable
run: chmod +x packages/e2e-tests/.cache/prebuilt/ckdev-mc-e2e packages/e2e-tests/.cache/prebuilt/ckdev-mc-e2e-drive-fault packages/e2e-tests/.cache/prebuilt/ck-subc
- name: Install pinned OpenCode
run: |
OPENCODE_VERSION=1.18.32 bash tests/docker/install-opencode.sh
echo "$HOME/.opencode/bin" >> "$GITHUB_PATH"
- name: Build host plugins
run: |
bun run --cwd packages/plugin build
bun run --cwd packages/pi-plugin build
- name: Run manifest shard
env:
MC_E2E_SHARD: ${{ matrix.shard }}/4
MC_E2E_CK_MC_PREBUILT_BIN: ${{ github.workspace }}/packages/e2e-tests/.cache/prebuilt/ckdev-mc-e2e
MC_E2E_CK_MC_DRIVE_FAULT_BIN: ${{ github.workspace }}/packages/e2e-tests/.cache/prebuilt/ckdev-mc-e2e-drive-fault
MC_E2E_CK_SUBC_BIN: ${{ github.workspace }}/packages/e2e-tests/.cache/prebuilt/ck-subc
run: scripts/run-rust-hermetic-e2e.sh