Repository navigation
795 lines (684 loc) · 31.6 KB
/
Copy pathci.yml
File metadata and controls
795 lines (684 loc) · 31.6 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
130
131
132
133
134
135
136
137
138
139
140
141
142
143
144
145
146
147
148
149
150
151
152
153
154
155
156
157
158
159
160
161
162
163
164
165
166
167
168
169
170
171
172
173
174
175
176
177
178
179
180
181
182
183
184
185
186
187
188
189
190
191
192
193
194
195
196
197
198
199
200
201
202
203
204
205
206
207
208
209
210
211
212
213
214
215
216
217
218
219
220
221
222
223
224
225
226
227
228
229
230
231
232
233
234
235
236
237
238
239
240
241
242
243
244
245
246
247
248
249
250
251
252
253
254
255
256
257
258
259
260
261
262
263
264
265
266
267
268
269
270
271
272
273
274
275
276
277
278
279
280
281
282
283
284
285
286
287
288
289
290
291
292
293
294
295
296
297
298
299
300
301
302
303
304
305
306
307
308
309
310
311
312
313
314
315
316
317
318
319
320
321
322
323
324
325
326
327
328
329
330
331
332
333
334
335
336
337
338
339
340
341
342
343
344
345
346
347
348
349
350
351
352
353
354
355
356
357
358
359
360
361
362
363
364
365
366
367
368
369
370
371
372
373
374
375
376
377
378
379
380
381
382
383
384
385
386
387
388
389
390
391
392
393
394
395
396
397
398
399
400
401
402
403
404
405
406
407
408
409
410
411
412
413
414
415
416
417
418
419
420
421
422
423
424
425
426
427
428
429
430
431
432
433
434
435
436
437
438
439
440
441
442
443
444
445
446
447
448
449
450
451
452
453
454
455
456
457
458
459
460
461
462
463
464
465
466
467
468
469
470
471
472
473
474
475
476
477
478
479
480
481
482
483
484
485
486
487
488
489
490
491
492
493
494
495
496
497
498
499
500
501
502
503
504
505
506
507
508
509
510
511
512
513
514
515
516
517
518
519
520
521
522
523
524
525
526
527
528
529
530
531
532
533
534
535
536
537
538
539
540
541
542
543
544
545
546
547
548
549
550
551
552
553
554
555
556
557
558
559
560
561
562
563
564
565
566
567
568
569
570
571
572
573
574
575
576
577
578
579
580
581
582
583
584
585
586
587
588
589
590
591
592
593
594
595
596
597
598
599
600
601
602
603
604
605
606
607
608
609
610
611
612
613
614
615
616
617
618
619
620
621
622
623
624
625
626
627
628
629
630
631
632
633
634
635
636
637
638
639
640
641
642
643
644
645
646
647
648
649
650
651
652
653
654
655
656
657
658
659
660
661
662
663
664
665
666
667
668
669
670
671
672
673
674
675
676
677
678
679
680
681
682
683
684
685
686
687
688
689
690
691
692
693
694
695
696
697
698
699
700
701
702
703
704
705
706
707
708
709
710
711
712
713
714
715
716
717
718
719
720
721
722
723
724
725
726
727
728
729
730
731
732
733
734
735
736
737
738
739
740
741
742
743
744
745
746
747
748
749
750
751
752
753
754
755
756
757
758
759
760
761
762
763
764
765
766
767
768
769
770
771
772
773
774
775
776
777
778
779
780
781
782
783
784
785
786
787
788
789
790
791
792
793
794
795
name: CI
on:
push:
# train/** runs the same checks on a train branch before it is fast-forwarded
# onto master; required status checks on master are satisfied by that run.
branches: [master, main, "train/**"]
# The nightly run rechecks the Cargo graph pinned by Cargo.lock;
# workflow_dispatch remains available for an operator-triggered run.
schedule:
- cron: "17 3 * * *"
workflow_dispatch:
# A train branch gets pushed again with each merge, and every run is about twenty
# jobs against a shared runner limit, so a new push cancels the train's older run.
# master keeps every run, so a failure still names the commit that broke it.
concurrency:
group: ci-${{ github.ref }}
cancel-in-progress: ${{ github.ref != 'refs/heads/master' && github.ref != 'refs/heads/main' }}
env:
FORCE_JAVASCRIPT_ACTIONS_TO_NODE24: true
# Pipeline shape on every push to master/main:
#
# check-plugin (plugin, CLI, retina), check-pi-plugin (unit tests + lint + typecheck, parallel)
# ↓
# e2e-opencode, e2e-opencode2, e2e-pi, e2e-omp (Docker install + smoke, parallel — gated by unit)
# e2e-host-opencode, e2e-host-opencode2, e2e-host-pi, e2e-host-omp (host-behavior lanes from the mode manifest)
# ↓
#
# Two e2e layers cover different concerns:
# - Docker e2e: fresh-install smoke (plugin loads, doctor clean, one mock turn writes DB rows
# under cortexkit path with right harness). Catches packaging / install-flow regressions.
# - Host e2e: behavior suite with byte-level wire assertions, multi-turn cache stability,
# historian publish behavior, tag-owner collision, synthetic todowrite, cross-harness memory,
# etc. Spawns real `opencode serve` / Pi subprocesses against an embedded mock provider.
# Catches cache-stability + correctness regressions that the smoke layer cannot see.
#
# Docker e2e was previously in a separate workflow (e2e-docker.yml). Folding it here means
# every master/main push exercises the full unit → Docker → host gauntlet. The
# Rust jobs run on every push and scheduled run. Pushes use Cargo.lock-pinned crates;
# the scheduled hermetic build additionally probes the subconscious default branch:
#
# rust-crates cargo fmt / clippy --all-targets / cargo test, including every
# integration target under crates/*/tests
# e2e-rust-hermetic-build → e2e-rust-hermetic (4 shards)
#
# The mc-module integration tests always build ck-subc from its Cargo.lock revision.
# Hermetic push builds use that same revision; the nightly build intentionally builds
# subconscious default-branch HEAD and reports it as drift in the job summary.
jobs:
check-plugin:
name: Check (plugin)
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@v5
- uses: oven-sh/setup-bun@v2
with:
bun-version: latest
# node:sqlite (the Pi / OpenCode-Desktop SQLite backend) is only reachable
# under Node, not Bun. Node 24 also strips the smoke script's inline TS.
- uses: actions/setup-node@v4
with:
node-version: "24"
- name: Install dependencies
run: bun install --frozen-lockfile
- name: TypeScript typecheck
run: |
bun run --cwd packages/plugin typecheck
bun run --cwd packages/cli typecheck
bun run --cwd packages/retina-local-fs typecheck
- name: Lint
run: |
bun run --cwd packages/plugin lint
bun run --cwd packages/cli lint
bun run --cwd packages/retina-local-fs lint
- name: Build
run: |
bun run --cwd packages/plugin build
bun run --cwd packages/cli build
# Plugin tests load the Pi worker bundles from packages/pi-plugin/dist.
bun run --cwd packages/pi-plugin build
- name: Check compiled TUI freshness
run: bun run --cwd packages/plugin check:tui-compiled
# The historian prompt golden is the byte-parity contract between the
# TypeScript historian renderer and the Rust mc-module port. The Rust
# golden test pins the committed file from the Rust side, but only this
# regeneration check catches a TypeScript renderer change whose golden
# was never regenerated.
- name: Historian prompt golden drift check
run: bun crates/mc-module/gen/gen-historian-prompt-golden.ts --check
- name: Test
# Keep CLI and retina coverage here, but let check-pi-plugin own Pi's
# normal/assertion pair rather than fanning out through the root script.
run: |
bun run --cwd packages/plugin test
bun run --cwd packages/cli test
bun run --cwd packages/retina-local-fs test
- name: Test (debug assertions)
env:
MAGIC_CONTEXT_DEBUG_ASSERTIONS: "1"
# Keep each package's existing assertion-lane timeout; the root command
# previously forwarded --timeout=60000 only to the final retina suite.
run: |
bun run --cwd packages/plugin test
bun run --cwd packages/cli test
bun run --cwd packages/retina-local-fs test --timeout=60000
# Exercise the node:sqlite branch of shared/sqlite.ts under REAL Node —
# bun test only covers the bun:sqlite branch, so the transaction() shim,
# readonly→readOnly mapping, and the array-bind normalization (#151) would
# otherwise ship unverified on Pi/Desktop.
- name: Smoke (node:sqlite backend)
run: node packages/plugin/scripts/smoke-node-sqlite.ts
# The smart-note QuickJS sandbox loads a ~1MB WASM. `bun test` runs it from
# src (wasm resolves via node_modules), so it cannot catch a BUNDLING break
# where the wasm isn't embedded in dist. This bundles sandbox-runner exactly
# like the package build and runs a real check against the bundle.
- name: Smoke (smart-note wasm bundle)
run: bun packages/plugin/scripts/smoke-smartnote-wasm.ts
# The raw-TSX ./tui entry imports @opentui/solid's JSX runtime. `bun test`
# never imports it, so a missing/mismatched OpenTUI or Solid dep (as broke
# on OpenCode 1.17.10's OpenTUI 0.4.2 bump) ships a TUI that won't load.
# Import the entry the way OpenCode loads the ./tui export to catch it.
- name: Smoke (TUI entry import)
run: bun packages/plugin/scripts/smoke-tui-import.ts
# The dev-path import above cannot catch packaging breaks: OpenTUI's Solid
# transform skips node_modules sources, so only a packed PROD install
# exercises the resolution path OpenCode's plugin cache uses (v0.31.1
# shipped without runtime deps and passed every dev-path check).
- name: Smoke (TUI packaged install import)
run: bun packages/plugin/scripts/smoke-tui-pack-install.ts --skip-build
# Tokenizer loading is lazy, so an import-only smoke misses resolution
# failures. Pack + npm-install prod deps, then exercise an estimate from a
# compiled Bun host matching OpenCode's /$bunfs/root runtime.
- name: Smoke (tokenizer packaged install estimate)
run: bun packages/plugin/scripts/smoke-tokenizer-pack-install.ts --skip-build
check-pi-plugin:
name: Check (pi-plugin)
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@v5
- uses: oven-sh/setup-bun@v2
with:
bun-version: latest
- name: Install dependencies
run: bun install --frozen-lockfile
- name: TypeScript typecheck
run: bun run --cwd packages/pi-plugin typecheck
- name: Lint
run: bun run --cwd packages/pi-plugin lint
- name: Build
run: bun run --cwd packages/pi-plugin build
- name: Test
run: bun run --cwd packages/pi-plugin test
- name: Test (debug assertions)
env:
MAGIC_CONTEXT_DEBUG_ASSERTIONS: "1"
# Run serially so full-content assertion walks do not compete with Pi's
# full-runtime tests, whose existing per-test budgets remain 15 seconds.
run: bun run --cwd packages/pi-plugin test --parallel=1 --timeout=60000
check-dashboard:
name: Check (dashboard)
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@v5
- uses: oven-sh/setup-bun@v2
with:
bun-version: latest
- name: Install dependencies
run: bun install --frozen-lockfile
# Frontend-only checks (no Rust/Tauri needed). The key gate is the test
# step, which runs config-parity.test.ts — it fails the build if the
# plugin config schema gains/renames/removes a field the dashboard's
# ConfigEditor coverage manifest doesn't account for, so the form can't
# silently drift out of sync with the schema again.
- name: TypeScript typecheck
run: bun run --cwd packages/dashboard typecheck
- name: Lint
run: bun run --cwd packages/dashboard lint
- name: Test
run: bun run --cwd packages/dashboard test
- name: Build (frontend)
run: bun run --cwd packages/dashboard build
e2e-opencode:
name: E2E (OpenCode, Docker)
runs-on: ubuntu-latest
needs: [check-plugin]
timeout-minutes: 25
steps:
- uses: actions/checkout@v5
- uses: oven-sh/setup-bun@v2
with:
bun-version: latest
- name: Install workspace deps
run: bun install --frozen-lockfile
- name: Build OpenCode plugin
run: bun run --cwd packages/plugin build
- name: Build CLI
# The CLI is its own package (@cortexkit/magic-context) since
# v0.16.1; Dockerfile.opencode COPYs packages/cli/dist/ in.
run: bun run --cwd packages/cli build
- name: Build E2E image
run: |
docker build \
--platform linux/amd64 \
-f tests/docker/Dockerfile.opencode \
-t mc-e2e-opencode \
.
- name: Run E2E
run: docker run --rm --platform linux/amd64 mc-e2e-opencode
e2e-opencode2:
name: E2E (OpenCode 2.0.22, Docker)
runs-on: ubuntu-latest
needs: [check-plugin]
timeout-minutes: 30
steps:
- uses: actions/checkout@v5
- uses: oven-sh/setup-bun@v2
with:
bun-version: latest
- name: Install workspace dependencies
run: bun install --frozen-lockfile
# The wrapper is the single local/CI entrypoint. It builds the publishable
# plugin, fails if Docker or opencode2 is missing, and runs the exact-pinned
# GA host through a real transform, host fold, database check, and TUI boot.
- name: Run pinned OpenCode 2 container lane
run: tests/docker/opencode2/run.sh
e2e-pi:
name: E2E (Pi, Docker)
runs-on: ubuntu-latest
needs: [check-pi-plugin]
timeout-minutes: 25
steps:
- uses: actions/checkout@v5
- uses: oven-sh/setup-bun@v2
with:
bun-version: latest
- name: Install workspace deps
run: bun install --frozen-lockfile
- name: Build Pi plugin
run: bun run --cwd packages/pi-plugin build
- name: Build CLI
# The CLI moved to its own package (@cortexkit/magic-context) in
# v0.16.1. Dockerfile.pi COPYs packages/cli/dist/ in for the
# `magic-context doctor --harness pi` test invocation.
run: bun run --cwd packages/cli build
- name: Build E2E image
# The Pi Dockerfile installs runtime deps fresh inside the image
# (better-sqlite3 builds against linux/amd64), so no host-side
# `npm install` is needed.
run: |
docker build \
--platform linux/amd64 \
-f tests/docker/Dockerfile.pi \
-t mc-e2e-pi \
.
- name: Run E2E
run: docker run --rm --platform linux/amd64 mc-e2e-pi
e2e-omp:
name: E2E (Oh My Pi, real Docker)
runs-on: ubuntu-latest
needs: [check-pi-plugin]
timeout-minutes: 25
steps:
- uses: actions/checkout@v5
- uses: oven-sh/setup-bun@v2
with:
bun-version: latest
- name: Install workspace deps
run: bun install --frozen-lockfile
- name: Build Pi-compatible plugin and OMP argv renderer
run: |
bun run --cwd packages/pi-plugin build
bun run --cwd packages/pi-plugin build:e2e-argv
- name: Build CLI
run: bun run --cwd packages/cli build
- name: Build real OMP E2E image
run: |
docker build \
--platform linux/amd64 \
-f tests/docker/Dockerfile.omp \
-t mc-e2e-omp \
.
- name: Run real OMP install and session smoke
run: docker run --rm --platform linux/amd64 mc-e2e-omp
e2e-host-opencode:
name: E2E (OpenCode, host behavior)
runs-on: ubuntu-latest
# Gated on Docker e2e: no point exercising the deep behavior suite if
# the simpler install+smoke path is broken.
needs: [e2e-opencode]
timeout-minutes: 40
steps:
- uses: actions/checkout@v5
- uses: oven-sh/setup-bun@v2
with:
bun-version: latest
- name: Install workspace deps
run: bun install --frozen-lockfile
# Install opencode the same way the Docker image does — the host
# suite spawns `opencode serve` from PATH.
- name: Install opencode
# Float to LATEST (no --version) so CI exercises the opencode version
# users actually run and catches upstream breakage as it ships — not at
# our release time. (A fixed pin previously hid opencode 1.16's
# post-overflow change, commit 7e09660c3, until release; the
# overflow-recovery host test is now version-agnostic.) Trade-off: a
# known-bad upstream release can turn CI red for unrelated PRs — if that
# happens, temporarily re-pin with `--version X.Y.Z` here until it's
# resolved upstream.
run: |
OPENCODE_VERSION=latest bash tests/docker/install-opencode.sh
echo "$HOME/.opencode/bin" >> "$GITHUB_PATH"
- name: Verify opencode on PATH
run: opencode --version
- name: Build OpenCode plugin
# Host tests spawn `opencode serve` with a file:// plugin
# specifier pointing at packages/plugin/, so dist must exist.
run: bun run --cwd packages/plugin build
# Strip inherited NODE_ENV=test so the spawned opencode subprocess
# gets the same logging + runtime behavior as a normal local run
# (documented in CONTRIBUTING / project memory).
#
# Per-test (and per-hook) timeout bumped to 300s: the first test file
# Bun loads on a cold GitHub-hosted runner pays the dependency-resolution
# + opencode-binary cold-start cost in its `beforeAll(TestHarness.create)`,
# which can exceed Bun's 120s default. Subsequent files run in 5-10s.
- name: Run host e2e suite (OpenCode tests only)
env:
NODE_ENV: ""
MC_E2E_MODE: ts
MC_E2E_HOST: opencode
run: |
# The mode validator independently checks tests/**/*.test.ts and
# derives this OpenCode list. Rust coverage runs in the dedicated crate
# and hermetic jobs below, including on pushes.
cd packages/e2e-tests
# A validator failure must fail the job, never fall through to an empty
# list: `bun test` with no files runs every file in the package.
set -o pipefail
files=$(bun scripts/validate-mode-manifest.ts --mode ts --harness opencode | tr '\n' ' ')
if [ -z "${files// /}" ]; then echo 'mode manifest selected no files'; exit 1; fi
echo "Running OpenCode host tests from mode manifest: $files"
# shellcheck disable=SC2086 # The repository-controlled file list must expand into Bun arguments.
bun test --timeout 600000 $files
# This oracle is outside the manifest's tests/**/*.test.ts inventory.
bun test --timeout 600000 src/cache-analysis.test.ts
e2e-host-pi:
name: E2E (Pi, host behavior)
runs-on: ubuntu-latest
needs: [e2e-pi]
timeout-minutes: 40
steps:
- uses: actions/checkout@v5
- uses: oven-sh/setup-bun@v2
with:
bun-version: latest
# Pi tests resolve the Pi binary via createRequire against
# @earendil-works/pi-coding-agent, which is a workspace dep of
# packages/pi-plugin. `bun install` brings it in.
- name: Install workspace deps
run: bun install --frozen-lockfile
# pi-cross-harness.test.ts spawns BOTH a Pi runner and an OpenCode
# serve to verify cross-harness memory sharing, so this job needs
# opencode on PATH too. Float to LATEST like the OpenCode host job
# (see that step for the rationale + re-pin escape hatch).
- name: Install opencode
run: |
OPENCODE_VERSION=latest bash tests/docker/install-opencode.sh
echo "$HOME/.opencode/bin" >> "$GITHUB_PATH"
- name: Verify opencode on PATH
run: opencode --version
- name: Build Pi plugin
run: bun run --cwd packages/pi-plugin build
# pi-cross-harness also instantiates the OpenCode harness, which
# spawns `opencode serve` with a file:// plugin specifier pointing
# at packages/plugin/. That dist must exist.
- name: Build OpenCode plugin
run: bun run --cwd packages/plugin build
# Per-test timeout bumped to 300s for the same cold-start reason as
# the OpenCode host job. Pi historian publish path also crosses an
# HTTP boundary into the mock provider, which is slower on shared
# runners than on local hardware.
- name: Run host e2e suite (Pi tests from mode manifest)
env:
NODE_ENV: ""
MC_E2E_MODE: ts
MC_E2E_HOST: pi
run: |
cd packages/e2e-tests
# A validator failure must fail the job, never fall through to an empty
# list: `bun test` with no files runs every file in the package.
set -o pipefail
files=$(bun scripts/validate-mode-manifest.ts --mode ts --harness pi | tr '\n' ' ')
if [ -z "${files// /}" ]; then echo 'mode manifest selected no files'; exit 1; fi
echo "Running Pi host tests from mode manifest: $files"
# shellcheck disable=SC2086 # The repository-controlled file list must expand into Bun arguments.
bun test --timeout 600000 $files
e2e-host-opencode2:
name: E2E (OpenCode 2.0.22, host behavior)
runs-on: ubuntu-latest
needs: [e2e-opencode2]
timeout-minutes: 40
steps:
- uses: actions/checkout@v5
- uses: oven-sh/setup-bun@v2
with:
bun-version: latest
# The OpenCode 2 harness spawns the real GA host from @opencode/cli, a
# workspace dev dependency whose postinstall unpacks the platform binary
# (trustedDependencies at the workspace root lets bun run it).
- name: Install workspace deps
run: bun install --frozen-lockfile
# The conversion regression boots both generations and doctor probes the
# v1 CLI on PATH; the v2 binary comes from the pinned workspace dependency.
# The installer one-liner resolves "latest" through the rate-limited GitHub API
# and can exit 0 without installing; the repo's installer pins, retries and
# asserts the binary runs.
- name: Install OpenCode 1 for conversion coverage
run: |
OPENCODE_VERSION=1.18.31 bash tests/docker/install-opencode.sh
echo "$HOME/.opencode/bin" >> "$GITHUB_PATH"
- name: Verify the GA host binary
run: bun -e "const { CLI } = await import('./packages/e2e-tests/src/opencode2-runner/spawn.ts'); const { execFileSync } = await import('node:child_process'); const version = execFileSync(CLI, ['--version']).toString().trim(); console.log(CLI, version); if (version !== 'opencode v2.0.22') throw new Error('OpenCode 2 host lane requires 2.0.22')"
- name: Build OpenCode plugin (v1 + v2 entries)
run: bun run --cwd packages/plugin build
- name: Run host e2e suite (OpenCode 2 tests from mode manifest)
env:
NODE_ENV: ""
MC_E2E_MODE: ts
MC_E2E_HOST: opencode2
run: |
cd packages/e2e-tests
set -o pipefail
files=$(bun scripts/validate-mode-manifest.ts --mode ts --harness opencode2 | tr '\n' ' ')
if [ -z "${files// /}" ]; then echo 'mode manifest selected no files'; exit 1; fi
echo "Running OpenCode 2 host tests from mode manifest: $files"
# shellcheck disable=SC2086 # The repository-controlled file list must expand into Bun arguments.
bun test --timeout 600000 $files
# These long-lived dual-host fixtures manipulate separate throwaway stores,
# but run sequentially to avoid contending with one another's live hosts.
- name: Run OC2 conversion and marker regressions
env:
NODE_ENV: ""
MC_E2E_MODE: ts
MC_E2E_HOST: opencode2
run: |
cd packages/e2e-tests
bun test --timeout 600000 tests/opencode2/store-generation-conversion.test.ts
bun test --timeout 600000 tests/opencode2/marker-s3-runtime.test.ts
e2e-host-omp:
name: E2E (Oh My Pi, host behavior)
runs-on: ubuntu-latest
needs: [e2e-omp]
timeout-minutes: 40
steps:
- uses: actions/checkout@v5
- uses: oven-sh/setup-bun@v2
with:
bun-version: latest
# OMP runs the same Pi plugin through Pi's extension API; the harness
# resolves @oh-my-pi/pi-coding-agent (a workspace dev dependency) when
# MC_E2E_HOST=omp.
- name: Install workspace deps
run: bun install --frozen-lockfile
- name: Install opencode
run: |
OPENCODE_VERSION=latest bash tests/docker/install-opencode.sh
echo "$HOME/.opencode/bin" >> "$GITHUB_PATH"
- name: Build Pi plugin
run: bun run --cwd packages/pi-plugin build
- name: Build OpenCode plugin
run: bun run --cwd packages/plugin build
- name: Run host e2e suite (OMP tests from mode manifest)
env:
NODE_ENV: ""
MC_E2E_MODE: ts
MC_E2E_HOST: omp
run: |
cd packages/e2e-tests
set -o pipefail
files=$(bun scripts/validate-mode-manifest.ts --mode ts --harness omp | tr '\n' ' ')
if [ -z "${files// /}" ]; then echo 'mode manifest selected no files'; exit 1; fi
echo "Running OMP host tests from mode manifest: $files"
# shellcheck disable=SC2086 # The repository-controlled file list must expand into Bun arguments.
bun test --timeout 600000 $files
rust-crates:
name: Rust (crates)
# mc-module integration tests build ck-subc from the locked source revision.
# Published commons and subconscious crates resolve from this repository's
# Cargo.lock, so there is no commons checkout or floating crate source here.
#
# It exists because no other CI job runs cargo test; the hermetic build below
# compiles the crates only as part of producing its Rust test binaries, so an
# integration test under crates/*/tests could fail unobserved. It depends on the
# no other suite, so a Rust regression is reported even
# when an unrelated host suite is red.
runs-on: ubuntu-latest
timeout-minutes: 45
permissions:
contents: read
steps:
- uses: actions/checkout@v5
- uses: dtolnay/rust-toolchain@stable
with:
components: clippy, rustfmt
# The hostless-store integration test provisions context.db through the CLI.
- uses: oven-sh/setup-bun@v2
with:
bun-version: latest
- name: Install CLI dependencies
run: bun install --frozen-lockfile
- name: Resolve Cargo.lock crate pins
id: cargo-pins
shell: bash
run: |
set -euo pipefail
python3 scripts/cargo-lock-pins.py --self-test
pins="$(python3 scripts/cargo-lock-pins.py)"
printf '%s\n' "$pins" >> "$GITHUB_OUTPUT"
locked_crates="$(printf '%s\n' "$pins" | sed -n 's/^locked_crates=//p')"
echo "Cargo.lock pins: $locked_crates" >> "$GITHUB_STEP_SUMMARY"
# real_daemon.rs builds ck-subc and checks its launch-nonce history; this
# exact locked checkout is therefore needed only by this integration-test job.
- name: Check out locked subconscious source for daemon integration tests
uses: actions/checkout@v5
with:
repository: cortexkit/subconscious
path: .siblings/subconscious
ref: ${{ steps.cargo-pins.outputs.subc_revision }}
fetch-depth: 0
# These integration tests use ../subconscious to build ck-subc. Cargo now
# resolves commons crates from the registry/Git lock instead of ../commons.
- name: Link locked daemon source for integration tests
shell: bash
run: |
set -euo pipefail
ln -sfn "$GITHUB_WORKSPACE/.siblings/subconscious" "$GITHUB_WORKSPACE/../subconscious"
test -f "$GITHUB_WORKSPACE/../subconscious/Cargo.lock"
- name: Check Cargo path dependency boundaries
run: |
timeout 180s python3 scripts/check-cargo-path-dependencies.py
timeout 180s python3 scripts/check-cargo-path-dependencies.py --self-test
- name: Format check
run: cargo fmt --check
# --all-targets puts the integration tests under crates/*/tests through clippy
# too; a lib-only lint cannot see them.
- name: Clippy
run: cargo clippy --workspace --all-targets -- -D warnings
# `cargo test -p mc-module` runs the lib unit tests AND every integration test
# target under crates/mc-module/tests, which is where cold_flip_adversarial and
# the other cross-crate behaviour proofs live. Naming the package (not --lib)
# is the whole point of this step.
- name: Test mc-module (lib + integration targets)
run: cargo test -p mc-module
- name: Test the remaining workspace crates
run: cargo test --workspace --exclude mc-module
e2e-rust-hermetic-build:
name: E2E (Rust hermetic build)
# Cargo.lock pins the published crate versions and both git dependency revisions.
# On schedule the daemon checkout below intentionally switches to upstream HEAD.
runs-on: ubuntu-latest
timeout-minutes: 120
permissions:
contents: read
steps:
- uses: actions/checkout@v5
- uses: dtolnay/rust-toolchain@stable
- uses: oven-sh/setup-bun@v2
with:
bun-version: latest
- name: Resolve Cargo.lock crate pins
id: cargo-pins
shell: bash
run: |
set -euo pipefail
python3 scripts/cargo-lock-pins.py --self-test
pins="$(python3 scripts/cargo-lock-pins.py)"
printf '%s\n' "$pins" >> "$GITHUB_OUTPUT"
locked_crates="$(printf '%s\n' "$pins" | sed -n 's/^locked_crates=//p')"
echo "Cargo.lock pins: $locked_crates" >> "$GITHUB_STEP_SUMMARY"
# Cargo can resolve subc-core as a library dependency but does not build its
# ck-subc binary target. Pushes use the root lockfile revision; only the scheduled
# run deliberately checks the subconscious default branch for upstream drift.
- name: Check out Cargo.lock-pinned subconscious source for ck-subc
if: ${{ github.event_name != 'schedule' }}
uses: actions/checkout@v5
with:
repository: cortexkit/subconscious
path: .siblings/subconscious
ref: ${{ steps.cargo-pins.outputs.subc_revision }}
- name: Check out subconscious default branch for scheduled drift
if: ${{ github.event_name == 'schedule' }}
uses: actions/checkout@v5
with:
repository: cortexkit/subconscious
path: .siblings/subconscious
- name: Record ck-subc source revision
id: daemon-source
shell: bash
run: |
set -euo pipefail
sha="$(git -C "$GITHUB_WORKSPACE/.siblings/subconscious" rev-parse HEAD)"
if [[ "$GITHUB_EVENT_NAME" == "schedule" ]]; then
summary="ck-subc source drift: subconscious default-branch HEAD $sha"
else
summary="ck-subc source pinned by Cargo.lock: $sha"
fi
echo "$summary"
echo "$summary" >> "$GITHUB_STEP_SUMMARY"
echo "sha=$sha" >> "$GITHUB_OUTPUT"
- name: Derive hermetic Cargo cache key
id: cargo-cache-key
shell: bash
run: |
set -euo pipefail
# Key on the resolved Cargo graph plus the exact daemon source, including
# nightly HEAD, so pinned and drift builds never reuse one another's cache.
lock_digest="$(sha256sum Cargo.lock | awk '{print $1}')"
source_sha="${{ steps.daemon-source.outputs.sha }}"
digest="$(printf '%s\n%s\n' "$lock_digest" "$source_sha" | sha256sum | awk '{print $1}')"
echo "key=rust-hermetic-${RUNNER_OS}-${RUNNER_ARCH}-${digest}" >> "$GITHUB_OUTPUT"
- name: Restore ck-subc and ckdev-mc-e2e Cargo target cache
uses: actions/cache@v4
with:
path: packages/e2e-tests/.cache/rust-e2e-cargo-target
key: ${{ steps.cargo-cache-key.outputs.key }}
- name: Install workspace dependencies
run: bun install --frozen-lockfile
- name: Build hermetic binary pair (including fault-injection variant)
shell: bash
run: |
set -euo pipefail
target="$GITHUB_WORKSPACE/packages/e2e-tests/.cache/rust-e2e-cargo-target"
mkdir -p "$target/prebuilt"
CARGO_TARGET_DIR="$target" cargo build --release -p mc-module
cp "$target/release/ck-mc" "$target/prebuilt/ckdev-mc-e2e"
CARGO_TARGET_DIR="$target" cargo build --release -p mc-module --features drive-fault
cp "$target/release/ck-mc" "$target/prebuilt/ckdev-mc-e2e-drive-fault"
(cd "$GITHUB_WORKSPACE/.siblings/subconscious" && CARGO_TARGET_DIR="$target" cargo build --release -p subc-core --bins)
cp "$target/release/ck-subc" "$target/prebuilt/ckdev-subc"
- uses: actions/upload-artifact@v4
with:
name: rust-hermetic-binaries
path: packages/e2e-tests/.cache/rust-e2e-cargo-target/prebuilt/
if-no-files-found: error
retention-days: 1
e2e-rust-hermetic:
name: E2E (Rust hermetic ${{ matrix.shard }}/4)
runs-on: ubuntu-latest
needs: [e2e-rust-hermetic-build]
timeout-minutes: 60
strategy:
fail-fast: false
matrix:
shard: [0, 1, 2, 3]
permissions:
contents: read
steps:
- uses: actions/checkout@v5
- uses: dtolnay/rust-toolchain@stable
- uses: oven-sh/setup-bun@v2
with:
bun-version: latest
- name: Install workspace dependencies
run: bun install --frozen-lockfile
- uses: actions/download-artifact@v4
with:
name: rust-hermetic-binaries
path: packages/e2e-tests/.cache/prebuilt
- name: Make downloaded binaries executable
run: chmod +x packages/e2e-tests/.cache/prebuilt/ckdev-mc-e2e packages/e2e-tests/.cache/prebuilt/ckdev-mc-e2e-drive-fault packages/e2e-tests/.cache/prebuilt/ckdev-subc
- name: Install pinned OpenCode
run: |
OPENCODE_VERSION=1.18.32 bash tests/docker/install-opencode.sh
echo "$HOME/.opencode/bin" >> "$GITHUB_PATH"
- name: Build host plugins
run: |
bun run --cwd packages/plugin build
bun run --cwd packages/pi-plugin build
- name: Run manifest shard
env:
MC_E2E_SHARD: ${{ matrix.shard }}/4
MC_E2E_CK_MC_PREBUILT_BIN: ${{ github.workspace }}/packages/e2e-tests/.cache/prebuilt/ckdev-mc-e2e
MC_E2E_CK_MC_DRIVE_FAULT_BIN: ${{ github.workspace }}/packages/e2e-tests/.cache/prebuilt/ckdev-mc-e2e-drive-fault
MC_E2E_CK_SUBC_BIN: ${{ github.workspace }}/packages/e2e-tests/.cache/prebuilt/ckdev-subc
run: scripts/run-rust-hermetic-e2e.sh