-
Notifications
You must be signed in to change notification settings - Fork 0
177 lines (155 loc) · 6.85 KB
/
Copy pathci.yml
File metadata and controls
177 lines (155 loc) · 6.85 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
130
131
132
133
134
135
136
137
138
139
140
141
142
143
144
145
146
147
148
149
150
151
152
153
154
155
156
157
158
159
160
161
162
163
164
165
166
167
168
169
170
171
172
173
174
175
176
177
name: CI
on:
push:
branches: [main]
pull_request:
branches: [main]
# Cancel in-progress CI runs on the same ref when a newer commit
# arrives. Per-ref grouping means a PR getting two pushes in quick
# succession only runs CI once on the latest sha; same for a series
# of main-branch merges. Doesn't affect release.yml — tag-build
# cancellation could leave half-uploaded signed artefacts.
concurrency:
group: ${{ github.workflow }}-${{ github.ref }}
cancel-in-progress: true
env:
FORCE_JAVASCRIPT_ACTIONS_TO_NODE24: "true"
permissions:
contents: read
# Two tiers: fast PR gate, post-merge validation.
#
# Pull requests run only the cheap gates — non-race `go test`, lint,
# govulncheck, the bundled-wasm determinism check (plus gitleaks + CodeQL in
# their own workflows) — so PR feedback is fast. `push: main` adds the slow
# `-race` test (the early race signal on main).
#
# There is deliberately NO cross-compile build job here. GoReleaser
# (release.yml) cross-compiles + signs every target at release time, and a
# platform break fails the release run rather than publishing — so a separate
# compile-only matrix would only duplicate that gate, never add to it.
# release.yml also re-runs the `-race` suite before building, so a data race
# can't reach a release either. The tag ruleset requires `test`/`lint`
# (present on the merge commit from push:main) + CodeQL + gitleaks; it must
# NOT require any `build (...)` context (none is produced anymore).
# Accepted trade-off: data races are caught post-merge, and a platform-specific
# compile break surfaces at release time (a failed release attempt), not on
# the PR or on push:main.
jobs:
test:
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
- name: Setup Go
uses: actions/setup-go@b7ad1dad31e06c5925ef5d2fc7ad053ef454303e # v7.0.0
with:
go-version: "1.26.6"
cache: true
- name: Build bundled wasm (EP-0042 Part B — built from source, not committed)
run: bash plugins/bundled/build.sh
- name: Download dependencies
run: go mod download
# PRs run the fast non-race suite; push:main runs the full -race
# suite (the post-merge race gate). -race requires cgo; release
# binaries are built pure-Go (CGO_ENABLED=0) by GoReleaser.
- name: Run tests
run: |
if [ "${{ github.event_name }}" = "push" ]; then
CGO_ENABLED=1 go test -race ./...
else
go test ./...
fi
- name: govulncheck
# Pin a version instead of @latest so the go.sum cache catches
# the download — otherwise sum.golang.org hiccups fail CI.
# Retry once on transient network errors.
run: |
set -e
for i in 1 2 3; do
go install golang.org/x/vuln/cmd/govulncheck@v1.1.4 && break
echo "retry $i: govulncheck install hiccup, sleeping"
sleep 10
done
govulncheck ./...
lint:
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
- name: Setup Go
uses: actions/setup-go@b7ad1dad31e06c5925ef5d2fc7ad053ef454303e # v7.0.0
with:
go-version: "1.26.6"
cache: true
- name: Build bundled wasm (EP-0042 Part B — built from source, not committed)
run: bash plugins/bundled/build.sh
- name: golangci-lint
uses: golangci/golangci-lint-action@ba0d7d2ec06a0ea1cb5fa41b2e4a3ab91d21278a # v9
with:
version: v2.11.4
args: --timeout=5m
official-plugins-abi:
name: Official plugins ABI
runs-on: ubuntu-24.04
timeout-minutes: 15
steps:
- name: Check out stado
uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
- name: Check out official plugins
uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
with:
repository: foobarto/stado-plugins
path: .tmp/official-plugins
- name: Setup Go
uses: actions/setup-go@b7ad1dad31e06c5925ef5d2fc7ad053ef454303e # v7.0.0
with:
go-version: "1.26.6"
cache: true
- name: Build bundled wasm
run: bash plugins/bundled/build.sh
- name: Check every released official plugin against this host ABI
run: |
set -euo pipefail
mapfile -t released < <(
jq -r '.plugins[] | select(.status == "released") | .path' \
.tmp/official-plugins/plugin-inventory.json | LC_ALL=C sort
)
if [ "${#released[@]}" -eq 0 ]; then
echo "::error::official released-plugin inventory is empty"
exit 1
fi
plugin_dirs=()
for plugin in "${released[@]}"; do
plugin_dirs+=(".tmp/official-plugins/${plugin}/dist")
done
go run ./cmd/stado plugin abi-check "${plugin_dirs[@]}"
# EP-0042 D3 / item-7: the bundled wasm is built from source at
# build/release time and go:embed'd, so the binary-level signature only
# covers reproducible bytes if the rebuild is byte-for-byte deterministic.
# Build it twice and compare shas; a mismatch means a non-deterministic
# build crept in (historically these corrupted //go:wasmexport arities).
# Not in the tag ruleset's required set — informational gate on PR/main.
wasm-determinism:
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
- name: Setup Go
uses: actions/setup-go@b7ad1dad31e06c5925ef5d2fc7ad053ef454303e # v7.0.0
with:
go-version: "1.26.6"
cache: true
- name: Verify bundled wasm rebuild is deterministic
run: |
set -euo pipefail
# Each build uses a fresh, isolated GOCACHE so the second run can't
# replay the first run's cached package/link outputs — otherwise the
# gate could hash cache hits and miss compiler-stage nondeterminism
# (the failure mode this is meant to catch). Both builds compile cold.
GOCACHE="${RUNNER_TEMP}/gocache-1" bash plugins/bundled/build.sh
sha256sum internal/plugins/bundled/wasm/*.wasm | sort > "${RUNNER_TEMP}/wasm-sha-1.txt"
rm -f internal/plugins/bundled/wasm/*.wasm
GOCACHE="${RUNNER_TEMP}/gocache-2" bash plugins/bundled/build.sh
sha256sum internal/plugins/bundled/wasm/*.wasm | sort > "${RUNNER_TEMP}/wasm-sha-2.txt"
if ! diff -u "${RUNNER_TEMP}/wasm-sha-1.txt" "${RUNNER_TEMP}/wasm-sha-2.txt"; then
echo "::error::bundled wasm rebuild is non-deterministic (EP-0042 D3) — release artefacts would not be reproducible from source"
exit 1
fi
echo "bundled wasm rebuild is deterministic ($(wc -l < "${RUNNER_TEMP}/wasm-sha-1.txt") artefacts)"