Repository navigation
conformance #1141
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
| name: conformance | |
| # COST: the cross-port conformance matrix + full Java reactor + drift/mutation gates | |
| # are heavy, so they do NOT run on every push/PR — release gate (tag `v*`), a NIGHTLY | |
| # schedule, and on-demand (workflow_dispatch). Run them LOCALLY before opening/merging | |
| # a PR: | |
| # scripts/ci-local.sh # full parity (this + integration suite + drift) | |
| # scripts/ci-local.sh --quick # everything except the docker integration suite | |
| # The .githooks/pre-push hook also runs the TS build+typecheck gate locally, and the | |
| # cheap public-repo SECURITY gate (hygiene / leak-scan) still runs on every PR. | |
| # Push-to-main coverage comes from local-ci.yml on the self-hosted runner. | |
| # | |
| # THIN WRAPPER: scripts/ci-local.sh is the single definition of every check here. Each | |
| # job checks out, installs the toolchain its lane needs, and calls the script with that | |
| # lane's `--only` selector and `--no-integration` — integration-tests.yml owns the docker | |
| # suites. Change a check in the script, never here. Lanes, as the script defines them: | |
| # gates — fixture-lint, doc-template drift, embedded-library drift, leak scan and | |
| # the other offline repo gates (`--only gates`) | |
| # ts-fast — workspace build + typecheck, TS conformance, completeness (mutation) gate | |
| # csharp / java-fast (java + kotlin) / python — each port's conformance corpora | |
| # java-reactor — full-reactor `mvn clean install`, tests on (`--only java-slow`) | |
| # The Java lanes point the script's Maven repository at ~/.m2/repository so setup-java's | |
| # maven cache applies; the script's own default (~/.m2-ci) protects a developer's ~/.m2, | |
| # which an ephemeral hosted runner does not have. | |
| # | |
| # WHY A SCHEDULE, given local-ci already runs nightly: local-ci's `java-slow` lane runs | |
| # the same full reactor (`gate_java_reactor`, `mvn clean install`) — so "it does not run | |
| # the reactor" is NOT the gap. The gap is environmental, and it is measured. Two Java | |
| # test defects (a test asserting on an NPE message HotSpot's fast-throw is entitled to | |
| # stop producing once the path is hot; two test classes sharing files with nothing | |
| # declaring their surefire order) were found by the `v1.0.0-rc.5` tag's run of THIS | |
| # workflow and fixed in 1c24b8f9d / cd0158073. The 08:17 nightly local-ci run that | |
| # preceded both fixes reported `java-slow: success` with both defects live on `main`. | |
| # The two runs differ in environment, not in scope — hosted ubuntu-latest with jacoco ON | |
| # here, self-hosted with `-Djacoco.skip=true` there — and JIT heat and filesystem | |
| # ordering are exactly the defect classes one environment cannot see on its own. A | |
| # tag-only trigger meant the second environment looked only at a cut, which is the most | |
| # expensive moment to find out. Standard runners are free for a public repo, so the | |
| # second look costs nothing but wall-clock. The java-reactor job below sets | |
| # MO_CI_JACOCO=1 so the script keeps JaCoCo ON here — that is the second environment. | |
| on: | |
| push: | |
| tags: | |
| - 'v*' | |
| # Offset from local-ci's 08:17 so the two full-reactor runs do not overlap. | |
| schedule: | |
| - cron: '41 4 * * *' | |
| workflow_dispatch: | |
| permissions: | |
| contents: read | |
| jobs: | |
| gates: | |
| runs-on: ubuntu-latest | |
| steps: | |
| - uses: actions/checkout@v4 | |
| with: | |
| fetch-depth: 0 # leak-scan and the version gates diff against origin/main | |
| persist-credentials: false | |
| - uses: oven-sh/setup-bun@v2 | |
| with: | |
| bun-version: '1.3.14' | |
| - name: Cache Bun install cache | |
| uses: actions/cache@v4 | |
| with: | |
| path: ~/.bun/install/cache | |
| key: ${{ runner.os }}-bun-${{ hashFiles('bun.lock') }} | |
| restore-keys: | | |
| ${{ runner.os }}-bun- | |
| - run: scripts/ci-local.sh --only gates --strict-toolchains | |
| conformance: | |
| runs-on: ubuntu-latest | |
| strategy: | |
| fail-fast: false | |
| matrix: | |
| lane: [ts-fast, csharp, java-fast, python] | |
| steps: | |
| - uses: actions/checkout@v4 | |
| with: | |
| persist-credentials: false | |
| - name: Set up Bun (TS) | |
| if: matrix.lane == 'ts-fast' | |
| uses: oven-sh/setup-bun@v2 | |
| with: | |
| bun-version: '1.3.14' | |
| - name: Cache Bun install cache (TS) | |
| if: matrix.lane == 'ts-fast' | |
| uses: actions/cache@v4 | |
| with: | |
| path: ~/.bun/install/cache | |
| key: ${{ runner.os }}-bun-${{ hashFiles('bun.lock') }} | |
| restore-keys: | | |
| ${{ runner.os }}-bun- | |
| - name: Set up .NET (C#) | |
| if: matrix.lane == 'csharp' | |
| uses: actions/setup-dotnet@v4 | |
| with: | |
| dotnet-version: '8.0.x' | |
| - name: Cache NuGet packages (C#) | |
| if: matrix.lane == 'csharp' | |
| uses: actions/cache@v4 | |
| with: | |
| path: ~/.nuget/packages | |
| key: ${{ runner.os }}-nuget-${{ hashFiles('server/csharp/**/*.csproj') }} | |
| restore-keys: | | |
| ${{ runner.os }}-nuget- | |
| - name: Set up JDK (Java + Kotlin) | |
| if: matrix.lane == 'java-fast' | |
| uses: actions/setup-java@v4 | |
| with: | |
| distribution: 'temurin' | |
| java-version: '21' | |
| cache: maven | |
| - name: Set up uv (Python) | |
| if: matrix.lane == 'python' | |
| uses: astral-sh/setup-uv@v3 | |
| with: | |
| enable-cache: true | |
| - name: Conformance (${{ matrix.lane }}) | |
| env: | |
| LANE: ${{ matrix.lane }} | |
| run: | | |
| METAOBJECTS_CI_M2_REPO="$HOME/.m2/repository" \ | |
| scripts/ci-local.sh --only "$LANE" --no-integration --strict-toolchains | |
| java-reactor: | |
| # FULL-REACTOR build AND test of the Java parent reactor (server/java) — the | |
| # script's gate_java_reactor, which says why it exists and what stays out of it. | |
| # The integration-tests* modules are out-of-reactor and gated by | |
| # integration-tests.yml, hence --no-integration on the java-slow lane. | |
| runs-on: ubuntu-latest | |
| steps: | |
| - uses: actions/checkout@v4 | |
| with: | |
| persist-credentials: false | |
| - name: Set up JDK | |
| uses: actions/setup-java@v4 | |
| with: | |
| distribution: 'temurin' | |
| java-version: '21' | |
| cache: maven | |
| - name: Full-reactor build + test (all modules, tests on, JaCoCo on) | |
| env: | |
| MO_CI_JACOCO: '1' | |
| run: | | |
| METAOBJECTS_CI_M2_REPO="$HOME/.m2/repository" \ | |
| scripts/ci-local.sh --only java-slow --no-integration --strict-toolchains |