Skip to content

conformance

conformance #1141

Workflow file for this run

name: conformance
# COST: the cross-port conformance matrix + full Java reactor + drift/mutation gates
# are heavy, so they do NOT run on every push/PR — release gate (tag `v*`), a NIGHTLY
# schedule, and on-demand (workflow_dispatch). Run them LOCALLY before opening/merging
# a PR:
# scripts/ci-local.sh # full parity (this + integration suite + drift)
# scripts/ci-local.sh --quick # everything except the docker integration suite
# The .githooks/pre-push hook also runs the TS build+typecheck gate locally, and the
# cheap public-repo SECURITY gate (hygiene / leak-scan) still runs on every PR.
# Push-to-main coverage comes from local-ci.yml on the self-hosted runner.
#
# THIN WRAPPER: scripts/ci-local.sh is the single definition of every check here. Each
# job checks out, installs the toolchain its lane needs, and calls the script with that
# lane's `--only` selector and `--no-integration` — integration-tests.yml owns the docker
# suites. Change a check in the script, never here. Lanes, as the script defines them:
# gates — fixture-lint, doc-template drift, embedded-library drift, leak scan and
# the other offline repo gates (`--only gates`)
# ts-fast — workspace build + typecheck, TS conformance, completeness (mutation) gate
# csharp / java-fast (java + kotlin) / python — each port's conformance corpora
# java-reactor — full-reactor `mvn clean install`, tests on (`--only java-slow`)
# The Java lanes point the script's Maven repository at ~/.m2/repository so setup-java's
# maven cache applies; the script's own default (~/.m2-ci) protects a developer's ~/.m2,
# which an ephemeral hosted runner does not have.
#
# WHY A SCHEDULE, given local-ci already runs nightly: local-ci's `java-slow` lane runs
# the same full reactor (`gate_java_reactor`, `mvn clean install`) — so "it does not run
# the reactor" is NOT the gap. The gap is environmental, and it is measured. Two Java
# test defects (a test asserting on an NPE message HotSpot's fast-throw is entitled to
# stop producing once the path is hot; two test classes sharing files with nothing
# declaring their surefire order) were found by the `v1.0.0-rc.5` tag's run of THIS
# workflow and fixed in 1c24b8f9d / cd0158073. The 08:17 nightly local-ci run that
# preceded both fixes reported `java-slow: success` with both defects live on `main`.
# The two runs differ in environment, not in scope — hosted ubuntu-latest with jacoco ON
# here, self-hosted with `-Djacoco.skip=true` there — and JIT heat and filesystem
# ordering are exactly the defect classes one environment cannot see on its own. A
# tag-only trigger meant the second environment looked only at a cut, which is the most
# expensive moment to find out. Standard runners are free for a public repo, so the
# second look costs nothing but wall-clock. The java-reactor job below sets
# MO_CI_JACOCO=1 so the script keeps JaCoCo ON here — that is the second environment.
on:
push:
tags:
- 'v*'
# Offset from local-ci's 08:17 so the two full-reactor runs do not overlap.
schedule:
- cron: '41 4 * * *'
workflow_dispatch:
permissions:
contents: read
jobs:
gates:
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@v4
with:
fetch-depth: 0 # leak-scan and the version gates diff against origin/main
persist-credentials: false
- uses: oven-sh/setup-bun@v2
with:
bun-version: '1.3.14'
- name: Cache Bun install cache
uses: actions/cache@v4
with:
path: ~/.bun/install/cache
key: ${{ runner.os }}-bun-${{ hashFiles('bun.lock') }}
restore-keys: |
${{ runner.os }}-bun-
- run: scripts/ci-local.sh --only gates --strict-toolchains
conformance:
runs-on: ubuntu-latest
strategy:
fail-fast: false
matrix:
lane: [ts-fast, csharp, java-fast, python]
steps:
- uses: actions/checkout@v4
with:
persist-credentials: false
- name: Set up Bun (TS)
if: matrix.lane == 'ts-fast'
uses: oven-sh/setup-bun@v2
with:
bun-version: '1.3.14'
- name: Cache Bun install cache (TS)
if: matrix.lane == 'ts-fast'
uses: actions/cache@v4
with:
path: ~/.bun/install/cache
key: ${{ runner.os }}-bun-${{ hashFiles('bun.lock') }}
restore-keys: |
${{ runner.os }}-bun-
- name: Set up .NET (C#)
if: matrix.lane == 'csharp'
uses: actions/setup-dotnet@v4
with:
dotnet-version: '8.0.x'
- name: Cache NuGet packages (C#)
if: matrix.lane == 'csharp'
uses: actions/cache@v4
with:
path: ~/.nuget/packages
key: ${{ runner.os }}-nuget-${{ hashFiles('server/csharp/**/*.csproj') }}
restore-keys: |
${{ runner.os }}-nuget-
- name: Set up JDK (Java + Kotlin)
if: matrix.lane == 'java-fast'
uses: actions/setup-java@v4
with:
distribution: 'temurin'
java-version: '21'
cache: maven
- name: Set up uv (Python)
if: matrix.lane == 'python'
uses: astral-sh/setup-uv@v3
with:
enable-cache: true
- name: Conformance (${{ matrix.lane }})
env:
LANE: ${{ matrix.lane }}
run: |
METAOBJECTS_CI_M2_REPO="$HOME/.m2/repository" \
scripts/ci-local.sh --only "$LANE" --no-integration --strict-toolchains
java-reactor:
# FULL-REACTOR build AND test of the Java parent reactor (server/java) — the
# script's gate_java_reactor, which says why it exists and what stays out of it.
# The integration-tests* modules are out-of-reactor and gated by
# integration-tests.yml, hence --no-integration on the java-slow lane.
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@v4
with:
persist-credentials: false
- name: Set up JDK
uses: actions/setup-java@v4
with:
distribution: 'temurin'
java-version: '21'
cache: maven
- name: Full-reactor build + test (all modules, tests on, JaCoCo on)
env:
MO_CI_JACOCO: '1'
run: |
METAOBJECTS_CI_M2_REPO="$HOME/.m2/repository" \
scripts/ci-local.sh --only java-slow --no-integration --strict-toolchains