-
Notifications
You must be signed in to change notification settings - Fork 0
172 lines (145 loc) · 6.17 KB
/
Copy pathci.yml
File metadata and controls
172 lines (145 loc) · 6.17 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
130
131
132
133
134
135
136
137
138
139
140
141
142
143
144
145
146
147
148
149
150
151
152
153
154
155
156
157
158
159
160
161
162
163
164
165
166
167
168
169
170
171
172
name: CI
on:
push:
branches:
- dev
- main
pull_request:
permissions:
contents: read
concurrency:
# 同分支新推送自动取消旧排队 run——防 runner 拥塞时排队堆积与新旧 run 互相覆盖
group: ci-${{ github.ref }}
cancel-in-progress: true
jobs:
quality:
name: ${{ matrix.os }}
strategy:
fail-fast: false
matrix:
os: [ubuntu-latest, macos-latest]
runs-on: ${{ matrix.os }}
steps:
- name: Checkout
uses: actions/checkout@v7
- name: Checkout fixed Thymeleaf baseline
uses: actions/checkout@v7
with:
repository: thymeleaf/thymeleaf
ref: 10f9dd2eb8cbd98515ce14b149d115e0287d0add
path: upstream-thymeleaf
- name: Install fixed Java Oracle runtime
uses: actions/setup-java@v6
with:
distribution: temurin
java-version: "21"
cache: maven
- name: Install Rust
uses: dtolnay/rust-toolchain@stable
with:
components: clippy, llvm-tools-preview, rustfmt
- name: Cache Cargo
uses: Swatinem/rust-cache@v2
- name: Install cargo-llvm-cov
uses: taiki-e/install-action@cargo-llvm-cov
- name: Check formatting
run: cargo fmt --all --check
- name: Generate source-test parity manifest (required at compile time)
# acceptance.rs 在编译期 include_str!("../source-test-parity.json");
# 该文件由 *.json 忽略规则排除入库,CI 必须先于任何编译步骤生成
# (TEST_CASE 2,608 + TEST_ASSET 2,686,SHA-256 与 acceptance 校验一致)。
run: >-
python3 scripts/generate_test_asset_manifest.py
--output thymeleaf-test/source-test-parity.json
- name: Run Clippy
run: cargo clippy --workspace --all-targets --all-features -- -D warnings
- name: Check migration tooling
run: >-
cargo clippy
--manifest-path xtask/Cargo.toml
--all-targets
--
-D warnings
- name: Check migration tooling formatting
run: cargo fmt --manifest-path xtask/Cargo.toml --all --check
- name: Test migration tooling
run: cargo test --manifest-path xtask/Cargo.toml
- name: Enforce migration manifest and layout
run: >-
cargo xtask migration-check
--upstream upstream-thymeleaf
--baseline 10f9dd2eb8cbd98515ce14b149d115e0287d0add
--json target/migration-check.json
- name: Enforce generic migration layout audit (vendored, approvals-aware)
# 硬门禁:strict_blockers=0 + 来源注释警告(missing_java_source_comment)
# 已清零(阶段 1.4),--fail-on-warning 全量启用。
run: >-
python3 scripts/audit_migration_layout.py
--rust-root thymeleaf
--java-package-root upstream-thymeleaf/lib/thymeleaf/src/main/java/org/thymeleaf
--retain-segments 1
--approvals docs/migration/layout_approvals.json
--require-source-comments
--fail-on-warning
- name: Validate fixed Java semantic baseline (core only)
# Spring 集成测试(spring5/6/springsecurity5/6)已从 baseline 静态清单中
# 移除(对象级对照表.md 范围声明:Spring 集成语义不入清单),Maven 与
# parity ledger 同步收窄到 tests/thymeleaf-tests-core 单模块,省 ~2 分钟
# 构建/运行成本。
working-directory: upstream-thymeleaf
run: >-
mvn
-pl
tests/thymeleaf-tests-core
-am
test
-DskipITs
'-DargLine=-Duser.language=en -Duser.country=US'
- name: Enforce Java source and runtime case parity ledger
env:
THYMELEAF_UPSTREAM: ${{ github.workspace }}/upstream-thymeleaf
run: |
python3 scripts/generate_source_parity_inventory.py \
--surefire-root upstream-thymeleaf/tests/thymeleaf-tests-core/target/surefire-reports \
--output target/source_parity_inventory.json
diff -u \
docs/migration/baseline/source_parity_inventory.json \
target/source_parity_inventory.json
cargo test -p thymeleaf-test --test source_parity_inventory
- name: Run tests
run: cargo test --workspace --all-features
- name: Enforce complete Rust semantic parity corpus
env:
THYMELEAF_UPSTREAM: ${{ github.workspace }}/upstream-thymeleaf
THYMELEAF_SCOPE: semantic_all
run: cargo test -p thymeleaf-test --test thtest_upstream_plain_batch
- name: Report source coverage
run: >-
cargo llvm-cov
--workspace
--all-features
--summary-only
- name: Check dependency licenses, sources, and duplicates
# EmbarkStudios/cargo-deny-action 是容器 action,仅支持 Linux runner;
# 许可证/来源/重复检查与平台无关,macOS 任务跳过(复用 ubuntu 结果)。
if: runner.os == 'Linux'
uses: EmbarkStudios/cargo-deny-action@v2
- name: Install cargo-audit
uses: taiki-e/install-action@cargo-audit
- name: Check dependency vulnerabilities (cargo-audit)
run: cargo audit
- name: Install cargo-public-api
run: cargo install cargo-public-api --locked
# cargo-public-api 需要 nightly rustdoc(--output-format json)。
# 放在本 job 最后:dtolnay/rust-toolchain 会切换默认 toolchain,
# 前面 fmt/clippy/test 步骤必须保持 stable;固定 nightly 与
# api-baseline.txt 生成版本一致,public-api 步骤因此成为硬门禁。
- name: Install pinned nightly (public-api)
uses: dtolnay/rust-toolchain@nightly
with:
toolchain: nightly-2026-07-28
- name: Check core crate public API baseline (hard gate)
# 使用与 baseline 生成版本一致的固定 nightly;任何 API 漂移都会使
# 本步骤失败(alpha 阶段 API 变更必须显式更新 docs/release/api-baseline.txt)。
run: |
cargo +nightly-2026-07-28 public-api -p thymeleaf 2>/dev/null | diff - docs/release/api-baseline.txt