Repository navigation
189 lines (177 loc) · 7.66 KB
/
Copy pathci.yml
File metadata and controls
189 lines (177 loc) · 7.66 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
130
131
132
133
134
135
136
137
138
139
140
141
142
143
144
145
146
147
148
149
150
151
152
153
154
155
156
157
158
159
160
161
162
163
164
165
166
167
168
169
170
171
172
173
174
175
176
177
178
179
180
181
182
183
184
185
186
187
188
189
name: CI
# What every change is checked against. Everything here runs on one runner
# family and is expected to finish quickly enough to read before moving on;
# the checks that need a second operating system, a compiler helper, or a real
# build toolchain live in the verify workflow, which runs when a change lands
# on main.
#
# Prose is exempt. A change that touches only Markdown or the documentation
# tree cannot alter what any of these checks answer, so running them there
# spends the whole workflow to re-confirm the previous result. The exemption is
# by path, not by branch: a push carrying both prose and code is a code change
# and still runs. The list is spelled out under each trigger because the
# workflow parser does not resolve YAML anchors.
on:
push:
branches: [main, develop]
paths-ignore:
- '**/*.md'
- 'docs/**'
pull_request:
paths-ignore:
- '**/*.md'
- 'docs/**'
workflow_dispatch:
concurrency:
group: ${{ github.workflow }}-${{ github.ref }}
cancel-in-progress: true
env:
CARGO_TERM_COLOR: always
RUSTFLAGS: "-D warnings"
jobs:
lint:
name: fmt + clippy + docs + boundaries
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@v7
- uses: dtolnay/rust-toolchain@stable
with:
components: rustfmt, clippy
- uses: Swatinem/rust-cache@v2
- name: Format
run: cargo fmt --all --check
- name: Clippy
run: cargo clippy --workspace --all-targets --all-features -- -D warnings
- name: Verify compiler helper boundaries
run: make verify-helper-boundaries
- name: Verify artifact dependency boundary
run: make verify-artifact-boundaries
- name: Docs
run: cargo doc --workspace --no-deps --all-features
env:
RUSTDOCFLAGS: "-D warnings"
test:
name: test
runs-on: ubuntu-latest
steps:
# The whole history, not the default single commit. The seam tests count
# co-changes and breaches over this repository's own commits, and a
# shallow checkout would leave them measuring one commit and reporting
# the emptiness as an answer.
- uses: actions/checkout@v7
with:
fetch-depth: 0
# `rust-toolchain.toml` names the components, `rust-src` among them.
- uses: dtolnay/rust-toolchain@stable
- uses: Swatinem/rust-cache@v2
# The suite includes the Semantic-mode tests, which ask the C/C++ helper
# about real translation units. It loads libclang at run time and reads a
# control-flow graph by invoking `clang` separately, so both the library
# and the unversioned driver have to be here. Neither is a CI-only extra:
# they are what running this suite needs anywhere.
- name: Install Clang and libclang
run: |
sudo apt-get update
sudo apt-get install -y --no-install-recommends clang libclang-dev libc++-dev libc++abi-dev
# The labelled precision tests refuse to pass on an empty measurement:
# with no case materialized they report that nothing was measured rather
# than reporting success. The suite therefore needs the same sources the
# accuracy job fetches.
- name: Materialize the labelled corpora
run: corpus/scripts/materialize-labeled.sh
# Formatting, lints and docs belong to the lint job. Running them here as
# well only buys a second copy of the same answer.
#
# Every test binary runs, rather than stopping at the first one that
# fails. A fault that only shows on one platform is rarely alone, and
# stopping at the first means meeting the next a full round trip later.
- name: Test
run: cargo test --workspace --all-targets --all-features --no-fail-fast
# `--all-targets` excludes doc examples, so a second run is what actually
# compiles them. An example that no longer builds is documentation that is
# wrong, and no other job here would say so.
- name: Test doc examples
run: cargo test --workspace --doc --all-features --no-fail-fast
helperless-modes:
name: Fast and Structural without compiler helpers
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@v7
- uses: dtolnay/rust-toolchain@stable
# Do not restore a target directory from another job. This package-only
# build compiles the CLI and its library dependencies, never either
# compiler-helper binary.
- name: Exercise helper-free modes
run: cargo test -p codehelion --test scan fast_and_structural_modes_run_without_compiler_helpers
env:
CARGO_TARGET_DIR: ${{ runner.temp }}/codehelion-helperless-target
accuracy:
name: detection accuracy
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@v7
- uses: dtolnay/rust-toolchain@stable
- uses: Swatinem/rust-cache@v2
# The labelled cases record a commit, not the code it names: the sources
# belong to the projects they came from and are fetched here rather than
# committed. Without this step the accuracy run still passes, with every
# labelled case reported as unscored — which is the point of the step.
- name: Materialize the labelled corpora
run: corpus/scripts/materialize-labeled.sh
- name: Measure
run: make eval
seam:
name: seam report
runs-on: ubuntu-latest
steps:
# Reading co-change needs the commits it is computed over, so this job
# is one of the two that checks the tree out in full.
- uses: actions/checkout@v7
with:
fetch-depth: 0
- uses: dtolnay/rust-toolchain@stable
- uses: Swatinem/rust-cache@v2
# Reported, not enforced. `--deny-asymmetric` is deliberately absent: a
# change touching one member of a seam is often the right change, and a
# check that cannot tell those apart belongs in the log where a reviewer
# reads it rather than in a status that blocks the branch.
# `--no-record` because the database this would write to is thrown away
# with the runner. A generation nothing can ever be compared against is
# not a generation, and recording one here would only teach a reader to
# expect a trend that never survives the job.
- name: Report seam metrics
run: cargo run -p codehelion -- seam --no-record
# `HEAD~1` rather than a branch name: a pull request is checked out as a
# merge commit whose first parent is the base, so this reads the change
# under review, and on a push it reads the commit that was pushed.
- name: Report what this change touched
run: cargo run -p codehelion -- guard --since HEAD~1
packaging:
name: publishable crates build from their own package
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@v7
- uses: dtolnay/rust-toolchain@stable
- uses: Swatinem/rust-cache@v2
# Building a crate from its own package directory is the only thing that
# reads it the way a dependent will, and nothing else in this workflow
# does. Asking on every change rather than at release time keeps the
# answer current: the alternative is finding out at the tag that a crate
# has been unbuildable from its own tarball for weeks.
- name: Package every publishable crate
run: make verify-packaging
msrv:
name: minimum supported rust version
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@v7
- uses: dtolnay/rust-toolchain@1.98.0
- uses: Swatinem/rust-cache@v2
- name: Build
run: cargo build --all-features
deny:
name: cargo-deny
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@v7
- uses: EmbarkStudios/cargo-deny-action@v2