Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
14 changes: 12 additions & 2 deletions .github/workflows/cli-distribution-check.yml
Original file line number Diff line number Diff line change
Expand Up @@ -16,7 +16,7 @@ jobs:
matrix:
os: [ubuntu-22.04, ubuntu-22.04-arm, macos-15, macos-15-intel]
runs-on: ${{ matrix.os }}
timeout-minutes: 35
timeout-minutes: 45
steps:
- uses: actions/checkout@11d5960a326750d5838078e36cf38b85af677262
with:
Expand Down Expand Up @@ -103,11 +103,21 @@ jobs:
python3 -m unittest discover -s cli/ci -p test_rehearse_npm_identity.py
- name: Build, package and exercise fresh standalone and npm installations
run: python3 cli/ci/rehearse_release.py --output "$RUNNER_TEMP/cli-rehearsal" --trials 1
- name: Test Homebrew candidate archive admission
run: python3 -m unittest discover -s cli/ci -p test_homebrew_rehearsal.py
- uses: Homebrew/actions/setup-homebrew@dc7099b3e807f1e2ecc61f3ecabc840eedd5586a
- name: Rehearse Homebrew against this build's verified native archives
run: >-
"$RUNNER_TEMP/distribution-python/bin/python3" cli/ci/homebrew_rehearsal.py
--rehearsal "$RUNNER_TEMP/cli-rehearsal"
--output "$RUNNER_TEMP/cli-homebrew-rehearsal"
- name: Retain rehearsal evidence
if: always()
uses: actions/upload-artifact@ea165f8d65b6e75b540449e92b4886f43607fa02
with:
name: cli-rehearsal-${{ matrix.os }}
path: ${{ runner.temp }}/cli-rehearsal
path: |
${{ runner.temp }}/cli-rehearsal
${{ runner.temp }}/cli-homebrew-rehearsal
retention-days: 14
if-no-files-found: warn
11 changes: 11 additions & 0 deletions .github/workflows/cli-kernel-rc.yml
Original file line number Diff line number Diff line change
Expand Up @@ -75,6 +75,16 @@ jobs:
env:
RC_VERSION: ${{ inputs.version || '0.15.0-rc.1' }}
run: python3 cli/ci/build_kernel_rc.py --version "$RC_VERSION" --out "$RUNNER_TEMP/kernel-rc"
- uses: Homebrew/actions/setup-homebrew@dc7099b3e807f1e2ecc61f3ecabc840eedd5586a
- name: Rehearse Homebrew against these exact release archives
env:
RC_VERSION: ${{ inputs.version || '0.15.0-rc.1' }}
EXPECTED_SOURCE: ${{ github.sha }}
run: |
"$RUNNER_TEMP/distribution-python/bin/python3" cli/ci/homebrew_rehearsal.py \
--kernel-rc "$RUNNER_TEMP/kernel-rc" \
--expected-source "$EXPECTED_SOURCE" --expected-version "$RC_VERSION" \
--output "$RUNNER_TEMP/kernel-rc/homebrew"
- name: Retain packages and offline evidence
if: always()
uses: actions/upload-artifact@ea165f8d65b6e75b540449e92b4886f43607fa02
Expand All @@ -84,5 +94,6 @@ jobs:
${{ runner.temp }}/kernel-rc/package
${{ runner.temp }}/kernel-rc/logs
${{ runner.temp }}/kernel-rc/build-report.json
${{ runner.temp }}/kernel-rc/homebrew
retention-days: 14
if-no-files-found: warn
27 changes: 27 additions & 0 deletions cli/ci/check_workflows.py
Original file line number Diff line number Diff line change
Expand Up @@ -17,6 +17,7 @@
"astral-sh/setup-uv": "d0d8abe699bfb85fec6de9f7adb5ae17292296ff",
"oven-sh/setup-bun": "3d267786b128fe76c2f16a390aa2448b815359f3",
"actions/upload-artifact": "ea165f8d65b6e75b540449e92b4886f43607fa02",
"Homebrew/actions/setup-homebrew": "dc7099b3e807f1e2ecc61f3ecabc840eedd5586a",
"sigstore/cosign-installer": "828df1e55de306ba29db814d6057ddae71883cda",
}
JOBS = {
Expand Down Expand Up @@ -304,6 +305,32 @@ def require(condition: bool, message: str) -> None:
by_name[required_step]["run"] == command,
"required qualification command drift",
)
if name in ("cli-distribution-check.yml", "cli-kernel-rc.yml"):
kernel_rc = name == "cli-kernel-rc.yml"
label = ("Rehearse Homebrew against these exact release archives" if kernel_rc
else "Rehearse Homebrew against this build's verified native archives")
homebrew = by_name[label]
setup = next(step for step in steps if step.get("uses", "").startswith("Homebrew/actions/setup-homebrew@"))
retention = next(step for step in steps if step.get("uses", "").startswith("actions/upload-artifact@"))
require(homebrew.get("if") is None and setup.get("if") is None,
"Homebrew admission must not be conditional")
require(steps.index(by_name[required_step]) < steps.index(setup) < steps.index(homebrew) < steps.index(retention),
"test already-built Homebrew archives before retaining results")
fragments = ['"$RUNNER_TEMP/distribution-python/bin/python3" cli/ci/homebrew_rehearsal.py']
if kernel_rc:
fragments += ['--kernel-rc "$RUNNER_TEMP/kernel-rc"', '--expected-source "$EXPECTED_SOURCE"',
'--expected-version "$RC_VERSION"', '--output "$RUNNER_TEMP/kernel-rc/homebrew"']
require(homebrew.get("env") == {"RC_VERSION": "${{ inputs.version || '0.15.0-rc.1' }}",
"EXPECTED_SOURCE": "${{ github.sha }}"},
"exact release Homebrew admission must bind workflow source/version")
evidence_path = "${{ runner.temp }}/kernel-rc/homebrew"
else:
fragments += ['--rehearsal "$RUNNER_TEMP/cli-rehearsal"', '--output "$RUNNER_TEMP/cli-homebrew-rehearsal"']
evidence_path = "${{ runner.temp }}/cli-homebrew-rehearsal"
require(all(fragment in homebrew.get("run", "") for fragment in fragments),
"Homebrew admission must use pinned Python and verified archive custody")
require(evidence_path in retention.get("with", {}).get("path", "").splitlines(),
"retain Homebrew custody and cleanup results")
require(
any(
step.get("uses", "").startswith("actions/upload-artifact@")
Expand Down
Loading
Loading