Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
4 changes: 4 additions & 0 deletions .github/actionlint.yaml
Original file line number Diff line number Diff line change
@@ -0,0 +1,4 @@
# Custom labels for the self-hosted runners; actionlint cannot discover them.
self-hosted-runner:
labels:
- normal
35 changes: 25 additions & 10 deletions .github/actions/with-docker/action.yml
Original file line number Diff line number Diff line change
Expand Up @@ -3,36 +3,51 @@ description: 'Run a given stage with Docker Image'
inputs:
container-name:
description: 'Docker container name to use'
type: string
required: true
runs:
using: 'composite'
steps:
# The Dockerfile's first stage is `FROM ghcr.io/foundry-rs/foundry`, a
# third-party org's public image. Self-hosted runners can carry a stale
# ghcr.io credential in their docker config; BuildKit then sends it when
# fetching the pull token and ghcr.io rejects it ("denied: denied") instead
# of falling back to anonymous. Log in with a fresh token so the credential
# is always valid (a valid GITHUB_TOKEN can pull public images from any org).
- name: 'Log in to ghcr.io'
uses: docker/login-action@c94ce9fb468520275223c153574b00df6fe4bcc9 # v3.7.0
with:
registry: ghcr.io
username: ${{ github.actor }}
password: ${{ github.token }}
- name: 'Set up Docker'
env:
CONTAINER_NAME: ${{ inputs.container-name }}
shell: bash {0}
run: |
set -euxo pipefail

CONTAINER_NAME=${{ inputs.container-name }}
TAG=runtimeverificationinc/${CONTAINER_NAME}
TAG="runtimeverificationinc/${CONTAINER_NAME}"
K_VERSION=$(cat deps/k_release)
UV_VERSION=$(cat deps/uv_release)

docker build . \
--file .github/actions/with-docker/Dockerfile \
--tag ${TAG} \
--build-arg K_VERSION=${K_VERSION} \
--build-arg UV_VERSION=${UV_VERSION}
--tag "${TAG}" \
--build-arg K_VERSION="${K_VERSION}" \
--build-arg UV_VERSION="${UV_VERSION}"

docker run \
--name ${CONTAINER_NAME} \
--name "${CONTAINER_NAME}" \
--rm \
--interactive \
--tty \
--detach \
--user root \
--workdir /home/user \
${TAG}
"${TAG}"

docker cp . ${CONTAINER_NAME}:/home/user
docker exec ${CONTAINER_NAME} chown -R user:user /home/user
# `./.` copies the checkout's contents into /home/user under both Docker and
# Podman; with a bare `.`, Podman copies the directory itself to
# /home/user/<checkout-name>, leaving no project where `uv run` looks for one.
docker cp ./. "${CONTAINER_NAME}":/home/user
docker exec "${CONTAINER_NAME}" chown -R user:user /home/user
53 changes: 53 additions & 0 deletions .github/workflows/lint-workflows.yml
Original file line number Diff line number Diff line change
@@ -0,0 +1,53 @@
---
name: 'Lint Workflows'
on:
pull_request:
branches:
- 'main'
concurrency:
group: ${{ github.workflow }}-${{ github.ref }}
cancel-in-progress: true

permissions:
contents: read

jobs:
actionlint:
name: 'actionlint'
runs-on: ubuntu-latest
steps:
- name: 'Check out code'
uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
with:
persist-credentials: false
- name: 'Install actionlint'
env:
# Pin the release and verify it, both values should be updated together.
ACTIONLINT_VERSION: '1.7.12'
ACTIONLINT_SHA256: '8aca8db96f1b94770f1b0d72b6dddcb1ebb8123cb3712530b08cc387b349a3d8'
run: |
set -euxo pipefail
curl --fail --silent --show-error --location --output actionlint.tar.gz \
"https://github.com/rhysd/actionlint/releases/download/v${ACTIONLINT_VERSION}/actionlint_${ACTIONLINT_VERSION}_linux_amd64.tar.gz"
echo "${ACTIONLINT_SHA256} actionlint.tar.gz" | sha256sum --check --strict
tar --extract --gzip --file actionlint.tar.gz actionlint
- name: 'Run actionlint'
run: ./actionlint -color

zizmor:
name: 'zizmor'
runs-on: ubuntu-latest
permissions:
contents: read
security-events: write # upload SARIF, so findings annotate the diff
steps:
- name: 'Check out code'
uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
with:
persist-credentials: false
- name: 'Run zizmor'
uses: zizmorcore/zizmor-action@3dc1ecc9bcb9e94e9b2c709687979e1298497054 # v0.6.2
with:
version: '1.29.0'
online-audits: false
advanced-security: true
51 changes: 0 additions & 51 deletions .github/workflows/release.yml

This file was deleted.

68 changes: 31 additions & 37 deletions .github/workflows/test.yml
Original file line number Diff line number Diff line change
Expand Up @@ -6,77 +6,71 @@ concurrency:
group: ${{ github.workflow }}-${{ github.ref }}
cancel-in-progress: true

jobs:
# No job here writes to the repository, so the token stays read-only regardless of
# the repository default. Jobs that build the CI image additionally need
# `packages: read` to pull `ghcr.io/foundry-rs/foundry`.
permissions:
contents: read

version-bump:
name: 'Version Bump'
runs-on: [self-hosted, linux, flyweight]
steps:
- name: 'Check out code'
uses: actions/checkout@v4
with:
token: ${{ secrets.JENKINS_GITHUB_PAT }}
fetch-depth: 0
ref: ${{ github.event.pull_request.head.sha }}
- name: 'Configure GitHub user'
run: |
git config user.name devops
git config user.email devops@runtimeverification.com
- name: 'Update version'
run: |
og_version=$(git show origin/${GITHUB_BASE_REF}:package/version)
./package/version.sh bump ${og_version}
./package/version.sh sub
uv lock
new_version=$(cat package/version)
git add --update && git commit --message "Set Version: ${new_version}" || true
- name: 'Push updates'
run: git push origin HEAD:${GITHUB_HEAD_REF}
jobs:

code-quality-checks:
needs: version-bump
name: 'Code Quality Checks'
runs-on: [self-hosted, linux, normal]
permissions:
contents: read
packages: read
env:
CONTAINER: kontrol-node-code-quality-${{ github.sha }}
steps:
- name: 'Check out code'
uses: actions/checkout@v3
uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
with:
fetch-depth: 0
persist-credentials: false
- name: 'Set up Docker'
uses: ./.github/actions/with-docker
with:
container-name: ${CONTAINER}
container-name: ${{ env.CONTAINER }}
- name: 'Run code quality checks'
run: docker exec --user user ${CONTAINER} make check
run: docker exec --user user "${CONTAINER}" make check
- name: 'Run pyupgrade'
run: docker exec --user user ${CONTAINER} make pyupgrade
run: docker exec --user user "${CONTAINER}" make pyupgrade
- name: 'Run unit tests'
run: docker exec --user user ${CONTAINER} make test-unit
run: docker exec --user user "${CONTAINER}" make test-unit
- name: 'Tear down Docker'
if: always()
run: docker stop --time=0 ${CONTAINER}
run: |
# Best effort: the container does not exist if 'Set up Docker' failed, and a
# non-zero exit here would mask the step that actually failed.
docker stop --timeout=0 "${CONTAINER}" || true

tests:
needs: code-quality-checks
name: 'Tests'
runs-on: [self-hosted, linux, normal]
permissions:
contents: read
packages: read
env:
CONTAINER: kontrol-node-test-${{ github.sha }}
steps:
- name: 'Check out code'
uses: actions/checkout@v3
uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
with:
fetch-depth: 0
persist-credentials: false
- name: 'Set up Docker'
uses: ./.github/actions/with-docker
with:
container-name: ${CONTAINER}
container-name: ${{ env.CONTAINER }}
- name: 'Build kontrol-node'
run: docker exec --user user ${CONTAINER} uv run kdist -v build kontrol-node.simbolik
run: docker exec --user user "${CONTAINER}" uv run kdist -v build kontrol-node.simbolik
- name: 'Run tests'
run: docker exec --user user ${CONTAINER} make test
run: docker exec --user user "${CONTAINER}" make test
- name: 'Tear down Docker'
if: always()
run: docker stop --time=0 ${CONTAINER}
run: |
# Best effort: the container does not exist if 'Set up Docker' failed, and a
# non-zero exit here would mask the step that actually failed.
docker stop --timeout=0 "${CONTAINER}" || true
81 changes: 0 additions & 81 deletions .github/workflows/update.yml

This file was deleted.

2 changes: 2 additions & 0 deletions .gitignore
Original file line number Diff line number Diff line change
Expand Up @@ -2,3 +2,5 @@
__pycache__/
.coverage
.vscode
.kdist
io_dir*/
5 changes: 2 additions & 3 deletions .vscode/launch.json
Original file line number Diff line number Diff line change
@@ -1,15 +1,14 @@
{
"version": "0.2.0",
"configurations": [

{
"name": "Kontrol Node: debug",
"type": "debugpy",
"request": "launch",
"justMyCode": false,
"module": "kontrol_node",
"args": ["run", "--steps-tracing", "--port", "8081"],
"args": ["run", "--port", "8081"],
"cwd": "${workspaceFolder}"
}
]
}
}
Loading
Loading