Skip to content

test(tui): control inherited signal masks during delivery checks #411

test(tui): control inherited signal masks during delivery checks

test(tui): control inherited signal masks during delivery checks #411

Workflow file for this run

# Verifies every source boundary used by ManT without publishing artifacts.
name: CI
on:
push:
branches:
- main
- dev
pull_request:
workflow_dispatch:
# A pull request only needs to read the checked-out repository. Keep release
# permissions out of this workflow so untrusted changes cannot publish data.
permissions:
actions: read
contents: read
concurrency:
group: ci-${{ github.workflow }}-${{ github.ref }}
cancel-in-progress: true
env:
LIBMANDOC_RS_DENY_WARNINGS: "1"
RUST_MSRV: 1.88.0
jobs:
scope:
name: Plan CI
runs-on: ubuntu-24.04
timeout-minutes: 5
outputs:
run_full: ${{ steps.plan.outputs.run_full }}
steps:
- name: Check out repository
uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
with:
persist-credentials: false
# A fast-forward from dev to main carries the exact same tree and check
# suite. Reuse it only after the API confirms every full CI job passed
# for this SHA; direct main pushes and all other events still run fully.
- name: Decide whether this commit needs full CI
id: plan
shell: bash
run: |
run_full=true
if [[ "$GITHUB_EVENT_NAME" == push && "$GITHUB_REF" == refs/heads/main ]]; then
if ci_url=$(bash scripts/find-successful-ci.sh "$GITHUB_SHA" dev); then
run_full=false
echo "reusing complete dev CI: $ci_url"
fi
fi
echo "run_full=$run_full" >> "$GITHUB_OUTPUT"
env:
GH_TOKEN: ${{ github.token }}
supply-chain:
name: Supply chain
needs: scope
if: needs.scope.outputs.run_full == 'true'
runs-on: ubuntu-24.04
timeout-minutes: 15
steps:
- name: Check out repository
uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
with:
persist-credentials: false
- name: Audit advisories, licenses, sources, and dependency policy
uses: EmbarkStudios/cargo-deny-action@3c6349835b2b7b196a839186cb8b78e02f7b5f25 # v2.1.1
with:
rust-version: stable
command: check
arguments: --all-features
- name: Install cargo-about
uses: taiki-e/install-action@1ed6d7be6168f6c9046541087ff549b6bc581fdf # v2.87.2
with:
tool: cargo-about@0.9.2
fallback: none
- name: Verify distributable Rust dependency notices
run: |
cargo fetch --locked
scripts/generate-rust-licenses.sh --check
dependency-review:
name: Dependency review
if: github.event_name == 'pull_request'
runs-on: ubuntu-24.04
timeout-minutes: 10
steps:
- name: Check out repository
uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
with:
persist-credentials: false
- name: Review dependency changes
uses: actions/dependency-review-action@a1d282b36b6f3519aa1f3fc636f609c47dddb294 # v5.0.0
with:
fail-on-severity: moderate
build:
name: Build (Linux x64)
needs: scope
if: needs.scope.outputs.run_full == 'true'
runs-on: ubuntu-24.04
timeout-minutes: 30
steps:
- name: Check out repository
uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
with:
persist-credentials: false
- name: Install native dependencies
run: bash scripts/install-ci-native-dependencies.sh
- name: Install stable Rust toolchain
run: |
rustup toolchain install stable --profile minimal --component clippy,rustfmt
rustup default stable
# Cache only third-party build products. Workspace and incremental
# artifacts are cheap to rebuild and made the old cache exceed 1 GiB.
- name: Cache compiled Cargo dependencies
uses: Swatinem/rust-cache@6323deb102c322ba6fcbdcafc7e3dddab59af2b6 # v2.9.2
with:
shared-key: linux-x64-stable
workspaces: |
. -> target
fuzz -> target
cache-bin: false
save-if: ${{ github.event_name == 'push' }}
# The local script is the canonical verification boundary: formatting,
# workspace tests, clippy, fuzz compilation, and executable smoke tests.
# CI uses the already-warm debug profile; tagged releases independently
# build the optimized binary after proving this exact SHA passed CI.
- name: Build and test
run: bash scripts/check.sh --build-profile debug
- name: Verify vendored libmandoc matches upstream
run: bash crates/libmandoc-rs/scripts/sync-vendor --verify
macos-native:
# Guards the checked-in macOS C configuration (config/macos.h and its
# compat sources) against bit-rot. Release signing and packaging require
# certificates and are intentionally out of scope; this only compiles and
# tests the native crates on macOS/arm64, which needs no secrets.
name: Native (macOS arm64)
needs: scope
if: needs.scope.outputs.run_full == 'true'
runs-on: macos-14
timeout-minutes: 30
steps:
- name: Check out repository
uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
with:
persist-credentials: false
- name: Install stable Rust toolchain
run: |
rustup toolchain install stable --profile minimal
rustup default stable
- name: Cache compiled Cargo dependencies
uses: Swatinem/rust-cache@6323deb102c322ba6fcbdcafc7e3dddab59af2b6 # v2.9.2
with:
shared-key: macos-arm64-stable
cache-bin: false
save-if: ${{ github.event_name == 'push' }}
# Compile and test the native workspace plus libmandoc's default-off
# renderer so the macOS target family is exercised on every change, not
# only at release time. clang ships with the runner image, so libmandoc
# builds against config/macos.h.
- name: Test Rust workspace on macOS
run: |
cargo test --locked --workspace
cargo test --locked --package libmandoc-rs --all-features
windows-native:
# Windows builds the same memory-only libmandoc parser and manual fixtures
# as Unix while Rust owns source I/O, decompression, and .so redirects.
name: Native (Windows x64)
needs: scope
if: needs.scope.outputs.run_full == 'true'
runs-on: windows-2025
timeout-minutes: 30
steps:
- name: Check out repository
uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
with:
persist-credentials: false
- name: Install stable Rust toolchain
shell: pwsh
run: |
rustup toolchain install stable --profile minimal --component clippy,rustfmt
rustup default stable
- name: Cache compiled Cargo dependencies
uses: Swatinem/rust-cache@6323deb102c322ba6fcbdcafc7e3dddab59af2b6 # v2.9.2
with:
shared-key: windows-x64-stable
cache-bin: false
save-if: ${{ github.event_name == 'push' }}
- name: Build and test portable Windows product
shell: pwsh
run: ./scripts/check-windows.ps1 -BuildProfile debug
rust-msrv:
name: Rust MSRV (1.88.0)
needs: scope
if: needs.scope.outputs.run_full == 'true'
runs-on: ubuntu-24.04
timeout-minutes: 20
steps:
- name: Check out repository
uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
with:
persist-credentials: false
- name: Install native dependencies
run: bash scripts/install-ci-native-dependencies.sh
- name: Install minimum supported Rust toolchain
run: rustup toolchain install "$RUST_MSRV" --profile minimal
- name: Cache compiled Cargo dependencies for MSRV
uses: Swatinem/rust-cache@6323deb102c322ba6fcbdcafc7e3dddab59af2b6 # v2.9.2
with:
shared-key: linux-x64-msrv
cache-bin: false
save-if: ${{ github.event_name == 'push' }}
# Stable CI executes every test. The MSRV boundary only needs to prove
# that every product target and feature still compiles on Rust 1.88.
- name: Check workspace on MSRV
run: >-
cargo +"$RUST_MSRV" check --locked --workspace
--all-targets --all-features
coverage:
# Coverage runs beside the canonical build so instrumentation never slows
# or gates the primary verification path.
name: Coverage
needs: scope
if: needs.scope.outputs.run_full == 'true'
runs-on: ubuntu-24.04
timeout-minutes: 30
steps:
- name: Check out repository
uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
with:
persist-credentials: false
- name: Install native dependencies
run: bash scripts/install-ci-native-dependencies.sh
- name: Install stable Rust toolchain
run: |
rustup toolchain install stable --profile minimal --component llvm-tools-preview
rustup default stable
- name: Cache compiled Cargo dependencies for coverage
uses: Swatinem/rust-cache@6323deb102c322ba6fcbdcafc7e3dddab59af2b6 # v2.9.2
with:
shared-key: linux-x64-coverage
cache-bin: false
save-if: ${{ github.event_name == 'push' }}
- name: Install cargo-llvm-cov
uses: taiki-e/install-action@1ed6d7be6168f6c9046541087ff549b6bc581fdf # v2.87.2
with:
tool: cargo-llvm-cov
# --remap-path-prefix rewrites absolute source paths to the repository
# root, leaving every LCOV source path directly repository-relative.
- name: Collect Rust coverage
run: |
cargo llvm-cov --locked --workspace \
--remap-path-prefix --lcov --output-path rust-lcov.info
- name: Upload Rust coverage to Codecov
uses: codecov/codecov-action@fb8b3582c8e4def4969c97caa2f19720cb33a72f # v7.0.0
with:
files: rust-lcov.info
flags: rust
disable_search: true
token: ${{ secrets.CODECOV_TOKEN }}
fail_ci_if_error: false
complete:
name: CI verified
if: always()
needs:
- scope
- supply-chain
- build
- macos-native
- windows-native
- rust-msrv
- coverage
runs-on: ubuntu-24.04
timeout-minutes: 5
steps:
- name: Require a reused or newly completed full suite
shell: bash
run: |
[[ "$SCOPE_RESULT" == success ]]
if [[ "$RUN_FULL" == false ]]; then
echo "exact-SHA full CI was already completed on dev"
exit 0
fi
for result in \
"$SUPPLY_CHAIN_RESULT" \
"$BUILD_RESULT" \
"$MACOS_RESULT" \
"$WINDOWS_RESULT" \
"$MSRV_RESULT" \
"$COVERAGE_RESULT"; do
[[ "$result" == success ]]
done
env:
RUN_FULL: ${{ needs.scope.outputs.run_full }}
SCOPE_RESULT: ${{ needs.scope.result }}
SUPPLY_CHAIN_RESULT: ${{ needs.supply-chain.result }}
BUILD_RESULT: ${{ needs.build.result }}
MACOS_RESULT: ${{ needs.macos-native.result }}
WINDOWS_RESULT: ${{ needs.windows-native.result }}
MSRV_RESULT: ${{ needs.rust-msrv.result }}
COVERAGE_RESULT: ${{ needs.coverage.result }}