test(tui): control inherited signal masks during delivery checks #411
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
| # Verifies every source boundary used by ManT without publishing artifacts. | |
| name: CI | |
| on: | |
| push: | |
| branches: | |
| - main | |
| - dev | |
| pull_request: | |
| workflow_dispatch: | |
| # A pull request only needs to read the checked-out repository. Keep release | |
| # permissions out of this workflow so untrusted changes cannot publish data. | |
| permissions: | |
| actions: read | |
| contents: read | |
| concurrency: | |
| group: ci-${{ github.workflow }}-${{ github.ref }} | |
| cancel-in-progress: true | |
| env: | |
| LIBMANDOC_RS_DENY_WARNINGS: "1" | |
| RUST_MSRV: 1.88.0 | |
| jobs: | |
| scope: | |
| name: Plan CI | |
| runs-on: ubuntu-24.04 | |
| timeout-minutes: 5 | |
| outputs: | |
| run_full: ${{ steps.plan.outputs.run_full }} | |
| steps: | |
| - name: Check out repository | |
| uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 | |
| with: | |
| persist-credentials: false | |
| # A fast-forward from dev to main carries the exact same tree and check | |
| # suite. Reuse it only after the API confirms every full CI job passed | |
| # for this SHA; direct main pushes and all other events still run fully. | |
| - name: Decide whether this commit needs full CI | |
| id: plan | |
| shell: bash | |
| run: | | |
| run_full=true | |
| if [[ "$GITHUB_EVENT_NAME" == push && "$GITHUB_REF" == refs/heads/main ]]; then | |
| if ci_url=$(bash scripts/find-successful-ci.sh "$GITHUB_SHA" dev); then | |
| run_full=false | |
| echo "reusing complete dev CI: $ci_url" | |
| fi | |
| fi | |
| echo "run_full=$run_full" >> "$GITHUB_OUTPUT" | |
| env: | |
| GH_TOKEN: ${{ github.token }} | |
| supply-chain: | |
| name: Supply chain | |
| needs: scope | |
| if: needs.scope.outputs.run_full == 'true' | |
| runs-on: ubuntu-24.04 | |
| timeout-minutes: 15 | |
| steps: | |
| - name: Check out repository | |
| uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 | |
| with: | |
| persist-credentials: false | |
| - name: Audit advisories, licenses, sources, and dependency policy | |
| uses: EmbarkStudios/cargo-deny-action@3c6349835b2b7b196a839186cb8b78e02f7b5f25 # v2.1.1 | |
| with: | |
| rust-version: stable | |
| command: check | |
| arguments: --all-features | |
| - name: Install cargo-about | |
| uses: taiki-e/install-action@1ed6d7be6168f6c9046541087ff549b6bc581fdf # v2.87.2 | |
| with: | |
| tool: cargo-about@0.9.2 | |
| fallback: none | |
| - name: Verify distributable Rust dependency notices | |
| run: | | |
| cargo fetch --locked | |
| scripts/generate-rust-licenses.sh --check | |
| dependency-review: | |
| name: Dependency review | |
| if: github.event_name == 'pull_request' | |
| runs-on: ubuntu-24.04 | |
| timeout-minutes: 10 | |
| steps: | |
| - name: Check out repository | |
| uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 | |
| with: | |
| persist-credentials: false | |
| - name: Review dependency changes | |
| uses: actions/dependency-review-action@a1d282b36b6f3519aa1f3fc636f609c47dddb294 # v5.0.0 | |
| with: | |
| fail-on-severity: moderate | |
| build: | |
| name: Build (Linux x64) | |
| needs: scope | |
| if: needs.scope.outputs.run_full == 'true' | |
| runs-on: ubuntu-24.04 | |
| timeout-minutes: 30 | |
| steps: | |
| - name: Check out repository | |
| uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 | |
| with: | |
| persist-credentials: false | |
| - name: Install native dependencies | |
| run: bash scripts/install-ci-native-dependencies.sh | |
| - name: Install stable Rust toolchain | |
| run: | | |
| rustup toolchain install stable --profile minimal --component clippy,rustfmt | |
| rustup default stable | |
| # Cache only third-party build products. Workspace and incremental | |
| # artifacts are cheap to rebuild and made the old cache exceed 1 GiB. | |
| - name: Cache compiled Cargo dependencies | |
| uses: Swatinem/rust-cache@6323deb102c322ba6fcbdcafc7e3dddab59af2b6 # v2.9.2 | |
| with: | |
| shared-key: linux-x64-stable | |
| workspaces: | | |
| . -> target | |
| fuzz -> target | |
| cache-bin: false | |
| save-if: ${{ github.event_name == 'push' }} | |
| # The local script is the canonical verification boundary: formatting, | |
| # workspace tests, clippy, fuzz compilation, and executable smoke tests. | |
| # CI uses the already-warm debug profile; tagged releases independently | |
| # build the optimized binary after proving this exact SHA passed CI. | |
| - name: Build and test | |
| run: bash scripts/check.sh --build-profile debug | |
| - name: Verify vendored libmandoc matches upstream | |
| run: bash crates/libmandoc-rs/scripts/sync-vendor --verify | |
| macos-native: | |
| # Guards the checked-in macOS C configuration (config/macos.h and its | |
| # compat sources) against bit-rot. Release signing and packaging require | |
| # certificates and are intentionally out of scope; this only compiles and | |
| # tests the native crates on macOS/arm64, which needs no secrets. | |
| name: Native (macOS arm64) | |
| needs: scope | |
| if: needs.scope.outputs.run_full == 'true' | |
| runs-on: macos-14 | |
| timeout-minutes: 30 | |
| steps: | |
| - name: Check out repository | |
| uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 | |
| with: | |
| persist-credentials: false | |
| - name: Install stable Rust toolchain | |
| run: | | |
| rustup toolchain install stable --profile minimal | |
| rustup default stable | |
| - name: Cache compiled Cargo dependencies | |
| uses: Swatinem/rust-cache@6323deb102c322ba6fcbdcafc7e3dddab59af2b6 # v2.9.2 | |
| with: | |
| shared-key: macos-arm64-stable | |
| cache-bin: false | |
| save-if: ${{ github.event_name == 'push' }} | |
| # Compile and test the native workspace plus libmandoc's default-off | |
| # renderer so the macOS target family is exercised on every change, not | |
| # only at release time. clang ships with the runner image, so libmandoc | |
| # builds against config/macos.h. | |
| - name: Test Rust workspace on macOS | |
| run: | | |
| cargo test --locked --workspace | |
| cargo test --locked --package libmandoc-rs --all-features | |
| windows-native: | |
| # Windows builds the same memory-only libmandoc parser and manual fixtures | |
| # as Unix while Rust owns source I/O, decompression, and .so redirects. | |
| name: Native (Windows x64) | |
| needs: scope | |
| if: needs.scope.outputs.run_full == 'true' | |
| runs-on: windows-2025 | |
| timeout-minutes: 30 | |
| steps: | |
| - name: Check out repository | |
| uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 | |
| with: | |
| persist-credentials: false | |
| - name: Install stable Rust toolchain | |
| shell: pwsh | |
| run: | | |
| rustup toolchain install stable --profile minimal --component clippy,rustfmt | |
| rustup default stable | |
| - name: Cache compiled Cargo dependencies | |
| uses: Swatinem/rust-cache@6323deb102c322ba6fcbdcafc7e3dddab59af2b6 # v2.9.2 | |
| with: | |
| shared-key: windows-x64-stable | |
| cache-bin: false | |
| save-if: ${{ github.event_name == 'push' }} | |
| - name: Build and test portable Windows product | |
| shell: pwsh | |
| run: ./scripts/check-windows.ps1 -BuildProfile debug | |
| rust-msrv: | |
| name: Rust MSRV (1.88.0) | |
| needs: scope | |
| if: needs.scope.outputs.run_full == 'true' | |
| runs-on: ubuntu-24.04 | |
| timeout-minutes: 20 | |
| steps: | |
| - name: Check out repository | |
| uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 | |
| with: | |
| persist-credentials: false | |
| - name: Install native dependencies | |
| run: bash scripts/install-ci-native-dependencies.sh | |
| - name: Install minimum supported Rust toolchain | |
| run: rustup toolchain install "$RUST_MSRV" --profile minimal | |
| - name: Cache compiled Cargo dependencies for MSRV | |
| uses: Swatinem/rust-cache@6323deb102c322ba6fcbdcafc7e3dddab59af2b6 # v2.9.2 | |
| with: | |
| shared-key: linux-x64-msrv | |
| cache-bin: false | |
| save-if: ${{ github.event_name == 'push' }} | |
| # Stable CI executes every test. The MSRV boundary only needs to prove | |
| # that every product target and feature still compiles on Rust 1.88. | |
| - name: Check workspace on MSRV | |
| run: >- | |
| cargo +"$RUST_MSRV" check --locked --workspace | |
| --all-targets --all-features | |
| coverage: | |
| # Coverage runs beside the canonical build so instrumentation never slows | |
| # or gates the primary verification path. | |
| name: Coverage | |
| needs: scope | |
| if: needs.scope.outputs.run_full == 'true' | |
| runs-on: ubuntu-24.04 | |
| timeout-minutes: 30 | |
| steps: | |
| - name: Check out repository | |
| uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 | |
| with: | |
| persist-credentials: false | |
| - name: Install native dependencies | |
| run: bash scripts/install-ci-native-dependencies.sh | |
| - name: Install stable Rust toolchain | |
| run: | | |
| rustup toolchain install stable --profile minimal --component llvm-tools-preview | |
| rustup default stable | |
| - name: Cache compiled Cargo dependencies for coverage | |
| uses: Swatinem/rust-cache@6323deb102c322ba6fcbdcafc7e3dddab59af2b6 # v2.9.2 | |
| with: | |
| shared-key: linux-x64-coverage | |
| cache-bin: false | |
| save-if: ${{ github.event_name == 'push' }} | |
| - name: Install cargo-llvm-cov | |
| uses: taiki-e/install-action@1ed6d7be6168f6c9046541087ff549b6bc581fdf # v2.87.2 | |
| with: | |
| tool: cargo-llvm-cov | |
| # --remap-path-prefix rewrites absolute source paths to the repository | |
| # root, leaving every LCOV source path directly repository-relative. | |
| - name: Collect Rust coverage | |
| run: | | |
| cargo llvm-cov --locked --workspace \ | |
| --remap-path-prefix --lcov --output-path rust-lcov.info | |
| - name: Upload Rust coverage to Codecov | |
| uses: codecov/codecov-action@fb8b3582c8e4def4969c97caa2f19720cb33a72f # v7.0.0 | |
| with: | |
| files: rust-lcov.info | |
| flags: rust | |
| disable_search: true | |
| token: ${{ secrets.CODECOV_TOKEN }} | |
| fail_ci_if_error: false | |
| complete: | |
| name: CI verified | |
| if: always() | |
| needs: | |
| - scope | |
| - supply-chain | |
| - build | |
| - macos-native | |
| - windows-native | |
| - rust-msrv | |
| - coverage | |
| runs-on: ubuntu-24.04 | |
| timeout-minutes: 5 | |
| steps: | |
| - name: Require a reused or newly completed full suite | |
| shell: bash | |
| run: | | |
| [[ "$SCOPE_RESULT" == success ]] | |
| if [[ "$RUN_FULL" == false ]]; then | |
| echo "exact-SHA full CI was already completed on dev" | |
| exit 0 | |
| fi | |
| for result in \ | |
| "$SUPPLY_CHAIN_RESULT" \ | |
| "$BUILD_RESULT" \ | |
| "$MACOS_RESULT" \ | |
| "$WINDOWS_RESULT" \ | |
| "$MSRV_RESULT" \ | |
| "$COVERAGE_RESULT"; do | |
| [[ "$result" == success ]] | |
| done | |
| env: | |
| RUN_FULL: ${{ needs.scope.outputs.run_full }} | |
| SCOPE_RESULT: ${{ needs.scope.result }} | |
| SUPPLY_CHAIN_RESULT: ${{ needs.supply-chain.result }} | |
| BUILD_RESULT: ${{ needs.build.result }} | |
| MACOS_RESULT: ${{ needs.macos-native.result }} | |
| WINDOWS_RESULT: ${{ needs.windows-native.result }} | |
| MSRV_RESULT: ${{ needs.rust-msrv.result }} | |
| COVERAGE_RESULT: ${{ needs.coverage.result }} |