CI #46
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
| name: CI | |
| on: | |
| push: | |
| branches: [main] | |
| pull_request: | |
| # Weekly scheduled run: executes every job below, including the | |
| # network-dependent knowledge-drift gate (which is skipped on push/PR). | |
| schedule: | |
| - cron: "17 3 * * 1" | |
| workflow_dispatch: | |
| env: | |
| CARGO_TERM_COLOR: always | |
| permissions: | |
| contents: read | |
| jobs: | |
| fmt: | |
| runs-on: ubuntu-latest | |
| steps: | |
| - uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2 | |
| with: | |
| persist-credentials: false | |
| - uses: dtolnay/rust-toolchain@4cda84d5c5c54efe2404f9d843567869ab1699d4 # stable 2026-07-16 | |
| with: | |
| toolchain: stable | |
| components: rustfmt | |
| - run: cargo fmt --check | |
| clippy: | |
| runs-on: ubuntu-latest | |
| steps: | |
| - uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2 | |
| with: | |
| persist-credentials: false | |
| - uses: dtolnay/rust-toolchain@4cda84d5c5c54efe2404f9d843567869ab1699d4 # stable 2026-07-16 | |
| with: | |
| toolchain: stable | |
| components: clippy | |
| - uses: Swatinem/rust-cache@c19371144df3bb44fab255c43d04cbc2ab54d1c4 # v2.9.1 | |
| - run: cargo clippy --all-targets --all-features -- -D warnings | |
| test: | |
| runs-on: ubuntu-latest | |
| steps: | |
| - uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2 | |
| with: | |
| persist-credentials: false | |
| - uses: dtolnay/rust-toolchain@4cda84d5c5c54efe2404f9d843567869ab1699d4 # stable 2026-07-16 | |
| with: | |
| toolchain: stable | |
| - uses: Swatinem/rust-cache@c19371144df3bb44fab255c43d04cbc2ab54d1c4 # v2.9.1 | |
| # The labeled-corpus release gate (DESIGN 11.4) is a plain test and | |
| # also runs inside `cargo test`; surfacing it as its own step makes a | |
| # corpus regression identifiable at a glance. | |
| - name: Corpus gate | |
| run: cargo test --test corpus_gate | |
| - run: cargo test --all-features | |
| msrv: | |
| name: Rust 1.85 MSRV | |
| runs-on: ubuntu-latest | |
| steps: | |
| - uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2 | |
| with: | |
| persist-credentials: false | |
| - uses: dtolnay/rust-toolchain@4cda84d5c5c54efe2404f9d843567869ab1699d4 # stable 2026-07-16 | |
| with: | |
| toolchain: 1.85.0 | |
| - uses: Swatinem/rust-cache@c19371144df3bb44fab255c43d04cbc2ab54d1c4 # v2.9.1 | |
| - run: cargo check --locked --all-targets --all-features | |
| release-metadata: | |
| runs-on: ubuntu-latest | |
| steps: | |
| - uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2 | |
| with: | |
| persist-credentials: false | |
| - uses: dtolnay/rust-toolchain@4cda84d5c5c54efe2404f9d843567869ab1699d4 # stable 2026-07-16 | |
| with: | |
| toolchain: stable | |
| - uses: Swatinem/rust-cache@c19371144df3bb44fab255c43d04cbc2ab54d1c4 # v2.9.1 | |
| - name: Check release metadata and compliance files | |
| run: python3 scripts/check_release.py | |
| - name: Verify the crates.io source package | |
| run: cargo publish --locked --dry-run | |
| - name: Verify the LGPL corresponding-source bundle | |
| run: | | |
| python3 scripts/build_lgpl_source_bundle.py | |
| gzip -t target/release-assets/malachite-sources.tar.gz | |
| workflow-security: | |
| name: GitHub Actions security | |
| runs-on: ubuntu-latest | |
| steps: | |
| - uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2 | |
| with: | |
| persist-credentials: false | |
| - uses: astral-sh/setup-uv@37802adc94f370d6bfd71619e3f0bf239e1f3b78 # v7 | |
| - run: uvx zizmor==1.28.0 --format github .github/workflows | |
| # Layer-9 upstream drift gate (DESIGN 11.2): regenerates knowledge candidates | |
| # from the public Manim source at the profile's pinned base commit and asserts | |
| # the shipped upstream profile has no contradictions. The fork-overlay test | |
| # requires the private fast-manim checkout and remains a maintainer-local gate. | |
| # This job needs network for the clone, so it runs on schedule / manual | |
| # dispatch only, never per PR. | |
| knowledge-drift: | |
| if: github.event_name == 'schedule' || github.event_name == 'workflow_dispatch' | |
| runs-on: ubuntu-latest | |
| continue-on-error: false | |
| steps: | |
| - uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2 | |
| with: | |
| persist-credentials: false | |
| - uses: dtolnay/rust-toolchain@4cda84d5c5c54efe2404f9d843567869ab1699d4 # stable 2026-07-16 | |
| with: | |
| toolchain: stable | |
| - uses: Swatinem/rust-cache@c19371144df3bb44fab255c43d04cbc2ab54d1c4 # v2.9.1 | |
| - name: Fetch Manim at the pinned base commit | |
| # Shallow-fetch exactly the base commit the shipped profile is pinned | |
| # to (src/knowledge/profiles/README.md). The drift test reads the | |
| # checkout named by QUAL_MANIM_ROOT (tests/knowledge_drift.rs). | |
| run: | | |
| git init "${RUNNER_TEMP}/manim" | |
| git -C "${RUNNER_TEMP}/manim" remote add origin https://github.com/ManimCommunity/manim.git | |
| git -C "${RUNNER_TEMP}/manim" fetch --depth 1 origin 4d25c031ffe71c602e20935afd54a96f33545a6e | |
| git -C "${RUNNER_TEMP}/manim" checkout --detach FETCH_HEAD | |
| - name: Upstream knowledge drift gate | |
| env: | |
| QUAL_MANIM_ROOT: ${{ runner.temp }}/manim | |
| run: cargo test --test knowledge_drift -- --ignored upstream_profile_matches_clean_base_commit |