pa-tui: session_ui.rs split 9/14 - the panels concern moves out of sr… #361
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
| # Continuous build pipeline for Prime Agent (Rust). | |
| # | |
| # Builds the 4-target release matrix on every push to `main` or `rust` and | |
| # uploads the tarballs as workflow artifacts (downloadable from the run page). | |
| # Does NOT create tags or releases — the org repo's release history stays | |
| # owned by the merged product's release workflow (release.yml). | |
| # No Rust toolchain needed on the consumer side: the kernel runtime sidecar | |
| # ships inside every tarball. | |
| # | |
| name: continuous | |
| on: | |
| push: | |
| branches: | |
| - main | |
| - rust | |
| permissions: {} | |
| concurrency: | |
| group: continuous-main | |
| cancel-in-progress: false | |
| env: | |
| CARGO_TERM_COLOR: always | |
| CARGO_INCREMENTAL: 0 | |
| jobs: | |
| # The dependency audit gate (RELEASE_SECURITY pragmatic baseline): the | |
| # same advisories + licenses check as `make deny` (deny.toml), on every | |
| # tree the branch channel builds binaries from. Advisories that are | |
| # triaged-unmaintained carry an `ignore` entry with the reason and a | |
| # review date (docs/installer-ci-design.md §7); the gate fails on | |
| # anything new. SEAM: pin the advisory-DB snapshot (or vendor it) when | |
| # the channel goes public. | |
| deny: | |
| runs-on: ubuntu-latest | |
| permissions: | |
| contents: read | |
| steps: | |
| - uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683 # v4.2.2 | |
| with: | |
| persist-credentials: false | |
| - name: Dependency audit (cargo-deny advisories + licenses) | |
| uses: EmbarkStudios/cargo-deny-action@3c6349835b2b7b196a839186cb8b78e02f7b5f25 # v2.1.1 | |
| with: | |
| command: check | |
| arguments: --all-features --workspace | |
| command-arguments: advisories licenses | |
| # The audit gates every build: an unaudited tree must not produce | |
| # downloadable branch-channel binaries. | |
| build-gnu: | |
| needs: deny | |
| name: build-${{ matrix.target }} | |
| runs-on: ${{ matrix.runs-on }} | |
| # GLIBC 2.35 build baseline: artifacts built on the ubuntu-24.04 runner | |
| # image required GLIBC_2.39 and did not start on Ubuntu 22.04 (verified | |
| # 2026-09-24 on a deploy box). The host runner only supplies CPU; this | |
| # container pins the build glibc. The image is multi-arch, so aarch64 | |
| # stays a native build on the arm runner. | |
| container: | |
| # Pinned by digest (review finding: the mutable tag could drift the | |
| # release baseline under promote). Pin the multi-arch index so both | |
| # matrix arches resolve from one reviewed image; update the digest | |
| # only through reviewed changes. | |
| image: ubuntu:22.04@sha256:b8b6ee6aa931ecd9d0d952abc34dc0e5f7c6a30c6bb71b079fe399fde0329c02 | |
| # Container jobs run `run:` steps with the image's /bin/sh (dash on | |
| # ubuntu:22.04), which rejects `set -o pipefail`; pin the steps to bash. | |
| defaults: | |
| run: | |
| shell: bash | |
| permissions: | |
| contents: read | |
| timeout-minutes: 90 | |
| strategy: | |
| fail-fast: false | |
| matrix: | |
| include: | |
| - target: x86_64-unknown-linux-gnu | |
| runs-on: ubuntu-24.04 | |
| - target: aarch64-unknown-linux-gnu | |
| runs-on: ubuntu-24.04-arm | |
| env: | |
| # AppleDouble resource forks must not leak into the archive; the | |
| # assembler additionally enforces plain-file payloads. | |
| COPYFILE_DISABLE: "1" | |
| steps: | |
| # The base image is minimal: the checkout/toolchain/cache actions and | |
| # the build need these (git before checkout so clones do not fall | |
| # back to the REST-API download path). | |
| - name: Install build prerequisites (Ubuntu 22.04 container) | |
| run: | | |
| set -euo pipefail | |
| apt-get update | |
| apt-get install -y --no-install-recommends \ | |
| build-essential curl ca-certificates python3 git binutils | |
| - uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683 # v4.2.2 | |
| with: | |
| persist-credentials: false | |
| - uses: dtolnay/rust-toolchain@e081816240890017053eacbb1bdf337761dc5582 # 1.95.0 action pin; toolchain pinned below | |
| with: | |
| toolchain: "1.98.1" | |
| targets: ${{ matrix.target }} | |
| - uses: Swatinem/rust-cache@6323deb102c322ba6fcbdcafc7e3dddab59af2b6 # v2 | |
| with: | |
| # The glibc235 marker scopes the cache to the Ubuntu 22.04 build | |
| # baseline: cargo fingerprints do not encode the host libc, so a | |
| # key without it could restore a target/ tree linked on the old | |
| # ubuntu-24.04 host and reuse a GLIBC_2.39 binary. First run on | |
| # the new key builds cold; the marker moves only with reviewed | |
| # baseline changes (same protocol as the image digest below). | |
| key: ${{ matrix.target }}-glibc235 | |
| - name: Build (release, locked) | |
| run: cargo build --release --locked --target ${{ matrix.target }} -j 4 | |
| - name: Split the shipped binary + split-debug decoder (Option C posture) | |
| run: | | |
| set -euo pipefail | |
| version="$(sed -n 's/^version *= *"\([^"]*\)".*/\1/p' Cargo.toml | head -1)" | |
| [[ -n "${version}" ]] || { echo "could not read the workspace version"; exit 1; } | |
| python3 scripts/release/split_debug.py \ | |
| --binary "target/${{ matrix.target }}/release/prime-agent" \ | |
| --shipped "target/${{ matrix.target }}/dist/prime-agent" \ | |
| --out "target/${{ matrix.target }}/dist" \ | |
| --version "${version}" \ | |
| --target "${{ matrix.target }}" | |
| - name: "GLIBC baseline gate: no symbols above GLIBC_2.35 (Ubuntu 22.04)" | |
| run: | | |
| set -euo pipefail | |
| bin="target/${{ matrix.target }}/dist/prime-agent" | |
| syms="$(objdump -T "${bin}" | grep -o 'GLIBC_[0-9.]*' || true)" | |
| if [ -z "${syms}" ]; then | |
| echo "::error::could not inspect ${bin} with objdump (no GLIBC symbols found) - refusing to pass the gate without evidence" | |
| exit 1 | |
| fi | |
| max_glibc="$(printf '%s\n' "${syms}" | sort -Vu | tail -1)" | |
| echo "highest GLIBC symbol required: ${max_glibc}" | |
| top="$(printf '%s\nGLIBC_2.35\n' "${max_glibc}" | sort -Vu | tail -1)" | |
| if [ "${top}" != "GLIBC_2.35" ]; then | |
| echo "::error::binary requires ${max_glibc}, above the GLIBC_2.35 (Ubuntu 22.04) release baseline" | |
| exit 1 | |
| fi | |
| - name: Generate bundled catalog assets (fixture, offline-safe) | |
| run: | | |
| set -euo pipefail | |
| python3 scripts/release/bundle_catalog.py generate --fixture \ | |
| --out "target/${{ matrix.target }}/catalog-assets" | |
| - name: Assemble tarball + checksums + manifest (commit-stamped) | |
| run: | | |
| set -euo pipefail | |
| version="$(sed -n 's/^version *= *"\([^"]*\)".*/\1/p' Cargo.toml | head -1)" | |
| [[ -n "${version}" ]] || { echo "could not read the workspace version"; exit 1; } | |
| python3 scripts/release/assemble_artifacts.py \ | |
| --repo-root . \ | |
| --version "${version}" \ | |
| --target "${{ matrix.target }}" \ | |
| --sha "${GITHUB_SHA}" \ | |
| --binary "target/${{ matrix.target }}/dist/prime-agent" \ | |
| --decoder "target/${{ matrix.target }}/dist/prime-agent-${version}-$(case "${{ matrix.target }}" in x86_64*) echo linux-x64;; aarch64*) echo linux-arm64;; esac).debug.gz" \ | |
| --catalog-assets "target/${{ matrix.target }}/catalog-assets" \ | |
| --out-dir "target/${{ matrix.target }}/dist" | |
| cat "target/${{ matrix.target }}/dist/manifest.json" | |
| - name: Upload artifacts | |
| uses: actions/upload-artifact@bbbca2ddaa5d8feaa63e36b76fdaad77386f024f # v7.0.0 | |
| with: | |
| name: artifacts-${{ matrix.target }} | |
| path: | | |
| target/${{ matrix.target }}/dist/prime-agent-* | |
| target/${{ matrix.target }}/dist/SHA256SUMS | |
| target/${{ matrix.target }}/dist/manifest.json | |
| if-no-files-found: error | |
| build-darwin: | |
| needs: deny | |
| name: build-${{ matrix.target }} | |
| runs-on: ${{ matrix.runs-on }} | |
| permissions: | |
| contents: read | |
| timeout-minutes: 90 | |
| strategy: | |
| fail-fast: false | |
| matrix: | |
| include: | |
| - target: aarch64-apple-darwin | |
| runs-on: macos-14 | |
| - target: x86_64-apple-darwin | |
| runs-on: macos-15-intel # macos-13 is retired; this is the Intel runner now | |
| env: | |
| # AppleDouble resource forks must not leak into the archive; the | |
| # assembler additionally enforces plain-file payloads. | |
| COPYFILE_DISABLE: "1" | |
| steps: | |
| - uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683 # v4.2.2 | |
| with: | |
| persist-credentials: false | |
| - uses: dtolnay/rust-toolchain@e081816240890017053eacbb1bdf337761dc5582 # 1.95.0 action pin; toolchain pinned below | |
| with: | |
| toolchain: "1.98.1" | |
| targets: ${{ matrix.target }} | |
| - uses: Swatinem/rust-cache@6323deb102c322ba6fcbdcafc7e3dddab59af2b6 # v2 | |
| with: | |
| key: ${{ matrix.target }} | |
| - name: Build (release, locked) | |
| run: cargo build --release --locked --target ${{ matrix.target }} -j 4 | |
| - name: Generate bundled catalog assets (fixture, offline-safe) | |
| run: | | |
| set -euo pipefail | |
| python3 scripts/release/bundle_catalog.py generate --fixture \ | |
| --out "target/${{ matrix.target }}/catalog-assets" | |
| - name: Assemble tarball + checksums + manifest (commit-stamped) | |
| run: | | |
| set -euo pipefail | |
| version="$(sed -n 's/^version *= *"\([^"]*\)".*/\1/p' Cargo.toml | head -1)" | |
| [[ -n "${version}" ]] || { echo "could not read the workspace version"; exit 1; } | |
| python3 scripts/release/assemble_artifacts.py \ | |
| --repo-root . \ | |
| --version "${version}" \ | |
| --target "${{ matrix.target }}" \ | |
| --sha "${GITHUB_SHA}" \ | |
| --binary "target/${{ matrix.target }}/release/prime-agent" \ | |
| --catalog-assets "target/${{ matrix.target }}/catalog-assets" \ | |
| --out-dir "target/${{ matrix.target }}/dist" | |
| cat "target/${{ matrix.target }}/dist/manifest.json" | |
| - name: Upload artifacts | |
| uses: actions/upload-artifact@bbbca2ddaa5d8feaa63e36b76fdaad77386f024f # v7.0.0 | |
| with: | |
| name: artifacts-${{ matrix.target }} | |
| path: | | |
| target/${{ matrix.target }}/dist/prime-agent-* | |
| target/${{ matrix.target }}/dist/SHA256SUMS | |
| target/${{ matrix.target }}/dist/manifest.json | |
| if-no-files-found: error |