Skip to content

Add verifier process supervisor and broaden analyzer/contracts/effects coverage #954

Add verifier process supervisor and broaden analyzer/contracts/effects coverage

Add verifier process supervisor and broaden analyzer/contracts/effects coverage #954

name: Package, consumers, and release qualification
on:
push:
branches: [master]
tags:
- "v*"
pull_request:
branches: ["**"]
workflow_dispatch:
permissions:
contents: read
concurrency:
group: ${{ github.workflow }}-${{ github.event.pull_request.number || github.ref }}
cancel-in-progress: ${{ github.event_name == 'pull_request' }}
env:
SHARPPROOF_CONTAINER_CPU_LIMIT: 4
jobs:
security:
name: Exact-SHA security
if: startsWith(github.ref, 'refs/tags/v')
uses: ./.github/workflows/security-reusable.yml
permissions:
contents: read
packages: read
package:
name: Pack exact container artifacts
runs-on: ubuntu-latest
permissions:
contents: read
env:
COMPOSE_PROJECT_NAME: sharpproof-package-${{ github.run_id }}-${{ github.run_attempt }}
steps:
- uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
with:
fetch-depth: 0
- name: Build the pinned Linux amd64 toolchain
uses: ./.github/actions/build-tooling
- name: Validate release tag and checked-in version in-container
if: startsWith(github.ref, 'refs/tags/v')
run: >-
docker compose run --rm
-e GITHUB_REF -e GITHUB_REF_NAME -e GITHUB_SHA
tooling release-tag
- name: Pack, inventory, and validate the exact graph
run: >-
docker compose run --rm tooling pack
-Configuration Release
- name: Upload exact NuGet artifacts
uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1
with:
name: nuget-packages-${{ github.sha }}-${{ github.run_attempt }}
path: artifacts/container-packages/*
if-no-files-found: error
attest:
name: Attest canonical package provenance
if: >-
github.event_name == 'push' &&
(github.ref == 'refs/heads/master' || startsWith(github.ref, 'refs/tags/v')) &&
github.repository == 'alexyorke/SharpProof'
needs: package
runs-on: ubuntu-latest
permissions:
contents: read
id-token: write
attestations: write
artifact-metadata: write
steps:
- name: Download exact NuGet artifacts
uses: actions/download-artifact@3e5f45b2cfb9172054b4087a40e8e0b5a5461e7c # v8.0.1
with:
name: nuget-packages-${{ github.sha }}-${{ github.run_attempt }}
path: nupkgs
- name: Attest package and evidence provenance
uses: actions/attest@1e69f48acb82d1966a394da916b4c1698aa569d6 # v4.2.2
with:
subject-path: |
nupkgs/*.nupkg
nupkgs/*.snupkg
nupkgs/SharpProof.spdx.json
nupkgs/SharpProof.release.json
nupkgs/SHA256SUMS
- name: Attest package SBOM
uses: actions/attest@1e69f48acb82d1966a394da916b4c1698aa569d6 # v4.2.2
with:
subject-path: nupkgs/*.nupkg
sbom-path: nupkgs/SharpProof.spdx.json
container-verifier:
name: Canonical Linux analyzer and verifier consumers
needs: package
runs-on: ubuntu-latest
env:
COMPOSE_PROJECT_NAME: sharpproof-consumer-${{ github.run_id }}-${{ github.run_attempt }}
steps:
- uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
with:
fetch-depth: 0
- name: Download exact NuGet artifacts
uses: actions/download-artifact@3e5f45b2cfb9172054b4087a40e8e0b5a5461e7c # v8.0.1
with:
name: nuget-packages-${{ github.sha }}-${{ github.run_attempt }}
path: nupkgs
- name: Build the pinned toolchain
uses: ./.github/actions/build-tooling
- name: Run analyzer and real verifier consumers
run: >-
docker compose run --rm tooling package-consumers
-Configuration Release
-PackageSource nupkgs
portable-consumers:
name: Portable exact-package consumer (${{ matrix.os }})
if: >-
github.event_name == 'push' &&
startsWith(github.ref, 'refs/tags/v') &&
github.repository == 'alexyorke/SharpProof'
needs: package
strategy:
fail-fast: false
matrix:
include:
- os: ubuntu-latest
family: linux
- os: windows-latest
family: windows
- os: macos-latest
family: macos
runs-on: ${{ matrix.os }}
steps:
- uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
- uses: actions/download-artifact@3e5f45b2cfb9172054b4087a40e8e0b5a5461e7c # v8.0.1
with:
name: nuget-packages-${{ github.sha }}-${{ github.run_attempt }}
path: nupkgs
- name: Run portable-consumer against exact packages
run: >-
pwsh scripts/Test-SharpProofPortableConsumer.ps1
-PackageSource nupkgs -OsFamily ${{ matrix.family }}
- uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1
with:
name: portable-receipt-${{ matrix.family }}-${{ github.sha }}
path: artifacts/release-qualification
if-no-files-found: error
release-qualification:
name: Qualify the exact release SHA in-container
if: >-
github.event_name == 'push' &&
startsWith(github.ref, 'refs/tags/v') &&
github.repository == 'alexyorke/SharpProof'
needs:
- package
- container-verifier
- security
- attest
- portable-consumers
runs-on: ubuntu-latest
permissions:
contents: read
env:
COMPOSE_PROJECT_NAME: sharpproof-release-${{ github.run_id }}-${{ github.run_attempt }}
steps:
- uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
with:
fetch-depth: 0
- name: Download exact NuGet artifacts
uses: actions/download-artifact@3e5f45b2cfb9172054b4087a40e8e0b5a5461e7c # v8.0.1
with:
name: nuget-packages-${{ github.sha }}-${{ github.run_attempt }}
path: nupkgs
- name: Build the pinned toolchain
uses: ./.github/actions/build-tooling
- name: Require an annotated exact tag in-container
run: >-
docker compose run --rm
-e GITHUB_REF -e GITHUB_REF_NAME -e GITHUB_SHA
tooling release-tag
- name: Resolve the allowlisted release coverage baseline in-container
run: >-
docker compose run --rm
-e GITHUB_REF_NAME -e GITHUB_SHA
tooling release-baseline
- name: Export the container-resolved coverage baseline
run: cat artifacts/release-qualification/coverage.env >> "$GITHUB_ENV"
- name: Run exact-commit acceptance
run: >-
docker compose run --rm tooling acceptance
-Configuration Release
- name: Run exact-commit Debug solution gate
run: >-
docker compose run --rm tooling acceptance
-Configuration Debug
- name: Certify live release configuration
env:
GH_TOKEN: ${{ github.token }}
run: >-
pwsh ./scripts/Test-SharpProofReleaseConfiguration.ps1
-OutputPath artifacts/release-qualification/release-configuration.json
- name: Bind release-configuration receipt
run: >-
pwsh ./scripts/Write-SharpProofQualificationReceipt.ps1
-Gate release-configuration
-EvidencePath artifacts/release-qualification/release-configuration.json
- name: Download portable OS receipts
uses: actions/download-artifact@3e5f45b2cfb9172054b4087a40e8e0b5a5461e7c # v8.0.1
with:
pattern: portable-receipt-*-${{ github.sha }}
path: artifacts/release-qualification
merge-multiple: true
- name: Run exact-commit trusted mutations
run: >-
docker compose run --rm tooling mutation
-Configuration Release
- name: Enforce full release-delta coverage
run: >-
docker compose run --rm
-e SHARPPROOF_COVERAGE_COMPARISON_REF
tooling coverage -Configuration Release
- name: Revalidate downloaded packages with a real proof
run: >-
docker compose run --rm tooling package-consumers
-Configuration Release
-PackageSource nupkgs
- name: Run five exact-package pilots
run: >-
docker compose run --rm tooling pilots
-PackageSource nupkgs
- name: Produce publication dry-run evidence
run: >-
docker compose run --rm tooling release-plan
-PackageSource nupkgs
- name: Bind qualification to container inputs and package hashes
run: >-
docker compose run --rm
-e GITHUB_REF_NAME -e GITHUB_SHA
tooling release-qualification -PackageSource nupkgs
- name: Upload exact-SHA qualification evidence
uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1
if: always()
with:
name: release-qualification-${{ github.sha }}-${{ github.run_attempt }}
path: artifacts/release-qualification
if-no-files-found: error
retention-days: 90
publish-private-preview:
name: Promote preview.1 to the private feed
concurrency:
group: sharpproof-publish-${{ github.ref_name }}
cancel-in-progress: false
if: >-
github.event_name == 'push' &&
github.ref_name == 'v1.0.0-preview.1' &&
github.repository == 'alexyorke/SharpProof'
needs: release-qualification
runs-on: ubuntu-latest
environment: nuget.private-preview
permissions:
contents: read
env:
COMPOSE_PROJECT_NAME: sharpproof-private-${{ github.run_id }}-${{ github.run_attempt }}
steps:
- uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
with:
fetch-depth: 0
- uses: actions/download-artifact@3e5f45b2cfb9172054b4087a40e8e0b5a5461e7c # v8.0.1
with:
name: nuget-packages-${{ github.sha }}-${{ github.run_attempt }}
path: nupkgs
- name: Validate private-feed configuration
env:
NUGET_PRIVATE_API_KEY: ${{ secrets.NUGET_PRIVATE_API_KEY }}
NUGET_PRIVATE_SOURCE: ${{ vars.NUGET_PRIVATE_SOURCE }}
run: |
test -n "${NUGET_PRIVATE_SOURCE}"
test -n "${NUGET_PRIVATE_API_KEY}"
- name: Build the pinned toolchain
uses: ./.github/actions/build-tooling
- name: Publish already-qualified private-preview bytes in-container
env:
NUGET_API_KEY: ${{ secrets.NUGET_PRIVATE_API_KEY }}
NUGET_READ_API_KEY: ${{ secrets.NUGET_PRIVATE_API_KEY }}
NUGET_SOURCE: ${{ vars.NUGET_PRIVATE_SOURCE }}
run: >-
docker compose run --rm
-e GITHUB_REF_NAME -e NUGET_SOURCE -e NUGET_API_KEY -e NUGET_READ_API_KEY
tooling release-publish -PackageSource nupkgs
publish:
name: Promote qualified packages to public NuGet
concurrency:
group: sharpproof-publish-${{ github.ref_name }}
cancel-in-progress: false
if: >-
github.event_name == 'push' &&
(github.ref_name == 'v1.0.0-preview.2' ||
github.ref_name == 'v1.0.0-rc.1' ||
github.ref_name == 'v1.0.0') &&
github.repository == 'alexyorke/SharpProof'
needs: release-qualification
runs-on: ubuntu-latest
environment: nuget.org
permissions:
contents: read
id-token: write
env:
COMPOSE_PROJECT_NAME: sharpproof-public-${{ github.run_id }}-${{ github.run_attempt }}
steps:
- uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
with:
fetch-depth: 0
- uses: actions/download-artifact@3e5f45b2cfb9172054b4087a40e8e0b5a5461e7c # v8.0.1
with:
name: nuget-packages-${{ github.sha }}-${{ github.run_attempt }}
path: nupkgs
- name: Validate public-feed configuration
env:
NUGET_USER: ${{ vars.NUGET_USER }}
run: test -n "${NUGET_USER}"
- name: Exchange GitHub OIDC token for a temporary NuGet key
id: nuget-login
uses: NuGet/login@8d196754b4036150537f80ac539e15c2f1028841 # v1
with:
user: ${{ vars.NUGET_USER }}
- name: Build the pinned toolchain
uses: ./.github/actions/build-tooling
- name: Publish already-qualified package and symbol bytes in-container
env:
NUGET_API_KEY: ${{ steps.nuget-login.outputs.NUGET_API_KEY }}
NUGET_SOURCE: https://api.nuget.org/v3/index.json
run: >-
docker compose run --rm
-e GITHUB_REF_NAME -e NUGET_SOURCE -e NUGET_API_KEY
tooling release-publish -PackageSource nupkgs