Skip to content

Merge pull request #129 from animu-sphere/feat/v0.10.0-resolver-cache… #303

Merge pull request #129 from animu-sphere/feat/v0.10.0-resolver-cache…

Merge pull request #129 from animu-sphere/feat/v0.10.0-resolver-cache… #303

Workflow file for this run

# Generated by `ost ci generate github` from openstrata.ci.yaml.
# Regenerate after editing the matrix; do not edit the jobs by hand.
#
# Source CI: each job checks out the repo, obtains a digest-pinned runtime
# SDK artifact, and builds/tests/packages the bundle from source. On
# GitHub-hosted runners the job bootstraps a pinned, checksum-verified `ost`
# and pulls the runtime from the cell's remote (oci://) reference — an
# actions/cache restore keyed by digest is a speed optimization, never a
# correctness precondition. Self-hosted runners keep their operator-managed
# `ost` and registry (air-gapped local import stays supported).
#
# Fork-PR safety: this workflow never publishes, never promotes, and uses no
# secrets; keep it that way when editing the matrix.
name: ost source ci
on:
pull_request:
push:
branches: [main]
permissions:
contents: read
jobs:
pr:
if: github.event_name == 'pull_request'
name: ${{ matrix.name }}
runs-on: ${{ matrix.runs_on }}
env:
OST_CI_CELL: ${{ matrix.name }}
OST_CI_LANE: ${{ matrix.lane }}
OST_CI_RUNNER_PROFILE: ${{ matrix.runner_profile }}
OST_CI_RUNS_ON: ${{ join(matrix.runs_on, ',') }}
OST_CI_RUNTIME_ARTIFACT: ${{ matrix.runtime_artifact }}
OST_CI_MINIMUM_TRUST: ${{ matrix.minimum_trust }}
OST_HOME: ${{ matrix.hosted && format('{0}/.ost-ci-home', github.workspace) || '' }}
strategy:
fail-fast: false
matrix:
include:
- name: pointcloud-las-pr-windows
lane: pull_request
runtime_artifact: sha256:c3ed40122756ea118166e1619efcaec463e7d2a42f6d978fe4e20b6b774c4b03
target_trust: local
minimum_trust: local
require_evidence: all
evidence_flags: "--require-sbom --require-provenance"
platform: cy2026
profile: usd
up_to: 4
runs_on: ["windows-2022"]
hosted: true
runner_profile: windows-hosted
bundle: plugins/pointcloud-las
runtime_remote: "oci://ghcr.io/animu-sphere/openstrata-runtime-cy2026-usd@sha256:07cb84412017ece911adaed1175a6373865d863bc40124081cfc20c52de7f0d9"
host_python: ""
host_packages_apt: ""
host_packages_brew: ""
- name: pointcloud-laz-pr-windows
lane: pull_request
runtime_artifact: sha256:c3ed40122756ea118166e1619efcaec463e7d2a42f6d978fe4e20b6b774c4b03
target_trust: local
minimum_trust: local
require_evidence: all
evidence_flags: "--require-sbom --require-provenance"
platform: cy2026
profile: usd
up_to: 4
runs_on: ["windows-2022"]
hosted: true
runner_profile: windows-hosted
bundle: plugins/pointcloud-laz
runtime_remote: "oci://ghcr.io/animu-sphere/openstrata-runtime-cy2026-usd@sha256:07cb84412017ece911adaed1175a6373865d863bc40124081cfc20c52de7f0d9"
host_python: ""
host_packages_apt: ""
host_packages_brew: ""
- name: pointcloud-las-pr-macos-arm64
lane: pull_request
runtime_artifact: sha256:a9bb847ab5c7eb29d7425ff9acfb05b01c1751054d6a70628e48b06f8409a4a8
target_trust: local
minimum_trust: local
require_evidence: all
evidence_flags: "--require-sbom --require-provenance"
platform: cy2026
profile: usd
up_to: 5
runs_on: ["macos-15"]
hosted: true
runner_profile: macos-arm64-hosted
bundle: plugins/pointcloud-las
runtime_remote: "oci://ghcr.io/animu-sphere/openstrata-runtime-cy2026-usd@sha256:dc0c980b868f91fe33e6f35a67a2bc5693b89f0243141c55ecb068ab225b0f3e"
host_python: "3.13"
host_packages_apt: ""
host_packages_brew: ""
- name: pointcloud-las-pr-linux
lane: pull_request
runtime_artifact: sha256:03f7d4ef263abb50511d17237e7cbdbe1b83dee02cff8b8f901f0484c7a7898e
target_trust: local
minimum_trust: local
require_evidence: all
evidence_flags: "--require-sbom --require-provenance"
platform: cy2026
profile: usd
up_to: 5
runs_on: ["ubuntu-24.04"]
hosted: true
runner_profile: linux-hosted
bundle: plugins/pointcloud-las
runtime_remote: "oci://ghcr.io/animu-sphere/openstrata-runtime-cy2026-usd@sha256:367a32bd1985ca9b07e8f7e64f95c1ded8dba16d68f17e0bffb09cec0b9dc3f6"
host_python: "3.13"
host_packages_apt: "libx11-dev libxt-dev libxext-dev libgl1-mesa-dev"
host_packages_brew: ""
- name: pointcloud-laz-pr-macos-arm64
lane: pull_request
runtime_artifact: sha256:a9bb847ab5c7eb29d7425ff9acfb05b01c1751054d6a70628e48b06f8409a4a8
target_trust: local
minimum_trust: local
require_evidence: all
evidence_flags: "--require-sbom --require-provenance"
platform: cy2026
profile: usd
up_to: 5
runs_on: ["macos-15"]
hosted: true
runner_profile: macos-arm64-hosted
bundle: plugins/pointcloud-laz
runtime_remote: "oci://ghcr.io/animu-sphere/openstrata-runtime-cy2026-usd@sha256:dc0c980b868f91fe33e6f35a67a2bc5693b89f0243141c55ecb068ab225b0f3e"
host_python: "3.13"
host_packages_apt: ""
host_packages_brew: ""
- name: pointcloud-laz-pr-linux
lane: pull_request
runtime_artifact: sha256:03f7d4ef263abb50511d17237e7cbdbe1b83dee02cff8b8f901f0484c7a7898e
target_trust: local
minimum_trust: local
require_evidence: all
evidence_flags: "--require-sbom --require-provenance"
platform: cy2026
profile: usd
up_to: 5
runs_on: ["ubuntu-24.04"]
hosted: true
runner_profile: linux-hosted
bundle: plugins/pointcloud-laz
runtime_remote: "oci://ghcr.io/animu-sphere/openstrata-runtime-cy2026-usd@sha256:367a32bd1985ca9b07e8f7e64f95c1ded8dba16d68f17e0bffb09cec0b9dc3f6"
host_python: "3.13"
host_packages_apt: "libx11-dev libxt-dev libxext-dev libgl1-mesa-dev"
host_packages_brew: ""
- name: pointcloud-copc-pr-windows
lane: pull_request
runtime_artifact: sha256:c3ed40122756ea118166e1619efcaec463e7d2a42f6d978fe4e20b6b774c4b03
target_trust: local
minimum_trust: local
require_evidence: all
evidence_flags: "--require-sbom --require-provenance"
platform: cy2026
profile: usd
up_to: 4
runs_on: ["windows-2022"]
hosted: true
runner_profile: windows-hosted
bundle: plugins/pointcloud-copc
runtime_remote: "oci://ghcr.io/animu-sphere/openstrata-runtime-cy2026-usd@sha256:07cb84412017ece911adaed1175a6373865d863bc40124081cfc20c52de7f0d9"
host_python: ""
host_packages_apt: ""
host_packages_brew: ""
- name: pointcloud-copc-pr-macos-arm64
lane: pull_request
runtime_artifact: sha256:a9bb847ab5c7eb29d7425ff9acfb05b01c1751054d6a70628e48b06f8409a4a8
target_trust: local
minimum_trust: local
require_evidence: all
evidence_flags: "--require-sbom --require-provenance"
platform: cy2026
profile: usd
up_to: 5
runs_on: ["macos-15"]
hosted: true
runner_profile: macos-arm64-hosted
bundle: plugins/pointcloud-copc
runtime_remote: "oci://ghcr.io/animu-sphere/openstrata-runtime-cy2026-usd@sha256:dc0c980b868f91fe33e6f35a67a2bc5693b89f0243141c55ecb068ab225b0f3e"
host_python: "3.13"
host_packages_apt: ""
host_packages_brew: ""
- name: pointcloud-copc-pr-linux
lane: pull_request
runtime_artifact: sha256:03f7d4ef263abb50511d17237e7cbdbe1b83dee02cff8b8f901f0484c7a7898e
target_trust: local
minimum_trust: local
require_evidence: all
evidence_flags: "--require-sbom --require-provenance"
platform: cy2026
profile: usd
up_to: 5
runs_on: ["ubuntu-24.04"]
hosted: true
runner_profile: linux-hosted
bundle: plugins/pointcloud-copc
runtime_remote: "oci://ghcr.io/animu-sphere/openstrata-runtime-cy2026-usd@sha256:367a32bd1985ca9b07e8f7e64f95c1ded8dba16d68f17e0bffb09cec0b9dc3f6"
host_python: "3.13"
host_packages_apt: "libx11-dev libxt-dev libxext-dev libgl1-mesa-dev"
host_packages_brew: ""
- name: httpresolver-pr-windows
lane: pull_request
runtime_artifact: sha256:c3ed40122756ea118166e1619efcaec463e7d2a42f6d978fe4e20b6b774c4b03
target_trust: local
minimum_trust: local
require_evidence: all
evidence_flags: "--require-sbom --require-provenance"
platform: cy2026
profile: usd
up_to: 4
runs_on: ["windows-2022"]
hosted: true
runner_profile: windows-hosted
bundle: plugins/httpresolver
runtime_remote: "oci://ghcr.io/animu-sphere/openstrata-runtime-cy2026-usd@sha256:07cb84412017ece911adaed1175a6373865d863bc40124081cfc20c52de7f0d9"
host_python: ""
host_packages_apt: ""
host_packages_brew: ""
- name: httpresolver-pr-macos-arm64
lane: pull_request
runtime_artifact: sha256:a9bb847ab5c7eb29d7425ff9acfb05b01c1751054d6a70628e48b06f8409a4a8
target_trust: local
minimum_trust: local
require_evidence: all
evidence_flags: "--require-sbom --require-provenance"
platform: cy2026
profile: usd
up_to: 5
runs_on: ["macos-15"]
hosted: true
runner_profile: macos-arm64-hosted
bundle: plugins/httpresolver
runtime_remote: "oci://ghcr.io/animu-sphere/openstrata-runtime-cy2026-usd@sha256:dc0c980b868f91fe33e6f35a67a2bc5693b89f0243141c55ecb068ab225b0f3e"
host_python: "3.13"
host_packages_apt: ""
host_packages_brew: ""
- name: httpresolver-pr-linux
lane: pull_request
runtime_artifact: sha256:03f7d4ef263abb50511d17237e7cbdbe1b83dee02cff8b8f901f0484c7a7898e
target_trust: local
minimum_trust: local
require_evidence: all
evidence_flags: "--require-sbom --require-provenance"
platform: cy2026
profile: usd
up_to: 5
runs_on: ["ubuntu-24.04"]
hosted: true
runner_profile: linux-hosted
bundle: plugins/httpresolver
runtime_remote: "oci://ghcr.io/animu-sphere/openstrata-runtime-cy2026-usd@sha256:367a32bd1985ca9b07e8f7e64f95c1ded8dba16d68f17e0bffb09cec0b9dc3f6"
host_python: "3.13"
host_packages_apt: "libx11-dev libxt-dev libxext-dev libgl1-mesa-dev"
host_packages_brew: ""
- name: pointcloud-ply-pr-windows
lane: pull_request
runtime_artifact: sha256:c3ed40122756ea118166e1619efcaec463e7d2a42f6d978fe4e20b6b774c4b03
target_trust: local
minimum_trust: local
require_evidence: all
evidence_flags: "--require-sbom --require-provenance"
platform: cy2026
profile: usd
up_to: 4
runs_on: ["windows-2022"]
hosted: true
runner_profile: windows-hosted
bundle: plugins/pointcloud-ply
runtime_remote: "oci://ghcr.io/animu-sphere/openstrata-runtime-cy2026-usd@sha256:07cb84412017ece911adaed1175a6373865d863bc40124081cfc20c52de7f0d9"
host_python: ""
host_packages_apt: ""
host_packages_brew: ""
- name: pointcloud-ply-pr-macos-arm64
lane: pull_request
runtime_artifact: sha256:a9bb847ab5c7eb29d7425ff9acfb05b01c1751054d6a70628e48b06f8409a4a8
target_trust: local
minimum_trust: local
require_evidence: all
evidence_flags: "--require-sbom --require-provenance"
platform: cy2026
profile: usd
up_to: 5
runs_on: ["macos-15"]
hosted: true
runner_profile: macos-arm64-hosted
bundle: plugins/pointcloud-ply
runtime_remote: "oci://ghcr.io/animu-sphere/openstrata-runtime-cy2026-usd@sha256:dc0c980b868f91fe33e6f35a67a2bc5693b89f0243141c55ecb068ab225b0f3e"
host_python: "3.13"
host_packages_apt: ""
host_packages_brew: ""
- name: pointcloud-ply-pr-linux
lane: pull_request
runtime_artifact: sha256:03f7d4ef263abb50511d17237e7cbdbe1b83dee02cff8b8f901f0484c7a7898e
target_trust: local
minimum_trust: local
require_evidence: all
evidence_flags: "--require-sbom --require-provenance"
platform: cy2026
profile: usd
up_to: 5
runs_on: ["ubuntu-24.04"]
hosted: true
runner_profile: linux-hosted
bundle: plugins/pointcloud-ply
runtime_remote: "oci://ghcr.io/animu-sphere/openstrata-runtime-cy2026-usd@sha256:367a32bd1985ca9b07e8f7e64f95c1ded8dba16d68f17e0bffb09cec0b9dc3f6"
host_python: "3.13"
host_packages_apt: "libx11-dev libxt-dev libxext-dev libgl1-mesa-dev"
host_packages_brew: ""
steps:
- name: Check out the repository
uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 # v7.0.0
- name: Hosted runner billing notice
if: ${{ matrix.hosted }}
shell: bash
run: echo "::notice title=OpenStrata hosted-runner usage::This job uses GitHub-hosted infrastructure. Private repositories may incur GitHub Actions usage charges. Review repository billing and Actions usage settings."
- name: Bootstrap ost 0.22.2 (pinned release asset, checksum-verified)
if: ${{ matrix.hosted }}
shell: bash
run: |
set -euo pipefail
mkdir -p .ost-ci
case "${RUNNER_OS}-${RUNNER_ARCH}" in
Linux-X64) triple=x86_64-unknown-linux-musl ; ext=tar.xz ;;
macOS-ARM64) triple=aarch64-apple-darwin ; ext=tar.xz ;;
macOS-X64) triple=x86_64-apple-darwin ; ext=tar.xz ;;
Windows-X64) triple=x86_64-pc-windows-msvc ; ext=zip ;;
*) echo "::error title=ost bootstrap::no ost release asset for ${RUNNER_OS}-${RUNNER_ARCH}" ; exit 1 ;;
esac
pinned=""
case "$triple" in
*) : ;;
esac
asset="ost-cli-${triple}.${ext}"
base="https://github.com/animu-sphere/open-strata/releases/download/v0.22.2"
curl -fsSLo "$asset" "$base/$asset"
curl -fsSLo "$asset.sha256" "$base/$asset.sha256"
actual="$( (command -v sha256sum > /dev/null && sha256sum "$asset" || shasum -a 256 "$asset") | cut -d' ' -f1 )"
published="$(cut -d' ' -f1 "$asset.sha256")"
if [ "$actual" != "$published" ]; then
echo "::error title=ost bootstrap::$asset hashes to $actual but the release publishes $published" ; exit 1
fi
if [ -n "$pinned" ] && [ "$actual" != "$pinned" ]; then
echo "::error title=ost bootstrap::$asset hashes to $actual but the CI contract pins $pinned" ; exit 1
fi
mkdir -p .ost-ci/bootstrap-bin
if [ "$ext" = "zip" ]; then
powershell -NoProfile -Command "Expand-Archive -LiteralPath '$asset' -DestinationPath '.ost-ci/bootstrap-bin' -Force"
else
tar -xf "$asset" -C .ost-ci/bootstrap-bin
fi
bin="$(find .ost-ci/bootstrap-bin -type f \( -name ost -o -name ost.exe \) | head -n 1)"
if [ -z "$bin" ]; then echo "::error title=ost bootstrap::no ost binary inside $asset" ; exit 1 ; fi
chmod +x "$bin" 2> /dev/null || true
bin_dir="$(cd "$(dirname "$bin")" && pwd)"
bin="$bin_dir/$(basename "$bin")"
executable="$bin"
exported_path="$bin_dir"
if [ "$RUNNER_OS" = "Windows" ]; then
if ! command -v cygpath > /dev/null; then
echo "::error title=ost bootstrap::cygpath is required to export a native Windows PATH" ; exit 1
fi
executable="$(cygpath -w "$bin")"
exported_path="$(cygpath -w "$bin_dir")"
fi
echo "$exported_path" >> "$GITHUB_PATH"
json_executable="$(printf '%s' "$executable" | sed 's/\\/\\\\/g; s/"/\\"/g')"
json_exported_path="$(printf '%s' "$exported_path" | sed 's/\\/\\\\/g; s/"/\\"/g')"
printf '{"schema":1,"pinned_version":"%s","asset":"%s","sha256":"%s","executable":"%s","exported_path":"%s"}\n' "0.22.2" "$asset" "$actual" "$json_executable" "$json_exported_path" > .ost-ci/bootstrap.json
- name: Check ost is available and record its version
shell: bash
run: |
set -euo pipefail
mkdir -p .ost-ci
if [ "${{ matrix.hosted }}" = "true" ] && [ "$RUNNER_OS" = "Windows" ]; then
version="$(powershell -NoProfile -Command "& ost.exe --version" | tr -d '\r')"
else
version="$(ost --version)"
fi
echo "$version"
if [ "${{ matrix.hosted }}" = "true" ] && [ "$version" != "ost 0.22.2" ]; then
echo "::error title=ost bootstrap::expected 'ost 0.22.2', got '$version'" ; exit 1
fi
printf '{"schema":1,"ost_version":"%s"}\n' "$version" > .ost-ci/ost-version.json
- name: Validate the CI manifest
shell: bash
run: ost ci validate
- name: Restore the artifact registry cache (speed only, never correctness)
id: runtime-cache-restore
if: ${{ matrix.hosted && vars.OST_CI_DISABLE_CACHE != 'true' }}
uses: actions/cache/restore@55cc8345863c7cc4c66a329aec7e433d2d1c52a9 # v6.1.0
with:
path: .ost-ci-home/artifacts
key: ost-registry-0.22.2-${{ runner.os }}-${{ runner.arch }}-${{ matrix.name }}-${{ matrix.runtime_artifact }}
- name: Pull the pinned runtime SDK from its remote reference
if: ${{ matrix.runtime_remote != '' }}
shell: bash
run: |
set -euo pipefail
mkdir -p .ost-ci
if ost artifact show "${{ matrix.runtime_artifact }}" --json > /dev/null 2>&1 \
&& ost artifact verify "${{ matrix.runtime_artifact }}" ${{ matrix.evidence_flags }} --json > .ost-ci/runtime-cache-verify.json; then
echo "pinned runtime already present and verified (cache hit) -- skipping the remote pull"
else
if [ "${{ matrix.hosted }}" = "true" ] && [ -n "${OST_HOME:-}" ]; then
rm -rf "${OST_HOME}/artifacts"
fi
ost artifact pull "${{ matrix.runtime_remote }}" --expect-artifact "${{ matrix.runtime_artifact }}" --require-kind runtime --json | tee .ost-ci/runtime-pull.json
fi
- name: Verify and materialize the pinned runtime SDK
shell: bash
run: |
set -euo pipefail
mkdir -p .ost-ci
printf '{"schema":1,"runtime_artifact":"%s","source":"%s"}\n' "${{ matrix.runtime_artifact }}" "${{ matrix.runtime_remote != '' && 'remote-pull' || 'local-registry' }}" > .ost-ci/runtime-source.json
ost artifact verify ${{ matrix.runtime_artifact }} --minimum-trust ${{ matrix.minimum_trust }} ${{ matrix.evidence_flags }}
ost runtime pull ${{ matrix.platform }} --profile ${{ matrix.profile }} --from-artifact ${{ matrix.runtime_artifact }} --force
- name: Remove resumable transfer state before caching
if: ${{ matrix.hosted && vars.OST_CI_DISABLE_CACHE != 'true' && steps.runtime-cache-restore.outputs.cache-hit != 'true' }}
shell: bash
run: rm -rf .ost-ci-home/artifacts/.partial-blobs
- name: Save the verified artifact registry cache
if: ${{ matrix.hosted && vars.OST_CI_DISABLE_CACHE != 'true' && steps.runtime-cache-restore.outputs.cache-hit != 'true' }}
uses: actions/cache/save@55cc8345863c7cc4c66a329aec7e433d2d1c52a9 # v6.1.0
with:
path: .ost-ci-home/artifacts
key: ost-registry-0.22.2-${{ runner.os }}-${{ runner.arch }}-${{ matrix.name }}-${{ matrix.runtime_artifact }}
- name: Install the host packages this runtime needs to be consumed
if: ${{ matrix.host_packages_apt != '' || matrix.host_packages_brew != '' }}
shell: bash
env:
HOST_PACKAGES_APT: ${{ matrix.host_packages_apt }}
HOST_PACKAGES_BREW: ${{ matrix.host_packages_brew }}
run: |
set -euo pipefail
case "$RUNNER_OS" in
Linux)
packages="$HOST_PACKAGES_APT"
if [ -z "$packages" ]; then
echo "error: this cell declares host_packages but nothing under 'apt'; a Linux runner installs from the 'apt' list" >&2
exit 1
fi
sudo apt-get update
sudo apt-get install -y --no-install-recommends $packages
;;
macOS)
packages="$HOST_PACKAGES_BREW"
if [ -z "$packages" ]; then
echo "error: this cell declares host_packages but nothing under 'brew'; a macOS runner installs from the 'brew' list" >&2
exit 1
fi
brew install $packages
;;
*)
echo "error: host_packages has no installer for $RUNNER_OS; provision the dependency on the runner image instead" >&2
exit 1
;;
esac
- name: Validate the materialized runtime (runnable tools)
shell: bash
run: |
set -euo pipefail
mkdir -p .ost-ci
ost runtime validate ${{ matrix.platform }} --profile ${{ matrix.profile }} --json | tee .ost-ci/runtime-validate.json
- name: Set up host Python for schema tooling
if: ${{ matrix.hosted && matrix.host_python != '' }}
uses: actions/setup-python@ece7cb06caefa5fff74198d8649806c4678c61a1 # v6.3.0
with:
python-version: ${{ matrix.host_python }}
- name: Record the schema-tooling Python contract
shell: bash
run: |
set -euo pipefail
mkdir -p .ost-ci
if [ "${{ matrix.hosted }}" = "true" ] && [ -n "${{ matrix.host_python }}" ]; then
source=host-setup-python
elif [ -n "${{ matrix.host_python }}" ]; then
source=operator-provisioned
else
source=runtime-bundled
fi
printf '{"schema":1,"host_python":"%s","source":"%s"}\n' "${{ matrix.host_python }}" "$source" > .ost-ci/python-setup.json
- name: Build the plugin from source
shell: bash
run: ost plugin build ${{ matrix.bundle }} --target ${{ matrix.platform }} --profile ${{ matrix.profile }}
- name: Run the verification pyramid
shell: bash
run: ost plugin test ${{ matrix.bundle }} --target ${{ matrix.platform }} --profile ${{ matrix.profile }} --up-to ${{ matrix.up_to }} --json
- name: Package the plugin (never published from this workflow)
shell: bash
run: ost plugin package ${{ matrix.bundle }} --target ${{ matrix.platform }} --profile ${{ matrix.profile }}
- name: Upload the verification report and CI evidence
if: always()
uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7
with:
name: report-${{ matrix.name }}
path: |
${{ matrix.bundle }}/.strata/reports/
.ost-ci/
mainline:
if: github.event_name == 'push'
name: ${{ matrix.name }}
runs-on: ${{ matrix.runs_on }}
env:
OST_CI_CELL: ${{ matrix.name }}
OST_CI_LANE: ${{ matrix.lane }}
OST_CI_RUNNER_PROFILE: ${{ matrix.runner_profile }}
OST_CI_RUNS_ON: ${{ join(matrix.runs_on, ',') }}
OST_CI_RUNTIME_ARTIFACT: ${{ matrix.runtime_artifact }}
OST_CI_MINIMUM_TRUST: ${{ matrix.minimum_trust }}
OST_HOME: ${{ matrix.hosted && format('{0}/.ost-ci-home', github.workspace) || '' }}
strategy:
fail-fast: false
matrix:
include:
- name: pointcloud-las-main-windows
lane: main
runtime_artifact: sha256:c3ed40122756ea118166e1619efcaec463e7d2a42f6d978fe4e20b6b774c4b03
target_trust: local
minimum_trust: local
require_evidence: all
evidence_flags: "--require-sbom --require-provenance"
platform: cy2026
profile: usd
up_to: 4
runs_on: ["windows-2022"]
hosted: true
runner_profile: windows-hosted
bundle: plugins/pointcloud-las
runtime_remote: "oci://ghcr.io/animu-sphere/openstrata-runtime-cy2026-usd@sha256:07cb84412017ece911adaed1175a6373865d863bc40124081cfc20c52de7f0d9"
host_python: ""
host_packages_apt: ""
host_packages_brew: ""
- name: pointcloud-laz-main-windows
lane: main
runtime_artifact: sha256:c3ed40122756ea118166e1619efcaec463e7d2a42f6d978fe4e20b6b774c4b03
target_trust: local
minimum_trust: local
require_evidence: all
evidence_flags: "--require-sbom --require-provenance"
platform: cy2026
profile: usd
up_to: 4
runs_on: ["windows-2022"]
hosted: true
runner_profile: windows-hosted
bundle: plugins/pointcloud-laz
runtime_remote: "oci://ghcr.io/animu-sphere/openstrata-runtime-cy2026-usd@sha256:07cb84412017ece911adaed1175a6373865d863bc40124081cfc20c52de7f0d9"
host_python: ""
host_packages_apt: ""
host_packages_brew: ""
- name: pointcloud-las-main-macos-arm64
lane: main
runtime_artifact: sha256:a9bb847ab5c7eb29d7425ff9acfb05b01c1751054d6a70628e48b06f8409a4a8
target_trust: local
minimum_trust: local
require_evidence: all
evidence_flags: "--require-sbom --require-provenance"
platform: cy2026
profile: usd
up_to: 5
runs_on: ["macos-15"]
hosted: true
runner_profile: macos-arm64-hosted
bundle: plugins/pointcloud-las
runtime_remote: "oci://ghcr.io/animu-sphere/openstrata-runtime-cy2026-usd@sha256:dc0c980b868f91fe33e6f35a67a2bc5693b89f0243141c55ecb068ab225b0f3e"
host_python: "3.13"
host_packages_apt: ""
host_packages_brew: ""
- name: pointcloud-laz-main-macos-arm64
lane: main
runtime_artifact: sha256:a9bb847ab5c7eb29d7425ff9acfb05b01c1751054d6a70628e48b06f8409a4a8
target_trust: local
minimum_trust: local
require_evidence: all
evidence_flags: "--require-sbom --require-provenance"
platform: cy2026
profile: usd
up_to: 5
runs_on: ["macos-15"]
hosted: true
runner_profile: macos-arm64-hosted
bundle: plugins/pointcloud-laz
runtime_remote: "oci://ghcr.io/animu-sphere/openstrata-runtime-cy2026-usd@sha256:dc0c980b868f91fe33e6f35a67a2bc5693b89f0243141c55ecb068ab225b0f3e"
host_python: "3.13"
host_packages_apt: ""
host_packages_brew: ""
- name: pointcloud-las-main-linux
lane: main
runtime_artifact: sha256:03f7d4ef263abb50511d17237e7cbdbe1b83dee02cff8b8f901f0484c7a7898e
target_trust: local
minimum_trust: local
require_evidence: all
evidence_flags: "--require-sbom --require-provenance"
platform: cy2026
profile: usd
up_to: 5
runs_on: ["ubuntu-24.04"]
hosted: true
runner_profile: linux-hosted
bundle: plugins/pointcloud-las
runtime_remote: "oci://ghcr.io/animu-sphere/openstrata-runtime-cy2026-usd@sha256:367a32bd1985ca9b07e8f7e64f95c1ded8dba16d68f17e0bffb09cec0b9dc3f6"
host_python: "3.13"
host_packages_apt: "libx11-dev libxt-dev libxext-dev libgl1-mesa-dev"
host_packages_brew: ""
- name: pointcloud-laz-main-linux
lane: main
runtime_artifact: sha256:03f7d4ef263abb50511d17237e7cbdbe1b83dee02cff8b8f901f0484c7a7898e
target_trust: local
minimum_trust: local
require_evidence: all
evidence_flags: "--require-sbom --require-provenance"
platform: cy2026
profile: usd
up_to: 5
runs_on: ["ubuntu-24.04"]
hosted: true
runner_profile: linux-hosted
bundle: plugins/pointcloud-laz
runtime_remote: "oci://ghcr.io/animu-sphere/openstrata-runtime-cy2026-usd@sha256:367a32bd1985ca9b07e8f7e64f95c1ded8dba16d68f17e0bffb09cec0b9dc3f6"
host_python: "3.13"
host_packages_apt: "libx11-dev libxt-dev libxext-dev libgl1-mesa-dev"
host_packages_brew: ""
- name: pointcloud-copc-main-windows
lane: main
runtime_artifact: sha256:c3ed40122756ea118166e1619efcaec463e7d2a42f6d978fe4e20b6b774c4b03
target_trust: local
minimum_trust: local
require_evidence: all
evidence_flags: "--require-sbom --require-provenance"
platform: cy2026
profile: usd
up_to: 4
runs_on: ["windows-2022"]
hosted: true
runner_profile: windows-hosted
bundle: plugins/pointcloud-copc
runtime_remote: "oci://ghcr.io/animu-sphere/openstrata-runtime-cy2026-usd@sha256:07cb84412017ece911adaed1175a6373865d863bc40124081cfc20c52de7f0d9"
host_python: ""
host_packages_apt: ""
host_packages_brew: ""
- name: pointcloud-copc-main-macos-arm64
lane: main
runtime_artifact: sha256:a9bb847ab5c7eb29d7425ff9acfb05b01c1751054d6a70628e48b06f8409a4a8
target_trust: local
minimum_trust: local
require_evidence: all
evidence_flags: "--require-sbom --require-provenance"
platform: cy2026
profile: usd
up_to: 5
runs_on: ["macos-15"]
hosted: true
runner_profile: macos-arm64-hosted
bundle: plugins/pointcloud-copc
runtime_remote: "oci://ghcr.io/animu-sphere/openstrata-runtime-cy2026-usd@sha256:dc0c980b868f91fe33e6f35a67a2bc5693b89f0243141c55ecb068ab225b0f3e"
host_python: "3.13"
host_packages_apt: ""
host_packages_brew: ""
- name: pointcloud-copc-main-linux
lane: main
runtime_artifact: sha256:03f7d4ef263abb50511d17237e7cbdbe1b83dee02cff8b8f901f0484c7a7898e
target_trust: local
minimum_trust: local
require_evidence: all
evidence_flags: "--require-sbom --require-provenance"
platform: cy2026
profile: usd
up_to: 5
runs_on: ["ubuntu-24.04"]
hosted: true
runner_profile: linux-hosted
bundle: plugins/pointcloud-copc
runtime_remote: "oci://ghcr.io/animu-sphere/openstrata-runtime-cy2026-usd@sha256:367a32bd1985ca9b07e8f7e64f95c1ded8dba16d68f17e0bffb09cec0b9dc3f6"
host_python: "3.13"
host_packages_apt: "libx11-dev libxt-dev libxext-dev libgl1-mesa-dev"
host_packages_brew: ""
- name: pointcloud-ply-main-windows
lane: main
runtime_artifact: sha256:c3ed40122756ea118166e1619efcaec463e7d2a42f6d978fe4e20b6b774c4b03
target_trust: local
minimum_trust: local
require_evidence: all
evidence_flags: "--require-sbom --require-provenance"
platform: cy2026
profile: usd
up_to: 4
runs_on: ["windows-2022"]
hosted: true
runner_profile: windows-hosted
bundle: plugins/pointcloud-ply
runtime_remote: "oci://ghcr.io/animu-sphere/openstrata-runtime-cy2026-usd@sha256:07cb84412017ece911adaed1175a6373865d863bc40124081cfc20c52de7f0d9"
host_python: ""
host_packages_apt: ""
host_packages_brew: ""
- name: pointcloud-ply-main-macos-arm64
lane: main
runtime_artifact: sha256:a9bb847ab5c7eb29d7425ff9acfb05b01c1751054d6a70628e48b06f8409a4a8
target_trust: local
minimum_trust: local
require_evidence: all
evidence_flags: "--require-sbom --require-provenance"
platform: cy2026
profile: usd
up_to: 5
runs_on: ["macos-15"]
hosted: true
runner_profile: macos-arm64-hosted
bundle: plugins/pointcloud-ply
runtime_remote: "oci://ghcr.io/animu-sphere/openstrata-runtime-cy2026-usd@sha256:dc0c980b868f91fe33e6f35a67a2bc5693b89f0243141c55ecb068ab225b0f3e"
host_python: "3.13"
host_packages_apt: ""
host_packages_brew: ""
- name: pointcloud-ply-main-linux
lane: main
runtime_artifact: sha256:03f7d4ef263abb50511d17237e7cbdbe1b83dee02cff8b8f901f0484c7a7898e
target_trust: local
minimum_trust: local
require_evidence: all
evidence_flags: "--require-sbom --require-provenance"
platform: cy2026
profile: usd
up_to: 5
runs_on: ["ubuntu-24.04"]
hosted: true
runner_profile: linux-hosted
bundle: plugins/pointcloud-ply
runtime_remote: "oci://ghcr.io/animu-sphere/openstrata-runtime-cy2026-usd@sha256:367a32bd1985ca9b07e8f7e64f95c1ded8dba16d68f17e0bffb09cec0b9dc3f6"
host_python: "3.13"
host_packages_apt: "libx11-dev libxt-dev libxext-dev libgl1-mesa-dev"
host_packages_brew: ""
steps:
- name: Check out the repository
uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 # v7.0.0
- name: Hosted runner billing notice
if: ${{ matrix.hosted }}
shell: bash
run: echo "::notice title=OpenStrata hosted-runner usage::This job uses GitHub-hosted infrastructure. Private repositories may incur GitHub Actions usage charges. Review repository billing and Actions usage settings."
- name: Bootstrap ost 0.22.2 (pinned release asset, checksum-verified)
if: ${{ matrix.hosted }}
shell: bash
run: |
set -euo pipefail
mkdir -p .ost-ci
case "${RUNNER_OS}-${RUNNER_ARCH}" in
Linux-X64) triple=x86_64-unknown-linux-musl ; ext=tar.xz ;;
macOS-ARM64) triple=aarch64-apple-darwin ; ext=tar.xz ;;
macOS-X64) triple=x86_64-apple-darwin ; ext=tar.xz ;;
Windows-X64) triple=x86_64-pc-windows-msvc ; ext=zip ;;
*) echo "::error title=ost bootstrap::no ost release asset for ${RUNNER_OS}-${RUNNER_ARCH}" ; exit 1 ;;
esac
pinned=""
case "$triple" in
*) : ;;
esac
asset="ost-cli-${triple}.${ext}"
base="https://github.com/animu-sphere/open-strata/releases/download/v0.22.2"
curl -fsSLo "$asset" "$base/$asset"
curl -fsSLo "$asset.sha256" "$base/$asset.sha256"
actual="$( (command -v sha256sum > /dev/null && sha256sum "$asset" || shasum -a 256 "$asset") | cut -d' ' -f1 )"
published="$(cut -d' ' -f1 "$asset.sha256")"
if [ "$actual" != "$published" ]; then
echo "::error title=ost bootstrap::$asset hashes to $actual but the release publishes $published" ; exit 1
fi
if [ -n "$pinned" ] && [ "$actual" != "$pinned" ]; then
echo "::error title=ost bootstrap::$asset hashes to $actual but the CI contract pins $pinned" ; exit 1
fi
mkdir -p .ost-ci/bootstrap-bin
if [ "$ext" = "zip" ]; then
powershell -NoProfile -Command "Expand-Archive -LiteralPath '$asset' -DestinationPath '.ost-ci/bootstrap-bin' -Force"
else
tar -xf "$asset" -C .ost-ci/bootstrap-bin
fi
bin="$(find .ost-ci/bootstrap-bin -type f \( -name ost -o -name ost.exe \) | head -n 1)"
if [ -z "$bin" ]; then echo "::error title=ost bootstrap::no ost binary inside $asset" ; exit 1 ; fi
chmod +x "$bin" 2> /dev/null || true
bin_dir="$(cd "$(dirname "$bin")" && pwd)"
bin="$bin_dir/$(basename "$bin")"
executable="$bin"
exported_path="$bin_dir"
if [ "$RUNNER_OS" = "Windows" ]; then
if ! command -v cygpath > /dev/null; then
echo "::error title=ost bootstrap::cygpath is required to export a native Windows PATH" ; exit 1
fi
executable="$(cygpath -w "$bin")"
exported_path="$(cygpath -w "$bin_dir")"
fi
echo "$exported_path" >> "$GITHUB_PATH"
json_executable="$(printf '%s' "$executable" | sed 's/\\/\\\\/g; s/"/\\"/g')"
json_exported_path="$(printf '%s' "$exported_path" | sed 's/\\/\\\\/g; s/"/\\"/g')"
printf '{"schema":1,"pinned_version":"%s","asset":"%s","sha256":"%s","executable":"%s","exported_path":"%s"}\n' "0.22.2" "$asset" "$actual" "$json_executable" "$json_exported_path" > .ost-ci/bootstrap.json
- name: Check ost is available and record its version
shell: bash
run: |
set -euo pipefail
mkdir -p .ost-ci
if [ "${{ matrix.hosted }}" = "true" ] && [ "$RUNNER_OS" = "Windows" ]; then
version="$(powershell -NoProfile -Command "& ost.exe --version" | tr -d '\r')"
else
version="$(ost --version)"
fi
echo "$version"
if [ "${{ matrix.hosted }}" = "true" ] && [ "$version" != "ost 0.22.2" ]; then
echo "::error title=ost bootstrap::expected 'ost 0.22.2', got '$version'" ; exit 1
fi
printf '{"schema":1,"ost_version":"%s"}\n' "$version" > .ost-ci/ost-version.json
- name: Validate the CI manifest
shell: bash
run: ost ci validate
- name: Restore the artifact registry cache (speed only, never correctness)
id: runtime-cache-restore
if: ${{ matrix.hosted && vars.OST_CI_DISABLE_CACHE != 'true' }}
uses: actions/cache/restore@55cc8345863c7cc4c66a329aec7e433d2d1c52a9 # v6.1.0
with:
path: .ost-ci-home/artifacts
key: ost-registry-0.22.2-${{ runner.os }}-${{ runner.arch }}-${{ matrix.name }}-${{ matrix.runtime_artifact }}
- name: Pull the pinned runtime SDK from its remote reference
if: ${{ matrix.runtime_remote != '' }}
shell: bash
run: |
set -euo pipefail
mkdir -p .ost-ci
if ost artifact show "${{ matrix.runtime_artifact }}" --json > /dev/null 2>&1 \
&& ost artifact verify "${{ matrix.runtime_artifact }}" ${{ matrix.evidence_flags }} --json > .ost-ci/runtime-cache-verify.json; then
echo "pinned runtime already present and verified (cache hit) -- skipping the remote pull"
else
if [ "${{ matrix.hosted }}" = "true" ] && [ -n "${OST_HOME:-}" ]; then
rm -rf "${OST_HOME}/artifacts"
fi
ost artifact pull "${{ matrix.runtime_remote }}" --expect-artifact "${{ matrix.runtime_artifact }}" --require-kind runtime --json | tee .ost-ci/runtime-pull.json
fi
- name: Verify and materialize the pinned runtime SDK
shell: bash
run: |
set -euo pipefail
mkdir -p .ost-ci
printf '{"schema":1,"runtime_artifact":"%s","source":"%s"}\n' "${{ matrix.runtime_artifact }}" "${{ matrix.runtime_remote != '' && 'remote-pull' || 'local-registry' }}" > .ost-ci/runtime-source.json
ost artifact verify ${{ matrix.runtime_artifact }} --minimum-trust ${{ matrix.minimum_trust }} ${{ matrix.evidence_flags }}
ost runtime pull ${{ matrix.platform }} --profile ${{ matrix.profile }} --from-artifact ${{ matrix.runtime_artifact }} --force
- name: Remove resumable transfer state before caching
if: ${{ matrix.hosted && vars.OST_CI_DISABLE_CACHE != 'true' && steps.runtime-cache-restore.outputs.cache-hit != 'true' }}
shell: bash
run: rm -rf .ost-ci-home/artifacts/.partial-blobs
- name: Save the verified artifact registry cache
if: ${{ matrix.hosted && vars.OST_CI_DISABLE_CACHE != 'true' && steps.runtime-cache-restore.outputs.cache-hit != 'true' }}
uses: actions/cache/save@55cc8345863c7cc4c66a329aec7e433d2d1c52a9 # v6.1.0
with:
path: .ost-ci-home/artifacts
key: ost-registry-0.22.2-${{ runner.os }}-${{ runner.arch }}-${{ matrix.name }}-${{ matrix.runtime_artifact }}
- name: Install the host packages this runtime needs to be consumed
if: ${{ matrix.host_packages_apt != '' || matrix.host_packages_brew != '' }}
shell: bash
env:
HOST_PACKAGES_APT: ${{ matrix.host_packages_apt }}
HOST_PACKAGES_BREW: ${{ matrix.host_packages_brew }}
run: |
set -euo pipefail
case "$RUNNER_OS" in
Linux)
packages="$HOST_PACKAGES_APT"
if [ -z "$packages" ]; then
echo "error: this cell declares host_packages but nothing under 'apt'; a Linux runner installs from the 'apt' list" >&2
exit 1
fi
sudo apt-get update
sudo apt-get install -y --no-install-recommends $packages
;;
macOS)
packages="$HOST_PACKAGES_BREW"
if [ -z "$packages" ]; then
echo "error: this cell declares host_packages but nothing under 'brew'; a macOS runner installs from the 'brew' list" >&2
exit 1
fi
brew install $packages
;;
*)
echo "error: host_packages has no installer for $RUNNER_OS; provision the dependency on the runner image instead" >&2
exit 1
;;
esac
- name: Validate the materialized runtime (runnable tools)
shell: bash
run: |
set -euo pipefail
mkdir -p .ost-ci
ost runtime validate ${{ matrix.platform }} --profile ${{ matrix.profile }} --json | tee .ost-ci/runtime-validate.json
- name: Set up host Python for schema tooling
if: ${{ matrix.hosted && matrix.host_python != '' }}
uses: actions/setup-python@ece7cb06caefa5fff74198d8649806c4678c61a1 # v6.3.0
with:
python-version: ${{ matrix.host_python }}
- name: Record the schema-tooling Python contract
shell: bash
run: |
set -euo pipefail
mkdir -p .ost-ci
if [ "${{ matrix.hosted }}" = "true" ] && [ -n "${{ matrix.host_python }}" ]; then
source=host-setup-python
elif [ -n "${{ matrix.host_python }}" ]; then
source=operator-provisioned
else
source=runtime-bundled
fi
printf '{"schema":1,"host_python":"%s","source":"%s"}\n' "${{ matrix.host_python }}" "$source" > .ost-ci/python-setup.json
- name: Build the plugin from source
shell: bash
run: ost plugin build ${{ matrix.bundle }} --target ${{ matrix.platform }} --profile ${{ matrix.profile }}
- name: Run the verification pyramid
shell: bash
run: ost plugin test ${{ matrix.bundle }} --target ${{ matrix.platform }} --profile ${{ matrix.profile }} --up-to ${{ matrix.up_to }} --json
- name: Package the plugin (never published from this workflow)
shell: bash
run: ost plugin package ${{ matrix.bundle }} --target ${{ matrix.platform }} --profile ${{ matrix.profile }}
- name: Upload the verification report and CI evidence
if: always()
uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7
with:
name: report-${{ matrix.name }}
path: |
${{ matrix.bundle }}/.strata/reports/
.ost-ci/