Merge pull request #129 from animu-sphere/feat/v0.10.0-resolver-cache… #303
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
| # Generated by `ost ci generate github` from openstrata.ci.yaml. | |
| # Regenerate after editing the matrix; do not edit the jobs by hand. | |
| # | |
| # Source CI: each job checks out the repo, obtains a digest-pinned runtime | |
| # SDK artifact, and builds/tests/packages the bundle from source. On | |
| # GitHub-hosted runners the job bootstraps a pinned, checksum-verified `ost` | |
| # and pulls the runtime from the cell's remote (oci://) reference — an | |
| # actions/cache restore keyed by digest is a speed optimization, never a | |
| # correctness precondition. Self-hosted runners keep their operator-managed | |
| # `ost` and registry (air-gapped local import stays supported). | |
| # | |
| # Fork-PR safety: this workflow never publishes, never promotes, and uses no | |
| # secrets; keep it that way when editing the matrix. | |
| name: ost source ci | |
| on: | |
| pull_request: | |
| push: | |
| branches: [main] | |
| permissions: | |
| contents: read | |
| jobs: | |
| pr: | |
| if: github.event_name == 'pull_request' | |
| name: ${{ matrix.name }} | |
| runs-on: ${{ matrix.runs_on }} | |
| env: | |
| OST_CI_CELL: ${{ matrix.name }} | |
| OST_CI_LANE: ${{ matrix.lane }} | |
| OST_CI_RUNNER_PROFILE: ${{ matrix.runner_profile }} | |
| OST_CI_RUNS_ON: ${{ join(matrix.runs_on, ',') }} | |
| OST_CI_RUNTIME_ARTIFACT: ${{ matrix.runtime_artifact }} | |
| OST_CI_MINIMUM_TRUST: ${{ matrix.minimum_trust }} | |
| OST_HOME: ${{ matrix.hosted && format('{0}/.ost-ci-home', github.workspace) || '' }} | |
| strategy: | |
| fail-fast: false | |
| matrix: | |
| include: | |
| - name: pointcloud-las-pr-windows | |
| lane: pull_request | |
| runtime_artifact: sha256:c3ed40122756ea118166e1619efcaec463e7d2a42f6d978fe4e20b6b774c4b03 | |
| target_trust: local | |
| minimum_trust: local | |
| require_evidence: all | |
| evidence_flags: "--require-sbom --require-provenance" | |
| platform: cy2026 | |
| profile: usd | |
| up_to: 4 | |
| runs_on: ["windows-2022"] | |
| hosted: true | |
| runner_profile: windows-hosted | |
| bundle: plugins/pointcloud-las | |
| runtime_remote: "oci://ghcr.io/animu-sphere/openstrata-runtime-cy2026-usd@sha256:07cb84412017ece911adaed1175a6373865d863bc40124081cfc20c52de7f0d9" | |
| host_python: "" | |
| host_packages_apt: "" | |
| host_packages_brew: "" | |
| - name: pointcloud-laz-pr-windows | |
| lane: pull_request | |
| runtime_artifact: sha256:c3ed40122756ea118166e1619efcaec463e7d2a42f6d978fe4e20b6b774c4b03 | |
| target_trust: local | |
| minimum_trust: local | |
| require_evidence: all | |
| evidence_flags: "--require-sbom --require-provenance" | |
| platform: cy2026 | |
| profile: usd | |
| up_to: 4 | |
| runs_on: ["windows-2022"] | |
| hosted: true | |
| runner_profile: windows-hosted | |
| bundle: plugins/pointcloud-laz | |
| runtime_remote: "oci://ghcr.io/animu-sphere/openstrata-runtime-cy2026-usd@sha256:07cb84412017ece911adaed1175a6373865d863bc40124081cfc20c52de7f0d9" | |
| host_python: "" | |
| host_packages_apt: "" | |
| host_packages_brew: "" | |
| - name: pointcloud-las-pr-macos-arm64 | |
| lane: pull_request | |
| runtime_artifact: sha256:a9bb847ab5c7eb29d7425ff9acfb05b01c1751054d6a70628e48b06f8409a4a8 | |
| target_trust: local | |
| minimum_trust: local | |
| require_evidence: all | |
| evidence_flags: "--require-sbom --require-provenance" | |
| platform: cy2026 | |
| profile: usd | |
| up_to: 5 | |
| runs_on: ["macos-15"] | |
| hosted: true | |
| runner_profile: macos-arm64-hosted | |
| bundle: plugins/pointcloud-las | |
| runtime_remote: "oci://ghcr.io/animu-sphere/openstrata-runtime-cy2026-usd@sha256:dc0c980b868f91fe33e6f35a67a2bc5693b89f0243141c55ecb068ab225b0f3e" | |
| host_python: "3.13" | |
| host_packages_apt: "" | |
| host_packages_brew: "" | |
| - name: pointcloud-las-pr-linux | |
| lane: pull_request | |
| runtime_artifact: sha256:03f7d4ef263abb50511d17237e7cbdbe1b83dee02cff8b8f901f0484c7a7898e | |
| target_trust: local | |
| minimum_trust: local | |
| require_evidence: all | |
| evidence_flags: "--require-sbom --require-provenance" | |
| platform: cy2026 | |
| profile: usd | |
| up_to: 5 | |
| runs_on: ["ubuntu-24.04"] | |
| hosted: true | |
| runner_profile: linux-hosted | |
| bundle: plugins/pointcloud-las | |
| runtime_remote: "oci://ghcr.io/animu-sphere/openstrata-runtime-cy2026-usd@sha256:367a32bd1985ca9b07e8f7e64f95c1ded8dba16d68f17e0bffb09cec0b9dc3f6" | |
| host_python: "3.13" | |
| host_packages_apt: "libx11-dev libxt-dev libxext-dev libgl1-mesa-dev" | |
| host_packages_brew: "" | |
| - name: pointcloud-laz-pr-macos-arm64 | |
| lane: pull_request | |
| runtime_artifact: sha256:a9bb847ab5c7eb29d7425ff9acfb05b01c1751054d6a70628e48b06f8409a4a8 | |
| target_trust: local | |
| minimum_trust: local | |
| require_evidence: all | |
| evidence_flags: "--require-sbom --require-provenance" | |
| platform: cy2026 | |
| profile: usd | |
| up_to: 5 | |
| runs_on: ["macos-15"] | |
| hosted: true | |
| runner_profile: macos-arm64-hosted | |
| bundle: plugins/pointcloud-laz | |
| runtime_remote: "oci://ghcr.io/animu-sphere/openstrata-runtime-cy2026-usd@sha256:dc0c980b868f91fe33e6f35a67a2bc5693b89f0243141c55ecb068ab225b0f3e" | |
| host_python: "3.13" | |
| host_packages_apt: "" | |
| host_packages_brew: "" | |
| - name: pointcloud-laz-pr-linux | |
| lane: pull_request | |
| runtime_artifact: sha256:03f7d4ef263abb50511d17237e7cbdbe1b83dee02cff8b8f901f0484c7a7898e | |
| target_trust: local | |
| minimum_trust: local | |
| require_evidence: all | |
| evidence_flags: "--require-sbom --require-provenance" | |
| platform: cy2026 | |
| profile: usd | |
| up_to: 5 | |
| runs_on: ["ubuntu-24.04"] | |
| hosted: true | |
| runner_profile: linux-hosted | |
| bundle: plugins/pointcloud-laz | |
| runtime_remote: "oci://ghcr.io/animu-sphere/openstrata-runtime-cy2026-usd@sha256:367a32bd1985ca9b07e8f7e64f95c1ded8dba16d68f17e0bffb09cec0b9dc3f6" | |
| host_python: "3.13" | |
| host_packages_apt: "libx11-dev libxt-dev libxext-dev libgl1-mesa-dev" | |
| host_packages_brew: "" | |
| - name: pointcloud-copc-pr-windows | |
| lane: pull_request | |
| runtime_artifact: sha256:c3ed40122756ea118166e1619efcaec463e7d2a42f6d978fe4e20b6b774c4b03 | |
| target_trust: local | |
| minimum_trust: local | |
| require_evidence: all | |
| evidence_flags: "--require-sbom --require-provenance" | |
| platform: cy2026 | |
| profile: usd | |
| up_to: 4 | |
| runs_on: ["windows-2022"] | |
| hosted: true | |
| runner_profile: windows-hosted | |
| bundle: plugins/pointcloud-copc | |
| runtime_remote: "oci://ghcr.io/animu-sphere/openstrata-runtime-cy2026-usd@sha256:07cb84412017ece911adaed1175a6373865d863bc40124081cfc20c52de7f0d9" | |
| host_python: "" | |
| host_packages_apt: "" | |
| host_packages_brew: "" | |
| - name: pointcloud-copc-pr-macos-arm64 | |
| lane: pull_request | |
| runtime_artifact: sha256:a9bb847ab5c7eb29d7425ff9acfb05b01c1751054d6a70628e48b06f8409a4a8 | |
| target_trust: local | |
| minimum_trust: local | |
| require_evidence: all | |
| evidence_flags: "--require-sbom --require-provenance" | |
| platform: cy2026 | |
| profile: usd | |
| up_to: 5 | |
| runs_on: ["macos-15"] | |
| hosted: true | |
| runner_profile: macos-arm64-hosted | |
| bundle: plugins/pointcloud-copc | |
| runtime_remote: "oci://ghcr.io/animu-sphere/openstrata-runtime-cy2026-usd@sha256:dc0c980b868f91fe33e6f35a67a2bc5693b89f0243141c55ecb068ab225b0f3e" | |
| host_python: "3.13" | |
| host_packages_apt: "" | |
| host_packages_brew: "" | |
| - name: pointcloud-copc-pr-linux | |
| lane: pull_request | |
| runtime_artifact: sha256:03f7d4ef263abb50511d17237e7cbdbe1b83dee02cff8b8f901f0484c7a7898e | |
| target_trust: local | |
| minimum_trust: local | |
| require_evidence: all | |
| evidence_flags: "--require-sbom --require-provenance" | |
| platform: cy2026 | |
| profile: usd | |
| up_to: 5 | |
| runs_on: ["ubuntu-24.04"] | |
| hosted: true | |
| runner_profile: linux-hosted | |
| bundle: plugins/pointcloud-copc | |
| runtime_remote: "oci://ghcr.io/animu-sphere/openstrata-runtime-cy2026-usd@sha256:367a32bd1985ca9b07e8f7e64f95c1ded8dba16d68f17e0bffb09cec0b9dc3f6" | |
| host_python: "3.13" | |
| host_packages_apt: "libx11-dev libxt-dev libxext-dev libgl1-mesa-dev" | |
| host_packages_brew: "" | |
| - name: httpresolver-pr-windows | |
| lane: pull_request | |
| runtime_artifact: sha256:c3ed40122756ea118166e1619efcaec463e7d2a42f6d978fe4e20b6b774c4b03 | |
| target_trust: local | |
| minimum_trust: local | |
| require_evidence: all | |
| evidence_flags: "--require-sbom --require-provenance" | |
| platform: cy2026 | |
| profile: usd | |
| up_to: 4 | |
| runs_on: ["windows-2022"] | |
| hosted: true | |
| runner_profile: windows-hosted | |
| bundle: plugins/httpresolver | |
| runtime_remote: "oci://ghcr.io/animu-sphere/openstrata-runtime-cy2026-usd@sha256:07cb84412017ece911adaed1175a6373865d863bc40124081cfc20c52de7f0d9" | |
| host_python: "" | |
| host_packages_apt: "" | |
| host_packages_brew: "" | |
| - name: httpresolver-pr-macos-arm64 | |
| lane: pull_request | |
| runtime_artifact: sha256:a9bb847ab5c7eb29d7425ff9acfb05b01c1751054d6a70628e48b06f8409a4a8 | |
| target_trust: local | |
| minimum_trust: local | |
| require_evidence: all | |
| evidence_flags: "--require-sbom --require-provenance" | |
| platform: cy2026 | |
| profile: usd | |
| up_to: 5 | |
| runs_on: ["macos-15"] | |
| hosted: true | |
| runner_profile: macos-arm64-hosted | |
| bundle: plugins/httpresolver | |
| runtime_remote: "oci://ghcr.io/animu-sphere/openstrata-runtime-cy2026-usd@sha256:dc0c980b868f91fe33e6f35a67a2bc5693b89f0243141c55ecb068ab225b0f3e" | |
| host_python: "3.13" | |
| host_packages_apt: "" | |
| host_packages_brew: "" | |
| - name: httpresolver-pr-linux | |
| lane: pull_request | |
| runtime_artifact: sha256:03f7d4ef263abb50511d17237e7cbdbe1b83dee02cff8b8f901f0484c7a7898e | |
| target_trust: local | |
| minimum_trust: local | |
| require_evidence: all | |
| evidence_flags: "--require-sbom --require-provenance" | |
| platform: cy2026 | |
| profile: usd | |
| up_to: 5 | |
| runs_on: ["ubuntu-24.04"] | |
| hosted: true | |
| runner_profile: linux-hosted | |
| bundle: plugins/httpresolver | |
| runtime_remote: "oci://ghcr.io/animu-sphere/openstrata-runtime-cy2026-usd@sha256:367a32bd1985ca9b07e8f7e64f95c1ded8dba16d68f17e0bffb09cec0b9dc3f6" | |
| host_python: "3.13" | |
| host_packages_apt: "libx11-dev libxt-dev libxext-dev libgl1-mesa-dev" | |
| host_packages_brew: "" | |
| - name: pointcloud-ply-pr-windows | |
| lane: pull_request | |
| runtime_artifact: sha256:c3ed40122756ea118166e1619efcaec463e7d2a42f6d978fe4e20b6b774c4b03 | |
| target_trust: local | |
| minimum_trust: local | |
| require_evidence: all | |
| evidence_flags: "--require-sbom --require-provenance" | |
| platform: cy2026 | |
| profile: usd | |
| up_to: 4 | |
| runs_on: ["windows-2022"] | |
| hosted: true | |
| runner_profile: windows-hosted | |
| bundle: plugins/pointcloud-ply | |
| runtime_remote: "oci://ghcr.io/animu-sphere/openstrata-runtime-cy2026-usd@sha256:07cb84412017ece911adaed1175a6373865d863bc40124081cfc20c52de7f0d9" | |
| host_python: "" | |
| host_packages_apt: "" | |
| host_packages_brew: "" | |
| - name: pointcloud-ply-pr-macos-arm64 | |
| lane: pull_request | |
| runtime_artifact: sha256:a9bb847ab5c7eb29d7425ff9acfb05b01c1751054d6a70628e48b06f8409a4a8 | |
| target_trust: local | |
| minimum_trust: local | |
| require_evidence: all | |
| evidence_flags: "--require-sbom --require-provenance" | |
| platform: cy2026 | |
| profile: usd | |
| up_to: 5 | |
| runs_on: ["macos-15"] | |
| hosted: true | |
| runner_profile: macos-arm64-hosted | |
| bundle: plugins/pointcloud-ply | |
| runtime_remote: "oci://ghcr.io/animu-sphere/openstrata-runtime-cy2026-usd@sha256:dc0c980b868f91fe33e6f35a67a2bc5693b89f0243141c55ecb068ab225b0f3e" | |
| host_python: "3.13" | |
| host_packages_apt: "" | |
| host_packages_brew: "" | |
| - name: pointcloud-ply-pr-linux | |
| lane: pull_request | |
| runtime_artifact: sha256:03f7d4ef263abb50511d17237e7cbdbe1b83dee02cff8b8f901f0484c7a7898e | |
| target_trust: local | |
| minimum_trust: local | |
| require_evidence: all | |
| evidence_flags: "--require-sbom --require-provenance" | |
| platform: cy2026 | |
| profile: usd | |
| up_to: 5 | |
| runs_on: ["ubuntu-24.04"] | |
| hosted: true | |
| runner_profile: linux-hosted | |
| bundle: plugins/pointcloud-ply | |
| runtime_remote: "oci://ghcr.io/animu-sphere/openstrata-runtime-cy2026-usd@sha256:367a32bd1985ca9b07e8f7e64f95c1ded8dba16d68f17e0bffb09cec0b9dc3f6" | |
| host_python: "3.13" | |
| host_packages_apt: "libx11-dev libxt-dev libxext-dev libgl1-mesa-dev" | |
| host_packages_brew: "" | |
| steps: | |
| - name: Check out the repository | |
| uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 # v7.0.0 | |
| - name: Hosted runner billing notice | |
| if: ${{ matrix.hosted }} | |
| shell: bash | |
| run: echo "::notice title=OpenStrata hosted-runner usage::This job uses GitHub-hosted infrastructure. Private repositories may incur GitHub Actions usage charges. Review repository billing and Actions usage settings." | |
| - name: Bootstrap ost 0.22.2 (pinned release asset, checksum-verified) | |
| if: ${{ matrix.hosted }} | |
| shell: bash | |
| run: | | |
| set -euo pipefail | |
| mkdir -p .ost-ci | |
| case "${RUNNER_OS}-${RUNNER_ARCH}" in | |
| Linux-X64) triple=x86_64-unknown-linux-musl ; ext=tar.xz ;; | |
| macOS-ARM64) triple=aarch64-apple-darwin ; ext=tar.xz ;; | |
| macOS-X64) triple=x86_64-apple-darwin ; ext=tar.xz ;; | |
| Windows-X64) triple=x86_64-pc-windows-msvc ; ext=zip ;; | |
| *) echo "::error title=ost bootstrap::no ost release asset for ${RUNNER_OS}-${RUNNER_ARCH}" ; exit 1 ;; | |
| esac | |
| pinned="" | |
| case "$triple" in | |
| *) : ;; | |
| esac | |
| asset="ost-cli-${triple}.${ext}" | |
| base="https://github.com/animu-sphere/open-strata/releases/download/v0.22.2" | |
| curl -fsSLo "$asset" "$base/$asset" | |
| curl -fsSLo "$asset.sha256" "$base/$asset.sha256" | |
| actual="$( (command -v sha256sum > /dev/null && sha256sum "$asset" || shasum -a 256 "$asset") | cut -d' ' -f1 )" | |
| published="$(cut -d' ' -f1 "$asset.sha256")" | |
| if [ "$actual" != "$published" ]; then | |
| echo "::error title=ost bootstrap::$asset hashes to $actual but the release publishes $published" ; exit 1 | |
| fi | |
| if [ -n "$pinned" ] && [ "$actual" != "$pinned" ]; then | |
| echo "::error title=ost bootstrap::$asset hashes to $actual but the CI contract pins $pinned" ; exit 1 | |
| fi | |
| mkdir -p .ost-ci/bootstrap-bin | |
| if [ "$ext" = "zip" ]; then | |
| powershell -NoProfile -Command "Expand-Archive -LiteralPath '$asset' -DestinationPath '.ost-ci/bootstrap-bin' -Force" | |
| else | |
| tar -xf "$asset" -C .ost-ci/bootstrap-bin | |
| fi | |
| bin="$(find .ost-ci/bootstrap-bin -type f \( -name ost -o -name ost.exe \) | head -n 1)" | |
| if [ -z "$bin" ]; then echo "::error title=ost bootstrap::no ost binary inside $asset" ; exit 1 ; fi | |
| chmod +x "$bin" 2> /dev/null || true | |
| bin_dir="$(cd "$(dirname "$bin")" && pwd)" | |
| bin="$bin_dir/$(basename "$bin")" | |
| executable="$bin" | |
| exported_path="$bin_dir" | |
| if [ "$RUNNER_OS" = "Windows" ]; then | |
| if ! command -v cygpath > /dev/null; then | |
| echo "::error title=ost bootstrap::cygpath is required to export a native Windows PATH" ; exit 1 | |
| fi | |
| executable="$(cygpath -w "$bin")" | |
| exported_path="$(cygpath -w "$bin_dir")" | |
| fi | |
| echo "$exported_path" >> "$GITHUB_PATH" | |
| json_executable="$(printf '%s' "$executable" | sed 's/\\/\\\\/g; s/"/\\"/g')" | |
| json_exported_path="$(printf '%s' "$exported_path" | sed 's/\\/\\\\/g; s/"/\\"/g')" | |
| printf '{"schema":1,"pinned_version":"%s","asset":"%s","sha256":"%s","executable":"%s","exported_path":"%s"}\n' "0.22.2" "$asset" "$actual" "$json_executable" "$json_exported_path" > .ost-ci/bootstrap.json | |
| - name: Check ost is available and record its version | |
| shell: bash | |
| run: | | |
| set -euo pipefail | |
| mkdir -p .ost-ci | |
| if [ "${{ matrix.hosted }}" = "true" ] && [ "$RUNNER_OS" = "Windows" ]; then | |
| version="$(powershell -NoProfile -Command "& ost.exe --version" | tr -d '\r')" | |
| else | |
| version="$(ost --version)" | |
| fi | |
| echo "$version" | |
| if [ "${{ matrix.hosted }}" = "true" ] && [ "$version" != "ost 0.22.2" ]; then | |
| echo "::error title=ost bootstrap::expected 'ost 0.22.2', got '$version'" ; exit 1 | |
| fi | |
| printf '{"schema":1,"ost_version":"%s"}\n' "$version" > .ost-ci/ost-version.json | |
| - name: Validate the CI manifest | |
| shell: bash | |
| run: ost ci validate | |
| - name: Restore the artifact registry cache (speed only, never correctness) | |
| id: runtime-cache-restore | |
| if: ${{ matrix.hosted && vars.OST_CI_DISABLE_CACHE != 'true' }} | |
| uses: actions/cache/restore@55cc8345863c7cc4c66a329aec7e433d2d1c52a9 # v6.1.0 | |
| with: | |
| path: .ost-ci-home/artifacts | |
| key: ost-registry-0.22.2-${{ runner.os }}-${{ runner.arch }}-${{ matrix.name }}-${{ matrix.runtime_artifact }} | |
| - name: Pull the pinned runtime SDK from its remote reference | |
| if: ${{ matrix.runtime_remote != '' }} | |
| shell: bash | |
| run: | | |
| set -euo pipefail | |
| mkdir -p .ost-ci | |
| if ost artifact show "${{ matrix.runtime_artifact }}" --json > /dev/null 2>&1 \ | |
| && ost artifact verify "${{ matrix.runtime_artifact }}" ${{ matrix.evidence_flags }} --json > .ost-ci/runtime-cache-verify.json; then | |
| echo "pinned runtime already present and verified (cache hit) -- skipping the remote pull" | |
| else | |
| if [ "${{ matrix.hosted }}" = "true" ] && [ -n "${OST_HOME:-}" ]; then | |
| rm -rf "${OST_HOME}/artifacts" | |
| fi | |
| ost artifact pull "${{ matrix.runtime_remote }}" --expect-artifact "${{ matrix.runtime_artifact }}" --require-kind runtime --json | tee .ost-ci/runtime-pull.json | |
| fi | |
| - name: Verify and materialize the pinned runtime SDK | |
| shell: bash | |
| run: | | |
| set -euo pipefail | |
| mkdir -p .ost-ci | |
| printf '{"schema":1,"runtime_artifact":"%s","source":"%s"}\n' "${{ matrix.runtime_artifact }}" "${{ matrix.runtime_remote != '' && 'remote-pull' || 'local-registry' }}" > .ost-ci/runtime-source.json | |
| ost artifact verify ${{ matrix.runtime_artifact }} --minimum-trust ${{ matrix.minimum_trust }} ${{ matrix.evidence_flags }} | |
| ost runtime pull ${{ matrix.platform }} --profile ${{ matrix.profile }} --from-artifact ${{ matrix.runtime_artifact }} --force | |
| - name: Remove resumable transfer state before caching | |
| if: ${{ matrix.hosted && vars.OST_CI_DISABLE_CACHE != 'true' && steps.runtime-cache-restore.outputs.cache-hit != 'true' }} | |
| shell: bash | |
| run: rm -rf .ost-ci-home/artifacts/.partial-blobs | |
| - name: Save the verified artifact registry cache | |
| if: ${{ matrix.hosted && vars.OST_CI_DISABLE_CACHE != 'true' && steps.runtime-cache-restore.outputs.cache-hit != 'true' }} | |
| uses: actions/cache/save@55cc8345863c7cc4c66a329aec7e433d2d1c52a9 # v6.1.0 | |
| with: | |
| path: .ost-ci-home/artifacts | |
| key: ost-registry-0.22.2-${{ runner.os }}-${{ runner.arch }}-${{ matrix.name }}-${{ matrix.runtime_artifact }} | |
| - name: Install the host packages this runtime needs to be consumed | |
| if: ${{ matrix.host_packages_apt != '' || matrix.host_packages_brew != '' }} | |
| shell: bash | |
| env: | |
| HOST_PACKAGES_APT: ${{ matrix.host_packages_apt }} | |
| HOST_PACKAGES_BREW: ${{ matrix.host_packages_brew }} | |
| run: | | |
| set -euo pipefail | |
| case "$RUNNER_OS" in | |
| Linux) | |
| packages="$HOST_PACKAGES_APT" | |
| if [ -z "$packages" ]; then | |
| echo "error: this cell declares host_packages but nothing under 'apt'; a Linux runner installs from the 'apt' list" >&2 | |
| exit 1 | |
| fi | |
| sudo apt-get update | |
| sudo apt-get install -y --no-install-recommends $packages | |
| ;; | |
| macOS) | |
| packages="$HOST_PACKAGES_BREW" | |
| if [ -z "$packages" ]; then | |
| echo "error: this cell declares host_packages but nothing under 'brew'; a macOS runner installs from the 'brew' list" >&2 | |
| exit 1 | |
| fi | |
| brew install $packages | |
| ;; | |
| *) | |
| echo "error: host_packages has no installer for $RUNNER_OS; provision the dependency on the runner image instead" >&2 | |
| exit 1 | |
| ;; | |
| esac | |
| - name: Validate the materialized runtime (runnable tools) | |
| shell: bash | |
| run: | | |
| set -euo pipefail | |
| mkdir -p .ost-ci | |
| ost runtime validate ${{ matrix.platform }} --profile ${{ matrix.profile }} --json | tee .ost-ci/runtime-validate.json | |
| - name: Set up host Python for schema tooling | |
| if: ${{ matrix.hosted && matrix.host_python != '' }} | |
| uses: actions/setup-python@ece7cb06caefa5fff74198d8649806c4678c61a1 # v6.3.0 | |
| with: | |
| python-version: ${{ matrix.host_python }} | |
| - name: Record the schema-tooling Python contract | |
| shell: bash | |
| run: | | |
| set -euo pipefail | |
| mkdir -p .ost-ci | |
| if [ "${{ matrix.hosted }}" = "true" ] && [ -n "${{ matrix.host_python }}" ]; then | |
| source=host-setup-python | |
| elif [ -n "${{ matrix.host_python }}" ]; then | |
| source=operator-provisioned | |
| else | |
| source=runtime-bundled | |
| fi | |
| printf '{"schema":1,"host_python":"%s","source":"%s"}\n' "${{ matrix.host_python }}" "$source" > .ost-ci/python-setup.json | |
| - name: Build the plugin from source | |
| shell: bash | |
| run: ost plugin build ${{ matrix.bundle }} --target ${{ matrix.platform }} --profile ${{ matrix.profile }} | |
| - name: Run the verification pyramid | |
| shell: bash | |
| run: ost plugin test ${{ matrix.bundle }} --target ${{ matrix.platform }} --profile ${{ matrix.profile }} --up-to ${{ matrix.up_to }} --json | |
| - name: Package the plugin (never published from this workflow) | |
| shell: bash | |
| run: ost plugin package ${{ matrix.bundle }} --target ${{ matrix.platform }} --profile ${{ matrix.profile }} | |
| - name: Upload the verification report and CI evidence | |
| if: always() | |
| uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7 | |
| with: | |
| name: report-${{ matrix.name }} | |
| path: | | |
| ${{ matrix.bundle }}/.strata/reports/ | |
| .ost-ci/ | |
| mainline: | |
| if: github.event_name == 'push' | |
| name: ${{ matrix.name }} | |
| runs-on: ${{ matrix.runs_on }} | |
| env: | |
| OST_CI_CELL: ${{ matrix.name }} | |
| OST_CI_LANE: ${{ matrix.lane }} | |
| OST_CI_RUNNER_PROFILE: ${{ matrix.runner_profile }} | |
| OST_CI_RUNS_ON: ${{ join(matrix.runs_on, ',') }} | |
| OST_CI_RUNTIME_ARTIFACT: ${{ matrix.runtime_artifact }} | |
| OST_CI_MINIMUM_TRUST: ${{ matrix.minimum_trust }} | |
| OST_HOME: ${{ matrix.hosted && format('{0}/.ost-ci-home', github.workspace) || '' }} | |
| strategy: | |
| fail-fast: false | |
| matrix: | |
| include: | |
| - name: pointcloud-las-main-windows | |
| lane: main | |
| runtime_artifact: sha256:c3ed40122756ea118166e1619efcaec463e7d2a42f6d978fe4e20b6b774c4b03 | |
| target_trust: local | |
| minimum_trust: local | |
| require_evidence: all | |
| evidence_flags: "--require-sbom --require-provenance" | |
| platform: cy2026 | |
| profile: usd | |
| up_to: 4 | |
| runs_on: ["windows-2022"] | |
| hosted: true | |
| runner_profile: windows-hosted | |
| bundle: plugins/pointcloud-las | |
| runtime_remote: "oci://ghcr.io/animu-sphere/openstrata-runtime-cy2026-usd@sha256:07cb84412017ece911adaed1175a6373865d863bc40124081cfc20c52de7f0d9" | |
| host_python: "" | |
| host_packages_apt: "" | |
| host_packages_brew: "" | |
| - name: pointcloud-laz-main-windows | |
| lane: main | |
| runtime_artifact: sha256:c3ed40122756ea118166e1619efcaec463e7d2a42f6d978fe4e20b6b774c4b03 | |
| target_trust: local | |
| minimum_trust: local | |
| require_evidence: all | |
| evidence_flags: "--require-sbom --require-provenance" | |
| platform: cy2026 | |
| profile: usd | |
| up_to: 4 | |
| runs_on: ["windows-2022"] | |
| hosted: true | |
| runner_profile: windows-hosted | |
| bundle: plugins/pointcloud-laz | |
| runtime_remote: "oci://ghcr.io/animu-sphere/openstrata-runtime-cy2026-usd@sha256:07cb84412017ece911adaed1175a6373865d863bc40124081cfc20c52de7f0d9" | |
| host_python: "" | |
| host_packages_apt: "" | |
| host_packages_brew: "" | |
| - name: pointcloud-las-main-macos-arm64 | |
| lane: main | |
| runtime_artifact: sha256:a9bb847ab5c7eb29d7425ff9acfb05b01c1751054d6a70628e48b06f8409a4a8 | |
| target_trust: local | |
| minimum_trust: local | |
| require_evidence: all | |
| evidence_flags: "--require-sbom --require-provenance" | |
| platform: cy2026 | |
| profile: usd | |
| up_to: 5 | |
| runs_on: ["macos-15"] | |
| hosted: true | |
| runner_profile: macos-arm64-hosted | |
| bundle: plugins/pointcloud-las | |
| runtime_remote: "oci://ghcr.io/animu-sphere/openstrata-runtime-cy2026-usd@sha256:dc0c980b868f91fe33e6f35a67a2bc5693b89f0243141c55ecb068ab225b0f3e" | |
| host_python: "3.13" | |
| host_packages_apt: "" | |
| host_packages_brew: "" | |
| - name: pointcloud-laz-main-macos-arm64 | |
| lane: main | |
| runtime_artifact: sha256:a9bb847ab5c7eb29d7425ff9acfb05b01c1751054d6a70628e48b06f8409a4a8 | |
| target_trust: local | |
| minimum_trust: local | |
| require_evidence: all | |
| evidence_flags: "--require-sbom --require-provenance" | |
| platform: cy2026 | |
| profile: usd | |
| up_to: 5 | |
| runs_on: ["macos-15"] | |
| hosted: true | |
| runner_profile: macos-arm64-hosted | |
| bundle: plugins/pointcloud-laz | |
| runtime_remote: "oci://ghcr.io/animu-sphere/openstrata-runtime-cy2026-usd@sha256:dc0c980b868f91fe33e6f35a67a2bc5693b89f0243141c55ecb068ab225b0f3e" | |
| host_python: "3.13" | |
| host_packages_apt: "" | |
| host_packages_brew: "" | |
| - name: pointcloud-las-main-linux | |
| lane: main | |
| runtime_artifact: sha256:03f7d4ef263abb50511d17237e7cbdbe1b83dee02cff8b8f901f0484c7a7898e | |
| target_trust: local | |
| minimum_trust: local | |
| require_evidence: all | |
| evidence_flags: "--require-sbom --require-provenance" | |
| platform: cy2026 | |
| profile: usd | |
| up_to: 5 | |
| runs_on: ["ubuntu-24.04"] | |
| hosted: true | |
| runner_profile: linux-hosted | |
| bundle: plugins/pointcloud-las | |
| runtime_remote: "oci://ghcr.io/animu-sphere/openstrata-runtime-cy2026-usd@sha256:367a32bd1985ca9b07e8f7e64f95c1ded8dba16d68f17e0bffb09cec0b9dc3f6" | |
| host_python: "3.13" | |
| host_packages_apt: "libx11-dev libxt-dev libxext-dev libgl1-mesa-dev" | |
| host_packages_brew: "" | |
| - name: pointcloud-laz-main-linux | |
| lane: main | |
| runtime_artifact: sha256:03f7d4ef263abb50511d17237e7cbdbe1b83dee02cff8b8f901f0484c7a7898e | |
| target_trust: local | |
| minimum_trust: local | |
| require_evidence: all | |
| evidence_flags: "--require-sbom --require-provenance" | |
| platform: cy2026 | |
| profile: usd | |
| up_to: 5 | |
| runs_on: ["ubuntu-24.04"] | |
| hosted: true | |
| runner_profile: linux-hosted | |
| bundle: plugins/pointcloud-laz | |
| runtime_remote: "oci://ghcr.io/animu-sphere/openstrata-runtime-cy2026-usd@sha256:367a32bd1985ca9b07e8f7e64f95c1ded8dba16d68f17e0bffb09cec0b9dc3f6" | |
| host_python: "3.13" | |
| host_packages_apt: "libx11-dev libxt-dev libxext-dev libgl1-mesa-dev" | |
| host_packages_brew: "" | |
| - name: pointcloud-copc-main-windows | |
| lane: main | |
| runtime_artifact: sha256:c3ed40122756ea118166e1619efcaec463e7d2a42f6d978fe4e20b6b774c4b03 | |
| target_trust: local | |
| minimum_trust: local | |
| require_evidence: all | |
| evidence_flags: "--require-sbom --require-provenance" | |
| platform: cy2026 | |
| profile: usd | |
| up_to: 4 | |
| runs_on: ["windows-2022"] | |
| hosted: true | |
| runner_profile: windows-hosted | |
| bundle: plugins/pointcloud-copc | |
| runtime_remote: "oci://ghcr.io/animu-sphere/openstrata-runtime-cy2026-usd@sha256:07cb84412017ece911adaed1175a6373865d863bc40124081cfc20c52de7f0d9" | |
| host_python: "" | |
| host_packages_apt: "" | |
| host_packages_brew: "" | |
| - name: pointcloud-copc-main-macos-arm64 | |
| lane: main | |
| runtime_artifact: sha256:a9bb847ab5c7eb29d7425ff9acfb05b01c1751054d6a70628e48b06f8409a4a8 | |
| target_trust: local | |
| minimum_trust: local | |
| require_evidence: all | |
| evidence_flags: "--require-sbom --require-provenance" | |
| platform: cy2026 | |
| profile: usd | |
| up_to: 5 | |
| runs_on: ["macos-15"] | |
| hosted: true | |
| runner_profile: macos-arm64-hosted | |
| bundle: plugins/pointcloud-copc | |
| runtime_remote: "oci://ghcr.io/animu-sphere/openstrata-runtime-cy2026-usd@sha256:dc0c980b868f91fe33e6f35a67a2bc5693b89f0243141c55ecb068ab225b0f3e" | |
| host_python: "3.13" | |
| host_packages_apt: "" | |
| host_packages_brew: "" | |
| - name: pointcloud-copc-main-linux | |
| lane: main | |
| runtime_artifact: sha256:03f7d4ef263abb50511d17237e7cbdbe1b83dee02cff8b8f901f0484c7a7898e | |
| target_trust: local | |
| minimum_trust: local | |
| require_evidence: all | |
| evidence_flags: "--require-sbom --require-provenance" | |
| platform: cy2026 | |
| profile: usd | |
| up_to: 5 | |
| runs_on: ["ubuntu-24.04"] | |
| hosted: true | |
| runner_profile: linux-hosted | |
| bundle: plugins/pointcloud-copc | |
| runtime_remote: "oci://ghcr.io/animu-sphere/openstrata-runtime-cy2026-usd@sha256:367a32bd1985ca9b07e8f7e64f95c1ded8dba16d68f17e0bffb09cec0b9dc3f6" | |
| host_python: "3.13" | |
| host_packages_apt: "libx11-dev libxt-dev libxext-dev libgl1-mesa-dev" | |
| host_packages_brew: "" | |
| - name: pointcloud-ply-main-windows | |
| lane: main | |
| runtime_artifact: sha256:c3ed40122756ea118166e1619efcaec463e7d2a42f6d978fe4e20b6b774c4b03 | |
| target_trust: local | |
| minimum_trust: local | |
| require_evidence: all | |
| evidence_flags: "--require-sbom --require-provenance" | |
| platform: cy2026 | |
| profile: usd | |
| up_to: 4 | |
| runs_on: ["windows-2022"] | |
| hosted: true | |
| runner_profile: windows-hosted | |
| bundle: plugins/pointcloud-ply | |
| runtime_remote: "oci://ghcr.io/animu-sphere/openstrata-runtime-cy2026-usd@sha256:07cb84412017ece911adaed1175a6373865d863bc40124081cfc20c52de7f0d9" | |
| host_python: "" | |
| host_packages_apt: "" | |
| host_packages_brew: "" | |
| - name: pointcloud-ply-main-macos-arm64 | |
| lane: main | |
| runtime_artifact: sha256:a9bb847ab5c7eb29d7425ff9acfb05b01c1751054d6a70628e48b06f8409a4a8 | |
| target_trust: local | |
| minimum_trust: local | |
| require_evidence: all | |
| evidence_flags: "--require-sbom --require-provenance" | |
| platform: cy2026 | |
| profile: usd | |
| up_to: 5 | |
| runs_on: ["macos-15"] | |
| hosted: true | |
| runner_profile: macos-arm64-hosted | |
| bundle: plugins/pointcloud-ply | |
| runtime_remote: "oci://ghcr.io/animu-sphere/openstrata-runtime-cy2026-usd@sha256:dc0c980b868f91fe33e6f35a67a2bc5693b89f0243141c55ecb068ab225b0f3e" | |
| host_python: "3.13" | |
| host_packages_apt: "" | |
| host_packages_brew: "" | |
| - name: pointcloud-ply-main-linux | |
| lane: main | |
| runtime_artifact: sha256:03f7d4ef263abb50511d17237e7cbdbe1b83dee02cff8b8f901f0484c7a7898e | |
| target_trust: local | |
| minimum_trust: local | |
| require_evidence: all | |
| evidence_flags: "--require-sbom --require-provenance" | |
| platform: cy2026 | |
| profile: usd | |
| up_to: 5 | |
| runs_on: ["ubuntu-24.04"] | |
| hosted: true | |
| runner_profile: linux-hosted | |
| bundle: plugins/pointcloud-ply | |
| runtime_remote: "oci://ghcr.io/animu-sphere/openstrata-runtime-cy2026-usd@sha256:367a32bd1985ca9b07e8f7e64f95c1ded8dba16d68f17e0bffb09cec0b9dc3f6" | |
| host_python: "3.13" | |
| host_packages_apt: "libx11-dev libxt-dev libxext-dev libgl1-mesa-dev" | |
| host_packages_brew: "" | |
| steps: | |
| - name: Check out the repository | |
| uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 # v7.0.0 | |
| - name: Hosted runner billing notice | |
| if: ${{ matrix.hosted }} | |
| shell: bash | |
| run: echo "::notice title=OpenStrata hosted-runner usage::This job uses GitHub-hosted infrastructure. Private repositories may incur GitHub Actions usage charges. Review repository billing and Actions usage settings." | |
| - name: Bootstrap ost 0.22.2 (pinned release asset, checksum-verified) | |
| if: ${{ matrix.hosted }} | |
| shell: bash | |
| run: | | |
| set -euo pipefail | |
| mkdir -p .ost-ci | |
| case "${RUNNER_OS}-${RUNNER_ARCH}" in | |
| Linux-X64) triple=x86_64-unknown-linux-musl ; ext=tar.xz ;; | |
| macOS-ARM64) triple=aarch64-apple-darwin ; ext=tar.xz ;; | |
| macOS-X64) triple=x86_64-apple-darwin ; ext=tar.xz ;; | |
| Windows-X64) triple=x86_64-pc-windows-msvc ; ext=zip ;; | |
| *) echo "::error title=ost bootstrap::no ost release asset for ${RUNNER_OS}-${RUNNER_ARCH}" ; exit 1 ;; | |
| esac | |
| pinned="" | |
| case "$triple" in | |
| *) : ;; | |
| esac | |
| asset="ost-cli-${triple}.${ext}" | |
| base="https://github.com/animu-sphere/open-strata/releases/download/v0.22.2" | |
| curl -fsSLo "$asset" "$base/$asset" | |
| curl -fsSLo "$asset.sha256" "$base/$asset.sha256" | |
| actual="$( (command -v sha256sum > /dev/null && sha256sum "$asset" || shasum -a 256 "$asset") | cut -d' ' -f1 )" | |
| published="$(cut -d' ' -f1 "$asset.sha256")" | |
| if [ "$actual" != "$published" ]; then | |
| echo "::error title=ost bootstrap::$asset hashes to $actual but the release publishes $published" ; exit 1 | |
| fi | |
| if [ -n "$pinned" ] && [ "$actual" != "$pinned" ]; then | |
| echo "::error title=ost bootstrap::$asset hashes to $actual but the CI contract pins $pinned" ; exit 1 | |
| fi | |
| mkdir -p .ost-ci/bootstrap-bin | |
| if [ "$ext" = "zip" ]; then | |
| powershell -NoProfile -Command "Expand-Archive -LiteralPath '$asset' -DestinationPath '.ost-ci/bootstrap-bin' -Force" | |
| else | |
| tar -xf "$asset" -C .ost-ci/bootstrap-bin | |
| fi | |
| bin="$(find .ost-ci/bootstrap-bin -type f \( -name ost -o -name ost.exe \) | head -n 1)" | |
| if [ -z "$bin" ]; then echo "::error title=ost bootstrap::no ost binary inside $asset" ; exit 1 ; fi | |
| chmod +x "$bin" 2> /dev/null || true | |
| bin_dir="$(cd "$(dirname "$bin")" && pwd)" | |
| bin="$bin_dir/$(basename "$bin")" | |
| executable="$bin" | |
| exported_path="$bin_dir" | |
| if [ "$RUNNER_OS" = "Windows" ]; then | |
| if ! command -v cygpath > /dev/null; then | |
| echo "::error title=ost bootstrap::cygpath is required to export a native Windows PATH" ; exit 1 | |
| fi | |
| executable="$(cygpath -w "$bin")" | |
| exported_path="$(cygpath -w "$bin_dir")" | |
| fi | |
| echo "$exported_path" >> "$GITHUB_PATH" | |
| json_executable="$(printf '%s' "$executable" | sed 's/\\/\\\\/g; s/"/\\"/g')" | |
| json_exported_path="$(printf '%s' "$exported_path" | sed 's/\\/\\\\/g; s/"/\\"/g')" | |
| printf '{"schema":1,"pinned_version":"%s","asset":"%s","sha256":"%s","executable":"%s","exported_path":"%s"}\n' "0.22.2" "$asset" "$actual" "$json_executable" "$json_exported_path" > .ost-ci/bootstrap.json | |
| - name: Check ost is available and record its version | |
| shell: bash | |
| run: | | |
| set -euo pipefail | |
| mkdir -p .ost-ci | |
| if [ "${{ matrix.hosted }}" = "true" ] && [ "$RUNNER_OS" = "Windows" ]; then | |
| version="$(powershell -NoProfile -Command "& ost.exe --version" | tr -d '\r')" | |
| else | |
| version="$(ost --version)" | |
| fi | |
| echo "$version" | |
| if [ "${{ matrix.hosted }}" = "true" ] && [ "$version" != "ost 0.22.2" ]; then | |
| echo "::error title=ost bootstrap::expected 'ost 0.22.2', got '$version'" ; exit 1 | |
| fi | |
| printf '{"schema":1,"ost_version":"%s"}\n' "$version" > .ost-ci/ost-version.json | |
| - name: Validate the CI manifest | |
| shell: bash | |
| run: ost ci validate | |
| - name: Restore the artifact registry cache (speed only, never correctness) | |
| id: runtime-cache-restore | |
| if: ${{ matrix.hosted && vars.OST_CI_DISABLE_CACHE != 'true' }} | |
| uses: actions/cache/restore@55cc8345863c7cc4c66a329aec7e433d2d1c52a9 # v6.1.0 | |
| with: | |
| path: .ost-ci-home/artifacts | |
| key: ost-registry-0.22.2-${{ runner.os }}-${{ runner.arch }}-${{ matrix.name }}-${{ matrix.runtime_artifact }} | |
| - name: Pull the pinned runtime SDK from its remote reference | |
| if: ${{ matrix.runtime_remote != '' }} | |
| shell: bash | |
| run: | | |
| set -euo pipefail | |
| mkdir -p .ost-ci | |
| if ost artifact show "${{ matrix.runtime_artifact }}" --json > /dev/null 2>&1 \ | |
| && ost artifact verify "${{ matrix.runtime_artifact }}" ${{ matrix.evidence_flags }} --json > .ost-ci/runtime-cache-verify.json; then | |
| echo "pinned runtime already present and verified (cache hit) -- skipping the remote pull" | |
| else | |
| if [ "${{ matrix.hosted }}" = "true" ] && [ -n "${OST_HOME:-}" ]; then | |
| rm -rf "${OST_HOME}/artifacts" | |
| fi | |
| ost artifact pull "${{ matrix.runtime_remote }}" --expect-artifact "${{ matrix.runtime_artifact }}" --require-kind runtime --json | tee .ost-ci/runtime-pull.json | |
| fi | |
| - name: Verify and materialize the pinned runtime SDK | |
| shell: bash | |
| run: | | |
| set -euo pipefail | |
| mkdir -p .ost-ci | |
| printf '{"schema":1,"runtime_artifact":"%s","source":"%s"}\n' "${{ matrix.runtime_artifact }}" "${{ matrix.runtime_remote != '' && 'remote-pull' || 'local-registry' }}" > .ost-ci/runtime-source.json | |
| ost artifact verify ${{ matrix.runtime_artifact }} --minimum-trust ${{ matrix.minimum_trust }} ${{ matrix.evidence_flags }} | |
| ost runtime pull ${{ matrix.platform }} --profile ${{ matrix.profile }} --from-artifact ${{ matrix.runtime_artifact }} --force | |
| - name: Remove resumable transfer state before caching | |
| if: ${{ matrix.hosted && vars.OST_CI_DISABLE_CACHE != 'true' && steps.runtime-cache-restore.outputs.cache-hit != 'true' }} | |
| shell: bash | |
| run: rm -rf .ost-ci-home/artifacts/.partial-blobs | |
| - name: Save the verified artifact registry cache | |
| if: ${{ matrix.hosted && vars.OST_CI_DISABLE_CACHE != 'true' && steps.runtime-cache-restore.outputs.cache-hit != 'true' }} | |
| uses: actions/cache/save@55cc8345863c7cc4c66a329aec7e433d2d1c52a9 # v6.1.0 | |
| with: | |
| path: .ost-ci-home/artifacts | |
| key: ost-registry-0.22.2-${{ runner.os }}-${{ runner.arch }}-${{ matrix.name }}-${{ matrix.runtime_artifact }} | |
| - name: Install the host packages this runtime needs to be consumed | |
| if: ${{ matrix.host_packages_apt != '' || matrix.host_packages_brew != '' }} | |
| shell: bash | |
| env: | |
| HOST_PACKAGES_APT: ${{ matrix.host_packages_apt }} | |
| HOST_PACKAGES_BREW: ${{ matrix.host_packages_brew }} | |
| run: | | |
| set -euo pipefail | |
| case "$RUNNER_OS" in | |
| Linux) | |
| packages="$HOST_PACKAGES_APT" | |
| if [ -z "$packages" ]; then | |
| echo "error: this cell declares host_packages but nothing under 'apt'; a Linux runner installs from the 'apt' list" >&2 | |
| exit 1 | |
| fi | |
| sudo apt-get update | |
| sudo apt-get install -y --no-install-recommends $packages | |
| ;; | |
| macOS) | |
| packages="$HOST_PACKAGES_BREW" | |
| if [ -z "$packages" ]; then | |
| echo "error: this cell declares host_packages but nothing under 'brew'; a macOS runner installs from the 'brew' list" >&2 | |
| exit 1 | |
| fi | |
| brew install $packages | |
| ;; | |
| *) | |
| echo "error: host_packages has no installer for $RUNNER_OS; provision the dependency on the runner image instead" >&2 | |
| exit 1 | |
| ;; | |
| esac | |
| - name: Validate the materialized runtime (runnable tools) | |
| shell: bash | |
| run: | | |
| set -euo pipefail | |
| mkdir -p .ost-ci | |
| ost runtime validate ${{ matrix.platform }} --profile ${{ matrix.profile }} --json | tee .ost-ci/runtime-validate.json | |
| - name: Set up host Python for schema tooling | |
| if: ${{ matrix.hosted && matrix.host_python != '' }} | |
| uses: actions/setup-python@ece7cb06caefa5fff74198d8649806c4678c61a1 # v6.3.0 | |
| with: | |
| python-version: ${{ matrix.host_python }} | |
| - name: Record the schema-tooling Python contract | |
| shell: bash | |
| run: | | |
| set -euo pipefail | |
| mkdir -p .ost-ci | |
| if [ "${{ matrix.hosted }}" = "true" ] && [ -n "${{ matrix.host_python }}" ]; then | |
| source=host-setup-python | |
| elif [ -n "${{ matrix.host_python }}" ]; then | |
| source=operator-provisioned | |
| else | |
| source=runtime-bundled | |
| fi | |
| printf '{"schema":1,"host_python":"%s","source":"%s"}\n' "${{ matrix.host_python }}" "$source" > .ost-ci/python-setup.json | |
| - name: Build the plugin from source | |
| shell: bash | |
| run: ost plugin build ${{ matrix.bundle }} --target ${{ matrix.platform }} --profile ${{ matrix.profile }} | |
| - name: Run the verification pyramid | |
| shell: bash | |
| run: ost plugin test ${{ matrix.bundle }} --target ${{ matrix.platform }} --profile ${{ matrix.profile }} --up-to ${{ matrix.up_to }} --json | |
| - name: Package the plugin (never published from this workflow) | |
| shell: bash | |
| run: ost plugin package ${{ matrix.bundle }} --target ${{ matrix.platform }} --profile ${{ matrix.profile }} | |
| - name: Upload the verification report and CI evidence | |
| if: always() | |
| uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7 | |
| with: | |
| name: report-${{ matrix.name }} | |
| path: | | |
| ${{ matrix.bundle }}/.strata/reports/ | |
| .ost-ci/ |