Skip to content

export: public tree rebuilt from 066f656 #99

export: public tree rebuilt from 066f656

export: public tree rebuilt from 066f656 #99

Workflow file for this run

name: ci
on:
push:
branches: [main]
pull_request:
# Two reasons, and the second one was an accident that earned its keep.
#
# The stated one: the advisory database moves without anyone committing here,
# so `deny` has to run on a clock -- otherwise a fresh RUSTSEC entry stays
# unseen until the next unrelated pull request.
#
# The one found in practice (2026-08-17): the schedule runs the WHOLE
# workflow, so the suite is executed weekly against a commit nobody touched.
# That is the only thing in this project that can catch a flaky test after
# the fact -- a push-triggered run tests a change, and a change that passes
# once looks settled. The first scheduled run ever found a repair from the
# night before that had swapped one race for a subtler one. Keep it whole;
# narrowing this to the `deny` job would save minutes and lose that.
schedule:
- cron: "17 5 * * 1"
# A red scheduled run needs a second opinion, and asking for one should not
# require an empty commit. Without this, the only way to re-test the exact
# commit the cron tripped on is to push something -- which changes the thing
# under test. (Found the hard way on 2026-08-17.)
workflow_dispatch:
env:
CARGO_TERM_COLOR: always
# The public test suite compiles 400+ test binaries; with debuginfo the
# target tree outgrows the 14 GB a hosted runner has free (W13: the run
# died on ENOSPC in the middle of the build). Tests do not need line info.
CARGO_PROFILE_DEV_DEBUG: 0
CARGO_PROFILE_TEST_DEBUG: 0
jobs:
linux:
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@v4
- uses: Swatinem/rust-cache@v2
- name: fmt
run: cargo fmt --check
- name: clippy
run: cargo clippy --workspace --all-targets -- -D warnings
- name: test
run: cargo test --workspace
windows:
runs-on: windows-latest
steps:
- uses: actions/checkout@v4
- uses: Swatinem/rust-cache@v2
- name: check
run: cargo check --workspace
# The rules that used to live only in a document and in somebody's memory.
gates:
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@v4
- uses: Swatinem/rust-cache@v2
# Two frozen function bodies in crates/meclaw-colony/src/colony.rs,
# byte-compared against their reference under .github/fixtures/.
- name: corridor byte gates
run: .github/gates/corridor_byte_gates.sh
# CONTRIBUTING bans unwrap()/expect() outside tests. The clippy lints for
# it are allow-by-default, so `-D warnings` above never saw them. This
# pins the existing count per package and fails when it grows.
- name: unwrap/expect budget
run: python3 .github/gates/unwrap_budget.py
# docs/development-rules.md § 2a (GH #254). A review compares code
# against spec, so a spec that runs ahead of the code passes every review
# by construction. This runs the other direction: every behavioural claim
# in the trias is classified, a `pinned` row names a test that must
# exist, a `specified-not-built` row's paragraph must still carry its
# visible marker in both language versions, and no row's anchor may be
# rewritten out from under it.
#
# The registry's canonical home is plans/spec-claims/claims.tsv, which
# does not travel (export rule R2). The copy at .github/gates/claims.tsv
# is what this step reads -- same arrangement as the corridor fixtures.
#
# This run checks the travelling copy against the PUBLISHED documents:
# the export ships docs/X.en.md under the plain name docs/X.md, so the
# English half of every row is checked here and the German half is
# skipped with a counted, named notice (its document does not travel).
# The strict both-languages run, including the canonical-vs-copy
# divergence, is a private-tree matter and rides `cargo test` via
# crates/meclaw-colony/tests/a3_spec_claims_gate_drift.rs.
- name: spec-claims registry
run: python3 scripts/check_claims.py --check
# docs/development-rules.md § 2b (GH #319). An accepted ADR with nothing
# in the tree holding it up is a wish: legacy ADR 0011 kept reading
# `Akzeptiert` for three months after its capability had vanished, and the
# spec kept promising it, because nothing connected the decision to a line
# of code that could disappear. Every accepted ADR now names a test or a
# symbol, and this step resolves each one.
#
# Same two-tree arrangement as the spec-claims gate above and for the same
# reason: the corpus lives in plans/adr/, which does not travel (export
# rule R2), so a DERIVED registry travels as .github/gates/adr-anchors.tsv
# -- one row per anchor. This run resolves those rows against crates/,
# which does travel, and crates/ is exactly where the deletion this gate
# exists to catch would be visible. The private half -- the ADR texts
# themselves, the missing-Pinned-by check, and the byte-exactness of the
# derived copy -- rides `cargo test` via
# crates/meclaw-colony/tests/a4_adr_anchor_gate_drift.rs.
- name: ADR anchors
run: python3 scripts/check_adr_anchors.py --check
# GH #234 -- two gates USED to stand here: `build_librarian_seed.py
# --check` (GH #205) and `build_builder_hive.py --check` (GH #217),
# guarding the two committed trees that are generated. Do not put them
# back. Both generators live under workshop/, which is not part of this
# tree and is not meant to be, so the steps could not pass here -- they
# failed on a missing file, which says nothing about whether the artifacts
# drifted.
#
# They now run where their sources are: as R11 of the release gate, in the
# tree that has workshop/, before an export is built. The shipped Rust
# twins (librarian_seed_corpus.rs, builder_hive_template_tree.rs) cover
# this clone and skip when no generator is present -- which here is
# always, so a green run of theirs asserts nothing about the corpus. That
# is intentional: the assertion belongs to the tree that can make it.
deny:
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@v4
# Deterministic half: a verdict that depends only on this commit's
# Cargo.lock and deny.toml. Blocking.
- name: bans, licenses, sources
uses: EmbarkStudios/cargo-deny-action@v2
with:
command: check bans licenses sources
# Time-dependent half: RUSTSEC advisories and crates.io yank state change
# under a commit that never moved, so a red here is a report, not a
# verdict on the pull request. It is deliberately not blocking; the
# advisories standing open today are tracked in GH #127 (GH #115 is
# where the split was decided).
- name: advisories (reporting only)
continue-on-error: true
uses: EmbarkStudios/cargo-deny-action@v2
with:
command: check advisories