Repository navigation
216 lines (207 loc) · 9.07 KB
/
Copy pathci.yml
File metadata and controls
216 lines (207 loc) · 9.07 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
130
131
132
133
134
135
136
137
138
139
140
141
142
143
144
145
146
147
148
149
150
151
152
153
154
155
156
157
158
159
160
161
162
163
164
165
166
167
168
169
170
171
172
173
174
175
176
177
178
179
180
181
182
183
184
185
186
187
188
189
190
191
192
193
194
195
196
197
198
199
200
201
202
203
204
205
206
207
208
209
210
211
212
213
214
215
216
name: CI
on:
push:
branches:
- main
pull_request:
workflow_dispatch:
permissions:
contents: read
concurrency:
group: ci-${{ github.workflow }}-${{ github.ref }}
cancel-in-progress: true
env:
# GitHub-hosted Linux/Windows runners have 4 vCPUs; this was needlessly
# capped at 2, roughly doubling compile time on a cold cache. A cold
# cache (evicted after today's several Cargo.lock-changing version
# bumps) combined with the 60-minute job timeout let a full rebuild get
# cancelled mid-compile, before any test ever ran.
CARGO_BUILD_JOBS: 4
CARGO_TERM_COLOR: always
# CI runners have no recognized terminal brand (no WT_SESSION/TERM_PROGRAM
# etc.), so `is_legacy_windows_console()` default-denies to legacy/ASCII
# glyphs on the Windows runner -- unlike a real dev machine's terminal.
# Force the modern-glyph path so Windows tests exercise the same rendering
# as local development. No-op on non-Windows hosts.
CHUTES_BUILD_FORCE_LEGACY_CONSOLE: "0"
jobs:
security:
name: Secrets and dependency policy
runs-on: ubuntu-24.04
timeout-minutes: 15
steps:
- name: Check out full history
uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
with:
fetch-depth: 0
persist-credentials: false
- name: Install pinned Gitleaks
shell: bash
env:
GITLEAKS_VERSION: 8.30.1
GITLEAKS_SHA256: 551f6fc83ea457d62a0d98237cbad105af8d557003051f41f3e7ca7b3f2470eb
run: |
set -euo pipefail
archive="gitleaks_${GITLEAKS_VERSION}_linux_x64.tar.gz"
curl --fail --location --proto '=https' --tlsv1.2 --retry 3 \
--output "$archive" \
"https://github.com/gitleaks/gitleaks/releases/download/v${GITLEAKS_VERSION}/${archive}"
echo "${GITLEAKS_SHA256} ${archive}" | sha256sum --check --strict
tar --extract --gzip --file "$archive" gitleaks
./gitleaks version
- name: Scan Git history for secrets
run: ./gitleaks git . --no-banner --no-color --redact
- name: Check dependency advisories, licenses, bans, and sources
uses: EmbarkStudios/cargo-deny-action@3c6349835b2b7b196a839186cb8b78e02f7b5f25 # v2.1.1
with:
command: check
arguments: --locked
command-arguments: advisories licenses bans sources
rust-quality:
name: Rust quality (Linux)
runs-on: ubuntu-24.04
# 90, matching the Windows job. This was 60, which fitted while the job died
# early: for twenty runs it stopped at the formatting check or the pager tests,
# so the four steps below — auth and session integration, agent construction,
# the Chutes tools, clippy — never ran. The first run that reached the end took
# 59.7 minutes of work and was killed during the cache *save*, which then left
# the next run cold, slower, and killed in the same place.
#
# Measured twice since: 65 minutes, then 67. The cost is not compilation — it is
# ~45 minutes of tests plus ~11 of clippy — so a warm cache moves it very little
# and the headroom here is real but modest, around a quarter. Anything that adds
# a slow test suite to this job should re-measure rather than assume the margin.
#
# Cache policy: Cargo *dependencies* are cached, not `target`. The `target`
# cache for this workspace can exceed the Linux runner's disk and fails the job
# as `No space left on device` before any test runs.
timeout-minutes: 90
steps:
- name: Check out repository
uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
with:
persist-credentials: false
- name: Restore Cargo cache
uses: actions/cache@55cc8345863c7cc4c66a329aec7e433d2d1c52a9 # v6.1.0
with:
path: |
~/.cargo/registry/index
~/.cargo/registry/cache
~/.cargo/git/db
key: ${{ runner.os }}-${{ runner.arch }}-cargo-deps-v1-${{ hashFiles('Cargo.lock') }}
restore-keys: |
${{ runner.os }}-${{ runner.arch }}-cargo-deps-v1-
- name: Check formatting
run: cargo fmt --all -- --check
- name: Lint GitHub Actions workflows
run: go run github.com/rhysd/actionlint/cmd/actionlint@v1.7.7
- name: Check Chutes Build
run: cargo check -p chutes-build --locked
- name: Test Chutes Build core
run: cargo test -p chutes-build-core --locked
- name: Test CLI parser and pager behavior
run: |
cargo test -p chutes-build --locked
cargo test -p xai-grok-pager --lib --locked
cargo test -p xai-grok-pager --test settings_e2e --locked
- name: Test authentication and session integration
# The auth-provider fixtures run a real helper rather than a shell
# one-liner, because a provider command goes through `cmd /C` off Unix
# and the POSIX forms meant nothing there. `--lib` does not build a
# crate's binaries, so it is built explicitly first.
run: |
cargo build -p xai-grok-shell --bin auth-provider-fixture --locked
cargo test -p xai-grok-shell --lib auth:: --locked
- name: Test agent construction and bundled skills
run: |
cargo test -p xai-grok-agent --lib --locked
cargo test -p xai-grok-shell --lib builtin:: --locked
- name: Test Chutes-native tools
run: "cargo test -p xai-grok-tools --lib implementations::chutes:: --locked"
- name: Clippy (Chutes-owned packages)
run: |
cargo clippy -p chutes-build -p chutes-build-core -p xai-grok-tools \
--all-targets --locked --no-deps -- -D warnings
cargo clippy -p xai-grok-pager --lib --locked --no-deps -- -D warnings
npm-package:
name: npm package
runs-on: ubuntu-24.04
timeout-minutes: 10
steps:
- name: Check out repository
uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
with:
persist-credentials: false
- name: Set up Node.js
uses: actions/setup-node@820762786026740c76f36085b0efc47a31fe5020 # v7.0.0
with:
node-version: 22
package-manager-cache: false
- name: Test launcher
run: npm test
- name: Verify release versions
run: npm run verify:release
- name: Inspect package contents
run: npm pack --dry-run
windows-check:
name: Rust quality (Windows)
runs-on: windows-2025
# Back to 90 now that the known-failure gate is gone from this job. It was
# raised to 150 to accommodate that step, twice, before measurement showed
# the step was not slow but unbounded: `xai-grok-tools --lib` never
# completes on this runner. Raising a budget was the wrong response to a
# number (107 minutes against six on Linux) that was already saying so.
timeout-minutes: 90
steps:
- name: Check out repository
uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
with:
persist-credentials: false
- name: Restore Cargo cache
uses: actions/cache@55cc8345863c7cc4c66a329aec7e433d2d1c52a9 # v6.1.0
with:
path: |
~/.cargo/registry/index
~/.cargo/registry/cache
~/.cargo/git/db
key: ${{ runner.os }}-${{ runner.arch }}-cargo-deps-v1-${{ hashFiles('Cargo.lock') }}
restore-keys: |
${{ runner.os }}-${{ runner.arch }}-cargo-deps-v1-
- name: Check Chutes Build
run: cargo check -p chutes-build --locked
- name: Test CLI and pager on Windows
run: |
cargo test -p chutes-build --locked
cargo test -p xai-grok-pager --lib --locked
- name: Test authentication and tools on Windows
# The auth-provider fixtures run a real helper rather than a shell
# one-liner, because a provider command goes through `cmd /C` off Unix
# and the POSIX forms meant nothing there. `--lib` does not build a
# crate's binaries, so it is built explicitly first.
run: |
cargo build -p xai-grok-shell --bin auth-provider-fixture --locked
cargo test -p xai-grok-shell --lib auth:: --locked
cargo test -p xai-grok-tools --lib implementations::chutes:: --locked
macos-check:
name: Rust check (macOS)
runs-on: macos-15
timeout-minutes: 60
steps:
- name: Check out repository
uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
with:
persist-credentials: false
- name: Restore Cargo cache
uses: actions/cache@55cc8345863c7cc4c66a329aec7e433d2d1c52a9 # v6.1.0
with:
path: |
~/.cargo/registry/index
~/.cargo/registry/cache
~/.cargo/git/db
key: ${{ runner.os }}-${{ runner.arch }}-cargo-deps-v1-${{ hashFiles('Cargo.lock') }}
restore-keys: |
${{ runner.os }}-${{ runner.arch }}-cargo-deps-v1-
- name: Check Chutes Build
run: cargo check -p chutes-build --locked
- name: Test pager on macOS
run: cargo test -p xai-grok-pager --lib --locked