Skip to content

fix(release,packaging): prep Docker for release parity, fail-closed p… #49

fix(release,packaging): prep Docker for release parity, fail-closed p…

fix(release,packaging): prep Docker for release parity, fail-closed p… #49

Workflow file for this run

name: Go CLI
on:
push:
branches: [main, master]
pull_request:
branches: [main, master]
workflow_dispatch: {}
schedule:
# Daily 06:00 UTC: the full runtime parity matrix + publish parity. On
# push/PR only the cases affected by the change run (see parity-runtime).
- cron: "0 6 * * *"
jobs:
lint-and-test:
runs-on: ubuntu-latest
permissions:
contents: read
code-quality: write
steps:
- uses: actions/checkout@v7
- uses: actions/setup-go@v6
with:
go-version-file: go.mod
- uses: go-task/setup-task@v2
with:
version: 3.x
repo-token: ${{ secrets.GITHUB_TOKEN }}
- run: task lint
- run: task spec:compliance
- run: task vuln
- run: task test:race
- run: task coverage
- run: task test:integration
- run: task build
- run: ./devcontainer --version
# Convert the Go coverage profile (coverage.out) to Cobertura XML for
# GitHub's native Code Quality feature.
- name: Convert coverage to Cobertura XML
run: |
go install github.com/boumenot/gocover-cobertura@latest
gocover-cobertura < coverage.out > coverage.xml
- name: Upload coverage report
uses: actions/upload-code-coverage@v1
with:
file: coverage.xml
language: Go
label: code-coverage/go
- uses: actions/upload-artifact@v7
if: always()
with:
name: unit-coverage
path: coverage.out
if-no-files-found: error
e2e:
runs-on: ubuntu-latest
needs: lint-and-test
steps:
- uses: actions/checkout@v7
- uses: actions/setup-go@v6
with:
go-version-file: go.mod
- uses: go-task/setup-task@v2
with:
version: 3.x
repo-token: ${{ secrets.GITHUB_TOKEN }}
- run: task test:e2e
- if: always()
run: task clean
# Hermetic parity gate: read-configuration golden comparison + the contract
# lane of the parity matrix (flag validation / output contract, no Docker).
parity:
runs-on: ubuntu-latest
needs: lint-and-test
steps:
- uses: actions/checkout@v7
with:
submodules: recursive
- uses: actions/setup-go@v6
with:
go-version-file: go.mod
- uses: actions/setup-node@v6
with:
node-version: "20"
- uses: go-task/setup-task@v2
with:
version: 3.x
repo-token: ${{ secrets.GITHUB_TOKEN }}
- run: task reference
- run: task parity:contract
- run: task parity:network
- if: always()
run: |
mkdir -p artifacts
git -C reference rev-parse HEAD > artifacts/reference-commit.txt
- uses: actions/upload-artifact@v7
if: always()
with:
name: parity-contract-network-v0.88.0
path: artifacts/
if-no-files-found: error
# Runtime lane of the parity matrix (creates real containers via Docker) on
# push/PR, SCOPED to the commands affected by the change: the full matrix takes
# ~45 min, so .github/scripts/parity-affected.sh maps the diff to a
# PARITY_COMMAND allowlist (or "all"/"none"). The daily parity-runtime-full job
# is the backstop that always runs the whole thing.
parity-runtime:
if: github.event_name == 'push' || github.event_name == 'pull_request'
runs-on: ubuntu-latest
needs: lint-and-test
env:
PARITY_RUNTIME_TIMEOUT: "10m"
# 2-core hosted runners can't sustain 2 concurrent heavy docker builds; run
# serially for gate determinism (override with PARITY_PARALLEL for beefy runners).
PARITY_PARALLEL: "1"
steps:
- uses: actions/checkout@v7
with:
submodules: recursive
# Full history so the diff base (PR base / previous push) is present.
fetch-depth: 0
- name: Determine affected parity commands
id: affected
run: |
if [ "${{ github.event_name }}" = "pull_request" ]; then
base="${{ github.event.pull_request.base.sha }}"
head="${{ github.event.pull_request.head.sha }}"
else
base="${{ github.event.before }}"
head="${{ github.sha }}"
fi
# New branch / unknown base (e.g. all-zero before-SHA) → run everything.
if [ -z "$base" ] || ! git cat-file -e "${base}^{commit}" 2>/dev/null; then
echo "commands=all" >> "$GITHUB_OUTPUT"; echo "run=true" >> "$GITHUB_OUTPUT"
echo "unknown base → running the full matrix"; exit 0
fi
files=$(git diff --name-only "$base" "$head")
echo "changed files:"; echo "$files"
cmds=$(printf '%s\n' "$files" | .github/scripts/parity-affected.sh)
echo "affected parity commands: $cmds"
echo "commands=$cmds" >> "$GITHUB_OUTPUT"
if [ "$cmds" = "none" ]; then
echo "run=false" >> "$GITHUB_OUTPUT"
echo "no runtime-relevant changes → skipping the runtime matrix"
else
echo "run=true" >> "$GITHUB_OUTPUT"
fi
# The runtime matrix builds real images serially; they accumulate and
# exhaust the runner's root disk ("No space left on device" — the runner then
# dies hard, losing logs). /mnt is the SAME filesystem as / on these runners,
# so it buys nothing; instead free the big preinstalled SDKs (Go/Node are
# reinstalled by the setup steps that follow) for ~25-30GB of headroom. Also
# enable the containerd image store (needed for cache export / --platform).
- name: Free disk space + configure Docker (containerd store)
if: steps.affected.outputs.run == 'true'
run: |
echo "before:"; df -h / | tail -1
sudo rm -rf /usr/share/dotnet /opt/ghc /usr/local/lib/android \
/opt/hostedtoolcache/CodeQL /usr/share/swift \
/usr/local/share/boost /usr/lib/jvm || true
sudo docker image prune -af >/dev/null 2>&1 || true
echo "after:"; df -h / | tail -1
echo '{"features":{"containerd-snapshotter":true}}' | sudo tee /etc/docker/daemon.json
sudo systemctl restart docker
docker info -f 'driver={{.DriverStatus}}'
- uses: actions/setup-go@v6
if: steps.affected.outputs.run == 'true'
with:
go-version-file: go.mod
- uses: actions/setup-node@v6
if: steps.affected.outputs.run == 'true'
with:
node-version: "20"
- uses: go-task/setup-task@v2
if: steps.affected.outputs.run == 'true'
with:
version: 3.x
repo-token: ${{ secrets.GITHUB_TOKEN }}
- if: steps.affected.outputs.run == 'true'
run: task reference
- if: steps.affected.outputs.run == 'true'
env:
PARITY_COMMAND: ${{ steps.affected.outputs.commands }}
run: task parity:runtime
- if: always() && steps.affected.outputs.run == 'true'
run: |
mkdir -p artifacts
git -C reference rev-parse HEAD > artifacts/reference-commit.txt
- uses: actions/upload-artifact@v7
if: always() && steps.affected.outputs.run == 'true'
with:
name: parity-runtime-v0.88.0
path: artifacts/
if-no-files-found: error
- if: always() && steps.affected.outputs.run == 'true'
run: task clean
# Full runtime parity matrix + publish parity. Runs once a day (schedule) and
# on manual dispatch — the exhaustive backstop for the scoped push/PR job above.
parity-runtime-full:
if: github.event_name == 'schedule' || github.event_name == 'workflow_dispatch'
runs-on: ubuntu-latest
needs: lint-and-test
env:
PARITY_RUNTIME_TIMEOUT: "10m"
PARITY_PARALLEL: "1"
steps:
- uses: actions/checkout@v7
with:
submodules: recursive
- name: Free disk space + configure Docker (containerd store)
run: |
echo "before:"; df -h / | tail -1
sudo rm -rf /usr/share/dotnet /opt/ghc /usr/local/lib/android \
/opt/hostedtoolcache/CodeQL /usr/share/swift \
/usr/local/share/boost /usr/lib/jvm || true
sudo docker image prune -af >/dev/null 2>&1 || true
echo "after:"; df -h / | tail -1
echo '{"features":{"containerd-snapshotter":true}}' | sudo tee /etc/docker/daemon.json
sudo systemctl restart docker
docker info -f 'driver={{.DriverStatus}}'
- uses: actions/setup-go@v6
with:
go-version-file: go.mod
- uses: actions/setup-node@v6
with:
node-version: "20"
- uses: go-task/setup-task@v2
with:
version: 3.x
repo-token: ${{ secrets.GITHUB_TOKEN }}
- run: task reference
- run: task parity:runtime
- run: task parity:publish
- if: always()
run: |
mkdir -p artifacts
git -C reference rev-parse HEAD > artifacts/reference-commit.txt
- uses: actions/upload-artifact@v7
if: always()
with:
name: parity-runtime-full-v0.88.0
path: artifacts/
if-no-files-found: error
- if: always()
run: task clean
# Experimental, NON-gating: arm64 runtime via QEMU emulation. arm64 runtime is
# unsupported for now, so its cases are skipped-arm64 in the gate above. This job
# is SLOW (QEMU) and only runs on a manual trigger (workflow_dispatch), not on
# every push/PR — enable it when validating arm64.
parity-runtime-arm64-experimental:
if: github.event_name == 'workflow_dispatch'
runs-on: ubuntu-latest
needs: lint-and-test
continue-on-error: true
env:
PARITY_ARM64: "true"
PARITY_RUNTIME_TIMEOUT: "15m"
steps:
- uses: actions/checkout@v7
with:
submodules: recursive
- name: Set up QEMU (arm64 emulation)
uses: docker/setup-qemu-action@v3
with:
platforms: arm64
- name: Free disk space + configure Docker (containerd store)
run: |
sudo rm -rf /usr/share/dotnet /opt/ghc /usr/local/lib/android \
/opt/hostedtoolcache/CodeQL /usr/share/swift \
/usr/local/share/boost /usr/lib/jvm || true
echo '{"features":{"containerd-snapshotter":true}}' | sudo tee /etc/docker/daemon.json
sudo systemctl restart docker
- uses: actions/setup-go@v6
with:
go-version-file: go.mod
- uses: actions/setup-node@v6
with:
node-version: "20"
- uses: go-task/setup-task@v2
with:
version: 3.x
repo-token: ${{ secrets.GITHUB_TOKEN }}
- run: task reference
- run: task parity:runtime
- if: always()
run: task clean
cross-compile:
runs-on: ubuntu-latest
needs: lint-and-test
steps:
- uses: actions/checkout@v7
- uses: actions/setup-go@v6
with:
go-version-file: go.mod
- uses: go-task/setup-task@v2
with:
version: 3.x
repo-token: ${{ secrets.GITHUB_TOKEN }}
- run: task build:cross
- run: ls -lh dist/