Repository navigation
evidence #11
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
| name: evidence | |
| # The only check here that leaves this repository. It downloads the exact | |
| # artifact a plan names, from the vendor that publishes it, and installs the | |
| # real product from those bytes. | |
| # | |
| # Not a required context and not on pull requests: a gate that depends on a | |
| # registry reports that registry's bad day as this commit's failure. | |
| on: | |
| workflow_dispatch: | |
| schedule: | |
| # Weekly, at a minute derived from the harness name so the seven do not | |
| # all reach the same registries in the same second. Derived from the bytes | |
| # of the name rather than `hash()`, which Python randomises per process and | |
| # would make this render differ from itself. | |
| - cron: '51 6 * * 1' | |
| permissions: | |
| contents: read | |
| concurrency: | |
| group: evidence-${{ github.ref }} | |
| cancel-in-progress: true | |
| jobs: | |
| lifecycle: | |
| name: lifecycle (${{ matrix.platform }}) | |
| runs-on: ${{ matrix.runner }} | |
| timeout-minutes: 45 | |
| strategy: | |
| fail-fast: false | |
| matrix: | |
| # The release publishes six native provider binaries and every product | |
| # table names the same six host ids. Three runners exercised vendor | |
| # bytes until 2026-08-31, leaving Linux arm64, Windows arm64 and macOS | |
| # x86_64 as build-only claims. Use exact hosted labels rather than | |
| # `*-latest`, whose architecture can move without this file changing. | |
| include: | |
| - runner: ubuntu-24.04 | |
| platform: linux/x86_64 | |
| runner_arch: X64 | |
| - runner: ubuntu-24.04-arm | |
| platform: linux/arm64 | |
| runner_arch: ARM64 | |
| - runner: windows-2025 | |
| platform: windows/x86_64 | |
| runner_arch: X64 | |
| - runner: windows-11-arm | |
| platform: windows/arm64 | |
| runner_arch: ARM64 | |
| - runner: macos-15-intel | |
| platform: macos/x86_64 | |
| runner_arch: X64 | |
| - runner: macos-15 | |
| platform: macos/arm64 | |
| runner_arch: ARM64 | |
| defaults: | |
| run: | |
| shell: bash | |
| steps: | |
| - name: Checkout | |
| uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 | |
| with: | |
| persist-credentials: false | |
| - name: Set up Rust toolchain | |
| uses: actions-rust-lang/setup-rust-toolchain@166cdcfd11aee3cb47222f9ddb555ce30ddb9659 # v1.17.0 | |
| with: | |
| toolchain: '1.98.0' | |
| - name: Prove this is the native architecture, not emulation | |
| env: | |
| EXPECTED_RUNNER_ARCH: ${{ matrix.runner_arch }} | |
| EVIDENCE_PLATFORM: ${{ matrix.platform }} | |
| EVIDENCE_RUNNER: ${{ matrix.runner }} | |
| run: | | |
| set -euo pipefail | |
| test "$RUNNER_ARCH" = "$EXPECTED_RUNNER_ARCH" | |
| echo "native $EVIDENCE_PLATFORM on $EVIDENCE_RUNNER ($RUNNER_ARCH)" | |
| - run: cargo build --locked --release | |
| - name: The whole software lifecycle, against the vendor's own bytes | |
| run: | | |
| set -euo pipefail | |
| # `python3` is not on PATH on the Windows image; `python` is. | |
| py=python3 | |
| [ "$RUNNER_OS" = "Windows" ] && py=python | |
| suffix="" | |
| [ "$RUNNER_OS" = "Windows" ] && suffix=".exe" | |
| exe="target/release/codex-setup-system$suffix" | |
| "$py" scripts/evidence.py --binary "$exe" --harness codex --writes "mcp add nddev-evidence -- echo hi" --probe 'doctor' --probe-kind postures --probe-baseline 'OnRequest' --probe-full-auto 'Never' |