Skip to content

fix(release): validate candidate workflows and next push checks #510

fix(release): validate candidate workflows and next push checks

fix(release): validate candidate workflows and next push checks #510

Workflow file for this run

name: CI
on:
push:
branches:
- main
- next
tags-ignore:
- "v*"
pull_request:
jobs:
state-models:
name: Runtime state models
runs-on: ubuntu-latest
timeout-minutes: 5
permissions:
contents: read
steps:
- uses: actions/checkout@v4
- uses: oven-sh/setup-bun@v1
with:
bun-version: "1.4.2"
- uses: actions/setup-java@v4
with:
distribution: temurin
java-version: "17"
- uses: actions/setup-python@v5
with:
python-version: "3.12"
- name: Install mise for model-helper contract tests
uses: jdx/mise-action@c2a87611a18de5b3828c5652fe268e992400cb5c # v4
with:
version: "2026.9.12"
install: false
cache: false
env: false
- name: Validate release workflow syntax
run: mise x actionlint@1.7.12 -- actionlint -shellcheck= -pyflakes= .github/workflows/ci.yml .github/workflows/release.yml .github/workflows/prerelease.yml
- name: Fetch pinned model checker
run: curl --fail --location --retry 2 --max-time 60 https://github.com/tlaplus/tlaplus/releases/download/v1.7.4/tla2tools.jar --output "$RUNNER_TEMP/tla2tools.jar"
- name: Check evidence validation and models
env:
TLA2TOOLS_JAR: ${{ runner.temp }}/tla2tools.jar
run: |
python3 -m unittest discover -s .ai/skills/hack-repo-tla/tests
bun test tests/tla-result.test.ts
bun run test:models
- name: Check prepared-base benchmark harness controls
run: python3 -m unittest discover -s tests/python -p test_prepared_base_benchmark.py
- name: Check native frontend acceptance controls
run: python3 -m unittest discover -s tests/python -p test_native_frontend_acceptance.py
runtime-core:
name: Candidate core (${{ matrix.os }})
strategy:
matrix:
os: [ubuntu-latest, macos-latest]
runs-on: ${{ matrix.os }}
permissions:
contents: read
steps:
- uses: actions/checkout@v4
- uses: dtolnay/rust-toolchain@1.97.1
with:
components: rustfmt, clippy
- name: Install pinned Zig for guest helpers
uses: jdx/mise-action@c2a87611a18de5b3828c5652fe268e992400cb5c # v4
with:
version: "2026.9.12"
install_args: zig
add_shims_to_path: false
cache: false
env: false
- name: Check candidate formatting
run: cargo fmt --manifest-path packages/runtime-core/Cargo.toml --check
- name: Lint candidate core
run: cargo clippy --locked --manifest-path packages/runtime-core/Cargo.toml --target-dir .hack-local/target --all-targets --jobs 2 -- -D warnings
- name: Test candidate isolation contracts
run: cargo test --locked --manifest-path packages/runtime-core/Cargo.toml --target-dir .hack-local/target --jobs 2
- name: Build and inspect local candidate
run: |
mise exec zig -- ./scripts/build-hack-local.sh
./hack-local info --json
secret-scan:
runs-on: blacksmith-4vcpu-ubuntu-2404
permissions:
contents: read
steps:
- name: Checkout
uses: actions/checkout@v4
with:
fetch-depth: 0
- name: Install Gitleaks
id: gitleaks
uses: gacts/gitleaks@v1
with:
version: 8.30.1
run: 'false'
- name: Scan checked-out commit history
env:
GITLEAKS_BIN: ${{ steps.gitleaks.outputs.gitleaks-bin }}
run: |
"$GITLEAKS_BIN" git . \
--config .gitleaks.toml \
--redact \
--log-opts='--full-history --diff-filter=tuxdb HEAD' \
--report-format sarif \
--report-path "$RUNNER_TEMP/gitleaks.sarif"
runtime-images:
runs-on: blacksmith-4vcpu-ubuntu-2404
permissions:
contents: read
steps:
- name: Checkout
uses: actions/checkout@v4
- name: Setup Bun
uses: oven-sh/setup-bun@v1
with:
bun-version: "1.4.2"
- name: Setup Blacksmith Builder
uses: useblacksmith/setup-docker-builder@v1
- name: Install dependencies
run: bun install
- name: Build full runtime image
run: |
bun run scripts/build-node-runtime-image.ts \
--variant node-runtime \
--platform linux/amd64 \
--tag hack-runtime-ci:full
- name: Smoke full runtime image
run: |
docker run --rm --entrypoint hack hack-runtime-ci:full --help >/tmp/hack-full-help.txt
grep -q "hack" /tmp/hack-full-help.txt
- name: Build slim runtime image
run: |
bun run scripts/build-node-runtime-image.ts \
--variant slim \
--platform linux/amd64 \
--tag hack-runtime-ci:slim
- name: Smoke slim runtime image defaults
run: |
docker run --rm --entrypoint sh hack-runtime-ci:slim -lc 'command -v bun >/dev/null && command -v hack >/dev/null && test "${HACK_EXECUTION_MODE}" = "codex" && test "${HACK_DAEMON_DISABLE_DOCKER_EVENTS}" = "1" && hack --help >/tmp/hack-help.txt && grep -q "Usage:" /tmp/hack-help.txt'
- name: Smoke slim runtime mounted-project env flow
run: bash scripts/portable-container-smoke.sh hack-runtime-ci:slim linux/amd64
docker-e2e:
runs-on: blacksmith-4vcpu-ubuntu-2404
permissions:
contents: read
steps:
- name: Checkout
uses: actions/checkout@v4
- name: Setup Bun
uses: oven-sh/setup-bun@v1
with:
bun-version: "1.4.2"
- name: Install tmux
run: sudo apt-get update && sudo apt-get install --yes tmux
- name: Install dependencies
run: bun install
- name: Create isolated Hack network
run: docker network create --subnet 172.30.0.0/16 hack-dev
- name: Prepare offline cache fixture images
run: |
docker pull alpine:3.20
docker pull alpine:3.22
docker pull node:24.11.0-bookworm-slim
- name: Run local and Docker E2E
run: HACK_E2E_REQUIRE_DOCKER=1 HACK_E2E_REQUIRE_TMUX=1 bun run test:e2e:local:docker
- name: Smoke container resource metadata without optional fields
run: |
probe_id=$(docker create --network none --read-only alpine:3.20 true)
trap 'docker rm -f "$probe_id" >/dev/null' EXIT
bun scripts/inspect-container-resources.ts --container "$probe_id" > "$RUNNER_TEMP/resource-probe.json"
bun -e 'const r = await Bun.stdin.json(); if (r.probeStatus !== "not_running" || r.container.healthcheckIntervalNs !== null || r.container.writableLayerBytes !== null) throw new Error("Invalid optional resource metadata");' < "$RUNNER_TEMP/resource-probe.json"
bun scripts/inspect-container-resources.ts --container "$probe_id" --storage > "$RUNNER_TEMP/resource-probe.json"
bun -e 'const r = await Bun.stdin.json(); if (typeof r.container.writableLayerBytes !== "number") throw new Error("Missing writable-layer accounting");' < "$RUNNER_TEMP/resource-probe.json"
test:
runs-on: blacksmith-6vcpu-macos-15
steps:
- name: Checkout
uses: actions/checkout@v4
- name: Setup Bun
uses: oven-sh/setup-bun@v1
with:
bun-version: "1.4.2"
- name: Install dependencies
run: bun install
- name: Typecheck (Turbo)
run: bun run turbo:typecheck
- name: Privacy check
run: bun run privacy:check
- name: Quality checks (Turbo)
run: bun run turbo:check
- name: Tests (Turbo)
run: bun run turbo:test
- name: Build CLI
run: bun run build
- name: Build release smoke (no tests)
run: bun run build:release --skip-tests --no-clean --out=dist/release-ci
linux-process-lifetime:
runs-on: blacksmith-4vcpu-ubuntu-2404
steps:
- name: Checkout
uses: actions/checkout@v4
- name: Setup Bun
uses: oven-sh/setup-bun@v1
with:
bun-version: "1.4.2"
- name: Require native regression tools
run: |
command -v python3
command -v lsof
- name: Install dependencies
run: bun install --frozen-lockfile
- name: Run process and terminal regressions
run: bun test tests/daemon-command.test.ts tests/daemon-orphan.test.ts tests/host-exec-lifetime.test.ts tests/host-exec-tty.test.ts tests/shell-observation.test.ts