fix(release): validate candidate workflows and next push checks #510
Workflow file for this run
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
| name: CI | |
| on: | |
| push: | |
| branches: | |
| - main | |
| - next | |
| tags-ignore: | |
| - "v*" | |
| pull_request: | |
| jobs: | |
| state-models: | |
| name: Runtime state models | |
| runs-on: ubuntu-latest | |
| timeout-minutes: 5 | |
| permissions: | |
| contents: read | |
| steps: | |
| - uses: actions/checkout@v4 | |
| - uses: oven-sh/setup-bun@v1 | |
| with: | |
| bun-version: "1.4.2" | |
| - uses: actions/setup-java@v4 | |
| with: | |
| distribution: temurin | |
| java-version: "17" | |
| - uses: actions/setup-python@v5 | |
| with: | |
| python-version: "3.12" | |
| - name: Install mise for model-helper contract tests | |
| uses: jdx/mise-action@c2a87611a18de5b3828c5652fe268e992400cb5c # v4 | |
| with: | |
| version: "2026.9.12" | |
| install: false | |
| cache: false | |
| env: false | |
| - name: Validate release workflow syntax | |
| run: mise x actionlint@1.7.12 -- actionlint -shellcheck= -pyflakes= .github/workflows/ci.yml .github/workflows/release.yml .github/workflows/prerelease.yml | |
| - name: Fetch pinned model checker | |
| run: curl --fail --location --retry 2 --max-time 60 https://github.com/tlaplus/tlaplus/releases/download/v1.7.4/tla2tools.jar --output "$RUNNER_TEMP/tla2tools.jar" | |
| - name: Check evidence validation and models | |
| env: | |
| TLA2TOOLS_JAR: ${{ runner.temp }}/tla2tools.jar | |
| run: | | |
| python3 -m unittest discover -s .ai/skills/hack-repo-tla/tests | |
| bun test tests/tla-result.test.ts | |
| bun run test:models | |
| - name: Check prepared-base benchmark harness controls | |
| run: python3 -m unittest discover -s tests/python -p test_prepared_base_benchmark.py | |
| - name: Check native frontend acceptance controls | |
| run: python3 -m unittest discover -s tests/python -p test_native_frontend_acceptance.py | |
| runtime-core: | |
| name: Candidate core (${{ matrix.os }}) | |
| strategy: | |
| matrix: | |
| os: [ubuntu-latest, macos-latest] | |
| runs-on: ${{ matrix.os }} | |
| permissions: | |
| contents: read | |
| steps: | |
| - uses: actions/checkout@v4 | |
| - uses: dtolnay/rust-toolchain@1.97.1 | |
| with: | |
| components: rustfmt, clippy | |
| - name: Install pinned Zig for guest helpers | |
| uses: jdx/mise-action@c2a87611a18de5b3828c5652fe268e992400cb5c # v4 | |
| with: | |
| version: "2026.9.12" | |
| install_args: zig | |
| add_shims_to_path: false | |
| cache: false | |
| env: false | |
| - name: Check candidate formatting | |
| run: cargo fmt --manifest-path packages/runtime-core/Cargo.toml --check | |
| - name: Lint candidate core | |
| run: cargo clippy --locked --manifest-path packages/runtime-core/Cargo.toml --target-dir .hack-local/target --all-targets --jobs 2 -- -D warnings | |
| - name: Test candidate isolation contracts | |
| run: cargo test --locked --manifest-path packages/runtime-core/Cargo.toml --target-dir .hack-local/target --jobs 2 | |
| - name: Build and inspect local candidate | |
| run: | | |
| mise exec zig -- ./scripts/build-hack-local.sh | |
| ./hack-local info --json | |
| secret-scan: | |
| runs-on: blacksmith-4vcpu-ubuntu-2404 | |
| permissions: | |
| contents: read | |
| steps: | |
| - name: Checkout | |
| uses: actions/checkout@v4 | |
| with: | |
| fetch-depth: 0 | |
| - name: Install Gitleaks | |
| id: gitleaks | |
| uses: gacts/gitleaks@v1 | |
| with: | |
| version: 8.30.1 | |
| run: 'false' | |
| - name: Scan checked-out commit history | |
| env: | |
| GITLEAKS_BIN: ${{ steps.gitleaks.outputs.gitleaks-bin }} | |
| run: | | |
| "$GITLEAKS_BIN" git . \ | |
| --config .gitleaks.toml \ | |
| --redact \ | |
| --log-opts='--full-history --diff-filter=tuxdb HEAD' \ | |
| --report-format sarif \ | |
| --report-path "$RUNNER_TEMP/gitleaks.sarif" | |
| runtime-images: | |
| runs-on: blacksmith-4vcpu-ubuntu-2404 | |
| permissions: | |
| contents: read | |
| steps: | |
| - name: Checkout | |
| uses: actions/checkout@v4 | |
| - name: Setup Bun | |
| uses: oven-sh/setup-bun@v1 | |
| with: | |
| bun-version: "1.4.2" | |
| - name: Setup Blacksmith Builder | |
| uses: useblacksmith/setup-docker-builder@v1 | |
| - name: Install dependencies | |
| run: bun install | |
| - name: Build full runtime image | |
| run: | | |
| bun run scripts/build-node-runtime-image.ts \ | |
| --variant node-runtime \ | |
| --platform linux/amd64 \ | |
| --tag hack-runtime-ci:full | |
| - name: Smoke full runtime image | |
| run: | | |
| docker run --rm --entrypoint hack hack-runtime-ci:full --help >/tmp/hack-full-help.txt | |
| grep -q "hack" /tmp/hack-full-help.txt | |
| - name: Build slim runtime image | |
| run: | | |
| bun run scripts/build-node-runtime-image.ts \ | |
| --variant slim \ | |
| --platform linux/amd64 \ | |
| --tag hack-runtime-ci:slim | |
| - name: Smoke slim runtime image defaults | |
| run: | | |
| docker run --rm --entrypoint sh hack-runtime-ci:slim -lc 'command -v bun >/dev/null && command -v hack >/dev/null && test "${HACK_EXECUTION_MODE}" = "codex" && test "${HACK_DAEMON_DISABLE_DOCKER_EVENTS}" = "1" && hack --help >/tmp/hack-help.txt && grep -q "Usage:" /tmp/hack-help.txt' | |
| - name: Smoke slim runtime mounted-project env flow | |
| run: bash scripts/portable-container-smoke.sh hack-runtime-ci:slim linux/amd64 | |
| docker-e2e: | |
| runs-on: blacksmith-4vcpu-ubuntu-2404 | |
| permissions: | |
| contents: read | |
| steps: | |
| - name: Checkout | |
| uses: actions/checkout@v4 | |
| - name: Setup Bun | |
| uses: oven-sh/setup-bun@v1 | |
| with: | |
| bun-version: "1.4.2" | |
| - name: Install tmux | |
| run: sudo apt-get update && sudo apt-get install --yes tmux | |
| - name: Install dependencies | |
| run: bun install | |
| - name: Create isolated Hack network | |
| run: docker network create --subnet 172.30.0.0/16 hack-dev | |
| - name: Prepare offline cache fixture images | |
| run: | | |
| docker pull alpine:3.20 | |
| docker pull alpine:3.22 | |
| docker pull node:24.11.0-bookworm-slim | |
| - name: Run local and Docker E2E | |
| run: HACK_E2E_REQUIRE_DOCKER=1 HACK_E2E_REQUIRE_TMUX=1 bun run test:e2e:local:docker | |
| - name: Smoke container resource metadata without optional fields | |
| run: | | |
| probe_id=$(docker create --network none --read-only alpine:3.20 true) | |
| trap 'docker rm -f "$probe_id" >/dev/null' EXIT | |
| bun scripts/inspect-container-resources.ts --container "$probe_id" > "$RUNNER_TEMP/resource-probe.json" | |
| bun -e 'const r = await Bun.stdin.json(); if (r.probeStatus !== "not_running" || r.container.healthcheckIntervalNs !== null || r.container.writableLayerBytes !== null) throw new Error("Invalid optional resource metadata");' < "$RUNNER_TEMP/resource-probe.json" | |
| bun scripts/inspect-container-resources.ts --container "$probe_id" --storage > "$RUNNER_TEMP/resource-probe.json" | |
| bun -e 'const r = await Bun.stdin.json(); if (typeof r.container.writableLayerBytes !== "number") throw new Error("Missing writable-layer accounting");' < "$RUNNER_TEMP/resource-probe.json" | |
| test: | |
| runs-on: blacksmith-6vcpu-macos-15 | |
| steps: | |
| - name: Checkout | |
| uses: actions/checkout@v4 | |
| - name: Setup Bun | |
| uses: oven-sh/setup-bun@v1 | |
| with: | |
| bun-version: "1.4.2" | |
| - name: Install dependencies | |
| run: bun install | |
| - name: Typecheck (Turbo) | |
| run: bun run turbo:typecheck | |
| - name: Privacy check | |
| run: bun run privacy:check | |
| - name: Quality checks (Turbo) | |
| run: bun run turbo:check | |
| - name: Tests (Turbo) | |
| run: bun run turbo:test | |
| - name: Build CLI | |
| run: bun run build | |
| - name: Build release smoke (no tests) | |
| run: bun run build:release --skip-tests --no-clean --out=dist/release-ci | |
| linux-process-lifetime: | |
| runs-on: blacksmith-4vcpu-ubuntu-2404 | |
| steps: | |
| - name: Checkout | |
| uses: actions/checkout@v4 | |
| - name: Setup Bun | |
| uses: oven-sh/setup-bun@v1 | |
| with: | |
| bun-version: "1.4.2" | |
| - name: Require native regression tools | |
| run: | | |
| command -v python3 | |
| command -v lsof | |
| - name: Install dependencies | |
| run: bun install --frozen-lockfile | |
| - name: Run process and terminal regressions | |
| run: bun test tests/daemon-command.test.ts tests/daemon-orphan.test.ts tests/host-exec-lifetime.test.ts tests/host-exec-tty.test.ts tests/shell-observation.test.ts |