-
Notifications
You must be signed in to change notification settings - Fork 21
70 lines (63 loc) · 2.92 KB
/
Copy pathinstall-script.yml
File metadata and controls
70 lines (63 loc) · 2.92 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
# #3073 (operator rule 2026-09-10: no GitHub-hosted runners): runs on the
# clean-room pool like every other lightweight workflow (book.yml, etc.).
#
# Path-scoped to scripts/install.sh's own test suite (issue #3365) rather than
# folded into ci.yml's whole-repo job, because it does real network installs
# (a real stable release + a real nightly, per install_test.sh) and has no
# reason to run on every unrelated PR.
#
# Watches BOTH sides of the coupling, per book.yml's own documented lesson
# ("a parity gate must run when EITHER side moves; watching only one of them
# is how it comes to certify nothing", learned there the hard way twice):
# install.sh assumes a specific asset-naming shape from binary-release.yml
# (stable: apr-vX.Y.Z-<target>-<cpu|cuda>.tar.gz) and nightly.yml (nightly:
# apr-<target>.tar.gz, no variant suffix). A rename in either workflow breaks
# install.sh without a single line of install.sh itself changing.
name: apr install.sh
on:
push:
branches: [main]
paths:
- "scripts/install.sh"
- "scripts/tests/install_test.sh"
- ".github/workflows/install-script.yml"
- ".github/workflows/binary-release.yml"
- ".github/workflows/nightly.yml"
pull_request:
paths:
- "scripts/install.sh"
- "scripts/tests/install_test.sh"
- ".github/workflows/install-script.yml"
- ".github/workflows/binary-release.yml"
- ".github/workflows/nightly.yml"
# #3676 rule 3 (scripts/check_workflow_path_filters.sh): a path filter is a
# claim that nothing outside these paths can break this gate; the nightly run
# re-checks the claim every day. Set ~5h early for the dispatch delay (#3292).
schedule:
- cron: '0 23 * * *'
permissions:
contents: read
jobs:
test:
name: install_test.sh
runs-on: [self-hosted, Linux, X64, clean-room]
steps:
- uses: actions/checkout@v7
# pmat/bashrs are pinned-fleet tools, never installed per-job (BSE-10a,
# PMAT-1066) — see ci.yml's identical step for why.
- name: pmat/bashrs must match the pinned fleet versions (never install)
run: setsid --wait bash scripts/check_tool_versions.sh
- name: "bashrs SEC/DET/IDEM (scripts/install.sh, scripts/tests/install_test.sh)"
run: |
bashrs lint --level error scripts/install.sh
bashrs lint --level error scripts/tests/install_test.sh
# Proves install_test.sh's own mutual-exclusivity row discriminates
# before trusting the full run below — same discipline as
# check_bashrs_gate.sh --self-test in ci.yml.
- name: install_test.sh --self-test
run: bash scripts/tests/install_test.sh --self-test
# Full suite: real downloads from paiml/aprender's actual latest stable
# release and the nightly prerelease. This is deliberately not mocked —
# it is the same contract a user's `curl | sh` exercises.
- name: install_test.sh
run: bash scripts/tests/install_test.sh