diff --git a/.github-gen/velnor-workflow.toml b/.github-gen/velnor-workflow.toml index e3072ab..95a0a7e 100644 --- a/.github-gen/velnor-workflow.toml +++ b/.github-gen/velnor-workflow.toml @@ -6,33 +6,8 @@ revision = "e05aee6de1d1614d752b4d1b1d26a49ac2c5ef91" [workflow] runners = "both" -automatic = "both" -default_dispatch_runner = "github" automatic_lanes = "github" +default_dispatch_runner = "github" github_runner = "ubuntu-24.04" velnor_labels = ["self-hosted", "velnor-target-mvp"] default_branch = "main" - -[release] -enabled = true -reason = "Publish signed ruxel CLI archives and update the Homebrew tap." -kind = "rust-binary" -package = "ruxel-cli" -binary = "ruxel" -targets = [ - "aarch64-apple-darwin", - "x86_64-apple-darwin", - "aarch64-unknown-linux-gnu", - "x86_64-unknown-linux-gnu", -] -source_repository = "tailrocks/ruxel" - -[[declare]] -primitive = "release" -file = "release.yml" - -[[declare]] -primitive = "preview" -file = "preview.yml" - -# Note: rust-toolchain.toml targets are patched in the migration branch to match release targets. diff --git a/.github/actionlint.yaml b/.github/actionlint.yaml index 6db0ced..62587bd 100644 --- a/.github/actionlint.yaml +++ b/.github/actionlint.yaml @@ -4,7 +4,6 @@ self-hosted-runner: labels: - - macos-15 - self-hosted - ubuntu-24.04 - velnor-target-mvp diff --git a/.github/ci/.github-actions-generator-state b/.github/ci/.github-actions-generator-state index 287ece8..f740a09 100644 --- a/.github/ci/.github-actions-generator-state +++ b/.github/ci/.github-actions-generator-state @@ -1,12 +1,12 @@ # Generated ownership state; do not edit. schema = 2 [inputs] -config 04fe5ecdd1abff0e +config 4b2710c1154efb7d scan 73483f0bc233ebc4 generator 47 [outputs] -.github/actionlint.yaml b75eef6f28137009 -.github/ci/project.toml 37e1b1997575fa0d +.github/actionlint.yaml ec35f48ae7e90e0e +.github/ci/project.toml a0c5060b9b02e82b .github/workflows/ci-main.yml 537e2660324fc9cb .github/workflows/ci-policy.yml 679740121455a70d .github/workflows/ci-pr.yml c03fdd762bebc144 @@ -14,6 +14,4 @@ generator 47 .github/workflows/ci-unit-rust.yml c8f0cbd26e1ceb67 .github/workflows/maintenance.yml dd8712190b92c173 .github/workflows/nightly.yml 76e5e2bc12a599c6 -.github/workflows/preview.yml 98ef034306370cf6 -.github/workflows/release.yml 8fae2b06e584218a config/fleet/velnor-host.env d14b419216449423 diff --git a/.github/ci/project.toml b/.github/ci/project.toml index b813c52..844d5f1 100644 --- a/.github/ci/project.toml +++ b/.github/ci/project.toml @@ -14,18 +14,12 @@ limitations = ["Project code, build scripts, task runners, and commands are neve [workflow] github_runner = "ubuntu-24.04" velnor_labels = ["self-hosted", "velnor-target-mvp"] -files = ["ci-main.yml", "ci-policy.yml", "ci-pr.yml", "ci-unit-docker.yml", "ci-unit-rust.yml", "maintenance.yml", "nightly.yml", "preview.yml", "release.yml"] +files = ["ci-main.yml", "ci-policy.yml", "ci-pr.yml", "ci-unit-docker.yml", "ci-unit-rust.yml", "maintenance.yml", "nightly.yml"] notes = ["Rust verification uses Mr. Boxington 1.11.1 by default on both lanes. GitHub-hosted jobs use its GitHub cache backend with bounded snapshot keys (a key names the toolchain/image/linker compatibility class and the hashed source state, so a new source state saves a new snapshot and retention keeps generations bounded). Velnor jobs use an explicit local-backend setup step against the image/runner-provided local store."] [release] -enabled = true -reason = "Publish signed ruxel CLI archives and update the Homebrew tap." -kind = "rust-binary" -package = "ruxel-cli" -packages = [] -binary = "ruxel" -targets = ["aarch64-apple-darwin", "x86_64-apple-darwin", "aarch64-unknown-linux-gnu", "x86_64-unknown-linux-gnu"] -source_repository = "tailrocks/ruxel" +enabled = false +reason = "Release is fail-closed. Enable only after declaring immutable artifact, registry, provenance, and tag-protection policy." [[unit]] id = "docker-tools-fixtures-docker" diff --git a/.github/workflows/preview.yml b/.github/workflows/preview.yml deleted file mode 100644 index 6e7eb10..0000000 --- a/.github/workflows/preview.yml +++ /dev/null @@ -1,179 +0,0 @@ -# Generated by velnor-workflow. Regenerate; do not hand-edit. -name: Preview -run-name: Preview · ${{ github.event_name }} · ${{ github.ref_name }} - -on: - push: - branches: [main] - paths: - - ".cargo/**" - - ".cargo/audit.toml" - - ".cargo/deny.toml" - - ".github/ci/**" - - ".github/workflows/preview.yml" - - Cargo.lock - - Cargo.toml - - audit.toml - - "crates/ruxel-agent/**/*.rs" - - "crates/ruxel-agent/Cargo.toml" - - "crates/ruxel-agent/benches/**" - - "crates/ruxel-agent/examples/**" - - "crates/ruxel-agent/src/**" - - "crates/ruxel-agent/tests/**" - - "crates/ruxel-core/**/*.rs" - - "crates/ruxel-core/Cargo.toml" - - "crates/ruxel-core/benches/**" - - "crates/ruxel-core/examples/**" - - "crates/ruxel-core/src/**" - - "crates/ruxel-core/tests/**" - - "crates/ruxel-proto/**/*.rs" - - "crates/ruxel-proto/Cargo.toml" - - "crates/ruxel-proto/benches/**" - - "crates/ruxel-proto/build.rs" - - "crates/ruxel-proto/examples/**" - - "crates/ruxel-proto/src/**" - - "crates/ruxel-proto/tests/**" - - "crates/ruxel/**/*.rs" - - "crates/ruxel/Cargo.toml" - - "crates/ruxel/benches/**" - - "crates/ruxel/build.rs" - - "crates/ruxel/examples/**" - - "crates/ruxel/src/**" - - "crates/ruxel/tests/**" - - deny.toml - - mise.lock - - mise.toml - - rust-toolchain - - rust-toolchain.toml - - "tools/fixtures/docker/**" - - "tools/spec-extract/**/*.rs" - - "tools/spec-extract/Cargo.toml" - - "tools/spec-extract/benches/**" - - "tools/spec-extract/examples/**" - - "tools/spec-extract/src/**" - - "tools/spec-extract/tests/**" - workflow_dispatch: - -concurrency: - group: preview-${{ github.repository }} - cancel-in-progress: true - -permissions: - contents: read - id-token: write - attestations: write - -jobs: - build: - name: Preview / ${{ matrix.target }} - runs-on: ${{ matrix.runner }} - if: ${{ (github.event_name == 'push' && (github.ref_type == 'tag' || github.ref == 'refs/heads/main')) || github.event_name == 'schedule' || (github.event_name == 'workflow_dispatch' && github.ref == 'refs/heads/main') }} - timeout-minutes: 75 - strategy: - fail-fast: false - matrix: - include: - - target: aarch64-apple-darwin - lane: github - runner: macos-15 - - target: x86_64-apple-darwin - lane: github - runner: macos-15 - - target: aarch64-unknown-linux-gnu - lane: github - runner: ubuntu-24.04 - - target: x86_64-unknown-linux-gnu - lane: github - runner: ubuntu-24.04 - steps: - - name: Checkout - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 - with: - fetch-depth: 0 - persist-credentials: false - - name: Set up Velnor workflow runtime - if: ${{ runner.environment == 'github-hosted' }} - uses: tailrocks/velnor/.github/actions/setup-velnor-workflow@e05aee6de1d1614d752b4d1b1d26a49ac2c5ef91 - with: - rev: e05aee6de1d1614d752b4d1b1d26a49ac2c5ef91 - - name: Set trusted workflow policy revision - run: echo "VELNOR_WORKFLOW_POLICY_REVISION=e05aee6de1d1614d752b4d1b1d26a49ac2c5ef91" >> "$GITHUB_ENV" - - name: Enforce workflow policy - env: - EVENT_NAME: ${{ github.event_name }} - run: velnor-workflow policy --workflow-root "$GITHUB_WORKSPACE" - - name: Restore Rust toolchain - id: rustup-toolchain - uses: actions/cache/restore@55cc8345863c7cc4c66a329aec7e433d2d1c52a9 # v6.1.0 - with: - path: | - ~/.rustup - key: velnor-rustup-${{ runner.os }}-${{ runner.arch }}-${{ hashFiles('rust-toolchain.toml', 'rust-toolchain') }} - - name: Provision Rust toolchain - shell: bash - run: | - set -euo pipefail - rustup toolchain install - rustup target add 'x86_64-unknown-linux-musl' 'aarch64-apple-darwin' 'x86_64-apple-darwin' 'aarch64-unknown-linux-gnu' 'x86_64-unknown-linux-gnu' - - name: Save Rust toolchain - if: github.event_name == 'push' && github.ref == 'refs/heads/main' && steps.rustup-toolchain.outputs.cache-hit != 'true' - uses: actions/cache/save@55cc8345863c7cc4c66a329aec7e433d2d1c52a9 # v6.1.0 - with: - path: | - ~/.rustup - key: velnor-rustup-${{ runner.os }}-${{ runner.arch }}-${{ hashFiles('rust-toolchain.toml', 'rust-toolchain') }} - - name: Set up sccache - uses: mozilla-actions/sccache-action@fc920bf0ec8de6ee65d409111f7ec508035751ba # v0.0.11 - with: - version: v0.16.0 - - name: Add Rust target - run: rustup target add "${{ matrix.target }}" - - name: Build preview binary - env: - CARGO_INCREMENTAL: "0" - RUSTC_WRAPPER: sccache - run: mbx build --locked --release --package ruxel-cli --bin ruxel --target "${{ matrix.target }}" - - name: Package preview binary - run: velnor-workflow release package-binary --target "${{ matrix.target }}" --version preview --package ruxel-cli --binary ruxel - - name: Attest preview artifact - uses: actions/attest-build-provenance@4d101475d8b20a2381f78447822ac1eab6504dd8 # v4.2.2 - with: - subject-path: dist/*.tar.gz - - name: Upload preview artifact - uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1 - with: - name: ${{ matrix.lane }}-${{ matrix.target }} - path: dist/* - if-no-files-found: error - retention-days: 1 - - publish: - name: Publish rolling preview - needs: build - if: ${{ github.event_name == 'push' && github.ref == 'refs/heads/main' }} - runs-on: ubuntu-24.04 - timeout-minutes: 15 - environment: github-preview - permissions: - contents: write - steps: - - name: Download preview artifacts - uses: actions/download-artifact@3e5f45b2cfb9172054b4087a40e8e0b5a5461e7c # v8.0.1 - with: - path: dist - pattern: github-* - merge-multiple: true - - name: Verify preview provenance - env: - GH_TOKEN: ${{ github.token }} - run: | - set -euo pipefail - for artifact in dist/*.tar.gz; do gh attestation verify "$artifact" --repo "$GITHUB_REPOSITORY"; done - - name: Replace rolling preview - env: - GH_TOKEN: ${{ github.token }} - run: | - set -euo pipefail - gh release view preview >/dev/null 2>&1 || gh release create preview --prerelease --title "Rolling preview" - gh release edit preview --target "${{ github.sha }}" --prerelease - gh release upload preview dist/* --clobber diff --git a/.github/workflows/release.yml b/.github/workflows/release.yml deleted file mode 100644 index 45529f6..0000000 --- a/.github/workflows/release.yml +++ /dev/null @@ -1,1286 +0,0 @@ -# Generated by velnor-workflow. Regenerate; do not hand-edit. -name: Release -run-name: Release · ${{ github.ref_name }} - -on: - push: - tags: ["v*"] - -concurrency: - group: release-${{ github.ref }} - cancel-in-progress: false - -permissions: - contents: read - -jobs: - verify: - name: Control / Verify release - runs-on: ubuntu-24.04 - timeout-minutes: 60 - steps: - - name: Checkout - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 - with: - fetch-depth: 0 - persist-credentials: false - - name: Set up Velnor workflow runtime - if: ${{ runner.environment == 'github-hosted' }} - uses: tailrocks/velnor/.github/actions/setup-velnor-workflow@e05aee6de1d1614d752b4d1b1d26a49ac2c5ef91 - with: - rev: e05aee6de1d1614d752b4d1b1d26a49ac2c5ef91 - - name: Set trusted workflow policy revision - run: echo "VELNOR_WORKFLOW_POLICY_REVISION=e05aee6de1d1614d752b4d1b1d26a49ac2c5ef91" >> "$GITHUB_ENV" - - name: Enforce workflow policy - env: - EVENT_NAME: ${{ github.event_name }} - run: velnor-workflow policy --workflow-root "$GITHUB_WORKSPACE" - - name: Set up sccache - uses: mozilla-actions/sccache-action@fc920bf0ec8de6ee65d409111f7ec508035751ba # v0.0.11 - with: - version: v0.16.0 - - name: Verify tag - run: velnor-workflow release verify-tag --branch 'main' --package 'ruxel-cli' - - - release-github-docker-tools-fixtures-docker: - name: "GitHub / Docker / docker-tools-fixtures-docker" - needs: [verify] - runs-on: ubuntu-24.04 - timeout-minutes: 60 - steps: - - name: Checkout - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 - with: - persist-credentials: false - - name: Set up Velnor workflow runtime - if: ${{ runner.environment == 'github-hosted' }} - uses: tailrocks/velnor/.github/actions/setup-velnor-workflow@e05aee6de1d1614d752b4d1b1d26a49ac2c5ef91 - with: - rev: e05aee6de1d1614d752b4d1b1d26a49ac2c5ef91 - - name: Set trusted workflow policy revision - run: echo "VELNOR_WORKFLOW_POLICY_REVISION=e05aee6de1d1614d752b4d1b1d26a49ac2c5ef91" >> "$GITHUB_ENV" - - name: Expose GitHub Actions runtime - uses: crazy-max/ghaction-github-runtime@04d248b84655b509d8c44dc1d6f990c879747487 # v4.0.0 - - name: Set up Docker Buildx - uses: docker/setup-buildx-action@37fe631027851001ddb9b187196cc803df7f5f0e # v4.3.0 - - name: Run "Docker (tools/fixtures/docker)" checks - env: - CI_SCOPE: full - CI_UNIT_ID: docker-tools-fixtures-docker - EVENT_NAME: ${{ github.event_name }} - HEAD_SHA: ${{ github.sha }} - MISE_AUTO_INSTALL: "false" - MISE_EXEC_AUTO_INSTALL: "false" - MISE_NOT_FOUND_AUTO_INSTALL: "false" - run: velnor-workflow run --config .github/ci/project.toml --scope "$CI_SCOPE" --unit docker-tools-fixtures-docker - - release-github-rust-policy: - name: "GitHub / Rust / rust-policy" - needs: [verify] - runs-on: ubuntu-24.04 - timeout-minutes: 60 - steps: - - name: Checkout - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 - with: - persist-credentials: false - - name: Set up Velnor workflow runtime - if: ${{ runner.environment == 'github-hosted' }} - uses: tailrocks/velnor/.github/actions/setup-velnor-workflow@e05aee6de1d1614d752b4d1b1d26a49ac2c5ef91 - with: - rev: e05aee6de1d1614d752b4d1b1d26a49ac2c5ef91 - - name: Set trusted workflow policy revision - run: echo "VELNOR_WORKFLOW_POLICY_REVISION=e05aee6de1d1614d752b4d1b1d26a49ac2c5ef91" >> "$GITHUB_ENV" - - name: Restore Rust toolchain - id: rustup-toolchain - uses: actions/cache/restore@55cc8345863c7cc4c66a329aec7e433d2d1c52a9 # v6.1.0 - with: - path: | - ~/.rustup - key: velnor-rustup-${{ runner.os }}-${{ runner.arch }}-${{ hashFiles('rust-toolchain.toml', 'rust-toolchain') }} - - name: Provision Rust toolchain - shell: bash - run: | - set -euo pipefail - rustup toolchain install - rustup target add 'x86_64-unknown-linux-musl' 'aarch64-apple-darwin' 'x86_64-apple-darwin' 'aarch64-unknown-linux-gnu' 'x86_64-unknown-linux-gnu' - - name: Bound the Mr. Boxington store - shell: bash - run: echo "MBX_GC_MAX_SIZE=12GiB" >> "$GITHUB_ENV" - - name: Set up Mr. Boxington - id: mbx-cache - uses: jdx/mr-boxington-action@7234d3dd1a6ca8f6c381eea8e4dfb03f18fcf777 # v1.3.0 - with: - backend: github - github-cache-mode: objects - version: 1.11.1 - cache-key: velnor-mbx-v3-db4503222bd1-${{ runner.os }}-${{ runner.arch }}-rust-policy-${{ hashFiles('.cargo/**', 'Cargo.lock', 'deny.toml') }}-${{ hashFiles('.cargo/audit.toml', '.cargo/deny.toml', 'Cargo.lock', 'audit.toml', 'deny.toml') }} - restore-keys: | - velnor-mbx-v3-db4503222bd1-${{ runner.os }}-${{ runner.arch }}-rust-policy-${{ hashFiles('.cargo/**', 'Cargo.lock', 'deny.toml') }}- - velnor-mbx-v3-db4503222bd1-${{ runner.os }}-${{ runner.arch }}-rust-policy- - save-on-workflow-dispatch: true - - name: Restore cargo bin toolchain - id: cargo-bin-toolchain - uses: actions/cache/restore@55cc8345863c7cc4c66a329aec7e433d2d1c52a9 # v6.1.0 - with: - path: ~/.cargo/bin - key: velnor-cargo-bin-v2-${{ runner.os }}-${{ runner.arch }}-${{ hashFiles('mise.lock', 'mise.toml') }} - - name: Verify cargo bin tools - if: ${{ steps.cargo-bin-toolchain.outputs.cache-hit == 'true' }} - id: cargo-bin-verify - shell: bash - env: - CARGO_BIN_TOOLS: cargo-deny - run: | - set -euo pipefail - missing=0 - IFS=',' read -ra tools <<< "$CARGO_BIN_TOOLS" - for tool in "${tools[@]}"; do - tool="${tool#"${tool%%[![:space:]]*}"}" - tool="${tool%"${tool##*[![:space:]]}"}" - [[ -z "$tool" ]] && continue - if ! command -v "$tool" >/dev/null; then - missing=1 - break - fi - if ! "$tool" --version >/dev/null 2>&1; then - missing=1 - break - fi - if [[ "$tool" == cargo-* ]]; then - subcommand="${tool#cargo-}" - if ! cargo "$subcommand" --version >/dev/null 2>&1; then - missing=1 - break - fi - fi - done - echo "missing=$missing" >> "$GITHUB_OUTPUT" - - name: Set up cargo bin tools - if: ${{ steps.cargo-bin-toolchain.outputs.cache-hit != 'true' || steps.cargo-bin-verify.outputs.missing == 'true' }} - uses: taiki-e/install-action@0758d235715de2f3551eacc980d9ae8fce9342c3 # v2.87.3 - with: - tool: cargo-deny - fallback: none - - name: Restore mold 2.42.0 cache - id: mold-cache - uses: actions/cache/restore@55cc8345863c7cc4c66a329aec7e433d2d1c52a9 # v6.1.0 - with: - path: ~/.cache/velnor/mold/2.42.0 - key: velnor-mold-2.42.0-${{ runner.os }}-${{ runner.arch }} - - name: Set up mold 2.42.0 - shell: bash - env: - MOLD_VERSION: 2.42.0 - run: | - set -euo pipefail - case "$(uname -m)" in - x86_64) mold_arch=x86_64; expected='f5ed2f6e31d1ada4f07fe766fe0de7a73104d1c5cdc59086fcecc16a43720b6d' ;; - aarch64) mold_arch=aarch64; expected='3c9a0a3624aac8a2007569ae50c33b3129a0f0ae8bcc974aeee2f8939d295190' ;; - *) echo "unsupported mold architecture: $(uname -m)" >&2; exit 1 ;; - esac - cache_dir="$HOME/.cache/velnor/mold/$MOLD_VERSION" - archive="$cache_dir/mold-$MOLD_VERSION-$mold_arch-linux.tar.gz" - mkdir -p "$cache_dir" - if [[ ! -s "$archive" ]]; then - temporary="$archive.download" - trap 'rm -f "$temporary"' EXIT - curl --fail --silent --show-error --location --retry 3 --retry-delay 2 \ - --output "$temporary" \ - "https://github.com/rui314/mold/releases/download/v$MOLD_VERSION/mold-$MOLD_VERSION-$mold_arch-linux.tar.gz" - printf '%s %s\n' "$expected" "$temporary" | sha256sum --check --strict - mv "$temporary" "$archive" - trap - EXIT - fi - printf '%s %s\n' "$expected" "$archive" | sha256sum --check --strict - if [[ "$(id -u)" -eq 0 ]]; then - tar --directory /usr/local --strip-components=1 --no-overwrite-dir -xzf "$archive" - ln -sf /usr/local/bin/mold "$(realpath /usr/bin/ld 2>/dev/null || printf /usr/bin/ld)" - else - sudo tar --directory /usr/local --strip-components=1 --no-overwrite-dir -xzf "$archive" - sudo ln -sf /usr/local/bin/mold "$(realpath /usr/bin/ld 2>/dev/null || printf /usr/bin/ld)" - fi - mold --version | grep -F "$MOLD_VERSION" - - name: Restore "Rust dependency policy" cache - id: cache - uses: actions/cache/restore@55cc8345863c7cc4c66a329aec7e433d2d1c52a9 # v6.1.0 - with: - path: | - ~/.cargo/registry - ~/.cargo/git - key: ci-release-${{ runner.os }}-rust-policy-${{ hashFiles('.cargo/**', 'Cargo.lock', 'deny.toml') }} - - name: Run "Rust dependency policy" checks - env: - CI_SCOPE: full - CI_UNIT_ID: rust-policy - EVENT_NAME: ${{ github.event_name }} - HEAD_SHA: ${{ github.sha }} - MISE_AUTO_INSTALL: "false" - MISE_EXEC_AUTO_INSTALL: "false" - MISE_NOT_FOUND_AUTO_INSTALL: "false" - run: velnor-workflow run --config .github/ci/project.toml --scope "$CI_SCOPE" --unit rust-policy - - release-github-rust-ruxel-agent: - name: "GitHub / Rust / rust-ruxel-agent" - needs: [verify, release-github-rust-ruxel-core, release-github-rust-ruxel-proto] - runs-on: ubuntu-24.04 - timeout-minutes: 60 - steps: - - name: Checkout - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 - with: - persist-credentials: false - - name: Set up Velnor workflow runtime - if: ${{ runner.environment == 'github-hosted' }} - uses: tailrocks/velnor/.github/actions/setup-velnor-workflow@e05aee6de1d1614d752b4d1b1d26a49ac2c5ef91 - with: - rev: e05aee6de1d1614d752b4d1b1d26a49ac2c5ef91 - - name: Set trusted workflow policy revision - run: echo "VELNOR_WORKFLOW_POLICY_REVISION=e05aee6de1d1614d752b4d1b1d26a49ac2c5ef91" >> "$GITHUB_ENV" - - name: Restore Rust toolchain - id: rustup-toolchain - uses: actions/cache/restore@55cc8345863c7cc4c66a329aec7e433d2d1c52a9 # v6.1.0 - with: - path: | - ~/.rustup - key: velnor-rustup-${{ runner.os }}-${{ runner.arch }}-${{ hashFiles('rust-toolchain.toml', 'rust-toolchain') }} - - name: Provision Rust toolchain - shell: bash - run: | - set -euo pipefail - rustup toolchain install - rustup target add 'x86_64-unknown-linux-musl' 'aarch64-apple-darwin' 'x86_64-apple-darwin' 'aarch64-unknown-linux-gnu' 'x86_64-unknown-linux-gnu' - - name: Bound the Mr. Boxington store - shell: bash - run: echo "MBX_GC_MAX_SIZE=12GiB" >> "$GITHUB_ENV" - - name: Set up Mr. Boxington - id: mbx-cache - uses: jdx/mr-boxington-action@7234d3dd1a6ca8f6c381eea8e4dfb03f18fcf777 # v1.3.0 - with: - backend: github - github-cache-mode: objects - version: 1.11.1 - cache-key: velnor-mbx-v3-e77e749f2fa1-${{ runner.os }}-${{ runner.arch }}-rust-ruxel-agent-${{ hashFiles('.cargo/**', 'Cargo.lock', 'rust-toolchain', 'rust-toolchain.toml') }}-${{ hashFiles('crates/ruxel-agent/**/*.rs', 'crates/ruxel-agent/benches/**', 'crates/ruxel-agent/examples/**', 'crates/ruxel-agent/src/**', 'crates/ruxel-agent/tests/**', 'crates/ruxel-core/**/*.rs', 'crates/ruxel-core/benches/**', 'crates/ruxel-core/examples/**', 'crates/ruxel-core/src/**', 'crates/ruxel-core/tests/**', 'crates/ruxel-proto/**/*.rs', 'crates/ruxel-proto/benches/**', 'crates/ruxel-proto/build.rs', 'crates/ruxel-proto/examples/**', 'crates/ruxel-proto/src/**', 'crates/ruxel-proto/tests/**', 'mise.lock') }} - restore-keys: | - velnor-mbx-v3-e77e749f2fa1-${{ runner.os }}-${{ runner.arch }}-rust-ruxel-agent-${{ hashFiles('.cargo/**', 'Cargo.lock', 'rust-toolchain', 'rust-toolchain.toml') }}- - velnor-mbx-v3-e77e749f2fa1-${{ runner.os }}-${{ runner.arch }}-rust-ruxel-agent- - save-on-workflow-dispatch: true - - name: Restore mold 2.42.0 cache - id: mold-cache - uses: actions/cache/restore@55cc8345863c7cc4c66a329aec7e433d2d1c52a9 # v6.1.0 - with: - path: ~/.cache/velnor/mold/2.42.0 - key: velnor-mold-2.42.0-${{ runner.os }}-${{ runner.arch }} - - name: Set up mold 2.42.0 - shell: bash - env: - MOLD_VERSION: 2.42.0 - run: | - set -euo pipefail - case "$(uname -m)" in - x86_64) mold_arch=x86_64; expected='f5ed2f6e31d1ada4f07fe766fe0de7a73104d1c5cdc59086fcecc16a43720b6d' ;; - aarch64) mold_arch=aarch64; expected='3c9a0a3624aac8a2007569ae50c33b3129a0f0ae8bcc974aeee2f8939d295190' ;; - *) echo "unsupported mold architecture: $(uname -m)" >&2; exit 1 ;; - esac - cache_dir="$HOME/.cache/velnor/mold/$MOLD_VERSION" - archive="$cache_dir/mold-$MOLD_VERSION-$mold_arch-linux.tar.gz" - mkdir -p "$cache_dir" - if [[ ! -s "$archive" ]]; then - temporary="$archive.download" - trap 'rm -f "$temporary"' EXIT - curl --fail --silent --show-error --location --retry 3 --retry-delay 2 \ - --output "$temporary" \ - "https://github.com/rui314/mold/releases/download/v$MOLD_VERSION/mold-$MOLD_VERSION-$mold_arch-linux.tar.gz" - printf '%s %s\n' "$expected" "$temporary" | sha256sum --check --strict - mv "$temporary" "$archive" - trap - EXIT - fi - printf '%s %s\n' "$expected" "$archive" | sha256sum --check --strict - if [[ "$(id -u)" -eq 0 ]]; then - tar --directory /usr/local --strip-components=1 --no-overwrite-dir -xzf "$archive" - ln -sf /usr/local/bin/mold "$(realpath /usr/bin/ld 2>/dev/null || printf /usr/bin/ld)" - else - sudo tar --directory /usr/local --strip-components=1 --no-overwrite-dir -xzf "$archive" - sudo ln -sf /usr/local/bin/mold "$(realpath /usr/bin/ld 2>/dev/null || printf /usr/bin/ld)" - fi - mold --version | grep -F "$MOLD_VERSION" - - name: Restore "Rust crate (ruxel-agent)" cache - id: cache - uses: actions/cache/restore@55cc8345863c7cc4c66a329aec7e433d2d1c52a9 # v6.1.0 - with: - path: | - ~/.cargo/registry - ~/.cargo/git - key: ci-release-${{ runner.os }}-rust-ruxel-agent-${{ hashFiles('.cargo/**', 'Cargo.lock', 'rust-toolchain.toml', 'rust-toolchain') }} - - name: Prepare Cargo sources - if: ${{ steps.cache.outputs.cache-hit != 'true' }} - env: - MISE_AUTO_INSTALL: "false" - MISE_EXEC_AUTO_INSTALL: "false" - MISE_NOT_FOUND_AUTO_INSTALL: "false" - run: | - set -euo pipefail - root='crates/ruxel-agent' - if [[ "$root" != "." ]]; then - cd -- "$root" - fi - cargo fetch --locked - - name: Run "Rust crate (ruxel-agent)" checks - env: - CI_SCOPE: full - CI_UNIT_ID: rust-ruxel-agent - EVENT_NAME: ${{ github.event_name }} - HEAD_SHA: ${{ github.sha }} - CARGO_NET_OFFLINE: "true" - MISE_AUTO_INSTALL: "false" - MISE_EXEC_AUTO_INSTALL: "false" - MISE_NOT_FOUND_AUTO_INSTALL: "false" - run: velnor-workflow run --config .github/ci/project.toml --scope "$CI_SCOPE" --unit rust-ruxel-agent - - release-github-rust-ruxel-cli: - name: "GitHub / Rust / rust-ruxel-cli" - needs: [verify, release-github-rust-ruxel-core, release-github-rust-ruxel-proto] - runs-on: ubuntu-24.04 - timeout-minutes: 60 - steps: - - name: Checkout - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 - with: - persist-credentials: false - - name: Set up Velnor workflow runtime - if: ${{ runner.environment == 'github-hosted' }} - uses: tailrocks/velnor/.github/actions/setup-velnor-workflow@e05aee6de1d1614d752b4d1b1d26a49ac2c5ef91 - with: - rev: e05aee6de1d1614d752b4d1b1d26a49ac2c5ef91 - - name: Set trusted workflow policy revision - run: echo "VELNOR_WORKFLOW_POLICY_REVISION=e05aee6de1d1614d752b4d1b1d26a49ac2c5ef91" >> "$GITHUB_ENV" - - name: Restore Rust toolchain - id: rustup-toolchain - uses: actions/cache/restore@55cc8345863c7cc4c66a329aec7e433d2d1c52a9 # v6.1.0 - with: - path: | - ~/.rustup - key: velnor-rustup-${{ runner.os }}-${{ runner.arch }}-${{ hashFiles('rust-toolchain.toml', 'rust-toolchain') }} - - name: Provision Rust toolchain - shell: bash - run: | - set -euo pipefail - rustup toolchain install - rustup target add 'x86_64-unknown-linux-musl' 'aarch64-apple-darwin' 'x86_64-apple-darwin' 'aarch64-unknown-linux-gnu' 'x86_64-unknown-linux-gnu' - - name: Bound the Mr. Boxington store - shell: bash - run: echo "MBX_GC_MAX_SIZE=12GiB" >> "$GITHUB_ENV" - - name: Set up Mr. Boxington - id: mbx-cache - uses: jdx/mr-boxington-action@7234d3dd1a6ca8f6c381eea8e4dfb03f18fcf777 # v1.3.0 - with: - backend: github - github-cache-mode: objects - version: 1.11.1 - cache-key: velnor-mbx-v3-c86d78a667f8-${{ runner.os }}-${{ runner.arch }}-rust-ruxel-cli-${{ hashFiles('.cargo/**', 'Cargo.lock', 'rust-toolchain', 'rust-toolchain.toml') }}-${{ hashFiles('crates/ruxel-core/**/*.rs', 'crates/ruxel-core/benches/**', 'crates/ruxel-core/examples/**', 'crates/ruxel-core/src/**', 'crates/ruxel-core/tests/**', 'crates/ruxel-proto/**/*.rs', 'crates/ruxel-proto/benches/**', 'crates/ruxel-proto/build.rs', 'crates/ruxel-proto/examples/**', 'crates/ruxel-proto/src/**', 'crates/ruxel-proto/tests/**', 'crates/ruxel/**/*.rs', 'crates/ruxel/benches/**', 'crates/ruxel/build.rs', 'crates/ruxel/examples/**', 'crates/ruxel/src/**', 'crates/ruxel/tests/**', 'mise.lock') }} - restore-keys: | - velnor-mbx-v3-c86d78a667f8-${{ runner.os }}-${{ runner.arch }}-rust-ruxel-cli-${{ hashFiles('.cargo/**', 'Cargo.lock', 'rust-toolchain', 'rust-toolchain.toml') }}- - velnor-mbx-v3-c86d78a667f8-${{ runner.os }}-${{ runner.arch }}-rust-ruxel-cli- - save-on-workflow-dispatch: true - - name: Restore mold 2.42.0 cache - id: mold-cache - uses: actions/cache/restore@55cc8345863c7cc4c66a329aec7e433d2d1c52a9 # v6.1.0 - with: - path: ~/.cache/velnor/mold/2.42.0 - key: velnor-mold-2.42.0-${{ runner.os }}-${{ runner.arch }} - - name: Set up mold 2.42.0 - shell: bash - env: - MOLD_VERSION: 2.42.0 - run: | - set -euo pipefail - case "$(uname -m)" in - x86_64) mold_arch=x86_64; expected='f5ed2f6e31d1ada4f07fe766fe0de7a73104d1c5cdc59086fcecc16a43720b6d' ;; - aarch64) mold_arch=aarch64; expected='3c9a0a3624aac8a2007569ae50c33b3129a0f0ae8bcc974aeee2f8939d295190' ;; - *) echo "unsupported mold architecture: $(uname -m)" >&2; exit 1 ;; - esac - cache_dir="$HOME/.cache/velnor/mold/$MOLD_VERSION" - archive="$cache_dir/mold-$MOLD_VERSION-$mold_arch-linux.tar.gz" - mkdir -p "$cache_dir" - if [[ ! -s "$archive" ]]; then - temporary="$archive.download" - trap 'rm -f "$temporary"' EXIT - curl --fail --silent --show-error --location --retry 3 --retry-delay 2 \ - --output "$temporary" \ - "https://github.com/rui314/mold/releases/download/v$MOLD_VERSION/mold-$MOLD_VERSION-$mold_arch-linux.tar.gz" - printf '%s %s\n' "$expected" "$temporary" | sha256sum --check --strict - mv "$temporary" "$archive" - trap - EXIT - fi - printf '%s %s\n' "$expected" "$archive" | sha256sum --check --strict - if [[ "$(id -u)" -eq 0 ]]; then - tar --directory /usr/local --strip-components=1 --no-overwrite-dir -xzf "$archive" - ln -sf /usr/local/bin/mold "$(realpath /usr/bin/ld 2>/dev/null || printf /usr/bin/ld)" - else - sudo tar --directory /usr/local --strip-components=1 --no-overwrite-dir -xzf "$archive" - sudo ln -sf /usr/local/bin/mold "$(realpath /usr/bin/ld 2>/dev/null || printf /usr/bin/ld)" - fi - mold --version | grep -F "$MOLD_VERSION" - - name: Restore "Rust crate (ruxel-cli)" cache - id: cache - uses: actions/cache/restore@55cc8345863c7cc4c66a329aec7e433d2d1c52a9 # v6.1.0 - with: - path: | - ~/.cargo/registry - ~/.cargo/git - key: ci-release-${{ runner.os }}-rust-ruxel-cli-${{ hashFiles('.cargo/**', 'Cargo.lock', 'rust-toolchain.toml', 'rust-toolchain') }} - - name: Prepare Cargo sources - if: ${{ steps.cache.outputs.cache-hit != 'true' }} - env: - MISE_AUTO_INSTALL: "false" - MISE_EXEC_AUTO_INSTALL: "false" - MISE_NOT_FOUND_AUTO_INSTALL: "false" - run: | - set -euo pipefail - root='crates/ruxel' - if [[ "$root" != "." ]]; then - cd -- "$root" - fi - cargo fetch --locked - - name: Run "Rust crate (ruxel-cli)" checks - env: - CI_SCOPE: full - CI_UNIT_ID: rust-ruxel-cli - EVENT_NAME: ${{ github.event_name }} - HEAD_SHA: ${{ github.sha }} - CARGO_NET_OFFLINE: "true" - MISE_AUTO_INSTALL: "false" - MISE_EXEC_AUTO_INSTALL: "false" - MISE_NOT_FOUND_AUTO_INSTALL: "false" - run: velnor-workflow run --config .github/ci/project.toml --scope "$CI_SCOPE" --unit rust-ruxel-cli - - release-github-rust-ruxel-core: - name: "GitHub / Rust / rust-ruxel-core" - needs: [verify] - runs-on: ubuntu-24.04 - timeout-minutes: 60 - steps: - - name: Checkout - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 - with: - persist-credentials: false - - name: Set up Velnor workflow runtime - if: ${{ runner.environment == 'github-hosted' }} - uses: tailrocks/velnor/.github/actions/setup-velnor-workflow@e05aee6de1d1614d752b4d1b1d26a49ac2c5ef91 - with: - rev: e05aee6de1d1614d752b4d1b1d26a49ac2c5ef91 - - name: Set trusted workflow policy revision - run: echo "VELNOR_WORKFLOW_POLICY_REVISION=e05aee6de1d1614d752b4d1b1d26a49ac2c5ef91" >> "$GITHUB_ENV" - - name: Restore Rust toolchain - id: rustup-toolchain - uses: actions/cache/restore@55cc8345863c7cc4c66a329aec7e433d2d1c52a9 # v6.1.0 - with: - path: | - ~/.rustup - key: velnor-rustup-${{ runner.os }}-${{ runner.arch }}-${{ hashFiles('rust-toolchain.toml', 'rust-toolchain') }} - - name: Provision Rust toolchain - shell: bash - run: | - set -euo pipefail - rustup toolchain install - rustup target add 'x86_64-unknown-linux-musl' 'aarch64-apple-darwin' 'x86_64-apple-darwin' 'aarch64-unknown-linux-gnu' 'x86_64-unknown-linux-gnu' - - name: Bound the Mr. Boxington store - shell: bash - run: echo "MBX_GC_MAX_SIZE=12GiB" >> "$GITHUB_ENV" - - name: Set up Mr. Boxington - id: mbx-cache - uses: jdx/mr-boxington-action@7234d3dd1a6ca8f6c381eea8e4dfb03f18fcf777 # v1.3.0 - with: - backend: github - github-cache-mode: objects - version: 1.11.1 - cache-key: velnor-mbx-v3-213494d9a3ca-${{ runner.os }}-${{ runner.arch }}-rust-ruxel-core-${{ hashFiles('.cargo/**', 'Cargo.lock', 'rust-toolchain', 'rust-toolchain.toml') }}-${{ hashFiles('crates/ruxel-core/**/*.rs', 'crates/ruxel-core/benches/**', 'crates/ruxel-core/examples/**', 'crates/ruxel-core/src/**', 'crates/ruxel-core/tests/**', 'mise.lock') }} - restore-keys: | - velnor-mbx-v3-213494d9a3ca-${{ runner.os }}-${{ runner.arch }}-rust-ruxel-core-${{ hashFiles('.cargo/**', 'Cargo.lock', 'rust-toolchain', 'rust-toolchain.toml') }}- - velnor-mbx-v3-213494d9a3ca-${{ runner.os }}-${{ runner.arch }}-rust-ruxel-core- - save-on-workflow-dispatch: true - - name: Restore mold 2.42.0 cache - id: mold-cache - uses: actions/cache/restore@55cc8345863c7cc4c66a329aec7e433d2d1c52a9 # v6.1.0 - with: - path: ~/.cache/velnor/mold/2.42.0 - key: velnor-mold-2.42.0-${{ runner.os }}-${{ runner.arch }} - - name: Set up mold 2.42.0 - shell: bash - env: - MOLD_VERSION: 2.42.0 - run: | - set -euo pipefail - case "$(uname -m)" in - x86_64) mold_arch=x86_64; expected='f5ed2f6e31d1ada4f07fe766fe0de7a73104d1c5cdc59086fcecc16a43720b6d' ;; - aarch64) mold_arch=aarch64; expected='3c9a0a3624aac8a2007569ae50c33b3129a0f0ae8bcc974aeee2f8939d295190' ;; - *) echo "unsupported mold architecture: $(uname -m)" >&2; exit 1 ;; - esac - cache_dir="$HOME/.cache/velnor/mold/$MOLD_VERSION" - archive="$cache_dir/mold-$MOLD_VERSION-$mold_arch-linux.tar.gz" - mkdir -p "$cache_dir" - if [[ ! -s "$archive" ]]; then - temporary="$archive.download" - trap 'rm -f "$temporary"' EXIT - curl --fail --silent --show-error --location --retry 3 --retry-delay 2 \ - --output "$temporary" \ - "https://github.com/rui314/mold/releases/download/v$MOLD_VERSION/mold-$MOLD_VERSION-$mold_arch-linux.tar.gz" - printf '%s %s\n' "$expected" "$temporary" | sha256sum --check --strict - mv "$temporary" "$archive" - trap - EXIT - fi - printf '%s %s\n' "$expected" "$archive" | sha256sum --check --strict - if [[ "$(id -u)" -eq 0 ]]; then - tar --directory /usr/local --strip-components=1 --no-overwrite-dir -xzf "$archive" - ln -sf /usr/local/bin/mold "$(realpath /usr/bin/ld 2>/dev/null || printf /usr/bin/ld)" - else - sudo tar --directory /usr/local --strip-components=1 --no-overwrite-dir -xzf "$archive" - sudo ln -sf /usr/local/bin/mold "$(realpath /usr/bin/ld 2>/dev/null || printf /usr/bin/ld)" - fi - mold --version | grep -F "$MOLD_VERSION" - - name: Restore "Rust crate (ruxel-core)" cache - id: cache - uses: actions/cache/restore@55cc8345863c7cc4c66a329aec7e433d2d1c52a9 # v6.1.0 - with: - path: | - ~/.cargo/registry - ~/.cargo/git - key: ci-release-${{ runner.os }}-rust-ruxel-core-${{ hashFiles('.cargo/**', 'Cargo.lock', 'rust-toolchain.toml', 'rust-toolchain') }} - - name: Prepare Cargo sources - if: ${{ steps.cache.outputs.cache-hit != 'true' }} - env: - MISE_AUTO_INSTALL: "false" - MISE_EXEC_AUTO_INSTALL: "false" - MISE_NOT_FOUND_AUTO_INSTALL: "false" - run: | - set -euo pipefail - root='crates/ruxel-core' - if [[ "$root" != "." ]]; then - cd -- "$root" - fi - cargo fetch --locked - - name: Run "Rust crate (ruxel-core)" checks - env: - CI_SCOPE: full - CI_UNIT_ID: rust-ruxel-core - EVENT_NAME: ${{ github.event_name }} - HEAD_SHA: ${{ github.sha }} - CARGO_NET_OFFLINE: "true" - MISE_AUTO_INSTALL: "false" - MISE_EXEC_AUTO_INSTALL: "false" - MISE_NOT_FOUND_AUTO_INSTALL: "false" - run: velnor-workflow run --config .github/ci/project.toml --scope "$CI_SCOPE" --unit rust-ruxel-core - - release-github-rust-ruxel-proto: - name: "GitHub / Rust / rust-ruxel-proto" - needs: [verify] - runs-on: ubuntu-24.04 - timeout-minutes: 60 - steps: - - name: Checkout - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 - with: - persist-credentials: false - - name: Set up Velnor workflow runtime - if: ${{ runner.environment == 'github-hosted' }} - uses: tailrocks/velnor/.github/actions/setup-velnor-workflow@e05aee6de1d1614d752b4d1b1d26a49ac2c5ef91 - with: - rev: e05aee6de1d1614d752b4d1b1d26a49ac2c5ef91 - - name: Set trusted workflow policy revision - run: echo "VELNOR_WORKFLOW_POLICY_REVISION=e05aee6de1d1614d752b4d1b1d26a49ac2c5ef91" >> "$GITHUB_ENV" - - name: Restore Rust toolchain - id: rustup-toolchain - uses: actions/cache/restore@55cc8345863c7cc4c66a329aec7e433d2d1c52a9 # v6.1.0 - with: - path: | - ~/.rustup - key: velnor-rustup-${{ runner.os }}-${{ runner.arch }}-${{ hashFiles('rust-toolchain.toml', 'rust-toolchain') }} - - name: Provision Rust toolchain - shell: bash - run: | - set -euo pipefail - rustup toolchain install - rustup target add 'x86_64-unknown-linux-musl' 'aarch64-apple-darwin' 'x86_64-apple-darwin' 'aarch64-unknown-linux-gnu' 'x86_64-unknown-linux-gnu' - - name: Bound the Mr. Boxington store - shell: bash - run: echo "MBX_GC_MAX_SIZE=12GiB" >> "$GITHUB_ENV" - - name: Set up Mr. Boxington - id: mbx-cache - uses: jdx/mr-boxington-action@7234d3dd1a6ca8f6c381eea8e4dfb03f18fcf777 # v1.3.0 - with: - backend: github - github-cache-mode: objects - version: 1.11.1 - cache-key: velnor-mbx-v3-42c27a4a45de-${{ runner.os }}-${{ runner.arch }}-rust-ruxel-proto-${{ hashFiles('.cargo/**', 'Cargo.lock', 'rust-toolchain', 'rust-toolchain.toml') }}-${{ hashFiles('crates/ruxel-proto/**/*.rs', 'crates/ruxel-proto/benches/**', 'crates/ruxel-proto/build.rs', 'crates/ruxel-proto/examples/**', 'crates/ruxel-proto/src/**', 'crates/ruxel-proto/tests/**', 'mise.lock') }} - restore-keys: | - velnor-mbx-v3-42c27a4a45de-${{ runner.os }}-${{ runner.arch }}-rust-ruxel-proto-${{ hashFiles('.cargo/**', 'Cargo.lock', 'rust-toolchain', 'rust-toolchain.toml') }}- - velnor-mbx-v3-42c27a4a45de-${{ runner.os }}-${{ runner.arch }}-rust-ruxel-proto- - save-on-workflow-dispatch: true - - name: Restore mold 2.42.0 cache - id: mold-cache - uses: actions/cache/restore@55cc8345863c7cc4c66a329aec7e433d2d1c52a9 # v6.1.0 - with: - path: ~/.cache/velnor/mold/2.42.0 - key: velnor-mold-2.42.0-${{ runner.os }}-${{ runner.arch }} - - name: Set up mold 2.42.0 - shell: bash - env: - MOLD_VERSION: 2.42.0 - run: | - set -euo pipefail - case "$(uname -m)" in - x86_64) mold_arch=x86_64; expected='f5ed2f6e31d1ada4f07fe766fe0de7a73104d1c5cdc59086fcecc16a43720b6d' ;; - aarch64) mold_arch=aarch64; expected='3c9a0a3624aac8a2007569ae50c33b3129a0f0ae8bcc974aeee2f8939d295190' ;; - *) echo "unsupported mold architecture: $(uname -m)" >&2; exit 1 ;; - esac - cache_dir="$HOME/.cache/velnor/mold/$MOLD_VERSION" - archive="$cache_dir/mold-$MOLD_VERSION-$mold_arch-linux.tar.gz" - mkdir -p "$cache_dir" - if [[ ! -s "$archive" ]]; then - temporary="$archive.download" - trap 'rm -f "$temporary"' EXIT - curl --fail --silent --show-error --location --retry 3 --retry-delay 2 \ - --output "$temporary" \ - "https://github.com/rui314/mold/releases/download/v$MOLD_VERSION/mold-$MOLD_VERSION-$mold_arch-linux.tar.gz" - printf '%s %s\n' "$expected" "$temporary" | sha256sum --check --strict - mv "$temporary" "$archive" - trap - EXIT - fi - printf '%s %s\n' "$expected" "$archive" | sha256sum --check --strict - if [[ "$(id -u)" -eq 0 ]]; then - tar --directory /usr/local --strip-components=1 --no-overwrite-dir -xzf "$archive" - ln -sf /usr/local/bin/mold "$(realpath /usr/bin/ld 2>/dev/null || printf /usr/bin/ld)" - else - sudo tar --directory /usr/local --strip-components=1 --no-overwrite-dir -xzf "$archive" - sudo ln -sf /usr/local/bin/mold "$(realpath /usr/bin/ld 2>/dev/null || printf /usr/bin/ld)" - fi - mold --version | grep -F "$MOLD_VERSION" - - name: Restore "Rust crate (ruxel-proto)" cache - id: cache - uses: actions/cache/restore@55cc8345863c7cc4c66a329aec7e433d2d1c52a9 # v6.1.0 - with: - path: | - ~/.cargo/registry - ~/.cargo/git - key: ci-release-${{ runner.os }}-rust-ruxel-proto-${{ hashFiles('.cargo/**', 'Cargo.lock', 'rust-toolchain.toml', 'rust-toolchain') }} - - name: Prepare Cargo sources - if: ${{ steps.cache.outputs.cache-hit != 'true' }} - env: - MISE_AUTO_INSTALL: "false" - MISE_EXEC_AUTO_INSTALL: "false" - MISE_NOT_FOUND_AUTO_INSTALL: "false" - run: | - set -euo pipefail - root='crates/ruxel-proto' - if [[ "$root" != "." ]]; then - cd -- "$root" - fi - cargo fetch --locked - - name: Run "Rust crate (ruxel-proto)" checks - env: - CI_SCOPE: full - CI_UNIT_ID: rust-ruxel-proto - EVENT_NAME: ${{ github.event_name }} - HEAD_SHA: ${{ github.sha }} - CARGO_NET_OFFLINE: "true" - MISE_AUTO_INSTALL: "false" - MISE_EXEC_AUTO_INSTALL: "false" - MISE_NOT_FOUND_AUTO_INSTALL: "false" - run: velnor-workflow run --config .github/ci/project.toml --scope "$CI_SCOPE" --unit rust-ruxel-proto - - release-github-rust-ruxel-spec-extract: - name: "GitHub / Rust / rust-ruxel-spec-extract" - needs: [verify, release-github-rust-ruxel-core] - runs-on: ubuntu-24.04 - timeout-minutes: 60 - steps: - - name: Checkout - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 - with: - persist-credentials: false - - name: Set up Velnor workflow runtime - if: ${{ runner.environment == 'github-hosted' }} - uses: tailrocks/velnor/.github/actions/setup-velnor-workflow@e05aee6de1d1614d752b4d1b1d26a49ac2c5ef91 - with: - rev: e05aee6de1d1614d752b4d1b1d26a49ac2c5ef91 - - name: Set trusted workflow policy revision - run: echo "VELNOR_WORKFLOW_POLICY_REVISION=e05aee6de1d1614d752b4d1b1d26a49ac2c5ef91" >> "$GITHUB_ENV" - - name: Restore Rust toolchain - id: rustup-toolchain - uses: actions/cache/restore@55cc8345863c7cc4c66a329aec7e433d2d1c52a9 # v6.1.0 - with: - path: | - ~/.rustup - key: velnor-rustup-${{ runner.os }}-${{ runner.arch }}-${{ hashFiles('rust-toolchain.toml', 'rust-toolchain') }} - - name: Provision Rust toolchain - shell: bash - run: | - set -euo pipefail - rustup toolchain install - rustup target add 'x86_64-unknown-linux-musl' 'aarch64-apple-darwin' 'x86_64-apple-darwin' 'aarch64-unknown-linux-gnu' 'x86_64-unknown-linux-gnu' - - name: Bound the Mr. Boxington store - shell: bash - run: echo "MBX_GC_MAX_SIZE=12GiB" >> "$GITHUB_ENV" - - name: Set up Mr. Boxington - id: mbx-cache - uses: jdx/mr-boxington-action@7234d3dd1a6ca8f6c381eea8e4dfb03f18fcf777 # v1.3.0 - with: - backend: github - github-cache-mode: objects - version: 1.11.1 - cache-key: velnor-mbx-v3-dec8a5b0fa6f-${{ runner.os }}-${{ runner.arch }}-rust-ruxel-spec-extract-${{ hashFiles('.cargo/**', 'Cargo.lock', 'rust-toolchain', 'rust-toolchain.toml') }}-${{ hashFiles('crates/ruxel-core/**/*.rs', 'crates/ruxel-core/benches/**', 'crates/ruxel-core/examples/**', 'crates/ruxel-core/src/**', 'crates/ruxel-core/tests/**', 'mise.lock', 'tools/spec-extract/**/*.rs', 'tools/spec-extract/benches/**', 'tools/spec-extract/examples/**', 'tools/spec-extract/src/**', 'tools/spec-extract/tests/**') }} - restore-keys: | - velnor-mbx-v3-dec8a5b0fa6f-${{ runner.os }}-${{ runner.arch }}-rust-ruxel-spec-extract-${{ hashFiles('.cargo/**', 'Cargo.lock', 'rust-toolchain', 'rust-toolchain.toml') }}- - velnor-mbx-v3-dec8a5b0fa6f-${{ runner.os }}-${{ runner.arch }}-rust-ruxel-spec-extract- - save-on-workflow-dispatch: true - - name: Restore mold 2.42.0 cache - id: mold-cache - uses: actions/cache/restore@55cc8345863c7cc4c66a329aec7e433d2d1c52a9 # v6.1.0 - with: - path: ~/.cache/velnor/mold/2.42.0 - key: velnor-mold-2.42.0-${{ runner.os }}-${{ runner.arch }} - - name: Set up mold 2.42.0 - shell: bash - env: - MOLD_VERSION: 2.42.0 - run: | - set -euo pipefail - case "$(uname -m)" in - x86_64) mold_arch=x86_64; expected='f5ed2f6e31d1ada4f07fe766fe0de7a73104d1c5cdc59086fcecc16a43720b6d' ;; - aarch64) mold_arch=aarch64; expected='3c9a0a3624aac8a2007569ae50c33b3129a0f0ae8bcc974aeee2f8939d295190' ;; - *) echo "unsupported mold architecture: $(uname -m)" >&2; exit 1 ;; - esac - cache_dir="$HOME/.cache/velnor/mold/$MOLD_VERSION" - archive="$cache_dir/mold-$MOLD_VERSION-$mold_arch-linux.tar.gz" - mkdir -p "$cache_dir" - if [[ ! -s "$archive" ]]; then - temporary="$archive.download" - trap 'rm -f "$temporary"' EXIT - curl --fail --silent --show-error --location --retry 3 --retry-delay 2 \ - --output "$temporary" \ - "https://github.com/rui314/mold/releases/download/v$MOLD_VERSION/mold-$MOLD_VERSION-$mold_arch-linux.tar.gz" - printf '%s %s\n' "$expected" "$temporary" | sha256sum --check --strict - mv "$temporary" "$archive" - trap - EXIT - fi - printf '%s %s\n' "$expected" "$archive" | sha256sum --check --strict - if [[ "$(id -u)" -eq 0 ]]; then - tar --directory /usr/local --strip-components=1 --no-overwrite-dir -xzf "$archive" - ln -sf /usr/local/bin/mold "$(realpath /usr/bin/ld 2>/dev/null || printf /usr/bin/ld)" - else - sudo tar --directory /usr/local --strip-components=1 --no-overwrite-dir -xzf "$archive" - sudo ln -sf /usr/local/bin/mold "$(realpath /usr/bin/ld 2>/dev/null || printf /usr/bin/ld)" - fi - mold --version | grep -F "$MOLD_VERSION" - - name: Restore "Rust crate (ruxel-spec-extract)" cache - id: cache - uses: actions/cache/restore@55cc8345863c7cc4c66a329aec7e433d2d1c52a9 # v6.1.0 - with: - path: | - ~/.cargo/registry - ~/.cargo/git - key: ci-release-${{ runner.os }}-rust-ruxel-spec-extract-${{ hashFiles('.cargo/**', 'Cargo.lock', 'rust-toolchain.toml', 'rust-toolchain') }} - - name: Prepare Cargo sources - if: ${{ steps.cache.outputs.cache-hit != 'true' }} - env: - MISE_AUTO_INSTALL: "false" - MISE_EXEC_AUTO_INSTALL: "false" - MISE_NOT_FOUND_AUTO_INSTALL: "false" - run: | - set -euo pipefail - root='tools/spec-extract' - if [[ "$root" != "." ]]; then - cd -- "$root" - fi - cargo fetch --locked - - name: Run "Rust crate (ruxel-spec-extract)" checks - env: - CI_SCOPE: full - CI_UNIT_ID: rust-ruxel-spec-extract - EVENT_NAME: ${{ github.event_name }} - HEAD_SHA: ${{ github.sha }} - CARGO_NET_OFFLINE: "true" - MISE_AUTO_INSTALL: "false" - MISE_EXEC_AUTO_INSTALL: "false" - MISE_NOT_FOUND_AUTO_INSTALL: "false" - run: velnor-workflow run --config .github/ci/project.toml --scope "$CI_SCOPE" --unit rust-ruxel-spec-extract - - release-velnor-docker-tools-fixtures-docker: - name: "Velnor / Docker / docker-tools-fixtures-docker" - if: ${{ (github.event_name == 'push' && (github.ref_type == 'tag' || github.ref == 'refs/heads/main')) || github.event_name == 'schedule' || (github.event_name == 'workflow_dispatch' && github.ref == 'refs/heads/main') }} - needs: [verify] - runs-on: [self-hosted, velnor-target-mvp] - timeout-minutes: 60 - steps: - - name: Checkout - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 - with: - persist-credentials: false - - name: Velnor runner identity - shell: bash - run: | - set -euo pipefail - { - echo '## Velnor runner identity' - echo - echo "- Host: ${VELNOR_HOST:-unset}" - echo "- Instance: ${VELNOR_INSTANCE:-unset}" - echo "- Slot: ${VELNOR_SLOT:-unset}" - echo "- GitHub runner: ${RUNNER_NAME:-unset}" - echo "- OS/arch: ${RUNNER_OS:-unset}/${RUNNER_ARCH:-unset}" - echo "- Execution backend: ${VELNOR_EXECUTION_BACKEND:-unset}" - echo "- Velnor version: ${VELNOR_MANIFEST_VERSION:-${VELNOR_SOURCE_SHA:-unset}}" - } | tee -a "${GITHUB_STEP_SUMMARY:-/dev/null}" - - name: Run "Docker (tools/fixtures/docker)" checks - env: - CI_SCOPE: full - CI_UNIT_ID: docker-tools-fixtures-docker - EVENT_NAME: ${{ github.event_name }} - HEAD_SHA: ${{ github.sha }} - MISE_AUTO_INSTALL: "false" - MISE_EXEC_AUTO_INSTALL: "false" - MISE_NOT_FOUND_AUTO_INSTALL: "false" - run: velnor-workflow run --config .github/ci/project.toml --scope "$CI_SCOPE" --unit docker-tools-fixtures-docker - - release-velnor-rust-policy: - name: "Velnor / Rust / rust-policy" - if: ${{ (github.event_name == 'push' && (github.ref_type == 'tag' || github.ref == 'refs/heads/main')) || github.event_name == 'schedule' || (github.event_name == 'workflow_dispatch' && github.ref == 'refs/heads/main') }} - needs: [verify] - runs-on: [self-hosted, velnor-target-mvp] - timeout-minutes: 60 - steps: - - name: Checkout - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 - with: - persist-credentials: false - - name: Velnor runner identity - shell: bash - run: | - set -euo pipefail - { - echo '## Velnor runner identity' - echo - echo "- Host: ${VELNOR_HOST:-unset}" - echo "- Instance: ${VELNOR_INSTANCE:-unset}" - echo "- Slot: ${VELNOR_SLOT:-unset}" - echo "- GitHub runner: ${RUNNER_NAME:-unset}" - echo "- OS/arch: ${RUNNER_OS:-unset}/${RUNNER_ARCH:-unset}" - echo "- Execution backend: ${VELNOR_EXECUTION_BACKEND:-unset}" - echo "- Velnor version: ${VELNOR_MANIFEST_VERSION:-${VELNOR_SOURCE_SHA:-unset}}" - } | tee -a "${GITHUB_STEP_SUMMARY:-/dev/null}" - - name: Install declared Mise tools - run: | - set -euo pipefail - mise --yes install cargo:cargo-deny - - name: Set up Mr. Boxington - id: mbx-cache - uses: jdx/mr-boxington-action@7234d3dd1a6ca8f6c381eea8e4dfb03f18fcf777 # v1.3.0 - with: - backend: local - - name: Run "Rust dependency policy" checks - env: - CI_SCOPE: full - CI_UNIT_ID: rust-policy - EVENT_NAME: ${{ github.event_name }} - HEAD_SHA: ${{ github.sha }} - MISE_AUTO_INSTALL: "false" - MISE_EXEC_AUTO_INSTALL: "false" - MISE_NOT_FOUND_AUTO_INSTALL: "false" - run: velnor-workflow run --config .github/ci/project.toml --scope "$CI_SCOPE" --unit rust-policy - - release-velnor-rust-ruxel-agent: - name: "Velnor / Rust / rust-ruxel-agent" - if: ${{ (github.event_name == 'push' && (github.ref_type == 'tag' || github.ref == 'refs/heads/main')) || github.event_name == 'schedule' || (github.event_name == 'workflow_dispatch' && github.ref == 'refs/heads/main') }} - needs: [verify, release-velnor-rust-ruxel-core, release-velnor-rust-ruxel-proto] - runs-on: [self-hosted, velnor-target-mvp] - timeout-minutes: 60 - steps: - - name: Checkout - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 - with: - persist-credentials: false - - name: Velnor runner identity - shell: bash - run: | - set -euo pipefail - { - echo '## Velnor runner identity' - echo - echo "- Host: ${VELNOR_HOST:-unset}" - echo "- Instance: ${VELNOR_INSTANCE:-unset}" - echo "- Slot: ${VELNOR_SLOT:-unset}" - echo "- GitHub runner: ${RUNNER_NAME:-unset}" - echo "- OS/arch: ${RUNNER_OS:-unset}/${RUNNER_ARCH:-unset}" - echo "- Execution backend: ${VELNOR_EXECUTION_BACKEND:-unset}" - echo "- Velnor version: ${VELNOR_MANIFEST_VERSION:-${VELNOR_SOURCE_SHA:-unset}}" - } | tee -a "${GITHUB_STEP_SUMMARY:-/dev/null}" - - name: Set up Mr. Boxington - id: mbx-cache - uses: jdx/mr-boxington-action@7234d3dd1a6ca8f6c381eea8e4dfb03f18fcf777 # v1.3.0 - with: - backend: local - - name: Prepare Cargo sources - env: - MISE_AUTO_INSTALL: "false" - MISE_EXEC_AUTO_INSTALL: "false" - MISE_NOT_FOUND_AUTO_INSTALL: "false" - run: | - set -euo pipefail - root='crates/ruxel-agent' - if [[ "$root" != "." ]]; then - cd -- "$root" - fi - if cargo metadata --locked --offline --all-features --format-version 1 >/dev/null 2>&1; then - echo "Cargo sources warm; skipping fetch" - else - cargo fetch --locked - fi - - name: Run "Rust crate (ruxel-agent)" checks - env: - CI_SCOPE: full - CI_UNIT_ID: rust-ruxel-agent - EVENT_NAME: ${{ github.event_name }} - HEAD_SHA: ${{ github.sha }} - CARGO_NET_OFFLINE: "true" - MISE_AUTO_INSTALL: "false" - MISE_EXEC_AUTO_INSTALL: "false" - MISE_NOT_FOUND_AUTO_INSTALL: "false" - run: velnor-workflow run --config .github/ci/project.toml --scope "$CI_SCOPE" --unit rust-ruxel-agent - - release-velnor-rust-ruxel-cli: - name: "Velnor / Rust / rust-ruxel-cli" - if: ${{ (github.event_name == 'push' && (github.ref_type == 'tag' || github.ref == 'refs/heads/main')) || github.event_name == 'schedule' || (github.event_name == 'workflow_dispatch' && github.ref == 'refs/heads/main') }} - needs: [verify, release-velnor-rust-ruxel-core, release-velnor-rust-ruxel-proto] - runs-on: [self-hosted, velnor-target-mvp] - timeout-minutes: 60 - steps: - - name: Checkout - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 - with: - persist-credentials: false - - name: Velnor runner identity - shell: bash - run: | - set -euo pipefail - { - echo '## Velnor runner identity' - echo - echo "- Host: ${VELNOR_HOST:-unset}" - echo "- Instance: ${VELNOR_INSTANCE:-unset}" - echo "- Slot: ${VELNOR_SLOT:-unset}" - echo "- GitHub runner: ${RUNNER_NAME:-unset}" - echo "- OS/arch: ${RUNNER_OS:-unset}/${RUNNER_ARCH:-unset}" - echo "- Execution backend: ${VELNOR_EXECUTION_BACKEND:-unset}" - echo "- Velnor version: ${VELNOR_MANIFEST_VERSION:-${VELNOR_SOURCE_SHA:-unset}}" - } | tee -a "${GITHUB_STEP_SUMMARY:-/dev/null}" - - name: Set up Mr. Boxington - id: mbx-cache - uses: jdx/mr-boxington-action@7234d3dd1a6ca8f6c381eea8e4dfb03f18fcf777 # v1.3.0 - with: - backend: local - - name: Prepare Cargo sources - env: - MISE_AUTO_INSTALL: "false" - MISE_EXEC_AUTO_INSTALL: "false" - MISE_NOT_FOUND_AUTO_INSTALL: "false" - run: | - set -euo pipefail - root='crates/ruxel' - if [[ "$root" != "." ]]; then - cd -- "$root" - fi - if cargo metadata --locked --offline --all-features --format-version 1 >/dev/null 2>&1; then - echo "Cargo sources warm; skipping fetch" - else - cargo fetch --locked - fi - - name: Run "Rust crate (ruxel-cli)" checks - env: - CI_SCOPE: full - CI_UNIT_ID: rust-ruxel-cli - EVENT_NAME: ${{ github.event_name }} - HEAD_SHA: ${{ github.sha }} - CARGO_NET_OFFLINE: "true" - MISE_AUTO_INSTALL: "false" - MISE_EXEC_AUTO_INSTALL: "false" - MISE_NOT_FOUND_AUTO_INSTALL: "false" - run: velnor-workflow run --config .github/ci/project.toml --scope "$CI_SCOPE" --unit rust-ruxel-cli - - release-velnor-rust-ruxel-core: - name: "Velnor / Rust / rust-ruxel-core" - if: ${{ (github.event_name == 'push' && (github.ref_type == 'tag' || github.ref == 'refs/heads/main')) || github.event_name == 'schedule' || (github.event_name == 'workflow_dispatch' && github.ref == 'refs/heads/main') }} - needs: [verify] - runs-on: [self-hosted, velnor-target-mvp] - timeout-minutes: 60 - steps: - - name: Checkout - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 - with: - persist-credentials: false - - name: Velnor runner identity - shell: bash - run: | - set -euo pipefail - { - echo '## Velnor runner identity' - echo - echo "- Host: ${VELNOR_HOST:-unset}" - echo "- Instance: ${VELNOR_INSTANCE:-unset}" - echo "- Slot: ${VELNOR_SLOT:-unset}" - echo "- GitHub runner: ${RUNNER_NAME:-unset}" - echo "- OS/arch: ${RUNNER_OS:-unset}/${RUNNER_ARCH:-unset}" - echo "- Execution backend: ${VELNOR_EXECUTION_BACKEND:-unset}" - echo "- Velnor version: ${VELNOR_MANIFEST_VERSION:-${VELNOR_SOURCE_SHA:-unset}}" - } | tee -a "${GITHUB_STEP_SUMMARY:-/dev/null}" - - name: Set up Mr. Boxington - id: mbx-cache - uses: jdx/mr-boxington-action@7234d3dd1a6ca8f6c381eea8e4dfb03f18fcf777 # v1.3.0 - with: - backend: local - - name: Prepare Cargo sources - env: - MISE_AUTO_INSTALL: "false" - MISE_EXEC_AUTO_INSTALL: "false" - MISE_NOT_FOUND_AUTO_INSTALL: "false" - run: | - set -euo pipefail - root='crates/ruxel-core' - if [[ "$root" != "." ]]; then - cd -- "$root" - fi - if cargo metadata --locked --offline --all-features --format-version 1 >/dev/null 2>&1; then - echo "Cargo sources warm; skipping fetch" - else - cargo fetch --locked - fi - - name: Run "Rust crate (ruxel-core)" checks - env: - CI_SCOPE: full - CI_UNIT_ID: rust-ruxel-core - EVENT_NAME: ${{ github.event_name }} - HEAD_SHA: ${{ github.sha }} - CARGO_NET_OFFLINE: "true" - MISE_AUTO_INSTALL: "false" - MISE_EXEC_AUTO_INSTALL: "false" - MISE_NOT_FOUND_AUTO_INSTALL: "false" - run: velnor-workflow run --config .github/ci/project.toml --scope "$CI_SCOPE" --unit rust-ruxel-core - - release-velnor-rust-ruxel-proto: - name: "Velnor / Rust / rust-ruxel-proto" - if: ${{ (github.event_name == 'push' && (github.ref_type == 'tag' || github.ref == 'refs/heads/main')) || github.event_name == 'schedule' || (github.event_name == 'workflow_dispatch' && github.ref == 'refs/heads/main') }} - needs: [verify] - runs-on: [self-hosted, velnor-target-mvp] - timeout-minutes: 60 - steps: - - name: Checkout - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 - with: - persist-credentials: false - - name: Velnor runner identity - shell: bash - run: | - set -euo pipefail - { - echo '## Velnor runner identity' - echo - echo "- Host: ${VELNOR_HOST:-unset}" - echo "- Instance: ${VELNOR_INSTANCE:-unset}" - echo "- Slot: ${VELNOR_SLOT:-unset}" - echo "- GitHub runner: ${RUNNER_NAME:-unset}" - echo "- OS/arch: ${RUNNER_OS:-unset}/${RUNNER_ARCH:-unset}" - echo "- Execution backend: ${VELNOR_EXECUTION_BACKEND:-unset}" - echo "- Velnor version: ${VELNOR_MANIFEST_VERSION:-${VELNOR_SOURCE_SHA:-unset}}" - } | tee -a "${GITHUB_STEP_SUMMARY:-/dev/null}" - - name: Set up Mr. Boxington - id: mbx-cache - uses: jdx/mr-boxington-action@7234d3dd1a6ca8f6c381eea8e4dfb03f18fcf777 # v1.3.0 - with: - backend: local - - name: Prepare Cargo sources - env: - MISE_AUTO_INSTALL: "false" - MISE_EXEC_AUTO_INSTALL: "false" - MISE_NOT_FOUND_AUTO_INSTALL: "false" - run: | - set -euo pipefail - root='crates/ruxel-proto' - if [[ "$root" != "." ]]; then - cd -- "$root" - fi - if cargo metadata --locked --offline --all-features --format-version 1 >/dev/null 2>&1; then - echo "Cargo sources warm; skipping fetch" - else - cargo fetch --locked - fi - - name: Run "Rust crate (ruxel-proto)" checks - env: - CI_SCOPE: full - CI_UNIT_ID: rust-ruxel-proto - EVENT_NAME: ${{ github.event_name }} - HEAD_SHA: ${{ github.sha }} - CARGO_NET_OFFLINE: "true" - MISE_AUTO_INSTALL: "false" - MISE_EXEC_AUTO_INSTALL: "false" - MISE_NOT_FOUND_AUTO_INSTALL: "false" - run: velnor-workflow run --config .github/ci/project.toml --scope "$CI_SCOPE" --unit rust-ruxel-proto - - release-velnor-rust-ruxel-spec-extract: - name: "Velnor / Rust / rust-ruxel-spec-extract" - if: ${{ (github.event_name == 'push' && (github.ref_type == 'tag' || github.ref == 'refs/heads/main')) || github.event_name == 'schedule' || (github.event_name == 'workflow_dispatch' && github.ref == 'refs/heads/main') }} - needs: [verify, release-velnor-rust-ruxel-core] - runs-on: [self-hosted, velnor-target-mvp] - timeout-minutes: 60 - steps: - - name: Checkout - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 - with: - persist-credentials: false - - name: Velnor runner identity - shell: bash - run: | - set -euo pipefail - { - echo '## Velnor runner identity' - echo - echo "- Host: ${VELNOR_HOST:-unset}" - echo "- Instance: ${VELNOR_INSTANCE:-unset}" - echo "- Slot: ${VELNOR_SLOT:-unset}" - echo "- GitHub runner: ${RUNNER_NAME:-unset}" - echo "- OS/arch: ${RUNNER_OS:-unset}/${RUNNER_ARCH:-unset}" - echo "- Execution backend: ${VELNOR_EXECUTION_BACKEND:-unset}" - echo "- Velnor version: ${VELNOR_MANIFEST_VERSION:-${VELNOR_SOURCE_SHA:-unset}}" - } | tee -a "${GITHUB_STEP_SUMMARY:-/dev/null}" - - name: Set up Mr. Boxington - id: mbx-cache - uses: jdx/mr-boxington-action@7234d3dd1a6ca8f6c381eea8e4dfb03f18fcf777 # v1.3.0 - with: - backend: local - - name: Prepare Cargo sources - env: - MISE_AUTO_INSTALL: "false" - MISE_EXEC_AUTO_INSTALL: "false" - MISE_NOT_FOUND_AUTO_INSTALL: "false" - run: | - set -euo pipefail - root='tools/spec-extract' - if [[ "$root" != "." ]]; then - cd -- "$root" - fi - if cargo metadata --locked --offline --all-features --format-version 1 >/dev/null 2>&1; then - echo "Cargo sources warm; skipping fetch" - else - cargo fetch --locked - fi - - name: Run "Rust crate (ruxel-spec-extract)" checks - env: - CI_SCOPE: full - CI_UNIT_ID: rust-ruxel-spec-extract - EVENT_NAME: ${{ github.event_name }} - HEAD_SHA: ${{ github.sha }} - CARGO_NET_OFFLINE: "true" - MISE_AUTO_INSTALL: "false" - MISE_EXEC_AUTO_INSTALL: "false" - MISE_NOT_FOUND_AUTO_INSTALL: "false" - run: velnor-workflow run --config .github/ci/project.toml --scope "$CI_SCOPE" --unit rust-ruxel-spec-extract - - - build: - name: Build / ${{ matrix.target }} - needs: [verify, release-github-docker-tools-fixtures-docker, release-github-rust-policy, release-github-rust-ruxel-agent, release-github-rust-ruxel-cli, release-github-rust-ruxel-core, release-github-rust-ruxel-proto, release-github-rust-ruxel-spec-extract, release-velnor-docker-tools-fixtures-docker, release-velnor-rust-policy, release-velnor-rust-ruxel-agent, release-velnor-rust-ruxel-cli, release-velnor-rust-ruxel-core, release-velnor-rust-ruxel-proto, release-velnor-rust-ruxel-spec-extract] - strategy: - fail-fast: false - matrix: - include: - - target: aarch64-apple-darwin - lane: github - runner: macos-15 - - target: x86_64-apple-darwin - lane: github - runner: macos-15 - - target: aarch64-unknown-linux-gnu - lane: github - runner: ubuntu-24.04 - - target: x86_64-unknown-linux-gnu - lane: github - runner: ubuntu-24.04 - runs-on: ${{ matrix.runner }} - if: ${{ (github.event_name == 'push' && (github.ref_type == 'tag' || github.ref == 'refs/heads/main')) || github.event_name == 'schedule' || (github.event_name == 'workflow_dispatch' && github.ref == 'refs/heads/main') }} - timeout-minutes: 90 - permissions: - contents: read - id-token: write - attestations: write - steps: - - name: Checkout - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 - with: - persist-credentials: false - - name: Set up Velnor workflow runtime - if: ${{ runner.environment == 'github-hosted' }} - uses: tailrocks/velnor/.github/actions/setup-velnor-workflow@e05aee6de1d1614d752b4d1b1d26a49ac2c5ef91 - with: - rev: e05aee6de1d1614d752b4d1b1d26a49ac2c5ef91 - - name: Set trusted workflow policy revision - run: echo "VELNOR_WORKFLOW_POLICY_REVISION=e05aee6de1d1614d752b4d1b1d26a49ac2c5ef91" >> "$GITHUB_ENV" - - name: Set up sccache - uses: mozilla-actions/sccache-action@fc920bf0ec8de6ee65d409111f7ec508035751ba # v0.0.11 - with: - version: v0.16.0 - - name: Add Rust target - run: rustup target add "${{ matrix.target }}" - - name: Build release binary - env: - CARGO_INCREMENTAL: "0" - RUSTC_WRAPPER: sccache - run: mbx build --locked --release --package ruxel-cli --bin ruxel --target "${{ matrix.target }}" - - name: Package release binary - env: - VERSION: ${{ github.ref_name }} - run: | - set -euo pipefail - velnor-workflow release package-binary --target "${{ matrix.target }}" --version "${VERSION#v}" --package ruxel-cli --binary ruxel - - name: Attest release artifact - uses: actions/attest-build-provenance@4d101475d8b20a2381f78447822ac1eab6504dd8 # v4.2.2 - with: - subject-path: dist/*.tar.gz - - name: Upload release artifact - uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1 - with: - name: ${{ matrix.lane }}-${{ matrix.target }} - path: dist/* - if-no-files-found: error - retention-days: 2 - - publish: - name: Control / Publish - needs: [verify, build] - runs-on: ubuntu-24.04 - timeout-minutes: 20 - environment: github-release - permissions: - contents: write - steps: - - name: Download release artifacts - uses: actions/download-artifact@3e5f45b2cfb9172054b4087a40e8e0b5a5461e7c # v8.0.1 - with: - path: dist - pattern: github-* - merge-multiple: true - - name: Verify artifact provenance - env: - GH_TOKEN: ${{ github.token }} - run: | - set -euo pipefail - for artifact in dist/*.tar.gz; do gh attestation verify "$artifact" --repo "$GITHUB_REPOSITORY"; done - - name: Verify archive checksums - run: | - set -euo pipefail - cd dist - for checksum in *.sha256; do sha256sum --check "$checksum"; done - - name: Publish immutable GitHub release - env: - GH_TOKEN: ${{ github.token }} - run: gh release create "${{ github.ref_name }}" dist/* --verify-tag --generate-notes - -# Release tags are cut from the protected main branch.