Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
2 changes: 1 addition & 1 deletion .github-gen/velnor-workflow.toml
Original file line number Diff line number Diff line change
Expand Up @@ -2,7 +2,7 @@ schema = 1

[generator]
repository = "tailrocks/ruxel"
revision = "b9c3156cdb88e63c11b9e595a3e694b02238c09a"
revision = "4fa7a3a85f141a6bb95bc9bdf0eef9e3ddde165d"

[workflow]
runners = "both"
Expand Down
20 changes: 10 additions & 10 deletions .github/ci/.github-actions-generator-state
Original file line number Diff line number Diff line change
@@ -1,17 +1,17 @@
# Generated ownership state; do not edit.
schema = 2
[inputs]
config f03318060fdf269b
scan 73483f0bc233ebc4
generator 49
config e077738d5d760ac5
scan 64b8b7a298804718
generator 54
[outputs]
.github/actionlint.yaml ec35f48ae7e90e0e
.github/ci/project.toml a0c5060b9b02e82b
.github/workflows/ci-main.yml f876c8065e0aab47
.github/workflows/ci-policy.yml a9a48676140ac8dd
.github/workflows/ci-pr.yml c856ce561e05155e
.github/workflows/ci-unit-docker.yml f4a6ab47c5e4bbba
.github/workflows/ci-unit-rust.yml 2bd3bb41c4614dff
.github/workflows/maintenance.yml 44cdcd6db1e77d43
.github/ci/project.toml 90768fed45857d11
.github/workflows/ci-main.yml 95d34976db586b85
.github/workflows/ci-policy.yml e4f8d6d6bfe9cf06
.github/workflows/ci-pr.yml 9a26dfbcf69e2613
.github/workflows/ci-unit-docker.yml c1b32465f205557c
.github/workflows/ci-unit-rust.yml 3360faf9d71979b5
.github/workflows/maintenance.yml b38094a09a507115
.github/workflows/nightly.yml c73d542eaf687a7e
config/fleet/velnor-host.env d14b419216449423
2 changes: 1 addition & 1 deletion .github/ci/project.toml
Original file line number Diff line number Diff line change
Expand Up @@ -15,7 +15,7 @@ limitations = ["Project code, build scripts, task runners, and commands are neve
github_runner = "ubuntu-24.04"
velnor_labels = ["self-hosted", "velnor-target-mvp"]
files = ["ci-main.yml", "ci-policy.yml", "ci-pr.yml", "ci-unit-docker.yml", "ci-unit-rust.yml", "maintenance.yml", "nightly.yml"]
notes = ["Rust verification uses Mr. Boxington 1.11.1 by default on both lanes. GitHub-hosted jobs use its GitHub cache backend with bounded snapshot keys (a key names the toolchain/image/linker compatibility class and the hashed source state, so a new source state saves a new snapshot and retention keeps generations bounded). Velnor jobs use an explicit local-backend setup step against the image/runner-provided local store."]
notes = ["Rust verification uses Mr. Boxington 1.12.0 by default on both lanes. GitHub-hosted jobs use its GitHub cache backend with bounded snapshot keys (a key names the toolchain/image/linker compatibility class and the hashed source state, so a new source state saves a new snapshot and retention keeps generations bounded). Velnor jobs use an explicit local-backend setup step against the image/runner-provided local store."]

[release]
enabled = false
Expand Down
345 changes: 220 additions & 125 deletions .github/workflows/ci-main.yml

Large diffs are not rendered by default.

76 changes: 40 additions & 36 deletions .github/workflows/ci-policy.yml
Original file line number Diff line number Diff line change
Expand Up @@ -18,11 +18,16 @@ jobs:
name: Policy
runs-on: ubuntu-24.04
timeout-minutes: 20
# Trust invariant: this job runs the base branch's validator against the
# audited tree under pull_request_target. It holds `contents: read` only,
# references no secrets, and its checkout persists no credentials, so
# building and running the tree's declared generator here is no more
# privileged than the pull_request lanes that already build the tree.
# Trust invariant: this job runs the base branch's Stage-0 validator
# product against the audited tree under pull_request_target. It holds
# `contents: read` only, references no secrets, persists no credentials,
# and never compiles. When the audited tree differs from the declared
# pin's render, it additionally EXECUTES the PR run's prebuilt
# candidate generator — PR-built code, same-repository runs only, bound
# to the audited tree by manifest closure plus binary digest before
# execution — with no secret references, no persisted credentials, the
# read-only github.token confined to the Acquire/Ruleset API steps,
# and both candidate exec points tokenless.
permissions:
contents: read
steps:
Expand All @@ -43,39 +48,34 @@ jobs:
git fetch --no-tags "$GITHUB_SERVER_URL/$HEAD_REPOSITORY" "$HEAD_SHA"
fi
git checkout --quiet --detach "$HEAD_SHA"
- name: Bound the Mr. Boxington store
shell: bash
run: echo "MBX_GC_MAX_SIZE=12GiB" >> "$GITHUB_ENV"
- name: Set up Mr. Boxington
uses: jdx/mr-boxington-action@7234d3dd1a6ca8f6c381eea8e4dfb03f18fcf777 # v1.3.0
- name: Set up Velnor workflow runtime
uses: tailrocks/velnor/.github/actions/setup-velnor-workflow@4fa7a3a85f141a6bb95bc9bdf0eef9e3ddde165d
with:
backend: github
version: 1.11.1
cache-key: velnor-policy-mbx-1.11.1-${{ runner.os }}-${{ runner.arch }}-b9c3156cdb88e63c11b9e595a3e694b02238c09a
restore-keys: |
velnor-policy-mbx-1.11.1-${{ runner.os }}-${{ runner.arch }}-
- name: Install pinned Velnor workflow runtime
env:
CARGO_HOME: ${{ runner.temp }}/velnor-workflow-cargo-home
CARGO_TARGET_DIR: ${{ runner.temp }}/velnor-workflow-cargo-target
VELNOR_WORKFLOW_INSTALL_DIR: ${{ runner.temp }}/velnor-workflow-install
VELNOR_WORKFLOW_ROOT: ${{ runner.temp }}/velnor-workflow
rev: 4fa7a3a85f141a6bb95bc9bdf0eef9e3ddde165d
checkout-path: ${{ github.workspace }}/policy-checkout
- name: Read declared generator pin
id: pin
working-directory: policy-checkout
run: |
set -euo pipefail
install -d -m 700 \
"$CARGO_HOME" \
"$CARGO_TARGET_DIR" \
"$VELNOR_WORKFLOW_INSTALL_DIR"
cd "$VELNOR_WORKFLOW_INSTALL_DIR"
env -u RUSTC_WRAPPER -u SCCACHE_GHA_ENABLED -u CARGO_INCREMENTAL -u RUSTFLAGS -u CARGO_ENCODED_RUSTFLAGS \
cargo install \
--locked \
--git https://github.com/tailrocks/velnor \
--rev b9c3156cdb88e63c11b9e595a3e694b02238c09a \
--root "$VELNOR_WORKFLOW_ROOT" \
velnor-workflow \
--bin velnor-workflow
echo "$VELNOR_WORKFLOW_ROOT/bin" >> "$GITHUB_PATH"
pin="$(sed -n -E 's/^[[:space:]]*revision[[:space:]]*=[[:space:]]*"([0-9a-f]{40})".*/\1/p' .github-gen/velnor-workflow.toml | head -n 1)"
test "$pin" != '' || pin="$(sed -n -E 's/^.*VELNOR_WORKFLOW_POLICY_REVISION:[[:space:]]*([0-9a-f]{40}).*/\1/p' .github/workflows/ci-policy.yml | head -n 1)"
test "$pin" != '' || { echo "::error::audited tree declares no generator pin" >&2; exit 1; }
echo "value=$pin" >> "$GITHUB_OUTPUT"
- name: Set up declared generator product
id: renderer
if: steps.pin.outputs.value != '4fa7a3a85f141a6bb95bc9bdf0eef9e3ddde165d'
uses: tailrocks/velnor/.github/actions/setup-velnor-workflow@4fa7a3a85f141a6bb95bc9bdf0eef9e3ddde165d
with:
rev: ${{ steps.pin.outputs.value }}
checkout-path: ${{ github.workspace }}/policy-checkout
- name: Resolve declared generator product
if: steps.pin.outputs.value != '4fa7a3a85f141a6bb95bc9bdf0eef9e3ddde165d'
run: |
set -euo pipefail
binary="$HOME/.cache/velnor/workflow-runtime/${{ steps.renderer.outputs.closure }}/bin/velnor-workflow"
test -x "$binary"
echo "VELNOR_WORKFLOW_PINNED_BINARY=$binary" >> "$GITHUB_ENV"
- name: Resolve required status checks
env:
GH_TOKEN: ${{ github.token }}
Expand Down Expand Up @@ -104,19 +104,23 @@ jobs:
WORKFLOW_ROOT: ${{ github.workspace }}/policy-checkout
HEAD_SHA: ${{ github.event.pull_request.head.sha || github.sha }}
BASE_SHA: ${{ github.event.pull_request.base.sha || github.sha }}
VELNOR_WORKFLOW_POLICY_REVISION: b9c3156cdb88e63c11b9e595a3e694b02238c09a
VELNOR_WORKFLOW_POLICY_REVISION: 4fa7a3a85f141a6bb95bc9bdf0eef9e3ddde165d
run: |
set -euo pipefail
velnor-workflow policy \
--workflow-root "$WORKFLOW_ROOT" \
--head-sha "$HEAD_SHA" \
--base-sha "$BASE_SHA" \
--candidate-manifest "${VELNOR_WORKFLOW_CANDIDATE_MANIFEST:-}" \
--ruleset-contexts "$RULESET_CONTEXTS"

- name: Set up actionlint
uses: jdx/mise-action@c2a87611a18de5b3828c5652fe268e992400cb5c # v4.3.0
with:
install_args: actionlint@1.7.12
cache: false
- name: Lint caller workflows
working-directory: policy-checkout
env:
MISE_NO_CONFIG: "1"
run: mise exec actionlint@1.7.12 -- actionlint
Loading
Loading