-
Notifications
You must be signed in to change notification settings - Fork 1
146 lines (129 loc) · 5.87 KB
/
Copy pathci.yml
File metadata and controls
146 lines (129 loc) · 5.87 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
130
131
132
133
134
135
136
137
138
139
140
141
142
143
144
145
146
name: CI
on:
push:
branches: [main]
pull_request:
branches: [main]
# Cancel in-progress runs on the same PR / branch when a new commit arrives.
concurrency:
group: ${{ github.workflow }}-${{ github.ref }}
cancel-in-progress: true
jobs:
verify:
name: Verify on ${{ matrix.os }} (${{ matrix.arch }})
runs-on: ${{ matrix.runner }}
timeout-minutes: 45
strategy:
fail-fast: false
# Trimmed to the two runners GitHub reliably provides (the macOS runners
# are 10× the cost and were perpetually queued/cancelled; the arm runners
# are unavailable "GA-2025 preview" labels). `verify` is platform-agnostic
# logic, fully covered by ubuntu-x64; windows-x64 stays because Windows
# has real path/SQLite-lock behaviour the suite exercises. macOS is the
# dev platform, so it's covered locally. Per-OS packaging lives in
# release.yml / alpha.yml — it doesn't belong on every push.
matrix:
include:
- os: ubuntu-22.04
arch: x64
runner: ubuntu-22.04
rust-target: x86_64-unknown-linux-gnu
- os: windows-2022
arch: x64
runner: windows-2022
rust-target: x86_64-pc-windows-msvc
steps:
- uses: actions/checkout@v4
- name: Setup
uses: ./.github/actions/setup-bun-rust
with:
rust-target: ${{ matrix.rust-target }}
- name: Verify (typecheck + lint + tests)
# `verify` already builds the native addon + all apps before testing.
env:
# Cap parallel rustc units (native build inside `verify`).
CARGO_BUILD_JOBS: 2
run: bun run verify
# `verify` only runs the integration+entities vitest subset (fast
# pre-handoff gate). That subset is how the read-only-lock rollout merged
# red — its whiteboard/code-editor/app-side test breakage was never run in
# CI. Run the FULL suite once, on the cheap ubuntu runner, so a green PR
# means the whole suite is green. (native + apps are already built above.)
- name: Full test suite (ubuntu — guards verify's subset gap)
if: matrix.os == 'ubuntu-22.04'
run: bun run test
# `verify` runs `lint:apps` (the ratchets) on every OS, but NOT
# `biome check .` — Windows checks out CRLF and there is no .gitattributes
# normalising line endings, so the formatter reports every file as
# mis-formatted (4144 diagnostics). That is exactly why biome had never
# run in CI at all, which is how formatting kept landing red on main.
# Run it on the one runner whose checkout matches the committed bytes.
- name: Formatter + biome lint (ubuntu — CRLF makes this Windows-hostile)
if: matrix.os == 'ubuntu-22.04'
run: bunx biome check .
- name: Build shell bundle (sanity)
run: bun run --filter @brainstorm-os/shell build
# 13.3 — real-renderer smoke on a virtual display. Runs the Playwright e2e
# suite (beta-exit flows) and the KBN-P keyboard-accessibility specs against
# the production-built shell under `xvfb-run` (the harness needs a real
# display + GPU paint to mean anything; macOS/Windows devs run these
# directly via `bun run e2e` / `playwright test kbn-`).
e2e-smoke:
name: E2E + KBN smoke (xvfb)
runs-on: ubuntu-22.04
timeout-minutes: 45
steps:
- uses: actions/checkout@v4
- name: Setup
uses: ./.github/actions/setup-bun-rust
with:
rust-target: x86_64-unknown-linux-gnu
- name: Install display + Electron system deps
run: |
sudo apt-get update
sudo apt-get install -y xvfb libnss3 libatk-bridge2.0-0 libgtk-3-0 libgbm1 libasound2
- name: Build native (host-arch)
env:
CARGO_BUILD_JOBS: 2
run: bun run --filter @brainstorm-os/native build:linux-x64
- name: Rebuild SQLite natives for Electron's ABI
# bun install fetches Node-ABI prebuilds; the shell loads these inside
# Electron ("Module did not self-register" without the rebuild).
run: cd packages/shell && bunx @electron/rebuild -f -w better-sqlite3,better-sqlite3-multiple-ciphers
- name: Build shell + apps
env:
CARGO_BUILD_JOBS: 2
run: bun run e2e:build
- name: E2E smoke (xvfb)
env:
# GitHub's container kernel blocks Chromium's sandbox; the suite
# exercises app flows, not the sandbox itself.
ELECTRON_DISABLE_SANDBOX: "1"
# Headless runner has no Secret Service / unlocked keyring; the
# suite tests app flows, the keystore has its own unit suites.
BRAINSTORM_DEV_INSECURE_CREDENTIALS: "1"
# Harness runs are hidden by default so an agent-driven shell never
# paints over a developer's desktop mid-call. Under xvfb there is no
# desktop and nobody to disturb, and an unmapped X11 window does not
# behave like an unmapped macOS one: these specs went red the moment
# hidden mode landed, while passing hidden on macOS. So CI opts back
# into visible windows, which is also exactly what it did before.
BRAINSTORM_TEST_VISIBLE: "1"
run: xvfb-run --auto-servernum -- npx playwright test --config=playwright.e2e.config.ts
- name: KBN keyboard specs (xvfb)
env:
ELECTRON_DISABLE_SANDBOX: "1"
BRAINSTORM_DEV_INSECURE_CREDENTIALS: "1"
# Keyboard specs need a focused window, which an unmapped one is not.
BRAINSTORM_TEST_VISIBLE: "1"
run: xvfb-run --auto-servernum -- npx playwright test --config=playwright.config.ts kbn-
- name: Upload failure artefacts
if: failure()
uses: actions/upload-artifact@v4
with:
name: e2e-smoke-results
path: |
test-results/
tests/e2e/results/
tests/perf/results/
retention-days: 7