| 123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179 |
- # CI for the node-addon-system packages under native/system. A separate
- # workflow from ci.yml keeps the native OS/architecture matrix independent of
- # the harness Node matrix. Release assembly and publication use the companion
- # Node Addon System Release workflow.
- name: Node Addon System
- on:
- pull_request:
- paths:
- - '.github/workflows/node-addon-system.yml'
- - '.github/workflows/node-addon-system-release.yml'
- - 'native/system/**'
- - 'package.json'
- - 'pnpm-lock.yaml'
- - 'pnpm-workspace.yaml'
- push:
- branches: [master]
- paths:
- - '.github/workflows/node-addon-system.yml'
- - '.github/workflows/node-addon-system-release.yml'
- - 'native/system/**'
- - 'package.json'
- - 'pnpm-lock.yaml'
- - 'pnpm-workspace.yaml'
- workflow_dispatch:
- concurrency:
- group: ${{ github.workflow }}-${{ github.ref }}
- cancel-in-progress: true
- permissions:
- contents: read
- env:
- # CI runs must never report to the production telemetry endpoint baked
- # into apps/cli/cordis.yml (AppCLIEntry disables the row when set).
- DSH_TELEMETRY_DISABLED: '1'
- defaults:
- run:
- working-directory: native/system
- jobs:
- matrix:
- name: Matrix
- runs-on: ubuntu-24.04
- outputs:
- ci: ${{ steps.matrix.outputs.ci }}
- compatibility: ${{ steps.matrix.outputs.compatibility }}
- steps:
- - uses: actions/checkout@v4
- - id: matrix
- run: |
- echo "ci=$(node ./scripts/github-matrix.mjs ci)" >> "$GITHUB_OUTPUT"
- echo "compatibility=$(node ./scripts/github-matrix.mjs compatibility)" >> "$GITHUB_OUTPUT"
- native:
- name: ${{ matrix.platform }}
- needs: matrix
- runs-on: ${{ matrix.runner }}
- strategy:
- fail-fast: false
- matrix: ${{ fromJson(needs.matrix.outputs.ci) }}
- steps:
- - uses: actions/checkout@v4
- - uses: pnpm/action-setup@v4
- with:
- package_json_file: package.json
- - uses: actions/setup-node@v4
- with:
- node-version: 24
- cache: pnpm
- cache-dependency-path: pnpm-lock.yaml
- - name: Install dependencies
- run: pnpm install --filter @deepseek-ai/node-addon-system-workspace... --frozen-lockfile
- - name: Install musl toolchain
- if: runner.os == 'Linux'
- run: |
- sudo apt-get update -q
- sudo apt-get install -yq musl-tools
- - name: Build TypeScript
- run: pnpm build:ts
- - name: Typecheck
- run: pnpm typecheck
- - name: Build native binaries (this architecture is the builder of record)
- run: pnpm build:native
- - name: Entry tests (keyless)
- run: node ./test/entry.test.js
- # NALR_REQUIRE_LANDLOCK: a self-skip on the very platform that exists to
- # prove enforcement would be a false green, so an unenforcing kernel
- # fails the leg instead of skipping.
- - name: Launcher tests (real kernel enforcement)
- if: runner.os == 'Linux'
- run: node ./test/launcher.test.js
- env:
- NALR_REQUIRE_LANDLOCK: 1
- - name: Pack rehearsal (pack → install → confine, this platform only)
- run: |
- node ./scripts/pack-release.mjs .release/npm --current-platform-only
- node ./scripts/verify-packed-install.mjs .release/npm --current-platform-only
- env:
- NALR_REQUIRE_LANDLOCK: ${{ runner.os == 'Linux' && '1' || '0' }}
- - name: Verify platform payload rules
- run: pnpm test:packaging
- - name: Flock behavior (built addon)
- run: |
- pnpm build:test-oracle
- pnpm test:flock
- - name: Upload this platform's built addon and entry
- uses: actions/upload-artifact@v4
- with:
- name: system-compat-${{ matrix.platform }}
- path: |
- native/system/packages/*/bin/**
- native/system/packages/entry/lib/**
- if-no-files-found: error
- - name: Upload independent syscall test oracle
- uses: actions/upload-artifact@v4
- with:
- name: system-oracle-${{ matrix.platform }}
- path: native/system/test/bin/**
- if-no-files-found: error
- compatibility:
- name: ${{ matrix.platform }} / Node ${{ matrix.node }} (same binary)
- needs: [matrix, native]
- strategy:
- fail-fast: false
- matrix:
- include: ${{ fromJson(needs.matrix.outputs.compatibility) }}
- runs-on: ${{ matrix.runner }}
- steps:
- - uses: actions/checkout@v4
- - uses: actions/setup-node@v4
- with:
- node-version: ${{ matrix.node }}
- - name: Download the original platform build
- uses: actions/download-artifact@v4
- with:
- name: system-compat-${{ matrix.platform }}
- path: native/system/packages
- - name: Download independent syscall test oracle
- uses: actions/download-artifact@v4
- with:
- name: system-oracle-${{ matrix.platform }}
- path: native/system/test/bin
- - name: Restore oracle executable permissions
- run: find ./test/bin -type f -name flock-oracle -exec chmod +x {} +
- - name: Test without rebuilding or installing dependencies
- run: |
- node ./test/link-platform.mjs
- node --test ./test/flock.test.js ./test/package-matrix.test.js
- - name: Test the same musl addon without a compiler
- if: runner.os == 'Linux'
- run: >-
- docker run --rm -v "$PWD:$PWD" -w "$PWD"
- node:${{ matrix.node }}-alpine
- node --test ./test/flock.test.js ./test/package-matrix.test.js
|