ci-workflow.spec.ts 49 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327328329330331332333334335336337338339340341342343344345346347348349350351352353354355356357358359360361362363364365366367368369370371372373374375376377378379380381382383384385386387388389390391392393394395396397398399400401402403404405406407408409410411412413414415416417418419420421422423424425426427428429430431432433434435436437438439440441442443444445446447448449450451452453454455456457458459460461462463464465466467468469470471472473474475476477478479480481482483484485486487488489490491492493494495496497498499500501502503504505506507508509510511512513514515516517518519520521522523524525526527528529530531532533534535536537538539540541542543544545546547548549550551552553554555556557558559560561562563564565566567568569570571572573574575576577578579580581582583584585586587588589590591592593594595596597598599600601602603604605606607608609610611612613614615616617618619620621622623624625626627628629630631632633634635636637638639640641642643644645646647648649650651652653654655656657658659660661662663664665666667668669670671672673674675676677678679680681682683684685686687688689690691692693694695696697698699700701702703704705706707708709710711712713714715716717718719720721722723724725726727728729730731732733734735736737738739740741742743744745746747748749750751752753754755756757758759760761762763764765766767768769770771772773774775776777778779780781782783784785786787788789790791792793794795796797798799800801802803804805806807808809810811812813814815816817818819820821822823824825826827828829830831832833834835836837838839840841842843844845846847848849850851852853854855856857858859860861862863864865866867868869870871872873874875876877878879880881882883884885886887888889890891892893894895896897898899900901902903904
  1. import { readFileSync } from 'node:fs'
  2. import { resolve } from 'node:path'
  3. import * as yaml from 'js-yaml'
  4. import { describe, expect, it } from 'vitest'
  5. const root = resolve(import.meta.dirname, '..')
  6. const runnerPrivatePnpmDestination = /^\$\{\{ runner\.temp \}\}\/setup-pnpm-\$\{\{ github\.run_id \}\}-\$\{\{ github\.run_attempt \}\}$/
  7. const nativeWindowsPnpmDestination = '${{ runner.temp }}/setup-pnpm-js-${{ github.run_id }}-${{ github.run_attempt }}-${{ github.job }}'
  8. describe('CI workflow', () => {
  9. it('isolates every pnpm action setup destination per runner', () => {
  10. const files = ['.github/workflows/ci.yml', '.github/workflows/ci-master.yml']
  11. const setups: Array<{ jobName: string; step: unknown }> = []
  12. for (const file of files) {
  13. const workflow: unknown = yaml.load(readFileSync(resolve(root, file), 'utf8'))
  14. if (!isRecord(workflow) || !isRecord(workflow.jobs)) throw new TypeError(`${file} must define jobs`)
  15. for (const [jobName, job] of Object.entries(workflow.jobs)) {
  16. if (!isRecord(job) || !Array.isArray(job.steps)) continue
  17. for (const step of job.steps) {
  18. if (!isRecord(step) || typeof step.uses !== 'string' || !step.uses.startsWith('pnpm/action-setup@')) continue
  19. setups.push({ jobName, step })
  20. }
  21. }
  22. }
  23. expect(setups.length).toBeGreaterThan(0)
  24. for (const { jobName, step } of setups) {
  25. const stepDest = (step as { with?: { dest?: unknown } }).with?.dest
  26. if (jobName.startsWith('windows-')) {
  27. expect(stepDest, `${jobName} must use the native Windows pnpm destination`).toBe(nativeWindowsPnpmDestination)
  28. expect(step).not.toMatchObject({ with: { standalone: true } })
  29. } else {
  30. expect(typeof stepDest, `${jobName} must use a runner-and-run-private pnpm destination`).toBe('string')
  31. expect(stepDest as string).toMatch(runnerPrivatePnpmDestination)
  32. }
  33. }
  34. })
  35. it('isolates the python SDK exe pnpm setup destination per job', () => {
  36. const workflow: unknown = yaml.load(readFileSync(resolve(root, '.github/workflows/build-exe-for-python-sdk.yml'), 'utf8'))
  37. if (!isRecord(workflow) || !isRecord(workflow.jobs)) throw new TypeError('build-exe-for-python-sdk.yml must define jobs')
  38. const setups: Array<{ step: unknown }> = []
  39. for (const job of Object.values(workflow.jobs)) {
  40. if (!isRecord(job) || !Array.isArray(job.steps)) continue
  41. for (const step of job.steps) {
  42. if (!isRecord(step) || typeof step.uses !== 'string' || !step.uses.startsWith('pnpm/action-setup@')) continue
  43. setups.push({ step })
  44. }
  45. }
  46. expect(setups.length).toBeGreaterThan(0)
  47. for (const { step } of setups) {
  48. expect(step).toMatchObject({
  49. with: { dest: nativeWindowsPnpmDestination },
  50. })
  51. }
  52. })
  53. it('keeps required Wine and split native Windows jobs with failover, plus a master-only standby', () => {
  54. const workflow = loadWorkflow('.github/workflows/ci.yml')
  55. const masterWorkflow = loadWorkflow('.github/workflows/ci-master.yml')
  56. if (!isRecord(workflow.jobs)
  57. || !isRecord(workflow.jobs.windows)
  58. || !isRecord(workflow.jobs['windows-build'])
  59. || !isRecord(workflow.jobs['windows-coverage'])
  60. || !isRecord(workflow.jobs['windows-native-tests'])
  61. || !isRecord(workflow.jobs['windows-observational'])
  62. || !isRecord(workflow.jobs['node-24'])
  63. || !isRecord(workflow.jobs['node-24-coverage'])
  64. || !isRecord(workflow.jobs['node-24-bench'])
  65. || !isRecord(workflow.jobs['node-24-consumers'])
  66. || !isRecord(workflow.jobs['node-compat'])
  67. || !isRecord(workflow.jobs['all-checks-passed'])
  68. || !isRecord(masterWorkflow.jobs)
  69. || !isRecord(masterWorkflow.jobs['wine-apt-cache'])
  70. || !isRecord(masterWorkflow.jobs['serial-windows'])) {
  71. throw new TypeError('CI workflow must define windows, windows-build, windows-coverage, windows-native-tests, windows-observational, node-24, node-24-coverage, node-24-bench, node-24-consumers, node-compat, and all-checks-passed; ci-master must define wine-apt-cache and serial-windows')
  72. }
  73. const windows = workflow.jobs.windows
  74. const windowsBuild = workflow.jobs['windows-build']
  75. const windowsCoverage = workflow.jobs['windows-coverage']
  76. const windowsNativeTests = workflow.jobs['windows-native-tests']
  77. const windowsObservational = workflow.jobs['windows-observational']
  78. const wineAptCache = masterWorkflow.jobs['wine-apt-cache']
  79. const serialWindows = masterWorkflow.jobs['serial-windows']
  80. const node24 = workflow.jobs['node-24']
  81. const node24Coverage = workflow.jobs['node-24-coverage']
  82. const node24Bench = workflow.jobs['node-24-bench']
  83. const node24Consumers = workflow.jobs['node-24-consumers']
  84. const nodeCompat = workflow.jobs['node-compat']
  85. const aggregate = workflow.jobs['all-checks-passed']
  86. if (!Array.isArray(windows.steps) || !Array.isArray(aggregate.needs)) {
  87. throw new TypeError('Windows job must define steps and the aggregate must define needs')
  88. }
  89. const commandSteps = windows.steps.filter((step): step is Record<string, unknown> & { run: string } => (
  90. isRecord(step) && typeof step.run === 'string'
  91. ))
  92. // Required PR job: Wine on ubuntu-latest, runs wine-windows-gates.sh.
  93. expect(windows['runs-on']).toBe('ubuntu-latest')
  94. expect(windows.name).toBe('windows node 24 / wine blocking')
  95. expect(windows.if).toBe("github.event_name == 'pull_request'")
  96. expect(commandSteps.some(step => step.run.includes('wine-windows-gates.sh'))).toBe(true)
  97. // The split native jobs all resolve their pool through the Windows switch.
  98. for (const [jobName, job] of [['windows-build', windowsBuild], ['windows-coverage', windowsCoverage], ['windows-native-tests', windowsNativeTests], ['windows-observational', windowsObservational]] as const) {
  99. expect(typeof job['runs-on']).toBe('string')
  100. expect(job['runs-on'], `${jobName} runs-on must use the Windows failover switch`).toContain('DSH_CI_FAILOVER_WINDOWS')
  101. expect(job['runs-on'], `${jobName} runs-on must not use the Linux failover switch`).not.toContain('DSH_CI_FAILOVER_LINUX')
  102. expect(job['runs-on']).toContain('self-hosted')
  103. expect(job['runs-on']).toContain('dsh-win-ci')
  104. expect(job['runs-on']).toContain('dsh-windows-2025-16core')
  105. expect(job.if).toBe("github.event_name == 'pull_request'")
  106. }
  107. // windows-build runs the blocking build/site pair.
  108. expect(windowsBuild.name).toBe('windows node 24 / build')
  109. const buildSteps = windowsBuild.steps as unknown[]
  110. const buildCommands = buildSteps.filter((step): step is Record<string, unknown> & { run: string } => (
  111. isRecord(step) && typeof step.run === 'string'
  112. ))
  113. expect(buildCommands.map(step => step.run)).toContain('pnpm run check:ci:windows-blocking')
  114. // The four native Windows installs branch on the workspace filesystem:
  115. // clone (ReFS block clone) only on ReFS, plain install elsewhere. This
  116. // keeps the TS6231 store-path leak (see the Windows ReFS store note) out
  117. // of the self-hosted pool without forcing clone onto hosted NTFS, which
  118. // rejects copy-on-write. The branch must stay, or a hosted fallback would
  119. // fail installs with ERR_PNPM_LINKING_FAILED.
  120. for (const [jobName, job] of [['windows-build', windowsBuild], ['windows-coverage', windowsCoverage], ['windows-native-tests', windowsNativeTests], ['windows-observational', windowsObservational]] as const) {
  121. const steps = job.steps as unknown[]
  122. const install = steps.find((step): step is Record<string, unknown> & { run: string } => (
  123. isRecord(step) && step.name === 'Install (immutable)' && typeof step.run === 'string'
  124. ))
  125. expect(install, `${jobName} must define the filesystem-branched install`).toBeDefined()
  126. expect(install!.run).toContain("$fs -eq 'ReFS'")
  127. expect(install!.run).toContain('--package-import-method=clone')
  128. expect(install!.run).toContain('corepack pnpm install')
  129. // The else branch must keep the plain hosted install as a distinct line
  130. // (not the corepack clone line, which contains the same substring);
  131. // dropping it or making both branches clone would force clone onto
  132. // NTFS, which rejects copy-on-write (ERR_PNPM_LINKING_FAILED). The
  133. // YAML folded block keeps the first statement on line 1 and folds the
  134. // rest with leading two-space indents.
  135. const installLines = install!.run.split('\n').map(line => line.trim())
  136. expect(installLines).toContain('} else {')
  137. expect(installLines.some(line => line === 'pnpm install --frozen-lockfile'), `${jobName} else branch must keep the plain hosted install`).toBe(true)
  138. // The ReFS branch must not use the interpolated empty-flag form, which
  139. // passes a stray "" positional argument to pnpm.
  140. expect(install!.run).not.toContain('$cloneFlag')
  141. }
  142. // windows-coverage uses the lower 4-partition profile.
  143. expect(windowsCoverage.name).toBe('windows node 24 / coverage')
  144. expect(windowsCoverage.env).toMatchObject({ DSH_COVERAGE_PARTITIONS: '4' })
  145. const coverageSteps = windowsCoverage.steps as unknown[]
  146. const coverageCommands = coverageSteps.filter((step): step is Record<string, unknown> & { run: string } => (
  147. isRecord(step) && typeof step.run === 'string'
  148. ))
  149. expect(coverageCommands.map(step => step.run)).toContain('pnpm run check:ci:coverage')
  150. // Windows coverage runs zero-build like the Linux lane: workspace imports
  151. // resolve to src through the tsconfig paths map, and the lib-consuming
  152. // suites (webworker-packer image-loadable, webworker-runtime
  153. // transform-corpus, client ui-trajectory client-bundle) self-skip on
  154. // unbuilt checkouts. The regex catches a regression spelled as
  155. // 'corepack pnpm run build' or folded into a multi-line run block, which
  156. // an exact string match would miss.
  157. expect(coverageCommands.every(step => !/\bpnpm\s+run\s+build(?:\s|$)/.test(step.run))).toBe(true)
  158. // windows-native-tests runs the Windows-specific specs.
  159. expect(windowsNativeTests.name).toBe('windows node 24 / native tests')
  160. const nativeTestSteps = windowsNativeTests.steps as unknown[]
  161. const nativeTestCommands = nativeTestSteps.filter((step): step is Record<string, unknown> & { run: string } => (
  162. isRecord(step) && typeof step.run === 'string'
  163. ))
  164. const nativeTestCommand = nativeTestCommands.map(step => step.run).join('\n')
  165. expect(nativeTestCommand).toContain('--no-file-parallelism')
  166. expect(nativeTestCommand).toContain('--testTimeout 90000')
  167. expect(nativeTestCommand).toContain('tool-pwsh/tests/loader.spec.ts')
  168. expect(nativeTestCommand).toContain('workflow-worker-thread.spec.ts')
  169. // windows-observational is non-blocking.
  170. expect(windowsObservational.name).toBe('windows node 24 / observational')
  171. expect(windowsObservational['continue-on-error']).toBe(true)
  172. // wine-apt-cache: master-only, seeds the Wine apt cache, lives in ci-master.
  173. expect(wineAptCache.if).toBe("github.event_name == 'push' && github.ref == 'refs/heads/master'")
  174. expect(wineAptCache['runs-on']).toBe('ubuntu-latest')
  175. // serial-windows: master-only standby, self-hosted, non-blocking, lives in ci-master.
  176. expect(serialWindows.if).toBe("github.event_name == 'push' && github.ref == 'refs/heads/master'")
  177. expect(serialWindows['runs-on']).toEqual(['self-hosted', 'dsh-win-ci', 'windows'])
  178. expect(serialWindows.name).toBe('serial / windows (self-hosted standby)')
  179. // Its store must share the ReFS workspace volume for clone; the install
  180. // must carry the same filesystem branch as the PR jobs.
  181. const serialSteps = serialWindows.steps as unknown[]
  182. const serialStore = serialSteps.find((step): step is Record<string, unknown> & { run: string } => (
  183. isRecord(step) && step.name === 'Configure persistent pnpm store' && typeof step.run === 'string'
  184. ))
  185. expect(serialStore).toBeDefined()
  186. expect(serialStore!.run).toContain('F:\\.pnpm-store')
  187. const serialInstall = serialSteps.find((step): step is Record<string, unknown> & { run: string } => (
  188. isRecord(step) && step.name === 'Install (immutable)' && typeof step.run === 'string'
  189. ))
  190. expect(serialInstall).toBeDefined()
  191. expect(serialInstall!.run).toContain("$fs -eq 'ReFS'")
  192. expect(serialInstall!.run).toContain('--package-import-method=clone')
  193. expect(serialInstall!.run).toContain('corepack pnpm install')
  194. // Distinct else-branch line, as for the PR jobs: the corepack clone line
  195. // contains the plain-install substring too.
  196. expect(serialInstall!.run.split('\n').map(line => line.trim())).toContain('} else {')
  197. expect(serialInstall!.run.split('\n').map(line => line.trim())).toContain('pnpm install --frozen-lockfile')
  198. expect(serialInstall!.run).not.toContain('$cloneFlag')
  199. // The unsharded reference runs the whole coverage inventory at the same
  200. // per-test budget the PR coverage lane grants; the default 5000ms times
  201. // out load-sensitive store scans (e.g. gen-third-party-notices).
  202. const serialGate = serialSteps.find((step): step is Record<string, unknown> & { env?: Record<string, unknown> } => (
  203. isRecord(step) && step.name === 'Run complete unsharded Windows gate inventory serially'
  204. ))
  205. expect(serialGate).toBeDefined()
  206. expect(serialGate!.env).toMatchObject({ DSH_COVERAGE_TEST_TIMEOUT_MS: '90000' })
  207. // Aggregate: Wine and the required split native jobs are needed;
  208. // windows-coverage is temporarily non-blocking while Windows ACP
  209. // half-close tests are stabilized; observational stays out too.
  210. expect(aggregate.needs).toContain('windows')
  211. expect(aggregate.needs).toContain('windows-build')
  212. // The benchmark lane is a required verdict input and runs alone so its
  213. // wall-clock budgets never share a runner with a concurrent aggregate.
  214. expect(aggregate.needs).toContain('node-24-bench')
  215. expect(node24Bench.name).toBe('node 24 / benchmarks')
  216. expect(node24Bench.env).toBeUndefined()
  217. expect(aggregate.needs).not.toContain('windows-coverage')
  218. expect(aggregate.needs).toContain('windows-native-tests')
  219. expect(aggregate.needs).not.toContain('windows-observational')
  220. expect(aggregate.needs).not.toContain('serial-windows')
  221. // Linux failover is a separate switch: the three enterprise Linux workers
  222. // and the verdict job resolve their pool through DSH_CI_FAILOVER_LINUX,
  223. // never the Windows switch.
  224. for (const [jobName, job] of [['node-24', node24], ['node-24-coverage', node24Coverage], ['node-24-consumers', node24Consumers]] as const) {
  225. expect(typeof job['runs-on']).toBe('string')
  226. expect(job['runs-on'], `${jobName} runs-on must use the Linux failover switch`).toContain('DSH_CI_FAILOVER_LINUX')
  227. expect(job['runs-on'], `${jobName} runs-on must not use the Windows failover switch`).not.toContain('DSH_CI_FAILOVER_WINDOWS')
  228. expect(job['runs-on']).toContain('vm-backup')
  229. }
  230. expect(aggregate['runs-on']).toContain('DSH_CI_FAILOVER_LINUX')
  231. expect(aggregate['runs-on']).not.toContain('DSH_CI_FAILOVER_WINDOWS')
  232. expect(aggregate['runs-on']).toContain('vm-backup')
  233. // The run-gates aggregate lanes stop at the first blocking gate failure so
  234. // a red aggregate does not keep burning runner time on the remaining
  235. // gates. Removing the flag silently reverts to running every independent
  236. // gate to completion.
  237. for (const [jobName, job] of [['node-24', node24], ['node-24-coverage', node24Coverage], ['node-24-consumers', node24Consumers], ['node-compat', nodeCompat]] as const) {
  238. expect(job.env, `${jobName} must enable fail-fast`).toMatchObject({ DSH_GATE_FAIL_FAST: '1' })
  239. }
  240. // The native Windows lanes with run-gates aggregates fail fast for the
  241. // same reason: a failing gate aborts the sibling gate instead of waiting
  242. // out the multi-minute instrumented coverage run.
  243. expect(windowsBuild.env, 'windows-build must enable fail-fast').toMatchObject({ DSH_GATE_FAIL_FAST: '1' })
  244. expect(windowsCoverage.env, 'windows-coverage must enable fail-fast').toMatchObject({ DSH_GATE_FAIL_FAST: '1' })
  245. // The observational lane stays complete: it is continue-on-error by design
  246. // and exists to collect as much Windows-native evidence per run as
  247. // possible, so the first failure must not truncate the rest.
  248. expect(windowsObservational.env).toBeDefined()
  249. expect(windowsObservational.env).not.toMatchObject({ DSH_GATE_FAIL_FAST: '1' })
  250. })
  251. it('runs required benchmarks on standard hosted Linux independently of failover', () => {
  252. const workflow = loadWorkflow('.github/workflows/ci.yml')
  253. const benchmark = workflowJob(workflow, 'node-24-bench')
  254. const aggregate = workflowJob(workflow, 'all-checks-passed')
  255. expect(benchmark['runs-on']).toBe('ubuntu-24.04')
  256. expect(benchmark.if).toBe("github.event_name == 'pull_request'")
  257. expect(benchmark.needs).toBeUndefined()
  258. expect(benchmark['continue-on-error']).toBeUndefined()
  259. expect(benchmark.env).toBeUndefined()
  260. expect(aggregate.needs).toContain('node-24-bench')
  261. })
  262. it('always restores the hosted benchmark pnpm cache', () => {
  263. const benchmark = workflowJob(loadWorkflow('.github/workflows/ci.yml'), 'node-24-bench')
  264. if (!Array.isArray(benchmark.steps)) throw new TypeError('benchmark job must define steps')
  265. const caches = benchmark.steps.filter(step => isRecord(step) && step.uses === 'actions/cache/restore@v4')
  266. expect(caches).toHaveLength(1)
  267. expect(caches[0]).not.toHaveProperty('if')
  268. expect(caches[0]).toMatchObject({
  269. with: {
  270. path: '${{ steps.pnpm-store.outputs.path }}',
  271. key: "${{ runner.os }}-node-${{ env.PRIMARY_NODE_VERSION }}-pnpm-${{ hashFiles('pnpm-lock.yaml') }}",
  272. },
  273. })
  274. })
  275. it('bounds the complete benchmark job to fifteen minutes', () => {
  276. const benchmark = workflowJob(loadWorkflow('.github/workflows/ci.yml'), 'node-24-bench')
  277. expect(benchmark['timeout-minutes']).toBe(15)
  278. expect(benchmark.steps).toContainEqual({
  279. name: 'Run performance benchmarks',
  280. env: { DSH_GATE_VERBOSE: '1' },
  281. run: 'pnpm run check:ci:bench',
  282. })
  283. })
  284. it('gives the Wine Host TypeScript compile the repository heap budget', () => {
  285. const wineGates = readFileSync(resolve(root, 'scripts/wine-windows-gates.sh'), 'utf8')
  286. expect(wineGates).toContain(
  287. 'wine_node "$scratch/logs/host-tsc.log" --max-old-space-size=4096 "$tsc_js" -b tsconfig.host.json --pretty false',
  288. )
  289. })
  290. it('exempts push from cancellation in ci-master, so one master merge does not cancel the running drill', () => {
  291. const workflow = loadWorkflow('.github/workflows/ci-master.yml')
  292. const prWorkflow = loadWorkflow('.github/workflows/ci.yml')
  293. if (!isRecord(workflow.jobs) || !isRecord(workflow.concurrency)) {
  294. throw new TypeError('ci-master workflow must define jobs and a workflow-level concurrency block')
  295. }
  296. if (!isRecord(prWorkflow.jobs)) {
  297. throw new TypeError('ci workflow must define jobs')
  298. }
  299. // Cancellation applies to the whole superseded RUN, so this has to be
  300. // decided at workflow level and gated on the event: a job-level group
  301. // cannot exempt its job from its run being cancelled. Only push is exempt —
  302. // a drill takes longer than the interval between master merges. The negated
  303. // form is load-bearing: `== 'pull_request'` would also stop cancelling
  304. // workflow_dispatch, and a re-dispatched runner benchmark holds up to 12
  305. // larger runners for 15 minutes in this same group on master.
  306. expect(workflow.concurrency['cancel-in-progress']).toBe("${{ github.event_name != 'push' }}")
  307. // The PR-only ci.yml still cancels a superseded run on a new push, so a
  308. // fresh head does not stack a second full 9-job run behind a stale one.
  309. // Unlike ci-master it has no push carve-out: every PR event supersedes.
  310. expect(prWorkflow.concurrency).toMatchObject({
  311. 'cancel-in-progress': true,
  312. })
  313. // The exact event sets are what keep master-only jobs out of the PR check
  314. // panel: ci-master triggers only on push(master) + workflow_dispatch and
  315. // never on pull_request; ci.yml is exactly pull_request-only. Assert the
  316. // full sets so losing the wrong event, or gaining an extra one, fails.
  317. if (!isRecord(workflow.on) || !isRecord(prWorkflow.on)) {
  318. throw new TypeError('both CI workflows must define on')
  319. }
  320. expect(Object.keys(workflow.on).sort()).toEqual(['push', 'workflow_dispatch'])
  321. expect(Object.keys(prWorkflow.on)).toEqual(['pull_request'])
  322. // Neither drill may carry a job-level group: it would not exempt the job
  323. // from run-scoped cancellation.
  324. for (const name of ['serial-linux-selfhosted', 'serial-windows']) {
  325. const job = workflow.jobs[name]
  326. if (!isRecord(job)) throw new TypeError(`${name} must be defined`)
  327. expect(job.concurrency).toBeUndefined()
  328. // Both stay master-push-only; that is what makes the push carve-out safe.
  329. expect(job.if).toBe("github.event_name == 'push' && github.ref == 'refs/heads/master'")
  330. }
  331. // What bounds the cost of exempting push: a master push may only carry the
  332. // cache seeder and the two drills. Any job reachable on push would start
  333. // accumulating uncancelled runs, so the set is pinned here.
  334. const NOT_PUSH_REACHABLE = new Set([
  335. "github.event_name == 'workflow_dispatch' && inputs.suite == 'larger-runner-benchmark'",
  336. "github.event_name == 'workflow_dispatch' && inputs.suite == 'consolidated-runner-benchmark'",
  337. ])
  338. const pushReachable = Object.entries(workflow.jobs)
  339. .filter(([, job]) => {
  340. if (!isRecord(job)) return false
  341. if (job.if === undefined) return true // unconditional: runs on every event
  342. if (job.if === false) return false // `if: false` parses as a boolean
  343. if (typeof job.if !== 'string') return true // unrecognized shape: surface it
  344. return !NOT_PUSH_REACHABLE.has(job.if.trim())
  345. })
  346. .map(([name]) => name)
  347. .sort()
  348. expect(pushReachable).toEqual(['serial-linux-selfhosted', 'serial-windows', 'wine-apt-cache'])
  349. // Why workflow_dispatch must keep cancelling: each benchmark fans out to a
  350. // dozen larger runners at once, in this same group on master. If it stopped
  351. // cancelling, a re-dispatch would queue ahead of a drill instead of
  352. // replacing the stale measurement.
  353. for (const name of ['larger-runner-benchmark', 'consolidated-runner-benchmark']) {
  354. const job = workflow.jobs[name]
  355. if (!isRecord(job) || !isRecord(job.strategy)) {
  356. throw new TypeError(`${name} must define a matrix strategy`)
  357. }
  358. expect(job.strategy['max-parallel']).toBe(12)
  359. expect(job['timeout-minutes']).toBe(15)
  360. }
  361. })
  362. it('keeps supported LSP source under native Windows coverage', () => {
  363. const config = readFileSync(resolve(root, 'vitest.config.ts'), 'utf8')
  364. expect(config).not.toContain('packages/lsp/lsp-stdio/src/connection.ts')
  365. expect(config).not.toContain('packages/lsp/lsp-stdio/src/index.ts')
  366. expect(config).not.toContain('packages/lsp/lsp-stdio/src/instance.ts')
  367. })
  368. it('requires release-shaped Python runtime validation on every published target', () => {
  369. const workflow = loadWorkflow('.github/workflows/ci.yml')
  370. const pythonRuntime = workflowJob(workflow, 'python-runtime')
  371. const aggregate = workflowJob(workflow, 'all-checks-passed')
  372. if (!Array.isArray(aggregate.needs)) {
  373. throw new TypeError('CI aggregate must define required job dependencies')
  374. }
  375. expect(pythonRuntime).toMatchObject({
  376. if: "github.event_name == 'pull_request'",
  377. name: 'python runtime / release-shaped matrix',
  378. uses: './.github/workflows/build-exe-for-python-sdk.yml',
  379. with: {
  380. targets: 'node24-linux-x64,node24-linux-arm64,node24-macos-arm64,node24-macos-x64,node24-win-x64',
  381. ci: true,
  382. },
  383. secrets: {
  384. DEEPSEEK_API_KEY_EXTERNAL: '${{ secrets.DEEPSEEK_API_KEY_EXTERNAL }}',
  385. },
  386. })
  387. expect(aggregate.needs).toContain('python-runtime')
  388. })
  389. it('keeps every Vitest project process-isolated on native Windows', () => {
  390. const config = readFileSync(resolve(root, 'vitest.config.ts'), 'utf8')
  391. expect(config).not.toContain("pool: process.platform === 'win32' ? 'threads' : 'forks'")
  392. expect(config.match(/pool: 'forks'/g)).toHaveLength(2)
  393. })
  394. })
  395. describe('DeepSeek e2e workflow', () => {
  396. it('prepares bubblewrap from the pinned payload without a package transaction', () => {
  397. const workflow = loadWorkflow('.github/workflows/e2e.yml')
  398. const e2e = workflowJob(workflow, 'e2e')
  399. if (!Array.isArray(e2e.steps)) throw new TypeError('DeepSeek e2e workflow must define steps')
  400. const steps = e2e.steps.filter(isRecord)
  401. expect(steps.find(step => step.name === 'Prepare bubblewrap (unrestrict userns)')).toMatchObject({
  402. run: 'bash scripts/prepare-ci-bubblewrap.sh',
  403. })
  404. expect(JSON.stringify(steps)).not.toContain('apt-get')
  405. })
  406. it('bounds profile subprocess fan-out to the tested e2e default', () => {
  407. const workflow = loadWorkflow('.github/workflows/e2e.yml')
  408. const e2e = workflowJob(workflow, 'e2e')
  409. if (!Array.isArray(e2e.steps)) throw new TypeError('DeepSeek e2e workflow must define steps')
  410. const step = e2e.steps.filter(isRecord).find(candidate => candidate.name === 'E2E tests (real DeepSeek API)')
  411. expect(step).toMatchObject({ env: { DSH_E2E_MAX_WORKERS: 4 } })
  412. })
  413. })
  414. describe('E2B e2e workflow', () => {
  415. it('is manual-only and fails loud before running the focused live suite', () => {
  416. const workflow = loadWorkflow('.github/workflows/e2b-e2e.yml')
  417. expect(workflow.on).toEqual({ workflow_dispatch: null })
  418. if (!isRecord(workflow.jobs) || !isRecord(workflow.jobs.e2b) || !Array.isArray(workflow.jobs.e2b.steps)) {
  419. throw new TypeError('E2B e2e workflow must define the e2b job steps')
  420. }
  421. const steps = workflow.jobs.e2b.steps.filter(isRecord)
  422. const preflight = steps.find(step => step.name === 'Preflight (require E2B API key)')
  423. const e2b = steps.find(step => step.name === 'E2B tests (live sandbox)')
  424. expect(preflight).toMatchObject({
  425. env: { E2B_API_KEY: '${{ secrets.E2B_API_KEY_EXTERNAL }}' },
  426. })
  427. expect(preflight?.run).toContain('E2B_API_KEY_EXTERNAL repository secret')
  428. expect(e2b).toMatchObject({
  429. env: {
  430. E2B_API_KEY: '${{ secrets.E2B_API_KEY_EXTERNAL }}',
  431. DSH_E2E_MAX_WORKERS: '1',
  432. DSH_EXAMPLE_MODE: 'lib',
  433. },
  434. })
  435. expect(e2b?.run).toContain('packages/e2b/e2b/tests/composition.e2e.ts')
  436. })
  437. })
  438. describe('Python release workflows', () => {
  439. it('keeps complete wheel validation separate from protected public publication', () => {
  440. const workflow = loadWorkflow('.github/workflows/python-release.yml')
  441. const dispatch = workflowEvent(workflow, 'workflow_dispatch')
  442. const build = workflowJob(workflow, 'build')
  443. const pythonCompat = workflowJob(workflow, 'python-compat')
  444. const validate = workflowJob(workflow, 'validate')
  445. const publishRuntime = workflowJob(workflow, 'publish-runtime')
  446. const publishSdk = workflowJob(workflow, 'publish-sdk')
  447. if (!isRecord(dispatch.inputs)
  448. || !isRecord(dispatch.inputs.publish)
  449. || !Array.isArray(pythonCompat.steps)
  450. || !Array.isArray(validate.steps)
  451. || !Array.isArray(publishRuntime.steps)
  452. || !Array.isArray(publishSdk.steps)) {
  453. throw new TypeError('Python release workflow must define publish input and release steps')
  454. }
  455. expect(dispatch.inputs.publish).toMatchObject({ type: 'boolean', default: false })
  456. if (!isRecord(workflow.on)) throw new TypeError('python-release workflow must define on')
  457. expect(Object.keys(workflow.on)).toEqual(['workflow_dispatch'])
  458. expect(build).toMatchObject({
  459. uses: './.github/workflows/build-exe-for-python-sdk.yml',
  460. with: {
  461. targets: 'node24-linux-x64,node24-linux-arm64,node24-macos-arm64,node24-macos-x64,node24-win-x64',
  462. release: true,
  463. },
  464. })
  465. expect(pythonCompat.strategy).toMatchObject({ matrix: { python: ['3.10', '3.14'] } })
  466. const pythonCompatSteps = JSON.stringify(pythonCompat.steps)
  467. expect(pythonCompatSteps).toContain('dist/deepseek_harness_sdk-$VERSION-py3-none-any.whl')
  468. expect(pythonCompatSteps).toContain('dist/deepseek_harness_runtime_bin-$VERSION-py3-none-manylinux_2_28_x86_64.whl')
  469. expect(pythonCompatSteps).not.toContain('--find-links')
  470. const validateSteps = JSON.stringify(validate.steps)
  471. const authorize = validate.steps.filter(isRecord).find(step => step.name === 'Authorize publication request')
  472. if (!isRecord(authorize) || typeof authorize.run !== 'string') {
  473. throw new TypeError('Python release validation must authorize publication requests')
  474. }
  475. expect(validateSteps).toContain('PUBLIC_PYPI_RELEASE_ENABLED')
  476. expect(authorize).toMatchObject({
  477. env: {
  478. PYPI_PUBLISHER_REPOSITORY: '${{ vars.PYPI_PUBLISHER_REPOSITORY }}',
  479. REPOSITORY: '${{ github.repository }}',
  480. },
  481. })
  482. expect(authorize.run).toContain('[ "$REPOSITORY" = "$PYPI_PUBLISHER_REPOSITORY" ]')
  483. expect(validateSteps).toContain('100000000')
  484. expect(publishRuntime).toMatchObject({
  485. if: "github.event_name == 'workflow_dispatch' && inputs.publish",
  486. needs: 'validate',
  487. environment: 'pypi-runtime',
  488. permissions: { contents: 'read', 'id-token': 'write' },
  489. })
  490. expect(publishSdk).toMatchObject({
  491. if: "github.event_name == 'workflow_dispatch' && inputs.publish",
  492. needs: ['validate', 'publish-runtime'],
  493. environment: 'pypi',
  494. permissions: { contents: 'read', 'id-token': 'write' },
  495. })
  496. const runtimeSteps = publishRuntime.steps.filter(isRecord)
  497. const sdkSteps = publishSdk.steps.filter(isRecord)
  498. const runtimePublish = runtimeSteps.find(step => step.name === 'Publish runtime wheels')
  499. const sdkPublish = sdkSteps.find(step => step.name === 'Publish SDK wheel')
  500. const runtimeHashes = runtimeSteps.find(step => step.name === 'Verify release artifact hashes')
  501. const sdkHashes = sdkSteps.find(step => step.name === 'Verify release artifact hashes')
  502. expect([...runtimeSteps, ...sdkSteps].some(
  503. step => typeof step.uses === 'string' && step.uses.startsWith('actions/checkout@'),
  504. )).toBe(false)
  505. expect([...runtimeSteps, ...sdkSteps].filter(
  506. step => step.uses === 'pypa/gh-action-pypi-publish@release/v1',
  507. )).toHaveLength(2)
  508. expect(runtimePublish).toMatchObject({
  509. with: { 'packages-dir': 'dist/runtime/', attestations: false },
  510. })
  511. expect(sdkPublish).toMatchObject({
  512. with: { 'packages-dir': 'dist/sdk/', attestations: false },
  513. })
  514. expect(runtimeHashes).toMatchObject({ run: 'cd dist && sha256sum -c SHA256SUMS' })
  515. expect(sdkHashes).toMatchObject({ run: 'cd dist && sha256sum -c SHA256SUMS' })
  516. })
  517. it('exposes the native wheel builder to the release caller with normalized versions', () => {
  518. const workflow = loadWorkflow('.github/workflows/build-exe-for-python-sdk.yml')
  519. expect(Object.keys(workflow.on as Record<string, unknown>).sort()).toEqual(['workflow_call', 'workflow_dispatch'])
  520. const call = workflowEvent(workflow, 'workflow_call')
  521. const plan = workflowJob(workflow, 'plan')
  522. const build = workflowJob(workflow, 'build')
  523. if (!isRecord(call.inputs) || !isRecord(call.secrets) || !Array.isArray(plan.steps) || !Array.isArray(build.steps)) {
  524. throw new TypeError('Python wheel builder must define workflow_call inputs and plan steps')
  525. }
  526. const buildSteps: unknown[] = build.steps
  527. const manylinuxAddon = buildSteps.find(step => isRecord(step) && step.name === 'Rebuild Linux node-pty against manylinux 2.28')
  528. const macosCheck = buildSteps.find(step => isRecord(step) && step.name === 'Check macOS payload architecture and deployment target')
  529. const manylinuxSmoke = buildSteps.find(step => isRecord(step) && step.name === 'Run wheel in a manylinux 2.28 container')
  530. const cleanVenvPosix = buildSteps.find(step => isRecord(step) && step.name === 'Install local SDK and runtime wheels into a clean venv (POSIX)')
  531. const cleanVenvWindows = buildSteps.find(step => isRecord(step) && step.name === 'Install local SDK and runtime wheels into a clean venv (Windows)')
  532. const installedKeylessPosix = buildSteps.find(step => isRecord(step) && step.name === 'Run installed-wheel keyless black-box tests (POSIX)')
  533. const installedKeylessWindows = buildSteps.find(step => isRecord(step) && step.name === 'Run installed-wheel keyless black-box tests (Windows)')
  534. const realApiPreflightPosix = buildSteps.find(step => isRecord(step) && step.name === 'Preflight installed-wheel real API test (POSIX)')
  535. const realApiPreflightWindows = buildSteps.find(step => isRecord(step) && step.name === 'Preflight installed-wheel real API test (Windows)')
  536. const installedRealApiPosix = buildSteps.find(step => isRecord(step) && step.name === 'Run installed-wheel real API black-box test (POSIX)')
  537. const installedRealApiWindows = buildSteps.find(step => isRecord(step) && step.name === 'Run installed-wheel real API black-box test (Windows)')
  538. if (!isRecord(macosCheck) || typeof macosCheck.run !== 'string'
  539. || !isRecord(cleanVenvPosix) || !isRecord(cleanVenvWindows)
  540. || !isRecord(installedKeylessPosix) || !isRecord(installedKeylessWindows)
  541. || !isRecord(realApiPreflightPosix) || !isRecord(realApiPreflightWindows)
  542. || !isRecord(installedRealApiPosix) || !isRecord(installedRealApiWindows)) {
  543. throw new TypeError('Python wheel builder must define native POSIX and Windows installed-wheel steps')
  544. }
  545. expect(call.inputs).toHaveProperty('targets')
  546. expect(call.inputs).toMatchObject({
  547. ci: { type: 'boolean', default: false },
  548. release: { type: 'boolean', default: false },
  549. })
  550. expect(call.secrets).toMatchObject({
  551. DEEPSEEK_API_KEY_EXTERNAL: { required: false },
  552. })
  553. expect(workflow.concurrency).toMatchObject({
  554. group: 'build-single-exe-${{ github.workflow }}-${{ github.ref }}',
  555. })
  556. expect(build.defaults).toBeUndefined()
  557. expect(plan.if).toContain('inputs.ci')
  558. expect(plan.if).toContain('inputs.release')
  559. expect(JSON.stringify(plan.steps)).toContain('pep440_version')
  560. const workflowJson = JSON.stringify(workflow)
  561. expect(workflowJson).toContain('macosx_14_0_arm64')
  562. expect(workflowJson).toContain('macosx_14_0_x86_64')
  563. expect(workflowJson).toContain('node24-macos-x64')
  564. expect(workflowJson).toContain('macos-15-intel')
  565. expect(workflowJson).toContain('win_amd64')
  566. expect(workflowJson).toContain('node24-win-x64')
  567. expect(workflowJson).toContain('windows-2025')
  568. expect(workflowJson).toContain('dist-python/$SDK_WHEEL')
  569. expect(workflowJson).toContain('dist-python/$RUNTIME_WHEEL')
  570. expect(workflowJson).toContain('/work/dist-python/$SDK_WHEEL')
  571. expect(workflowJson).toContain('/work/dist-python/$RUNTIME_WHEEL')
  572. expect(workflowJson).not.toContain('--find-links dist-python')
  573. expect(workflowJson).not.toContain('--find-links /work/dist-python')
  574. expect(workflowJson).not.toContain('cygpath')
  575. expect(manylinuxAddon).toMatchObject({ if: "runner.os == 'Linux'" })
  576. expect(JSON.stringify(manylinuxAddon)).toContain('manylinux_2_28_x86_64')
  577. expect(JSON.stringify(manylinuxAddon)).toContain('manylinux_2_28_aarch64')
  578. expect(JSON.stringify(manylinuxAddon)).toContain('npm_config_build_from_source=true pnpm run install')
  579. expect(JSON.stringify(manylinuxAddon)).toContain('pnpm_setup_root')
  580. expect(JSON.stringify(manylinuxAddon)).toContain('$pnpm_setup_root:$pnpm_setup_root:ro')
  581. expect(JSON.stringify(manylinuxAddon)).toContain('node-pty-glibc-versions.txt')
  582. expect(JSON.stringify(manylinuxAddon)).toContain('le 2.28')
  583. expect(macosCheck).toMatchObject({ if: "runner.os == 'macOS'" })
  584. expect(macosCheck.run).toContain('scripts/check-macos-deployment-target.py')
  585. expect(macosCheck.run).toContain('lipo "$payload" -verify_arch')
  586. expect(macosCheck.run).toContain('$EXE-rg')
  587. expect(macosCheck.run).toContain('$EXE-spawn-helper')
  588. expect(JSON.stringify(installedKeylessPosix)).toContain('--scenario all')
  589. expect(JSON.stringify(installedKeylessPosix)).toContain('env -u PYTHONPATH')
  590. expect(JSON.stringify(installedKeylessWindows)).toContain('--scenario all --installed-wheel')
  591. expect(installedKeylessWindows).toMatchObject({ if: "runner.os == 'Windows'", shell: 'pwsh' })
  592. expect(cleanVenvWindows).toMatchObject({ if: "runner.os == 'Windows'", shell: 'pwsh' })
  593. expect(JSON.stringify(cleanVenvWindows)).toContain('Scripts\\\\python.exe')
  594. expect(realApiPreflightPosix).toMatchObject({
  595. env: { DEEPSEEK_API_KEY: '${{ secrets.DEEPSEEK_API_KEY_EXTERNAL }}' },
  596. })
  597. expect(String(realApiPreflightPosix.if)).toContain('inputs.ci')
  598. expect(String(realApiPreflightPosix.if)).toContain('head.repo.fork')
  599. expect(String(realApiPreflightPosix.if)).toContain('dependabot[bot]')
  600. expect(realApiPreflightWindows).toMatchObject({ shell: 'pwsh' })
  601. expect(installedRealApiPosix).toMatchObject({
  602. env: {
  603. DEEPSEEK_API_KEY: '${{ secrets.DEEPSEEK_API_KEY_EXTERNAL }}',
  604. DEEPSEEK_BASE_URL: 'https://api.deepseek.com',
  605. },
  606. })
  607. expect(JSON.stringify(installedRealApiPosix)).toContain('--scenario sdk-live')
  608. expect(JSON.stringify(installedRealApiPosix)).toContain('-u DSH_RUNTIME_MODE')
  609. expect(installedRealApiWindows).toMatchObject({ shell: 'pwsh' })
  610. expect(JSON.stringify(installedRealApiWindows)).toContain('--scenario sdk-live --installed-wheel')
  611. expect(manylinuxSmoke).toMatchObject({ if: "runner.os == 'Linux'" })
  612. expect(JSON.stringify(manylinuxSmoke)).toContain('-e DSH_TELEMETRY_DISABLED')
  613. })
  614. it('uses the shared macOS deployment-target check in GitLab', () => {
  615. const workflow = loadWorkflow('.gitlab-ci.yml')
  616. const runtimeWheel = workflow['.runtime-wheel']
  617. if (!isRecord(runtimeWheel) || !Array.isArray(runtimeWheel.script)) {
  618. throw new TypeError('GitLab CI must define the runtime wheel script')
  619. }
  620. const runtimeScript: unknown[] = runtimeWheel.script
  621. const macosCheck = runtimeScript.find(
  622. step => typeof step === 'string' && step.includes('${PLATFORM#macos-}'),
  623. )
  624. if (typeof macosCheck !== 'string') {
  625. throw new TypeError('GitLab CI must check the macOS deployment target')
  626. }
  627. expect(macosCheck).toContain('scripts/check-macos-deployment-target.py')
  628. expect(macosCheck).toContain('lipo "$payload" -verify_arch')
  629. expect(macosCheck).toContain('"$EXE" "$EXE-rg" "$EXE-spawn-helper"')
  630. })
  631. it('builds the macOS x64 wheel on the matching GitLab runner', () => {
  632. const workflow = loadWorkflow('.gitlab-ci.yml')
  633. const macosX64 = workflow['runtime-macos-x64']
  634. const publish = workflow['publish-python']
  635. if (!isRecord(macosX64) || !isRecord(publish) || !Array.isArray(publish.needs)) {
  636. throw new TypeError('GitLab CI must define the macOS x64 runtime and publication jobs')
  637. }
  638. expect(macosX64.tags).toEqual(['macos-x64'])
  639. expect(macosX64.variables).toMatchObject({ PKG_TARGET: 'node24-macos-x64', PLATFORM: 'macos-x64' })
  640. expect(publish.needs).toContainEqual({ job: 'runtime-macos-x64', artifacts: true })
  641. expect(JSON.stringify(publish.script)).toContain('macosx_14_0_x86_64.whl')
  642. })
  643. it('builds and black-box tests the Windows x64 wheel in GitLab', () => {
  644. const workflow = loadWorkflow('.gitlab-ci.yml')
  645. const windows = workflow['runtime-windows-x64']
  646. const publish = workflow['publish-python']
  647. if (!isRecord(windows) || !Array.isArray(windows.before_script) || !Array.isArray(windows.script)
  648. || !isRecord(publish) || !Array.isArray(publish.needs)) {
  649. throw new TypeError('GitLab CI must define the Windows runtime and aggregate publication jobs')
  650. }
  651. expect(windows.tags).toEqual(['windows-x64'])
  652. expect(windows.variables).toMatchObject({ PKG_TARGET: 'node24-win-x64', PLATFORM: 'win-x64' })
  653. expect(JSON.stringify(windows.before_script)).toContain('.ci-python\\\\Scripts')
  654. expect(JSON.stringify(windows.before_script)).toContain('[IO.Path]::PathSeparator')
  655. expect(JSON.stringify(windows.script)).toContain('win_amd64.whl')
  656. expect(JSON.stringify(windows.script)).toContain('--scenario all --installed-wheel')
  657. expect(publish.needs).toContainEqual({ job: 'runtime-windows-x64', artifacts: true })
  658. })
  659. })
  660. describe('Issue lifecycle workflow', () => {
  661. it('runs the lifecycle job on every PR/review event but gates token and board steps', () => {
  662. const lifecycle = loadWorkflow('.github/workflows/issue-lifecycle.yml')
  663. const policy = loadWorkflow('.github/workflows/issue-policy.yml')
  664. const lifecycleJob = workflowJob(lifecycle, 'lifecycle')
  665. if (!Array.isArray(lifecycleJob.steps)) throw new TypeError('Issue lifecycle job must define steps')
  666. // The job has no job-level `if`, so it is listed on every pull_request /
  667. // pull_request_review event and reports success instead of a gray skip. The
  668. // write-capable steps are gated at step level so approved/commented reviews
  669. // never mint a Project/Issue App token nor touch the board.
  670. expect(lifecycle.on).toHaveProperty('pull_request')
  671. expect(lifecycle.on).toHaveProperty('pull_request_review')
  672. expect(lifecycleJob.if).toBeUndefined()
  673. // Keep the subscription-type gates: issue-lifecycle does not re-subscribe
  674. // ready_for_review (issue-policy owns that) and only reacts to submitted
  675. // review events.
  676. const lifecyclePullRequest = workflowEvent(lifecycle, 'pull_request')
  677. const lifecycleReview = workflowEvent(lifecycle, 'pull_request_review')
  678. expect(lifecyclePullRequest.types).toContain('opened')
  679. expect(lifecyclePullRequest.types).not.toContain('ready_for_review')
  680. expect(lifecyclePullRequest.types).toContain('review_requested')
  681. expect(lifecycleReview.types).toEqual(['submitted'])
  682. const gated = "${{ github.event_name != 'pull_request_review' || github.event.review.state == 'changes_requested' }}"
  683. const steps = lifecycleJob.steps.filter(isRecord)
  684. const tokenStep = steps.find(s => s.name === 'Create project token')
  685. const handleStep = steps.find(s => s.name === 'Handle repository event')
  686. expect(tokenStep).toMatchObject({ if: gated })
  687. expect(handleStep).toMatchObject({ if: gated })
  688. // issue-policy owns PR validation; it is read-only and a real gate.
  689. const policyPullRequest = workflowEvent(policy, 'pull_request')
  690. expect(policyPullRequest.types).toContain('ready_for_review')
  691. })
  692. it('uses a read-only Project token only for human pull request policy metadata', () => {
  693. const policy = loadWorkflow('.github/workflows/issue-policy.yml')
  694. const policyJob = workflowJob(policy, 'policy')
  695. if (!Array.isArray(policyJob.steps)) throw new TypeError('Issue policy job must define steps')
  696. const steps = policyJob.steps.filter(isRecord)
  697. const tokenStep = steps.find(step => step.name === 'Create Project read token')
  698. const validateStep = steps.find(step => step.name === 'Validate pull request')
  699. const humanPullRequest =
  700. "${{ github.event.pull_request.user.type != 'Bot' && github.event.pull_request.user.type != 'App' }}"
  701. expect(tokenStep).toMatchObject({
  702. id: 'app-token',
  703. if: humanPullRequest,
  704. uses: 'actions/create-github-app-token@bcd2ba49218906704ab6c1aa796996da409d3eb1',
  705. with: {
  706. 'client-id': '${{ vars.DSH_ISSUE_APP_CLIENT_ID }}',
  707. 'private-key': '${{ secrets.DSH_ISSUE_APP_PRIVATE_KEY }}',
  708. owner: 'deepseek-harness',
  709. repositories: 'deepseek-harness',
  710. 'permission-issues': 'read',
  711. 'permission-organization-projects': 'read',
  712. },
  713. })
  714. expect(validateStep).toMatchObject({
  715. if: humanPullRequest,
  716. env: {
  717. GITHUB_TOKEN: '${{ github.token }}',
  718. PROJECT_TOKEN: '${{ steps.app-token.outputs.token }}',
  719. },
  720. })
  721. })
  722. })
  723. describe('npm release workflows', () => {
  724. it('keeps publication dispatch-only and pack in the PR workflow', () => {
  725. // pack stays in the PR/master release workflows so a PR proves the set packs.
  726. for (const file of ['release.yml', 'release-vendor.yml']) {
  727. const workflow = loadWorkflow(`.github/workflows/${file}`)
  728. if (!isRecord(workflow.jobs)) throw new TypeError(`${file} must define jobs`)
  729. expect(Object.keys(workflow.jobs).sort()).toEqual(file === 'release.yml' ? ['dependencies', 'pack'] : ['pack'])
  730. }
  731. // publication is workflow_dispatch-only (never a PR check) and keeps the
  732. // npm-publish environment plus the shared dist-tag group.
  733. for (const file of ['release-publish.yml', 'release-vendor-publish.yml']) {
  734. const workflow = loadWorkflow(`.github/workflows/${file}`)
  735. if (!isRecord(workflow.on) || !isRecord(workflow.jobs)) throw new TypeError(`${file} must define on and jobs`)
  736. expect(Object.keys(workflow.on)).toEqual(['workflow_dispatch'])
  737. const publish = workflow.jobs.publish
  738. if (!isRecord(publish)) throw new TypeError(`${file} must define a publish job`)
  739. expect(publish.environment).toBe('npm-publish')
  740. expect(publish.concurrency).toMatchObject({ group: 'Release-publish' })
  741. }
  742. })
  743. it('runs dependency policy and npm layout checks in the DSH release workflow', () => {
  744. const workflow = loadWorkflow('.github/workflows/release.yml')
  745. const dependencies = workflowJob(workflow, 'dependencies')
  746. if (!isRecord(workflow.on) || !Array.isArray(dependencies.steps)) {
  747. throw new TypeError('DSH release workflow must define triggers and dependency steps')
  748. }
  749. const commands = dependencies.steps.flatMap(step =>
  750. isRecord(step) && typeof step.run === 'string' ? [step.run] : [])
  751. expect(Object.keys(workflow.on).sort()).toEqual(['pull_request', 'push', 'workflow_dispatch'])
  752. expect(commands).toContain('pnpm run verify-package-dependencies')
  753. expect(commands).toContain('pnpm run verify-npm-install-layout')
  754. })
  755. })
  756. describe('Documentation site publication', () => {
  757. it('keeps Pages deployment dispatch-only from a dsh-v* tag', () => {
  758. const workflow = loadWorkflow('.github/workflows/docs-pages.yml')
  759. const build = workflowJob(workflow, 'build')
  760. const deploy = workflowJob(workflow, 'deploy')
  761. if (!isRecord(workflow.on) || !isRecord(workflow.env) || !Array.isArray(build.steps)) {
  762. throw new TypeError('Documentation deployment must define on, env, and build steps')
  763. }
  764. // The site presents a released snapshot: a merge must never publish it, and
  765. // publication must never appear as a PR check.
  766. expect(Object.keys(workflow.on)).toEqual(['workflow_dispatch'])
  767. // RELEASE_PUBLISH makes release:verify reject every ref that is not a dsh-v*
  768. // tag naming this tree's version, so the site and the npm sequence share one
  769. // definition of a released version.
  770. const steps = build.steps.filter(isRecord)
  771. const verify = steps.find(step => step.name === 'Verify release version')
  772. const checkout = steps.find(
  773. step => typeof step.uses === 'string' && step.uses.startsWith('actions/checkout@'),
  774. )
  775. expect(verify).toMatchObject({
  776. env: { RELEASE_PUBLISH: 'true' },
  777. run: 'pnpm run release:verify --family dsh',
  778. })
  779. // Complete history: the release scripts read tags.
  780. expect(checkout).toMatchObject({ with: { 'fetch-depth': 0 } })
  781. // Projected source links stay on the public repository's master. That
  782. // repository advances only to each release commit, so its master never
  783. // carries unreleased work, while it retains only the most recent tags:
  784. // following the dispatched tag would leave every source link on a deploy
  785. // from an older tag unresolvable.
  786. expect(workflow.env.DOCS_REPOSITORY_REF).toBe('master')
  787. // The environment owns the deployment tag policy and the required reviewers.
  788. expect(deploy.environment).toMatchObject({ name: 'github-pages' })
  789. })
  790. })
  791. describe('Git hooks', () => {
  792. it('leaves frozen Agent Note sidecars to the archive verifier', () => {
  793. const lefthook = loadWorkflow('lefthook.yml')
  794. for (const hookName of ['pre-commit', 'pre-merge-commit']) {
  795. const hook = lefthook[hookName]
  796. if (!isRecord(hook) || !Array.isArray(hook.jobs)) {
  797. throw new TypeError(`lefthook must define ${hookName} jobs`)
  798. }
  799. const pairing: unknown = hook.jobs.find(
  800. (job: unknown) => isRecord(job) && job.name === 'translation pairing (staged records)',
  801. )
  802. expect(pairing).toMatchObject({ exclude: ['.agents/notes/archived/**'] })
  803. }
  804. })
  805. })
  806. function loadWorkflow(path: string): Record<string, unknown> {
  807. const workflow: unknown = yaml.load(readFileSync(resolve(root, path), 'utf8'))
  808. if (!isRecord(workflow)) throw new TypeError(`${path} must define a workflow`)
  809. return workflow
  810. }
  811. function workflowEvent(workflow: Record<string, unknown>, event: string): Record<string, unknown> {
  812. if (!isRecord(workflow.on) || !isRecord(workflow.on[event])) {
  813. throw new TypeError(`workflow must define the ${event} event`)
  814. }
  815. return workflow.on[event]
  816. }
  817. function workflowJob(workflow: Record<string, unknown>, job: string): Record<string, unknown> {
  818. if (!isRecord(workflow.jobs) || !isRecord(workflow.jobs[job])) {
  819. throw new TypeError(`workflow must define the ${job} job`)
  820. }
  821. return workflow.jobs[job]
  822. }
  823. function isRecord(value: unknown): value is Record<string, unknown> {
  824. return typeof value === 'object' && value !== null && !Array.isArray(value)
  825. }