ci(ci): refactored CI setup and test-state isolation for coding-agent workflows

- Added a setup-system-deps action with preloaded-runner guards and apt fallbacks.
- Updated CI workflows to download Linux x64 native artifacts and gate on native job success.
- Renamed coding-agent fast mode to singleton in scripts and test partitioning logic.
- Added settings test-state begin/restore helpers with recursive cleanup in affected tests.
This commit is contained in:
can1357
2026-06-14 22:37:05 +02:00
parent 932de0a1dd
commit b8e4da23d0
16 changed files with 325 additions and 232 deletions
+6
View File
@@ -36,6 +36,12 @@ runs:
toolchain: nightly-2026-04-29
components: ${{ inputs.rust_checks == 'true' && 'clippy, rustfmt' || '' }}
targets: ${{ inputs.target }}
- name: Install Linux build prerequisites
if: runner.os == 'Linux'
shell: bash
run: |
sudo apt-get update
sudo apt-get install -y build-essential
- name: Prepend rustup toolchain bin to PATH
shell: bash
run: |
@@ -0,0 +1,26 @@
name: Setup system deps
description: >-
Install the canvas/native runtime deps CI needs (cairo/pango stack, fd,
ripgrep, imagemagick). No-op on the preloaded omp-kata runner image, which
already ships them; self-heals on a stock runner by installing via apt.
runs:
using: composite
steps:
- name: Install system deps (skip when preloaded)
shell: bash
run: |
# The preloaded omp-kata runner image bakes these in. Detect that
# and skip the apt round-trip; otherwise install the exact same set so
# stock runners (and any future host) still work.
if command -v fd >/dev/null 2>&1 \
&& command -v rg >/dev/null 2>&1 \
&& command -v magick >/dev/null 2>&1 \
&& pkg-config --exists cairo pango 2>/dev/null; then
echo "System deps already present (preloaded runner image); skipping apt."
exit 0
fi
sudo apt-get update
sudo apt-get install -y libcairo2-dev libpango1.0-dev libjpeg-dev libgif-dev librsvg2-dev fd-find ripgrep imagemagick
sudo ln -sf "$(command -v fdfind)" /usr/local/bin/fd
sudo ln -sf /usr/bin/convert /usr/local/bin/magick
+83 -71
View File
@@ -27,6 +27,10 @@ concurrency:
env:
FORCE_JAVASCRIPT_ACTIONS_TO_NODE24: true
permissions:
contents: read
actions: read
jobs:
# scripts/release.ts pushes the version-bump commit and its `v*` tag
# atomically (`git push --atomic origin refs/heads/main:refs/heads/main
@@ -255,6 +259,8 @@ jobs:
test_workspace:
name: Test TS workspace fast
runs-on: omp-kata
needs: [native_linux_x64, native_artifact_lookup]
if: ${{ !cancelled() && needs.native_linux_x64.result != 'failure' }}
timeout-minutes: 20
steps:
- uses: actions/checkout@v4
@@ -267,14 +273,31 @@ jobs:
path: ~/.bun/install/cache
key: bun-${{ runner.os }}-${{ hashFiles('**/bun.lock') }}
- run: bun install --frozen-lockfile
- name: Test pure workspaces and repo scripts (TS)
# Keep this job native-free and parallel: it deliberately excludes
# coding-agent plus native/TUI/browser-ish/integration packages.
- name: Resolve Linux x64 native artifact run
id: source
shell: bash
run: |
if [ "${{ needs.native_linux_x64.result }}" = "success" ]; then
echo "artifact-run-id=${{ github.run_id }}" >> "$GITHUB_OUTPUT"
else
echo "artifact-run-id=${{ needs.native_artifact_lookup.outputs.linux-x64-run-id }}" >> "$GITHUB_OUTPUT"
fi
- name: Download native addons
uses: actions/download-artifact@v4
with:
pattern: pi-natives-linux-x64-*-h${{ needs.native_artifact_lookup.outputs.source-hash }}
path: packages/natives/native
merge-multiple: true
run-id: ${{ steps.source.outputs.artifact-run-id }}
github-token: ${{ secrets.GITHUB_TOKEN }}
- name: Test workspace packages and repo scripts (TS)
run: bun run ci:test:ts:workspace
test_coding_agent_fast:
name: Test coding-agent fast (TS)
test_coding_agent_singleton:
name: Test coding-agent singleton/global-state (TS)
runs-on: omp-kata
needs: [native_linux_x64, native_artifact_lookup]
if: ${{ !cancelled() && needs.native_linux_x64.result != 'failure' }}
timeout-minutes: 20
steps:
- uses: actions/checkout@v4
@@ -287,10 +310,27 @@ jobs:
path: ~/.bun/install/cache
key: bun-${{ runner.os }}-${{ hashFiles('**/bun.lock') }}
- run: bun install --frozen-lockfile
- name: Test coding-agent fast unit bucket
# The fast bucket is the conservative native-free complement. It has
# an explicit worker cap forever; never use package-wide fan-out here.
run: bun run ci:test:coding-agent:fast
- name: Resolve Linux x64 native artifact run
id: source
shell: bash
run: |
if [ "${{ needs.native_linux_x64.result }}" = "success" ]; then
echo "artifact-run-id=${{ github.run_id }}" >> "$GITHUB_OUTPUT"
else
echo "artifact-run-id=${{ needs.native_artifact_lookup.outputs.linux-x64-run-id }}" >> "$GITHUB_OUTPUT"
fi
- name: Download native addons
uses: actions/download-artifact@v4
with:
pattern: pi-natives-linux-x64-*-h${{ needs.native_artifact_lookup.outputs.source-hash }}
path: packages/natives/native
merge-multiple: true
run-id: ${{ steps.source.outputs.artifact-run-id }}
github-token: ${{ secrets.GITHUB_TOKEN }}
- name: Test coding-agent singleton/global-state bucket
# Keep global Settings/env/fake-timer tests serial; native addon
# artifacts are still available like every other coding-agent bucket.
run: bun run ci:test:coding-agent:singleton
test_ts_native:
name: Test TS native/integration packages
@@ -308,12 +348,7 @@ jobs:
with:
path: ~/.bun/install/cache
key: bun-${{ runner.os }}-${{ hashFiles('**/bun.lock') }}
- name: Install system deps
run: |
sudo apt-get update
sudo apt-get install -y libcairo2-dev libpango1.0-dev libjpeg-dev libgif-dev librsvg2-dev fd-find ripgrep imagemagick
sudo ln -sf "$(command -v fdfind)" /usr/local/bin/fd
sudo ln -sf /usr/bin/convert /usr/local/bin/magick
- uses: ./.github/actions/setup-system-deps
- run: bun install --frozen-lockfile
- name: Resolve Linux x64 native artifact run
id: source
@@ -336,7 +371,7 @@ jobs:
run: bun run ci:test:ts:native
test_coding_agent_ui:
name: Test coding-agent UI/stateful (TS)
name: Test coding-agent UI/TUI (TS)
runs-on: omp-kata
needs: [native_linux_x64, native_artifact_lookup]
if: ${{ !cancelled() && needs.native_linux_x64.result != 'failure' }}
@@ -351,12 +386,7 @@ jobs:
with:
path: ~/.bun/install/cache
key: bun-${{ runner.os }}-${{ hashFiles('**/bun.lock') }}
- name: Install system deps
run: |
sudo apt-get update
sudo apt-get install -y libcairo2-dev libpango1.0-dev libjpeg-dev libgif-dev librsvg2-dev fd-find ripgrep imagemagick
sudo ln -sf "$(command -v fdfind)" /usr/local/bin/fd
sudo ln -sf /usr/bin/convert /usr/local/bin/magick
- uses: ./.github/actions/setup-system-deps
- run: bun install --frozen-lockfile
- name: Resolve Linux x64 native artifact run
id: source
@@ -379,7 +409,7 @@ jobs:
run: bun run ci:test:coding-agent:ui
test_coding_agent_runtime:
name: Test coding-agent runtime/stateful (TS)
name: Test coding-agent runtime/session (TS)
runs-on: omp-kata
needs: [native_linux_x64, native_artifact_lookup]
if: ${{ !cancelled() && needs.native_linux_x64.result != 'failure' }}
@@ -394,12 +424,6 @@ jobs:
with:
path: ~/.bun/install/cache
key: bun-${{ runner.os }}-${{ hashFiles('**/bun.lock') }}
- name: Install system deps
run: |
sudo apt-get update
sudo apt-get install -y libcairo2-dev libpango1.0-dev libjpeg-dev libgif-dev librsvg2-dev fd-find ripgrep imagemagick
sudo ln -sf "$(command -v fdfind)" /usr/local/bin/fd
sudo ln -sf /usr/bin/convert /usr/local/bin/magick
- run: bun install --frozen-lockfile
- name: Resolve Linux x64 native artifact run
id: source
@@ -419,6 +443,8 @@ jobs:
run-id: ${{ steps.source.outputs.artifact-run-id }}
github-token: ${{ secrets.GITHUB_TOKEN }}
- name: Test coding-agent runtime bucket
# Runtime/session tests import native-backed barrels too; keep this
# separate for concurrency, not as a native-free guardrail.
run: bun run ci:test:coding-agent:runtime
test_coding_agent_native:
@@ -437,12 +463,7 @@ jobs:
with:
path: ~/.bun/install/cache
key: bun-${{ runner.os }}-${{ hashFiles('**/bun.lock') }}
- name: Install system deps
run: |
sudo apt-get update
sudo apt-get install -y libcairo2-dev libpango1.0-dev libjpeg-dev libgif-dev librsvg2-dev fd-find ripgrep imagemagick
sudo ln -sf "$(command -v fdfind)" /usr/local/bin/fd
sudo ln -sf /usr/bin/convert /usr/local/bin/magick
- uses: ./.github/actions/setup-system-deps
- run: bun install --frozen-lockfile
- name: Resolve Linux x64 native artifact run
id: source
@@ -480,12 +501,7 @@ jobs:
with:
path: ~/.bun/install/cache
key: bun-${{ runner.os }}-${{ hashFiles('**/bun.lock') }}
- name: Install system deps
run: |
sudo apt-get update
sudo apt-get install -y libcairo2-dev libpango1.0-dev libjpeg-dev libgif-dev librsvg2-dev fd-find ripgrep imagemagick
sudo ln -sf "$(command -v fdfind)" /usr/local/bin/fd
sudo ln -sf /usr/bin/convert /usr/local/bin/magick
- uses: ./.github/actions/setup-system-deps
- run: bun install --frozen-lockfile
- name: Resolve Linux x64 native artifact run
id: source
@@ -542,12 +558,7 @@ jobs:
with:
path: ~/.bun/install/cache
key: bun-${{ runner.os }}-${{ hashFiles('**/bun.lock') }}
- name: Install system deps
run: |
sudo apt-get update
sudo apt-get install -y libcairo2-dev libpango1.0-dev libjpeg-dev libgif-dev librsvg2-dev fd-find ripgrep imagemagick
sudo ln -sf "$(command -v fdfind)" /usr/local/bin/fd
sudo ln -sf /usr/bin/convert /usr/local/bin/magick
- uses: ./.github/actions/setup-system-deps
- run: bun install --frozen-lockfile
- name: Install method smoke tests
run: bun run ci:test:install-methods
@@ -558,19 +569,20 @@ jobs:
needs.native_linux_x64.result == 'success' && needs.native_cross_platform.result ==
'success' && needs.test_workspace.result == 'success' &&
needs.test_coding_agent_fast.result == 'success' &&
needs.test_coding_agent_singleton.result == 'success' &&
needs.test_ts_native.result == 'success' &&
needs.test_coding_agent_ui.result == 'success' &&
needs.test_coding_agent_runtime.result == 'success' &&
needs.test_coding_agent_native.result == 'success' &&
needs.test_smoke.result == 'success' && needs.check.result == 'success' &&
needs.install_methods.result == 'success' }}
needs: [release_metadata, check, native_linux_x64, native_cross_platform, test_workspace, test_coding_agent_fast, test_ts_native, test_coding_agent_ui, test_coding_agent_runtime, test_coding_agent_native, test_smoke, install_methods, native_artifact_lookup]
needs: [release_metadata, check, native_linux_x64, native_cross_platform, test_workspace, test_coding_agent_fast, test_coding_agent_singleton, test_ts_native, test_coding_agent_ui, test_coding_agent_runtime, test_coding_agent_native, test_smoke, install_methods, native_artifact_lookup]
strategy:
fail-fast: false
matrix:
include:
- {
os: omp-kata,
os: ubuntu-22.04,
platform: linux,
arch: x64,
target_id: linux-x64,
@@ -598,7 +610,7 @@ jobs:
binary_path: packages/coding-agent/binaries/omp-darwin-arm64,
}
- {
os: omp-kata,
os: ubuntu-22.04,
platform: win32,
arch: x64,
target_id: win32-x64,
@@ -611,11 +623,11 @@ jobs:
env:
MACOS_SIGNING: ${{ secrets.APPLE_CERTIFICATE_P12 != '' && secrets.APPLE_CERTIFICATE_PASSWORD != '' && secrets.APPLE_API_KEY_ID != '' && secrets.APPLE_API_ISSUER_ID != '' && secrets.APPLE_API_KEY != '' }}
steps:
- uses: actions/checkout@v4
- uses: oven-sh/setup-bun@v2
- uses: actions/checkout@df4cb1c069e1874edd31b4311f1884172cec0e10 # v6.0.3
- uses: oven-sh/setup-bun@0c5077e51419868618aeaa5fe8019c62421857d6 # v2.2.0
with:
bun-version: "1.3"
- uses: actions/setup-node@v4
- uses: actions/setup-node@48b55a011bda9f5d6aeb4c2d9c7362e8dae4041e # v6.4.0
with:
node-version: "24"
registry-url: "https://registry.npmjs.org"
@@ -624,13 +636,13 @@ jobs:
if: ${{ !inputs.skip_npm }}
run: npm install -g npm@latest
- name: Cache bun dependencies
uses: actions/cache@v4
uses: actions/cache@0057852bfaa89a56745cba8c7296529d2fc39830 # v4.3.0
with:
path: ~/.bun/install/cache
key: bun-${{ runner.os }}-${{ hashFiles('**/bun.lock') }}
- run: bun install --frozen-lockfile
- name: Download native addon(s)
uses: actions/download-artifact@v4
uses: actions/download-artifact@3e5f45b2cfb9172054b4087a40e8e0b5a5461e7c # v8.0.1
with:
pattern: pi-natives-${{ matrix.platform }}-${{ matrix.arch }}*-h${{ needs.native_artifact_lookup.outputs.source-hash }}
path: packages/natives/native
@@ -671,7 +683,7 @@ jobs:
NODE_AUTH_TOKEN: ${{ secrets.NPM_TOKEN }}
run: bun run ci:release:publish-native-leaf ${{ matrix.target_id }}
- name: Upload release binary artifact
uses: actions/upload-artifact@v4
uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1
with:
name: omp-binary-${{ matrix.target_id }}
path: ${{ matrix.binary_path }}
@@ -681,24 +693,24 @@ jobs:
if: ${{ needs.release_metadata.outputs.is-release == 'true' && !cancelled() &&
needs.release_binary.result == 'success' }}
needs: [release_metadata, release_binary]
runs-on: omp-kata
runs-on: ubuntu-22.04
permissions:
contents: write
steps:
- uses: actions/checkout@v4
- uses: oven-sh/setup-bun@v2
- uses: actions/checkout@df4cb1c069e1874edd31b4311f1884172cec0e10 # v6.0.3
- uses: oven-sh/setup-bun@0c5077e51419868618aeaa5fe8019c62421857d6 # v2.2.0
with:
bun-version: "1.3"
- name: Generate release notes from CHANGELOGs
run: bun scripts/ci-release-notes.ts ${{ needs.release_metadata.outputs.release-tag }}
- name: Download release binaries
uses: actions/download-artifact@v4
uses: actions/download-artifact@3e5f45b2cfb9172054b4087a40e8e0b5a5461e7c # v8.0.1
with:
pattern: omp-binary-*
path: packages/coding-agent/binaries
merge-multiple: true
- name: Create GitHub Release
uses: softprops/action-gh-release@v2
uses: softprops/action-gh-release@3bb12739c298aeb8a4eeaf626c5b8d85266b0e65 # v2.6.2
with:
tag_name: ${{ needs.release_metadata.outputs.release-tag }}
files: |
@@ -748,7 +760,7 @@ jobs:
needs.release_github_verify.result == 'success' &&
!inputs.skip_npm }}
needs: [release_metadata, release_binary, release_github_verify, native_artifact_lookup]
runs-on: omp-kata
runs-on: ubuntu-22.04
# `id-token: write` lets npm mint the GitHub OIDC token it exchanges for a
# short-lived publish token (trusted publishing + provenance). When a
# package has no matching trusted publisher configured, npm silently falls
@@ -757,11 +769,11 @@ jobs:
id-token: write
contents: read
steps:
- uses: actions/checkout@v4
- uses: oven-sh/setup-bun@v2
- uses: actions/checkout@df4cb1c069e1874edd31b4311f1884172cec0e10 # v6.0.3
- uses: oven-sh/setup-bun@0c5077e51419868618aeaa5fe8019c62421857d6 # v2.2.0
with:
bun-version: "1.3"
- uses: actions/setup-node@v4
- uses: actions/setup-node@48b55a011bda9f5d6aeb4c2d9c7362e8dae4041e # v6.4.0
with:
node-version: "24"
registry-url: "https://registry.npmjs.org"
@@ -769,7 +781,7 @@ jobs:
- name: Ensure npm supports trusted publishing
run: npm install -g npm@latest
- name: Cache bun dependencies
uses: actions/cache@v4
uses: actions/cache@0057852bfaa89a56745cba8c7296529d2fc39830 # v4.3.0
with:
path: ~/.bun/install/cache
key: bun-${{ runner.os }}-${{ hashFiles('**/bun.lock') }}
@@ -780,7 +792,7 @@ jobs:
# Release runs always rebuild natives in this same run, so the
# default run-id resolves the artifacts.
- name: Download native addons
uses: actions/download-artifact@v4
uses: actions/download-artifact@3e5f45b2cfb9172054b4087a40e8e0b5a5461e7c # v8.0.1
with:
pattern: pi-natives-linux-x64-*-h${{ needs.native_artifact_lookup.outputs.source-hash }}
path: packages/natives/native
@@ -803,19 +815,19 @@ jobs:
if: ${{ needs.release_metadata.outputs.is-release == 'true' && !cancelled() &&
needs.release_github_verify.result == 'success' }}
needs: [release_metadata, release_github_verify]
runs-on: omp-kata
runs-on: ubuntu-22.04
env:
HAS_TAP_KEY: ${{ secrets.HOMEBREW_TAP_DEPLOY_KEY != '' }}
steps:
- uses: actions/checkout@v4
- uses: actions/checkout@df4cb1c069e1874edd31b4311f1884172cec0e10 # v6.0.3
if: env.HAS_TAP_KEY == 'true'
- uses: oven-sh/setup-bun@v2
- uses: oven-sh/setup-bun@0c5077e51419868618aeaa5fe8019c62421857d6 # v2.2.0
if: env.HAS_TAP_KEY == 'true'
with:
bun-version: "1.3"
- name: Check out the Homebrew tap
if: env.HAS_TAP_KEY == 'true'
uses: actions/checkout@v4
uses: actions/checkout@df4cb1c069e1874edd31b4311f1884172cec0e10 # v6.0.3
with:
repository: can1357/homebrew-tap
ssh-key: ${{ secrets.HOMEBREW_TAP_DEPLOY_KEY }}