Commit Graph

133 Commits

Author SHA1 Message Date
can1357 1be061a052 chore: added arg3t to vouched list
- Added arg3t to the .github/VOUCHED.td file.
2026-06-26 14:17:45 +02:00
can1357 7a06985cfa chore: added serverinspector to vouched list
- Added serverinspector to the .github/VOUCHED.td registry.
2026-06-26 10:48:24 +02:00
github-actions[bot] 02d0ccc555 Update VOUCHED list
https://github.com/can1357/oh-my-pi/discussions/3418#discussioncomment-DC_kwDOQxs0bc4BChZk
2026-06-25 20:14:15 +00:00
can1357 2eddcf540f chore: added new names to VOUCHED list 2026-06-25 22:00:55 +02:00
can1357 c4a02fe714 chore: updated vouched contributor list
- Added igasmi and pgupta-git to the list of vouched contributors.
2026-06-21 02:29:18 +02:00
github-actions[bot] 38de8e6203 Update VOUCHED list
https://github.com/can1357/oh-my-pi/discussions/3103#discussioncomment-DC_kwDOQxs0bc4BCSsa
2026-06-21 02:27:51 +02:00
can1357 339bd6c62a chore: added user to vouched list
- Added korri123 to the VOUCHED contributors list.
2026-06-19 17:39:38 +02:00
can1357 acd0d31f62 ci(workflows): ignored VOUCHED.td in CI triggers
- Added a paths-ignore filter to the CI workflow to prevent unnecessary runs during vouch bookkeeping commits.
- Ensured that pushes affecting both vouch files and project code continue to trigger the full CI matrix.
2026-06-19 17:02:13 +02:00
github-actions[bot] 42bd5e65b1 Update VOUCHED list
https://github.com/can1357/oh-my-pi/discussions/3015#discussioncomment-DC_kwDOQxs0bc4BCPtC
2026-06-19 14:34:54 +00:00
can1357 9e3dd1db7f ci: added vouch-manage workflow and contribution guidelines
- Added a GitHub Action workflow to manage user vouching through discussion comments.
- Created CONTRIBUTING.md to define the vouching policy and workflow for contributors.
- Updated README.md to include instructions on the required vouching process for pull requests.
2026-06-19 03:46:11 +02:00
can1357 0cfca30b24 ci(workflows): removed vouch-manage workflow
- Deleted the vouch-manage.yml CI configuration file.
2026-06-19 03:27:33 +02:00
can1357 aca5d5f48a feat(python): implemented pull request vouching and gated review system
- Introduced a vouching mechanism to manage PR authorization via a tracked user list and discussion-based management workflows.
- Added automated PR gatekeeping workflows to close contributions from unvouched users and require specific labels for review.
- Refactored PR event handling to support label-based review deferral and enforce authorization checks for labelers.
- Added comprehensive test coverage for vouch-gate logic, including label activation and unauthorized access scenarios.
2026-06-19 03:24:04 +02:00
can1357 75ab023434 fix(actions/bun-install): retried bun install with job-local cache on first-attempt failure
- Updated the bun-install action to retry `bun install --frozen-lockfile` when the first attempt fails.
- Added a fallback path that creates a temporary job-local cache directory and reruns install with `--cache-dir`.
- Emitted a warning to note the shared-store failure before the retry path is used.
2026-06-15 09:25:02 +02:00
can1357 55d42cd5cf ci(workflows): added conditional sccache setup for self-hosted and GitHub runners
- Detected the runner environment in CI by checking SCCACHE_BUCKET and exporting an on_infra output.
- Updated the workflow to use the local ensure-sccache action on self-hosted runners and mozilla-actions/sccache-action on GitHub-hosted runners.
2026-06-15 07:37:58 +02:00
can1357 bc6130aad4 fix(natives): build linux addons against a glibc 2.17 floor via cargo-zigbuild
Native linux-x64/arm64 builds moved onto the Ubuntu 24.04 (glibc 2.39)
omp-kata runner. The x64 addon was a plain host build that linked the
runner's glibc and failed to dlopen with `version 'GLIBC_2.39' not found`
on older distros; the arm64 cross-build floated up to GLIBC_2.30. Build
the shipped linux-gnu addons through cargo-zigbuild against a pinned 2.17
floor so they load on any glibc >= 2.17.

- build-native.ts: key the tree-sitter-just `-UNDEBUG` CFLAGS off the
  bare triple (cargo-zigbuild strips the `.2.17` glibc suffix before
  invoking cargo) and symlink the suffixed target dir napi 3.7.0 expects
  to the bare dir cargo-zigbuild writes, so postBuild copyArtifact finds
  the cdylib.
- build-native action: add a `glibc` input plus a resolve step deriving
  the zigbuild cross_target (suffixed) and the rustup bare_target
  (stripped); gate zig/cargo-zigbuild install on cross_target so the
  host-arch x64 build still runs native Rust tests.
- ci.yml: GLIBC_FLOOR=2.17 fed to the linux-x64 and linux-arm64 native
  jobs.

Re-tags 15.13.1, whose release failed at the linux-x64 binary smoke
before any publish step ran.
2026-06-15 05:39:02 +02:00
can1357 05fd499551 Merge PR #1435: feat: added isolated profiles with --profile and --alias
Closes #1435

# Conflicts:
#	.github/actions/bun-install/action.yml
2026-06-15 02:47:12 +02:00
can1357 f8e7874159 Merge remote-tracking branch 'origin/farm/ad9a74c4/release-notes-include-silent-tags' 2026-06-15 02:26:09 +02:00
Ogrodev 932ebe9a48 Merge remote-tracking branch 'upstream/main' into feat/profiles-and-alias
# Conflicts:
#	.github/actions/build-native/action.yml
#	.github/workflows/ci.yml
2026-06-14 21:26:03 -03:00
can1357 1f5307fdec feat(infra): migrated runner caches to PVC-backed Bun/Cargo and RustFS sccache
- Updated bun-install action to set mounted cache mode and use PVC cache paths.
- Removed RustFS Bun restore/save and maintenance scripts, replacing them with mounted cache setup.
- Removed zstd from runner image installation and baked-tool verification checks.
- Updated infra docs to describe split caching with RustFS for sccache and PVC for Bun/Cargo.
2026-06-15 02:24:35 +02:00
Ogrodev c7537eb1f4 fix(ci): disable rustfs bun cache on test jobs 2026-06-14 21:20:59 -03:00
roboomp 77a5befd53 fix(ci): authenticate gh release lookup and fail loud on lookup error
Two issues caught in review on #2597:

1. `gh release list` in GitHub Actions requires GH_TOKEN. The release
   notes step in `.github/workflows/ci.yml` had no env block, so gh would
   exit non-zero and the script's silent fallback would re-strand the
   silent-tag entries this change is meant to recover. Pass
   `GH_TOKEN: ${{ secrets.GITHUB_TOKEN }}` to the step.

2. Silently degrading to legacy single-version output on gh failure is
   itself the regression vector — a future token misconfig or gh outage
   would lose data with no signal. `resolvePublishedFloorTag` now throws
   on gh failure with an actionable hint ("pass GH_TOKEN in Actions; set
   OMP_RELEASE_NOTES_FLOOR= locally to opt into legacy mode"). The
   thrown error propagates out of `main` and exits non-zero, failing the
   CI step loudly so the release is rebuilt with the fix.

The legitimate null path is preserved: `OMP_RELEASE_NOTES_FLOOR=`
(empty) still forces single-version mode, and a successful gh call with
no candidate < target still returns null (first-ever publish case).

Verified locally: hiding gh from PATH now exits 1 with the hint;
`OMP_RELEASE_NOTES_FLOOR=` with hidden gh still produces the legacy
84-bullet single-version output.

Refs #2596
2026-06-14 23:43:17 +00:00
can1357 a6aa0c4ae8 fix(actions): fixed runner tooling setup and version parsing
- Updated Rust toolchain checks to use a prefix-aware grep pattern when validating installed components.
- Simplified the Zig installer action to extract into ~/.local and add the archive directory directly to PATH.
- Adjusted runner checks to parse sccache and gh version output via positional shell fields for stability.
2026-06-15 01:15:25 +02:00
can1357 ff5b06d0c2 ci: added CI workflows and actions for pinned toolchain-native builds
- Added composite GitHub actions to ensure rust toolchains and cargo helpers.
- Added a kata-native build action with variant checks and platform artifact uploads.
- Reworked CI matrices to split native cross-platform jobs and gate releases accordingly.
- Updated runner bootstrap and image to preinstall pinned build tools for CI consistency.
2026-06-15 01:01:45 +02:00
can1357 198b1cdec2 fix(ci): close bun-install cache backend branch
The backend-detection shell block in .github/actions/bun-install/action.yml was missing its closing fi, so every job that touched the composite failed immediately with . Restore the RustFS/GHA branch correctly and validate with YAML parse + bash -n.
2026-06-15 01:00:19 +02:00
can1357 82871093bd ci(actions): skipped bun setup and rust-cache on shared-sccache runners
- Updated the bun-install composite action to detect preinstalled Bun and only fetch it when missing.
- Added cache-backend detection and wiring so Bun dependencies use RustFS cache when SCCACHE credentials are present.
- Conditionally skipped rust-cache in build-native and CI jobs when shared sccache runners are available, relying on the existing RustFS/sccache layer instead.
2026-06-15 00:52:32 +02:00
can1357 5959bb0ad3 test(mnemopi): disabled embeddings in mnemopi tests
- Added beforeEach and afterEach hooks in mnemopi tests to set and clear MNEMOPI_NO_EMBEDDINGS so embeddings are skipped during those runs.
- Updated the bun-install cache script to archive only node_modules paths that exist as directories.
2026-06-15 00:29:24 +02:00
can1357 2be8256af0 ci(workflows): shared bun caching in CI via backend-aware install action
- Updated CI dependency install flow to share bun cache orchestration across jobs.
- Added RustFS-backed bun cache restore/save script keyed by bun.lock hash.
2026-06-15 00:18:43 +02:00
can1357 6d8bd80392 ci(workflows): share rust sccache via in-cluster RustFS S3 on self-hosted runners
Self-hosted omp-kata runners now inject a shared S3 (RustFS, in-cluster)
sccache backend via pod env (SCCACHE_BUCKET/ENDPOINT/REGION + AWS creds).
The Enable-sccache step branches on SCCACHE_BUCKET: when set, sccache reads
the S3 config from the inherited environment; otherwise GitHub-hosted
runners (macOS, ubuntu-arm) keep the GHA cache backend since they can't
reach the private RustFS.
2026-06-14 23:07:54 +02:00
can1357 3843a86df9 ci(workflows): updated CI job labels and removed fast test dependency
- Renamed the coding-agent native job and bucket names from tooling to unit in CI.
- Removed test_coding_agent_fast from the release job dependency list and gating condition.
2026-06-14 22:40:21 +02:00
can1357 b8e4da23d0 ci(ci): refactored CI setup and test-state isolation for coding-agent workflows
- Added a setup-system-deps action with preloaded-runner guards and apt fallbacks.
- Updated CI workflows to download Linux x64 native artifacts and gate on native job success.
- Renamed coding-agent fast mode to singleton in scripts and test partitioning logic.
- Added settings test-state begin/restore helpers with recursive cleanup in affected tests.
2026-06-14 22:37:05 +02:00
can1357 a734c29234 ci(scripts): reworked CI test execution with mode-based TypeScript buckets
- Added a mode-based `ci-test-ts.ts` runner with `--dry-run` support.
- Partitioned coding-agent tests into fast/ui/runtime/native/heavy buckets and separated workspace/native runs.
- Added coding-agent bucket modes that fail CI when a target bucket has no matching tests.
- Updated CI scripts/workflow to run the new TS buckets, use `omp-kata`, and gate releases on them.
2026-06-14 21:55:55 +02:00
can1357 73f2dbc3b5 ci(workflows): isolated manual workflow_dispatch runs in release concurrency groups
- Updated the CI workflow concurrency rules to treat `workflow_dispatch` like a release path, grouping those runs by SHA and disabling cancel-in-progress.
- Extended the `GhaEval` expression evaluator in `scripts/ci-concurrency.test.ts` to support `==`/`!=` and align falsy checks.
- Added a regression test covering tagged-main `workflow_dispatch` runs using the release-style concurrency behavior.
2026-06-14 19:04:05 +02:00
roboomp 9acc24329f fix(ci): scope release runs to per-sha concurrency group
The workflow-wide concurrency group was `${{ github.workflow }}-${{ github.ref }}`
with `cancel-in-progress: true`, so the release-script's atomic
`refs/heads/main + v* tag` push shared the `CI-refs/heads/main` group with every
later main push. The newer run cancelled the older release run before
`release_binary` / `release_github` / `release_npm` could execute, and no
future run carried the tag at HEAD, so the tag stayed published-as-a-ref but
unreleased on GitHub and npm (v15.12.6 in the wild).

Release runs are now routed to a per-sha group with `cancel-in-progress: false`
when either:
  * the push subject starts with `chore: bump version to ` (the release-script
    commit convention from scripts/release.ts), or
  * `github.ref` is a `v*` tag (workflow_dispatch recovery from a tag ref).

Other events keep the cheap branch-wide cancel-in-progress for PR/main churn.
release.ts's retry hint now uses the same release commit subject so manual
retries also land in the per-sha group.

Added scripts/ci-concurrency.test.ts: a regression test with a minimal GHA
expression evaluator that asserts the resolved group / cancel-in-progress for
auto-release pushes, retry pushes, tag-ref dispatches, plain main pushes, PRs,
distinct release shas, and a benign `revert: chore: bump version to ...`
follow-up.

Fixes #2564
2026-06-14 12:23:23 +00:00
can1357 8fa1f6c250 feat: added shared collab wire protocol and web guest collaboration client
- Added @oh-my-pi/pi-wire and reworked collab protocol types into shared contracts.
- Added wire-compatibility guards in coding-agent host to block unsupported events.
- Added standalone collab-web package with guest UI, mock-host tooling, and local relay.
- Added secure room-link validation, WebCrypto framing, and safer socket routing.
2026-06-12 11:54:41 +02:00
can1357 96defff9a5 ci(workflows): provisioned native addons for the npm publish job
The pi-coding-agent prepack (bundle-dist.ts) imports the pi-utils barrel,
which eagerly loads the pi-natives addon; release_npm never downloaded the
linux x64 .node artifacts, so the publish died in prepack. Mirror the
test job's download-artifact step (release runs always rebuild natives in
the same run, so the default run-id resolves).
2026-06-10 08:22:19 +02:00
can1357 61c2e29532 ci(ci): aligned CI release metadata flow after job and output renames
- Renamed the gate and native jobs in CI for consistent release naming.
- Renamed reusable-artifact output keys for native lookup compatibility.
- Rewired release and test jobs to read tags, flags, and hashes from metadata outputs.
2026-06-08 12:26:31 +02:00
can1357 392636d315 ci(workflows): gated Homebrew tap publish on release verification
- Updated the `release_brew` job to depend on `release_github_verify` instead of `release-github`.
- Changed the job guard so the tap release now requires `release_github_verify` to report success before running.
- Updated the workflow comment to describe that tap publishing is gated by verified release binaries.
2026-06-08 12:09:17 +02:00
can1357 af33d4bfe4 ci: added macOS release signing and Homebrew automation to CI
- Added macOS CI signing and notarization steps when APPLE_* secrets are configured.
- Added strict darwin verification checks to reject ad-hoc signatures and run smoke tests.
- Added Homebrew formula publishing from release assets with SHA-256 checksums.
- Added helper scripts for signing secret upload, entitlements, and release workflows.
2026-06-08 11:49:28 +02:00
can1357 7ffec14863 ci: force JavaScript actions to run on Node 24 2026-06-08 00:32:47 +02:00
can1357 71fe258320 ci: migrated release trigger from tag-push to branch-push
- Removed `tags: ["v*"]` trigger; release now fires from the single atomic `main` push that carries the tag.
- Replaced `gate.skip` with `gate.is-release` and `gate.release-tag` so downstream jobs detect the tag via `git tag --points-at HEAD`.
- Passed `release-tag` explicitly to release steps (gh-release, curl, release notes) since `github.ref` is now `refs/heads/main`, not the tag.
- Fixed rust-cache key collision on macOS x64 by setting `RUSTFLAGS` (target-cpu) before cache restore and including the native source hash in the shared key.
2026-05-31 02:33:19 +02:00
can1357 d0d5a6d60f config: disabled GITHUB_ACTIONS marker for TypeScript test script
- Updated the root package.json test:ts script to run with GITHUB_ACTIONS=0.
2026-05-31 01:14:52 +02:00
can1357 c7c627f0c5 ci(ci): published native leaf packages per target in the release flow
- CI now enabled OIDC publishing in the build matrix, installed Node 24/npm, and added a per-target native addon publish step.
- The release script now accepts `--native-leaf <tag>` and publishes only the matching generated native leaf package.
- Native package generation gained optional tag filtering with validation of requested leaf tags for targeted release publishing.
2026-05-30 19:22:36 +02:00
can1357 464314e3a2 fix(ci): scope fetch-tags to main pushes to unbreak tag-triggered checkout 2026-05-30 19:06:44 +02:00
can1357 e1a0d235ec ci(scripts): skipped duplicate release CI runs and enabled OIDC npm publishes
- Added a workflow `gate` job that marks `main` pushes with a `v*` tag at `HEAD` as duplicate release runs.
- Conditioned native, lint/test, and install CI jobs on that gate so redundant build and publish work is skipped on duplicate tagged pushes.
- Updated `scripts/ci-release-publish.ts` to publish packed tarballs via `npm publish` after `bun pm pack`, handling already-published versions as a no-op.
2026-05-30 18:28:50 +02:00
can1357 58d95ae258 ci: set CARGO_INCREMENTAL=0 to prevent sccache from being bypassed
- sccache silently skips caching when incremental compilation is enabled, making the wrapper a no-op.
- Applied fix to both the shared build-native action and the CI workflow setup step.
2026-05-27 02:09:14 +02:00
can1357 3514ea3cfa ci(actions): enabled cross-compilation toolchains across CI native and release builds
- Updated the build-native action to install cargo-zigbuild for non-MSVC targets and cargo-xwin with LLVM tooling for MSVC targets.
- Removed the fixed aarch64 linker variable and narrowed Rust test execution to skip duplicate macOS runs.
- Reworked CI matrices to build win32-x64 artifacts on ubuntu with x86_64-pc-windows-msvc and simplified smoke testing to skip those Windows binaries via matrix gating.
2026-05-27 01:54:26 +02:00
can1357 db3362be95 ci(workflows): optimized CI native artifact reuse and added sccache fallback
- Updated `rust-hash` to return separate `linux-run-id` and `release-run-id` outputs by checking each prior run for required native artifacts.
- Rewired `native_linux` and `native_release` gating to use those outputs, enabling Linux cache reuse on main and release pre-warm only when all cross-platform artifacts are present.
- Enabled sccache in both the shared native build action and CI setup, and excluded macOS workspace Rust tests from the generic native test step due to duplicated coverage.
2026-05-27 01:33:09 +02:00
can1357 bc355472af ci(ci): added automated release note generation to the GitHub release workflow
- Added a Bun-based `scripts/ci-release-notes.ts` utility that extracts `## [version]` entries from `packages/*/CHANGELOG.md` and writes a combined `release-notes.md` for the release tag.
- Updated the GitHub release workflow to install Bun, run the notes generator, and pass the generated `release-notes.md` to `softprops/action-gh-release` via `body_path`.
2026-05-26 20:53:59 +02:00
roboomp a6279e0730 fix(cli): restored binary update rollback
Rolled back binary updater replacements when post-install version verification fails instead of deleting the previous working binary first.

Added a release workflow gate that downloads the published macOS arm64 asset and verifies codesign plus --version before npm publishing.

Fixes #1240
2026-05-21 00:09:43 +00:00
can1357 f51d058c43 ci(workflows): set GITHUB_ACTIONS to an empty value for the
- Set `GITHUB_ACTIONS` to an empty value for the `Test workspace (TS)` step so Bun's `::group::` markers are not emitted as log text.
- Kept the override scoped to that step to avoid impacting other workflow steps while preserving normal annotation behavior.
2026-05-19 17:20:43 +09:00