- Added a paths-ignore filter to the CI workflow to prevent unnecessary runs during vouch bookkeeping commits.
- Ensured that pushes affecting both vouch files and project code continue to trigger the full CI matrix.
- Added a GitHub Action workflow to manage user vouching through discussion comments.
- Created CONTRIBUTING.md to define the vouching policy and workflow for contributors.
- Updated README.md to include instructions on the required vouching process for pull requests.
- Introduced a vouching mechanism to manage PR authorization via a tracked user list and discussion-based management workflows.
- Added automated PR gatekeeping workflows to close contributions from unvouched users and require specific labels for review.
- Refactored PR event handling to support label-based review deferral and enforce authorization checks for labelers.
- Added comprehensive test coverage for vouch-gate logic, including label activation and unauthorized access scenarios.
- Updated the bun-install action to retry `bun install --frozen-lockfile` when the first attempt fails.
- Added a fallback path that creates a temporary job-local cache directory and reruns install with `--cache-dir`.
- Emitted a warning to note the shared-store failure before the retry path is used.
- Detected the runner environment in CI by checking SCCACHE_BUCKET and exporting an on_infra output.
- Updated the workflow to use the local ensure-sccache action on self-hosted runners and mozilla-actions/sccache-action on GitHub-hosted runners.
Native linux-x64/arm64 builds moved onto the Ubuntu 24.04 (glibc 2.39)
omp-kata runner. The x64 addon was a plain host build that linked the
runner's glibc and failed to dlopen with `version 'GLIBC_2.39' not found`
on older distros; the arm64 cross-build floated up to GLIBC_2.30. Build
the shipped linux-gnu addons through cargo-zigbuild against a pinned 2.17
floor so they load on any glibc >= 2.17.
- build-native.ts: key the tree-sitter-just `-UNDEBUG` CFLAGS off the
bare triple (cargo-zigbuild strips the `.2.17` glibc suffix before
invoking cargo) and symlink the suffixed target dir napi 3.7.0 expects
to the bare dir cargo-zigbuild writes, so postBuild copyArtifact finds
the cdylib.
- build-native action: add a `glibc` input plus a resolve step deriving
the zigbuild cross_target (suffixed) and the rustup bare_target
(stripped); gate zig/cargo-zigbuild install on cross_target so the
host-arch x64 build still runs native Rust tests.
- ci.yml: GLIBC_FLOOR=2.17 fed to the linux-x64 and linux-arm64 native
jobs.
Re-tags 15.13.1, whose release failed at the linux-x64 binary smoke
before any publish step ran.
- Updated bun-install action to set mounted cache mode and use PVC cache paths.
- Removed RustFS Bun restore/save and maintenance scripts, replacing them with mounted cache setup.
- Removed zstd from runner image installation and baked-tool verification checks.
- Updated infra docs to describe split caching with RustFS for sccache and PVC for Bun/Cargo.
Two issues caught in review on #2597:
1. `gh release list` in GitHub Actions requires GH_TOKEN. The release
notes step in `.github/workflows/ci.yml` had no env block, so gh would
exit non-zero and the script's silent fallback would re-strand the
silent-tag entries this change is meant to recover. Pass
`GH_TOKEN: ${{ secrets.GITHUB_TOKEN }}` to the step.
2. Silently degrading to legacy single-version output on gh failure is
itself the regression vector — a future token misconfig or gh outage
would lose data with no signal. `resolvePublishedFloorTag` now throws
on gh failure with an actionable hint ("pass GH_TOKEN in Actions; set
OMP_RELEASE_NOTES_FLOOR= locally to opt into legacy mode"). The
thrown error propagates out of `main` and exits non-zero, failing the
CI step loudly so the release is rebuilt with the fix.
The legitimate null path is preserved: `OMP_RELEASE_NOTES_FLOOR=`
(empty) still forces single-version mode, and a successful gh call with
no candidate < target still returns null (first-ever publish case).
Verified locally: hiding gh from PATH now exits 1 with the hint;
`OMP_RELEASE_NOTES_FLOOR=` with hidden gh still produces the legacy
84-bullet single-version output.
Refs #2596
- Updated Rust toolchain checks to use a prefix-aware grep pattern when validating installed components.
- Simplified the Zig installer action to extract into ~/.local and add the archive directory directly to PATH.
- Adjusted runner checks to parse sccache and gh version output via positional shell fields for stability.
- Added composite GitHub actions to ensure rust toolchains and cargo helpers.
- Added a kata-native build action with variant checks and platform artifact uploads.
- Reworked CI matrices to split native cross-platform jobs and gate releases accordingly.
- Updated runner bootstrap and image to preinstall pinned build tools for CI consistency.
The backend-detection shell block in .github/actions/bun-install/action.yml was missing its closing fi, so every job that touched the composite failed immediately with . Restore the RustFS/GHA branch correctly and validate with YAML parse + bash -n.
- Updated the bun-install composite action to detect preinstalled Bun and only fetch it when missing.
- Added cache-backend detection and wiring so Bun dependencies use RustFS cache when SCCACHE credentials are present.
- Conditionally skipped rust-cache in build-native and CI jobs when shared sccache runners are available, relying on the existing RustFS/sccache layer instead.
- Added beforeEach and afterEach hooks in mnemopi tests to set and clear MNEMOPI_NO_EMBEDDINGS so embeddings are skipped during those runs.
- Updated the bun-install cache script to archive only node_modules paths that exist as directories.
- Updated CI dependency install flow to share bun cache orchestration across jobs.
- Added RustFS-backed bun cache restore/save script keyed by bun.lock hash.
Self-hosted omp-kata runners now inject a shared S3 (RustFS, in-cluster)
sccache backend via pod env (SCCACHE_BUCKET/ENDPOINT/REGION + AWS creds).
The Enable-sccache step branches on SCCACHE_BUCKET: when set, sccache reads
the S3 config from the inherited environment; otherwise GitHub-hosted
runners (macOS, ubuntu-arm) keep the GHA cache backend since they can't
reach the private RustFS.