Commit Graph

131 Commits

Author SHA1 Message Date
can1357 7e54061cbb chore(bazel): generated clippy config from workspace lints at release time
- Added scripts/gen-clippy-bazelrc.ts: emits bazel/clippy.bazelrc from
  [workspace.lints] in Cargo.toml (groups by ascending priority, then
  per-lint overrides, alphabetical within each tier); --check mode
  verifies sync without writing.
- release.ts regenerates it alongside the lockfiles; the release_gate CD
  job runs the --check so drift only blocks publishing, never ordinary
  CI. Added the gen:clippy package script.
2026-08-20 04:18:26 +02:00
can1357 6edbcf1f0e test(ci): ran watchdog attribution regression 2026-08-16 02:13:39 +02:00
can1357 04fab5ecb4 feat: replaced custom mupdf wasm pipeline with native function
- Replaced the custom MuPDF-WASM PDF extraction and rendering pipeline with the new `pdfToMarkdown` native function from `@oh-my-pi/pi-natives`.
- Removed legacy MuPDF extraction modules, WASM embedding scripts, and PDF image extraction tools.
- Added OCR warnings and browser/text redirection for unsupported PDF image reads.
- Updated native package definitions, documentation, and test suites for the new PDF inspection capability.
2026-08-14 14:08:28 +02:00
can1357 311c32eaf5 fix(natives): repaired win32 build and bazel feature drift
- Synced pi-builtins bazel crate_features with cargo's resolved default
  set: bazel features are literal, so the meta-features never expanded
  and the procs/rg cluster (nohup, pgrep, pidwait, pkill, proc-match,
  ps, rg, sleep, timeout, top) was silently compiled out, leaving the
  process builtins unregistered under bazel and failing pi-shell tests.
- Repaired windows compilation of pi-builtins: cfg-gated the
  uucore::mode import in mkdir, imported std::env in sort's non-unix
  locale probe, mapped ProcInfo::pid through a closure in kill, brought
  MetadataExt into scope in wc, and replaced stat's unstable
  windows_by_handle metadata with a stable GetFileInformationByHandle
  query (volume serial, link count, file index, no-dereference aware).
- Imported HashSet for pi-shell's windows-only PATH merge.
- Added a clippy-ported bazel config + CI bucket so pi-builtins keeps
  its manifest-declared clippy allows under the bazel aspect while rustc
  warnings stay denied, and zeroed the remaining windows-target rustc
  warnings (unused params/imports in find, mv, rm, proc_match, ps).
2026-08-09 03:17:34 +02:00
can1357 2ee9943563 refactor: unify builtins in one place 2026-08-08 10:19:25 +02:00
can1357 4e62f3b7fd Merge PR #7660: ci(release): add SHA256SUMS.txt to GitHub releases (@andrew-scott-fischer) 2026-08-05 22:16:29 +02:00
Andrew Fischer 5da9525afd ci(release): add SHA256SUMS.txt to GitHub releases
Generate a sha256sum-compatible checksums file covering every release
binary and the browser-relay zip, and upload it as a release asset so
downloads can be verified offline without hitting the GitHub API.
2026-08-04 15:38:18 -07:00
metaphorics ee492dbe75 fix(ci): run the release version guard in CI
Wave-3 review finding on #7586:
- scripts/release.test.ts ran in neither CI nor the documented root
  command, so the release-version regression assertions guarded nothing
- add it to test:scripts and invoke that file from the workspace job
- the job deliberately does not run all of test:scripts: musl-release
  fails on main, so the whole group would red this job on an unrelated
  break
2026-08-05 02:51:03 +09:00
can1357 92c79d80c7 feat: introduced OMP Browser Relay extension with CDP RPC execution
- Implement the OMP Browser Relay extension with WebSocket communication and CDP RPC execution.
- Add browser relay server, daemon management, and bridge multiplexing in the coding agent.
- Introduce CLI commands and settings schema options for configuring and installing the relay.
- Add utility functions and test suites supporting environment parsing and relay lifecycle handling.
2026-08-02 05:33:07 +02:00
can1357 4df68d6043 fix(ci): serialized native addon builds to avoid kata pod OOM
- The aggregate //:natives-linux-all build links all six addon cdylibs
  concurrently; rustc RSS peaks OOMed the pod and the kernel killed the
  bazel server (exit 37, runs 30556752623 / 30557524371, twice at the
  same spot).
- Build one addon target per invocation so the persistent server shares
  analysis and cached actions while the heavy links run one at a time;
  a final aggregate build stays as a completeness no-op.
2026-07-30 18:06:49 +02:00
can1357 8db0228f4d fix(ci): unblocked release run on formatting and chunk watchdog
- Reformatted the logger burst test per biome (the type-check job gates on
  check:tools, which failed on the previous hotfix's formatting).
- Raised the native/unit bucket's chunk watchdog to 1200 s: the mupdf PDF
  extraction chunk runs ~7 min per attempt on burstable runners under a
  full fan-out and the 600 s default SIGKILLed both tries in release run
  30519992654; the watchdog targets wedged children, not slow chunks.
2026-07-30 08:59:03 +02:00
can1357 c3d1586740 ci: triggered workflows on root dependency file changes
- bun.lock, bunfig.toml, root package.json, and patches/** now trigger CI:
  a lockfile-only push previously shipped untested, and a release retagged
  onto such a commit never started its release run at all (the v17.2.0
  lockfile-format fix hit exactly this).
2026-07-30 08:17:59 +02:00
can1357 d562e53b83 refactor: extracted audio and voice engine into a standalone library crate
- Extracted audio capture and playback implementations, along with the WebRTC peer engine, from `pi-natives` into a new `pi-voice` library crate.
- Updated `pi-natives` bindings to consume the extracted `pi_voice` audio streams and live peer core.
- Added release validation gate jobs, parallelized Linux binary builds, and introduced a concurrent macOS release build job in the CI workflow.
- Updated Bazel workspace configurations, Cargo manifests, and documentation to include the new `pi-voice` crate and its dependencies.
2026-07-30 05:12:40 +02:00
can1357 a38a2f25cf ci: optimized github actions caching and workflows
- Updated GitHub Actions workflows and custom actions to optimize caching strategies and runners.
- Configured separate restore and save steps for bun store caching with non-PR restrictions.
- Added darwin release bazel cache seeding and fallback keys for cache restore.
- Removed native-inputs workflow action and disabled PR-side Rust validation.
2026-07-30 04:56:47 +02:00
can1357 b550858265 ci: upgraded continuous integration workflows and migrated bazel dependency locking
- Updated CI workflows and GitHub actions to enhance Bazel cache keying, credential masking, and validation checks.
- Migrated dependency locking from Cargo.Bazel.lock to MODULE.bazel.lock using rules_rust crate_universe.
- Updated build configuration, documentation, and tooling scripts to reflect the lockfile and cache changes.
2026-07-28 12:53:23 +02:00
can1357 0820085890 ci: restructured workflow pipelines and introduced bazel cache actions
- Updated bazel cache key generation with v2 schema version and streamlined remote cache usage.
- Added native-inputs composite action to centralize change detection and artifact caching.
- Added a scheduled workflow to warm the hosted bazel disk cache.
- Split the rust validation job and integrated prebuilt native addon caching into the CI pipeline.
2026-07-28 11:55:57 +02:00
can1357 ed4c78bc0f feat: streamlined native addon builds and caching in ci workflows
- Enhance CI workflows to build and reuse native addon artifacts instead of recompiling.
- Update bazel cache actions with selective backend detection and separate remote and disk modes.
- Add `--source` CLI option to install prebuilt native targets without requiring Bazel.
- Increase Kata runner memory configuration from 12Gi to 24Gi.
2026-07-28 02:06:13 +02:00
can1357 a7abeff1b7 perf(ci): cut warm CI time via download-skipping, splat reuse, PR gating
Four levers on top of the green pipeline:
- kata jobs pass --remote_download_toplevel, so fully cache-hit builds
  stay metadata-only instead of pulling every intermediate artifact from
  bazel-remote (the bulk of the previous 6-minute TS-only main runs).
- the xwin MSVC splat caches its ~1GiB CDN payload on the runner-cache
  PVC (OMP_XWIN_CACHE_DIR), instead of re-downloading per ephemeral pod.
- main-push rust jobs export their bazel disk cache to the GitHub cache
  (once per lockfile change, shared linux scope). GitHub only shares
  default-branch caches across PRs, and main runs on kata where
  actions/cache never saved — so every fresh PR was building cold.
- TS-only pull requests skip Rust validation entirely (gh pr diff path
  gate); their test jobs restore addons from the main-exported cache.

Export runs disable top-level-only downloading: remote hits would
otherwise export action entries whose blobs were never materialized.
2026-07-27 14:31:24 +02:00
can1357 4fd3662114 fix(ci): reused sandbox trees to stop fd exhaustion on kata pods
The zig and xwin toolchains stage ~10k-file input trees per action;
building and async-deleting thousands of sandbox trees exhausted file
descriptors (EMFILE in unix_jni during sandbox setup). --reuse_sandbox_directories
under --config=ci removes the churn, with a raise-only ulimit guard in
the bazel-launching steps as belt and braces.
2026-07-27 12:48:57 +02:00
can1357 8facd237d5 feat(build): migrated native pipeline to bazel with remote caching
- Replaced the napi-cli/cargo-zigbuild/cargo-xwin/sccache build path with
  Bazel: rules_rust + crate_universe over Cargo.lock, hermetic zig cc
  toolchains (linux-gnu pinned to glibc 2.17, linux-musl), host Xcode for
  darwin, and a repo-local hermetic clang-cl + llvm-ml + xwin toolchain for
  windows-msvc (bazel/toolchains/msvc).
- All eight shipped addons build as //:natives-<target> via the release
  transition in bazel/defs.bzl (opt, thin LTO, cgu=16, stripped, canonical
  .node naming); scripts/bazel-natives.ts is the single driver for local
  dev and CI.
- Rust validation moved to bazel test + clippy aspects (strict workspace
  policy for opted-in crates, default lints elsewhere, mirroring cargo
  semantics) and the rustfmt aspect; cargo stays as the dev-iteration
  surface, with brush-core/brush-builtins promoted to workspace members
  and excluded from cargo dev tasks to keep their historical scope.
- CI caches through an in-cluster bazel-remote action cache (TLS + basic
  auth, cluster-internal only); GitHub-hosted runners never touch the
  infrastructure and use an actions/cache-backed disk cache instead.
- Deleted the hand-rolled caching machinery: ci-target-cache,
  ci-native-artifact-cache, ci-build-native, native-source-hash,
  find-native-artifacts, restore-linux-native, native-prewarm workflow,
  ensure-* toolchain actions, and all sccache/Swatinem wiring.
- Warm native rebuilds drop from ~20 minutes to seconds; a cold client
  with a warm remote cache rebuilds the linux x64 pair in ~2.5 minutes.
2026-07-27 12:22:19 +02:00
can1357 5f988a8270 ci: configured native artifact caching and parallel execution in ci workflows
- Enhanced CI workflows and GitHub actions to support native artifact caching and parallel builds.
- Added composite actions and scripts for computing sources, finding artifacts, and managing caches.
- Updated infrastructure documentation and runner deployment scripts with revised resource limits.
2026-07-27 07:53:28 +02:00
can1357 59619623e1 feat: enabled cargo target caching and conditional validation in workflows
- Add scripts/ci-target-cache.ts to snapshot and restore Cargo target directories to S3 storage on omp-kata runners.
- Update .github/actions/build-native/action.yml to support target cache restoration, saving, and compiler launcher configurations.
- Add skip_validation input in GitHub workflow actions to bypass clippy and Rust test checks on release runs.
2026-07-25 02:34:14 +02:00
can1357 90e0a8af28 fix(ci): repaired native builds broken by native audio stack deps
- Added ensure-cmake action installing pinned cmake/ninja on omp-kata pods; audiopus_sys builds bundled libopus via CMake (Ninja for MSVC cross).
- Set CMAKE_POLICY_VERSION_MINIMUM=3.5 globally and in build-native.ts: the bundled opus tree declares cmake_minimum_required below 3.5, which CMake 4.x refuses.
- Dropped the -C target-cpu=native fallback for non-x64 native builds: it baked build-host CPU features into shipped darwin arm64 addons and trips ring 0.17's aarch64-apple const assertion.
2026-07-24 09:36:31 +02:00
can1357 5e362714fe ci: installed libstdc++ and libgcc in alpine musl smoke
- Bun musl-target binaries link both dynamically, matching bun's own
  Alpine runtime requirements.
2026-07-23 02:45:13 +02:00
can1357 bb15939414 **no more vouching! let's see how it goes for a week :)** 2026-07-23 02:41:47 +02:00
can1357 1f7d2ff9ea ci: skipped glibc-host smoke for musl release binaries
- Musl-linked binaries cannot exec on glibc runners (missing
  /lib/ld-musl loader); the dedicated Alpine container step remains
  their smoke gate.
2026-07-23 02:22:51 +02:00
can1357 6a517cfbbc Merge farm/b12a11bd: feat(release): add musl-linked linux builds
# Conflicts:
#	package.json
2026-07-22 23:08:42 +02:00
roboomp 83cb70eafc fix(release): skip glibc floor for musl native builds
The glibc floor input was applied to every linux row, suffixing musl cross-targets to invalid *-unknown-linux-musl.2.17 triples. Gate the floor on non-musl libc.

Fixes #3367
2026-07-22 19:11:57 +00:00
roboomp 6efcdfb66e feat(release): added musl-linked linux builds
Built x64 and arm64 musl release artifacts with matching native addons, Alpine smoke coverage, and installer detection.

Fixes #3367
2026-07-22 19:06:20 +00:00
can1357 10846c255a ci(release): pinned npm 11 for publishing 2026-07-09 20:01:37 +02:00
can1357 acd0d31f62 ci(workflows): ignored VOUCHED.td in CI triggers
- Added a paths-ignore filter to the CI workflow to prevent unnecessary runs during vouch bookkeeping commits.
- Ensured that pushes affecting both vouch files and project code continue to trigger the full CI matrix.
2026-06-19 17:02:13 +02:00
can1357 55d42cd5cf ci(workflows): added conditional sccache setup for self-hosted and GitHub runners
- Detected the runner environment in CI by checking SCCACHE_BUCKET and exporting an on_infra output.
- Updated the workflow to use the local ensure-sccache action on self-hosted runners and mozilla-actions/sccache-action on GitHub-hosted runners.
2026-06-15 07:37:58 +02:00
can1357 bc6130aad4 fix(natives): build linux addons against a glibc 2.17 floor via cargo-zigbuild
Native linux-x64/arm64 builds moved onto the Ubuntu 24.04 (glibc 2.39)
omp-kata runner. The x64 addon was a plain host build that linked the
runner's glibc and failed to dlopen with `version 'GLIBC_2.39' not found`
on older distros; the arm64 cross-build floated up to GLIBC_2.30. Build
the shipped linux-gnu addons through cargo-zigbuild against a pinned 2.17
floor so they load on any glibc >= 2.17.

- build-native.ts: key the tree-sitter-just `-UNDEBUG` CFLAGS off the
  bare triple (cargo-zigbuild strips the `.2.17` glibc suffix before
  invoking cargo) and symlink the suffixed target dir napi 3.7.0 expects
  to the bare dir cargo-zigbuild writes, so postBuild copyArtifact finds
  the cdylib.
- build-native action: add a `glibc` input plus a resolve step deriving
  the zigbuild cross_target (suffixed) and the rustup bare_target
  (stripped); gate zig/cargo-zigbuild install on cross_target so the
  host-arch x64 build still runs native Rust tests.
- ci.yml: GLIBC_FLOOR=2.17 fed to the linux-x64 and linux-arm64 native
  jobs.

Re-tags 15.13.1, whose release failed at the linux-x64 binary smoke
before any publish step ran.
2026-06-15 05:39:02 +02:00
can1357 05fd499551 Merge PR #1435: feat: added isolated profiles with --profile and --alias
Closes #1435

# Conflicts:
#	.github/actions/bun-install/action.yml
2026-06-15 02:47:12 +02:00
can1357 f8e7874159 Merge remote-tracking branch 'origin/farm/ad9a74c4/release-notes-include-silent-tags' 2026-06-15 02:26:09 +02:00
Ogrodev 932ebe9a48 Merge remote-tracking branch 'upstream/main' into feat/profiles-and-alias
# Conflicts:
#	.github/actions/build-native/action.yml
#	.github/workflows/ci.yml
2026-06-14 21:26:03 -03:00
can1357 1f5307fdec feat(infra): migrated runner caches to PVC-backed Bun/Cargo and RustFS sccache
- Updated bun-install action to set mounted cache mode and use PVC cache paths.
- Removed RustFS Bun restore/save and maintenance scripts, replacing them with mounted cache setup.
- Removed zstd from runner image installation and baked-tool verification checks.
- Updated infra docs to describe split caching with RustFS for sccache and PVC for Bun/Cargo.
2026-06-15 02:24:35 +02:00
Ogrodev c7537eb1f4 fix(ci): disable rustfs bun cache on test jobs 2026-06-14 21:20:59 -03:00
roboomp 77a5befd53 fix(ci): authenticate gh release lookup and fail loud on lookup error
Two issues caught in review on #2597:

1. `gh release list` in GitHub Actions requires GH_TOKEN. The release
   notes step in `.github/workflows/ci.yml` had no env block, so gh would
   exit non-zero and the script's silent fallback would re-strand the
   silent-tag entries this change is meant to recover. Pass
   `GH_TOKEN: ${{ secrets.GITHUB_TOKEN }}` to the step.

2. Silently degrading to legacy single-version output on gh failure is
   itself the regression vector — a future token misconfig or gh outage
   would lose data with no signal. `resolvePublishedFloorTag` now throws
   on gh failure with an actionable hint ("pass GH_TOKEN in Actions; set
   OMP_RELEASE_NOTES_FLOOR= locally to opt into legacy mode"). The
   thrown error propagates out of `main` and exits non-zero, failing the
   CI step loudly so the release is rebuilt with the fix.

The legitimate null path is preserved: `OMP_RELEASE_NOTES_FLOOR=`
(empty) still forces single-version mode, and a successful gh call with
no candidate < target still returns null (first-ever publish case).

Verified locally: hiding gh from PATH now exits 1 with the hint;
`OMP_RELEASE_NOTES_FLOOR=` with hidden gh still produces the legacy
84-bullet single-version output.

Refs #2596
2026-06-14 23:43:17 +00:00
can1357 ff5b06d0c2 ci: added CI workflows and actions for pinned toolchain-native builds
- Added composite GitHub actions to ensure rust toolchains and cargo helpers.
- Added a kata-native build action with variant checks and platform artifact uploads.
- Reworked CI matrices to split native cross-platform jobs and gate releases accordingly.
- Updated runner bootstrap and image to preinstall pinned build tools for CI consistency.
2026-06-15 01:01:45 +02:00
can1357 82871093bd ci(actions): skipped bun setup and rust-cache on shared-sccache runners
- Updated the bun-install composite action to detect preinstalled Bun and only fetch it when missing.
- Added cache-backend detection and wiring so Bun dependencies use RustFS cache when SCCACHE credentials are present.
- Conditionally skipped rust-cache in build-native and CI jobs when shared sccache runners are available, relying on the existing RustFS/sccache layer instead.
2026-06-15 00:52:32 +02:00
can1357 2be8256af0 ci(workflows): shared bun caching in CI via backend-aware install action
- Updated CI dependency install flow to share bun cache orchestration across jobs.
- Added RustFS-backed bun cache restore/save script keyed by bun.lock hash.
2026-06-15 00:18:43 +02:00
can1357 6d8bd80392 ci(workflows): share rust sccache via in-cluster RustFS S3 on self-hosted runners
Self-hosted omp-kata runners now inject a shared S3 (RustFS, in-cluster)
sccache backend via pod env (SCCACHE_BUCKET/ENDPOINT/REGION + AWS creds).
The Enable-sccache step branches on SCCACHE_BUCKET: when set, sccache reads
the S3 config from the inherited environment; otherwise GitHub-hosted
runners (macOS, ubuntu-arm) keep the GHA cache backend since they can't
reach the private RustFS.
2026-06-14 23:07:54 +02:00
can1357 3843a86df9 ci(workflows): updated CI job labels and removed fast test dependency
- Renamed the coding-agent native job and bucket names from tooling to unit in CI.
- Removed test_coding_agent_fast from the release job dependency list and gating condition.
2026-06-14 22:40:21 +02:00
can1357 b8e4da23d0 ci(ci): refactored CI setup and test-state isolation for coding-agent workflows
- Added a setup-system-deps action with preloaded-runner guards and apt fallbacks.
- Updated CI workflows to download Linux x64 native artifacts and gate on native job success.
- Renamed coding-agent fast mode to singleton in scripts and test partitioning logic.
- Added settings test-state begin/restore helpers with recursive cleanup in affected tests.
2026-06-14 22:37:05 +02:00
can1357 a734c29234 ci(scripts): reworked CI test execution with mode-based TypeScript buckets
- Added a mode-based `ci-test-ts.ts` runner with `--dry-run` support.
- Partitioned coding-agent tests into fast/ui/runtime/native/heavy buckets and separated workspace/native runs.
- Added coding-agent bucket modes that fail CI when a target bucket has no matching tests.
- Updated CI scripts/workflow to run the new TS buckets, use `omp-kata`, and gate releases on them.
2026-06-14 21:55:55 +02:00
can1357 73f2dbc3b5 ci(workflows): isolated manual workflow_dispatch runs in release concurrency groups
- Updated the CI workflow concurrency rules to treat `workflow_dispatch` like a release path, grouping those runs by SHA and disabling cancel-in-progress.
- Extended the `GhaEval` expression evaluator in `scripts/ci-concurrency.test.ts` to support `==`/`!=` and align falsy checks.
- Added a regression test covering tagged-main `workflow_dispatch` runs using the release-style concurrency behavior.
2026-06-14 19:04:05 +02:00
roboomp 9acc24329f fix(ci): scope release runs to per-sha concurrency group
The workflow-wide concurrency group was `${{ github.workflow }}-${{ github.ref }}`
with `cancel-in-progress: true`, so the release-script's atomic
`refs/heads/main + v* tag` push shared the `CI-refs/heads/main` group with every
later main push. The newer run cancelled the older release run before
`release_binary` / `release_github` / `release_npm` could execute, and no
future run carried the tag at HEAD, so the tag stayed published-as-a-ref but
unreleased on GitHub and npm (v15.12.6 in the wild).

Release runs are now routed to a per-sha group with `cancel-in-progress: false`
when either:
  * the push subject starts with `chore: bump version to ` (the release-script
    commit convention from scripts/release.ts), or
  * `github.ref` is a `v*` tag (workflow_dispatch recovery from a tag ref).

Other events keep the cheap branch-wide cancel-in-progress for PR/main churn.
release.ts's retry hint now uses the same release commit subject so manual
retries also land in the per-sha group.

Added scripts/ci-concurrency.test.ts: a regression test with a minimal GHA
expression evaluator that asserts the resolved group / cancel-in-progress for
auto-release pushes, retry pushes, tag-ref dispatches, plain main pushes, PRs,
distinct release shas, and a benign `revert: chore: bump version to ...`
follow-up.

Fixes #2564
2026-06-14 12:23:23 +00:00
can1357 8fa1f6c250 feat: added shared collab wire protocol and web guest collaboration client
- Added @oh-my-pi/pi-wire and reworked collab protocol types into shared contracts.
- Added wire-compatibility guards in coding-agent host to block unsupported events.
- Added standalone collab-web package with guest UI, mock-host tooling, and local relay.
- Added secure room-link validation, WebCrypto framing, and safer socket routing.
2026-06-12 11:54:41 +02:00
can1357 96defff9a5 ci(workflows): provisioned native addons for the npm publish job
The pi-coding-agent prepack (bundle-dist.ts) imports the pi-utils barrel,
which eagerly loads the pi-natives addon; release_npm never downloaded the
linux x64 .node artifacts, so the publish died in prepack. Mirror the
test job's download-artifact step (release runs always rebuild natives in
the same run, so the default run-id resolves).
2026-06-10 08:22:19 +02:00