Files
oh-my-pi/.github/actions/native-inputs/action.yml
T
can1357 b550858265 ci: upgraded continuous integration workflows and migrated bazel dependency locking
- Updated CI workflows and GitHub actions to enhance Bazel cache keying, credential masking, and validation checks.
- Migrated dependency locking from Cargo.Bazel.lock to MODULE.bazel.lock using rules_rust crate_universe.
- Updated build configuration, documentation, and tooling scripts to reflect the lockfile and cache changes.
2026-07-28 12:53:23 +02:00

79 lines
3.7 KiB
YAML

name: "Native inputs: change detection + artifact cache key"
description: >
Single source of truth for what counts as a native-affecting change.
`rust` gates Rust validation (tests, clippy, rustfmt); `cache-key`
addresses the prebuilt Linux x64 addon pair published by trusted main
builds. The detector pathspec and the hashed file set MUST cover the same
inputs — drift means a native change could ship without validation or be
tested against stale addons. The key embeds a schema version, OS, arch,
target pair, and build profile so a future target/profile change can
never resolve valid-but-wrong .node files under the same source hash.
outputs:
rust:
description: Whether the event touches native inputs (always true off pull_request)
value: ${{ steps.changes.outputs.rust }}
source-hash:
description: 16-hex fingerprint over every native build input
value: ${{ steps.hash.outputs.source-hash }}
cache-key:
description: Exact actions/cache key for the prebuilt Linux x64 addon pair
value: ${{ steps.hash.outputs.cache-key }}
runs:
using: composite
steps:
- name: Detect native-affecting changes
id: changes
shell: bash
env:
GH_TOKEN: ${{ github.token }}
run: |
set -euo pipefail
if [ "${{ github.event_name }}" != "pull_request" ]; then
echo "rust=true" >> "$GITHUB_OUTPUT"
exit 0
fi
# Write the diff to a file before matching: in a pipeline, an API
# failure is indistinguishable from "no native changes" (skips
# validation — fail-open), and grep -q can close the pipe early so
# gh dies on SIGPIPE and pipefail flips a MATCH to rust=false.
changed_files="$RUNNER_TEMP/native-changed-files"
gh pr diff ${{ github.event.pull_request.number }} --name-only > "$changed_files"
if grep -qE '^(crates/|bazel/|Cargo\.(toml|lock)|MODULE\.bazel(\.lock)?|BUILD\.bazel|\.bazelrc|\.bazelignore|\.bazelversion|rust-toolchain\.toml|rustfmt\.toml|scripts/bazel-natives\.ts|\.github/actions/(bazel-cache|bazel-natives|native-artifacts|native-inputs)/|\.github/workflows/ci\.yml)' "$changed_files"; then
echo "rust=true" >> "$GITHUB_OUTPUT"
else
echo "No native-affecting changes; skipping Rust validation."
echo "rust=false" >> "$GITHUB_OUTPUT"
fi
# Content-addresses the addon bytes from git index entries (mode,
# blob identity, path) — `git ls-files -s` covers the executable bit
# and never follows symlinks into worktree bytes. `--error-unmatch`
# fails the step loudly when a listed path disappears instead of
# silently narrowing the key.
- name: Compute native source hash
id: hash
shell: bash
run: |
set -euo pipefail
source_hash=$(git ls-files -s -z --error-unmatch -- \
crates bazel \
Cargo.toml Cargo.lock \
MODULE.bazel MODULE.bazel.lock BUILD.bazel \
.bazelrc .bazelignore .bazelversion \
rust-toolchain.toml rustfmt.toml \
scripts/bazel-natives.ts \
.github/actions/bazel-cache .github/actions/bazel-natives \
.github/actions/native-artifacts .github/actions/native-inputs \
.github/workflows/ci.yml \
| sort -z \
| sha256sum \
| cut -c1-16)
{
echo "source-hash=$source_hash"
echo "cache-key=native-addons-v1-linux-x64-baseline+modern-opt-$source_hash"
} >> "$GITHUB_OUTPUT"
echo "Native source hash: $source_hash"