|
| 1 | +# Standalone CI for the public ClickHouse/code-interpreter repo, which is |
| 2 | +# published from services/codeapi as snapshot commits (see |
| 3 | +# .github/workflows/publish-codeapi.yml in the monorepo). This file is |
| 4 | +# inert inside the monorepo — GitHub only runs workflows from the repo |
| 5 | +# root — and becomes the root workflow in the published repo. Keep it in |
| 6 | +# sync with ci-codeapi.yml. |
| 7 | +name: CI |
| 8 | + |
| 9 | +on: |
| 10 | + push: |
| 11 | + # sync/** is included because the sync PR is opened by the GitHub Actions |
| 12 | + # bot, whose events don't trigger pull_request workflows — the push-event |
| 13 | + # runs on the branch satisfy the PR's checks instead. |
| 14 | + branches: [main, 'sync/**'] |
| 15 | + pull_request: |
| 16 | + |
| 17 | +concurrency: |
| 18 | + group: ci-${{ github.ref_name }} |
| 19 | + cancel-in-progress: true |
| 20 | + |
| 21 | +jobs: |
| 22 | + api-unit-tests: |
| 23 | + name: API Unit Tests |
| 24 | + runs-on: ubuntu-latest |
| 25 | + defaults: |
| 26 | + run: |
| 27 | + working-directory: api |
| 28 | + steps: |
| 29 | + - uses: actions/checkout@v6 |
| 30 | + |
| 31 | + - uses: oven-sh/setup-bun@v2 |
| 32 | + with: |
| 33 | + bun-version: 1.3.13 |
| 34 | + |
| 35 | + - name: Cache Bun packages |
| 36 | + uses: actions/cache@v5 |
| 37 | + with: |
| 38 | + path: ~/.bun/install/cache |
| 39 | + key: ${{ runner.os }}-codeapi-api-bun-1.3.13-${{ hashFiles('api/bun.lock') }} |
| 40 | + restore-keys: | |
| 41 | + ${{ runner.os }}-codeapi-api-bun-1.3.13- |
| 42 | +
|
| 43 | + - name: Install dependencies |
| 44 | + run: bun ci |
| 45 | + |
| 46 | + - name: Build API |
| 47 | + run: bun run build |
| 48 | + |
| 49 | + - name: Compile + smoke spec-guard |
| 50 | + # spec-guard.c is otherwise only compiled by api/Dockerfile, which |
| 51 | + # the helm workflow builds post-merge. Catching syntax errors and |
| 52 | + # exec-semantic regressions pre-merge prevents broken sandbox |
| 53 | + # binaries from reaching the image build. |
| 54 | + working-directory: api/src |
| 55 | + run: | |
| 56 | + gcc -O2 -static -Wall -Wextra -Werror -o /tmp/spec-guard spec-guard.c |
| 57 | + # Smoke: spec-guard must execvp its argument cleanly. Use a |
| 58 | + # parent process with a known FD population so we also assert |
| 59 | + # the close-inherited-FDs path runs (child must see only the |
| 60 | + # FDs `ls` itself opens). |
| 61 | + PARENT_FDS=$(bash -c 'exec 10<&0 11<&0 12<&0 13<&0 14<&0; ls /proc/self/fd | wc -l') |
| 62 | + CHILD_FDS=$(bash -c 'exec 10<&0 11<&0 12<&0 13<&0 14<&0; /tmp/spec-guard /bin/ls /proc/self/fd | wc -l') |
| 63 | + echo "parent fds (with 5 extra inherited): $PARENT_FDS" |
| 64 | + echo "child fds via spec-guard: $CHILD_FDS" |
| 65 | + test "$PARENT_FDS" -ge 8 || { echo "FAIL: parent did not actually inherit extra FDs"; exit 1; } |
| 66 | + test "$CHILD_FDS" -le 5 || { echo "FAIL: spec-guard did not close inherited FDs (child saw $CHILD_FDS)"; exit 1; } |
| 67 | +
|
| 68 | + - name: Bun tests |
| 69 | + run: bun run test |
| 70 | + |
| 71 | + service-unit-tests: |
| 72 | + name: Service Unit Tests |
| 73 | + runs-on: ubuntu-latest |
| 74 | + defaults: |
| 75 | + run: |
| 76 | + working-directory: service |
| 77 | + steps: |
| 78 | + - uses: actions/checkout@v6 |
| 79 | + |
| 80 | + - uses: oven-sh/setup-bun@v2 |
| 81 | + with: |
| 82 | + bun-version: 1.3.13 |
| 83 | + |
| 84 | + - name: Cache Bun packages |
| 85 | + uses: actions/cache@v5 |
| 86 | + with: |
| 87 | + path: ~/.bun/install/cache |
| 88 | + key: ${{ runner.os }}-codeapi-service-bun-1.3.13-${{ hashFiles('service/bun.lock') }} |
| 89 | + restore-keys: | |
| 90 | + ${{ runner.os }}-codeapi-service-bun-1.3.13- |
| 91 | +
|
| 92 | + - name: Install dependencies |
| 93 | + run: bun ci |
| 94 | + |
| 95 | + - name: Bun tests |
| 96 | + run: bun run test |
0 commit comments