Repository navigation
137 lines (124 loc) · 4.78 KB
/
Copy pathci.yml
File metadata and controls
137 lines (124 loc) · 4.78 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
130
131
132
133
134
135
136
137
name: CI
on:
push:
branches: [main]
tags: ["v*"]
pull_request:
concurrency:
group: ci-${{ github.ref }}
cancel-in-progress: true
jobs:
test:
name: ${{ matrix.os }} · py${{ matrix.python-version }}
runs-on: ${{ matrix.os }}
# Windows is not a supported platform yet (the shell tool assumes a POSIX shell); it runs
# so we can see how far off it is, but cannot fail the build.
continue-on-error: ${{ matrix.experimental || false }}
strategy:
fail-fast: false
matrix:
os: [ubuntu-latest]
python-version: ["3.11", "3.12", "3.13"]
include:
- os: macos-latest
python-version: "3.12"
- os: windows-latest
python-version: "3.12"
experimental: true
steps:
- uses: actions/checkout@v7
- uses: astral-sh/setup-uv@v7
with:
enable-cache: true
- name: Install
shell: bash
run: |
uv venv --python ${{ matrix.python-version }}
uv pip install -e ".[dev]"
- name: Install bubblewrap (the sandbox tests run for real on Linux)
if: runner.os == 'Linux'
run: |
sudo apt-get update -qq && sudo apt-get install -y -qq bubblewrap
bwrap --version
# Ubuntu 24.04 leaves unprivileged user namespaces without capabilities unless an
# AppArmor profile covers the binary; the runner has none for bwrap, so a network
# namespace cannot be set up ("loopback: Failed RTM_NEWADDR"). Load the stock
# profile, as docs/sentinel.md tells users to; fall back to lifting the restriction.
echo "apparmor_restrict_unprivileged_userns=$(cat /proc/sys/kernel/apparmor_restrict_unprivileged_userns 2>/dev/null || echo n/a)"
if ! bwrap --unshare-all --ro-bind / / -- /bin/true 2>/dev/null; then
sudo apt-get install -y -qq apparmor-profiles apparmor-utils >/dev/null 2>&1 || true
if [ -f /usr/share/apparmor/extra-profiles/bwrap-userns-restrict ]; then
sudo install -m 0644 /usr/share/apparmor/extra-profiles/bwrap-userns-restrict /etc/apparmor.d/ \
&& sudo apparmor_parser -r /etc/apparmor.d/bwrap-userns-restrict \
&& echo "loaded the bwrap-userns-restrict profile" || true
fi
bwrap --unshare-all --ro-bind / / -- /bin/true 2>/dev/null \
|| { sudo sysctl -w kernel.apparmor_restrict_unprivileged_userns=0 || true; }
fi
bwrap --unshare-all --ro-bind / / -- /bin/true && echo "bubblewrap works here" || echo "bubblewrap cannot create a namespace here; the boxed tests will skip"
- name: Ruff lint
run: uv run ruff check openmuse tests scripts
- name: Ruff format
run: uv run ruff format --check openmuse tests scripts
- name: Mypy
run: uv run mypy
- name: Tests (no live LLM calls)
run: uv run python -m pytest -q -m "not live"
- name: Package builds and installs
if: matrix.os == 'ubuntu-latest' && matrix.python-version == '3.12'
shell: bash
run: |
uv build
uv venv --python 3.12 /tmp/smoke
uv pip install --python /tmp/smoke/bin/python dist/*.whl
/tmp/smoke/bin/openmuse version
web:
name: web app build
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@v7
- uses: actions/setup-node@v7
with:
node-version: 22
cache: npm
cache-dependency-path: web/package-lock.json
- name: Install
run: npm ci
working-directory: web
- name: Lint
run: npm run lint
working-directory: web
- name: Unit tests
run: npm test
working-directory: web
- name: Type-check and build
run: npm run build
working-directory: web
- name: Built app is committed
# a dependency bump changes the bundle by definition; the rebuild lands right after
# the merge (see CONTRIBUTING.md, "Releasing")
if: github.actor != 'dependabot[bot]'
run: |
if [ -n "$(git status --porcelain openmuse/server/static)" ]; then
echo "openmuse/server/static is out of date — run 'cd web && npm run build' and commit the result"
git status --porcelain openmuse/server/static
exit 1
fi
docker:
name: docker build
runs-on: ubuntu-latest
needs: test
steps:
- uses: actions/checkout@v7
- uses: docker/setup-buildx-action@v4
- name: Build image
uses: docker/build-push-action@v7
with:
context: .
push: false
load: true
tags: openmuse:ci
cache-from: type=gha
cache-to: type=gha,mode=max
- name: Smoke test
run: docker run --rm openmuse:ci version