ci: re-pin codeql-action to the true v4.38.0 commit (#56) #129
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
| # This workflow is managed by gh actions-lock. | |
| # SPDX-License-Identifier: MPL-2.0 | |
| # This workflow is managed by gh actions-lock. | |
| # This workflow is managed by gh actions-lock. | |
| # This workflow is managed by gh actions-lock. | |
| # Lithoglyph - Full Test Suite | |
| # | |
| # Runs Forth, Zig, C FFI, Lean, and ReScript tests. | |
| # Complements zig-tests.yml (which focuses on multiversion Zig testing). | |
| name: Test Suite | |
| on: | |
| push: | |
| branches: [ main, develop ] | |
| pull_request: | |
| branches: [ main, develop ] | |
| permissions: read-all | |
| jobs: | |
| test-forth: | |
| name: Forth Block Tests | |
| runs-on: ubuntu-latest | |
| permissions: | |
| contents: read | |
| steps: | |
| - name: Checkout | |
| uses: actions/checkout@v7.0.1 | |
| - name: Install gforth | |
| run: sudo apt-get update && sudo apt-get install -y gforth | |
| - name: Run block tests | |
| working-directory: core-forth/test | |
| run: | | |
| echo "=== Forth Block Storage Tests ===" | |
| gforth test-blocks.fs -e bye | |
| - name: Check Forth source loads | |
| working-directory: core-forth/src | |
| run: | | |
| echo "=== Loading Forth source files ===" | |
| gforth lithoglyph-blocks.fs -e 'bye' | |
| gforth lithoglyph-journal.fs -e 'bye' | |
| gforth lithoglyph-model.fs -e 'bye' | |
| echo "All Forth files load successfully" | |
| test-zig-core: | |
| name: Zig Core Tests | |
| runs-on: ubuntu-latest | |
| permissions: | |
| contents: read | |
| steps: | |
| - name: Checkout | |
| uses: actions/checkout@v7.0.1 | |
| - name: Setup Zig | |
| uses: goto-bus-stop/setup-zig@v2.2.1 | |
| with: | |
| version: '0.15.2' | |
| - name: Run unit tests | |
| working-directory: core-zig | |
| run: | | |
| echo "=== Zig Unit Tests ===" | |
| zig build test | |
| echo "All Zig tests passed" | |
| - name: Build libraries | |
| working-directory: core-zig | |
| run: | | |
| echo "=== Building Libraries ===" | |
| zig build | |
| ls -lh zig-out/lib/ | |
| test-ffi: | |
| name: C FFI Integration Tests | |
| runs-on: ubuntu-latest | |
| needs: test-zig-core | |
| permissions: | |
| contents: read | |
| steps: | |
| - name: Checkout | |
| uses: actions/checkout@v7.0.1 | |
| - name: Setup Zig | |
| uses: goto-bus-stop/setup-zig@v2.2.1 | |
| with: | |
| version: '0.15.2' | |
| - name: Build Zig libraries | |
| working-directory: core-zig | |
| run: zig build | |
| - name: Compile C FFI tests | |
| working-directory: core-zig | |
| run: | | |
| gcc -o test-version-only test-version-only.c -L zig-out/lib -llith_bridge | |
| gcc -o test-db-open test-db-open.c -L zig-out/lib -llith_bridge | |
| # -I../generated/abi: test-ffi-integration.c is the only one of the | |
| # three that #includes "bridge.h", and bridge.h is generated to | |
| # generated/abi/ at the repo root, not into core-zig. Without it: | |
| # test-ffi-integration.c:17:10: fatal error: bridge.h: No such file | |
| # ci.yml already had this flag; it was never copied here or into | |
| # build/just/lithoglyph.just. Same compile, three call sites, fixed in | |
| # one — which is why CI passed while Test Suite failed on the same commit. | |
| gcc -I../generated/abi -o test-ffi-integration test-ffi-integration.c -L zig-out/lib -llith_bridge | |
| - name: Run FFI tests | |
| working-directory: core-zig | |
| run: | | |
| echo "=== C FFI Integration Tests ===" | |
| LD_LIBRARY_PATH=zig-out/lib ./test-version-only | |
| LD_LIBRARY_PATH=zig-out/lib ./test-db-open | |
| LD_LIBRARY_PATH=zig-out/lib ./test-ffi-integration | |
| echo "All FFI tests passed" | |
| - name: Verify ABI exports | |
| working-directory: core-zig | |
| run: | | |
| echo "=== ABI Export Check ===" | |
| nm -D zig-out/lib/liblith_bridge.so | grep ' T lith_' | sort | |
| nm -D zig-out/lib/liblith_bridge.so | grep -q 'lith_db_open' | |
| nm -D zig-out/lib/liblith_bridge.so | grep -q 'lith_apply' | |
| nm -D zig-out/lib/liblith_bridge.so | grep -q 'lith_introspect_schema' | |
| echo "All expected ABI exports present" | |
| test-lean: | |
| name: Lean 4 Normalizer Tests | |
| runs-on: ubuntu-latest | |
| permissions: | |
| contents: read | |
| steps: | |
| - name: Checkout | |
| uses: actions/checkout@v7.0.1 | |
| - name: Install elan (Lean version manager) | |
| uses: leanprover/lean-action@50fcf42d2e460296f1a34b402e990d1b24f8b596 # v1.6.0 | |
| with: | |
| auto-config: false | |
| build: false | |
| test: false | |
| lint: false | |
| use-mathlib-cache: false | |
| use-github-cache: false | |
| lake-package-directory: normalizer/lean | |
| - name: Build and test Lean project | |
| working-directory: normalizer/lean | |
| run: | | |
| echo "=== Lean 4 Normalizer ===" | |
| lake build | |
| echo "Lean build successful (tests run via #eval during build)" | |
| # The "ReScript Test Suites" job was removed here, not repaired. | |
| # | |
| # It was unrunnable and, had it run, could not have failed: | |
| # | |
| # 1. It pinned denoland/setup-deno@5fae568d37c3b73e63e2911f55b8b3fbc76d26f8, | |
| # a SHA that does not resolve — "Unable to resolve action ... unable to | |
| # find version". The job never started. | |
| # 2. Both steps ended `|| echo "... (skipping for now)"`, so a real failure | |
| # was swallowed and reported as success. | |
| # 3. `deno test` finds nothing to run: tests/property, tests/fuzz, | |
| # tests/integration and tests/e2e each report "No test modules found". | |
| # 4. No file under tests/ calls Deno.test. There are no tests. | |
| # | |
| # So the suite it guarded is empty, and ReScript is not the intended language | |
| # for this layer — AffineScript is. See docs/lithoglyph/AFFINESCRIPT-PORT.adoc | |
| # for the inventory and what has to exist before a real gate can go here. | |
| # | |
| # Deliberately left with NO replacement job rather than a permanently-red or | |
| # always-green placeholder: per scripts/check-no-placeholders.sh, an | |
| # unsatisfiable gate trains people to ignore CI. When the AffineScript | |
| # toolchain can check these sources, add a job that genuinely fails. |