name: Rust CI on: workflow_call: push: branches: - master - main pull_request: concurrency: group: rust-ci-${{ github.event_name }}-${{ github.workflow }}-${{ github.event.pull_request.number || github.ref }} cancel-in-progress: true permissions: contents: read env: CARGO_INCREMENTAL: 0 CARGO_PROFILE_DEV_DEBUG: 0 CARGO_PROFILE_TEST_DEBUG: 0 CARGO_TERM_COLOR: always jobs: changes: name: Detect Rust CI scope runs-on: ubuntu-latest outputs: rust: ${{ steps.scope.outputs.rust }} shell: ${{ steps.scope.outputs.shell }} steps: - uses: actions/checkout@fbc6f3992d24b796d5a048ff273f7fcc4a7b6c09 # v5 with: fetch-depth: 0 - name: Classify changed paths id: scope shell: bash run: | # workflow_call(Nightly)仍须完整执行;普通 push/PR 只按源码和构建 # 指纹触发 Rust jobs,安装脚本、Compose、README 等由 shell scope 覆盖。 if [ "$GITHUB_EVENT_NAME" = "workflow_call" ]; then echo "rust=true" >> "$GITHUB_OUTPUT" echo "shell=true" >> "$GITHUB_OUTPUT" exit 0 fi if [ "$GITHUB_EVENT_NAME" = "pull_request" ]; then git fetch --no-tags origin "$GITHUB_BASE_REF" --depth=1 changed_paths=$(git diff --name-only "origin/$GITHUB_BASE_REF...$GITHUB_SHA") elif [ "$GITHUB_EVENT_NAME" = "push" ] && [ "$GITHUB_EVENT_BEFORE" != "0000000000000000000000000000000000000000" ]; then changed_paths=$(git diff --name-only "$GITHUB_EVENT_BEFORE" "$GITHUB_SHA") else changed_paths=$(git ls-files) fi rust=false shell=false while IFS= read -r path; do case "$path" in Cargo.toml|Cargo.lock|rust-toolchain.toml|.cargo/*|*.rs|*/Cargo.toml|*/build.rs|*.sql|.github/workflows/*.yml|.github/workflows/*.yaml) rust=true ;; *.sh|*.py|README.md|*/README.md|.env.example|Dockerfile*|docker-compose*.yml|docker-compose*.yaml) shell=true ;; esac done <<< "$changed_paths" echo "rust=$rust" >> "$GITHUB_OUTPUT" echo "shell=$shell" >> "$GITHUB_OUTPUT" shell_security: name: Shell security fixtures needs: changes if: ${{ needs.changes.outputs.shell == 'true' }} runs-on: ubuntu-latest steps: - uses: actions/checkout@fbc6f3992d24b796d5a048ff273f7fcc4a7b6c09 # v5 - name: Run installer and supply-chain fixtures shell: bash run: | python3 tests/compose_database_config_test.py bash tests/deploy_state_safety_test.sh bash tests/install_archive_safety_test.sh bash tests/install_container_runtime_security_test.sh bash tests/install_current_release_link_test.sh bash tests/install_local_bundle_safety_test.sh bash tests/install_privileged_write_safety_test.sh bash tests/install_source_trust_test.sh bash tests/release_supply_chain_test.sh bash tests/update_compose_safety_test.sh bash tests/tunnel_installer_config_security_test.sh fmt: name: Format needs: changes if: ${{ needs.changes.outputs.rust == 'true' }} runs-on: ubuntu-latest steps: - uses: actions/checkout@fbc6f3992d24b796d5a048ff273f7fcc4a7b6c09 # v5 - name: Install Rust toolchain uses: dtolnay/rust-toolchain@4360b52568e2003a75bf9bc1d59f33a8e3fc893c # stable with: toolchain: 1.95.0 components: rustfmt - name: Format run: cargo fmt --all --check clippy_gateway: name: Clippy (Gateway) needs: changes if: ${{ needs.changes.outputs.rust == 'true' }} runs-on: ubuntu-latest steps: - uses: actions/checkout@fbc6f3992d24b796d5a048ff273f7fcc4a7b6c09 # v5 - name: Install Rust toolchain uses: dtolnay/rust-toolchain@4360b52568e2003a75bf9bc1d59f33a8e3fc893c # stable with: toolchain: 1.95.0 components: clippy - name: Rust cache uses: Swatinem/rust-cache@49a0bdc70d2e1b713ca9e2869b211fcce03d3c1c # v2 with: # Gateway lint 与 Gateway 测试都可能触发 mold/大型链接依赖,单独隔离缓存 # 指纹,避免不同 job 的构建产物互相驱逐或复用错误的链接参数。 shared-key: rust-ci-gateway-clippy-${{ runner.os }} workspaces: . -> target - name: Setup sccache uses: mozilla-actions/sccache-action@7d986dd989559c6ecdb630a3fd2557667be217ad # v0.0.9 - name: Clippy env: RUSTC_WRAPPER: sccache SCCACHE_GHA_ENABLED: "true" run: cargo clippy -p aether-gateway --lib --bins --examples -- -D warnings - name: Show sccache stats if: always() env: RUSTC_WRAPPER: sccache SCCACHE_GHA_ENABLED: "true" run: sccache --show-stats clippy_data: name: Clippy (Data) needs: changes if: ${{ needs.changes.outputs.rust == 'true' }} runs-on: ubuntu-latest steps: - uses: actions/checkout@fbc6f3992d24b796d5a048ff273f7fcc4a7b6c09 # v5 - name: Install Rust toolchain uses: dtolnay/rust-toolchain@4360b52568e2003a75bf9bc1d59f33a8e3fc893c # stable with: toolchain: 1.95.0 components: clippy - name: Rust cache uses: Swatinem/rust-cache@49a0bdc70d2e1b713ca9e2869b211fcce03d3c1c # v2 with: shared-key: rust-ci-${{ runner.os }} workspaces: . -> target - name: Setup sccache uses: mozilla-actions/sccache-action@7d986dd989559c6ecdb630a3fd2557667be217ad # v0.0.9 - name: Clippy env: RUSTC_WRAPPER: sccache SCCACHE_GHA_ENABLED: "true" run: cargo clippy -p aether-data --all-targets -- -D warnings - name: Show sccache stats if: always() env: RUSTC_WRAPPER: sccache SCCACHE_GHA_ENABLED: "true" run: sccache --show-stats clippy_rest: name: Clippy (Workspace Rest) needs: changes if: ${{ needs.changes.outputs.rust == 'true' }} runs-on: ubuntu-latest steps: - uses: actions/checkout@fbc6f3992d24b796d5a048ff273f7fcc4a7b6c09 # v5 - name: Install Rust toolchain uses: dtolnay/rust-toolchain@4360b52568e2003a75bf9bc1d59f33a8e3fc893c # stable with: toolchain: 1.95.0 components: clippy - name: Rust cache uses: Swatinem/rust-cache@49a0bdc70d2e1b713ca9e2869b211fcce03d3c1c # v2 with: shared-key: rust-ci-${{ runner.os }} workspaces: . -> target - name: Setup sccache uses: mozilla-actions/sccache-action@7d986dd989559c6ecdb630a3fd2557667be217ad # v0.0.9 - name: Clippy env: RUSTC_WRAPPER: sccache SCCACHE_GHA_ENABLED: "true" run: cargo clippy --workspace --exclude aether-gateway --exclude aether-data --exclude aether-integration-tests --all-targets -- -D warnings - name: Show sccache stats if: always() env: RUSTC_WRAPPER: sccache SCCACHE_GHA_ENABLED: "true" run: sccache --show-stats clippy: name: Clippy runs-on: ubuntu-latest needs: - changes - clippy_gateway - clippy_data - clippy_rest if: ${{ always() }} steps: - name: Verify clippy jobs run: | if [ "${{ needs.changes.outputs.rust }}" != "true" ]; then echo "Rust scope unchanged; clippy jobs skipped" exit 0 fi if [ "${{ needs.clippy_gateway.result }}" != "success" ] || \ [ "${{ needs.clippy_data.result }}" != "success" ] || \ [ "${{ needs.clippy_rest.result }}" != "success" ]; then echo "Clippy failed" exit 1 fi test_gateway: name: Test (Gateway) needs: changes if: ${{ needs.changes.outputs.rust == 'true' }} runs-on: ubuntu-latest # 构建指纹提到 job 级:mold RUSTFLAGS / 栈 / sccache 对 lib、bins、integration 三步保持一致, # 避免 step 级 env 漂移导致同 job 内 rustc 指纹不一致。 env: RUSTC_WRAPPER: sccache SCCACHE_GHA_ENABLED: "true" RUST_MIN_STACK: "16777216" RUSTFLAGS: "-C link-arg=-fuse-ld=mold" steps: - uses: actions/checkout@fbc6f3992d24b796d5a048ff273f7fcc4a7b6c09 # v5 - name: Install Rust toolchain uses: dtolnay/rust-toolchain@4360b52568e2003a75bf9bc1d59f33a8e3fc893c # stable with: # 与 rust-toolchain.toml、fmt/clippy 钉在同一版本,避免浮动 stable 换指纹导致全量重编 toolchain: 1.95.0 - name: Show Rust toolchain run: rustup show active-toolchain - name: Rust cache uses: Swatinem/rust-cache@49a0bdc70d2e1b713ca9e2869b211fcce03d3c1c # v2 with: # mold RUSTFLAGS 只在本 job 生效:独立 cache key,避免与无 mold 的 job 互相污染指纹 shared-key: rust-ci-gateway-test-${{ runner.os }} workspaces: . -> target - name: Setup sccache uses: mozilla-actions/sccache-action@7d986dd989559c6ecdb630a3fd2557667be217ad # v0.0.9 - name: Setup mold uses: rui314/setup-mold@7e4f20ad28a2e8ca6fd0892ccf72e2abb706b9c3 # v1 - name: Install nextest uses: taiki-e/install-action@d5f9268ff7620505a81ada10ddf18cdd72240185 # nextest - name: Expose PostgreSQL test binaries run: pg_config --bindir >> "$GITHUB_PATH" - name: Test lib run: cargo nextest run -p aether-gateway --lib - name: Test bins run: cargo nextest run -p aether-gateway --bins # 只运行独立 integration targets;显式列出目标,避免 --tests 再次执行 lib/bin 测试。 - name: Test integration targets run: >- cargo nextest run -p aether-gateway --test admin_unsigned_identity_headers --test architecture_guard - name: Show sccache stats if: always() run: sccache --show-stats test_data: name: Test (Data) needs: changes if: ${{ needs.changes.outputs.rust == 'true' }} runs-on: ubuntu-latest steps: - uses: actions/checkout@fbc6f3992d24b796d5a048ff273f7fcc4a7b6c09 # v5 - name: Install Rust toolchain uses: dtolnay/rust-toolchain@4360b52568e2003a75bf9bc1d59f33a8e3fc893c # stable with: toolchain: 1.95.0 - name: Show Rust toolchain run: rustup show active-toolchain - name: Rust cache uses: Swatinem/rust-cache@49a0bdc70d2e1b713ca9e2869b211fcce03d3c1c # v2 with: shared-key: rust-ci-${{ runner.os }} workspaces: . -> target - name: Setup sccache uses: mozilla-actions/sccache-action@7d986dd989559c6ecdb630a3fd2557667be217ad # v0.0.9 - name: Install nextest uses: taiki-e/install-action@d5f9268ff7620505a81ada10ddf18cdd72240185 # nextest - name: Expose PostgreSQL test binaries run: pg_config --bindir >> "$GITHUB_PATH" - name: Test env: RUSTC_WRAPPER: sccache SCCACHE_GHA_ENABLED: "true" AETHER_REQUIRE_LOCAL_POSTGRES_TESTS: "true" run: cargo nextest run -p aether-data - name: Show sccache stats if: always() env: RUSTC_WRAPPER: sccache SCCACHE_GHA_ENABLED: "true" run: sccache --show-stats check_data_features: name: Check (Data Feature - ${{ matrix.feature }}) needs: changes if: ${{ needs.changes.outputs.rust == 'true' }} runs-on: ubuntu-latest strategy: fail-fast: false matrix: feature: - postgres - all-drivers steps: - uses: actions/checkout@fbc6f3992d24b796d5a048ff273f7fcc4a7b6c09 # v5 - name: Install Rust toolchain uses: dtolnay/rust-toolchain@4360b52568e2003a75bf9bc1d59f33a8e3fc893c # stable with: toolchain: 1.95.0 - name: Rust cache uses: Swatinem/rust-cache@49a0bdc70d2e1b713ca9e2869b211fcce03d3c1c # v2 with: shared-key: rust-ci-${{ runner.os }} workspaces: . -> target - name: Setup sccache uses: mozilla-actions/sccache-action@7d986dd989559c6ecdb630a3fd2557667be217ad # v0.0.9 - name: Check selected data driver env: RUSTC_WRAPPER: sccache SCCACHE_GHA_ENABLED: "true" run: cargo check -p aether-data --no-default-features --features ${{ matrix.feature }} - name: Show sccache stats if: always() env: RUSTC_WRAPPER: sccache SCCACHE_GHA_ENABLED: "true" run: sccache --show-stats test_rest: name: Test (Workspace Rest) needs: changes if: ${{ needs.changes.outputs.rust == 'true' }} runs-on: ubuntu-latest steps: - uses: actions/checkout@fbc6f3992d24b796d5a048ff273f7fcc4a7b6c09 # v5 - name: Install Rust toolchain uses: dtolnay/rust-toolchain@4360b52568e2003a75bf9bc1d59f33a8e3fc893c # stable with: toolchain: 1.95.0 - name: Show Rust toolchain run: rustup show active-toolchain - name: Rust cache uses: Swatinem/rust-cache@49a0bdc70d2e1b713ca9e2869b211fcce03d3c1c # v2 with: shared-key: rust-ci-${{ runner.os }} workspaces: . -> target - name: Setup sccache uses: mozilla-actions/sccache-action@7d986dd989559c6ecdb630a3fd2557667be217ad # v0.0.9 - name: Install nextest uses: taiki-e/install-action@d5f9268ff7620505a81ada10ddf18cdd72240185 # nextest - name: Test env: RUSTC_WRAPPER: sccache SCCACHE_GHA_ENABLED: "true" run: cargo nextest run --workspace --exclude aether-gateway --exclude aether-data --exclude aether-integration-tests - name: Show sccache stats if: always() env: RUSTC_WRAPPER: sccache SCCACHE_GHA_ENABLED: "true" run: sccache --show-stats test_data_adapters: name: Test (Data Adapter - ${{ matrix.package }}) needs: changes if: ${{ needs.changes.outputs.rust == 'true' }} runs-on: ubuntu-latest strategy: fail-fast: false matrix: package: - aether-data-postgres steps: - uses: actions/checkout@fbc6f3992d24b796d5a048ff273f7fcc4a7b6c09 # v5 - name: Install Rust toolchain uses: dtolnay/rust-toolchain@4360b52568e2003a75bf9bc1d59f33a8e3fc893c # stable with: toolchain: 1.95.0 - name: Rust cache uses: Swatinem/rust-cache@49a0bdc70d2e1b713ca9e2869b211fcce03d3c1c # v2 with: shared-key: rust-ci-${{ runner.os }} workspaces: . -> target - name: Setup sccache uses: mozilla-actions/sccache-action@7d986dd989559c6ecdb630a3fd2557667be217ad # v0.0.9 - name: Install nextest uses: taiki-e/install-action@d5f9268ff7620505a81ada10ddf18cdd72240185 # nextest - name: Test adapter env: RUSTC_WRAPPER: sccache SCCACHE_GHA_ENABLED: "true" run: cargo nextest run -p ${{ matrix.package }} - name: Show sccache stats if: always() env: RUSTC_WRAPPER: sccache SCCACHE_GHA_ENABLED: "true" run: sccache --show-stats check_integration_scenarios: name: Test (Integration Scenarios) needs: changes if: ${{ needs.changes.outputs.rust == 'true' }} runs-on: ubuntu-latest steps: - uses: actions/checkout@fbc6f3992d24b796d5a048ff273f7fcc4a7b6c09 # v5 - name: Install Rust toolchain uses: dtolnay/rust-toolchain@4360b52568e2003a75bf9bc1d59f33a8e3fc893c # stable with: toolchain: 1.95.0 - name: Rust cache uses: Swatinem/rust-cache@49a0bdc70d2e1b713ca9e2869b211fcce03d3c1c # v2 with: shared-key: rust-ci-${{ runner.os }} workspaces: . -> target - name: Setup sccache uses: mozilla-actions/sccache-action@7d986dd989559c6ecdb630a3fd2557667be217ad # v0.0.9 - name: Expose PostgreSQL test binaries run: pg_config --bindir >> "$GITHUB_PATH" - name: Test scenario binaries and end-to-end suites env: RUSTC_WRAPPER: sccache SCCACHE_GHA_ENABLED: "true" run: cargo test -p aether-integration-tests --bins --tests - name: Show sccache stats if: always() env: RUSTC_WRAPPER: sccache SCCACHE_GHA_ENABLED: "true" run: sccache --show-stats test: name: Test runs-on: ubuntu-latest needs: - changes - test_gateway - test_data - check_data_features - test_rest - test_data_adapters - check_integration_scenarios if: ${{ always() }} steps: - name: Verify test jobs run: | if [ "${{ needs.changes.outputs.rust }}" != "true" ]; then echo "Rust scope unchanged; test jobs skipped" exit 0 fi if [ "${{ needs.test_gateway.result }}" != "success" ] || \ [ "${{ needs.test_data.result }}" != "success" ] || \ [ "${{ needs.check_data_features.result }}" != "success" ] || \ [ "${{ needs.test_rest.result }}" != "success" ] || \ [ "${{ needs.test_data_adapters.result }}" != "success" ] || \ [ "${{ needs.check_integration_scenarios.result }}" != "success" ]; then echo "Tests failed" exit 1 fi data_db_smoke_postgres: name: Data DB Smoke (Postgres) needs: changes if: ${{ needs.changes.outputs.rust == 'true' }} runs-on: ubuntu-latest services: postgres: image: postgres:16 env: POSTGRES_DB: aether_test POSTGRES_USER: aether POSTGRES_PASSWORD: aether ports: - 5432:5432 options: >- --health-cmd="pg_isready -h 127.0.0.1 -U aether -d aether_test" --health-interval=5s --health-timeout=5s --health-retries=20 steps: - uses: actions/checkout@fbc6f3992d24b796d5a048ff273f7fcc4a7b6c09 # v5 - name: Install Rust toolchain uses: dtolnay/rust-toolchain@4360b52568e2003a75bf9bc1d59f33a8e3fc893c # stable with: toolchain: 1.95.0 - name: Show Rust toolchain run: rustup show active-toolchain - name: Rust cache uses: Swatinem/rust-cache@49a0bdc70d2e1b713ca9e2869b211fcce03d3c1c # v2 with: shared-key: rust-ci-${{ runner.os }} workspaces: . -> target - name: Setup sccache uses: mozilla-actions/sccache-action@7d986dd989559c6ecdb630a3fd2557667be217ad # v0.0.9 - name: Add PostgreSQL server binaries to PATH run: echo "$(pg_config --bindir)" >> "$GITHUB_PATH" - name: Run Postgres migration smoke test env: RUSTC_WRAPPER: sccache SCCACHE_GHA_ENABLED: "true" AETHER_TEST_POSTGRES_URL: postgres://aether:aether@127.0.0.1:5432/aether_test run: cargo test -p aether-data --all-features postgres_migrations_create_core_config_tables_when_url_is_set --lib -- --nocapture - name: Run Postgres provider metadata migration smoke test env: RUSTC_WRAPPER: sccache SCCACHE_GHA_ENABLED: "true" AETHER_TEST_POSTGRES_URL: postgres://aether:aether@127.0.0.1:5432/aether_test run: cargo test -p aether-data --all-features postgres_provider_upstream_metadata_migration_preserves_json_when_url_is_set --lib -- --nocapture - name: Run Postgres payment callback regression tests env: RUSTC_WRAPPER: sccache SCCACHE_GHA_ENABLED: "true" AETHER_TEST_DATABASE_URL: postgres://aether:aether@127.0.0.1:5432/aether_test run: cargo test -p aether-data-postgres live_payment_callback --lib -- --ignored --nocapture - name: Run Postgres API key lifecycle tests env: RUSTC_WRAPPER: sccache SCCACHE_GHA_ENABLED: "true" AETHER_REQUIRE_LOCAL_POSTGRES_TESTS: "true" run: | cargo test -p aether-data --all-features lifecycle::migrate::tests::postgres_request_candidates_preserve_deleted_api_key_identity --lib -- --exact --nocapture cargo test -p aether-data --all-features lifecycle::migrate::tests::postgres_request_candidate_migration_decouples_legacy_api_key_foreign_key --lib -- --exact --nocapture cargo test -p aether-data --all-features lifecycle::migrate::tests::postgres_stats_daily_api_key_migration_decouples_legacy_foreign_key --lib -- --exact --nocapture cargo test -p aether-data --all-features lifecycle::migrate::tests::postgres_expired_api_key_cleanup_preserves_historical_identity --lib -- --exact --nocapture cargo test -p aether-data --all-features lifecycle::migrate::tests::postgres_api_key_leaderboard_user_filter_preserves_aggregate_history --lib -- --exact --nocapture - name: Run Postgres core export smoke test env: RUSTC_WRAPPER: sccache SCCACHE_GHA_ENABLED: "true" AETHER_TEST_POSTGRES_URL: postgres://aether:aether@127.0.0.1:5432/aether_test run: cargo test -p aether-data --all-features postgres_core_export_reads_migrated_database_rows_when_url_is_set --lib -- --nocapture - name: Show sccache stats if: always() env: RUSTC_WRAPPER: sccache SCCACHE_GHA_ENABLED: "true" run: sccache --show-stats data_db_smoke: name: Data DB Smoke runs-on: ubuntu-latest needs: - changes - data_db_smoke_postgres if: ${{ always() }} steps: - name: Verify database smoke jobs run: | if [ "${{ needs.changes.outputs.rust }}" != "true" ]; then echo "Rust scope unchanged; database smoke jobs skipped" exit 0 fi if [ "${{ needs.data_db_smoke_postgres.result }}" != "success" ]; then echo "Data DB smoke failed" exit 1 fi check: name: check runs-on: ubuntu-latest needs: - changes - fmt - clippy - test - data_db_smoke - shell_security if: ${{ always() }} steps: - name: Verify required jobs run: | rust="${{ needs.changes.outputs.rust }}" shell="${{ needs.changes.outputs.shell }}" if [ "$rust" != "true" ] && [ "$shell" != "true" ]; then echo "No Rust or shell scope changed" exit 0 fi if [ "$rust" = "true" ] && { [ "${{ needs.fmt.result }}" != "success" ] || [ "${{ needs.clippy.result }}" != "success" ] || [ "${{ needs.test.result }}" != "success" ] || [ "${{ needs.data_db_smoke.result }}" != "success" ]; }; then echo "Rust CI failed" exit 1 fi if [ "$shell" = "true" ] && [ "${{ needs.shell_security.result }}" != "success" ]; then echo "Rust CI failed" exit 1 fi