mirror of
https://github.com/fawney19/Aether.git
synced 2026-10-04 00:17:45 +08:00
- changes 脚本加 set -euo pipefail,git fetch/diff 失败即中止,避免写出 rust=false/shell=false 让下游误判为“无需测试”。 - changed_paths 为空(异常事件)时保守置 rust=true/shell=true,宁可多跑不漏测。 - check 与 data_db_smoke 增加 needs.changes.result 兜底。 - 恢复 push/pull_request 的 paths 白名单,并补齐 rust-toolchain.toml、 .cargo/**、*.sql,workflow 触发规则与分类脚本对齐,避免“分类正确但 workflow 未启动”的漏测。 - nextest 删除硬编码 test-threads,改用默认 num-cpus,避免在大规格 runner 上主动压低并发;保留 slow-timeout 卡死保护。 - 补真实 TCP smoke test,覆盖管理员安全接口的监听端口与 HTTP/JSON 链路。
775 lines
26 KiB
YAML
775 lines
26 KiB
YAML
name: Rust CI
|
|
|
|
on:
|
|
workflow_call:
|
|
inputs:
|
|
full_scope:
|
|
description: "Run all Rust and shell scopes, used by Nightly"
|
|
required: false
|
|
type: boolean
|
|
default: false
|
|
push:
|
|
branches:
|
|
- master
|
|
- main
|
|
paths:
|
|
- "Cargo.toml"
|
|
- "Cargo.lock"
|
|
- "rust-toolchain.toml"
|
|
- ".cargo/**"
|
|
- "crates/**"
|
|
- "apps/**"
|
|
- "*.sql"
|
|
- "install.sh"
|
|
- "deploy.sh"
|
|
- "update.sh"
|
|
- "generate_keys.sh"
|
|
- ".env.example"
|
|
- "README.md"
|
|
- "Dockerfile.app"
|
|
- "docker-compose.yml"
|
|
- "docker-compose.single-node.yml"
|
|
- "docker-compose.local.yml"
|
|
- "docker-compose.release-local.yml"
|
|
- "tests/compose_database_config_test.py"
|
|
- "tests/install_*_test.sh"
|
|
- "tests/deploy_*_test.sh"
|
|
- "tests/update_*_test.sh"
|
|
- "tests/release_supply_chain_test.sh"
|
|
- "tests/tunnel_installer_config_security_test.sh"
|
|
- ".github/workflows/*.yml"
|
|
- ".github/workflows/*.yaml"
|
|
pull_request:
|
|
paths:
|
|
- "Cargo.toml"
|
|
- "Cargo.lock"
|
|
- "rust-toolchain.toml"
|
|
- ".cargo/**"
|
|
- "crates/**"
|
|
- "apps/**"
|
|
- "*.sql"
|
|
- "install.sh"
|
|
- "deploy.sh"
|
|
- "update.sh"
|
|
- "generate_keys.sh"
|
|
- ".env.example"
|
|
- "README.md"
|
|
- "Dockerfile.app"
|
|
- "docker-compose.yml"
|
|
- "docker-compose.single-node.yml"
|
|
- "docker-compose.local.yml"
|
|
- "docker-compose.release-local.yml"
|
|
- "tests/compose_database_config_test.py"
|
|
- "tests/install_*_test.sh"
|
|
- "tests/deploy_*_test.sh"
|
|
- "tests/update_*_test.sh"
|
|
- "tests/release_supply_chain_test.sh"
|
|
- "tests/tunnel_installer_config_security_test.sh"
|
|
- ".github/workflows/*.yml"
|
|
- ".github/workflows/*.yaml"
|
|
|
|
concurrency:
|
|
group: rust-ci-${{ github.event_name }}-${{ github.workflow }}-${{ github.event.pull_request.number || github.ref }}
|
|
cancel-in-progress: true
|
|
|
|
permissions:
|
|
contents: read
|
|
|
|
env:
|
|
CARGO_INCREMENTAL: 0
|
|
CARGO_PROFILE_DEV_DEBUG: 0
|
|
CARGO_PROFILE_TEST_DEBUG: 0
|
|
CARGO_TERM_COLOR: always
|
|
|
|
jobs:
|
|
changes:
|
|
name: Detect Rust CI scope
|
|
runs-on: ubuntu-latest
|
|
outputs:
|
|
rust: ${{ steps.scope.outputs.rust }}
|
|
shell: ${{ steps.scope.outputs.shell }}
|
|
steps:
|
|
- uses: actions/checkout@fbc6f3992d24b796d5a048ff273f7fcc4a7b6c09 # v5
|
|
with:
|
|
fetch-depth: 0
|
|
|
|
- name: Classify changed paths
|
|
id: scope
|
|
shell: bash
|
|
env:
|
|
RUST_CI_FULL_SCOPE: ${{ inputs.full_scope || false }}
|
|
run: |
|
|
# 任何命令失败都必须让本 job 失败,否则 git fetch/diff 出错后仍会写出
|
|
# rust=false/shell=false,下游会误判为“无需测试”而假绿放行。
|
|
set -euo pipefail
|
|
|
|
# Nightly 通过 workflow_call 显式传入 full_scope;普通 push/PR 只按源码和构建
|
|
# 指纹触发 Rust jobs,安装脚本、Compose、README 等由 shell scope 覆盖。
|
|
if [ "$RUST_CI_FULL_SCOPE" = "true" ]; then
|
|
echo "rust=true" >> "$GITHUB_OUTPUT"
|
|
echo "shell=true" >> "$GITHUB_OUTPUT"
|
|
exit 0
|
|
fi
|
|
|
|
if [ "$GITHUB_EVENT_NAME" = "pull_request" ] \
|
|
&& [ -n "${GITHUB_BASE_REF:-}" ] \
|
|
&& [ -n "${GITHUB_SHA:-}" ]; then
|
|
git fetch --no-tags origin "$GITHUB_BASE_REF" --depth=1
|
|
changed_paths=$(git diff --name-only "origin/$GITHUB_BASE_REF...$GITHUB_SHA")
|
|
elif [ "$GITHUB_EVENT_NAME" = "push" ] \
|
|
&& [ -n "${GITHUB_EVENT_BEFORE:-}" ] \
|
|
&& [ "$GITHUB_EVENT_BEFORE" != "0000000000000000000000000000000000000000" ] \
|
|
&& [ -n "${GITHUB_SHA:-}" ]; then
|
|
changed_paths=$(git diff --name-only "$GITHUB_EVENT_BEFORE" "$GITHUB_SHA")
|
|
else
|
|
changed_paths=$(git ls-files)
|
|
fi
|
|
|
|
# 防御性兜底:diff 结果为空(异常事件或比较失败)时按全量运行,
|
|
# 宁可多跑也不能漏测。
|
|
if [ -z "$changed_paths" ]; then
|
|
echo "rust=true" >> "$GITHUB_OUTPUT"
|
|
echo "shell=true" >> "$GITHUB_OUTPUT"
|
|
exit 0
|
|
fi
|
|
|
|
rust=false
|
|
shell=false
|
|
while IFS= read -r path; do
|
|
case "$path" in
|
|
Cargo.toml|Cargo.lock|rust-toolchain.toml|.cargo/*|*.rs|*/Cargo.toml|*/build.rs|*.sql|.github/workflows/*.yml|.github/workflows/*.yaml)
|
|
rust=true
|
|
;;
|
|
*.sh|*.py|README.md|*/README.md|.env.example|Dockerfile*|docker-compose*.yml|docker-compose*.yaml)
|
|
shell=true
|
|
;;
|
|
esac
|
|
done <<< "$changed_paths"
|
|
|
|
echo "rust=$rust" >> "$GITHUB_OUTPUT"
|
|
echo "shell=$shell" >> "$GITHUB_OUTPUT"
|
|
|
|
shell_security:
|
|
name: Shell security fixtures
|
|
needs: changes
|
|
if: ${{ needs.changes.outputs.shell == 'true' }}
|
|
runs-on: ubuntu-latest
|
|
steps:
|
|
- uses: actions/checkout@fbc6f3992d24b796d5a048ff273f7fcc4a7b6c09 # v5
|
|
|
|
- name: Run installer and supply-chain fixtures
|
|
shell: bash
|
|
run: |
|
|
python3 tests/compose_database_config_test.py
|
|
bash tests/deploy_state_safety_test.sh
|
|
bash tests/install_archive_safety_test.sh
|
|
bash tests/install_container_runtime_security_test.sh
|
|
bash tests/install_current_release_link_test.sh
|
|
bash tests/install_local_bundle_safety_test.sh
|
|
bash tests/install_privileged_write_safety_test.sh
|
|
bash tests/install_source_trust_test.sh
|
|
bash tests/release_supply_chain_test.sh
|
|
bash tests/update_compose_safety_test.sh
|
|
bash tests/tunnel_installer_config_security_test.sh
|
|
|
|
fmt:
|
|
name: Format
|
|
needs: changes
|
|
if: ${{ needs.changes.outputs.rust == 'true' }}
|
|
runs-on: ubuntu-latest
|
|
steps:
|
|
- uses: actions/checkout@fbc6f3992d24b796d5a048ff273f7fcc4a7b6c09 # v5
|
|
|
|
- name: Install Rust toolchain
|
|
uses: dtolnay/rust-toolchain@4360b52568e2003a75bf9bc1d59f33a8e3fc893c # stable
|
|
with:
|
|
toolchain: 1.95.0
|
|
components: rustfmt
|
|
|
|
- name: Format
|
|
run: cargo fmt --all --check
|
|
|
|
clippy_gateway:
|
|
name: Clippy (Gateway)
|
|
needs: changes
|
|
if: ${{ needs.changes.outputs.rust == 'true' }}
|
|
runs-on: ubuntu-latest
|
|
steps:
|
|
- uses: actions/checkout@fbc6f3992d24b796d5a048ff273f7fcc4a7b6c09 # v5
|
|
|
|
- name: Install Rust toolchain
|
|
uses: dtolnay/rust-toolchain@4360b52568e2003a75bf9bc1d59f33a8e3fc893c # stable
|
|
with:
|
|
toolchain: 1.95.0
|
|
components: clippy
|
|
|
|
- name: Rust cache
|
|
uses: Swatinem/rust-cache@49a0bdc70d2e1b713ca9e2869b211fcce03d3c1c # v2
|
|
with:
|
|
# Gateway lint 与 Gateway 测试都可能触发 mold/大型链接依赖,单独隔离缓存
|
|
# 指纹,避免不同 job 的构建产物互相驱逐或复用错误的链接参数。
|
|
shared-key: rust-ci-gateway-clippy-${{ runner.os }}
|
|
workspaces: . -> target
|
|
|
|
- name: Setup sccache
|
|
uses: mozilla-actions/sccache-action@7d986dd989559c6ecdb630a3fd2557667be217ad # v0.0.9
|
|
|
|
- name: Clippy
|
|
env:
|
|
RUSTC_WRAPPER: sccache
|
|
SCCACHE_GHA_ENABLED: "true"
|
|
run: cargo clippy -p aether-gateway --lib --bins --examples -- -D warnings
|
|
|
|
- name: Show sccache stats
|
|
if: always()
|
|
env:
|
|
RUSTC_WRAPPER: sccache
|
|
SCCACHE_GHA_ENABLED: "true"
|
|
run: sccache --show-stats
|
|
|
|
clippy_data:
|
|
name: Clippy (Data)
|
|
needs: changes
|
|
if: ${{ needs.changes.outputs.rust == 'true' }}
|
|
runs-on: ubuntu-latest
|
|
steps:
|
|
- uses: actions/checkout@fbc6f3992d24b796d5a048ff273f7fcc4a7b6c09 # v5
|
|
|
|
- name: Install Rust toolchain
|
|
uses: dtolnay/rust-toolchain@4360b52568e2003a75bf9bc1d59f33a8e3fc893c # stable
|
|
with:
|
|
toolchain: 1.95.0
|
|
components: clippy
|
|
|
|
- name: Rust cache
|
|
uses: Swatinem/rust-cache@49a0bdc70d2e1b713ca9e2869b211fcce03d3c1c # v2
|
|
with:
|
|
shared-key: rust-ci-${{ runner.os }}
|
|
workspaces: . -> target
|
|
|
|
- name: Setup sccache
|
|
uses: mozilla-actions/sccache-action@7d986dd989559c6ecdb630a3fd2557667be217ad # v0.0.9
|
|
|
|
- name: Clippy
|
|
env:
|
|
RUSTC_WRAPPER: sccache
|
|
SCCACHE_GHA_ENABLED: "true"
|
|
run: cargo clippy -p aether-data --all-targets -- -D warnings
|
|
|
|
- name: Show sccache stats
|
|
if: always()
|
|
env:
|
|
RUSTC_WRAPPER: sccache
|
|
SCCACHE_GHA_ENABLED: "true"
|
|
run: sccache --show-stats
|
|
|
|
clippy_rest:
|
|
name: Clippy (Workspace Rest)
|
|
needs: changes
|
|
if: ${{ needs.changes.outputs.rust == 'true' }}
|
|
runs-on: ubuntu-latest
|
|
steps:
|
|
- uses: actions/checkout@fbc6f3992d24b796d5a048ff273f7fcc4a7b6c09 # v5
|
|
|
|
- name: Install Rust toolchain
|
|
uses: dtolnay/rust-toolchain@4360b52568e2003a75bf9bc1d59f33a8e3fc893c # stable
|
|
with:
|
|
toolchain: 1.95.0
|
|
components: clippy
|
|
|
|
- name: Rust cache
|
|
uses: Swatinem/rust-cache@49a0bdc70d2e1b713ca9e2869b211fcce03d3c1c # v2
|
|
with:
|
|
shared-key: rust-ci-${{ runner.os }}
|
|
workspaces: . -> target
|
|
|
|
- name: Setup sccache
|
|
uses: mozilla-actions/sccache-action@7d986dd989559c6ecdb630a3fd2557667be217ad # v0.0.9
|
|
|
|
- name: Clippy
|
|
env:
|
|
RUSTC_WRAPPER: sccache
|
|
SCCACHE_GHA_ENABLED: "true"
|
|
run: cargo clippy --workspace --exclude aether-gateway --exclude aether-data --exclude aether-integration-tests --all-targets -- -D warnings
|
|
|
|
- name: Show sccache stats
|
|
if: always()
|
|
env:
|
|
RUSTC_WRAPPER: sccache
|
|
SCCACHE_GHA_ENABLED: "true"
|
|
run: sccache --show-stats
|
|
|
|
clippy:
|
|
name: Clippy
|
|
runs-on: ubuntu-latest
|
|
needs:
|
|
- changes
|
|
- clippy_gateway
|
|
- clippy_data
|
|
- clippy_rest
|
|
if: ${{ always() }}
|
|
steps:
|
|
- name: Verify clippy jobs
|
|
run: |
|
|
if [ "${{ needs.changes.outputs.rust }}" != "true" ]; then
|
|
echo "Rust scope unchanged; clippy jobs skipped"
|
|
exit 0
|
|
fi
|
|
if [ "${{ needs.clippy_gateway.result }}" != "success" ] || \
|
|
[ "${{ needs.clippy_data.result }}" != "success" ] || \
|
|
[ "${{ needs.clippy_rest.result }}" != "success" ]; then
|
|
echo "Clippy failed"
|
|
exit 1
|
|
fi
|
|
|
|
test_gateway:
|
|
name: Test (Gateway)
|
|
needs: changes
|
|
if: ${{ needs.changes.outputs.rust == 'true' }}
|
|
runs-on: ubuntu-latest
|
|
# 构建指纹提到 job 级:mold RUSTFLAGS / 栈 / sccache 对 lib、bins、integration 三步保持一致,
|
|
# 避免 step 级 env 漂移导致同 job 内 rustc 指纹不一致。
|
|
env:
|
|
RUSTC_WRAPPER: sccache
|
|
SCCACHE_GHA_ENABLED: "true"
|
|
RUST_MIN_STACK: "16777216"
|
|
RUSTFLAGS: "-C link-arg=-fuse-ld=mold"
|
|
steps:
|
|
- uses: actions/checkout@fbc6f3992d24b796d5a048ff273f7fcc4a7b6c09 # v5
|
|
|
|
- name: Install Rust toolchain
|
|
uses: dtolnay/rust-toolchain@4360b52568e2003a75bf9bc1d59f33a8e3fc893c # stable
|
|
with:
|
|
# 与 rust-toolchain.toml、fmt/clippy 钉在同一版本,避免浮动 stable 换指纹导致全量重编
|
|
toolchain: 1.95.0
|
|
|
|
- name: Show Rust toolchain
|
|
run: rustup show active-toolchain
|
|
|
|
- name: Rust cache
|
|
uses: Swatinem/rust-cache@49a0bdc70d2e1b713ca9e2869b211fcce03d3c1c # v2
|
|
with:
|
|
# mold RUSTFLAGS 只在本 job 生效:独立 cache key,避免与无 mold 的 job 互相污染指纹
|
|
shared-key: rust-ci-gateway-test-${{ runner.os }}
|
|
workspaces: . -> target
|
|
|
|
- name: Setup sccache
|
|
uses: mozilla-actions/sccache-action@7d986dd989559c6ecdb630a3fd2557667be217ad # v0.0.9
|
|
|
|
- name: Setup mold
|
|
uses: rui314/setup-mold@7e4f20ad28a2e8ca6fd0892ccf72e2abb706b9c3 # v1
|
|
|
|
- name: Install nextest
|
|
uses: taiki-e/install-action@d5f9268ff7620505a81ada10ddf18cdd72240185 # nextest
|
|
|
|
- name: Expose PostgreSQL test binaries
|
|
run: pg_config --bindir >> "$GITHUB_PATH"
|
|
|
|
- name: Test lib
|
|
run: cargo nextest run -p aether-gateway --lib
|
|
|
|
- name: Test bins
|
|
run: cargo nextest run -p aether-gateway --bins
|
|
|
|
# 只运行独立 integration targets;显式列出目标,避免 --tests 再次执行 lib/bin 测试。
|
|
- name: Test integration targets
|
|
run: >-
|
|
cargo nextest run -p aether-gateway
|
|
--test admin_unsigned_identity_headers
|
|
--test architecture_guard
|
|
|
|
- name: Show sccache stats
|
|
if: always()
|
|
run: sccache --show-stats
|
|
|
|
test_data:
|
|
name: Test (Data)
|
|
needs: changes
|
|
if: ${{ needs.changes.outputs.rust == 'true' }}
|
|
runs-on: ubuntu-latest
|
|
steps:
|
|
- uses: actions/checkout@fbc6f3992d24b796d5a048ff273f7fcc4a7b6c09 # v5
|
|
|
|
- name: Install Rust toolchain
|
|
uses: dtolnay/rust-toolchain@4360b52568e2003a75bf9bc1d59f33a8e3fc893c # stable
|
|
with:
|
|
toolchain: 1.95.0
|
|
|
|
- name: Show Rust toolchain
|
|
run: rustup show active-toolchain
|
|
|
|
- name: Rust cache
|
|
uses: Swatinem/rust-cache@49a0bdc70d2e1b713ca9e2869b211fcce03d3c1c # v2
|
|
with:
|
|
shared-key: rust-ci-${{ runner.os }}
|
|
workspaces: . -> target
|
|
|
|
- name: Setup sccache
|
|
uses: mozilla-actions/sccache-action@7d986dd989559c6ecdb630a3fd2557667be217ad # v0.0.9
|
|
|
|
- name: Install nextest
|
|
uses: taiki-e/install-action@d5f9268ff7620505a81ada10ddf18cdd72240185 # nextest
|
|
|
|
- name: Expose PostgreSQL test binaries
|
|
run: pg_config --bindir >> "$GITHUB_PATH"
|
|
|
|
- name: Test
|
|
env:
|
|
RUSTC_WRAPPER: sccache
|
|
SCCACHE_GHA_ENABLED: "true"
|
|
AETHER_REQUIRE_LOCAL_POSTGRES_TESTS: "true"
|
|
run: cargo nextest run -p aether-data
|
|
|
|
- name: Show sccache stats
|
|
if: always()
|
|
env:
|
|
RUSTC_WRAPPER: sccache
|
|
SCCACHE_GHA_ENABLED: "true"
|
|
run: sccache --show-stats
|
|
|
|
check_data_features:
|
|
name: Check (Data Feature - ${{ matrix.feature }})
|
|
needs: changes
|
|
if: ${{ needs.changes.outputs.rust == 'true' }}
|
|
runs-on: ubuntu-latest
|
|
strategy:
|
|
fail-fast: false
|
|
matrix:
|
|
feature:
|
|
- postgres
|
|
- all-drivers
|
|
steps:
|
|
- uses: actions/checkout@fbc6f3992d24b796d5a048ff273f7fcc4a7b6c09 # v5
|
|
|
|
- name: Install Rust toolchain
|
|
uses: dtolnay/rust-toolchain@4360b52568e2003a75bf9bc1d59f33a8e3fc893c # stable
|
|
with:
|
|
toolchain: 1.95.0
|
|
|
|
- name: Rust cache
|
|
uses: Swatinem/rust-cache@49a0bdc70d2e1b713ca9e2869b211fcce03d3c1c # v2
|
|
with:
|
|
shared-key: rust-ci-${{ runner.os }}
|
|
workspaces: . -> target
|
|
|
|
- name: Setup sccache
|
|
uses: mozilla-actions/sccache-action@7d986dd989559c6ecdb630a3fd2557667be217ad # v0.0.9
|
|
|
|
- name: Check selected data driver
|
|
env:
|
|
RUSTC_WRAPPER: sccache
|
|
SCCACHE_GHA_ENABLED: "true"
|
|
run: cargo check -p aether-data --no-default-features --features ${{ matrix.feature }}
|
|
|
|
- name: Show sccache stats
|
|
if: always()
|
|
env:
|
|
RUSTC_WRAPPER: sccache
|
|
SCCACHE_GHA_ENABLED: "true"
|
|
run: sccache --show-stats
|
|
|
|
test_rest:
|
|
name: Test (Workspace Rest)
|
|
needs: changes
|
|
if: ${{ needs.changes.outputs.rust == 'true' }}
|
|
runs-on: ubuntu-latest
|
|
steps:
|
|
- uses: actions/checkout@fbc6f3992d24b796d5a048ff273f7fcc4a7b6c09 # v5
|
|
|
|
- name: Install Rust toolchain
|
|
uses: dtolnay/rust-toolchain@4360b52568e2003a75bf9bc1d59f33a8e3fc893c # stable
|
|
with:
|
|
toolchain: 1.95.0
|
|
|
|
- name: Show Rust toolchain
|
|
run: rustup show active-toolchain
|
|
|
|
- name: Rust cache
|
|
uses: Swatinem/rust-cache@49a0bdc70d2e1b713ca9e2869b211fcce03d3c1c # v2
|
|
with:
|
|
shared-key: rust-ci-${{ runner.os }}
|
|
workspaces: . -> target
|
|
|
|
- name: Setup sccache
|
|
uses: mozilla-actions/sccache-action@7d986dd989559c6ecdb630a3fd2557667be217ad # v0.0.9
|
|
|
|
- name: Install nextest
|
|
uses: taiki-e/install-action@d5f9268ff7620505a81ada10ddf18cdd72240185 # nextest
|
|
|
|
- name: Test
|
|
env:
|
|
RUSTC_WRAPPER: sccache
|
|
SCCACHE_GHA_ENABLED: "true"
|
|
run: cargo nextest run --workspace --exclude aether-gateway --exclude aether-data --exclude aether-integration-tests
|
|
|
|
- name: Show sccache stats
|
|
if: always()
|
|
env:
|
|
RUSTC_WRAPPER: sccache
|
|
SCCACHE_GHA_ENABLED: "true"
|
|
run: sccache --show-stats
|
|
|
|
test_data_adapters:
|
|
name: Test (Data Adapter - ${{ matrix.package }})
|
|
needs: changes
|
|
if: ${{ needs.changes.outputs.rust == 'true' }}
|
|
runs-on: ubuntu-latest
|
|
strategy:
|
|
fail-fast: false
|
|
matrix:
|
|
package:
|
|
- aether-data-postgres
|
|
steps:
|
|
- uses: actions/checkout@fbc6f3992d24b796d5a048ff273f7fcc4a7b6c09 # v5
|
|
|
|
- name: Install Rust toolchain
|
|
uses: dtolnay/rust-toolchain@4360b52568e2003a75bf9bc1d59f33a8e3fc893c # stable
|
|
with:
|
|
toolchain: 1.95.0
|
|
|
|
- name: Rust cache
|
|
uses: Swatinem/rust-cache@49a0bdc70d2e1b713ca9e2869b211fcce03d3c1c # v2
|
|
with:
|
|
shared-key: rust-ci-${{ runner.os }}
|
|
workspaces: . -> target
|
|
|
|
- name: Setup sccache
|
|
uses: mozilla-actions/sccache-action@7d986dd989559c6ecdb630a3fd2557667be217ad # v0.0.9
|
|
|
|
- name: Install nextest
|
|
uses: taiki-e/install-action@d5f9268ff7620505a81ada10ddf18cdd72240185 # nextest
|
|
|
|
- name: Test adapter
|
|
env:
|
|
RUSTC_WRAPPER: sccache
|
|
SCCACHE_GHA_ENABLED: "true"
|
|
run: cargo nextest run -p ${{ matrix.package }}
|
|
|
|
- name: Show sccache stats
|
|
if: always()
|
|
env:
|
|
RUSTC_WRAPPER: sccache
|
|
SCCACHE_GHA_ENABLED: "true"
|
|
run: sccache --show-stats
|
|
|
|
check_integration_scenarios:
|
|
name: Test (Integration Scenarios)
|
|
needs: changes
|
|
if: ${{ needs.changes.outputs.rust == 'true' }}
|
|
runs-on: ubuntu-latest
|
|
steps:
|
|
- uses: actions/checkout@fbc6f3992d24b796d5a048ff273f7fcc4a7b6c09 # v5
|
|
|
|
- name: Install Rust toolchain
|
|
uses: dtolnay/rust-toolchain@4360b52568e2003a75bf9bc1d59f33a8e3fc893c # stable
|
|
with:
|
|
toolchain: 1.95.0
|
|
|
|
- name: Rust cache
|
|
uses: Swatinem/rust-cache@49a0bdc70d2e1b713ca9e2869b211fcce03d3c1c # v2
|
|
with:
|
|
shared-key: rust-ci-${{ runner.os }}
|
|
workspaces: . -> target
|
|
|
|
- name: Setup sccache
|
|
uses: mozilla-actions/sccache-action@7d986dd989559c6ecdb630a3fd2557667be217ad # v0.0.9
|
|
|
|
- name: Expose PostgreSQL test binaries
|
|
run: pg_config --bindir >> "$GITHUB_PATH"
|
|
|
|
- name: Test scenario binaries and end-to-end suites
|
|
env:
|
|
RUSTC_WRAPPER: sccache
|
|
SCCACHE_GHA_ENABLED: "true"
|
|
run: cargo test -p aether-integration-tests --bins --tests
|
|
|
|
- name: Show sccache stats
|
|
if: always()
|
|
env:
|
|
RUSTC_WRAPPER: sccache
|
|
SCCACHE_GHA_ENABLED: "true"
|
|
run: sccache --show-stats
|
|
|
|
test:
|
|
name: Test
|
|
runs-on: ubuntu-latest
|
|
needs:
|
|
- changes
|
|
- test_gateway
|
|
- test_data
|
|
- check_data_features
|
|
- test_rest
|
|
- test_data_adapters
|
|
- check_integration_scenarios
|
|
if: ${{ always() }}
|
|
steps:
|
|
- name: Verify test jobs
|
|
run: |
|
|
if [ "${{ needs.changes.outputs.rust }}" != "true" ]; then
|
|
echo "Rust scope unchanged; test jobs skipped"
|
|
exit 0
|
|
fi
|
|
if [ "${{ needs.test_gateway.result }}" != "success" ] || \
|
|
[ "${{ needs.test_data.result }}" != "success" ] || \
|
|
[ "${{ needs.check_data_features.result }}" != "success" ] || \
|
|
[ "${{ needs.test_rest.result }}" != "success" ] || \
|
|
[ "${{ needs.test_data_adapters.result }}" != "success" ] || \
|
|
[ "${{ needs.check_integration_scenarios.result }}" != "success" ]; then
|
|
echo "Tests failed"
|
|
exit 1
|
|
fi
|
|
|
|
data_db_smoke_postgres:
|
|
name: Data DB Smoke (Postgres)
|
|
needs: changes
|
|
if: ${{ needs.changes.outputs.rust == 'true' }}
|
|
runs-on: ubuntu-latest
|
|
services:
|
|
postgres:
|
|
image: postgres:16
|
|
env:
|
|
POSTGRES_DB: aether_test
|
|
POSTGRES_USER: aether
|
|
POSTGRES_PASSWORD: aether
|
|
ports:
|
|
- 5432:5432
|
|
options: >-
|
|
--health-cmd="pg_isready -h 127.0.0.1 -U aether -d aether_test"
|
|
--health-interval=5s
|
|
--health-timeout=5s
|
|
--health-retries=20
|
|
steps:
|
|
- uses: actions/checkout@fbc6f3992d24b796d5a048ff273f7fcc4a7b6c09 # v5
|
|
|
|
- name: Install Rust toolchain
|
|
uses: dtolnay/rust-toolchain@4360b52568e2003a75bf9bc1d59f33a8e3fc893c # stable
|
|
with:
|
|
toolchain: 1.95.0
|
|
|
|
- name: Show Rust toolchain
|
|
run: rustup show active-toolchain
|
|
|
|
- name: Rust cache
|
|
uses: Swatinem/rust-cache@49a0bdc70d2e1b713ca9e2869b211fcce03d3c1c # v2
|
|
with:
|
|
shared-key: rust-ci-${{ runner.os }}
|
|
workspaces: . -> target
|
|
|
|
- name: Setup sccache
|
|
uses: mozilla-actions/sccache-action@7d986dd989559c6ecdb630a3fd2557667be217ad # v0.0.9
|
|
|
|
- name: Add PostgreSQL server binaries to PATH
|
|
run: echo "$(pg_config --bindir)" >> "$GITHUB_PATH"
|
|
|
|
- name: Run Postgres migration smoke test
|
|
env:
|
|
RUSTC_WRAPPER: sccache
|
|
SCCACHE_GHA_ENABLED: "true"
|
|
AETHER_TEST_POSTGRES_URL: postgres://aether:[email protected]:5432/aether_test
|
|
run: cargo test -p aether-data --all-features postgres_migrations_create_core_config_tables_when_url_is_set --lib -- --nocapture
|
|
|
|
- name: Run Postgres provider metadata migration smoke test
|
|
env:
|
|
RUSTC_WRAPPER: sccache
|
|
SCCACHE_GHA_ENABLED: "true"
|
|
AETHER_TEST_POSTGRES_URL: postgres://aether:[email protected]:5432/aether_test
|
|
run: cargo test -p aether-data --all-features postgres_provider_upstream_metadata_migration_preserves_json_when_url_is_set --lib -- --nocapture
|
|
|
|
- name: Run Postgres payment callback regression tests
|
|
env:
|
|
RUSTC_WRAPPER: sccache
|
|
SCCACHE_GHA_ENABLED: "true"
|
|
AETHER_TEST_DATABASE_URL: postgres://aether:[email protected]:5432/aether_test
|
|
run: cargo test -p aether-data-postgres live_payment_callback --lib -- --ignored --nocapture
|
|
|
|
- name: Run Postgres API key lifecycle tests
|
|
env:
|
|
RUSTC_WRAPPER: sccache
|
|
SCCACHE_GHA_ENABLED: "true"
|
|
AETHER_REQUIRE_LOCAL_POSTGRES_TESTS: "true"
|
|
run: |
|
|
cargo test -p aether-data --all-features lifecycle::migrate::tests::postgres_request_candidates_preserve_deleted_api_key_identity --lib -- --exact --nocapture
|
|
cargo test -p aether-data --all-features lifecycle::migrate::tests::postgres_request_candidate_migration_decouples_legacy_api_key_foreign_key --lib -- --exact --nocapture
|
|
cargo test -p aether-data --all-features lifecycle::migrate::tests::postgres_stats_daily_api_key_migration_decouples_legacy_foreign_key --lib -- --exact --nocapture
|
|
cargo test -p aether-data --all-features lifecycle::migrate::tests::postgres_expired_api_key_cleanup_preserves_historical_identity --lib -- --exact --nocapture
|
|
cargo test -p aether-data --all-features lifecycle::migrate::tests::postgres_api_key_leaderboard_user_filter_preserves_aggregate_history --lib -- --exact --nocapture
|
|
|
|
- name: Run Postgres core export smoke test
|
|
env:
|
|
RUSTC_WRAPPER: sccache
|
|
SCCACHE_GHA_ENABLED: "true"
|
|
AETHER_TEST_POSTGRES_URL: postgres://aether:[email protected]:5432/aether_test
|
|
run: cargo test -p aether-data --all-features postgres_core_export_reads_migrated_database_rows_when_url_is_set --lib -- --nocapture
|
|
|
|
- name: Show sccache stats
|
|
if: always()
|
|
env:
|
|
RUSTC_WRAPPER: sccache
|
|
SCCACHE_GHA_ENABLED: "true"
|
|
run: sccache --show-stats
|
|
|
|
data_db_smoke:
|
|
name: Data DB Smoke
|
|
runs-on: ubuntu-latest
|
|
needs:
|
|
- changes
|
|
- data_db_smoke_postgres
|
|
if: ${{ always() }}
|
|
steps:
|
|
- name: Verify database smoke jobs
|
|
run: |
|
|
if [ "${{ needs.changes.result }}" != "success" ]; then
|
|
echo "Scope detection failed"
|
|
exit 1
|
|
fi
|
|
if [ "${{ needs.changes.outputs.rust }}" != "true" ]; then
|
|
echo "Rust scope unchanged; database smoke jobs skipped"
|
|
exit 0
|
|
fi
|
|
if [ "${{ needs.data_db_smoke_postgres.result }}" != "success" ]; then
|
|
echo "Data DB smoke failed"
|
|
exit 1
|
|
fi
|
|
|
|
check:
|
|
name: check
|
|
runs-on: ubuntu-latest
|
|
needs:
|
|
- changes
|
|
- fmt
|
|
- clippy
|
|
- test
|
|
- data_db_smoke
|
|
- shell_security
|
|
if: ${{ always() }}
|
|
steps:
|
|
- name: Verify required jobs
|
|
run: |
|
|
# changes 失败或未产出 scope 时不允许直接放行,避免假绿。
|
|
if [ "${{ needs.changes.result }}" != "success" ]; then
|
|
echo "Scope detection failed"
|
|
exit 1
|
|
fi
|
|
rust="${{ needs.changes.outputs.rust }}"
|
|
shell="${{ needs.changes.outputs.shell }}"
|
|
|
|
if [ "$rust" != "true" ] && [ "$shell" != "true" ]; then
|
|
echo "No Rust or shell scope changed"
|
|
exit 0
|
|
fi
|
|
|
|
if [ "$rust" = "true" ] && {
|
|
[ "${{ needs.fmt.result }}" != "success" ] ||
|
|
[ "${{ needs.clippy.result }}" != "success" ] ||
|
|
[ "${{ needs.test.result }}" != "success" ] ||
|
|
[ "${{ needs.data_db_smoke.result }}" != "success" ];
|
|
}; then
|
|
echo "Rust CI failed"
|
|
exit 1
|
|
fi
|
|
|
|
if [ "$shell" = "true" ] && [ "${{ needs.shell_security.result }}" != "success" ]; then
|
|
echo "Rust CI failed"
|
|
exit 1
|
|
fi
|