mirror of
https://github.com/deepseek-ai/deepseek-harness.git
synced 2026-09-11 04:00:38 +00:00
refactor(native): rename package family to node-addon-system
This commit is contained in:
@@ -0,0 +1,144 @@
|
||||
# CI for the node-addon-system packages under native/system. A separate
|
||||
# workflow from ci.yml keeps the native OS/architecture matrix independent of
|
||||
# the harness Node matrix. Release assembly and publication use the companion
|
||||
# Node Addon System Release workflow.
|
||||
name: Node Addon System
|
||||
|
||||
on:
|
||||
pull_request:
|
||||
paths:
|
||||
- '.github/workflows/node-addon-system.yml'
|
||||
- '.github/workflows/node-addon-system-release.yml'
|
||||
- 'native/system/**'
|
||||
- 'package.json'
|
||||
- 'pnpm-lock.yaml'
|
||||
- 'pnpm-workspace.yaml'
|
||||
push:
|
||||
branches: [master]
|
||||
paths:
|
||||
- '.github/workflows/node-addon-system.yml'
|
||||
- '.github/workflows/node-addon-system-release.yml'
|
||||
- 'native/system/**'
|
||||
- 'package.json'
|
||||
- 'pnpm-lock.yaml'
|
||||
- 'pnpm-workspace.yaml'
|
||||
workflow_dispatch:
|
||||
|
||||
concurrency:
|
||||
group: ${{ github.workflow }}-${{ github.ref }}
|
||||
cancel-in-progress: true
|
||||
|
||||
permissions:
|
||||
contents: read
|
||||
|
||||
env:
|
||||
# CI runs must never report to the production telemetry endpoint baked
|
||||
# into apps/cli/cordis.yml (AppCLIEntry disables the row when set).
|
||||
DSH_TELEMETRY_DISABLED: '1'
|
||||
|
||||
defaults:
|
||||
run:
|
||||
working-directory: native/system
|
||||
|
||||
jobs:
|
||||
matrix:
|
||||
name: Matrix
|
||||
runs-on: ubuntu-24.04
|
||||
outputs:
|
||||
ci: ${{ steps.matrix.outputs.ci }}
|
||||
steps:
|
||||
- uses: actions/checkout@v4
|
||||
|
||||
- id: matrix
|
||||
run: echo "ci=$(node ./scripts/github-matrix.mjs ci)" >> "$GITHUB_OUTPUT"
|
||||
|
||||
native:
|
||||
name: ${{ matrix.platform }}
|
||||
needs: matrix
|
||||
runs-on: ${{ matrix.runner }}
|
||||
strategy:
|
||||
fail-fast: false
|
||||
matrix: ${{ fromJson(needs.matrix.outputs.ci) }}
|
||||
steps:
|
||||
- uses: actions/checkout@v4
|
||||
|
||||
- uses: pnpm/action-setup@v4
|
||||
with:
|
||||
package_json_file: package.json
|
||||
|
||||
- uses: actions/setup-node@v4
|
||||
with:
|
||||
node-version: 24
|
||||
cache: pnpm
|
||||
cache-dependency-path: pnpm-lock.yaml
|
||||
|
||||
- name: Install dependencies
|
||||
run: pnpm install --filter @deepseek-ai/node-addon-system-workspace... --frozen-lockfile
|
||||
|
||||
- name: Install musl toolchain
|
||||
run: |
|
||||
sudo apt-get update -q
|
||||
sudo apt-get install -yq musl-tools
|
||||
|
||||
- name: Build TypeScript
|
||||
run: pnpm build:ts
|
||||
|
||||
- name: Typecheck
|
||||
run: pnpm typecheck
|
||||
|
||||
- name: Build native binaries (this architecture is the builder of record)
|
||||
run: pnpm build:native
|
||||
|
||||
- name: Entry tests (keyless)
|
||||
run: node ./test/entry.test.js
|
||||
|
||||
# NALR_REQUIRE_LANDLOCK: a self-skip on the very platform that exists to
|
||||
# prove enforcement would be a false green, so an unenforcing kernel
|
||||
# fails the leg instead of skipping.
|
||||
- name: Launcher tests (real kernel enforcement)
|
||||
run: node ./test/launcher.test.js
|
||||
env:
|
||||
NALR_REQUIRE_LANDLOCK: 1
|
||||
|
||||
- name: Pack rehearsal (pack → install → confine, this platform only)
|
||||
run: |
|
||||
node ./scripts/pack-release.mjs .release/npm --current-platform-only
|
||||
node ./scripts/verify-packed-install.mjs .release/npm --current-platform-only
|
||||
env:
|
||||
NALR_REQUIRE_LANDLOCK: 1
|
||||
|
||||
darwin:
|
||||
name: darwin (no platform package — degradation proof)
|
||||
runs-on: macos-latest
|
||||
steps:
|
||||
- uses: actions/checkout@v4
|
||||
|
||||
- uses: pnpm/action-setup@v4
|
||||
with:
|
||||
package_json_file: package.json
|
||||
|
||||
- uses: actions/setup-node@v4
|
||||
with:
|
||||
node-version: 24
|
||||
cache: pnpm
|
||||
cache-dependency-path: pnpm-lock.yaml
|
||||
|
||||
- name: Install dependencies
|
||||
run: pnpm install --filter @deepseek-ai/node-addon-system-workspace... --frozen-lockfile
|
||||
|
||||
- name: Build TypeScript
|
||||
run: pnpm build:ts
|
||||
|
||||
- name: Typecheck
|
||||
run: pnpm typecheck
|
||||
|
||||
- name: Entry tests (keyless)
|
||||
run: node ./test/entry.test.js
|
||||
|
||||
- name: Launcher tests (must self-skip cleanly)
|
||||
run: node ./test/launcher.test.js
|
||||
|
||||
- name: Pack rehearsal (entry only — fallback resolution + unusable probe)
|
||||
run: |
|
||||
node ./scripts/pack-release.mjs .release/npm --current-platform-only
|
||||
node ./scripts/verify-packed-install.mjs .release/npm --current-platform-only
|
||||
Reference in New Issue
Block a user