Files
deepseek-harness/.github/workflows/node-addon-system.yml
T
Workflow config file is invalid. Please check your config file: getMatrixes: matrix include must be a list of mappings

180 lines
5.4 KiB
YAML

# CI for the node-addon-system packages under native/system. A separate
# workflow from ci.yml keeps the native OS/architecture matrix independent of
# the harness Node matrix. Release assembly and publication use the companion
# Node Addon System Release workflow.
name: Node Addon System
on:
pull_request:
paths:
- '.github/workflows/node-addon-system.yml'
- '.github/workflows/node-addon-system-release.yml'
- 'native/system/**'
- 'package.json'
- 'pnpm-lock.yaml'
- 'pnpm-workspace.yaml'
push:
branches: [master]
paths:
- '.github/workflows/node-addon-system.yml'
- '.github/workflows/node-addon-system-release.yml'
- 'native/system/**'
- 'package.json'
- 'pnpm-lock.yaml'
- 'pnpm-workspace.yaml'
workflow_dispatch:
concurrency:
group: ${{ github.workflow }}-${{ github.ref }}
cancel-in-progress: true
permissions:
contents: read
env:
# CI runs must never report to the production telemetry endpoint baked
# into apps/cli/cordis.yml (AppCLIEntry disables the row when set).
DSH_TELEMETRY_DISABLED: '1'
defaults:
run:
working-directory: native/system
jobs:
matrix:
name: Matrix
runs-on: ubuntu-24.04
outputs:
ci: ${{ steps.matrix.outputs.ci }}
compatibility: ${{ steps.matrix.outputs.compatibility }}
steps:
- uses: actions/checkout@v4
- id: matrix
run: |
echo "ci=$(node ./scripts/github-matrix.mjs ci)" >> "$GITHUB_OUTPUT"
echo "compatibility=$(node ./scripts/github-matrix.mjs compatibility)" >> "$GITHUB_OUTPUT"
native:
name: ${{ matrix.platform }}
needs: matrix
runs-on: ${{ matrix.runner }}
strategy:
fail-fast: false
matrix: ${{ fromJson(needs.matrix.outputs.ci) }}
steps:
- uses: actions/checkout@v4
- uses: pnpm/action-setup@v4
with:
package_json_file: package.json
- uses: actions/setup-node@v4
with:
node-version: 24
cache: pnpm
cache-dependency-path: pnpm-lock.yaml
- name: Install dependencies
run: pnpm install --filter @deepseek-ai/node-addon-system-workspace... --frozen-lockfile
- name: Install musl toolchain
if: runner.os == 'Linux'
run: |
sudo apt-get update -q
sudo apt-get install -yq musl-tools
- name: Build TypeScript
run: pnpm build:ts
- name: Typecheck
run: pnpm typecheck
- name: Build native binaries (this architecture is the builder of record)
run: pnpm build:native
- name: Entry tests (keyless)
run: node ./test/entry.test.js
# NALR_REQUIRE_LANDLOCK: a self-skip on the very platform that exists to
# prove enforcement would be a false green, so an unenforcing kernel
# fails the leg instead of skipping.
- name: Launcher tests (real kernel enforcement)
if: runner.os == 'Linux'
run: node ./test/launcher.test.js
env:
NALR_REQUIRE_LANDLOCK: 1
- name: Pack rehearsal (pack → install → confine, this platform only)
run: |
node ./scripts/pack-release.mjs .release/npm --current-platform-only
node ./scripts/verify-packed-install.mjs .release/npm --current-platform-only
env:
NALR_REQUIRE_LANDLOCK: ${{ runner.os == 'Linux' && '1' || '0' }}
- name: Verify platform payload rules
run: pnpm test:packaging
- name: Flock behavior (built addon)
run: |
pnpm build:test-oracle
pnpm test:flock
- name: Upload this platform's built addon and entry
uses: actions/upload-artifact@v4
with:
name: system-compat-${{ matrix.platform }}
path: |
native/system/packages/*/bin/**
native/system/packages/entry/lib/**
if-no-files-found: error
- name: Upload independent syscall test oracle
uses: actions/upload-artifact@v4
with:
name: system-oracle-${{ matrix.platform }}
path: native/system/test/bin/**
if-no-files-found: error
compatibility:
name: ${{ matrix.platform }} / Node ${{ matrix.node }} (same binary)
needs: [matrix, native]
strategy:
fail-fast: false
matrix:
include: ${{ fromJson(needs.matrix.outputs.compatibility) }}
runs-on: ${{ matrix.runner }}
steps:
- uses: actions/checkout@v4
- uses: actions/setup-node@v4
with:
node-version: ${{ matrix.node }}
- name: Download the original platform build
uses: actions/download-artifact@v4
with:
name: system-compat-${{ matrix.platform }}
path: native/system/packages
- name: Download independent syscall test oracle
uses: actions/download-artifact@v4
with:
name: system-oracle-${{ matrix.platform }}
path: native/system/test/bin
- name: Restore oracle executable permissions
run: find ./test/bin -type f -name flock-oracle -exec chmod +x {} +
- name: Test without rebuilding or installing dependencies
run: |
node ./test/link-platform.mjs
node --test ./test/flock.test.js ./test/package-matrix.test.js
- name: Test the same musl addon without a compiler
if: runner.os == 'Linux'
run: >-
docker run --rm -v "$PWD:$PWD" -w "$PWD"
node:${{ matrix.node }}-alpine
node --test ./test/flock.test.js ./test/package-matrix.test.js