memlnaut-nisps/.github/workflows/ci.yml
monkey-w1n5t0n 8c249ea8af ci: restore verification — reachable submodule pin, codegen + WASM freshness gates
Phase 0 of the 2026-07 simplification audit (plan §1). CI has been 100% red on
main since 2026-07-13 and every "gates green" claim since rested on local runs.

- S7 / critic gap 2: push memllib `feat/nisps-core-swap` (3 commits incl. the
  pin b37fc53) to monkey-w1n5t0n/memllib and repoint .gitmodules at the fork.
  Those commits existed on exactly one disk; `git ls-remote` now resolves the
  pin, so `submodules: recursive` checkout and fresh clones work again. Drops
  the compensating unreachable-pin error paragraph in build-firmware-arch.sh.
- S24 / S31: the manifold-tests job regenerates from schemas/, runs the codegen
  golden test, and fails on a dirty diff — the "schema changes ship with both
  generated outputs" rule is now enforced rather than assumed.
- S32: a WASM freshness gate runs the parity harness against the *committed*
  manifold/public/nisps.{js,wasm} before the CI rebuild overwrites it. That
  artifact is what the webhook ships to production, so a stale commit now fails
  loudly instead of shipping.
- critic gap 3 / operator decision §7.4: the VPS webhook
  (~/.config/webhooks/meml-deploy.sh, not in this repo) waits for the `CI`
  workflow to conclude success on the pushed SHA before building. Fail-closed;
  MEML_SKIP_CI_GATE=1 for an emergency hand-deploy. Verified the gate query
  returns `failure` for fa37047, i.e. it would have blocked that deploy.
- S31: corrected run-all-tests.sh's false "single command CI invokes" header.

Docs moved with the code: ALIGNMENT defect 1 deleted (resolved) and the rest
renumbered; MAP.md's unreachable-pin warning replaced with the fork pin and a
pointer to the §7.5 vendoring decision; ONBOARDING documents the deploy gate
and the tracked-WASM-ships-to-prod hazard; plan §1 marked burned down.

Gates: scripts/run-all-tests.sh ALL GREEN (ctest 4/4, parity 1273 floats within
1e-5, lint, typecheck, 33 Playwright specs).
2026-07-21 11:57:32 +02:00

159 lines
5 KiB
YAML

name: CI
# Stream 11 verification pipeline.
#
# Two parallel jobs:
# * cpp-tests — builds nisps host C++ tests, builds nisps.wasm, runs
# the parity check, runs the lint script.
# * manifold-tests — typechecks the React manifold app, runs bun unit
# tests, builds the production bundle, runs Playwright
# e2e tests.
#
# Firmware compilation is NOT included in this workflow. Arduino-cli +
# rp2040 board package add ~2 minutes per run, and the verification value
# is low compared to the time cost; firmware build is documented as a
# manual `scripts/build-firmware.sh` step in README.md / CLAUDE.md.
on:
push:
branches: [main, port-solidjs]
pull_request:
branches: [main, port-solidjs]
workflow_dispatch:
jobs:
cpp-tests:
name: C++ tests + WASM + parity + lint
runs-on: ubuntu-latest
steps:
- name: Checkout
uses: actions/checkout@v4
with:
submodules: recursive
- name: Install build deps
run: |
sudo apt-get update
sudo apt-get install -y --no-install-recommends \
cmake ninja-build build-essential perl
- name: Setup Emscripten
# mymindstorm/setup-emsdk caches the SDK between runs. Pin to a
# known-working version; bump deliberately.
uses: mymindstorm/setup-emsdk@v14
with:
version: '3.1.69'
actions-cache-folder: 'emsdk-cache'
- name: Verify emcc
run: emcc --version
- name: Setup Node (for parity_wasm.mjs)
uses: actions/setup-node@v4
with:
node-version: '20'
- name: Build C++ tests + run ctest
env:
# CI is non-interactive — turn off colour for log readability.
CMAKE_BUILD_PARALLEL_LEVEL: '4'
run: bash scripts/build-cpp-tests.sh
# Freshness gate. manifold/public/nisps.{js,wasm} are TRACKED artifacts:
# the VPS webhook builds only manifold/, so vite copies whatever is
# committed into the production bundle. Prove the committed artifact
# still agrees with the C++ we just built, BEFORE the rebuild below
# overwrites it. A stale commit fails here instead of silently shipping.
- name: WASM freshness gate (committed artifact vs native)
env:
NISPS_PARITY_NO_BUILD: '1'
run: bash scripts/parity-check.sh
- name: Build WASM
env:
# The script defaults to /usr/lib/emscripten/emcc; the runner gets
# emcc on PATH via setup-emsdk. Override.
EMCC: emcc
run: bash scripts/build-wasm.sh
- name: Parity check (native vs WASM)
env:
NISPS_PARITY_NO_BUILD: '1' # we just built; don't re-build
run: bash scripts/parity-check.sh
- name: Lint
run: bash scripts/lint-cpp.sh
- name: Upload parity blobs on failure
if: failure()
uses: actions/upload-artifact@v4
with:
name: parity-blobs
path: |
tests/cpp/parity_native.bin
tests/cpp/parity_wasm.bin
if-no-files-found: ignore
retention-days: 7
manifold-tests:
name: Manifold typecheck + unit + e2e
runs-on: ubuntu-latest
steps:
- name: Checkout
uses: actions/checkout@v4
- name: Setup Bun
uses: oven-sh/setup-bun@v2
with:
bun-version: latest
# Enforces the "schema changes ship with regenerated C++ AND TypeScript
# in the same change" rule. Regenerate from schemas/ and fail if the
# committed outputs differ; then run the codegen golden test.
- name: Codegen is committed and idempotent
run: |
cd codegen
bun install --frozen-lockfile
bun run generate.ts
bun run generate-midi-devices.ts
bun run tests/golden_test.ts
cd ..
GEN_DIRS="nisps/modes/generated nisps/midi/generated \
manifold/src/modes/generated manifold/src/midi-devices/generated"
git add -N $GEN_DIRS
if ! git diff --exit-code -- $GEN_DIRS; then
echo "::error::Generated outputs are stale. Run codegen and commit the result." >&2
exit 1
fi
- name: Install manifold deps
working-directory: manifold
run: bun install --frozen-lockfile
- name: Typecheck
working-directory: manifold
run: bun run typecheck
- name: Unit tests
working-directory: manifold
run: bun run test
- name: Build manifold bundle
working-directory: manifold
run: bun run build
- name: Install Playwright browsers
working-directory: manifold
run: bunx playwright install --with-deps chromium
- name: Run Playwright tests
working-directory: manifold
run: bunx playwright test
- name: Upload Playwright report on failure
if: failure()
uses: actions/upload-artifact@v4
with:
name: playwright-report
path: manifold/playwright-report/
retention-days: 7