mirror of
https://github.com/stablyai/orca.git
synced 2026-09-21 16:02:20 +00:00
* docs(windows): record the measured MSYS job-breakaway mechanism The per-PTY job already denies JOB_OBJECT_LIMIT_BREAKAWAY_OK for Cygwin/MSYS shells (#19068), but nothing records why, and a conpty.node built before that commit fails windows-msys-job.win32.test.ts in a way that reads as a source defect. Measured on a real Windows 11 host: both the plain and the exec- replacement Git Bash shapes leak, the escape is the MSYS runtime's own spawn/exec (fork keeps membership), and a single-variable A/B on usesCygwinRuntime flips the result 0/2 -> 4/4. Also names the gap the failure hid behind: node-pty-job-ownership.cjs asserts symbol presence, which cannot distinguish patch revisions. * fix(windows): reject a node-pty addon that predates the MSYS breakaway denial The native-runtime gate asserted only that terminateJob, listJobProcessIds and assignCurrentProcessToJob were exported. All three predate the Cygwin/MSYS breakaway denial, so an addon built before it passes every gate, isPtyJobOwnershipAvailable() returns true, and windows-pty-job.win32.test.ts passes 6/6 -- while every Git Bash child is created outside its pane's job and survives terminatePtyJob. Read the resolved .node and require the wide msys-2.0.dll literal that usesCygwinRuntime holds, the way stagedRelayAddonIsUnpatched() already tells a patched windows-process-tree addon from a published one. An addon the caller cannot name is refused rather than skipped: a gate that cannot see its subject is not a gate. Verified against real binaries on a Windows 11 host: the shared checkout's pre-#19068 build errors, a build from current patched source passes, a missing path errors. Also closes the cross-host packaging skip. The export half has to load the addon so it cannot run when the packaging host is not the target, which is how a Windows release built elsewhere could ship this. The marker is a file read and needs neither; an unrecognised layout warns rather than fails a release that was packaging fine. * fix(windows): check the MSYS breakaway denial on the rebuild path too The Electron probe carried the marker check, but it lives inside probeElectronNativeModules, which returns early whenever the Electron package binary is unusable. Covered by another path is not this path checks -- and the defect this whole change closes was a gate that looked like it checked. Reading the binary needs neither a loadable Electron nor an executable target arch, so assert it after the rebuild, beside the windows-process-tree assertion that exists for the same reason: this is the addon copied into the packaged app. Absent warns (a cross-platform rebuild need not leave a win32 addon on this disk); present and unmarked is fatal. The fixtures now write a real addon file, because the gate reads the binary it was told about rather than trusting the exports. Verified against the two real binaries measured on the Windows host: the pre-#19068 build fails this path, the build from current patched source passes. * fix(windows): check the marker on every ConPTY path the packaged app can load The packaged marker check read one hard-coded path, `build/Release/conpty.node`, and warned when it was absent. `loadNativeModule` tries `build/Release`, then `build/Debug`, then `prebuilds/win32-<arch>`, swallowing each failure, and `prunePackagedNodePty` drops the published prebuild only when a same-arch `build/Release` exists to replace it. So the two packages the check was added for were the two it could not see: - cross-host: no host but Windows can build conpty.node, so there is no `build/Release` and the prebuild is what ships. The check warned and returned. - cross-arch: `build/Release` is the packaging host's own arch, patched and marked, so the check printed OK -- while the target app cannot load it and falls through to the unmarked prebuild underneath. Measured, not assumed: both published Windows prebuilds in the node-pty tarball contain neither `msys-2.0.dll` nor `cygwin1.dll` in any encoding. They are the binary that leaks every MSYS pane child out of its job. It now sweeps every candidate present for the *target* arch and refuses a package with no candidate at all, which is a package with no ConPTY backend rather than a layout to shrug at. It runs for every Windows slice instead of only the branch the export check skips, so deleting the export check cannot silently take it too. A stale source build keeps the rebuild advice; the prebuild gets the advice that actually works, which is to package the slice on a Windows host of that arch. Also: the marker constant was re-typed in four places and was tied to the C++ literal that produces it by nothing at all, so editing the patch would have left a gate that fails every correctly rebuilt addon and tells the developer to do the one thing that cannot help. The fixtures now take the constant from the gate, and a test asserts the patch still adds `L"msys-2.0.dll"` to conpty.cc. And the rebuild path treated a missing addon as a warning even on the host that will run the install, where node-pty would fall through to that same prebuild. The verdict is now a value, so it is tested without a platform gate. * fix(windows): resolve the packaged ConPTY the way its loader does Sweeping every candidate and demanding the marker on all of them was wrong in the one case it was meant to make safe. `beforeBuild` runs `rebuild-native-deps.mjs --platform=win32 --arch=<target>`, so a cross-arch slice normally does get a patched `build/Release` for the target; `prunePackagedNodePty` keeps the prebuild anyway because its guard is `electronArch === process.arch` rather than the arch of the binary. That package is correct and its leftover prebuild is never reached, and the sweep failed it -- telling whoever ran it to package on a Windows arm64 host, which is both the wrong remedy and one no runner here can offer. Presence cannot separate that package from the one whose cross-arch rebuild quietly emitted the host's architecture, because the only difference is the arch of `build/Release`. So the gate now resolves the addon the way `loadNativeModule` does -- first candidate whose PE `IMAGE_FILE_HEADER.Machine` matches the target, walking root-then-lib for each layout in node-pty's own order -- and checks the marker on the one that will actually run. A package with no candidate, or none of the target's architecture, is refused: it has no ConPTY backend either way, and the second is exactly what a silently host-arch cross-build looks like. The PE machine reader already existed, privately, in the relay addon builder that needed the same "a cross-build cannot silently emit host arch" guarantee. It is now shared rather than copied. Two seams were unreachable from anything but Windows, so nothing tested them: - the afterPack hook's win32 block was an inline if/else that only a source-text assertion could inspect, and that assertion could not tell the difference between the check running and the check being wrapped in `try {} catch {}`. It is now `verifyPackagedWindowsNodePty`, and "the marker check runs even where the export check cannot" is four spied assertions instead of a string match. - the rebuild path's verdict read `process` directly, so the branch that fires only on the host being rebuilt for was dead on every other host. It now takes the host as arguments, and the fs checks, the warning and the failure are all exercised from macOS. Fixtures write a real PE header rather than `MZ fake addon`, since the gate now reads one. The machine table is pinned to the documented IMAGE_FILE_MACHINE values, because every fixture builds its header from that table and a table wrong in both entries would otherwise agree with itself. * fix(windows): say why the packaged ConPTY fell back, not just that it did The previous commit resolved the addon by architecture but still had one message for every way the resolution could land on the published prebuild. Those ways want opposite remedies, and the one it printed was the remedy the commit before it had just called wrong: - no source build in the package at all — the slice has to be built somewhere that can build node-pty for the target arch. - a source build that is there but is the packaging host's architecture, because the cross-arch rebuild did not honour `--arch` — re-running that rebuild is the fix, and "package on a Windows arm64 host" is neither necessary nor possible. The second is the common one, since node-pty publishes a prebuild for both Windows arches and prune keeps the target's on every cross-arch package. So the old text fired mostly on the case it described least. It now reports which source builds were skipped and the machine field each carried, and names the rebuild command. "Nothing the target can load" had the same problem in reverse: a zero-length or truncated `conpty.node` got a cross-architecture diagnosis. Every candidate is now named with what was actually read, including "not a PE image". The rebuild path asserts the architecture too. A rebuild that ignored `--arch` was otherwise only visible at packaging, two steps from the command that fixes it. Arches with no known machine value are left unjudged rather than guessed at. Two things the extraction broke or nearly broke, both found by mutation: - the shared PE reader answers `null` where the relay builder's private copy returned a number, which would have turned its "node-gyp ignored --arch" error into a `TypeError`. Both callers now go through `describePeMachine`. - the rebuild fixtures stage a script's co-located modules by walking its imports, and the walker only understood `from '...'` — so the gate's new `require('./windows-pe-machine.cjs')` was left behind and every subprocess test failed with a resolution error, which is the exact failure its own comment warns about. It now follows `require` and bare side-effect `import` as well, and has tests; the fixture stages the gate by walking it rather than by naming one file. Fixtures write real PE headers through one shared builder instead of three hand-rolled ones. * fix(windows): run the node-pty addon gates on the Windows job that can `rebuild-native-deps-node-pty.test.mjs` carries four `skipIf(platform !== 'win32')` tests. The full suite runs on ubuntu, and the Windows PR job runs an explicit file list that never named this file -- so those tests were skipped on Linux and never reached anywhere else. Three of them predate this branch. The Windows job is added the four node-pty addon suites plus the module-walker one; the comment above that list already says why it is the right place, which is that the addon assertions only hold once natives have been rebuilt. Running the path-joining suites there also covers the separator this gate's candidate list is built from. The rest is round-three review: - the rebuild-time arch assertion told a reader "node-gyp did not honour --arch" about a file that was not a PE image at all, which is a truncated or quarantined artifact and a different command to run. The two now read differently, and neither claims the other's cause. Same fix the packaged gate had one commit ago, in the place that had not had it yet. - the missing-addon error said node-pty "would load" a prebuild without checking it is there. It says "fall through to" now, which is true either way. - `isLoadableByArch` had no caller left once the packaged gate started needing the raw machine field for its message. Removed rather than kept warm. - each candidate's header is read once instead of up to three times. - the module walker's comment claimed every shape that reaches a co-located module; it does not follow `projectRequire`/`requireLocal`, and it must not -- those specifiers resolve against the project root, so following one stages the wrong path and the copy fails. Proven by trying: widening the pattern to require-shaped names broke nine tests on `projectRequire('./config/scripts/...')`. The comment now says what it follows and why it stops there. - a new test resolved a file URL with `.pathname`, which keeps the drive-letter slash on Windows -- the very job this commit adds it to. * docs(windows): put the superseded export-only gate in the past tense It describes what used to pass a broken addon, so present tense reads as a description of the gate the same document then explains replacing it. * fix(windows): repair what running the node-pty suites on Windows exposed Putting these files on the Windows job turned four assertions red on the first run. Three of them were in tests that carried `skipIf(platform !== 'win32')` and had therefore never executed anywhere, on any branch. - `writeFakeElectronRebuild` emitted the `windows-process-tree` addon a real rebuild leaves but never node-pty's, so every Windows test of the rebuild path ran against a tree no real rebuild can produce: node-pty "rebuilt" with nothing in `build/Release`. The new same-host check reads that state correctly and said so. The fake rebuild now writes `build/Release/conpty.node` when it was asked to rebuild node-pty for win32, with the marker and the target machine. - `mkTempProject` never staged `windows-process-tree-creation-time.cjs`. The rebuild script reaches it through `projectRequire`, which resolves against the project root, so the module walker cannot follow it and must not try. Staged by name, with a comment saying which of the two it is. Without it the windows-process-tree probe failed to load its own checker and the module joined `modulesToRebuild`, which is the second and third red assertion. - the two `nodePtyAddonPath` cases compared against a literal POSIX string. `resolve` returns a drive letter and backslashes on Windows, so they could only ever pass off it. Built from segments now, which still pins the `..` traversal that is the point of the test. Verified on macOS: ensure-native-runtime-job-ownership, verify-packaged-node-pty-job-ownership, windows-pe-machine, script-module-dependencies, rebuild-native-deps-node-pty, rebuild-native-deps, rebuild-native-deps-windows-process-tree, ensure-native-runtime -- 109 passed, 6 skipped. The 6 are the Windows-gated rebuild tests, which is the job this change is aimed at; Windows CI is the arbiter. * fix(windows): give the packaged fallback a third verdict, for a file that is no image The packaged gate had two remedies for landing on the published prebuild and picked between them on `!prebuilt`, which puts a truncated, empty or quarantined `build/Release/conpty.node` in the cross-arch bucket: "the source build beside it is the wrong architecture ... re-run with --arch". It is not the wrong architecture, it is not an architecture, and `--arch` is not the command. The rebuild-path gate was split for exactly this a commit ago; this is the same split in the place that had not had it. Also from review of the settled state: - the stale-source-build branch ended in a call that happened to throw, so a reader could not see it was terminal and the file was read twice to get there. The verdict is now an Error the caller throws, built once from the read it already did, and shared with `assertCygwinBreakawayDenied` rather than copied. - four injection seams had no consumer in production or in tests (`deniesBreakaway`, `peMachine`, and `exists`/`peMachine` on the rebuild verdict). An unused seam is a way for the tested path and the real one to drift apart; the tests drive both with real files. Removed. - the loader table existed in a docblock and in the reference doc, already disagreeing about row four. The docblock cites the doc now. - `peImage` stamped machine `0x0000` for an arch it had no value for, because `writeUInt16LE(undefined)` coerces to zero. A fixture that quietly invents the field the gates read is the same species of silent lie the gates exist to catch; it throws, and a test holds it to that. - a test named for refusing an unreadable candidate asserted only that something threw. Renamed to what it proves. * fix(windows): make the rebuild fixtures represent a tree that can exist Second round of what running these suites on Windows exposed. The module the walker could not stage is now staged, so the probe reached its own checker and the real reasons surfaced: - `writeFakeWindowsProcessTree` exported `{}`. The creation-time gate reads `supportedProcessDataFlags` off the addon and calls its absence "the tarball prebuilt, not a build of the patched source" — correctly. The fixture predates that gate and, being Windows-only, never met it. The healthy fake now reports the flag, taken from the gate's own constant. Two tests were failing on this, the second only because the module then joined `modulesToRebuild`. - `rebuilds a loadable ConPTY native that lacks Orca job ownership` asked for a node-pty rebuild in a tree where node-pty had none of the payload its package ships. It gets `writeFakeNodePtyConptyPayload` like its two siblings. I also tried making the fake rebuild emit `build/Release/conpty.node` the way a real one does, and backed it out: `restoreNodePtyWindowsConptyRuntime` keys off that file and then reads `third_party/conpty`, so emitting it in a tree without the package payload turns one honest gap into an ENOENT two steps away. The payload fixture is where "node-pty has its addon" belongs. macOS: ensure-native-runtime-job-ownership, verify-packaged-node-pty-job-ownership, windows-pe-machine, script-module-dependencies, rebuild-native-deps-node-pty, rebuild-native-deps, rebuild-native-deps-windows-process-tree, ensure-native-runtime — 112 passed, 6 skipped. The 6 are the Windows-gated rebuild tests; Windows CI is the arbiter and is why they are on that job now. * fix(windows): register the node-pty addon suites in the scope list too Putting the five suites in the Windows lane's vitest argv gets them run once the job starts; `WINDOWS_PACKAGE_TESTS` in `pr-code-change-scope.mjs` is what decides whether the job starts at all. Only the argv was updated, so a PR touching just `rebuild-native-deps-node-pty.test.mjs` would not have started the Windows job, and its four Windows-only cases — including the same-host-absent one added here — would have run on no machine for that PR. Exactly the shape of gap this branch is about. Both lists now name all five, and `windows-pe-machine`, `windows-pe-image-fixture` and `script-module-dependencies` join `NATIVE_RUNTIME_PREFIXES` so a change to the modules themselves starts it too. `win32-test-lane-registration.test.mjs` exists to catch precisely this and did not, because its matcher only recognises suite-level gates (`describe.runIf` / `describe.skipIf`) and a `.win32.` filename. These tests gate per `it`. Widening it is not this branch's change to make: about thirty files across the repo carry per-`it` Windows gates and are unregistered, so the ratchet would move far beyond node-pty. Flagged rather than done. Message repairs from the same review: - the non-PE arm of the rebuild-time arch error read "... is not a PE image, so nothing can load it, so node-pty would fall back ...". The shared consequence clause already opens with ", so". - the no-source-build packaging error ended "Package this Windows slice on such a host", which is wrong advice for the case where the host IS such a host and the rebuild simply left nothing — reachable when the artifact is removed before prune runs. It now names both readings and points at the beforeBuild output. - the relay-addon builder blamed `--arch` for a build output that is not a PE at all, the same guess the node-pty gate was taught to stop making. - the patch-drift assertion was a bare `toBe(true)`, so a real drift read as "expected false to be true". It now names the two things that can have drifted and what happens until they agree.
1097 lines
51 KiB
YAML
1097 lines
51 KiB
YAML
name: PR Checks
|
|
|
|
on:
|
|
pull_request:
|
|
types:
|
|
- opened
|
|
- synchronize
|
|
- reopened
|
|
- ready_for_review
|
|
|
|
concurrency:
|
|
group: pr-checks-${{ github.event.pull_request.number }}
|
|
cancel-in-progress: true
|
|
|
|
permissions:
|
|
contents: read
|
|
|
|
jobs:
|
|
# Why: a README/docs-only PR used to start the full matrix (test shards,
|
|
# two package jobs, typecheck, git compat, xterm, shell contracts). Path
|
|
# filters on `on.pull_request` would drop the `verify` check entirely; this
|
|
# detector keeps verify as the required aggregate and skips the expensive jobs.
|
|
# Per-job outputs also skip git-compat/xterm/packaging/shell when those
|
|
# inputs are unchanged; empty diffs fail closed and run everything.
|
|
code_paths:
|
|
name: detect code-relevant changes
|
|
runs-on: ubuntu-latest
|
|
outputs:
|
|
should_run: ${{ steps.filter.outputs.should_run }}
|
|
native_cache_changed: ${{ steps.filter.outputs.native_cache_changed }}
|
|
mobile_dependencies: ${{ steps.filter.outputs.mobile_dependencies }}
|
|
static_analysis: ${{ steps.filter.outputs.static_analysis }}
|
|
typecheck: ${{ steps.filter.outputs.typecheck }}
|
|
git_compatibility: ${{ steps.filter.outputs.git_compatibility }}
|
|
codex_index_heal_contract: ${{ steps.filter.outputs.codex_index_heal_contract }}
|
|
xterm_patch_sync: ${{ steps.filter.outputs.xterm_patch_sync }}
|
|
shell_contracts: ${{ steps.filter.outputs.shell_contracts }}
|
|
test: ${{ steps.filter.outputs.test }}
|
|
orcad_browser: ${{ steps.filter.outputs.orcad_browser }}
|
|
cross-version-wire: ${{ steps.filter.outputs.cross-version-wire }}
|
|
managed_hook_node18: ${{ steps.filter.outputs.managed_hook_node18 }}
|
|
package: ${{ steps.filter.outputs.package }}
|
|
package_windows: ${{ steps.filter.outputs.package_windows }}
|
|
e2e_should_run: ${{ steps.e2e_filter.outputs.should_run }}
|
|
test_files: ${{ steps.e2e_filter.outputs.test_files }}
|
|
ssh_source_changed: ${{ steps.e2e_filter.outputs.ssh_source_changed }}
|
|
native_ime_source_changed: ${{ steps.e2e_filter.outputs.native_ime_source_changed }}
|
|
wsl_source_changed: ${{ steps.e2e_filter.outputs.wsl_source_changed }}
|
|
steps:
|
|
- name: Checkout
|
|
uses: actions/checkout@v6
|
|
with:
|
|
# Why blob:none: full history is needed for the merge-base diff, but historical
|
|
# file contents are not. Blobs are ~89% of this repo's pack, and Git fetches the
|
|
# few this job actually reads on demand.
|
|
fetch-depth: 0
|
|
filter: blob:none
|
|
persist-credentials: false
|
|
|
|
- name: Classify changed paths
|
|
id: filter
|
|
env:
|
|
BASE_SHA: ${{ github.event.pull_request.base.sha }}
|
|
HEAD_SHA: ${{ github.event.pull_request.head.sha }}
|
|
run: |
|
|
set -euo pipefail
|
|
# Why --no-renames: name-only rename detection can report only the destination.
|
|
# A code file moved under docs/ must still expose its code-side deletion.
|
|
CHANGED="$(git diff --name-only --no-renames --diff-filter=ACDMR --merge-base "$BASE_SHA" "$HEAD_SHA")"
|
|
echo "Changed paths:"
|
|
printf '%s\n' "$CHANGED"
|
|
printf '%s\n' "$CHANGED" | node config/scripts/pr-code-change-scope.mjs | tee -a "$GITHUB_OUTPUT"
|
|
|
|
# Reuse the path-detector checkout instead of queuing another runner.
|
|
- name: Filter changed E2E specs
|
|
id: e2e_filter
|
|
if: github.event.pull_request.draft != true && steps.filter.outputs.should_run == 'true'
|
|
run: |
|
|
set -euo pipefail
|
|
BASE="${{ github.event.pull_request.base.sha }}"
|
|
HEAD="${{ github.event.pull_request.head.sha }}"
|
|
CHANGED="$(git diff --name-only --diff-filter=AMCR --merge-base "$BASE" "$HEAD")"
|
|
# Source routes are executable contracts so a test can prove exact
|
|
# authorities, exclusions, and sentinels without evaluating workflow shell.
|
|
TEST_FILES_JSON="$(printf '%s\n' "$CHANGED" | node config/scripts/pr-e2e-source-routing.mjs)"
|
|
echo "test_files=$TEST_FILES_JSON" >> "$GITHUB_OUTPUT"
|
|
# Why a separate signal: the Docker-SSH lane must trigger on SSH source, not on a
|
|
# spec name surviving in a route's list. Same routes, so the two cannot drift.
|
|
SSH_SOURCE_CHANGED="$(printf '%s\n' "$CHANGED" | node config/scripts/pr-e2e-source-routing.mjs --ssh-source)"
|
|
echo "ssh_source_changed=$SSH_SOURCE_CHANGED" >> "$GITHUB_OUTPUT"
|
|
echo "SSH source changed: $SSH_SOURCE_CHANGED"
|
|
# Why its own signal: the real-IME lane is a whole ibus session, not a spec, so it must
|
|
# trigger on IME source rather than on a spec name in some route's list.
|
|
NATIVE_IME_SOURCE_CHANGED="$(printf '%s\n' "$CHANGED" | node config/scripts/pr-e2e-source-routing.mjs --native-ime-source)"
|
|
echo "native_ime_source_changed=$NATIVE_IME_SOURCE_CHANGED" >> "$GITHUB_OUTPUT"
|
|
WSL_CHANGED="$(git diff --name-only --no-renames --diff-filter=ACDMR --merge-base "$BASE" "$HEAD")"
|
|
WSL_SOURCE_CHANGED="$(printf '%s\n' "$WSL_CHANGED" | node config/scripts/pr-e2e-source-routing.mjs --wsl-source)"
|
|
echo "wsl_source_changed=$WSL_SOURCE_CHANGED" >> "$GITHUB_OUTPUT"
|
|
echo "Native IME source changed: $NATIVE_IME_SOURCE_CHANGED"
|
|
SHOULD_RUN="$(printf '%s\n' "$CHANGED" | node config/scripts/pr-e2e-source-routing.mjs --reusable-workflow)"
|
|
if [ "$SHOULD_RUN" = true ]; then
|
|
echo "should_run=true" >> "$GITHUB_OUTPUT"
|
|
echo "Changed E2E specs: $TEST_FILES_JSON"
|
|
else
|
|
echo "should_run=false" >> "$GITHUB_OUTPUT"
|
|
echo "No specs requiring the reusable E2E workflow"
|
|
fi
|
|
|
|
static_analysis:
|
|
name: static analysis
|
|
needs: [code_paths]
|
|
if: needs.code_paths.outputs.static_analysis == 'true'
|
|
runs-on: ubuntu-latest
|
|
|
|
steps:
|
|
- name: Checkout
|
|
uses: actions/checkout@v6
|
|
with:
|
|
# Why blob:none: full history is needed for the merge-base diff, but historical
|
|
# file contents are not. Blobs are ~89% of this repo's pack, and Git fetches the
|
|
# few this job actually reads on demand.
|
|
fetch-depth: 0
|
|
filter: blob:none
|
|
persist-credentials: false
|
|
|
|
- uses: ./.github/actions/install-node-dependencies
|
|
with:
|
|
native-runtime: node
|
|
cache-dependency-path: |
|
|
pnpm-lock.yaml
|
|
mobile/pnpm-lock.yaml
|
|
|
|
- name: Lint
|
|
run: pnpm exec oxlint --format github
|
|
|
|
- name: Reject low-evidence patterns
|
|
run: pnpm run audit:anti-slop
|
|
|
|
- name: Enforce focused code-quality plugins
|
|
run: pnpm run audit:code-quality:native
|
|
|
|
- name: Enforce type-aware code-quality baseline
|
|
run: pnpm run audit:code-quality:type-aware
|
|
|
|
# Why: the changed-code gate lints mobile files too, and its type-aware pass
|
|
# resolves types from mobile/node_modules. Mobile is a separate pnpm project,
|
|
# so the root install above leaves it empty and every mobile type degrades to
|
|
# an `error` type — reported as phantom findings against the changed lines.
|
|
# Why no --ignore-scripts, unlike the root install: mobile's postinstall generates
|
|
# the gitignored terminal/mermaid webview engine modules that tracked source imports,
|
|
# and skipping it degrades those very types the step exists to resolve. The drift
|
|
# guard mirrors the root install so a stale mobile lockfile fails by name — mobile's
|
|
# lockfile carries patchedDependencies that a silent rewrite would drop.
|
|
- name: Install mobile dependencies
|
|
if: needs.code_paths.outputs.mobile_dependencies == 'true'
|
|
working-directory: mobile
|
|
run: |
|
|
pnpm install --frozen-lockfile
|
|
if [ "$(git -C "$GITHUB_WORKSPACE" rev-parse --is-inside-work-tree 2>/dev/null)" = true ]; then
|
|
git -C "$GITHUB_WORKSPACE" diff --exit-code -- \
|
|
mobile/package.json mobile/pnpm-lock.yaml mobile/pnpm-workspace.yaml
|
|
fi
|
|
|
|
- name: Enforce changed-code quality
|
|
run: pnpm run check:code-quality:changed -- "${{ github.event.pull_request.base.sha }}"
|
|
|
|
- name: Enforce React Doctor on changed lines
|
|
run: pnpm run check:react-doctor:changed -- "${{ github.event.pull_request.base.sha }}"
|
|
|
|
- name: Check Zustand selector fan-out budget
|
|
run: pnpm run check:zustand-selector-fanout
|
|
|
|
- name: Check reliability gate manifest
|
|
run: pnpm run check:reliability-gates
|
|
|
|
- name: Enforce dead design-system classes
|
|
run: pnpm run check:dead-classes
|
|
|
|
- name: Check VM runtime rollback compatibility
|
|
env:
|
|
BASE_SHA: ${{ github.event.pull_request.base.sha }}
|
|
HEAD_SHA: ${{ github.event.pull_request.head.sha }}
|
|
run: |
|
|
if git diff --quiet --merge-base "$BASE_SHA" "$HEAD_SHA" -- \
|
|
src/shared/ephemeral-vm-runtime-store.ts \
|
|
src/shared/ephemeral-vm-runtime-feature-store.ts \
|
|
src/shared/ephemeral-vm-runtime-rollback-projection.ts \
|
|
src/shared/ephemeral-vm-runtimes.ts \
|
|
src/shared/ephemeral-vm-recipes.ts \
|
|
src/shared/orca-yaml-hook-types.ts \
|
|
src/main/ephemeral-vm-runtime-service.ts \
|
|
src/main/ephemeral-vm-runtime-provisioning-persistence.ts \
|
|
src/main/ephemeral-vm-failed-start-cleanup.ts; then
|
|
echo "VM runtime persistence is unchanged."
|
|
exit 0
|
|
fi
|
|
node config/scripts/run-ephemeral-vm-runtime-store-rollback-repro.mjs \
|
|
config/scripts/ephemeral-vm-runtime-store-cross-version.test.ts
|
|
|
|
- name: Enforce max-lines ratchet
|
|
run: pnpm run check:max-lines-ratchet
|
|
|
|
- name: Enforce ts-nocheck ratchet
|
|
run: pnpm run check:ts-nocheck-ratchet
|
|
|
|
- name: Enforce runtime Electron-import ratchet
|
|
run: pnpm run check:runtime-electron-ratchet
|
|
|
|
# Why both: the ratchet proves nothing reachable from the runtime imports electron,
|
|
# which is a property of the import graph. This proves the Node artifact it enables
|
|
# actually boots, pairs, creates a worktree and round-trips a real PTY.
|
|
- name: Boot orcad and round-trip a terminal
|
|
run: pnpm run smoke:orcad-terminal
|
|
|
|
- name: Verify the generated RPC params catalog
|
|
run: pnpm run verify:rpc-params-catalog
|
|
|
|
- name: Verify bundled skill guides
|
|
run: pnpm run verify:bundled-skill-guides
|
|
|
|
- name: Verify skill freshness manifest
|
|
run: pnpm run verify:skill-bundle-manifest
|
|
|
|
- name: Verify localization catalog
|
|
run: pnpm run verify:localization-catalog
|
|
|
|
# Why: the renderer ships only the English entries i18next cannot rebuild
|
|
# from each call site's inline default, so the generated subset has to
|
|
# track en.json and those defaults.
|
|
- name: Verify runtime-required localization catalog
|
|
run: pnpm run verify:localization-runtime-catalog
|
|
|
|
# Why: extraction writes sorted evidence to an isolated temporary path,
|
|
# so feature PRs need one normalized AST pass rather than a three-OS matrix.
|
|
- name: Verify localization extraction
|
|
run: pnpm run verify:localization-extraction
|
|
|
|
- name: Verify localization coverage
|
|
run: pnpm run verify:localization-coverage
|
|
|
|
# Why: project-owned type declarations must live in .ts so tsc
|
|
# actually checks them. TypeScript's skipLibCheck: true (inherited
|
|
# from @electron-toolkit/tsconfig) silently widens unresolved names
|
|
# in .d.ts to `any`, which is how #1186 shipped a broken IPC signature
|
|
# past typecheck. See .github/CONTRIBUTING.md#type-declarations-prefer-ts-over-dts.
|
|
- name: Guard against project-owned .d.ts in preload/shared
|
|
run: |
|
|
matches=$(find src/preload src/shared -name '*.d.ts' 2>/dev/null || true)
|
|
if [ -n "$matches" ]; then
|
|
echo "::error::Project-owned .d.ts files are not allowed under src/preload or src/shared."
|
|
echo "Move type declarations into a .ts file so skipLibCheck does not hide errors."
|
|
echo "See .github/CONTRIBUTING.md#type-declarations-prefer-ts-over-dts."
|
|
echo "Found:"
|
|
echo "$matches"
|
|
exit 1
|
|
fi
|
|
|
|
- name: Check feature wall asset budget
|
|
run: pnpm check:feature-wall-assets
|
|
|
|
- name: Verify macOS entitlements
|
|
run: pnpm verify:macos-entitlements
|
|
|
|
root_directory_guard:
|
|
name: root directory guard
|
|
runs-on: ubuntu-latest
|
|
|
|
steps:
|
|
- name: Checkout
|
|
uses: actions/checkout@v6
|
|
with:
|
|
# Why blob:none: full history is needed for the merge-base diff, but historical
|
|
# file contents are not. Blobs are ~89% of this repo's pack, and Git fetches the
|
|
# few this job actually reads on demand.
|
|
fetch-depth: 0
|
|
filter: blob:none
|
|
persist-credentials: false
|
|
|
|
- name: Reject new root-level files and folders
|
|
env:
|
|
BASE_SHA: ${{ github.event.pull_request.base.sha }}
|
|
HEAD_SHA: ${{ github.event.pull_request.head.sha }}
|
|
run: node .github/scripts/check-root-directory-entries.mjs "$BASE_SHA" "$HEAD_SHA"
|
|
|
|
# Why here: the READMEs embed media owned by docs/site and resources/onboarding,
|
|
# and the classifier skips static_analysis for docs-only diffs. This job runs
|
|
# on every PR and needs no install.
|
|
- name: Check README local links
|
|
run: node config/scripts/check-readme-local-links.mjs
|
|
|
|
typecheck:
|
|
needs: [code_paths]
|
|
if: needs.code_paths.outputs.typecheck == 'true'
|
|
runs-on: ubuntu-latest
|
|
|
|
steps:
|
|
- name: Checkout
|
|
uses: actions/checkout@v6
|
|
with:
|
|
persist-credentials: false
|
|
|
|
- uses: ./.github/actions/install-node-dependencies
|
|
|
|
# Why: every project is `composite`, so tsc already writes a .tsbuildinfo that lets
|
|
# the next run skip unchanged files. Share one cache entry across commits while the
|
|
# PR base stays stable; actions/cache keeps the first successful graph and the
|
|
# compiler still invalidates stale files from its content hashes.
|
|
- name: Cache TypeScript incremental state
|
|
uses: actions/cache@v5
|
|
with:
|
|
path: config/*.tsbuildinfo
|
|
key: tsbuildinfo-${{ runner.os }}-${{ hashFiles('pnpm-lock.yaml', 'config/tsconfig*.json') }}-${{ github.event.pull_request.base.sha }}
|
|
restore-keys: |
|
|
tsbuildinfo-${{ runner.os }}-${{ hashFiles('pnpm-lock.yaml', 'config/tsconfig*.json') }}-
|
|
|
|
- run: pnpm run typecheck
|
|
|
|
git_compatibility:
|
|
name: Git compatibility
|
|
needs: [code_paths]
|
|
if: needs.code_paths.outputs.git_compatibility == 'true'
|
|
runs-on: ubuntu-latest
|
|
|
|
steps:
|
|
- name: Checkout
|
|
uses: actions/checkout@v6
|
|
with:
|
|
persist-credentials: false
|
|
|
|
- uses: ./.github/actions/install-node-dependencies
|
|
|
|
# Why: the 2.25.5 lane is a source build of a pinned tarball, so it produced the
|
|
# same binary on every PR for minutes of runner time. The key carries the version
|
|
# because that is the only input; the sha256 assertion below still guards the
|
|
# tarball on the miss path that actually builds. Only this PR's own later pushes
|
|
# can restore it — GitHub scopes a cache written from a pull_request run to that
|
|
# ref — so a first push always takes the build path below.
|
|
- name: Cache baseline Git build
|
|
uses: actions/cache@v5
|
|
with:
|
|
path: ~/.cache/orca-git-compat/git-2.25.5
|
|
key: git-compat-baseline-${{ runner.os }}-${{ runner.arch }}-2.25.5
|
|
|
|
# Why its own step: this is `make -j$(nproc)` on every core, and the lanes below
|
|
# spend their wall clock waiting on container starts, not on Git. Sharing a runner
|
|
# with the build stretched one ~1.5s boundary case past Vitest's 30s timeout, so
|
|
# the build has to finish before anything timed starts.
|
|
- name: Build the baseline Git binary
|
|
run: |
|
|
archive="$RUNNER_TEMP/git-2.25.5.tar.gz"
|
|
source="$HOME/.cache/orca-git-compat/git-2.25.5"
|
|
if [ -x "$source/git" ]; then
|
|
exit 0
|
|
fi
|
|
curl -fsSL https://www.kernel.org/pub/software/scm/git/git-2.25.5.tar.gz -o "$archive"
|
|
echo "41662c52fc16fec4963bfc41075e71f8ead6b5e386797eb6f9a1111ff95a8ddf $archive" \
|
|
| sha256sum --check
|
|
mkdir -p "$source"
|
|
tar -xzf "$archive" -C "$source" --strip-components=1
|
|
make -C "$source" -j"$(nproc)" \
|
|
NO_GETTEXT=YesPlease NO_TCLTK=YesPlease NO_PYTHON=YesPlease git
|
|
# Why: the linked binaries are what the next run needs; the objects that
|
|
# produced them are most of the tree and would bloat the cache entry.
|
|
find "$source" -name '*.o' -delete
|
|
|
|
- name: Verify Git binary compatibility matrix
|
|
run: |
|
|
specs=(
|
|
"alpine/git:edge-2.38.1|2.38.1"
|
|
"alpine/git:v2.49.1|2.49.1"
|
|
)
|
|
# Why pull up front: a lane's first `docker run` otherwise pulls its image
|
|
# while the sibling lane is mid-test, and that stall is charged to the test.
|
|
for spec in "${specs[@]}"; do
|
|
docker pull --quiet "${spec%%|*}"
|
|
done
|
|
|
|
pids=()
|
|
(
|
|
ORCA_GIT_COMPAT_BINARY="$HOME/.cache/orca-git-compat/git-2.25.5/git" \
|
|
ORCA_GIT_COMPAT_VERSION="2.25.5" \
|
|
pnpm exec vitest run --config config/vitest.config.ts \
|
|
src/shared/git-binary-compatibility.test.ts
|
|
) &
|
|
pids+=("$!")
|
|
|
|
for spec in "${specs[@]}"; do
|
|
(
|
|
image="${spec%%|*}"
|
|
version="${spec#*|}"
|
|
ORCA_GIT_COMPAT_IMAGE="$image" ORCA_GIT_COMPAT_VERSION="$version" \
|
|
pnpm exec vitest run --config config/vitest.config.ts \
|
|
src/shared/git-binary-compatibility.test.ts
|
|
) &
|
|
pids+=("$!")
|
|
done
|
|
|
|
status=0
|
|
for pid in "${pids[@]}"; do
|
|
wait "$pid" || status=1
|
|
done
|
|
exit "$status"
|
|
|
|
# Why this job: Orca's session index-heal depends on a Codex behavior — a
|
|
# `thread/read` of an unindexed rollout performs a read-repair that inserts the
|
|
# `threads` row. Every unit test drives a stub app-server and asserts only that the
|
|
# call did not error, so if Codex dropped the repair they would all stay green while
|
|
# the subsystem went inert. This runs the pinned real binary and fails when the
|
|
# repair stops happening. Pinned because the binary is the thing expected to drift.
|
|
codex_index_heal_contract:
|
|
name: Codex index-heal contract
|
|
needs: [code_paths]
|
|
if: needs.code_paths.outputs.codex_index_heal_contract == 'true'
|
|
runs-on: ubuntu-latest
|
|
env:
|
|
CODEX_CLI_VERSION: '0.150.1'
|
|
|
|
steps:
|
|
- name: Checkout
|
|
uses: actions/checkout@v6
|
|
with:
|
|
persist-credentials: false
|
|
|
|
- uses: ./.github/actions/install-node-dependencies
|
|
|
|
- name: Install pinned Codex CLI
|
|
run: |
|
|
set -euo pipefail
|
|
npm install --no-audit --no-fund --prefix "$RUNNER_TEMP/codex-cli" \
|
|
"@openai/codex@$CODEX_CLI_VERSION"
|
|
|
|
- name: Verify Codex index-heal contract
|
|
env:
|
|
# Why REQUIRED: without a binary the suite skips, and a job that skips
|
|
# reports success. This turns a failed or missing install into a red test
|
|
# instead of a green no-op.
|
|
ORCA_CODEX_CONTRACT_REQUIRED: '1'
|
|
ORCA_CODEX_CONTRACT_VERSION: ${{ env.CODEX_CLI_VERSION }}
|
|
run: |
|
|
set -euo pipefail
|
|
ORCA_CODEX_CONTRACT_BINARY="$RUNNER_TEMP/codex-cli/node_modules/.bin/codex" \
|
|
pnpm exec vitest run --config config/vitest.config.ts \
|
|
src/main/codex/codex-index-heal-binary-contract.test.ts
|
|
|
|
xterm_patch_sync:
|
|
name: xterm patch sync
|
|
needs: [code_paths]
|
|
if: needs.code_paths.outputs.xterm_patch_sync == 'true'
|
|
runs-on: ubuntu-latest
|
|
|
|
steps:
|
|
- name: Checkout
|
|
uses: actions/checkout@v6
|
|
with:
|
|
persist-credentials: false
|
|
|
|
- uses: ./.github/actions/install-node-dependencies
|
|
|
|
# Why: the check rebuilds every package in the manifest from a pinned upstream
|
|
# commit — @xterm/xterm and its three addons, each built twice (once unmodified to
|
|
# prove the toolchain still reproduces the published bundles, once patched). Caching
|
|
# the npm metadata and the shallow clone keeps the repeated cost to the builds
|
|
# themselves; the key is the manifest, so a commit, package or toolchain bump
|
|
# invalidates it.
|
|
- name: Restore upstream xterm build inputs
|
|
uses: actions/cache@v5
|
|
with:
|
|
path: |
|
|
~/.npm
|
|
${{ runner.temp }}/xterm-patch-build/upstream/.git
|
|
key: xterm-upstream-${{ hashFiles('config/patches/xterm-upstream.json') }}
|
|
|
|
- name: Verify xterm patches match the pinned upstream build
|
|
env:
|
|
WORK_DIR: ${{ runner.temp }}/xterm-patch-build
|
|
run: node config/scripts/regenerate-xterm-patches.mjs --check --work-dir="$WORK_DIR"
|
|
|
|
shell_contracts:
|
|
name: shell contracts
|
|
needs: [code_paths]
|
|
if: needs.code_paths.outputs.shell_contracts == 'true'
|
|
runs-on: ubuntu-latest
|
|
# Why: this job's cost is almost entirely package download, and a stalled mirror has
|
|
# no wall-clock bound of its own. A successful run finishes in ~4.5 minutes, so this
|
|
# is generous; it exists so a wedge fails the job instead of holding the whole run
|
|
# open for the 6h GitHub default — which also blocks `gh run rerun --failed`.
|
|
timeout-minutes: 15
|
|
env:
|
|
# Why: the suites below gate their live fish tests on the binary, which is
|
|
# right on a developer machine and wrong here — this job is a required check
|
|
# and its fish lane is the only end-to-end guard for #9993, so a skip would
|
|
# report green with nothing exercised. Turns those skips into failures.
|
|
ORCA_REQUIRE_FISH: '1'
|
|
|
|
steps:
|
|
- name: Checkout
|
|
uses: actions/checkout@v6
|
|
with:
|
|
persist-credentials: false
|
|
|
|
# Why fish: shell-ready.test.ts gates its live fish test on the binary being
|
|
# present, so without this the fish barrier is only covered by config-shape
|
|
# assertions and never actually exercised.
|
|
# Why release-4: DECSET 2031 arming lives in the fish 4.0 Rust tty_handoff, and
|
|
# fish-color-scheme-child-stdin.node-pty.test.ts (#9993) needs it. Noble ships
|
|
# 3.7, so the PPA is what makes that lane real.
|
|
- name: Install zsh and fish
|
|
run: |
|
|
# Why the update/PPA/fish steps are tolerant: a repo the runner image already
|
|
# ships can lack a Release file for this suite, and a failed add-apt-repository
|
|
# still leaves its list entry behind — either makes `apt-get update` exit
|
|
# non-zero and would red this required check over something unrelated to the
|
|
# PR. Every fish outcome is judged by the version gate below instead, so only
|
|
# the zsh install (which has no such gate) stays fatal here.
|
|
# Why retry only here: adding the PPA is the network-flaky step, and the
|
|
# version gate below is fatal, so a transient Launchpad blip would
|
|
# otherwise red a required check on PRs unrelated to shells.
|
|
# Why -n: add-apt-repository refreshes every configured repo on its own. With
|
|
# an update on each side of it this step refreshed them three times over, and
|
|
# the Azure archive mirror alone costs ~15-30s a pass. The PPA index is the
|
|
# only thing the repo list gains here, and the single update below fetches it.
|
|
# Why bound acquisition: measured on a *passing* run, this step spent 40s
|
|
# fetching 11.4 MB of index and then 2m17s fetching 8.9 MB of packages at
|
|
# 65 kB/s — it is dominated by download throughput, not by work. apt applies
|
|
# no wall-clock bound to a stalled mirror, so a slow Launchpad or archive
|
|
# host wedges the step for tens of minutes. This job is a required check, so
|
|
# a wedge holds the entire run open and blocks `gh run rerun --failed`.
|
|
# Bounded timeouts plus retries turn an unbounded hang into a fast, legible
|
|
# failure. Set in apt.conf.d rather than on each command line so the two
|
|
# invocations below stay exactly as pr-workflow-parallelism.test.mjs parses
|
|
# them. Retries are 1, not 3: a first attempt at these bounds already multiplied
|
|
# 30s x 3 retries across every index file into a ~15 minute stall on a dead
|
|
# mirror, which is worse than failing once and moving on.
|
|
sudo tee /etc/apt/apt.conf.d/99-orca-shell-contracts >/dev/null <<'APTCONF'
|
|
Acquire::http::Timeout "15";
|
|
Acquire::https::Timeout "15";
|
|
Acquire::Retries "1";
|
|
APTCONF
|
|
for attempt in 1 2 3; do
|
|
sudo add-apt-repository -y -n ppa:fish-shell/release-4 && break
|
|
echo "add-apt-repository attempt ${attempt} failed; retrying" >&2
|
|
sudo add-apt-repository -y -n -r ppa:fish-shell/release-4 || true
|
|
sleep 5
|
|
done
|
|
# Why a wall-clock bound on each command: apt's Acquire timeouts are per-connection,
|
|
# so a dead mirror costs timeout x retries x every index file. Measured: the archive
|
|
# mirror stalled with zero bytes and the step burned 14m26s before the job bound
|
|
# killed it. `timeout` is the only thing that bounds the command as a whole.
|
|
# The update is already tolerant by design (see above), so bounding it just caps
|
|
# what a dead mirror can cost before the install runs against whatever index exists.
|
|
timeout 120 sudo apt-get update || true
|
|
# Why both shells on one line: pr-workflow-parallelism.test.mjs parses only the
|
|
# first install command in this step to prove the lane really installs them.
|
|
timeout 300 sudo apt-get install -y zsh fish
|
|
|
|
# Separate from the install so the failure names the contract, not an apt error.
|
|
# ORCA_REQUIRE_FISH re-checks this at test time; this step just fails in seconds
|
|
# instead of after a full dependency install.
|
|
- name: Require fish 4+
|
|
run: |
|
|
version="$(fish --version 2>/dev/null || true)"
|
|
major="${version##*version }"
|
|
major="${major%%.*}"
|
|
case "$major" in '' | *[!0-9]*) major=0 ;; esac
|
|
echo "${version:-<fish not installed>}"
|
|
if [ "$major" -lt 4 ]; then
|
|
echo "::error::shell contracts needs fish 4+ (DECSET 2031 arming, #9993) but got '${version:-none}'. Fix the ppa:fish-shell/release-4 install rather than letting the fish lane skip." >&2
|
|
exit 1
|
|
fi
|
|
|
|
- uses: ./.github/actions/install-node-dependencies
|
|
with:
|
|
native-runtime: node
|
|
|
|
- name: Test real shell contracts
|
|
run: |
|
|
pnpm exec vitest run --config config/vitest.config.ts --maxWorkers=1 \
|
|
src/main/daemon/repro-13767-shell-ready-marker-lost-to-exec.test.ts \
|
|
src/main/daemon/shell-ready.test.ts \
|
|
src/main/daemon/node-pty-fd-leak.test.ts \
|
|
src/main/providers/local-pty-shell-ready-zsh-launch-environment.test.ts \
|
|
src/main/providers/__tests__/shell-ready-framework-example.test.ts \
|
|
src/main/pty/codex-shell-launch-preflight.test.ts \
|
|
src/main/pty/omp-shell-wrapper-alias-safety.test.ts \
|
|
src/main/pty/omp-shell-wrapper.node-pty.test.ts \
|
|
src/main/shell-startup-feature-channel.test.ts \
|
|
src/main/terminal-history-fish-session.node-pty.test.ts \
|
|
src/main/zsh-scoped-histfile.live-shell.test.ts \
|
|
src/main/zsh-startup-hook-user-config-equivalence.live-shell.test.ts \
|
|
src/main/zsh-wrapper-version-mismatch.live-shell.test.ts \
|
|
src/renderer/src/components/terminal-pane/fish-color-scheme-child-stdin.node-pty.test.ts \
|
|
src/shared/fish-query-reply-child-stdin.node-pty.test.ts \
|
|
src/shared/pty-reply-echo-shapes.node-pty.test.ts \
|
|
src/shared/startup-shell-portability.live-shell.test.ts \
|
|
src/shared/posix-command-path-lookup.test.ts
|
|
|
|
# Cache-key input changes would otherwise make every shard compile the same
|
|
# native addon concurrently. Prime the supported Node ABI before the matrix fans out.
|
|
test_native_cache:
|
|
name: prepare test native cache node 24
|
|
needs: [code_paths]
|
|
if: needs.code_paths.outputs.native_cache_changed == 'true'
|
|
runs-on: ubuntu-latest
|
|
|
|
steps:
|
|
- name: Checkout
|
|
uses: actions/checkout@v6
|
|
with:
|
|
persist-credentials: false
|
|
|
|
- uses: ./.github/actions/install-node-dependencies
|
|
with:
|
|
native-runtime: node
|
|
node-version: '24'
|
|
|
|
test:
|
|
needs: [code_paths, test_native_cache]
|
|
if: >-
|
|
always() &&
|
|
needs.code_paths.outputs.test == 'true' &&
|
|
(needs.test_native_cache.result == 'success' || needs.test_native_cache.result == 'skipped')
|
|
uses: ./.github/workflows/unit-tests.yml
|
|
with:
|
|
node_versions: '["24"]'
|
|
|
|
# Why a separate job: the test needs a real Chrome, and the sharded `test` matrix
|
|
# would pay for it on every shard to run one file in whichever shard it landed in.
|
|
orcad_browser:
|
|
name: orcad browser provider
|
|
needs: [code_paths]
|
|
if: needs.code_paths.outputs.orcad_browser == 'true'
|
|
runs-on: ubuntu-latest
|
|
|
|
steps:
|
|
- name: Checkout
|
|
uses: actions/checkout@v6
|
|
with:
|
|
persist-credentials: false
|
|
|
|
# Why no native-runtime: the provider drives the prebuilt agent-browser binary
|
|
# shipped in node_modules and never touches node-pty.
|
|
- uses: ./.github/actions/install-node-dependencies
|
|
|
|
# Why the runner's Google Chrome and not its chromium: Ubuntu 24.04 only ships an
|
|
# AppArmor userns profile for the Chrome .deb, so chromium dies with "No usable
|
|
# sandbox" and the provider passes no --no-sandbox. Why fail instead of skip: an
|
|
# unset ORCA_BROWSER_EXECUTABLE is exactly how this test went uncovered for so long.
|
|
- name: Resolve Chrome for the browser provider
|
|
run: |
|
|
set -euo pipefail
|
|
chrome="$(command -v google-chrome || command -v google-chrome-stable || true)"
|
|
if [ -z "$chrome" ]; then
|
|
echo "::error::No Google Chrome on the runner; the browser provider test would silently skip."
|
|
exit 1
|
|
fi
|
|
"$chrome" --version
|
|
echo "ORCA_BROWSER_EXECUTABLE=$chrome" >> "$GITHUB_ENV"
|
|
|
|
- name: Test external Chromium browser provider
|
|
run: |
|
|
pnpm exec vitest run --config config/vitest.config.ts \
|
|
src/main/orcad/external-chromium-browser-process.integration.test.ts
|
|
|
|
cross-version-wire:
|
|
name: cross-version wire compatibility
|
|
needs: [code_paths]
|
|
if: needs.code_paths.outputs.cross-version-wire == 'true'
|
|
runs-on: ubuntu-latest
|
|
|
|
steps:
|
|
# Why fetch-depth 0: the harness extracts the newest release tag to skew
|
|
# current code against it. The default shallow clone has no tags, which is
|
|
# why this cannot ride along in the sharded `test` job.
|
|
- name: Checkout
|
|
uses: actions/checkout@v6
|
|
with:
|
|
# Why blob:none: full history is needed for the merge-base diff, but historical
|
|
# file contents are not. Blobs are ~89% of this repo's pack, and Git fetches the
|
|
# few this job actually reads on demand.
|
|
fetch-depth: 0
|
|
filter: blob:none
|
|
persist-credentials: false
|
|
|
|
- uses: ./.github/actions/install-node-dependencies
|
|
with:
|
|
native-runtime: node
|
|
|
|
# A path filter that matches nothing exits 1 ("No test files found"), so this
|
|
# lane cannot report success while running zero tests.
|
|
- name: Old/new client and server compatibility journeys
|
|
run: >-
|
|
pnpm exec vitest run --config config/vitest.config.ts
|
|
tests/e2e/cross-version-wire/release-checkout.unit.test.ts
|
|
tests/e2e/cross-version-wire/cross-version-browser-placement.unit.test.ts
|
|
tests/e2e/cross-version-wire/cross-version-terminal-wire.unit.test.ts
|
|
tests/e2e/cross-version-wire/reported-lossy-initial-snapshot.unit.test.ts
|
|
tests/e2e/cross-version-wire/cross-version-agent-session-wire.unit.test.ts
|
|
|
|
managed_hook_node18:
|
|
name: managed hooks on Node 18
|
|
needs: [code_paths]
|
|
if: needs.code_paths.outputs.managed_hook_node18 == 'true'
|
|
runs-on: ubuntu-latest
|
|
|
|
steps:
|
|
- name: Checkout
|
|
uses: actions/checkout@v6
|
|
with:
|
|
persist-credentials: false
|
|
|
|
- uses: ./.github/actions/install-node-dependencies
|
|
|
|
- name: Build relay companions
|
|
run: pnpm run build:relay
|
|
|
|
- name: Setup Node 18 runtime
|
|
uses: actions/setup-node@v6
|
|
with:
|
|
node-version: '18'
|
|
|
|
- name: Smoke managed-hook companions
|
|
run: node config/scripts/smoke-managed-hook-runtime-node18.mjs
|
|
|
|
package:
|
|
name: package
|
|
needs: [code_paths]
|
|
if: needs.code_paths.outputs.package == 'true'
|
|
runs-on: ubuntu-latest
|
|
# Let the serial Docker gates reach their own deadlines and report cleanup failures.
|
|
timeout-minutes: 90
|
|
|
|
steps:
|
|
- name: Checkout
|
|
uses: actions/checkout@v6
|
|
with:
|
|
persist-credentials: false
|
|
|
|
- name: Cache electron-builder downloads
|
|
uses: actions/cache@v5
|
|
with:
|
|
path: ~/.cache/electron-builder
|
|
key: electron-builder-linux-${{ hashFiles('pnpm-lock.yaml') }}
|
|
restore-keys: |
|
|
electron-builder-linux-
|
|
|
|
- uses: ./.github/actions/install-node-dependencies
|
|
with:
|
|
native-runtime: electron
|
|
|
|
# Why --no-file-parallelism: every file here launches a full Electron stack twice, and each
|
|
# probe carries its own in-process deadline. Four at once on a 4-vCPU runner starve each other
|
|
# past those deadlines; serial, every probe owns the runner.
|
|
- name: Test Linux Electron lifecycle boundary
|
|
run: >-
|
|
xvfb-run --auto-servernum pnpm exec vitest run --config config/vitest.config.ts
|
|
--no-file-parallelism
|
|
src/main/browser/browser-client-page-renderer-lifecycle.electron.test.ts
|
|
src/main/browser/browser-route-tcp-egress.electron.test.ts
|
|
src/main/browser/browser-route-webrtc-egress.electron.test.ts
|
|
src/main/browser/browser-route-h3-egress.electron.test.ts
|
|
src/main/browser/browser-route-dns-prefetch.electron.test.ts
|
|
|
|
- name: Build package inputs
|
|
run: |
|
|
status=0
|
|
pnpm run build:cli || status=1
|
|
|
|
scripts=(build:relay build:electron-vite:parallel)
|
|
pids=()
|
|
for script in "${scripts[@]}"; do
|
|
pnpm run "$script" &
|
|
pids+=("$!")
|
|
done
|
|
|
|
for pid in "${pids[@]}"; do
|
|
wait "$pid" || status=1
|
|
done
|
|
exit "$status"
|
|
|
|
- name: Project web client from renderer build
|
|
run: pnpm run build:web-from-renderer
|
|
|
|
- name: Build native components
|
|
run: pnpm run build:native
|
|
|
|
- name: Install Linux package tooling
|
|
run: sudo apt-get update && sudo apt-get install -y cpio rpm
|
|
|
|
- name: Package unpacked app
|
|
env:
|
|
ORCA_REUSE_PREPARED_NATIVE_RUNTIME: '1'
|
|
# PR artifacts are only inspected locally; gzip avoids release-size xz compression.
|
|
run: >-
|
|
pnpm exec electron-builder --config config/electron-builder.config.cjs
|
|
--linux AppImage deb rpm --x64 --publish never
|
|
--config.deb.compression=gz --config.rpm.compression=gzip
|
|
|
|
- name: Verify root-package marker payloads
|
|
run: |
|
|
set -euo pipefail
|
|
version="$(node -p "require('./package.json').version")"
|
|
deb="dist/orca-ide_${version}_amd64.deb"
|
|
rpm="dist/orca-ide-${version}.x86_64.rpm"
|
|
test -s "$deb"
|
|
test -s "$rpm"
|
|
deb_marker="$(dpkg-deb --fsys-tarfile "$deb" | tar -xOf - ./opt/Orca/resources/package-type)"
|
|
rpm_marker="$(rpm2cpio "$rpm" | cpio --quiet --extract --to-stdout ./opt/Orca/resources/package-type)"
|
|
[[ "$deb_marker" == deb ]] || { echo "Expected deb marker, got: $deb_marker"; exit 1; }
|
|
[[ "$rpm_marker" == rpm ]] || { echo "Expected rpm marker, got: $rpm_marker"; exit 1; }
|
|
|
|
- name: Verify headless serve signal shutdown
|
|
run: >-
|
|
node config/scripts/run-headless-serve-shutdown-docker.mjs
|
|
--appimage dist/orca-linux.AppImage --all-entrypoints
|
|
|
|
# A default container reproduces the hostile AppImage launch environment.
|
|
- name: Verify Linux CLI launch contract
|
|
run: node config/scripts/run-linux-cli-launch-contract-docker.mjs --appimage dist/orca-linux.AppImage
|
|
|
|
- name: Smoke packaged CLI
|
|
run: node config/scripts/smoke-packaged-cli.mjs --app-dir=dist/linux-unpacked
|
|
|
|
- name: Smoke packaged hang watchdog worker
|
|
run: xvfb-run --auto-servernum node config/scripts/smoke-packaged-hang-watchdog-worker.mjs --app-dir=dist/linux-unpacked
|
|
|
|
package_windows:
|
|
name: package (windows)
|
|
needs: [code_paths]
|
|
if: needs.code_paths.outputs.package_windows == 'true'
|
|
runs-on: windows-2022
|
|
timeout-minutes: 30
|
|
|
|
steps:
|
|
- name: Checkout
|
|
uses: actions/checkout@v6
|
|
with:
|
|
persist-credentials: false
|
|
|
|
- name: Cache electron-builder downloads
|
|
uses: actions/cache@v5
|
|
with:
|
|
path: |
|
|
~\AppData\Local\electron\Cache
|
|
~\AppData\Local\electron-builder\Cache
|
|
key: electron-builder-windows-${{ hashFiles('pnpm-lock.yaml') }}
|
|
restore-keys: |
|
|
electron-builder-windows-
|
|
|
|
# Why persist-native-cache false: this job later rebuilds the same path for
|
|
# Electron. A post-job save would store the Electron ABI under the Node key.
|
|
- uses: ./.github/actions/install-node-dependencies
|
|
id: deps
|
|
with:
|
|
native-runtime: node
|
|
persist-native-cache: 'false'
|
|
|
|
- name: Save compiled Node native modules
|
|
if: steps.deps.outputs.native-cache-hit != 'true'
|
|
uses: actions/cache/save@v5
|
|
with:
|
|
path: |
|
|
node_modules/.pnpm/node-pty@*/node_modules/node-pty/build
|
|
native/windows-registry/build
|
|
node_modules/.pnpm/@vscode+windows-process-tre*/node_modules/@vscode/windows-process-tree/build
|
|
key: native-modules-${{ runner.os }}-${{ steps.deps.outputs.native-cache-scope }}-${{ runner.arch }}-node-node${{ steps.deps.outputs.node-version }}-${{ hashFiles('pnpm-lock.yaml', '.github/actions/install-node-dependencies/action.yml', 'config/scripts/ensure-native-runtime.mjs', 'config/scripts/rebuild-native-deps.mjs', 'config/patches/node-pty@1.1.0.patch', 'config/patches/@vscode__windows-process-tree@0.8.0.patch', 'native/windows-registry/src/addon.cc', 'native/windows-registry/binding.gyp', 'native/windows-registry/package.json') }}
|
|
|
|
# vitest runs here directly rather than through `pnpm test`, so the addon
|
|
# assertions only hold once install-node-dependencies has rebuilt natives.
|
|
- name: Test Windows-specific boundaries
|
|
run: >-
|
|
pnpm exec vitest run --config config/vitest.config.ts
|
|
config/scripts/rebuild-native-deps.test.mjs
|
|
config/scripts/rebuild-native-deps-windows-process-tree.test.mjs
|
|
config/scripts/rebuild-native-deps-node-pty.test.mjs
|
|
config/scripts/ensure-native-runtime-job-ownership.test.mjs
|
|
config/scripts/verify-packaged-node-pty-job-ownership.test.mjs
|
|
config/scripts/windows-pe-machine.test.mjs
|
|
config/scripts/script-module-dependencies.test.mjs
|
|
src/main/windows-registry-addon.test.ts
|
|
config/scripts/windows-process-tree-gyp-path.test.mjs
|
|
config/scripts/windows-process-tree-gyp-rebuild.test.mjs
|
|
config/scripts/package-electron-runtime-contract.test.mjs
|
|
config/scripts/electron-builder-runtime-resources.test.mjs
|
|
src/main/browser/browser-client-page-renderer-lifecycle.electron.test.ts
|
|
src/main/browser/browser-route-tcp-egress.electron.test.ts
|
|
src/main/browser/browser-route-webrtc-egress.electron.test.ts
|
|
src/main/browser/browser-route-h3-egress.electron.test.ts
|
|
src/main/browser/browser-route-dns-prefetch.electron.test.ts
|
|
src/main/providers/windows-conpty-wide-char-duplication.node-pty.test.ts
|
|
src/main/providers/pty-repaint-wide-char-buffer.node-pty.test.ts
|
|
src/shared/child-process/windows-command-line.win32.test.ts
|
|
src/shared/child-process/windows-cmd-shim-resolution.test.ts
|
|
src/shared/child-process/windows-cmd-shim-resolution.win32.test.ts
|
|
src/main/agent-hooks/windows-hook-payload-delivery.test.ts
|
|
src/main/agent-hooks/windows-direct-cmd-hook-command.test.ts
|
|
src/main/codex/windows-hook-command.test.ts
|
|
src/main/codex/windows-hook-upgrade.test.ts
|
|
src/main/windows/windows-pty-job.win32.test.ts
|
|
src/main/windows/windows-msys-job.win32.test.ts
|
|
src/main/windows/windows-host-job.win32.test.ts
|
|
src/main/windows/windows-process-tree-command-line-patch.test.ts
|
|
src/main/windows/windows-process-table-native-addon.win32.test.ts
|
|
src/main/windows-live-tree-kill.win32.test.ts
|
|
src/main/wsl/wsl-runner.test.ts
|
|
src/main/wsl/wsl-guest-environment.test.ts
|
|
src/main/wsl/wsl-invocation-boundary.test.ts
|
|
src/main/wsl/wsl-executable-path.win32.test.ts
|
|
src/main/wsl/wsl-w1-w3-contract.test.ts
|
|
src/shared/source-scan/source-tree-scan.test.ts
|
|
src/main/cli/wsl-cli-powershell-boundary.test.ts
|
|
src/main/computer/desktop-script-runtime-host.win32.test.ts
|
|
src/main/cursor/hook-service.test.ts
|
|
src/main/orca-profiles/profile-index-store.test.ts
|
|
src/main/startup/windows-install-dir-acl-repair.win32.test.ts
|
|
src/main/runtime/repo-worktree-admin-fingerprint.test.ts
|
|
src/main/runtime/worktree-scan-admin-fingerprint-gate.test.ts
|
|
src/shared/secure-file-fsync-flags.test.ts
|
|
src/shared/secure-path-windows-acl.win32.test.ts
|
|
src/main/runtime/unreadable-secret-store-preservation.win32.test.ts
|
|
src/main/ipc/pty-codex-account-attribution.test.ts
|
|
src/main/ipc/pty-spawn-env-codex-resume-provenance.test.ts
|
|
src/relay/windows-port-scan.win32.test.ts
|
|
|
|
# Why the :parallel variant: identical to build:release except the three
|
|
# electron-vite targets overlap instead of running back to back. The Linux package
|
|
# job already packages and smoke-tests an AppImage built that way.
|
|
- name: Cache Windows CLI launcher
|
|
uses: actions/cache@v5
|
|
with:
|
|
path: native/windows-cli-launcher/.build
|
|
key: windows-cli-launcher-${{ runner.os }}-${{ runner.arch }}-${{ hashFiles('native/windows-cli-launcher/**', 'config/scripts/build-windows-cli-launcher.mjs') }}
|
|
|
|
- name: Build package inputs
|
|
env:
|
|
ORCA_REUSE_WINDOWS_CLI_LAUNCHER: '1'
|
|
run: pnpm run build:release:parallel
|
|
|
|
- name: Restore compiled Electron native modules
|
|
uses: actions/cache@v5
|
|
with:
|
|
path: |
|
|
node_modules/.pnpm/node-pty@*/node_modules/node-pty/build
|
|
native/windows-registry/build
|
|
node_modules/.pnpm/@vscode+windows-process-tre*/node_modules/@vscode/windows-process-tree/build
|
|
key: native-modules-${{ runner.os }}-${{ steps.deps.outputs.native-cache-scope }}-${{ runner.arch }}-electron-node${{ steps.deps.outputs.node-version }}-${{ hashFiles('pnpm-lock.yaml', '.github/actions/install-node-dependencies/action.yml', 'config/scripts/ensure-native-runtime.mjs', 'config/scripts/rebuild-native-deps.mjs', 'config/patches/node-pty@1.1.0.patch', 'config/patches/@vscode__windows-process-tree@0.8.0.patch', 'native/windows-registry/src/addon.cc', 'native/windows-registry/binding.gyp', 'native/windows-registry/package.json') }}
|
|
|
|
- name: Prepare Electron native runtime
|
|
run: node config/scripts/ensure-native-runtime.mjs --runtime=electron
|
|
|
|
- name: Package unpacked app
|
|
env:
|
|
ORCA_REUSE_PREPARED_NATIVE_RUNTIME: '1'
|
|
run: pnpm exec electron-builder --config config/electron-builder.config.cjs --dir
|
|
|
|
- name: Smoke packaged Windows PTY native capability
|
|
run: pnpm run smoke:windows-pty-native-capability -- --exe=dist/win-unpacked/Orca.exe
|
|
|
|
- name: Smoke packaged CLI
|
|
run: node config/scripts/smoke-packaged-cli.mjs --app-dir=dist/win-unpacked
|
|
|
|
e2e:
|
|
name: e2e
|
|
needs: code_paths
|
|
if: needs.code_paths.outputs.e2e_should_run == 'true'
|
|
# Why: reusable e2e.yml only checkouts, builds, and uploads artifacts.
|
|
permissions:
|
|
contents: read
|
|
uses: ./.github/workflows/e2e.yml
|
|
with:
|
|
# The synthetic pull-request merge ref can disappear while this reusable
|
|
# workflow is queued. The head SHA is immutable and works for every PR.
|
|
ref: ${{ github.event.pull_request.head.sha }}
|
|
test_files: ${{ needs.code_paths.outputs.test_files }}
|
|
ssh_source_changed: ${{ needs.code_paths.outputs.ssh_source_changed }}
|
|
|
|
# Why this is not in verify's needs: it is the first PR-gate run of a harness whose reliability
|
|
# is only known from nightly main runs (20/20 green, 2026-08-09..2026-08-29, p50 3m25s). It
|
|
# reports a red X on the PR without blocking, exactly like `e2e` above. Deliberately no
|
|
# continue-on-error: that renders the check green and hides the signal it exists to give. To
|
|
# make it blocking, add it to verify.needs, add TERMINAL_IME_NATIVE to the env below, and
|
|
# require `success || skipped` outside the strict loop — see the note on `e2e`.
|
|
terminal_ime_native:
|
|
name: real IME
|
|
needs: code_paths
|
|
if: needs.code_paths.outputs.native_ime_source_changed == 'true'
|
|
# Why: the reusable workflow only checks out, builds, and uploads artifacts.
|
|
permissions:
|
|
contents: read
|
|
uses: ./.github/workflows/terminal-ime-e2e.yml
|
|
|
|
windows_wsl:
|
|
name: real WSL terminal
|
|
needs: code_paths
|
|
if: needs.code_paths.outputs.wsl_source_changed == 'true'
|
|
permissions:
|
|
contents: read
|
|
uses: ./.github/workflows/windows-wsl-e2e.yml
|
|
with:
|
|
ref: ${{ github.event.pull_request.head.sha }}
|
|
|
|
verify:
|
|
if: always()
|
|
needs:
|
|
- code_paths
|
|
- static_analysis
|
|
- root_directory_guard
|
|
- typecheck
|
|
- git_compatibility
|
|
- codex_index_heal_contract
|
|
- xterm_patch_sync
|
|
- shell_contracts
|
|
- test
|
|
- orcad_browser
|
|
- cross-version-wire
|
|
- managed_hook_node18
|
|
- package
|
|
- package_windows
|
|
runs-on: ubuntu-latest
|
|
|
|
steps:
|
|
# Why: e2e is deliberately absent from needs. The suite is currently red on
|
|
# main (every scheduled run), so gating merges on it would block any PR that
|
|
# touches tests/e2e/** — including the ones fixing the suite. Until it is
|
|
# green the job runs and reports for E2E-path PRs without blocking. To flip
|
|
# it on: add `e2e` to needs, add E2E to the env below, and require
|
|
# `"$E2E" = success || skipped` after the loop — skipped is the normal
|
|
# result for a path-filtered job and must keep passing, so it has to be
|
|
# checked outside the loop or it would excuse the jobs above.
|
|
- name: Require successful checks
|
|
env:
|
|
CODE_PATHS: ${{ needs.code_paths.result }}
|
|
SHOULD_RUN: ${{ needs.code_paths.outputs.should_run }}
|
|
STATIC_ANALYSIS: ${{ needs.static_analysis.result }}
|
|
STATIC_ANALYSIS_SHOULD_RUN: ${{ needs.code_paths.outputs.static_analysis }}
|
|
ROOT_DIRECTORY_GUARD: ${{ needs.root_directory_guard.result }}
|
|
TYPECHECK: ${{ needs.typecheck.result }}
|
|
TYPECHECK_SHOULD_RUN: ${{ needs.code_paths.outputs.typecheck }}
|
|
GIT_COMPATIBILITY: ${{ needs.git_compatibility.result }}
|
|
GIT_COMPATIBILITY_SHOULD_RUN: ${{ needs.code_paths.outputs.git_compatibility }}
|
|
CODEX_INDEX_HEAL_CONTRACT: ${{ needs.codex_index_heal_contract.result }}
|
|
CODEX_INDEX_HEAL_CONTRACT_SHOULD_RUN: ${{ needs.code_paths.outputs.codex_index_heal_contract }}
|
|
XTERM_PATCH_SYNC: ${{ needs.xterm_patch_sync.result }}
|
|
XTERM_PATCH_SYNC_SHOULD_RUN: ${{ needs.code_paths.outputs.xterm_patch_sync }}
|
|
SHELL_CONTRACTS: ${{ needs.shell_contracts.result }}
|
|
SHELL_CONTRACTS_SHOULD_RUN: ${{ needs.code_paths.outputs.shell_contracts }}
|
|
TEST: ${{ needs.test.result }}
|
|
TEST_SHOULD_RUN: ${{ needs.code_paths.outputs.test }}
|
|
ORCAD_BROWSER: ${{ needs.orcad_browser.result }}
|
|
ORCAD_BROWSER_SHOULD_RUN: ${{ needs.code_paths.outputs.orcad_browser }}
|
|
CROSS_VERSION_WIRE: ${{ needs.cross-version-wire.result }}
|
|
CROSS_VERSION_WIRE_SHOULD_RUN: ${{ needs.code_paths.outputs.cross-version-wire }}
|
|
MANAGED_HOOK_NODE18: ${{ needs.managed_hook_node18.result }}
|
|
MANAGED_HOOK_NODE18_SHOULD_RUN: ${{ needs.code_paths.outputs.managed_hook_node18 }}
|
|
PACKAGE: ${{ needs.package.result }}
|
|
PACKAGE_SHOULD_RUN: ${{ needs.code_paths.outputs.package }}
|
|
PACKAGE_WINDOWS: ${{ needs.package_windows.result }}
|
|
PACKAGE_WINDOWS_SHOULD_RUN: ${{ needs.code_paths.outputs.package_windows }}
|
|
run: |
|
|
if [ "$CODE_PATHS" != "success" ]; then
|
|
exit 1
|
|
fi
|
|
if [ "$ROOT_DIRECTORY_GUARD" != "success" ]; then
|
|
exit 1
|
|
fi
|
|
if [ "$SHOULD_RUN" != "true" ]; then
|
|
echo "Docs-only change; expensive PR checks skipped."
|
|
fi
|
|
failed=0
|
|
check_job() {
|
|
local name="$1" result="$2" should="$3"
|
|
if [ "$should" = "true" ]; then
|
|
if [ "$result" != "success" ]; then
|
|
echo "$name: expected success, got $result"
|
|
failed=1
|
|
fi
|
|
else
|
|
if [ "$result" != "skipped" ]; then
|
|
echo "$name: expected skipped, got $result"
|
|
failed=1
|
|
fi
|
|
fi
|
|
}
|
|
# Require success when the PR has code-relevant changes
|
|
check_job static_analysis "$STATIC_ANALYSIS" "$STATIC_ANALYSIS_SHOULD_RUN"
|
|
check_job typecheck "$TYPECHECK" "$TYPECHECK_SHOULD_RUN"
|
|
check_job git_compatibility "$GIT_COMPATIBILITY" "$GIT_COMPATIBILITY_SHOULD_RUN"
|
|
check_job codex_index_heal_contract "$CODEX_INDEX_HEAL_CONTRACT" "$CODEX_INDEX_HEAL_CONTRACT_SHOULD_RUN"
|
|
check_job xterm_patch_sync "$XTERM_PATCH_SYNC" "$XTERM_PATCH_SYNC_SHOULD_RUN"
|
|
check_job shell_contracts "$SHELL_CONTRACTS" "$SHELL_CONTRACTS_SHOULD_RUN"
|
|
check_job test "$TEST" "$TEST_SHOULD_RUN"
|
|
check_job orcad_browser "$ORCAD_BROWSER" "$ORCAD_BROWSER_SHOULD_RUN"
|
|
check_job cross-version-wire "$CROSS_VERSION_WIRE" "$CROSS_VERSION_WIRE_SHOULD_RUN"
|
|
check_job managed_hook_node18 "$MANAGED_HOOK_NODE18" "$MANAGED_HOOK_NODE18_SHOULD_RUN"
|
|
check_job package "$PACKAGE" "$PACKAGE_SHOULD_RUN"
|
|
check_job package_windows "$PACKAGE_WINDOWS" "$PACKAGE_WINDOWS_SHOULD_RUN"
|
|
exit "$failed"
|