apexe 0.8.0

Outside-In CLI-to-Agent Bridge
name: CI

permissions:
  contents: read

on:
  push:
    branches: ["main"]
  pull_request:
    branches: ["main"]

jobs:
  test:
    name: Test on Rust ${{ matrix.rust }}
    runs-on: ubuntu-latest
    strategy:
      fail-fast: false
      matrix:
        rust: ["stable"]

    steps:
      - uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683 # v4.2.2

      # dtolnay/rust-toolchain@stable tracks a rolling branch rather than
      # tagged releases; pinned to the branch HEAD at the time this was added.
      - name: Install Rust toolchain
        uses: dtolnay/rust-toolchain@4cda84d5c5c54efe2404f9d843567869ab1699d4 # stable
        with:
          toolchain: ${{ matrix.rust }}
          components: rustfmt, clippy

      - name: Cache cargo registry & build
        uses: actions/cache@5a3ec84eff668545956fd18022155c47e93e2684 # v4.2.3
        with:
          path: |
            ~/.cargo/registry
            ~/.cargo/git
            target
          key: ${{ runner.os }}-cargo-${{ hashFiles('**/Cargo.lock') }}
          restore-keys: |
            ${{ runner.os }}-cargo-

      - name: Install apdev-rs
        run: cargo install apdev-rs
        continue-on-error: true

      - name: Check characters
        run: apdev-rs check-chars src/
        continue-on-error: true

      - name: Check formatting
        run: cargo fmt --all -- --check

      - name: Lint with Clippy
        run: cargo clippy --all-targets --all-features -- -D warnings

      - name: Build
        run: cargo build --all-features

      - name: Run tests
        # The corpus-dependent tests skip here: this job deliberately does not
        # fetch it, so the other ~990 stay green whatever happens upstream.
        run: cargo test --all-features

  corpus:
    name: Tests against the cli-permissions corpus
    runs-on: ubuntu-latest
    # apexe ships no overlays. The entries live in a separate repository, and
    # roughly twenty tests assert things about real ones — conflicts_with,
    # long_running, operand placement — that no scan can recover. They skip
    # when the corpus is absent, so without this job they would report green
    # while covering nothing.
    #
    # Its own job on purpose: a corpus that cannot be fetched should fail
    # visibly and by itself, not take the whole workflow down with it.
    steps:
      - uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683 # v4.2.2
        with:
          path: apexe

      - name: Check out the corpus
        uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683 # v4.2.2
        with:
          repository: aiperceivable/cli-permissions
          path: cli-permissions

      - name: Install Rust toolchain
        uses: dtolnay/rust-toolchain@4cda84d5c5c54efe2404f9d843567869ab1699d4 # stable
        with:
          toolchain: stable

      - name: Cache cargo registry & build
        uses: actions/cache@5a3ec84eff668545956fd18022155c47e93e2684 # v4.2.3
        with:
          path: |
            ~/.cargo/registry
            ~/.cargo/git
            apexe/target
          key: ${{ runner.os }}-cargo-corpus-${{ hashFiles('apexe/Cargo.lock') }}
          restore-keys: |
            ${{ runner.os }}-cargo-

      - name: Run tests with the corpus
        working-directory: apexe
        # Set but missing panics rather than skipping, so a checkout that
        # silently produced nothing fails here instead of passing quietly.
        env:
          APEXE_TEST_CORPUS: ${{ github.workspace }}/cli-permissions/overlays
        run: cargo test --all-features