1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
name: CI
on:
pull_request:
push:
branches:
env:
CARGO_TERM_COLOR: always
RUSTFLAGS: "-D warnings"
jobs:
test:
name: test + lint + coverage
runs-on: ubuntu-latest
timeout-minutes: 6
steps:
- uses: actions/checkout@v5
# The disclosure scan (bl-816b/bl-4423): shell only, sub-second, so it
# runs before the toolchain is even installed. The same scanner judges
# the task store in store-scan.yml.
- name: leak scan
run: make leak-scan
- name: Install Rust toolchain
uses: dtolnay/rust-toolchain@stable
with:
components: clippy, rustfmt
- uses: Swatinem/rust-cache@v2
- name: Install cargo-tarpaulin
uses: taiki-e/install-action@v2
with:
tool: cargo-tarpaulin
- name: Install cargo-audit
uses: taiki-e/install-action@v2
with:
tool: cargo-audit
- name: cargo test
run: cargo test --all-targets
- name: cargo clippy
run: cargo clippy --all-targets -- -D warnings
- name: cargo audit
run: cargo audit
# The blessed doc build: private items documented, every rustdoc warning
# denied, so a broken intra-doc link fails the build (bl-3d09). The
# invocation itself lives only in the Makefile.
- name: rustdoc (warning-clean)
run: make doc
- name: line-length check
run: bash scripts/check-line-lengths.sh
# The CD reconciler is shell: no compiler and no coverage gate reaches
# it, so its own selftest is what does (bl-4316). It drives the real
# scripts/deploy/bl-update under fake curl/cargo in a scratch HOME.
- name: deploy selftest
run: sh scripts/deploy/update-selftest.sh
- name: coverage selftest
run: sh scripts/coverage-selftest.sh
- name: coverage (100%)
run: bash scripts/check-coverage.sh
- name: cargo publish --dry-run
run: cargo publish --dry-run
cross-check:
name: cross-compile check (macOS)
runs-on: ubuntu-latest
timeout-minutes: 6
steps:
- uses: actions/checkout@v5
- name: Install Rust toolchain with macOS target
uses: dtolnay/rust-toolchain@stable
with:
targets: x86_64-apple-darwin
- uses: Swatinem/rust-cache@v2
# Catches Linux-only syscalls (e.g. pipe2) landing in portable
# code without cfg gating. `cargo check` is the lightest tool
# that verifies the non-Linux branches actually compile.
- name: cargo check --target x86_64-apple-darwin
run: cargo check --target x86_64-apple-darwin --all-targets