1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
130
131
132
133
134
135
136
137
name: ci
on:
push:
branches:
pull_request:
branches:
schedule:
- cron: "0 4 * * *"
workflow_dispatch:
concurrency:
group: ci-${{ github.workflow }}-${{ github.ref }}
cancel-in-progress: ${{ github.ref != 'refs/heads/main' }}
env:
CARGO_TERM_COLOR: always
RUST_BACKTRACE: 1
# ~keep The `full` feature build (ONNX + lancedb + vendored stack-graphs) produces huge debug objects
# ~keep that exhaust the standard runners' disk — surfacing as an `ld` bus error (truncated object) on
# ~keep Linux and an explicit ENOSPC on macOS. Level 1 keeps panic file:line (so backtraces stay useful)
# ~keep while dropping the variable/type DWARF that dominates the size.
CARGO_PROFILE_DEV_DEBUG: "1"
CARGO_PROFILE_TEST_DEBUG: "1"
jobs:
validate:
uses: xberg-io/actions/.github/workflows/reusable-validate.yml@v1
with:
setup-rust: true
test:
name: test / ${{ matrix.os }} / ${{ matrix.features }}
runs-on: ${{ matrix.os }}
timeout-minutes: ${{ matrix.timeout_minutes }}
strategy:
fail-fast: false
matrix:
include:
- os: ubuntu-latest
features: ""
timeout_minutes: 30
- os: ubuntu-latest
features: "full"
timeout_minutes: 60
- os: macos-latest
features: ""
timeout_minutes: 30
- os: macos-14
features: "full"
timeout_minutes: 90
- os: windows-latest
features: "comms shells"
timeout_minutes: 30
steps:
- uses: actions/checkout@v4
# ~keep The `full` build is disk-heavy; reclaim space up front on the legs that build it so the
# ~keep debug + release target dirs and the downloaded ONNX models don't hit ENOSPC.
- name: Free disk space (Linux)
if: runner.os == 'Linux' && matrix.features == 'full'
run: |
sudo rm -rf /usr/share/dotnet /opt/ghc /usr/local/lib/android \
/opt/hostedtoolcache/CodeQL /usr/local/share/boost "$AGENT_TOOLSDIRECTORY" || true
sudo docker image prune --all --force || true
df -h /
- name: Free disk space (macOS)
if: runner.os == 'macOS' && matrix.features == 'full'
run: |
sudo rm -rf ~/Library/Developer/CoreSimulator/Caches/* || true
sudo rm -rf /Library/Developer/CoreSimulator/Profiles/Runtimes/* || true
df -h /
- uses: dtolnay/rust-toolchain@stable
with:
components: rustfmt, clippy
- name: Install system dependencies
if: matrix.features == 'full'
uses: ./.github/actions/install-system-deps
- name: Install protoc (Linux, default-features)
if: runner.os == 'Linux' && matrix.features == ''
run: sudo apt-get update && sudo apt-get install -y protobuf-compiler
- name: Install protoc (macOS, default-features)
if: runner.os == 'macOS' && matrix.features == ''
run: brew install protobuf
- uses: Swatinem/rust-cache@v2
with:
key: ${{ matrix.os }}-${{ matrix.features }}
- name: cargo fmt
run: cargo fmt --all --check
- name: cargo clippy
run: cargo clippy --workspace --all-targets --tests --features "${{ matrix.features }}" -- -D warnings
- name: cargo test
run: cargo test --workspace --features "${{ matrix.features }}" --quiet
- name: cargo build --release
run: cargo build --release --quiet --bin basemind --features "${{ matrix.features }}"
deny:
name: cargo-deny
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@v4
- uses: dtolnay/rust-toolchain@stable
- uses: Swatinem/rust-cache@v2
- uses: EmbarkStudios/cargo-deny-action@v2
with:
command: check
hardening:
name: hardening harness (nightly)
runs-on: ubuntu-latest
if: github.event_name == 'workflow_dispatch' || github.event_name == 'schedule'
steps:
- uses: actions/checkout@v4
- uses: dtolnay/rust-toolchain@stable
- name: Install system dependencies
uses: ./.github/actions/install-system-deps
- uses: Swatinem/rust-cache@v2
- name: run harden.sh
run: ./scripts/harden.sh
- name: upload results
if: always()
uses: actions/upload-artifact@v4
with:
name: harden-results
path: /tmp/basemind-harden/results.ndjson