ic-memory 0.27.0

Durable stable-memory allocation governance for Internet Computer canisters
Documentation
name: CI

on:
  pull_request:
  push:
    branches:
      - main

permissions:
  contents: read

concurrency:
  group: ${{ github.workflow }}-${{ github.ref }}
  cancel-in-progress: true

jobs:
  tooling-lint:
    runs-on: ubuntu-24.04
    timeout-minutes: 10
    steps:
      - uses: actions/checkout@df4cb1c069e1874edd31b4311f1884172cec0e10 # reviewed Shared Tooling pin
        with:
          persist-credentials: false
      - run: make verify-shared-tooling
      - name: Install exact validation tools
        shell: bash
        run: |
          source ci-tool-versions.env
          tool_dir="$RUNNER_TEMP/ic-memory-tools"
          actionlint_bin="$(bash scripts/ci/install-actionlint.sh \
            --version "$IC_MEMORY_ACTIONLINT_VERSION" \
            --sha256 "$IC_MEMORY_ACTIONLINT_SHA256_LINUX_AMD64" \
            --install-dir "$tool_dir")"
          shellcheck_bin="$(bash scripts/ci/install-shellcheck.sh \
            --version "$IC_MEMORY_SHELLCHECK_VERSION" \
            --sha256 "$IC_MEMORY_SHELLCHECK_SHA256_LINUX_X86_64" \
            --install-dir "$tool_dir")"
          {
            echo "ACTIONLINT_BIN=$actionlint_bin"
            echo "SHELLCHECK_BIN=$shellcheck_bin"
          } >> "$GITHUB_ENV"
      - run: make lint-tooling

  test:
    strategy:
      fail-fast: false
      matrix:
        os: [ubuntu-24.04, macos-15, macos-15-intel]
    runs-on: ${{ matrix.os }}
    timeout-minutes: 30
    steps:
      - uses: actions/checkout@df4cb1c069e1874edd31b4311f1884172cec0e10 # reviewed Shared Tooling pin
        with:
          persist-credentials: false
      - name: Read pinned Rust toolchain
        id: pin
        shell: bash
        run: |
          channel="$(sed -n 's/^channel = "\([^"]*\)"$/\1/p' rust-toolchain.toml)"
          [[ "$channel" =~ ^[0-9]+\.[0-9]+\.[0-9]+$ ]]
          echo "channel=$channel" >> "$GITHUB_OUTPUT"
      - uses: dtolnay/rust-toolchain@e97e2d8cc328f1b50210efc529dca0028893a2d9 # reviewed master-history commit
        with:
          toolchain: ${{ steps.pin.outputs.channel }}
          components: clippy, rustfmt
          targets: wasm32-unknown-unknown
      - name: Install exact manifest formatter
        shell: bash
        env:
          RUSTUP_TOOLCHAIN: ${{ steps.pin.outputs.channel }}
        run: |
          source ci-tool-versions.env
          cargo install cargo-sort --version "$IC_MEMORY_CARGO_SORT_VERSION" --locked
      - name: Check both workspaces without changing files
        run: make fmt-check
      - name: Exercise hook isolation on the native host
        run: make test-hooks
      - name: Select and prepare dependency inputs
        run: |
          cargo generate-lockfile
          make fetch-dependencies
          shasum -a 256 Cargo.lock
          rustc -Vv
          uname -sm
      - run: make validate-toolchain

  msrv:
    strategy:
      fail-fast: false
      matrix:
        os: [ubuntu-24.04, macos-15, macos-15-intel]
    runs-on: ${{ matrix.os }}
    timeout-minutes: 20
    steps:
      - uses: actions/checkout@df4cb1c069e1874edd31b4311f1884172cec0e10 # reviewed Shared Tooling pin
        with:
          persist-credentials: false
      - name: Read declared MSRV
        id: pin
        shell: bash
        run: |
          channel="$(sed -n 's/^rust-version = "\([^"]*\)"$/\1/p' Cargo.toml)"
          [[ "$channel" =~ ^[0-9]+\.[0-9]+\.[0-9]+$ ]]
          echo "channel=$channel" >> "$GITHUB_OUTPUT"
      - uses: dtolnay/rust-toolchain@e97e2d8cc328f1b50210efc529dca0028893a2d9 # reviewed master-history commit
        with:
          toolchain: ${{ steps.pin.outputs.channel }}
      - name: Select and prepare dependency inputs
        env:
          RUSTUP_TOOLCHAIN: ${{ steps.pin.outputs.channel }}
        run: |
          cargo generate-lockfile
          cargo fetch --locked
          shasum -a 256 Cargo.lock
          rustc -Vv
          uname -sm
      - name: Check all targets with the declared MSRV
        env:
          RUSTUP_TOOLCHAIN: ${{ steps.pin.outputs.channel }}
        run: cargo check --locked --offline --all-targets