ic-memory 0.29.0

Durable stable-memory allocation governance for Internet Computer canisters
Documentation
name: CI

on:
  pull_request:
  push:
    branches:
      - main

permissions:
  contents: read

concurrency:
  group: ${{ github.workflow }}-${{ github.ref }}
  cancel-in-progress: true

jobs:
  tooling-lint:
    runs-on: ubuntu-24.04
    timeout-minutes: 10
    steps:
      - uses: actions/checkout@df4cb1c069e1874edd31b4311f1884172cec0e10 # reviewed Shared Tooling pin
        with:
          persist-credentials: false
      - run: make verify-shared-tooling
      - name: Install exact validation tools
        shell: bash
        run: |
          source ci/tool-versions.env
          tool_dir="$RUNNER_TEMP/ic-memory-tools"
          actionlint_bin="$(bash scripts/ci/install-actionlint.sh \
            --version "$SHARED_TOOLING_ACTIONLINT_VERSION" \
            --sha256 "$SHARED_TOOLING_ACTIONLINT_SHA256_LINUX_AMD64" \
            --install-dir "$tool_dir")"
          shellcheck_bin="$(bash scripts/ci/install-shellcheck.sh \
            --version "$SHARED_TOOLING_SHELLCHECK_VERSION" \
            --sha256 "$SHARED_TOOLING_SHELLCHECK_SHA256_LINUX_X86_64" \
            --install-dir "$tool_dir")"
          {
            echo "ACTIONLINT_BIN=$actionlint_bin"
            echo "SHELLCHECK_BIN=$shellcheck_bin"
          } >> "$GITHUB_ENV"
      - run: make lint-tooling

  test:
    strategy:
      fail-fast: false
      matrix:
        os: [ubuntu-24.04, macos-15, macos-15-intel]
    runs-on: ${{ matrix.os }}
    timeout-minutes: 30
    steps:
      - uses: actions/checkout@df4cb1c069e1874edd31b4311f1884172cec0e10 # reviewed Shared Tooling pin
        with:
          persist-credentials: false
      - name: Read pinned Rust toolchain
        id: pin
        shell: bash
        run: |
          channel="$(sed -n 's/^channel = "\([^"]*\)"$/\1/p' rust-toolchain.toml)"
          [[ "$channel" =~ ^[0-9]+\.[0-9]+\.[0-9]+$ ]]
          echo "channel=$channel" >> "$GITHUB_OUTPUT"
      - name: Prepare retained fixture directory
        shell: bash
        run: |
          mkdir -p "$RUNNER_TEMP/ic-memory-fixtures"
          echo "TMPDIR=$RUNNER_TEMP/ic-memory-fixtures" >> "$GITHUB_ENV"
      - uses: dtolnay/rust-toolchain@e97e2d8cc328f1b50210efc529dca0028893a2d9 # reviewed master-history commit
        with:
          toolchain: ${{ steps.pin.outputs.channel }}
          components: clippy, rustfmt
          targets: wasm32-unknown-unknown
      - name: Install exact manifest formatter
        shell: bash
        env:
          RUSTUP_TOOLCHAIN: ${{ steps.pin.outputs.channel }}
        run: |
          source ci/tool-versions.env
          cargo install cargo-sort --version "$SHARED_TOOLING_CARGO_SORT_VERSION" --locked
      - name: Install and verify repository-local host and IC tools
        shell: bash
        run: |
          make install-tools tools-check 2>&1 | tee "$RUNNER_TEMP/tools-setup.log"
          echo "$PWD/.tools/host/bin" >> "$GITHUB_PATH"
          echo "$PWD/.tools/ic/bin" >> "$GITHUB_PATH"
      - name: Check both workspaces without changing files
        run: make fmt-check
      - name: Exercise hook isolation on the native host
        run: make test-hooks
      - name: Prepare tracked dependency inputs
        shell: bash
        run: |
          make fetch-dependencies 2>&1 | tee "$RUNNER_TEMP/dependencies.log"
          shasum -a 256 Cargo.lock
          rustc -Vv
          uname -sm
      - name: Qualify pinned toolchain
        shell: bash
        run: make validate-toolchain 2>&1 | tee "$RUNNER_TEMP/validation.log"
      - name: Retain failed validation and installer evidence
        if: failure()
        uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # reviewed Shared Tooling pin, v7
        with:
          name: validation-failure-${{ matrix.os }}
          path: |
            ${{ runner.temp }}/ic-memory-fixtures
            ${{ runner.temp }}/tools-setup.log
            ${{ runner.temp }}/dependencies.log
            ${{ runner.temp }}/validation.log
            ${{ github.workspace }}/target/qualification
            ${{ github.workspace }}/target/release-validation
            ${{ github.workspace }}/.tools/host-set.*
            ${{ github.workspace }}/.tools/ic-set.*
          include-hidden-files: true
          retention-days: 14
          if-no-files-found: ignore

  msrv:
    strategy:
      fail-fast: false
      matrix:
        os: [ubuntu-24.04, macos-15, macos-15-intel]
    runs-on: ${{ matrix.os }}
    timeout-minutes: 20
    steps:
      - uses: actions/checkout@df4cb1c069e1874edd31b4311f1884172cec0e10 # reviewed Shared Tooling pin
        with:
          persist-credentials: false
      - name: Read declared MSRV
        id: pin
        shell: bash
        run: |
          channel="$(sed -n 's/^rust-version = "\([^"]*\)"$/\1/p' Cargo.toml)"
          [[ "$channel" =~ ^[0-9]+\.[0-9]+\.[0-9]+$ ]]
          echo "channel=$channel" >> "$GITHUB_OUTPUT"
      - uses: dtolnay/rust-toolchain@e97e2d8cc328f1b50210efc529dca0028893a2d9 # reviewed master-history commit
        with:
          toolchain: ${{ steps.pin.outputs.channel }}
      - name: Prepare tracked dependency inputs
        env:
          RUSTUP_TOOLCHAIN: ${{ steps.pin.outputs.channel }}
        run: |
          cargo fetch --locked
          shasum -a 256 Cargo.lock
          rustc -Vv
          uname -sm
      - name: Check all targets with the declared MSRV
        shell: bash
        env:
          RUSTUP_TOOLCHAIN: ${{ steps.pin.outputs.channel }}
        run: cargo check --locked --offline --all-targets 2>&1 | tee "$RUNNER_TEMP/msrv.log"
      - name: Retain failed MSRV diagnostics
        if: failure()
        uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # reviewed Shared Tooling pin, v7
        with:
          name: msrv-failure-${{ matrix.os }}
          path: ${{ runner.temp }}/msrv.log
          retention-days: 14
          if-no-files-found: ignore