mpp 0.14.0

Rust SDK for the Machine Payments Protocol (MPP)
Documentation
name: CI

on:
  push:
    branches: [main]
  pull_request:
    branches: [main]
  workflow_call:
    inputs:
      ref:
        type: string
        required: false

env:
  CARGO_TERM_COLOR: always

permissions: {}

jobs:
  lint:
    name: Lint
    runs-on: ubuntu-latest
    env:
      NODE_EXTRA_CA_CERTS: /etc/ssl/certs/ca-certificates.crt
    permissions:
      contents: read
      id-token: write
    steps:
      - name: Secure runner
        uses: tempoxyz/gh-actions/actions/secure-runner@55fe3b63d9612623cc51e6c62d9d62fbcb175fb0 # 2026-09-29T01-25-15Z-55fe3b63
      - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
        with:
          ref: ${{ inputs.ref || '' }}
          persist-credentials: false
      - uses: tempoxyz/gh-actions/vendor/dtolnay/rust-toolchain@55fe3b63d9612623cc51e6c62d9d62fbcb175fb0 # 2026-09-29T01-25-15Z-55fe3b63
        with:
          toolchain: stable
          components: rustfmt, clippy
      - uses: tempoxyz/gh-actions/vendor/Swatinem/rust-cache@55fe3b63d9612623cc51e6c62d9d62fbcb175fb0 # 2026-09-29T01-25-15Z-55fe3b63
      - name: Resolve Cargo dependencies
        run: .github/scripts/resolve-cargo-dependencies.sh
      - run: cargo fmt --all -- --check
      - run: cargo clippy --workspace --all-targets --all-features -- -D warnings
      - uses: actions/setup-node@820762786026740c76f36085b0efc47a31fe5020 # v7.0.0
        with:
          node-version: 22
      - name: Pin pnpm for Tempo Lints
        run: |
          set -o pipefail
          for attempt in 1 2 3; do
            if corepack prepare pnpm@10.28.1 --activate 2>&1 | tee "$RUNNER_TEMP/corepack.log"; then
              exit 0
            fi
            if ! grep -q 'Error when performing the request' "$RUNNER_TEMP/corepack.log" || [[ "$attempt" == 3 ]]; then
              exit 1
            fi
            sleep $((attempt * 5))
          done
      - name: Run Tempo Lints
        uses: tempoxyz/lints@f9268eb2b828dbacf9f4b5d4bf6ad4541826567f # 2026-08-25T05-00-01Z-f9268eb2 # zizmor: ignore[ref-version-mismatch]
        env:
          COREPACK_DEFAULT_TO_LATEST: "0"
        with:
          language: rust
          path: "."
          post-comment: false
          github-token: ${{ secrets.GITHUB_TOKEN }}
      - name: Install ast-grep
        uses: tempoxyz/gh-actions/vendor/jaxxstorm/action-install-gh-release@55fe3b63d9612623cc51e6c62d9d62fbcb175fb0 # 2026-09-29T01-25-15Z-55fe3b63
        with:
          repo: ast-grep/ast-grep
          tag: "0.45.0"
        env:
          GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }}
      - name: Run ast-grep lint
        run: sg scan -c sgconfig.yml src/
      - name: Run ast-grep tests
        run: sg test -c sgconfig.yml

  test:
    name: Test
    runs-on: ubuntu-latest
    permissions:
      contents: read
      id-token: write
    steps:
      - name: Secure runner
        uses: tempoxyz/gh-actions/actions/secure-runner@55fe3b63d9612623cc51e6c62d9d62fbcb175fb0 # 2026-09-29T01-25-15Z-55fe3b63
      - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
        with:
          ref: ${{ inputs.ref || '' }}
          persist-credentials: false
      - uses: tempoxyz/gh-actions/vendor/dtolnay/rust-toolchain@55fe3b63d9612623cc51e6c62d9d62fbcb175fb0 # 2026-09-29T01-25-15Z-55fe3b63
        with:
          toolchain: stable
      - uses: tempoxyz/gh-actions/vendor/Swatinem/rust-cache@55fe3b63d9612623cc51e6c62d9d62fbcb175fb0 # 2026-09-29T01-25-15Z-55fe3b63
      - name: Resolve Cargo dependencies
        run: .github/scripts/resolve-cargo-dependencies.sh
      - uses: tempoxyz/gh-actions/vendor/taiki-e/install-action@55fe3b63d9612623cc51e6c62d9d62fbcb175fb0 # 2026-09-29T01-25-15Z-55fe3b63
        with:
          tool: cargo-hack
      - name: Tests
        run: cargo test --features tempo,stripe,ws,server,client,axum,middleware,tower,utils,integration-stripe,integration-ws
        env:
          STRIPE_SECRET_KEY: ${{ secrets.STRIPE_SECRET_KEY }}
      - name: Check Ring transport dependency graph
        run: |
          tree=$(cargo tree -p alloy-transport-mpp --no-default-features --features ring --edges normal --prefix none)
          if grep -q '^aws-lc-sys ' <<< "$tree"; then
            echo "Ring-only transport unexpectedly includes aws-lc-sys"
            exit 1
          fi
      - run: cargo hack check --each-feature --no-dev-deps --skip integration,integration-stripe,integration-ws
      - name: Check examples
        run: cargo check --workspace --exclude mpp

  integration:
    name: Integration Test
    runs-on: ubuntu-latest
    permissions:
      contents: read
      id-token: write
      packages: read
    steps:
      - name: Secure runner
        uses: tempoxyz/gh-actions/actions/secure-runner@55fe3b63d9612623cc51e6c62d9d62fbcb175fb0 # 2026-09-29T01-25-15Z-55fe3b63
      - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
        with:
          ref: ${{ inputs.ref || '' }}
          persist-credentials: false
      - uses: tempoxyz/gh-actions/vendor/dtolnay/rust-toolchain@55fe3b63d9612623cc51e6c62d9d62fbcb175fb0 # 2026-09-29T01-25-15Z-55fe3b63
        with:
          toolchain: stable
      - uses: tempoxyz/gh-actions/vendor/Swatinem/rust-cache@55fe3b63d9612623cc51e6c62d9d62fbcb175fb0 # 2026-09-29T01-25-15Z-55fe3b63
      - name: Resolve Cargo dependencies
        run: .github/scripts/resolve-cargo-dependencies.sh

      - name: Start Tempo localnet
        run: docker compose up -d --wait

      - name: Run integration tests
        run: cargo test --features integration --test integration_charge -- --nocapture

      - name: Stop Tempo localnet
        if: always()
        run: docker compose down

  deny:
    uses: tempoxyz/gh-actions/.github/workflows/rust-deny.yml@55fe3b63d9612623cc51e6c62d9d62fbcb175fb0 # 2026-09-29T01-25-15Z-55fe3b63
    with:
      rust-toolchain: nightly
    permissions:
      contents: read
      id-token: write

  ci-gate:
    name: CI Gate
    if: always()
    needs: [lint, test, integration, deny]
    runs-on: ubuntu-latest
    permissions:
      contents: read
      id-token: write
    steps:
      - name: Secure runner
        uses: tempoxyz/gh-actions/actions/secure-runner@55fe3b63d9612623cc51e6c62d9d62fbcb175fb0 # 2026-09-29T01-25-15Z-55fe3b63
      - run: |
          if [[ "${{ contains(needs.*.result, 'failure') || contains(needs.*.result, 'cancelled') }}" == "true" ]]; then
            echo "One or more required jobs failed or were cancelled"
            exit 1
          fi