Skip to content

docs(upstream): record the v0.52.2 release (#297) #686

docs(upstream): record the v0.52.2 release (#297)

docs(upstream): record the v0.52.2 release (#297) #686

Workflow file for this run

name: CI
on:
push:
branches: [main]
pull_request:
branches: [main]
merge_group:
concurrency:
group: ${{ github.workflow }}-${{ github.ref }}
cancel-in-progress: true
permissions:
contents: read
env:
CARGO_TERM_COLOR: always
CARGO_INCREMENTAL: 0
RUST_BACKTRACE: "1"
SCCACHE_GHA_ENABLED: "true"
RUSTC_WRAPPER: sccache
jobs:
workspace-version:
name: Workspace Version
runs-on: ubuntu-24.04
timeout-minutes: 10
steps:
- name: Checkout
uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
with:
persist-credentials: false
- name: Install Rust toolchain
uses: dtolnay/rust-toolchain@6c977a6ca4077a0ceb28ffbe03f59d46e9ac8772 # master 2026-08-21
with:
toolchain: 1.98.0
- name: Require the version gate's parser
run: command -v jq >/dev/null 2>&1 || { echo "jq is required"; exit 1; }
# This is deliberately the workflow's first Cargo subprocess. Every
# Cargo-running job below depends on this job.
- name: Verify workspace version surfaces
run: bash scripts/check-workspace-versions.sh
linux:
name: Linux
needs: workspace-version
runs-on: ubuntu-24.04
timeout-minutes: 45
steps:
- name: Checkout
uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
with:
persist-credentials: false
- name: Install Rust toolchain
uses: dtolnay/rust-toolchain@6c977a6ca4077a0ceb28ffbe03f59d46e9ac8772 # master 2026-08-21
with:
toolchain: 1.98.0
components: rustfmt,clippy
- name: Verify workspace version surfaces before Cargo/cache
run: bash scripts/check-workspace-versions.sh
- name: Cache Rust inputs
uses: Swatinem/rust-cache@6323deb102c322ba6fcbdcafc7e3dddab59af2b6 # v2.9.2
with:
shared-key: cargo-home-${{ runner.os }}-${{ runner.arch }}
cache-targets: false
- name: Configure compiler cache
uses: mozilla-actions/sccache-action@fc920bf0ec8de6ee65d409111f7ec508035751ba # v0.0.11
with:
version: "v0.16.0"
- name: Set up Node.js
uses: actions/setup-node@820762786026740c76f36085b0efc47a31fe5020 # v7.0.0
with:
node-version: "24"
- name: Install pinned repository tools
run: npm install --global oxfmt@0.64.0
- name: Install pinned actionlint
run: bash .github/scripts/install-actionlint.sh
- name: Require fixture parsers and shell linter
run: |
set -euo pipefail
command -v shellcheck >/dev/null 2>&1 || { echo "shellcheck is required"; exit 1; }
python3 -c 'import yaml' \
|| python3 -m pip install --break-system-packages PyYAML==6.0.3 \
|| python3 -m pip install PyYAML==6.0.3
- name: Run the complete local gate
run: make check
windows-clippy:
name: Windows Clippy
needs: workspace-version
runs-on: windows-2025
timeout-minutes: 35
env:
CARGO_PROFILE_TEST_DEBUG: 0
CARGO_PROFILE_TEST_SPLIT_DEBUGINFO: off
steps:
- name: Checkout
uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
with:
persist-credentials: false
- name: Install Rust toolchain
uses: dtolnay/rust-toolchain@6c977a6ca4077a0ceb28ffbe03f59d46e9ac8772 # master 2026-08-21
with:
toolchain: 1.98.0
components: clippy
- name: Verify workspace version surfaces before Cargo/cache
shell: bash
run: bash scripts/check-workspace-versions.sh
- name: Cache Rust inputs
uses: Swatinem/rust-cache@6323deb102c322ba6fcbdcafc7e3dddab59af2b6 # v2.9.2
with:
shared-key: cargo-home-${{ runner.os }}-${{ runner.arch }}
cache-targets: false
- name: Configure compiler cache
uses: mozilla-actions/sccache-action@fc920bf0ec8de6ee65d409111f7ec508035751ba # v0.0.11
with:
version: "v0.16.0"
- name: Clippy
run: cargo clippy --workspace --exclude codegraph-bench --all-targets --locked -- -D warnings
windows-test:
name: Windows Tests
needs: workspace-version
runs-on: windows-2025
timeout-minutes: 40
env:
CARGO_PROFILE_TEST_DEBUG: 0
CARGO_PROFILE_TEST_SPLIT_DEBUGINFO: off
steps:
- name: Checkout
uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
with:
persist-credentials: false
- name: Install Rust toolchain
uses: dtolnay/rust-toolchain@6c977a6ca4077a0ceb28ffbe03f59d46e9ac8772 # master 2026-08-21
with:
toolchain: 1.98.0
- name: Verify workspace version surfaces before Cargo/cache
shell: bash
run: bash scripts/check-workspace-versions.sh
- name: Parse the PowerShell installer
shell: pwsh
run: |
$tokens = $null
$errors = $null
[System.Management.Automation.Language.Parser]::ParseFile(
"scripts/install.ps1", [ref]$tokens, [ref]$errors
) | Out-Null
if ($errors.Count -ne 0) {
$errors | ForEach-Object { Write-Error $_.ToString() }
exit 1
}
- name: Cache Rust inputs
uses: Swatinem/rust-cache@6323deb102c322ba6fcbdcafc7e3dddab59af2b6 # v2.9.2
with:
shared-key: cargo-home-${{ runner.os }}-${{ runner.arch }}
cache-targets: false
- name: Configure compiler cache
uses: mozilla-actions/sccache-action@fc920bf0ec8de6ee65d409111f7ec508035751ba # v0.0.11
with:
version: "v0.16.0"
- name: Run native Windows tests
run: cargo test --workspace --exclude codegraph-bench --locked
# A retained SQLite handle makes the replacement rename fail with a
# sharing violation, so this remains an explicit native acceptance gate.
- name: Run long-lived MCP database replacement acceptance
run: cargo test -p codegraph-rs --locked --test batch_m_long_lived_mcp
# FSEvents is the one native-recursive watcher backend no other job runs:
# Linux uses inotify and Windows ReadDirectoryChangesW. This job runs the
# symlink-following scan and watcher tests on macOS (#770).
macos-watcher:
name: macOS Watcher
needs: workspace-version
runs-on: macos-15
timeout-minutes: 40
steps:
- name: Checkout
uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
with:
persist-credentials: false
- name: Install Rust toolchain
uses: dtolnay/rust-toolchain@6c977a6ca4077a0ceb28ffbe03f59d46e9ac8772 # master 2026-08-21
with:
toolchain: 1.98.0
- name: Verify workspace version surfaces before Cargo/cache
run: bash scripts/check-workspace-versions.sh
- name: Cache Rust inputs
uses: Swatinem/rust-cache@6323deb102c322ba6fcbdcafc7e3dddab59af2b6 # v2.9.2
with:
shared-key: cargo-home-${{ runner.os }}-${{ runner.arch }}
cache-targets: false
- name: Configure compiler cache
uses: mozilla-actions/sccache-action@fc920bf0ec8de6ee65d409111f7ec508035751ba # v0.0.11
with:
version: "v0.16.0"
- name: Run the symlink scan and watcher tests
run: |
cargo test -p codegraph-extract --locked --test scan_symlinks
cargo test -p codegraph-watch --locked symlink
audit:
name: Security Audit
needs: workspace-version
runs-on: ubuntu-24.04
timeout-minutes: 15
steps:
- name: Checkout
uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
with:
persist-credentials: false
- name: Install Rust toolchain
uses: dtolnay/rust-toolchain@6c977a6ca4077a0ceb28ffbe03f59d46e9ac8772 # master 2026-08-21
with:
toolchain: 1.98.0
- name: Verify workspace version surfaces before Cargo
run: bash scripts/check-workspace-versions.sh
- name: Install cargo-audit
uses: taiki-e/install-action@a2a5f6e99e1a31540baa0468acfa302cff0f359f # v2.86.4
with:
tool: cargo-audit@0.22.2
- name: Audit dependencies
run: cargo audit
# Informational by policy: omitted from CI Success and informational in
# codecov.yml. A reporting outage or a below-target percentage cannot block.
coverage:
name: Coverage
needs: workspace-version
runs-on: ubuntu-24.04
timeout-minutes: 45
steps:
- name: Checkout
uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
with:
persist-credentials: false
- name: Install Rust toolchain
uses: dtolnay/rust-toolchain@6c977a6ca4077a0ceb28ffbe03f59d46e9ac8772 # master 2026-08-21
with:
toolchain: 1.98.0
components: llvm-tools-preview
- name: Verify workspace version surfaces before Cargo/cache
run: bash scripts/check-workspace-versions.sh
- name: Cache Rust inputs
uses: Swatinem/rust-cache@6323deb102c322ba6fcbdcafc7e3dddab59af2b6 # v2.9.2
with:
shared-key: cargo-home-${{ runner.os }}-${{ runner.arch }}
cache-targets: false
- name: Install cargo-llvm-cov
uses: taiki-e/install-action@a2a5f6e99e1a31540baa0468acfa302cff0f359f # v2.86.4
with:
tool: cargo-llvm-cov@0.8.7
- name: Generate coverage
# Instrumented builds bypass the compiler cache: this job never
# configures sccache, so the workflow-level wrapper must not apply.
env:
RUSTC_WRAPPER: ""
SCCACHE_GHA_ENABLED: "false"
run: make coverage-lcov
- name: Upload coverage to Codecov
uses: codecov/codecov-action@fb8b3582c8e4def4969c97caa2f19720cb33a72f # v7.0.0
with:
files: lcov.info
fail_ci_if_error: false
token: ${{ secrets.CODECOV_TOKEN }}
ci-success:
name: CI Success
needs: [workspace-version, linux, windows-clippy, windows-test, macos-watcher, audit]
if: always()
runs-on: ubuntu-24.04
timeout-minutes: 5
steps:
- name: Require every CI job to succeed
env:
NEEDS_JSON: ${{ toJSON(needs) }}
run: |
set -euo pipefail
if [ -z "${NEEDS_JSON:-}" ]; then
echo "::error title=CI gate::the needs context was empty; failing closed"
exit 1
fi
if ! printf '%s' "$NEEDS_JSON" | jq -e 'type == "object" and length > 0' >/dev/null 2>&1; then
echo "::error title=CI gate::the needs context was not a non-empty object; failing closed"
exit 1
fi
mapfile -t rows < <(
printf '%s' "$NEEDS_JSON" \
| jq -r 'to_entries | sort_by(.key)[] | "\(.key)\t\(.value.result // "<missing>")"'
)
((${#rows[@]} > 0)) || { echo "::error title=CI gate::no required jobs found"; exit 1; }
offenders=0
for row in "${rows[@]}"; do
job="${row%%$'\t'*}"
result="${row#*$'\t'}"
if [ "$result" = success ]; then
printf ' OK %-20s %s\n' "$job" "$result"
else
printf ' FAIL %-20s %s\n' "$job" "$result"
echo "::error title=CI gate::required job '${job}' concluded '${result}', not 'success'"
offenders=$((offenders + 1))
fi
done
if [ "$offenders" -ne 0 ]; then
echo "CI failed: ${offenders} of ${#rows[@]} required job(s) did not conclude 'success'."
exit 1
fi
echo "CI passed: all ${#rows[@]} required job(s) concluded 'success'."