返回 CodeWhale
.cnb.yml
根目录 / .cnb.yml
1 # CNB is a one-way mirror from GitHub. Keep this file source-controlled here;
2 # CNB-side edits will be overwritten by the GitHub -> CNB sync workflow.
3
4 .feishu_bridge_tests: &feishu_bridge_tests
5 name: feishu bridge tests
6 runner:
7 tags: cnb:arch:amd64
8 cpus: 8
9 docker:
10 image: node:22-bookworm
11 stages:
12 - name: feishu bridge tests
13 script: |
14 set -eu
15 cd integrations/feishu-bridge
16 npm ci
17 npm run check
18 npm test
19
20 .rust_workspace_gates_stage: &rust_workspace_gates_stage
21 name: rust workspace gates
22 # The all-feature TUI test crate is large enough that concurrent rustc and
23 # clippy processes or disposable test debug metadata can exceed the shared
24 # CNB runner's memory. Keep the full gate surface, but serialize Cargo,
25 # omit test-only debug tables, and use the established workspace-test stack
26 # size so deep runtime API tests do not abort on the platform default.
27 timeout: 45m
28 script: |
29 set -eu
30 export CARGO_BUILD_JOBS=1
31 export CARGO_PROFILE_TEST_DEBUG=0
32 ./scripts/release/check-versions.sh
33 ./scripts/release/check-ohos-deps.sh
34 cargo fmt --all -- --check
35 cargo check --workspace --all-targets --locked
36 cargo clippy --workspace --all-targets --all-features --locked -- -D warnings
37 cargo build -p codewhale-cli --bin codewhale --all-features --locked
38 # Use the shared test HOME boundary while retaining the real toolchain.
39 RUST_MIN_STACK=16777216 sh scripts/with-hermetic-test-home.sh cargo test --workspace --all-features --locked
40 # Parity gates as first-class steps so drift surfaces as a named failure,
41 # not a buried workspace-test entry. Mirrors release.yml's parity job.
42 sh scripts/with-hermetic-test-home.sh cargo test -p codewhale-protocol --test parity_protocol --locked
43 sh scripts/with-hermetic-test-home.sh cargo test -p codewhale-state --test parity_state --locked
44
45 .linux_rust_gates: &linux_rust_gates
46 name: linux rust gates
47 runner:
48 tags: cnb:arch:amd64
49 cpus: 16
50 docker:
51 image: rust:1.88-bookworm
52 # codewhale-cnb-bridge GitHub App credentials from the CNB KeyStore
53 # (codewhale.net/codewhale-ci-secrets, github-bridge.yml), injected as
54 # environment variables. Values are never printed.
55 # https://docs.cnb.cool/en/repo/secret.html
56 imports:
57 - https://cnb.cool/codewhale.net/codewhale-ci-secrets/-/blob/main/github-bridge.yml
58 stages:
59 - name: install linux dependencies
60 script: |
61 set -eu
62 apt-get update
63 apt-get install -y git libdbus-1-dev nodejs npm pkg-config
64 if command -v rustup >/dev/null 2>&1; then
65 rustup component add rustfmt clippy
66 fi
67
68 - *rust_workspace_gates_stage
69
70 - name: linux npm wrapper smoke
71 # Full LTO can link silently for longer than CNB's default 10-minute
72 # no-output window. Keep the production profile and give the job enough
73 # time to emit its version and wrapper receipts.
74 timeout: 45m
75 script: |
76 set -eu
77 # The release profile uses full LTO and one codegen unit. Bound Cargo's
78 # parallelism so the final links cannot exhaust a shared CNB runner.
79 cargo build --jobs 2 --release --locked -p codewhale-cli
80 cp target/release/codewhale target/release/codew
81 export PATH="$PWD/target/release:$PATH"
82 node scripts/release/npm-wrapper-smoke.js
83 ./target/release/codewhale --version
84 ./target/release/codew --version
85
86 # Shadow-parity bridge (ops design: CNB-PRIMARY-CI-DESIGN-20260830). Post one
87 # non-required "-cnb" Check Run on the exact GitHub SHA being built so the
88 # CNB verdict is visible on GitHub while GitHub Actions stays the canonical,
89 # required CI. endStages always run and cannot fail the pipeline, so a
90 # bridge outage never turns a green CNB build red (and vice versa: the CNB
91 # verdict is reported from CNB_PIPELINE_STATUS, not from this stage).
92 endStages:
93 - name: github shadow check run
94 script: |
95 set -eu
96 case "${CNB_PIPELINE_STATUS:-error}" in
97 success) conclusion="success" ;;
98 cancel) conclusion="cancelled" ;;
99 *) conclusion="failure" ;;
100 esac
101 node scripts/ci/cnb-github-checkrun.mjs \
102 --name "linux rust gates -cnb" \
103 --sha "${CNB_COMMIT}" \
104 --status completed \
105 --conclusion "${conclusion}" \
106 --details-url "${CNB_BUILD_WEB_URL:-https://cnb.cool/${CNB_REPO_SLUG}}" \
107 --summary "CNB pipeline '${CNB_PIPELINE_NAME:-linux rust gates}' finished with status ${CNB_PIPELINE_STATUS:-unknown} on ${CNB_BRANCH:-unknown branch} (${CNB_COMMIT}). Shadow lane per the CNB-primary CI design: GitHub Actions remains canonical and required; nothing is gated on this check."
108
109 .linux_release_preflight: &linux_release_preflight
110 name: linux release preflight
111 runner:
112 tags: cnb:arch:amd64
113 cpus: 16
114 docker:
115 image: rust:1.88-bookworm
116 stages:
117 - name: install release dependencies
118 script: |
119 set -eu
120 apt-get update
121 apt-get install -y curl git libdbus-1-dev nodejs npm pkg-config
122 if command -v rustup >/dev/null 2>&1; then
123 rustup component add rustfmt clippy
124 fi
125
126 - *rust_workspace_gates_stage
127
128 - name: crate publish dry-run
129 script: |
130 set -eu
131 ./scripts/release/publish-crates.sh dry-run
132
133 - name: release binary smoke
134 # Full LTO can link silently for longer than CNB's default 10-minute
135 # no-output window. Keep the production profile and give the job enough
136 # time to emit its version and wrapper receipts.
137 timeout: 45m
138 script: |
139 set -eu
140 # Keep the production release profile intact while avoiding a burst of
141 # concurrent rustc/linker processes on the shared release runner.
142 cargo build --jobs 2 --release --locked -p codewhale-cli
143 cp target/release/codewhale target/release/codew
144 export PATH="$PWD/target/release:$PATH"
145 node scripts/release/npm-wrapper-smoke.js
146 ./target/release/codewhale --version
147 ./target/release/codew --version
148
149 main:
150 push:
151 - *feishu_bridge_tests
152 - *linux_rust_gates
153
154 "(fix/*|rebrand/*)":
155 push:
156 - *linux_rust_gates
157
158 "work/v*":
159 push:
160 - *feishu_bridge_tests
161 - *linux_release_preflight
162
163 $:
164 tag_push:
165 - docker:
166 image: rust:1.88-bookworm
167 stages:
168 - name: build linux x64 release assets (static)
169 # The static full-LTO link can also outlive CNB's default no-output
170 # window. Do not weaken the release profile to keep the runner alive.
171 timeout: 45m
172 script: |
173 set -eu
174
175 apt-get update
176 apt-get install -y git musl-tools nodejs pkg-config
177 rustup target add x86_64-unknown-linux-musl
178
179 ./scripts/release/check-versions.sh --require-dated-release
180 ./scripts/release/check-ohos-deps.sh
181 checkout_sha="$(git rev-parse 'HEAD^{commit}')"
182 commit_sha="${CNB_COMMIT:-${checkout_sha}}"
183 if [ "$commit_sha" != "$checkout_sha" ]; then
184 echo "ERROR: CNB_COMMIT ${commit_sha} does not match checkout ${checkout_sha}" >&2
185 exit 1
186 fi
187 export CODEWHALE_BUILD_SHA="$commit_sha"
188 cargo build --jobs 2 --release --locked \
189 --target x86_64-unknown-linux-musl \
190 -p codewhale-cli # single binary
191
192 mkdir -p target/cnb-release
193 BIN_DIR="target/x86_64-unknown-linux-musl/release"
194 cp "$BIN_DIR/codewhale" target/cnb-release/codewhale-linux-x64
195 cp "$BIN_DIR/codewhale" target/cnb-release/codew-linux-x64
196 cp "$BIN_DIR/codewhale" target/cnb-release/codewhale-tui-linux-x64
197 strip \
198 target/cnb-release/codewhale-linux-x64 \
199 target/cnb-release/codew-linux-x64 \
200 target/cnb-release/codewhale-tui-linux-x64 \
201 || true
202
203 (
204 cd target/cnb-release
205 sha256sum \
206 codewhale-linux-x64 \
207 codew-linux-x64 \
208 codewhale-tui-linux-x64 \
209 > codewhale-artifacts-sha256.txt
210 )
211
212 tag_name="${CNB_BRANCH:-}"
213 if [ -z "$tag_name" ]; then
214 tag_name="$(git describe --tags --exact-match 2>/dev/null || true)"
215 fi
216 version="${tag_name#v}"
217 cargo_version="$(grep -E '^version = "' Cargo.toml | head -n1 | sed -E 's/^version = "([^"]+)".*/\1/')"
218 if [ -n "$tag_name" ] && [ "$version" != "$cargo_version" ]; then
219 echo "ERROR: tag ${tag_name} does not match Cargo.toml version ${cargo_version}" >&2
220 exit 1
221 fi
222 {
223 echo "# ${tag_name:-CNB release}"
224 echo
225 awk -v version="${version}" '
226 index($0, "## [" version "]") == 1 { in_section = 1; next }
227 in_section && /^## \[/ { exit }
228 in_section { print }
229 ' CHANGELOG.md
230 echo
231 echo "Built by CNB from ${commit_sha}."
232 echo
233 echo "Assets:"
234 echo "- codewhale-linux-x64"
235 echo "- codew-linux-x64"
236 echo "- codewhale-tui-linux-x64 (v0.9.4 compatibility alias)"
237 echo "- codewhale-artifacts-sha256.txt"
238 } > target/cnb-release/CNB_RELEASE.md
239
240 - name: create cnb release
241 type: git:release
242 options:
243 descriptionFromFile: target/cnb-release/CNB_RELEASE.md
244 latest: true
245
246 - name: upload linux x64 release assets
247 image: cnbcool/attachments:latest
248 settings:
249 attachments:
250 - target/cnb-release/codewhale-linux-x64
251 - target/cnb-release/codew-linux-x64
252 - target/cnb-release/codewhale-tui-linux-x64
253 - target/cnb-release/codewhale-artifacts-sha256.txt
254
254 lines YAML