426e9eeabd
Voice Workbench / headless workbench (mocked backends) (push) Has been cancelled
Voice Workbench / real acoustic lane (nightly, provisioned only) (push) Has been cancelled
ci / test (push) Has been cancelled
ci / lint-and-format (push) Has been cancelled
ci / build (push) Has been cancelled
ci / dev-startup (push) Has been cancelled
gitleaks / gitleaks (push) Has been cancelled
Markdown Links / Relative Markdown Links (push) Has been cancelled
Quality (Extended) / Homepage Build (PR smoke) (push) Has been cancelled
Quality (Extended) / Comment-only diff guard (push) Has been cancelled
Quality (Extended) / Format + Type Safety Ratchet (push) Has been cancelled
Quality (Extended) / Develop Gate (secret scan + UI determinism) (push) Has been cancelled
Quality (Extended) / Develop Gate (lint) (push) Has been cancelled
Chat shell gestures / Chat shell gesture + parity e2e (push) Has been cancelled
Cloud Gateway Discord / Test (push) Has been cancelled
Benchmark Bridge Tests / benchmark (bunx @biomejs/biome check packages/lifeops-bench/src, benchmark-lint) (push) Has been cancelled
Benchmark Bridge Tests / benchmark (bunx vitest run --config packages/lifeops-bench/vitest.config.ts --root packages/lifeops-bench --passWithNoTests, benchmark-tests) (push) Has been cancelled
Build Agent Image / build-and-push (push) Has been cancelled
Dev Smoke / bun run dev onboarding chat (push) Has been cancelled
Dev Smoke / Vite HMR dependency-level smoke (push) Has been cancelled
Electrobun Submodule Guard / electrobun gitlink is fetchable (push) Has been cancelled
Publish @elizaos/example-code / check_npm (push) Has been cancelled
Publish @elizaos/example-code / publish_npm (push) Has been cancelled
Publish @elizaos/plugin-elizacloud / verify_version (push) Has been cancelled
Publish @elizaos/plugin-elizacloud / publish_npm (push) Has been cancelled
Sandbox Live Smoke / Sandbox live smoke (push) Has been cancelled
Snap Build & Test / Build Snap (amd64) (push) Has been cancelled
Snap Build & Test / Build Snap (arm64) (push) Has been cancelled
Test Packaging / elizaos CLI global-install smoke (node + bun) (push) Has been cancelled
Cloud Gateway Webhook / Test (push) Has been cancelled
Cloud Tests / lint-and-types (push) Has been cancelled
Cloud Tests / unit-tests (push) Has been cancelled
Cloud Tests / integration-tests (push) Has been cancelled
Cloud Tests / e2e-tests (push) Has been cancelled
CodeQL Advanced / Analyze (javascript-typescript) (push) Has been cancelled
Deploy Apps Worker (Product 2) / Determine environment (push) Has been cancelled
Deploy Apps Worker (Product 2) / Deploy apps worker to apps-control host (${{ needs.determine-env.outputs.environment }}) (push) Has been cancelled
Deploy Eliza Provisioning Worker / Determine environment (push) Has been cancelled
Deploy Eliza Provisioning Worker / Deploy worker to Hetzner host (${{ needs.determine-env.outputs.environment }} @ ${{ needs.determine-env.outputs.deployment_sha }}) (push) Has been cancelled
Dev Smoke / Classify changed paths (push) Has been cancelled
supply-chain / sbom (push) Has been cancelled
supply-chain / vulnerability-scan (push) Has been cancelled
Build, Push & Deploy to Phala Cloud / build-and-push (push) Has been cancelled
Test Packaging / Validate Packaging Configs (push) Has been cancelled
Test Packaging / Build & Test PyPI Package (push) Has been cancelled
Test Packaging / PyPI on Python ${{ matrix.python }} (push) Has been cancelled
Test Packaging / Pack & Test JS Tarballs (push) Has been cancelled
UI Fixture E2E / ui-fixture-e2e (push) Has been cancelled
UI Fixture E2E / fixture-e2e (push) Has been cancelled
UI Story Gate / story-gate (push) Has been cancelled
vault-ci / test (macos-latest) (push) Has been cancelled
vault-ci / test (ubuntu-latest) (push) Has been cancelled
vault-ci / test (windows-latest) (push) Has been cancelled
vault-ci / app-core wiring tests (push) Has been cancelled
verify-patches / verify patches/CHECKSUMS.sha256 (push) Has been cancelled
Voice Benchmark Smoke / voice-emotion fixture smoke (push) Has been cancelled
Voice Benchmark Smoke / voiceagentbench fixture smoke (push) Has been cancelled
Voice Benchmark Smoke / voicebench-quality unit smoke (push) Has been cancelled
Voice Benchmark Smoke / voicebench TypeScript unit (no audio) (push) Has been cancelled
Voice Benchmark Smoke / voice bench smoke summary (push) Has been cancelled
Windows CI / windows ([bun run --cwd packages/app-core test bun run --cwd packages/elizaos test bun run --cwd packages/cloud/shared test], app-and-cli) (push) Has been cancelled
Windows CI / windows ([bun run --cwd packages/scenario-runner test bun run --cwd packages/vault test bun run --cwd packages/security test bun run --cwd plugins/plugin-coding-tools test], framework-packages) (push) Has been cancelled
Windows CI / windows ([bun run --cwd plugins/plugin-elizacloud test bun run --cwd plugins/plugin-discord test bun run --cwd plugins/plugin-anthropic test bun run --cwd plugins/plugin-openai test bun run --cwd plugins/plugin-app-control test bun run --cwd plugins/pl… (push) Has been cancelled
Windows CI / windows ([node packages/scripts/run-turbo.mjs run build --filter=@elizaos/core --filter=@elizaos/shared --filter=@elizaos/agent --concurrency=4 node packages/scripts/run-bash-linux-only.mjs scripts/verify-riscv64-buildpaths.sh node packages/scripts/run… (push) Has been cancelled
Windows CI / windows ([node packages/scripts/run-turbo.mjs run typecheck --filter=@elizaos/core --filter=@elizaos/shared --filter=@elizaos/cloud-shared --concurrency=4 bun run --cwd packages/core test bun run --cwd packages/shared test], core-runtime, 75) (push) Has been cancelled
169 lines
4.9 KiB
TypeScript
169 lines
4.9 KiB
TypeScript
// Pins the CI Bun-version contract (#13402) against synthetic repo trees: a
|
|
// clean tree with every gate pinned to the canonical version passes (and a
|
|
// `canary` named only in a comment is ignored), while a divergent concrete pin,
|
|
// a gate floated back to `canary`, a gate missing the pin, and a floating source
|
|
// of truth each fail. Also runs the shipped contract against the real repo so
|
|
// the guard stays true as workflows change. Deterministic — no workflow runs.
|
|
import { describe, expect, test } from "bun:test";
|
|
import { mkdirSync, mkdtempSync, rmSync, writeFileSync } from "node:fs";
|
|
import { tmpdir } from "node:os";
|
|
import { join } from "node:path";
|
|
import { fileURLToPath } from "node:url";
|
|
|
|
const { runContract } = await import(
|
|
new URL("../ci-bun-version-contract.mjs", import.meta.url).href
|
|
);
|
|
|
|
const REAL_REPO_ROOT = fileURLToPath(new URL("../../..", import.meta.url));
|
|
|
|
const CANONICAL = "1.3.14";
|
|
|
|
const GATE_WORKFLOWS = [
|
|
"ci.yaml",
|
|
"test.yml",
|
|
"develop-exhaustive.yml",
|
|
"ci-full-matrix-proof.yml",
|
|
"benchmark-tests.yml",
|
|
"windows-desktop-preload-smoke.yml",
|
|
"feed-env-audit.yml",
|
|
];
|
|
|
|
// A gate stub that pins via a BUN_VERSION env literal and references it from the
|
|
// step by expression — the shape the real gates use. The comment naming
|
|
// `canary` proves the contract reads YAML wiring, not prose.
|
|
function gateStub(version = CANONICAL): string {
|
|
return `name: Gate
|
|
on: [push]
|
|
env:
|
|
# pinned: floating canary writes lockfileVersion 2 and breaks --frozen-lockfile
|
|
BUN_VERSION: "${version}"
|
|
jobs:
|
|
build:
|
|
runs-on: ubuntu-24.04
|
|
steps:
|
|
- uses: ./.github/actions/setup-bun-workspace
|
|
with:
|
|
bun-version: \${{ env.BUN_VERSION }}
|
|
`;
|
|
}
|
|
|
|
const GATE_FLOATING = `name: Gate
|
|
on: [push]
|
|
jobs:
|
|
build:
|
|
runs-on: ubuntu-24.04
|
|
steps:
|
|
- uses: oven-sh/setup-bun@v2
|
|
with:
|
|
bun-version: canary
|
|
`;
|
|
|
|
const GATE_NO_PIN = `name: Gate
|
|
on: [push]
|
|
jobs:
|
|
build:
|
|
runs-on: ubuntu-24.04
|
|
steps:
|
|
- run: echo "no bun setup here"
|
|
`;
|
|
|
|
// A non-gate workflow carrying a concrete pin that diverges from canonical.
|
|
function driftWorkflow(version: string): string {
|
|
return `name: Drift
|
|
on: [push]
|
|
jobs:
|
|
build:
|
|
runs-on: ubuntu-24.04
|
|
steps:
|
|
- uses: oven-sh/setup-bun@v2
|
|
with:
|
|
bun-version: "${version}"
|
|
`;
|
|
}
|
|
|
|
function buildRepo({
|
|
version = CANONICAL,
|
|
overrides = {},
|
|
extra = {},
|
|
}: {
|
|
version?: string;
|
|
overrides?: Record<string, string>;
|
|
extra?: Record<string, string>;
|
|
}): string {
|
|
const root = mkdtempSync(join(tmpdir(), "ci-bun-version-contract-"));
|
|
mkdirSync(join(root, ".github", "workflows"), { recursive: true });
|
|
writeFileSync(
|
|
join(root, ".github", "ci-bun-version.json"),
|
|
JSON.stringify({ version }),
|
|
);
|
|
for (const name of GATE_WORKFLOWS) {
|
|
writeFileSync(
|
|
join(root, ".github", "workflows", name),
|
|
overrides[name] ?? gateStub(),
|
|
);
|
|
}
|
|
for (const [name, content] of Object.entries(extra)) {
|
|
writeFileSync(join(root, ".github", "workflows", name), content);
|
|
}
|
|
return root;
|
|
}
|
|
|
|
describe("ci-bun-version-contract", () => {
|
|
test("passes a clean tree with every gate pinned to canonical", () => {
|
|
const root = buildRepo({});
|
|
try {
|
|
const { canonical, gateWorkflows } = runContract(root);
|
|
expect(canonical).toBe(CANONICAL);
|
|
expect(gateWorkflows).toEqual(GATE_WORKFLOWS);
|
|
} finally {
|
|
rmSync(root, { recursive: true, force: true });
|
|
}
|
|
});
|
|
|
|
test("fails when a concrete pin diverges from the source of truth", () => {
|
|
const root = buildRepo({ extra: { "drift.yml": driftWorkflow("1.3.99") } });
|
|
try {
|
|
expect(() => runContract(root)).toThrow(
|
|
/canonical CI Bun version is 1\.3\.14/,
|
|
);
|
|
} finally {
|
|
rmSync(root, { recursive: true, force: true });
|
|
}
|
|
});
|
|
|
|
test("fails when a gate workflow floats back to canary", () => {
|
|
const root = buildRepo({ overrides: { "test.yml": GATE_FLOATING } });
|
|
try {
|
|
expect(() => runContract(root)).toThrow(/wires floating Bun/);
|
|
} finally {
|
|
rmSync(root, { recursive: true, force: true });
|
|
}
|
|
});
|
|
|
|
test("fails when a gate workflow drops the canonical pin entirely", () => {
|
|
const root = buildRepo({ overrides: { "ci.yaml": GATE_NO_PIN } });
|
|
try {
|
|
expect(() => runContract(root)).toThrow(
|
|
/does not wire the canonical Bun pin/,
|
|
);
|
|
} finally {
|
|
rmSync(root, { recursive: true, force: true });
|
|
}
|
|
});
|
|
|
|
test("fails when the source of truth itself floats", () => {
|
|
const root = buildRepo({ version: "canary" });
|
|
try {
|
|
expect(() => runContract(root)).toThrow(/must be a concrete Bun pin/);
|
|
} finally {
|
|
rmSync(root, { recursive: true, force: true });
|
|
}
|
|
});
|
|
|
|
test("the real repo satisfies the contract", () => {
|
|
const { canonical, gateWorkflows } = runContract(REAL_REPO_ROOT);
|
|
expect(canonical).toBe(CANONICAL);
|
|
expect(gateWorkflows.length).toBeGreaterThan(0);
|
|
});
|
|
});
|