Skip to content

Preserve native corruption boundaries and isolate benchmark credentials #115

Preserve native corruption boundaries and isolate benchmark credentials

Preserve native corruption boundaries and isolate benchmark credentials #115

Workflow file for this run

name: CI
on:
push:
branches: [main]
pull_request:
workflow_dispatch:
permissions:
contents: read
concurrency:
group: keyload-ci-${{ github.ref }}
cancel-in-progress: ${{ github.event_name == 'pull_request' }}
jobs:
repository-checks:
name: Check repository rules
runs-on: ubuntu-latest
timeout-minutes: 5
steps:
- name: Download source code
uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
- name: Check repository rules
run: node scripts/Features/RepositoryGovernance/verify.mjs
analyzer-rules:
name: Test code analyzers
runs-on: ubuntu-latest
timeout-minutes: 10
steps:
- name: Download source code
uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
- name: Set up .NET
uses: actions/setup-dotnet@a98b56852c35b8e3190ac28c8c2271da59106c68 # v6.0.0
with:
global-json-file: global.json
- name: Restore .NET packages
run: dotnet restore tests/KeyLoad.Analyzers.Tests/KeyLoad.Analyzers.Tests.csproj
- name: Build analyzer tests
run: dotnet build tests/KeyLoad.Analyzers.Tests/KeyLoad.Analyzers.Tests.csproj --no-restore --configuration Release
- name: Run analyzer tests
run: dotnet test --project tests/KeyLoad.Analyzers.Tests --no-build --no-restore --configuration Release
- name: Save analyzer test results
uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1
if: always()
with:
name: analyzer-rule-evidence
path: |
TestResults/**
tests/KeyLoad.Analyzers.Tests/**/TestResults/**
artifacts/code-quality/**
if-no-files-found: error
verify:
name: Build and test KeyLoad
needs: repository-checks
strategy:
fail-fast: false
matrix:
os: [ubuntu-latest]
runs-on: ${{ matrix.os }}
timeout-minutes: 30
steps:
- name: Download source code
uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
- name: Set up .NET
uses: actions/setup-dotnet@a98b56852c35b8e3190ac28c8c2271da59106c68 # v6.0.0
with:
global-json-file: global.json
- name: Restore .NET packages
run: dotnet restore KeyLoad.slnx
- name: Build KeyLoad
id: build
run: dotnet build KeyLoad.slnx --no-restore --configuration Release
- name: Check code formatting
run: dotnet format KeyLoad.slnx --verify-no-changes --no-restore
- name: Check repository rules
run: node scripts/Features/RepositoryGovernance/verify.mjs
- name: Test code analyzers
run: dotnet test --project tests/KeyLoad.Analyzers.Tests --no-build --no-restore --configuration Release
- name: Run unit tests
run: dotnet test --project tests/KeyLoad.UnitTests --no-build --no-restore --configuration Release
- name: Run unit tests without CPU intrinsics
run: dotnet test --project tests/KeyLoad.UnitTests --no-build --no-restore --configuration Release --results-directory TestResults/unit-scalar
env:
DOTNET_EnableHWIntrinsic: 0
- name: Test recovery after process crashes
if: ${{ !cancelled() && steps.build.outcome == 'success' }}
run: dotnet test --project tests/KeyLoad.RecoveryTests --no-build --no-restore --configuration Release
- name: Save test results
uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1
if: always()
with:
name: test-results-${{ matrix.os }}
path: |
**/TestResults/**
artifacts/qualification/**
if-no-files-found: ignore
- name: Save build diagnostics
uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1
if: always()
with:
name: code-quality-${{ matrix.os }}
path: artifacts/code-quality/**
if-no-files-found: error
docker-rf3:
name: Test three-node database
runs-on: ubuntu-latest
timeout-minutes: 60
steps:
- name: Download source code
uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
- name: Set up .NET
uses: actions/setup-dotnet@a98b56852c35b8e3190ac28c8c2271da59106c68 # v6.0.0
with:
global-json-file: global.json
- name: Check Docker
run: docker version
- name: Build KeyLoad server and benchmark Docker images
id: images
run: node scripts/Features/BenchmarkComparisons/prepare-images.mjs
- name: Configure Docker image references
shell: bash
env:
KEYLOAD_SERVER_IMAGE: ${{ steps.images.outputs.server-image }}
KEYLOAD_RUNNER_IMAGE: ${{ steps.images.outputs.load-generator-image }}
run: |
test -n "$KEYLOAD_SERVER_IMAGE" && test -n "$KEYLOAD_RUNNER_IMAGE"
printf 'KeyLoad__ContainerImages__Server=%s\nBenchmarks__ContainerImages__LoadGenerator=%s\nKEYLOAD_IMAGE_RECEIPT=%s\n' "$KEYLOAD_SERVER_IMAGE" "$KEYLOAD_RUNNER_IMAGE" "$RUNNER_TEMP/keyload-images/image-receipt.json" >> "$GITHUB_ENV"
- name: Find Chrome for admin tests
shell: bash
run: |
admin_chrome=$(command -v google-chrome || command -v google-chrome-stable || command -v chromium || command -v chromium-browser)
test -n "$admin_chrome" && test -x "$admin_chrome"
"$admin_chrome" --version
printf 'KEYLOAD_ADMIN_CHROME_PATH=%s\n' "$admin_chrome" >> "$GITHUB_ENV"
- name: Restore .NET packages
run: dotnet restore KeyLoad.slnx
- name: Build three-node database tests
run: dotnet build tests/KeyLoad.IntegrationTests --no-restore --configuration Release
- name: Test three-node database with .NET and MCP clients
run: dotnet test --project tests/KeyLoad.IntegrationTests --no-build --no-restore --configuration Release
- name: Clean up Docker registry
if: ${{ always() && (steps.images.outcome == 'success' || steps.images.outcome == 'failure') }}
run: node scripts/Features/BenchmarkComparisons/cleanup-images.mjs
- name: Save three-node Docker image logs
if: ${{ always() && (steps.images.outcome == 'success' || steps.images.outcome == 'failure') }}
uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1
with:
name: docker-rf3-image-evidence
path: ${{ runner.temp }}/keyload-images/**
if-no-files-found: error
- name: Save three-node database test results
uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1
if: always()
with:
name: docker-rf3-qualification
path: |
TestResults/**
tests/KeyLoad.IntegrationTests/**/TestResults/**
artifacts/qualification/**
if-no-files-found: error
- name: Save three-node build diagnostics
uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1
if: always()
with:
name: code-quality-docker-rf3
path: artifacts/code-quality/**
if-no-files-found: error