scripts/ci/check-unsafe-hygiene.sh — textual gates for three classes no lint covers: A. unsafe fn markers carrying no contract. unsafe_op_in_unsafe_fn forces real ops into blocks, so an unsafe fn with no `unsafe` in its body is a marker with no contract (db659809found two by hand). Contract-deferring fns (Vec::set_len shape) waive with `// unsafe-fn-no-op-ok: <reason>`; fenced files and `unsafe extern "ABI" fn` (signature-mandated markers) are skipped structurally. B. unwrap/expect/panic! inside extern "C"/"system" bodies — an abort since Rust 1.81, not linted, not fuzzable (8b98d0b3). catch_unwind bodies are exempt; `// panic-in-extern-ok: <reason>` waives a deliberate abort. C. Safe-but-process-global APIs (env::set_var/remove_var, sigaction, setlocale, set_current_dir) — the972af299environ race lived in a file with zero occurrences of the word `unsafe`. Per-file count ratchet with the baseline in the script; any increase or new file fails. Making gate B clean on main surfaced 14 real instances of exactly its class — `.lock().unwrap()` in unguarded extern fns, where a poisoned mutex aborts the embedding process: six punktfunk-core abi.rs entry points (poll_frame, next_au, next_audio, next_audio_pcm, next_cursor_shape, next_clipboard), seven Android JNI entry points, and the Windows client's deeplink wnd_proc. All fixed with poison-recovering locks (the slots are last-value caches, valid whatever a poisoned writer left) and Option::insert for the set-then-unwrap shape; punktfunk-core's 203 lib tests pass. Gate A's findings were six genuine contract-deferring fns — waived with reasons, not fixed, because the markers are correct. Gate-of-the-gate: all three shown to FAIL on deliberately planted instances (marker fn, panicking extern callback, env::set_var in an unlisted file) and to run clean on the tree, before the ci.yml step made them blocking.
333 lines
17 KiB
YAML
333 lines
17 KiB
YAML
# CI for punktfunk (Gitea Actions). Linux jobs run on the `ubuntu-24.04` fleet label; the
|
|
# Rust job runs inside the prebuilt builder image (ci/rust-ci.Dockerfile — system FFmpeg 8,
|
|
# PipeWire, GL/GBM, libcuda link stub, pinned-channel rustup) so the workspace links the
|
|
# same libs as the dev boxes. Builder images come from the LAN registry on home-ci-core
|
|
# (content-keyed, docker.yml) — never the WAN. Apple client CI lives in apple.yml (macOS
|
|
# runner). The report-only benchmarks moved to bench.yml (nightly + dispatch) so they stop
|
|
# occupying a fleet slot on every push.
|
|
name: ci
|
|
# One pending run per workflow+ref: a newer push supersedes the queued/running one and cancels
|
|
# it (a canary only needs the latest commit; each release tag is its own ref so tag runs never
|
|
# cancel each other). Keeps a busy push cadence from piling ~10 queued runs per commit onto the
|
|
# runner fleet. Gitea honors this for push triggers (PR triggers: see gitea#35933).
|
|
concurrency:
|
|
group: ${{ github.workflow }}-${{ github.ref }}
|
|
cancel-in-progress: true
|
|
|
|
|
|
on:
|
|
push:
|
|
branches: [main]
|
|
pull_request:
|
|
|
|
# Shared compile cache: sccache -> RustFS S3 (storage.unom.io, LAN-pinned via ci-core's
|
|
# unbound). Keys include compiler hash + target + flags, so cross-OS/arch entries can
|
|
# never collide; every Rust job on every host feeds and reads one warm cache.
|
|
env:
|
|
RUSTC_WRAPPER: sccache
|
|
SCCACHE_BUCKET: unom-ci-sccache
|
|
SCCACHE_ENDPOINT: https://storage.unom.io
|
|
SCCACHE_REGION: home-central
|
|
AWS_ACCESS_KEY_ID: ${{ secrets.SCCACHE_ACCESS_KEY_ID }}
|
|
AWS_SECRET_ACCESS_KEY: ${{ secrets.SCCACHE_SECRET_ACCESS_KEY }}
|
|
# sccache and incremental compilation are mutually exclusive; CI wants the shared
|
|
# cache, dev boxes keep incremental.
|
|
CARGO_INCREMENTAL: "0"
|
|
|
|
jobs:
|
|
rust:
|
|
runs-on: ubuntu-24.04
|
|
container:
|
|
image: 192.168.1.58:5010/punktfunk-rust-ci:latest
|
|
timeout-minutes: 90
|
|
steps:
|
|
- uses: actions/checkout@v4
|
|
|
|
# Shared compile cache (sccache -> RustFS S3 over the LAN). Baked into the builder
|
|
# images; this fetch keeps the job green while the running :latest predates the bake.
|
|
- name: sccache (no-op once the image bakes it)
|
|
run: |
|
|
command -v sccache >/dev/null 2>&1 || {
|
|
curl -fsSL https://github.com/mozilla/sccache/releases/download/v0.10.0/sccache-v0.10.0-x86_64-unknown-linux-musl.tar.gz \
|
|
| tar -xz --wildcards --strip-components=1 -C /usr/local/bin '*/sccache'
|
|
}
|
|
sccache --version
|
|
|
|
# punktfunk-client-linux link deps. Also baked into rust-ci.Dockerfile — but ci.yml
|
|
# runs against the image from the PREVIOUS push (docker.yml bootstrap note), so this
|
|
# keeps the job green across image-content changes; a no-op once the image has them.
|
|
- name: GTK4/libadwaita/SDL3 dev packages
|
|
run: |
|
|
apt-get update
|
|
apt-get install -y --no-install-recommends libgtk-4-dev libadwaita-1-dev libsdl3-dev
|
|
|
|
# The committed pf-zerocopy SPIR-V blobs are pulled in with include_bytes! and rebuilt only
|
|
# by hand — edit a .comp, forget the rebuild, and the OLD kernel ships with no compile error
|
|
# or failing test. Recompile each shader and diff the disassembly. Filtering OpSourceExtension
|
|
# (+ --no-header) is exactly what absorbs the shaderc-vs-glslang generator difference; every
|
|
# instruction, ID and constant must match.
|
|
#
|
|
# Disassemble to FILES rather than `diff <(…) <(…)`: Gitea's runner executes a step's `run:`
|
|
# under `sh -e`, not bash, and dash has no process substitution — the shell rejected the
|
|
# script at PARSE time, so the gate never compared anything. Worse, it took the whole `rust`
|
|
# job with it: Format, Clippy, Build, Test and every gate below were skipped on each of the
|
|
# 35 commits between the gate landing (143a707f) and this fix. A gate that cannot run is
|
|
# indistinguishable from one that passes, which is exactly the failure it exists to prevent.
|
|
- name: Shader SPIR-V drift gate (pf-zerocopy)
|
|
run: |
|
|
apt-get install -y --no-install-recommends glslang-tools spirv-tools
|
|
for s in rgb2nv12_buf cursor_blend; do
|
|
d=crates/pf-zerocopy/src/imp
|
|
glslangValidator -V "$d/$s.comp" -o "/tmp/$s.spv" >/dev/null
|
|
spirv-dis --no-header "$d/$s.spv" | grep -v OpSourceExtension > "/tmp/$s.committed"
|
|
spirv-dis --no-header "/tmp/$s.spv" | grep -v OpSourceExtension > "/tmp/$s.rebuilt"
|
|
diff "/tmp/$s.committed" "/tmp/$s.rebuilt" \
|
|
|| { echo "::error::$d/$s.spv is stale — rebuild it from $s.comp"; exit 1; }
|
|
done
|
|
|
|
# Best-effort caches (act_runner's built-in cache server). Keyed on Cargo.lock:
|
|
# registry/git are download caches, target/ the incremental build. The target key
|
|
# carries the rustc version — resolved via `rustc --version` (below) rather than parsed
|
|
# from rust-toolchain.toml, so a pin bump there invalidates stale incremental state too.
|
|
- name: Cache keys
|
|
run: echo "rustc=$(rustc --version | cut -d' ' -f2)" >> "$GITHUB_ENV"
|
|
- uses: actions/cache@v4
|
|
with:
|
|
path: |
|
|
/usr/local/cargo/registry
|
|
/usr/local/cargo/git
|
|
key: cargo-home-${{ hashFiles('Cargo.lock') }}
|
|
restore-keys: cargo-home-
|
|
- uses: actions/cache@v4
|
|
with:
|
|
path: target
|
|
# -v3-: the prior `cargo-target-<rustc>-*` cache was poisoned when the runner ran
|
|
# out of disk mid-build and actions/cache saved a truncated target/ (a dep's .rmeta
|
|
# went missing -> E0463 "can't find crate"). A suffix bump wouldn't help — restore-keys
|
|
# would fall back to the poisoned prefix — so the prefix itself is versioned.
|
|
key: cargo-target-v3-${{ env.rustc }}-${{ hashFiles('Cargo.lock') }}
|
|
restore-keys: cargo-target-v3-${{ env.rustc }}-
|
|
|
|
- name: Format
|
|
run: cargo fmt --all --check
|
|
|
|
# rust-safety WP2c: three textual gates for classes no lint covers — unsafe fn markers
|
|
# carrying no contract, panic across an extern boundary (an abort since 1.81), and
|
|
# process-global safe APIs (env::set_var & co, count-ratcheted). Pure grep/awk, no cargo.
|
|
# Both failure modes were demonstrated before this became blocking (planted instances).
|
|
- name: Unsafe-hygiene grep gates
|
|
run: sh scripts/ci/check-unsafe-hygiene.sh
|
|
|
|
- name: Clippy (deny warnings)
|
|
run: cargo clippy --workspace --all-targets --locked -- -D warnings
|
|
|
|
# WP19 (rust-safety): the hardened NATIVE-ONLY host — no Moonlight-compat planes, no
|
|
# `rusty_enet` (transpiled C ENet), no `rsa`. Kept compiling here so the cfg boundary can't
|
|
# rot, and the dependency claim is ASSERTED, not assumed: `cargo tree -i` must find neither
|
|
# crate in the native-only graph (it exits non-zero with "nothing depends on" — inverted).
|
|
- name: Clippy + tree (native-only host, no gamestream feature)
|
|
run: |
|
|
cargo clippy -p punktfunk-host --no-default-features --features pyrowave \
|
|
--all-targets --locked -- -D warnings
|
|
if cargo tree -p punktfunk-host --no-default-features --features pyrowave \
|
|
--locked -i rusty_enet 2>/dev/null | grep -q rusty_enet; then
|
|
echo "native-only build still depends on rusty_enet"; exit 1; fi
|
|
if cargo tree -p punktfunk-host --no-default-features --features pyrowave \
|
|
--locked -i rsa 2>/dev/null | grep -q "^rsa"; then
|
|
echo "native-only build still depends on rsa"; exit 1; fi
|
|
|
|
- name: Build
|
|
run: cargo build --workspace --locked
|
|
|
|
- name: Test (unit + loopback + proptest + C ABI harness)
|
|
run: cargo test --workspace --locked
|
|
|
|
# The GPU encode backends are OFF by default, so every step above compiles ~none of them:
|
|
# `nvenc` gates enc/linux/nvenc_cuda.rs (+ nvenc_core/nvenc_status) and `vulkan-encode` gates
|
|
# enc/linux/vulkan_video.rs (+ the vendored vk_av1_encode/vk_valve_rgb bindings) — ~8,150
|
|
# lines carrying ~70 `unsafe` blocks. Their ONLY prior CI coverage was deb.yml's
|
|
# `cargo build`, where warnings are not errors, so pf-encode's own
|
|
# `#![deny(clippy::undocumented_unsafe_blocks)]` — the crate's stated unsafe-proof gate —
|
|
# was never actually enforced on them. (`pyrowave` needs no extra step: punktfunk-host has
|
|
# `default = ["pyrowave"]`, so the steps above already cover it.)
|
|
#
|
|
# `--all-targets` is load-bearing, not decoration: without it the feature-gated
|
|
# `#[cfg(test)]` modules are never compiled, which is exactly how all ten
|
|
# `NvencCudaEncoder::open` call sites in nvenc_cuda.rs's tests drifted to the wrong arity
|
|
# (E0061 x10) without any job noticing.
|
|
#
|
|
# GPU-free: every test needing real hardware is `#[ignore]`d, and NVENC/CUDA resolve their
|
|
# entry points at RUNTIME (dlopen), so the test binary links without a driver present.
|
|
# (On MSVC the same crate link-imports those symbols instead, which is why windows-host.yml
|
|
# can only type-check these tests via clippy — see the note there.)
|
|
#
|
|
# Scoped to `-p pf-encode` with ITS OWN feature names: punktfunk-host has no code gated on
|
|
# `nvenc`/`vulkan-encode` (its only `cfg(feature)` sites are the two `pyrowave` ones in
|
|
# capture.rs, and pyrowave is default-on, so the steps above already cover them). Going
|
|
# through `--features punktfunk-host/...` would force punktfunk-host into the selection and
|
|
# re-run its entire test suite a second time for no extra coverage.
|
|
#
|
|
# `pyrowave` is listed explicitly even though it is punktfunk-host's default: selecting only
|
|
# `-p pf-encode` takes the host out of the resolution, and pf-encode's own default is empty.
|
|
# Naming it keeps this the SHIPPED Linux feature set — deb.yml builds
|
|
# `--features punktfunk-host/nvenc,punktfunk-host/vulkan-encode` WITHOUT
|
|
# `--no-default-features`, so the .deb carries nvenc + vulkan-encode + pyrowave together, and
|
|
# that combination is what deserves the lint.
|
|
- name: Clippy + test the feature-gated Linux encode backends
|
|
run: |
|
|
cargo clippy -p pf-encode --all-targets --locked \
|
|
--features nvenc,vulkan-encode,pyrowave -- -D warnings
|
|
cargo test -p pf-encode --locked --features nvenc,vulkan-encode,pyrowave
|
|
|
|
- name: C ABI harness (standalone link proof)
|
|
run: bash crates/punktfunk-core/tests/c/run.sh
|
|
|
|
- name: sccache stats (visibility only)
|
|
run: sccache --show-stats
|
|
|
|
- name: Verify generated header is committed & up to date
|
|
run: |
|
|
cargo build -p punktfunk-core --locked
|
|
git config --global --add safe.directory "$PWD"
|
|
git diff --exit-code include/punktfunk_core.h \
|
|
|| (echo "include/punktfunk_core.h is stale — commit the regenerated header" && exit 1)
|
|
|
|
# The client stack cross-checked for aarch64. NOT an artifact job — deb.yml ships those —
|
|
# this exists so a portability defect fails here instead of surfacing in a release build or
|
|
# on a user's board. It earns its runtime: the bug that motivated it (a Vulkan extension
|
|
# array typed `*const i8`, where `c_char` is signed on x86_64 and UNSIGNED on aarch64)
|
|
# compiled cleanly on every target CI built at the time.
|
|
#
|
|
# Client crates only, listed explicitly: the host's encode stack is x86 (NVENC/QSV/AMF) and
|
|
# `--workspace` would drag it in. Runs in the cross image (amd64 toolchain + arm64 sysroot,
|
|
# ci/rust-ci-arm64cross.Dockerfile) on the ordinary runner — no arm64 runner involved.
|
|
rust-arm64:
|
|
runs-on: ubuntu-24.04
|
|
container:
|
|
image: 192.168.1.58:5010/punktfunk-rust-ci-arm64cross:latest
|
|
timeout-minutes: 60
|
|
steps:
|
|
- uses: actions/checkout@v4
|
|
|
|
# Shared compile cache (sccache -> RustFS S3 over the LAN). Baked into the builder
|
|
# images; this fetch keeps the job green while the running :latest predates the bake.
|
|
- name: sccache (no-op once the image bakes it)
|
|
run: |
|
|
command -v sccache >/dev/null 2>&1 || {
|
|
curl -fsSL https://github.com/mozilla/sccache/releases/download/v0.10.0/sccache-v0.10.0-x86_64-unknown-linux-musl.tar.gz \
|
|
| tar -xz --wildcards --strip-components=1 -C /usr/local/bin '*/sccache'
|
|
}
|
|
sccache --version
|
|
|
|
- name: Cache keys
|
|
run: echo "rustc=$(rustc --version | cut -d' ' -f2)" >> "$GITHUB_ENV"
|
|
- uses: actions/cache@v4
|
|
with:
|
|
path: |
|
|
/usr/local/cargo/registry
|
|
/usr/local/cargo/git
|
|
key: cargo-home-${{ hashFiles('Cargo.lock') }}
|
|
restore-keys: cargo-home-
|
|
- uses: actions/cache@v4
|
|
with:
|
|
path: target
|
|
# Its OWN prefix: aarch64 artifacts must never share the amd64 jobs' target cache.
|
|
key: cargo-target-arm64-v1-${{ env.rustc }}-${{ hashFiles('Cargo.lock') }}
|
|
restore-keys: cargo-target-arm64-v1-${{ env.rustc }}-
|
|
|
|
- name: Clippy for aarch64 (deny warnings)
|
|
run: |
|
|
cargo clippy --target aarch64-unknown-linux-gnu --all-targets --locked \
|
|
-p punktfunk-core -p pf-client-core -p pf-presenter -p pf-console-ui \
|
|
-p punktfunk-client-session -p punktfunk-client-linux \
|
|
-- -D warnings
|
|
|
|
# The minimal embedded build — no Skia, no PyroWave — is what a small image installs, so
|
|
# it has to keep compiling on its own, not just as a subset of the default features.
|
|
- name: Build the session binary, minimal features
|
|
run: |
|
|
cargo build --release --target aarch64-unknown-linux-gnu --locked \
|
|
-p punktfunk-client-session --no-default-features
|
|
|
|
web:
|
|
runs-on: ubuntu-24.04
|
|
container:
|
|
image: oven/bun:1
|
|
timeout-minutes: 30
|
|
defaults:
|
|
run:
|
|
working-directory: web
|
|
steps:
|
|
# oven/bun ships neither git nor a real node (only a bun shim) — actions/checkout
|
|
# needs both. The slim Debian base also lacks ca-certificates, so without it git's
|
|
# HTTPS fetch of the repo dies with "Problem with the SSL CA cert (path? access
|
|
# rights?)" — no CA bundle to validate git.unom.io's (public) Let's Encrypt cert.
|
|
- name: Install git + node + CA certs
|
|
working-directory: /
|
|
run: apt-get update && apt-get install -y --no-install-recommends ca-certificates git nodejs
|
|
- uses: actions/checkout@v4
|
|
- name: Install dependencies
|
|
run: bun install --frozen-lockfile --ignore-scripts
|
|
# Build first: it generates the orval API client + paraglide messages that
|
|
# typechecking imports.
|
|
- name: Build
|
|
run: bun run build
|
|
- name: Typecheck
|
|
run: bun run lint
|
|
# Scoped to server/: the console's browser code has no test runner, but the gate that keeps a
|
|
# plugin's origin apart from the console's does — and its failure mode is a well-formed header
|
|
# that only a browser rejects, which nothing else here would catch.
|
|
- name: Test
|
|
run: bun run test
|
|
|
|
docs-site:
|
|
runs-on: ubuntu-24.04
|
|
container:
|
|
image: oven/bun:1
|
|
timeout-minutes: 30
|
|
defaults:
|
|
run:
|
|
working-directory: docs-site
|
|
steps:
|
|
# ca-certificates: the slim Debian base lacks a CA bundle, so actions/checkout's
|
|
# HTTPS fetch otherwise fails with "Problem with the SSL CA cert" (see web job).
|
|
- name: Install git + CA certs
|
|
working-directory: /
|
|
run: apt-get update && apt-get install -y --no-install-recommends ca-certificates git
|
|
- uses: actions/checkout@v4
|
|
- name: Install dependencies
|
|
run: bun install --frozen-lockfile --ignore-scripts
|
|
# Build first: fumadocs-mdx emits the .source typegen the typecheck imports.
|
|
- name: Build
|
|
run: bun run build
|
|
- name: Typecheck
|
|
run: bun run lint
|
|
|
|
# web/bun.nix and sdk/bun.nix are GENERATED from their bun.lock (bun2nix) and committed; the Nix
|
|
# build fetches node_modules from nothing else. They regenerate only on a local `bun install` that
|
|
# runs lifecycle scripts — never under CI's `--ignore-scripts`, and never on a merge or rebase,
|
|
# which happily carries a lockfile change past a bun.nix generated before it. That is not
|
|
# theoretical: web/bun.nix sat stale on main for 553 commits (2026-07-27 → 2026-08-05) with
|
|
# `nix build .#punktfunk-web` broken, and was repaired only by accident when an advisory bump
|
|
# happened to rerun a real `bun install`.
|
|
#
|
|
# Deliberately UNFILTERED and in ci.yml rather than nix.yml: it needs no Nix, takes well under a
|
|
# minute, and the whole point is that the drift arrives through commits that look unrelated to
|
|
# Nix. The Nix-toolchain gates (flake eval + building the bun packages) live in nix.yml.
|
|
bun-nix:
|
|
runs-on: ubuntu-24.04
|
|
container:
|
|
image: oven/bun:1
|
|
timeout-minutes: 15
|
|
steps:
|
|
# oven/bun ships neither git nor a real node, and the slim base has no CA bundle —
|
|
# actions/checkout needs all three (see the web job).
|
|
- name: Install git + node + CA certs
|
|
run: apt-get update && apt-get install -y --no-install-recommends ca-certificates git nodejs
|
|
- uses: actions/checkout@v4
|
|
# Regenerates each bun.nix from its committed bun.lock and diffs, and checks that the
|
|
# bun2nix version pin agrees across flake.nix and both package.json files (bun.nix has no
|
|
# schema stability across bun2nix releases). Fix with: scripts/ci/check-bun-nix.sh --fix
|
|
- name: bun.nix drift gate
|
|
run: sh scripts/ci/check-bun-nix.sh
|