Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
50 changes: 9 additions & 41 deletions .github/workflows/ci-test.yml
Original file line number Diff line number Diff line change
Expand Up @@ -13,12 +13,7 @@
# every push to `main`. Required status checks retain their names.
# Notes : `cancel-in-progress: false` — every main push gets a full run
# No trigger on feat/* or fix/* (frequent changes).
# Trust : push, manual dispatch and same-repository pull requests use the
# repository self-hosted Linux/Windows runners; fork pull requests
# and dependabot keep GitHub-hosted runners. Routing is exposure
# reduction, not a security boundary (a fork PR runs its own copy of
# this workflow), so the self-hosted services stay stopped until the
# repository admission policy is accepted.
# Runners : All events use GitHub-hosted Ubuntu and Windows runners.
# ============================================================================

name: 🧪 CI · Test
Expand Down Expand Up @@ -56,16 +51,13 @@ jobs:
settings:
- name: linux
host: ubuntu-latest
selfHosted: [self-hosted, Linux, X64]
# windows dropped: this fork runs on free windows-latest runners
# (not the paid Blacksmith 4vCPU hosts upstream uses), and the
# opencode:test suite (3048 tests, many spawning real CLI
# subprocesses) doesn't fit the standard runner's slower
# process-spawn/IO within a reasonable CI budget. E2E Tests
# (windows) is unaffected and still covers the platform.
# Trusted events only; GitHub-hosted remains the fallback for fork pull
# requests and dependabot.
runs-on: ${{ (github.event_name == 'push' || github.event_name == 'workflow_dispatch' || (github.event_name == 'pull_request' && github.event.pull_request.head.repo.full_name == github.repository && github.event.pull_request.user.login != 'dependabot[bot]' && github.actor != 'dependabot[bot]')) && matrix.settings.selfHosted || matrix.settings.host }}
runs-on: ${{ matrix.settings.host }}
defaults:
run:
shell: bash
Expand All @@ -87,7 +79,7 @@ jobs:
with:
check: unit
job-name: Unit Tests (${{ matrix.settings.name }})
runner-label: ${{ (github.event_name == 'push' || github.event_name == 'workflow_dispatch' || (github.event_name == 'pull_request' && github.event.pull_request.head.repo.full_name == github.repository && github.event.pull_request.user.login != 'dependabot[bot]' && github.actor != 'dependabot[bot]')) && join(matrix.settings.selfHosted, ',') || matrix.settings.host }}
runner-label: ${{ matrix.settings.host }}

- name: Setup Go
if: steps.evidence.outputs.reused != 'true' && (runner.os == 'Linux')
Expand Down Expand Up @@ -120,16 +112,10 @@ jobs:
# tool.glob tests hit ripgrep; without the system binary, binary.ts
# downloads rg from GitHub releases every run (temp XDG per preload),
# gambling on network stability — ECONNRESET fails the test.
# GitHub-hosted runners install it with sudo; the self-hosted runner
# account has no sudo, so require host provisioning and fail clearly.
run: |
if command -v rg >/dev/null 2>&1; then
exit 0
fi
if [ "$RUNNER_ENVIRONMENT" = "self-hosted" ]; then
echo "::error::ripgrep (rg) is required but missing on this self-hosted runner. Provision it on the host; CI jobs run without sudo."
exit 1
fi
sudo apt-get update && sudo apt-get install -y ripgrep

- name: Cache Turbo
Expand Down Expand Up @@ -159,8 +145,10 @@ jobs:
# time it runs — that silence can look like a hang but isn't one.
# 20m was never sized against real data; give it margin above the
# measured baseline instead of racing it.
# Hosted runners execute workspace tasks one at a time. This avoids
# CPU contention between builds and tests timing out 250ms Node workers.
timeout-minutes: 35
run: GITHUB_ACTIONS=false bun turbo test
run: GITHUB_ACTIONS=false bun turbo test --concurrency=1
env:
OPENCODE_EXPERIMENTAL_DISABLE_FILEWATCHER: ${{ runner.os == 'Windows' && 'true' || 'false' }}

Expand Down Expand Up @@ -214,13 +202,9 @@ jobs:
settings:
- name: linux
host: ubuntu-latest
selfHosted: [self-hosted, Linux, X64]
- name: windows
host: windows-latest
selfHosted: [self-hosted, Windows, X64]
# Trusted events only; GitHub-hosted remains the fallback for fork pull
# requests and dependabot.
runs-on: ${{ (github.event_name == 'push' || github.event_name == 'workflow_dispatch' || (github.event_name == 'pull_request' && github.event.pull_request.head.repo.full_name == github.repository && github.event.pull_request.user.login != 'dependabot[bot]' && github.actor != 'dependabot[bot]')) && matrix.settings.selfHosted || matrix.settings.host }}
runs-on: ${{ matrix.settings.host }}
env:
PLAYWRIGHT_BROWSERS_PATH: ${{ github.workspace }}/.playwright-browsers
defaults:
Expand All @@ -245,7 +229,7 @@ jobs:
with:
check: e2e
job-name: E2E Tests (${{ matrix.settings.name }})
runner-label: ${{ (github.event_name == 'push' || github.event_name == 'workflow_dispatch' || (github.event_name == 'pull_request' && github.event.pull_request.head.repo.full_name == github.repository && github.event.pull_request.user.login != 'dependabot[bot]' && github.actor != 'dependabot[bot]')) && join(matrix.settings.selfHosted, ',') || matrix.settings.host }}
runner-label: ${{ matrix.settings.host }}

- name: Setup Bun
if: steps.evidence.outputs.reused != 'true'
Expand All @@ -271,11 +255,7 @@ jobs:
key: ${{ runner.os }}-${{ runner.arch }}-playwright-${{ steps.playwright-version.outputs.version }}-chromium

- name: Install Playwright system dependencies
# GitHub-hosted runners install the Chromium system libraries here.
# The self-hosted runner account has no sudo: the host is provisioned
# up front and the verification step below fails actionably when a
# library is missing.
if: steps.evidence.outputs.reused != 'true' && (runner.os == 'Linux') && (runner.environment == 'github-hosted')
if: steps.evidence.outputs.reused != 'true' && (runner.os == 'Linux')
working-directory: packages/app
run: bunx playwright install-deps chromium

Expand All @@ -284,18 +264,6 @@ jobs:
working-directory: packages/app
run: bunx playwright install chromium

- name: Verify Playwright Chromium dependencies
# Self-hosted only: execute the resolved browser so the dynamic loader
# proves every required system library is present. No sudo is used.
if: steps.evidence.outputs.reused != 'true' && (runner.os == 'Linux') && (runner.environment == 'self-hosted')
working-directory: packages/app
run: |
browser="$(node -e "process.stdout.write(require('@playwright/test').chromium.executablePath())")"
if ! "$browser" --version; then
echo "::error::Chromium cannot start on this self-hosted runner. Provision the Playwright Chromium system dependencies on the host; CI jobs run without sudo."
exit 1
fi

- name: Verify DAG artifact storage on Windows
if: steps.evidence.outputs.reused != 'true' && runner.os == 'Windows'
working-directory: packages/opencode
Expand Down
13 changes: 3 additions & 10 deletions .github/workflows/ci-typecheck.yml
Original file line number Diff line number Diff line change
Expand Up @@ -9,12 +9,7 @@
# state-machine and persistence changes before they merge to main.
# Notes : No push trigger on feat/* or fix/* (frequent changes); PRs cover
# them.
# Trust : push, manual dispatch and same-repository pull requests use the
# repository self-hosted Linux runner; fork pull requests and
# dependabot keep GitHub-hosted runners. Routing is exposure
# reduction, not a security boundary (a fork PR runs its own copy of
# this workflow), so the self-hosted services stay stopped until the
# repository admission policy is accepted.
# Runners : All events use GitHub-hosted Ubuntu runners.
# ============================================================================

name: 🔍 CI · Typecheck
Expand All @@ -37,9 +32,7 @@ permissions:
jobs:
typecheck:
name: Typecheck
# Trusted events only; GitHub-hosted remains the fallback for fork pull
# requests and dependabot.
runs-on: ${{ (github.event_name == 'push' || github.event_name == 'workflow_dispatch' || (github.event_name == 'pull_request' && github.event.pull_request.head.repo.full_name == github.repository && github.event.pull_request.user.login != 'dependabot[bot]' && github.actor != 'dependabot[bot]')) && fromJSON('["self-hosted","Linux","X64"]') || 'ubuntu-latest' }}
runs-on: ubuntu-latest
steps:
- name: Checkout repository
uses: actions/checkout@34e114876b0b11c390a56381ad16ebd13914f8d5 # v4.3.1
Expand All @@ -56,7 +49,7 @@ jobs:
with:
check: typecheck
job-name: Typecheck
runner-label: ${{ (github.event_name == 'push' || github.event_name == 'workflow_dispatch' || (github.event_name == 'pull_request' && github.event.pull_request.head.repo.full_name == github.repository && github.event.pull_request.user.login != 'dependabot[bot]' && github.actor != 'dependabot[bot]')) && 'self-hosted,Linux,X64' || 'ubuntu-latest' }}
runner-label: ubuntu-latest

- name: Setup Bun
if: steps.evidence.outputs.reused != 'true'
Expand Down
14 changes: 7 additions & 7 deletions .github/workflows/release-fork.yml
Original file line number Diff line number Diff line change
Expand Up @@ -63,7 +63,7 @@ jobs:
version:
name: Resolve GraphAgent Version
if: github.event_name == 'workflow_dispatch'
runs-on: [self-hosted, Linux, X64]
runs-on: ubuntu-latest
timeout-minutes: 10
outputs:
channel: ${{ steps.release-version.outputs.channel }}
Expand Down Expand Up @@ -107,7 +107,7 @@ jobs:
package-templates:
name: Package Reference Templates
if: github.event_name == 'workflow_dispatch' && github.ref == 'refs/heads/main'
runs-on: [self-hosted, Linux, X64]
runs-on: ubuntu-latest
timeout-minutes: 30
permissions:
contents: read
Expand Down Expand Up @@ -178,11 +178,11 @@ jobs:
fail-fast: false
matrix:
include:
- runner: [self-hosted, Linux, X64]
- runner: ubuntu-latest
name: linux
- runner: macos-latest
name: macos
- runner: [self-hosted, Windows, X64]
- runner: windows-latest
name: windows
runs-on: ${{ matrix.runner }}
timeout-minutes: 45
Expand Down Expand Up @@ -316,7 +316,7 @@ jobs:
name: Prepare Release Candidate
needs: [version, build-cli, package-templates]
if: github.event_name == 'workflow_dispatch' && github.ref == 'refs/heads/main'
runs-on: [self-hosted, Linux, X64]
runs-on: ubuntu-latest
timeout-minutes: 15
steps:
- name: Checkout Repository
Expand Down Expand Up @@ -415,7 +415,7 @@ jobs:
name: Create GitHub Release
needs: [version, prepare-release]
if: inputs.create_release && github.ref == 'refs/heads/main'
runs-on: [self-hosted, Linux, X64]
runs-on: ubuntu-latest
timeout-minutes: 10
permissions:
contents: write
Expand Down Expand Up @@ -487,7 +487,7 @@ jobs:
register:
name: Register Workflow
if: github.event_name == 'push'
runs-on: [self-hosted, Linux, X64]
runs-on: ubuntu-latest
timeout-minutes: 5
steps:
- name: Register Workflow
Expand Down
11 changes: 5 additions & 6 deletions .github/workflows/runner-smoke.yml
Original file line number Diff line number Diff line change
@@ -1,10 +1,9 @@
# ============================================================================
# Runner smoke
# ----------------------------------------------------------------------------
# Purpose : Dispatch-only probe for the repository-scoped self-hosted runners
# on 192.168.34.92 (Ubuntu) and 192.168.34.93 (Windows)
# Purpose : Dispatch-only probe for GitHub-hosted runners
# Trigger : Manual `workflow_dispatch` with a required linux/windows choice
# Jobs : exactly one platform job per dispatch, standard self-hosted labels
# Jobs : exactly one platform job per dispatch, standard GitHub-hosted labels
# Notes : no checkout, no third-party actions, no secrets and no token; each
# job is bounded to 10 minutes and reports runner/account identity
# and installed tool versions only.
Expand All @@ -16,7 +15,7 @@ on:
workflow_dispatch:
inputs:
platform:
description: Platform to exercise on its self-hosted runner
description: Platform to exercise on its GitHub-hosted runner
required: true
type: choice
options:
Expand All @@ -34,7 +33,7 @@ jobs:
smoke-linux:
name: Runner smoke (linux)
if: inputs.platform == 'linux'
runs-on: [self-hosted, Linux, X64]
runs-on: ubuntu-latest
timeout-minutes: 10
permissions: {}
steps:
Expand Down Expand Up @@ -71,7 +70,7 @@ jobs:
smoke-windows:
name: Runner smoke (windows)
if: inputs.platform == 'windows'
runs-on: [self-hosted, Windows, X64]
runs-on: windows-latest
timeout-minutes: 10
permissions: {}
steps:
Expand Down
Loading
Loading