Repository navigation
169 lines (149 loc) · 6.19 KB
/
Copy pathci.yml
File metadata and controls
169 lines (149 loc) · 6.19 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
130
131
132
133
134
135
136
137
138
139
140
141
142
143
144
145
146
147
148
149
150
151
152
153
154
155
156
157
158
159
160
161
162
163
164
165
166
167
168
169
# Copyright 2026 Query Farm LLC - https://query.farm
#
# Unit tests and a javadoc build for the SDK itself. The Integration suite
# workflow covers the protocol end-to-end against a real DuckDB, but it only
# ever compiles the example worker -- vgi/src/test carried 278 JUnit tests that
# nothing in CI ran. This workflow is that gate.
#
# vgi-rpc-java is built from source here for the same reason integration.yml
# does it (see the pin's comment there); keep VGI_RPC_JAVA_REF in step with it.
name: CI
on:
push:
pull_request:
workflow_dispatch:
permissions:
contents: read
concurrency:
group: ci-${{ github.ref }}
cancel-in-progress: true
env:
# The vgi-rpc-java revision built from source via the composite include. The
# composite substitutes the `farm.query:vgirpc` coordinate declared in
# vgi/build.gradle.kts, so this ref -- not the declared version -- is what
# :vgi:compileJava actually compiles and runs against here. A stale pin fails
# as `cannot find symbol` on whatever the newer vgirpc added, or as a runtime
# marshalling error. Because CI builds this ref from source while the
# published artifact resolves the declared version, the two can silently
# disagree: keep this tag and `farm.query:vgirpc` in vgi/build.gradle.kts
# pointing at the same release, and move them in the same commit.
#
# v0.25.1 is what carries `@ProtocolName`, without which this repo cannot
# declare the `vgi.v2` wire name at all: the name would fall back to the
# VgiService interface's simple name, and no Java identifier contains a dot.
# A stale pin here fails as `cannot find symbol: class ProtocolName`.
#
# v0.27.0 moves to Apache Arrow 19 (Netty 4.2), so arrow-c-data in
# vgi-example-worker/build.gradle.kts moves with this pin.
#
# (It had earlier been an untagged SHA, 920dc42, because no release yet
# carried the `writeListElement` LargeBinary case; v0.25.0 contains it.)
#
# v0.28.0 adds RpcServer.addProtocol, the error model and the Identity
# translation that Worker.hostedProtocols / resolveToken build on; a stale
# pin fails as `cannot find symbol: method addProtocol`, and the
# hosted-protocols job below cannot pass without it.
#
# v0.29.0 adds sealed grants and resolveToken-backed bearer authentication
# (GrantKeys, IdentityBearer) that Worker.grantKeys builds on.
#
# v0.30.0 adds the public reflection client (Introspect.listProtocols /
# describeProtocol).
#
# v0.31.0 makes identity.XChaCha20Poly1305 public; AttachTickets uses it
# instead of a copy.
# Keep in step with the identical pin in integration.yml.
VGI_RPC_JAVA_REF: v0.31.0
jobs:
test:
name: Unit tests (JDK 25)
runs-on: ubuntu-latest
steps:
- name: Checkout vgi-java
uses: actions/checkout@v4
- name: Checkout pinned vgi-rpc-java
uses: actions/checkout@v4
with:
repository: Query-farm/vgi-rpc-java
ref: ${{ env.VGI_RPC_JAVA_REF }}
path: vgi-rpc-java
- name: Set up JDK 25
uses: actions/setup-java@v4
with:
distribution: temurin
java-version: '25'
- name: Cache Gradle
uses: actions/cache@v4
with:
path: |
~/.gradle/caches
~/.gradle/wrapper
key: gradle-${{ runner.os }}-${{ hashFiles('**/*.gradle*', '**/gradle-wrapper.properties') }}
restore-keys: gradle-${{ runner.os }}-
- name: Unit tests
run: ./gradlew --no-daemon :vgi:test
env:
VGI_RPC_JAVA_DIR: ${{ github.workspace }}/vgi-rpc-java
# The published artifact carries javadoc, so a doc comment that does not
# build is a broken release, not a warning.
- name: Javadoc
run: ./gradlew --no-daemon :vgi:javadoc
env:
VGI_RPC_JAVA_DIR: ${{ github.workspace }}/vgi-rpc-java
- name: Upload test report on failure
if: failure()
uses: actions/upload-artifact@v4
with:
name: test-results
path: vgi/build/reports/tests/test
# vgi-rpc's hosted-protocols group against the example worker on stdio, unix
# and HTTP: conformance.Secondary.v1 hosted beside vgi.v2 through
# Worker.hostedProtocols, the error model, the traceback policy, and over HTTP
# the vgi_rpc.Identity.v1 conformance policy (--identity).
#
# The reference is cloned from main, deliberately unpinned -- the same pattern
# vgi-rpc-java's conformance lanes use: it is the yardstick, and a pinned
# yardstick lets a lane stay green against a stale contract.
hosted-protocols:
name: Hosted protocols (stdio, unix, http)
runs-on: ubuntu-latest
steps:
- name: Checkout vgi-java
uses: actions/checkout@v4
- name: Checkout pinned vgi-rpc-java
uses: actions/checkout@v4
with:
repository: Query-farm/vgi-rpc-java
ref: ${{ env.VGI_RPC_JAVA_REF }}
path: vgi-rpc-java
- name: Set up JDK 25
uses: actions/setup-java@v4
with:
distribution: temurin
java-version: '25'
- name: Set up Python 3.13
uses: actions/setup-python@v5
with:
python-version: '3.13'
- name: Cache Gradle
uses: actions/cache@v4
with:
path: |
~/.gradle/caches
~/.gradle/wrapper
key: gradle-${{ runner.os }}-${{ hashFiles('**/*.gradle*', '**/gradle-wrapper.properties') }}
restore-keys: gradle-${{ runner.os }}-
- name: Clone vgi-rpc-python reference (main, deliberately unpinned)
run: git clone --depth 1 https://github.com/Query-farm/vgi-rpc-python.git "$RUNNER_TEMP/vgi-rpc-python"
- name: Install the reference's conformance runner
run: |
python -m pip install --upgrade pip
python -m pip install "$RUNNER_TEMP/vgi-rpc-python[http,conformance]" pytest pytest-timeout
- name: Build example worker
run: ./gradlew --no-daemon :vgi-example-worker:installDist
env:
VGI_RPC_JAVA_DIR: ${{ github.workspace }}/vgi-rpc-java
- name: Run hosted-protocols group
run: ci/run-hosted-protocols.sh
env:
VGI_WORKER_BIN: ${{ github.workspace }}/vgi-example-worker/build/install/vgi-example-worker/bin/vgi-example-worker