diff --git a/.github/workflows/build.yml b/.github/workflows/build.yml index 80dc2f6b1..11f041aff 100644 --- a/.github/workflows/build.yml +++ b/.github/workflows/build.yml @@ -44,22 +44,6 @@ on: - "**/*.svg" - ".gitignore" - ".dockerignore" - pull_request: - branches: [ main ] - paths-ignore: - - "**.md" - - "**.txt" - - ".github/**" - - "docs/**" - - "deploy/**" - - "scripts/dev_*.sh" - - "LICENSE*" - - "README*" - - "**/*.png" - - "**/*.jpg" - - "**/*.svg" - - ".gitignore" - - ".dockerignore" schedule: - cron: "0 0 * * 0" # Weekly on Sunday at midnight UTC workflow_dispatch: diff --git a/.github/workflows/ci.yml b/.github/workflows/ci.yml index 9c3ae8128..9aa65ffb1 100644 --- a/.github/workflows/ci.yml +++ b/.github/workflows/ci.yml @@ -91,6 +91,8 @@ jobs: typos: name: Typos + needs: skip-check + if: needs.skip-check.outputs.should_skip != 'true' runs-on: ubicloud-standard-2 steps: - uses: actions/checkout@v6 @@ -116,9 +118,6 @@ jobs: github-token: ${{ secrets.GITHUB_TOKEN }} cache-save-if: ${{ github.ref == 'refs/heads/main' }} - - name: Install cargo-nextest - uses: taiki-e/install-action@nextest - - name: Run tests run: | cargo nextest run --all --exclude e2e_test @@ -133,9 +132,40 @@ jobs: - name: Check layered dependencies run: ./scripts/check_layer_dependencies.sh + build-rustfs-debug-binary: + name: Build RustFS Debug Binary + needs: skip-check + if: needs.skip-check.outputs.should_skip != 'true' + runs-on: ubicloud-standard-4 + timeout-minutes: 30 + steps: + - name: Checkout repository + uses: actions/checkout@v6 + + - name: Setup Rust environment + uses: ./.github/actions/setup + with: + rust-version: stable + cache-shared-key: ci-rustfs-debug-binary-${{ hashFiles('**/Cargo.lock') }} + cache-save-if: ${{ github.ref == 'refs/heads/main' }} + github-token: ${{ secrets.GITHUB_TOKEN }} + + - name: Build debug binary + run: | + touch rustfs/build.rs + cargo build -p rustfs --bins --jobs 2 + + - name: Upload debug binary + uses: actions/upload-artifact@v6 + with: + name: rustfs-debug-binary + path: target/debug/rustfs + if-no-files-found: error + retention-days: 1 + e2e-tests: name: End-to-End Tests - needs: skip-check + needs: [ skip-check, build-rustfs-debug-binary ] if: needs.skip-check.outputs.should_skip != 'true' runs-on: ubicloud-standard-2 timeout-minutes: 30 @@ -148,13 +178,17 @@ jobs: rm -rf /tmp/rustfs rm -f /tmp/rustfs.log - - name: Setup Rust environment - uses: ./.github/actions/setup + - name: Download debug binary + uses: actions/download-artifact@v7 with: - rust-version: stable - cache-shared-key: ci-e2e-${{ hashFiles('**/Cargo.lock') }} - cache-save-if: ${{ github.ref == 'refs/heads/main' }} - github-token: ${{ secrets.GITHUB_TOKEN }} + name: rustfs-debug-binary + path: target/debug + + - name: Make binary executable + run: chmod +x ./target/debug/rustfs + + - name: Setup Rust toolchain for s3s-e2e installation + uses: dtolnay/rust-toolchain@stable - name: Install s3s-e2e test tool uses: taiki-e/cache-cargo-install-action@v2 @@ -163,12 +197,6 @@ jobs: git: https://github.com/s3s-project/s3s.git rev: 4a04a670cf41274d9be9ab65dc36f4aa3f92fbad - - name: Build debug binary - run: | - touch rustfs/build.rs - # Limit concurrency to prevent OOM - cargo build -p rustfs --bins --jobs 2 - - name: Run end-to-end tests run: | s3s-e2e --version @@ -184,7 +212,7 @@ jobs: s3-implemented-tests: name: S3 Implemented Tests - needs: skip-check + needs: [ skip-check, build-rustfs-debug-binary ] if: needs.skip-check.outputs.should_skip != 'true' runs-on: ubicloud-standard-4 timeout-minutes: 60 @@ -192,18 +220,14 @@ jobs: - name: Checkout repository uses: actions/checkout@v6 - - name: Setup Rust environment - uses: ./.github/actions/setup + - name: Download debug binary + uses: actions/download-artifact@v7 with: - rust-version: stable - cache-shared-key: ci-s3tests-${{ hashFiles('**/Cargo.lock') }} - cache-save-if: ${{ github.ref == 'refs/heads/main' }} - github-token: ${{ secrets.GITHUB_TOKEN }} + name: rustfs-debug-binary + path: target/debug - - name: Build debug binary - run: | - touch rustfs/build.rs - cargo build -p rustfs --bins --jobs 2 + - name: Make binary executable + run: chmod +x ./target/debug/rustfs - name: Run implemented s3-tests run: | diff --git a/.github/workflows/e2e-s3tests.yml b/.github/workflows/e2e-s3tests.yml index 513278536..a2a8829ae 100644 --- a/.github/workflows/e2e-s3tests.yml +++ b/.github/workflows/e2e-s3tests.yml @@ -50,6 +50,11 @@ env: RUST_LOG: info PLATFORM: linux/amd64 + BUILDX_CACHE_SCOPE: rustfs-e2e-s3tests-source + +concurrency: + group: ${{ github.workflow }}-${{ github.ref }}-${{ github.event.inputs['test-mode'] || 'single' }} + cancel-in-progress: true defaults: run: @@ -57,12 +62,25 @@ defaults: jobs: s3tests-single: - if: github.event.inputs.test-mode == 'single' + if: github.event.inputs['test-mode'] == 'single' runs-on: ubicloud-standard-2 timeout-minutes: 120 steps: - uses: actions/checkout@v6 + - name: Cache pip downloads + uses: actions/cache@v4 + with: + path: ~/.cache/pip + key: ${{ runner.os }}-pip-e2e-s3tests-${{ hashFiles('.github/workflows/e2e-s3tests.yml') }} + restore-keys: | + ${{ runner.os }}-pip-e2e-s3tests- + + - name: Install Python tools + run: | + python3 -m pip install --user --upgrade pip awscurl tox + echo "$HOME/.local/bin" >> "$GITHUB_PATH" + - name: Enable buildx uses: docker/setup-buildx-action@v3 @@ -70,8 +88,8 @@ jobs: run: | DOCKER_BUILDKIT=1 docker buildx build --load \ --platform ${PLATFORM} \ - --cache-from type=gha \ - --cache-to type=gha,mode=max \ + --cache-from type=gha,scope=${BUILDX_CACHE_SCOPE} \ + --cache-to type=gha,mode=max,scope=${BUILDX_CACHE_SCOPE} \ -t rustfs-ci \ -f Dockerfile.source . @@ -121,9 +139,6 @@ jobs: - name: Provision s3-tests alt user (required by suite) run: | - python3 -m pip install --user --upgrade pip awscurl - export PATH="$HOME/.local/bin:$PATH" - # Admin API requires AWS SigV4 signing. awscurl is used by RustFS codebase as well. awscurl \ --service s3 \ @@ -156,8 +171,6 @@ jobs: - name: Prepare s3-tests run: | - python3 -m pip install --user --upgrade pip tox - export PATH="$HOME/.local/bin:$PATH" git clone --depth 1 https://github.com/ceph/s3-tests.git s3-tests - name: Run ceph s3-tests (debug friendly) @@ -211,12 +224,25 @@ jobs: path: artifacts/** s3tests-multi: - if: github.event_name == 'workflow_dispatch' && github.event.inputs.test-mode == 'multi' + if: github.event_name == 'workflow_dispatch' && github.event.inputs['test-mode'] == 'multi' runs-on: ubicloud-standard-2 timeout-minutes: 150 steps: - uses: actions/checkout@v6 + - name: Cache pip downloads + uses: actions/cache@v4 + with: + path: ~/.cache/pip + key: ${{ runner.os }}-pip-e2e-s3tests-${{ hashFiles('.github/workflows/e2e-s3tests.yml') }} + restore-keys: | + ${{ runner.os }}-pip-e2e-s3tests- + + - name: Install Python tools + run: | + python3 -m pip install --user --upgrade pip awscurl tox + echo "$HOME/.local/bin" >> "$GITHUB_PATH" + - name: Enable buildx uses: docker/setup-buildx-action@v3 @@ -224,8 +250,8 @@ jobs: run: | DOCKER_BUILDKIT=1 docker buildx build --load \ --platform ${PLATFORM} \ - --cache-from type=gha \ - --cache-to type=gha,mode=max \ + --cache-from type=gha,scope=${BUILDX_CACHE_SCOPE} \ + --cache-to type=gha,mode=max,scope=${BUILDX_CACHE_SCOPE} \ -t rustfs-ci \ -f Dockerfile.source . @@ -337,9 +363,6 @@ jobs: - name: Provision s3-tests alt user (required by suite) run: | - python3 -m pip install --user --upgrade pip awscurl - export PATH="$HOME/.local/bin:$PATH" - awscurl \ --service s3 \ --region "${S3_REGION}" \ @@ -368,8 +391,6 @@ jobs: - name: Prepare s3-tests run: | - python3 -m pip install --user --upgrade pip tox - export PATH="$HOME/.local/bin:$PATH" git clone --depth 1 https://github.com/ceph/s3-tests.git s3-tests - name: Run ceph s3-tests (multi, debug friendly) diff --git a/AGENTS.md b/AGENTS.md index 45ba1d6bb..58a53f2b9 100644 --- a/AGENTS.md +++ b/AGENTS.md @@ -87,6 +87,14 @@ Work on feature branches (e.g., `feat/...`) after syncing `main`. Follow Convent - Follow the PR template format and fill in all required sections - Wait for reviewer approval before merging +### PR Template Enforcement (MANDATORY) + +- Always use `.github/pull_request_template.md` when creating or updating a PR body. +- Keep all template section headings in the final PR description (do not replace with custom sections only). +- If a section is not applicable, explicitly write `N/A` instead of removing the section. +- Before requesting review, verify the PR body still contains all template sections. +- If a PR is created without the template, immediately update the PR body to match the template before any further action. + ## Security & Configuration Tips Do not commit secrets or cloud credentials; prefer environment variables or vault tooling. Review IAM- and KMS-related changes with a second maintainer. Confirm proxy settings before running sensitive tests to avoid leaking traffic outside localhost.