mirror of
https://github.com/rustfs/rustfs.git
synced 2026-08-01 19:12:14 +00:00
2b31bda6d1
actions/checkout writes its token into .git/config as an http extraheader, where it stays for the rest of the job. That matters more here than usual: pull_request jobs run on self-hosted runners and execute the PR's own build.rs, proc-macros and tests, any of which can read that file. Test and Lint holds actions: write on top of that, so its token can cancel runs and delete the Actions caches the whole pipeline now depends on — it was given persist-credentials: false when that permission was added, and this extends the same treatment to the other 45 checkouts. Two are exempt because the token IS the credential the job needs. helm-package's publish job pushes to rustfs/helm with it; clearing it would break chart publishing. nix-flake-update is exempt pending verification: it passes FLAKE_UPDATE_TOKEN to create-pull-request directly rather than reusing .git/config, so it very likely does not need persistence, but that is unproven and a broken weekly bot is not worth the guess. Both carry a persist-credentials-exempt comment saying which. scripts/security/check_persist_credentials.sh requires every checkout to either clear its credentials or carry that comment, so the decision stays visible in review rather than being an omission nobody notices. Refs: rustfs/backlog#1598, rustfs/backlog#1602
142 lines
5.4 KiB
YAML
142 lines
5.4 KiB
YAML
# Copyright 2026 RustFS Team
|
|
#
|
|
# Licensed under the Apache License, Version 2.0 (the "License");
|
|
# you may not use this file except in compliance with the License.
|
|
# You may obtain a copy of the License at
|
|
#
|
|
# http://www.apache.org/licenses/LICENSE-2.0
|
|
#
|
|
# Unless required by applicable law or agreed to in writing, software
|
|
# distributed under the License is distributed on an "AS IS" BASIS,
|
|
# WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
|
|
# See the License for the specific language governing permissions and
|
|
# limitations under the License.
|
|
|
|
# Companion to ci.yml for required status checks.
|
|
#
|
|
# ci.yml skips docs-only pull requests via paths-ignore, but the branch ruleset
|
|
# requires a check named "Test and Lint" — without this workflow a docs-only PR
|
|
# would wait on it forever. This workflow triggers on exactly the paths ci.yml
|
|
# ignores and reports success under the same job name. Mixed PRs trigger both
|
|
# workflows and the real check still gates: a required check with any failing
|
|
# run blocks the merge.
|
|
# https://docs.github.com/en/repositories/configuring-branches-and-merges-in-your-repository/defining-the-mergeability-of-pull-requests/troubleshooting-required-status-checks#handling-skipped-but-required-checks
|
|
#
|
|
# "Quick Checks" is mirrored here ahead of the ruleset change that will make it
|
|
# required too (rustfs/backlog#1599). Until that change lands this job is
|
|
# inert; mirroring it first is what lets the ruleset change happen without
|
|
# stranding docs-only PRs on a check nobody reports.
|
|
#
|
|
# Keep the paths list below in sync with the pull_request paths-ignore list
|
|
# in ci.yml, and keep the quick-checks steps below byte-identical to the
|
|
# quick-checks job in ci.yml.
|
|
|
|
name: Continuous Integration (docs only)
|
|
|
|
on:
|
|
pull_request:
|
|
types: [ opened, synchronize, reopened ]
|
|
branches: [ main ]
|
|
paths:
|
|
- "**.md"
|
|
- "docs/**"
|
|
- "deploy/**"
|
|
- "scripts/dev_*.sh"
|
|
- "scripts/probe.sh"
|
|
- "LICENSE*"
|
|
- ".gitignore"
|
|
- ".dockerignore"
|
|
- "README*"
|
|
- "**/*.png"
|
|
- "**/*.jpg"
|
|
- "**/*.svg"
|
|
- ".github/workflows/build.yml"
|
|
- ".github/workflows/docker.yml"
|
|
- ".github/workflows/audit.yml"
|
|
- "flake.lock"
|
|
|
|
permissions:
|
|
contents: read
|
|
|
|
jobs:
|
|
# Deliberately NOT a bare `echo`. Once "Quick Checks" becomes a required
|
|
# check, ci.yml gates every expensive job behind it, so a mixed PR reports
|
|
# two check runs with this name: the real one (45-51s) and this companion.
|
|
# GitHub has no written contract for how it picks between same-named
|
|
# required check runs ("latest wins" vs "any failure blocks"), so instead of
|
|
# relying on ordering we make both runs execute the same commands against
|
|
# the same merge ref — their conclusions are then necessarily identical and
|
|
# the choice does not matter. Keep these steps byte-identical to the
|
|
# quick-checks job in ci.yml (a guard script that asserts this, and the paths
|
|
# sync below, is tracked in rustfs/backlog#1603).
|
|
#
|
|
# For a genuinely docs-only PR this adds no strictness (no code changed, so
|
|
# fmt and the guards always pass) and costs ~50s of ubuntu-latest.
|
|
quick-checks:
|
|
name: Quick Checks
|
|
runs-on: ubuntu-latest
|
|
timeout-minutes: 10
|
|
steps:
|
|
- name: Checkout repository
|
|
uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 # v7
|
|
with:
|
|
persist-credentials: false
|
|
|
|
- name: Install ripgrep
|
|
run: sudo apt-get update && sudo apt-get install -y ripgrep
|
|
|
|
- name: Install Rust toolchain
|
|
uses: dtolnay/rust-toolchain@29eef336d9b2848a0b548edc03f92a220660cdb8 # stable
|
|
with:
|
|
components: rustfmt
|
|
|
|
- name: Check code formatting
|
|
run: cargo fmt --all --check
|
|
|
|
- name: Check unsafe code allowances
|
|
run: ./scripts/check_unsafe_code_allowances.sh
|
|
|
|
- name: Check layered dependencies
|
|
run: ./scripts/check_layer_dependencies.sh
|
|
|
|
- name: Check architecture migration rules
|
|
run: ./scripts/check_architecture_migration_rules.sh
|
|
|
|
- name: Check tokio io-uring feature guard
|
|
run: ./scripts/check_no_tokio_io_uring.sh
|
|
|
|
- name: Check extension schema boundaries
|
|
run: ./scripts/check_extension_schema_boundaries.sh
|
|
|
|
- name: Check body-cache whitelist guard
|
|
run: ./scripts/check_body_cache_whitelist.sh
|
|
|
|
- name: Check no planning docs committed
|
|
run: ./scripts/check_no_planning_docs.sh
|
|
|
|
- name: Check CI paths stay in sync
|
|
run: ./scripts/check_ci_paths_sync.sh
|
|
|
|
- name: Check io_uring lane --lib precondition
|
|
run: ./scripts/check_uring_lane_lib_only.sh
|
|
|
|
test-and-lint:
|
|
name: Test and Lint
|
|
runs-on: ubuntu-latest
|
|
timeout-minutes: 10
|
|
steps:
|
|
- name: Checkout repository
|
|
uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 # v7
|
|
with:
|
|
persist-credentials: false
|
|
|
|
# Docs-only PRs skip the full code CI, but they are exactly where a
|
|
# planning-type document could be slipped in (git add -f bypasses
|
|
# .gitignore). Run the guard here so the required "Test and Lint" check
|
|
# stays meaningful for docs-only changes.
|
|
- name: Check no planning docs committed
|
|
run: ./scripts/check_no_planning_docs.sh
|
|
|
|
- name: Satisfy required check for docs-only changes
|
|
run: echo "Docs-only change — code CI is skipped by paths-ignore; planning-docs guard passed, reporting success for the required 'Test and Lint' check."
|