Repository navigation
263 lines (238 loc) · 10.1 KB
/
Copy pathci.yml
File metadata and controls
263 lines (238 loc) · 10.1 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
130
131
132
133
134
135
136
137
138
139
140
141
142
143
144
145
146
147
148
149
150
151
152
153
154
155
156
157
158
159
160
161
162
163
164
165
166
167
168
169
170
171
172
173
174
175
176
177
178
179
180
181
182
183
184
185
186
187
188
189
190
191
192
193
194
195
196
197
198
199
200
201
202
203
204
205
206
207
208
209
210
211
212
213
214
215
216
217
218
219
220
221
222
223
224
225
226
227
228
229
230
231
232
233
234
235
236
237
238
239
240
241
242
243
244
245
246
247
248
249
250
251
252
253
254
255
256
257
258
259
260
261
262
263
name: CI
# `dev` is the default branch and the target of all contributor pull requests;
# `main` only ever receives releases. Pull requests are built for every branch.
on:
push:
branches: [dev, main]
pull_request:
# Least privilege: nothing in this workflow writes to the repository.
permissions:
contents: read
# A newer push to the same ref makes the in-flight run obsolete, so cancel it
# instead of paying for runner minutes on a result nobody will read.
concurrency:
group: ${{ github.workflow }}-${{ github.ref }}
cancel-in-progress: true
jobs:
# ---------------------------------------------------------------------------
# Always runs. LabFox targets a global audience, so every tracked text file
# must be English (see AGENTS.md -> "Language: English only").
# ---------------------------------------------------------------------------
language-policy:
name: Language policy (English only)
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@11d5960a326750d5838078e36cf38b85af677262 # v4
- name: Check for Hangul / CJK characters in tracked files
run: |
python3 - <<'PY'
import re
import subprocess
import sys
# Character ranges that must never appear in this repository.
# Written as \u escapes on purpose: this file stays pure ASCII, so the
# check can never flag its own source.
# Covers Hangul (syllables + every Jamo block + halfwidth), CJK
# ideographs, Kana and CJK/fullwidth punctuation, so Korean, Chinese
# and Japanese text are all rejected by a single pass.
NON_ENGLISH = re.compile(
r"["
r"\u1100-\u11FF" # Hangul Jamo
r"\u2E80-\u2EFF" # CJK Radicals Supplement
r"\u2F00-\u2FDF" # Kangxi Radicals
r"\u3000-\u303F" # CJK Symbols and Punctuation
r"\u3040-\u309F" # Hiragana
r"\u30A0-\u30FF" # Katakana
r"\u3130-\u318F" # Hangul Compatibility Jamo
r"\u3400-\u4DBF" # CJK Unified Ideographs Extension A
r"\u4E00-\u9FFF" # CJK Unified Ideographs
r"\uA960-\uA97F" # Hangul Jamo Extended-A
r"\uAC00-\uD7A3" # Hangul Syllables
r"\uD7B0-\uD7FF" # Hangul Jamo Extended-B
r"\uF900-\uFAFF" # CJK Compatibility Ideographs
r"\uFF01-\uFF60" # Fullwidth forms
r"\uFF66-\uFF9F" # Halfwidth Katakana
r"\uFFA0-\uFFDC" # Halfwidth Hangul
r"]"
)
# LICENSE is verbatim upstream text that contributors never edit.
EXCLUDED = {"LICENSE"}
# Translation resources are the one place non-English text is correct:
# the English-only rule governs code, comments, docs and commits, and
# AGENTS.md explicitly exempts localized UI strings. Skip the non-English
# ARB files and the generated per-locale Dart, but NOT app_en.arb (the
# source of truth, which must stay English) and NOT the app-wide
# generated delegate.
# Store copy is the same category as ARB files: text written to be read
# by a user in their own language. Only docs/store/, and only a file
# that names its locale — docs/store/<name>.<locale>.md — so it cannot
# become a way to smuggle non-English prose into the repository, and
# the English source beside it (docs/store/<name>.md) stays checked.
STORE_COPY = re.compile(r"^docs/store/[a-z-]+\.[a-z]{2}(-[A-Za-z]+)?\.md$")
def is_translation(path):
if path.endswith(".arb"):
return not path.endswith("app_en.arb")
if STORE_COPY.match(path):
return True
# app_localizations_ko.dart, _ja.dart, ... but not the base file.
name = path.rsplit("/", 1)[-1]
return (
name.startswith("app_localizations_")
and name.endswith(".dart")
and name != "app_localizations_en.dart"
)
# git ls-files keeps untracked scratch files out of the check.
files = subprocess.run(
["git", "ls-files", "-z"],
check=True,
capture_output=True,
text=True,
).stdout.split("\0")
violations = []
scanned = 0
for path in files:
if not path or path in EXCLUDED or is_translation(path):
continue
try:
with open(path, "rb") as handle:
raw = handle.read()
except OSError:
# Symlinks to directories, submodules, unreadable entries.
continue
if b"\0" in raw:
continue # binary file
try:
text = raw.decode("utf-8")
except UnicodeDecodeError:
continue # not UTF-8 text
scanned += 1
for lineno, line in enumerate(text.splitlines(), start=1):
if NON_ENGLISH.search(line):
violations.append((path, lineno, line.strip()))
if violations:
print("Language policy violation: non-English (Hangul/CJK) characters found.")
print("LabFox is English-only. See AGENTS.md -> 'Language: English only'.")
print("")
print("Offending files:")
for path in sorted({v[0] for v in violations}):
print(" " + path)
print("")
print("Offending lines:")
for path, lineno, line in violations:
print(" {}:{}: {}".format(path, lineno, line))
sys.exit(1)
print(
"Language policy OK: {} tracked text files scanned, all English.".format(
scanned
)
)
PY
# ---------------------------------------------------------------------------
# Runs once the Flutter workspace exists. Kept conditional so the workflow
# stayed green while the repository was documentation-only; it now activates
# on every push because the root pubspec.yaml declares the pub workspace.
# ---------------------------------------------------------------------------
detect-flutter:
name: Detect Flutter project
runs-on: ubuntu-latest
outputs:
found: ${{ steps.look.outputs.found }}
steps:
- uses: actions/checkout@11d5960a326750d5838078e36cf38b85af677262 # v4
- id: look
name: Look for pubspec.yaml
run: |
if [ -f pubspec.yaml ] || [ -f apps/labfox/pubspec.yaml ]; then
echo "found=true" >> "$GITHUB_OUTPUT"
else
echo "found=false" >> "$GITHUB_OUTPUT"
fi
# Release uploads run only after a main promotion and need store credentials.
# Exercise the same Xcode and iOS SDK on every PR without those credentials,
# explicitly checking out the submitted head instead of GitHub's merge ref.
ios-sdk:
name: iOS SDK validation
needs: detect-flutter
if: github.event_name == 'pull_request' && needs.detect-flutter.outputs.found == 'true'
runs-on: macos-26
steps:
- uses: actions/checkout@11d5960a326750d5838078e36cf38b85af677262 # v4
with:
ref: ${{ github.event.pull_request.head.sha }}
persist-credentials: false
- uses: subosito/flutter-action@1a449444c387b1966244ae4d4f8c696479add0b2 # v2
with:
channel: stable
flutter-version: 3.38.9
cache: true
- name: Verify Xcode and iOS SDK
run: |
set -euo pipefail
xcodebuild -version
sdk_version="$(xcrun --sdk iphoneos --show-sdk-version)"
case "$sdk_version" in
26.*) ;;
*)
echo "Expected an iOS 26 SDK, found $sdk_version." >&2
exit 1
;;
esac
- name: Resolve the workspace
run: flutter pub get
- name: Build unsigned iOS app
working-directory: apps/labfox
run: flutter build ios --release --no-codesign
flutter:
name: Flutter quality gate
needs: detect-flutter
if: needs.detect-flutter.outputs.found == 'true'
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@11d5960a326750d5838078e36cf38b85af677262 # v4
- uses: subosito/flutter-action@1a449444c387b1966244ae4d4f8c696479add0b2 # v2
with:
channel: stable
flutter-version: 3.38.9
cache: true
# One resolution for the whole workspace; each package does not get its
# own lockfile.
- name: Resolve the workspace
run: flutter pub get
- name: Verify formatting
run: dart format --output=none --set-exit-if-changed .
- name: Analyze
run: flutter analyze --fatal-infos
# `flutter test` at the workspace root finds no test directory, so each
# package is run in turn. The loop reports every failing package instead
# of stopping at the first, which makes one CI run enough to see the
# whole picture.
- name: Test
run: |
set -uo pipefail
failed=""
for dir in apps/labfox packages/*; do
[ -d "$dir/test" ] || continue
echo "::group::$dir"
if (cd "$dir" && flutter test); then
echo "$dir passed"
else
failed="$failed $dir"
fi
echo "::endgroup::"
done
if [ -n "$failed" ]; then
echo "Failing packages:$failed" >&2
exit 1
fi
# Codegen output is committed, so a stale generated file must fail here
# rather than surprising the next contributor.
- name: Verify generated code is up to date
run: |
set -euo pipefail
(cd packages/gitlab_models && dart run build_runner build --delete-conflicting-outputs)
(cd apps/labfox && flutter gen-l10n)
if ! git diff --quiet; then
echo "Generated code is out of date. Re-run build_runner and gen-l10n, then commit." >&2
git diff --stat >&2
exit 1
fi