diff --git a/.github/workflows/alert.yml b/.github/workflows/alert.yml index d0d3f51a29..2c4084d32e 100644 --- a/.github/workflows/alert.yml +++ b/.github/workflows/alert.yml @@ -39,6 +39,7 @@ on: - Nightly - OBS - Platform + - Quest - release-brew - Release Dart - Release Dart FFI diff --git a/.github/workflows/quest.yml b/.github/workflows/quest.yml new file mode 100644 index 0000000000..ce282e9b47 --- /dev/null +++ b/.github/workflows/quest.yml @@ -0,0 +1,58 @@ +name: Quest + +# Validates the quest tree on every branch that carries one. check.yml already +# runs `quest check` on a pull request into any branch, but a direct push (a +# merge to `main` or `dev`, or `main` merged into a questline) is nobody's pull +# request, so a broken tree could land there unseen. +# +# Push only: a pull request is check.yml's job, and a pull_request trigger here +# would spawn a skipped Alert run on every push to every pull request. +# +# The paths mirror the quest module in sh/dispatch.sh's impact map: the +# documents, and flake.lock, which pins the validator. + +permissions: + contents: read + +on: + push: + branches: + - main + - dev + - "quest/**" + paths: + - "quest/**" + - "flake.lock" + - ".github/workflows/quest.yml" + +# Only the newest push to a branch matters; Alert ignores the cancelled runs. +concurrency: + group: quest-${{ github.ref }} + cancel-in-progress: true + +jobs: + check: + # Not `Check`: that is check.yml's required status, and a second job with + # the same name would make it ambiguous on a head that runs both. + name: Quest + runs-on: ubuntu-24.04-arm + timeout-minutes: 15 + + steps: + - name: Checkout + uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 + with: + persist-credentials: false + + - uses: DeterminateSystems/nix-installer-action@1d87d45818068401a10cf16bdc5f00b24994a83f # main + with: + determinate: false + # Trust the flake's cachix substituter, which holds the dev shell; + # see check.yml. + extra-conf: | + extra-substituters = https://kixelated.cachix.org + extra-trusted-public-keys = kixelated.cachix.org-1:CmFcV0lyM6KuVM2m9mih0q4SrAa0XyCsiM7GHrz3KKk= + + # The whole tree, unscoped: a push has no base to diff against. + - name: Check + run: nix develop --command quest check diff --git a/quest/m0/README.md b/quest/m0/README.md index fae3a99c49..ad416b83fb 100644 --- a/quest/m0/README.md +++ b/quest/m0/README.md @@ -46,7 +46,6 @@ Published API or wire breaks still land on dev; each quest's Plan says so. - [Subgroup refusal](/quest/m0/ietf-subgroup-refusal.md) - a non-zero moq-transport subgroup costs that one stream, never the session - [IETF stream types](/quest/m0/ietf-uni-stream-types.md) - padding streams are discarded stream-only and an unknown uni type closes the session, per draft-21 - [Request caps](/quest/m0/request-caps.md) - lite message sizes, IETF request IDs, and per-session announces and subscriptions are bounded -- [quest check everywhere](/quest/m0/quest-check-everywhere.md) - `quest check` guards `main`, `dev`, and the line branches on push and PR, not only PRs into `main` - [noq reassembly cap](/quest/m0/noq-reassembly-cap.md) - noq carries quinn's stream reassembly cap and the connection receive window is finite by default - [qmux reset race](/quest/m0/qmux-reset-race.md) - qmux handles RESET_STREAM under one lock instead of panicking - [Remove gossip](/quest/m0/remove-gossip.md) - a relay dials only configured peers; `cluster.mesh` is refused at startup diff --git a/quest/m0/quest-check-everywhere.md b/quest/m0/quest-check-everywhere.md deleted file mode 100644 index 447eadfca6..0000000000 --- a/quest/m0/quest-check-everywhere.md +++ /dev/null @@ -1,19 +0,0 @@ -# [XS] quest check runs on every branch that carries quests - -## Goal - -`quest check` fails any push or PR that breaks quest structure on `main`, -`dev`, and the questline branches, not only PRs into `main`. - -## Plan - -- `check.yml` runs `quest check` on pull requests only. Also run it on push to - `main`, `dev`, and `quest/**`, so a direct merge commit (such as `main` - merged into a line) can't land a broken tree. Use a dedicated job that runs - `quest check` unconditionally: `check.yml`'s scope steps diff against - `origin/$GITHUB_BASE_REF`, which is empty on a push. -- `dev` already pins main's `quest` (8590d2a) and passes since #4428. Only the - wildcard line still pins 46d7fe8: merge `main` into it to bump the pin, and - fix what the new check reports. - -Public API: none. Wire: none.