diff --git a/.github/workflows/ci.yml b/.github/workflows/ci.yml index 1f9df1f..29ed404 100644 --- a/.github/workflows/ci.yml +++ b/.github/workflows/ci.yml @@ -25,15 +25,10 @@ jobs: run: cargo check --workspace --locked - name: cargo test --workspace env: - # Storage tests must not hit the real OS keyring on CI: - # there is no D-Bus session available and the call would - # block. The runtime code carries the same toggle for - # headless / sandboxed environments. CHANORA_DISABLE_KEYRING: "1" run: cargo test --workspace --locked --no-fail-fast - name: cargo clippy run: cargo clippy --workspace --all-targets -- -D warnings - continue-on-error: true supply-chain: name: cargo deny (licenses + advisories + bans + sources) @@ -43,9 +38,6 @@ jobs: - uses: EmbarkStudios/cargo-deny-action@v2 with: command: check - # `licenses` enforces the DEC-020 license posture; the - # other three are minimal supply-chain hygiene per - # `docs/governance/legal-review-readiness.md` §5. arguments: --workspace --all-features license-inventory: @@ -58,10 +50,6 @@ jobs: - name: Install cargo-about run: cargo install --locked --features cli cargo-about - name: Regenerate inventory and compare - # Build the inventory in a temp file and diff against the - # committed copy. CI fails when the committed inventory is - # stale, forcing contributors to run the tool locally - # before opening a PR that touches the dependency tree. run: | cargo about generate --output-file /tmp/license-inventory.md about-md.hbs diff docs/security/license-inventory.md /tmp/license-inventory.md \ @@ -80,9 +68,6 @@ jobs: run: flutter pub get - name: Regenerate Flutter license inventory and compare env: - # Resolved by the wrapper from $HOME/sdks/flutter when - # not set; CI's subosito/flutter-action puts flutter on - # PATH but exports the SDK root under FLUTTER_ROOT. FLUTTER_ROOT: ${{ env.FLUTTER_ROOT }} run: | ./tools/dump_flutter_licenses.sh @@ -136,3 +121,63 @@ jobs: if: steps.silero-coreml.outputs.available == 'true' working-directory: apps/chanora_flutter run: flutter build ios --release --no-codesign + - name: xcodebuild archive verification + if: steps.silero-coreml.outputs.available == 'true' + working-directory: apps/chanora_flutter + run: | + xcodebuild archive \ + -workspace ios/Runner.xcworkspace \ + -scheme Runner \ + -archive build/Runner.xcarchive \ + CODE_SIGNING_ALLOWED=NO \ + | xcpretty || { echo "::error::xcodebuild archive failed — see issue-history-analysis.md §4 'Xcode Archive vs build divergence'"; exit 1; } + + android-build: + name: Android build (${{ matrix.target }}) + runs-on: ubuntu-latest + strategy: + fail-fast: false + matrix: + include: + - target: aarch64-linux-android + abi: arm64-v8a + - target: armv7-linux-androideabi + abi: armeabi-v7a + - target: x86_64-linux-android + abi: x86_64 + steps: + - uses: actions/checkout@v4 + - uses: dtolnay/rust-toolchain@stable + with: + targets: ${{ matrix.target }} + - uses: Swatinem/rust-cache@v2 + - name: Install cargo-ndk + run: cargo install --locked cargo-ndk + - name: Setup NDK + run: | + ANDROID_ROOT="/usr/local/lib/android/sdk" + SDKMANAGER="$ANDROID_ROOT/cmdline-tools/latest/bin/sdkmanager" + echo "y" | $SDKMANAGER "ndk;27.0.12077973" + echo "ANDROID_NDK_HOME=$ANDROID_ROOT/ndk/27.0.12077973" >> "$GITHUB_ENV" + - name: cargo ndk build + run: cargo ndk -t ${{ matrix.abi }} build --workspace --locked + + windows-build: + name: Windows build + runs-on: windows-latest + steps: + - uses: actions/checkout@v4 + - uses: dtolnay/rust-toolchain@stable + - uses: Swatinem/rust-cache@v2 + - name: cargo check --workspace + run: cargo check --workspace --locked + + macos-build: + name: macOS build + runs-on: macos-latest + steps: + - uses: actions/checkout@v4 + - uses: dtolnay/rust-toolchain@stable + - uses: Swatinem/rust-cache@v2 + - name: cargo check --workspace + run: cargo check --workspace --locked