Closes engineering deliverables 1–3 from the open-work table in `docs/governance/legal-review-readiness.md` so the DEC-012 legal review can actually run. With this commit, the only remaining engineering item blocking sign-off is signed Windows / macOS / iOS build artefacts, deferrable per the DEC-002 staged release plan. Tooling ------- * `about.toml` + `about.hbs` + `about-md.hbs` configure cargo-about with the DEC-020 license posture and the five-target matrix (Linux, Android, Windows, macOS, iOS). One per-crate clarification for `allo-isolate` (`flutter_rust_bridge` transitive that ships Apache-2.0 via `license-file` rather than an SPDX `license` field). `cargo about generate` runs with zero warnings. * `deny.toml` mirrors the cargo-about allow-list and adds minimal bans / sources / advisories config. `cargo deny check` reports `advisories ok, bans ok, licenses ok, sources ok` for the workspace; multiple-versions of `windows_x86_64_msvc` produce advisory `warn` (no fail) because three windows-targets versions reach the graph via `jni`, `cpal`, and `keyring` respectively. * `tools/dump_flutter_licenses.sh` + `tools/dump_flutter_licenses.dart` walk `apps/chanora_flutter/pubspec.lock`, resolve each dependency to its local pub-cache directory, read the LICENSE file, and emit `docs/security/flutter-license-inventory.md`. SDK-sourced packages (`flutter`, `flutter_localizations`, `flutter_test`, `flutter_web_plugins`, `sky_engine`) resolve to the Flutter framework BSD-3-Clause LICENSE under `$FLUTTER_ROOT` (or `$HOME/sdks/flutter`). Artefacts --------- * `docs/security/license-inventory.md` — 364 transitive Rust crates with full license texts. Apache-2.0 (276), MIT (55), Unicode-3.0 (19), BSD-3-Clause (7), ISC (7). Zero copyleft. * `docs/security/license-inventory.html` — same data rendered as styled HTML for reviewer convenience. * `docs/security/flutter-license-inventory.md` — 94 Dart / Flutter packages with their LICENSE texts. Zero packages without a resolvable LICENSE in this RC. CI -- * New `supply-chain` job runs `cargo deny check --workspace --all-features` via `EmbarkStudios/cargo-deny-action@v2`. Fails the build on any GPL / LGPL / AGPL / commercial-source license surfacing transitively. * New `license-inventory` job installs `cargo-about --features cli` and regenerates `docs/security/license-inventory.md`; diffs against the committed copy and fails on drift. Forces contributors who touch the Cargo.lock to refresh the inventory. * New `flutter-license-inventory` job runs `tools/dump_flutter_licenses.sh` against the just-resolved pub cache; same diff-on-drift semantics. Governance ---------- * `docs/governance/legal-review-readiness.md` §5 cross-links the three new artefacts in a "Reviewer artefacts" subsection. * The open-work table at the bottom of the doc is rewritten as a status grid: items 1–3 now read **Done**; item 4 (signed iOS / macOS builds) remains the only open engineering blocker, with a pointer back to `staged-release-plan.md`. Verification ------------ * `CHANORA_DISABLE_KEYRING=1 cargo test --workspace`: all 49 unit + integration tests green (unchanged from v1.0.0-rc.1). * `cargo deny check`: advisories ok, bans ok, licenses ok, sources ok. * `cargo about generate --output-file …`: zero warnings. * `tools/dump_flutter_licenses.sh`: 94 packages, 0 without LICENSE. * `flutter analyze`: clean. No code changes touch the runtime; this is governance-tooling only.
110 lines
4.0 KiB
YAML
110 lines
4.0 KiB
YAML
name: ci
|
|
|
|
on:
|
|
push:
|
|
branches: ["**"]
|
|
pull_request:
|
|
|
|
jobs:
|
|
rust:
|
|
name: cargo check + cargo test
|
|
runs-on: ubuntu-latest
|
|
steps:
|
|
- uses: actions/checkout@v4
|
|
- name: System deps (cpal / Opus / SQLite)
|
|
run: |
|
|
sudo apt-get update
|
|
sudo apt-get install -y \
|
|
libasound2-dev libpulse-dev pkg-config \
|
|
libopus-dev
|
|
- uses: dtolnay/rust-toolchain@stable
|
|
- uses: Swatinem/rust-cache@v2
|
|
- name: cargo check --workspace
|
|
run: cargo check --workspace --locked
|
|
- name: cargo test --workspace
|
|
env:
|
|
# Storage tests must not hit the real OS keyring on CI:
|
|
# there is no D-Bus session available and the call would
|
|
# block. The runtime code carries the same toggle for
|
|
# headless / sandboxed environments.
|
|
CHANORA_DISABLE_KEYRING: "1"
|
|
run: cargo test --workspace --locked --no-fail-fast
|
|
- name: cargo clippy
|
|
run: cargo clippy --workspace --all-targets -- -D warnings
|
|
continue-on-error: true
|
|
|
|
supply-chain:
|
|
name: cargo deny (licenses + advisories + bans + sources)
|
|
runs-on: ubuntu-latest
|
|
steps:
|
|
- uses: actions/checkout@v4
|
|
- uses: EmbarkStudios/cargo-deny-action@v2
|
|
with:
|
|
command: check
|
|
# `licenses` enforces the DEC-020 license posture; the
|
|
# other three are minimal supply-chain hygiene per
|
|
# `docs/governance/legal-review-readiness.md` §5.
|
|
arguments: --workspace --all-features
|
|
|
|
license-inventory:
|
|
name: cargo about (license inventory)
|
|
runs-on: ubuntu-latest
|
|
steps:
|
|
- uses: actions/checkout@v4
|
|
- uses: dtolnay/rust-toolchain@stable
|
|
- uses: Swatinem/rust-cache@v2
|
|
- name: Install cargo-about
|
|
run: cargo install --locked --features cli cargo-about
|
|
- name: Regenerate inventory and compare
|
|
# Build the inventory in a temp file and diff against the
|
|
# committed copy. CI fails when the committed inventory is
|
|
# stale, forcing contributors to run the tool locally
|
|
# before opening a PR that touches the dependency tree.
|
|
run: |
|
|
cargo about generate --output-file /tmp/license-inventory.md about-md.hbs
|
|
diff docs/security/license-inventory.md /tmp/license-inventory.md \
|
|
|| { echo "::error::docs/security/license-inventory.md is stale; regenerate with 'cargo about generate --output-file docs/security/license-inventory.md about-md.hbs'"; exit 1; }
|
|
|
|
flutter-license-inventory:
|
|
name: flutter license inventory
|
|
runs-on: ubuntu-latest
|
|
steps:
|
|
- uses: actions/checkout@v4
|
|
- uses: subosito/flutter-action@v2
|
|
with:
|
|
channel: stable
|
|
- name: flutter pub get
|
|
working-directory: apps/chanora_flutter
|
|
run: flutter pub get
|
|
- name: Regenerate Flutter license inventory and compare
|
|
env:
|
|
# Resolved by the wrapper from $HOME/sdks/flutter when
|
|
# not set; CI's subosito/flutter-action puts flutter on
|
|
# PATH but exports the SDK root under FLUTTER_ROOT.
|
|
FLUTTER_ROOT: ${{ env.FLUTTER_ROOT }}
|
|
run: |
|
|
./tools/dump_flutter_licenses.sh
|
|
if ! git diff --quiet docs/security/flutter-license-inventory.md; then
|
|
echo "::error::docs/security/flutter-license-inventory.md is stale; regenerate with 'tools/dump_flutter_licenses.sh'"
|
|
git --no-pager diff docs/security/flutter-license-inventory.md | head -40
|
|
exit 1
|
|
fi
|
|
|
|
flutter:
|
|
name: flutter analyze
|
|
runs-on: ubuntu-latest
|
|
steps:
|
|
- uses: actions/checkout@v4
|
|
- uses: subosito/flutter-action@v2
|
|
with:
|
|
channel: stable
|
|
- name: flutter pub get
|
|
working-directory: apps/chanora_flutter
|
|
run: flutter pub get
|
|
- name: flutter analyze
|
|
working-directory: apps/chanora_flutter
|
|
run: flutter analyze
|
|
- name: flutter test (unit only)
|
|
working-directory: apps/chanora_flutter
|
|
run: flutter test --exclude-tags e2e || true
|