Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
4 changes: 2 additions & 2 deletions .github/workflows/ci.yml
Original file line number Diff line number Diff line change
Expand Up @@ -199,9 +199,9 @@ jobs:
# Downloads the pinned prebuilt installer and verifies it against a
# digest pinned in the action. The action owns the cache for the
# installer binary, its version marker, and ~/.local/share/whitaker.
uses: leynos/shared-actions/.github/actions/install-whitaker@c5a54701c8603a0fa756a6b34c49bc2af75a6c11
uses: leynos/shared-actions/.github/actions/install-whitaker@6cec89bac47a21cf756d68d638a9a510998e57f8
with:
installer-version: '0.2.7'
installer-version: '0.2.9'
cache-provider: github
- name: Lint
run: |
Expand Down
20 changes: 14 additions & 6 deletions docs/developers-guide.md
Original file line number Diff line number Diff line change
Expand Up @@ -461,12 +461,20 @@ carry, matching the action by its own name so a lookalike is held to the
default. The rule is that no reference floats, not that every action moves
together.

The exceptions are the two coverage actions, `generate-coverage` and
`upload-codescene-coverage`, which share `COVERAGE_ACTIONS_SHA`, currently
`a5765019912a8ab6882b12db049c7cde635f3a85`, so that they carry one commit (the
shared CV-005 contract holds this as `coverage.selection-parity`). At that
revision the uploader verifies the `cs-coverage` archive against its committed
`cli-manifest.json` and rejects a non-empty `installer-checksum` outright, so
The exceptions are `install-whitaker` and the two coverage actions.
`install-whitaker` is held to `WHITAKER_ACTION_SHA`, currently
`6cec89bac47a21cf756d68d638a9a510998e57f8` (shared-actions #546). It advances
independently of the estate default because the concordat QG-002 rule accepts
any shared-actions commit at or after `6dea5677` (#522) that leaves the action
directory content-identical to it, so repinning it to the estate default would
break QG-002. The workflow passes `installer-version: '0.2.9'`, the floor the
action accepts, and `supply_chain.rs` asserts it. The coverage actions,
`generate-coverage` and `upload-codescene-coverage`, share
`COVERAGE_ACTIONS_SHA`, currently `a5765019912a8ab6882b12db049c7cde635f3a85`,
so that they carry one commit (the shared CV-005 contract holds this as
`coverage.selection-parity`). At that revision the uploader verifies the
`cs-coverage` archive against its committed `cli-manifest.json` and rejects a
non-empty `installer-checksum` outright, so
`tests/contracts/codescene_uploader.rs` refuses that input and the
`CODESCENE_CLI_SHA256` variable that fed it in any workflow, even in a comment,
requires every uploader reference to carry the approved commit, and requires the
Expand Down
2 changes: 1 addition & 1 deletion tests/contracts/supply_chain.rs
Original file line number Diff line number Diff line change
Expand Up @@ -131,7 +131,7 @@ fn sccache_is_installed_from_a_pinned_prebuilt_release(workflows: Vec<Workflow>)
fn whitaker_is_installed_from_a_pinned_prebuilt_release(workflows: Vec<Workflow>) {
let job = job_named(&workflows, "build-test");
let step = step_using(job, &shared_action("install-whitaker"));
assert_input("build-test", step, "installer-version", "0.2.7");
assert_input("build-test", step, "installer-version", "0.2.9");
assert_input("build-test", step, "cache-provider", "github");
}

Expand Down
12 changes: 11 additions & 1 deletion tests/support/workflow_estate.rs
Original file line number Diff line number Diff line change
Expand Up @@ -38,6 +38,15 @@ pub const SHARED_ACTIONS_SHA: &str = "c5a54701c8603a0fa756a6b34c49bc2af75a6c11";
/// nobody checks.
pub const COVERAGE_ACTIONS_SHA: &str = "a5765019912a8ab6882b12db049c7cde635f3a85";

/// Commit `install-whitaker` must pin.
///
/// It is a shared-actions commit at or after `6dea5677` (#522) that leaves the
/// action directory content-identical to it, which is the set the concordat
/// QG-002 rule accepts. This one is #546, the merge that also gives sccache's
/// server startup 60 s. It sits apart from [`SHARED_ACTIONS_SHA`] because
/// the action moved on its own, ahead of the estate default.
pub const WHITAKER_ACTION_SHA: &str = "6cec89bac47a21cf756d68d638a9a510998e57f8";

/// Shared actions whose reviewed revision is not [`SHARED_ACTIONS_SHA`].
///
/// The estate's rule is that no reference floats, not that every action
Expand All @@ -47,7 +56,8 @@ pub const COVERAGE_ACTIONS_SHA: &str = "a5765019912a8ab6882b12db049c7cde635f3a85
/// nobody asked for. Each exception is named here with the action it
/// governs, so a reference is still held to a reviewed commit by value and
/// a new exception has to be added deliberately.
pub const SHARED_ACTION_PIN_EXCEPTIONS: [(&str, &str); 2] = [
pub const SHARED_ACTION_PIN_EXCEPTIONS: [(&str, &str); 3] = [
("install-whitaker", WHITAKER_ACTION_SHA),
Comment thread
leynos marked this conversation as resolved.
("generate-coverage", COVERAGE_ACTIONS_SHA),
("upload-codescene-coverage", COVERAGE_ACTIONS_SHA),
];
Expand Down
Loading