Quality gate, lifetimes module (WPF leaks), spec + proposals, and a real C# leak pipeline #40
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
| name: CI | |
| # Least privilege: every job only reads the repo (no job pushes or needs write). | |
| # Action SHA-pinning / persist-credentials hardening is deliberately deferred to | |
| # a Dependabot/hardening pass — see README "где оно жульничает" item #7. | |
| permissions: | |
| contents: read | |
| on: | |
| push: | |
| branches: ["**"] | |
| pull_request: | |
| workflow_dispatch: | |
| jobs: | |
| # Quality gate: ruff (style/bugs) on the whole tree, and mypy --strict on the | |
| # ownlang package (tests are dynamic/fuzzer code, covered by ruff only). These | |
| # are the "tighten the screws on Python" guard rails — see README. | |
| lint: | |
| name: lint (ruff + mypy --strict) | |
| runs-on: ubuntu-latest | |
| steps: | |
| - uses: actions/checkout@v4 | |
| - uses: actions/setup-python@v5 | |
| with: | |
| python-version: "3.11" | |
| - name: Install linters | |
| run: pip install "ruff==0.15.8" "mypy==1.19.1" | |
| - name: ruff | |
| run: ruff check . | |
| - name: mypy --strict (ownlang) | |
| run: mypy | |
| tests: | |
| name: tests (py${{ matrix.python-version }}) | |
| runs-on: ubuntu-latest | |
| strategy: | |
| fail-fast: false | |
| matrix: | |
| # The PoC needs 3.11+ (see README). Run the floor and current releases. | |
| python-version: ["3.11", "3.12", "3.13"] | |
| steps: | |
| - uses: actions/checkout@v4 | |
| - name: Set up Python ${{ matrix.python-version }} | |
| uses: actions/setup-python@v5 | |
| with: | |
| python-version: ${{ matrix.python-version }} | |
| # Zero-dependency project: nothing to install. The suite runs the | |
| # analyzer cases, the golden ArrayPool lowering, the codegen content | |
| # assertions, and the property fuzzer (fixed seed) in one entrypoint. | |
| - name: Run test suite | |
| run: python tests/run_tests.py | |
| # A heavier, non-blocking fuzz pass so a flake-free regression that only | |
| # shows up on other random draws still gets surfaced on every push. | |
| fuzz-extended: | |
| name: extended codegen fuzz | |
| runs-on: ubuntu-latest | |
| steps: | |
| - uses: actions/checkout@v4 | |
| - uses: actions/setup-python@v5 | |
| with: | |
| python-version: "3.13" | |
| - name: Property fuzz (50k draws, rotating seed) | |
| run: python tests/test_codegen_props.py 50000 ${{ github.run_number }} | |
| # Prove the lowering is real: take the generated C# and put it through the | |
| # actual .NET compiler (the PoC sandbox has no SDK, so this is the only place | |
| # the golden example is genuinely compiled and run, not "verified by | |
| # construction"). | |
| dotnet-golden: | |
| name: golden C# compiles & runs (.NET) | |
| runs-on: ubuntu-latest | |
| steps: | |
| - uses: actions/checkout@v4 | |
| - uses: actions/setup-python@v5 | |
| with: | |
| python-version: "3.13" | |
| - uses: actions/setup-dotnet@v4 | |
| with: | |
| dotnet-version: "8.0.x" | |
| - name: Check the emitted method is still in sync with the golden host | |
| run: python examples/golden_arraypool/verify_emit.py | |
| - name: Compile & run the generated C# with the real compiler | |
| run: | | |
| dotnet new console -o "$RUNNER_TEMP/golden_app" | |
| cp examples/golden_arraypool/Program.cs "$RUNNER_TEMP/golden_app/Program.cs" | |
| dotnet run --project "$RUNNER_TEMP/golden_app" | |
| # P-001: prove the C# leak pipeline end-to-end on real C# — the Roslyn | |
| # extractor turns sample .cs into OwnIR facts, and the core surfaces the | |
| # subscription leak at its C# location (and stays silent on the disposed one). | |
| wpf-extractor: | |
| name: C# leak extractor (Roslyn) -> OwnIR -> core | |
| runs-on: ubuntu-latest | |
| steps: | |
| - uses: actions/checkout@v4 | |
| - uses: actions/setup-python@v5 | |
| with: | |
| python-version: "3.13" | |
| - uses: actions/setup-dotnet@v4 | |
| with: | |
| dotnet-version: "8.0.x" | |
| - name: Extract OwnIR facts from sample C# | |
| run: | | |
| dotnet run --project frontend/roslyn/OwnSharp.Extractor -- \ | |
| frontend/roslyn/samples/CustomerViewModel.cs \ | |
| frontend/roslyn/samples/OrdersViewModel.cs \ | |
| -o "$RUNNER_TEMP/facts.json" | |
| cat "$RUNNER_TEMP/facts.json" | |
| - name: Check facts through the core | |
| run: | | |
| out=$(python -m ownlang ownir "$RUNNER_TEMP/facts.json" || true) | |
| echo "$out" | |
| echo "$out" | grep -q "CustomerViewModel.cs" \ | |
| || { echo "FAIL: expected the CustomerViewModel leak"; exit 1; } | |
| echo "$out" | grep -q "OWN001" \ | |
| || { echo "FAIL: expected OWN001"; exit 1; } | |
| if echo "$out" | grep -q "OrdersViewModel.cs"; then | |
| echo "FAIL: disposed subscription wrongly reported"; exit 1 | |
| fi | |
| echo "OK: real C# -> facts -> OWN001 at the C# location" | |