Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
16 changes: 0 additions & 16 deletions .github/actions/collect-ci-summary/action.yml

This file was deleted.

111 changes: 111 additions & 0 deletions .github/actions/run-mobile-e2e/action.yml
Original file line number Diff line number Diff line change
@@ -0,0 +1,111 @@
name: Run installed mobile app
description: Shared platform setup, exact-launch SDK smoke, and reports for CI and replay.
inputs:
platform:
required: true
description: android or ios
source-sha:
required: true
description: Exact source SHA of the downloaded app
runs:
using: composite
steps:
- name: Set up Node and Bun
uses: ./.github/actions/setup-node-bun

- name: Reclaim Android emulator disk
if: ${{ inputs.platform == 'android' }}
shell: bash
run: bash .github/scripts/reclaim-android-mobile-build-disk.sh

- name: Set up Android
if: ${{ inputs.platform == 'android' }}
uses: ./.github/actions/setup-android
with:
gradle-cache: "false"
native-tools: "false"

- name: List Android app artifact
if: ${{ inputs.platform == 'android' }}
shell: bash
run: find target/mobile-build/react-native/android -maxdepth 2 -type f -print

- name: Provision runner KVM access
if: ${{ inputs.platform == 'android' }}
shell: bash
run: |
test -c /dev/kvm
if [ ! -r /dev/kvm ] || [ ! -w /dev/kvm ]; then
sudo chmod a+rw /dev/kvm
fi

- name: Start Android emulator
if: ${{ inputs.platform == 'android' }}
env:
OLIPHAUNT_ANDROID_EMULATOR_API: "35"
OLIPHAUNT_ANDROID_EMULATOR_DISK_HEADROOM_MB: "2048"
OLIPHAUNT_ANDROID_EMULATOR_PARTITION_SIZE_MB: "6144"
shell: bash
run: tools/ci/start-android-emulator-ci.sh

- name: Run Android installed-app E2E
if: ${{ inputs.platform == 'android' }}
env:
CI_HEAD_SHA: ${{ inputs.source-sha }}
OLIPHAUNT_EXPO_ANDROID_BUILD_ARTIFACT_DIR: ${{ github.workspace }}/target/mobile-build/react-native/android
OLIPHAUNT_EXPO_ANDROID_BUILD_TYPE: release
OLIPHAUNT_EXPO_ANDROID_LIFECYCLE_SMOKE: "0"
shell: bash
run: bash src/native/sdks/react-native/tools/mobile-e2e.sh android

- name: Upload Android E2E reports
if: ${{ always() && inputs.platform == 'android' }}
uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a
with:
name: react-native-mobile-android-e2e-reports
path: |
target/mobile/react-native/android-e2e/reports
target/mobile/react-native/android-e2e/logs
${{ runner.temp }}/oliphaunt-android-emulator.log
if-no-files-found: ignore
- name: Set up Apple
if: ${{ inputs.platform == 'ios' }}
uses: ./.github/actions/setup-apple
with:
install-build-dependencies: "false"

- name: Verify and extract iOS app artifact
if: ${{ inputs.platform == 'ios' }}
shell: bash
run: |
rm -rf target/mobile-build/react-native/ios
bash src/native/sdks/react-native/tools/ios-app-transport.sh verify-extract \
--transport-dir target/mobile-build/react-native/ios-transport \
--output-dir target/mobile-build/react-native/ios

- name: List iOS app artifact
if: ${{ inputs.platform == 'ios' }}
shell: bash
run: find target/mobile-build/react-native/ios -maxdepth 2 -print

- name: Run iOS installed-app E2E
if: ${{ inputs.platform == 'ios' }}
env:
CI_HEAD_SHA: ${{ inputs.source-sha }}
OLIPHAUNT_EXPO_IOS_BUILD_ARTIFACT_DIR: ${{ github.workspace }}/target/mobile-build/react-native/ios
OLIPHAUNT_EXPO_IOS_CONFIGURATION: Release
OLIPHAUNT_EXPO_IOS_SDK: iphonesimulator
OLIPHAUNT_EXPO_IOS_LIFECYCLE_SMOKE: "0"
shell: bash
run: bash src/native/sdks/react-native/tools/mobile-e2e.sh ios

- name: Upload iOS E2E reports
if: ${{ always() && inputs.platform == 'ios' }}
uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a
with:
name: react-native-mobile-ios-e2e-reports
path: |
target/mobile/react-native/ios-e2e/reports
target/mobile/react-native/ios-e2e/logs
target/mobile/react-native/ios-e2e/*.log
if-no-files-found: ignore
43 changes: 21 additions & 22 deletions .github/actions/setup-android/action.yml
Original file line number Diff line number Diff line change
Expand Up @@ -2,18 +2,12 @@ name: Set up Android
description: Set up Java and expose Android SDK paths for Gradle/Expo jobs.

inputs:
ndk-version:
description: Android NDK side-by-side version required by native SDK builds.
required: false
default: "27.0.12077973"
cmake-version:
description: Android CMake version required by native SDK builds.
required: false
default: "3.22.1"
compile-sdk:
description: Android platform API level used by SDK checks.
required: false
default: "36"
native-tools:
description: Install NDK and CMake for native compilation.
default: "true"
expo:
description: Also provision the Expo app NDK before Gradle runs.
default: "false"
native-ccache:
description: Whether to install and configure ccache for native Android C/C++ builds.
required: false
Expand Down Expand Up @@ -109,12 +103,21 @@ runs:
ccache --set-config=max_size=2G
ccache --zero-stats

- name: Set up macOS acquisition timer
if: ${{ runner.os == 'macOS' }}
shell: bash
run: |
. tools/dev/acquisition.sh
if ! oliphaunt_acquisition_timeout >/dev/null 2>&1; then
HOMEBREW_NO_AUTO_UPDATE=1 brew install coreutils
fi
oliphaunt_acquisition_timeout >/dev/null

- name: Configure Android SDK
shell: bash
env:
NDK_VERSION: ${{ inputs.ndk-version }}
CMAKE_VERSION: ${{ inputs.cmake-version }}
COMPILE_SDK: ${{ inputs.compile-sdk }}
NATIVE_TOOLS: ${{ inputs.native-tools }}
EXPO: ${{ inputs.expo }}
run: | # zizmor: ignore[github-env] Android SDK paths are runner-owned or HOME-scoped and validated before export.
set -euo pipefail
if [[ -z "${ANDROID_HOME:-}" ]]; then
Expand All @@ -128,16 +131,12 @@ runs:
export ANDROID_HOME="$HOME/android-sdk"
fi
fi
tools/dev/setup-android-sdk.sh \
--sdk-root "$ANDROID_HOME" \
--ndk-version "$NDK_VERSION" \
--cmake-version "$CMAKE_VERSION" \
--compile-sdk "$COMPILE_SDK"
args=(--sdk-root "$ANDROID_HOME" --native-tools "$NATIVE_TOOLS")
case "$EXPO" in true) args+=(--expo) ;; false) ;; *) exit 1 ;; esac
tools/dev/setup-android-sdk.sh "${args[@]}"

echo "ANDROID_HOME=${ANDROID_HOME}" >> "$GITHUB_ENV"
echo "ANDROID_SDK_ROOT=${ANDROID_HOME}" >> "$GITHUB_ENV"
echo "ANDROID_NDK_HOME=${ANDROID_HOME}/ndk/${NDK_VERSION}" >> "$GITHUB_ENV"
echo "${ANDROID_HOME}/cmdline-tools/latest/bin" >> "$GITHUB_PATH"
echo "${ANDROID_HOME}/platform-tools" >> "$GITHUB_PATH"
echo "ANDROID_HOME=${ANDROID_HOME}"
echo "ANDROID_NDK_HOME=${ANDROID_HOME}/ndk/${NDK_VERSION}"
4 changes: 2 additions & 2 deletions .github/actions/setup-deno/action.yml
Original file line number Diff line number Diff line change
Expand Up @@ -3,9 +3,9 @@ description: Install the pinned Deno toolchain for TypeScript runtime checks.

inputs:
deno-version:
description: Deno version.
description: Optional assertion against the repository Deno pin.
required: false
default: "v2.8.1"
default: ""

outputs:
execution-envelope:
Expand Down
15 changes: 0 additions & 15 deletions .github/actions/setup-maestro/action.yml

This file was deleted.

11 changes: 8 additions & 3 deletions .github/actions/setup-moon/action.yml
Original file line number Diff line number Diff line change
Expand Up @@ -2,6 +2,10 @@ name: Set up Moon
description: Install verified Node.js, Moon, and Bun binaries and optionally hydrate JavaScript workspace dependencies.

inputs:
task-cache:
description: Restore/save Moon task outputs; disable for planning and uncached finalizers.
required: false
default: "true"
install-workspace:
description: Install Bun workspace dependencies for JavaScript-family tasks.
required: false
Expand All @@ -17,7 +21,7 @@ runs:
path: |
${{ runner.temp }}/oliphaunt-moon-toolchain
${{ runner.temp }}/oliphaunt-pinned-tools
key: verified-moon-toolchain-v1-${{ runner.os }}-${{ runner.arch }}-${{ hashFiles('.prototools', '.moon/toolchains.yml', '.github/actions/setup-moon/action.yml', '.github/actions/setup-node-bun/action.yml', '.github/actions/setup-moon/install-pinned-toolchain.sh', '.github/actions/setup-moon/toolchain-archive.mts', 'tools/dev/moon-cli.toml', 'tools/dev/moon-plugins.toml', 'tools/dev/proto.toml', 'tools/dev/bun.toml', 'tools/dev/install-pinned-js-runtime.sh', 'tools/dev/extract-pinned-zip.sh', 'tools/packaging/portable-archive.mts', 'tools/dev/extract-pinned-binary.sh', 'tools/dev/curl-platform-flags.sh') }}
key: verified-moon-toolchain-v1-${{ runner.os }}-${{ runner.arch }}-${{ hashFiles('.prototools', '.moon/toolchains.yml', '.github/actions/setup-moon/action.yml', '.github/actions/setup-node-bun/action.yml', '.github/actions/setup-moon/install-pinned-toolchain.sh', '.github/actions/setup-moon/toolchain-archive.mts', 'tools/dev/moon-cli.toml', 'tools/dev/moon-plugins.toml', 'tools/dev/proto.toml', 'tools/dev/bun.toml', 'tools/dev/install-pinned-js-runtime.sh', 'tools/dev/extract-pinned-zip.sh', 'tools/packaging/portable-archive.mts', 'tools/dev/extract-pinned-binary.sh', 'tools/dev/curl-platform-flags.sh', 'tools/dev/acquisition.sh') }}

- name: Set up exact Node.js and Bun
uses: ./.github/actions/setup-node-bun
Expand Down Expand Up @@ -70,7 +74,7 @@ runs:
node --version
bun --version
# This shell probe needs no source comparison or fetched base branch.
.github/scripts/run-moon-targets.sh --base HEAD --head HEAD ci-workflows:verify-bash
.github/scripts/run-moon-targets.sh ci-workflows:verify-bash

- name: Save verified tool archives
if: ${{ steps.restore_verified_moon_toolchain.outputs.cache-hit != 'true' }}
Expand All @@ -80,14 +84,15 @@ runs:
path: |
${{ runner.temp }}/oliphaunt-moon-toolchain
${{ runner.temp }}/oliphaunt-pinned-tools
key: verified-moon-toolchain-v1-${{ runner.os }}-${{ runner.arch }}-${{ hashFiles('.prototools', '.moon/toolchains.yml', '.github/actions/setup-moon/action.yml', '.github/actions/setup-node-bun/action.yml', '.github/actions/setup-moon/install-pinned-toolchain.sh', '.github/actions/setup-moon/toolchain-archive.mts', 'tools/dev/moon-cli.toml', 'tools/dev/moon-plugins.toml', 'tools/dev/proto.toml', 'tools/dev/bun.toml', 'tools/dev/install-pinned-js-runtime.sh', 'tools/dev/extract-pinned-zip.sh', 'tools/packaging/portable-archive.mts', 'tools/dev/extract-pinned-binary.sh', 'tools/dev/curl-platform-flags.sh') }}
key: verified-moon-toolchain-v1-${{ runner.os }}-${{ runner.arch }}-${{ hashFiles('.prototools', '.moon/toolchains.yml', '.github/actions/setup-moon/action.yml', '.github/actions/setup-node-bun/action.yml', '.github/actions/setup-moon/install-pinned-toolchain.sh', '.github/actions/setup-moon/toolchain-archive.mts', 'tools/dev/moon-cli.toml', 'tools/dev/moon-plugins.toml', 'tools/dev/proto.toml', 'tools/dev/bun.toml', 'tools/dev/install-pinned-js-runtime.sh', 'tools/dev/extract-pinned-zip.sh', 'tools/packaging/portable-archive.mts', 'tools/dev/extract-pinned-binary.sh', 'tools/dev/curl-platform-flags.sh', 'tools/dev/acquisition.sh') }}

- name: Install workspace dependencies
if: ${{ inputs.install-workspace == 'true' }}
shell: bash
run: bun install --frozen-lockfile

- name: Restore Moon task outputs
if: ${{ inputs.task-cache == 'true' }}
uses: actions/cache@55cc8345863c7cc4c66a329aec7e433d2d1c52a9
with:
# casOutputsCache uses these directories; hashes/ is diagnostic metadata.
Expand Down
7 changes: 4 additions & 3 deletions .github/actions/setup-moon/install-pinned-node.sh
Original file line number Diff line number Diff line change
Expand Up @@ -33,6 +33,8 @@ done

# shellcheck source=tools/dev/curl-platform-flags.sh
. "$curl_platform_flags"
. "${curl_platform_flags%/*}/acquisition.sh"
oliphaunt_acquisition_start "Node.js bootstrap" 300


manifest_value() {
Expand Down Expand Up @@ -204,15 +206,14 @@ if [ "$archive_valid" != "1" ]; then
curl_args=(
--fail --location --silent --show-error
--proto '=https' --proto-redir '=https' --tlsv1.2
--retry 5 --retry-all-errors --retry-connrefused --retry-delay 2 --retry-max-time 300
--connect-timeout 20 --max-time 300 --speed-limit 1024 --speed-time 30
--connect-timeout 20 --speed-limit 1024 --speed-time 30
--remove-on-error --max-filesize "$archive_bytes" --output "$partial"
)
if [ -n "$curl_tls_flag" ]; then
curl_args+=("$curl_tls_flag")
fi
curl_args+=("$url")
if ! "$curl_command" "${curl_args[@]}"; then
if ! oliphaunt_acquisition_curl 300 6 2 "$curl_command" "${curl_args[@]}"; then
rm -f "$partial"
fail "could not download pinned Node.js archive $url"
fi
Expand Down
6 changes: 5 additions & 1 deletion .github/actions/setup-moon/install-pinned-node.test.sh
Original file line number Diff line number Diff line change
Expand Up @@ -4,6 +4,10 @@ set -euo pipefail
root="$(git rev-parse --show-toplevel)"
installer="$root/.github/actions/setup-moon/install-pinned-node.sh"
work="$(mktemp -d)"
mkdir -p "$work/no-delay"
printf '#!/bin/sh\nexit 0\n' > "$work/no-delay/sleep"
chmod +x "$work/no-delay/sleep"
export PATH="$work/no-delay:$PATH"
trap 'rm -rf "$work"' EXIT

mkdir -p "$work/payload/node-v22.22.3-linux-x64/bin" "$work/bin"
Expand Down Expand Up @@ -42,7 +46,7 @@ set -euo pipefail
output=""
last=""
joined=" $* "
for required in "--fail" "--location" "--proto =https" "--proto-redir =https" "--tlsv1.2" "--retry-all-errors" "--retry-connrefused" "--remove-on-error" "--max-filesize"; do
for required in "--fail" "--location" "--proto =https" "--proto-redir =https" "--tlsv1.2" "--retry 0" "--remove-on-error" "--max-filesize"; do
[[ "$joined" == *" $required "* ]] || {
echo "missing hardened curl argument: $required" >&2
exit 91
Expand Down
11 changes: 6 additions & 5 deletions .github/actions/setup-moon/install-pinned-toolchain.sh
Original file line number Diff line number Diff line change
Expand Up @@ -42,6 +42,8 @@ done

# shellcheck source=tools/dev/curl-platform-flags.sh
. "$curl_platform_flags"
. "${curl_platform_flags%/*}/acquisition.sh"
oliphaunt_acquisition_start "Moon toolchain and plugins" 900

command -v bun >/dev/null 2>&1 || fail "Bun is required; run setup-node-bun first"

Expand Down Expand Up @@ -257,8 +259,7 @@ curl_tls_flag="$(oliphaunt_curl_platform_tls_flag)"
curl_common=(
--fail --location --silent --show-error
--proto '=https' --proto-redir '=https' --tlsv1.2
--retry 6 --retry-all-errors --retry-connrefused --retry-max-time 300
--connect-timeout 20 --max-time 300 --speed-limit 1024 --speed-time 30
--connect-timeout 20 --speed-limit 1024 --speed-time 30
--remove-on-error
)
if [ -n "$curl_tls_flag" ]; then
Expand Down Expand Up @@ -287,7 +288,7 @@ download_verified() {
args+=(--header "Authorization: Bearer $bearer")
fi
args+=("$url")
if "${OLIPHAUNT_MOON_CURL:-curl}" "${args[@]}"; then
if oliphaunt_acquisition_curl 300 7 2 "${OLIPHAUNT_MOON_CURL:-curl}" "${args[@]}"; then
:
else
rc=$?
Expand Down Expand Up @@ -317,7 +318,7 @@ registry_token() {
--output "$response"
"https://ghcr.io/token?scope=repository:$repository:pull"
)
if ! "${OLIPHAUNT_MOON_CURL:-curl}" "${args[@]}"; then
if ! oliphaunt_acquisition_curl 300 7 2 "${OLIPHAUNT_MOON_CURL:-curl}" "${args[@]}"; then
rm -f "$response"
fail "could not obtain a bounded read-only GHCR token for $repository"
fi
Expand Down Expand Up @@ -356,7 +357,7 @@ download_oci_manifest() {
--output "$partial"
"https://ghcr.io/v2/$repository/manifests/sha256:$digest"
)
if ! "${OLIPHAUNT_MOON_CURL:-curl}" "${args[@]}"; then
if ! oliphaunt_acquisition_curl 300 7 2 "${OLIPHAUNT_MOON_CURL:-curl}" "${args[@]}"; then
rm -f "$partial" "$headers"
fail "could not fetch pinned OCI manifest $repository@sha256:$digest"
fi
Expand Down
7 changes: 6 additions & 1 deletion .github/actions/setup-moon/install-pinned-toolchain.test.sh
Original file line number Diff line number Diff line change
Expand Up @@ -5,6 +5,10 @@ root="$(git rev-parse --show-toplevel)"
installer="$root/.github/actions/setup-moon/install-pinned-toolchain.sh"
extractor="$root/.github/actions/setup-moon/toolchain-archive.mts"
tmp="$(mktemp -d)"
mkdir -p "$tmp/no-delay"
printf '#!/bin/sh\nexit 0\n' > "$tmp/no-delay/sleep"
chmod +x "$tmp/no-delay/sleep"
export PATH="$tmp/no-delay:$PATH"
trap 'rm -rf "$tmp"' EXIT

fail() {
Expand All @@ -27,6 +31,7 @@ mkdir -p \
"$fixture/content" \
"$fixture/blobs"
cp "$root/tools/dev/curl-platform-flags.sh" "$fixture/tools/dev/curl-platform-flags.sh"
cp "$root/tools/dev/acquisition.sh" "$fixture/tools/dev/acquisition.sh"

moon_version="9.8.7"
proto_version="7.6.5"
Expand Down Expand Up @@ -201,7 +206,7 @@ final="$(bash "$installer")"
[ "$(find "$final/plugins" -mindepth 1 -maxdepth 1 | wc -l | tr -d '[:space:]')" = "4" ] || fail "wrong plugin count"
[ "$(wc -l <"$FAKE_CURL_LOG" | tr -d '[:space:]')" = "13" ] || fail "unexpected first-install request count"
while IFS= read -r call; do
for flag in --ssl-revoke-best-effort --tlsv1.2 --retry-all-errors --retry-connrefused --max-filesize --max-time --speed-limit; do
for flag in --ssl-revoke-best-effort --tlsv1.2 --retry --max-filesize --max-time --speed-limit; do
[[ "$call" == *"$flag"* ]] || fail "curl request omitted $flag"
done
done <"$FAKE_CURL_LOG"
Expand Down
Loading
Loading