Merge: name the parser commit CI pins, and log the %E fix and re-vendor #12
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
| name: test | |
| on: | |
| push: | |
| branches: [main, master] | |
| pull_request: | |
| branches: [main, master] | |
| jobs: | |
| test: | |
| name: Python ${{ matrix.python }} on ${{ matrix.os }} | |
| runs-on: ${{ matrix.os }} | |
| env: | |
| # The upstream commit scripts/xer_parser.py is vendored from, and the | |
| # SHA-256 of that file. Re-vendoring is a two-line change: bump both | |
| # together, and the checks below do the rest. | |
| XER_PIN: a8edac6f2ef19f6cddb02dee51dc320f99f6ba38 | |
| XER_SHA256: 96edf66b18819e556f891a2a11e3a50240808506ffda32ad3644effe34fa1796 | |
| strategy: | |
| fail-fast: false | |
| matrix: | |
| os: [ubuntu-latest, macos-latest, windows-latest] | |
| python: ['3.10', '3.11', '3.12'] | |
| steps: | |
| - uses: actions/checkout@v4 | |
| - uses: actions/setup-python@v5 | |
| with: | |
| python-version: ${{ matrix.python }} | |
| - name: Install pytest | |
| run: python -m pip install --upgrade pip pytest | |
| - name: Clone cpp-cpm-engine (for LPM cross-check) | |
| shell: bash | |
| run: | | |
| git clone --depth 1 https://github.com/danafitkowski/cpp-cpm-engine "$RUNNER_TEMP/cpp-cpm-engine" | |
| echo "CPP_CPM_ENGINE_PATH=$RUNNER_TEMP/cpp-cpm-engine/python_reference" >> "$GITHUB_ENV" | |
| - name: Run unit tests (pytest) | |
| shell: bash | |
| env: | |
| PYTHONPATH: ${{ env.CPP_CPM_ENGINE_PATH }} | |
| run: pytest tests/ -v | |
| - name: Run unit tests (direct, no pytest) | |
| shell: bash | |
| env: | |
| PYTHONPATH: ${{ env.CPP_CPM_ENGINE_PATH }} | |
| run: | | |
| python tests/test_cp_validator.py | |
| python tests/test_dcma14.py | |
| python tests/test_cp_forensic.py | |
| # The vendored parser is checked against a PINNED upstream commit rather | |
| # than against `main`, and the hard check is offline. | |
| # | |
| # Against `main` this check went red on 2026-05-16 and stayed red through | |
| # 2026-08-23. Nothing in this repo was wrong: an upstream docstring | |
| # rewrite landed in cpp-xer-parser, and because the check compared with | |
| # whatever `main` happened to be, an unrelated upstream edit failed every | |
| # build here over text this repo does not execute. A floating comparison | |
| # also cannot be reproduced: re-running the old workflow today gives a | |
| # different answer than it gave in May. | |
| # | |
| # So the failing check is the one that needs no network at all: the | |
| # vendored file must hash to the SHA-256 recorded in XER_SHA256. That is | |
| # deterministic, reproducible years from now, and immune to a network | |
| # blip turning the build red. | |
| - name: Verify vendored xer_parser.py against its recorded pin | |
| if: matrix.os == 'ubuntu-latest' && matrix.python == '3.12' | |
| shell: bash | |
| run: | | |
| LOCAL=$(sha256sum scripts/xer_parser.py | awk '{print $1}') | |
| echo "recorded pin: cpp-xer-parser@$XER_PIN" | |
| echo "recorded sha256: $XER_SHA256" | |
| echo "vendored sha256: $LOCAL" | |
| if [ "$LOCAL" != "$XER_SHA256" ]; then | |
| echo "::error::scripts/xer_parser.py does not match its recorded pin. Re-vendor from cpp-xer-parser@$XER_PIN, or bump XER_PIN and XER_SHA256 together." | |
| exit 1 | |
| fi | |
| echo "Vendored copy matches its recorded pin." | |
| # Advisory only, and deliberately incapable of failing the job. It | |
| # confirms the recorded pin still describes the real upstream blob, and | |
| # reports when upstream has moved past it. Upstream moving on is normal | |
| # and is not a defect here, so it must never turn this repo red again. | |
| - name: Cross-check the pin and report upstream movement (advisory) | |
| if: matrix.os == 'ubuntu-latest' && matrix.python == '3.12' | |
| shell: bash | |
| run: | | |
| set +e +o pipefail | |
| RAW=https://raw.githubusercontent.com/danafitkowski/cpp-xer-parser | |
| LOCAL=$(sha256sum scripts/xer_parser.py | awk '{print $1}') | |
| PINNED=$(curl -fsSL "$RAW/$XER_PIN/scripts/xer_parser.py" | sha256sum | awk '{print $1}') | |
| HEAD=$(curl -fsSL "$RAW/main/scripts/xer_parser.py" | sha256sum | awk '{print $1}') | |
| echo "pinned upstream blob: $PINNED" | |
| echo "upstream main blob: $HEAD" | |
| if [ "$PINNED" != "$XER_SHA256" ]; then | |
| echo "::warning::Could not confirm the recorded pin against cpp-xer-parser@$XER_PIN (fetched $PINNED). Either the fetch failed or XER_PIN and XER_SHA256 disagree; check by hand." | |
| fi | |
| if [ "$HEAD" != "$LOCAL" ]; then | |
| echo "::warning::cpp-xer-parser main ($HEAD) has moved past the vendored copy ($LOCAL). Re-vendor when convenient. This does not fail the build." | |
| else | |
| echo "Vendored copy is also current with cpp-xer-parser main." | |
| fi | |
| exit 0 |