Skip to content

Merge: name the parser commit CI pins, and log the %E fix and re-vendor #12

Merge: name the parser commit CI pins, and log the %E fix and re-vendor

Merge: name the parser commit CI pins, and log the %E fix and re-vendor #12

Workflow file for this run

name: test
on:
push:
branches: [main, master]
pull_request:
branches: [main, master]
jobs:
test:
name: Python ${{ matrix.python }} on ${{ matrix.os }}
runs-on: ${{ matrix.os }}
env:
# The upstream commit scripts/xer_parser.py is vendored from, and the
# SHA-256 of that file. Re-vendoring is a two-line change: bump both
# together, and the checks below do the rest.
XER_PIN: a8edac6f2ef19f6cddb02dee51dc320f99f6ba38
XER_SHA256: 96edf66b18819e556f891a2a11e3a50240808506ffda32ad3644effe34fa1796
strategy:
fail-fast: false
matrix:
os: [ubuntu-latest, macos-latest, windows-latest]
python: ['3.10', '3.11', '3.12']
steps:
- uses: actions/checkout@v4
- uses: actions/setup-python@v5
with:
python-version: ${{ matrix.python }}
- name: Install pytest
run: python -m pip install --upgrade pip pytest
- name: Clone cpp-cpm-engine (for LPM cross-check)
shell: bash
run: |
git clone --depth 1 https://github.com/danafitkowski/cpp-cpm-engine "$RUNNER_TEMP/cpp-cpm-engine"
echo "CPP_CPM_ENGINE_PATH=$RUNNER_TEMP/cpp-cpm-engine/python_reference" >> "$GITHUB_ENV"
- name: Run unit tests (pytest)
shell: bash
env:
PYTHONPATH: ${{ env.CPP_CPM_ENGINE_PATH }}
run: pytest tests/ -v
- name: Run unit tests (direct, no pytest)
shell: bash
env:
PYTHONPATH: ${{ env.CPP_CPM_ENGINE_PATH }}
run: |
python tests/test_cp_validator.py
python tests/test_dcma14.py
python tests/test_cp_forensic.py
# The vendored parser is checked against a PINNED upstream commit rather
# than against `main`, and the hard check is offline.
#
# Against `main` this check went red on 2026-05-16 and stayed red through
# 2026-08-23. Nothing in this repo was wrong: an upstream docstring
# rewrite landed in cpp-xer-parser, and because the check compared with
# whatever `main` happened to be, an unrelated upstream edit failed every
# build here over text this repo does not execute. A floating comparison
# also cannot be reproduced: re-running the old workflow today gives a
# different answer than it gave in May.
#
# So the failing check is the one that needs no network at all: the
# vendored file must hash to the SHA-256 recorded in XER_SHA256. That is
# deterministic, reproducible years from now, and immune to a network
# blip turning the build red.
- name: Verify vendored xer_parser.py against its recorded pin
if: matrix.os == 'ubuntu-latest' && matrix.python == '3.12'
shell: bash
run: |
LOCAL=$(sha256sum scripts/xer_parser.py | awk '{print $1}')
echo "recorded pin: cpp-xer-parser@$XER_PIN"
echo "recorded sha256: $XER_SHA256"
echo "vendored sha256: $LOCAL"
if [ "$LOCAL" != "$XER_SHA256" ]; then
echo "::error::scripts/xer_parser.py does not match its recorded pin. Re-vendor from cpp-xer-parser@$XER_PIN, or bump XER_PIN and XER_SHA256 together."
exit 1
fi
echo "Vendored copy matches its recorded pin."
# Advisory only, and deliberately incapable of failing the job. It
# confirms the recorded pin still describes the real upstream blob, and
# reports when upstream has moved past it. Upstream moving on is normal
# and is not a defect here, so it must never turn this repo red again.
- name: Cross-check the pin and report upstream movement (advisory)
if: matrix.os == 'ubuntu-latest' && matrix.python == '3.12'
shell: bash
run: |
set +e +o pipefail
RAW=https://raw.githubusercontent.com/danafitkowski/cpp-xer-parser
LOCAL=$(sha256sum scripts/xer_parser.py | awk '{print $1}')
PINNED=$(curl -fsSL "$RAW/$XER_PIN/scripts/xer_parser.py" | sha256sum | awk '{print $1}')
HEAD=$(curl -fsSL "$RAW/main/scripts/xer_parser.py" | sha256sum | awk '{print $1}')
echo "pinned upstream blob: $PINNED"
echo "upstream main blob: $HEAD"
if [ "$PINNED" != "$XER_SHA256" ]; then
echo "::warning::Could not confirm the recorded pin against cpp-xer-parser@$XER_PIN (fetched $PINNED). Either the fetch failed or XER_PIN and XER_SHA256 disagree; check by hand."
fi
if [ "$HEAD" != "$LOCAL" ]; then
echo "::warning::cpp-xer-parser main ($HEAD) has moved past the vendored copy ($LOCAL). Re-vendor when convenient. This does not fail the build."
else
echo "Vendored copy is also current with cpp-xer-parser main."
fi
exit 0