Fix hub analysis and bounded trails; audit graph comparison evidence #989
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
| name: Compass Rust CI | |
| on: | |
| push: | |
| branches: ["main"] | |
| pull_request: | |
| branches: ["main"] | |
| workflow_dispatch: | |
| concurrency: | |
| group: compass-rust-${{ github.workflow }}-${{ github.ref }} | |
| cancel-in-progress: true | |
| permissions: | |
| contents: read | |
| defaults: | |
| run: | |
| working-directory: . | |
| jobs: | |
| code-graph-v1-fixtures: | |
| runs-on: ubuntu-24.04 | |
| steps: | |
| - uses: actions/checkout@df4cb1c069e1874edd31b4311f1884172cec0e10 # v6 | |
| - uses: actions/setup-node@49933ea5288caeca8642d1e84afbd3f7d6820020 # v4 | |
| with: | |
| node-version: "24.15.0" # Playwright browser extraction workaround on Ubuntu 24.04. | |
| cache: npm | |
| - name: Install pinned Rust toolchain | |
| uses: dtolnay/rust-toolchain@2c7215f132e9ebf062739d9130488b56d53c060c # master | |
| with: | |
| toolchain: 1.97.1 | |
| components: rustfmt, clippy | |
| - uses: Swatinem/rust-cache@e18b497796c12c097a38f9edb9d0641fb99eee32 # v2 | |
| with: | |
| workspaces: . | |
| - run: npm ci | |
| - run: npx playwright install --with-deps chromium | |
| - name: Provision pinned parser sources | |
| env: | |
| TSLP_PARSER_SOURCE_DIR: ${{ runner.temp }}/compass-parser-sources | |
| run: ./scripts/provision_parser_sources.sh "$TSLP_PARSER_SOURCE_DIR" | |
| - name: Fetch pinned Rust dependencies | |
| run: cargo fetch --locked | |
| - name: Qualify Compass code graph v1 | |
| env: | |
| CARGO_TARGET_DIR: ${{ runner.temp }}/compass-code-graph-v1 | |
| TSLP_PARSER_SOURCE_DIR: ${{ runner.temp }}/compass-parser-sources | |
| run: ./scripts/qualify_code_graph_v1.sh --fixtures-only | |
| javascript-and-vscode: | |
| runs-on: ubuntu-24.04 | |
| steps: | |
| - uses: actions/checkout@df4cb1c069e1874edd31b4311f1884172cec0e10 # v6 | |
| - uses: actions/setup-node@49933ea5288caeca8642d1e84afbd3f7d6820020 # v4 | |
| with: | |
| node-version: "24.15.0" # Playwright browser extraction workaround on Ubuntu 24.04. | |
| cache: npm | |
| - run: npm ci | |
| - run: npx playwright install --with-deps chromium | |
| - run: npm run typecheck:js | |
| - run: npm run test:js | |
| - run: xvfb-run -a npm run test:integration -w editors/vscode | |
| - run: node scripts/check_viewer_assets.mjs | |
| - run: npm run build:vscode | |
| - run: npm run package -w editors/vscode | |
| - run: npm run smoke:vsix -w editors/vscode | |
| quality: | |
| runs-on: ubuntu-24.04 | |
| steps: | |
| - uses: actions/checkout@df4cb1c069e1874edd31b4311f1884172cec0e10 # v6 | |
| - name: Enforce Compass product boundary | |
| run: sh scripts/check_product_boundary.sh | |
| - name: Install pinned Rust toolchain | |
| uses: dtolnay/rust-toolchain@2c7215f132e9ebf062739d9130488b56d53c060c # master | |
| with: | |
| toolchain: 1.97.1 | |
| components: rustfmt, clippy | |
| - uses: Swatinem/rust-cache@e18b497796c12c097a38f9edb9d0641fb99eee32 # v2 | |
| with: | |
| workspaces: . | |
| - name: Install pinned nextest runner | |
| uses: taiki-e/install-action@07b4745e0c39a41822af610387492e3e53aa222b # v2 | |
| with: | |
| tool: nextest@0.9.124 | |
| - name: Formatting | |
| run: cargo fmt --all -- --check | |
| - name: Lints | |
| run: cargo clippy --workspace --lib --bins --locked -- -D warnings | |
| - name: Native tests | |
| run: | | |
| cargo test --workspace --lib --bins --locked | |
| cargo test -p compass-cli --test compass_product --locked | |
| # The CLI integration suites cover the text projections, exit codes | |
| # and streams this product exposes; without them the review and | |
| # agent-view contracts rot silently. | |
| cargo test -p compass-cli --tests --locked | |
| - name: Hub and bounded path regressions | |
| run: | | |
| cargo test -p compass-graph --test analyze_coverage --locked | |
| cargo test -p compass-query --test bounded_path_oracle --test code_traversal --test coverage_paths --locked | |
| - name: Comparison scorer regressions (no competitor installation) | |
| run: python3 -m unittest discover -s benchmarks/agent_query/tests | |
| - name: Qualify natural-language query relevance | |
| env: | |
| CARGO_TARGET_DIR: ${{ github.workspace }}/target | |
| run: python3 scripts/qualify_query_relevance.py | |
| - name: Verify pinned CompassQL support evidence | |
| run: | | |
| cargo test -p compass-cypher --test tck --locked | |
| cargo test -p compass-query --test opencypher_tck --locked | |
| python3 scripts/check_compassql_support.py | |
| - name: Isolated native tests | |
| run: cargo nextest run --workspace --lib --bins --locked | |
| - name: Verify publishable crate archives | |
| run: | | |
| cargo package --workspace --locked --no-verify \ | |
| --exclude compass-transcribe \ | |
| --exclude compass-whisper | |
| - name: Verify cargo install and standalone launch | |
| shell: bash | |
| run: | | |
| install_root="$(mktemp -d)" | |
| cargo install --path crates/compass-cli --locked --root "$install_root" | |
| "$install_root/bin/compass" --help | |
| - name: Validate qualification and completion scripts | |
| shell: bash | |
| run: | | |
| sh -n scripts/check_critical_coverage.sh | |
| bash -n scripts/publish_crates.sh | |
| sh -n scripts/install.sh | |
| sh -n scripts/package_release.sh | |
| sh -n scripts/test_release_scripts.sh | |
| bash -n scripts/qualify_code_graph_v1.sh | |
| python scripts/check_universal_evidence_promotion.py | |
| python -m unittest scripts.tests.test_universal_evidence_promotion | |
| sh scripts/test_release_scripts.sh | |
| bash -n completions/compass.bash | |
| python -c "import ast,pathlib; ast.parse(pathlib.Path('scripts/measure_process.py').read_text())" | |
| python -c "import ast,pathlib; ast.parse(pathlib.Path('scripts/check_compassql_support.py').read_text())" | |
| sh -n scripts/benchmark_compassql.sh | |
| native-platforms: | |
| name: ${{ matrix.target }} | |
| strategy: | |
| fail-fast: false | |
| matrix: | |
| include: | |
| - runner: ubuntu-24.04 | |
| target: x86_64-unknown-linux-gnu | |
| - runner: ubuntu-24.04-arm | |
| target: aarch64-unknown-linux-gnu | |
| - runner: macos-15-intel | |
| target: x86_64-apple-darwin | |
| - runner: macos-15 | |
| target: aarch64-apple-darwin | |
| - runner: windows-2025 | |
| target: x86_64-pc-windows-msvc | |
| - runner: windows-11-arm | |
| target: aarch64-pc-windows-msvc | |
| runs-on: ${{ matrix.runner }} | |
| steps: | |
| - uses: actions/checkout@df4cb1c069e1874edd31b4311f1884172cec0e10 # v6 | |
| - name: Install pinned Rust toolchain | |
| uses: dtolnay/rust-toolchain@2c7215f132e9ebf062739d9130488b56d53c060c # master | |
| with: | |
| toolchain: 1.97.1 | |
| target: ${{ matrix.target }} | |
| - uses: Swatinem/rust-cache@e18b497796c12c097a38f9edb9d0641fb99eee32 # v2 | |
| with: | |
| workspaces: . | |
| key: ${{ matrix.target }} | |
| - name: Native tests | |
| run: cargo test --workspace --lib --bins --locked --target ${{ matrix.target }} | |
| - name: Code graph deterministic publication and SQLite recovery | |
| run: | | |
| cargo test -p compass-core --test code_graph_v1_determinism --locked --target ${{ matrix.target }} | |
| cargo test -p compass-query --test index_recovery --locked --target ${{ matrix.target }} | |
| - name: Test PowerShell installer | |
| if: runner.os == 'Windows' | |
| shell: pwsh | |
| run: | | |
| cargo build --release --locked -p compass-cli --bin compass --target ${{ matrix.target }} | |
| ./scripts/test_install_ps1.ps1 ` | |
| -CompassBinary "target/${{ matrix.target }}/release/compass.exe" | |
| code-graph-client-platforms: | |
| strategy: | |
| fail-fast: false | |
| matrix: | |
| runner: [ubuntu-24.04, macos-15, windows-2025] | |
| runs-on: ${{ matrix.runner }} | |
| steps: | |
| - uses: actions/checkout@df4cb1c069e1874edd31b4311f1884172cec0e10 # v6 | |
| - uses: actions/setup-node@49933ea5288caeca8642d1e84afbd3f7d6820020 # v4 | |
| with: | |
| node-version: "24.13.1" | |
| cache: npm | |
| - run: npm ci | |
| - name: Source containment and process cancellation | |
| run: >- | |
| npm exec -w editors/vscode -- | |
| vitest run | |
| src/views/sourceResolution.test.ts | |
| src/cli/processManager.test.ts | |
| dependency-audit: | |
| runs-on: ubuntu-24.04 | |
| permissions: | |
| contents: read | |
| checks: write | |
| steps: | |
| - uses: actions/checkout@df4cb1c069e1874edd31b4311f1884172cec0e10 # v6 | |
| - name: Install locked cargo-audit | |
| run: cargo install cargo-audit --version 0.22.2 --locked | |
| - name: Audit Rust dependencies | |
| uses: rustsec/audit-check@858dc40f52ca2b8570b7a997c1c4e35c6fc9a432 # Node 24 update | |
| with: | |
| working-directory: . | |
| token: ${{ secrets.GITHUB_TOKEN }} | |
| dependency-policy: | |
| runs-on: ubuntu-24.04 | |
| steps: | |
| - uses: actions/checkout@df4cb1c069e1874edd31b4311f1884172cec0e10 # v6 | |
| - name: Check licenses, bans, advisories, and sources | |
| uses: EmbarkStudios/cargo-deny-action@3c6349835b2b7b196a839186cb8b78e02f7b5f25 # v2.1.1 | |
| with: | |
| manifest-path: Cargo.toml | |
| arguments: --all-features | |
| - name: Check fuzz-harness dependency policy | |
| uses: EmbarkStudios/cargo-deny-action@3c6349835b2b7b196a839186cb8b78e02f7b5f25 # v2.1.1 | |
| with: | |
| manifest-path: fuzz/Cargo.toml |