|
26 | 26 | - os: windows-latest |
27 | 27 | runner: windows-latest |
28 | 28 | runs-on: ${{ matrix.runner }} |
29 | | - timeout-minutes: 10 |
| 29 | + timeout-minutes: 15 |
30 | 30 | steps: |
31 | 31 | - uses: actions/checkout@v4 |
32 | 32 | with: |
|
35 | 35 | - uses: actions/setup-python@v5 |
36 | 36 | with: |
37 | 37 | python-version: '3.12' |
| 38 | + - name: Provision the current WFL nightly |
| 39 | + shell: pwsh |
| 40 | + run: | |
| 41 | + $ErrorActionPreference = 'Stop' |
| 42 | + # The GitHub daily release is an immutable mirror. The canonical |
| 43 | + # publisher can release a newer runtime on the same day to this CDN. |
| 44 | + $cdn = 'https://wfl.nyc3.cdn.digitaloceanspaces.com' |
| 45 | + # A previously cached pointer can retain the CDN's older one-hour TTL. |
| 46 | + $publicationUri = "$cdn/status.json?request=$([guid]::NewGuid().ToString('N'))" |
| 47 | + $publication = Invoke-RestMethod -Uri $publicationUri |
| 48 | + if ($publication.result -ne 'success' -or $publication.branch -ne 'main' -or |
| 49 | + $publication.version -notmatch '^\d+\.\d+\.\d+$' -or |
| 50 | + $publication.sha -notmatch '^[a-f0-9]{40}$') { |
| 51 | + throw 'Invalid official WFL publication record' |
| 52 | + } |
| 53 | + $releaseVersion = [regex]::Escape($publication.version) |
| 54 | + $pattern = if ($IsWindows) { "^wfl-$releaseVersion\.msi$" } else { "^wfl-$releaseVersion-linux-x86_64-[a-f0-9]{7,40}\.tar\.gz$" } |
| 55 | + $assets = @($publication.message -split '\s+' | Where-Object { $_ -match $pattern }) |
| 56 | + if ($assets.Count -ne 1) { throw 'Publication must name one immutable platform-specific WFL asset' } |
| 57 | + $assetName = $assets[0] |
| 58 | + if (-not $IsWindows -and $assetName -match '-linux-x86_64-([a-f0-9]{7,40})\.tar\.gz$') { |
| 59 | + if (-not $publication.sha.StartsWith($Matches[1])) { throw 'WFL artifact revision does not match publication' } |
| 60 | + } |
| 61 | + $assetUrl = "$cdn/releases/$assetName" |
| 62 | + $checksum = (Invoke-WebRequest -Uri "$assetUrl.sha256").Content.Trim() |
| 63 | + $checksumPattern = '^([a-fA-F0-9]{64})\s+\*?' + [regex]::Escape($assetName) + '$' |
| 64 | + if ($checksum -notmatch $checksumPattern) { throw 'Invalid immutable WFL checksum sidecar' } |
| 65 | + $expectedDigest = $Matches[1].ToLowerInvariant() |
| 66 | + $runtimeRoot = Join-Path $env:RUNNER_TEMP 'scriptorium-wfl' |
| 67 | + New-Item -ItemType Directory -Path $runtimeRoot -Force | Out-Null |
| 68 | + $archive = Join-Path $runtimeRoot $assetName |
| 69 | + Invoke-WebRequest -Uri $assetUrl -OutFile $archive |
| 70 | + $digest = (Get-FileHash -LiteralPath $archive -Algorithm SHA256).Hash.ToLowerInvariant() |
| 71 | + if ($expectedDigest -ne $digest) { throw 'WFL release asset digest mismatch' } |
| 72 | + if ($IsWindows) { |
| 73 | + $expanded = Join-Path $runtimeRoot 'expanded' |
| 74 | + $arguments = @('/a', "`"$archive`"", '/qn', "TARGETDIR=`"$expanded`"") |
| 75 | + $installer = Start-Process msiexec.exe -ArgumentList $arguments -Wait -PassThru -WindowStyle Hidden |
| 76 | + if ($installer.ExitCode -ne 0) { throw "WFL extraction failed: $($installer.ExitCode)" } |
| 77 | + $programs = @(Get-ChildItem -LiteralPath $expanded -Filter wfl.exe -File -Recurse) |
| 78 | + } else { |
| 79 | + tar -xzf $archive -C $runtimeRoot |
| 80 | + if ($LASTEXITCODE -ne 0) { throw 'WFL extraction failed' } |
| 81 | + $programs = @(Get-ChildItem -LiteralPath $runtimeRoot -Filter wfl -File -Recurse) |
| 82 | + } |
| 83 | + if ($programs.Count -ne 1) { throw 'Expected one extracted WFL executable' } |
| 84 | + $runtimePath = $programs[0].FullName |
| 85 | + $programs[0].DirectoryName | Out-File -FilePath $env:GITHUB_PATH -Append |
| 86 | + $version = & $runtimePath --version |
| 87 | + if ($LASTEXITCODE -ne 0) { throw 'Extracted WFL runtime did not start' } |
| 88 | + if ($version -ne "WebFirst Language (WFL) version $($publication.version)") { throw 'WFL executable version does not match publication' } |
| 89 | + @( |
| 90 | + '### Governance runtime', |
| 91 | + "- Publication: $cdn/status.json", |
| 92 | + "- WFL revision: $($publication.sha)", |
| 93 | + "- Asset: $assetUrl", |
| 94 | + "- SHA256: $digest", |
| 95 | + "- Runtime: $version", |
| 96 | + "- Scriptorium: $env:GITHUB_SHA" |
| 97 | + ) | Out-File -FilePath $env:GITHUB_STEP_SUMMARY -Append |
38 | 98 | - name: Test repository tooling |
39 | | - run: python -m unittest discover -s tests/tooling -v |
| 99 | + run: wfl scripts/run_tests.wfl --group tooling |
40 | 100 | - name: Check repository hygiene |
41 | 101 | run: python scripts/check_repo_hygiene.py |
0 commit comments