diff --git a/.github/RELEASING.md b/.github/RELEASING.md index 7918b8d01..f3fa783b6 100644 --- a/.github/RELEASING.md +++ b/.github/RELEASING.md @@ -49,7 +49,7 @@ the commands to resolve it by hand. ## Nightly `nightly.yml` is dev's status (the "nightly" badge in the README). Every night it builds `dev` -from scratch: no cached engines, the five suites, all four platforms' engines, then +from scratch: no cached engines, the five suites, every platform's engines, then `e2e-install.sh` packs the npm tarballs, installs them into an empty project without Soufflé and runs `axiomcode` in four languages, and `npm publish --dry-run` checks each package. diff --git a/.github/scripts/protect-main.sh b/.github/scripts/protect-main.sh index 428529ade..6a7fa16e8 100755 --- a/.github/scripts/protect-main.sh +++ b/.github/scripts/protect-main.sh @@ -49,6 +49,7 @@ payload="$(cat <<'JSON' "dismiss_stale_reviews_on_push": false, "require_code_owner_review": false, "require_last_push_approval": false, + "require_extra_approval_for_unattributed_changes": false, "required_review_thread_resolution": true, "allowed_merge_methods": ["squash", "rebase"] } diff --git a/.github/workflows/build-engines.yml b/.github/workflows/build-engines.yml index d182aadef..167fbf1f1 100644 --- a/.github/workflows/build-engines.yml +++ b/.github/workflows/build-engines.yml @@ -10,9 +10,9 @@ # C++ runtime. Same flags as the local compile (no OpenMP/zlib/sqlite), portable targets. # # Artifacts: engines-/ holding /axiomcode-engine-[.exe] + /ENGINE_ID -# Platforms are named the npm way (process.platform-process.arch): darwin-arm64, linux-x64, -# linux-arm64, win32-x64, each on a standard GitHub-hosted runner (free for a public -# repository; darwin-arm64 is the Apple Silicon macos-15 image). +# Platforms are named the npm way (process.platform-process.arch): darwin-arm64, darwin-x64, +# linux-x64, linux-arm64, win32-x64, each on a standard GitHub-hosted runner (free for a +# public repository; macOS builds on macos-15 for Apple Silicon and macos-15-intel for Intel). # ───────────────────────────────────────────────────────────────────────────── name: build-engines @@ -157,7 +157,14 @@ jobs: build-macos: needs: generate - runs-on: macos-15 + strategy: + fail-fast: false + matrix: + target: + # each on its own architecture's runner, so the smoke step runs the binary natively + - { os: macos-15, arch: arm64, platform: darwin-arm64 } + - { os: macos-15-intel, arch: x86_64, platform: darwin-x64 } + runs-on: ${{ matrix.target.os }} steps: - uses: actions/download-artifact@v4 with: { name: generated, path: gen } @@ -167,17 +174,20 @@ jobs: uses: actions/cache/restore@v4 with: path: engines - key: engines-darwin-arm64-${{ needs.generate.outputs.flags }}-${{ needs.generate.outputs.key }} - restore-keys: engines-darwin-arm64-${{ needs.generate.outputs.flags }}- - - name: Compile every language (macOS arm64) + key: engines-${{ matrix.target.platform }}-${{ needs.generate.outputs.flags }}-${{ needs.generate.outputs.key }} + restore-keys: engines-${{ matrix.target.platform }}-${{ needs.generate.outputs.flags }}- + - name: Compile every language (macOS ${{ matrix.target.arch }}) + env: + ARCH: ${{ matrix.target.arch }} run: | set -e for lang in $LANGUAGES; do if cmp -s "gen/$lang.id" "engines/$lang/ENGINE_ID"; then echo "$lang: cached, rules unchanged"; continue; fi mkdir -p "engines/$lang" - c++ -std=c++17 -O3 -w -arch arm64 -mmacosx-version-min=12.0 -I gen "gen/$lang.cpp" -o "engines/$lang/axiomcode-engine-$lang" + c++ -std=c++17 -O3 -w -arch "$ARCH" -mmacosx-version-min=12.0 -I gen "gen/$lang.cpp" -o "engines/$lang/axiomcode-engine-$lang" cp "gen/$lang.id" "engines/$lang/ENGINE_ID" done + file engines/java/axiomcode-engine-java otool -L engines/java/axiomcode-engine-java - name: Smoke — every binary starts on empty inputs run: | @@ -192,6 +202,6 @@ jobs: uses: actions/cache/save@v4 with: path: engines - key: engines-darwin-arm64-${{ needs.generate.outputs.flags }}-${{ needs.generate.outputs.key }} + key: engines-${{ matrix.target.platform }}-${{ needs.generate.outputs.flags }}-${{ needs.generate.outputs.key }} - uses: actions/upload-artifact@v4 - with: { name: engines-darwin-arm64, path: engines, if-no-files-found: error } + with: { name: 'engines-${{ matrix.target.platform }}', path: engines, if-no-files-found: error } diff --git a/.github/workflows/ci.yml b/.github/workflows/ci.yml index 138a3feed..5623fa166 100644 --- a/.github/workflows/ci.yml +++ b/.github/workflows/ci.yml @@ -18,7 +18,7 @@ # changed. The `CI` job reports either way. # # dev is the default branch: every pull request lands there and gets build, hygiene -# and the five suites. The four-platform engine build is the slow part and no test +# and the five suites. The every-platform engine build is the slow part and no test # uses its output, so it runs on the way INTO main (a promotion pull request, a push # to main) and in the nightly, not on every change to dev. # ───────────────────────────────────────────────────────────────────────────── diff --git a/.github/workflows/nightly.yml b/.github/workflows/nightly.yml index f7120c662..4a089ff80 100644 --- a/.github/workflows/nightly.yml +++ b/.github/workflows/nightly.yml @@ -6,13 +6,13 @@ # `npm i @axiomcode/code-graph@nightly` installs dev as of that night. Pull request # runs test each change on its own; this is the only # full check of dev's head as it actually is — after several merges, after direct -# pushes and sync-dev's merges from main, with the four-platform build and the +# pushes and sync-dev's merges from main, with the every-platform engine build and the # install-and-run check that dev's pull requests skip, and against whatever versions # of the dependencies a fresh install resolves today (no lock file is committed, so # those move without a commit here). # # 1. CI with fresh=true: a clean checkout, no restored engine cache, every engine -# compiled from the rules, the five suites, and all four platforms' engines. +# compiled from the rules, the five suites, and every platform's engines. # 2. End to end: pack @axiomcode/code-graph and the linux-x64 engine package exactly # as publish-npm.yml would, install them into an empty project with no Soufflé, # and run axiomcode on a test project (.github/scripts/e2e-install.sh). diff --git a/package.json b/package.json index 8049fd963..aee53b533 100644 --- a/package.json +++ b/package.json @@ -1,7 +1,7 @@ { "name": "@axiomcode/code-graph", "version": "0.1.0", - "description": "AxiomCode code graph: parser (IR extraction) + type-directed reasoning engine + language-neutral graph.sqlite output. bin/axiomcode runs the whole pipeline.", + "description": "AxiomCode Graph: a resolved call graph of your codebase grounded in formal methods, so you and your coding agents can see who calls what, what a change breaks, and which tests it reaches.", "repository": { "type": "git", "url": "git+https://github.com/AxiomCodeAI/axiomcodegraph.git" @@ -31,6 +31,7 @@ "license": "FSL-1.1-Apache-2.0", "optionalDependencies": { "@axiomcode/engine-darwin-arm64": "0.1.0", + "@axiomcode/engine-darwin-x64": "0.1.0", "@axiomcode/engine-linux-x64": "0.1.0", "@axiomcode/engine-linux-arm64": "0.1.0", "@axiomcode/engine-win32-x64": "0.1.0" diff --git a/packaging/assemble-engine-package.sh b/packaging/assemble-engine-package.sh index d6a90bac6..df1c20787 100755 --- a/packaging/assemble-engine-package.sh +++ b/packaging/assemble-engine-package.sh @@ -12,14 +12,22 @@ HERE="$(cd "$(dirname "$0")" && pwd)" rm -rf "$out"; mkdir -p "$out" cp -R "$src"/. "$out/" langs="$(ls -d "$out"/*/ | xargs -n1 basename | tr '\n' ' ')" +case "$platform" in + darwin-arm64) label="macOS (Apple Silicon)";; darwin-x64) label="macOS (Intel)";; + linux-x64) label="Linux x64";; linux-arm64) label="Linux arm64";; win32-x64) label="Windows x64";; + *) label="$os $cpu";; +esac sed -e "s|@@SCOPE@@|$ENGINE_PACKAGE_SCOPE|g" -e "s|@@PLATFORM@@|$platform|g" -e "s|@@VERSION@@|$version|g" \ - -e "s|@@OS@@|$os|g" -e "s|@@CPU@@|$cpu|g" -e "s|@@LANGS@@|${langs% }|g" \ + -e "s|@@OS@@|$os|g" -e "s|@@CPU@@|$cpu|g" -e "s|@@LANGS@@|${langs% }|g" -e "s|@@LABEL@@|$label|g" \ "$HERE/engine-package.json" > "$out/package.json" cp "$HERE/../LICENSE.md" "$out/LICENSE.md" { echo "# $ENGINE_PACKAGE_SCOPE/engine-$platform"; echo - echo "Prebuilt AxiomCode code-graph engines for $os/$cpu: ${langs% }. Installed automatically as an" - echo "optional dependency of the code-graph package on a matching machine; not meant to be used directly." - echo; for l in $langs; do echo "- $l: rules id \`$(cat "$out/$l/ENGINE_ID")\`"; done + echo "The $label engine for AxiomCode Graph ([$ENGINE_PACKAGE_SCOPE/code-graph](https://www.npmjs.com/package/$ENGINE_PACKAGE_SCOPE/code-graph))," + echo "a resolved call graph of your codebase grounded in formal methods."; echo + echo "Installed automatically with \`$ENGINE_PACKAGE_SCOPE/code-graph\` on $label; you don't need to install it yourself." + echo; echo "Languages: ${langs% }." + echo; echo "Rules each engine was built from:"; echo + for l in $langs; do echo "- $l: \`$(cat "$out/$l/ENGINE_ID")\`"; done } > "$out/README.md" chmod +x "$out"/*/axiomcode-engine-* 2>/dev/null || true echo "assembled $out: $(ls "$out" | tr '\n' ' ')" diff --git a/packaging/engine-package.json b/packaging/engine-package.json index be89a8f55..b8fc3b53d 100644 --- a/packaging/engine-package.json +++ b/packaging/engine-package.json @@ -1,7 +1,7 @@ { "name": "@@SCOPE@@/engine-@@PLATFORM@@", "version": "@@VERSION@@", - "description": "AxiomCode code-graph engines (@@LANGS@@) compiled for @@OS@@/@@CPU@@. Installed as an optional dependency of the code-graph package; npm selects this package by os/cpu.", + "description": "The @@LABEL@@ engine for AxiomCode Graph (@axiomcode/code-graph), a resolved call graph of your codebase grounded in formal methods.", "license": "FSL-1.1-Apache-2.0", "os": ["@@OS@@"], "cpu": ["@@CPU@@"],