From 0491a17185608e58c2c8a93671663aa036b74712 Mon Sep 17 00:00:00 2001 From: swapnil <78632212+swapnilpaliwal-sd@users.noreply.github.com> Date: Thu, 24 Sep 2026 22:48:27 -0700 Subject: [PATCH 1/2] build: ship an Intel macOS engine, @axiomcode/engine-darwin-x64 macOS shipped for Apple Silicon only, so on an Intel Mac npm installed no engine and the driver fell back to a local compile that needs Souffle and a C++ toolchain. build-engines' macOS job is now a matrix: darwin-arm64 on macos-15 and darwin-x64 on macos-15-intel, each on its own architecture so the smoke step runs the binary natively. package.json pins the new package, and publish-npm already requires every pinned platform before a real publish. run-souffle.sh already maps Darwin/x86_64 to darwin-x64. Also records in protect-main.sh the ruleset settings applied by hand while merging the release PR. --- .github/RELEASING.md | 2 +- .github/scripts/protect-main.sh | 1 + .github/workflows/build-engines.yml | 30 +++++++++++++++++++---------- .github/workflows/ci.yml | 2 +- .github/workflows/nightly.yml | 4 ++-- package.json | 1 + 6 files changed, 26 insertions(+), 14 deletions(-) diff --git a/.github/RELEASING.md b/.github/RELEASING.md index 7918b8d01..f3fa783b6 100644 --- a/.github/RELEASING.md +++ b/.github/RELEASING.md @@ -49,7 +49,7 @@ the commands to resolve it by hand. ## Nightly `nightly.yml` is dev's status (the "nightly" badge in the README). Every night it builds `dev` -from scratch: no cached engines, the five suites, all four platforms' engines, then +from scratch: no cached engines, the five suites, every platform's engines, then `e2e-install.sh` packs the npm tarballs, installs them into an empty project without Soufflé and runs `axiomcode` in four languages, and `npm publish --dry-run` checks each package. diff --git a/.github/scripts/protect-main.sh b/.github/scripts/protect-main.sh index 428529ade..6a7fa16e8 100755 --- a/.github/scripts/protect-main.sh +++ b/.github/scripts/protect-main.sh @@ -49,6 +49,7 @@ payload="$(cat <<'JSON' "dismiss_stale_reviews_on_push": false, "require_code_owner_review": false, "require_last_push_approval": false, + "require_extra_approval_for_unattributed_changes": false, "required_review_thread_resolution": true, "allowed_merge_methods": ["squash", "rebase"] } diff --git a/.github/workflows/build-engines.yml b/.github/workflows/build-engines.yml index d182aadef..167fbf1f1 100644 --- a/.github/workflows/build-engines.yml +++ b/.github/workflows/build-engines.yml @@ -10,9 +10,9 @@ # C++ runtime. Same flags as the local compile (no OpenMP/zlib/sqlite), portable targets. # # Artifacts: engines-/ holding /axiomcode-engine-[.exe] + /ENGINE_ID -# Platforms are named the npm way (process.platform-process.arch): darwin-arm64, linux-x64, -# linux-arm64, win32-x64, each on a standard GitHub-hosted runner (free for a public -# repository; darwin-arm64 is the Apple Silicon macos-15 image). +# Platforms are named the npm way (process.platform-process.arch): darwin-arm64, darwin-x64, +# linux-x64, linux-arm64, win32-x64, each on a standard GitHub-hosted runner (free for a +# public repository; macOS builds on macos-15 for Apple Silicon and macos-15-intel for Intel). # ───────────────────────────────────────────────────────────────────────────── name: build-engines @@ -157,7 +157,14 @@ jobs: build-macos: needs: generate - runs-on: macos-15 + strategy: + fail-fast: false + matrix: + target: + # each on its own architecture's runner, so the smoke step runs the binary natively + - { os: macos-15, arch: arm64, platform: darwin-arm64 } + - { os: macos-15-intel, arch: x86_64, platform: darwin-x64 } + runs-on: ${{ matrix.target.os }} steps: - uses: actions/download-artifact@v4 with: { name: generated, path: gen } @@ -167,17 +174,20 @@ jobs: uses: actions/cache/restore@v4 with: path: engines - key: engines-darwin-arm64-${{ needs.generate.outputs.flags }}-${{ needs.generate.outputs.key }} - restore-keys: engines-darwin-arm64-${{ needs.generate.outputs.flags }}- - - name: Compile every language (macOS arm64) + key: engines-${{ matrix.target.platform }}-${{ needs.generate.outputs.flags }}-${{ needs.generate.outputs.key }} + restore-keys: engines-${{ matrix.target.platform }}-${{ needs.generate.outputs.flags }}- + - name: Compile every language (macOS ${{ matrix.target.arch }}) + env: + ARCH: ${{ matrix.target.arch }} run: | set -e for lang in $LANGUAGES; do if cmp -s "gen/$lang.id" "engines/$lang/ENGINE_ID"; then echo "$lang: cached, rules unchanged"; continue; fi mkdir -p "engines/$lang" - c++ -std=c++17 -O3 -w -arch arm64 -mmacosx-version-min=12.0 -I gen "gen/$lang.cpp" -o "engines/$lang/axiomcode-engine-$lang" + c++ -std=c++17 -O3 -w -arch "$ARCH" -mmacosx-version-min=12.0 -I gen "gen/$lang.cpp" -o "engines/$lang/axiomcode-engine-$lang" cp "gen/$lang.id" "engines/$lang/ENGINE_ID" done + file engines/java/axiomcode-engine-java otool -L engines/java/axiomcode-engine-java - name: Smoke — every binary starts on empty inputs run: | @@ -192,6 +202,6 @@ jobs: uses: actions/cache/save@v4 with: path: engines - key: engines-darwin-arm64-${{ needs.generate.outputs.flags }}-${{ needs.generate.outputs.key }} + key: engines-${{ matrix.target.platform }}-${{ needs.generate.outputs.flags }}-${{ needs.generate.outputs.key }} - uses: actions/upload-artifact@v4 - with: { name: engines-darwin-arm64, path: engines, if-no-files-found: error } + with: { name: 'engines-${{ matrix.target.platform }}', path: engines, if-no-files-found: error } diff --git a/.github/workflows/ci.yml b/.github/workflows/ci.yml index 138a3feed..5623fa166 100644 --- a/.github/workflows/ci.yml +++ b/.github/workflows/ci.yml @@ -18,7 +18,7 @@ # changed. The `CI` job reports either way. # # dev is the default branch: every pull request lands there and gets build, hygiene -# and the five suites. The four-platform engine build is the slow part and no test +# and the five suites. The every-platform engine build is the slow part and no test # uses its output, so it runs on the way INTO main (a promotion pull request, a push # to main) and in the nightly, not on every change to dev. # ───────────────────────────────────────────────────────────────────────────── diff --git a/.github/workflows/nightly.yml b/.github/workflows/nightly.yml index f7120c662..4a089ff80 100644 --- a/.github/workflows/nightly.yml +++ b/.github/workflows/nightly.yml @@ -6,13 +6,13 @@ # `npm i @axiomcode/code-graph@nightly` installs dev as of that night. Pull request # runs test each change on its own; this is the only # full check of dev's head as it actually is — after several merges, after direct -# pushes and sync-dev's merges from main, with the four-platform build and the +# pushes and sync-dev's merges from main, with the every-platform engine build and the # install-and-run check that dev's pull requests skip, and against whatever versions # of the dependencies a fresh install resolves today (no lock file is committed, so # those move without a commit here). # # 1. CI with fresh=true: a clean checkout, no restored engine cache, every engine -# compiled from the rules, the five suites, and all four platforms' engines. +# compiled from the rules, the five suites, and every platform's engines. # 2. End to end: pack @axiomcode/code-graph and the linux-x64 engine package exactly # as publish-npm.yml would, install them into an empty project with no Soufflé, # and run axiomcode on a test project (.github/scripts/e2e-install.sh). diff --git a/package.json b/package.json index 8049fd963..f3564ab0c 100644 --- a/package.json +++ b/package.json @@ -31,6 +31,7 @@ "license": "FSL-1.1-Apache-2.0", "optionalDependencies": { "@axiomcode/engine-darwin-arm64": "0.1.0", + "@axiomcode/engine-darwin-x64": "0.1.0", "@axiomcode/engine-linux-x64": "0.1.0", "@axiomcode/engine-linux-arm64": "0.1.0", "@axiomcode/engine-win32-x64": "0.1.0" From 183a32b9f6416915e69d947672bf117345dc765b Mon Sep 17 00:00:00 2001 From: swapnil <78632212+swapnilpaliwal-sd@users.noreply.github.com> Date: Thu, 24 Sep 2026 23:05:10 -0700 Subject: [PATCH 2/2] package: descriptions that say what AxiomCode Graph is The npm one-liner read like an internal note ("parser (IR extraction) + type-directed reasoning engine ..."). It now leads with the product name and says what it does, as esbuild, Biome and Turborepo do. Each engine package names its platform in words, e.g. "The macOS (Intel) engine for AxiomCode Graph (@axiomcode/code-graph)", and its README links back to the main package and says it installs automatically. --- package.json | 2 +- packaging/assemble-engine-package.sh | 16 ++++++++++++---- packaging/engine-package.json | 2 +- 3 files changed, 14 insertions(+), 6 deletions(-) diff --git a/package.json b/package.json index f3564ab0c..aee53b533 100644 --- a/package.json +++ b/package.json @@ -1,7 +1,7 @@ { "name": "@axiomcode/code-graph", "version": "0.1.0", - "description": "AxiomCode code graph: parser (IR extraction) + type-directed reasoning engine + language-neutral graph.sqlite output. bin/axiomcode runs the whole pipeline.", + "description": "AxiomCode Graph: a resolved call graph of your codebase grounded in formal methods, so you and your coding agents can see who calls what, what a change breaks, and which tests it reaches.", "repository": { "type": "git", "url": "git+https://github.com/AxiomCodeAI/axiomcodegraph.git" diff --git a/packaging/assemble-engine-package.sh b/packaging/assemble-engine-package.sh index d6a90bac6..df1c20787 100755 --- a/packaging/assemble-engine-package.sh +++ b/packaging/assemble-engine-package.sh @@ -12,14 +12,22 @@ HERE="$(cd "$(dirname "$0")" && pwd)" rm -rf "$out"; mkdir -p "$out" cp -R "$src"/. "$out/" langs="$(ls -d "$out"/*/ | xargs -n1 basename | tr '\n' ' ')" +case "$platform" in + darwin-arm64) label="macOS (Apple Silicon)";; darwin-x64) label="macOS (Intel)";; + linux-x64) label="Linux x64";; linux-arm64) label="Linux arm64";; win32-x64) label="Windows x64";; + *) label="$os $cpu";; +esac sed -e "s|@@SCOPE@@|$ENGINE_PACKAGE_SCOPE|g" -e "s|@@PLATFORM@@|$platform|g" -e "s|@@VERSION@@|$version|g" \ - -e "s|@@OS@@|$os|g" -e "s|@@CPU@@|$cpu|g" -e "s|@@LANGS@@|${langs% }|g" \ + -e "s|@@OS@@|$os|g" -e "s|@@CPU@@|$cpu|g" -e "s|@@LANGS@@|${langs% }|g" -e "s|@@LABEL@@|$label|g" \ "$HERE/engine-package.json" > "$out/package.json" cp "$HERE/../LICENSE.md" "$out/LICENSE.md" { echo "# $ENGINE_PACKAGE_SCOPE/engine-$platform"; echo - echo "Prebuilt AxiomCode code-graph engines for $os/$cpu: ${langs% }. Installed automatically as an" - echo "optional dependency of the code-graph package on a matching machine; not meant to be used directly." - echo; for l in $langs; do echo "- $l: rules id \`$(cat "$out/$l/ENGINE_ID")\`"; done + echo "The $label engine for AxiomCode Graph ([$ENGINE_PACKAGE_SCOPE/code-graph](https://www.npmjs.com/package/$ENGINE_PACKAGE_SCOPE/code-graph))," + echo "a resolved call graph of your codebase grounded in formal methods."; echo + echo "Installed automatically with \`$ENGINE_PACKAGE_SCOPE/code-graph\` on $label; you don't need to install it yourself." + echo; echo "Languages: ${langs% }." + echo; echo "Rules each engine was built from:"; echo + for l in $langs; do echo "- $l: \`$(cat "$out/$l/ENGINE_ID")\`"; done } > "$out/README.md" chmod +x "$out"/*/axiomcode-engine-* 2>/dev/null || true echo "assembled $out: $(ls "$out" | tr '\n' ' ')" diff --git a/packaging/engine-package.json b/packaging/engine-package.json index be89a8f55..b8fc3b53d 100644 --- a/packaging/engine-package.json +++ b/packaging/engine-package.json @@ -1,7 +1,7 @@ { "name": "@@SCOPE@@/engine-@@PLATFORM@@", "version": "@@VERSION@@", - "description": "AxiomCode code-graph engines (@@LANGS@@) compiled for @@OS@@/@@CPU@@. Installed as an optional dependency of the code-graph package; npm selects this package by os/cpu.", + "description": "The @@LABEL@@ engine for AxiomCode Graph (@axiomcode/code-graph), a resolved call graph of your codebase grounded in formal methods.", "license": "FSL-1.1-Apache-2.0", "os": ["@@OS@@"], "cpu": ["@@CPU@@"],