Repository navigation
build: engines ship on npm as @axiomcode/engine-<os>-<cpu>; publish is a dispatch-only workflow (dry run by default) - #478
Conversation
…s a dispatch-only workflow (dry run by default) Running the engine needed Soufflé and a C++ toolchain. The compiled engine is one self-contained executable per language and platform, so CI builds them (build-engines.yml: generate the portable C++ once on Ubuntu with the pinned Soufflé, compile on linux-x64, linux-arm64, win32-x64 and a self-hosted darwin-arm64, smoke-run each) and publish-npm.yml assembles one package per platform — @axiomcode/engine-<os>-<cpu>, every language's engine under <lang>/ with its ENGINE_ID — and publishes them. The workflow runs only on demand (version, dry_run=true by default, macos) or on a v* tag; a dry run packs and prints without uploading. This package lists the four as optionalDependencies, so `npm install` fetches exactly the one npm's os/cpu filter matches; nothing is committed to git. run-souffle.sh resolves the engine in order: the installed package when its ENGINE_ID equals the checkout's rule hash (edited rules never run a stale binary), else a local compile when souffle is present, else an error naming both ways out. The program the id hashes is a pure function of the repository (relative includes, inputs derived from the maps), exposed as --print-engine-id and --emit-program; the pinned Soufflé version lives in graph/pipeline/engine.conf. Guards, without souffle or network, as Java-suite preflights: engine-id-test.sh (same id from two paths; changed by a rule, a map, the manifest, the pin) and engine-package-test.sh (a hand-made engine package: used when its id matches, refused with both ways out when not, absence explained).
f1827c7 to
febf8b4
Compare
…e — LANGUAGES gains javascript in the generate, Linux, Windows and smoke steps, and in the engine-id preflight Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
|
Merged into |
…he committed-binaries workflow, the release fetch test and the binaries .gitattributes are superseded by build-engines.yml, publish-npm.yml and engine-package-test.sh
|
Reopened: the engine build and npm publish stays its own open pull request until it merges to main. The same commits were also merged into #418's branch; whichever merges first carries the work, the other rebases. |
|
Not mergeable as it stands: |
|
Cross-checking this branch against a real install, on GCP rather than Actions. Results and two gaps. Verified working. Built all engines from this branch for five platforms and ran them end to end. The engine id is path independent (same tree at two paths gives the same id), the generated C++ carries no build-machine paths, and every platform's ENGINE_ID matches the generate step. Smoke counts agree across three operating systems and two architectures: java 22, typescript 45, python 85, javascript 34 relations. Gap 1: darwin-x64 is not built. The matrix covers darwin-arm64, linux-x64, linux-arm64 and win32-x64, so an Intel Mac gets no engine and falls back to needing souffle and a compiler. A missing optional dependency is not an install error, so it fails silently. This needs no Intel hardware and no extra runner: the Apple Silicon runner cross compiles with Gap 2: the build depends on Actions minutes. With none available this branch cannot produce a binary at all, which blocks a release for a reason unrelated to the tool. Worth a documented path that does not need runners. The shape of this design makes that cheap, since Notes from doing it:
#887 is required before this ships. It fixes four defects in front of the engine: the built parser is not in the tarball, there is no bin entry, the bin root walk fails through the node_modules/.bin symlink, and no runtime dependencies are declared. With those in place the engine resolves correctly from the package and the run still fails, because the parser half is not installable. On a clean VM with both changes, all four languages complete against real projects with nothing compiled. |
# Conflicts: # graph/pipeline/run-souffle.sh
|
Resolved the conflict on this branch locally and did not merge, because the merge result 1. The conflict hid a real drop.
2. With that resolved and built, the suite regresses. On the merge result the bundle
Control: current main, same shell, same Also worth noting for validation: all four I have not pushed anything to this branch. The conflict resolution above is the part I am |
|
Correcting my comment above and clearing this for merge. Pushed I was wrong about the bundle. I reported the bundle stage failing for every language The engine-id and engine-package failures were real, and are fixed here. Both There is no Verified with souffle present, which is the case that matters until the packages are
The cache lands I also carried Understood that the |
Both engine sandboxes rebuilt PATH from a whitelist of symlinked tools. That cannot work on macOS: /usr/bin/shasum is a perl script and the system perl dispatches on the script's canonical path, so a symlink to it, or a copy of it, is refused with 'perl version 5.30.3 cannot run <path>'. With no sha256sum on a machine without coreutils, the sandbox had no digest tool at all: engine-id reported 8 failures and engine-package 4, none of them about the engine. Dropping the one directory that holds souffle hides it and leaves every other tool where the system expects to find it. The sandbox asserts souffle is really gone.
|
Blocker for this branch, filed as #895 with the fix in #897 against main. The engine id is a function of the shell locale as well as the rules. The Measured with engines built from this branch, installed as a real package:
End to end on Windows with the correct engine installed, java and python fail with CI runs under a C-ish locale and users commonly do not, so published engines would be refused for java and python on a large share of machines, with an error naming the rules rather than the locale. #897 pins the collation in the executor; Separately,
That one is a parser dependency upgrade and needs the suites run against the newer grammars, so it is not folded into either PR. |
…478) (#903) Reverts f6ba1c2. The engine binaries work is not ready to ship, so it goes back to a pull request and #454 reopens with it. Not a plain revert, because two changes landed on top of it and both have to keep working: - #897 pinned the collation inside write_program, which #478 introduced. Reverting removes that function and would take the guard with it, and the restored executor has the same defect: its #include lines come from unguarded globs, so the cache key follows the user's locale. The guard is re-applied to the restored program generation, and engine-id-locale-test.sh now accepts either shape of the executor so it keeps measuring rather than failing for the wrong reason. Its --emit-program checks skip here, since that flag belongs to #478, and they report the skip rather than passing silently. - #887 added bin, files and dependencies, which are independent of the engine work and stay. optionalDependencies goes with the feature: nothing resolves a packaged engine any more, so those entries would name packages the executor never looks for. What comes back: the executor compiles with a local souffle and caches the binary, exactly as before #478. engine.conf, packaging/ and the two engine tests go with it.
Graphify was labelled "Slug-graph" in the figure alt text and in the comparison tables — the same label the two SVGs carried. Every tool now reads the way the other figures read it: AxiomCode, GitNexus, CodeGraph, Graphify, Code-Review-Graph. Package and marketplace ids are untouched: axiomcodegraph, @axiomcode/code-graph and @colbymchenry/codegraph are ids, not names. The requirements line led with Soufflé and cited #478 as the reason, but #478 is merged — the machinery it added is a dispatch-only publish workflow that has not been run for real, so a reader was pointed at finished work as though it were the blocker. It now says the intended thing first: npm install fetches @axiomcode/engine-<os>-<cpu> for the platform and nothing else is needed to run. Soufflé and a C++ compiler are the temporary fallback while those packages are absent from npm, which they still are. The test-selection alt text also still described tests-selected-per-bug; that panel reports F1 now.
#1258 dropped both when it restructured the header, leaving Build, License and Node. They are status, not decoration: engines-not-yet-published is the one line that tells a reader why the Requirements paragraph still asks for Soufflé, and nightly-not-yet-enabled says the scheduled run is not there rather than passing. Restored as they were, static shields rather than workflow badges — which is deliberate, per the commit that made the nightly badge render by not asking for a run that has not happened. Worth a look before release: the engines badge points at #478, which is merged. The machinery landed; the publish has not run. #418 is where the CI arrives, and is the honest target for both.
Fixes #454. Supersedes #455 (binaries committed to the repository), engines ship on npm instead; nothing is committed.
How it works
build-engines.yml(reusable + dispatchable):souffle -gonce on Ubuntu with the pinned Soufflé → portable C++ per language → compiled onlinux-x64,linux-arm64,win32-x64(MSVC) and a self-hosteddarwin-arm64, smoke-run on empty inputs, uploaded asengines-<platform>artifacts. Platform names are npm's (process.platform-process.arch).publish-npm.yml, runs only on demand (version,dry_run= true by default,macos) or on av*tag. Assembles@axiomcode/engine-<os>-<cpu>per platform (every language's engine under<lang>/with itsENGINE_ID, license, readme,os/cpufields) and runsnpm publish --access public, with--dry-runit packs and prints without uploading, so the pipeline can be exercised before any token exists.package.jsonlists the four asoptionalDependencies: npm installs exactly the one whoseos/cpumatch the machine, skips the rest. Verifiednpm installsucceeds today with them unpublished (optional).run-souffle.shresolves the engine: (1)node_modules/@axiomcode/engine-<platform>/<lang>/if itsENGINE_IDequals the checkout's rule hash; (2) local compile whensouffleis present; else an error naming both ways out. The program the id hashes is a pure function of the repository (--print-engine-id,--emit-program); the Soufflé pin isgraph/pipeline/engine.conf.To publish (one-time setup, then one the CLI-argument library)
axiomcodeorg; a granular token with publish on@axiomcode/*→ repo secretNPM_TOKEN.gh workflow run publish-npm.yml -f version=0.1.0 -f dry_run=true -f macos=false→ inspect; thendry_run=false(orgit tag v0.1.0 && git push --tags).package.json.Verified
npm install).engine-id-test.sh(same id from two paths; changed by rule/map/manifest/pin) andengine-package-test.sh(a hand-made engine package is used when its id matches, refused with both ways out when not, absence explained).bin/axiomcode <mixed Java+TS+Python tree> <out> --library …→ three graphs, Java library targets named.npm publish --dry-runlocally: correct tarball contents.