From 49d32f9eb34a7744035d07accaf0d20725660799 Mon Sep 17 00:00:00 2001 From: swapnil <78632212+swapnilpaliwal-sd@users.noreply.github.com> Date: Thu, 17 Sep 2026 22:26:18 -0700 Subject: [PATCH] chore: take the CI workflows out of the tree for now Removes .github/workflows/build-engines.yml and publish-npm.yml. The workflows go back in later, together with the rest of CI. Only the workflow files. Everything else that makes engines shippable stays: the engine resolution in run-souffle.sh, graph/pipeline/engine.conf, packaging/ and the optionalDependencies entries are untouched, so a checkout still resolves a packaged engine and still falls back to a local compile. Two places named the workflows and would have dangled: the README told the reader to publish from Actions, and a comment in the executor named publish-npm.yml as the thing that produces the package. Both now describe what is actually in the tree. --- .github/workflows/build-engines.yml | 143 ---------------------------- .github/workflows/publish-npm.yml | 76 --------------- README.md | 2 +- graph/pipeline/run-souffle.sh | 2 +- 4 files changed, 2 insertions(+), 221 deletions(-) delete mode 100644 .github/workflows/build-engines.yml delete mode 100644 .github/workflows/publish-npm.yml diff --git a/.github/workflows/build-engines.yml b/.github/workflows/build-engines.yml deleted file mode 100644 index 326e1cd28..000000000 --- a/.github/workflows/build-engines.yml +++ /dev/null @@ -1,143 +0,0 @@ -# ───────────────────────────────────────────────────────────────────────────── -# Build the engine binaries — every language, every platform — as artifacts. -# -# Reusable (workflow_call) so publish-npm.yml can build then publish in one run, and -# dispatchable on its own to check that the rules still compile everywhere without -# publishing anything. Soufflé is a BUILD-time dependency only: `souffle -g` turns each -# language's rules into portable C++ once on Ubuntu (the pinned .deb), and every platform -# compiles that C++ with its own C++17 compiler against Soufflé's headers. The result is -# one self-contained executable per language per platform, linked against nothing but the -# C++ runtime. Same flags as the local compile (no OpenMP/zlib/sqlite), portable targets. -# -# Artifacts: engines-/ holding /axiomcode-engine-[.exe] + /ENGINE_ID -# Platforms are named the npm way (process.platform-process.arch): darwin-arm64, linux-x64, -# linux-arm64, win32-x64. macOS builds on a SELF-HOSTED Apple Silicon runner (hosted macOS -# minutes bill at 10x); pass macos=false to skip it while no runner is registered. -# ───────────────────────────────────────────────────────────────────────────── -name: build-engines - -on: - workflow_call: - inputs: - macos: - description: build the darwin-arm64 engines on the self-hosted macOS runner - type: boolean - default: true - workflow_dispatch: - inputs: - macos: - description: build the darwin-arm64 engines on the self-hosted macOS runner - type: boolean - default: false - -env: - LANGUAGES: java typescript python javascript - -jobs: - generate: - runs-on: ubuntu-24.04 - steps: - - uses: actions/checkout@v4 - - name: Install the pinned Soufflé - run: | - . graph/pipeline/engine.conf - deb="x86_64-ubuntu-2404-souffle-${SOUFFLE_VERSION}-Linux.deb" - curl -fsSL -o "/tmp/$deb" "https://github.com/souffle-lang/souffle/releases/download/${SOUFFLE_VERSION}/$deb" - sudo apt-get update -qq && sudo apt-get install -y -qq "/tmp/$deb" - souffle --version | head -2 - test -f /usr/include/souffle/CompiledSouffle.h - - name: Generate portable C++ per language - run: | - set -e - mkdir -p gen - for lang in $LANGUAGES; do - id="$(bash graph/pipeline/run-souffle.sh --language "$lang" --print-engine-id)" - echo "$lang: $id"; printf '%s' "$id" > "gen/$lang.id" - bash graph/pipeline/run-souffle.sh --language "$lang" --emit-program "gen/$lang.dl" - souffle -I graph -g "gen/$lang.cpp" "gen/$lang.dl" 2> "gen/$lang.gen.log" || { cat "gen/$lang.gen.log"; exit 1; } - awk '/No rules\/facts defined/{skip=2;next} skip>0{skip--;next} {print}' "gen/$lang.gen.log" - done - cp -r /usr/include/souffle gen/souffle - - uses: actions/upload-artifact@v4 - with: { name: generated, path: gen, retention-days: 3, if-no-files-found: error } - - build: - needs: generate - strategy: - fail-fast: false - matrix: - target: - - { os: ubuntu-24.04, platform: linux-x64 } - - { os: ubuntu-24.04-arm, platform: linux-arm64 } - - { os: windows-2025, platform: win32-x64 } - runs-on: ${{ matrix.target.os }} - steps: - - uses: actions/download-artifact@v4 - with: { name: generated, path: gen } - - name: Compile every language (Linux) - if: startsWith(matrix.target.platform, 'linux') - run: | - set -e - for lang in $LANGUAGES; do - mkdir -p "engines/$lang" - c++ -std=c++17 -O3 -w -static-libstdc++ -static-libgcc -I gen "gen/$lang.cpp" -o "engines/$lang/axiomcode-engine-$lang" - cp "gen/$lang.id" "engines/$lang/ENGINE_ID" - done - ls -la engines/*; ldd engines/java/axiomcode-engine-java || true - - uses: ilammy/msvc-dev-cmd@v1 - if: startsWith(matrix.target.platform, 'win32') - with: { arch: x64 } - - name: Compile every language (Windows, MSVC) - if: startsWith(matrix.target.platform, 'win32') - shell: cmd - run: | - for %%L in (java typescript python javascript) do ( - mkdir engines\%%L - cl /nologo /std:c++17 /O2 /EHsc /bigobj /w /permissive- /Zc:__cplusplus /D_CRT_SECURE_NO_WARNINGS /DNOMINMAX /DUSE_CUSTOM_GETOPTLONG /I gen gen\%%L.cpp /Fe:engines\%%L\axiomcode-engine-%%L.exe - if errorlevel 1 exit /b 1 - copy gen\%%L.id engines\%%L\ENGINE_ID - ) - dir /s engines - - name: Smoke — every binary starts on empty inputs - shell: bash - run: | - set -e - for lang in $LANGUAGES; do - bin="$(ls engines/$lang/axiomcode-engine-$lang* )"; chmod +x "$bin" 2>/dev/null || true - mkdir -p "facts-$lang" "out-$lang" - sed -n 's/^\.input \([A-Za-z0-9_]*\)(.*/\1/p' "gen/$lang.dl" | while read -r r; do : > "facts-$lang/$r.facts"; done - "./$bin" -F "facts-$lang" -D "out-$lang" - echo "$lang: ok ($(ls out-$lang | wc -l) relations written)" - done - - uses: actions/upload-artifact@v4 - with: - name: engines-${{ matrix.target.platform }} - path: engines - if-no-files-found: error - - build-macos: - needs: generate - if: inputs.macos - runs-on: [self-hosted, macOS, ARM64] - steps: - - uses: actions/download-artifact@v4 - with: { name: generated, path: gen } - - name: Compile every language (macOS arm64) - run: | - set -e - for lang in $LANGUAGES; do - mkdir -p "engines/$lang" - c++ -std=c++17 -O3 -w -arch arm64 -mmacosx-version-min=12.0 -I gen "gen/$lang.cpp" -o "engines/$lang/axiomcode-engine-$lang" - cp "gen/$lang.id" "engines/$lang/ENGINE_ID" - done - otool -L engines/java/axiomcode-engine-java - - name: Smoke — every binary starts on empty inputs - run: | - set -e - for lang in $LANGUAGES; do - mkdir -p "facts-$lang" "out-$lang" - sed -n 's/^\.input \([A-Za-z0-9_]*\)(.*/\1/p' "gen/$lang.dl" | while read -r r; do : > "facts-$lang/$r.facts"; done - "./engines/$lang/axiomcode-engine-$lang" -F "facts-$lang" -D "out-$lang" - done - - uses: actions/upload-artifact@v4 - with: { name: engines-darwin-arm64, path: engines, if-no-files-found: error } diff --git a/.github/workflows/publish-npm.yml b/.github/workflows/publish-npm.yml deleted file mode 100644 index a6255048e..000000000 --- a/.github/workflows/publish-npm.yml +++ /dev/null @@ -1,76 +0,0 @@ -# ───────────────────────────────────────────────────────────────────────────── -# Publish the engine packages to npm: @axiomcode/engine--, one per platform, each -# holding every language's engine for that platform. This package lists them as optional -# dependencies, so `npm install` fetches exactly the one for the machine — no Soufflé, no -# compiler, no download of ours. -# -# Runs ONLY when asked: -# • manually (Actions → publish-npm → Run workflow): version, dry_run (default TRUE — packs -# and prints exactly what would be published, uploads nothing), macos. -# • on a version tag `v1.2.3`: a real publish of that version. -# Needs the NPM_TOKEN secret (an npmjs automation token with publish rights on @axiomcode) -# for a real publish; a dry run needs nothing. -# ───────────────────────────────────────────────────────────────────────────── -name: publish-npm - -on: - workflow_dispatch: - inputs: - version: - description: version to publish (e.g. 0.1.0) - required: true - type: string - dry_run: - description: pack and print, publish nothing - type: boolean - default: true - macos: - description: include darwin-arm64 (needs the self-hosted macOS runner) - type: boolean - default: true - push: - tags: ['v*'] - -permissions: - contents: read - id-token: write - -jobs: - engines: - uses: ./.github/workflows/build-engines.yml - with: - macos: ${{ github.event_name == 'push' || inputs.macos }} - - publish: - needs: engines - runs-on: ubuntu-24.04 - steps: - - uses: actions/checkout@v4 - - uses: actions/setup-node@v4 - with: - node-version: '22' - registry-url: 'https://registry.npmjs.org' - - uses: actions/download-artifact@v4 - with: { pattern: engines-*, path: artifacts } - - name: Assemble one package per platform - run: | - set -e - if [ "${{ github.event_name }}" = push ]; then version="${GITHUB_REF_NAME#v}"; else version="${{ inputs.version }}"; fi - echo "version=$version" >> "$GITHUB_ENV" - for d in artifacts/engines-*; do - platform="${d#artifacts/engines-}" - bash packaging/assemble-engine-package.sh "$platform" "$version" "$d" "packages/engine-$platform" - cat "packages/engine-$platform/package.json" - done - - name: Publish (or dry-run) - env: - NODE_AUTH_TOKEN: ${{ secrets.NPM_TOKEN }} - DRY: ${{ github.event_name == 'workflow_dispatch' && inputs.dry_run }} - run: | - set -e - flag=""; [ "$DRY" = true ] && flag="--dry-run" - for p in packages/engine-*; do - echo "══ $p $flag" - ( cd "$p" && npm publish --access public $flag ) - done - [ "$DRY" = true ] && echo "DRY RUN — nothing was uploaded. Re-run with dry_run=false, or push tag v$version, to publish." || echo "published version $version" diff --git a/README.md b/README.md index 1028d42c2..c1cefdfc1 100644 --- a/README.md +++ b/README.md @@ -227,7 +227,7 @@ bin/axiomcode test # everything Each suite parses its fixture cases with the parser in this repository, solves them, guards that no call site was dropped, and diffs the normalised edges against a golden. `--keep` retains per-case work directories (`graph/test//.work//out/graph.sqlite` is a real bundle to poke at); `--bless` regenerates goldens; review the diff. Torture harnesses under `graph/test//torture/` score real projects against their oracles. -Editing rules requires [Soufflé](https://souffle-lang.github.io) 2.5 locally (`brew install souffle`; the pinned version is in `graph/pipeline/engine.conf`); the engine recompiles on the first solve after a rule change. Publishing engines: *Actions → publish-npm → Run workflow* (dry run by default) or push a `v*` tag. +Editing rules requires [Soufflé](https://souffle-lang.github.io) 2.5 locally (`brew install souffle`; the pinned version is in `graph/pipeline/engine.conf`); the engine recompiles on the first solve after a rule change. Publishing engines: the CI workflows are not in the tree yet, so the packages are assembled with `packaging/assemble-engine-package.sh` and published by hand for now. ## Known limits diff --git a/graph/pipeline/run-souffle.sh b/graph/pipeline/run-souffle.sh index 1221ed3a6..a04763c7a 100755 --- a/graph/pipeline/run-souffle.sh +++ b/graph/pipeline/run-souffle.sh @@ -8,7 +8,7 @@ # # NO SOUFFLÉ NEEDED TO RUN. The rules compile to one self-contained executable that is # project-independent; CI builds it for every platform and publishes it on npm as -# @axiomcode/engine-- (publish-npm.yml), which this package lists as an optional +# @axiomcode/engine--, which this package lists as an optional # dependency so `npm install` fetches exactly the one for the machine. The binary is # resolved in this order: # 1. node_modules/@axiomcode/engine-// — used only if its ENGINE_ID equals