Merge RC1 branch: security model, GUC configuration, and CI improvements #81
Workflow file for this run
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
| name: CI | |
| on: | |
| pull_request: | |
| types: [opened, synchronize, reopened, labeled] | |
| push: | |
| branches: [main] # Runs on main after merge | |
| schedule: | |
| - cron: '0 2 * * *' # Nightly at 2 AM UTC | |
| workflow_dispatch: | |
| inputs: | |
| pg_version: | |
| description: 'PostgreSQL version(s) to test' | |
| required: false | |
| default: '17' | |
| type: choice | |
| options: | |
| - '17' | |
| - '18' | |
| - '17, 18' | |
| env: | |
| CARGO_TERM_COLOR: always | |
| GITHUB_TOKEN: ${{ secrets.GH_PAT }} | |
| concurrency: | |
| group: ci-${{ github.event.pull_request.number || github.ref }} | |
| cancel-in-progress: true | |
| jobs: | |
| format: | |
| name: Format Check | |
| runs-on: ubuntu-latest | |
| steps: | |
| - uses: actions/checkout@v4 | |
| - name: Install Rust nightly | |
| run: | | |
| rustup toolchain install nightly --profile minimal --component rustfmt | |
| rustup default nightly | |
| - name: Check formatting | |
| run: cargo fmt --all -- --check | |
| prepare: | |
| name: Prepare Matrix | |
| runs-on: ubuntu-latest | |
| outputs: | |
| pg_versions: ${{ steps.set-matrix.outputs.pg_versions }} | |
| steps: | |
| - id: set-matrix | |
| run: | | |
| if [ "${{ github.event_name }}" = "workflow_dispatch" ]; then | |
| echo 'pg_versions=[${{ github.event.inputs.pg_version }}]' >> "$GITHUB_OUTPUT" | |
| elif [ "${{ github.event_name }}" = "pull_request" ]; then | |
| if [ "${{ contains(github.event.pull_request.labels.*.name, 'test-pg18') }}" = "true" ]; then | |
| echo 'pg_versions=[17, 18]' >> "$GITHUB_OUTPUT" | |
| else | |
| echo 'pg_versions=[17]' >> "$GITHUB_OUTPUT" | |
| fi | |
| else | |
| echo 'pg_versions=[17, 18]' >> "$GITHUB_OUTPUT" | |
| fi | |
| test: | |
| name: Clippy & Tests (PG${{ matrix.pg_version }}) | |
| runs-on: ubuntu-latest | |
| needs: [format, prepare] | |
| permissions: | |
| contents: read | |
| strategy: | |
| fail-fast: false | |
| matrix: | |
| pg_version: ${{ fromJson(needs.prepare.outputs.pg_versions) }} | |
| # PG18 failures are non-blocking while compatibility is being established | |
| continue-on-error: ${{ matrix.pg_version == 18 }} | |
| steps: | |
| - uses: actions/checkout@v4 | |
| - name: Install Rust nightly | |
| run: | | |
| rustup toolchain install nightly --profile minimal --component clippy | |
| rustup default nightly | |
| - name: Install system dependencies | |
| run: | | |
| sudo apt-get update | |
| sudo apt-get install -y \ | |
| pkg-config \ | |
| libssl-dev \ | |
| libclang-dev \ | |
| clang \ | |
| bison \ | |
| flex \ | |
| libreadline-dev \ | |
| zlib1g-dev \ | |
| libxml2-dev \ | |
| libxslt1-dev \ | |
| libicu-dev | |
| - name: Cache cargo registry | |
| uses: actions/cache@v4 | |
| with: | |
| path: | | |
| ~/.cargo/registry | |
| ~/.cargo/git | |
| ~/.pgrx | |
| target | |
| key: ${{ runner.os }}-cargo-pgrx-pg${{ matrix.pg_version }}-${{ hashFiles('**/Cargo.lock') }} | |
| restore-keys: | | |
| ${{ runner.os }}-cargo-pgrx-pg${{ matrix.pg_version }}- | |
| - name: Install cargo-pgrx | |
| run: cargo install cargo-pgrx --version 0.16.1 --locked | |
| - name: Initialize pgrx | |
| run: cargo pgrx init --pg${{ matrix.pg_version }} download | |
| - name: Configure git credentials for private repos | |
| run: | | |
| git config --global url."https://${{ secrets.GH_PAT }}@github.com/".insteadOf "https://github.com/" | |
| - name: Verify duroxide migrations match upstream | |
| run: | | |
| # Clone duroxide-pg-opt to verify our checked-in copies match upstream. | |
| # NOTE: The branch must match the duroxide-pg-opt ref in Cargo.toml. | |
| # Update this when switching to a tag or a different branch. | |
| git clone --depth=1 --branch pinodeca/initialization \ | |
| https://${{ secrets.GH_PAT }}@github.com/microsoft/duroxide-pg-opt.git | |
| ./scripts/verify-duroxide-migrations.sh | |
| - name: Run clippy | |
| run: cargo clippy --no-default-features --features pg${{ matrix.pg_version }} -- -D warnings | |
| - name: Run unit tests | |
| run: cargo pgrx test pg${{ matrix.pg_version }} | |
| - name: Run E2E tests (shared_preload_libraries enforcement) | |
| id: e2e_no_preload | |
| run: ./scripts/test-e2e-local.sh --clean --no-preload | |
| - name: Run E2E tests | |
| id: e2e_tests | |
| run: ./scripts/test-e2e-local.sh --clean --pg-version ${{ matrix.pg_version }} | |
| - name: Upload PostgreSQL logs on E2E failure | |
| if: failure() | |
| uses: actions/upload-artifact@v4 | |
| with: | |
| name: postgresql-logs-pg${{ matrix.pg_version }} | |
| path: | | |
| ~/.pgrx/${{ matrix.pg_version }}.log | |
| ~/.pgrx/data-${{ matrix.pg_version }}/log/*.log | |
| if-no-files-found: warn | |
| # TODO: Re-enable once pg_regress tests are stabilized | |
| # - name: Run pg_regress tests | |
| # id: pg_regress | |
| # env: | |
| # PGDATABASE: contrib_regression | |
| # run: | | |
| # ./scripts/pg-start.sh | |
| # cd test/regress | |
| # make installcheck | |
| # - name: Upload pg_regress results on failure | |
| # if: steps.pg_regress.outcome == 'failure' | |
| # uses: actions/upload-artifact@v4 | |
| # with: | |
| # name: pg_regress-results | |
| # path: | | |
| # test/regress/regression.out | |
| # test/regress/regression.diffs | |
| # if-no-files-found: ignore | |
| # - name: Stop PostgreSQL after pg_regress | |
| # if: steps.pg_regress.outcome != 'skipped' | |
| # run: ./scripts/pg-stop.sh |