Skip to content

QVAC-20987 infra: Sync with fabric 9341 #559

QVAC-20987 infra: Sync with fabric 9341

QVAC-20987 infra: Sync with fabric 9341 #559

Workflow file for this run

name: On PR Trigger (VLA)
on:
pull_request_target:
types:
- opened
- synchronize
- reopened
- labeled
branches:
- main
- release-*
- feature-*
- tmp-*
paths:
- "packages/vla-ggml/**"
- ".github/workflows/*-vla.yml"
- ".github/actions/cache-models/**"
workflow_dispatch:
workflow_call:
permissions:
contents: read
pull-requests: read
packages: read
id-token: write
env:
PKG_DIR: packages/vla-ggml
concurrency:
group: ${{ github.workflow }}-${{ github.event.pull_request.number || github.run_id }}
cancel-in-progress: true
jobs:
label-gate:
name: Authorise (label-gate)
runs-on: ubuntu-latest
permissions:
contents: read
pull-requests: write
outputs:
authorised: ${{ steps.gate.outputs.authorised }}
steps:
- name: Checkout (label-gate action only)
uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # 6.0.2
with:
ref: ${{ github.event.repository.default_branch }}
sparse-checkout: .github/actions/label-gate
sparse-checkout-cone-mode: false
- name: Run label-gate
id: gate
uses: ./.github/actions/label-gate
with:
github-token: ${{ secrets.PAT_TOKEN }}
authorize:
runs-on: ubuntu-latest
permissions:
contents: read
pull-requests: write
outputs:
allowed: ${{ steps.auth.outputs.allowed }}
steps:
- name: Checkout
uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # 6.0.2
- name: Authorize
id: auth
uses: ./.github/actions/authorize-pr
with:
github-token: ${{ github.token }}
verify-fabric-lockstep:
if: needs.authorize.outputs.allowed == 'true'
needs: [authorize]
runs-on: ubuntu-latest
steps:
- name: Checkout code
uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # 6.0.2
- name: Verify qvac-fabric versions are lockstep
id: lockstep
uses: ./.github/actions/verify-qvac-fabric-lockstep
- name: Report verified version
run: 'echo "Verified qvac-fabric version: ${{ steps.lockstep.outputs.version }}"'
sanity-checks:
if: always() && !cancelled() && needs.label-gate.outputs.authorised == 'true' && needs.authorize.outputs.allowed == 'true'
needs: [authorize, verify-fabric-lockstep, label-gate]
runs-on: ubuntu-latest
steps:
- name: Checkout code
uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # 6.0.2
with:
fetch-depth: 0
- name: Run Sanity checks
uses: ./.github/actions/sanity-checks
with:
secret-token: ${{ secrets.GITHUB_TOKEN }}
pat-token: ${{ secrets.PAT_TOKEN }}
run-integration: ${{ needs.authorize.outputs.allowed == 'true' }}
workdir: packages/vla-ggml
cpp-lint:
# Only runs when we have a PR base SHA to diff against. Workflow_dispatch
# has no pull_request context, which would make the diff target empty.
if: always() && !cancelled() && needs.label-gate.outputs.authorised == 'true' && needs.authorize.outputs.allowed == 'true' && github.event_name == 'pull_request_target'
needs: [authorize, label-gate]
uses: ./.github/workflows/cpp-lint.yaml
secrets: inherit
with:
sha: ${{ github.event.pull_request.base.sha }}
pr_head_sha: ${{ github.event.pull_request.head.sha }}
workdir: packages/vla-ggml
cpp-tests:
permissions:
contents: read
packages: read
pull-requests: write
if: always() && !cancelled() && needs.label-gate.outputs.authorised == 'true' && needs.authorize.outputs.allowed == 'true'
needs: [authorize, sanity-checks, label-gate]
uses: ./.github/workflows/cpp-tests-vla.yml
secrets: inherit
with:
repository: ${{ github.event.pull_request.head.repo.full_name }}
ref: ${{ github.event.pull_request.head.ref }}
ts-checks:
if: needs.authorize.outputs.allowed == 'true'
needs: authorize
runs-on: ubuntu-latest
environment: release
steps:
- name: Checkout code
uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # 6.0.2
- name: Set up Node.js
uses: actions/setup-node@53b83947a5a98c8d113130e565377fae1a50d02f # 6.3.0
with:
node-version: 20
- name: Install dependencies
working-directory: packages/vla-ggml
run: npm install
- name: Type declaration check
working-directory: packages/vla-ggml
run: npm run test:dts
- name: Run lint and unit tests
id: run_lint_and_unit_tests
uses: ./.github/actions/run-lint-and-unit-tests
with:
gpr-token: ${{ secrets.GITHUB_TOKEN }}
pat-token: ${{ secrets.GITHUB_TOKEN }}
registry-type: gpr
workdir: packages/vla-ggml
prebuild:
permissions:
contents: write
packages: write
pull-requests: write
id-token: write
if: always() && !cancelled() && needs.label-gate.outputs.authorised == 'true' && needs.authorize.outputs.allowed == 'true'
needs: [authorize, sanity-checks, label-gate]
uses: ./.github/workflows/prebuilds-vla.yml
secrets: inherit
with:
repository: ${{ github.event.pull_request.head.repo.full_name }}
ref: ${{ github.event.pull_request.head.ref }}
integration-tests:
needs: [authorize, prebuild, label-gate]
if: needs.label-gate.outputs.authorised == 'true' && needs.authorize.outputs.allowed == 'true'
permissions:
contents: read
packages: read
id-token: write
uses: ./.github/workflows/integration-test-vla.yml
secrets: inherit
with:
repository: ${{ github.event.pull_request.head.repo.full_name }}
ref: ${{ github.event.pull_request.head.ref }}
run-mobile-integration-tests:
permissions:
contents: read
packages: read
pull-requests: write
id-token: write
if: needs.label-gate.outputs.authorised == 'true' && needs.authorize.outputs.allowed == 'true'
needs: [authorize, prebuild, label-gate]
uses: ./.github/workflows/integration-mobile-test-vla.yml
secrets: inherit
with:
repository: ${{ github.event.pull_request.head.repo.full_name }}
ref: ${{ github.event.pull_request.head.ref }}
merge-guard:
needs: [authorize, verify-fabric-lockstep, sanity-checks, cpp-lint, cpp-tests, prebuild, integration-tests, run-mobile-integration-tests, ts-checks]
if: always() && !cancelled()
uses: ./.github/workflows/public-pr.yml
with:
sanity-checks-status: ${{ needs.verify-fabric-lockstep.result == 'success' && needs.sanity-checks.result == 'success' }}
build-status: ${{ needs.prebuild.result == 'success' }}