Merge pull request #899 from ecto/claude/ffi-sync-open-uncached #256
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
| name: WASM refresh | |
| # Single writer for the generated kernel-wasm artifacts. | |
| # | |
| # wasm-pack output is not byte-reproducible, so two branches that each | |
| # rebuilt packages/kernel-wasm/vcad_kernel_wasm* conflict on every merge | |
| # even when their Rust changes don't overlap. Feature branches therefore | |
| # never commit those files (ci.yml's wasm-artifact-guard enforces it); | |
| # instead this workflow rebuilds them on main after any kernel-source | |
| # merge and commits the refresh itself. | |
| # | |
| # The refresh commit only touches packages/kernel-wasm/**, which does not | |
| # match the paths filter below — so it can never re-trigger itself. | |
| on: | |
| push: | |
| branches: [main] | |
| paths: | |
| - "crates/**" | |
| # loon stdlib is include_str! into crates/vcad-loon | |
| - "lib/**" | |
| - "Cargo.toml" | |
| - "Cargo.lock" | |
| # Manual re-fire for the rare push race (a merge landing between this | |
| # workflow's checkout and its push makes the push fail cleanly). | |
| workflow_dispatch: {} | |
| permissions: | |
| contents: write | |
| concurrency: | |
| group: wasm-refresh-main | |
| # Only the newest kernel state matters — a superseded rebuild is waste. | |
| cancel-in-progress: true | |
| jobs: | |
| refresh: | |
| runs-on: ubuntu-latest | |
| steps: | |
| - uses: actions/checkout@v6 | |
| - name: Clone sibling repos | |
| run: | | |
| git clone --depth 1 https://github.com/ecto/tang.git ../tang | |
| git clone --depth 1 https://github.com/ecto/phyz.git ../phyz | |
| git clone --depth 1 https://github.com/ecto/loon.git ../loon | |
| - uses: dtolnay/rust-toolchain@master | |
| with: | |
| toolchain: stable | |
| targets: wasm32-unknown-unknown | |
| - uses: Swatinem/rust-cache@v2 | |
| with: | |
| cache-workspace-crates: true | |
| - name: Install wasm-pack | |
| # Via cargo so the binary comes through the same trust chain as the | |
| # rest of the toolchain (matches ci.yml). | |
| run: cargo install wasm-pack --locked --version 0.13.1 | |
| - uses: actions/setup-node@v6 | |
| with: | |
| node-version: 22 | |
| cache: npm | |
| # node_modules is needed for the builtin font include_bytes! in | |
| # vcad-kernel-text; --ignore-scripts skips native builds we don't use. | |
| - run: npm ci --prefer-offline --no-audit --no-fund --ignore-scripts | |
| # build.mjs (not raw wasm-pack): it also re-applies the trap-recovery | |
| # hook to the wasm-bindgen glue, which the checked-in artifacts carry. | |
| - name: Rebuild kernel WASM artifacts | |
| run: node packages/kernel-wasm/scripts/build.mjs | |
| - name: Commit refreshed artifacts | |
| run: | | |
| git add packages/kernel-wasm/vcad_kernel_wasm.js \ | |
| packages/kernel-wasm/vcad_kernel_wasm.d.ts \ | |
| packages/kernel-wasm/vcad_kernel_wasm_bg.wasm \ | |
| packages/kernel-wasm/vcad_kernel_wasm_bg.wasm.d.ts | |
| if git diff --cached --quiet; then | |
| echo "artifacts unchanged — nothing to refresh" | |
| exit 0 | |
| fi | |
| git config user.name "vcad-agent[bot]" | |
| git config user.email "vcad-agent@users.noreply.github.com" | |
| git commit -m "chore(wasm): refresh kernel artifacts for ${GITHUB_SHA:0:7}" | |
| # The build can dirty tracked files this job doesn't own — most | |
| # commonly Cargo.lock, when a PR pinned a sibling-repo version from | |
| # a stale local checkout and cargo re-resolves against the fresh | |
| # clones above. Single-writer policy: this job only ever commits the | |
| # kernel-wasm artifacts, so surface the drift as a warning and | |
| # discard it — a dirty tree here otherwise wedges `pull --rebase` | |
| # and silently freezes the published artifacts (see #469→#473, | |
| # where a phyz 0.3.1→0.3.0 lockfile regression did exactly that). | |
| if ! git diff --quiet; then | |
| echo "::warning::discarding non-artifact build dirt (stale sibling pin in a merged PR?):" | |
| git --no-pager diff --stat | |
| git checkout -- . | |
| fi | |
| # Cheap insurance against a non-artifact merge racing us; a binary | |
| # conflict here means a policy violation upstream and should fail | |
| # loudly (re-run via workflow_dispatch after fixing). | |
| git pull --rebase origin main | |
| git push origin HEAD:main |