name: CI on: push: branches: - main pull_request: branches: - main concurrency: group: ci-${{ github.workflow }}-${{ github.ref }} cancel-in-progress: true permissions: contents: read jobs: linux: name: Build & test (Linux) runs-on: warp-ubuntu-latest-x64-8x steps: - name: Checkout uses: actions/checkout@v4 with: # gpui/ is a git submodule; its crates are workspace members of # their own repo and build as path dependencies of oakapp. submodules: true - name: Install Rust (stable) uses: dtolnay/rust-toolchain@stable # ------------------------------------------------------------------ # System dependencies # ------------------------------------------------------------------ - name: Install system dependencies run: | # Codec/filter libraries for the ffmpeg-sys-next build feature # (see tooling/install-deps.sh). tooling/install-deps.sh # cmake/make for the vendored OpenColorIO build (ocio-sys # `bundled`; Ubuntu's libopencolorio-dev is 2.1, older than the # bridge's API floor) plus the headless test infra gpui needs: # X11, software Mesa Vulkan (lavapipe) and xvfb. sudo apt-get install -y \ cmake \ libpipewire-0.3-dev libspa-0.2-dev libjack-jackd2-dev \ libasound2-dev libpulse-dev libsndfile1-dev \ libgl1-mesa-dev libgl1-mesa-dri mesa-vulkan-drivers \ libvulkan-dev libxkbcommon-dev libxkbcommon-x11-dev xvfb build-essential clang libclang-dev # ------------------------------------------------------------------ # Build environment # ------------------------------------------------------------------ # ocio-sys builds a stub bridge unless these are set; the oak-core # ocioutils tests need the real library. # tooling/ocio-env.sh: vendored static OCIO (the [patch.crates-io] # ocio-sys tracks shaloong/ocio-rs main, whose vendored sources build # on GCC >= 16). - name: Configure build environment run: | bash tooling/ocio-env.sh >> "$GITHUB_ENV" echo "FFMPEG_DIR=.cache/ffmpeg" >> "$GITHUB_ENV" # ------------------------------------------------------------------ # Caches # ------------------------------------------------------------------ # Covers the whole target/ dir plus ~/.cargo; shared across branches # of the same OS. - name: Cache cargo artifacts uses: Swatinem/rust-cache@v2 with: shared-key: oak-ci-linux cache-on-failure: true # The project FFmpeg (release/8.0, static, all free codecs + hwaccel) # is built by tooling/ffmpeg/build-ffmpeg.sh — 10-20 min on a cold # cache. It does not depend on the Rust toolchain, so key it on the # script itself and keep it out of rust-cache. - name: Cache project FFmpeg uses: actions/cache@v4 with: path: .cache/ffmpeg key: ffmpeg-${{ runner.os }}-${{ hashFiles('tooling/ffmpeg/build-ffmpeg.sh') }} # ------------------------------------------------------------------ # Project FFmpeg (script + FFMPEG_DIR; see docs/build.md) # ------------------------------------------------------------------ - name: Build project FFmpeg run: | tooling/ffmpeg/build-ffmpeg.sh echo "FFMPEG_DIR=$PWD/.cache/ffmpeg" >> "$GITHUB_ENV" # ------------------------------------------------------------------ # Build & test # ------------------------------------------------------------------ # `cargo check` (not build): the Test step links the test binaries # anyway, and a full build would codegen every workspace crate twice # (once without and once with cfg(test)). - name: Build run: cargo check --workspace --locked # xvfb + 24-bit screen: the gpui #[gpui::test] tests open real windows # and render through wgpu on Mesa's software Vulkan (lavapipe). # The watchdog bounds the step: a deadlocked test produces no output # and no failure, so after 1800 s it dumps every hung process's # thread stacks and kills the suite. - name: Test run: | sudo apt-get install -y gdb run_suite() { xvfb-run -a -s "-screen 0 1920x1080x24" cargo test --workspace --locked & TEST_PID=$! # The watchdog inherits the step's stdout/stderr; detach it so # it cannot keep the runner's I/O pipes open after the step # ends ("WaitDelay expired before I/O complete" otherwise). ( sleep 1800 echo "::warning::test suite exceeded 1800s; dumping hung-process stacks" for p in $(pgrep -f 'target/debug/deps/|target/debug/oak-worker'); do echo "===== thread stacks of pid $p ($(readlink /proc/$p/exe 2>/dev/null)) =====" sudo gdb -batch -ex 'thread apply all bt' -p "$p" || true done pkill -9 -f 'target/debug/deps/' || true pkill -9 -f 'target/debug/oak-worker' || true ) >/dev/null 2>&1 & WATCHDOG_PID=$! wait $TEST_PID rc=$? kill $WATCHDOG_PID 2>/dev/null || true # Reap the watchdog so no child holds the step's pipes. wait $WATCHDOG_PID 2>/dev/null || true return $rc } # Retry once (same policy as the Windows job): worker-pool # startup under full-suite parallelism has flaked once # (full_res_worker_outlives_a_dropped_project: the render # manager's process dispatcher failed to start while every other # test passed). A real regression fails both passes. if ! run_suite; then echo "first pass failed; retrying once for worker-pool flakes" run_suite fi # A crashing (SIGSEGV) test gives no Rust backtrace; rerun the # crashing test binaries under gdb to capture the native stack. # `--args` is required — plain `--` makes gdb treat the test args as # a core file. The extra probes target loader-stage crashes (the # copier_test SIGSEGV happens inside ld.so's dl_main): si_addr/si_code # pin down the fault type, the dynsym dump exposes symbols the # executable exports for interposition, strace shows the last loader # syscalls, and valgrind catches a corrupting static initializer. - name: Backtrace on test failure if: failure() run: | sudo apt-get install -y gdb strace valgrind for name in node_e2e_test suites_test copier_test; do BIN=$(ls -t target/debug/deps/$name-* | grep -v '\.d$' | head -1) [ -n "$BIN" ] || continue echo "===== $BIN =====" file "$BIN" || true echo "--- exported defined dynsyms:" readelf --dyn-syms -W "$BIN" 2>/dev/null | grep -v ' UND ' | tail -n +4 | head -30 || true echo "--- strace tail:" strace -f "$BIN" --list 2>&1 | tail -15 || true echo "--- valgrind tail:" valgrind -q "$BIN" --list 2>&1 | tail -25 || true echo "--- gdb:" xvfb-run -a gdb -batch \ -ex run \ -ex 'bt' \ -ex 'p $_siginfo.si_code' \ -ex 'p/x $_siginfo._sifields._sigfault.si_addr' \ -ex 'x/6i $rip' \ --args "$BIN" --nocapture || true done # ------------------------------------------------------------------ # OFX plugin discovery end-to-end # ------------------------------------------------------------------ # Build a minimal but real OFX plugin into a .ofx.bundle, point # OFX_PLUGIN_PATH at it and let the scan_probe example run the full # host path (directory scan -> dlopen -> setHost -> load -> describe # -> register). The assertion is the plugin's registration line; CI # machines have no system-wide OFX plugins, so the fixture is the # only discovery. - name: Build OFX fixture plugin run: crates/oak-plugin/tests/fixtures/build_fixture.sh .cache/ofx-fixture - name: Probe OFX plugin discovery run: | OFX_PLUGIN_PATH="$PWD/.cache/ofx-fixture" \ cargo run --locked -p oak-plugin --example scan_probe > probe.log 2>&1 grep -q 'type_id=rs.oak.CiTestPlugin' probe.log # A project carrying a plugin node must survive save/load (the # serializer resolves plugin types via the dynamic factory). OAK_OFX_FIXTURE_DIR="$PWD/.cache/ofx-fixture" \ cargo test --locked -p oak-plugin --test ofx_roundtrip windows: name: Build & test (Windows) runs-on: warp-windows-latest-x64-16x env: # The build needs the UCRT64 environment (mingw-w64-ucrt-x86_64-* # toolchain), not the base MSYS one. MSYSTEM: UCRT64 defaults: run: shell: msys2 {0} steps: - name: Checkout uses: actions/checkout@v4 with: # gpui/ is a git submodule; its crates are workspace members of # their own repo and build as path dependencies of oakapp. submodules: true - name: Setup MSYS2 uses: msys2/setup-msys2@v2 with: msystem: UCRT64 update: true # MSYS2's own Rust targets x86_64-pc-windows-gnu by default — # the Windows build is GNU-target (the MSVC linker rejects the # Unix-style link args the build scripts emit). install: >- git mingw-w64-ucrt-x86_64-gcc mingw-w64-ucrt-x86_64-rust # ------------------------------------------------------------------ # System dependencies # ------------------------------------------------------------------ - name: Install system dependencies run: | bash ./tooling/install-deps.sh pacman -S --needed --noconfirm \ mingw-w64-ucrt-x86_64-cmake \ mingw-w64-ucrt-x86_64-opencolorio \ mingw-w64-ucrt-x86_64-ffnvcodec-headers \ mingw-w64-ucrt-x86_64-pkgconf \ mingw-w64-ucrt-x86_64-clang mingw-w64-ucrt-x86_64-clang-libs git # ------------------------------------------------------------------ # Build environment # ------------------------------------------------------------------ # Windows uses the MSYS2 OpenColorIO package (the exact 2.5.2 the # bridge targets; the vendored source needs MSVC-only constructs). # Dynamic here — the CD packages the DLLs next to the binaries. - name: Configure build environment run: | # System OCIO (MSYS2, the exact 2.5.2 the bridge targets); # tooling/ocio-env.sh links it STATICALLY when the package ships # libOpenColorIO.a, dynamically otherwise. bash tooling/ocio-env.sh >> "$GITHUB_ENV" echo "FFMPEG_DIR=.cache/ffmpeg" >> "$GITHUB_ENV" # ocio-sys is the GIT fork (Mike-Solar/ocio-rs main, pinned in # the root manifest): its build.rs already carries the # fork's GNU-toolchain fix, so NO crate-unpack/glob patch step # applies here. The old code unpacked `ocio-sys-0.2.1.crate` # from the registry cache — impossible for a git dependency # (no .crate archive; git sources land under # registry/src/git/), hence the # "ls .../ocio-sys-0.2.1/build.rs: No such file" Windows CI # failure. echo "OCIO_RS_NO_MSVC_INCLUDES=1" >> "$GITHUB_ENV" # ------------------------------------------------------------------ # Caches # ------------------------------------------------------------------ # Covers the whole target/ dir plus ~/.cargo; shared across branches # of the same OS. - name: Cache cargo artifacts uses: Swatinem/rust-cache@v2 with: shared-key: oak-ci-windows cache-on-failure: true # The project FFmpeg (release/8.0, static, all free codecs + hwaccel) # is built by tooling/ffmpeg/build-ffmpeg.sh — 10-20 min on a cold # cache. It does not depend on the Rust toolchain, so key it on the # script itself and keep it out of rust-cache. - name: Cache project FFmpeg uses: actions/cache@v4 with: path: .cache/ffmpeg key: ffmpeg-${{ runner.os }}-${{ hashFiles('tooling/ffmpeg/build-ffmpeg.sh') }} # ------------------------------------------------------------------ # Project FFmpeg (script + FFMPEG_DIR; see docs/build.md) # ------------------------------------------------------------------ - name: Build project FFmpeg run: | bash tooling/ffmpeg/build-ffmpeg.sh echo "FFMPEG_DIR=$(cygpath -m "$PWD/.cache/ffmpeg")" >> "$GITHUB_ENV" # ------------------------------------------------------------------ # Build & test # ------------------------------------------------------------------ # `cargo check` (not build): the Test step links the test binaries # anyway, and a full build would codegen every workspace crate twice # (once without and once with cfg(test)). cargo check performs no # final link, so the mingw-w64 link-order workaround is only needed # in the Test step. - name: Build run: | cargo check --workspace --locked - name: Test run: | # The GitHub image injects the MSVC INCLUDE/LIB into the # environment; clear them in-step (they poison the MinGW # compiles with MSVC SDK headers). unset INCLUDE LIB # mingw-w64 >= Nov 2025 forwards _assert to __msvcrt_assert inside # libmingwex.a; rustc's link order puts -lmingwex last, so any # binary that pulls _assert.o leaves _fileno/_setmode/ # __imp___msvcrt_assert unresolved. A trailing -lmsvcrt re-scans # the CRT import lib after libmingwex. export RUSTFLAGS="-C link-args=-lmsvcrt" if ! cargo test --workspace --locked; then # Retry once: a few gpui keystroke tests flake on Windows CI — # a synthetic keystroke is occasionally never delivered (the # undo/redo pair and a plain 's' toggle both failed once, # each identically to its pass state). A real regression # fails both passes. echo "first pass failed; retrying once for gpui keystroke flakes" cargo test --workspace --locked fi macos: name: Build & test (macOS) runs-on: warp-macos-26-arm64-6x steps: - name: Checkout uses: actions/checkout@v4 with: # gpui/ is a git submodule; its crates are workspace members of # their own repo and build as path dependencies of oakapp. submodules: true - name: Install Rust (stable) uses: dtolnay/rust-toolchain@stable # ------------------------------------------------------------------ # System dependencies # ------------------------------------------------------------------ - name: Install system dependencies run: | tooling/install-deps.sh brew install cmake # ------------------------------------------------------------------ # Build environment # ------------------------------------------------------------------ - name: Configure build environment run: | # Vendored static OCIO (same as every non-Windows platform via # tooling/ocio-env.sh); no OCIO_INSTALL_DIR override. bash tooling/ocio-env.sh >> "$GITHUB_ENV" # Homebrew quirks: lame.pc / snappy / libopenjp2.pc live off the # default pkg-config search paths (see docs/build.md). { echo "CFLAGS=-I/opt/homebrew/include" echo "LDFLAGS=-L/opt/homebrew/lib" echo "PKG_CONFIG_PATH=/opt/homebrew/lib/pkgconfig/openjpeg" } >> "$GITHUB_ENV" echo "FFMPEG_DIR=.cache/ffmpeg" >> "$GITHUB_ENV" # ------------------------------------------------------------------ # Caches # ------------------------------------------------------------------ # Covers the whole target/ dir plus ~/.cargo; shared across branches # of the same OS. - name: Cache cargo artifacts uses: Swatinem/rust-cache@v2 with: shared-key: oak-ci-macos cache-on-failure: true # The project FFmpeg (release/8.0, static, all free codecs + hwaccel) # is built by tooling/ffmpeg/build-ffmpeg.sh — 10-20 min on a cold # cache. It does not depend on the Rust toolchain, so key it on the # script itself and keep it out of rust-cache. - name: Cache project FFmpeg uses: actions/cache@v4 with: path: .cache/ffmpeg key: ffmpeg-${{ runner.os }}-${{ hashFiles('tooling/ffmpeg/build-ffmpeg.sh') }} # ------------------------------------------------------------------ # Project FFmpeg (script + FFMPEG_DIR; see docs/build.md) # ------------------------------------------------------------------ - name: Build project FFmpeg run: | tooling/ffmpeg/build-ffmpeg.sh echo "FFMPEG_DIR=$PWD/.cache/ffmpeg" >> "$GITHUB_ENV" # ------------------------------------------------------------------ # Build & test # ------------------------------------------------------------------ # `cargo check` (not build): the Test step links the test binaries # anyway, and a full build would codegen every workspace crate twice # (once without and once with cfg(test)). - name: Build run: cargo check --workspace --locked # The runner's GUI session doubles as the display for the gpui # #[gpui::test] windows; wgpu renders through Metal. - name: Test run: | # Retry once (same policy as the other platforms): worker-pool # startup under full-suite parallelism has flaked on Linux. A # real regression fails both passes. if ! cargo test --workspace --locked; then echo "first pass failed; retrying once for worker-pool flakes" cargo test --workspace --locked fi