Researched current industry practice on code organization/maintainability (Ousterhout's deep modules and information hiding, package-by-feature vs. package-by-layer, functional-core/imperative-shell testability, tech-debt prevention via ADR-equivalent inline rationale) and wrote it into ARCHITECTURE.md as a set of concrete, project-specific rules rather than a generic essay — each principle cites a real example already in this codebase or fixed by this commit. Cross-linked from SPEC.md, which stays about product design, not code organization. Applied it to this PR's own code: - Pulled process_package/fetch_and_verify/build_and_publish/run_review/ approve out of main.rs into a new pipeline.rs. main.rs's own main() had grown to 278 lines and zero tests by treating "it's just the entry point" as an excuse to skip separating logic from wiring; now main.rs is argv dispatch only. - Extracted decide_tier_action as a pure function (verification outcome + pending-state -> what to do), replacing dispatch logic that was previously inlined into a function that also made the real network/ build calls. Four unit tests, no I/O, covering all four outcomes. - Added a `//!` module doc comment to every file touched in this branch, each stating that module's one job in a sentence, per the "deep modules" principle the spec argues for. Coverage's reported total drops (94% -> 78%) because pipeline.rs is deliberately NOT excluded from it the way main.rs is, even though it's mostly the same kind of untestable I/O orchestration — excluding it would hide decide_tier_action's real unit-test coverage along with the untested parts. Noted inline in Makefile.toml/ci.yml so the number doesn't look like a quality regression at a glance. Also added a project reference memory pointing at ARCHITECTURE.md rather than duplicating its content there, per this session's own memory-hygiene rules (architecture/conventions are derivable from the repo and shouldn't be duplicated somewhere that can go stale). Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
127 lines
3.8 KiB
YAML
127 lines
3.8 KiB
YAML
name: CI
|
|
|
|
on:
|
|
push:
|
|
branches: [master]
|
|
pull_request:
|
|
|
|
jobs:
|
|
build:
|
|
runs-on: rust-ci
|
|
steps:
|
|
- uses: actions/checkout@v4
|
|
|
|
- name: Cache cargo registry and build artifacts
|
|
uses: actions/cache@v4
|
|
with:
|
|
path: |
|
|
~/.cargo/registry
|
|
~/.cargo/git
|
|
target
|
|
key: cargo-${{ runner.os }}-${{ hashFiles('Cargo.lock') }}
|
|
restore-keys: |
|
|
cargo-${{ runner.os }}-
|
|
|
|
- name: Cache sccache compilation objects
|
|
uses: actions/cache@v4
|
|
with:
|
|
path: /root/.cache/sccache
|
|
# Not keyed to Cargo.lock: sccache caches individual compiler
|
|
# invocations by content hash, so it should accumulate across
|
|
# dependency bumps rather than reset like the target/ cache above.
|
|
key: sccache-${{ runner.os }}-${{ github.run_id }}
|
|
restore-keys: |
|
|
sccache-${{ runner.os }}-
|
|
|
|
- name: Format check
|
|
run: cargo fmt --check
|
|
|
|
- name: Clippy
|
|
run: cargo clippy --all-targets -- -D warnings
|
|
|
|
# Cognitive complexity (clippy nursery lint — see clippy.toml for why
|
|
# not literal cyclomatic complexity), bin target only so test code's
|
|
# naturally higher complexity isn't gated on this.
|
|
- name: Complexity
|
|
run: cargo clippy --bins -- -D warnings -W clippy::cognitive_complexity
|
|
|
|
- name: Check release profile compiles
|
|
run: cargo check --release
|
|
|
|
test:
|
|
needs: build
|
|
runs-on: rust-ci
|
|
steps:
|
|
- uses: actions/checkout@v4
|
|
|
|
- name: Cache cargo registry and build artifacts
|
|
uses: actions/cache@v4
|
|
with:
|
|
path: |
|
|
~/.cargo/registry
|
|
~/.cargo/git
|
|
target
|
|
key: cargo-${{ runner.os }}-${{ hashFiles('Cargo.lock') }}
|
|
restore-keys: |
|
|
cargo-${{ runner.os }}-
|
|
|
|
- name: Cache sccache compilation objects
|
|
uses: actions/cache@v4
|
|
with:
|
|
path: /root/.cache/sccache
|
|
key: sccache-${{ runner.os }}-${{ github.run_id }}
|
|
restore-keys: |
|
|
sccache-${{ runner.os }}-
|
|
|
|
- name: Test
|
|
run: cargo test
|
|
|
|
coverage:
|
|
needs: build
|
|
runs-on: rust-ci
|
|
steps:
|
|
- uses: actions/checkout@v4
|
|
|
|
- name: Cache cargo registry and build artifacts
|
|
uses: actions/cache@v4
|
|
with:
|
|
path: |
|
|
~/.cargo/registry
|
|
~/.cargo/git
|
|
target
|
|
key: cargo-${{ runner.os }}-${{ hashFiles('Cargo.lock') }}
|
|
restore-keys: |
|
|
cargo-${{ runner.os }}-
|
|
|
|
- name: Cache sccache compilation objects
|
|
uses: actions/cache@v4
|
|
with:
|
|
path: /root/.cache/sccache
|
|
key: sccache-${{ runner.os }}-${{ github.run_id }}
|
|
restore-keys: |
|
|
sccache-${{ runner.os }}-
|
|
|
|
# Not baked into the rust-ci image (see docker/rust-ci in
|
|
# infrastructure) — install fresh each run rather than bumping the
|
|
# shared image just for this one project.
|
|
- name: Install cargo-llvm-cov
|
|
run: |
|
|
rustup component add llvm-tools-preview
|
|
command -v cargo-llvm-cov >/dev/null 2>&1 || cargo install cargo-llvm-cov --locked
|
|
|
|
# Reports coverage only — no --fail-under-lines yet. main.rs is
|
|
# excluded: thin argv dispatch exercised by the real end-to-end
|
|
# `cargo run`, not unit tests, so it's not a meaningful signal here.
|
|
# See Makefile.toml > coverage-report for why pipeline.rs, despite
|
|
# being mostly untestable I/O orchestration too, stays included.
|
|
- name: Coverage
|
|
run: cargo llvm-cov --ignore-filename-regex 'main\.rs' --summary-only
|
|
|
|
audit:
|
|
needs: test
|
|
runs-on: rust-ci
|
|
steps:
|
|
- uses: actions/checkout@v4
|
|
|
|
- name: cargo audit
|
|
run: cargo audit
|