perf: run memory extraction off the turn-end critical path #740
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
| name: CI | |
| on: | |
| push: | |
| branches: [main] | |
| pull_request: | |
| branches: [main] | |
| env: | |
| CARGO_TERM_COLOR: always | |
| jobs: | |
| retrieval-soak: | |
| name: Retrieval soak | |
| uses: ./.github/workflows/workspace-retrieval-soak.yml | |
| memory-restart-soak: | |
| name: Memory restart soak | |
| uses: ./.github/workflows/durable-memory-restart-soak.yml | |
| sdk-runtime: | |
| name: SDK runtime | |
| uses: ./.github/workflows/sdk-runtime.yml | |
| hermetic-integrations: | |
| name: Hermetic integrations | |
| uses: ./.github/workflows/hermetic-integrations.yml | |
| check: | |
| name: Check | |
| runs-on: ubuntu-latest | |
| # The complete default and feature-gated workspace suites are intentionally | |
| # part of this gate. A cold hosted runner can take longer than the | |
| # lightweight 25-minute budget even when the tests are making progress. | |
| timeout-minutes: 45 | |
| steps: | |
| - uses: actions/checkout@v4 | |
| - name: Setup workspace context | |
| run: bash .github/setup-workspace.sh | |
| - name: Install Rust | |
| uses: dtolnay/rust-toolchain@stable | |
| with: | |
| components: rustfmt, clippy | |
| - name: Relock standalone dependencies | |
| run: bash .github/relock-standalone-deps.sh | |
| - uses: Swatinem/rust-cache@v2 | |
| - name: Install Linux build and sandbox prerequisites | |
| shell: bash | |
| run: | | |
| sudo apt-get update | |
| sudo apt-get install -y protobuf-compiler bubblewrap | |
| if sysctl -N kernel.apparmor_restrict_unprivileged_userns >/dev/null 2>&1; then | |
| sudo sysctl -w kernel.apparmor_restrict_unprivileged_userns=0 | |
| fi | |
| if sysctl -N kernel.unprivileged_userns_clone >/dev/null 2>&1; then | |
| sudo sysctl -w kernel.unprivileged_userns_clone=1 | |
| fi | |
| - name: Verify capability architecture and evidence | |
| run: | | |
| python3 scripts/check_scoped_capability_architecture.py | |
| python3 scripts/check_capability_verification.py | |
| - name: Test repository validation scripts | |
| run: python3 -m unittest discover -s scripts/tests -p 'test_*.py' | |
| - name: Format check | |
| run: cargo fmt --all -- --check | |
| - name: Rustdoc warning gate | |
| env: | |
| RUSTDOCFLAGS: -D warnings | |
| run: cargo doc --locked -p a3s-code-core -p a3s-code-go-bridge --features ci-all --no-deps | |
| - name: Check browser dependency boundary | |
| shell: bash | |
| run: | | |
| set -euo pipefail | |
| minimal_tree="$(cargo tree -p a3s-code-core --no-default-features -e normal)" | |
| if grep -q 'chromiumoxide' <<<"$minimal_tree"; then | |
| echo "minimal Core must not compile the browser/CDP dependency stack" >&2 | |
| exit 1 | |
| fi | |
| local_code_tree="$(cargo tree -p a3s-code-core --no-default-features --features local-code -e normal)" | |
| if grep -q 'chromiumoxide' <<<"$local_code_tree"; then | |
| echo "local-code Core must not compile the browser/CDP dependency stack" >&2 | |
| exit 1 | |
| fi | |
| if grep -q 'a3s-apofasi' <<<"$local_code_tree"; then | |
| echo "local-code Core must not link a3s-apofasi" >&2 | |
| exit 1 | |
| fi | |
| headless_tree="$(cargo tree -p a3s-code-core --no-default-features --features headless-search -e normal)" | |
| grep -q 'chromiumoxide' <<<"$headless_tree" | |
| - name: Local-code harness gate | |
| env: | |
| RUST_MIN_STACK: "16777216" | |
| run: | | |
| cargo check -p a3s-code-core --no-default-features --features local-code | |
| cargo test -p a3s-code-core --no-default-features --features local-code --lib | |
| cargo test -p a3s-code-core --no-default-features --features apofasi --lib typed_decision | |
| - name: Clippy | |
| # --features ci-all: every optional surface except Apple-only apofasi-metal. | |
| run: cargo clippy -p a3s-code-core -p a3s-code-go-bridge --lib --bins --features ci-all -- -D warnings | |
| - name: Check public API compatibility with v5.3.5 | |
| run: | | |
| cargo install cargo-semver-checks --version 0.50.0 --locked | |
| bash scripts/check_semver.sh 5.3.5 | |
| - name: Default tests | |
| env: | |
| RUST_MIN_STACK: "16777216" | |
| run: cargo test --workspace | |
| - name: Feature-gated library tests | |
| env: | |
| RUST_MIN_STACK: "16777216" | |
| run: cargo test -p a3s-code-core -p a3s-code-go-bridge --features ci-all --lib | |
| - name: Agent convergence benchmark | |
| run: cargo run -p a3s-code-core --example agent_convergence_benchmark | |
| sdk-check: | |
| name: SDK contract and Go runtime | |
| runs-on: ubuntu-latest | |
| timeout-minutes: 20 | |
| steps: | |
| - uses: actions/checkout@v4 | |
| - name: Setup workspace context | |
| run: bash .github/setup-workspace.sh | |
| - name: Install Rust | |
| uses: dtolnay/rust-toolchain@stable | |
| - name: Relock standalone dependencies | |
| run: bash .github/relock-standalone-deps.sh | |
| - uses: Swatinem/rust-cache@v2 | |
| - name: Install protobuf compiler | |
| run: sudo apt-get update && sudo apt-get install -y protobuf-compiler | |
| - name: Check SDK protocol and API alignment | |
| run: | | |
| node scripts/generate_event_protocol_artifacts.mjs --check | |
| node scripts/generate_evaluation_protocol_artifacts.mjs --check | |
| node scripts/check_evaluation_protocol_artifacts.mjs | |
| node scripts/generate_research_protocol_artifacts.mjs --check | |
| node scripts/check_research_protocol_artifacts.mjs | |
| node scripts/sdk_api_alignment_check.mjs | |
| - uses: actions/setup-go@v6 | |
| with: | |
| go-version: "1.23.x" | |
| cache-dependency-path: sdk/go/go.mod | |
| - name: Check Go SDK | |
| run: | | |
| cargo build --package a3s-code-go-bridge --bin a3s-code-go-bridge | |
| A3S_CODE_GO_BRIDGE_TEST_BINARY="$PWD/../../target/debug/a3s-code-go-bridge" \ | |
| RUST_MIN_STACK="${RUST_MIN_STACK:-16777216}" \ | |
| go test -race ./... | |
| working-directory: sdk/go | |
| windows-check: | |
| name: Windows check | |
| runs-on: windows-latest | |
| # Serial `--test-threads=1` lib tests (AppContainer host ACL safety) plus | |
| # clippy and Go bridge routinely need more than 25m on windows-latest. | |
| timeout-minutes: 45 | |
| steps: | |
| - uses: actions/checkout@v4 | |
| - name: Setup workspace context | |
| shell: bash | |
| run: bash .github/setup-workspace.sh | |
| - name: Install Rust | |
| uses: dtolnay/rust-toolchain@stable | |
| with: | |
| components: clippy | |
| - name: Relock standalone dependencies | |
| run: bash .github/relock-standalone-deps.sh | |
| - name: Clippy | |
| # --features ci-all: every optional surface except Apple-only apofasi-metal. | |
| run: cargo clippy -p a3s-code-core -p a3s-code-go-bridge --lib --bins --features ci-all -- -D warnings | |
| - name: Library tests | |
| # a3s-sandbox's AppContainer backend temporarily reserves DOS drive | |
| # mappings and mutates host ACLs. Keep the test process serial so | |
| # unrelated Code tests cannot race those process-global resources. | |
| env: | |
| RUST_MIN_STACK: "16777216" | |
| run: cargo test --workspace --lib -- --test-threads=1 | |
| - uses: actions/setup-go@v6 | |
| with: | |
| go-version: "1.23.x" | |
| cache-dependency-path: sdk/go/go.mod | |
| - name: Go SDK integration | |
| shell: pwsh | |
| working-directory: sdk/go | |
| run: | | |
| cargo build --package a3s-code-go-bridge --bin a3s-code-go-bridge | |
| $env:A3S_CODE_GO_BRIDGE_TEST_BINARY = (Resolve-Path "..\..\target\debug\a3s-code-go-bridge.exe").Path | |
| if (-not $env:RUST_MIN_STACK) { $env:RUST_MIN_STACK = "16777216" } | |
| go test ./... |