Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
8 changes: 8 additions & 0 deletions .github/workflows/ci.yml
Original file line number Diff line number Diff line change
Expand Up @@ -24,6 +24,7 @@ jobs:
- uses: jdx/mise-action@c37c93293d6b742fc901e1406b8f764f6fb19dac # v2
with:
version: 2026.5.5
install_args: --jobs=1
cache: false
- run: >-
mise exec -- uv run --frozen --project . pytest -q
Expand Down Expand Up @@ -61,6 +62,7 @@ jobs:
- uses: jdx/mise-action@c37c93293d6b742fc901e1406b8f764f6fb19dac # v2
with:
version: 2026.5.5
install_args: --jobs=1
cache: false
- run: mise exec -- uv lock --check --project .
- run: mise run sync
Expand Down Expand Up @@ -90,6 +92,7 @@ jobs:
- uses: jdx/mise-action@c37c93293d6b742fc901e1406b8f764f6fb19dac # v2
with:
version: 2026.5.5
install_args: --jobs=1
cache: false
- run: mise exec -- pnpm install --frozen-lockfile
- run: mise run ts -- build
Expand All @@ -108,6 +111,7 @@ jobs:
- uses: jdx/mise-action@c37c93293d6b742fc901e1406b8f764f6fb19dac # v2
with:
version: 2026.5.5
install_args: --jobs=1
cache: false
- run: mise run sync
- run: mise run rust-fmt -- --check
Expand Down Expand Up @@ -143,6 +147,7 @@ jobs:
- uses: jdx/mise-action@c37c93293d6b742fc901e1406b8f764f6fb19dac # v2
with:
version: 2026.5.5
install_args: --jobs=1
cache: false
- run: mise run sync
- run: mise run openapi
Expand All @@ -165,6 +170,7 @@ jobs:
- uses: jdx/mise-action@c37c93293d6b742fc901e1406b8f764f6fb19dac # v2
with:
version: 2026.5.5
install_args: --jobs=1
cache: false
- run: mise run helm -- dependencies
- run: mise run helm -- lint --set payloadStore.enabled=false
Expand Down Expand Up @@ -196,6 +202,7 @@ jobs:
- uses: jdx/mise-action@c37c93293d6b742fc901e1406b8f764f6fb19dac # v2
with:
version: 2026.5.5
install_args: --jobs=1
cache: false
- run: mise run sync
- run: mise exec -- pnpm install --frozen-lockfile
Expand Down Expand Up @@ -225,6 +232,7 @@ jobs:
- uses: jdx/mise-action@c37c93293d6b742fc901e1406b8f764f6fb19dac # v2
with:
version: 2026.5.5
install_args: --jobs=1
cache: false
- run: mise run cpu-stack
- name: Preserve diagnostics
Expand Down
7 changes: 7 additions & 0 deletions .github/workflows/release-docker.yml
Original file line number Diff line number Diff line change
Expand Up @@ -33,6 +33,7 @@ jobs:
- uses: jdx/mise-action@c37c93293d6b742fc901e1406b8f764f6fb19dac # v2
with:
version: 2026.5.5
install_args: --jobs=1
- id: resolve
name: Validate source closure and coordinated versions
env:
Expand Down Expand Up @@ -64,6 +65,7 @@ jobs:
- uses: jdx/mise-action@c37c93293d6b742fc901e1406b8f764f6fb19dac # v2
with:
version: 2026.5.5
install_args: --jobs=1
- uses: docker/setup-buildx-action@8d2750c68a42422c14e847fe6c8ac0403b4cbd6f # v3
- id: restore
name: Reuse an already retained original-run image on retry
Expand Down Expand Up @@ -155,6 +157,7 @@ jobs:
- uses: jdx/mise-action@c37c93293d6b742fc901e1406b8f764f6fb19dac # v2
with:
version: 2026.5.5
install_args: --jobs=1
- uses: docker/setup-buildx-action@8d2750c68a42422c14e847fe6c8ac0403b4cbd6f # v3
- uses: actions/download-artifact@d3f86a106a0bac45b974a628896c90dbdf5c8093 # v4
with:
Expand Down Expand Up @@ -191,6 +194,7 @@ jobs:
- uses: jdx/mise-action@c37c93293d6b742fc901e1406b8f764f6fb19dac # v2
with:
version: 2026.5.5
install_args: --jobs=1
- uses: docker/setup-buildx-action@8d2750c68a42422c14e847fe6c8ac0403b4cbd6f # v3
- id: restore
name: Reuse an already retained original-run image on retry
Expand Down Expand Up @@ -283,6 +287,7 @@ jobs:
- uses: jdx/mise-action@c37c93293d6b742fc901e1406b8f764f6fb19dac # v2
with:
version: 2026.5.5
install_args: --jobs=1
- uses: docker/setup-buildx-action@8d2750c68a42422c14e847fe6c8ac0403b4cbd6f # v3
- uses: actions/download-artifact@d3f86a106a0bac45b974a628896c90dbdf5c8093 # v4
with:
Expand Down Expand Up @@ -326,6 +331,7 @@ jobs:
- uses: jdx/mise-action@c37c93293d6b742fc901e1406b8f764f6fb19dac # v2
with:
version: 2026.5.5
install_args: --jobs=1
- uses: docker/setup-buildx-action@8d2750c68a42422c14e847fe6c8ac0403b4cbd6f # v3
- uses: actions/download-artifact@d3f86a106a0bac45b974a628896c90dbdf5c8093 # v4
with:
Expand Down Expand Up @@ -391,6 +397,7 @@ jobs:
- uses: jdx/mise-action@c37c93293d6b742fc901e1406b8f764f6fb19dac # v2
with:
version: 2026.5.5
install_args: --jobs=1
- uses: docker/setup-buildx-action@8d2750c68a42422c14e847fe6c8ac0403b4cbd6f # v3
- uses: actions/download-artifact@d3f86a106a0bac45b974a628896c90dbdf5c8093 # v4
with:
Expand Down
2 changes: 2 additions & 0 deletions .github/workflows/release-helm.yml
Original file line number Diff line number Diff line change
Expand Up @@ -31,6 +31,7 @@ jobs:
- uses: jdx/mise-action@c37c93293d6b742fc901e1406b8f764f6fb19dac # v2
with:
version: 2026.5.5
install_args: --jobs=1
- name: Validate, render, and retain the exact chart
env:
RELEASE_VERSION: ${{ inputs.version }}
Expand Down Expand Up @@ -96,6 +97,7 @@ jobs:
- uses: jdx/mise-action@c37c93293d6b742fc901e1406b8f764f6fb19dac # v2
with:
version: 2026.5.5
install_args: --jobs=1
- uses: docker/login-action@c94ce9fb468520275223c153574b00df6fe4bcc9 # v3
with:
registry: ghcr.io
Expand Down
1 change: 1 addition & 0 deletions .github/workflows/release-native.yml
Original file line number Diff line number Diff line change
Expand Up @@ -31,6 +31,7 @@ jobs:
- uses: jdx/mise-action@c37c93293d6b742fc901e1406b8f764f6fb19dac # v2
with:
version: 2026.5.5
install_args: --jobs=1
- uses: actions/download-artifact@d3f86a106a0bac45b974a628896c90dbdf5c8093 # v4
with:
name: docker-service-sie-server-sidecar-${{ inputs.version }}
Expand Down
3 changes: 2 additions & 1 deletion .github/workflows/release-npm.yml
Original file line number Diff line number Diff line change
Expand Up @@ -31,7 +31,8 @@ jobs:
- uses: jdx/mise-action@c37c93293d6b742fc901e1406b8f764f6fb19dac # v2
with:
version: 2026.5.5
install_args: python uv node pnpm
# Install everything here; later mise exec would auto-install omitted tools.
install_args: --jobs=1
- name: Validate source and optional release identity
env:
GH_TOKEN: ${{ github.token }}
Expand Down
3 changes: 2 additions & 1 deletion .github/workflows/release-python.yml
Original file line number Diff line number Diff line change
Expand Up @@ -31,7 +31,8 @@ jobs:
- uses: jdx/mise-action@c37c93293d6b742fc901e1406b8f764f6fb19dac # v2
with:
version: 2026.5.5
install_args: python uv
# Install everything here; later mise exec would auto-install omitted tools.
install_args: --jobs=1
- name: Validate source and optional release identity
env:
GH_TOKEN: ${{ github.token }}
Expand Down
1 change: 1 addition & 0 deletions .github/workflows/release.yml
Original file line number Diff line number Diff line change
Expand Up @@ -83,6 +83,7 @@ jobs:
- uses: jdx/mise-action@c37c93293d6b742fc901e1406b8f764f6fb19dac # v2
with:
version: 2026.5.5
install_args: --jobs=1
if: steps.release.outputs.prs != '' && steps.release.outputs.prs != '[]'
- name: Refresh coupled locks on the release pull request
if: steps.release.outputs.prs != '' && steps.release.outputs.prs != '[]'
Expand Down
42 changes: 42 additions & 0 deletions tools/ci/tests/test_required_ci.py
Original file line number Diff line number Diff line change
Expand Up @@ -100,6 +100,48 @@ def test_mise_workflow_setups_pin_concrete_versions():
)


def test_mise_bootstrap_serializes_the_complete_toolset():
# Partial installs defer the other tools to `mise exec`, outside install_args.
for path in sorted((ROOT / ".github/workflows").glob("*.y*ml")):
workflow = yaml.safe_load(path.read_text())
for name, job in workflow["jobs"].items():
for step in job.get("steps", []):
if not step.get("uses", "").startswith("jdx/mise-action@"):
continue
inputs = step.get("with", {})
if inputs.get("install", True) is not False:
assert shlex.split(inputs.get("install_args", "")) == ["--jobs=1"], (
f"{path.name}: {name} must serialize the full tool install to avoid Node GPG races"
)


@pytest.mark.parametrize("install_status", [0, 1])
def test_init_serializes_install_and_stops_on_failure(tmp_path, install_status):
log = tmp_path / "mise.log"
mise = tmp_path / "mise"
mise.write_text(
'#!/bin/sh\nprintf "%s\\n" "$*" >> "$MISE_TEST_LOG"\n'
'if [ "$1" = install ]; then exit "$MISE_TEST_INSTALL_STATUS"; fi\n'
)
mise.chmod(0o755)
result = subprocess.run(
["bash", str(ROOT / "tools/init.sh")],
env={
**os.environ,
"PATH": f"{tmp_path}{os.pathsep}{os.environ['PATH']}",
"MISE_TEST_LOG": str(log),
"MISE_TEST_INSTALL_STATUS": str(install_status),
},
capture_output=True,
check=False,
)
assert result.returncode == install_status
expected = ["trust", "install --jobs=1"]
if install_status == 0:
expected.append("run full-sync")
assert log.read_text().splitlines() == expected


@pytest.mark.parametrize(("mutate_lock", "old_venv", "code"), [(False, False, 0), (True, False, 1), (False, True, 1)])
def test_bootstrap_rejects_reused_environment_and_changed_lock(tmp_path, mutate_lock, old_venv, code):
subprocess.run(["git", "init", "--quiet", str(tmp_path)], check=True)
Expand Down
3 changes: 2 additions & 1 deletion tools/init.sh
Original file line number Diff line number Diff line change
Expand Up @@ -13,7 +13,8 @@ echo "Trusting mise config..."
mise trust

echo "Installing mise tools and deps..."
mise install
# The pinned Node versions share GPG bootstrap state; install them sequentially.
mise install --jobs=1
mise run full-sync

if ! command -v cmake >/dev/null 2>&1; then
Expand Down
Loading