headroom/.github/workflows/init-native-e2e.yml
Patrick A 53d2342291
ci: speed up GitHub Actions — path filters, caching, timeouts, version upgrades (#620)
* ci: speed up GitHub Actions - path filters, caching, timeouts, version upgrades

Performance improvements:
- init-e2e.yml, wrap-e2e.yml: add path filters so e2e Docker builds only run when
  e2e-related files change (saves ~10 min per irrelevant PR push)
- init-e2e.yml, wrap-e2e.yml: add concurrency groups to cancel superseded PR runs
- ci.yml: add pip caching to lint and build jobs
- ci.yml: cache actionlint + act binaries in workflow-validation (skip curl on hits)
- eval.yml: add pip caching to smoke-test and weekly-suite jobs
- docs.yml: add pip caching for mkdocs-material install
- rust.yml: replace cargo install --locked cargo-audit/deny with taiki-e/install-action
  (prebuilt binaries; saves 2-5 min per audit run)

Bug fixes:
- docker.yml: fix actions/checkout@v6 -> @v4 (v6 does not exist; would break all
  Docker builds on every release/PR touching docker paths)

Version upgrades:
- wagoid/commitlint-github-action: @v5 -> @v6
- devcontainers.yml: docker/setup-buildx-action@v3 -> @v4 (align with docker.yml)

Safety improvements:
- ci.yml: add timeout-minutes to all 13 jobs (changes, lint, build-wheel,
  prefetch-model, test x4, test-extras, test-agno, commitlint, build,
  workflow-validation, docker-native-e2e, windows-native-wrapper, macos-native-wrapper)
- docker.yml: add timeout-minutes to docker-build (75m), docker-manifest (20m),
  promote-latest (10m)
- eval.yml: add timeout-minutes to smoke-test (30m); bump weekly-suite 60->90m
- rust.yml: add timeout-minutes to test (30m), wheels (45m), audit (20m)

Observed wall-clock impact on recent PRs:
- Init E2E and Wrap E2E were running on every single PR push regardless of content
- CI workflow was taking 12-17 min; path filters reduce unnecessary e2e runs to 0

* fix(ci): bust actionlint+act cache when workflow file changes

Static cache key 'ci-tools-actionlint-act-v1' never invalidated on
tool version updates. Switched to hashFiles('.github/workflows/ci.yml')
so the cache busts automatically whenever the download scripts are
updated to point at a newer release.

Flagged by adversarial review (Architecture + Testing/Reliability personas).

* fix(ci): add missing Dockerfile COPY paths to e2e path filters

e2e/init/Dockerfile and e2e/wrap/Dockerfile COPY files not covered
by the initial path filter set:

  init-e2e: Cargo.toml, Cargo.lock, rust-toolchain.toml, uv.lock,
            .claude-plugin, .github/plugin/**, plugins/headroom-agent-hooks/**
  wrap-e2e: Cargo.toml, Cargo.lock, rust-toolchain.toml, uv.lock,
            sdk/typescript/**, plugins/openclaw/**

Without these, a Rust toolchain bump or SDK change on a PR would
skip the e2e gate entirely, only catching it on the merge to main.

Flagged by adversarial review (Domain/Correctness persona).

* fix(devcontainer): upgrade uv to >=0.7.0 to parse uv.lock revision=3

* fix(devcontainer): set UV_SKIP_WHEEL_FILENAME_CHECK=1 in post-create.sh for gitpython wheel

* ci: bump actions/checkout and actions/setup-node to v5 (Node.js 20 EOL Jun 16)

* fix(devcontainer): export UV_SKIP_WHEEL_FILENAME_CHECK so uv run also skips wheel check

* ci: bump all GitHub Actions to latest versions (Node.js 24)

* fix(test): accept release-please-action v4 or v5 in workflow assertion

* fix(format): ruff format test_release_workflows.py
2026-06-05 14:32:53 -08:00

139 lines
5.3 KiB
YAML

name: Init Native E2E
# Cross-platform (linux / macos / windows) smoke tests for the per-subcommand
# ``headroom init -g <target>`` flows. Each matrix cell drops a noop shim for
# the target agent onto PATH and asserts ``headroom init -g <target>``
# succeeds, writes the expected settings file, and (for claude/codex) places
# hooks in the right place.
#
# Deliberately scoped to pull_request + push-to-main + workflow_dispatch to
# avoid bloating CI minutes on every push to every feature branch. The Docker
# init-e2e.yml still runs on every PR and provides the deeper functional
# coverage; this workflow exists to catch platform-specific bugs (Windows
# path separators, macos keychain prompts, PowerShell-vs-bash hook matchers)
# that the single-platform Docker suite can miss.
#
# Extending to other commands (``headroom install``, ``headroom wrap``) is
# expected to be a near-copy of this file. The shared composite action at
# ``.github/actions/headroom-e2e-setup`` absorbs the Python + shim setup so
# each per-command workflow only supplies its matrix and assertion steps.
on:
pull_request:
branches: [main]
paths:
- "headroom/cli/init.py"
- "headroom/install/**"
- "e2e/_lib/**"
- "e2e/init/**"
- ".github/actions/headroom-e2e-setup/**"
- ".github/workflows/init-native-e2e.yml"
push:
branches: [main]
workflow_dispatch:
jobs:
init-native:
runs-on: ${{ matrix.os }}
timeout-minutes: 25
strategy:
fail-fast: false
matrix:
# Windows is excluded today: upstream `esaxx-rs` (transitively from
# `tokenizers`) and `ort-sys` (onnxruntime via `fastembed`) link
# with conflicting MSVC C runtime libraries (/MT vs /MD), so the
# Rust extension cannot build for `win_amd64` until the upstream
# CRT conflict is resolved. Re-add `windows-latest` once the wheel
# builds cleanly there. Tracked in the project plan; not a blocker
# for headroom-ai installs on Linux + macOS.
os: [ubuntu-latest, macos-latest]
target: [claude, codex, copilot, openclaw]
exclude:
# openclaw delegates to ``headroom wrap openclaw`` which needs a
# running OpenClaw CLI; it can't be shimmed cheaply, so it's
# covered by the bundled Docker e2e instead.
- target: openclaw
steps:
- uses: actions/checkout@v6
- name: Setup (shim=${{ matrix.target }})
uses: ./.github/actions/headroom-e2e-setup
with:
python-version: "3.11"
shim-target: ${{ matrix.target }}
- name: Verify shim is on PATH (POSIX)
if: runner.os != 'Windows'
shell: bash
run: |
which "${{ matrix.target }}"
- name: Verify shim is on PATH (Windows)
if: runner.os == 'Windows'
shell: pwsh
run: |
# On Windows the shim is ``<target>.cmd``; Get-Command resolves via
# PATHEXT (same as Python's ``shutil.which`` used by headroom init).
# Git Bash's ``which`` cannot find ``.cmd`` shims, so we use pwsh.
$cmd = Get-Command "${{ matrix.target }}" -ErrorAction Stop
Write-Output $cmd.Source
- name: Run headroom init -g ${{ matrix.target }}
shell: bash
run: |
set -euo pipefail
headroom init -g "${{ matrix.target }}"
- name: Assert settings file (POSIX)
if: runner.os != 'Windows'
shell: bash
run: |
set -euo pipefail
case "${{ matrix.target }}" in
claude)
test -f "$HOME/.claude/settings.json"
grep -q "ANTHROPIC_BASE_URL" "$HOME/.claude/settings.json"
;;
codex)
test -f "$HOME/.codex/config.toml"
test -f "$HOME/.codex/hooks.json"
grep -q "headroom" "$HOME/.codex/config.toml"
;;
copilot)
test -f "$HOME/.copilot/config.json"
grep -q "SessionStart" "$HOME/.copilot/config.json"
;;
esac
- name: Assert settings file (Windows)
if: runner.os == 'Windows'
shell: pwsh
run: |
$ErrorActionPreference = "Stop"
$home_ = $env:USERPROFILE
switch ("${{ matrix.target }}") {
"claude" {
$p = Join-Path $home_ ".claude\settings.json"
if (-not (Test-Path $p)) { throw "Missing $p" }
if (-not ((Get-Content $p -Raw) -match "ANTHROPIC_BASE_URL")) {
throw "settings.json missing ANTHROPIC_BASE_URL"
}
}
"codex" {
$c = Join-Path $home_ ".codex\config.toml"
$h = Join-Path $home_ ".codex\hooks.json"
if (-not (Test-Path $c)) { throw "Missing $c" }
if (-not (Test-Path $h)) { throw "Missing $h" }
if (-not ((Get-Content $c -Raw) -match "headroom")) {
throw "config.toml missing headroom provider"
}
}
"copilot" {
$p = Join-Path $home_ ".copilot\config.json"
if (-not (Test-Path $p)) { throw "Missing $p" }
if (-not ((Get-Content $p -Raw) -match "SessionStart")) {
throw "copilot config missing SessionStart hooks"
}
}
}