Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
The table of contents is too big for display.
Diff view
Diff view
  •  
  •  
  •  
130 changes: 110 additions & 20 deletions .github/workflows/ci.yml
Original file line number Diff line number Diff line change
Expand Up @@ -13,6 +13,7 @@ on:
- conductor/reporting-receipt-ingress-b22
- conductor/reporting-frozen-account-feed-b23
- conductor/reporting-schema-proof-receipt-diagnostics-hardening
- conductor/reporting-production-tier-capabilities-b24

# Default @adcp/sdk runner alias for storyboard jobs. Tracks the current
# stable @adcp/sdk release via the ``latest`` npm dist-tag.
Expand Down Expand Up @@ -205,6 +206,7 @@ jobs:
--ignore-glob='tests/conformance/reporting/test_reporting_projection*.py' \
--ignore=tests/conformance/reporting/test_reporting_tier_projection.py \
--ignore=tests/conformance/reporting/test_reporting_schedule_schema.py \
--ignore=tests/conformance/reporting/test_reporting_rc6_rolling.py \
-v -ra
;;
process)
Expand Down Expand Up @@ -435,14 +437,19 @@ jobs:
path: pg-reporting-receipts-evidence.log
if-no-files-found: error

pg-reporting-receipt-compatibility:
name: Receipt rolling compatibility (eight actual artifacts)
pg-reporting-receipt-compatibility-shard:
name: Receipt rolling shard (${{ matrix.artifact }})
runs-on: ubuntu-latest
# Separate databases avoid shared account advisory locks. Keep five minutes
# outside the bounded suite for checkout, installations and cleanup.
timeout-minutes: 35
permissions:
contents: read
strategy:
fail-fast: false
matrix:
artifact: [beta15, records, integration, a, b, c, b1, b21]
env:
RECEIPT_ARTIFACT: ${{ matrix.artifact }}
RECEIPT_SOURCE_HEAD: ${{ github.event.pull_request.head.sha || github.sha }}
services:
postgres:
image: postgres:16
Expand All @@ -457,7 +464,43 @@ jobs:
--health-timeout 5s
--health-retries 10
steps:
- uses: actions/checkout@v6
# runner.temp survives checkout cleanup. Setup failures still identify the
# attempted shard; an incomplete artifact can never satisfy the aggregate.
- name: Record attempted shard identity before checkout
timeout-minutes: 1
shell: bash
run: |
python3 - <<'PYTHON'
import json
import os
import re
from pathlib import Path
root = Path(os.environ["RUNNER_TEMP"]) / "receipt-rolling-evidence"
root.mkdir(mode=0o700)
fields = {
"source_head": "RECEIPT_SOURCE_HEAD", "event_sha": "GITHUB_SHA",
"event_name": "GITHUB_EVENT_NAME", "run_id": "GITHUB_RUN_ID",
"run_attempt": "GITHUB_RUN_ATTEMPT", "repository": "GITHUB_REPOSITORY",
"artifact": "RECEIPT_ARTIFACT",
}
values = {key: os.environ[value] for key, value in fields.items()}
valid = (
all(re.fullmatch(r"[0-9a-f]{40}", values[k]) for k in ("source_head", "event_sha"))
and all(re.fullmatch(r"[1-9][0-9]{0,19}", values[k]) for k in ("run_id", "run_attempt"))
and values["repository"] == "adcontextprotocol/adcp-client-python"
and values["event_name"] in {"pull_request", "push"}
and values["artifact"] in {"beta15", "records", "integration", "a", "b", "c", "b1", "b21"}
and (values["event_name"] != "push" or values["source_head"] == values["event_sha"])
)
if not valid:
raise SystemExit("invalid shard attempt identity")
(root / "attempted.json").write_text(json.dumps(values) + "\n")
PYTHON
- uses: actions/checkout@d23441a48e516b6c34aea4fa41551a30e30af803 # v6.1.0
timeout-minutes: 2
with:
ref: ${{ env.RECEIPT_SOURCE_HEAD }}
persist-credentials: false
- name: Fetch all eight exact approved historical artifacts
timeout-minutes: 2
run: |
Expand All @@ -470,30 +513,72 @@ jobs:
967b6e286301d7e5d089aea6fdbb90bea8ee5a16 \
5487f2bdef23c5102118b305be9e868228f6ce61 \
3fd62121c96a074e3ea458c30c5224d6a586f169
- uses: actions/setup-python@v6
- uses: actions/setup-python@ece7cb06caefa5fff74198d8649806c4678c61a1 # v6
timeout-minutes: 2
with:
python-version: "3.12"
cache: pip
cache-dependency-path: pyproject.toml
- name: Install test dependencies
run: pip install -e ".[dev,pg]"
- name: Run all historical binaries against approved parent and receipt schema
- name: Install test and workflow-control dependencies
timeout-minutes: 5
run: pip install -e ".[dev,pg]" "PyYAML==6.0.3"
# The unchanged single node includes its notification branches and all
# builds/migrations/recovery. Inner timeout is 15m plus <=30s cleanup;
# all step ceilings total 33m, below this job's unchanged 35m ceiling.
- name: Verify collection and run one complete historical parameter
shell: bash
timeout-minutes: 30
timeout-minutes: 18
env:
ADCP_PG_TEST_URL: postgresql://postgres@localhost:5432/adcp_receipt_rolling_test
run: |
python scripts/reporting_test_harness.py pytest \
tests/conformance/reporting/test_reporting_receipt_rolling.py \
-v -s -ra | tee pg-reporting-receipt-compatibility-evidence.log
- name: Preserve commands, counts, installed provenance and skip reasons
timeout --signal=TERM --kill-after=5s 60s python -m unittest discover -s scripts -p test_receipt_rolling_ci.py -v
python scripts/receipt_rolling_ci.py run
- name: Preserve safe partial output and exact shard result
if: always()
uses: actions/upload-artifact@v7
timeout-minutes: 3
uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7
with:
name: pg-reporting-receipt-compatibility-evidence-${{ github.run_attempt }}
path: pg-reporting-receipt-compatibility-evidence.log
name: receipt-rolling-shard-${{ github.run_id }}-${{ github.run_attempt }}-${{ matrix.artifact }}
path: ${{ runner.temp }}/receipt-rolling-evidence/
if-no-files-found: error

pg-reporting-receipt-compatibility:
name: Receipt rolling compatibility (eight actual artifacts)
needs: pg-reporting-receipt-compatibility-shard
if: ${{ always() && !cancelled() }}
runs-on: ubuntu-latest
timeout-minutes: 8
permissions:
contents: read
actions: read
env:
RECEIPT_SOURCE_HEAD: ${{ github.event.pull_request.head.sha || github.sha }}
steps:
- uses: actions/checkout@d23441a48e516b6c34aea4fa41551a30e30af803 # v6.1.0
timeout-minutes: 2
with:
ref: ${{ env.RECEIPT_SOURCE_HEAD }}
persist-credentials: false
- name: Download this attempt's unmerged shard directories
id: shard-download
timeout-minutes: 3
uses: actions/download-artifact@3e5f45b2cfb9172054b4087a40e8e0b5a5461e7c # v8
with:
pattern: receipt-rolling-shard-${{ github.run_id }}-${{ github.run_attempt }}-*
path: receipt-rolling-aggregate
merge-multiple: false
digest-mismatch: error
# Hard job cancellation can prevent an always-upload step. Missing,
# incomplete, duplicate or mismatched evidence is deliberately fatal.
- name: Require every shard and verify exact run evidence
if: ${{ always() && !cancelled() }}
timeout-minutes: 2
env:
GH_TOKEN: ${{ github.token }}
RECEIPT_MATRIX_RESULT: ${{ needs.pg-reporting-receipt-compatibility-shard.result }}
RECEIPT_DOWNLOAD_RESULT: ${{ steps.shard-download.outcome }}
run: python scripts/receipt_rolling_ci.py aggregate

pg-reporting-feed:
name: Frozen authorized feed and mounted isolation (Postgres 16)
runs-on: ubuntu-latest
Expand Down Expand Up @@ -726,6 +811,7 @@ jobs:
tests/test_reporting_revision_ownership.py \
tests/test_reporting_production_public.py \
tests/test_schema_datetime_formats.py \
tests/test_rc6_adoption.py \
-v -s -ra | tee pg-reporting-production-evidence.log
- name: Preserve production contract evidence
if: always()
Expand Down Expand Up @@ -808,9 +894,9 @@ jobs:
--health-timeout 5s --health-retries 10
steps:
- uses: actions/checkout@v6
- name: Fetch integrated feed and hardening comparison artifacts
- name: Fetch integrated feed, hardening and production comparison artifacts
timeout-minutes: 1
run: git fetch --no-tags origin 2d777ace7b4bf8be519ce0abd4fd0a25ed4f1da7 e16eb8cf3074cabd45aab42840950f05ad6d2b43
run: git fetch --no-tags origin 2d777ace7b4bf8be519ce0abd4fd0a25ed4f1da7 e16eb8cf3074cabd45aab42840950f05ad6d2b43 34c8f6d929aeac3407e2f595104a8e903e572623
- uses: actions/setup-python@v6
id: production-python310
with:
Expand All @@ -832,6 +918,7 @@ jobs:
run: |
python scripts/reporting_test_harness.py pytest \
tests/conformance/reporting/test_reporting_production_rolling.py \
tests/conformance/reporting/test_reporting_rc6_rolling.py \
-v -s -ra | tee pg-reporting-production-rolling.log
- name: Preserve exact installed historical continuity and fence evidence
if: always()
Expand Down Expand Up @@ -948,7 +1035,10 @@ jobs:
for child in schema_root.iterdir()
if child.is_dir()
}
assert packaged_versions == {"2.5", "3.0", "3.1", current_bundle}
# Preserve explicit rc.3 and the frozen v32 (beta.6) schemas offline.
assert packaged_versions == {
"2.5", "3.0", "3.1", "3.2.0-beta.6", "3.2.0-rc.3", current_bundle
}
error_schema = json.loads(
(schema_root / current_bundle / "enums/error-code.json").read_text(encoding="utf-8")
)
Expand Down
2 changes: 1 addition & 1 deletion .github/workflows/pr-title-check.yml
Original file line number Diff line number Diff line change
Expand Up @@ -3,7 +3,7 @@ name: PR Title Check
on:
pull_request:
types: [opened, edited, synchronize, reopened]
branches: [main, conductor/1167b2-durable-managed-reporting, conductor/reporting-receipt-ingress-b22, conductor/reporting-frozen-account-feed-b23, conductor/reporting-schema-proof-receipt-diagnostics-hardening]
branches: [main, conductor/1167b2-durable-managed-reporting, conductor/reporting-receipt-ingress-b22, conductor/reporting-frozen-account-feed-b23, conductor/reporting-schema-proof-receipt-diagnostics-hardening, conductor/reporting-production-tier-capabilities-b24]

permissions:
contents: read
Expand Down
8 changes: 7 additions & 1 deletion MANIFEST.in
Original file line number Diff line number Diff line change
Expand Up @@ -4,13 +4,16 @@ include LICENSE
include MIGRATION*.md
recursive-include src/adcp py.typed
recursive-include src/adcp/reporting/materializer/assets *.json
recursive-include src/adcp/_compliance/3.2.0-rc.6 *.json *.jsonl *.yaml *.md
# Bundled AdCP JSON schemas. ``scripts/bundle_schemas.py`` mirrors
# ``schemas/cache/`` into ``src/adcp/_schemas/`` before ``python -m
# build`` so the validator ships with the wheel. Keep distributions on
# stable supported bundles; historical prerelease caches are dev-only.
# supported bundles, including historical v32's beta.6 and rc.3 continuations.
recursive-include src/adcp/_schemas/2.5 *.json
recursive-include src/adcp/_schemas/3.0 *.json
recursive-include src/adcp/_schemas/3.1 *.json
recursive-include src/adcp/_schemas/3.2.0-beta.6 *.json
recursive-include src/adcp/_schemas/3.2.0-rc.3 *.json
recursive-include src/adcp/_schemas/3.2.0-rc.6 *.json
prune src/adcp/_schemas/3.1.0-*
# A clean VCS source tree has no ignored ``src/adcp/_schemas`` directory.
Expand All @@ -19,4 +22,7 @@ prune src/adcp/_schemas/3.1.0-*
recursive-include schemas/cache/2.5 *.json
recursive-include schemas/cache/3.0 *.json
recursive-include schemas/cache/3.1 *.json
recursive-include schemas/cache/3.2.0-beta.6 *.json
recursive-include schemas/cache/3.2.0-rc.3 *.json
recursive-include schemas/cache/3.2.0-rc.6 *.json
recursive-include schemas/releases *.json
Loading
Loading