diff --git a/.github/workflows/build-zuban.yml b/.github/workflows/build-zuban.yml new file mode 100644 index 000000000..34200644d --- /dev/null +++ b/.github/workflows/build-zuban.yml @@ -0,0 +1,156 @@ +# SPDX-FileCopyrightText: 2026 The RISE Project +# SPDX-License-Identifier: MIT +--- +# This workflow is based on the `build` job of +# https://github.com/zubanls/zuban/blob/v0.9.3/.github/workflows/wheels.yml +name: Build zuban wheels (riscv64) + +on: + workflow_dispatch: + inputs: + version: + description: 'zuban version to build (git tag without the leading v, e.g. 0.9.3)' + required: true + default: '0.9.3' + pull_request: + paths: + - '.github/workflows/build-zuban.yml' + +concurrency: + group: ${{ github.workflow }}-${{ inputs.version || '0.9.3' }}-${{ github.head_ref || github.run_id }} + cancel-in-progress: true + +permissions: + contents: read # to fetch code (actions/checkout) + +env: + # `inputs.version` is empty on pull_request events; default to 0.9.3 there. + ZUBAN_VERSION: ${{ inputs.version || '0.9.3' }} + +jobs: + setup: + uses: $/.github/workflows/_setup.yml + + build_wheel: + needs: [setup] + name: Build zuban ${{ inputs.version || '0.9.3' }} manylinux_riscv64 + runs-on: ubuntu-24.04-riscv + timeout-minutes: 360 + + steps: + - name: Checkout zuban v${{ env.ZUBAN_VERSION }} + uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 + with: + repository: zubanls/zuban + ref: v${{ env.ZUBAN_VERSION }} + submodules: recursive + persist-credentials: false + + # `[tool.maturin] license-files = ["licenses.html"]` in + # deploy/pypi/zuban/pyproject.toml requires this file to exist before + # maturin builds; upstream's own pre-maturin-build.sh generates it the + # same way. The riscv64 runner ships no Rust toolchain (unlike + # upstream's GitHub-hosted runners), so install one first. + - uses: dtolnay/rust-toolchain@6c977a6ca4077a0ceb28ffbe03f59d46e9ac8772 # master + with: + toolchain: stable + + - name: Generate third-party licenses.html + working-directory: deploy/pypi/zuban + run: | + cargo install --features cli --locked --debug cargo-about --version 0.9.0 + cargo about generate -o licenses.html about.hbs --fail --manifest-path ../../../Cargo.toml + + - name: Build wheel + uses: PyO3/maturin-action@e83996d129638aa358a18fbd1dfb82f0b0fb5d3b # v1.51.0 + with: + command: build + target: riscv64gc-unknown-linux-gnu + working-directory: deploy/pypi/zuban + args: --release --locked --out dist --ignore-rust-version + manylinux: '2_39' + before-script-linux: git config --global --add safe.directory "*" + + - uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1 + with: + name: zuban-${{ env.ZUBAN_VERSION }}-manylinux_riscv64 + path: deploy/pypi/zuban/dist/*.whl + if-no-files-found: error + + test_wheel: + name: Test zuban ${{ inputs.version || '0.9.3' }} on Python ${{ matrix.python-version }} + needs: [setup, build_wheel] + runs-on: ubuntu-24.04-riscv + timeout-minutes: 30 + env: + # Without this uv would reuse the runner image's system CPython for 3.12 + # and download a standalone build for the others. + UV_PYTHON_PREFERENCE: only-managed + strategy: + fail-fast: false + matrix: + # This repo's default interpreter matrix (gotcha in workflow-anatomy.md); + # the wheel is interpreter-agnostic (bindings = "bin"), so every + # interpreter -- including free-threaded -- exercises the same binary. + python-version: ['3.12', '3.13', '3.14', '3.14t'] + + steps: + - name: Download wheel + uses: actions/download-artifact@3e5f45b2cfb9172054b4087a40e8e0b5a5461e7c # v8.0.1 + with: + name: zuban-${{ env.ZUBAN_VERSION }}-manylinux_riscv64 + + - name: Install Python + uses: astral-sh/setup-uv@20cfd1bf945f4377ade1205e4dbc17946fc9a30d # v10.0.1 + with: + python-version: ${{ matrix.python-version }} + activate-environment: true + enable-cache: false + + - name: Install wheel + run: uv pip install --reinstall --no-index --find-links . zuban + + # No `python -m zuban` (gotcha 224): zuban/__init__.py deliberately + # raises, so only the installed console scripts are usable. `zuban + # check` exercises the bundled typeshed stubs (submodule checkout), not + # just process startup; `zmypy` execs `zuban mypy` via a sibling-path + # lookup, so it also proves both console scripts installed together. + - name: Test wheel + run: | + set -euo pipefail + zuban --help >/dev/null + zmypy --version + + work=$(mktemp -d) + cat > "$work/bad.py" <<'PY' + def add(a: int, b: int) -> int: + return a + b + + add("1", "2") + PY + + set +e + out=$(zuban check "$work/bad.py" 2>&1) + rc=$? + set -e + echo "$out" + [ "$rc" -ne 0 ] + echo "$out" | grep -qi 'error' + + cat > "$work/good.py" <<'PY' + def add(a: int, b: int) -> int: + return a + b + + add(1, 2) + PY + zuban check "$work/good.py" + + publish: + name: Publish zuban ${{ inputs.version || '0.9.3' }} + needs: [setup, build_wheel, test_wheel] + permissions: + contents: write + pull-requests: write + uses: $/.github/workflows/_publish-wheel.yml + with: + artifact-pattern: zuban-${{ inputs.version || '0.9.3' }}-manylinux_riscv64