Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
55 changes: 30 additions & 25 deletions .github/workflows/testnet-nightly.yml
Original file line number Diff line number Diff line change
Expand Up @@ -4,8 +4,10 @@ name: Testnet Nightly
#
# The suites this drives are implemented and live in the repo:
# * forge-web/e2e/ — Playwright: read paths, fallback browse, zero-backend, a11y
# * e2e/cli/run.sh — 7 CLI scenarios: clone/push round-trip, non-ff, ref delete,
# frozen push, no-token push, third-party verify, depth+filter
# * e2e/cli/run.sh — 8 CLI scenarios on devnet moutai (forge-v2): clone/push
# round-trip, non-ff, ref delete, revoked-writer push, non-member
# push, third-party verify, depth+filter; plus a testnet v1
# read-compat clone
#
# They split by what they need:
# * READ-ONLY specs need only a network path to testnet DAPI and the read fixture repo
Expand All @@ -17,13 +19,15 @@ name: Testnet Nightly
# green job with everything gated out — a distinction any badge or alert rule can see.
#
# Fixture identity secrets (e2e/cli/config.sh names the roles):
# FORGE_TEST_IDENTITY_DEPLOYER - owns the CLI suite's repo and the read fixture, grants
# tokens (which repo each suite may write: e2e/README.md)
# FORGE_TEST_IDENTITY_COLLAB - holds an unfrozen WRITE token
# FORGE_TEST_IDENTITY_CONTRIB - holds no token (negative push case)
# FORGE_TEST_IDENTITY_FROZEN - holds a frozen WRITE token (negative push case)
# FORGE_MOUTAI_IDENTITY_OWNER - owns the forge-v2 e2e-cli repo, adds/removes members
# FORGE_MOUTAI_IDENTITY_COLLAB - added as a writer, then removed (scenario 04)
# FORGE_MOUTAI_IDENTITY_CONTRIB - never a member (scenario 05)
# FORGE_TEST_IDENTITY_CONTRIB - any testnet identity, for the v1 read-compat clone (08)
# FORGE_TEST_IDENTITY_DEPLOYER - testnet: owns the browser specs' read fixture (v1),
# verified by the seed job
# Each holds the bridge-format identity JSON that `dg` reads from
# ~/.config/dash-forge/test-identities/<ROLE>.identity.json.
# ~/.config/dash-forge/test-identities/devnet-moutai/<ROLE>.identity.json (moutai) or
# ~/.config/dash-forge/test-identities/<ROLE>.identity.json (testnet).

on:
workflow_dispatch:
Expand Down Expand Up @@ -89,10 +93,11 @@ jobs:
- name: Probe
id: probe
env:
FORGE_TEST_IDENTITY_DEPLOYER: ${{ secrets.FORGE_TEST_IDENTITY_DEPLOYER }}
FORGE_TEST_IDENTITY_COLLAB: ${{ secrets.FORGE_TEST_IDENTITY_COLLAB }}
FORGE_MOUTAI_IDENTITY_OWNER: ${{ secrets.FORGE_MOUTAI_IDENTITY_OWNER }}
FORGE_MOUTAI_IDENTITY_COLLAB: ${{ secrets.FORGE_MOUTAI_IDENTITY_COLLAB }}
FORGE_MOUTAI_IDENTITY_CONTRIB: ${{ secrets.FORGE_MOUTAI_IDENTITY_CONTRIB }}
FORGE_TEST_IDENTITY_CONTRIB: ${{ secrets.FORGE_TEST_IDENTITY_CONTRIB }}
FORGE_TEST_IDENTITY_FROZEN: ${{ secrets.FORGE_TEST_IDENTITY_FROZEN }}
FORGE_TEST_IDENTITY_DEPLOYER: ${{ secrets.FORGE_TEST_IDENTITY_DEPLOYER }}
run: |
if [ -n "$FORGE_TEST_IDENTITY_DEPLOYER" ]; then
echo "deployer=true" >> "$GITHUB_OUTPUT"
Expand All @@ -101,8 +106,8 @@ jobs:
fi
missing=()
# Report the SECRET names an operator has to create, not internal aliases.
for name in FORGE_TEST_IDENTITY_DEPLOYER FORGE_TEST_IDENTITY_COLLAB \
FORGE_TEST_IDENTITY_CONTRIB FORGE_TEST_IDENTITY_FROZEN; do
for name in FORGE_MOUTAI_IDENTITY_OWNER FORGE_MOUTAI_IDENTITY_COLLAB \
FORGE_MOUTAI_IDENTITY_CONTRIB FORGE_TEST_IDENTITY_CONTRIB; do
[ -z "${!name}" ] && missing+=("$name")
done
if [ "${#missing[@]}" -ne 0 ]; then
Expand All @@ -112,7 +117,7 @@ jobs:
echo
echo "Missing repository secrets: \`${missing[*]}\`."
echo
echo "These identities must exist and be funded on testnet for the CLI suite"
echo "These identities must exist and be funded (moutai; testnet for 08) for the CLI suite"
echo "to run. The suite job below reports SKIPPED — it is **not** a passing"
echo "run. See \`e2e/cli/config.sh\` for the role pool and"
echo "\`docs/testing/e2e-test-plan.md\` for provisioning."
Expand Down Expand Up @@ -163,17 +168,17 @@ jobs:
run: bash e2e/cli/seed-read-fixture.sh

cli-suite:
name: cli e2e (live testnet)
name: cli e2e (live devnet moutai)
needs: fixtures
if: needs.fixtures.outputs.present == 'true'
runs-on: ubuntu-latest
# checkout + protoc + toolchain + cache (~3 min), build (≤30), suite (≤45).
timeout-minutes: 85
env:
ID_DEPLOYER_JSON: ${{ secrets.FORGE_TEST_IDENTITY_DEPLOYER }}
ID_COLLAB_JSON: ${{ secrets.FORGE_TEST_IDENTITY_COLLAB }}
ID_CONTRIB_JSON: ${{ secrets.FORGE_TEST_IDENTITY_CONTRIB }}
ID_FROZEN_JSON: ${{ secrets.FORGE_TEST_IDENTITY_FROZEN }}
ID_OWNER_JSON: ${{ secrets.FORGE_MOUTAI_IDENTITY_OWNER }}
ID_COLLAB_JSON: ${{ secrets.FORGE_MOUTAI_IDENTITY_COLLAB }}
ID_CONTRIB_JSON: ${{ secrets.FORGE_MOUTAI_IDENTITY_CONTRIB }}
ID_TESTNET_JSON: ${{ secrets.FORGE_TEST_IDENTITY_CONTRIB }}
steps:
- uses: actions/checkout@v5

Expand All @@ -200,12 +205,12 @@ jobs:
- name: Materialize fixture identities
run: |
dir="${HOME}/.config/dash-forge/test-identities"
mkdir -p "$dir" && chmod 700 "$dir"
printf '%s' "$ID_DEPLOYER_JSON" > "$dir/DEPLOYER.identity.json"
printf '%s' "$ID_COLLAB_JSON" > "$dir/COLLAB.identity.json"
printf '%s' "$ID_CONTRIB_JSON" > "$dir/CONTRIB.identity.json"
printf '%s' "$ID_FROZEN_JSON" > "$dir/FROZEN.identity.json"
chmod 600 "$dir"/*.identity.json
mkdir -p "$dir/devnet-moutai" && chmod 700 "$dir" "$dir/devnet-moutai"
printf '%s' "$ID_OWNER_JSON" > "$dir/devnet-moutai/OWNER.identity.json"
printf '%s' "$ID_COLLAB_JSON" > "$dir/devnet-moutai/COLLAB.identity.json"
printf '%s' "$ID_CONTRIB_JSON" > "$dir/devnet-moutai/CONTRIB.identity.json"
printf '%s' "$ID_TESTNET_JSON" > "$dir/CONTRIB.identity.json"
chmod 600 "$dir"/*.identity.json "$dir"/devnet-moutai/*.identity.json

# Built in its own step so a slow (cache-miss) build cannot eat into the suite's time
# budget below; run.sh picks the binaries up from target/debug.
Expand Down
7 changes: 4 additions & 3 deletions Makefile
Original file line number Diff line number Diff line change
Expand Up @@ -54,7 +54,8 @@ infra-up:
infra-down:
docker compose -f $(COMPOSE_FILE) down -v

## e2e: run the CLI end-to-end suite (LIVE testnet) against its reserved repo (e2e/README.md).
## e2e: run the CLI end-to-end suite (LIVE devnet moutai, forge-v2; scenario 08 reads a
## testnet v1 repo) against the OWNER-owned e2e-cli repo (created on first run).
## Builds the binaries if needed, then drives real git push/clone through the
## dash:// helper. See e2e/cli/README-less run.sh header for env knobs
## (RUN_ID, E2E_TIMEOUT, E2E_NO_CLEANUP, subset args). Exits non-zero on any FAIL.
Expand Down Expand Up @@ -110,8 +111,8 @@ storage-it: infra-up
FORGE_IT_S3=1 FORGE_IT_IPFS=1 cargo test -p forge-core --lib -- backends::live_tests storage::

## storage-e2e: a REAL `git push` / `git clone` through git-remote-dash with packs stored
## on local MinIO + kubo and only the manifest + ref on testnet, against the dedicated
## storage-e2e-a / storage-e2e-b repos (e2e/README.md; created once, ~1.18 tDASH each).
## on local MinIO + kubo and only the manifest + ref on devnet moutai, against the
## dedicated storage-e2e-a / storage-e2e-b repos (e2e/README.md; ~0.001 DASH each, once).
## Builds the helper with the `test-hooks` fault-injection feature. Opt-in.
storage-e2e: infra-up
cargo build -p dg
Expand Down
Loading
Loading