Skip to content

Forge CI: ci, release and deploy-website workflows (.ultimator/) - #108

Merged
pcarrier merged 3 commits into
mainfrom
forge/p3-workflows
Oct 9, 2026
Merged

pcarrier merged 3 commits into
mainfrom
forge/p3-workflows

Conversation

@pcarrier

@pcarrier pcarrier commented Oct 9, 2026 •

Copy link
Copy Markdown
Collaborator

Forge P3 (design m5weenadk7pdbxgx §10). This adds YAS's workflows in Forge's CI format. The GitHub workflows stay as they are and keep running until Forge's P4.

What it adds (.ultimator/)

actions/nix

Replaces DeterminateSystems/nix-installer-action and magic-nix-cache-action, which are Marketplace actions Forge doesn't run.

  • It keeps a machine's own Nix (crab).
  • Otherwise it installs Nix with Determinate's installer and turns on flakes.
  • There's no binary cache beyond cache.nixos.org, so a fresh sandbox's first build is cold.

actions/packages and actions/windows-x64

GitHub's reusable _build-packages.yml and _build-windows.yml become composite actions: Forge has no reusable workflows.

Windows x86_64 builds on crab-win (Windows 11 ARM64) under x64 emulation:

  • It uses the stable-x86_64-pc-windows-msvc toolchain (--force-non-host) and checks that yas.exe's PE machine is x86_64.
  • crab-win needs Visual Studio's x64/x86 build tools; the job says so if they're missing.
  • The job installs wasm-pack, pnpm 10 and bun 1.3.13 itself.

workflows/ci.yml

The same jobs as GitHub's:

  • Nix syntax, lint and publication plan, package-crates, tests, a 60 s fuzz;
  • e2e, with the Playwright report kept as an artifact;
  • coverage, with its summary in the job summary (there's no sticky PR comment);
  • packages on sandbox (linux-x86_64), arm64-ci (linux-aarch64) and crab (macos-aarch64, with the macOS graph tests);
  • Windows on crab-win.

workflows/release.yml

On v* tags.

  • Signature: it verifies the tag's SSH signature with git verify-tag against YAS_TAG_SIGNERS, an allowed_signers line. That replaces GitHub's "verified identity" check. Without it, or for an unsigned tag, the release stops.
    • YAS_TAG_SIGNERS is a sealed secret only because Forge has no repository variables yet, and admins alone set secrets.
  • Gates and builds: lint, tests, e2e, coverage, packages, Windows, extensions, and three one-hour fuzz campaigns.
  • Release artifact: release-<tag> with the stable asset names and SHA256SUMS, kept 400 days. P4 gives releases a home on Forge.
  • Publishing:
    • crates.io with CARGO_REGISTRY_TOKEN;
    • npm packages and binary packages with a granular NPM_TOKEN, written to the job's npmrc.
    • --provenance is dropped: it needs GitHub's OIDC.

workflows/deploy-website.yml

nix run .#deploy-website with FLY_API_TOKEN, on the same paths as GitHub's workflow.

Evidence

ultimator ci check .ultimator, built from xmit-dev/ultimator forge/p3-store, reads and plans every file with no errors:

  • ci.yml: 11 jobs;
  • release.yml: 17 jobs;
  • deploy-website.yml: 1 job;
  • three composite actions.

The jobs run on sandbox, arm64-ci, crab and crab-win.

Not run yet. That needs Pierre's steps:

  • YAS hosted on Forge, with the ci module on;
  • executors for those labels;
  • the secrets:
    • on refs/tags/v*: CARGO_REGISTRY_TOKEN, NPM_TOKEN and YAS_TAG_SIGNERS;
    • on main: FLY_API_TOKEN;
  • protections on main and refs/tags/v*, so those runs are trusted.

…ted from GitHub's

Linux jobs in sandboxes with Nix (./.ultimator/actions/nix), packages also on arm64-ci and crab, Windows x86_64 on
crab-win under emulation (./.ultimator/actions/windows-x64); the reusable workflows become composite actions. The
release verifies the tag's SSH signature against vars.YAS_TAG_SIGNERS, keeps a release-<tag> artifact with
SHA256SUMS, and publishes with CARGO_REGISTRY_TOKEN and NPM_TOKEN. GitHub's workflows stay until Forge's P4.

@ultimator-agent ultimator-agent Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Ultimator's review of 09d389b

Adds Forge CI workflows under .ultimator/ (ci, release, deploy-website) and three composite actions (nix, packages, windows-x64), ported from the existing GitHub workflows. I found no defects in the diff itself. The x86_64 PE-machine check (6486), job dependencies, secret scoping and artifact names are consistent. I couldn't run the workflows or read the scripts they call (bin/coverage, bin/publish-npm-packages and similar), and the PR says the workflows haven't run yet.

No issues found.

Reviewed in 43s · Session · @ultimator-agent review reviews again · @ultimator-agent fix fixes the open issues

@ultimator-agent ultimator-agent Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Ultimator's review of 09d389b

The new commit only changes where the tag signers come from: the YAS_TAG_SIGNERS secret instead of a repository variable. The secrets. reference, error message, header comment and PR description all agree. Nothing new to report.

No issues found.

Reviewed in 9s · Session · @ultimator-agent review reviews again · @ultimator-agent fix fixes the open issues

@ultimator-agent ultimator-agent Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Ultimator's review of 6957cd5

The new commit only reformats the release job's needs list across lines. The list is the same eight jobs, so behavior is unchanged. Nothing new to report.

No issues found.

Reviewed in 8s · Session · @ultimator-agent review reviews again · @ultimator-agent fix fixes the open issues

@github-actions

github-actions Bot commented Oct 9, 2026 •

Copy link
Copy Markdown

Coverage

Crate Lines Functions Regions
alacritty-driver 85.6% (1081/1263) 89.4% (84/94) 89.3% (1746/1955)
browser 25.5% (309/1212) 30.4% (34/112) 27.7% (605/2183)
cli 33.3% (6497/19523) 35.2% (611/1738) 34.4% (9644/28024)
client 68.3% (5806/8497) 68.5% (708/1033) 66.5% (7533/11331)
composite-transport 96.3% (526/546) 98.4% (60/61) 96.2% (884/919)
compositor 55.0% (11454/20820) 66.2% (837/1265) 54.9% (15867/28909)
desktop 78.4% (4460/5691) 71.6% (393/549) 75.1% (6211/8267)
edge 62.9% (798/1268) 50.9% (82/161) 57.7% (1038/1799)
fonts 77.3% (1257/1626) 82.7% (129/156) 78.9% (2424/3071)
fssync 85.5% (1601/1872) 85.4% (181/212) 86.7% (2821/3255)
git 70.5% (4472/6344) 68.5% (337/492) 67.3% (6332/9407)
guest 67.3% (6829/10148) 67.0% (488/728) 66.6% (8935/13416)
lsp 78.7% (3573/4542) 80.8% (336/416) 76.7% (5409/7054)
proxy 63.1% (1902/3012) 56.3% (184/327) 63.4% (2931/4626)
runtime-dir 93.6% (117/125) 100.0% (14/14) 94.8% (218/230)
sd-notify 73.9% (68/92) 100.0% (6/6) 83.2% (109/131)
server 71.0% (85349/120159) 73.6% (6198/8420) 69.0% (114440/165745)
ssh 67.2% (708/1054) 75.9% (85/112) 67.2% (1105/1645)
terminal-model 49.9% (314/629) 62.3% (38/61) 50.3% (505/1004)
uplink 94.2% (582/618) 92.6% (50/54) 93.1% (1062/1141)
webrtc-forwarder 33.6% (1321/3932) 44.9% (146/325) 36.0% (2279/6336)
webserver 80.7% (1490/1846) 81.1% (193/238) 83.2% (2551/3067)
website 35.1% (355/1012) 34.4% (53/154) 35.8% (607/1694)
xtask 0.0% (0/5149) 0.0% (0/131) 0.0% (0/9157)
yas 88.9% (28014/31522) 93.9% (2147/2286) 84.0% (44003/52388)
Total 66.9% (168883/252502) 70.0% (13394/19145) 65.2% (239259/366754)

@pcarrier
pcarrier merged commit 303b267 into main Oct 9, 2026
11 checks passed
@pcarrier
pcarrier deleted the forge/p3-workflows branch October 9, 2026 18:27
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant