perf(blockchain): bound attestation ancestry walks by fork depth (#610) #37
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
| name: CI | |
| on: | |
| push: | |
| branches: [main] | |
| pull_request: | |
| branches: ["**"] | |
| merge_group: | |
| workflow_dispatch: | |
| # Cancel in-progress runs when a new commit is pushed to the same PR or branch | |
| concurrency: | |
| group: ${{ github.workflow }}-${{ github.head_ref || github.run_id }} | |
| cancel-in-progress: true | |
| env: | |
| CARGO_NET_GIT_FETCH_WITH_CLI: "true" | |
| CARGO_NET_RETRY: "10" | |
| jobs: | |
| lint: | |
| name: Lint | |
| runs-on: ubuntu-latest | |
| steps: | |
| - uses: actions/checkout@v6 | |
| - name: Setup Rust | |
| uses: dtolnay/rust-toolchain@master | |
| with: | |
| toolchain: "1.97.1" | |
| components: rustfmt, clippy | |
| - name: Setup cache | |
| # Tools under tooling/ are separate Cargo workspaces with their own | |
| # target dir and Cargo.lock, so they need listing explicitly or their | |
| # builds are neither cached nor reflected in the cache key. | |
| uses: Swatinem/rust-cache@v2 | |
| with: | |
| workspaces: | | |
| . | |
| tooling/event-monitor | |
| - name: Check formatting | |
| run: cargo fmt --all -- --check | |
| - name: Cargo check | |
| run: cargo check --locked --workspace --all-targets | |
| - name: Clippy | |
| run: cargo clippy --locked --workspace --all-targets -- -D warnings | |
| # tooling/event-monitor declares its own [workspace] table, so every step | |
| # above stops at the root workspace members and never reaches it. Its | |
| # tests run in this job rather than in `test` because clippy has already | |
| # compiled the test targets, and because they need none of that job's | |
| # leanSpec fixtures. | |
| # `--locked` so the committed Cargo.lock is actually enforced: without it | |
| # cargo silently resolves and rewrites the lockfile in CI, and a stale or | |
| # missing entry never fails the build. | |
| - name: Lint tooling | |
| working-directory: tooling/event-monitor | |
| run: | | |
| cargo fmt --all -- --check | |
| cargo clippy --locked --all-targets -- -D warnings | |
| - name: Test tooling | |
| working-directory: tooling/event-monitor | |
| run: cargo test --locked | |
| test: | |
| name: Test | |
| runs-on: ubuntu-latest | |
| steps: | |
| - uses: actions/checkout@v6 | |
| - name: Run fixture-based tests | |
| uses: ./.github/actions/run-fixture-tests | |
| # Reuses the release build from the test step; validates the benchmark | |
| # harness end-to-end and its JSON output contract in a few seconds. | |
| - name: Benchmark smoke (mock crypto) | |
| run: | | |
| cargo run --locked --profile release-fast --bin ethlambda -- benchmark synthetic --mock-crypto \ | |
| --num-validators 4 --warmup-slots 4 --iterations 3 --format json \ | |
| | jq -e '.schema_version == 1 and (.samples | length == 3)' | |
| # Stable cargo ignores the publish-age cooldown in .cargo/config.toml, so the | |
| # lockfile can pin too-young crates. Fail the build when either lockfile does. | |
| # Infrastructure failures (toolchain download, a resolution that fails for | |
| # reasons unrelated to age, e.g. a yanked upstream crate) only warn: they are | |
| # outside the PR's control and would block every PR. | |
| cooldown: | |
| name: Dependency cooldown | |
| runs-on: ubuntu-latest | |
| steps: | |
| - uses: actions/checkout@v6 | |
| - name: Check lockfiles against the publish-age cooldown | |
| run: | | |
| if ! rustup toolchain install nightly-2026-06-21 --profile minimal; then | |
| echo "::warning title=Publish-age cooldown check skipped::toolchain install failed" | |
| exit 0 | |
| fi | |
| status=0 | |
| for manifest in Cargo.toml tooling/event-monitor/Cargo.toml; do | |
| if ! cargo +nightly-2026-06-21 update --dry-run -Z min-publish-age --manifest-path "$manifest" > cooldown.txt 2>&1; then | |
| # Drop the index/git refresh chatter so the excerpt is the actual error; %0A = newline in annotations | |
| msg=$(grep -v '^ *Updating ' cooldown.txt | head -20 | sed ':a;N;$!ba;s/\n/%0A/g') | |
| echo "::warning title=Publish-age cooldown probe failed for $manifest::$msg" | |
| continue | |
| fi | |
| # A cooldown-driven downgrade is annotated with the too-young version's | |
| # publish date; downgrades for other reasons (MSRV, a tightened | |
| # requirement) carry no such note and are not this check's business. | |
| hits=$(grep -E '^ *Downgrading .*published' cooldown.txt || true) | |
| if [ -n "$hits" ]; then | |
| count=$(echo "$hits" | wc -l | tr -d ' ') | |
| msg=$(echo "$hits" | head -20 | sed ':a;N;$!ba;s/\n/%0A/g') | |
| echo "::error title=$manifest pins $count crate(s) younger than the publish-age cooldown::$msg" | |
| status=1 | |
| fi | |
| done | |
| exit $status |