Skip to content

CI

CI #786

Workflow file for this run

name: CI
on:
push:
branches: [main]
pull_request:
branches: [main]
workflow_dispatch:
schedule:
- cron: "0 8 * * *"
env:
DOTNET_VERSION: "10.0.x"
DOTNET_NOLOGO: true
DOTNET_CLI_TELEMETRY_OPTOUT: true
NUGET_PACKAGES: ${{ github.workspace }}/.nuget/packages
FAST_BUILD_PROPERTIES: "-p:OpenClawSkipDashboardBuild=true"
concurrency:
group: ${{ github.workflow }}-${{ github.ref }}
cancel-in-progress: ${{ github.event_name == 'pull_request' }}
jobs:
go-whatsapp-security:
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0
- name: Setup Go
uses: actions/setup-go@924ae3a1cded613372ab5595356fb5720e22ba16
with:
go-version: "1.26.4"
cache-dependency-path: src/whatsapp-whatsmeow-worker/go.sum
- name: Check Go module tidiness
working-directory: src/whatsapp-whatsmeow-worker
run: |
go mod tidy
git diff --exit-code -- go.mod go.sum
- name: Test WhatsApp whatsmeow worker
working-directory: src/whatsapp-whatsmeow-worker
run: go test ./...
- name: Run govulncheck
working-directory: src/whatsapp-whatsmeow-worker
run: go run golang.org/x/vuln/cmd/govulncheck@v1.3.0 ./...
build-and-test:
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0
- name: Setup .NET
uses: actions/setup-dotnet@26b0ec14cb23fa6904739307f278c14f94c95bf1
with:
dotnet-version: ${{ env.DOTNET_VERSION }}
- name: Cache NuGet packages
uses: actions/cache@55cc8345863c7cc4c66a329aec7e433d2d1c52a9
with:
path: ${{ env.NUGET_PACKAGES }}
key: nuget-${{ runner.os }}-${{ hashFiles('OpenClaw.Net.slnx', '**/*.csproj', '**/*.props', '**/*.targets') }}
restore-keys: |
nuget-${{ runner.os }}-
- name: Setup Node
uses: actions/setup-node@48b55a011bda9f5d6aeb4c2d9c7362e8dae4041e
with:
node-version: "20"
- name: Restore solution
run: dotnet restore OpenClaw.Net.slnx
- name: Build solution
run: dotnet build OpenClaw.Net.slnx --no-restore -c Release
- name: Test standard targets
run: dotnet test --no-build -c Release --verbosity normal --logger "trx;LogFileName=results.trx" src/OpenClaw.Tests
- name: HelloAgent smoke
run: dotnet run --project samples/OpenClaw.HelloAgent -c Release --no-build
- name: Restore sandbox-enabled solution
run: dotnet restore OpenClaw.Net.slnx -p:OpenClawEnableOpenSandbox=true
- name: Build sandbox-enabled solution
run: dotnet build OpenClaw.Net.slnx --no-restore -c Release -p:OpenClawEnableOpenSandbox=true
- name: Test sandbox-enabled targets
run: dotnet test --no-build -c Release -p:OpenClawEnableOpenSandbox=true --verbosity normal --logger "trx;LogFileName=results-sandbox.trx" src/OpenClaw.Tests
- name: Upload test results
if: always()
uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a
with:
name: test-results
path: "**/*.trx"
publish-aot:
needs: build-and-test
runs-on: ubuntu-latest
if: github.event_name != 'schedule'
steps:
- uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0
- name: Setup .NET
uses: actions/setup-dotnet@26b0ec14cb23fa6904739307f278c14f94c95bf1
with:
dotnet-version: ${{ env.DOTNET_VERSION }}
- name: Cache NuGet packages
uses: actions/cache@55cc8345863c7cc4c66a329aec7e433d2d1c52a9
with:
path: ${{ env.NUGET_PACKAGES }}
key: nuget-${{ runner.os }}-${{ hashFiles('OpenClaw.Net.slnx', '**/*.csproj', '**/*.props', '**/*.targets') }}
restore-keys: |
nuget-${{ runner.os }}-
- name: Ensure AOT prerequisites
timeout-minutes: 8
run: bash .github/scripts/install-nativeaot-prereqs.sh
- name: Publish and smoke-test standard NativeAOT binaries
run: |
chmod +x ./eng/verify-aot-smoke.sh
./eng/verify-aot-smoke.sh
- name: Publish and smoke-test MAF NativeAOT gateway
if: github.event_name != 'pull_request'
run: |
chmod +x ./eng/verify-aot-maf-smoke.sh
./eng/verify-aot-maf-smoke.sh
- name: Upload gateway artifact
if: github.event_name == 'push' && github.ref == 'refs/heads/main'
uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a
with:
name: gateway-aot-linux-x64
path: ./artifacts/aot/gateway/
- name: Upload CLI artifact
if: github.event_name == 'push' && github.ref == 'refs/heads/main'
uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a
with:
name: openclaw-cli-aot-linux-x64
path: ./artifacts/aot/cli/
macos-gateway-linker-probe:
needs: build-and-test
runs-on: macos-15
if: github.event_name == 'schedule' || github.event_name == 'workflow_dispatch'
timeout-minutes: 60
steps:
- uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0
- name: Setup .NET
uses: actions/setup-dotnet@26b0ec14cb23fa6904739307f278c14f94c95bf1
with:
dotnet-version: ${{ env.DOTNET_VERSION }}
- name: Cache NuGet packages
uses: actions/cache@55cc8345863c7cc4c66a329aec7e433d2d1c52a9
with:
path: ${{ env.NUGET_PACKAGES }}
key: nuget-${{ runner.os }}-${{ hashFiles('OpenClaw.Net.slnx', '**/*.csproj', '**/*.props', '**/*.targets') }}
restore-keys: |
nuget-${{ runner.os }}-
- name: Configure macOS Swift library path
shell: bash
run: |
set -euo pipefail
developer_dir="$(xcode-select -p)"
sdk_path="$(xcrun --sdk macosx --show-sdk-path)"
library_paths=()
for candidate in \
"/usr/lib/swift" \
"$developer_dir/Toolchains/XcodeDefault.xctoolchain/usr/lib/swift/macosx" \
"$sdk_path/usr/lib/swift"; do
if [[ -d "$candidate" ]]; then
library_paths+=("$candidate")
fi
done
if [[ -n "${LIBRARY_PATH:-}" ]]; then
library_paths+=("$LIBRARY_PATH")
fi
joined="$(IFS=:; echo "${library_paths[*]}")"
echo "LIBRARY_PATH=$joined" >> "$GITHUB_ENV"
echo "Using macOS Swift library paths: $joined"
- name: Probe gateway NativeAOT without classic linker
id: probe
continue-on-error: true
shell: bash
run: |
set -euo pipefail
mkdir -p artifacts/linker-probe
dotnet publish src/OpenClaw.Gateway/OpenClaw.Gateway.csproj \
-c Release \
-r osx-arm64 \
--self-contained true \
-p:PublishAot=true \
-p:OpenClawUseClassicMacLd=false \
-o artifacts/linker-probe/gateway \
2>&1 | tee artifacts/linker-probe/publish.log
- name: Report linker probe outcome
shell: bash
run: |
if [[ "${{ steps.probe.outcome }}" == "success" ]]; then
echo "::notice title=Gateway linked without classic linker::Remove the gateway OpenClawUseClassicMacLd default after validating release smoke coverage."
else
echo "::warning title=Gateway still needs classic linker::The no-classic-linker probe failed on macos-15; keep the scoped gateway fallback."
fi
- name: Upload linker probe log
if: always()
uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a
with:
name: macos-gateway-linker-probe
path: artifacts/linker-probe/
publish-jit:
needs: build-and-test
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0
- name: Setup .NET
uses: actions/setup-dotnet@26b0ec14cb23fa6904739307f278c14f94c95bf1
with:
dotnet-version: ${{ env.DOTNET_VERSION }}
- name: Cache NuGet packages
uses: actions/cache@55cc8345863c7cc4c66a329aec7e433d2d1c52a9
with:
path: ${{ env.NUGET_PACKAGES }}
key: nuget-${{ runner.os }}-${{ hashFiles('OpenClaw.Net.slnx', '**/*.csproj', '**/*.props', '**/*.targets') }}
restore-keys: |
nuget-${{ runner.os }}-
- name: Publish and smoke-test JIT binaries
run: |
chmod +x ./eng/verify-jit-smoke.sh
chmod +x ./eng/verify-jit-maf-smoke.sh
./eng/verify-jit-smoke.sh
./eng/verify-jit-maf-smoke.sh
- name: Upload gateway artifact
if: github.event_name == 'push' && github.ref == 'refs/heads/main'
uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a
with:
name: gateway-jit-linux-x64
path: ./artifacts/jit/gateway/
- name: Upload CLI artifact
if: github.event_name == 'push' && github.ref == 'refs/heads/main'
uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a
with:
name: openclaw-cli-jit-linux-x64
path: ./artifacts/jit/cli/
docker:
needs: build-and-test
runs-on: ubuntu-latest
if: github.event_name == 'push' && github.ref == 'refs/heads/main'
permissions:
packages: write
steps:
- uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0
- name: Set up Docker Buildx
uses: docker/setup-buildx-action@d7f5e7f509e45cec5c76c4d5afdd7de93d0b3df5
- name: Log in to GitHub Container Registry
uses: docker/login-action@650006c6eb7dba73a995cc03b0b2d7f5ca915bee
with:
registry: ghcr.io
username: ${{ github.actor }}
password: ${{ secrets.GITHUB_TOKEN }}
- name: Build and push
uses: docker/build-push-action@f9f3042f7e2789586610d6e8b85c8f03e5195baf
with:
context: .
push: true
tags: |
ghcr.io/${{ github.repository }}:latest
ghcr.io/${{ github.repository }}:${{ github.sha }}
cache-from: type=gha
cache-to: type=gha,mode=max
public-compatibility-smoke:
needs: build-and-test
runs-on: ubuntu-latest
if: github.event_name == 'schedule' || github.event_name == 'workflow_dispatch'
timeout-minutes: 30
env:
OPENCLAW_PUBLIC_SMOKE: "1"
steps:
- uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0
- name: Setup .NET
uses: actions/setup-dotnet@26b0ec14cb23fa6904739307f278c14f94c95bf1
with:
dotnet-version: ${{ env.DOTNET_VERSION }}
- name: Cache NuGet packages
uses: actions/cache@55cc8345863c7cc4c66a329aec7e433d2d1c52a9
with:
path: ${{ env.NUGET_PACKAGES }}
key: nuget-${{ runner.os }}-${{ hashFiles('OpenClaw.Net.slnx', '**/*.csproj', '**/*.props', '**/*.targets') }}
restore-keys: |
nuget-${{ runner.os }}-
- name: Setup Node
uses: actions/setup-node@48b55a011bda9f5d6aeb4c2d9c7362e8dae4041e
with:
node-version: "20"
- name: Restore
run: dotnet restore src/OpenClaw.Tests
- name: Build
run: dotnet build --no-restore -c Release src/OpenClaw.Tests ${{ env.FAST_BUILD_PROPERTIES }}
- name: Run Public Compatibility Smoke
run: dotnet test --no-build -c Release --filter "Category=PublicSmoke" --verbosity normal --logger "trx;LogFileName=public-smoke.trx" src/OpenClaw.Tests
- name: Upload smoke results
if: always()
uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a
with:
name: public-smoke-results
path: "**/public-smoke.trx"