mirror of
https://github.com/eclipse-threadx/threadx.git
synced 2026-10-06 06:59:08 +08:00
cortex_m / Cortex M0 build (push) Canceled after 0s
cortex_m / Cortex M3 build (push) Canceled after 0s
cortex_m / Cortex M4 build (push) Canceled after 0s
cortex_m / Cortex M7 build (push) Canceled after 0s
regression_test / tx (push) Canceled after 0s
regression_test / smp (push) Canceled after 0s
regression_test / freertos (push) Canceled after 0s
regression_test / deploy (push) Canceled after 0s
regression_template / run_tests (push) Canceled after 0s
regression_template / deploy_code_coverage (push) Canceled after 0s
The coverage summary reported a percentage and could not fail. Coverage could fall from 99.97% to anything at all and every check stayed green, against an AGENTS.md that asks for 100% test coverage -- a stated requirement measured with a gauge that had no failure mode. CodeCoverageSummary already takes thresholds and fail_below_min; neither was set. Both are now, through a new coverage_thresholds input on the template, because the two suites do not sit at the same figure: ThreadX 99, SMP 98. Three things were probed against the pinned action on a runner before picking those numbers, using the real merged.xml files from the dev push run of #666. The floor compares the line rate and nothing else. That mattered because branch coverage is around 78% in both suites while line coverage is 98.8-100%, so a floor aimed at the line figure would have been an immediate red wall had it tested branches or the lower of the two. The ThreadX report at 100.00% lines and 77.67% branches clears a floor of 99. The thresholds are whole numbers. '99.9 100' -- the value this was meant to be -- is rejected with 'System.ArgumentException - Threshold parameter set incorrectly.', and the step fails whether or not fail_below_min is set. So the choice is 99 or 100 with nothing between. 100 would fail on a race. tx_thread_system_resume.c:529 is reached by timing rather than by construction and flaps between runs of the same green tree, which is why #666 left it; 4502/4503 fails a floor of 100 and clears one of 99. A coverage gate that goes red on a coin toss is how coverage gates get switched off. SMP is 5114/5178 lines, 98.76%, with 64 uncovered lines across 11 files of common_smp/src -- #666 closed the equivalent gaps in common/src only. A shared floor of 99 would have failed that job on every run while ThreadX passed. One limit is recorded in the file rather than fixed: an empty report reads as 100%. gcovr writes line-rate="1.0" beside lines-valid="0" when it finds no data, and the action prints 'Line Rate = 100% (0 / 0)' and passes any floor. The check for that is the emptiness assertion #664 put in each suite's coverage.sh, not this one. Also corrected two stale filenames in the deploy job's comment: since #665 each coverage artifact carries merged.xml, not default_build_coverage.xml. Verified on the runner. Assisted-by: Claude Opus 5 <noreply@anthropic.com>
331 lines
15 KiB
YAML
331 lines
15 KiB
YAML
# This is a basic workflow that is manually triggered
|
|
|
|
name: regression_template
|
|
|
|
on:
|
|
workflow_call:
|
|
inputs:
|
|
install_script:
|
|
default: './scripts/install.sh'
|
|
required: false
|
|
type: string
|
|
build_script:
|
|
default: './scripts/build.sh'
|
|
required: false
|
|
type: string
|
|
test_script:
|
|
default: './scripts/test.sh'
|
|
required: false
|
|
type: string
|
|
cmake_path:
|
|
default: './test/cmake'
|
|
required: false
|
|
type: string
|
|
skip_test:
|
|
default: false
|
|
required: false
|
|
type: boolean
|
|
skip_coverage:
|
|
default: false
|
|
required: false
|
|
type: boolean
|
|
# The merged report, not one configuration's. Every configuration is
|
|
# instrumented now (TX_COVERAGE below) and coverage.sh --merge unions
|
|
# them; default_build_coverage was one build of five, and the code the
|
|
# other four select was absent from its denominator rather than uncovered
|
|
# in it.
|
|
coverage_name:
|
|
default: 'merged'
|
|
required: false
|
|
type: string
|
|
# The lower and upper threshold percentages handed to
|
|
# CodeCoverageSummary, lower first. The lower one is a hard floor: the
|
|
# step below sets fail_below_min, so a run whose merged line rate falls
|
|
# under it turns the job red.
|
|
#
|
|
# Both must be whole numbers. Probed against the pinned action on a
|
|
# runner, 26 Aug 2026: '99.9 100' is rejected with
|
|
# 'System.ArgumentException - Threshold parameter set incorrectly.' and
|
|
# the step fails whether or not fail_below_min is set, because the action
|
|
# parses each half with an integer parse. So a floor can be 99 or 100 and
|
|
# nothing between, and the intended 99.9 is not expressible.
|
|
#
|
|
# The floor is compared against the LINE rate only -- not the branch
|
|
# rate, and not the lower of the two. Probed on the same run: the
|
|
# ThreadX report at 100.00% lines and 77.67% branches passes a floor of
|
|
# 99. Worth knowing, because branch coverage is around 78% in both
|
|
# suites while AGENTS.md asks for 100%, and a floor set from the
|
|
# headline line figure says nothing about it.
|
|
#
|
|
# Each suite sets its own in regression_test.yml, because they do not
|
|
# sit at the same figure. The default here is the action's own, low
|
|
# enough to be no floor at all in practice -- a caller that collects
|
|
# coverage is expected to name its number.
|
|
coverage_thresholds:
|
|
default: '50 75'
|
|
required: false
|
|
type: string
|
|
skip_deploy:
|
|
default: false
|
|
required: false
|
|
type: boolean
|
|
deploy_list:
|
|
default: ''
|
|
required: false
|
|
type: string
|
|
result_affix:
|
|
default: ''
|
|
required: false
|
|
type: string
|
|
|
|
# A workflow run is made up of one or more jobs that can run sequentially or in parallel
|
|
jobs:
|
|
# This workflow contains a single job called "linux_job"
|
|
run_tests:
|
|
if: ${{ !inputs.skip_test}}
|
|
permissions:
|
|
contents: read
|
|
issues: read
|
|
checks: write
|
|
pull-requests: write
|
|
|
|
# The type of runner that the job will run on
|
|
runs-on: ubuntu-24.04
|
|
|
|
# Steps represent a sequence of tasks that will be executed as part of the job
|
|
steps:
|
|
# Actions are pinned to a commit SHA, with the version in the trailing
|
|
# comment. A tag can be moved; a SHA cannot, so this is what makes "which
|
|
# code ran in CI" answerable from the repository. Dependabot moves these
|
|
# pins and rewrites the comment with them -- see .github/dependabot.yml.
|
|
- name: Check out the repository
|
|
uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
|
|
with:
|
|
submodules: true
|
|
|
|
# apt and PyPI have stalled this step twice, for 55 minutes and for over two
|
|
# hours, against a normal 27 to 152 seconds. Nothing here had a timeout, so a
|
|
# stall ran until the six hour job limit and cost a whole run rather than
|
|
# failing and being retried.
|
|
- name: Install softwares
|
|
timeout-minutes: 10
|
|
run: ${{ inputs.install_script }}
|
|
|
|
# TX_COVERAGE instruments every build configuration rather than only the one
|
|
# whose name ends in _coverage. It has to be set for the build as well as the
|
|
# test: the build is where -fprofile-arcs is decided, and the test run is
|
|
# where the reports are collected and merged.
|
|
- name: Build
|
|
timeout-minutes: 15
|
|
env:
|
|
TX_COVERAGE: ${{ inputs.skip_coverage && 'OFF' || 'ON' }}
|
|
run: ${{ inputs.build_script }}
|
|
|
|
- name: Test
|
|
timeout-minutes: 60
|
|
env:
|
|
TX_COVERAGE: ${{ inputs.skip_coverage && 'OFF' || 'ON' }}
|
|
run: ${{ inputs.test_script }}
|
|
|
|
- name: Publish Test Results
|
|
uses: EnricoMi/publish-unit-test-result-action@d0a4676d0e0b938bc201470d88276b7c74c712b3 # v2.24.0
|
|
if: always()
|
|
with:
|
|
check_name: Test Results ${{ inputs.result_affix }}
|
|
files: |
|
|
${{ inputs.cmake_path }}/build/*/*.xml
|
|
|
|
- name: Upload Test Results
|
|
if: success() || failure()
|
|
uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1
|
|
with:
|
|
name: test_reports ${{ inputs.result_affix }}
|
|
path: |
|
|
${{ inputs.cmake_path }}/build/*.txt
|
|
${{ inputs.cmake_path }}/build/*/Testing/**/*.xml
|
|
${{ inputs.cmake_path }}/build/**/regression/output_files/*.bin
|
|
|
|
- name: Configure GitHub Pages
|
|
uses: actions/configure-pages@45bfe0192ca1faeb007ade9deae92b16b8254a0d # v6.0.0
|
|
|
|
# The coverage steps below run even when a test failed. cmake_bootstrap.sh
|
|
# now produces the report in that case, and the run whose behaviour changed
|
|
# is the one whose coverage is worth reading; previously a single flaky test
|
|
# suppressed the report for the whole run. !cancelled() rather than always(),
|
|
# so a cancelled run still stops promptly -- the same idiom the
|
|
# deploy_code_coverage job below already uses. The ${{ }} is required: a bare
|
|
# ! opens a YAML tag, and the expression will not parse without it.
|
|
#
|
|
# fail_below_min turns the summary into a gate. Until now coverage could
|
|
# fall from any figure to any other and no check went red, against an
|
|
# AGENTS.md that asks for 100% -- a stated requirement measured with a
|
|
# gauge that could not fail.
|
|
#
|
|
# One thing the floor does not defend, and it is the likeliest way for
|
|
# coverage to break: an empty report reads as 100%. gcovr writes
|
|
# line-rate="1.0" beside lines-valid="0" when it finds no data, and the
|
|
# action reports 'Line Rate = 100% (0 / 0)' and passes any floor --
|
|
# probed on a runner, 26 Aug 2026. The check that catches that is the
|
|
# emptiness assertion in each suite's coverage.sh, not this one.
|
|
- name: Generate Code Coverage Results Summary
|
|
if: ${{ !cancelled() && (!inputs.skip_coverage) }}
|
|
uses: irongut/CodeCoverageSummary@51cc3a756ddcd398d447c044c02cb6aa83fdae95 # v1.3.0
|
|
with:
|
|
filename: ${{ inputs.cmake_path }}/coverage_report/${{ inputs.coverage_name }}.xml
|
|
format: markdown
|
|
badge: true
|
|
hide_complexity: true
|
|
output: file
|
|
thresholds: ${{ inputs.coverage_thresholds }}
|
|
fail_below_min: true
|
|
|
|
- name: Write Code Coverage Summary
|
|
if: ${{ !cancelled() && (!inputs.skip_coverage) }}
|
|
run: |
|
|
echo "## Coverage Report ${{ inputs.result_affix }}" >> $GITHUB_STEP_SUMMARY
|
|
cat code-coverage-results.md >> $GITHUB_STEP_SUMMARY
|
|
|
|
- name: Create CheckRun for Code Coverage
|
|
if: ${{ !cancelled() && ((github.event_name == 'push') || (github.event_name == 'workflow_dispatch') || (github.event.pull_request.head.repo.full_name == github.repository)) && (!inputs.skip_coverage) }}
|
|
uses: LouisBrunner/checks-action@937cbbcde3259005b50746dc91cde29098aac2ff # v3.1.0
|
|
with:
|
|
token: ${{ secrets.GITHUB_TOKEN }}
|
|
name: Code Coverage ${{ inputs.result_affix }}
|
|
conclusion: ${{ job.status }}
|
|
output: |
|
|
{"summary":"Coverage Report"}
|
|
output_text_description_file: code-coverage-results.md
|
|
|
|
- name: Add Code Coverage PR Comment
|
|
if: ${{ !cancelled() && ((github.event_name == 'push') || (github.event.pull_request.head.repo.full_name == github.repository)) && (!inputs.skip_coverage) }}
|
|
uses: marocchino/sticky-pull-request-comment@5770ad5eb8f42dd2c4f34da00c94c5381e49af88 # v3.0.5
|
|
with:
|
|
header: Code Coverage ${{ inputs.result_affix }}
|
|
path: code-coverage-results.md
|
|
|
|
# Add sudo to move coverage folder created by root user
|
|
- name: Prepare Coverage GitHub Pages
|
|
if: ${{ !cancelled() && (!inputs.skip_coverage) }}
|
|
run: >-
|
|
if [ "${{ inputs.result_affix }}" != "" ] && ${{ inputs.skip_deploy }}; then
|
|
sudo mv ${{ inputs.cmake_path }}/coverage_report/${{ inputs.coverage_name }} \
|
|
${{ inputs.cmake_path }}/coverage_report/${{ inputs.result_affix }}
|
|
fi
|
|
|
|
- name: Coverage Report name
|
|
id: artifact
|
|
if: ${{ !cancelled() && (!inputs.skip_coverage) }}
|
|
run: echo "coverage_report=coverage_report-$(date +%s)" >> $GITHUB_OUTPUT
|
|
|
|
# per_configuration is excluded deliberately. deploy_code_coverage downloads
|
|
# every coverage_report-* artifact with merge-multiple, so whatever is in
|
|
# here lands on the published site -- and each suite's per-configuration
|
|
# directories carry the same names, so ThreadX's would overwrite SMP's.
|
|
# The top level therefore holds only the suite directory and the merged XML,
|
|
# which is the shape the deploy already expects.
|
|
- name: Upload Code Coverage Artifacts
|
|
uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1
|
|
if: ${{ !cancelled() && (inputs.skip_deploy && !inputs.skip_coverage) }}
|
|
with:
|
|
name: ${{ steps.artifact.outputs.coverage_report }}
|
|
path: |
|
|
${{ inputs.cmake_path }}/coverage_report
|
|
!${{ inputs.cmake_path }}/coverage_report/per_configuration/**
|
|
retention-days: 1
|
|
|
|
# The per-configuration reports, kept separately so they are downloadable
|
|
# when the merged number moves and the question is which configuration moved
|
|
# it. The name deliberately does not match coverage_report-*, so the deploy
|
|
# job's pattern does not pick it up and it never reaches the published site.
|
|
- name: Upload Per-Configuration Coverage
|
|
uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1
|
|
if: ${{ !cancelled() && (!inputs.skip_coverage) }}
|
|
with:
|
|
name: coverage_detail ${{ inputs.result_affix }}
|
|
path: ${{ inputs.cmake_path }}/coverage_report/per_configuration
|
|
retention-days: 1
|
|
|
|
- name: Upload Code Coverage Pages
|
|
uses: actions/upload-pages-artifact@fc324d3547104276b827a68afc52ff2a11cc49c9 # v5.0.0
|
|
if: ${{ !cancelled() && (!inputs.skip_deploy && !inputs.skip_coverage) }}
|
|
with:
|
|
path: ${{ inputs.cmake_path }}/coverage_report/${{ inputs.coverage_name }}
|
|
|
|
deploy_code_coverage:
|
|
runs-on: ubuntu-24.04
|
|
if: ((github.event_name == 'push') || (github.event_name == 'workflow_dispatch')) && !inputs.skip_coverage && !inputs.skip_deploy && !failure() && !cancelled()
|
|
needs: run_tests
|
|
environment:
|
|
name: github-pages
|
|
url: ${{ steps.deployment.outputs.page_url }}
|
|
permissions:
|
|
pages: write
|
|
id-token: write
|
|
|
|
steps:
|
|
# Selects the coverage artifacts by pattern rather than by name.
|
|
#
|
|
# This used to ask for ${{ steps.artifact.outputs.coverage_report }},
|
|
# which is set by the "Coverage Report name" step of run_tests -- a
|
|
# different job. The steps context does not cross jobs, so that
|
|
# expression evaluated to the empty string and the action fell back to
|
|
# its documented behaviour for an unspecified name: "No input name,
|
|
# artifact-ids or pattern filtered specified, downloading all
|
|
# artifacts". It pulled down four, the two coverage reports and the two
|
|
# test_reports bundles of JUnit XML, each into a directory named after
|
|
# the artifact -- so the published site carried the test reports as well
|
|
# as the coverage, under paths containing a run timestamp that changed
|
|
# on every publish.
|
|
#
|
|
# merge-multiple puts the contents of both coverage artifacts directly
|
|
# into coverage_report rather than under a directory named for each
|
|
# artifact. Each one holds a single directory named for its suite,
|
|
# ThreadX or SMP, renamed from merged by the "Prepare Coverage GitHub
|
|
# Pages" step, so the merge yields exactly the two suite directories the
|
|
# deploy expects, and the artifact name -- with its timestamp -- stops
|
|
# appearing in the published path at all.
|
|
#
|
|
# The two artifacts also each carry a merged.xml -- it was
|
|
# default_build_coverage.xml until #665 instrumented every configuration
|
|
# and unioned them -- and the merge means one overwrites the other.
|
|
# Verified on the runner: both hold merged.xml. That file is consumed by
|
|
# CodeCoverageSummary back in run_tests and is not read here, so this is
|
|
# untidy rather than wrong.
|
|
- uses: actions/download-artifact@3e5f45b2cfb9172054b4087a40e8e0b5a5461e7c # v8.0.1
|
|
if: ${{ inputs.skip_test }}
|
|
with:
|
|
pattern: coverage_report-*
|
|
merge-multiple: true
|
|
path: ${{ inputs.cmake_path }}/coverage_report
|
|
|
|
- name: Upload Code Coverage Pages
|
|
uses: actions/upload-pages-artifact@fc324d3547104276b827a68afc52ff2a11cc49c9 # v5.0.0
|
|
if: ${{ inputs.skip_test }}
|
|
with:
|
|
path: .
|
|
|
|
# The artifacts are named coverage_report-<epoch> by run_tests, so the
|
|
# bare name matched nothing: useGlob defaults to true in this action, and
|
|
# as a glob "coverage_report" matches only the literal string. The step
|
|
# has therefore been deleting nothing. It does not fail on a miss, which
|
|
# is why that went unnoticed; retention-days: 1 on the upload is what has
|
|
# actually been clearing these up.
|
|
- name: Delete Duplicate Code Coverage Artifact
|
|
uses: geekyeggo/delete-artifact@176a747ab7e287e3ff4787bf8a148716375ca118 # v6.0.0
|
|
with:
|
|
name: coverage_report-*
|
|
|
|
- name: Deploy GitHub Pages site
|
|
id: deployment
|
|
uses: actions/deploy-pages@cd2ce8fcbc39b97be8ca5fce6e763baed58fa128 # v5.0.0
|
|
|
|
- name: Write Code Coverage Report URL
|
|
run: >-
|
|
if [ "${{ inputs.deploy_list }}" != "" ]; then
|
|
for i in ${{ inputs.deploy_list }}; do
|
|
echo 'Coverage report for ' $i ':${{ steps.deployment.outputs.page_url }}'$i >> $GITHUB_STEP_SUMMARY
|
|
done
|
|
else
|
|
echo 'Coverage report: ${{ steps.deployment.outputs.page_url }}' >> $GITHUB_STEP_SUMMARY
|
|
fi
|