Files
threadx/.github/workflows/clang_check.yml
T
Frédéric Desbiens 3d852eb451 Pinned every action to a commit SHA, and moved them off Node 20 (#660)
Node 20 is removed from the GitHub runners on 16 September 2026. Every run
in this repository currently emits the deprecation warning for it, naming
actions/checkout, actions/configure-pages, actions/upload-artifact,
LouisBrunner/checks-action and marocchino/sticky-pull-request-comment among
others. After that date those actions stop working rather than warning, so
this is a deadline and not housekeeping.

Every action is now referenced by a 40-character commit SHA with the version
in a trailing comment. A tag can be repointed at any commit; a SHA cannot, so
this is what makes "which code ran in our CI" answerable from the repository
rather than from whatever the tag meant at the time. The versions were behind
by as much as four majors -- download-artifact was on v4.3.0 against v8.0.1 --
because nothing in this repository has ever reported that an action moved.

Compatibility was checked against each new action.yml rather than assumed,
for every input this repository actually passes:

  checkout            submodules is unchanged
  cache               path and key are unchanged
  upload-artifact     name, path and retention-days are unchanged
  download-artifact   pattern, merge-multiple and path are unchanged
  configure-pages     takes no input here, and none became required
  deploy-pages        still exposes page_url, which the job reads
  upload-pages-art.   path is unchanged
  checks-action       token, name, conclusion, output and
                      output_text_description_file all survive v2 to v3
  sticky-comment      header and path survive v2 to v3, and the new
                      GITHUB_TOKEN input defaults to github.token, which is
                      what v2 used implicitly
  delete-artifact     name survives v5 to v6, and useGlob still defaults to
                      true, so the coverage_report-* glob from #655 still
                      matches
  CodeCoverageSummary already current at v1.3.0; pinned, not moved

The artifact pair moves together, as it must. The round trip was verified on
a runner before this commit: upload-artifact v7 to download-artifact v8,
through the pattern and merge-multiple selection #655 introduced, filtered 4
artifacts to 2 and produced exactly the tree the deploy expects.

Two behaviour changes worth knowing. download-artifact v8 adds a
digest-mismatch input defaulting to error, so a corrupted artifact now fails
the job instead of passing through -- the right default, but a change.
upload-artifact v6 and above require a runner of at least 2.327.1, which the
hosted runners satisfy and a self-hosted runner would need checking for.

Assisted-by: Claude Opus 5 <noreply@anthropic.com>
2026-08-25 15:52:49 -04:00

59 lines
2.1 KiB
YAML

name: clang_check
# Builds the Arm ports with Arm Toolchain for Embedded, which is LLVM based and
# is the successor to Arm Compiler 6. The gnu ports are otherwise only ever
# built with GNU tooling, and GNU as accepts several non-canonical forms that
# LLVM's assembler rejects; this catches those before they accumulate.
on:
pull_request:
branches: [ master, dev ]
paths:
- ".github/workflows/clang_check.yml"
- "scripts/check_clang.sh"
- "common/**"
- "ports/**"
- "ports_arch/**"
- "ports_module/**"
- "ports_smp/**"
jobs:
atfe:
runs-on: ubuntu-24.04
env:
# Pinned deliberately, as the runner image is: a toolchain upgrade should
# be a reviewable commit rather than something that changes underneath the
# ports. Releases: https://github.com/arm/arm-toolchain/releases
ATFE_VERSION: 22.1.0
steps:
# Actions are pinned to a commit SHA, with the version in the trailing
# comment. A tag can be moved; a SHA cannot, so this is what makes "which
# code ran in CI" answerable from the repository. Dependabot moves these
# pins and rewrites the comment with them -- see .github/dependabot.yml.
- name: Checkout sources
uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
- name: Cache Arm Toolchain for Embedded
id: cache-atfe
uses: actions/cache@55cc8345863c7cc4c66a329aec7e433d2d1c52a9 # v6.1.0
with:
path: atfe
key: atfe-${{ env.ATFE_VERSION }}-linux-x86_64
- name: Install Arm Toolchain for Embedded
if: steps.cache-atfe.outputs.cache-hit != 'true'
run: |
set -eu
base="https://github.com/arm/arm-toolchain/releases/download/release-${ATFE_VERSION}-ATfE"
archive="ATfE-${ATFE_VERSION}-Linux-x86_64.tar.xz"
mkdir -p atfe && cd atfe
curl -fsSLO "$base/$archive"
curl -fsSLO "$base/$archive.sha256"
sha256sum -c "$archive.sha256"
tar xf "$archive"
rm -f "$archive"
- name: Build the Arm ports with clang
run: scripts/check_clang.sh --clang "atfe/ATfE-${ATFE_VERSION}-Linux-x86_64/bin/clang"