mirror of
https://github.com/nlohmann/json.git
synced 2026-09-25 14:20:14 +01:00
* Add missing headers to BUILD.bazel and make its generator reproduce it The "json" cc_library did not list three headers that the library includes: - detail/meta/logic.hpp (added in #5016, included by from_json.hpp) - detail/input/number_parse.hpp (added in #5283, included by lexer.hpp) - detail/input/string_scan.hpp (added in #5283, included by lexer.hpp and serializer.hpp) Bazel's sandbox only exposes declared headers, so any target depending on @nlohmann_json//:json and including <nlohmann/json.hpp> failed with "'nlohmann/detail/meta/logic.hpp' file not found". The file could not simply be regenerated, because the generator behind "make BUILD.bazel" was stale: it wrote only the "json" cc_library and dropped the load() statements, the license block, and the "singleheader-json" target that were added by hand in #4584. The generator now emits the complete file, so its output differs from the previous BUILD.bazel only by the three headers. It also resolves the glob against the project root instead of the working directory and sorts the list explicitly. "make BUILD.bazel" is now phony: in a fresh checkout, BUILD.bazel is not older than the headers, so make considered it up to date, and a removed header would never trigger a rebuild. "make check-amalgamation" also checks that BUILD.bazel is up to date. Signed-off-by: Niels Lohmann <mail@nlohmann.me> * Check in CI that BUILD.bazel is up to date The "Check amalgamation" workflow now also regenerates BUILD.bazel, so a pull request that adds, renames, or removes a header without updating the Bazel header list fails, and the attached amalgamation.patch contains the fix. The failure comment and the contribution guidelines mention the new check, and the comment now links to the existing "Amalgamate the source code" section instead of the "Files to change" anchor that was removed in #4560. Signed-off-by: Niels Lohmann <mail@nlohmann.me> --------- Signed-off-by: Niels Lohmann <mail@nlohmann.me>
108 lines
4.7 KiB
YAML
108 lines
4.7 KiB
YAML
name: Comment Check Amalgamation
|
|
on:
|
|
workflow_run:
|
|
workflows: ["Check amalgamation"]
|
|
types:
|
|
- completed
|
|
|
|
permissions:
|
|
contents: read
|
|
|
|
jobs:
|
|
comment:
|
|
if: ${{ github.event.workflow_run.conclusion == 'failure' }}
|
|
runs-on: ubuntu-latest
|
|
permissions:
|
|
contents: read
|
|
actions: read
|
|
issues: read
|
|
pull-requests: write
|
|
steps:
|
|
- name: Harden Runner
|
|
uses: step-security/harden-runner@e14015d583714f6e62063499dc959a02595150a1 # v2.21.1
|
|
with:
|
|
egress-policy: audit
|
|
|
|
- name: 'Download artifact'
|
|
id: download
|
|
uses: actions/github-script@3a2844b7e9c422d3c10d287c895573f7108da1b3 # v9.0.0
|
|
with:
|
|
script: |
|
|
var artifacts = await github.rest.actions.listWorkflowRunArtifacts({
|
|
owner: context.repo.owner,
|
|
repo: context.repo.repo,
|
|
run_id: ${{github.event.workflow_run.id }},
|
|
});
|
|
var matchArtifact = artifacts.data.artifacts.filter((artifact) => {
|
|
return artifact.name == "pr"
|
|
})[0];
|
|
var download = await github.rest.actions.downloadArtifact({
|
|
owner: context.repo.owner,
|
|
repo: context.repo.repo,
|
|
artifact_id: matchArtifact.id,
|
|
archive_format: 'zip',
|
|
});
|
|
var fs = require('fs');
|
|
fs.writeFileSync('${{github.workspace}}/pr.zip', Buffer.from(download.data));
|
|
|
|
var hasPatch = artifacts.data.artifacts.some((artifact) => artifact.name == "amalgamation-patch");
|
|
core.setOutput('has_patch', String(hasPatch));
|
|
# Extract the untrusted PR artifact into a dedicated empty directory and
|
|
# read only the two expected files by fixed path afterwards. This avoids a
|
|
# malicious archive overwriting workspace files or escaping via ../ paths.
|
|
- run: unzip -o pr.zip -d ./pr_artifact
|
|
|
|
- name: 'Comment on PR'
|
|
uses: actions/github-script@3a2844b7e9c422d3c10d287c895573f7108da1b3 # v9.0.0
|
|
with:
|
|
github-token: ${{ secrets.GITHUB_TOKEN }}
|
|
script: |
|
|
var fs = require('fs');
|
|
// Both values come from a fork-triggered workflow and are therefore
|
|
// attacker-controlled. Validate them strictly before use to prevent
|
|
// Markdown/mention injection and bogus REST API filters.
|
|
const author = fs.readFileSync('./pr_artifact/author', 'utf8').trim();
|
|
if (!/^[A-Za-z0-9-]{1,39}$/.test(author)) {
|
|
core.setFailed(`Refusing to proceed: untrusted author value '${author}' is not a valid GitHub username.`);
|
|
return;
|
|
}
|
|
const issue_number = Number(fs.readFileSync('./pr_artifact/number', 'utf8').trim());
|
|
if (!Number.isInteger(issue_number) || issue_number <= 0) {
|
|
core.setFailed('Refusing to proceed: untrusted PR number is not a positive integer.');
|
|
return;
|
|
}
|
|
const opts = github.rest.issues.listForRepo.endpoint.merge({
|
|
owner: context.repo.owner,
|
|
repo: context.repo.repo,
|
|
creator: author,
|
|
state: 'all'
|
|
})
|
|
let first = true
|
|
const issues = await github.paginate(opts)
|
|
for (const issue of issues) {
|
|
if (issue.number === issue_number) {
|
|
continue
|
|
}
|
|
if (issue.pull_request) {
|
|
first = false
|
|
break
|
|
}
|
|
}
|
|
const hasPatch = '${{ steps.download.outputs.has_patch }}' === 'true';
|
|
const runUrl = '${{ github.event.workflow_run.html_url }}';
|
|
|
|
await github.rest.issues.createComment({
|
|
issue_number: issue_number,
|
|
owner: context.repo.owner,
|
|
repo: context.repo.repo,
|
|
body: '## 🔴 Amalgamation check failed! 🔴\nThe source code has not been amalgamated and/or formatted correctly, or `BUILD.bazel` is out of date.'
|
|
+ (hasPatch ? '\n\n📎 A ready-to-apply patch is attached to the [failed workflow run](' + runUrl + ') as the `amalgamation-patch` artifact.'
|
|
+ ' Download it, then apply it locally from the repository root with:'
|
|
+ '\n\n```shell\ngit apply amalgamation.patch\n```\n\n'
|
|
+ 'This does not require installing astyle yourself.'
|
|
: '')
|
|
+ (first ? '\n\n@' + author + ' Please read and follow the [Contribution Guidelines]'
|
|
+ '(https://github.com/nlohmann/json/blob/develop/.github/CONTRIBUTING.md#amalgamate-the-source-code).'
|
|
: '')
|
|
})
|