Skip to content

HF14: Prediction Markets #744

HF14: Prediction Markets

HF14: Prediction Markets #744

name: Build docker image for a PR
on:
pull_request:
# `labeled`/`unlabeled` are added to the default set (opened, synchronize,
# reopened) so that adding the `check-boost-range` label to an open PR
# immediately triggers a run — the label-gated build_boost_183 job below
# would otherwise only be evaluated on the next push.
types: [opened, synchronize, reopened, labeled, unlabeled]
paths-ignore:
- 'docs/**'
- '@l10n/**'
- '**.md'
jobs:
build:
name: Build and push Docker image to Docker Hub
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@v6
with:
submodules: recursive
# setup-buildx-action is required for advanced cache features
# (cache-from / cache-to with type=gha and mode=max). The id: lets
# buildkit-cache-dance below pick up the builder name.
- uses: docker/setup-buildx-action@v4
id: setup-buildx
- uses: docker/login-action@v4
with:
username: ${{ secrets.DOCKER_USERNAME }}
password: ${{ secrets.DOCKER_PASSWORD }}
# Docker tags cannot contain '/', but git branch names can (e.g.
# 'ci/build-time-reduction'). Sanitize via bash parameter expansion
# in an env-var (not direct ${{ }} interpolation) to avoid workflow
# injection if a branch name ever contains shell metacharacters.
- name: Compute docker tag from branch name
id: tag
env:
BRANCH_NAME: ${{ github.head_ref }}
run: |
set -euo pipefail
echo "value=${BRANCH_NAME//\//-}" >> "$GITHUB_OUTPUT"
# cache-from/cache-to type=gha exports Docker LAYERS but not the
# contents of --mount=type=cache directories (ccache, apt). On
# ephemeral GHA runners the BuildKit daemon is fresh each run, so
# named cache mounts always start empty without the dance below.
# actions/cache restores a host directory across runs;
# buildkit-cache-dance binds it into the build's cache mounts and
# extracts the post-build state for the next save.
- name: Restore BuildKit cache mounts from Actions Cache
uses: actions/cache@v5
id: cache-mounts
with:
path: cache-mount
key: viz-cache-mount-${{ runner.os }}-pr-${{ github.base_ref }}-${{ hashFiles('share/vizd/docker/Dockerfile-production') }}-${{ github.sha }}
restore-keys: |
viz-cache-mount-${{ runner.os }}-pr-${{ github.base_ref }}-${{ hashFiles('share/vizd/docker/Dockerfile-production') }}-
viz-cache-mount-${{ runner.os }}-pr-${{ github.base_ref }}-
- name: Inject cache mounts into BuildKit
uses: reproducible-containers/buildkit-cache-dance@v3
with:
builder: ${{ steps.setup-buildx.outputs.name }}
cache-map: |
{
"cache-mount/var-cache-apt": "/var/cache/apt",
"cache-mount/var-lib-apt-lists": "/var/lib/apt/lists",
"cache-mount/ccache": {
"target": "/root/.ccache",
"id": "viz-ccache"
}
}
skip-extraction: ${{ steps.cache-mounts.outputs.cache-hit }}
# Layer cache scope is keyed on the PR's base branch so all PRs
# targeting master share one warm-cache pool, while PRs against
# release branches cannot poison master's cache.
- uses: docker/build-push-action@v7
with:
context: .
file: ./share/vizd/docker/Dockerfile-production
push: true
tags: vizblockchain/vizd:${{ steps.tag.outputs.value }}
cache-from: type=gha,scope=pr-${{ github.base_ref }}
cache-to: type=gha,scope=pr-${{ github.base_ref }},mode=max
# The Docker build above proves the top of the supported Boost range (1.91,
# from the vizblockchain/vizd:boost-base base image). The tree is also supposed to build
# against the 1.83 that Ubuntu 24.04 ships, and nothing else covers that end.
# Gated on a label so it does not tax every PR: add `check-boost-range` to any
# PR that touches build files, Asio usage, or thirdparty submodule pointers.
build_boost_183:
name: Build against distro Boost 1.83 (range floor)
runs-on: ubuntu-latest
if: contains(github.event.pull_request.labels.*.name, 'check-boost-range')
steps:
- uses: actions/checkout@v6
with:
submodules: recursive
- name: Install distro Boost and build deps
# Runners fetch packages from azure.archive.ubuntu.com; when that mirror goes quiet
# apt keeps retrying it and the job hangs for hours instead of failing (seen
# 2026-08-19). Pin the canonical mirror, bound the wait, and cap the step.
timeout-minutes: 15
run: |
set -euo pipefail
sudo sed -i 's|azure.archive.ubuntu.com|archive.ubuntu.com|g' \
/etc/apt/apt-mirrors.txt /etc/apt/sources.list 2>/dev/null || true
apt="sudo apt-get -o Acquire::Retries=3 -o Acquire::http::Timeout=20 -o Acquire::https::Timeout=20"
$apt update
$apt install -y --no-install-recommends \
build-essential cmake libboost-all-dev libssl-dev \
libbz2-dev liblzma-dev libzstd-dev libreadline-dev \
libtool ncurses-dev pkg-config zlib1g-dev
- name: Configure and build
run: |
set -euo pipefail
sed -i '/add_subdirectory(tests)/d' thirdparty/fc/CMakeLists.txt
mkdir -p build && cd build
cmake -DCMAKE_BUILD_TYPE=Release \
-DBUILD_SHARED_LIBRARIES=FALSE \
-DCHAINBASE_CHECK_LOCKING=FALSE ..
make -j"$(nproc)" vizd
# L3 (audit 2026-08-13): the tree's PM unit tests (LMSR vector parity, parimutuel
# conservation, leverage math, meta parsing, chain-properties validate() sweep) were
# only ever run manually — CI proved compilation alone. Gated on the `pm-tests` label
# (like check-boost-range) so the default PR build stays fast; add the label to any PR
# touching PM consensus math, evaluators, crons, or chain properties. Builds only the
# tests/pm targets (chain/protocol/fc compile as make-dependencies); the consensus_sim
# harness is configured by BUILD_CONSENSUS_TESTS but never built here.
pm_tests:
name: PM unit tests (ctest)
runs-on: ubuntu-latest
if: contains(github.event.pull_request.labels.*.name, 'pm-tests')
steps:
- uses: actions/checkout@v6
with:
submodules: recursive
- name: Install distro Boost and build deps
# Runners fetch packages from azure.archive.ubuntu.com; when that mirror goes quiet
# apt keeps retrying it and the job hangs for hours instead of failing (seen
# 2026-08-19). Pin the canonical mirror, bound the wait, and cap the step.
timeout-minutes: 15
run: |
set -euo pipefail
sudo sed -i 's|azure.archive.ubuntu.com|archive.ubuntu.com|g' \
/etc/apt/apt-mirrors.txt /etc/apt/sources.list 2>/dev/null || true
apt="sudo apt-get -o Acquire::Retries=3 -o Acquire::http::Timeout=20 -o Acquire::https::Timeout=20"
$apt update
$apt install -y --no-install-recommends \
build-essential cmake libboost-all-dev libssl-dev \
libbz2-dev liblzma-dev libzstd-dev libreadline-dev \
libtool ncurses-dev pkg-config zlib1g-dev
- name: Configure and build PM test targets
run: |
set -euo pipefail
sed -i '/add_subdirectory(tests)/d' thirdparty/fc/CMakeLists.txt
mkdir -p build && cd build
cmake -DCMAKE_BUILD_TYPE=Release \
-DBUILD_SHARED_LIBRARIES=FALSE \
-DCHAINBASE_CHECK_LOCKING=FALSE \
-DBUILD_CONSENSUS_TESTS=ON ..
make -j"$(nproc)" \
pm_lmsr_vectors_tests pm_parimutuel_tests pm_leverage_tests \
pm_meta_parse_tests pm_props_validate_tests
- name: Run ctest (PM suite)
run: |
set -euo pipefail
cd build
ctest -R '^pm_' --output-on-failure