HF14: Prediction Markets #744
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
| name: Build docker image for a PR | |
| on: | |
| pull_request: | |
| # `labeled`/`unlabeled` are added to the default set (opened, synchronize, | |
| # reopened) so that adding the `check-boost-range` label to an open PR | |
| # immediately triggers a run — the label-gated build_boost_183 job below | |
| # would otherwise only be evaluated on the next push. | |
| types: [opened, synchronize, reopened, labeled, unlabeled] | |
| paths-ignore: | |
| - 'docs/**' | |
| - '@l10n/**' | |
| - '**.md' | |
| jobs: | |
| build: | |
| name: Build and push Docker image to Docker Hub | |
| runs-on: ubuntu-latest | |
| steps: | |
| - uses: actions/checkout@v6 | |
| with: | |
| submodules: recursive | |
| # setup-buildx-action is required for advanced cache features | |
| # (cache-from / cache-to with type=gha and mode=max). The id: lets | |
| # buildkit-cache-dance below pick up the builder name. | |
| - uses: docker/setup-buildx-action@v4 | |
| id: setup-buildx | |
| - uses: docker/login-action@v4 | |
| with: | |
| username: ${{ secrets.DOCKER_USERNAME }} | |
| password: ${{ secrets.DOCKER_PASSWORD }} | |
| # Docker tags cannot contain '/', but git branch names can (e.g. | |
| # 'ci/build-time-reduction'). Sanitize via bash parameter expansion | |
| # in an env-var (not direct ${{ }} interpolation) to avoid workflow | |
| # injection if a branch name ever contains shell metacharacters. | |
| - name: Compute docker tag from branch name | |
| id: tag | |
| env: | |
| BRANCH_NAME: ${{ github.head_ref }} | |
| run: | | |
| set -euo pipefail | |
| echo "value=${BRANCH_NAME//\//-}" >> "$GITHUB_OUTPUT" | |
| # cache-from/cache-to type=gha exports Docker LAYERS but not the | |
| # contents of --mount=type=cache directories (ccache, apt). On | |
| # ephemeral GHA runners the BuildKit daemon is fresh each run, so | |
| # named cache mounts always start empty without the dance below. | |
| # actions/cache restores a host directory across runs; | |
| # buildkit-cache-dance binds it into the build's cache mounts and | |
| # extracts the post-build state for the next save. | |
| - name: Restore BuildKit cache mounts from Actions Cache | |
| uses: actions/cache@v5 | |
| id: cache-mounts | |
| with: | |
| path: cache-mount | |
| key: viz-cache-mount-${{ runner.os }}-pr-${{ github.base_ref }}-${{ hashFiles('share/vizd/docker/Dockerfile-production') }}-${{ github.sha }} | |
| restore-keys: | | |
| viz-cache-mount-${{ runner.os }}-pr-${{ github.base_ref }}-${{ hashFiles('share/vizd/docker/Dockerfile-production') }}- | |
| viz-cache-mount-${{ runner.os }}-pr-${{ github.base_ref }}- | |
| - name: Inject cache mounts into BuildKit | |
| uses: reproducible-containers/buildkit-cache-dance@v3 | |
| with: | |
| builder: ${{ steps.setup-buildx.outputs.name }} | |
| cache-map: | | |
| { | |
| "cache-mount/var-cache-apt": "/var/cache/apt", | |
| "cache-mount/var-lib-apt-lists": "/var/lib/apt/lists", | |
| "cache-mount/ccache": { | |
| "target": "/root/.ccache", | |
| "id": "viz-ccache" | |
| } | |
| } | |
| skip-extraction: ${{ steps.cache-mounts.outputs.cache-hit }} | |
| # Layer cache scope is keyed on the PR's base branch so all PRs | |
| # targeting master share one warm-cache pool, while PRs against | |
| # release branches cannot poison master's cache. | |
| - uses: docker/build-push-action@v7 | |
| with: | |
| context: . | |
| file: ./share/vizd/docker/Dockerfile-production | |
| push: true | |
| tags: vizblockchain/vizd:${{ steps.tag.outputs.value }} | |
| cache-from: type=gha,scope=pr-${{ github.base_ref }} | |
| cache-to: type=gha,scope=pr-${{ github.base_ref }},mode=max | |
| # The Docker build above proves the top of the supported Boost range (1.91, | |
| # from the vizblockchain/vizd:boost-base base image). The tree is also supposed to build | |
| # against the 1.83 that Ubuntu 24.04 ships, and nothing else covers that end. | |
| # Gated on a label so it does not tax every PR: add `check-boost-range` to any | |
| # PR that touches build files, Asio usage, or thirdparty submodule pointers. | |
| build_boost_183: | |
| name: Build against distro Boost 1.83 (range floor) | |
| runs-on: ubuntu-latest | |
| if: contains(github.event.pull_request.labels.*.name, 'check-boost-range') | |
| steps: | |
| - uses: actions/checkout@v6 | |
| with: | |
| submodules: recursive | |
| - name: Install distro Boost and build deps | |
| # Runners fetch packages from azure.archive.ubuntu.com; when that mirror goes quiet | |
| # apt keeps retrying it and the job hangs for hours instead of failing (seen | |
| # 2026-08-19). Pin the canonical mirror, bound the wait, and cap the step. | |
| timeout-minutes: 15 | |
| run: | | |
| set -euo pipefail | |
| sudo sed -i 's|azure.archive.ubuntu.com|archive.ubuntu.com|g' \ | |
| /etc/apt/apt-mirrors.txt /etc/apt/sources.list 2>/dev/null || true | |
| apt="sudo apt-get -o Acquire::Retries=3 -o Acquire::http::Timeout=20 -o Acquire::https::Timeout=20" | |
| $apt update | |
| $apt install -y --no-install-recommends \ | |
| build-essential cmake libboost-all-dev libssl-dev \ | |
| libbz2-dev liblzma-dev libzstd-dev libreadline-dev \ | |
| libtool ncurses-dev pkg-config zlib1g-dev | |
| - name: Configure and build | |
| run: | | |
| set -euo pipefail | |
| sed -i '/add_subdirectory(tests)/d' thirdparty/fc/CMakeLists.txt | |
| mkdir -p build && cd build | |
| cmake -DCMAKE_BUILD_TYPE=Release \ | |
| -DBUILD_SHARED_LIBRARIES=FALSE \ | |
| -DCHAINBASE_CHECK_LOCKING=FALSE .. | |
| make -j"$(nproc)" vizd | |
| # L3 (audit 2026-08-13): the tree's PM unit tests (LMSR vector parity, parimutuel | |
| # conservation, leverage math, meta parsing, chain-properties validate() sweep) were | |
| # only ever run manually — CI proved compilation alone. Gated on the `pm-tests` label | |
| # (like check-boost-range) so the default PR build stays fast; add the label to any PR | |
| # touching PM consensus math, evaluators, crons, or chain properties. Builds only the | |
| # tests/pm targets (chain/protocol/fc compile as make-dependencies); the consensus_sim | |
| # harness is configured by BUILD_CONSENSUS_TESTS but never built here. | |
| pm_tests: | |
| name: PM unit tests (ctest) | |
| runs-on: ubuntu-latest | |
| if: contains(github.event.pull_request.labels.*.name, 'pm-tests') | |
| steps: | |
| - uses: actions/checkout@v6 | |
| with: | |
| submodules: recursive | |
| - name: Install distro Boost and build deps | |
| # Runners fetch packages from azure.archive.ubuntu.com; when that mirror goes quiet | |
| # apt keeps retrying it and the job hangs for hours instead of failing (seen | |
| # 2026-08-19). Pin the canonical mirror, bound the wait, and cap the step. | |
| timeout-minutes: 15 | |
| run: | | |
| set -euo pipefail | |
| sudo sed -i 's|azure.archive.ubuntu.com|archive.ubuntu.com|g' \ | |
| /etc/apt/apt-mirrors.txt /etc/apt/sources.list 2>/dev/null || true | |
| apt="sudo apt-get -o Acquire::Retries=3 -o Acquire::http::Timeout=20 -o Acquire::https::Timeout=20" | |
| $apt update | |
| $apt install -y --no-install-recommends \ | |
| build-essential cmake libboost-all-dev libssl-dev \ | |
| libbz2-dev liblzma-dev libzstd-dev libreadline-dev \ | |
| libtool ncurses-dev pkg-config zlib1g-dev | |
| - name: Configure and build PM test targets | |
| run: | | |
| set -euo pipefail | |
| sed -i '/add_subdirectory(tests)/d' thirdparty/fc/CMakeLists.txt | |
| mkdir -p build && cd build | |
| cmake -DCMAKE_BUILD_TYPE=Release \ | |
| -DBUILD_SHARED_LIBRARIES=FALSE \ | |
| -DCHAINBASE_CHECK_LOCKING=FALSE \ | |
| -DBUILD_CONSENSUS_TESTS=ON .. | |
| make -j"$(nproc)" \ | |
| pm_lmsr_vectors_tests pm_parimutuel_tests pm_leverage_tests \ | |
| pm_meta_parse_tests pm_props_validate_tests | |
| - name: Run ctest (PM suite) | |
| run: | | |
| set -euo pipefail | |
| cd build | |
| ctest -R '^pm_' --output-on-failure |