fix(interop)!: reserve ns and nsapi as interop namespaces (LAB-5876) #290
Workflow file for this run
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
| name: verify | |
| on: | |
| push: | |
| branches: [main] | |
| pull_request: | |
| permissions: | |
| contents: read | |
| jobs: | |
| test-vectors: | |
| name: Test vectors match reference implementations | |
| runs-on: ubuntu-latest | |
| steps: | |
| - uses: actions/checkout@34e114876b0b11c390a56381ad16ebd13914f8d5 # v4 | |
| with: | |
| persist-credentials: false | |
| - uses: actions/setup-python@a26af69be951a213d495a4c3e4e4022e16d87065 # v5 | |
| with: | |
| python-version: "3.12" | |
| - uses: actions/setup-node@49933ea5288caeca8642d1e84afbd3f7d6820020 # v4 | |
| with: | |
| node-version: "22" | |
| - name: Python reference verify (stdlib only) | |
| run: | | |
| # Mutation suite first, same doctrine as the version-floor guard below: | |
| # prove the fail-closed guards still fail before trusting the verify. | |
| python3 tools/test_wire_format_reference.py | |
| python3 tools/interop-reference.py verify | |
| python3 tools/interop-v2-reference.py verify | |
| python3 tools/test_encryption_verify.py | |
| python3 tools/encryption-verify.py | |
| python3 tools/wire-format-reference.py verify | |
| - name: Python reference verify (optional deps — AES-GCM seal + msgpack third-encoder + lz4 C-implementation conformance) | |
| run: | | |
| pip install cryptography==49.0.0 msgpack==1.2.1 lz4==4.4.5 | |
| python3 tools/interop-reference.py verify | |
| python3 tools/interop-v2-reference.py verify | |
| python3 tools/test_encryption_verify.py | |
| python3 tools/encryption-verify.py --require-seal | |
| python3 tools/wire-format-reference.py verify --require-extras | |
| - name: JS cross-check (independent encoder + @noble/hashes + WebCrypto) | |
| run: | | |
| npm init -y >/dev/null | |
| npm install --no-audit --no-fund --ignore-scripts @noble/hashes@2.2.0 | |
| node tools/interop-crosscheck.mjs | |
| - name: Interop v2 JS cross-check (zero-dep independent container parser + LZ4 decoder + WebCrypto) | |
| run: node tools/interop-v2-crosscheck.mjs | |
| - name: Python-frame verify (stdlib only) | |
| run: | | |
| python3 tools/test_python_frame_reference.py | |
| python3 tools/python-frame-reference.py verify | |
| - name: File-backend format verify (stdlib only) | |
| run: python3 tools/file-backend-reference.py | |
| # LAB-1202: the mutation suite runs first so the lz4 allocation guard | |
| # cannot silently degrade to reporting OK (same rule as the version-floors | |
| # suite below). | |
| - name: Python-frame JS cross-check (zero-dep independent reader, full round-trip) | |
| run: | | |
| node tools/test-frame-crosscheck-guard.mjs | |
| node tools/frame-crosscheck.mjs | |
| # Narrow on purpose: catches one facet of ONE of the six matrix incidents | |
| # listed in decisions/matrix-version-verification.md — a version in the SDK | |
| # Overview table stated as a snapshot, true when written and false at the | |
| # next release. The other five need a reader, not a regex. The mutation | |
| # suite runs first so the guard cannot degrade to silently reporting OK. | |
| - name: SDK Overview versions are floors, not snapshots | |
| run: | | |
| python3 tools/test_check_version_floors.py | |
| python3 tools/check-version-floors.py |