Phase 2 of the personal-data catalog spec. resources/privacy/catalog.toml classifies every object in the schema (316) and inbuxa's own JMAP objects (12): each property that can hold personal data, with its categories, and for objects that hold any, whose data it is, where it lives, its scope and what bounds its retention (a named setting where there is one). Twenty sources that are no object -- the log file, exporters, webhooks, spam lookups, the Explain cache, relays and hooks, push, legacy-use records -- carry the same facts plus the settings that turn them on, whether the data leaves the host, and the code that writes it. Classifications of objects that hold data about people are from the spec's source map; the rest are typed from the schema alone (address, IP, secret). tools/fork/privacy-check.py fails CI when an object or inbuxa object has no entry, when a property the schema types as an address, IP or secret is left to its object's default, when an entry names an object, property, setting or code path that is gone, or when it uses a word outside the catalog's vocabulary. --unlisted prints starting entries. strip.py's report gains "Unclassified in the privacy catalog": objects and fields new in an import and not classified, informational like the Enterprise flags. Tested: 13 unit tests (tools/fork/tests): the check passes on this tree; fails on an unclassified object, an address hidden behind a default, a secret in a set or object reference, stale properties, objects, settings and code paths, an unlisted inbuxa object and a word outside the vocabulary; --unlisted's entries; and the strip report on a synthetic import. The check and the tests run in the fork-checks job.
100 lines
4.8 KiB
YAML
100 lines
4.8 KiB
YAML
# CI on the self-hosted Gitea, ported from .gitlab-ci.yml during the move off
|
|
# GitLab (2026-09-22). Gitea reads .gitea/workflows and ignores .github/ once
|
|
# this directory exists; .github/workflows stays as it was for GitHub.
|
|
#
|
|
# Every job runs in an image pinned by digest (tag in the trailing comment),
|
|
# and the only action used is coffey-labs/actions/checkout pinned by SHA. The
|
|
# instance resolves short `uses:` against itself, never GitHub, so nothing
|
|
# unreviewed can be pulled in.
|
|
#
|
|
# Not ported, as on GitLab: publish.yml and release.yml still need doing.
|
|
name: ci
|
|
|
|
on:
|
|
push:
|
|
branches: [main]
|
|
pull_request:
|
|
|
|
concurrency:
|
|
group: ${{ github.workflow }}-${{ github.ref }}
|
|
cancel-in-progress: true
|
|
|
|
jobs:
|
|
# What an upstream merge can bring in or leave behind without a conflict:
|
|
# the upstream name in a new string literal, and a changed upstream file
|
|
# without the AGPL 5(a) notice. Seconds, and needs no toolchain. The notice
|
|
# check diffs against the upstream snapshot branch, hence the full fetch.
|
|
fork-checks:
|
|
runs-on: light
|
|
container:
|
|
image: python:3.13-slim@sha256:8d9d0b8bcf6506481eae4907c18f5e3e7902e629f5f6d684f9e7c32e85e3ddf0 # 3.13-slim
|
|
steps:
|
|
- uses: coffey-labs/actions/checkout@fab0c4d45e0162963965f1555df27b7bed5e20ec
|
|
with:
|
|
fetch-depth: 0
|
|
- run: python3 tools/fork/name-check.py
|
|
- if: always()
|
|
run: python3 tools/fork/notice-check.py
|
|
# Cargo can patch a dependency to a directory in this repository, and
|
|
# the image builds from a context .dockerignore prunes to almost
|
|
# nothing. CI never sees the difference; a release does.
|
|
- if: always()
|
|
run: python3 tools/fork/context-check.py
|
|
# The personal-data catalog must classify every object and field the
|
|
# schema has, and name nothing that is gone.
|
|
- if: always()
|
|
run: python3 tools/fork/privacy-check.py
|
|
- if: always()
|
|
run: python3 -m unittest discover -s tools/fork/tests
|
|
|
|
build:
|
|
# Either runner (host1 or host2): the build needs no docker socket.
|
|
runs-on: light
|
|
container:
|
|
image: rust:1-bookworm@sha256:93ce27a88655056a51dbdd8f5f2d7ddc071c7b0070fb288a37b5a285fc83971e # 1-bookworm
|
|
# A named volume per host that outlives the job: Cargo's registry/git
|
|
# cache and the target dir. Without it every run recompiled RocksDB and
|
|
# the rest of the dependency tree from scratch. Each runner allows this
|
|
# one volume in its valid_volumes; each host keeps its own copy.
|
|
volumes:
|
|
- inbuxa-server-cargo:/cache
|
|
env:
|
|
CARGO_HOME: /cache/cargo-home
|
|
CARGO_TARGET_DIR: /cache/target
|
|
# Dependencies are reused whole; incremental data for the workspace
|
|
# crates would only bloat a shared target dir.
|
|
CARGO_INCREMENTAL: "0"
|
|
steps:
|
|
- uses: coffey-labs/actions/checkout@fab0c4d45e0162963965f1555df27b7bed5e20ec
|
|
# Cargo sizes its parallelism from the host's core count, not the job's
|
|
# CPU cap (2 on host2, 4 on host1); a C++ build of RocksDB at 8-way
|
|
# parallelism inside 6 GB gets OOM-killed. Match jobs to the cap.
|
|
- run: |
|
|
jobs=$(awk '$1 != "max" { printf "%d", $1 / $2 }' /sys/fs/cgroup/cpu.max 2>/dev/null)
|
|
echo "CARGO_BUILD_JOBS=${jobs:-$(nproc)}" >> "$GITHUB_ENV"
|
|
echo "cargo jobs: ${jobs:-$(nproc)}; cache: $(du -sh /cache 2>/dev/null | cut -f1)"
|
|
- run: apt-get update -qq && apt-get install -y -qq --no-install-recommends clang >/dev/null
|
|
- run: cargo build -p inbuxa --locked
|
|
# --no-run: the workflow compiled every test target without running them,
|
|
# which catches a test that no longer builds without paying for the suite.
|
|
- run: cargo test --workspace --locked --no-run
|
|
# The release profile, on main only. It is the profile the image is
|
|
# built with, and it fails in ways the dev profile does not: v2026.9.24
|
|
# was tagged on a commit whose CI was green and whose release build
|
|
# could not compile the scim crate at all. A few minutes per merge is
|
|
# cheaper than finding that out from a tag, which throws away a
|
|
# multi-architecture build and leaves a version half-cut.
|
|
#
|
|
# Pull requests stay on the dev profile, where the wait is worth less.
|
|
- if: github.event_name == 'push'
|
|
run: cargo build -p inbuxa --locked --release
|
|
# Keep the cache from growing without bound: past 60 GB the target dir
|
|
# is dropped and the next build starts cold. The download cache stays.
|
|
# Two builds (dev + test profiles) already fill ~22 GB, so the limit
|
|
# has to sit well above that or it would wipe a warm cache every run.
|
|
- if: always()
|
|
run: |
|
|
used=$(du -s --block-size=1G /cache/target 2>/dev/null | cut -f1)
|
|
echo "target dir: ${used:-0} GB"
|
|
if [ "${used:-0}" -gt 60 ]; then rm -rf /cache/target && echo "over 60 GB: target dir cleared"; fi
|