Skip to content

Commit 558a3ca

Browse files
committed
Remove custom JDK processing
1 parent cf7e958 commit 558a3ca

87 files changed

Lines changed: 491 additions & 914 deletions

File tree

Some content is hidden

Large Commits have some content hidden by default. Use the searchbox below for content that may be hidden.

‎.github/dependabot.yml‎

Lines changed: 13 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,13 @@
1+
version: 2
2+
updates:
3+
- package-ecosystem: "github-actions"
4+
directory: "/"
5+
schedule:
6+
interval: "weekly"
7+
target-branch: "main"
8+
9+
- package-ecosystem: "gradle"
10+
directory: "/"
11+
schedule:
12+
interval: "weekly"
13+
target-branch: "main"

‎.github/workflows/ci.yml‎

Lines changed: 43 additions & 49 deletions
Original file line numberDiff line numberDiff line change
@@ -14,51 +14,31 @@ concurrency:
1414
cancel-in-progress: ${{ github.event_name == 'pull_request' }}
1515

1616
jobs:
17-
# Compiles everything, runs the whole test suite, and — because the GraalVM
18-
# plugin wires `nativeCompile` into `assemble` — also produces the
19-
# linux-x86-64 native image. This is the job every other one depends on.
17+
# Jars, plugins and tests. No GraalVM: the native image is gated out of the lifecycle
18+
# tasks (see rootProject.build.gradle) so this job never needs a GraalVM toolchain.
2019
build:
21-
name: build (linux-x86-64)
22-
runs-on: ubuntu-24.04
23-
timeout-minutes: 90
20+
name: build
21+
runs-on: ubuntu-latest
2422
steps:
2523
- uses: actions/checkout@11d5960a326750d5838078e36cf38b85af677262 # v4.4.0
2624
with:
2725
# gradle-git-version derives the project version from `git describe`,
2826
# so it needs the full history and all tags.
2927
fetch-depth: 0
3028

31-
- name: Cache JDKs provisioned by gradle-jdks
32-
uses: actions/cache@0057852bfaa89a56745cba8c7296529d2fc39830 # v4.3.0
33-
with:
34-
path: ~/.gradle/gradle-jdks
35-
key: gradle-jdks-${{ runner.os }}-${{ runner.arch }}-${{ hashFiles('gradle/jdks/**', 'gradle/gradle-daemon-jdk-version') }}
36-
37-
# gradle/actions/setup-gradle needs a JVM on PATH. This is only a bootstrap:
38-
# the Gradle daemon and every toolchain come from gradle-jdks (gradle/jdks/**),
39-
# because gradle.properties disables installation auto-detection. Kept in sync
40-
# with gradle/gradle-daemon-jdk-version.
41-
- name: Set up a bootstrap JDK
29+
# Everything the jars are built with. Gradle provisions no JDKs of its own —
30+
# auto-download is off in gradle.properties — so JDK21_HOME is the toolchain it reads.
31+
- name: Install JDK 21
4232
uses: actions/setup-java@cf277c60eb25467037889841efdb72551f06f6c3 # v4.9.1
4333
with:
4434
distribution: temurin
4535
java-version: '21'
4636

47-
- uses: gradle/actions/setup-gradle@748248ddd2a24f49513d8f472f81c3a07d4d50e1 # v4.4.4
48-
with:
49-
# Only the default branch writes to the shared Gradle cache; every
50-
# other ref reads it. Avoids pinning the trunk name in two places.
51-
cache-read-only: ${{ github.ref != format('refs/heads/{0}', github.event.repository.default_branch) }}
37+
- name: Point Gradle at the JDK
38+
run: echo "JDK21_HOME=${JAVA_HOME_21_X64:-$JAVA_HOME_21_ARM64}" >> "$GITHUB_ENV"
5239

5340
- name: Build
54-
run: ./gradlew --stacktrace --continue build
55-
56-
- name: Upload native image
57-
uses: actions/upload-artifact@ea165f8d65b6e75b540449e92b4886f43607fa02 # v4.6.2
58-
with:
59-
name: native-image-linux-x86-64
60-
path: palantir-java-format-native/build/native/nativeCompile/*
61-
if-no-files-found: error
41+
run: ./gradlew --stacktrace build
6242

6343
- name: Upload jars and plugin distributions
6444
uses: actions/upload-artifact@ea165f8d65b6e75b540449e92b4886f43607fa02 # v4.6.2
@@ -73,52 +53,66 @@ jobs:
7353
if: always()
7454
uses: actions/upload-artifact@ea165f8d65b6e75b540449e92b4886f43607fa02 # v4.6.2
7555
with:
76-
name: test-results-linux-x86-64
56+
name: test-results-build
7757
path: '**/build/test-results/**/*.xml'
7858
if-no-files-found: warn
7959

80-
# The platforms the linux-x86-64 job cannot produce. One explicit job per
81-
# target, so every published binary is traceable to a named workflow run.
60+
# One explicit job per target, so every binary we ship is traceable to a named run.
8261
native:
83-
name: nativeCompile (${{ matrix.platform }})
62+
name: native (${{ matrix.platform }})
8463
needs: build
8564
runs-on: ${{ matrix.runner }}
8665
timeout-minutes: 90
8766
strategy:
8867
fail-fast: false
8968
matrix:
9069
include:
70+
- platform: linux-x86-64
71+
runner: ubuntu-latest
72+
# The tests that drive the binary run once, on the cheapest runner, rather
73+
# than on all four: they are TestKit suites and spawn a Gradle build each.
74+
nativeTests: true
9175
- platform: linux-aarch64
9276
runner: ubuntu-24.04-arm
9377
- platform: macos-aarch64
9478
runner: macos-15
79+
- platform: macos-x86-64
80+
runner: macos-15-intel
81+
9582
steps:
9683
- uses: actions/checkout@11d5960a326750d5838078e36cf38b85af677262 # v4.4.0
9784
with:
9885
fetch-depth: 0
9986

100-
- name: Cache JDKs provisioned by gradle-jdks
101-
uses: actions/cache@0057852bfaa89a56745cba8c7296529d2fc39830 # v4.3.0
87+
# GraalVM 25 compiles the image and nothing else. The binary ships standalone, so it
88+
# owes nobody backwards compatibility — which is what buys the newer compiler and
89+
# --exact-reachability-metadata, a GraalVM 23+ option.
90+
- name: Install GraalVM 25 for the image
91+
uses: graalvm/setup-graalvm@5298d94fb55a4f185c602eeac5de1b553882abe2 # v1.6.4
10292
with:
103-
path: ~/.gradle/gradle-jdks
104-
key: gradle-jdks-${{ runner.os }}-${{ runner.arch }}-${{ hashFiles('gradle/jdks/**', 'gradle/gradle-daemon-jdk-version') }}
105-
106-
# gradle/actions/setup-gradle needs a JVM on PATH. This is only a bootstrap:
107-
# the Gradle daemon and every toolchain come from gradle-jdks (gradle/jdks/**),
108-
# because gradle.properties disables installation auto-detection. Kept in sync
109-
# with gradle/gradle-daemon-jdk-version.
110-
- name: Set up a bootstrap JDK
93+
java-version: '25'
94+
distribution: 'graalvm-community'
95+
github-token: ${{ secrets.GITHUB_TOKEN }}
96+
97+
# After GraalVM, so JAVA_HOME — and the Gradle daemon — is 21 like everywhere else, and
98+
# so the jars this job feeds into native-image are compiled at 21. GRAALVM_HOME survives.
99+
- name: Install JDK 21 for the jars
111100
uses: actions/setup-java@cf277c60eb25467037889841efdb72551f06f6c3 # v4.9.1
112101
with:
113102
distribution: temurin
114103
java-version: '21'
115104

116-
- uses: gradle/actions/setup-gradle@748248ddd2a24f49513d8f472f81c3a07d4d50e1 # v4.4.4
117-
with:
118-
cache-read-only: true
105+
- name: Point Gradle at the JDKs
106+
run: echo "JDK21_HOME=${JAVA_HOME_21_X64:-$JAVA_HOME_21_ARM64}" >> "$GITHUB_ENV"
107+
108+
- name: Compile the native image
109+
run: ./gradlew --stacktrace -PnativeImage=true :palantir-java-format-native:nativeCompile
119110

120-
- name: Compile native image
121-
run: ./gradlew --stacktrace :palantir-java-format-native:nativeCompile
111+
# These reach the binary through a resolved configuration rather than a task dependency,
112+
# so they only work with -PnativeImage=true. Excluded from the `build` job for that reason.
113+
- name: Run the tests that drive the native binary
114+
if: matrix.nativeTests
115+
run: ./gradlew --stacktrace -PnativeImage=true :palantir-java-format-jdk-bootstrap:test :gradle-palantir-java-format:test
122116

123117
- name: Upload native image
124118
uses: actions/upload-artifact@ea165f8d65b6e75b540449e92b4886f43607fa02 # v4.6.2
Lines changed: 48 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,48 @@
1+
name: "CodeQL"
2+
3+
on:
4+
push:
5+
branches: [ 'main' ]
6+
pull_request:
7+
# The branches below must be a subset of the branches above
8+
branches: [ 'main' ]
9+
schedule:
10+
- cron: '33 9 * * 6'
11+
12+
jobs:
13+
analyze:
14+
if: ${{ github.actor != 'dependabot[bot]' }}
15+
name: Analyze
16+
runs-on: ubuntu-latest
17+
permissions:
18+
actions: read
19+
contents: read
20+
security-events: write
21+
22+
steps:
23+
- name: Checkout repository
24+
uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
25+
26+
# Only a bootstrap JVM for the Gradle launcher: the daemon and every toolchain
27+
# are provisioned by gradle-jdks (gradle/jdks/**), because gradle.properties
28+
# disables installation auto-detection.
29+
- name: Set up a bootstrap JDK
30+
uses: actions/setup-java@cf277c60eb25467037889841efdb72551f06f6c3 # v4.9.1
31+
with:
32+
distribution: temurin
33+
java-version: '21'
34+
35+
# Initializes the CodeQL tools for scanning.
36+
# Must run AFTER setup-java so CodeQL hooks into the correct JDK.
37+
- name: Initialize CodeQL
38+
uses: github/codeql-action/init@5595ccaf912efad79be6eef63a5619ff05969be3 # v4
39+
with:
40+
languages: 'java'
41+
42+
- name: Build all source sets for CodeQL
43+
# --no-build-cache forces javac to run even if outputs are cached,
44+
# so CodeQL can intercept all compilation calls.
45+
run: ./gradlew --no-build-cache clean compileJava compileTestJava
46+
47+
- name: Perform CodeQL Analysis
48+
uses: github/codeql-action/analyze@5595ccaf912efad79be6eef63a5619ff05969be3 # v4
Lines changed: 32 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,32 @@
1+
name: Dependabot auto-approve and auto-merge
2+
3+
on: pull_request
4+
5+
permissions:
6+
contents: write
7+
pull-requests: write
8+
9+
jobs:
10+
dependabot:
11+
runs-on: ubuntu-latest
12+
if: github.actor == 'dependabot[bot]'
13+
steps:
14+
- name: Fetch Dependabot metadata
15+
id: metadata
16+
uses: dependabot/fetch-metadata@25dd0e34f4fe68f24cc83900b1fe3fe149efef98 # v3
17+
with:
18+
github-token: "${{ secrets.GITHUB_TOKEN }}"
19+
20+
- name: Approve patch and minor updates
21+
if: steps.metadata.outputs.update-type != 'version-update:semver-major'
22+
run: gh pr review --approve "$PR_URL"
23+
env:
24+
PR_URL: ${{ github.event.pull_request.html_url }}
25+
GH_TOKEN: ${{ secrets.GITHUB_TOKEN }}
26+
27+
- name: Enable auto-merge for patch and minor updates
28+
if: steps.metadata.outputs.update-type != 'version-update:semver-major'
29+
run: gh pr merge --auto --squash "$PR_URL"
30+
env:
31+
PR_URL: ${{ github.event.pull_request.html_url }}
32+
GH_TOKEN: ${{ secrets.GITHUB_TOKEN }}
Lines changed: 28 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,28 @@
1+
name: Submit dependency graph
2+
3+
on:
4+
push:
5+
branches: [ 'main' ]
6+
7+
permissions:
8+
contents: write
9+
10+
jobs:
11+
full-build:
12+
runs-on: ubuntu-latest
13+
steps:
14+
- uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
15+
16+
- name: Set up a bootstrap JDK
17+
uses: actions/setup-java@cf277c60eb25467037889841efdb72551f06f6c3 # v4.9.1
18+
with:
19+
distribution: temurin
20+
java-version: '21'
21+
22+
- name: Submit Dependency Snapshot
23+
uses: gradle/actions/dependency-submission@9c971963bec38e04b3d30dcc455b5382be2fdbfb # v6.3.0
24+
env:
25+
# Only runtime-classpath dependencies of the published modules count as 'runtime';
26+
# annotation processors, Gradle plugin classpaths and test-only dependencies are
27+
# reported as 'development' so Dependabot auto-triage rules can dismiss their alerts.
28+
DEPENDENCY_GRAPH_RUNTIME_INCLUDE_CONFIGURATIONS: 'runtimeClasspath'
Lines changed: 15 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,15 @@
1+
name: Ensure SHA-pinned actions
2+
3+
on:
4+
pull_request:
5+
branches: [ 'main' ]
6+
push:
7+
branches: [ 'main' ]
8+
9+
jobs:
10+
pin-check:
11+
runs-on: ubuntu-latest
12+
steps:
13+
- uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
14+
15+
- uses: zgosalvez/github-actions-ensure-sha-pinned-actions@c5fc58bd0be7a4b94b73ce40250322d5b838a108 # v5.0.7
Lines changed: 19 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,19 @@
1+
name: Update PR branches
2+
3+
on:
4+
push:
5+
branches: [ 'main' ]
6+
schedule:
7+
# Run every hour to catch stuck PRs
8+
- cron: '0 * * * *'
9+
10+
jobs:
11+
update:
12+
runs-on: ubuntu-latest
13+
steps:
14+
- uses: adRise/update-pr-branch@e96e796f4ab23ab388016fdaed7092de99bd71cf # v0.11.1
15+
with:
16+
token: ${{ secrets.BOT_PAT }}
17+
base: 'main'
18+
required_approval_count: 1
19+
require_passed_checks: true

‎.gitignore‎

Lines changed: 1 addition & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -61,3 +61,4 @@ node_modules/
6161

6262
# Gradle JDKs setup
6363
!gradle/*
64+
.intellijPlatform/

0 commit comments

Comments
 (0)