ci: schedule nightly race and fuzz, pin actions, add release-check and docs drift
Test / test (push) Successful in 1m37s

Assisted-by: GLM 5.3 Flash
This commit is contained in:
2026-09-22 01:26:48 +02:00
parent 3ffae35a20
commit f6a96379e6
6 changed files with 116 additions and 10 deletions
+40
View File
@@ -0,0 +1,40 @@
# Fuzz smoke, Go. A nightly time-boxed run of the fuzz targets, and a hand
# dispatch when a change asks for it.
#
# Fuzzing is exploration, so it never belongs to the push pipeline; a 30 second
# smoke per target, run nightly, is the compromise that catches a new crash
# within a day without holding the shared box. The targets run the seeds and
# whatever the corpus has gathered; a failure leaves its crashing input in
# testdata/fuzz, which the ordinary suite then reproduces on every push.
#
# Every step is one command, so the step that fails is the gate that failed.
name: Fuzz
on:
workflow_dispatch:
schedule:
# Nightly at 03:30 UTC, after the race sweep has had the box first.
- cron: "30 3 * * *"
env:
# One core: parallelism buys no speed here and costs memory the box does not have.
GOFLAGS: -p=1
GOMAXPROCS: "2"
jobs:
fuzz:
runs-on: fedora
timeout-minutes: 10
steps:
- uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7
- uses: actions/setup-go@924ae3a1cded613372ab5595356fb5720e22ba16 # v6
with:
go-version-file: go.mod
cache: true
- name: Fuzz the parser
run: go test -run '^$' -fuzz FuzzParse -fuzztime=30s -timeout 10m .
- name: Fuzz the encoder
run: go test -run '^$' -fuzz FuzzMarshal -fuzztime=30s -timeout 10m .
+10 -4
View File
@@ -1,14 +1,20 @@
# Race, Go. Dispatched by hand, and run as part of the release gates.
# Race, Go. Dispatched by hand, run nightly on a schedule, and run as part of
# the release gates.
#
# The race detector roughly doubles both time and memory, which the shared runner box
# cannot afford on every push. Locally it belongs to `just gates`, which runs it once per
# task; here it is an explicit decision rather than a routine.
# task; here it is an explicit decision rather than a routine. The schedule is the
# nightly sweep: a failing race on development is known by morning without anyone
# remembering to dispatch it.
#
# Every step is one command, so the step that fails is the gate that failed.
name: Race
on:
workflow_dispatch:
schedule:
# Nightly at 03:00 UTC, the quietest hours of the shared box.
- cron: "0 3 * * *"
env:
# One core: parallelism buys no speed here and costs memory the box does not have.
@@ -20,9 +26,9 @@ jobs:
runs-on: fedora
timeout-minutes: 45
steps:
- uses: actions/checkout@v7
- uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7
- uses: actions/setup-go@v6
- uses: actions/setup-go@924ae3a1cded613372ab5595356fb5720e22ba16 # v6
with:
go-version-file: go.mod
cache: true
+3 -3
View File
@@ -31,9 +31,9 @@ jobs:
runs-on: fedora
timeout-minutes: 10
steps:
- uses: actions/checkout@v7
- uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7
- uses: actions/setup-go@v6
- uses: actions/setup-go@924ae3a1cded613372ab5595356fb5720e22ba16 # v6
with:
# The module is the source of truth for the version, so it cannot drift.
go-version-file: go.mod
@@ -103,7 +103,7 @@ jobs:
contents: read
releases: write
steps:
- uses: actions/checkout@v7
- uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7
- name: Install Perl
# The runner images are minimal and Perl is not guaranteed. The install is a
+2 -2
View File
@@ -43,9 +43,9 @@ jobs:
runs-on: fedora
timeout-minutes: 10
steps:
- uses: actions/checkout@v7
- uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7
- uses: actions/setup-go@v6
- uses: actions/setup-go@924ae3a1cded613372ab5595356fb5720e22ba16 # v6
with:
# The module is the source of truth for the version, so it cannot drift.
go-version-file: go.mod