| name: Compliance Checks |
| |
| on: |
| pull_request: |
| types: |
| - edited |
| - opened |
| - reopened |
| - synchronize |
| |
| permissions: |
| contents: read |
| |
| concurrency: |
| group: ${{ github.workflow }}-${{ github.event_name }}-${{ github.head_ref || github.ref }} |
| cancel-in-progress: true |
| |
| jobs: |
| check_compliance: |
| runs-on: ubuntu-24.04 |
| timeout-minutes: 30 |
| name: Run compliance checks on patch series (PR) |
| steps: |
| - name: Update PATH for west |
| run: | |
| echo "$HOME/.local/bin" >> $GITHUB_PATH |
| |
| - name: Checkout the code |
| uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 |
| with: |
| persist-credentials: false |
| ref: ${{ github.event.pull_request.head.sha }} |
| fetch-depth: 0 |
| |
| - name: Rebase onto the target branch |
| env: |
| BASE_REF: ${{ github.base_ref }} |
| run: | |
| git config --global user.email "you@example.com" |
| git config --global user.name "Your Name" |
| git remote -v |
| # Ensure there's no merge commits in the PR |
| [[ "$(git rev-list --merges --count origin/${BASE_REF}..)" == "0" ]] || \ |
| (echo "::error ::Merge commits not allowed, rebase instead";false) |
| rm -fr ".git/rebase-apply" |
| rm -fr ".git/rebase-merge" |
| git rebase origin/${BASE_REF} |
| git clean -f -d |
| # debug |
| git log --pretty=oneline | head -n 10 |
| |
| - name: Set up Python |
| uses: actions/setup-python@5fda3b95a4ea91299a34e894583c3862153e4b97 # v7.0.0 |
| with: |
| python-version: 3.12 |
| cache: pip |
| cache-dependency-path: scripts/requirements-actions.txt |
| |
| - name: Install Python packages |
| run: | |
| pip install -r scripts/requirements-actions.txt --require-hashes |
| |
| - name: west setup |
| run: | |
| west init -l . || true |
| west config manifest.group-filter -- +ci,-optional |
| west update -o=--depth=1 -n 2>&1 1> west.update.log || west update -o=--depth=1 -n 2>&1 1> west.update2.log |
| |
| - name: Setup Node.js |
| uses: actions/setup-node@820762786026740c76f36085b0efc47a31fe5020 # v7.0.0 |
| with: |
| node-version: "lts/*" |
| cache: npm |
| check-latest: true |
| cache-dependency-path: ./scripts/ci/package-lock.json |
| |
| - name: Install Node dependencies |
| run: npm --prefix ./scripts/ci ci |
| |
| - name: Run Compliance Tests |
| continue-on-error: true |
| id: compliance |
| env: |
| BASE_REF: ${{ github.base_ref }} |
| run: | |
| export ZEPHYR_BASE=$PWD |
| # debug |
| ls -la |
| git log --pretty=oneline | head -n 10 |
| # Increase rename limit to allow for large PRs |
| git config diff.renameLimit 10000 |
| excludes="-e KconfigBasic -e SysbuildKconfigBasic -e ClangFormat" |
| ./scripts/ci/check_compliance.py --annotate $excludes --parallel -c origin/${BASE_REF}.. |
| |
| - name: upload-results |
| uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1 |
| continue-on-error: true |
| with: |
| name: compliance.xml |
| path: compliance.xml |
| |
| - name: Upload dts linter patch |
| uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1 |
| continue-on-error: true |
| if: hashFiles('dts_linter.patch') != '' |
| with: |
| name: dts_linter.patch |
| path: dts_linter.patch |
| |
| - name: check-warns |
| run: | |
| if [[ ! -s "compliance.xml" ]]; then |
| exit 1; |
| fi |
| |
| warns=("ClangFormat" "LicenseAndCopyrightCheck") |
| files=($(./scripts/ci/check_compliance.py -l)) |
| |
| for file in "${files[@]}"; do |
| f="${file}.txt" |
| if [[ -s $f ]]; then |
| results=$(cat $f) |
| results="${results//'%'/'%25'}" |
| results="${results//$'\n'/'%0A'}" |
| results="${results//$'\r'/'%0D'}" |
| |
| if [[ "${warns[@]}" =~ "${file}" ]]; then |
| echo "::warning file=${f}::$results" |
| else |
| echo "::error file=${f}::$results" |
| exit=1 |
| fi |
| fi |
| done |
| |
| if [ "${exit}" == "1" ]; then |
| echo "Compliance error, check for error messages in the \"Run Compliance Tests\" step" |
| echo "You can run this step locally with the ./scripts/ci/check_compliance.py script." |
| exit 1; |
| fi |