Skip to content

fix(ci): post-rename path refs (unblocks merge train) - #46

Merged
lusoris merged 4 commits into
masterfrom
fix/ci-paths-libvmaf-to-core-20260528
May 28, 2026
Merged

lusoris merged 4 commits into
masterfrom
fix/ci-paths-libvmaf-to-core-20260528

Conversation

@lusoris

@lusoris lusoris commented May 28, 2026

Copy link
Copy Markdown
Contributor

Summary

Post-ADR-0700 rename (libvmaf/ → core/) left stale source-directory
references in five CI workflow files. This caused CodeQL (C/C++ and Python),
Docker image, FFmpeg integration, nightly clang-tidy, and supply-chain
workflows to fail, blocking all merges via the Required Checks Aggregator.
Also fixes Gitleaks (org license) and Dependency Review (graph not enabled).

Type

  • build / ci — tooling / infra

Checklist

  • Commits follow Conventional Commits (the commit-msg hook enforces this).
  • make format && make lint is green locally.
  • Unit tests pass: meson test -C build. — no C changes; YAML-only
  • If I touched any SIMD/GPU code path, I ran /cross-backend-diff and the worst ULP is ≤ 2. — no SIMD/GPU code touched
  • If I touched a feature extractor with SIMD/GPU twins, I either updated every twin or listed the gap under "Known follow-ups" below. — N/A
  • If I added a new .c / .cpp / .cu / .h / .hpp, it has the appropriate license header (see CONTRIBUTING.md). — no C/C++ files added
  • If this is a breaking change, the commit message uses ! or BREAKING CHANGE: and the migration path is documented below. — not a breaking change

Bug-status hygiene (ADR-0165)

  • docs/state.md updated in this PR with a row in the appropriate section.

Netflix golden-data gate (ADR-0024)

  • I did not modify any assertAlmostEqual(...) score in the Netflix golden Python tests.

Cross-backend numerical results

Not applicable — YAML-only CI fix.

Deep-dive deliverables (ADR-0108)

  • Research digest — no digest needed: post-rename path fix, mechanical equivalent.
  • Decision matrix — no decision matrix needed: pure path-rename fix following ADR-0700.
  • AGENTS.md invariant note — no rebase-sensitive invariants.
  • Reproducer / smoke-test command — see Reproducer below.
  • CHANGELOG fragment — changelog.d/fixed/ci-path-rename-fix.md.
  • Rebase note — docs/rebase-notes.md entry added.

Reproducer

# Verify no stale libvmaf/ source-directory refs remain in CI workflows:
grep -rn 'libvmaf/' .github/workflows/ | grep -v 'core/include/libvmaf\|libvmaf\.so\|libvmaf_\|enable_libvmaf\|pkgconfig'
# Expected: no output

# Verify gitleaks CLI installs and runs:
# (On CI: gitleaks detect --source . --config .gitleaks.toml --exit-code 1)

Files fixed:

  • .github/workflows/docker-image.yml — path filters libvmaf/** → core/**
  • .github/workflows/ffmpeg-integration.yml — path filters + meson setup libvmaf → core
  • .github/workflows/supply-chain.yml — meson setup build libvmaf → meson setup build core
  • .github/workflows/nightly.yml — cd libvmaf → cd core; find libvmaf/src → find core/src
  • .github/workflows/tests-and-quality-gates.yml — stale comments
  • .github/workflows/libvmaf-build-matrix.yml — stale comment
  • .github/workflows/security-scans.yml — replace gitleaks/gitleaks-action@v2.3.9 (requires GITLEAKS_LICENSE on org repos) with direct gitleaks CLI binary install; repo dependency graph enabled via GitHub API

Root causes:

  1. ADR-0700 rename PR did not update CI workflow source-directory arguments.
  2. gitleaks-action v2+ requires GITLEAKS_LICENSE for org repos (even public); replaced with free CLI binary.
  3. Dependency graph was not enabled on the repo; enabled via PATCH/PUT API.

no user-discoverable surface change — CI infra repair

Following the ADR-0700 repo-layout rename (libvmaf/ → core/), five CI
workflow files still referenced the old source-directory path. This
caused CodeQL (Python/C++), Docker, FFmpeg-integration, nightly
clang-tidy, and supply-chain builds to fail, blocking all merges via
the Required Checks Aggregator.

Changes:
- docker-image.yml, ffmpeg-integration.yml: path filters libvmaf/** → core/**
- ffmpeg-integration.yml: meson setup sourcedir libvmaf → core (×3)
- supply-chain.yml: meson setup sourcedir libvmaf → core
- nightly.yml: cd libvmaf → cd core; find libvmaf/src libvmaf/tools → core/src core/tools
- tests-and-quality-gates.yml, libvmaf-build-matrix.yml: stale comments updated
- security-scans.yml: replace gitleaks-action@v2.3.9 (requires
  GITLEAKS_LICENSE on org repos) with direct gitleaks CLI binary
  install (Apache-2.0 CLI, no license required); keeps SARIF upload
- Repo: vulnerability alerts + dependency graph enabled via GitHub API

no user-discoverable surface change — CI infra repair
no digest needed: post-rename path fix, mechanical equivalent
no decision matrix needed: pure path-rename fix following ADR-0700
no rebase-sensitive invariants

Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
@lusoris
lusoris enabled auto-merge (squash) May 28, 2026 15:25
@github-advanced-security

Copy link
Copy Markdown

You are seeing this message because GitHub Code Scanning has recently been set up for this repository, or this pull request contains the workflow file for the Code Scanning tool.

What Enabling Code Scanning Means:

  • The 'Security' tab will display more code scanning analysis results (e.g., for the default branch).
  • Depending on your configuration and choice of analysis tool, future pull requests will be annotated with code scanning analysis results.
  • You will be able to see the analysis results for the pull request's branch on this overview once the scans have completed and the checks have passed.

For more information about GitHub Code Scanning, check out the documentation.

PR #46 caught 5 workflow files but 7 more retained `meson setup <BUILDDIR>
-<FLAGS>` without a positional source dir. Since the root-level meson.build
moved into core/ (ADR-0700), those calls fail with "no meson.build found".
Adds `core` between BUILDDIR and the first flag for:

- tests-and-quality-gates.yml: 10 occurrences (build, build-mcp,
  build-coverage, build-coverage-gpu)
- sanitizers.yml: 2
- security-scans.yml: 1
- rust-ci.yml: 1
- lint-and-format.yml: 3 (also swap stale libvmaf sourcedir → core)
- libvmaf-build-matrix.yml: 4 (same swap)
- fuzz.yml: 1 (same swap)

Unblocks the cpp23 merge train (PR #41, #43, #44, #45).

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
@lusoris

lusoris commented May 28, 2026

Copy link
Copy Markdown
Contributor Author

Added supplementary commit fixing 7 more workflow files (tests-and-quality-gates, sanitizers, security-scans, rust-ci, lint-and-format, libvmaf-build-matrix, fuzz) that were missed in first pass. Diff: ~23 ins / ~23 del across 7 files.

test_ansnr_simd.c was deleted by the ansnr drop (PR #38 / ADR-0720) but
the corresponding executable() and test() blocks in core/test/meson.build
were never cleaned up, causing `meson setup` to fail with
"File test_ansnr_simd.c does not exist" on every downstream PR.

Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
…CI runners)

Flips the meson_options.txt default from true to false so CI builds
do not attempt to link libvmafx_tad.a when cargo/cbindgen are absent.
Opt-in with -Denable_rust_features=true on developer machines.

Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
@lusoris

lusoris commented May 28, 2026

Copy link
Copy Markdown
Contributor Author

Added rust default flip — this branch now has both workflow path fixes AND the rust meson_options fix that was on PR #53. Should unblock CI.

@lusoris
lusoris merged commit 3cdc9f2 into master May 28, 2026
35 of 64 checks passed
@lusoris
lusoris deleted the fix/ci-paths-libvmaf-to-core-20260528 branch May 28, 2026 17:18
lusoris added a commit that referenced this pull request May 28, 2026
…60)

PR #46 supplement's sed replaced `meson setup build -` with
`meson setup build core -` globally. Steps that already set
`working-directory: core` (or equivalent) treat `.` as their
source tree, so the appended `core` positional directed meson
to `core/core/` which does not exist — producing "Neither source
directory 'build' nor build directory 'core' exist."

Revert the extra `core` positional in every step that carries
`working-directory: core`:
- tests-and-quality-gates.yml: netflix-golden build, cross-backend
  build, vulkan-vif-cross-backend build (lavapipe + Arc nightly),
  vulkan-parity-matrix-gate build, sanitizer-matrix build,
  dnn-onnx build, build-mcp step, build-coverage step,
  build-coverage-gpu step (10 occurrences).
- sanitizers.yml: ASan+UBSan build, TSan build (2 occurrences).
- security-scans.yml: CodeQL C++ build (1 occurrence).

Steps without working-directory (lint-and-format.yml clang-tidy +
cppcheck, supply-chain.yml release build, rust-ci.yml libvmaf
install, fuzz.yml, sanitizers.yml build-fuzz) run from repo root
and correctly retain the `core` source-dir positional.

Co-authored-by: Claude Sonnet 4.6 <noreply@anthropic.com>
@lusoris lusoris added this to the 1.0.0 — First release milestone Sep 4, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants