Skip to content
Draft
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
2 changes: 1 addition & 1 deletion .github/actions/cache-svm-artifacts/action.yml
Original file line number Diff line number Diff line change
Expand Up @@ -26,7 +26,7 @@ runs:
# The job that generates the artifacts is responsible for archiving them to the cache tarball. This avoids any
# conflicts with other caching actions that might have cleaned some of cached contents.
path: svm-${{ inputs.type }}.tar
key: svm-${{ inputs.type }}-${{ runner.os }}-node-${{ steps.resolved-node.outputs.version }}-${{ hashFiles('yarn.lock', 'Cargo.lock', 'programs/**/Cargo.toml', 'programs/**/Xargo.toml', 'programs/**/*.rs', 'scripts/svm/buildHelpers/**') }}
key: svm-${{ inputs.type }}-${{ runner.os }}-node-${{ steps.resolved-node.outputs.version }}-${{ hashFiles('Cargo.toml', 'Anchor.toml', 'verified-build.json', '.github/actions/setup-solana-anchor/**', 'yarn.lock', 'Cargo.lock', 'programs/**/Cargo.toml', 'programs/**/Xargo.toml', 'programs/**/*.rs', 'idls/**/*.json', 'scripts/svm/buildHelpers/**') }}
- name: Unpack restored SVM artifacts
if: steps.svm-artifacts-cache.outputs.cache-hit == 'true'
shell: bash
Expand Down
58 changes: 52 additions & 6 deletions .github/actions/setup-solana-anchor/action.yml
Original file line number Diff line number Diff line change
Expand Up @@ -14,12 +14,58 @@ runs:
uses: ./.github/actions/setup-node-if-needed
with:
node_version: ${{ inputs.node_version }}
# Host Cargo is used for IDLs/unit tests; the verified image pins the SBF compiler.
- name: Install host Rust
uses: dtolnay/rust-toolchain@stable
- name: Extract Solana versions
uses: solana-developers/github-actions/extract-versions@v0.2.5
id: versions
- name: Setup Anchor & Solana
uses: solana-developers/github-actions/setup-all@v0.2.5
shell: bash
run: |
node <<'NODE' >> "$GITHUB_OUTPUT"
const fs = require("fs");
const config = fs.readFileSync("Anchor.toml", "utf8");
for (const name of ["solana_version", "anchor_version"]) {
const match = config.match(new RegExp(`^${name} = "([0-9.]+)"$`, "m"));
if (!match) throw new Error(`Missing ${name} in Anchor.toml`);
console.log(`${name}=${match[1]}`);
}
NODE
- name: Cache SVM tools
uses: actions/cache@v4
with:
anchor_version: ${{ steps.versions.outputs.anchor_version }}
solana_version: ${{ steps.versions.outputs.solana_version }}
verify_version: ${{ inputs.verify_version }}
path: |
~/svm-tools
~/.cache/solana
key: svm-tools-${{ runner.os }}-${{ runner.arch }}-solana-${{ steps.versions.outputs.solana_version }}-anchor-${{ steps.versions.outputs.anchor_version }}-verify-${{ inputs.verify_version }}-v1
- name: Install pinned Solana and Anchor release binaries
shell: bash
env:
SOLANA_VERSION: ${{ steps.versions.outputs.solana_version }}
ANCHOR_VERSION: ${{ steps.versions.outputs.anchor_version }}
VERIFY_VERSION: ${{ inputs.verify_version }}
run: |
set -euo pipefail
tools="$HOME/svm-tools"
mkdir -p "$tools/bin"
if [ ! -x "$tools/solana-release/bin/solana" ]; then
curl -sSfL --retry 3 "https://github.com/anza-xyz/agave/releases/download/v${SOLANA_VERSION}/solana-release-x86_64-unknown-linux-gnu.tar.bz2" -o "$RUNNER_TEMP/solana-release.tar.bz2"
tar -xjf "$RUNNER_TEMP/solana-release.tar.bz2" -C "$tools"
fi
if [ ! -x "$tools/bin/anchor" ]; then
curl -sSfL --retry 3 "https://github.com/otter-sec/anchor/releases/download/v${ANCHOR_VERSION}/anchor-${ANCHOR_VERSION}-x86_64-unknown-linux-gnu" -o "$tools/bin/anchor"
chmod +x "$tools/bin/anchor"
fi
"$tools/solana-release/bin/solana" --version | grep -F "solana-cli ${SOLANA_VERSION} "
test "$("$tools/bin/anchor" --version)" = "anchor-cli ${ANCHOR_VERSION}"
if [ -n "$VERIFY_VERSION" ]; then
if [ ! -x "$tools/bin/solana-verify" ]; then
curl -sSfL --retry 3 "https://github.com/solana-foundation/solana-verifiable-build/releases/download/v${VERIFY_VERSION}/solana-verify-${VERIFY_VERSION}-linux" -o "$tools/bin/solana-verify"
chmod +x "$tools/bin/solana-verify"
fi
test "$("$tools/bin/solana-verify" --version)" = "solana-verify ${VERIFY_VERSION}"
test "$VERIFY_VERSION" = "$(node -p 'require("./verified-build.json").solana_verify_version')"
checksum=$(node -p 'require("./verified-build.json").solana_verify_sha256.linux')
echo "$checksum $tools/bin/solana-verify" | sha256sum --check
fi
echo "$tools/solana-release/bin" >> "$GITHUB_PATH"
echo "$tools/bin" >> "$GITHUB_PATH"
15 changes: 14 additions & 1 deletion .github/workflows/pr.yml
Original file line number Diff line number Diff line change
Expand Up @@ -140,11 +140,21 @@ jobs:
with:
filters: |
svm:
- 'Anchor.toml'
- 'verified-build.json'
- 'Cargo.toml'
- 'Cargo.lock'
- 'package.json'
- 'yarn.lock'
- '.github/actions/setup-solana-anchor/**'
- '.github/workflows/pr.yml'
- 'programs/**'
- 'idls/**'
- 'scripts/svm/**'
- 'src/svm/**'
- 'test/svm/**'
- 'test/svm-gateway/**'
- 'test/svm-production/**'
- name: Download SVM artifacts
uses: actions/download-artifact@v4
with:
Expand Down Expand Up @@ -173,7 +183,10 @@ jobs:
run: tar -cf svm-verified-test-binaries.tar target/deploy
- name: Test verified SVM build
if: steps.filter.outputs.svm == 'true'
run: anchor test --skip-build
run: anchor test --skip-build --validator legacy
- name: Test verified production binary in a fresh ledger
if: steps.filter.outputs.svm == 'true'
run: yarn test-svm-production
build-ts:
name: Build TypeScript
needs:
Expand Down
5 changes: 5 additions & 0 deletions Anchor.toml
Original file line number Diff line number Diff line change
@@ -1,4 +1,7 @@
[toolchain]
anchor_version = "1.1.2"
solana_version = "4.1.2"
package_manager = "yarn"

[features]
resolution = true
Expand Down Expand Up @@ -70,6 +73,8 @@ repayRentFundDebtSponsoredCctpSrc = "NODE_NO_WARNINGS=1 yarn run ts-node ./scrip

[test]
upgradeable = true
# Agave 4.x genesis loading and Circle clones can exceed Anchor's five-second default.
startup_wait = 60000

[test.validator]
url = "https://api.mainnet-beta.solana.com"
Expand Down
Loading
Loading