Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
43 changes: 43 additions & 0 deletions .github/workflows/Documentation.yml
Original file line number Diff line number Diff line change
@@ -0,0 +1,43 @@
# SPDX-License-Identifier: MPL-2.0
# SPDX-FileCopyrightText: 2025-2026 Jonathan D.A. Jewell (hyperpolymath) <j.d.a.jewell@open.ac.uk>

# Documenter build + (main-branch only) GitHub Pages deploy (G13).
#
# Per the estate required-check rule: no `on.*.paths` filter -- this
# workflow always runs so it is never stuck "Expected" on unrelated PRs.

name: Documentation

permissions:
contents: read
pages: write
id-token: write

on:
push:
branches: [main]
pull_request:
branches: [main]

concurrency:
group: ${{ github.workflow }}-${{ github.ref }}
cancel-in-progress: true

jobs:
build:
name: Build docs (Documenter, with doctests)
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v4

- uses: julia-actions/setup-julia@4c0cb0fce8556fdb04a90347310e5db8b1f98fb9 # v2
with:
version: '1.10'

- uses: julia-actions/cache@e33b4bfa0ea7cd9caedd7cb82b0e36956ef40285 # v2

- name: Build documentation (doctest=true)
env:
GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }}
DOCUMENTER_KEY: ${{ secrets.DOCUMENTER_KEY }}
run: julia --project=docs docs/make.jl
80 changes: 80 additions & 0 deletions .github/workflows/estate-rules.yml
Original file line number Diff line number Diff line change
@@ -0,0 +1,80 @@
# SPDX-License-Identifier: MPL-2.0
# SPDX-FileCopyrightText: 2026 Axiom.jl Contributors
#
# Estate Rules — enforces hyperpolymath estate-wide conventions relevant to a
# Julia numerics package: no-Python (banned estate-wide, replacement is
# Julia/Rust/AffineScript), AsciiDoc-by-default under docs/ (excluding the
# docs/wiki/ GitHub-wiki mirror, which is legitimately Markdown because
# GitHub's wiki renderer consumes .md, not .adoc), and no V-lang (vlang.io)
# references — NOT a ban on Zig. Zig is the current estate default for
# APIs/FFI/gateways (hyperpolymath/standards CLAUDE.md, "Estate default
# 2026-05-28"), and Axiom.jl legitimately ships a Zig compute layer
# (zig/, ffi/zig/); a same-named check adapted from an older template
# repo had inverted this (banning the string "zig" itself, seemingly from a
# botched V-lang-ban rename) — do not repeat that mistake here.
#
# Checks are inlined (no external scripts/ dependency) because this repo's
# .github/workflows/ ownership does not include a scripts/ directory of its
# own for these checks.
name: Estate Rules
on:
push:
branches: [main]
pull_request:
concurrency:
group: ${{ github.workflow }}-${{ github.ref }}
cancel-in-progress: true
permissions:
contents: read
jobs:
estate-rules:
runs-on: ubuntu-latest
timeout-minutes: 15
steps:
- name: Checkout
uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2

- name: No Python anywhere (estate-banned; Julia/Rust/AffineScript only)
run: |
HITS=$(find . -type f \( -name '*.py' -o -name '*.pyi' \) \
-not -path './crypto/target/*' \
-not -path './.git/*' \
2>/dev/null || true)
if [ -n "$HITS" ]; then
echo "::error::Python files found — Python is fully banned estate-wide:"
echo "$HITS"
exit 1
fi
echo "PASS: no Python files found"

- name: AsciiDoc by default under docs/ (excluding docs/wiki/ GitHub-wiki mirror)
run: |
HITS=$(find docs -name '*.md' -type f -not -path 'docs/wiki/*' 2>/dev/null || true)
if [ -n "$HITS" ]; then
echo "::error::.md files found under docs/ outside the docs/wiki/ mirror (estate rule: AsciiDoc by default):"
echo "$HITS"
exit 1
fi
echo "PASS: no disallowed .md files under docs/ (docs/wiki/ is the GitHub-wiki Markdown mirror, exempt by design)"

- name: No V-lang references (Zig is the estate default — do not confuse the two)
run: |
# V-lang (vlang.io) was banned 2026-04-10, superseded by Zig. This
# check must NOT match "zig" — Zig is the estate default for
# APIs/FFI/gateways and Axiom.jl ships a legitimate Zig compute
# layer under zig/ and ffi/zig/.
PATTERNS='vlang|v-lang|V-lang|asdf-vlang'
HITS=$(grep -rniE "$PATTERNS" . \
--exclude-dir=.git \
--exclude-dir=node_modules \
--exclude-dir=target \
--include='*.jl' --include='*.rs' --include='*.toml' \
--include='*.zig' --include='*.idr' --include='*.adoc' \
--include='*.a2ml' --include='Justfile' \
2>/dev/null || true)
if [ -n "$HITS" ]; then
echo "::error::V-lang reference(s) found (estate rule: V-lang is banned, replaced by Zig):"
echo "$HITS"
exit 1
fi
echo "PASS: no V-lang references found"
106 changes: 106 additions & 0 deletions .github/workflows/julia-test.yml
Original file line number Diff line number Diff line change
@@ -0,0 +1,106 @@
# SPDX-License-Identifier: MPL-2.0
# SPDX-FileCopyrightText: 2025-2026 Jonathan D.A. Jewell (hyperpolymath) <j.d.a.jewell@open.ac.uk>

# Julia test gate (required check).
#
# `ci.yml`'s `julia-compat` job runs `Pkg.test()` but never builds the
# hybrid Ed448+Dilithium5 crypto cdylib (crypto/), so
# `test/verification/hybrid_signing_tests.jl` always takes the
# `@test_skip` branch there and the real signing path is never exercised
# in CI. This workflow builds the crypto shim first so those tests
# actually run, and also runs the new Aqua/JET quality-gate testsets
# (test/aqua.jl, test/jet.jl).
#
# Per the estate required-check rule: no `on.*.paths` filter on a required
# gate -- a path-filtered required workflow that never triggers is
# reported as permanently "Expected" and blocks merges. This workflow
# always runs.

name: Julia Test Gate

permissions:
contents: read

on:
push:
branches: [main, develop]
pull_request:
branches: [main]
schedule:
- cron: '0 0 * * 0'

concurrency:
group: ${{ github.workflow }}-${{ github.ref }}
cancel-in-progress: true

env:
JULIA_NUM_THREADS: 2

jobs:
test:
name: Julia ${{ matrix.julia-version }} (crypto-enabled) - ubuntu-latest
runs-on: ubuntu-latest
strategy:
fail-fast: false
matrix:
# 1.10 is the LTS floor declared in Project.toml's `[compat] julia`;
# '1' resolves to the current stable release.
julia-version: ['1.10', '1']

steps:
- uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v4

- name: Install Rust toolchain
uses: dtolnay/rust-toolchain@efa25f7f19611383d5b0ccf2d1c8914531636bf9 # stable

- name: Cache Cargo (crypto shim)
uses: actions/cache@668228422ae6a00e4ad889ee87cd7109ec5666a7 # v5.0.4
with:
path: |
~/.cargo/registry
~/.cargo/git
crypto/target
key: ${{ runner.os }}-cargo-crypto-${{ hashFiles('crypto/Cargo.lock') }}

- name: Build hybrid-signing crypto cdylib
run: cd crypto && cargo build --release

- uses: julia-actions/setup-julia@4c0cb0fce8556fdb04a90347310e5db8b1f98fb9 # v2
with:
version: ${{ matrix.julia-version }}

- uses: julia-actions/cache@e33b4bfa0ea7cd9caedd7cb82b0e36956ef40285 # v2

- name: Instantiate / Build / Precompile / Test
run: julia --project=. -e 'using Pkg; Pkg.instantiate(); Pkg.build(); Pkg.precompile(); Pkg.test()'

test-nightly:
name: Julia nightly (crypto-enabled) - ubuntu-latest
runs-on: ubuntu-latest
continue-on-error: true
steps:
- uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v4

- name: Install Rust toolchain
uses: dtolnay/rust-toolchain@efa25f7f19611383d5b0ccf2d1c8914531636bf9 # stable

- name: Cache Cargo (crypto shim)
uses: actions/cache@668228422ae6a00e4ad889ee87cd7109ec5666a7 # v5.0.4
with:
path: |
~/.cargo/registry
~/.cargo/git
crypto/target
key: ${{ runner.os }}-cargo-crypto-${{ hashFiles('crypto/Cargo.lock') }}

- name: Build hybrid-signing crypto cdylib
run: cd crypto && cargo build --release

- uses: julia-actions/setup-julia@4c0cb0fce8556fdb04a90347310e5db8b1f98fb9 # v2
with:
version: nightly

- uses: julia-actions/cache@e33b4bfa0ea7cd9caedd7cb82b0e36956ef40285 # v2

- name: Instantiate / Build / Precompile / Test
run: julia --project=. -e 'using Pkg; Pkg.instantiate(); Pkg.build(); Pkg.precompile(); Pkg.test()'
Loading
Loading