diff --git a/.github/workflows/codeql.yml b/.github/workflows/codeql.yml index b36896e9c..4b342e644 100644 --- a/.github/workflows/codeql.yml +++ b/.github/workflows/codeql.yml @@ -1,11 +1,28 @@ --- name: codeql +# Push and pull_request run only when Rust, workflow, or script inputs change. +# A Markdown-only commit skips both analyzers. The weekly schedule has no path +# filter, so that scan still covers the whole tree. on: push: branches: [main] + paths: + - '**/*.rs' + - '**/Cargo.toml' + - '**/Cargo.lock' + - '.github/**' + - '**/*.sh' + - '**/*.py' pull_request: branches: [main] + paths: + - '**/*.rs' + - '**/Cargo.toml' + - '**/Cargo.lock' + - '.github/**' + - '**/*.sh' + - '**/*.py' schedule: - cron: "44 3 * * 6" diff --git a/.github/workflows/cutile-rs.yml b/.github/workflows/cutile-rs.yml index 2c3735f6d..74e8f98f7 100644 --- a/.github/workflows/cutile-rs.yml +++ b/.github/workflows/cutile-rs.yml @@ -39,8 +39,11 @@ defaults: jobs: # Tile lane gate: cutile-rs tree plus shared host crates. Skips when only - # cuda-oxide changes. When copy-pr-bot yields no detectable file diff, run - # anyway so the mirror push is never silently skipped. + # cuda-oxide (or any other non-tile path) changes. `any_changed` is a real + # filter: dorny/paths-filter sets an output only for filters declared here, + # and an undeclared name stays empty, which would make `!= 'true'` always + # succeed. When copy-pr-bot yields no detectable file diff, both outputs are + # false and the jobs run anyway so the mirror push is never silently skipped. changes: runs-on: ubuntu-latest outputs: @@ -65,6 +68,10 @@ jobs: - 'rust-toolchain.toml' - '.github/workflows/cutile-rs.yml' - '.github/copy-pr-bot.yaml' + # `*` covers a root file such as AGENTS.md. `**` covers every nested path. + any_changed: + - '*' + - '**' # Exercise the oldest Tile IR assembler, including its lack of # --list-versions. The separate 13.0 lane only checks shared host crates. diff --git a/.github/workflows/naming-guard.yml b/.github/workflows/naming-guard.yml index 5a5a09b6f..b80537eed 100644 --- a/.github/workflows/naming-guard.yml +++ b/.github/workflows/naming-guard.yml @@ -1,11 +1,26 @@ --- name: naming-guard +# check-reserved-prefixes.sh searches only cuda-oxide/crates. The strings it +# looks for are the SIMT link-symbol prefixes owned by reserved-oxide-symbols; +# every other SIMT crate must use that crate's constants. cutile-rs and the +# shared host crates (cuda-bindings, cuda-core, cuda-core-derive, cuda-async) +# are outside that rule, so these paths omit them. Listing those directories +# here would rerun the same search; covering them means adding them to +# SEARCH_ROOTS in the script first. on: push: branches: [main] + paths: + - 'cuda-oxide/crates/**' + - 'cuda-oxide/scripts/check-reserved-prefixes.sh' + - '.github/workflows/naming-guard.yml' pull_request: branches: [main] + paths: + - 'cuda-oxide/crates/**' + - 'cuda-oxide/scripts/check-reserved-prefixes.sh' + - '.github/workflows/naming-guard.yml' concurrency: group: ${{ github.workflow }}-${{ github.ref_name }}