-
Notifications
You must be signed in to change notification settings - Fork 36
test: add RPS settlement stress workflow #129
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Changes from all commits
File filter
Filter by extension
Conversations
Jump to
Diff view
Diff view
There are no files selected for viewing
| Original file line number | Diff line number | Diff line change |
|---|---|---|
| @@ -0,0 +1,126 @@ | ||
| name: Diagnose RPS Settlement | ||
|
|
||
| on: | ||
| pull_request: | ||
| paths: | ||
| - .github/workflows/diagnose-rps-settlement.yml | ||
| workflow_dispatch: | ||
| inputs: | ||
| runs_per_stack: | ||
| description: RPS runs against each fresh MagicBlock stack | ||
| required: true | ||
| default: "5" | ||
| type: choice | ||
| options: | ||
| - "3" | ||
| - "5" | ||
| - "10" | ||
|
|
||
| permissions: | ||
| contents: read | ||
|
|
||
| jobs: | ||
| stress-rps: | ||
| name: stack ${{ matrix.stack }} (${{ inputs.runs_per_stack || '3' }} runs) | ||
| runs-on: ubuntu-latest | ||
| timeout-minutes: 45 | ||
| strategy: | ||
| fail-fast: false | ||
| matrix: | ||
| stack: [1, 2, 3] | ||
|
|
||
| steps: | ||
| - uses: actions/checkout@v4 | ||
|
Contributor
There was a problem hiding this comment. Choose a reason for hiding this commentThe reason will be displayed to describe this comment to others. Learn more. 🔒 Security & Privacy | 🟠 Major | ⚡ Quick win 🧩 Analysis chain🏁 Script executed: #!/bin/bash
set -eu
printf '%s\n' '--- applicable convention files ---'
find /tmp/coderabbit-repo-knowledge/magicblock-labs-magicblock-engine-examples-c4d8eb60 -type f -name '*.md' -print
printf '%s\n' '--- workflow ---'
cat -n .github/workflows/diagnose-rps-settlement.yml
printf '%s\n' '--- relevant repository references ---'
rg -n --glob '.github/workflows/**' 'uses:|id\.json|solana|upload-artifact|checkout|setup-' .Repository: magicblock-labs/magicblock-engine-examples Length of output: 5273 🏁 Script executed: #!/bin/bash
set -eu
for f in /tmp/coderabbit-repo-knowledge/magicblock-labs-magicblock-engine-examples-c4d8eb60/learnings/*.md; do
printf '\n--- %s ---\n' "$f"
cat "$f"
doneRepository: magicblock-labs/magicblock-engine-examples Length of output: 1735 Security Misconfiguration (CWE-829): Inclusion of Functionality from Untrusted Control Sphere Reachability: External · Exploitability: Difficult Pin every GitHub Action to a full commit SHA. The workflow uses mutable references for four third-party actions. 🧰 Tools🪛 zizmor (1.29.0)[warning] 33-33: credential persistence through GitHub Actions artifacts (artipacked): does not set persist-credentials: false (artipacked) [error] 33-33: unpinned action reference (unpinned-uses): action is not pinned to a hash (required by blanket policy) (unpinned-uses) 🤖 Prompt for AI AgentsSource: Linters/SAST tools |
||
|
|
||
| - name: Setup Node.js | ||
| uses: actions/setup-node@v4 | ||
| with: | ||
| node-version: "20.20" | ||
|
|
||
| - name: Enable Corepack | ||
| run: | | ||
| corepack enable | ||
| corepack prepare yarn@1.22.19 --activate | ||
| corepack prepare yarn@1.22.22 --activate | ||
|
|
||
| - name: Setup Rust | ||
| uses: dtolnay/rust-toolchain@stable | ||
| with: | ||
| toolchain: "1.89.0" | ||
|
|
||
| - name: Ensure stable Rust for Anchor IDL | ||
| run: | | ||
| rustup toolchain install stable --profile minimal | ||
| rustup default 1.89.0 | ||
|
|
||
| - name: Install native dependencies | ||
| run: | | ||
| sudo apt-get update | ||
| sudo apt-get install -y libudev-dev pkg-config | ||
|
|
||
| - name: Install Solana | ||
| run: | | ||
| sh -c "$(curl -sSfL https://release.anza.xyz/v3.1.9/install)" | ||
| echo "$HOME/.local/share/solana/install/active_release/bin" >> "$GITHUB_PATH" | ||
|
|
||
| - name: Install Anchor | ||
| run: cargo install --git https://github.com/solana-foundation/anchor --tag v1.0.2 anchor-cli | ||
|
|
||
| - name: Install MagicBlock Ephemeral Validator | ||
| run: npm install -g @magicblock-labs/ephemeral-validator@latest | ||
|
Contributor
There was a problem hiding this comment. Choose a reason for hiding this commentThe reason will be displayed to describe this comment to others. Learn more. 🎯 Functional Correctness | 🟠 Major | ⚡ Quick win 🔎 Supported by static analysis🏁 Script executed: #!/bin/bash
set -euo pipefail
curl -fsSL 'https://registry.npmjs.org/@magicblock-labs%2fephemeral-validator' |
jq -r '.["dist-tags"].latest'Repository: magicblock-labs/magicblock-engine-examples Length of output: 188 🏁 Script executed: #!/bin/bash
set -euo pipefail
printf '%s\n' '--- workflow context ---'
sed -n '55,80p' .github/workflows/diagnose-rps-settlement.yml
printf '%s\n' '--- repository package manifests ---'
find . -maxdepth 3 -type f \( -name 'package.json' -o -name 'package-lock.json' -o -name 'npm-shrinkwrap.json' \) -print
printf '%s\n' '--- scoped repository conventions and learnings ---'
find /tmp/coderabbit-repo-knowledge/magicblock-labs-magicblock-engine-examples-c4d8eb60 \
-maxdepth 2 -type f -name '*.md' -printRepository: magicblock-labs/magicblock-engine-examples Length of output: 2733 Pin the ephemeral-validator package version.
🧰 Tools🪛 zizmor (1.29.0)[warning] 70-70: ad-hoc installation of packages (adhoc-packages): installs a package outside of a lockfile (adhoc-packages) 🤖 Prompt for AI AgentsSource: Linters/SAST tools |
||
|
|
||
| - name: Record tool versions | ||
| run: | | ||
| mkdir -p "rps-diagnostics/stack-${{ matrix.stack }}" | ||
| { | ||
| node --version | ||
| rustc --version | ||
| solana --version | ||
| anchor --version | ||
| npm list -g --depth=0 @magicblock-labs/ephemeral-validator | ||
| mb-stack --version || true | ||
| ephemeral-validator --version || true | ||
| } | tee "rps-diagnostics/stack-${{ matrix.stack }}/versions.log" | ||
|
|
||
| - name: Configure Solana | ||
| env: | ||
| DEVNET_KEYPAIR_JSON: ${{ secrets.DEVNET_KEYPAIR_JSON }} | ||
| run: | | ||
| solana config set --url localhost | ||
| mkdir -p ~/.config/solana | ||
| if [ -n "$DEVNET_KEYPAIR_JSON" ]; then | ||
| printf '%s' "$DEVNET_KEYPAIR_JSON" > ~/.config/solana/id.json | ||
| chmod 600 ~/.config/solana/id.json | ||
| else | ||
| solana-keygen new --no-bip39-passphrase --silent --outfile ~/.config/solana/id.json | ||
| fi | ||
|
|
||
| - name: Run repeated RPS settlement tests | ||
| id: stress | ||
| continue-on-error: true | ||
| env: | ||
| FAIL_FAST: "0" | ||
| TEST_REPETITIONS: ${{ inputs.runs_per_stack || '3' }} | ||
| TEST_LOG_DIR: ${{ github.workspace }}/rps-diagnostics/stack-${{ matrix.stack }} | ||
| run: | | ||
| sudo sysctl -w fs.inotify.max_user_instances=1280 | ||
| sudo sysctl -w fs.inotify.max_user_watches=655360 | ||
| sudo sysctl -w fs.file-max=2097152 | ||
| sudo prlimit --pid $$ --nofile=1000000:1000000 | ||
| bash scripts/test-example.sh rock-paper-scissor | ||
|
|
||
| - name: Upload diagnostic logs | ||
| if: always() | ||
| uses: actions/upload-artifact@v4 | ||
| with: | ||
| name: rps-settlement-stack-${{ matrix.stack }} | ||
| if-no-files-found: error | ||
| retention-days: 14 | ||
| path: | | ||
| rps-diagnostics/stack-${{ matrix.stack }} | ||
| mb-stack.log | ||
| /tmp/build_rock-paper-scissor.log | ||
|
|
||
| - name: Fail when any repetition failed | ||
| if: steps.stress.outcome == 'failure' | ||
| run: exit 1 | ||
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
🎯 Functional Correctness | 🟡 Minor | ⚡ Quick win
🔎 Supported by static analysis
🏁 Script executed:
Repository: magicblock-labs/magicblock-engine-examples
Length of output: 5240
🌐 Web query:
GitHub Actions official documentation inputs context available workflow_dispatch reusable workflows undefined context property empty string expression || fallback💡 Result:
In GitHub Actions, when you access a nonexistent property in a context (such as an input that was not provided), it evaluates to an empty string ("") [1][2]. This behavior is fundamental to how fallback expressions function within the workflow syntax [3]. To implement a fallback mechanism for an input that might be undefined or empty, you can use the logical OR (||) operator [3]. For example,
${{ inputs.my_input || 'default_value' }}will evaluate to 'default_value' ifinputs.my_inputis an empty string [3]. Important technical considerations regarding this behavior include: 1. Empty String vs. Undefined: GitHub Actions does not distinguish between a property that is "missing" and one that is explicitly provided as an empty string; both result in an empty string in the expression context [4][5]. This means that if you define a default value in your workflow configuration, it may be bypassed if an empty string is passed during the workflow invocation [4][5]. 2. Reusable Workflows andworkflow_dispatch: Since the unification of inputs forworkflow_dispatchand reusable workflows (workflow_call), both trigger types populate theinputscontext [6][7]. If you call a reusable workflow without specifying an optional input, it is passed as an empty string, not as a null or undefined value [4]. 3. Expression Fallback Syntax: The expression${{ context.property || 'fallback' }}is the standard way to provide a default value [3]. Because an empty string is considered falsy in this context, the expression will correctly fallback to the value provided on the right side of the || operator [3]. 4. Conditional Logic: If you need to differentiate between an input being "not provided" and "provided as empty," the current architecture of GitHub Actions makes this difficult, as the runner often converts omitted inputs into empty strings before they reach the workflow [5]. A common workaround is to use anifconditional in a separate step or job to detect the empty state and set an environment variable dynamically [8].Citations:
Use the declared default for pull-request runs.
On
pull_request, theinputscontext is unavailable, so both expressions select3. This conflicts with the declaredworkflow_dispatchdefault of5. Change both fallbacks to5, or define one shared default.🤖 Prompt for AI Agents