deepseek-harness/.github/workflows
Tianyi Cui 3c1c6a89b1 test(python): gate installed runtime wheels across release targets (#2953)
* test(python): exercise installed wheels as black boxes

Add an installed-wheel mode that refuses source/editable imports, repository working directories, mismatched SDK/runtime versions, unpinned runtime dependencies, and executables outside the installed runtime distribution. The mode resolves the wheel-owned executable itself, so callers cannot accidentally prove an explicit checkout artifact.

Add a real-API scenario that drives two tool-using turns through the public synchronous SDK, verifies the file bytes outside the agent, checks completed turn/tool events and persistence, and projects provider failures without retaining credential-bearing error text. The existing deterministic scenario set remains the keyless behavior oracle.

Refs #2952.

* ci(python): require installed-wheel checks on every release target

Move the complete deterministic runtime scenarios behind construction and clean installation of the SDK and matching runtime wheels. Each native leg runs outside the checkout with source-resolution environment variables removed; Linux manylinux smokes assert the same installed provenance.

Expand the required pull-request call from Linux x64 to Linux x64, Linux arm64, and macOS arm64. Trusted heads receive only DEEPSEEK_API_KEY_EXTERNAL for a fail-loud live two-turn smoke on each carrier, while fork and Dependabot heads retain the full keyless path without exposing secrets.

Pin the reusable secret declaration, matrix call, aggregate dependency, untrusted-head condition, and live/keyless commands in the workflow contract test.

Refs #2952.

* docs(testing): make installed wheels the Python CI authority

Record the clean-wheel provenance boundary, complete keyless scenario set, trusted real-API contract, secret handling, and three-target required topology in a new implemented testing decision. Update the SEA distribution and portable-CI authorities plus the Python contributor reference to describe the same current state.

Archive the fully superseded Linux-x64-only decision after consolidating its rationale and alternatives into the new owner. Preserve its bilingual triplet as a sealed historical snapshot and redirect every active current-state reference.

Refs #2952.
2026-08-23 16:53:55 +08:00
..
build-exe-for-python-sdk.yml test(python): gate installed runtime wheels across release targets (#2953) 2026-08-23 16:53:55 +08:00
build-preview-cloudflare.yml ci: put the preview-comment marker on its own line 2026-08-21 20:35:34 +08:00
ci-master.yml fix(cic): restore serial-linux drill comment, sync pnpm-isolation note, polish runbook 2026-08-19 17:44:40 +08:00
ci.yml test(python): gate installed runtime wheels across release targets (#2953) 2026-08-23 16:53:55 +08:00
docs-pages.yml ci(docs): publish the documentation site from a release tag 2026-08-21 13:17:06 +08:00
e2b-e2e.yml feat(build): bind client artifacts to build profiles 2026-08-19 18:21:27 +08:00
e2e.yml ci: bound profile e2e subprocess fan-out 2026-08-23 10:59:01 +08:00
expected-filenames.yml ci: disable session telemetry in all GitHub workflows 2026-07-31 01:34:41 +08:00
issue-lifecycle.yml fix(cic): address gray-check PR review - official build, step-level gate, note sync 2026-08-20 15:21:59 +08:00
issue-policy.yml chore: enable Issue management automation 2026-08-03 19:53:36 +08:00
landlock-run-release.yml fix(release): make publication retry, space out, and skip what landed 2026-08-13 15:31:09 +08:00
landlock-run.yml fix(landlock-run): publish under deepseek scope 2026-08-06 14:41:17 +08:00
pi-ai-provider-e2e.yml ci: disable session telemetry in all GitHub workflows 2026-07-31 01:34:41 +08:00
python-release.yml refactor(python): drop now-always-true build.if 2026-08-21 11:55:57 +08:00
release-publish.yml fix(cic): address gray-check PR review - official build, step-level gate, note sync 2026-08-20 15:21:59 +08:00
release-vendor-publish.yml ci: stop PR gray checks from lifecycle and release publish jobs 2026-08-20 13:15:58 +08:00
release-vendor.yml ci: stop PR gray checks from lifecycle and release publish jobs 2026-08-20 13:15:58 +08:00
release.yml ci: stop PR gray checks from lifecycle and release publish jobs 2026-08-20 13:15:58 +08:00
sandbox.yml feat(build): bind client artifacts to build profiles 2026-08-19 18:21:27 +08:00