* Withhold HF_TOKEN from pull_request runs of CI workflows The pull_request-triggered CI workflows check out and execute PR-controlled code (install.sh, .github/scripts/**, tests/**) with secrets.HF_TOKEN in the step environment. For a same-repo PR, GitHub provides repository secrets to the run, so a malicious or compromised branch could modify a checked-out script to read and exfiltrate HF_TOKEN, including by writing it into the uploaded logs/ artifact. HF_TOKEN is an external Hugging Face credential of unknown scope, so this is the high-value exposure. Gate every HF_TOKEN reference in these workflows with `github.event_name != 'pull_request' && secrets.HF_TOKEN || ''`, so the real token flows only on the trusted schedule/push/workflow_dispatch runs and PR runs see an empty string. All model repos used by these jobs are public (unsloth/*-GGUF), so anonymous download still works on PRs; install_llama_prebuilt.py only sends HF auth to Hugging Face hosts and tolerates an absent token. GITHUB_TOKEN (passed as GH_TOKEN) is intentionally left in place: it is the auto-provisioned, job-scoped, contents:read token that expires with the job and gives a same-repo PR author nothing they do not already have, and install_llama_prebuilt.py needs it to authenticate the GitHub releases API or the prebuilt llama.cpp download hits the anonymous rate-limit bucket and 403s. * Trim the HF_TOKEN gating comments to one line per site Comment/whitespace-only: collapse the per-step rationale to a single line and shorten the local-agent-guides header note. No workflow logic changes (verified each file's parsed YAML is identical before/after).
82 lines
2.7 KiB
YAML
82 lines
2.7 KiB
YAML
# SPDX-License-Identifier: AGPL-3.0-only
|
|
# Copyright 2026-present the Unsloth AI Inc. team. All rights reserved.
|
|
|
|
# Proves Studio's llama.cpp install loads on every supported macOS. The heavy
|
|
# app smokes stay single-OS; this matrix covers the OS-version dimension cheaply
|
|
# (install.sh + binary-load assert). Regression guard for the macOS-version
|
|
# selection in studio/install_llama_prebuilt.py.
|
|
|
|
name: Mac Studio Install Matrix CI
|
|
|
|
on:
|
|
pull_request:
|
|
paths:
|
|
- 'studio/install_llama_prebuilt.py'
|
|
- 'studio/setup.sh'
|
|
- 'install.sh'
|
|
- '.github/scripts/assert-llama-loads.sh'
|
|
- '.github/workflows/studio-mac-install-matrix.yml'
|
|
push:
|
|
branches: [main, pip]
|
|
workflow_dispatch:
|
|
|
|
concurrency:
|
|
group: ${{ github.workflow }}-${{ github.ref }}
|
|
cancel-in-progress: true
|
|
|
|
permissions:
|
|
contents: read
|
|
|
|
jobs:
|
|
install-load:
|
|
name: Install + load (${{ matrix.os }})
|
|
runs-on: ${{ matrix.os }}
|
|
timeout-minutes: 25
|
|
continue-on-error: ${{ matrix.experimental }}
|
|
strategy:
|
|
fail-fast: false
|
|
matrix:
|
|
include:
|
|
- os: macos-14 # Apple Silicon, macOS 14 Sonoma
|
|
experimental: false
|
|
- os: macos-15 # Apple Silicon, macOS 15 Sequoia
|
|
experimental: false
|
|
- os: macos-26 # Apple Silicon, macOS 26 Tahoe
|
|
experimental: false
|
|
- os: macos-15-intel # Intel x86_64, macOS 15 (informational)
|
|
experimental: true
|
|
- os: macos-26-intel # Intel x86_64, macOS 26 (last Intel macOS)
|
|
experimental: true
|
|
steps:
|
|
- uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2
|
|
with:
|
|
persist-credentials: false
|
|
|
|
- uses: actions/setup-node@48b55a011bda9f5d6aeb4c2d9c7362e8dae4041e # v6.4.0
|
|
with:
|
|
node-version: '22'
|
|
|
|
- uses: actions/setup-python@a309ff8b426b58ec0e2a45f0f869d46889d02405 # v6.2.0
|
|
with:
|
|
python-version: '3.12'
|
|
|
|
- name: Install Studio (--local, --no-torch)
|
|
env:
|
|
GH_TOKEN: ${{ secrets.GITHUB_TOKEN }}
|
|
# Withheld on PR: this step runs checked-out PR code; public GGUF still downloads.
|
|
HF_TOKEN: ${{ github.event_name != 'pull_request' && secrets.HF_TOKEN || '' }}
|
|
run: |
|
|
mkdir -p logs
|
|
set -o pipefail
|
|
bash install.sh --local --no-torch 2>&1 | tee logs/install.log
|
|
|
|
- name: Assert llama.cpp loads on this macOS
|
|
run: bash .github/scripts/assert-llama-loads.sh
|
|
|
|
- name: Upload install log
|
|
if: always()
|
|
uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1
|
|
with:
|
|
name: mac-install-matrix-${{ matrix.os }}-log
|
|
path: logs/install.log
|
|
retention-days: 7
|