Skip to content

Commit 5bbf2a4

Browse files
committed
less comments
1 parent 7f201d4 commit 5bbf2a4

1 file changed

Lines changed: 1 addition & 35 deletions

File tree

‎.github/workflows/coverity.yml‎

Lines changed: 1 addition & 35 deletions
Original file line numberDiff line numberDiff line change
@@ -1,23 +1,8 @@
11
name: Coverity Scan
22

3-
# Public static analysis via the free Coverity Scan service (scan.coverity.com,
4-
# operated by Black Duck). Coverity is a compiled-language analyzer: it must wrap
5-
# the real C build with `cov-build`, so this workflow installs the Meson build
6-
# stack, compiles the extension under capture, and uploads the result.
7-
#
8-
# One-time setup (done once per project, outside this workflow):
9-
# 1. Register IntelPython/mkl_fft at https://scan.coverity.com/github
10-
# (the project name must match COVERITY_PROJECT below).
11-
# 2. Add two repository secrets (Settings -> Secrets and variables -> Actions):
12-
# COVERITY_SCAN_TOKEN - the project token from the Project Settings tab
13-
# COVERITY_SCAN_EMAIL - a maintainer email for build notifications
14-
#
15-
# Free-tier quota for a project under 100K LOC is 28 builds/week, max 4/day, so
16-
# this runs on a weekly schedule plus on demand rather than per-push.
17-
183
on:
194
schedule:
20-
- cron: "0 1 * * 1" # Mondays 01:00 UTC; well under the free build quota
5+
- cron: "0 1 * * 1"
216
workflow_dispatch:
227

238
permissions:
@@ -32,10 +17,8 @@ env:
3217

3318
jobs:
3419
coverity-scan:
35-
# Forks lack the COVERITY_SCAN_* secrets; only run on the canonical repo.
3620
if: github.repository == 'IntelPython/mkl_fft'
3721
runs-on: ubuntu-latest
38-
# backstop timeout for whole job
3922
timeout-minutes: 60
4023

4124
steps:
@@ -48,8 +31,6 @@ jobs:
4831
python-version: "3.12"
4932
architecture: x64
5033

51-
# Meson locates MKL through its CMake config (see meson.build), so the
52-
# mkl-devel wheel is enough -- no MKLROOT or oneAPI install required.
5334
- name: Install mkl_fft dependencies
5435
run: pip install meson-python ninja cmake cython "numpy>=2" mkl-devel
5536

@@ -63,13 +44,6 @@ jobs:
6344
--data-urlencode "project=${COVERITY_PROJECT}" \
6445
--output cov-analysis.tar.gz \
6546
https://scan.coverity.com/download/linux64
66-
# An invalid token/project returns a small HTML error page, not the
67-
# multi-hundred-MB tarball. Fail loudly with a clear hint if so.
68-
if [ "$(stat -c '%s' cov-analysis.tar.gz)" -lt 1000000 ]; then
69-
echo "::error::Coverity build tool download failed. Verify the COVERITY_SCAN_TOKEN secret and that the registered project name matches '${COVERITY_PROJECT}'."
70-
head -c 512 cov-analysis.tar.gz || true
71-
exit 1
72-
fi
7347
mkdir -p cov-analysis
7448
tar -xzf cov-analysis.tar.gz --strip 1 -C cov-analysis
7549
echo "${PWD}/cov-analysis/bin" >> "$GITHUB_PATH"
@@ -78,18 +52,10 @@ jobs:
7852
run: cov-configure --gcc
7953

8054
- name: Build under cov-build
81-
# cov-build wraps the compiler and can wedge without producing output;
82-
# cap it so a hang fails fast instead of idling until the job timeout.
83-
# 2 translation units normally finish in a couple of minutes.
8455
timeout-minutes: 20
8556
run: |
86-
# Meson caches its build tree in build/ and skips compiling when it is
87-
# up to date, which would leave Coverity with nothing to capture and
88-
# get the upload rejected. Remove it to force a real rebuild.
8957
rm -rf build
9058
cov-build --dir cov-int pip install -e . --no-build-isolation --no-deps 2>&1 | tee cov-build.log
91-
# The extension has 2 C translation units (the generated mklfft.c and
92-
# the Cython-generated _pydfti.c); bail out if none were captured.
9359
if ! grep -qE "Emitted [1-9][0-9]* .*compilation unit" cov-build.log; then
9460
echo "::error::Coverity captured 0 compilation units — the C build did not run under cov-build."
9561
exit 1

0 commit comments

Comments
 (0)