Skip to content
Open
Show file tree
Hide file tree
Changes from all commits
Commits
Show all changes
19 commits
Select commit Hold shift + click to select a range
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
20 changes: 20 additions & 0 deletions .agents/plugins/marketplace.json
Original file line number Diff line number Diff line change
@@ -0,0 +1,20 @@
{
"name": "idac",
"interface": {
"displayName": "idac"
},
"plugins": [
{
"name": "idac",
"source": {
"source": "local",
"path": "./plugins/idac"
},
"policy": {
"installation": "AVAILABLE",
"authentication": "ON_INSTALL"
},
"category": "Productivity"
}
]
}
21 changes: 21 additions & 0 deletions .github/scripts/sync_agent_plugin_version.py
Original file line number Diff line number Diff line change
@@ -0,0 +1,21 @@
from __future__ import annotations

import json
import sys
from pathlib import Path


def main() -> int:
if len(sys.argv) != 2:
print(f"usage: {Path(sys.argv[0]).name} VERSION", file=sys.stderr)
return 2

manifest_path = Path("plugins/idac/plugin.json")
manifest = json.loads(manifest_path.read_text(encoding="utf-8"))
manifest["version"] = sys.argv[1]
manifest_path.write_text(json.dumps(manifest, indent=2) + "\n", encoding="utf-8")
return 0


if __name__ == "__main__":
raise SystemExit(main())
74 changes: 50 additions & 24 deletions .github/workflows/ci.yml
Original file line number Diff line number Diff line change
Expand Up @@ -28,35 +28,57 @@ jobs:
- name: Lint
run: make lint

test:
name: Test (IDA ${{ matrix.ida-version }})
# Steps run only in the merge queue and only for non-docs changes. The
# skips are per-step because a job-level `if` suppresses matrix expansion
# and the required per-version checks would never report.
unit:
name: Unit tests (Python 3.11, no IDA)
runs-on: ubuntu-latest
permissions:
contents: read
steps:
- name: Check out repository
uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
with:
persist-credentials: false

- name: Install uv
uses: astral-sh/setup-uv@20cfd1bf945f4377ade1205e4dbc17946fc9a30d # v10.0.1
with:
python-version: "3.11"

- name: Test without IDA
run: make test-unit

test:
name: Test (IDA ${{ matrix.ida-version }})
# Steps run for manual dispatches and for non-docs merge-queue changes. The
# skips remain per-step so this required check still reports for pull requests
# and docs-only merges.
runs-on: ubuntu-latest
strategy:
fail-fast: false
matrix:
include:
- ida-version: "9.3"
ida-installer: release/9.3/ida-pro/ida-pro_93_x64linux.run
- ida-version: "9.4"
ida-installer: release/9.4/ida-pro/ida-pro_94_x64linux.run
installer-id: release/9.4/ida-pro/ida-pro_94_x64linux.run
permissions:
contents: read
steps:
- name: Check out repository
if: github.event_name == 'merge_group'
if: github.event_name != 'pull_request'
uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
with:
persist-credentials: false

- name: Detect code changes
if: github.event_name == 'merge_group'
if: github.event_name != 'pull_request'
id: changes
env:
BASE_SHA: ${{ github.event.merge_group.base_sha }}
EVENT_NAME: ${{ github.event_name }}
run: |
if [[ "$EVENT_NAME" == "workflow_dispatch" ]]; then
echo "code=true" >>"$GITHUB_OUTPUT"
exit 0
fi
git fetch --quiet --no-tags --depth=1 origin "$BASE_SHA"
# markdown under src/ and tests/ is test-covered, so it counts as code
if git diff --name-only "$BASE_SHA" HEAD | grep -qvE '^([^/]+\.md|docs/.+|LICENSE|\.gitignore)$'; then
Expand All @@ -65,22 +87,26 @@ jobs:
echo "code=false" >>"$GITHUB_OUTPUT"
fi

- name: Install IDA Pro
if: github.event_name == 'merge_group' && steps.changes.outputs.code == 'true'
id: ida
uses: HexRaysSA/ida-hcli-actions/install-ida@2ff7f4e7c466809cfae6ea20c81264bdb6a33d49 # v1.1.0
with:
installer-id: ${{ matrix.ida-installer }}
license-id: ${{ secrets.IDA_LICENSE_ID }}
api-key: ${{ secrets.HCLI_API_KEY }}
python-version: "3.12"

- name: Install uv
if: github.event_name == 'merge_group' && steps.changes.outputs.code == 'true'
if: github.event_name != 'pull_request' && steps.changes.outputs.code == 'true'
uses: astral-sh/setup-uv@20cfd1bf945f4377ade1205e4dbc17946fc9a30d # v10.0.1
with:
python-version: "3.12"

- name: Test
if: github.event_name == 'merge_group' && steps.changes.outputs.code == 'true'
run: make test
- name: Install IDA Pro
if: github.event_name != 'pull_request' && steps.changes.outputs.code == 'true'
env:
IDA_INSTALLER_ID: ${{ matrix.installer-id }}
IDA_LICENSE_ID: ${{ secrets.IDA_LICENSE_ID }}
HCLI_API_KEY: ${{ secrets.HCLI_API_KEY }}
run: |
export IDADIR="$RUNNER_TEMP/opt/ida"
echo "IDADIR=$IDADIR" >>"$GITHUB_ENV"
uv run --locked hcli ida install --yes --download-id "$IDA_INSTALLER_ID" \
--license-id "$IDA_LICENSE_ID" --install-dir "$IDADIR"

- name: Test through ida-nexus
if: github.event_name != 'pull_request' && steps.changes.outputs.code == 'true'
run: |
uv run --locked ida-nexus worker --probe
make test-integration
15 changes: 7 additions & 8 deletions .github/workflows/prepare-release.yml
Original file line number Diff line number Diff line change
Expand Up @@ -47,6 +47,7 @@ jobs:
fi

release_version=$(uv version --short)
uv run .github/scripts/sync_agent_plugin_version.py "$release_version"
release_tags=$(git ls-remote --tags origin 'v*' | cut -f2 | sed -e 's|^refs/tags/||' -e '/\^{}$/d')
RELEASE_VERSION="$release_version" RELEASE_TAGS="$release_tags" uv run .github/scripts/check_release_version.py

Expand All @@ -59,10 +60,10 @@ jobs:
echo "PREVIOUS_TAG=$(printf '%s\n' "$release_tags" | sort -V | tail -1)" >> "$GITHUB_ENV"

- name: Write changelog entry
uses: anthropics/claude-code-action@1f291e1cfe0f5fc21db2aef19af844591600ade7 # v1.0.206
uses: openai/codex-action@86365089eb2b84e0a8fb0717b304f8bdcb13b20e # v1.12
with:
anthropic_api_key: ${{ secrets.ANTHROPIC_API_KEY }}
github_token: ${{ github.token }}
openai-api-key: ${{ secrets.OPENAI_CODEX_API_KEY }}
permission-profile: ":workspace"
prompt: |
Write the CHANGELOG.md entry for idac ${{ env.RELEASE_VERSION }}.
Publishing the release copies this section verbatim into the
Expand All @@ -73,8 +74,8 @@ jobs:
`git show` on individual commits for detail.

Only changes someone installing idac would notice belong in the
entry: commands, flags, output, behavior and bug fixes, GUI bridge
and idalib backend behavior, packaging, and the bundled skill,
entry: commands, flags, output, behavior and bug fixes, ida-nexus
target and database behavior, packaging, and the bundled skill,
docs, and workspace templates. Mention runtime dependency changes
only when they fix a vulnerability or change behavior.

Expand All @@ -94,8 +95,6 @@ jobs:
the release theme, then short bullets in the user's language, no
PR numbers or commit hashes. Do not modify already-released
sections or any other file.
claude_args: |
--allowedTools "Read,Edit,Write,Bash(git log:*),Bash(git show:*),Bash(git diff:*),Bash(git tag:*)"

- name: Create release branch
id: commit
Expand All @@ -116,7 +115,7 @@ jobs:

git config user.name "github-actions[bot]"
git config user.email "41898282+github-actions[bot]@users.noreply.github.com"
git add pyproject.toml uv.lock CHANGELOG.md
git add pyproject.toml uv.lock CHANGELOG.md plugins/idac/plugin.json
git commit -m "Prepare release v$RELEASE_VERSION"

release_commit=$(git rev-parse HEAD)
Expand Down
Loading
Loading