Skip to content
Merged
Show file tree
Hide file tree
Changes from 8 commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
2 changes: 1 addition & 1 deletion .github/ISSUE_TEMPLATE/ask-a-question.md
Original file line number Diff line number Diff line change
Expand Up @@ -46,6 +46,6 @@ These channels provide faster responses for general inquiries.
- Operating System: <!-- e.g., Ubuntu 20.04 -->
- Java version: <!-- e.g., java version "1.8.0_391" -->

## Additional Information
## Additional Information (Optional)

<!-- Any other details that might be helpful -->
2 changes: 1 addition & 1 deletion .github/ISSUE_TEMPLATE/report-a-bug.md
Original file line number Diff line number Diff line change
Expand Up @@ -72,7 +72,7 @@ Include relevant logs from FullNode.jar or other components
[Paste error messages, stack traces, or relevant logs here]
```

## Additional Context
## Additional Context (Optional)

<!-- Add any other context about the problem -->

Expand Down
80 changes: 27 additions & 53 deletions .github/ISSUE_TEMPLATE/request-a-feature.md
Original file line number Diff line number Diff line change
Expand Up @@ -12,28 +12,9 @@ Thank you for contributing to java-tron!
Please provide as much detail as possible to help us evaluate your feature request.
-->

## Background

<!-- Describe the context and motivation for this feature request -->

## Problem Statement

<!-- What problem does this feature solve? What pain points does it address? -->

## Rationale

**Why should this feature exist?**
<!-- Explain the benefits and value this feature would provide -->

**What are the use cases?**
<!-- Describe specific scenarios where this feature would be useful -->

1.
2.
3.

**Who would benefit from this feature?**
<!-- e.g., node operators, developers, end users, validators -->
<!-- Describe the problem this feature solves, the context/motivation, and who would benefit -->

## Proposed Solution

Expand All @@ -52,30 +33,17 @@ Please provide as much detail as possible to help us evaluate your feature reque
**Protocol Changes** (if applicable)
<!-- Describe any changes to the TRON protocol -->

## Testing Strategy

<!-- How should this feature be tested? -->

**Test Scenarios**

1.
2.
3.

**Performance Considerations**
<!-- Describe any performance implications -->

## Scope of Impact

<!-- What parts of the system will be affected? -->

- [ ] Core protocol
- [ ] API/RPC
- [ ] Database
- [ ] Network layer
- [ ] Smart contracts
- [ ] Documentation
- [ ] Other: <!-- specify -->
<!-- Select the system components that will be affected by this feature:
- Core protocol
- API/RPC
- Database
- Network layer
- Smart contracts
- Documentation
- Others, please specify
-->

**Breaking Changes**
<!-- Will this feature introduce any breaking changes? -->
Expand All @@ -90,23 +58,29 @@ Please provide as much detail as possible to help us evaluate your feature reque

**Are you willing to implement this feature?**
<!-- Let us know if you'd like to contribute the implementation -->
- [ ] Yes, I can implement this feature
- [ ] I can help with implementation
- [ ] I need help with implementation
- [ ] I'm just suggesting the idea

**Estimated Complexity**
<!-- Your assessment of implementation complexity -->
- [ ] Low (minor changes)
- [ ] Medium (moderate changes)
- [ ] High (significant changes)
- [ ] Unknown
<!-- Your assessment of implementation complexity, choose among
- Low (minor changes)
- Medium (moderate changes)
- High (significant changes)
- Unknown
-->

## Testing Strategy

<!-- How should this feature be tested? -->

**Test Scenarios**

**Performance Considerations**
<!-- Describe any performance implications -->

## Alternatives Considered
## Alternatives Considered (Optional)

<!-- Describe any alternative solutions or features you've considered -->

## Additional Context
## Additional Context (Optional)

<!-- Add any other context, mockups, diagrams, or examples -->

Expand Down
16 changes: 13 additions & 3 deletions .github/workflows/codeql.yml
Original file line number Diff line number Diff line change
Expand Up @@ -6,6 +6,9 @@ on:
pull_request:
# The branches below must be a subset of the branches above
branches: [ 'develop' ]
paths-ignore: [ '**/*.md', '.gitignore', '**/.gitignore', '.editorconfig',
'.gitattributes', 'docs/**', 'CHANGELOG', '.github/ISSUE_TEMPLATE/**',
'.github/PULL_REQUEST_TEMPLATE/**', '.github/CODEOWNERS' ]
schedule:
- cron: '6 10 * * 0'

Expand All @@ -29,16 +32,23 @@ jobs:

steps:
- name: Checkout repository
uses: actions/checkout@v4
uses: actions/checkout@v5

@cubic-dev-ai cubic-dev-ai Bot Apr 1, 2026 •

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P2: Pin GitHub Actions to immutable commit SHAs instead of major tags to reduce workflow supply-chain risk.

Prompt for AI agents
Check if this issue is valid — if so, understand the root cause and fix it. At .github/workflows/codeql.yml, line 35:

<comment>Pin GitHub Actions to immutable commit SHAs instead of major tags to reduce workflow supply-chain risk.</comment>

<file context>
@@ -29,16 +32,23 @@ jobs:
     steps:
     - name: Checkout repository
-      uses: actions/checkout@v4
+      uses: actions/checkout@v5
 
     # Initializes the CodeQL tools for scanning.
</file context>
Fix with Cubic


# Initializes the CodeQL tools for scanning.
- name: Initialize CodeQL
uses: github/codeql-action/init@v4
with:
languages: ${{ matrix.language }}
build-mode: manual

- name: Autobuild
uses: github/codeql-action/autobuild@v4
- name: Set up JDK 8
uses: actions/setup-java@v5
with:
java-version: '8'
distribution: 'temurin'

- name: Build
run: ./gradlew build -x test --no-daemon

- name: Perform CodeQL Analysis
uses: github/codeql-action/analyze@v4
Expand Down
6 changes: 3 additions & 3 deletions .github/workflows/math-check.yml
Original file line number Diff line number Diff line change
Expand Up @@ -12,7 +12,7 @@ jobs:
runs-on: ubuntu-latest

steps:
- uses: actions/checkout@v4
- uses: actions/checkout@v5

- name: Check for java.lang.Math usage
id: check-math
Expand Down Expand Up @@ -55,14 +55,14 @@ jobs:

- name: Upload findings
if: steps.check-math.outputs.math_found == 'true'
uses: actions/upload-artifact@v4
uses: actions/upload-artifact@v6
with:
name: math-usage-report
path: math_usage.txt

- name: Create comment
if: github.event_name == 'pull_request' && steps.check-math.outputs.math_found == 'true'
uses: actions/github-script@v6
uses: actions/github-script@v8
with:
script: |
const fs = require('fs');
Expand Down
130 changes: 130 additions & 0 deletions .github/workflows/pr-build.yml
Original file line number Diff line number Diff line change
@@ -0,0 +1,130 @@
name: PR Build

on:
pull_request:
branches: [ 'master','develop', 'release_**' ]
types: [ opened, synchronize, reopened ]
paths:
- '**/*.java'
- '**/*.gradle'
- 'build.gradle'
- 'settings.gradle'
- 'gradle.properties'
- 'gradle/**'
- 'gradlew'
- 'gradlew.bat'
Comment thread
cubic-dev-ai[bot] marked this conversation as resolved.
Outdated
workflow_dispatch:

concurrency:
group: ${{ github.workflow }}-${{ github.event.pull_request.number || github.ref }}
cancel-in-progress: true

jobs:
docker-build-debian11:
name: Build debian11 (JDK 8 / x86_64)
runs-on: ubuntu-latest
timeout-minutes: 60

container:
image: eclipse-temurin:8-jdk # base image is Debian 11 (Bullseye)

defaults:
run:
shell: bash

env:
GRADLE_USER_HOME: /github/home/.gradle

steps:
- name: Checkout code
uses: actions/checkout@v5

- name: Install dependencies (Debian + build tools)
run: |
set -euxo pipefail
apt-get update
apt-get install -y git wget unzip build-essential curl jq

- name: Check Java version
run: java -version

- name: Cache Gradle
uses: actions/cache@v4
with:
path: |
/github/home/.gradle/caches
/github/home/.gradle/wrapper
key: debian11-x86_64-gradle-${{ hashFiles('**/*.gradle', '**/gradle-wrapper.properties') }}
restore-keys: |
debian11-x86_64-gradle-

- name: Build (no tests)
run: ./gradlew clean assemble --no-daemon

- name: Run smoke unit tests
run: |
./gradlew \
:framework:test --tests "org.tron.common.ParameterTest" --tests "org.tron.common.ComparatorTest" \
:plugins:test --tests "org.tron.plugins.utils.ByteArrayTest" \
--no-daemon

- name: Generate module coverage reports
run: |
./gradlew jacocoTestReport --no-daemon

- name: Upload coverage reports
if: always()
uses: actions/upload-artifact@v6
with:
name: jacoco-coverage-reports
path: |
**/build/reports/jacoco/test/jacocoTestReport.xml
if-no-files-found: error

coverage:
name: Coverage Check
needs: docker-build-debian11
if: ${{ github.event_name == 'pull_request' }}
runs-on: ubuntu-latest
timeout-minutes: 5
permissions:
pull-requests: write

@cubic-dev-ai cubic-dev-ai Bot Apr 1, 2026 •

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P1: Add contents: read to the coverage job permissions; otherwise checkout/repository reads can fail because only pull-requests: write is granted.

Prompt for AI agents
Check if this issue is valid — if so, understand the root cause and fix it. At .github/workflows/pr-build.yml, line 85:

<comment>Add `contents: read` to the `coverage` job permissions; otherwise checkout/repository reads can fail because only `pull-requests: write` is granted.</comment>

<file context>
@@ -0,0 +1,123 @@
+    runs-on: ubuntu-latest
+    timeout-minutes: 5
+    permissions:
+      pull-requests: write
+
+    steps:
</file context>
Fix with Cubic


steps:
- name: Checkout code
uses: actions/checkout@v5
with:
fetch-depth: 0

- name: Download coverage reports
uses: actions/download-artifact@v4
with:
name: jacoco-coverage-reports
path: coverage-input

- name: Collect coverage report paths
id: collect-xml
run: |
XMLS=$(find coverage-input -name "jacocoTestReport.xml" | sort | paste -sd, -)
if [ -z "$XMLS" ]; then
echo "No jacocoTestReport.xml files found."
exit 1
fi
echo "xmls=$XMLS" >> "$GITHUB_OUTPUT"

- name: Add coverage to PR
id: jacoco
uses: madrapps/jacoco-report@v1.7.2
with:
paths: ${{ steps.collect-xml.outputs.xmls }}
token: ${{ secrets.GITHUB_TOKEN }}
min-coverage-overall: 0
min-coverage-changed-files: 0
skip-if-no-changes: true
title: '## Code Coverage Report'
update-comment: true

- name: Coverage summary
run: |
echo "Overall Coverage: ${{ steps.jacoco.outputs.coverage-overall }}"
echo "Changed Files Coverage: ${{ steps.jacoco.outputs.coverage-changed-files }}"
51 changes: 51 additions & 0 deletions .github/workflows/pr-cancel.yml
Original file line number Diff line number Diff line change
@@ -0,0 +1,51 @@
name: Cancel PR Workflows on Close

on:
pull_request:
types: [ closed ]

permissions:
actions: write

jobs:
cancel:
name: Cancel In-Progress Workflows
if: github.event.pull_request.merged == false
runs-on: ubuntu-latest
steps:
- name: Cancel PR Build and System Test
uses: actions/github-script@v8
with:
script: |
const workflows = ['pr-build.yml', 'system-test.yml', 'codeql.yml'];
const headSha = context.payload.pull_request.head.sha;
const prNumber = context.payload.pull_request.number;

for (const workflowId of workflows) {
for (const status of ['in_progress', 'queued']) {
const runs = await github.paginate(
github.rest.actions.listWorkflowRuns,
{
owner: context.repo.owner,
repo: context.repo.repo,
workflow_id: workflowId,
status,
event: 'pull_request',
per_page: 100,
},
(response) => response.data.workflow_runs
);

for (const run of runs) {
const isTargetPr = !run.pull_requests?.length || run.pull_requests.some((pr) => pr.number === prNumber);
if (run.head_sha === headSha && isTargetPr) {

@cubic-dev-ai cubic-dev-ai Bot Apr 1, 2026 •

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P2: The SHA equality check only cancels runs for the latest commit, so older in-flight runs from the same PR can keep running after the PR is closed.

Prompt for AI agents
Check if this issue is valid — if so, understand the root cause and fix it. At .github/workflows/pr-cancel.yml, line 41:

<comment>The SHA equality check only cancels runs for the latest commit, so older in-flight runs from the same PR can keep running after the PR is closed.</comment>

<file context>
@@ -0,0 +1,51 @@
+
+                for (const run of runs) {
+                  const isTargetPr = !run.pull_requests?.length || run.pull_requests.some((pr) => pr.number === prNumber);
+                  if (run.head_sha === headSha && isTargetPr) {
+                    await github.rest.actions.cancelWorkflowRun({
+                      owner: context.repo.owner,
</file context>
Fix with Cubic

await github.rest.actions.cancelWorkflowRun({
owner: context.repo.owner,
repo: context.repo.repo,
run_id: run.id,
});
console.log(`Cancelled ${workflowId} run #${run.id} (${status})`);
}
}
}
}
Loading
Loading