Build macOS wheels is the pull-request and main-branch gate. Its first job runs the driver on CPython 3.9–3.13, with a fresh DM8 database per version on GitHub-hosted ARM Linux runners. Each job pulls a community ARM development image by immutable digest, creates a dedicated test account, and runs P0/P1 on pull requests or the complete real-database suite on main and tags. Missing database, failed tests, skipped tests, and an empty JUnit report fail the job. Each version uploads its own JUnit summary and Python/server-version record. The official-image Orb comparison passed the complete suite on all five Python versions; GitHub-hosted runners received HTTP 403 from the vendor download URL.
The data-type and connection-option matrix adds 38 P1 cases. CI sets TZ=Asia/Shanghai during the real-database run so the TIME binding regression remains observable on UTC-hosted runners. The matrix records currently unverified option effects and the high-precision DECIMAL write defect.
A separate ARM Linux job starts DM8 with mandatory SSL and tests a verified encrypted connection on Python 3.10. It also checks paths containing spaces and &, rejection of a wrong or missing server certificate pin, and rejection of a plain server when ssl_path is requested. The repository does not upload the CI client key as an artifact.
Another isolated ARM job restarts DM8 while a DECIMAL(30,8) write is
uncommitted. It requires commit() on that manual transaction connection to
fail, verifies that no row was persisted, and checks that an already-open
autocommit connection can resume querying. This runs through
scripts/verify_dm_restart_transaction.py without access to the user's Orb
network.
The real-database job also exposes its disposable DM8 container to the BFILE tests. Those tests create a binary file in the container and a database directory with the temporary CI administrator credential, grant the test user read access, then remove both resources. Local runs need DM_BFILE_TEST_CONTAINER and DM_CI_ADMIN_PASSWORD to run these cases; without them, the BFILE cases are skipped. CI supplies both and treats skips as a gate failure.
After all five real-database jobs pass, five macOS ARM jobs build and install wheels for CPython 3.9–3.13. They use the existing DPI_HEADERS_TAR_B64 repository secret, so fork pull requests run the real-database matrix but skip macOS wheel builds. The required CI gate check accepts that documented fork exception; it requires both real-database and wheel jobs for trusted branches. Headers and image archives are not committed or uploaded as artifacts. The standalone Integration Tests workflow also runs the full five-version suite nightly and can be started manually. Five-version results and release rehearsal record the exact scope.
No GitHub repository database credentials or self-hosted runner are needed. The CI image is supplied by a third party and is pinned to its tested digest; it is not an official Dameng distribution. The publisher lists its development license expiry as 2027-07-07. Monitor the nightly job, validate image updates locally, and replace the digest only after recording the server version and full regression result.
The DMPYTHON_RELEASE_ENABLED repository variable must remain unset until the vendored Go driver's public redistribution rights are documented. While unset, CI still builds and verifies wheels but does not upload wheel artifacts or publish a GitHub Release. Publishing to PyPI is a separate step.