Repository navigation
Fix CI jobs that check less than they claim; move arm64 to GitHub - #5733
Merged
Merged
Conversation
The CMake 3.31.6 flag list referred to itself before it was defined,
so only JSON_BuildTests was checked with that version. The targets for
the CMake running the build ("_2") were created but never added to
ci_cmake_flags, and the three versions shared one build directory.
JSON_StrictNulHandling was not in the list at all.
Use the 3.5.0 list for 3.31.6, add JSON_StrictNulHandling, and create
one ci_cmake_flag_<flag> target per option for the running CMake with
its own build directory. Also use the function parameter in the
COMMENT, refresh the stale version comment, and let ci_clean remove
the downloaded cmake-<version> directories instead of the long-gone
cmake-3.5.0-Darwin64.
Part of #5715
Signed-off-by: Niels Lohmann <mail@nlohmann.me>
CMake only seeds CMAKE_CXX_FLAGS from the CXXFLAGS environment variable
when the cache entry is unset, so the explicit -DCMAKE_CXX_FLAGS="-stdlib=libc++"
argument made it ignore CXXFLAGS="${CLANG_CXXFLAGS}" entirely. The six
ci_test_standards_clang (..., libcxx) jobs therefore compiled without
-Weverything/-Werror while their libstdc++ siblings did use them.
Pass -stdlib=libc++ through the same CXXFLAGS value instead of a separate
-D argument, and give the target its own build directory
(build_clang_libcxx_cxx${CXX_STANDARD}) so it no longer shares a CMake
cache with the libstdc++ variant. Suppress the resulting
-Wthread-safety-negative finding from libc++'s std::mutex annotations,
which fires on doctest's reporters in this translation unit only.
Part of #5715
Signed-off-by: Niels Lohmann <mail@nlohmann.me>
The with_win_header matrix entry patched Windows.h into single_include/nlohmann/json.hpp before building, but JSON_MultipleHeaders has defaulted to ON since #3532 (2022-06), so CMakeLists.txt points the tests at include/ and the patched single header is never compiled. The job has been a no-op VS2015 build since then. Windows.h coverage already exists through tests/src/unit-windows_h.cpp (#3631), which runs in every MSVC job. Delete the dead matrix entry and its before_build steps, and cite unit-windows_h.cpp from the QA page. Part of #5715 Signed-off-by: Niels Lohmann <mail@nlohmann.me>
No workflow invokes ci_oclint, ci_pvs_studio, or their tool discovery. ci_oclint also had a side effect on every JSON_CI configure: it copied the single header into src_single/all.cpp and added an add_executable() for it without EXCLUDE_FROM_ALL, so a plain build compiled a 1.2 MB translation unit that only that unused target consumed. ci_pvs_studio duplicates the Makefile's pvs_studio target, which is kept. Also drop the duplicate --check-level=exhaustive flag passed twice to the same ci_cppcheck invocation. Part of #5715 Signed-off-by: Niels Lohmann <mail@nlohmann.me>
astyle is deliberately pinned at 3.4.13 because newer versions reformat unrelated lines and this version defines the formatting that check_amalgamation.yml enforces. Without an ignore rule, Dependabot keeps opening PRs for every new astyle release (most recently #4580, #4942, #5445, #5448), each of which fails the amalgamation check and gets closed unmerged. Part of #5715 Signed-off-by: Niels Lohmann <mail@nlohmann.me>
Cirrus CI stopped reporting check runs on develop sometime after d10879b (2026-05-26); every commit since has only github-actions check runs, so .cirrus.yml silently lost its only consumer while README.md, FILES.md and the QA page kept advertising the coverage. Add a ci_test_arm64 job to ubuntu.yml using the same pinned actions/checkout and lukka/get-cmake actions as the other jobs, on the native ubuntu-24.04-arm runner, with a step that confirms uname -m reports aarch64. Delete .cirrus.yml and its README badge and FILES.md section, and update the QA page's arm64 row. Part of #5715 Signed-off-by: Niels Lohmann <mail@nlohmann.me>
…item 4a)
ci_clang_analyze ran scan-build without --status-bugs, so the job
passed whenever the ninja build succeeded, no matter what the
analyzer found ("No bugs found" in a green run gave no signal either
way). It is also missing --use-analyzer=${CLANG_TOOL}, so scan-build
picks whichever clang happens to be first on PATH inside the
silkeh/clang:dev container instead of the one this file already
selected and versioned.
Add --status-bugs and --use-analyzer=${CLANG_TOOL} to the scan-build
invocation. While here, drop the osx.*, webkit.*, fuchsia.*, and
optin.mpi.* checkers from CLANG_ANALYZER_CHECKS: none of them apply
to this portable C++ library, and leaving them enabled only adds
noise once the job can actually fail on a finding.
The job is currently clean (0 bugs), so this alone does not surface
any new finding; it only makes the existing "no bugs found" result
authoritative. This is 4a of 3 independent steps in #5715 item 4;
4b (Infer) and 4c (IWYU) still need their existing findings triaged
before --fail-on-issue/-Xiwyu --error can be added, and are handled
in separate commits.
Signed-off-by: Niels Lohmann <mail@nlohmann.me>
…zel (#5715 item 5) The amalgamation/format check existed three times with three different file sets: the Makefile's pretty/check-amalgamation, the pull_request-only check_amalgamation.yml workflow, and the ci_test_amalgamation CMake target that also runs on direct pushes to develop/master/release/*. The CMake target's glob was a strict subset of the workflow's (missing the docs/mkdocs/docs/examples/*.hpp headers, tests/abi/, tests/cmake_*/project/, tests/cuda_example/, tests/fmt_formatter/, and tests/module_cpp20/), and it never checked BUILD.bazel at all, so a misformatted file in any of those paths, or a stale BUILD.bazel, could reach develop through a direct push even though the PR-only workflow would have caught it. Make ci_test_amalgamation glob the same roots (docs/mkdocs/docs/examples, include, tests) and extensions (*.hpp, *.cpp, *.cu) as check_amalgamation.yml, excluding tests/thirdparty/ and tests/abi/include/nlohmann/ the same way, and regenerate and diff BUILD.bazel next to json.hpp/json_fwd.hpp. Also add docs/mkdocs/docs/examples/*.hpp to the Makefile's pretty/pretty_format targets, which were missing the four custom_*_type.hpp example headers, and drop the stale "called by Travis" comment on check-amalgamation (Travis is gone; nothing currently calls that Makefile target from CI). Leaves the workflow itself untouched: it deliberately runs amalgamate.py from a fresh develop checkout so a PR cannot change the tool that checks it. Overlaps #5610 and #5621, which each add a new amalgamated header and touch the same INDENT_FILES/ci_test_amalgamation/check_amalgamation.yml hunks. Verified with `make check-amalgamation` on this branch: clean, no diff. #5715 item 5. Signed-off-by: Niels Lohmann <mail@nlohmann.me>
…from source (#5715 item 6) ci_get_cmake() downloaded the source tarball of CMake 3.5.0, 3.31.6, and 4.0.0 and compiled each one completely (including CMake's own test helpers) with -DCMAKE_POLICY_VERSION_MINIMUM=3.5 as a workaround for building old CMake with a newer one. On CI this made the ci_cmake_options (ci_cmake_flags) job take about 11 minutes, most of it spent building CMake itself, even though Kitware has published ready-to-run Linux x86_64 archives for all three of these releases since 3.20 (lowercase platform name). On Linux x86_64, download and unpack the prebuilt cmake-<version>-linux-x86_64.tar.gz archive instead and point the existing ${var} output at its bin/cmake, skipping the configure/build steps and CMAKE_POLICY_VERSION_MINIMUM entirely. Keep the previous source build as a fallback for any other platform (macOS, Linux aarch64), since Kitware does not publish binaries for every CMake/platform combination this project might build on. Verify the downloaded archive against Kitware's own published checksum before unpacking it: download cmake-<version>-SHA-256.txt alongside the archive and run `sha256sum -c` on the matching line. A CI job that wgets and untars a binary from a release page with no integrity check is a supply-chain gap; Kitware has published this file for every release since 3.20, so checking it costs one extra download and one grep. As a separate, mechanical change: the ci_cmake_options job's container only needed to stay on ubuntu:focal for the source build's libssl-dev dependency and its own aging toolchain; now that the Linux/x86_64 path never compiles CMake, drop libssl-dev from its apt install line and move the job to ubuntu:24.04 (Ubuntu 20.04 left standard support in May 2025). ci_clean already removes the cmake-3.5.0/cmake-3.31.6/cmake-4.0.0 directories from the #5715 item 3 fix, and the prebuilt path reuses those same directory names, so no further cleanup changes are needed. Overlaps #5598, which edits the same ci_cmake_options matrix line in ubuntu.yml; a rebase may be needed once that lands. Verified locally: `cmake -S . -B build -DJSON_CI=On` configures cleanly on macOS/arm64 (source-build fallback branch) and on Linux/x86_64 in an ubuntu:24.04 Docker container (47 `ci_cmake_flag_*` targets generated, one built and run successfully); `.github/workflows/ubuntu.yml` still parses as valid YAML; downloaded the real v3.31.6 Linux x86_64 archive and SHA-256 file from Kitware and confirmed the `grep | sha256sum -c` pipeline both accepts the genuine file and is anchored to the exact filename (not a prefix match). CI must confirm: the prebuilt-binary path actually runs on the ubuntu-latest/ubuntu:24.04 x86_64 runner, all `ci_cmake_options` entries still pass with the new container's GCC, and the job's runtime drops from roughly 11 minutes. Signed-off-by: Niels Lohmann <mail@nlohmann.me>
…pre-existing ones (#5715 item 4b) ci_infer ran `infer run` without --fail-on-issue, so the job passed regardless of what Pulse found; the last recorded run (35829411620, commit 1054b20) logged "Found 174 issues" and still went green. report.txt was also never uploaded, so the full finding list was only ever visible in the truncated 5-issue console excerpt. Add a repository-root .inferconfig (auto-discovered by Infer; passing --project-root on the `infer run` invocation makes sure it is found even though the analysis runs from build/build_infer) that sets fail-on-issue and disables the six PULSE issue types that made up all 174 findings in that run: PULSE_UNNECESSARY_COPY_ASSIGNMENT (129), PULSE_UNNECESSARY_COPY (22), PULSE_UNNECESSARY_COPY_INTERMEDIATE (15), PULSE_RESOURCE_LEAK (5), PULSE_CONST_REFABLE (2), and PULSE_UNNECESSARY_COPY_OPTIONAL (1). This is a deliberate, narrower fix than "triage and fix everything in this PR": the visible sample is entirely doctest-macro copies in test code (for example tests/src/unit-algorithms.cpp:141 and tests/src/unit-bjdata.cpp:3706), but 169 of the 174 findings were never uploaded anywhere and this PR cannot respectably claim to have fixed issues it never saw, including the resource-leak and const-refable ones that are the most likely to be genuine bugs. Disabling by issue type is a coarser baseline than a per-finding one (Infer has no built-in per-finding baseline short of the two-run `infer reportdiff` workflow, which this repository does not have the CI infrastructure for), but it has the same effect today: the job goes from always green to green-only-when-clean-of-everything-else, so CI now fails the moment a *new* issue type appears, and report.txt is uploaded as a workflow artifact on every run (including failures) so the six disabled types can be triaged and re-enabled incrementally in follow-up PRs. #5715 item 4b. 4a (scan-build) and 4c (IWYU) are handled in separate commits. Verified: .inferconfig parses as JSON, ubuntu.yml still parses as YAML. Infer itself is not available in this environment (v1.3.0 tar.xz requires a Linux x86_64 runner), so CI must confirm that `infer run --project-root ... -- make` picks up .inferconfig, that fail-on-issue takes effect, and that the six disabled types actually suppress the existing findings without also hiding an unrelated new one. Signed-off-by: Niels Lohmann <mail@nlohmann.me>
…CI fail on new ones (#5715 item 4c) ci_single_binaries ran IWYU via CMake's CXX_INCLUDE_WHAT_YOU_USE launcher property, which only printed "Warning: include-what-you-use reported diagnostics" without failing the build: CMake's own __run_co_compile wrapper does not propagate the launched tool's exit code, so even `-Xiwyu --error` could never fail `cmake --build` this way. Verified this empirically by injecting a deliberately-unused #include and confirming the build still exited 0. Fix the findings from the last recorded run (issue #5715 item 4, log 35829411620): - ordered_map.hpp: add <new> (placement new) and nlohmann/detail/abi_macros.hpp; drop <memory> (std::allocator is still visible transitively via <vector>, confirmed by full local and containerized test suite runs). - json_fwd.hpp: drop <memory> (same reasoning). Keep every forward declaration IWYU wanted removed (adl_serializer, basic_json, json_pointer, ordered_map): this file's only job is to forward-declare them for downstream users, so "nothing in this TU uses them" is expected, not a real finding. Mark each with `// IWYU pragma: keep`. - json.hpp: add <cmath>, <cstdint>, <set>, <type_traits>, <unordered_map>, and the detail/abi_macros.hpp, detail/input/json_sax.hpp, detail/meta/detected.hpp, thirdparty/hedley/hedley.hpp includes IWYU says it needs. Do NOT remove adl_serializer.hpp, detail/conversions/from_json.hpp, detail/conversions/to_json.hpp, detail/macro_unscope.hpp, or ordered_map.hpp as IWYU suggests: nothing else in include/nlohmann includes adl_serializer.hpp or ordered_map.hpp, so basic_json<>'s own default template arguments (JSONSerializer = adl_serializer, and ordered_json = basic_json<ordered_map>) would lose their complete type; detail/macro_unscope.hpp is what undoes the JSON_* macros detail/macro_scope.hpp defines earlier in this same file, and removing it leaks those macros into every translation unit that includes <nlohmann/json.hpp>. Verified by actually removing them in a scratch test: the header still "compiles" stand-alone but ordered_json and every macro-using translation unit break. Marked each `// IWYU pragma: keep`. Enforce it with `iwyu_tool` (ships with IWYU, e.g. as /usr/bin/iwyu_tool on Debian/Ubuntu) instead of relying on the launcher property: it reads compile_commands.json (now exported project-wide under JSON_CI) and does return a real exit code for its own analysis, independent of CMake's wrapper. ci_single_binaries now runs it over every src_single/*.cpp with `-Xiwyu --error`, so a *new* finding fails CI. json.hpp itself is excluded from that hard gate: even after every fix above, IWYU's suggestion for one remaining symbol (a container `swap, operator!=` used somewhere via a templated comparator) is not deterministic — repeated, otherwise-identical containerized runs reported <set>, then <unordered_map>, then <map> as "the" header to add/remove for the exact same source. Gating a whole CI job on a nondeterministic suggestion would make ci_single_binaries flaky rather than informative, so json.hpp keeps the existing informational warning (still shown during its normal compile) without failing the build on it. Every other one of the ~50 single-header checks is included in the hard gate. #5715 item 4c. 4a (scan-build) and 4b (Infer) are separate commits. Verified: full local ctest suite (129/129) and the ci_single_binaries target itself both green in a containerized silkeh/clang:dev run (matching the actual CI job) after this fix; a deliberately-reintroduced unused #include in ordered_map.hpp was confirmed to fail `cmake --build ... --target ci_single_binaries` (exit 2) with this change, and to pass without it, on the same container/IWYU version CI uses. `make check-amalgamation` is clean. Compiled with Clang and GCC at -std=c++11/14/17/20 locally with no new warnings. Signed-off-by: Niels Lohmann <mail@nlohmann.me>
Conflicts: - Makefile: pretty formats both develop's json_literals.hpp and this branch's docs/mkdocs/docs/examples/*.hpp - cmake/ci.cmake: ci_test_amalgamation checks both develop's json_literals.hpp and this branch's BUILD.bazel - include/nlohmann/json.hpp: kept <set> (this branch) and <stdexcept> (develop); took develop's move of the global UDLs to json_literals.hpp and kept this branch's IWYU pragma/comment on macro_unscope.hpp - include/nlohmann/ordered_map.hpp: took develop's includes (<tuple>, updated comments) with this branch's <new> instead of <memory> - single_include/nlohmann/json.hpp: regenerated with make amalgamate Signed-off-by: Niels Lohmann <mail@nlohmann.me>
Owner
Author
|
Merged develop into this branch (0d2d205) to resolve conflicts:
Not verified locally: — posted by Claude Code on behalf of @nlohmann |
gregmarr
approved these changes
Sep 30, 2026
Resolve the Makefile conflict by keeping develop's removal of the pretty_format target (#5735); the added docs/mkdocs/docs/examples/*.hpp glob is kept for the pretty target. Signed-off-by: Niels Lohmann <mail@nlohmann.me>
nlohmann
added a commit
that referenced
this pull request
Oct 1, 2026
Conflict resolutions: - value_in_range_of test and SaxCountdown moved to shared headers on develop; dropped the CAPTURE() semicolons there and at the 12 new CAPTURE(x); sites develop added (-Wextra-semi-stmt is no longer suppressed on this branch). - tests/CMakeLists.txt: doctest stays a SYSTEM include; fifo_map is now only on test-regression1's include path (develop). - json_sax.hpp: took develop's shared position handling (already without the malformed -warnings-as-errors NOLINT). - output_adapters.hpp: keep develop's removal of JSON_HEDLEY_NON_NULL(2), keep this branch's NOLINTNEXTLINE. - serializer.hpp: hex_bytes() is gone on develop; keep "\\uXXXX". - ci_clang_analyze: develop (#5733) made the target a working scan-build gate, so this branch no longer removes it; the SCAN_BUILD_TOOL lookup, the ubuntu.yml matrix entry, clang-tools, and the docs follow develop. Signed-off-by: Niels Lohmann <mail@nlohmann.me>
nlohmann
added a commit
that referenced
this pull request
Oct 4, 2026
Signed-off-by: Niels Lohmann <mail@nlohmann.me> #5733 moved ci_cmake_options from ubuntu:focal to ubuntu:24.04, which no longer ships libidn.so.11; the CMake 3.5.0 release binary links against it, so every ci_cmake_flags run has failed since. Install focal's libidn11 package for that matrix entry only.
nlohmann
added a commit
that referenced
this pull request
Oct 4, 2026
* Keep the serializer conversion for objects whose keys cannot be converted #5591 added a test converting nlohmann::json into a basic_json whose string type cannot be constructed from std::string. That instantiates convert_iteratively(), whose members.emplace_back(next.key(), ...) needs exactly that key conversion, and broke the build of unit-alt-string. Dispatch on the key's constructibility and leave such conversions to the serializers, as the levels above the nesting bound already do (#3425). Signed-off-by: Niels Lohmann <mail@nlohmann.me> * Fix the remaining CI failures on develop - unit-wstring: with a 16-bit wchar_t (Windows), a lone surrogate is reported as the ill-formed byte 0xFF since #5704; the std::wstring expectations still had the previous <U+0000>. - ci_single_binaries: json_literals.hpp (#5610) and json.hpp include each other on purpose, and IWYU, not following the cycle, asks to replace json.hpp with json_fwd.hpp. Report its findings without failing the build, as already done for json.hpp. Signed-off-by: Niels Lohmann <mail@nlohmann.me> * Fix the library warnings and noexcept specifications from the merged PRs - binary_reader: rename the error_handler constructor parameter, which shadowed the member (-Wshadow, -Wshadow-field-in-constructor; #5746) - basic_json(copy_construct_tag, ...): declare it noexcept when copying the base class is (GCC 16 -Wnoexcept; #5690) - the scalar-on-left legacy comparison operators: noexcept only when converting the scalar is, like their member counterparts (#5682, #5751) - compare_leaves: use std::is_eq/is_lt/is_gt instead of comparing a std::partial_ordering with 0 (-Wzero-as-null-pointer-constant; #5686) - serializer: silence MSVC C4127 for the EnsureAscii template parameter (#5741, #5746) - clang-tidy: return the sanitized reference in binary_writer, take the key of ordered_map::find_impl by const reference (#5727), and mark the switches over parse_array_index (#5728) - ordered_map: keep <memory> for std::allocator (IWYU) Signed-off-by: Niels Lohmann <mail@nlohmann.me> * Split unit-conversions.cpp so MinGW can link it clang 18 with the MinGW linker failed to link test-conversions_cpp17 ("relocation truncated to fit: IMAGE_REL_AMD64_REL32"). As windows.yml recommends, keep the objects small by splitting the test file. Signed-off-by: Niels Lohmann <mail@nlohmann.me> * Fix the tests added by the merged PRs for all CI configurations - discard the results of dump() and from_*() in CHECK_THROWS with utils::ignore_return_value (GCC -Werror=unused-result) - give unit-bson's huge_string_t a default constructor (MSVC C2512, GCC 5, clang 3.5) - unit-disabled_exceptions: use the literals namespace when the global UDLs are off (ci_test_noglobaludls; #5700) - unit-binary_utf8_strict: expect the JSON pointer prefix with JSON_DIAGNOSTICS (#5741) - skip the tests that rely on exceptions under JSON_NOEXCEPTION (#5678, #5732) - clang-tidy and clang -Werror: static test data, CAPTURE(...);, const-correctness, use-after-move alias, unused conversion operator, a missing <iterator> include Signed-off-by: Niels Lohmann <mail@nlohmann.me> * Title the macro examples and add JSON_STRICT_BINARY_UTF8 to the docset The documentation style check requires "Example: ..." titles on pages with several examples (#5741, #5591) and a docset entry for every macro page. Signed-off-by: Niels Lohmann <mail@nlohmann.me> * Regenerate BUILD.bazel and nlohmann_json.natvis Signed-off-by: Niels Lohmann <mail@nlohmann.me> #5746 added detail/output/error_handler.hpp and #5741 the json_abi_sbu8 ABI tag. * Install libidn11 for the CMake 3.5.0 binary in ci_cmake_flags Signed-off-by: Niels Lohmann <mail@nlohmann.me> #5733 moved ci_cmake_options from ubuntu:focal to ubuntu:24.04, which no longer ships libidn.so.11; the CMake 3.5.0 release binary links against it, so every ci_cmake_flags run has failed since. Install focal's libidn11 package for that matrix entry only. * Suppress Infer's false STACK_VARIABLE_ADDRESS_ESCAPE in get_impl get_impl() returns its local by value. A test added by the merged PRs instantiates it with a type Infer misreads, so ci_infer reported the 2021 code for the first time. Signed-off-by: Niels Lohmann <mail@nlohmann.me> --------- Signed-off-by: Niels Lohmann <mail@nlohmann.me>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
This removes CI/tooling debt found in a technical-debt review of
developat 633de8e: jobs and helper targets that pass while checking less than their name, the README, or the QA page claim (a dead Cirrus arm64 job, libc++ jobs silently missing their warning flags, aci_cmake_flagswiring bug, unused analysis targets, a no-op AppVeyor job, and a Dependabot rule that keeps proposing a version bump the project deliberately blocks). Each commit implements one checklist item from the umbrella issue #5715 and can be reviewed and reverted independently. None of the changes touchinclude/, so they carry no library-behavior, public-API, or ABI impact. The follow-up commits listed under "Remaining checklist items" implement every item that was left open, so this PR now closes #5715; see "Public API" for their effects.Changes
ci_cmake_flagswiring so every option is checked: base the CMake 3.31.6 flag list on the 3.5.0 list instead of a self-reference, addJSON_StrictNulHandling, create oneci_cmake_flag_<flag>target per option for the running CMake with its own build directory, fix theCOMMENTto use the loop variable, refresh the stale version comment, and letci_cleanremove the downloadedcmake-<version>directories (CI: jobs that check less than they claim (dead Cirrus arm64 job, libc++ without warning flags, ci_cmake_flags wiring, static analysis that cannot fail, duplicated amalgamation checks, dead targets) #5715 item 3)ci_test_clang_libcxx_cxx*jobs building without-Weverything/-Werror: pass-stdlib=libc++throughCXXFLAGSinstead of a separate-DCMAKE_CXX_FLAGSargument that was overriding it, give the target its own build directory, and suppress the resulting-Wthread-safety-negativefinding from libc++'sstd::mutexannotations (CI: jobs that check less than they claim (dead Cirrus arm64 job, libc++ without warning flags, ci_cmake_flags wiring, static analysis that cannot fail, duplicated amalgamation checks, dead targets) #5715 item 2)with_win_headerjob:JSON_MultipleHeadershas defaulted toONsince CI: Enable 32bit unit test (3) #3532, so the patched single header it built was never actually compiled; the equivalent coverage already exists viatests/src/unit-windows_h.cppin every MSVC job (CI: jobs that check less than they claim (dead Cirrus arm64 job, libc++ without warning flags, ci_cmake_flags wiring, static analysis that cannot fail, duplicated amalgamation checks, dead targets) #5715 item 8)ci_oclintandci_pvs_studiotargets, including the always-builtsingle_allexecutable thatci_oclintadded as a side effect of everyJSON_CIconfigure, and drop a duplicate--check-level=exhaustiveflag onci_cppcheck(CI: jobs that check less than they claim (dead Cirrus arm64 job, libc++ without warning flags, ci_cmake_flags wiring, static analysis that cannot fail, duplicated amalgamation checks, dead targets) #5715 item 7)ubuntu-24.04-armrunner: Cirrus stopped reporting check runs after 2026-06-07 although.cirrus.yml, the README badge,FILES.md, and the QA page still advertised the coverage; addci_test_arm64toubuntu.ymlwith the same pinned actions used elsewhere, delete.cirrus.yml, and update the README/FILES.md/QA page accordingly (CI: jobs that check less than they claim (dead Cirrus arm64 job, libc++ without warning flags, ci_cmake_flags wiring, static analysis that cannot fail, duplicated amalgamation checks, dead targets) #5715 item 1)Tests
make check-amalgamation(amalgamate +make pretty+gen_bazel_build_file) ran clean on the branch tip with no diff afterward; consistent with no commit touchinginclude/.ci_cmake_flags: configured with-DJSON_CI=ONand ranninja -t query ci_cmake_flags, confirming 47 flag-check targets across the 3.5.0/3.31.6/4.0.0/current-CMake groups, includingci_cmake_flag_json_strictnulhandling; built that target directly and it configured and printed the expected "Strict NUL-byte handling enabled" note.ci_test_clang_libcxx_cxx*: vianinja -t commands, confirmed the generated command carries-stdlib=libc++insideCXXFLAGSwith no conflicting-DCMAKE_CXX_FLAGS; built and ranci_test_clang_libcxx_cxx11locally with AppleClang (C++11): configured clean, built with zero warnings, 106/106 tests passed; the added__has_warning-guarded pragma matches an existing precedent intests/src/unit-regression3.cppand was also compiled standalone with warnings clean.with_win_headerremoval:git grep with_win_headerfinds nothing left; confirmedtests/src/unit-windows_h.cppexists and runs in every MSVC job.ci_oclint/ci_pvs_studioremoval: configured with-DJSON_CI=ONand confirmed vianinja -t targetsthatci_oclint,ci_pvs_studio, andsingle_allare gone; greppedCMakeLists.txt,Makefile, and the workflows for any remaining reference (none found); confirmed the duplicate cppcheck flag was deduplicated.python3 -c "import yaml; yaml.safe_load(...)".ubuntu.ymlYAML parses cleanly; confirmed the new job reuses the same pinnedactions/checkout/lukka/get-cmakeSHAs and container pattern as the existingci_test_gccjob;grep -rni cirrusacross*.md/*.yml/*.yamlnow matches only the historicalChangeLog.mdentry.CI must confirm:
ci_test_clang_libcxx_cxx*jobs go green on Linux + libc++, where-Weverything/-Werroractually fire for the first time and the-Wthread-safety-negativesuppression proves sufficient.ci_cmake_options(ci_cmake_flags) passes for all three pinned CMake downloads (3.5.0, 3.31.6, 4.0.0), not just the current-CMake group exercised locally.ci_test_arm64job actually schedules onubuntu-24.04-armand itsuname -mstep printsaarch64.ubuntu.ymlci_cppcheck/ci_single_binaries/general build jobs stay green with the removed targets gone.Public API
No breaking changes. All six commits are CI/tooling configuration only; none touches
include/, so there is no change to any public-namespace name, behavior, or compile error.Follow-up commits:
json.hpp,json_fwd.hpp(<memory>dropped) andordered_map.hpp(<memory>replaced by<new>). Code that relied on these headers pulling in<memory>transitively may need its own include.Remaining checklist items (follow-up commits)
The items that were left open are now implemented here as well, so this PR closes #5715.
29c8d0e96Make scan-build fail on findings (--status-bugs,--use-analyzer) and drop the irrelevant osx/webkit/fuchsia/MPI checkers; the job is currently clean (CI: jobs that check less than they claim (dead Cirrus arm64 job, libc++ without warning flags, ci_cmake_flags wiring, static analysis that cannot fail, duplicated amalgamation checks, dead targets) #5715 item 4a)00af70f84Makeci_test_amalgamation's file set matchcheck_amalgamation.ymlexactly and also regenerate and diffBUILD.bazel; adddocs/mkdocs/docs/examples/*.hpptomake pretty(CI: jobs that check less than they claim (dead Cirrus arm64 job, libc++ without warning flags, ci_cmake_flags wiring, static analysis that cannot fail, duplicated amalgamation checks, dead targets) #5715 item 5)1fe751446Download Kitware's prebuilt CMake on Linux x86_64 instead of building it from source, verified against the release'sSHA-256.txt(source build stays as fallback elsewhere); moveci_cmake_optionsfromubuntu:focaltoubuntu:24.04and droplibssl-dev(CI: jobs that check less than they claim (dead Cirrus arm64 job, libc++ without warning flags, ci_cmake_flags wiring, static analysis that cannot fail, duplicated amalgamation checks, dead targets) #5715 item 6)589dda809Make Infer fail on findings: a checked-in.inferconfigwithfail-on-issue, the six issue types of the 174 existing findings (PULSE_UNNECESSARY_COPY*,PULSE_RESOURCE_LEAK,PULSE_CONST_REFABLE) disabled as the issue allows, andreport.txtuploaded as an artifact for triage (CI: jobs that check less than they claim (dead Cirrus arm64 job, libc++ without warning flags, ci_cmake_flags wiring, static analysis that cannot fail, duplicated amalgamation checks, dead targets) #5715 item 4b)c093f3bebMake IWYU fail on findings: runiwyu_tooloncompile_commands.json(the CMakeCXX_INCLUDE_WHAT_YOU_USElauncher does not propagate IWYU's exit code), fix the findings inordered_map.hpp,json_fwd.hppandjson.hpp, and mark the includes IWYU wrongly suggests removing withIWYU pragma: keep;json.hppitself stays informational because IWYU's suggestion for it changes between identical runs (CI: jobs that check less than they claim (dead Cirrus arm64 job, libc++ without warning flags, ci_cmake_flags wiring, static analysis that cannot fail, duplicated amalgamation checks, dead targets) #5715 item 4c)Tests for these commits:
ordered_map.hppandjson_fwd.hppcompiled standalone with clang/libc++ and GCC 16/libstdc++ at C++11 and C++20;unit-ordered_mapwith ASan/UBSansilkeh/clang:devimage: the new gate fails (exit 2) on an injected unused include and passes when cleanci_test_amalgamationtarget built and passed;make check-amalgamationcleanubuntu:24.04(GCC 13.3):-DJSON_CI=Onconfigures all 47ci_cmake_flag_*targets and one builds and runsItem 5 overlaps #5610 and #5621, item 6 overlaps #5598. Whichever PR lands second needs a rebase. CI must confirm the Infer, IWYU and
ci_cmake_optionsjobs on their real runners, and MSVC for the include changes.Infer's findings are baselined by issue type, not per finding: new findings of the six disabled types are not caught. A per-finding baseline needs a full Linux x86_64 Infer run to record; the uploaded
report.txtmakes that possible as a follow-up.Closes #5715
This PR was written by Claude Code on behalf of @nlohmann.
🤖 Generated with Claude Code