Let's try this again :) Since cache entries with the same key are not updated/replaced and there is no option to do so, we manually delete the previous entry for the current branch. This reduces the cache storage for active branches, which can cause caches of the master branch to get evicted, which in turn will slow down builds of not only master but also new branches as they can't fall back on those caches. Permission has to be explicitly granted in order to delete the cache entries when not using the legacy all-write tokens that are the default for old repositories. The continue-on-error option is set for the step that deletes the old cache entry as it's expected that cache-hit will be true for a new feature branch when restoring the cache from the master branch. However, because there won't be anything to delete for this branch yet, the command will fail. The --succeed-on-no-caches option of the command unfortunately only works with --all. For the Linux tests, several jobs use the same cache key. So there is a chance that two jobs try to store a new entry concurrently, which will fail (it works if there was a cache hit and they are slightly off as previous entries are first deleted). To avoid that, we store the cache only for one particular config. Also made sure that the "openssl" test does not remove "openssl-3/4" caches by adding a suffix to the former. For alpine, the repository had to be set explicitly as gh wasn't able to determine it (didn't detect the Git working dir).
294 lines
10 KiB
YAML
294 lines
10 KiB
YAML
name: Linux
|
|
|
|
on: [push, pull_request]
|
|
|
|
concurrency:
|
|
group: ${{ github.workflow }}-${{ github.ref }}
|
|
cancel-in-progress: true
|
|
|
|
permissions:
|
|
actions: write
|
|
|
|
env:
|
|
# this test case does not actually test anything but tries to access system
|
|
# directories that might be inaccessible on build hosts
|
|
TESTS_CASES_EXCLUDE: sw_collector
|
|
TESTS_REDUCED_KEYLENGTHS: yes
|
|
CCACHE_BASEDIR: ${{ github.workspace }}
|
|
CCACHE_COMPRESS: true
|
|
CCACHE_MAXSIZE: 200M
|
|
OS_NAME: linux
|
|
|
|
jobs:
|
|
pre-check:
|
|
runs-on: ubuntu-latest
|
|
outputs:
|
|
should_skip: ${{ steps.skip-check.outputs.should_skip }}
|
|
steps:
|
|
- id: skip-check
|
|
uses: fkirc/skip-duplicate-actions@master
|
|
with:
|
|
concurrent_skipping: 'same_content_newer'
|
|
|
|
latest:
|
|
needs: pre-check
|
|
if: ${{ needs.pre-check.outputs.should_skip != 'true' }}
|
|
runs-on: ${{ matrix.os || 'ubuntu-latest' }}
|
|
strategy:
|
|
fail-fast: false
|
|
matrix:
|
|
test: [ all, default, printf-builtin ]
|
|
compiler: [ gcc, clang ]
|
|
leak-detective: [ no, yes ]
|
|
monolithic: [ no, yes ]
|
|
exclude:
|
|
# leaks will show up whether we build monolithic or not
|
|
- leak-detective: yes
|
|
monolithic: yes
|
|
# monolithic builds don't affect the printf-hook implementation
|
|
- test: printf-builtin
|
|
monolithic: yes
|
|
include:
|
|
- test: apidoc
|
|
- test: coverage
|
|
- test: dist
|
|
- test: nm
|
|
- test: no-dbg
|
|
- test: no-dbg
|
|
compiler: clang
|
|
- test: no-testable-ke
|
|
- test: no-testable-ke
|
|
compiler: clang
|
|
- test: fuzzing
|
|
compiler: clang
|
|
monolithic: yes
|
|
env:
|
|
LEAK_DETECTIVE: ${{ matrix.leak-detective || 'no' }}
|
|
MONOLITHIC: ${{ matrix.monolithic || 'no' }}
|
|
CC: ${{ matrix.compiler || 'gcc' }}
|
|
TEST: ${{ matrix.test }}
|
|
# as several jobs use the same key, make sure we only store the cache for
|
|
# one specific config in case there is a race
|
|
STORE_CACHE: >-
|
|
${{
|
|
!contains(fromJSON('["all", "default", "printf-builtin"]'),
|
|
matrix.test) ||
|
|
(matrix.leak-detective == 'no' && matrix.monolithic == 'no')
|
|
}}
|
|
steps:
|
|
- uses: actions/checkout@v6
|
|
- uses: actions/cache/restore@v5
|
|
id: cache-restore
|
|
with:
|
|
path: ~/.cache/ccache
|
|
# with regards to ccache, monolithic builds don't differ from regular
|
|
# builds and, similarly, builds with leak-detective only differ in two
|
|
# files (LD itself and library.c); but different tests build different
|
|
# dependencies, so different caches are needed
|
|
key: ccache-ubuntu-latest-${{ env.CC }}-${{ matrix.test }}
|
|
restore-keys: |
|
|
ccache-ubuntu-latest-${{ env.CC }}-
|
|
- run: |
|
|
sudo apt-get install -qq ccache
|
|
echo "PATH=/usr/lib/ccache:$PATH" >> $GITHUB_ENV
|
|
ccache -z
|
|
- uses: ./.github/actions/default
|
|
- run: ccache -sv
|
|
# delete old cache entry as we currently can't update it any other way
|
|
- env:
|
|
GH_TOKEN: ${{ github.token }}
|
|
if: steps.cache-restore.outputs.cache-hit && fromJSON(env.STORE_CACHE)
|
|
continue-on-error: true
|
|
run: gh cache delete -r ${{ github.ref }} ${{ steps.cache-restore.outputs.cache-primary-key }}
|
|
- if: fromJSON(env.STORE_CACHE)
|
|
uses: actions/cache/save@v5
|
|
with:
|
|
path: ~/.cache/ccache
|
|
key: ${{ steps.cache-restore.outputs.cache-primary-key }}
|
|
- if: ${{ success() && matrix.test == 'coverage' }}
|
|
uses: codecov/codecov-action@v4
|
|
with:
|
|
disable_search: true
|
|
fail_ci_if_error: true
|
|
file: coverage/coverage.cleaned.info
|
|
token: ${{ secrets.CODECOV_TOKEN }}
|
|
verbose: true
|
|
- if: ${{ failure() }}
|
|
uses: actions/upload-artifact@v6
|
|
with:
|
|
name: Logs ${{ github.job }}
|
|
path: config.log
|
|
retention-days: 5
|
|
|
|
crypto:
|
|
needs: pre-check
|
|
if: ${{ needs.pre-check.outputs.should_skip != 'true' }}
|
|
runs-on: ${{ matrix.os }}
|
|
strategy:
|
|
fail-fast: false
|
|
matrix:
|
|
test: [ botan, wolfssl, openssl-sys, openssl-3, openssl-4, openssl-awslc, gcrypt ]
|
|
os: [ ubuntu-latest, ubuntu-22.04 ]
|
|
leak-detective: [ no, yes ]
|
|
exclude:
|
|
# test custom-built libs only on the latest platform
|
|
- os: ubuntu-22.04
|
|
test: botan
|
|
- os: ubuntu-22.04
|
|
test: wolfssl
|
|
- os: ubuntu-22.04
|
|
test: openssl-3
|
|
- os: ubuntu-22.04
|
|
test: openssl-4
|
|
- os: ubuntu-22.04
|
|
test: openssl-awslc
|
|
env:
|
|
LEAK_DETECTIVE: ${{ matrix.leak-detective || 'no' }}
|
|
CC: ${{ matrix.compiler || 'gcc' }}
|
|
TEST: ${{ matrix.test }}
|
|
ACTIVE_TRANSFORMS_REF: .github/active-transforms/${{ matrix.test }}
|
|
STORE_CACHE: ${{ !matrix.leak-detective || matrix.leak-detective == 'no' }}
|
|
steps:
|
|
- uses: actions/checkout@v6
|
|
- uses: actions/cache/restore@v5
|
|
id: cache-restore
|
|
with:
|
|
# path is different on newer systems
|
|
path: |
|
|
~/.cache/ccache
|
|
~/.ccache
|
|
key: ccache-${{ matrix.os }}-${{ env.CC }}-${{ matrix.test }}
|
|
restore-keys: |
|
|
ccache-${{ matrix.os }}-${{ env.CC }}-all
|
|
ccache-${{ matrix.os }}-${{ env.CC }}-
|
|
- run: |
|
|
sudo apt-get install -qq ccache
|
|
echo "PATH=/usr/lib/ccache:$PATH" >> $GITHUB_ENV
|
|
ccache -z
|
|
echo "TESTS_ACTIVE_TRANSFORMS=$HOME/active-transforms.log" >> $GITHUB_ENV
|
|
- uses: ./.github/actions/default
|
|
- name: Upload active transforms
|
|
uses: actions/upload-artifact@v6
|
|
with:
|
|
name: active-transforms-${{ matrix.test }}-${{ matrix.os }}-${{ matrix.leak-detective }}
|
|
path: ${{ env.TESTS_ACTIVE_TRANSFORMS }}
|
|
retention-days: 5
|
|
- name: Verify active transforms
|
|
run: |
|
|
test ! -f $ACTIVE_TRANSFORMS_REF || diff -u --color=always $ACTIVE_TRANSFORMS_REF $TESTS_ACTIVE_TRANSFORMS
|
|
- run: ccache -sv
|
|
# delete old cache entry as we currently can't update it any other way
|
|
- env:
|
|
GH_TOKEN: ${{ github.token }}
|
|
if: steps.cache-restore.outputs.cache-hit && fromJSON(env.STORE_CACHE)
|
|
continue-on-error: true
|
|
run: gh cache delete -r ${{ github.ref }} ${{ steps.cache-restore.outputs.cache-primary-key }}
|
|
- if: fromJSON(env.STORE_CACHE)
|
|
uses: actions/cache/save@v5
|
|
with:
|
|
path: |
|
|
~/.cache/ccache
|
|
~/.ccache
|
|
key: ${{ steps.cache-restore.outputs.cache-primary-key }}
|
|
- if: ${{ failure() }}
|
|
uses: actions/upload-artifact@v6
|
|
with:
|
|
name: Logs ${{ github.job }}
|
|
path: config.log
|
|
retention-days: 5
|
|
|
|
older:
|
|
needs: pre-check
|
|
if: ${{ needs.pre-check.outputs.should_skip != 'true' }}
|
|
runs-on: ${{ matrix.os }}
|
|
strategy:
|
|
matrix:
|
|
os: [ ubuntu-22.04 ]
|
|
test: [ all, nm ]
|
|
compiler: [ gcc, clang ]
|
|
exclude:
|
|
- test: nm
|
|
compiler: clang
|
|
env:
|
|
LEAK_DETECTIVE: ${{ matrix.leak-detective || 'no' }}
|
|
CC: ${{ matrix.compiler || 'gcc' }}
|
|
TEST: ${{ matrix.test }}
|
|
steps:
|
|
- uses: actions/checkout@v6
|
|
- uses: actions/cache/restore@v5
|
|
id: cache-restore
|
|
with:
|
|
# path is different on newer systems
|
|
path: |
|
|
~/.cache/ccache
|
|
~/.ccache
|
|
key: ccache-${{ matrix.os }}-${{ env.CC }}-${{ matrix.test }}
|
|
restore-keys: |
|
|
ccache-${{ matrix.os }}-${{ env.CC }}-
|
|
- run: |
|
|
sudo apt-get install -qq ccache
|
|
echo "PATH=/usr/lib/ccache:$PATH" >> $GITHUB_ENV
|
|
ccache -z
|
|
- uses: ./.github/actions/default
|
|
- run: ccache -sv
|
|
# delete old cache entry as we currently can't update it any other way
|
|
- env:
|
|
GH_TOKEN: ${{ github.token }}
|
|
if: steps.cache-restore.outputs.cache-hit
|
|
continue-on-error: true
|
|
run: gh cache delete -r ${{ github.ref }} ${{ steps.cache-restore.outputs.cache-primary-key }}
|
|
- uses: actions/cache/save@v5
|
|
with:
|
|
path: |
|
|
~/.cache/ccache
|
|
~/.ccache
|
|
key: ${{ steps.cache-restore.outputs.cache-primary-key }}
|
|
- if: ${{ failure() }}
|
|
uses: actions/upload-artifact@v6
|
|
with:
|
|
name: Logs ${{ github.job }}
|
|
path: config.log
|
|
retention-days: 5
|
|
|
|
alpine:
|
|
needs: pre-check
|
|
if: ${{ needs.pre-check.outputs.should_skip != 'true' }}
|
|
runs-on: ubuntu-latest
|
|
container: alpine:latest
|
|
env:
|
|
TESTS_REDUCED_KEYLENGTHS: yes
|
|
TEST: alpine
|
|
OS_NAME: alpine
|
|
steps:
|
|
- uses: actions/checkout@v6
|
|
# install tar and zstd before the cache action that requires them
|
|
- run: |
|
|
apk add ccache tar zstd github-cli
|
|
echo "PATH=/usr/lib/ccache/bin:$PATH" >> $GITHUB_ENV
|
|
- uses: actions/cache/restore@v5
|
|
id: cache-restore
|
|
with:
|
|
path: ~/.cache/ccache
|
|
key: ccache-alpine
|
|
- run: ccache -z
|
|
# don't use the default action as we don't want to build dependencies or install bash
|
|
- run: ./scripts/test.sh deps
|
|
- run: ./scripts/test.sh
|
|
- run: ccache -sv
|
|
# delete old cache entry as we currently can't update it any other way
|
|
- env:
|
|
GH_TOKEN: ${{ github.token }}
|
|
if: steps.cache-restore.outputs.cache-hit
|
|
continue-on-error: true
|
|
run: gh cache delete --repo ${{ github.repository }} -r ${{ github.ref }} ${{ steps.cache-restore.outputs.cache-primary-key }}
|
|
- uses: actions/cache/save@v5
|
|
with:
|
|
path: ~/.cache/ccache
|
|
key: ${{ steps.cache-restore.outputs.cache-primary-key }}
|
|
- if: ${{ failure() }}
|
|
uses: actions/upload-artifact@v6
|
|
with:
|
|
name: Logs ${{ github.job }}
|
|
path: config.log
|
|
retention-days: 5
|