mirror of
https://github.com/troglobit/finit.git
synced 2026-10-08 00:24:17 +07:00
keventd is the only thing in the tree that links libblkid, so a tree that used to build now stops in configure with no hint of which package to install. Say so where people look for dependencies, and give CI the package it now needs. Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
152 lines
5.5 KiB
YAML
152 lines
5.5 KiB
YAML
name: Bob the Builder
|
|
|
|
# Run on all branches, including all pull requests, except the 'dev'
|
|
# branch since that's where we run Coverity Scan (limited tokens/day)
|
|
on:
|
|
push:
|
|
branches:
|
|
- '**'
|
|
- '!dev'
|
|
pull_request:
|
|
types: [opened, synchronize, reopened, labeled]
|
|
|
|
permissions:
|
|
contents: read
|
|
|
|
concurrency:
|
|
group: ${{ github.workflow }}-${{ github.head_ref || github.ref }}
|
|
cancel-in-progress: true
|
|
|
|
jobs:
|
|
fuzz:
|
|
name: fuzz
|
|
runs-on: ubuntu-latest
|
|
if: github.event_name != 'push' || github.ref == 'refs/heads/master'
|
|
steps:
|
|
- name: Install dependencies
|
|
run: |
|
|
sudo apt-get -y update
|
|
sudo apt-get -y install pkg-config libconfuse-dev clang libblkid-dev
|
|
# clang picks the newest gcc tree it finds and needs the
|
|
# matching libstdc++ headers to link the fuzzer runtime
|
|
sudo apt-get -y install libstdc++-14-dev || true
|
|
wget https://github.com/troglobit/libuev/releases/download/v2.4.1/libuev-2.4.1.tar.xz
|
|
wget https://github.com/troglobit/libite/releases/download/v2.6.2/libite-2.6.2.tar.gz
|
|
tar xf libuev-2.4.1.tar.xz
|
|
tar xf libite-2.6.2.tar.gz
|
|
(cd libuev-2.4.1 && ./configure && make -j9 && sudo make install-strip)
|
|
(cd libite-2.6.2 && ./configure && make -j9 && sudo make install-strip)
|
|
sudo ldconfig
|
|
- uses: actions/checkout@v7
|
|
- name: Configure
|
|
run: |
|
|
./autogen.sh
|
|
./configure --prefix=/usr --exec-prefix= --sysconfdir=/etc --localstatedir=/var
|
|
- name: Build fuzz target
|
|
run: |
|
|
clang -fsanitize=fuzzer,address -DLINK_FUZZ_LIBFUZZER -D_GNU_SOURCE \
|
|
-I libink -I . -o fuzz-msg-parse \
|
|
test/src/fuzz-msg-parse.c libink/*.c
|
|
# Restores the newest corpus and saves a fresh one, since a cache
|
|
# entry is immutable once written. Caches made on a branch are
|
|
# private to it, so the corpus that accumulates on master is what
|
|
# pull requests start from, rather than nothing.
|
|
- name: Restore corpus
|
|
uses: actions/cache@v6
|
|
with:
|
|
path: .fuzz-corpus
|
|
key: fuzz-corpus-${{ github.run_id }}
|
|
restore-keys: fuzz-corpus-
|
|
- name: Fuzz
|
|
run: |
|
|
mkdir -p .fuzz-corpus
|
|
./fuzz-msg-parse .fuzz-corpus -max_total_time=120 -max_len=4096 \
|
|
-print_final_stats=1
|
|
# Without this the corpus only ever grows, and most of what it
|
|
# accumulates reaches code some earlier input already reached.
|
|
- name: Minimise corpus
|
|
if: always()
|
|
run: |
|
|
mkdir -p .fuzz-corpus-min
|
|
./fuzz-msg-parse -merge=1 .fuzz-corpus-min .fuzz-corpus
|
|
rm -rf .fuzz-corpus
|
|
mv .fuzz-corpus-min .fuzz-corpus
|
|
echo "corpus: $(ls .fuzz-corpus | wc -l) inputs"
|
|
- name: Upload crashers
|
|
if: failure()
|
|
uses: actions/upload-artifact@v7
|
|
with:
|
|
name: fuzz-crashers
|
|
path: |
|
|
crash-*
|
|
leak-*
|
|
timeout-*
|
|
if-no-files-found: ignore
|
|
|
|
build:
|
|
# Verify we can build on latest Ubuntu with both gcc and clang
|
|
name: ${{ matrix.compiler }}
|
|
runs-on: ubuntu-latest
|
|
# Skip redundant builds for PRs - prefer PR builds over push builds
|
|
if: github.event_name != 'push' || github.ref == 'refs/heads/master'
|
|
strategy:
|
|
matrix:
|
|
compiler: [gcc, clang]
|
|
fail-fast: false
|
|
env:
|
|
CC: ${{ matrix.compiler }}
|
|
steps:
|
|
- name: Install dependencies
|
|
run: |
|
|
sudo apt-get -y update
|
|
sudo apt-get -y install pkg-config tree jq libcap-dev libconfuse-dev libblkid-dev
|
|
wget https://github.com/troglobit/libuev/releases/download/v2.4.1/libuev-2.4.1.tar.xz
|
|
wget https://github.com/troglobit/libite/releases/download/v2.6.2/libite-2.6.2.tar.gz
|
|
tar xf libuev-2.4.1.tar.xz
|
|
tar xf libite-2.6.2.tar.gz
|
|
(cd libuev-2.4.1 && ./configure && make -j9 && sudo make install-strip)
|
|
(cd libite-2.6.2 && ./configure && make -j9 && sudo make install-strip)
|
|
sudo ldconfig
|
|
- uses: actions/checkout@v7
|
|
- name: Static Finit
|
|
run: |
|
|
./autogen.sh
|
|
./configure --prefix= --enable-static
|
|
make -j9 V=1
|
|
- name: Regular Finit
|
|
run: |
|
|
./configure --prefix=/usr --exec-prefix= --sysconfdir=/etc --localstatedir=/var \
|
|
--enable-x11-common-plugin --enable-testserv-plugin --with-watchdog \
|
|
--with-keventd \
|
|
CFLAGS="-fsanitize=address -ggdb"
|
|
make -j9 clean
|
|
make -j9 V=1
|
|
- name: Install to /tmp
|
|
run: |
|
|
DESTDIR=/tmp make install-strip
|
|
tree /tmp || true
|
|
- name: Check dependencies
|
|
run: |
|
|
ldd /tmp/sbin/finit
|
|
size /tmp/sbin/finit
|
|
ldd /tmp/sbin/initctl
|
|
size /tmp/sbin/initctl
|
|
ldd /tmp/sbin/reboot
|
|
size /tmp/sbin/reboot
|
|
- name: Verify starting and showing usage text
|
|
run: |
|
|
sudo /tmp/sbin/finit -h
|
|
sudo /tmp/sbin/initctl -h
|
|
- name: Enable unprivileged userns (unshare)
|
|
run: |
|
|
sudo sysctl kernel.apparmor_restrict_unprivileged_userns=0
|
|
- name: Run Unit Tests
|
|
run: |
|
|
make -j1 check || (cat test/test-suite.log; false)
|
|
- name: Upload Test Results
|
|
if: always()
|
|
uses: actions/upload-artifact@v7
|
|
with:
|
|
name: finit-test-${{ matrix.compiler }}
|
|
path: test/*.log
|