-
-
Notifications
You must be signed in to change notification settings - Fork 230
266 lines (228 loc) · 11.1 KB
/
Copy pathlinux_ci.yml
File metadata and controls
266 lines (228 loc) · 11.1 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
130
131
132
133
134
135
136
137
138
139
140
141
142
143
144
145
146
147
148
149
150
151
152
153
154
155
156
157
158
159
160
161
162
163
164
165
166
167
168
169
170
171
172
173
174
175
176
177
178
179
180
181
182
183
184
185
186
187
188
189
190
191
192
193
194
195
196
197
198
199
200
201
202
203
204
205
206
207
208
209
210
211
212
213
214
215
216
217
218
219
220
221
222
223
224
225
226
227
228
229
230
231
232
233
234
235
236
237
238
239
240
241
242
243
244
245
246
247
248
249
250
251
252
253
254
255
256
257
258
259
260
261
262
263
264
265
266
name: Linux CI
on:
push:
branches:
- master
pull_request:
jobs:
linux_ci:
runs-on: ubuntu-22.04
strategy:
fail-fast: true
matrix:
sanitize: [ubsan, asan, tsan, msan]
env:
# Indicates the CMake build directory where project files and binaries are being produced.
CMAKE_BUILD_DIR: ${{ github.workspace }}/build
# Indicates the location of the vcpkg as a Git submodule of the project repository.
VCPKG_ROOT: ${{ github.workspace }}/external/vcpkg
VCPKG_DEFAULT_BINARY_CACHE: ${{ github.workspace }}/.vcpkg-binary-cache
VCPKG_BINARY_SOURCES: clear;files,${{ github.workspace }}/.vcpkg-binary-cache,readwrite
SSH_PORT: 2222
steps:
- uses: actions/checkout@v4
- name: Setup
shell: bash
run: |
mkdir -p ~/.ssh/
echo -e "Host github.com\n\tStrictHostKeyChecking no\n" >> ~/.ssh/config
sudo apt-get -o Acquire::ForceIPv4=true update
sudo DEBIAN_FRONTEND=noninteractive ACCEPT_EULA=Y apt-get -o Acquire::ForceIPv4=true install -y curl zip unzip tar libssl-dev libcurl4-openssl-dev libunwind-dev git cmake ninja-build gdb protobuf-compiler libsodium-dev libgflags-dev libprotobuf-dev libutempter-dev g++ libtool libtool-bin autoconf autoconf-archive automake
echo -e "Host localhost 127.0.0.1 ::1\n Port ${SSH_PORT}\n\n" >> ~/.ssh/config
sudo mkdir -p /run/sshd
sudo /usr/sbin/sshd -p "${SSH_PORT}"
ssh-keygen -t rsa -f ~/.ssh/id_rsa -P "" -N ""
cat ~/.ssh/id_rsa.pub >> ~/.ssh/authorized_keys
cat ~/.ssh/id_rsa.pub >> ~/.ssh/known_hosts
ssh -vvvvvvv -o "StrictHostKeyChecking no" -o 'PreferredAuthentications=publickey' localhost "echo foobar" # Fails if we can't ssh into localhost without a password
if [[ -z "${ACT}" ]]; then auth_header="$(git config --local --get http.https://github.com/.extraheader)"; fi
git submodule sync --recursive
git submodule update --init --force --recursive
# Restore both vcpkg and its artifacts from the GitHub cache service.
- name: Restore vcpkg binary cache
uses: actions/cache@v5
with:
# The first path is where vcpkg generates artifacts while consuming the vcpkg.json manifest file.
# The second path is the location of vcpkg (it contains the vcpkg executable and data files).
# The other paths starting with '!' are exclusions: they contain temporary files generated during the build of the installed packages.
path: |
${{ github.workspace }}/.vcpkg-binary-cache
${{ env.CMAKE_BUILD_DIR }}/vcpkg_installed
key: et-vcpkg-bin-${{ hashFiles('vcpkg.json') }}-${{ hashFiles('.git/modules/external/vcpkg/HEAD') }}-linux-${{ matrix.sanitize }}
- name: Ensure vcpkg binary cache directory
shell: bash
run: mkdir -p "${{ github.workspace }}/.vcpkg-binary-cache"
- name: Build with ubsan
run: |
parallel_level="${CI_PARALLEL_LEVEL:-2}"
if [[ -n "${ACT:-}" ]]; then
parallel_level="${CI_PARALLEL_LEVEL:-14}"
fi
mkdir -p build
pushd build
cmake -DDISABLE_TELEMETRY=ON -DSANITIZE_UNDEFINED=ON ../
make -j"${parallel_level}"
TSAN_OPTIONS="suppressions=../test/test_tsan.suppression" ctest --parallel "${parallel_level}" --output-on-failure
popd
if: matrix.sanitize == 'ubsan'
- name: Build with asan
run: |
parallel_level="${CI_PARALLEL_LEVEL:-2}"
if [[ -n "${ACT:-}" ]]; then
parallel_level="${CI_PARALLEL_LEVEL:-14}"
fi
mkdir -p build
pushd build
cmake -DDISABLE_TELEMETRY=ON -DSANITIZE_ADDRESS=ON ../
make -j"${parallel_level}"
TSAN_OPTIONS="suppressions=../test/test_tsan.suppression" ctest --parallel "${parallel_level}" --output-on-failure
popd
if: matrix.sanitize == 'asan'
- name: Build with msan
run: |
parallel_level="${CI_PARALLEL_LEVEL:-2}"
if [[ -n "${ACT:-}" ]]; then
parallel_level="${CI_PARALLEL_LEVEL:-14}"
fi
mkdir -p build
pushd build
cmake -DDISABLE_TELEMETRY=ON -DSANITIZE_MEMORY=ON ../
make -j"${parallel_level}"
TSAN_OPTIONS="suppressions=../test/test_tsan.suppression" ctest --parallel "${parallel_level}" --output-on-failure
popd
if: matrix.sanitize == 'msan'
- name: Build with tsan
run: |
parallel_level="${CI_PARALLEL_LEVEL:-2}"
if [[ -n "${ACT:-}" ]]; then
parallel_level="${CI_PARALLEL_LEVEL:-14}"
fi
mkdir -p build
pushd build
cmake -DDISABLE_TELEMETRY=ON -DSANITIZE_THREAD=ON -DSANITIZE_LINK_STATIC=ON ../
make -j"${parallel_level}"
TSAN_OPTIONS="suppressions=../test/test_tsan.suppression:die_after_fork=0:report_thread_leaks=0" ctest --parallel "${parallel_level}" --output-on-failure
popd
if: matrix.sanitize == 'tsan'
- name: Stop sshd for act
if: ${{ always() }}
run: |
if [[ -n "${ACT:-}" ]]; then
sudo pkill -x sshd || true
fi
linux_jumphost_system_test:
runs-on: ubuntu-22.04
env:
CMAKE_BUILD_DIR: ${{ github.workspace }}/build
VCPKG_ROOT: ${{ github.workspace }}/external/vcpkg
VCPKG_DEFAULT_BINARY_CACHE: ${{ github.workspace }}/.vcpkg-binary-cache
VCPKG_BINARY_SOURCES: clear;files,${{ github.workspace }}/.vcpkg-binary-cache,readwrite
SSH_PORT: 2223
steps:
- uses: actions/checkout@v4
- name: Setup
shell: bash
run: |
mkdir -p ~/.ssh/
echo -e "Host github.com\n\tStrictHostKeyChecking no\n" >> ~/.ssh/config
sudo apt-get -o Acquire::ForceIPv4=true update
sudo DEBIAN_FRONTEND=noninteractive ACCEPT_EULA=Y apt-get -o Acquire::ForceIPv4=true install -y curl zip unzip tar libssl-dev libcurl4-openssl-dev libunwind-dev git cmake ninja-build gdb protobuf-compiler libsodium-dev libgflags-dev libprotobuf-dev libutempter-dev g++ libtool libtool-bin autoconf autoconf-archive automake
echo -e "Host localhost 127.0.0.1 ::1\n Port ${SSH_PORT}\n\n" >> ~/.ssh/config
sudo mkdir -p /run/sshd
sudo /usr/sbin/sshd -p "${SSH_PORT}"
ssh-keygen -t rsa -f ~/.ssh/id_rsa -P "" -N ""
cat ~/.ssh/id_rsa.pub >> ~/.ssh/authorized_keys
cat ~/.ssh/id_rsa.pub >> ~/.ssh/known_hosts
ssh -vvvvvvv -o "StrictHostKeyChecking no" -o 'PreferredAuthentications=publickey' localhost "echo foobar" # Fails if we can't ssh into localhost without a password
if [[ -z "${ACT}" ]]; then auth_header="$(git config --local --get http.https://github.com/.extraheader)"; fi
git submodule sync --recursive
git submodule update --init --force --recursive
- name: Restore vcpkg binary cache
uses: actions/cache@v5
with:
path: |
${{ github.workspace }}/.vcpkg-binary-cache
${{ env.CMAKE_BUILD_DIR }}/vcpkg_installed
key: et-vcpkg-bin-${{ hashFiles('vcpkg.json') }}-${{ hashFiles('.git/modules/external/vcpkg/HEAD') }}-linux-ubsan
- name: Ensure vcpkg binary cache directory
shell: bash
run: mkdir -p "${{ github.workspace }}/.vcpkg-binary-cache"
- name: Build for jumphost system test
run: |
parallel_level="${CI_PARALLEL_LEVEL:-2}"
if [[ -n "${ACT:-}" ]]; then
parallel_level="${CI_PARALLEL_LEVEL:-14}"
fi
mkdir -p build
pushd build
cmake -DDISABLE_TELEMETRY=ON -DSANITIZE_UNDEFINED=ON ../
cmake --build . --target et etserver etterminal --parallel "${parallel_level}"
popd
- name: Connect with jumphost
run: ./test/system_tests/connect_with_jumphost.sh
- name: Named sessions survive client death
run: ./test/system_tests/named_sessions.sh
- name: Sessions survive etserver restart
run: ./test/system_tests/router_restart.sh
- name: Stop sshd for act
if: ${{ always() }}
run: |
if [[ -n "${ACT:-}" ]]; then
sudo pkill -x sshd || true
fi
linux_backwards_compatibility:
runs-on: ubuntu-22.04
env:
CMAKE_BUILD_DIR: ${{ github.workspace }}/build
VCPKG_ROOT: ${{ github.workspace }}/external/vcpkg
VCPKG_DEFAULT_BINARY_CACHE: ${{ github.workspace }}/.vcpkg-binary-cache
VCPKG_BINARY_SOURCES: clear;files,${{ github.workspace }}/.vcpkg-binary-cache,readwrite
SSH_PORT: 2224
steps:
- uses: actions/checkout@v4
- name: Setup
shell: bash
run: |
mkdir -p ~/.ssh/
echo -e "Host github.com\n\tStrictHostKeyChecking no\n" >> ~/.ssh/config
sudo apt-get -o Acquire::ForceIPv4=true update
sudo DEBIAN_FRONTEND=noninteractive ACCEPT_EULA=Y apt-get -o Acquire::ForceIPv4=true install -y curl zip unzip tar libssl-dev libcurl4-openssl-dev libunwind-dev git cmake ninja-build gdb protobuf-compiler libsodium-dev libgflags-dev libprotobuf-dev libutempter-dev g++ libtool libtool-bin autoconf autoconf-archive automake
echo -e "Host localhost 127.0.0.1 ::1\n Port ${SSH_PORT}\n\n" >> ~/.ssh/config
sudo mkdir -p /run/sshd
sudo /usr/sbin/sshd -p "${SSH_PORT}"
ssh-keygen -t rsa -f ~/.ssh/id_rsa -P "" -N ""
cat ~/.ssh/id_rsa.pub >> ~/.ssh/authorized_keys
cat ~/.ssh/id_rsa.pub >> ~/.ssh/known_hosts
ssh -vvvvvvv -o "StrictHostKeyChecking no" -o 'PreferredAuthentications=publickey' localhost "echo foobar" # Fails if we can't ssh into localhost without a password
if [[ -z "${ACT}" ]]; then auth_header="$(git config --local --get http.https://github.com/.extraheader)"; fi
git submodule sync --recursive
git submodule update --init --force --recursive
- name: Restore vcpkg binary cache
uses: actions/cache@v5
with:
path: |
${{ github.workspace }}/.vcpkg-binary-cache
${{ env.CMAKE_BUILD_DIR }}/vcpkg_installed
key: et-vcpkg-bin-${{ hashFiles('vcpkg.json') }}-${{ hashFiles('.git/modules/external/vcpkg/HEAD') }}-linux-ubsan
- name: Ensure vcpkg binary cache directory
shell: bash
run: mkdir -p "${{ github.workspace }}/.vcpkg-binary-cache"
- name: Build for backwards compatibility system test
run: |
parallel_level="${CI_PARALLEL_LEVEL:-2}"
if [[ -n "${ACT:-}" ]]; then
parallel_level="${CI_PARALLEL_LEVEL:-14}"
fi
mkdir -p build
pushd build
cmake -DDISABLE_TELEMETRY=ON -DSANITIZE_UNDEFINED=ON ../
cmake --build . --target et etserver etterminal --parallel "${parallel_level}"
popd
- name: Backwards compatibility with et-v7.0.0
run: ./test/system_tests/backwards_compatibility.sh
- name: Stop sshd for act
if: ${{ always() }}
run: |
if [[ -n "${ACT:-}" ]]; then
sudo pkill -x sshd || true
fi