Skip to content

Build: Put sdkmanager on PATH before installing the NDK #4

Build: Put sdkmanager on PATH before installing the NDK

Build: Put sdkmanager on PATH before installing the NDK #4

Workflow file for this run

name: CI
on:
push:
branches: [main]
pull_request:
# A second push to the same branch makes the first run irrelevant.
concurrency:
group: ${{ github.workflow }}-${{ github.ref }}
cancel-in-progress: true
jobs:
build:
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@v4
# The daemon JVM is pinned by gradle/gradle-daemon-jvm.properties and provisioned
# automatically; this is only the JVM that launches the wrapper.
- uses: actions/setup-java@v4
with:
distribution: temurin
java-version: '21'
- uses: gradle/actions/setup-gradle@v4
- uses: android-actions/setup-android@v4
- name: Install NDK
run: sdkmanager --install "ndk;28.2.13676358" "cmake;3.22.1"
- name: Unit tests
run: ./gradlew :rootect-core:test
# Release, because that is the build that ships: R8 runs, NDEBUG strips the debug JNI
# probes, and the optimiser gets its chance to undo the string hiding.
- name: Build release
run: ./gradlew :rootect-core:assembleRelease :sample:assembleRelease
- name: Check for plaintext detection strings
run: bash scripts/check-no-plaintext.sh
# Every ABI must be present. Losing x86_64 silently would cost the emulator, which is
# the false-positive control.
- name: Verify all ABIs built
run: |
set -e
aar=rootect-core/build/outputs/aar/rootect-core-release.aar
for abi in arm64-v8a armeabi-v7a x86_64; do
unzip -l "$aar" | grep -q "jni/$abi/librootect.so" \
|| { echo "missing ABI: $abi"; exit 1; }
done
echo "all three ABIs present"
- name: Upload release AAR
uses: actions/upload-artifact@v4
with:
name: rootect-core-release
path: rootect-core/build/outputs/aar/*.aar
# The native layer only runs on a device, and a clean emulator is the false-positive
# control: these tests assert nothing claims root on an unmodified image.
instrumented:
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@v4
- uses: actions/setup-java@v4
with:
distribution: temurin
java-version: '21'
- uses: gradle/actions/setup-gradle@v4
- uses: android-actions/setup-android@v4
- name: Install NDK
run: sdkmanager --install "ndk;28.2.13676358" "cmake;3.22.1"
# Without KVM the emulator falls back to software rendering and times out.
- name: Enable KVM
run: |
echo 'KERNEL=="kvm", GROUP="kvm", MODE="0666", OPTIONS+="static_node=kvm"' \
| sudo tee /etc/udev/rules.d/99-kvm4all.rules
sudo udevadm control --reload-rules
sudo udevadm trigger --name-match=kvm
# rootectExpect=emulator turns on the clean-device assertions, skipped by default.
- name: Instrumented tests
uses: reactivecircus/android-emulator-runner@v2
with:
api-level: 34
arch: x86_64
target: google_apis
script: >
./gradlew :rootect-core:connectedDebugAndroidTest
-Pandroid.testInstrumentationRunnerArguments.rootectExpect=emulator