diff options
context:
space:
mode:
authorBryce Kwon <bryce@brycekwon.com>
committerBryce Kwon <bryce@brycekwon.com>
commit
parent
tree
download
Add a CI workflow
-rw-r--r--.github/workflows/ci.yml106
1 file changed, 106 insertions, 0 deletions
diff --git a/.github/workflows/ci.yml b/.github/workflows/ci.yml
new file mode 100644
index 0000000..794f0b0
--- /dev/null
+++ b/.github/workflows/ci.yml
@@ -0,0 +1,106 @@
+name: ci
+
+on:
+ push:
+ pull_request:
+ workflow_dispatch:
+
+concurrency:
+ group: ci-${{ github.ref }}
+ cancel-in-progress: true
+
+jobs:
+ build-and-test:
+ runs-on: ubuntu-24.04
+ strategy:
+ fail-fast: false
+ matrix:
+ cc: [gcc, clang]
+ steps:
+ - uses: actions/checkout@v7
+ with:
+ submodules: recursive
+ - name: Install build dependencies
+ run: |
+ sudo apt-get update
+ sudo apt-get install -y build-essential clang zlib1g-dev gettext libtool
+ # CC is passed on the command line because git's Makefile hard-assigns
+ # CC = cc, which would override it as an environment variable.
+ - name: Build
+ run: make NO_LUA=1 CC=${{ matrix.cc }}
+ - name: Run the test suite
+ # The submodule is pinned by SHA without its release tag, so skip the
+ # test that runs `git describe` inside it.
+ run: make NO_LUA=1 CC=${{ matrix.cc }} test
+ env:
+ CGIT_TEST_NO_GIT_VERSION: YesPlease
+
+ lua:
+ runs-on: ubuntu-24.04
+ steps:
+ - uses: actions/checkout@v7
+ with:
+ submodules: recursive
+ - name: Install build dependencies
+ run: |
+ sudo apt-get update
+ sudo apt-get install -y build-essential zlib1g-dev gettext libtool libluajit-5.1-dev
+ # A plain build auto-detects luajit and links the lua: filter backend.
+ - name: Build with Lua
+ run: make
+ - name: Confirm Lua is compiled in
+ run: ./build/cgit --version | grep -F '[+] Lua scripting'
+ - name: Run the test suite
+ run: make test
+ env:
+ CGIT_TEST_NO_GIT_VERSION: YesPlease
+
+ sanitizers:
+ runs-on: ubuntu-24.04
+ steps:
+ - uses: actions/checkout@v7
+ with:
+ submodules: recursive
+ - name: Install build dependencies
+ run: |
+ sudo apt-get update
+ sudo apt-get install -y build-essential zlib1g-dev gettext libtool
+ # Runs the test suite against a cgit built with AddressSanitizer and
+ # UndefinedBehaviorSanitizer. Leak detection is off because cgit is a
+ # short-lived CGI that leaves cleanup to process exit.
+ - name: Run the test suite under ASan and UBSan
+ run: make NO_LUA=1 SANITIZE=address,undefined test
+ env:
+ CGIT_TEST_NO_GIT_VERSION: YesPlease
+ ASAN_OPTIONS: abort_on_error=1:detect_leaks=0
+ UBSAN_OPTIONS: print_stacktrace=1:halt_on_error=1
+
+ sparse:
+ runs-on: ubuntu-24.04
+ # Static analysis. Non-blocking, since sparse is noisy on a large codebase.
+ continue-on-error: true
+ steps:
+ - uses: actions/checkout@v7
+ with:
+ submodules: recursive
+ - name: Install build dependencies
+ run: |
+ sudo apt-get update
+ sudo apt-get install -y build-essential zlib1g-dev gettext libtool sparse
+ - name: Static-check the cgit sources with sparse
+ run: make NO_LUA=1 sparse
+
+ hardened-build:
+ runs-on: ubuntu-24.04
+ steps:
+ - uses: actions/checkout@v7
+ with:
+ submodules: recursive
+ - name: Install build dependencies
+ run: |
+ sudo apt-get update
+ sudo apt-get install -y build-essential zlib1g-dev gettext libtool
+ - name: Build with release hardening flags
+ run: ./tools/release-build.sh
+ - name: Confirm the binary is position independent
+ run: file build/cgit | grep -q 'pie executable'