diff options
context:
space:
mode:
-rw-r--r--.gitattributes2
-rw-r--r--.github/workflows/ci.yml107
-rw-r--r--.github/workflows/release.yml52
-rw-r--r--Makefile23
4 files changed, 1 insertion, 183 deletions
diff --git a/.gitattributes b/.gitattributes
index 50da209..e13769c 100644
--- a/.gitattributes
+++ b/.gitattributes
@@ -13,5 +13,3 @@ Makefile text eol=lf
.gitignore export-ignore
.gitattributes export-ignore
-
-.github/ export-ignore
diff --git a/.github/workflows/ci.yml b/.github/workflows/ci.yml
deleted file mode 100644
index 7764ac2..0000000
--- a/.github/workflows/ci.yml
+++ /dev/null
@@ -1,107 +0,0 @@
-name: ci
-
-on:
- push:
- branches:
- - '**'
- workflow_dispatch:
-
-concurrency:
- group: ci-${{ github.ref }}
- cancel-in-progress: true
-
-jobs:
- build-and-test:
- runs-on: ubuntu-24.04
- strategy:
- fail-fast: false
- matrix:
- cc: [gcc, clang]
- steps:
- - uses: actions/checkout@v7
- with:
- submodules: recursive
- - name: Install build dependencies
- run: |
- sudo apt-get update
- sudo apt-get install -y build-essential clang zlib1g-dev gettext libtool
- # CC is passed on the command line because git's Makefile hard-assigns
- # CC = cc, which would override it as an environment variable.
- - name: Build
- run: make NO_LUA=1 CC=${{ matrix.cc }}
- - name: Run the test suite
- # The submodule is pinned by SHA without its release tag, so skip the
- # test that runs `git describe` inside it.
- run: make NO_LUA=1 CC=${{ matrix.cc }} test
- env:
- CGIT_TEST_NO_GIT_VERSION: YesPlease
-
- lua:
- runs-on: ubuntu-24.04
- steps:
- - uses: actions/checkout@v7
- with:
- submodules: recursive
- - name: Install build dependencies
- run: |
- sudo apt-get update
- sudo apt-get install -y build-essential zlib1g-dev gettext libtool libluajit-5.1-dev
- # A plain build auto-detects luajit and links the lua: filter backend.
- - name: Build with Lua
- run: make
- - name: Confirm Lua is compiled in
- run: ./build/cgit --version | grep -F '[+] Lua scripting'
- - name: Run the test suite
- run: make test
- env:
- CGIT_TEST_NO_GIT_VERSION: YesPlease
-
- sanitizers:
- runs-on: ubuntu-24.04
- steps:
- - uses: actions/checkout@v7
- with:
- submodules: recursive
- - name: Install build dependencies
- run: |
- sudo apt-get update
- sudo apt-get install -y build-essential zlib1g-dev gettext libtool
- # Runs the test suite against a cgit built with AddressSanitizer and
- # UndefinedBehaviorSanitizer. Leak detection is off because cgit is a
- # short-lived CGI that leaves cleanup to process exit.
- - name: Run the test suite under ASan and UBSan
- run: make NO_LUA=1 SANITIZE=address,undefined test
- env:
- CGIT_TEST_NO_GIT_VERSION: YesPlease
- ASAN_OPTIONS: abort_on_error=1:detect_leaks=0
- UBSAN_OPTIONS: print_stacktrace=1:halt_on_error=1
-
- sparse:
- runs-on: ubuntu-24.04
- # Static analysis. Non-blocking, since sparse is noisy on a large codebase.
- continue-on-error: true
- steps:
- - uses: actions/checkout@v7
- with:
- submodules: recursive
- - name: Install build dependencies
- run: |
- sudo apt-get update
- sudo apt-get install -y build-essential zlib1g-dev gettext libtool sparse
- - name: Static-check the cgit sources with sparse
- run: make NO_LUA=1 sparse
-
- hardened-build:
- runs-on: ubuntu-24.04
- steps:
- - uses: actions/checkout@v7
- with:
- submodules: recursive
- - name: Install build dependencies
- run: |
- sudo apt-get update
- sudo apt-get install -y build-essential zlib1g-dev gettext libtool
- - name: Build with release hardening flags
- run: ./tools/release-build.sh
- - name: Confirm the binary is position independent
- run: file build/cgit | grep -q 'pie executable'
diff --git a/.github/workflows/release.yml b/.github/workflows/release.yml
deleted file mode 100644
index 994e8eb..0000000
--- a/.github/workflows/release.yml
+++ /dev/null
@@ -1,52 +0,0 @@
-name: release
-
-on:
- push:
- tags:
- - 'v*'
-
-# Needed to create the draft release.
-permissions:
- contents: write
-
-jobs:
- draft-release:
- runs-on: ubuntu-24.04
- steps:
- - uses: actions/checkout@v7
- with:
- submodules: recursive
- # Tags let git describe stamp the exact release version into
- # the binary rather than the Makefile fallback.
- fetch-tags: true
- fetch-depth: 0
- - name: Install build dependencies
- run: |
- sudo apt-get update
- sudo apt-get install -y build-essential zlib1g-dev gettext libtool libluajit-5.1-dev
- # Build two hardened variants: a self-contained one with no Lua, and one
- # that links the lua: filter backend. Each is packaged with a checksum.
- - name: Build and package both variants
- run: |
- package() { # $1 = release-build.sh arg, $2 = tarball suffix
- ./tools/release-build.sh $1
- dist="cgit-${GITHUB_REF_NAME}${2}"
- make dist DIST_NAME="$dist"
- mv "build/${dist}.tar.gz" .
- sha256sum "${dist}.tar.gz" > "${dist}.tar.gz.sha256"
- }
- package "" ""
- package "lua" "-lua"
- # Creates a DRAFT release only. Review and publish it by hand.
- - name: Create draft release
- env:
- GH_TOKEN: ${{ github.token }}
- run: |
- gh release create "${GITHUB_REF_NAME}" \
- --draft \
- --title "cgit ${GITHUB_REF_NAME}" \
- --generate-notes \
- "cgit-${GITHUB_REF_NAME}.tar.gz" \
- "cgit-${GITHUB_REF_NAME}.tar.gz.sha256" \
- "cgit-${GITHUB_REF_NAME}-lua.tar.gz" \
- "cgit-${GITHUB_REF_NAME}-lua.tar.gz.sha256"
diff --git a/Makefile b/Makefile
index 6029c77..8c07692 100644
--- a/Makefile
+++ b/Makefile
@@ -43,13 +43,6 @@ mandir = $(prefix)/share/man
ASSETS = cgit.css cgit.js cgit.png favicon.ico robots.txt
FILTER_FILES = $(notdir $(wildcard $(EXTDIR)/*.lua))
-# Extra files and whole trees the dist target bundles into the release tarball,
-# alongside the binary and the assets above.
-DIST_DOCS = cgitrc.5.txt README.txt LICENSE.txt AUTHORS
-DIST_TREES = custom
-DIST_NAME = cgit-$(CGIT_VERSION)
-DIST_DIR = $(BUILDDIR)/$(DIST_NAME)
-
# The man-page source (*.5.txt) sits at the project root and is rendered into
# build/. Only one man section exists, so DOC_* derive straight from MAN5_TXT.
MAN5_TXT = $(wildcard *.5.txt)
@@ -57,7 +50,6 @@ DOC_MAN5 = $(patsubst %.txt,$(BUILDDIR)/%,$(MAN5_TXT))
DOC_HTML = $(patsubst %.txt,$(BUILDDIR)/%.html,$(MAN5_TXT))
INSTALL = install
-COPYTREE = cp -r
ASCIIDOC = asciidoc
ASCIIDOC_EXTRA =
ASCIIDOC_HTML = xhtml11
@@ -138,19 +130,6 @@ uninstall-html:
rm -fv $(DESTDIR)$(htmldir)/$$i; \
done
-# Stage a release tarball under build/ from an already-built binary. It has no
-# `all` prerequisite on purpose, so tools/release-build.sh keeps ownership of
-# the hardening flags rather than triggering a plain rebuild here.
-dist:
- @test -f $(BUILDDIR)/cgit || { echo 'build/cgit missing, run make first' >&2; exit 1; }
- $(RM) -r $(DIST_DIR)
- $(INSTALL) -m 0755 -d $(DIST_DIR)
- $(INSTALL) -m 0755 $(BUILDDIR)/cgit $(DIST_DIR)/$(CGIT_SCRIPT_NAME)
- $(INSTALL) -m 0644 $(addprefix $(ASSETDIR)/,$(ASSETS)) $(DIST_DIR)
- $(INSTALL) -m 0644 $(DIST_DOCS) $(DIST_DIR)
- $(COPYTREE) $(DIST_TREES) $(DIST_DIR)
- tar czf $(DIST_DIR).tar.gz -C $(BUILDDIR) $(DIST_NAME)
-
# Compiled output lives under build/; the test suite writes into tests/, so
# cleaning removes both. The tests descent is guarded because tests/Makefile
# includes git's config.mak.uname, which needs the submodule present.
@@ -175,4 +154,4 @@ tags:
.PHONY: doc doc-man doc-html
.PHONY: install install-doc install-man install-html
.PHONY: uninstall uninstall-doc uninstall-man uninstall-html
-.PHONY: dist clean cleanall get-git tags
+.PHONY: clean cleanall get-git tags