diff options
| -rw-r--r-- | .github/workflows/ci.yml | 106 | |||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
1 file changed, 106 insertions, 0 deletions
diff --git a/.github/workflows/ci.yml b/.github/workflows/ci.yml new file mode 100644 index 0000000..794f0b0 --- /dev/null +++ b/.github/workflows/ci.yml @@ -0,0 +1,106 @@ +name: ci + +on: + push: + pull_request: + workflow_dispatch: + +concurrency: + group: ci-${{ github.ref }} + cancel-in-progress: true + +jobs: + build-and-test: + runs-on: ubuntu-24.04 + strategy: + fail-fast: false + matrix: + cc: [gcc, clang] + steps: + - uses: actions/checkout@v7 + with: + submodules: recursive + - name: Install build dependencies + run: | + sudo apt-get update + sudo apt-get install -y build-essential clang zlib1g-dev gettext libtool + # CC is passed on the command line because git's Makefile hard-assigns + # CC = cc, which would override it as an environment variable. + - name: Build + run: make NO_LUA=1 CC=${{ matrix.cc }} + - name: Run the test suite + # The submodule is pinned by SHA without its release tag, so skip the + # test that runs `git describe` inside it. + run: make NO_LUA=1 CC=${{ matrix.cc }} test + env: + CGIT_TEST_NO_GIT_VERSION: YesPlease + + lua: + runs-on: ubuntu-24.04 + steps: + - uses: actions/checkout@v7 + with: + submodules: recursive + - name: Install build dependencies + run: | + sudo apt-get update + sudo apt-get install -y build-essential zlib1g-dev gettext libtool libluajit-5.1-dev + # A plain build auto-detects luajit and links the lua: filter backend. + - name: Build with Lua + run: make + - name: Confirm Lua is compiled in + run: ./build/cgit --version | grep -F '[+] Lua scripting' + - name: Run the test suite + run: make test + env: + CGIT_TEST_NO_GIT_VERSION: YesPlease + + sanitizers: + runs-on: ubuntu-24.04 + steps: + - uses: actions/checkout@v7 + with: + submodules: recursive + - name: Install build dependencies + run: | + sudo apt-get update + sudo apt-get install -y build-essential zlib1g-dev gettext libtool + # Runs the test suite against a cgit built with AddressSanitizer and + # UndefinedBehaviorSanitizer. Leak detection is off because cgit is a + # short-lived CGI that leaves cleanup to process exit. + - name: Run the test suite under ASan and UBSan + run: make NO_LUA=1 SANITIZE=address,undefined test + env: + CGIT_TEST_NO_GIT_VERSION: YesPlease + ASAN_OPTIONS: abort_on_error=1:detect_leaks=0 + UBSAN_OPTIONS: print_stacktrace=1:halt_on_error=1 + + sparse: + runs-on: ubuntu-24.04 + # Static analysis. Non-blocking, since sparse is noisy on a large codebase. + continue-on-error: true + steps: + - uses: actions/checkout@v7 + with: + submodules: recursive + - name: Install build dependencies + run: | + sudo apt-get update + sudo apt-get install -y build-essential zlib1g-dev gettext libtool sparse + - name: Static-check the cgit sources with sparse + run: make NO_LUA=1 sparse + + hardened-build: + runs-on: ubuntu-24.04 + steps: + - uses: actions/checkout@v7 + with: + submodules: recursive + - name: Install build dependencies + run: | + sudo apt-get update + sudo apt-get install -y build-essential zlib1g-dev gettext libtool + - name: Build with release hardening flags + run: ./tools/release-build.sh + - name: Confirm the binary is position independent + run: file build/cgit | grep -q 'pie executable' |
