name: ci on: push: pull_request: workflow_dispatch: concurrency: group: ci-${{ github.ref }} cancel-in-progress: true jobs: build-and-test: runs-on: ubuntu-24.04 strategy: fail-fast: false matrix: cc: [gcc, clang] steps: - uses: actions/checkout@v7 with: submodules: recursive - name: Install build dependencies run: | sudo apt-get update sudo apt-get install -y build-essential clang zlib1g-dev gettext libtool # CC is passed on the command line because git's Makefile hard-assigns # CC = cc, which would override it as an environment variable. - name: Build run: make NO_LUA=1 CC=${{ matrix.cc }} - name: Run the test suite # The submodule is pinned by SHA without its release tag, so skip the # test that runs `git describe` inside it. run: make NO_LUA=1 CC=${{ matrix.cc }} test env: CGIT_TEST_NO_GIT_VERSION: YesPlease lua: runs-on: ubuntu-24.04 steps: - uses: actions/checkout@v7 with: submodules: recursive - name: Install build dependencies run: | sudo apt-get update sudo apt-get install -y build-essential zlib1g-dev gettext libtool libluajit-5.1-dev # A plain build auto-detects luajit and links the lua: filter backend. - name: Build with Lua run: make - name: Confirm Lua is compiled in run: ./build/cgit --version | grep -F '[+] Lua scripting' - name: Run the test suite run: make test env: CGIT_TEST_NO_GIT_VERSION: YesPlease sanitizers: runs-on: ubuntu-24.04 steps: - uses: actions/checkout@v7 with: submodules: recursive - name: Install build dependencies run: | sudo apt-get update sudo apt-get install -y build-essential zlib1g-dev gettext libtool # Runs the test suite against a cgit built with AddressSanitizer and # UndefinedBehaviorSanitizer. Leak detection is off because cgit is a # short-lived CGI that leaves cleanup to process exit. - name: Run the test suite under ASan and UBSan run: make NO_LUA=1 SANITIZE=address,undefined test env: CGIT_TEST_NO_GIT_VERSION: YesPlease ASAN_OPTIONS: abort_on_error=1:detect_leaks=0 UBSAN_OPTIONS: print_stacktrace=1:halt_on_error=1 sparse: runs-on: ubuntu-24.04 # Static analysis. Non-blocking, since sparse is noisy on a large codebase. continue-on-error: true steps: - uses: actions/checkout@v7 with: submodules: recursive - name: Install build dependencies run: | sudo apt-get update sudo apt-get install -y build-essential zlib1g-dev gettext libtool sparse - name: Static-check the cgit sources with sparse run: make NO_LUA=1 sparse hardened-build: runs-on: ubuntu-24.04 steps: - uses: actions/checkout@v7 with: submodules: recursive - name: Install build dependencies run: | sudo apt-get update sudo apt-get install -y build-essential zlib1g-dev gettext libtool - name: Build with release hardening flags run: ./tools/release-build.sh - name: Confirm the binary is position independent run: file build/cgit | grep -q 'pie executable'