blob: 794f0b09c36518af67512d2957aa84492da1ac58 (plain)
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
name: ci

on:
  push:
  pull_request:
  workflow_dispatch:

concurrency:
  group: ci-${{ github.ref }}
  cancel-in-progress: true

jobs:
  build-and-test:
    runs-on: ubuntu-24.04
    strategy:
      fail-fast: false
      matrix:
        cc: [gcc, clang]
    steps:
      - uses: actions/checkout@v7
        with:
          submodules: recursive
      - name: Install build dependencies
        run: |
          sudo apt-get update
          sudo apt-get install -y build-essential clang zlib1g-dev gettext libtool
      # CC is passed on the command line because git's Makefile hard-assigns
      # CC = cc, which would override it as an environment variable.
      - name: Build
        run: make NO_LUA=1 CC=${{ matrix.cc }}
      - name: Run the test suite
        # The submodule is pinned by SHA without its release tag, so skip the
        # test that runs `git describe` inside it.
        run: make NO_LUA=1 CC=${{ matrix.cc }} test
        env:
          CGIT_TEST_NO_GIT_VERSION: YesPlease

  lua:
    runs-on: ubuntu-24.04
    steps:
      - uses: actions/checkout@v7
        with:
          submodules: recursive
      - name: Install build dependencies
        run: |
          sudo apt-get update
          sudo apt-get install -y build-essential zlib1g-dev gettext libtool libluajit-5.1-dev
      # A plain build auto-detects luajit and links the lua: filter backend.
      - name: Build with Lua
        run: make
      - name: Confirm Lua is compiled in
        run: ./build/cgit --version | grep -F '[+] Lua scripting'
      - name: Run the test suite
        run: make test
        env:
          CGIT_TEST_NO_GIT_VERSION: YesPlease

  sanitizers:
    runs-on: ubuntu-24.04
    steps:
      - uses: actions/checkout@v7
        with:
          submodules: recursive
      - name: Install build dependencies
        run: |
          sudo apt-get update
          sudo apt-get install -y build-essential zlib1g-dev gettext libtool
      # Runs the test suite against a cgit built with AddressSanitizer and
      # UndefinedBehaviorSanitizer. Leak detection is off because cgit is a
      # short-lived CGI that leaves cleanup to process exit.
      - name: Run the test suite under ASan and UBSan
        run: make NO_LUA=1 SANITIZE=address,undefined test
        env:
          CGIT_TEST_NO_GIT_VERSION: YesPlease
          ASAN_OPTIONS: abort_on_error=1:detect_leaks=0
          UBSAN_OPTIONS: print_stacktrace=1:halt_on_error=1

  sparse:
    runs-on: ubuntu-24.04
    # Static analysis. Non-blocking, since sparse is noisy on a large codebase.
    continue-on-error: true
    steps:
      - uses: actions/checkout@v7
        with:
          submodules: recursive
      - name: Install build dependencies
        run: |
          sudo apt-get update
          sudo apt-get install -y build-essential zlib1g-dev gettext libtool sparse
      - name: Static-check the cgit sources with sparse
        run: make NO_LUA=1 sparse

  hardened-build:
    runs-on: ubuntu-24.04
    steps:
      - uses: actions/checkout@v7
        with:
          submodules: recursive
      - name: Install build dependencies
        run: |
          sudo apt-get update
          sudo apt-get install -y build-essential zlib1g-dev gettext libtool
      - name: Build with release hardening flags
        run: ./tools/release-build.sh
      - name: Confirm the binary is position independent
        run: file build/cgit | grep -q 'pie executable'