Finit 5: udev/eudev replacement #790
Workflow file for this run
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
| name: Bob the Builder | |
| # Run on all branches, including all pull requests, except the 'dev' | |
| # branch since that's where we run Coverity Scan (limited tokens/day) | |
| on: | |
| push: | |
| branches: | |
| - '**' | |
| - '!dev' | |
| pull_request: | |
| types: [opened, synchronize, reopened, labeled] | |
| permissions: | |
| contents: read | |
| concurrency: | |
| group: ${{ github.workflow }}-${{ github.head_ref || github.ref }} | |
| cancel-in-progress: true | |
| jobs: | |
| fuzz: | |
| name: fuzz | |
| runs-on: ubuntu-latest | |
| if: github.event_name != 'push' || github.ref == 'refs/heads/master' | |
| steps: | |
| - name: Install dependencies | |
| run: | | |
| sudo apt-get -y update | |
| sudo apt-get -y install pkg-config libconfuse-dev clang | |
| # clang picks the newest gcc tree it finds and needs the | |
| # matching libstdc++ headers to link the fuzzer runtime | |
| sudo apt-get -y install libstdc++-14-dev || true | |
| wget https://github.com/troglobit/libuev/releases/download/v2.4.1/libuev-2.4.1.tar.xz | |
| wget https://github.com/troglobit/libite/releases/download/v2.6.2/libite-2.6.2.tar.gz | |
| tar xf libuev-2.4.1.tar.xz | |
| tar xf libite-2.6.2.tar.gz | |
| (cd libuev-2.4.1 && ./configure && make -j9 && sudo make install-strip) | |
| (cd libite-2.6.2 && ./configure && make -j9 && sudo make install-strip) | |
| sudo ldconfig | |
| - uses: actions/checkout@v7 | |
| - name: Configure | |
| run: | | |
| ./autogen.sh | |
| ./configure --prefix=/usr --exec-prefix= --sysconfdir=/etc --localstatedir=/var | |
| - name: Build fuzz target | |
| run: | | |
| clang -fsanitize=fuzzer,address -DLINK_FUZZ_LIBFUZZER -D_GNU_SOURCE \ | |
| -I libink -I . -o fuzz-msg-parse \ | |
| test/src/fuzz-msg-parse.c libink/*.c | |
| # Restores the newest corpus and saves a fresh one, since a cache | |
| # entry is immutable once written. Caches made on a branch are | |
| # private to it, so the corpus that accumulates on master is what | |
| # pull requests start from, rather than nothing. | |
| - name: Restore corpus | |
| uses: actions/cache@v6 | |
| with: | |
| path: .fuzz-corpus | |
| key: fuzz-corpus-${{ github.run_id }} | |
| restore-keys: fuzz-corpus- | |
| - name: Fuzz | |
| run: | | |
| mkdir -p .fuzz-corpus | |
| ./fuzz-msg-parse .fuzz-corpus -max_total_time=120 -max_len=4096 \ | |
| -print_final_stats=1 | |
| # Without this the corpus only ever grows, and most of what it | |
| # accumulates reaches code some earlier input already reached. | |
| - name: Minimise corpus | |
| if: always() | |
| run: | | |
| mkdir -p .fuzz-corpus-min | |
| ./fuzz-msg-parse -merge=1 .fuzz-corpus-min .fuzz-corpus | |
| rm -rf .fuzz-corpus | |
| mv .fuzz-corpus-min .fuzz-corpus | |
| echo "corpus: $(ls .fuzz-corpus | wc -l) inputs" | |
| - name: Upload crashers | |
| if: failure() | |
| uses: actions/upload-artifact@v7 | |
| with: | |
| name: fuzz-crashers | |
| path: | | |
| crash-* | |
| leak-* | |
| timeout-* | |
| if-no-files-found: ignore | |
| build: | |
| # Verify we can build on latest Ubuntu with both gcc and clang | |
| name: ${{ matrix.compiler }} | |
| runs-on: ubuntu-latest | |
| # Skip redundant builds for PRs - prefer PR builds over push builds | |
| if: github.event_name != 'push' || github.ref == 'refs/heads/master' | |
| strategy: | |
| matrix: | |
| compiler: [gcc, clang] | |
| fail-fast: false | |
| env: | |
| CC: ${{ matrix.compiler }} | |
| steps: | |
| - name: Install dependencies | |
| run: | | |
| sudo apt-get -y update | |
| sudo apt-get -y install pkg-config tree jq libcap-dev libconfuse-dev libblkid-dev | |
| wget https://github.com/troglobit/libuev/releases/download/v2.4.1/libuev-2.4.1.tar.xz | |
| wget https://github.com/troglobit/libite/releases/download/v2.6.2/libite-2.6.2.tar.gz | |
| tar xf libuev-2.4.1.tar.xz | |
| tar xf libite-2.6.2.tar.gz | |
| (cd libuev-2.4.1 && ./configure && make -j9 && sudo make install-strip) | |
| (cd libite-2.6.2 && ./configure && make -j9 && sudo make install-strip) | |
| sudo ldconfig | |
| - uses: actions/checkout@v7 | |
| - name: Static Finit | |
| run: | | |
| ./autogen.sh | |
| ./configure --prefix= --enable-static | |
| make -j9 V=1 | |
| - name: Regular Finit | |
| run: | | |
| ./configure --prefix=/usr --exec-prefix= --sysconfdir=/etc --localstatedir=/var \ | |
| --enable-x11-common-plugin --enable-testserv-plugin --with-watchdog \ | |
| --with-keventd \ | |
| CFLAGS="-fsanitize=address -ggdb" | |
| make -j9 clean | |
| make -j9 V=1 | |
| - name: Install to /tmp | |
| run: | | |
| DESTDIR=/tmp make install-strip | |
| tree /tmp || true | |
| - name: Check dependencies | |
| run: | | |
| ldd /tmp/sbin/finit | |
| size /tmp/sbin/finit | |
| ldd /tmp/sbin/initctl | |
| size /tmp/sbin/initctl | |
| ldd /tmp/sbin/reboot | |
| size /tmp/sbin/reboot | |
| - name: Verify starting and showing usage text | |
| run: | | |
| sudo /tmp/sbin/finit -h | |
| sudo /tmp/sbin/initctl -h | |
| - name: Enable unprivileged userns (unshare) | |
| run: | | |
| sudo sysctl kernel.apparmor_restrict_unprivileged_userns=0 | |
| - name: Run Unit Tests | |
| run: | | |
| make -j1 check || (cat test/test-suite.log; false) | |
| - name: Upload Test Results | |
| if: always() | |
| uses: actions/upload-artifact@v7 | |
| with: | |
| name: finit-test-${{ matrix.compiler }} | |
| path: test/*.log |