-
Notifications
You must be signed in to change notification settings - Fork 0
260 lines (244 loc) · 10.5 KB
/
Copy pathci.yml
File metadata and controls
260 lines (244 loc) · 10.5 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
130
131
132
133
134
135
136
137
138
139
140
141
142
143
144
145
146
147
148
149
150
151
152
153
154
155
156
157
158
159
160
161
162
163
164
165
166
167
168
169
170
171
172
173
174
175
176
177
178
179
180
181
182
183
184
185
186
187
188
189
190
191
192
193
194
195
196
197
198
199
200
201
202
203
204
205
206
207
208
209
210
211
212
213
214
215
216
217
218
219
220
221
222
223
224
225
226
227
228
229
230
231
232
233
234
235
236
237
238
239
240
241
242
243
244
245
246
247
248
249
250
251
252
253
254
255
256
257
258
259
260
---
name: CI
"on":
push:
branches: [main]
pull_request:
schedule:
# Re-proves the vendored bytes against the upstream release and the build on current runners.
- cron: "41 6 * * 2"
# The release workflow runs this whole file on the tagged commit before publishing.
workflow_call:
permissions:
contents: read
concurrency:
group: ${{ github.workflow }}-${{ github.ref }}
cancel-in-progress: ${{ github.ref != 'refs/heads/main' }}
env:
CARGO_TERM_COLOR: always
jobs:
test:
name: Test ${{ matrix.toolchain }}
runs-on: ubuntu-latest
strategy:
fail-fast: false
matrix:
toolchain: [stable, "1.81"]
steps:
- uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
with:
persist-credentials: false
- uses: dtolnay/rust-toolchain@02cb101ec7c40f2c49e1d9714d64511d8e1b74de # master
with:
toolchain: ${{ matrix.toolchain }}
- run: cargo test --all-targets
- run: cargo test --doc
lint:
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
with:
persist-credentials: false
- uses: dtolnay/rust-toolchain@02cb101ec7c40f2c49e1d9714d64511d8e1b74de # master
with:
toolchain: stable
components: rustfmt, clippy
- run: cargo fmt --check
- run: cargo clippy --all-targets -- -D warnings
- run: cargo fmt --manifest-path smoke/Cargo.toml --check
- run: cargo clippy --manifest-path smoke/Cargo.toml --all-targets -- -D warnings
- run: cargo fmt --manifest-path wasm/Cargo.toml --check
- run: cargo fmt --manifest-path fuzz/Cargo.toml --check
- run: cargo clippy --manifest-path fuzz/Cargo.toml --all-targets -- -D warnings
- run: cargo doc --no-deps
env:
RUSTDOCFLAGS: -D warnings
# The fuzz crate is its own workspace, so no other job runs its tests.
fuzz:
name: Fuzz corpus replays cleanly
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
- uses: dtolnay/rust-toolchain@02cb101ec7c40f2c49e1d9714d64511d8e1b74de # master
with:
toolchain: stable
- run: cargo test --manifest-path fuzz/Cargo.toml
scripts:
name: Scripts and workflows
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
with:
persist-credentials: false
- run: shellcheck -x upgrade.sh bump.sh sigstore.sh interop.sh suite/run.sh .clusterfuzzlite/build.sh
- name: actionlint
run: |
bash <(curl -sSfL https://raw.githubusercontent.com/rhysd/actionlint/914e7df21a07ef503a81201c76d2b11c789d3fca/scripts/download-actionlint.bash) 1.7.12
./actionlint -color
- uses: taiki-e/install-action@7623a79cdfecb99d681017af368ca353d9f49bb5 # v2.87.19
with:
tool: zizmor@1.30.1
# The token enables the online audits, which catch impostor commits and known-vulnerable actions.
- run: zizmor .
env:
GH_TOKEN: ${{ github.token }}
deny:
name: Dependencies of the test crates pass cargo-deny
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
with:
persist-credentials: false
- uses: dtolnay/rust-toolchain@02cb101ec7c40f2c49e1d9714d64511d8e1b74de # master
with:
toolchain: stable
- uses: taiki-e/install-action@7623a79cdfecb99d681017af368ca353d9f49bb5 # v2.87.19
with:
tool: cargo-deny@0.20.2
- run: cargo deny --manifest-path smoke/Cargo.toml check
- run: cargo deny --manifest-path wasm/Cargo.toml check
compile:
name: Compile the packaged amalgamation on ${{ matrix.os }}
runs-on: ${{ matrix.os }}
strategy:
fail-fast: false
matrix:
os: [ubuntu-latest, macos-latest, windows-latest]
steps:
- uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
with:
persist-credentials: false
- uses: dtolnay/rust-toolchain@02cb101ec7c40f2c49e1d9714d64511d8e1b74de # master
with:
toolchain: stable
# The consumer runs against the unpacked .crate, which holds only what crates.io would serve.
- name: Package and unpack
shell: bash
run: |
cargo package
crate=$(echo target/package/sqlite3mc-src-*.crate)
dir=$(basename "$crate" .crate)
tar -xzf "$crate" -C target/package
cp -r smoke "target/package/$dir/smoke"
echo "SMOKE_MANIFEST=target/package/$dir/smoke/Cargo.toml" >> "$GITHUB_ENV"
- run: cargo run --manifest-path "$SMOKE_MANIFEST"
shell: bash
interop:
name: Native and Wasm SQLite3MC open each other's files
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
with:
persist-credentials: false
- uses: dtolnay/rust-toolchain@02cb101ec7c40f2c49e1d9714d64511d8e1b74de # master
with:
toolchain: stable
targets: wasm32-unknown-unknown
components: clippy
- uses: taiki-e/install-action@7623a79cdfecb99d681017af368ca353d9f49bb5 # v2.87.19
with:
tool: wasm-pack
# Both sides compile the unpacked .crate, and a C library function the released sqlite-wasm-rs does not provide fails the Wasm link.
- name: Package and unpack
run: |
set -euo pipefail
cargo package
crate=$(echo target/package/sqlite3mc-src-*.crate)
dir="$PWD/target/package/$(basename "$crate" .crate)"
tar -xzf "$crate" -C target/package
cp -r smoke "$dir/smoke"
echo "PACKAGE_DIR=$dir" >> "$GITHUB_ENV"
- run: ./interop.sh node
env:
INTEROP_CRATE: ${{ env.PACKAGE_DIR }}
WASM_BINDGEN_TEST_TIMEOUT: "300"
# sqlite-wasm-rs vendors the same release, so only its build log shows which copy it compiled.
- run: grep -rqsF "rerun-if-changed=$PACKAGE_DIR/sqlite3mc" wasm/target/wasm32-unknown-unknown/release/build
- run: cargo clippy --manifest-path wasm/Cargo.toml --target wasm32-unknown-unknown --all-targets -- -D warnings
env:
SQLITE_WASM_RS_SOURCE_DIR: ${{ env.PACKAGE_DIR }}/sqlite3mc
browsers:
name: Wasm SQLite3MC in Chrome and Firefox opens native files and writes files native opens, on OPFS too
runs-on: ubuntu-latest
env:
WASM_BINDGEN_TEST_TIMEOUT: "300"
steps:
- uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
with:
persist-credentials: false
- uses: dtolnay/rust-toolchain@02cb101ec7c40f2c49e1d9714d64511d8e1b74de # master
with:
toolchain: stable
targets: wasm32-unknown-unknown
- uses: taiki-e/install-action@7623a79cdfecb99d681017af368ca353d9f49bb5 # v2.87.19
with:
tool: wasm-pack
- run: ./interop.sh chrome
- run: ./interop.sh firefox
rusqlite:
name: rusqlite's SQLite3MC tests pass on these sources
runs-on: ubuntu-latest
env:
# Head of LucaCappelletti94/rusqlite feat/sqlite3mc-src, moved by hand when rusqlite-pin.yml goes red.
RUSQLITE_REV: 15c7356af30f42c5938b48217a240e61203eac50
steps:
- uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
with:
persist-credentials: false
- uses: dtolnay/rust-toolchain@02cb101ec7c40f2c49e1d9714d64511d8e1b74de # master
with:
toolchain: stable
- name: Fetch rusqlite and point its sqlite3mc-src at this checkout
run: |
set -euo pipefail
rusqlite="$RUNNER_TEMP/rusqlite"
git init -q "$rusqlite"
git -C "$rusqlite" fetch -q --depth 1 https://github.com/LucaCappelletti94/rusqlite.git "$RUSQLITE_REV"
git -C "$rusqlite" checkout -q FETCH_HEAD
version=$(cargo metadata --no-deps --format-version 1 | jq -r '.packages[0].version')
# rusqlite requires one exact release, and a patch whose version misses it is silently dropped.
sed -i -E "s/^(sqlite3mc-src = \{ version = \")=[^\"]+\"/\1=${version%%+*}\"/" "$rusqlite/libsqlite3-sys/Cargo.toml"
printf '\n[patch.crates-io]\nsqlite3mc-src = { path = "%s" }\n' "$PWD" >> "$rusqlite/Cargo.toml"
echo "RUSQLITE_DIR=$rusqlite" >> "$GITHUB_ENV"
- run: cargo test --features bundled-sqlite3mc --workspace --all-targets
working-directory: ${{ env.RUSQLITE_DIR }}
- run: cargo test --features "modern-full bundled-sqlite3mc" --workspace --all-targets
working-directory: ${{ env.RUSQLITE_DIR }}
- run: cargo test --features "modern-full bundled-sqlite3mc" --workspace --doc
working-directory: ${{ env.RUSQLITE_DIR }}
- run: cargo test --features "modern-full bundled-sqlite3mc session buildtime_bindgen preupdate_hook" --workspace --all-targets
working-directory: ${{ env.RUSQLITE_DIR }}
# The crates.io release carries the same bytes until a bump, so only the build log shows which copy was compiled.
- run: grep -rqsF "rerun-if-changed=$GITHUB_WORKSPACE/sqlite3mc/" "$RUSQLITE_DIR/target/debug/build"
suite:
name: SQLite3MC's and SQLite's tests pass on the shipped amalgamation
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
with:
persist-credentials: false
- uses: sigstore/cosign-installer@6f9f17788090df1f26f669e9d70d6ae9567deba6 # v4.1.2
- run: sudo apt-get install -y --no-install-recommends tcl-dev
- run: ./suite/run.sh
sanitizers:
name: SQLite3MC's and SQLite's tests are clean under ASAN and UBSan
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
with:
persist-credentials: false
- uses: sigstore/cosign-installer@6f9f17788090df1f26f669e9d70d6ae9567deba6 # v4.1.2
- run: sudo apt-get install -y --no-install-recommends tcl-dev
- run: ./suite/run.sh
env:
SANITIZE: "1"
release-bytes:
name: Vendored files match the release
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
with:
persist-credentials: false
- uses: sigstore/cosign-installer@6f9f17788090df1f26f669e9d70d6ae9567deba6 # v4.1.2
- run: ./upgrade.sh
- run: git diff --exit-code