[StepSecurity] Apply security best practices #20
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
| # Runs unit tests. | |
| name: unit | |
| on: | |
| pull_request: | |
| merge_group: | |
| push: | |
| branches: [main] | |
| env: | |
| CARGO_TERM_COLOR: always | |
| SEED: rustethereumethereumrust | |
| concurrency: | |
| group: ${{ github.workflow }}-${{ github.head_ref || github.run_id }} | |
| cancel-in-progress: true | |
| jobs: | |
| test: | |
| name: test / ${{ matrix.type }} (${{ matrix.partition }}/${{ matrix.total_partitions }}) | |
| runs-on: | |
| group: Reth | |
| env: | |
| RUST_BACKTRACE: 1 | |
| strategy: | |
| matrix: | |
| include: | |
| - type: ethereum | |
| args: --features "asm-keccak ethereum" --locked | |
| partition: 1 | |
| total_partitions: 2 | |
| - type: ethereum | |
| args: --features "asm-keccak ethereum" --locked | |
| partition: 2 | |
| total_partitions: 2 | |
| - type: optimism | |
| args: --features "asm-keccak" --locked --exclude reth --exclude reth-bench --exclude "example-*" --exclude "reth-ethereum-*" --exclude "*-ethereum" | |
| partition: 1 | |
| total_partitions: 2 | |
| - type: optimism | |
| args: --features "asm-keccak" --locked --exclude reth --exclude reth-bench --exclude "example-*" --exclude "reth-ethereum-*" --exclude "*-ethereum" | |
| partition: 2 | |
| total_partitions: 2 | |
| timeout-minutes: 30 | |
| steps: | |
| - name: Harden the runner (Audit all outbound calls) | |
| uses: step-security/harden-runner@58077d3c7e43986b6b15fba718e8ea69e387dfcc # v2.15.1 | |
| with: | |
| egress-policy: audit | |
| - uses: actions/checkout@93cb6efe18208431cddfb8368fd83d5badbf9bfd # v5.0.1 | |
| - uses: rui314/setup-mold@725a8794d15fc7563f59595bd9556495c0564878 # v1 | |
| - uses: dtolnay/rust-toolchain@631a55b12751854ce901bb631d5902ceb48146f7 # stable | |
| - uses: Swatinem/rust-cache@779680da715d629ac1d338a641029a2f4372abb5 # v2.8.2 | |
| with: | |
| cache-on-failure: true | |
| - uses: taiki-e/install-action@65695e4d3f689d823ed155c836d20e98522ad93f # nextest | |
| - if: "${{ matrix.type == 'book' }}" | |
| uses: arduino/setup-protoc@c65c819552d16ad3c9b72d9dfd5ba5237b9c906b # v3.0.0 | |
| with: | |
| repo-token: ${{ secrets.GITHUB_TOKEN }} | |
| - name: Run tests | |
| run: | | |
| cargo nextest run \ | |
| ${{ matrix.args }} --workspace \ | |
| --exclude ef-tests --no-tests=warn \ | |
| --partition hash:${{ matrix.partition }}/2 \ | |
| -E "!kind(test) and not binary(e2e_testsuite)" | |
| state: | |
| name: Ethereum state tests | |
| runs-on: | |
| group: Reth | |
| env: | |
| RUST_LOG: info,sync=error | |
| RUST_BACKTRACE: 1 | |
| timeout-minutes: 30 | |
| steps: | |
| - name: Harden the runner (Audit all outbound calls) | |
| uses: step-security/harden-runner@58077d3c7e43986b6b15fba718e8ea69e387dfcc # v2.15.1 | |
| with: | |
| egress-policy: audit | |
| - uses: actions/checkout@93cb6efe18208431cddfb8368fd83d5badbf9bfd # v5.0.1 | |
| - name: Checkout ethereum/tests | |
| uses: actions/checkout@93cb6efe18208431cddfb8368fd83d5badbf9bfd # v5.0.1 | |
| with: | |
| repository: ethereum/tests | |
| ref: 81862e4848585a438d64f911a19b3825f0f4cd95 | |
| path: testing/ef-tests/ethereum-tests | |
| submodules: recursive | |
| fetch-depth: 1 | |
| - name: Download & extract EEST fixtures (public) | |
| shell: bash | |
| env: | |
| EEST_TESTS_TAG: v4.5.0 | |
| run: | | |
| set -euo pipefail | |
| mkdir -p testing/ef-tests/execution-spec-tests | |
| URL="https://github.com/ethereum/execution-spec-tests/releases/download/${EEST_TESTS_TAG}/fixtures_stable.tar.gz" | |
| curl -L "$URL" | tar -xz --strip-components=1 -C testing/ef-tests/execution-spec-tests | |
| - uses: rui314/setup-mold@725a8794d15fc7563f59595bd9556495c0564878 # v1 | |
| - uses: dtolnay/rust-toolchain@631a55b12751854ce901bb631d5902ceb48146f7 # stable | |
| - uses: taiki-e/install-action@65695e4d3f689d823ed155c836d20e98522ad93f # nextest | |
| - uses: Swatinem/rust-cache@779680da715d629ac1d338a641029a2f4372abb5 # v2.8.2 | |
| with: | |
| cache-on-failure: true | |
| - run: cargo nextest run --release -p ef-tests --features "asm-keccak ef-tests" | |
| doc: | |
| name: doc tests | |
| runs-on: | |
| group: Reth | |
| env: | |
| RUST_BACKTRACE: 1 | |
| timeout-minutes: 30 | |
| steps: | |
| - name: Harden the runner (Audit all outbound calls) | |
| uses: step-security/harden-runner@58077d3c7e43986b6b15fba718e8ea69e387dfcc # v2.15.1 | |
| with: | |
| egress-policy: audit | |
| - uses: actions/checkout@93cb6efe18208431cddfb8368fd83d5badbf9bfd # v5.0.1 | |
| - uses: rui314/setup-mold@725a8794d15fc7563f59595bd9556495c0564878 # v1 | |
| - uses: dtolnay/rust-toolchain@631a55b12751854ce901bb631d5902ceb48146f7 # stable | |
| - uses: Swatinem/rust-cache@779680da715d629ac1d338a641029a2f4372abb5 # v2.8.2 | |
| with: | |
| cache-on-failure: true | |
| - name: Run doctests | |
| run: cargo test --doc --workspace --all-features | |
| unit-success: | |
| name: unit success | |
| runs-on: ubuntu-latest | |
| if: always() | |
| needs: [test, state, doc] | |
| timeout-minutes: 30 | |
| steps: | |
| - name: Harden the runner (Audit all outbound calls) | |
| uses: step-security/harden-runner@58077d3c7e43986b6b15fba718e8ea69e387dfcc # v2.15.1 | |
| with: | |
| egress-policy: audit | |
| - name: Decide whether the needed jobs succeeded or failed | |
| uses: re-actors/alls-green@05ac9388f0aebcb5727afa17fcccfecd6f8ec5fe # release/v1 | |
| with: | |
| jobs: ${{ toJSON(needs) }} |