Skip to content

Build the FIPS profile in CI, and make it build again #621

Build the FIPS profile in CI, and make it build again

Build the FIPS profile in CI, and make it build again #621

Workflow file for this run

name: Build PR
on:
pull_request:
branches: [ main ]
# Allows you to run this workflow manually from the Actions tab
workflow_dispatch:
permissions:
contents: read
env:
MAVEN_OPTS: -Dhttp.keepAlive=false -Dmaven.wagon.http.pool=false -Dmaven.wagon.http.retryhandler.count=5 -Dmaven.wagon.httpconnectionManager.ttlSeconds=240
# Cancel running jobs when a new push happens to the same branch as otherwise it will
# tie up too many resources without providing much value.
concurrency:
group: ${{ github.workflow }}-${{ github.ref }}
cancel-in-progress: true
jobs:
build-pr:
runs-on: ubuntu-latest
strategy:
fail-fast: false
matrix:
include:
- setup: centos6-x86_64
docker-compose-run: "-f docker/docker-compose.centos-6.yaml -f docker/docker-compose.centos-6.18.yaml run build"
docker-bake-args: "-f docker-compose.centos-6.yaml -f docker-compose.centos-6.18.yaml"
- setup: debian7-x86_64
docker-compose-run: "-f docker/docker-compose.debian.yaml -f docker/docker-compose.debian-7.18.yaml run build-dynamic-only"
docker-bake-args: "-f docker-compose.debian.yaml -f docker-compose.debian-7.18.yaml"
- setup: centos7-aarch64
docker-compose-run: "-f docker/docker-compose.centos-7.yaml run cross-compile-aarch64-build"
docker-bake-args: "-f docker-compose.centos-7.yaml"
- setup: al2023-x86_64-aws_lc
docker-compose-run: "-f docker/docker-compose.al2023.yaml run build"
docker-bake-args: "-f docker-compose.al2023.yaml"
# boringssl-static on a current toolchain, and the only CI leg that builds the FIPS
# profile (it needs clang-17; see docker/Dockerfile.debian13). Neither is a release
# artifact. Before these legs the FIPS profile had no CI at all, so a change to the
# release profiles that was not ported to it went unnoticed until a downstream build.
- setup: debian13-x86_64
docker-compose-run: "-f docker/docker-compose.debian-13.yaml run build"
docker-bake-args: "-f docker-compose.debian-13.yaml"
- setup: debian13-x86_64-fips
docker-compose-run: "-f docker/docker-compose.debian-13.yaml run build-fips"
docker-bake-args: "-f docker-compose.debian-13.yaml"
name: ${{ matrix.setup }}
steps:
- uses: actions/checkout@11d5960a326750d5838078e36cf38b85af677262 # v4.4.0
- name: Set up Docker Buildx
uses: docker/setup-buildx-action@8d2750c68a42422c14e847fe6c8ac0403b4cbd6f # v3.12.0
# Cache .m2/repository
- uses: actions/cache@0057852bfaa89a56745cba8c7296529d2fc39830 # v4.3.0
continue-on-error: true
with:
path: ~/.m2/repository
key: build-pr-${{ matrix.setup }}-m2-repository-cache-${{ hashFiles('**/pom.xml') }}
restore-keys: |
build-pr-${{ matrix.setup }}-m2-repository-cache-
- name: Extract OpenSSL version from pom.xml
run: echo "OPENSSL_VERSION=$(./mvnw -q -Dexpression=opensslVersion -DforceStdout -N help:evaluate --no-transfer-progress)" >> $GITHUB_ENV
- name: Extract OpenSSL SHA256 from pom.xml
run: echo "OPENSSL_SHA256=$(./mvnw -q -Dexpression=opensslSha256 -DforceStdout -N help:evaluate --no-transfer-progress)" >> $GITHUB_ENV
- name: Build docker image
working-directory: docker
env:
BUILDX_BAKE_ENTITLEMENTS_FS: "0"
run: docker buildx bake ${{ matrix.docker-bake-args }} --load --set "*.cache-from=type=gha,scope=${{ matrix.setup }}" --set "*.cache-to=type=gha,scope=${{ matrix.setup }},mode=max"
- name: Build project
run: docker compose ${{ matrix.docker-compose-run }} | tee build.output
- name: Checking for test failures
run: ./.github/scripts/check_build_result.sh build.output
- uses: actions/upload-artifact@ea165f8d65b6e75b540449e92b4886f43607fa02 # v4.6.2
if: ${{ always() }}
with:
name: build-pr-${{ matrix.setup }}-jars
path: |
**/target/*.jar
- uses: actions/upload-artifact@ea165f8d65b6e75b540449e92b4886f43607fa02 # v4.6.2
if: ${{ failure() }}
with:
name: build-pr-${{ matrix.setup }}-target
path: |
**/target/surefire-reports/
**/hs_err*.log
build-pr-windows:
runs-on: windows-2022
name: windows-x86_64
steps:
- uses: actions/checkout@11d5960a326750d5838078e36cf38b85af677262 # v4.4.0
- name: Set up JDK 8
uses: actions/setup-java@cf277c60eb25467037889841efdb72551f06f6c3 # v4.9.1
with:
java-version: 8
distribution: zulu
- name: Add msbuild to PATH
uses: microsoft/setup-msbuild@6fb02220983dee41ce7ae257b6f4d8f9bf5ed4ce # v2.0.0
- name: Configuring Developer Command Prompt
uses: ilammy/msvc-dev-cmd@0b201ec74fa43914dc39ae48a89fd1d8cb592756 # v1.13.0
with:
arch: x86_amd64
- name: Install tools
uses: crazy-max/ghaction-chocolatey@2526f467ccbd337d307fe179959cabbeca0bc8c0 # v3.4.0
with:
args: install ninja nasm
# Cache .m2/repository
- uses: actions/cache@0057852bfaa89a56745cba8c7296529d2fc39830 # v4.3.0
continue-on-error: true
with:
path: ~/.m2/repository
key: build-pr-windows-m2-repository-cache-${{ hashFiles('**/pom.xml') }}
restore-keys: |
build-pr-windows-m2-repository-cache-
- name: Build netty-tcnative-boringssl-static
run: ./mvnw.cmd --file pom.xml -am -pl boringssl-static clean package
- uses: actions/upload-artifact@ea165f8d65b6e75b540449e92b4886f43607fa02 # v4.6.2
if: ${{ always() }}
with:
name: build-pr-windows-jars
path: |
**/target/*.jar
- uses: actions/upload-artifact@ea165f8d65b6e75b540449e92b4886f43607fa02 # v4.6.2
if: ${{ failure() }}
with:
name: build-pr-windows-target
path: |
**/target/surefire-reports/
**/hs_err*.log
build-pr-macos:
strategy:
fail-fast: false
matrix:
include:
- setup: macos-x86_64
os: macos-15-intel
- setup: macos-aarch64
os: macos-15
runs-on: ${{ matrix.os }}
name: ${{ matrix.setup }} build
steps:
- uses: actions/checkout@11d5960a326750d5838078e36cf38b85af677262 # v4.4.0
- name: Set up JDK 8
uses: actions/setup-java@cf277c60eb25467037889841efdb72551f06f6c3 # v4.9.1
with:
distribution: 'zulu'
java-version: '8'
# Cache .m2/repository
# Caching of maven dependencies
- uses: actions/cache@0057852bfaa89a56745cba8c7296529d2fc39830 # v4.3.0
continue-on-error: true
with:
path: ~/.m2/repository
key: pr-${{ matrix.setup }}-maven-cache-${{ hashFiles('**/pom.xml') }}
restore-keys: |
pr-${{ matrix.setup }}-maven-cache-
- name: Install tools via brew
run: brew bundle
- name: Build project
run: ./mvnw -B -ntp --file pom.xml -am -pl openssl-dynamic,boringssl-static clean package
- uses: actions/upload-artifact@ea165f8d65b6e75b540449e92b4886f43607fa02 # v4.6.2
if: ${{ always() }}
with:
name: build-pr-${{ matrix.setup }}-jars
path: |
**/target/*.jar
- uses: actions/upload-artifact@ea165f8d65b6e75b540449e92b4886f43607fa02 # v4.6.2
if: ${{ failure() }}
with:
name: build-pr-${{ matrix.setup }}-target
path: |
**/target/surefire-reports/
**/hs_err*.log
# Verify that the glibc-built Linux artifacts really load under musl. This consumes the jars
# the build jobs above already upload, so nothing is rebuilt. The static half of this invariant
# is enforced inside the build by scripts/check_musl_compat.sh; what only a real musl system can
# show is whether the library loads, because on aarch64 the historical failure was a JVM SIGSEGV
# during dlopen rather than an UnsatisfiedLinkError. See docs/musl-compatibility.md.
#
# `needs` cannot depend on a single matrix leg, so this waits for all of build-pr.
#
# The gcompat legs are not expected to change the answer -- libc.so.6 is one of the names musl
# resolves internally, so gcompat's symlink is never read. They earn their place by making a
# bare failure diagnostic: if bare fails and gcompat passes, the artifact has re-acquired a
# dependency on the compatibility shim, which is exactly how 2.0.65 appeared to work.
musl-verify:
needs: build-pr
strategy:
fail-fast: false
matrix:
include:
# Both runners are pinned: there is no ubuntu-latest-arm, so pairing ubuntu-latest with
# a pinned arm label would drift apart as soon as ubuntu-latest moves on. The host only
# supplies Docker here, so pinning costs nothing.
- setup: alpine-x86_64
os: ubuntu-24.04
jars: build-pr-centos6-x86_64-jars
variant: bare
extra-pkgs: ""
drop-elftools: "1"
build-service: runtime-setup
run-service: verify
- setup: alpine-aarch64
os: ubuntu-24.04-arm
jars: build-pr-centos7-aarch64-jars
variant: bare
extra-pkgs: ""
drop-elftools: "1"
build-service: runtime-setup
run-service: verify
# The invariant leg: an Alpine JDK that ships no `libgcc` package of its own, so
# `apk del .elftools` really does leave libgcc absent. eclipse-temurin's JDK depends on
# libgcc, so the bare legs above cannot prove the artifact loads without it.
- setup: alpine-x86_64-nolibgcc
os: ubuntu-24.04
jars: build-pr-centos6-x86_64-jars
variant: nolibgcc
extra-pkgs: ""
drop-elftools: "1"
jdk-image: amazoncorretto:21-alpine
build-service: runtime-setup
run-service: verify
- setup: alpine-aarch64-nolibgcc
os: ubuntu-24.04-arm
jars: build-pr-centos7-aarch64-jars
variant: nolibgcc
extra-pkgs: ""
drop-elftools: "1"
jdk-image: amazoncorretto:21-alpine
build-service: runtime-setup
run-service: verify
- setup: alpine-x86_64-gcompat
os: ubuntu-24.04
jars: build-pr-centos6-x86_64-jars
variant: gcompat
extra-pkgs: gcompat
drop-elftools: "0"
build-service: runtime-setup
run-service: verify
- setup: alpine-aarch64-gcompat
os: ubuntu-24.04-arm
jars: build-pr-centos7-aarch64-jars
variant: gcompat
extra-pkgs: gcompat
drop-elftools: "0"
build-service: runtime-setup
run-service: verify
# The Debian 13-built jars: the FIPS artifact is the one that matters (its power-on
# self-test and integrity check run inside an ELF constructor at dlopen, so only a
# real load proves the patchelf'd library is still intact), and the default-profile
# one shows what a modern-gcc build looks like on musl. bare x86_64 only: aarch64
# would need an arm64 FIPS build leg, and the gcompat/nolibgcc variants add nothing
# the CentOS 6 legs do not already establish.
- setup: alpine-x86_64-fips
os: ubuntu-24.04
jars: build-pr-debian13-x86_64-fips-jars
variant: bare
extra-pkgs: ""
drop-elftools: "1"
build-service: runtime-setup
run-service: verify
- setup: alpine-x86_64-debian13
os: ubuntu-24.04
jars: build-pr-debian13-x86_64-jars
variant: bare
extra-pkgs: ""
drop-elftools: "1"
build-service: runtime-setup
run-service: verify
# Control: anything failing on Alpine must pass here, or the check is at fault rather
# than the artifact.
- setup: glibc-control-x86_64
os: ubuntu-24.04
jars: build-pr-centos6-x86_64-jars
variant: glibc-control
extra-pkgs: ""
drop-elftools: "0"
build-service: control-runtime-setup
run-service: control-verify
runs-on: ${{ matrix.os }}
name: musl-verify ${{ matrix.setup }}
steps:
- uses: actions/checkout@11d5960a326750d5838078e36cf38b85af677262 # v4.4.0
- uses: actions/download-artifact@d3f86a106a0bac45b974a628896c90dbdf5c8093 # v4.3.0
with:
name: ${{ matrix.jars }}
path: musl-verify-jars
- name: Build verification image
env:
MUSL_VARIANT: ${{ matrix.variant }}
MUSL_EXTRA_PKGS: ${{ matrix.extra-pkgs }}
MUSL_JDK_IMAGE: ${{ matrix.jdk-image }}
run: docker compose -f docker/docker-compose.alpine.yaml build ${{ matrix.build-service }}
- name: Verify the artifact under ${{ matrix.variant }}
env:
MUSL_VARIANT: ${{ matrix.variant }}
MUSL_EXTRA_PKGS: ${{ matrix.extra-pkgs }}
MUSL_DROP_ELFTOOLS: ${{ matrix.drop-elftools }}
MUSL_JDK_IMAGE: ${{ matrix.jdk-image }}
MUSL_JARS_DIR: musl-verify-jars
run: docker compose -f docker/docker-compose.alpine.yaml run --rm ${{ matrix.run-service }}