Skip to content

Bump up macosxDeploymentTarget to 11 as lower is not supported anymore by latest macos release #628

Bump up macosxDeploymentTarget to 11 as lower is not supported anymore by latest macos release

Bump up macosxDeploymentTarget to 11 as lower is not supported anymore by latest macos release #628

Workflow file for this run

name: Build PR
on:
pull_request:
branches: [ main ]
# Allows you to run this workflow manually from the Actions tab
workflow_dispatch:
permissions:
contents: read
env:
MAVEN_OPTS: -Dhttp.keepAlive=false -Dmaven.wagon.http.pool=false -Dmaven.wagon.http.retryhandler.count=5 -Dmaven.wagon.httpconnectionManager.ttlSeconds=240
# Cancel running jobs when a new push happens to the same branch as otherwise it will
# tie up too many resources without providing much value.
concurrency:
group: ${{ github.workflow }}-${{ github.ref }}
cancel-in-progress: true
jobs:
build-pr:
runs-on: ubuntu-latest
strategy:
fail-fast: false
matrix:
include:
- setup: centos6-x86_64
docker-compose-run: "-f docker/docker-compose.centos-6.yaml -f docker/docker-compose.centos-6.18.yaml run build"
docker-bake-args: "-f docker-compose.centos-6.yaml -f docker-compose.centos-6.18.yaml"
- setup: debian7-x86_64
docker-compose-run: "-f docker/docker-compose.debian.yaml -f docker/docker-compose.debian-7.18.yaml run build-dynamic-only"
docker-bake-args: "-f docker-compose.debian.yaml -f docker-compose.debian-7.18.yaml"
- setup: centos7-aarch64
docker-compose-run: "-f docker/docker-compose.centos-7.yaml run cross-compile-aarch64-build"
docker-bake-args: "-f docker-compose.centos-7.yaml"
- setup: al2023-x86_64-aws_lc
docker-compose-run: "-f docker/docker-compose.al2023.yaml run build"
docker-bake-args: "-f docker-compose.al2023.yaml"
name: ${{ matrix.setup }}
steps:
- uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
- name: Set up Docker Buildx
uses: docker/setup-buildx-action@37fe631027851001ddb9b187196cc803df7f5f0e # v4.3.0
# Cache .m2/repository
- uses: actions/cache@55cc8345863c7cc4c66a329aec7e433d2d1c52a9 # v6.1.0
continue-on-error: true
with:
path: ~/.m2/repository
key: build-pr-${{ matrix.setup }}-m2-repository-cache-${{ hashFiles('**/pom.xml') }}
restore-keys: |
build-pr-${{ matrix.setup }}-m2-repository-cache-
- name: Extract OpenSSL version from pom.xml
run: echo "OPENSSL_VERSION=$(./mvnw -q -Dexpression=opensslVersion -DforceStdout -N help:evaluate --no-transfer-progress)" >> $GITHUB_ENV
- name: Extract OpenSSL SHA256 from pom.xml
run: echo "OPENSSL_SHA256=$(./mvnw -q -Dexpression=opensslSha256 -DforceStdout -N help:evaluate --no-transfer-progress)" >> $GITHUB_ENV
- name: Build docker image
working-directory: docker
env:
BUILDX_BAKE_ENTITLEMENTS_FS: "0"
run: docker buildx bake ${{ matrix.docker-bake-args }} --load --set "*.cache-from=type=gha,scope=${{ matrix.setup }}" --set "*.cache-to=type=gha,scope=${{ matrix.setup }},mode=max"
- name: Build project
run: docker compose ${{ matrix.docker-compose-run }} | tee build.output
- name: Checking for test failures
run: ./.github/scripts/check_build_result.sh build.output
- uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1
if: ${{ always() }}
with:
name: build-pr-${{ matrix.setup }}-jars
path: |
**/target/*.jar
- uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1
if: ${{ failure() }}
with:
name: build-pr-${{ matrix.setup }}-target
path: |
**/target/surefire-reports/
**/hs_err*.log
build-pr-windows:
runs-on: windows-2022
name: windows-x86_64
steps:
- uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
- name: Set up JDK 8
uses: actions/setup-java@de7274f081f381c8f8158605e0321c36c376e2e6 # v6.0.1
with:
java-version: 8
distribution: zulu
- name: Add msbuild to PATH
uses: microsoft/setup-msbuild@30375c66a4eea26614e0d39710365f22f8b0af57 # v3.0.0
- name: Configuring Developer Command Prompt
uses: ilammy/msvc-dev-cmd@0b201ec74fa43914dc39ae48a89fd1d8cb592756 # v1.13.0
with:
arch: x86_amd64
- name: Install tools
uses: crazy-max/ghaction-chocolatey@dfdcf5bba9c0a16358a21c13a06ec5c89024b3ac # v4.1.0
with:
args: install ninja nasm
# Cache .m2/repository
- uses: actions/cache@55cc8345863c7cc4c66a329aec7e433d2d1c52a9 # v6.1.0
continue-on-error: true
with:
path: ~/.m2/repository
key: build-pr-windows-m2-repository-cache-${{ hashFiles('**/pom.xml') }}
restore-keys: |
build-pr-windows-m2-repository-cache-
- name: Build netty-tcnative-boringssl-static
run: ./mvnw.cmd --file pom.xml -am -pl boringssl-static clean package
- uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1
if: ${{ always() }}
with:
name: build-pr-windows-jars
path: |
**/target/*.jar
- uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1
if: ${{ failure() }}
with:
name: build-pr-windows-target
path: |
**/target/surefire-reports/
**/hs_err*.log
build-pr-macos:
strategy:
fail-fast: false
matrix:
include:
- setup: macos-x86_64
os: macos-15-intel
- setup: macos-aarch64
os: macos-15
runs-on: ${{ matrix.os }}
name: ${{ matrix.setup }} build
steps:
- uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
- name: Set up JDK 8
uses: actions/setup-java@de7274f081f381c8f8158605e0321c36c376e2e6 # v6.0.1
with:
distribution: 'zulu'
java-version: '8'
# Cache .m2/repository
# Caching of maven dependencies
- uses: actions/cache@55cc8345863c7cc4c66a329aec7e433d2d1c52a9 # v6.1.0
continue-on-error: true
with:
path: ~/.m2/repository
key: pr-${{ matrix.setup }}-maven-cache-${{ hashFiles('**/pom.xml') }}
restore-keys: |
pr-${{ matrix.setup }}-maven-cache-
- name: Install tools via brew
run: brew bundle
- name: Build project
run: ./mvnw -B -ntp --file pom.xml -am -pl openssl-dynamic,boringssl-static clean package
- uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1
if: ${{ always() }}
with:
name: build-pr-${{ matrix.setup }}-jars
path: |
**/target/*.jar
- uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1
if: ${{ failure() }}
with:
name: build-pr-${{ matrix.setup }}-target
path: |
**/target/surefire-reports/
**/hs_err*.log
# Verify that the glibc-built Linux artifacts really load under musl. This consumes the jars
# the build jobs above already upload, so nothing is rebuilt. The static half of this invariant
# is enforced inside the build by scripts/check_musl_compat.sh; what only a real musl system can
# show is whether the library loads, because on aarch64 the historical failure was a JVM SIGSEGV
# during dlopen rather than an UnsatisfiedLinkError. See docs/musl-compatibility.md.
#
# `needs` cannot depend on a single matrix leg, so this waits for all of build-pr.
#
# The gcompat legs are not expected to change the answer -- libc.so.6 is one of the names musl
# resolves internally, so gcompat's symlink is never read. They earn their place by making a
# bare failure diagnostic: if bare fails and gcompat passes, the artifact has re-acquired a
# dependency on the compatibility shim, which is exactly how 2.0.65 appeared to work.
musl-verify:
needs: build-pr
strategy:
fail-fast: false
matrix:
include:
# Both runners are pinned: there is no ubuntu-latest-arm, so pairing ubuntu-latest with
# a pinned arm label would drift apart as soon as ubuntu-latest moves on. The host only
# supplies Docker here, so pinning costs nothing.
- setup: alpine-x86_64
os: ubuntu-24.04
jars: build-pr-centos6-x86_64-jars
variant: bare
extra-pkgs: ""
drop-elftools: "1"
build-service: runtime-setup
run-service: verify
- setup: alpine-aarch64
os: ubuntu-24.04-arm
jars: build-pr-centos7-aarch64-jars
variant: bare
extra-pkgs: ""
drop-elftools: "1"
build-service: runtime-setup
run-service: verify
# The invariant leg: an Alpine JDK that ships no `libgcc` package of its own, so
# `apk del .elftools` really does leave libgcc absent. eclipse-temurin's JDK depends on
# libgcc, so the bare legs above cannot prove the artifact loads without it.
- setup: alpine-x86_64-nolibgcc
os: ubuntu-24.04
jars: build-pr-centos6-x86_64-jars
variant: nolibgcc
extra-pkgs: ""
drop-elftools: "1"
jdk-image: amazoncorretto:21-alpine
build-service: runtime-setup
run-service: verify
- setup: alpine-aarch64-nolibgcc
os: ubuntu-24.04-arm
jars: build-pr-centos7-aarch64-jars
variant: nolibgcc
extra-pkgs: ""
drop-elftools: "1"
jdk-image: amazoncorretto:21-alpine
build-service: runtime-setup
run-service: verify
- setup: alpine-x86_64-gcompat
os: ubuntu-24.04
jars: build-pr-centos6-x86_64-jars
variant: gcompat
extra-pkgs: gcompat
drop-elftools: "0"
build-service: runtime-setup
run-service: verify
- setup: alpine-aarch64-gcompat
os: ubuntu-24.04-arm
jars: build-pr-centos7-aarch64-jars
variant: gcompat
extra-pkgs: gcompat
drop-elftools: "0"
build-service: runtime-setup
run-service: verify
# Control: anything failing on Alpine must pass here, or the check is at fault rather
# than the artifact.
- setup: glibc-control-x86_64
os: ubuntu-24.04
jars: build-pr-centos6-x86_64-jars
variant: glibc-control
extra-pkgs: ""
drop-elftools: "0"
build-service: control-runtime-setup
run-service: control-verify
runs-on: ${{ matrix.os }}
name: musl-verify ${{ matrix.setup }}
steps:
- uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
- uses: actions/download-artifact@3e5f45b2cfb9172054b4087a40e8e0b5a5461e7c # v8.0.1
with:
name: ${{ matrix.jars }}
path: musl-verify-jars
- name: Build verification image
env:
MUSL_VARIANT: ${{ matrix.variant }}
MUSL_EXTRA_PKGS: ${{ matrix.extra-pkgs }}
MUSL_JDK_IMAGE: ${{ matrix.jdk-image }}
run: docker compose -f docker/docker-compose.alpine.yaml build ${{ matrix.build-service }}
- name: Verify the artifact under ${{ matrix.variant }}
env:
MUSL_VARIANT: ${{ matrix.variant }}
MUSL_EXTRA_PKGS: ${{ matrix.extra-pkgs }}
MUSL_DROP_ELFTOOLS: ${{ matrix.drop-elftools }}
MUSL_JDK_IMAGE: ${{ matrix.jdk-image }}
MUSL_JARS_DIR: musl-verify-jars
run: docker compose -f docker/docker-compose.alpine.yaml run --rm ${{ matrix.run-service }}