Repository navigation
Bump up macosxDeploymentTarget to 11 as lower is not supported anymore by latest macos release #628
Workflow file for this run
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
| name: Build PR | |
| on: | |
| pull_request: | |
| branches: [ main ] | |
| # Allows you to run this workflow manually from the Actions tab | |
| workflow_dispatch: | |
| permissions: | |
| contents: read | |
| env: | |
| MAVEN_OPTS: -Dhttp.keepAlive=false -Dmaven.wagon.http.pool=false -Dmaven.wagon.http.retryhandler.count=5 -Dmaven.wagon.httpconnectionManager.ttlSeconds=240 | |
| # Cancel running jobs when a new push happens to the same branch as otherwise it will | |
| # tie up too many resources without providing much value. | |
| concurrency: | |
| group: ${{ github.workflow }}-${{ github.ref }} | |
| cancel-in-progress: true | |
| jobs: | |
| build-pr: | |
| runs-on: ubuntu-latest | |
| strategy: | |
| fail-fast: false | |
| matrix: | |
| include: | |
| - setup: centos6-x86_64 | |
| docker-compose-run: "-f docker/docker-compose.centos-6.yaml -f docker/docker-compose.centos-6.18.yaml run build" | |
| docker-bake-args: "-f docker-compose.centos-6.yaml -f docker-compose.centos-6.18.yaml" | |
| - setup: debian7-x86_64 | |
| docker-compose-run: "-f docker/docker-compose.debian.yaml -f docker/docker-compose.debian-7.18.yaml run build-dynamic-only" | |
| docker-bake-args: "-f docker-compose.debian.yaml -f docker-compose.debian-7.18.yaml" | |
| - setup: centos7-aarch64 | |
| docker-compose-run: "-f docker/docker-compose.centos-7.yaml run cross-compile-aarch64-build" | |
| docker-bake-args: "-f docker-compose.centos-7.yaml" | |
| - setup: al2023-x86_64-aws_lc | |
| docker-compose-run: "-f docker/docker-compose.al2023.yaml run build" | |
| docker-bake-args: "-f docker-compose.al2023.yaml" | |
| name: ${{ matrix.setup }} | |
| steps: | |
| - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 | |
| - name: Set up Docker Buildx | |
| uses: docker/setup-buildx-action@37fe631027851001ddb9b187196cc803df7f5f0e # v4.3.0 | |
| # Cache .m2/repository | |
| - uses: actions/cache@55cc8345863c7cc4c66a329aec7e433d2d1c52a9 # v6.1.0 | |
| continue-on-error: true | |
| with: | |
| path: ~/.m2/repository | |
| key: build-pr-${{ matrix.setup }}-m2-repository-cache-${{ hashFiles('**/pom.xml') }} | |
| restore-keys: | | |
| build-pr-${{ matrix.setup }}-m2-repository-cache- | |
| - name: Extract OpenSSL version from pom.xml | |
| run: echo "OPENSSL_VERSION=$(./mvnw -q -Dexpression=opensslVersion -DforceStdout -N help:evaluate --no-transfer-progress)" >> $GITHUB_ENV | |
| - name: Extract OpenSSL SHA256 from pom.xml | |
| run: echo "OPENSSL_SHA256=$(./mvnw -q -Dexpression=opensslSha256 -DforceStdout -N help:evaluate --no-transfer-progress)" >> $GITHUB_ENV | |
| - name: Build docker image | |
| working-directory: docker | |
| env: | |
| BUILDX_BAKE_ENTITLEMENTS_FS: "0" | |
| run: docker buildx bake ${{ matrix.docker-bake-args }} --load --set "*.cache-from=type=gha,scope=${{ matrix.setup }}" --set "*.cache-to=type=gha,scope=${{ matrix.setup }},mode=max" | |
| - name: Build project | |
| run: docker compose ${{ matrix.docker-compose-run }} | tee build.output | |
| - name: Checking for test failures | |
| run: ./.github/scripts/check_build_result.sh build.output | |
| - uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1 | |
| if: ${{ always() }} | |
| with: | |
| name: build-pr-${{ matrix.setup }}-jars | |
| path: | | |
| **/target/*.jar | |
| - uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1 | |
| if: ${{ failure() }} | |
| with: | |
| name: build-pr-${{ matrix.setup }}-target | |
| path: | | |
| **/target/surefire-reports/ | |
| **/hs_err*.log | |
| build-pr-windows: | |
| runs-on: windows-2022 | |
| name: windows-x86_64 | |
| steps: | |
| - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 | |
| - name: Set up JDK 8 | |
| uses: actions/setup-java@de7274f081f381c8f8158605e0321c36c376e2e6 # v6.0.1 | |
| with: | |
| java-version: 8 | |
| distribution: zulu | |
| - name: Add msbuild to PATH | |
| uses: microsoft/setup-msbuild@30375c66a4eea26614e0d39710365f22f8b0af57 # v3.0.0 | |
| - name: Configuring Developer Command Prompt | |
| uses: ilammy/msvc-dev-cmd@0b201ec74fa43914dc39ae48a89fd1d8cb592756 # v1.13.0 | |
| with: | |
| arch: x86_amd64 | |
| - name: Install tools | |
| uses: crazy-max/ghaction-chocolatey@dfdcf5bba9c0a16358a21c13a06ec5c89024b3ac # v4.1.0 | |
| with: | |
| args: install ninja nasm | |
| # Cache .m2/repository | |
| - uses: actions/cache@55cc8345863c7cc4c66a329aec7e433d2d1c52a9 # v6.1.0 | |
| continue-on-error: true | |
| with: | |
| path: ~/.m2/repository | |
| key: build-pr-windows-m2-repository-cache-${{ hashFiles('**/pom.xml') }} | |
| restore-keys: | | |
| build-pr-windows-m2-repository-cache- | |
| - name: Build netty-tcnative-boringssl-static | |
| run: ./mvnw.cmd --file pom.xml -am -pl boringssl-static clean package | |
| - uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1 | |
| if: ${{ always() }} | |
| with: | |
| name: build-pr-windows-jars | |
| path: | | |
| **/target/*.jar | |
| - uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1 | |
| if: ${{ failure() }} | |
| with: | |
| name: build-pr-windows-target | |
| path: | | |
| **/target/surefire-reports/ | |
| **/hs_err*.log | |
| build-pr-macos: | |
| strategy: | |
| fail-fast: false | |
| matrix: | |
| include: | |
| - setup: macos-x86_64 | |
| os: macos-15-intel | |
| - setup: macos-aarch64 | |
| os: macos-15 | |
| runs-on: ${{ matrix.os }} | |
| name: ${{ matrix.setup }} build | |
| steps: | |
| - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 | |
| - name: Set up JDK 8 | |
| uses: actions/setup-java@de7274f081f381c8f8158605e0321c36c376e2e6 # v6.0.1 | |
| with: | |
| distribution: 'zulu' | |
| java-version: '8' | |
| # Cache .m2/repository | |
| # Caching of maven dependencies | |
| - uses: actions/cache@55cc8345863c7cc4c66a329aec7e433d2d1c52a9 # v6.1.0 | |
| continue-on-error: true | |
| with: | |
| path: ~/.m2/repository | |
| key: pr-${{ matrix.setup }}-maven-cache-${{ hashFiles('**/pom.xml') }} | |
| restore-keys: | | |
| pr-${{ matrix.setup }}-maven-cache- | |
| - name: Install tools via brew | |
| run: brew bundle | |
| - name: Build project | |
| run: ./mvnw -B -ntp --file pom.xml -am -pl openssl-dynamic,boringssl-static clean package | |
| - uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1 | |
| if: ${{ always() }} | |
| with: | |
| name: build-pr-${{ matrix.setup }}-jars | |
| path: | | |
| **/target/*.jar | |
| - uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1 | |
| if: ${{ failure() }} | |
| with: | |
| name: build-pr-${{ matrix.setup }}-target | |
| path: | | |
| **/target/surefire-reports/ | |
| **/hs_err*.log | |
| # Verify that the glibc-built Linux artifacts really load under musl. This consumes the jars | |
| # the build jobs above already upload, so nothing is rebuilt. The static half of this invariant | |
| # is enforced inside the build by scripts/check_musl_compat.sh; what only a real musl system can | |
| # show is whether the library loads, because on aarch64 the historical failure was a JVM SIGSEGV | |
| # during dlopen rather than an UnsatisfiedLinkError. See docs/musl-compatibility.md. | |
| # | |
| # `needs` cannot depend on a single matrix leg, so this waits for all of build-pr. | |
| # | |
| # The gcompat legs are not expected to change the answer -- libc.so.6 is one of the names musl | |
| # resolves internally, so gcompat's symlink is never read. They earn their place by making a | |
| # bare failure diagnostic: if bare fails and gcompat passes, the artifact has re-acquired a | |
| # dependency on the compatibility shim, which is exactly how 2.0.65 appeared to work. | |
| musl-verify: | |
| needs: build-pr | |
| strategy: | |
| fail-fast: false | |
| matrix: | |
| include: | |
| # Both runners are pinned: there is no ubuntu-latest-arm, so pairing ubuntu-latest with | |
| # a pinned arm label would drift apart as soon as ubuntu-latest moves on. The host only | |
| # supplies Docker here, so pinning costs nothing. | |
| - setup: alpine-x86_64 | |
| os: ubuntu-24.04 | |
| jars: build-pr-centos6-x86_64-jars | |
| variant: bare | |
| extra-pkgs: "" | |
| drop-elftools: "1" | |
| build-service: runtime-setup | |
| run-service: verify | |
| - setup: alpine-aarch64 | |
| os: ubuntu-24.04-arm | |
| jars: build-pr-centos7-aarch64-jars | |
| variant: bare | |
| extra-pkgs: "" | |
| drop-elftools: "1" | |
| build-service: runtime-setup | |
| run-service: verify | |
| # The invariant leg: an Alpine JDK that ships no `libgcc` package of its own, so | |
| # `apk del .elftools` really does leave libgcc absent. eclipse-temurin's JDK depends on | |
| # libgcc, so the bare legs above cannot prove the artifact loads without it. | |
| - setup: alpine-x86_64-nolibgcc | |
| os: ubuntu-24.04 | |
| jars: build-pr-centos6-x86_64-jars | |
| variant: nolibgcc | |
| extra-pkgs: "" | |
| drop-elftools: "1" | |
| jdk-image: amazoncorretto:21-alpine | |
| build-service: runtime-setup | |
| run-service: verify | |
| - setup: alpine-aarch64-nolibgcc | |
| os: ubuntu-24.04-arm | |
| jars: build-pr-centos7-aarch64-jars | |
| variant: nolibgcc | |
| extra-pkgs: "" | |
| drop-elftools: "1" | |
| jdk-image: amazoncorretto:21-alpine | |
| build-service: runtime-setup | |
| run-service: verify | |
| - setup: alpine-x86_64-gcompat | |
| os: ubuntu-24.04 | |
| jars: build-pr-centos6-x86_64-jars | |
| variant: gcompat | |
| extra-pkgs: gcompat | |
| drop-elftools: "0" | |
| build-service: runtime-setup | |
| run-service: verify | |
| - setup: alpine-aarch64-gcompat | |
| os: ubuntu-24.04-arm | |
| jars: build-pr-centos7-aarch64-jars | |
| variant: gcompat | |
| extra-pkgs: gcompat | |
| drop-elftools: "0" | |
| build-service: runtime-setup | |
| run-service: verify | |
| # Control: anything failing on Alpine must pass here, or the check is at fault rather | |
| # than the artifact. | |
| - setup: glibc-control-x86_64 | |
| os: ubuntu-24.04 | |
| jars: build-pr-centos6-x86_64-jars | |
| variant: glibc-control | |
| extra-pkgs: "" | |
| drop-elftools: "0" | |
| build-service: control-runtime-setup | |
| run-service: control-verify | |
| runs-on: ${{ matrix.os }} | |
| name: musl-verify ${{ matrix.setup }} | |
| steps: | |
| - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 | |
| - uses: actions/download-artifact@3e5f45b2cfb9172054b4087a40e8e0b5a5461e7c # v8.0.1 | |
| with: | |
| name: ${{ matrix.jars }} | |
| path: musl-verify-jars | |
| - name: Build verification image | |
| env: | |
| MUSL_VARIANT: ${{ matrix.variant }} | |
| MUSL_EXTRA_PKGS: ${{ matrix.extra-pkgs }} | |
| MUSL_JDK_IMAGE: ${{ matrix.jdk-image }} | |
| run: docker compose -f docker/docker-compose.alpine.yaml build ${{ matrix.build-service }} | |
| - name: Verify the artifact under ${{ matrix.variant }} | |
| env: | |
| MUSL_VARIANT: ${{ matrix.variant }} | |
| MUSL_EXTRA_PKGS: ${{ matrix.extra-pkgs }} | |
| MUSL_DROP_ELFTOOLS: ${{ matrix.drop-elftools }} | |
| MUSL_JDK_IMAGE: ${{ matrix.jdk-image }} | |
| MUSL_JARS_DIR: musl-verify-jars | |
| run: docker compose -f docker/docker-compose.alpine.yaml run --rm ${{ matrix.run-service }} |