diff --git a/.github/workflows/ci-build.yml b/.github/workflows/ci-build.yml index cb4c631e6..a722be720 100644 --- a/.github/workflows/ci-build.yml +++ b/.github/workflows/ci-build.yml @@ -42,12 +42,26 @@ jobs: docker-bake-args: "-f docker-compose.al2023.yaml" name: ${{ matrix.setup }} + permissions: + contents: read + packages: write # to push the docker build cache to ghcr.io steps: - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 - name: Set up Docker Buildx uses: docker/setup-buildx-action@37fe631027851001ddb9b187196cc803df7f5f0e # v4.3.0 + # The docker-compose*.yaml files push/pull their build cache to + # ghcr.io/netty/netty-tcnative-build-cache (distinct from netty/netty's own + # ghcr.io/netty/netty-build-cache, so the two repos' caches never collide). + - name: Log in to GitHub Container Registry + uses: docker/login-action@dbcb813823bdd20940b903addbd779551569679f # v4.6.0 + continue-on-error: true + with: + registry: ghcr.io + username: ${{ github.actor }} + password: ${{ secrets.GITHUB_TOKEN }} + # Cache .m2/repository - uses: actions/cache@55cc8345863c7cc4c66a329aec7e433d2d1c52a9 # v6.1.0 continue-on-error: true @@ -67,7 +81,7 @@ jobs: working-directory: docker env: BUILDX_BAKE_ENTITLEMENTS_FS: "0" - run: docker buildx bake ${{ matrix.docker-bake-args }} --load --set "*.cache-from=type=gha,scope=${{ matrix.setup }}" --set "*.cache-to=type=gha,scope=${{ matrix.setup }},mode=max" + run: docker buildx bake ${{ matrix.docker-bake-args }} --load - name: Build project run: docker compose ${{ matrix.docker-compose-run }} | tee build.output diff --git a/.github/workflows/ci-deploy.yml b/.github/workflows/ci-deploy.yml index 07af1a1e0..d9575a7d2 100644 --- a/.github/workflows/ci-deploy.yml +++ b/.github/workflows/ci-deploy.yml @@ -25,23 +25,40 @@ concurrency: jobs: stage-snapshot: runs-on: ubuntu-latest + permissions: + contents: read + packages: write # to push the docker build cache to ghcr.io strategy: matrix: include: - setup: centos6-x86_64 - docker-compose-build: "-f docker/docker-compose.centos-6.yaml -f docker/docker-compose.centos-6.18.yaml build" + docker-bake-args: "-f docker-compose.centos-6.yaml -f docker-compose.centos-6.18.yaml" docker-compose-run: "-f docker/docker-compose.centos-6.yaml -f docker/docker-compose.centos-6.18.yaml run stage-snapshot" - setup: debian7-x86_64 - docker-compose-build: "-f docker/docker-compose.debian.yaml -f docker/docker-compose.debian-7.18.yaml build" + docker-bake-args: "-f docker-compose.debian.yaml -f docker-compose.debian-7.18.yaml" docker-compose-run: "-f docker/docker-compose.debian.yaml -f docker/docker-compose.debian-7.18.yaml run stage-snapshot" - setup: centos7-aarch64 - docker-compose-build: "-f docker/docker-compose.centos-7.yaml build" + docker-bake-args: "-f docker-compose.centos-7.yaml" docker-compose-run: "-f docker/docker-compose.centos-7.yaml run cross-compile-aarch64-stage-snapshot" name: stage-snapshot-${{ matrix.setup }} steps: - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 + - name: Set up Docker Buildx + uses: docker/setup-buildx-action@37fe631027851001ddb9b187196cc803df7f5f0e # v4.3.0 + + # This workflow's token only has read-all permissions unless the job grants packages: + # write above; ignore-error=true on cache_to in the compose files absorbs any push + # failure. Cache reads (populated by ci-build.yml/ci-pr.yml) still work either way. + - name: Log in to GitHub Container Registry + uses: docker/login-action@dbcb813823bdd20940b903addbd779551569679f # v4.6.0 + continue-on-error: true + with: + registry: ghcr.io + username: ${{ github.actor }} + password: ${{ secrets.GITHUB_TOKEN }} + # Cache .m2/repository - uses: actions/cache@55cc8345863c7cc4c66a329aec7e433d2d1c52a9 # v6.1.0 continue-on-error: true @@ -55,7 +72,10 @@ jobs: run: mkdir -p ~/local-staging - name: Build docker image - run: docker compose ${{ matrix.docker-compose-build }} + working-directory: docker + env: + BUILDX_BAKE_ENTITLEMENTS_FS: "0" + run: docker buildx bake ${{ matrix.docker-bake-args }} --load - name: Stage snapshots to local staging directory run: docker compose ${{ matrix.docker-compose-run }} diff --git a/.github/workflows/ci-pr.yml b/.github/workflows/ci-pr.yml index c783be3ee..e34756631 100644 --- a/.github/workflows/ci-pr.yml +++ b/.github/workflows/ci-pr.yml @@ -40,12 +40,25 @@ jobs: docker-bake-args: "-f docker-compose.al2023.yaml" name: ${{ matrix.setup }} + permissions: + contents: read + packages: write # to push the docker build cache to ghcr.io; no-op (ignored) for fork PRs steps: - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 - name: Set up Docker Buildx uses: docker/setup-buildx-action@37fe631027851001ddb9b187196cc803df7f5f0e # v4.3.0 + # Only succeeds for same-repo runs; fork PRs get a read-only GITHUB_TOKEN and simply won't + # get cache hits/pushes, which is fine since it only means a slower, non-cached build. + - name: Log in to GitHub Container Registry + uses: docker/login-action@dbcb813823bdd20940b903addbd779551569679f # v4.6.0 + continue-on-error: true + with: + registry: ghcr.io + username: ${{ github.actor }} + password: ${{ secrets.GITHUB_TOKEN }} + # Cache .m2/repository - uses: actions/cache@55cc8345863c7cc4c66a329aec7e433d2d1c52a9 # v6.1.0 continue-on-error: true @@ -65,7 +78,7 @@ jobs: working-directory: docker env: BUILDX_BAKE_ENTITLEMENTS_FS: "0" - run: docker buildx bake ${{ matrix.docker-bake-args }} --load --set "*.cache-from=type=gha,scope=${{ matrix.setup }}" --set "*.cache-to=type=gha,scope=${{ matrix.setup }},mode=max" + run: docker buildx bake ${{ matrix.docker-bake-args }} --load - name: Build project run: docker compose ${{ matrix.docker-compose-run }} | tee build.output diff --git a/.github/workflows/ci-release.yml b/.github/workflows/ci-release.yml index 08c22a0a8..7b2d70f60 100644 --- a/.github/workflows/ci-release.yml +++ b/.github/workflows/ci-release.yml @@ -75,17 +75,18 @@ jobs: needs: prepare-release permissions: contents: write + packages: write # to push the docker build cache to ghcr.io strategy: matrix: include: - setup: centos6-x86_64 - docker-compose-build: "-f docker/docker-compose.centos-6.yaml -f docker/docker-compose.centos-6.18.yaml build" + docker-bake-args: "-f docker-compose.centos-6.yaml -f docker-compose.centos-6.18.yaml" docker-compose-run: "-f docker/docker-compose.centos-6.yaml -f docker/docker-compose.centos-6.18.yaml run stage-release" - setup: debian7-x86_64 - docker-compose-build: "-f docker/docker-compose.debian.yaml -f docker/docker-compose.debian-7.18.yaml build" + docker-bake-args: "-f docker-compose.debian.yaml -f docker-compose.debian-7.18.yaml" docker-compose-run: "-f docker/docker-compose.debian.yaml -f docker/docker-compose.debian-7.18.yaml run stage-release" - setup: centos7-aarch64 - docker-compose-build: "-f docker/docker-compose.centos-7.yaml build" + docker-bake-args: "-f docker-compose.centos-7.yaml" docker-compose-run: "-f docker/docker-compose.centos-7.yaml run cross-compile-aarch64-stage-release" name: stage-release-${{ matrix.setup }} @@ -117,6 +118,17 @@ jobs: key: ${{ secrets.SSH_PRIVATE_KEY_PEM }} known_hosts: ${{ secrets.SSH_KNOWN_HOSTS }} + - name: Set up Docker Buildx + uses: docker/setup-buildx-action@37fe631027851001ddb9b187196cc803df7f5f0e # v4.3.0 + + - name: Log in to GitHub Container Registry + uses: docker/login-action@dbcb813823bdd20940b903addbd779551569679f # v4.6.0 + continue-on-error: true + with: + registry: ghcr.io + username: ${{ github.actor }} + password: ${{ secrets.GITHUB_TOKEN }} + # Cache .m2/repository - uses: actions/cache@55cc8345863c7cc4c66a329aec7e433d2d1c52a9 # v6.1.0 continue-on-error: true @@ -146,12 +158,11 @@ jobs: working-directory: ./prepare-release-workspace/ run: echo "OPENSSL_SHA256=$(./mvnw -q -Dexpression=opensslSha256 -DforceStdout -N help:evaluate --no-transfer-progress)" >> $GITHUB_ENV - # Release builds intentionally use docker compose (not buildx bake) for a clean, - # cache-free build. OPENSSL_VERSION is still extracted above so docker-compose can - # interpolate it as a build arg. - name: Build docker image - working-directory: ./prepare-release-workspace/ - run: docker compose ${{ matrix.docker-compose-build }} + working-directory: ./prepare-release-workspace/docker + env: + BUILDX_BAKE_ENTITLEMENTS_FS: "0" + run: docker buildx bake ${{ matrix.docker-bake-args }} --load - name: Stage release to local staging directory working-directory: ./prepare-release-workspace/ diff --git a/boringssl-static/pom.xml b/boringssl-static/pom.xml index 21a57707e..59c59fde2 100644 --- a/boringssl-static/pom.xml +++ b/boringssl-static/pom.xml @@ -97,8 +97,8 @@ ${javaDefaultModuleName} - MACOSX_DEPLOYMENT_TARGET=10.13 - -DCMAKE_OSX_DEPLOYMENT_TARGET=10.13 + MACOSX_DEPLOYMENT_TARGET=11 + -DCMAKE_OSX_DEPLOYMENT_TARGET=11 netty-tcnative-boringssl-static @@ -1325,8 +1325,8 @@ true mac arm64-apple-macos11 - OSX_DEPLOYMENT_TARGET=11.0 - -DCMAKE_OSX_DEPLOYMENT_TARGET=11.0 + OSX_DEPLOYMENT_TARGET=11 + -DCMAKE_OSX_DEPLOYMENT_TARGET=11 -Wa,--noexecstack -target ${target} -O3 -fno-omit-frame-pointer -target ${target} @@ -1573,8 +1573,8 @@ true mac x86_64-apple-macos10.12 - OSX_DEPLOYMENT_TARGET=10.12 - -DCMAKE_OSX_DEPLOYMENT_TARGET=10.12 + OSX_DEPLOYMENT_TARGET=11 + -DCMAKE_OSX_DEPLOYMENT_TARGET=11 -Wa,--noexecstack -target ${target} -O3 -fno-omit-frame-pointer -target ${target} diff --git a/docker/docker-compose.al2023.yaml b/docker/docker-compose.al2023.yaml index 666521d50..b5cd41a17 100644 --- a/docker/docker-compose.al2023.yaml +++ b/docker/docker-compose.al2023.yaml @@ -7,6 +7,10 @@ services: build: context: ../ dockerfile: docker/Dockerfile.al2023 + cache_from: + - type=registry,ref=ghcr.io/netty/netty-tcnative-build-cache:al2023 + cache_to: + - type=registry,ref=ghcr.io/netty/netty-tcnative-build-cache:al2023,mode=max,ignore-error=true common: &common image: netty-tcnative-al2023:x86_64 diff --git a/docker/docker-compose.centos-6.yaml b/docker/docker-compose.centos-6.yaml index 18ae36315..3be968ddf 100644 --- a/docker/docker-compose.centos-6.yaml +++ b/docker/docker-compose.centos-6.yaml @@ -10,6 +10,10 @@ services: args: openssl_version: "${OPENSSL_VERSION:-3.6.1}" openssl_sha256: "${OPENSSL_SHA256:-b1bfedcd5b289ff22aee87c9d600f515767ebf45f77168cb6d64f231f518a82e}" + cache_from: + - type=registry,ref=ghcr.io/netty/netty-tcnative-build-cache:centos6 + cache_to: + - type=registry,ref=ghcr.io/netty/netty-tcnative-build-cache:centos6,mode=max,ignore-error=true common: &common image: netty-tcnative-centos:default diff --git a/docker/docker-compose.centos-7.yaml b/docker/docker-compose.centos-7.yaml index 56c89d7e2..2d1a1148b 100644 --- a/docker/docker-compose.centos-7.yaml +++ b/docker/docker-compose.centos-7.yaml @@ -12,6 +12,10 @@ services: apr_version: "1.7.6" openssl_version: "${OPENSSL_VERSION:-3.6.1}" openssl_sha256: "${OPENSSL_SHA256:-b1bfedcd5b289ff22aee87c9d600f515767ebf45f77168cb6d64f231f518a82e}" + cache_from: + - type=registry,ref=ghcr.io/netty/netty-tcnative-build-cache:cross-aarch64 + cache_to: + - type=registry,ref=ghcr.io/netty/netty-tcnative-build-cache:cross-aarch64,mode=max,ignore-error=true cross-compile-aarch64-common: &cross-compile-aarch64-common image: netty-tcnative-centos:cross_compile_aarch64 diff --git a/docker/docker-compose.debian.yaml b/docker/docker-compose.debian.yaml index 751d1a920..ffc91cd29 100644 --- a/docker/docker-compose.debian.yaml +++ b/docker/docker-compose.debian.yaml @@ -10,6 +10,10 @@ services: args: openssl_version: "${OPENSSL_VERSION:-3.6.1}" openssl_sha256: "${OPENSSL_SHA256:-b1bfedcd5b289ff22aee87c9d600f515767ebf45f77168cb6d64f231f518a82e}" + cache_from: + - type=registry,ref=ghcr.io/netty/netty-tcnative-build-cache:debian7 + cache_to: + - type=registry,ref=ghcr.io/netty/netty-tcnative-build-cache:debian7,mode=max,ignore-error=true common: &common image: netty-tcnative-debian:default diff --git a/pom.xml b/pom.xml index beb989837..24ab89e5a 100644 --- a/pom.xml +++ b/pom.xml @@ -121,8 +121,8 @@ false false ${project.build.directory}/generated-sources - MACOSX_DEPLOYMENT_TARGET=10.9 - -DCMAKE_OSX_DEPLOYMENT_TARGET=10.9 + MACOSX_DEPLOYMENT_TARGET=11 + -DCMAKE_OSX_DEPLOYMENT_TARGET=11 ${os.detected.arch} ${os.detected.name}-${os.detected.arch} false