diff --git a/.github/workflows/test.yml b/.github/workflows/test.yml index efae350..77973da 100644 --- a/.github/workflows/test.yml +++ b/.github/workflows/test.yml @@ -14,17 +14,23 @@ jobs: fail-fast: false matrix: go-version: [1.19.x, 1.25.x, 1.26.x] - libseccomp: ["v2.3.3", "v2.4.4", "v2.5.6", "v2.6.0", "HEAD"] - os: [ubuntu-24.04, ubuntu-24.04-arm] + libseccomp: ["v2.3.3", "v2.4.4", "v2.5.6", "v2.6.1", "HEAD"] + os: [ubuntu-24.04, ubuntu-24.04-arm, ubuntu-26.04, ubuntu-26.04-arm] runs-on: ${{ matrix.os }} steps: - name: checkout - uses: actions/checkout@v6 + uses: actions/checkout@v7 - name: build libseccomp ${{ matrix.libseccomp }} + env: + # sha256 checksums for libseccomp release tarballs. + SHA256_2_3_3: 7fc28f4294cc72e61c529bedf97e705c3acf9c479a8f1a3028d4cd2ca9f3b155 + SHA256_2_4_4: 4e79738d1ef3c9b7ca9769f1f8b8d84fc17143c2c1c432e53b9c64787e0ff3eb + SHA256_2_5_6: 04c37d72965dce218a0c94519b056e1775cf786b5260ee2b7992956c4ee38633 + SHA256_2_6_1: 501f66c667225d53791b97e1d7cf85ab764c297d04881f60f38f451c4b0ee1be run: | set -x sudo apt -qq update @@ -33,25 +39,38 @@ jobs: PREFIX="$(pwd)/seccomp" LIBDIR="$PREFIX/lib" - git clone https://github.com/seccomp/libseccomp - cd libseccomp - git checkout ${{ matrix.libseccomp }} - # In main branch, configure.ac sets libseccomp version to 0.0.0, which - # results in error when compiling libseccomp-golang. While 0.0.0 is - # there for a reason, here we need to build and test against HEAD, so - # set it to a suitable value. - # - # Version 9.9.9 is used because: - # - version >= current is needed; - # - chances are good such version won't ever exist; - # - it is easy to spot in tests output; - # - the LIBFILE pattern below expects single digits. VER="${{ matrix.libseccomp }}" - if [ "$VER" == "HEAD" ]; then + if [[ "$VER" == v* ]]; then + # A specific release: fetch and verify the release tarball + # instead of cloning the whole repo. + mkdir libseccomp + cd libseccomp + VER="${VER#v}" + TAR="libseccomp-$VER.tar.gz" + CKSUM_VAR="SHA256_${VER//./_}" + curl -fsSL --remote-name "https://github.com/seccomp/libseccomp/releases/download/v$VER/$TAR" + sha256sum --strict --check - <<<"${!CKSUM_VAR} *$TAR" + tar --strip-components=1 -xzf "$TAR" + rm -f "$TAR" + else + # Any other git tag/branch/sha: clone and build from the repo. + git clone https://github.com/seccomp/libseccomp + cd libseccomp + git checkout $VER + # In main branch, configure.ac sets libseccomp version to 0.0.0, which + # results in error when compiling libseccomp-golang. While 0.0.0 is + # there for a reason, here we need to build and test against HEAD, so + # set it to a suitable value. + # + # Version 9.9.9 is used because: + # - version >= current is needed; + # - chances are good such version won't ever exist; + # - it is easy to spot in tests output; + # - the LIBFILE pattern below expects single digits. VER=9.9.9 sed -i "/^AC_INIT(/s/0\.0\.0/$VER/" configure.ac + ./autogen.sh fi - ./autogen.sh ./configure --prefix="$PREFIX" --libdir="$LIBDIR" make sudo make install @@ -66,7 +85,7 @@ jobs: echo "_EXPECTED_LIBSECCOMP_VERSION=$VER" >> $GITHUB_ENV - name: install go ${{ matrix.go-version }} - uses: actions/setup-go@v6 + uses: actions/setup-go@v7 with: go-version: ${{ matrix.go-version }} # Add libseccomp.pc path so that setup-go adds this file hash to cache key. @@ -77,7 +96,7 @@ jobs: - name: build - run: make check-build + run: make build - name: test run: make test diff --git a/.github/workflows/validate.yml b/.github/workflows/validate.yml index 10987c9..066b7ab 100644 --- a/.github/workflows/validate.yml +++ b/.github/workflows/validate.yml @@ -13,8 +13,8 @@ jobs: lint: runs-on: ubuntu-24.04 steps: - - uses: actions/checkout@v6 - - uses: actions/setup-go@v6 + - uses: actions/checkout@v7 + - uses: actions/setup-go@v7 with: go-version: stable - name: install deps @@ -23,16 +23,16 @@ jobs: sudo apt -q install libseccomp-dev - uses: golangci/golangci-lint-action@v9 with: - version: v2.11 + version: v2.12 codespell: runs-on: ubuntu-24.04 steps: - - uses: actions/checkout@v6 + - uses: actions/checkout@v7 - name: install deps # Version of codespell bundled with Ubuntu will become old, so use pip. # OTOH, we want to pin it to specific version to avoid breaking CI. - run: pip install --break-system-packages codespell==v2.4.2 + run: pip install --break-system-packages codespell==v2.4.3 - name: run codespell run: codespell diff --git a/Makefile b/Makefile index 530f5b4..b893a48 100644 --- a/Makefile +++ b/Makefile @@ -1,22 +1,8 @@ -# libseccomp-golang +.PHONY: all +all: check -.PHONY: all check check-build check-syntax fix-syntax vet test lint - -all: check-build - -check: lint test - -check-build: - go build - -check-syntax: - gofmt -d . - -fix-syntax: - gofmt -w . - -vet: - go vet -v ./... +.PHONY: check +check: lint build test # Previous bugs have made the tests freeze until the timeout. Golang default # timeout for tests is 10 minutes, which is too long, considering current tests @@ -24,8 +10,14 @@ vet: # be noticed earlier in the CI. TEST_TIMEOUT=10s +.PHONY: test test: go test -v -timeout $(TEST_TIMEOUT) +.PHONY: lint lint: - golangci-lint run . + golangci-lint run + +.PHONY: build +build: + go build diff --git a/doc/admin/RELEASE_PROCESS.md b/doc/admin/RELEASE_PROCESS.md index 3fc35e3..3180c4d 100644 --- a/doc/admin/RELEASE_PROCESS.md +++ b/doc/admin/RELEASE_PROCESS.md @@ -9,14 +9,14 @@ libseccomp-golang release. * https://github.com/seccomp/libseccomp-golang/milestones -#### 2. Verify that the syntax/style meets the guidelines +#### 2. Verify that the syntax/style meets the guidelines, and the tests run without error - % make check-syntax + % make check -#### 3. Verify that the bundled tests run without error +#### 3. Verify that CI is passing - % make vet - % make check +Open the following URL and check that latest CI runs are green: +https://github.com/seccomp/libseccomp-golang/actions?query=event%3Apush #### 4. If any problems were found up to this point that resulted in code changes, restart the process