From 8bbeca327903c3615f64f4e078bb8708a672a4bd Mon Sep 17 00:00:00 2001 From: Kir Kolyshkin Date: Fri, 17 Jul 2026 12:04:13 -0700 Subject: [PATCH 1/7] ci: bump libseccomp 2.6.0 -> 2.6.1 Signed-off-by: Kir Kolyshkin --- .github/workflows/test.yml | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/.github/workflows/test.yml b/.github/workflows/test.yml index efae350..f1e78ed 100644 --- a/.github/workflows/test.yml +++ b/.github/workflows/test.yml @@ -14,7 +14,7 @@ jobs: fail-fast: false matrix: go-version: [1.19.x, 1.25.x, 1.26.x] - libseccomp: ["v2.3.3", "v2.4.4", "v2.5.6", "v2.6.0", "HEAD"] + libseccomp: ["v2.3.3", "v2.4.4", "v2.5.6", "v2.6.1", "HEAD"] os: [ubuntu-24.04, ubuntu-24.04-arm] runs-on: ${{ matrix.os }} From 0c41a72b7896501c34fab0987fc444fc2545ac17 Mon Sep 17 00:00:00 2001 From: Kir Kolyshkin Date: Fri, 17 Jul 2026 12:05:11 -0700 Subject: [PATCH 2/7] ci: add ubuntu-26.04 to the matrix Signed-off-by: Kir Kolyshkin --- .github/workflows/test.yml | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/.github/workflows/test.yml b/.github/workflows/test.yml index f1e78ed..9103b56 100644 --- a/.github/workflows/test.yml +++ b/.github/workflows/test.yml @@ -15,7 +15,7 @@ jobs: matrix: go-version: [1.19.x, 1.25.x, 1.26.x] libseccomp: ["v2.3.3", "v2.4.4", "v2.5.6", "v2.6.1", "HEAD"] - os: [ubuntu-24.04, ubuntu-24.04-arm] + os: [ubuntu-24.04, ubuntu-24.04-arm, ubuntu-26.04, ubuntu-26.04-arm] runs-on: ${{ matrix.os }} From 3b1ed777456e646d295c9edaaecd767a431a8c04 Mon Sep 17 00:00:00 2001 From: Kir Kolyshkin Date: Fri, 17 Jul 2026 12:12:11 -0700 Subject: [PATCH 3/7] ci: bump actions/checkout, actions/setup-go to v7 Signed-off-by: Kir Kolyshkin --- .github/workflows/test.yml | 4 ++-- .github/workflows/validate.yml | 6 +++--- 2 files changed, 5 insertions(+), 5 deletions(-) diff --git a/.github/workflows/test.yml b/.github/workflows/test.yml index 9103b56..499864d 100644 --- a/.github/workflows/test.yml +++ b/.github/workflows/test.yml @@ -22,7 +22,7 @@ jobs: steps: - name: checkout - uses: actions/checkout@v6 + uses: actions/checkout@v7 - name: build libseccomp ${{ matrix.libseccomp }} run: | @@ -66,7 +66,7 @@ jobs: echo "_EXPECTED_LIBSECCOMP_VERSION=$VER" >> $GITHUB_ENV - name: install go ${{ matrix.go-version }} - uses: actions/setup-go@v6 + uses: actions/setup-go@v7 with: go-version: ${{ matrix.go-version }} # Add libseccomp.pc path so that setup-go adds this file hash to cache key. diff --git a/.github/workflows/validate.yml b/.github/workflows/validate.yml index 10987c9..3cfc79b 100644 --- a/.github/workflows/validate.yml +++ b/.github/workflows/validate.yml @@ -13,8 +13,8 @@ jobs: lint: runs-on: ubuntu-24.04 steps: - - uses: actions/checkout@v6 - - uses: actions/setup-go@v6 + - uses: actions/checkout@v7 + - uses: actions/setup-go@v7 with: go-version: stable - name: install deps @@ -28,7 +28,7 @@ jobs: codespell: runs-on: ubuntu-24.04 steps: - - uses: actions/checkout@v6 + - uses: actions/checkout@v7 - name: install deps # Version of codespell bundled with Ubuntu will become old, so use pip. # OTOH, we want to pin it to specific version to avoid breaking CI. From a888f068a42367c0f0fa0de492cda23bd10b49b7 Mon Sep 17 00:00:00 2001 From: Kir Kolyshkin Date: Fri, 17 Jul 2026 12:13:05 -0700 Subject: [PATCH 4/7] ci: bump golangci-lint to v2.12 Signed-off-by: Kir Kolyshkin --- .github/workflows/validate.yml | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/.github/workflows/validate.yml b/.github/workflows/validate.yml index 3cfc79b..17252b6 100644 --- a/.github/workflows/validate.yml +++ b/.github/workflows/validate.yml @@ -23,7 +23,7 @@ jobs: sudo apt -q install libseccomp-dev - uses: golangci/golangci-lint-action@v9 with: - version: v2.11 + version: v2.12 codespell: runs-on: ubuntu-24.04 From c556bab8a7710cc4ff49f3c781f100921d66a3b9 Mon Sep 17 00:00:00 2001 From: Kir Kolyshkin Date: Fri, 17 Jul 2026 12:13:57 -0700 Subject: [PATCH 5/7] ci: bump codespell to v2.4.3 Signed-off-by: Kir Kolyshkin --- .github/workflows/validate.yml | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/.github/workflows/validate.yml b/.github/workflows/validate.yml index 17252b6..066b7ab 100644 --- a/.github/workflows/validate.yml +++ b/.github/workflows/validate.yml @@ -32,7 +32,7 @@ jobs: - name: install deps # Version of codespell bundled with Ubuntu will become old, so use pip. # OTOH, we want to pin it to specific version to avoid breaking CI. - run: pip install --break-system-packages codespell==v2.4.2 + run: pip install --break-system-packages codespell==v2.4.3 - name: run codespell run: codespell From 89e62ee7500038f6825ef11ceca1cc6b7b4efb09 Mon Sep 17 00:00:00 2001 From: Kir Kolyshkin Date: Mon, 20 Jul 2026 17:05:47 -0700 Subject: [PATCH 6/7] ci: install libseccomp from a release tarball ... instead of git clone && git checkout. Signed-off-by: Kir Kolyshkin --- .github/workflows/test.yml | 49 ++++++++++++++++++++++++++------------ 1 file changed, 34 insertions(+), 15 deletions(-) diff --git a/.github/workflows/test.yml b/.github/workflows/test.yml index 499864d..b90e3e2 100644 --- a/.github/workflows/test.yml +++ b/.github/workflows/test.yml @@ -25,6 +25,12 @@ jobs: uses: actions/checkout@v7 - name: build libseccomp ${{ matrix.libseccomp }} + env: + # sha256 checksums for libseccomp release tarballs. + SHA256_2_3_3: 7fc28f4294cc72e61c529bedf97e705c3acf9c479a8f1a3028d4cd2ca9f3b155 + SHA256_2_4_4: 4e79738d1ef3c9b7ca9769f1f8b8d84fc17143c2c1c432e53b9c64787e0ff3eb + SHA256_2_5_6: 04c37d72965dce218a0c94519b056e1775cf786b5260ee2b7992956c4ee38633 + SHA256_2_6_1: 501f66c667225d53791b97e1d7cf85ab764c297d04881f60f38f451c4b0ee1be run: | set -x sudo apt -qq update @@ -33,25 +39,38 @@ jobs: PREFIX="$(pwd)/seccomp" LIBDIR="$PREFIX/lib" - git clone https://github.com/seccomp/libseccomp - cd libseccomp - git checkout ${{ matrix.libseccomp }} - # In main branch, configure.ac sets libseccomp version to 0.0.0, which - # results in error when compiling libseccomp-golang. While 0.0.0 is - # there for a reason, here we need to build and test against HEAD, so - # set it to a suitable value. - # - # Version 9.9.9 is used because: - # - version >= current is needed; - # - chances are good such version won't ever exist; - # - it is easy to spot in tests output; - # - the LIBFILE pattern below expects single digits. VER="${{ matrix.libseccomp }}" - if [ "$VER" == "HEAD" ]; then + if [[ "$VER" == v* ]]; then + # A specific release: fetch and verify the release tarball + # instead of cloning the whole repo. + mkdir libseccomp + cd libseccomp + VER="${VER#v}" + TAR="libseccomp-$VER.tar.gz" + CKSUM_VAR="SHA256_${VER//./_}" + curl -fsSL --remote-name "https://github.com/seccomp/libseccomp/releases/download/v$VER/$TAR" + sha256sum --strict --check - <<<"${!CKSUM_VAR} *$TAR" + tar --strip-components=1 -xzf "$TAR" + rm -f "$TAR" + else + # Any other git tag/branch/sha: clone and build from the repo. + git clone https://github.com/seccomp/libseccomp + cd libseccomp + git checkout $VER + # In main branch, configure.ac sets libseccomp version to 0.0.0, which + # results in error when compiling libseccomp-golang. While 0.0.0 is + # there for a reason, here we need to build and test against HEAD, so + # set it to a suitable value. + # + # Version 9.9.9 is used because: + # - version >= current is needed; + # - chances are good such version won't ever exist; + # - it is easy to spot in tests output; + # - the LIBFILE pattern below expects single digits. VER=9.9.9 sed -i "/^AC_INIT(/s/0\.0\.0/$VER/" configure.ac + ./autogen.sh fi - ./autogen.sh ./configure --prefix="$PREFIX" --libdir="$LIBDIR" make sudo make install From 12d0159dae40d73f2ce7d1305e7e21a24c4a02db Mon Sep 17 00:00:00 2001 From: Kir Kolyshkin Date: Fri, 17 Jul 2026 12:55:38 -0700 Subject: [PATCH 7/7] Makefile: simplify Remove gofmt and go vet since those are obsoleted by golangci-lint (which includes govet linter and gofumpt formatter). Use per-rule .PHONY marks to make sure we don't miss any. Fix doc/admin/RELEASE_PROCESS.md accordingly, and add a step to check the actual GitHub CI for being green. Signed-off-by: Kir Kolyshkin --- .github/workflows/test.yml | 2 +- Makefile | 30 +++++++++++------------------- doc/admin/RELEASE_PROCESS.md | 10 +++++----- 3 files changed, 17 insertions(+), 25 deletions(-) diff --git a/.github/workflows/test.yml b/.github/workflows/test.yml index b90e3e2..77973da 100644 --- a/.github/workflows/test.yml +++ b/.github/workflows/test.yml @@ -96,7 +96,7 @@ jobs: - name: build - run: make check-build + run: make build - name: test run: make test diff --git a/Makefile b/Makefile index 530f5b4..b893a48 100644 --- a/Makefile +++ b/Makefile @@ -1,22 +1,8 @@ -# libseccomp-golang +.PHONY: all +all: check -.PHONY: all check check-build check-syntax fix-syntax vet test lint - -all: check-build - -check: lint test - -check-build: - go build - -check-syntax: - gofmt -d . - -fix-syntax: - gofmt -w . - -vet: - go vet -v ./... +.PHONY: check +check: lint build test # Previous bugs have made the tests freeze until the timeout. Golang default # timeout for tests is 10 minutes, which is too long, considering current tests @@ -24,8 +10,14 @@ vet: # be noticed earlier in the CI. TEST_TIMEOUT=10s +.PHONY: test test: go test -v -timeout $(TEST_TIMEOUT) +.PHONY: lint lint: - golangci-lint run . + golangci-lint run + +.PHONY: build +build: + go build diff --git a/doc/admin/RELEASE_PROCESS.md b/doc/admin/RELEASE_PROCESS.md index 3fc35e3..3180c4d 100644 --- a/doc/admin/RELEASE_PROCESS.md +++ b/doc/admin/RELEASE_PROCESS.md @@ -9,14 +9,14 @@ libseccomp-golang release. * https://github.com/seccomp/libseccomp-golang/milestones -#### 2. Verify that the syntax/style meets the guidelines +#### 2. Verify that the syntax/style meets the guidelines, and the tests run without error - % make check-syntax + % make check -#### 3. Verify that the bundled tests run without error +#### 3. Verify that CI is passing - % make vet - % make check +Open the following URL and check that latest CI runs are green: +https://github.com/seccomp/libseccomp-golang/actions?query=event%3Apush #### 4. If any problems were found up to this point that resulted in code changes, restart the process