name: CI checks on: push: branches: - main pull_request: branches: - main jobs: check: name: Build with gcc and test runs-on: ubuntu-latest steps: - name: Check out uses: actions/checkout@v1 - name: Install build-dependencies run: sudo ./ci/builddeps.sh - name: Create logs dir run: mkdir test-logs - name: autogen.sh run: NOCONFIGURE=1 ./autogen.sh - name: configure run: | mkdir _build pushd _build ../configure \ --enable-man \ --enable-selinux \ ${NULL+} popd env: CFLAGS: >- -O2 -Wp,-D_FORTIFY_SOURCE=2 -fsanitize=address -fsanitize=undefined - name: make run: make -C _build -j $(getconf _NPROCESSORS_ONLN) V=1 - name: smoke-test run: | set -x ./_build/bwrap --bind / / --tmpfs /tmp true env: ASAN_OPTIONS: detect_leaks=0 - name: check run: | make -C _build -j $(getconf _NPROCESSORS_ONLN) check VERBOSE=1 BWRAP_MUST_WORK=1 env: ASAN_OPTIONS: detect_leaks=0 - name: Collect overall test logs on failure if: failure() run: mv _build/test-suite.log test-logs/ || true - name: Collect individual test logs on cancel if: failure() || cancelled() run: mv _build/tests/*.log test-logs/ || true - name: Upload test logs uses: actions/upload-artifact@v1 if: failure() || cancelled() with: name: test logs path: test-logs - name: install run: | make -C _build install DESTDIR="$(pwd)/DESTDIR" ( cd DESTDIR && find -ls ) - name: distcheck run: | make -C _build -j $(getconf _NPROCESSORS_ONLN) distcheck VERBOSE=1 BWRAP_MUST_WORK=1 clang: name: Build with clang and analyze runs-on: ubuntu-latest strategy: fail-fast: false matrix: language: - cpp steps: - name: Initialize CodeQL uses: github/codeql-action/init@v1 with: languages: ${{ matrix.language }} - name: Check out uses: actions/checkout@v1 - name: Install build-dependencies run: sudo ./ci/builddeps.sh --clang - name: autogen.sh run: NOCONFIGURE=1 ./autogen.sh - name: configure run: ./configure --enable-selinux env: CC: clang CFLAGS: >- -O2 -Werror=unused-variable - name: make run: make -j $(getconf _NPROCESSORS_ONLN) V=1 - name: CodeQL analysis uses: github/codeql-action/analyze@v1