From a843357c8f85bb6ef811aafc480cf8b066d0a1ca Mon Sep 17 00:00:00 2001 From: Rain Date: Tue, 6 Oct 2026 17:11:31 -0700 Subject: [PATCH] [DNM] minimal workflow to test whether GitHub Actions fires in this repo Try to figure out what's going on with #387. --- .github/workflows/actions-smoke-test.yml | 14 ++++ .github/workflows/bisect-macos-runner.yml | 14 ++++ .github/workflows/bisect-renamed.yml | 87 +++++++++++++++++++++++ .github/workflows/bisect-same-name.yml | 87 +++++++++++++++++++++++ .github/workflows/build-macos.yml | 87 +++++++++++++++++++++++ 5 files changed, 289 insertions(+) create mode 100644 .github/workflows/actions-smoke-test.yml create mode 100644 .github/workflows/bisect-macos-runner.yml create mode 100644 .github/workflows/bisect-renamed.yml create mode 100644 .github/workflows/bisect-same-name.yml create mode 100644 .github/workflows/build-macos.yml diff --git a/.github/workflows/actions-smoke-test.yml b/.github/workflows/actions-smoke-test.yml new file mode 100644 index 00000000..39cbc925 --- /dev/null +++ b/.github/workflows/actions-smoke-test.yml @@ -0,0 +1,14 @@ +name: actions-smoke-test + +on: + push: + pull_request: + +permissions: + contents: read + +jobs: + hello: + runs-on: ubuntu-latest + steps: + - run: echo "GitHub Actions ran for ${GITHUB_SHA} on ${GITHUB_EVENT_NAME}" diff --git a/.github/workflows/bisect-macos-runner.yml b/.github/workflows/bisect-macos-runner.yml new file mode 100644 index 00000000..0b5c761e --- /dev/null +++ b/.github/workflows/bisect-macos-runner.yml @@ -0,0 +1,14 @@ +name: bisect-macos-runner + +on: + push: + pull_request: + +permissions: + contents: read + +jobs: + hello: + runs-on: macos-15 + steps: + - run: echo "GitHub Actions ran for ${GITHUB_SHA} on ${GITHUB_EVENT_NAME}" diff --git a/.github/workflows/bisect-renamed.yml b/.github/workflows/bisect-renamed.yml new file mode 100644 index 00000000..e6c2b3bb --- /dev/null +++ b/.github/workflows/bisect-renamed.yml @@ -0,0 +1,87 @@ +name: bisect-renamed + +on: + push: + pull_request: + +permissions: + contents: read + +defaults: + run: + shell: bash + +jobs: + build: + # TODO: An optimization we can do here is to skip duplicate + # push/pull_request runs on branches created in this repo, e.g.: + # + # if: github.event_name == 'push' || github.event.pull_request.head.repo.full_name != github.repository + # + # But the fetch-gh-artifacts.sh script (which is copied verbatim from + # github.com/oxidecomputer/cockroach) doesn't handle skipped jobs at the + # moment. We should consider fixing both copies of the script. + # + # --- + # + # Use the oldest supported arm64 image to do this build. Building on a newer + # image risks binaries that fail on older versions of macOS. + runs-on: macos-15 + # This must stay below the 40 minutes the macos buildomat job waits for this + # run. See the XXX in .github/buildomat/jobs/macos.sh. + timeout-minutes: 35 + env: + CARGO_TERM_COLOR: always + CARGO_INCREMENTAL: "0" + # Omicron downloads these binaries onto machines that may lack Homebrew's + # OpenSSL dylibs, so link it statically. + OPENSSL_STATIC: "1" + steps: + - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 + with: + # Build the tip of the PR, not the merge commit GitHub synthesizes, so + # that the artifact matches the buildomat commit. + ref: ${{ github.event.pull_request.head.sha }} + persist-credentials: false + - name: Report toolchain versions + run: | + cargo --version + rustc --version + - name: Find or install Homebrew OpenSSL + run: | + openssl_dir="$(brew --prefix openssl@3)" + if [[ ! -f "${openssl_dir}/lib/libssl.a" ]]; then + brew install openssl@3 + fi + echo "OPENSSL_DIR=${openssl_dir}" >> "${GITHUB_ENV}" + - name: Build dpd and swadm + run: cargo build --release --locked --features=tofino_stub --bin dpd --bin swadm + - name: Check binaries + run: | + set -o nounset + for bin in dpd swadm; do + bin_path="target/release/${bin}" + + archs="$(lipo -archs "${bin_path}")" + if [[ "${archs}" != "arm64" ]]; then + echo "::error::${bin} was built for '${archs}', expected 'arm64'" + exit 1 + fi + + linked="$(otool -L "${bin_path}")" + echo "${linked}" + non_system="$(awk 'NR > 1 && $1 !~ /^(\/usr\/lib\/|\/System\/Library\/)/ { print $1 }' <<<"${linked}")" + if [[ -n "${non_system}" ]]; then + echo "::error::${bin} links against non-system libraries that machines downloading it may not have: ${non_system//$'\n'/ }" + exit 1 + fi + + "${bin_path}" --help >/dev/null + done + - uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1 + with: + name: macos-aarch64 + path: | + target/release/dpd + target/release/swadm + if-no-files-found: error diff --git a/.github/workflows/bisect-same-name.yml b/.github/workflows/bisect-same-name.yml new file mode 100644 index 00000000..f74d48a7 --- /dev/null +++ b/.github/workflows/bisect-same-name.yml @@ -0,0 +1,87 @@ +name: build-macos + +on: + push: + pull_request: + +permissions: + contents: read + +defaults: + run: + shell: bash + +jobs: + build: + # TODO: An optimization we can do here is to skip duplicate + # push/pull_request runs on branches created in this repo, e.g.: + # + # if: github.event_name == 'push' || github.event.pull_request.head.repo.full_name != github.repository + # + # But the fetch-gh-artifacts.sh script (which is copied verbatim from + # github.com/oxidecomputer/cockroach) doesn't handle skipped jobs at the + # moment. We should consider fixing both copies of the script. + # + # --- + # + # Use the oldest supported arm64 image to do this build. Building on a newer + # image risks binaries that fail on older versions of macOS. + runs-on: macos-15 + # This must stay below the 40 minutes the macos buildomat job waits for this + # run. See the XXX in .github/buildomat/jobs/macos.sh. + timeout-minutes: 35 + env: + CARGO_TERM_COLOR: always + CARGO_INCREMENTAL: "0" + # Omicron downloads these binaries onto machines that may lack Homebrew's + # OpenSSL dylibs, so link it statically. + OPENSSL_STATIC: "1" + steps: + - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 + with: + # Build the tip of the PR, not the merge commit GitHub synthesizes, so + # that the artifact matches the buildomat commit. + ref: ${{ github.event.pull_request.head.sha }} + persist-credentials: false + - name: Report toolchain versions + run: | + cargo --version + rustc --version + - name: Find or install Homebrew OpenSSL + run: | + openssl_dir="$(brew --prefix openssl@3)" + if [[ ! -f "${openssl_dir}/lib/libssl.a" ]]; then + brew install openssl@3 + fi + echo "OPENSSL_DIR=${openssl_dir}" >> "${GITHUB_ENV}" + - name: Build dpd and swadm + run: cargo build --release --locked --features=tofino_stub --bin dpd --bin swadm + - name: Check binaries + run: | + set -o nounset + for bin in dpd swadm; do + bin_path="target/release/${bin}" + + archs="$(lipo -archs "${bin_path}")" + if [[ "${archs}" != "arm64" ]]; then + echo "::error::${bin} was built for '${archs}', expected 'arm64'" + exit 1 + fi + + linked="$(otool -L "${bin_path}")" + echo "${linked}" + non_system="$(awk 'NR > 1 && $1 !~ /^(\/usr\/lib\/|\/System\/Library\/)/ { print $1 }' <<<"${linked}")" + if [[ -n "${non_system}" ]]; then + echo "::error::${bin} links against non-system libraries that machines downloading it may not have: ${non_system//$'\n'/ }" + exit 1 + fi + + "${bin_path}" --help >/dev/null + done + - uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1 + with: + name: macos-aarch64 + path: | + target/release/dpd + target/release/swadm + if-no-files-found: error diff --git a/.github/workflows/build-macos.yml b/.github/workflows/build-macos.yml new file mode 100644 index 00000000..f74d48a7 --- /dev/null +++ b/.github/workflows/build-macos.yml @@ -0,0 +1,87 @@ +name: build-macos + +on: + push: + pull_request: + +permissions: + contents: read + +defaults: + run: + shell: bash + +jobs: + build: + # TODO: An optimization we can do here is to skip duplicate + # push/pull_request runs on branches created in this repo, e.g.: + # + # if: github.event_name == 'push' || github.event.pull_request.head.repo.full_name != github.repository + # + # But the fetch-gh-artifacts.sh script (which is copied verbatim from + # github.com/oxidecomputer/cockroach) doesn't handle skipped jobs at the + # moment. We should consider fixing both copies of the script. + # + # --- + # + # Use the oldest supported arm64 image to do this build. Building on a newer + # image risks binaries that fail on older versions of macOS. + runs-on: macos-15 + # This must stay below the 40 minutes the macos buildomat job waits for this + # run. See the XXX in .github/buildomat/jobs/macos.sh. + timeout-minutes: 35 + env: + CARGO_TERM_COLOR: always + CARGO_INCREMENTAL: "0" + # Omicron downloads these binaries onto machines that may lack Homebrew's + # OpenSSL dylibs, so link it statically. + OPENSSL_STATIC: "1" + steps: + - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 + with: + # Build the tip of the PR, not the merge commit GitHub synthesizes, so + # that the artifact matches the buildomat commit. + ref: ${{ github.event.pull_request.head.sha }} + persist-credentials: false + - name: Report toolchain versions + run: | + cargo --version + rustc --version + - name: Find or install Homebrew OpenSSL + run: | + openssl_dir="$(brew --prefix openssl@3)" + if [[ ! -f "${openssl_dir}/lib/libssl.a" ]]; then + brew install openssl@3 + fi + echo "OPENSSL_DIR=${openssl_dir}" >> "${GITHUB_ENV}" + - name: Build dpd and swadm + run: cargo build --release --locked --features=tofino_stub --bin dpd --bin swadm + - name: Check binaries + run: | + set -o nounset + for bin in dpd swadm; do + bin_path="target/release/${bin}" + + archs="$(lipo -archs "${bin_path}")" + if [[ "${archs}" != "arm64" ]]; then + echo "::error::${bin} was built for '${archs}', expected 'arm64'" + exit 1 + fi + + linked="$(otool -L "${bin_path}")" + echo "${linked}" + non_system="$(awk 'NR > 1 && $1 !~ /^(\/usr\/lib\/|\/System\/Library\/)/ { print $1 }' <<<"${linked}")" + if [[ -n "${non_system}" ]]; then + echo "::error::${bin} links against non-system libraries that machines downloading it may not have: ${non_system//$'\n'/ }" + exit 1 + fi + + "${bin_path}" --help >/dev/null + done + - uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1 + with: + name: macos-aarch64 + path: | + target/release/dpd + target/release/swadm + if-no-files-found: error