Skip to content
Closed
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
14 changes: 14 additions & 0 deletions .github/workflows/actions-smoke-test.yml
Original file line number Diff line number Diff line change
@@ -0,0 +1,14 @@
name: actions-smoke-test

on:
push:
pull_request:

permissions:
contents: read

jobs:
hello:
runs-on: ubuntu-latest
steps:
- run: echo "GitHub Actions ran for ${GITHUB_SHA} on ${GITHUB_EVENT_NAME}"
14 changes: 14 additions & 0 deletions .github/workflows/bisect-macos-runner.yml
Original file line number Diff line number Diff line change
@@ -0,0 +1,14 @@
name: bisect-macos-runner

on:
push:
pull_request:

permissions:
contents: read

jobs:
hello:
runs-on: macos-15
steps:
- run: echo "GitHub Actions ran for ${GITHUB_SHA} on ${GITHUB_EVENT_NAME}"
87 changes: 87 additions & 0 deletions .github/workflows/bisect-renamed.yml
Original file line number Diff line number Diff line change
@@ -0,0 +1,87 @@
name: bisect-renamed

on:
push:
pull_request:

permissions:
contents: read

defaults:
run:
shell: bash

jobs:
build:
# TODO: An optimization we can do here is to skip duplicate
# push/pull_request runs on branches created in this repo, e.g.:
#
# if: github.event_name == 'push' || github.event.pull_request.head.repo.full_name != github.repository
#
# But the fetch-gh-artifacts.sh script (which is copied verbatim from
# github.com/oxidecomputer/cockroach) doesn't handle skipped jobs at the
# moment. We should consider fixing both copies of the script.
#
# ---
#
# Use the oldest supported arm64 image to do this build. Building on a newer
# image risks binaries that fail on older versions of macOS.
runs-on: macos-15
# This must stay below the 40 minutes the macos buildomat job waits for this
# run. See the XXX in .github/buildomat/jobs/macos.sh.
timeout-minutes: 35
env:
CARGO_TERM_COLOR: always
CARGO_INCREMENTAL: "0"
# Omicron downloads these binaries onto machines that may lack Homebrew's
# OpenSSL dylibs, so link it statically.
OPENSSL_STATIC: "1"
steps:
- uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
with:
# Build the tip of the PR, not the merge commit GitHub synthesizes, so
# that the artifact matches the buildomat commit.
ref: ${{ github.event.pull_request.head.sha }}
persist-credentials: false
- name: Report toolchain versions
run: |
cargo --version
rustc --version
- name: Find or install Homebrew OpenSSL
run: |
openssl_dir="$(brew --prefix openssl@3)"
if [[ ! -f "${openssl_dir}/lib/libssl.a" ]]; then
brew install openssl@3
fi
echo "OPENSSL_DIR=${openssl_dir}" >> "${GITHUB_ENV}"
- name: Build dpd and swadm
run: cargo build --release --locked --features=tofino_stub --bin dpd --bin swadm
- name: Check binaries
run: |
set -o nounset
for bin in dpd swadm; do
bin_path="target/release/${bin}"

archs="$(lipo -archs "${bin_path}")"
if [[ "${archs}" != "arm64" ]]; then
echo "::error::${bin} was built for '${archs}', expected 'arm64'"
exit 1
fi

linked="$(otool -L "${bin_path}")"
echo "${linked}"
non_system="$(awk 'NR > 1 && $1 !~ /^(\/usr\/lib\/|\/System\/Library\/)/ { print $1 }' <<<"${linked}")"
if [[ -n "${non_system}" ]]; then
echo "::error::${bin} links against non-system libraries that machines downloading it may not have: ${non_system//$'\n'/ }"
exit 1
fi

"${bin_path}" --help >/dev/null
done
- uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1
with:
name: macos-aarch64
path: |
target/release/dpd
target/release/swadm
if-no-files-found: error
87 changes: 87 additions & 0 deletions .github/workflows/bisect-same-name.yml
Original file line number Diff line number Diff line change
@@ -0,0 +1,87 @@
name: build-macos

on:
push:
pull_request:

permissions:
contents: read

defaults:
run:
shell: bash

jobs:
build:
# TODO: An optimization we can do here is to skip duplicate
# push/pull_request runs on branches created in this repo, e.g.:
#
# if: github.event_name == 'push' || github.event.pull_request.head.repo.full_name != github.repository
#
# But the fetch-gh-artifacts.sh script (which is copied verbatim from
# github.com/oxidecomputer/cockroach) doesn't handle skipped jobs at the
# moment. We should consider fixing both copies of the script.
#
# ---
#
# Use the oldest supported arm64 image to do this build. Building on a newer
# image risks binaries that fail on older versions of macOS.
runs-on: macos-15
# This must stay below the 40 minutes the macos buildomat job waits for this
# run. See the XXX in .github/buildomat/jobs/macos.sh.
timeout-minutes: 35
env:
CARGO_TERM_COLOR: always
CARGO_INCREMENTAL: "0"
# Omicron downloads these binaries onto machines that may lack Homebrew's
# OpenSSL dylibs, so link it statically.
OPENSSL_STATIC: "1"
steps:
- uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
with:
# Build the tip of the PR, not the merge commit GitHub synthesizes, so
# that the artifact matches the buildomat commit.
ref: ${{ github.event.pull_request.head.sha }}
persist-credentials: false
- name: Report toolchain versions
run: |
cargo --version
rustc --version
- name: Find or install Homebrew OpenSSL
run: |
openssl_dir="$(brew --prefix openssl@3)"
if [[ ! -f "${openssl_dir}/lib/libssl.a" ]]; then
brew install openssl@3
fi
echo "OPENSSL_DIR=${openssl_dir}" >> "${GITHUB_ENV}"
- name: Build dpd and swadm
run: cargo build --release --locked --features=tofino_stub --bin dpd --bin swadm
- name: Check binaries
run: |
set -o nounset
for bin in dpd swadm; do
bin_path="target/release/${bin}"

archs="$(lipo -archs "${bin_path}")"
if [[ "${archs}" != "arm64" ]]; then
echo "::error::${bin} was built for '${archs}', expected 'arm64'"
exit 1
fi

linked="$(otool -L "${bin_path}")"
echo "${linked}"
non_system="$(awk 'NR > 1 && $1 !~ /^(\/usr\/lib\/|\/System\/Library\/)/ { print $1 }' <<<"${linked}")"
if [[ -n "${non_system}" ]]; then
echo "::error::${bin} links against non-system libraries that machines downloading it may not have: ${non_system//$'\n'/ }"
exit 1
fi

"${bin_path}" --help >/dev/null
done
- uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1
with:
name: macos-aarch64
path: |
target/release/dpd
target/release/swadm
if-no-files-found: error
87 changes: 87 additions & 0 deletions .github/workflows/build-macos.yml
Original file line number Diff line number Diff line change
@@ -0,0 +1,87 @@
name: build-macos

on:
push:
pull_request:

permissions:
contents: read

defaults:
run:
shell: bash

jobs:
build:
# TODO: An optimization we can do here is to skip duplicate
# push/pull_request runs on branches created in this repo, e.g.:
#
# if: github.event_name == 'push' || github.event.pull_request.head.repo.full_name != github.repository
#
# But the fetch-gh-artifacts.sh script (which is copied verbatim from
# github.com/oxidecomputer/cockroach) doesn't handle skipped jobs at the
# moment. We should consider fixing both copies of the script.
#
# ---
#
# Use the oldest supported arm64 image to do this build. Building on a newer
# image risks binaries that fail on older versions of macOS.
runs-on: macos-15
# This must stay below the 40 minutes the macos buildomat job waits for this
# run. See the XXX in .github/buildomat/jobs/macos.sh.
timeout-minutes: 35
env:
CARGO_TERM_COLOR: always
CARGO_INCREMENTAL: "0"
# Omicron downloads these binaries onto machines that may lack Homebrew's
# OpenSSL dylibs, so link it statically.
OPENSSL_STATIC: "1"
steps:
- uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
with:
# Build the tip of the PR, not the merge commit GitHub synthesizes, so
# that the artifact matches the buildomat commit.
ref: ${{ github.event.pull_request.head.sha }}
persist-credentials: false
- name: Report toolchain versions
run: |
cargo --version
rustc --version
- name: Find or install Homebrew OpenSSL
run: |
openssl_dir="$(brew --prefix openssl@3)"
if [[ ! -f "${openssl_dir}/lib/libssl.a" ]]; then
brew install openssl@3
fi
echo "OPENSSL_DIR=${openssl_dir}" >> "${GITHUB_ENV}"
- name: Build dpd and swadm
run: cargo build --release --locked --features=tofino_stub --bin dpd --bin swadm
- name: Check binaries
run: |
set -o nounset
for bin in dpd swadm; do
bin_path="target/release/${bin}"

archs="$(lipo -archs "${bin_path}")"
if [[ "${archs}" != "arm64" ]]; then
echo "::error::${bin} was built for '${archs}', expected 'arm64'"
exit 1
fi

linked="$(otool -L "${bin_path}")"
echo "${linked}"
non_system="$(awk 'NR > 1 && $1 !~ /^(\/usr\/lib\/|\/System\/Library\/)/ { print $1 }' <<<"${linked}")"
if [[ -n "${non_system}" ]]; then
echo "::error::${bin} links against non-system libraries that machines downloading it may not have: ${non_system//$'\n'/ }"
exit 1
fi

"${bin_path}" --help >/dev/null
done
- uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1
with:
name: macos-aarch64
path: |
target/release/dpd
target/release/swadm
if-no-files-found: error
Loading