-
Notifications
You must be signed in to change notification settings - Fork 0
115 lines (109 loc) · 4.89 KB
/
Copy pathci.yml
File metadata and controls
115 lines (109 loc) · 4.89 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
name: CI
# ci: calls sidick/amiga-workflows' build-test.yml, which implements the
# five-verb contract (see that repo's README.md, the document of record) --
# build/test-host/test-target/lint all resolve to Makefile targets of the
# same name (see Makefile's own "Verb contract" comment). Each of those
# jobs is independent (no artifact-passing between them), unlike this
# repo's previous bespoke pipeline (one m68k-build job producing both
# binaries, one host-tests job, one asm-crypto-tests job) -- the m68k
# cross-build now runs more than once per CI run (build and test-target
# each call it), a deliberate tradeoff of standardizing on the shared
# workflow rather than keeping a repo-specific optimization.
#
# The `changes` job stays local (repo-specific path patterns aren't
# something a shared workflow should know about) and its outputs feed
# build-test.yml's run-* inputs directly, preserving the path-based
# skip-on-docs-only-PR behavior. `differential` (opt-in OpenSSL fuzz) and
# `docs-build` (strict MkDocs + AmigaGuide check) stay local jobs too --
# neither fits the five verbs, and the shared workflow has no hook for an
# extra per-project job. `catalog-lint`'s check-catalog now runs as `make
# lint` inside build-test.yml's lint job instead of its own job.
#
# NOTE: branch protection's required status checks reference job names
# directly (e.g. "m68k Amiga build") -- those all changed shape here
# (nested reusable-workflow jobs report as "ci / build" etc). Updated to
# match as part of this same change; see amiga-dev's docs/plan.md Phase 4
# entry for the mapping.
on:
push:
branches: [main]
pull_request:
jobs:
# Decide which jobs are relevant to the files a PR changes. Docs-only PRs
# (README, docs/, AmiAuth.readme, CLAUDE.md, ...) skip the build/test jobs
# entirely. The gated jobs are *required* status checks on main, which is why
# they are skipped via `if:` on a job that still runs (branch protection
# counts a skipped check as satisfied; a workflow filtered out by `paths:`
# would leave the PR blocked on "Expected" forever). Pushes to main always
# run everything. Workflow changes also run everything.
changes:
name: Detect changed paths
runs-on: ubuntu-latest
outputs:
host: ${{ steps.filter.outputs.host }}
core: ${{ steps.filter.outputs.core }}
build: ${{ steps.filter.outputs.build }}
target: ${{ steps.filter.outputs.target }}
docs: ${{ steps.filter.outputs.docs }}
catalog: ${{ steps.filter.outputs.catalog }}
steps:
- uses: actions/checkout@v7
with:
fetch-depth: 0
- id: filter
name: Classify changed files
run: |
if [ "${{ github.event_name }}" != "pull_request" ]; then
for k in host core build target docs catalog; do echo "$k=true" >> "$GITHUB_OUTPUT"; done
exit 0
fi
files=$(git diff --name-only "${{ github.event.pull_request.base.sha }}...HEAD")
echo "Changed files:"; echo "$files"
match() { echo "$files" | grep -qE "$1" && echo true || echo false; }
always='^(Makefile|\.github/workflows/)'
{
echo "host=$(match "$always|^(src/|tests/)")"
echo "core=$(match "$always|^(src/core/|tests/diff/)")"
echo "build=$(match "$always|^src/")"
echo "target=$(match "$always|^(src/|tests/copperline/)")"
echo "docs=$(match "$always|^(userdocs/|mkdocs\.yml|tools/docs2guide\.py|tools/docs-requirements\.txt)")"
echo "catalog=$(match "$always|^(locale/|tools/check_catalog\.py)")"
} >> "$GITHUB_OUTPUT"
ci:
name: ci
needs: changes
uses: sidick/amiga-workflows/.github/workflows/build-test.yml@v1
with:
run-build: ${{ needs.changes.outputs.build == 'true' }}
run-test-host: ${{ needs.changes.outputs.host == 'true' }}
run-test-target: ${{ needs.changes.outputs.target == 'true' }}
run-lint: ${{ needs.changes.outputs.catalog == 'true' }}
secrets:
AMIGA_REAL_ROM_B64: ${{ secrets.AMIGA_REAL_ROM_B64 }}
docs-build:
name: Docs site + AmigaGuide build
runs-on: ubuntu-latest
needs: changes
if: needs.changes.outputs.docs == 'true'
steps:
- uses: actions/checkout@v7
- uses: actions/setup-python@v7
with:
python-version: '3.14'
- name: Install docs toolchain
run: pip install -r tools/docs-requirements.txt
- name: Strict MkDocs build
run: mkdocs build --strict
- name: AmigaGuide conversion
run: make guide
differential:
name: Differential fuzz (vs OpenSSL)
runs-on: ubuntu-latest
needs: changes
if: needs.changes.outputs.core == 'true'
steps:
- uses: actions/checkout@v7
- name: Install OpenSSL headers
run: sudo apt-get update && sudo apt-get install -y libssl-dev pkg-config
- name: Fuzz crypto primitives against OpenSSL
run: make diff DIFF_ITERS=20000