Skip to content

Surface remote stderr on SSH handshake failure; add EC2 test screenshots #40

Surface remote stderr on SSH handshake failure; add EC2 test screenshots

Surface remote stderr on SSH handshake failure; add EC2 test screenshots #40

Workflow file for this run

name: CI
on:
push:
branches:
- main
pull_request:
permissions:
contents: read
jobs:
build:
name: build & vet
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@v6
- uses: actions/setup-go@v6
with:
go-version-file: go.mod
- name: go build
run: go build ./...
- name: go vet
run: go vet ./...
lint:
name: golangci-lint
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@v6
- uses: actions/setup-go@v6
with:
go-version-file: go.mod
- uses: golangci/golangci-lint-action@v9
with:
version: v2.12
test:
name: test (${{ matrix.os }})
strategy:
fail-fast: false
matrix:
os: [ubuntu-latest, windows-latest]
runs-on: ${{ matrix.os }}
steps:
- uses: actions/checkout@v6
- uses: actions/setup-go@v6
with:
go-version-file: go.mod
# Real-rsync comparison tests (internal/cli/rsync_compare_test.go)
# skip gracefully without a real rsync binary on PATH - the same
# established pattern this project's SSH tests already use for an
# environment-dependent capability - but leaving that skip as the
# *only* thing CI ever exercises would mean those tests never
# actually run for real anywhere. Installing rsync here, on the
# Linux leg only, guarantees they get a genuine execution on at
# least one platform; windows-latest has no equivalent easy
# install, so it continues to exercise (and prove) the graceful
# skip path instead, exactly as a Windows dev machine without
# rsync already does locally.
- name: install rsync (Linux only, for real-rsync comparison tests)
if: runner.os == 'Linux'
run: sudo apt-get update && sudo apt-get install -y rsync
# -race requires cgo (it links a C-based runtime), which is
# reliably available out of the box on ubuntu-latest but not
# something this project can verify is equally well-supported on
# windows-latest's own default toolchain without access to a real
# GitHub Actions runner to test against - so -race runs where it's
# known-good (Linux), and windows-latest still gets a full,
# real, native (not cross-compiled) test run without it. This
# isn't just checkbox coverage: the first real CI run of this leg
# caught a genuine deadlock in syncLocal (internal/cli/sync.go) -
# a receiver failure partway through a sync left the sender
# goroutine parked forever reading a reply that would never come,
# timing out the whole test binary after 10 minutes. The bug ran
# fine every time on Windows without -race (the race window never
# opened), which is exactly why relying on local, non-race runs
# alone would never have caught it.
- name: go test -race (Linux)
if: runner.os == 'Linux'
run: go test -race -timeout 10m ./...
- name: go test (Windows)
if: runner.os != 'Linux'
run: go test -timeout 10m ./...
fuzz:
name: fuzz
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@v6
- uses: actions/setup-go@v6
with:
go-version-file: go.mod
# `go test ./...` alone only ever replays each Fuzz function's seed
# corpus as ordinary subtests - it does not actually fuzz anything
# (verified locally: a 10s -fuzz run finds thousands of new
# "interesting" corpus entries per target that a seed-only run
# never would). Each target gets its own explicit step, for a
# real, bounded fuzzing burst - not just existing, unexercised, in
# the source tree - and so a failure clearly names which target
# found it rather than a single opaque combined step.
- name: FuzzWeakChecksumRoll
run: go test ./internal/sync/... -run '^$' -fuzz '^FuzzWeakChecksumRoll$' -fuzztime 15s
- name: FuzzRoundTripDelta
run: go test ./internal/sync/... -run '^$' -fuzz '^FuzzRoundTripDelta$' -fuzztime 15s
- name: FuzzCompileAndMatch
run: go test ./internal/sync/... -run '^$' -fuzz '^FuzzCompileAndMatch$' -fuzztime 15s
- name: FuzzReadGreeting
run: go test ./internal/daemon/... -run '^$' -fuzz '^FuzzReadGreeting$' -fuzztime 15s
- name: FuzzReadLine
run: go test ./internal/daemon/... -run '^$' -fuzz '^FuzzReadLine$' -fuzztime 15s
- name: FuzzReadFrame
run: go test ./internal/transport/... -run '^$' -fuzz '^FuzzReadFrame$' -fuzztime 15s
vulncheck:
name: govulncheck
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@v6
- uses: actions/setup-go@v6
with:
go-version-file: go.mod
- uses: golang/govulncheck-action@v1