-
Notifications
You must be signed in to change notification settings - Fork 0
141 lines (116 loc) · 4.72 KB
/
Copy pathci.yaml
File metadata and controls
141 lines (116 loc) · 4.72 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
130
131
132
133
134
135
136
137
138
139
140
141
name: CI
on:
push:
branches:
- main
pull_request:
permissions:
contents: read
jobs:
build:
name: build & vet
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@v6
- uses: actions/setup-go@v6
with:
go-version-file: go.mod
- name: go build
run: go build ./...
- name: go vet
run: go vet ./...
lint:
name: golangci-lint
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@v6
- uses: actions/setup-go@v6
with:
go-version-file: go.mod
- uses: golangci/golangci-lint-action@v9
with:
version: v2.12
test:
name: test (${{ matrix.os }})
strategy:
fail-fast: false
matrix:
os: [ubuntu-latest, windows-latest]
runs-on: ${{ matrix.os }}
steps:
- uses: actions/checkout@v6
- uses: actions/setup-go@v6
with:
go-version-file: go.mod
# Real-rsync comparison tests (internal/cli/rsync_compare_test.go)
# skip gracefully without a real rsync binary on PATH - the same
# established pattern this project's SSH tests already use for an
# environment-dependent capability - but leaving that skip as the
# *only* thing CI ever exercises would mean those tests never
# actually run for real anywhere. Installing rsync here, on the
# Linux leg only, guarantees they get a genuine execution on at
# least one platform; windows-latest has no equivalent easy
# install, so it continues to exercise (and prove) the graceful
# skip path instead, exactly as a Windows dev machine without
# rsync already does locally.
- name: install rsync (Linux only, for real-rsync comparison tests)
if: runner.os == 'Linux'
run: sudo apt-get update && sudo apt-get install -y rsync
# -race requires cgo (it links a C-based runtime), which is
# reliably available out of the box on ubuntu-latest but not
# something this project can verify is equally well-supported on
# windows-latest's own default toolchain without access to a real
# GitHub Actions runner to test against - so -race runs where it's
# known-good (Linux), and windows-latest still gets a full,
# real, native (not cross-compiled) test run without it. This
# isn't just checkbox coverage: the first real CI run of this leg
# caught a genuine deadlock in syncLocal (internal/cli/sync.go) -
# a receiver failure partway through a sync left the sender
# goroutine parked forever reading a reply that would never come,
# timing out the whole test binary after 10 minutes. The bug ran
# fine every time on Windows without -race (the race window never
# opened), which is exactly why relying on local, non-race runs
# alone would never have caught it.
- name: go test -race (Linux)
if: runner.os == 'Linux'
run: go test -race -timeout 10m ./...
- name: go test (Windows)
if: runner.os != 'Linux'
run: go test -timeout 10m ./...
fuzz:
name: fuzz
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@v6
- uses: actions/setup-go@v6
with:
go-version-file: go.mod
# `go test ./...` alone only ever replays each Fuzz function's seed
# corpus as ordinary subtests - it does not actually fuzz anything
# (verified locally: a 10s -fuzz run finds thousands of new
# "interesting" corpus entries per target that a seed-only run
# never would). Each target gets its own explicit step, for a
# real, bounded fuzzing burst - not just existing, unexercised, in
# the source tree - and so a failure clearly names which target
# found it rather than a single opaque combined step.
- name: FuzzWeakChecksumRoll
run: go test ./internal/sync/... -run '^$' -fuzz '^FuzzWeakChecksumRoll$' -fuzztime 15s
- name: FuzzRoundTripDelta
run: go test ./internal/sync/... -run '^$' -fuzz '^FuzzRoundTripDelta$' -fuzztime 15s
- name: FuzzCompileAndMatch
run: go test ./internal/sync/... -run '^$' -fuzz '^FuzzCompileAndMatch$' -fuzztime 15s
- name: FuzzReadGreeting
run: go test ./internal/daemon/... -run '^$' -fuzz '^FuzzReadGreeting$' -fuzztime 15s
- name: FuzzReadLine
run: go test ./internal/daemon/... -run '^$' -fuzz '^FuzzReadLine$' -fuzztime 15s
- name: FuzzReadFrame
run: go test ./internal/transport/... -run '^$' -fuzz '^FuzzReadFrame$' -fuzztime 15s
vulncheck:
name: govulncheck
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@v6
- uses: actions/setup-go@v6
with:
go-version-file: go.mod
- uses: golang/govulncheck-action@v1