aboutsummaryrefslogtreecommitdiffhomepage
path: root/internal/workflows/step.go
blob: 83d9c5f31cb60dcacc9df0b74e71089edc24cd47 (plain)
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
//go:build workflows

package main

import "strings"

// fixup is a step to work around a Podman regression introduced by a bad
// container escape mitigation.
var fixup = Step{
	Name: "Fix container filesystem",
	Run:  "rm /var/run && ln -sf ../run /var",
}

// checkout is the standard actions/checkout step.
var checkout = Step{Name: "Checkout", Uses: "actions/checkout@v4"}

// toolchain is a step for setting up the Go toolchain.
var toolchain = Step{
	Name: "Set up Go toolchain",
	Uses: "actions/setup-go@v6",

	With: []KV[any]{
		{"go-version-file", "go.mod"},
	},
}

// newUploadArtifact returns an actions/upload-artifact step uploading
// everything in the result directory as the specified name.
func newUploadArtifact(display, name string) Step {
	return Step{
		Name: "Upload " + display,
		Uses: "actions/upload-artifact@v3",

		With: Map[any]{
			{"name", name},
			{"path", "result/*"},

			{"retention-days", 1},
		},
	}
}

// newCIRequest returns a step for requesting a mbf CI task.
func newCIRequest(display, name, id string) Step {
	return Step{
		Name: "Request " + display,
		ID:   id,
		Run: "HAKUREI_REV=\"$(git rev-parse --short HEAD)\" && " +
			"/rosa/bin/mbf ci " + name + " " +
			". \"$(cat cmd/dist/VERSION)-$HAKUREI_REV\" && " +
			"echo \"rev=$HAKUREI_REV\" >> \"$GITHUB_OUTPUT\"",
	}
}

// install is a step to unpack and deploy a hakurei distribution created by a
// step with identifier dist.
var install = Step{
	Name: "Install hakurei",
	Run: "HAKUREI_VERSION=\"$(cat cmd/dist/VERSION)-${{ steps.dist.outputs.rev }}\" && " +
		"tar xf result/hakurei-$HAKUREI_VERSION*-amd64.tar.gz && " +
		"./hakurei-$HAKUREI_VERSION*-amd64/install.sh && " +
		"sudo -u ubuntu hakurei version && " +
		"echo 'Defaults closefrom_override' > " +
		"/etc/sudoers.d/closefrom_override && " +
		"mkdir /var/empty",
}

// newTestsuite returns a step for running an integration test suite.
func newTestsuite(name, prefix string) Step {
	return Step{
		Name: "Compile and run test suite",
		Run: prefix + "rm -rf result && " +
			"go run -tags=testsuite ./test/" + name,
	}
}

// newPackages returns a job for installing the specified packages with
// best-effort caching. Package names must not contain spaces.
func newPackages(rev int, packages ...string) Step {
	return Step{
		Name: "Install packages",
		Uses: "awalsh128/cache-apt-pkgs-action@v1",
		With: []KV[any]{
			{"packages", strings.Join(packages, " ")},
			{"version", rev},
			{"execute_install_scripts", true},
		},
	}
}

// newNixOSTest returns a step for running the named NixOS test.
func newNixOSTest(name string) Step {
	return Step{
		Name: "Run NixOS test",
		Run: "nix build " +
			"--out-link result " +
			"--print-out-paths " +
			"--print-build-logs " +
			"./test#checks.x86_64-linux." + name,
	}
}