summaryrefslogtreecommitdiff
path: root/.gitlab-ci.yml
Commit message (Collapse)AuthorAgeFilesLines
* Merge branch 'ahf/macos-cross-build' into 'main'Alexander Hansen Færøy2024-09-021-2/+0
|\ | | | | | | | | | | | | Fix reproducible build CI job for macOS Closes #1394 and #1507 See merge request tpo/core/arti!2377
| * Disallow failures for our CI job `build-repro-macos`Alexander Færøy2024-09-011-2/+0
| | | | | | | | See: tpo/core/arti#1394.
* | Merge branch 'ci' into 'main'Ian Jackson2024-08-271-6/+9
|\ \ | | | | | | | | | | | | Run tests of every crate, with all features disabled See merge request tpo/core/arti!2350
| * | Add script for *testing* without any features enabledIan Jackson2024-08-191-4/+7
| | | | | | | | | | | | | | | | | | | | | | | | | | | We can't do this for every crate. I looked at what is now matrix-check to see if I wanted to use any of the code. But it seems too entangled with its particular purpose, and has a lot of embedded knowledge of our crates' features. I found it sufficiently far from what I wanted that I decided on a fresh script.
| * | Rename matrix-check from matrix_testIan Jackson2024-08-191-2/+2
| | | | | | | | | | | | | | | There's a TODO asking for `check` to be changed to `test`. And we're about to invent a thing that does, sort of, the `test`.
* | | Fix CI on main by always running the deb-source jobIan Jackson2024-08-271-3/+0
| | | | | | | | | | | | The rules: was removed from these jobs but this one was missed.
* | | Add comment on big-endian targets to .gitlab-ci.ymlNoisyCoil2024-08-271-0/+4
| | |
* | | Cross-build an arm64 deb binary package in CINoisyCoil2024-08-271-0/+30
| | |
* | | Temporarily disable testing in native deb packageNoisyCoil2024-08-271-1/+2
| | |
* | | Build an amd64 native deb binary package in CINoisyCoil2024-08-271-0/+18
| | |
* | | Build a deb source package in CINoisyCoil2024-08-271-0/+18
| |/ |/|
* | shadow: add obfs4 arti client + tor bridgeopara2024-08-211-1/+1
|/
* CI: allow the MacOS build test to failIan Jackson2024-08-151-0/+2
| | | | | | | My efforts to fix it by flailing with CC versions have not been successful. We need CI passing so we can continue to do other work.
* CI: Use "via-cargo-install-in-ci" to cache grcov in 'coverage-aggregated'Nick Mathewson2024-08-081-2/+1
| | | | | (This is what we do in all the other CI tests when we want to cargo-install something.)
* Test cbindgen correctness in CINick Mathewson2024-08-071-0/+9
| | | | | | | With the introduction of FFI, we ship generated header files that we need to keep up-to-date. This CI test double-checks that the generated files match those that we would generate from cbindgen.
* CI: Enable restricted-discovery for arti-extra.Gabriela Moldovan2024-08-051-1/+1
| | | | This enables us to test "restricted discovery" mode in shadow.
* integration-shadow test: fix broken reference to apt-install scriptJim Newsome2024-08-021-1/+1
| | | | | | | | Relative directory reference here is incorrect since we changed directories. Move this line to before the directory-change. Looks like this was broken in c4e1d0c582164e17e0226af754a08692da5efb29, but only surfaces on a cache miss of the tgen build.
* CI: Only preserve rust-recent artifacts, don't process rust-latest onesIan Jackson2024-07-311-5/+5
| | | | | | | | The -latest jobs don't actually have artifacts. But: In the -latest jobs this can cause errors due to duplication: the artifacts from the -recent jobs in the same pipeline result in EEXIST errors.
* CI: Use YAML anchors rather than .extends for rust-recent/rust-latestIan Jackson2024-07-311-6/+12
| | | | | This will let us make the artifact processing only happen when we want to save artifacts.
* CI: Add TODOs about rethinking matrix_test.Gabriela Moldovan2024-07-301-0/+9
| | | | Prompted by https://gitlab.torproject.org/tpo/core/arti/-/merge_requests/2275#note_3054040
* CI: Add cli-test job.Gabriela Moldovan2024-07-301-0/+11
|
* CI: Rename "latest" jobs to "recent"; pin them; and replace them.Ian Jackson2024-07-291-10/+30
| | | | | | | | | | | We replace uses of `amd64/rust:bookworm` in the `recent-*` jobs. We add new latest-* jobs which * aren't used for artifacts * occur later in the pipeline * only run on main, since we don't want them to block MRs This is done with templates, to reuse the script parts.
* CI: Use RECENT_RUST_IMAGE instead of unpinned Rust, in most jobsIan Jackson2024-07-291-21/+10
| | | | | | | | | | | | | | | | Replace almost all the open-coded occurrences of `amd64/rust:bookworm`. This rewinds us to Rust 1.79. We can update after https://github.com/rustsec/rustsec/issues/1217 is fixed upstream. We're going to handle the rust-latest-* jobs specially. There are still a few other images that look, from the name, like they might be uncontrolled inputs into our CI, but they don't look risky. Let's leave them for now.
* CI: Introduce RECENT_RUST_IMAGE variableIan Jackson2024-07-291-1/+4
| | | | So far only used by the cargo-audit job.
* Use a pinned compiler version to run cargo auditIan Jackson2024-07-291-1/+1
| | | | | | | | | | | | | | | | | | This avoids CI failures like this https://gitlab.torproject.org/nickm/arti/-/jobs/617654 arising from situations like this cargo-audit install fails with rust 1.80 https://github.com/rustsec/rustsec/issues/1217 error[E0282]: type annotations needed for Box<_> https://github.com/time-rs/time/issues/693 IMO we should pin many of the other images too but I suspect that may be controversial. I'm hoping that pinning this one to get CI working is uncontroversial (perhaps only on a temporary basis). The other way to solve this would be to remove --locked which IMO is going in the wrong direction, by exposing us to more rather than fewer uncontrolled inputs from our upstreams.
* Run update-shell-includes, to forbid cwd-dependent script includesIan Jackson2024-07-161-0/+1
|
* Switch to maint/common/forbid-script-extensionsIan Jackson2024-07-161-1/+1
|
* Switch to maint/common/forbid-absolute-shebangsIan Jackson2024-07-161-1/+1
|
* CI: maint-checks job: Install gitIan Jackson2024-07-161-1/+1
| | | | Without this, maint/shebang is broken.
* Use maint/common/apt-install instead of open-coding (multiline)Ian Jackson2024-07-161-10/+8
|
* Use maint/common/apt-install instead of open-coding (apt-get)Ian Jackson2024-07-161-8/+8
|
* Use maint/common/apt-install instead of open-coding (apt)Ian Jackson2024-07-161-3/+3
|
* Switch to maint/common/via-cargo-install-in-ciIan Jackson2024-07-161-4/+4
| | | | And delete our old version of the script.
* via-cargo-install-in-ci: Split a multi-package invocationIan Jackson2024-07-161-1/+2
| | | | We're about to switch to a version that doesn't support this.
* Replace maint/shellcheck_all with maint/common/shellcheck-allIan Jackson2024-07-161-1/+1
| | | | | | | | * Change all in-tree reference * Delete our copy of script, which now lives in the rust-maint-common subtree. * Leave a symlink behind, so that old git hooks that people (IMO possibly unwisely) installed, still work.
* maint/cargo-check-publishable: run in CIIan Jackson2024-07-101-1/+2
|
* maint/cargo-check-publishable: Check categoriesIan Jackson2024-07-101-0/+3
| | | | What a palaver.
* maint/list_crates: Run mypy in CIIan Jackson2024-07-101-0/+1
|
* Merge branch 'split-build-repro' into 'main'Ian Jackson2024-07-091-6/+29
|\ | | | | | | | | | | | | CI: Split build-repro job Closes #1478 See merge request tpo/core/arti!2252
| * CI: Use templating to reduce duplication in build-repro jobsIan Jackson2024-07-091-23/+20
| | | | | | | | | | As suggested here: https://gitlab.torproject.org/tpo/core/arti/-/merge_requests/2252#note_3046205
| * CI: Split build-repro jobIan Jackson2024-07-091-3/+29
| | | | | | | | | | This will allow the elements to run in parallel, hopefully speeding things up (but using no fewer resources).
* | CI: set default image to amd64/debian:bookworm-slimJim Newsome2024-07-081-18/+2
| |
* | CI: maint-check-ownership use single-arch imageJim Newsome2024-07-081-1/+2
|/
* Test for broken docs in rust-latest job, denying failuresIan Jackson2024-07-081-0/+1
| | | | | | | Broken docs keep slipping in because we test this only with nightly, where we allow failures. Currently nightly is broken; see #1467. I'm not addressing that here yet.
* Enable the build-repro CI job in MR jobsIan Jackson2024-06-261-4/+1
| | | | | | Hopefully this will not be too slow. Fixes #1472.
* Revert "Disable macos build tests"Ian Jackson2024-06-261-1/+2
| | | | This reverts commit a6801c10584558316ff38f354167812d0c697549.
* Merge branch 'no-osxcross' into 'main'gabi-2502024-06-251-2/+1
|\ | | | | | | | | Disable macos build tests See merge request tpo/core/arti!2226
| * Disable macos build testsIan Jackson2024-06-251-2/+1
| |
* | Turn crate ownership discrepancies into a warningIan Jackson2024-06-241-0/+1
|/ | | | | Ideally we'd tolerate situations with unaccepted ownership requests, but that information doesn't seem to be public.
* Check crate ownership in CI, but only on mainIan Jackson2024-06-241-0/+13
| | | | | | | | | | | | | | | I think that the effect of this will be as follows: * MR branches will never run this, so when the crate ownership is wrong, development can continue. * When a new crate is first published, it will transition from "ignored" to "complaining". This will happen on the first CI run on main after "cargo publish" is run. But it *won't* happen on the CI run on the publication tag. The intent is that we discover a failure to `git add` while the release technician who published the new crate is still around.