aboutsummaryrefslogtreecommitdiff
path: root/.gitlab-ci.yml
Commit message (Collapse)AuthorAgeFilesLines
...
* Pass -uc to dpkg-buildpackage when building .debsIan Jackson2024-09-051-2/+2
| | | | | | | | | | | By default dpkg-buildpackage signs the output if the d/changelog isn't UNRELEASED. If we ever change the d/changelog, we don't want it to fail because it tries to sign things. In the future, if and when we want to sign things, that probably won't be done directly in gitlab CI when the package is built.
* Merge branch 'ahf/macos-cross-build' into 'main'Alexander Hansen Færøy2024-09-021-2/+0
|\ | | | | | | | | | | | | Fix reproducible build CI job for macOS Closes #1394 and #1507 See merge request tpo/core/arti!2377
| * Disallow failures for our CI job `build-repro-macos`Alexander Færøy2024-09-011-2/+0
| | | | | | | | See: tpo/core/arti#1394.
* | Merge branch 'ci' into 'main'Ian Jackson2024-08-271-6/+9
|\ \ | | | | | | | | | | | | Run tests of every crate, with all features disabled See merge request tpo/core/arti!2350
| * | Add script for *testing* without any features enabledIan Jackson2024-08-191-4/+7
| | | | | | | | | | | | | | | | | | | | | | | | | | | We can't do this for every crate. I looked at what is now matrix-check to see if I wanted to use any of the code. But it seems too entangled with its particular purpose, and has a lot of embedded knowledge of our crates' features. I found it sufficiently far from what I wanted that I decided on a fresh script.
| * | Rename matrix-check from matrix_testIan Jackson2024-08-191-2/+2
| | | | | | | | | | | | | | | There's a TODO asking for `check` to be changed to `test`. And we're about to invent a thing that does, sort of, the `test`.
* | | Fix CI on main by always running the deb-source jobIan Jackson2024-08-271-3/+0
| | | | | | | | | | | | The rules: was removed from these jobs but this one was missed.
* | | Add comment on big-endian targets to .gitlab-ci.ymlNoisyCoil2024-08-271-0/+4
| | |
* | | Cross-build an arm64 deb binary package in CINoisyCoil2024-08-271-0/+30
| | |
* | | Temporarily disable testing in native deb packageNoisyCoil2024-08-271-1/+2
| | |
* | | Build an amd64 native deb binary package in CINoisyCoil2024-08-271-0/+18
| | |
* | | Build a deb source package in CINoisyCoil2024-08-271-0/+18
| |/ |/|
* | shadow: add obfs4 arti client + tor bridgeopara2024-08-211-1/+1
|/
* CI: allow the MacOS build test to failIan Jackson2024-08-151-0/+2
| | | | | | | My efforts to fix it by flailing with CC versions have not been successful. We need CI passing so we can continue to do other work.
* CI: Use "via-cargo-install-in-ci" to cache grcov in 'coverage-aggregated'Nick Mathewson2024-08-081-2/+1
| | | | | (This is what we do in all the other CI tests when we want to cargo-install something.)
* Test cbindgen correctness in CINick Mathewson2024-08-071-0/+9
| | | | | | | With the introduction of FFI, we ship generated header files that we need to keep up-to-date. This CI test double-checks that the generated files match those that we would generate from cbindgen.
* CI: Enable restricted-discovery for arti-extra.Gabriela Moldovan2024-08-051-1/+1
| | | | This enables us to test "restricted discovery" mode in shadow.
* integration-shadow test: fix broken reference to apt-install scriptJim Newsome2024-08-021-1/+1
| | | | | | | | Relative directory reference here is incorrect since we changed directories. Move this line to before the directory-change. Looks like this was broken in c4e1d0c582164e17e0226af754a08692da5efb29, but only surfaces on a cache miss of the tgen build.
* CI: Only preserve rust-recent artifacts, don't process rust-latest onesIan Jackson2024-07-311-5/+5
| | | | | | | | The -latest jobs don't actually have artifacts. But: In the -latest jobs this can cause errors due to duplication: the artifacts from the -recent jobs in the same pipeline result in EEXIST errors.
* CI: Use YAML anchors rather than .extends for rust-recent/rust-latestIan Jackson2024-07-311-6/+12
| | | | | This will let us make the artifact processing only happen when we want to save artifacts.
* CI: Add TODOs about rethinking matrix_test.Gabriela Moldovan2024-07-301-0/+9
| | | | Prompted by https://gitlab.torproject.org/tpo/core/arti/-/merge_requests/2275#note_3054040
* CI: Add cli-test job.Gabriela Moldovan2024-07-301-0/+11
|
* CI: Rename "latest" jobs to "recent"; pin them; and replace them.Ian Jackson2024-07-291-10/+30
| | | | | | | | | | | We replace uses of `amd64/rust:bookworm` in the `recent-*` jobs. We add new latest-* jobs which * aren't used for artifacts * occur later in the pipeline * only run on main, since we don't want them to block MRs This is done with templates, to reuse the script parts.
* CI: Use RECENT_RUST_IMAGE instead of unpinned Rust, in most jobsIan Jackson2024-07-291-21/+10
| | | | | | | | | | | | | | | | Replace almost all the open-coded occurrences of `amd64/rust:bookworm`. This rewinds us to Rust 1.79. We can update after https://github.com/rustsec/rustsec/issues/1217 is fixed upstream. We're going to handle the rust-latest-* jobs specially. There are still a few other images that look, from the name, like they might be uncontrolled inputs into our CI, but they don't look risky. Let's leave them for now.
* CI: Introduce RECENT_RUST_IMAGE variableIan Jackson2024-07-291-1/+4
| | | | So far only used by the cargo-audit job.
* Use a pinned compiler version to run cargo auditIan Jackson2024-07-291-1/+1
| | | | | | | | | | | | | | | | | | This avoids CI failures like this https://gitlab.torproject.org/nickm/arti/-/jobs/617654 arising from situations like this cargo-audit install fails with rust 1.80 https://github.com/rustsec/rustsec/issues/1217 error[E0282]: type annotations needed for Box<_> https://github.com/time-rs/time/issues/693 IMO we should pin many of the other images too but I suspect that may be controversial. I'm hoping that pinning this one to get CI working is uncontroversial (perhaps only on a temporary basis). The other way to solve this would be to remove --locked which IMO is going in the wrong direction, by exposing us to more rather than fewer uncontrolled inputs from our upstreams.
* Run update-shell-includes, to forbid cwd-dependent script includesIan Jackson2024-07-161-0/+1
|
* Switch to maint/common/forbid-script-extensionsIan Jackson2024-07-161-1/+1
|
* Switch to maint/common/forbid-absolute-shebangsIan Jackson2024-07-161-1/+1
|
* CI: maint-checks job: Install gitIan Jackson2024-07-161-1/+1
| | | | Without this, maint/shebang is broken.
* Use maint/common/apt-install instead of open-coding (multiline)Ian Jackson2024-07-161-10/+8
|
* Use maint/common/apt-install instead of open-coding (apt-get)Ian Jackson2024-07-161-8/+8
|
* Use maint/common/apt-install instead of open-coding (apt)Ian Jackson2024-07-161-3/+3
|
* Switch to maint/common/via-cargo-install-in-ciIan Jackson2024-07-161-4/+4
| | | | And delete our old version of the script.
* via-cargo-install-in-ci: Split a multi-package invocationIan Jackson2024-07-161-1/+2
| | | | We're about to switch to a version that doesn't support this.
* Replace maint/shellcheck_all with maint/common/shellcheck-allIan Jackson2024-07-161-1/+1
| | | | | | | | * Change all in-tree reference * Delete our copy of script, which now lives in the rust-maint-common subtree. * Leave a symlink behind, so that old git hooks that people (IMO possibly unwisely) installed, still work.
* maint/cargo-check-publishable: run in CIIan Jackson2024-07-101-1/+2
|
* maint/cargo-check-publishable: Check categoriesIan Jackson2024-07-101-0/+3
| | | | What a palaver.
* maint/list_crates: Run mypy in CIIan Jackson2024-07-101-0/+1
|
* Merge branch 'split-build-repro' into 'main'Ian Jackson2024-07-091-6/+29
|\ | | | | | | | | | | | | CI: Split build-repro job Closes #1478 See merge request tpo/core/arti!2252
| * CI: Use templating to reduce duplication in build-repro jobsIan Jackson2024-07-091-23/+20
| | | | | | | | | | As suggested here: https://gitlab.torproject.org/tpo/core/arti/-/merge_requests/2252#note_3046205
| * CI: Split build-repro jobIan Jackson2024-07-091-3/+29
| | | | | | | | | | This will allow the elements to run in parallel, hopefully speeding things up (but using no fewer resources).
* | CI: set default image to amd64/debian:bookworm-slimJim Newsome2024-07-081-18/+2
| |
* | CI: maint-check-ownership use single-arch imageJim Newsome2024-07-081-1/+2
|/
* Test for broken docs in rust-latest job, denying failuresIan Jackson2024-07-081-0/+1
| | | | | | | Broken docs keep slipping in because we test this only with nightly, where we allow failures. Currently nightly is broken; see #1467. I'm not addressing that here yet.
* Enable the build-repro CI job in MR jobsIan Jackson2024-06-261-4/+1
| | | | | | Hopefully this will not be too slow. Fixes #1472.
* Revert "Disable macos build tests"Ian Jackson2024-06-261-1/+2
| | | | This reverts commit a6801c10584558316ff38f354167812d0c697549.
* Merge branch 'no-osxcross' into 'main'gabi-2502024-06-251-2/+1
|\ | | | | | | | | Disable macos build tests See merge request tpo/core/arti!2226
| * Disable macos build testsIan Jackson2024-06-251-2/+1
| |
* | Turn crate ownership discrepancies into a warningIan Jackson2024-06-241-0/+1
|/ | | | | Ideally we'd tolerate situations with unaccepted ownership requests, but that information doesn't seem to be public.