| # Copyright 2021-2026 The OpenSSL Project Authors. All Rights Reserved. |
| # |
| # Licensed under the Apache License 2.0 (the "License"). You may not use |
| # this file except in compliance with the License. You can obtain a copy |
| # in the file LICENSE in the source distribution or at |
| # https://www.openssl.org/source/license.html |
| |
| name: GitHub CI |
| |
| on: |
| pull_request: |
| paths-ignore: |
| - 'doc/**' |
| - '*.md' |
| - '*.pod' |
| - 'README*' |
| - 'funding.json' |
| - 'LICENSE.txt' |
| - 'VERSION.dat' |
| push: |
| paths-ignore: |
| - 'doc/**' |
| - '*.md' |
| - '*.pod' |
| - 'README*' |
| - 'funding.json' |
| - 'LICENSE.txt' |
| - 'VERSION.dat' |
| |
| # for some reason, this does not work: |
| # variables: |
| # BUILDOPTS: "-j4" |
| # HARNESS_JOBS: "${HARNESS_JOBS:-4}" |
| |
| # for some reason, this does not work: |
| # before_script: |
| # - make="make -s" |
| |
| permissions: |
| contents: read |
| |
| env: |
| OSSL_RUN_CI_TESTS: 1 |
| |
| jobs: |
| check_update: |
| runs-on: ubuntu-latest |
| steps: |
| - name: install unifdef |
| run: | |
| sudo apt-get update |
| sudo apt-get -yq --no-install-suggests --no-install-recommends --allow-unauthenticated --allow-downgrades --allow-remove-essential --allow-change-held-packages install unifdef |
| - uses: actions/checkout@v6 |
| with: |
| fetch-depth: 0 |
| persist-credentials: false |
| - name: config |
| run: ./config --strict-warnings --banner=Configured enable-fips && perl configdata.pm --dump |
| - name: make build_generated |
| run: make -s build_generated |
| - name: make update |
| run: make update |
| - name: git diff |
| run: git diff --exit-code |
| |
| # This checks that we use ANSI C language syntax and semantics. |
| # We are not as strict with libraries, but rather adapt to what's |
| # expected to be available in a certain version of each platform. |
| check-c99: |
| runs-on: ubuntu-latest |
| steps: |
| - uses: actions/checkout@v6 |
| with: |
| persist-credentials: false |
| - name: config |
| run: CPPFLAGS='-std=c99 -D_XOPEN_SOURCE=1 -D_POSIX_C_SOURCE=200809L' ./config --strict-warnings --banner=Configured enable-sslkeylog no-asm no-secure-memory no-makedepend enable-buildtest-c++ enable-fips enable-lms && perl configdata.pm --dump |
| - name: make |
| run: make -s -j4 |
| |
| basic_gcc: |
| runs-on: ubuntu-latest |
| steps: |
| - uses: actions/checkout@v6 |
| with: |
| persist-credentials: false |
| - name: checkout fuzz/corpora submodule |
| run: git submodule update --init --depth 1 fuzz/corpora |
| - name: localegen |
| run: sudo locale-gen tr_TR.UTF-8 |
| - name: cmocka |
| run: sudo apt-get -y install libcmocka-dev |
| - name: install dependencies for perl Net::Curl |
| run: | |
| sudo apt-get update |
| sudo apt-get -y install libcurl4-openssl-dev cpanminus build-essential |
| - name: install Net::Curl |
| run: | |
| url=https://cpan.metacpan.org/authors/id/S/SY/SYP/Net-Curl-0.58.tar.gz |
| sha=37c1585cc70e21579c7c733e306e97a46adc093a3777af6d8ba37d73986d7f5a |
| curl -fsSL "$url" -o Net-Curl.tar.gz |
| echo "$sha Net-Curl.tar.gz" | sha256sum -c - |
| sudo cpanm --notest ./Net-Curl.tar.gz |
| - name: fipsvendor |
| # Make one fips build use a customized FIPS vendor |
| run: echo "FIPS_VENDOR=CI" >> VERSION.dat |
| - name: config |
| # enable-quic is on by default, but we leave it here to check we're testing the explicit enable somewhere |
| run: CC=gcc ./config --strict-warnings --banner=Configured enable-demos enable-h3demo enable-ec_explicit_curves enable-sslkeylog enable-fips enable-quic enable-lms enable-unit-tests && perl configdata.pm --dump |
| - name: make |
| run: make -s -j4 |
| - name: get cpu info |
| run: | |
| cat /proc/cpuinfo |
| ./util/opensslwrap.sh version -c |
| - name: make test |
| run: .github/workflows/make-test |
| - name: check fipsvendor |
| run: | |
| util/wrap.pl -fips apps/openssl list -providers | grep 'name: CI FIPS Provider for OpenSSL$' |
| - name: save artifacts |
| if: success() || failure() |
| uses: actions/upload-artifact@v5 |
| with: |
| name: "ci@basic-gcc" |
| path: artifacts.tar.gz |
| |
| basic_clang: |
| runs-on: ubuntu-latest |
| steps: |
| - uses: actions/checkout@v6 |
| with: |
| persist-credentials: false |
| - name: checkout fuzz/corpora submodule |
| run: git submodule update --init --depth 1 fuzz/corpora |
| - name: config |
| run: CC=clang ./config --strict-warnings --banner=Configured enable-demos enable-h3demo no-fips && perl configdata.pm --dump |
| - name: make |
| run: make -s -j4 |
| - name: get cpu info |
| run: | |
| cat /proc/cpuinfo |
| ./util/opensslwrap.sh version -c |
| - name: make test |
| run: .github/workflows/make-test |
| - name: save artifacts |
| if: success() || failure() |
| uses: actions/upload-artifact@v5 |
| with: |
| name: "ci@basic-clang" |
| path: artifacts.tar.gz |
| |
| linux-arm64: |
| runs-on: ubuntu-24.04-arm |
| steps: |
| - uses: actions/checkout@v6 |
| with: |
| persist-credentials: false |
| - name: config |
| run: ./config --strict-warnings enable-demos enable-fips enable-lms enable-ec_nistp_64_gcc_128 enable-md2 enable-rc5 enable-trace |
| - name: config dump |
| run: ./configdata.pm --dump |
| - name: make |
| run: make -j4 |
| - name: get cpu info |
| run: | |
| cat /proc/cpuinfo |
| ./util/opensslwrap.sh version -c |
| - name: make test |
| run: .github/workflows/make-test |
| - name: save artifacts |
| if: success() || failure() |
| uses: actions/upload-artifact@v5 |
| with: |
| name: "ci@linux-arm64" |
| path: artifacts.tar.gz |
| |
| gcc-min-version: |
| runs-on: ubuntu-latest |
| container: |
| image: docker.io/gcc:9 |
| timeout-minutes: 90 |
| strategy: |
| fail-fast: false |
| steps: |
| - uses: actions/checkout@v6 |
| with: |
| persist-credentials: false |
| - name: config |
| run: ./config --strict-warnings --banner=Configured enable-fips && perl configdata.pm --dump |
| - name: make |
| run: make -s -j4 |
| - name: print gcc version |
| run: | |
| gcc --version |
| - name: get cpu info |
| run: | |
| cat /proc/cpuinfo |
| ./util/opensslwrap.sh version -c |
| - name: make test |
| run: .github/workflows/make-test |
| |
| linux-x86: |
| runs-on: ubuntu-latest |
| steps: |
| - uses: actions/checkout@v6 |
| with: |
| persist-credentials: false |
| - name: run container |
| run: | |
| CONTAINER_ID=$(podman run -d -v $(pwd):/mnt -w /mnt --platform=linux/i386 docker.io/i386/debian:13 sleep infinity) |
| echo "CONTAINER_ID=$CONTAINER_ID" >> "$GITHUB_ENV" |
| - name: install dependencies |
| run: |
| podman exec -t $CONTAINER_ID sh -c "apt-get update && apt-get install -y gcc perl make" |
| - name: config |
| run: | |
| podman exec -t $CONTAINER_ID sh -c \ |
| "./config --strict-warnings linux-x86 enable-demos enable-fips enable-lms enable-md2 enable-rc5 enable-trace" |
| - name: config dump |
| run: | |
| podman exec -t $CONTAINER_ID sh -c \ |
| "./configdata.pm --dump" |
| - name: make |
| run: | |
| podman exec -t $CONTAINER_ID sh -c \ |
| "make -j" |
| - name: get cpu info |
| run: | |
| cat /proc/cpuinfo |
| podman exec -t $CONTAINER_ID sh -c \ |
| "./util/opensslwrap.sh version -c" |
| - name: make test |
| run: | |
| podman exec -t $CONTAINER_ID sh -c \ |
| ".github/workflows/make-test" |
| - name: save artifacts |
| if: success() || failure() |
| uses: actions/upload-artifact@v5 |
| with: |
| name: "ci@linux-x86" |
| path: artifacts.tar.gz |
| |
| freebsd-x86_64: |
| runs-on: ubuntu-latest |
| steps: |
| - uses: actions/checkout@v6 |
| with: |
| persist-credentials: false |
| - name: config |
| uses: cross-platform-actions/action@46e8d7fb25520a8d6c64fd2b7a1192611da98eda #v0.30.0 |
| with: |
| operating_system: freebsd |
| version: "13.4" |
| shutdown_vm: false |
| run: | |
| sudo pkg install -y gcc perl5 |
| ./config --strict-warnings enable-fips enable-lms enable-ec_nistp_64_gcc_128 enable-md2 enable-rc5 enable-trace |
| - name: config dump |
| uses: cross-platform-actions/action@46e8d7fb25520a8d6c64fd2b7a1192611da98eda #v0.30.0 |
| with: |
| operating_system: freebsd |
| version: "13.4" |
| shutdown_vm: false |
| run: ./configdata.pm --dump |
| - name: make |
| uses: cross-platform-actions/action@46e8d7fb25520a8d6c64fd2b7a1192611da98eda #v0.30.0 |
| with: |
| operating_system: freebsd |
| version: "13.4" |
| shutdown_vm: false |
| run: make -j4 |
| - name: make test |
| uses: cross-platform-actions/action@46e8d7fb25520a8d6c64fd2b7a1192611da98eda #v0.30.0 |
| with: |
| operating_system: freebsd |
| version: "13.4" |
| run: | |
| ./util/opensslwrap.sh version -c |
| .github/workflows/make-test |
| - name: save artifacts |
| if: success() || failure() |
| uses: actions/upload-artifact@v5 |
| with: |
| name: "ci@BSD-x86_64" |
| path: artifacts.tar.gz |
| |
| minimal: |
| runs-on: ubuntu-latest |
| steps: |
| - uses: actions/checkout@v6 |
| with: |
| persist-credentials: false |
| - name: checkout fuzz/corpora submodule |
| run: git submodule update --init --depth 1 fuzz/corpora |
| - name: config |
| run: ./config --strict-warnings --banner=Configured enable-demos enable-h3demo no-bulk no-pic no-asm no-lms -DOPENSSL_NO_SECURE_MEMORY -DOPENSSL_SMALL_FOOTPRINT && perl configdata.pm --dump |
| - name: make |
| run: make -j4 # verbose, so no -s here |
| - name: get cpu info |
| run: | |
| cat /proc/cpuinfo |
| ./util/opensslwrap.sh version -c |
| - name: make test |
| run: .github/workflows/make-test |
| - name: save artifacts |
| if: success() || failure() |
| uses: actions/upload-artifact@v5 |
| with: |
| name: "ci@minimal" |
| path: artifacts.tar.gz |
| |
| no-deprecated: |
| runs-on: ubuntu-latest |
| steps: |
| - uses: actions/checkout@v6 |
| with: |
| persist-credentials: false |
| - name: checkout fuzz/corpora submodule |
| run: git submodule update --init --depth 1 fuzz/corpora |
| - name: config |
| run: ./config --strict-warnings --banner=Configured enable-demos enable-h3demo no-deprecated enable-fips && perl configdata.pm --dump |
| - name: make |
| run: make -s -j4 |
| - name: get cpu info |
| run: | |
| cat /proc/cpuinfo |
| ./util/opensslwrap.sh version -c |
| - name: make test |
| run: .github/workflows/make-test |
| - name: save artifacts |
| if: success() || failure() |
| uses: actions/upload-artifact@v5 |
| with: |
| name: "ci@no-deprecated" |
| path: artifacts.tar.gz |
| |
| no-shared-ubuntu: |
| runs-on: ubuntu-latest |
| steps: |
| - uses: actions/checkout@v6 |
| with: |
| persist-credentials: false |
| - name: checkout fuzz/corpora submodule |
| run: git submodule update --init --depth 1 fuzz/corpora |
| - name: config |
| run: ./config --strict-warnings --banner=Configured enable-demos enable-h3demo no-shared no-fips && perl configdata.pm --dump |
| - name: make |
| run: make -s -j4 |
| - name: get cpu info |
| run: | |
| cat /proc/cpuinfo |
| ./util/opensslwrap.sh version -c |
| - name: make test |
| run: .github/workflows/make-test |
| - name: save artifacts |
| if: success() || failure() |
| uses: actions/upload-artifact@v5 |
| with: |
| name: "ci@no-shared-ubuntu" |
| path: artifacts.tar.gz |
| |
| no-shared-macos: |
| runs-on: macos-14 |
| steps: |
| - uses: actions/checkout@v6 |
| with: |
| persist-credentials: false |
| - name: checkout fuzz/corpora submodule |
| run: git submodule update --init --depth 1 fuzz/corpora |
| - name: config |
| run: ./config --strict-warnings --banner=Configured enable-demos enable-h3demo no-shared no-fips && perl configdata.pm --dump |
| - name: make |
| run: make -s -j4 |
| - name: get cpu info |
| run: | |
| sysctl machdep.cpu |
| ./util/opensslwrap.sh version -c |
| - name: make test |
| run: .github/workflows/make-test |
| - name: save artifacts |
| if: success() || failure() |
| uses: actions/upload-artifact@v5 |
| with: |
| name: "ci@no-shared-macos-14" |
| path: artifacts.tar.gz |
| |
| non-caching: |
| runs-on: ubuntu-latest |
| steps: |
| - uses: actions/checkout@v6 |
| with: |
| persist-credentials: false |
| - name: checkout fuzz/corpora submodule |
| run: git submodule update --init --depth 1 fuzz/corpora |
| - name: Adjust ASLR for sanitizer |
| run: | |
| sudo cat /proc/sys/vm/mmap_rnd_bits |
| sudo sysctl -w vm.mmap_rnd_bits=28 |
| - name: config |
| run: ./config --strict-warnings --banner=Configured --debug enable-demos enable-h3demo enable-asan enable-ubsan no-cached-fetch no-fips no-dtls no-tls1 no-tls1-method no-tls1_1 no-tls1_1-method no-async && perl configdata.pm --dump |
| - name: make |
| run: make -s -j4 |
| - name: get cpu info |
| run: | |
| cat /proc/cpuinfo |
| ./util/opensslwrap.sh version -c |
| - name: make test |
| run: .github/workflows/make-test OPENSSL_TEST_RAND_ORDER=0 TESTS="-test_fuzz* -test_ssl_* -test_sslapi -test_evp -test_cmp_http -test_verify -test_cms -test_store -test_enc -[01][0-9]" |
| - name: save artifacts |
| if: success() || failure() |
| uses: actions/upload-artifact@v5 |
| with: |
| name: "ci@non-caching" |
| path: artifacts.tar.gz |
| |
| address_ub_sanitizer: |
| runs-on: ubuntu-latest |
| steps: |
| - uses: actions/checkout@v6 |
| with: |
| persist-credentials: false |
| - name: checkout fuzz/corpora submodule |
| run: git submodule update --init --depth 1 fuzz/corpora |
| - name: Adjust ASLR for sanitizer |
| run: | |
| sudo cat /proc/sys/vm/mmap_rnd_bits |
| sudo sysctl -w vm.mmap_rnd_bits=28 |
| - name: config |
| run: ./config --strict-warnings --banner=Configured --debug enable-demos enable-h3demo enable-asan enable-ec_explicit_curves enable-ubsan enable-rc5 enable-md2 enable-ec_nistp_64_gcc_128 enable-fips enable-lms && perl configdata.pm --dump |
| - name: make |
| run: make -s -j4 |
| - name: get cpu info |
| run: | |
| cat /proc/cpuinfo |
| ./util/opensslwrap.sh version -c |
| - name: make test |
| run: .github/workflows/make-test OPENSSL_TEST_RAND_ORDER=0 |
| - name: save artifacts |
| if: success() || failure() |
| uses: actions/upload-artifact@v5 |
| with: |
| name: "ci@address_ub_sanitizer" |
| path: artifacts.tar.gz |
| |
| fuzz_tests: |
| runs-on: ubuntu-latest |
| steps: |
| - uses: actions/checkout@v6 |
| with: |
| persist-credentials: false |
| - name: checkout fuzz/corpora submodule |
| run: git submodule update --init --depth 1 fuzz/corpora |
| - name: Adjust ASLR for sanitizer |
| run: | |
| sudo cat /proc/sys/vm/mmap_rnd_bits |
| sudo sysctl -w vm.mmap_rnd_bits=28 |
| - name: config |
| run: ./config --strict-warnings --banner=Configured --debug -DPEDANTIC -DFUZZING_BUILD_MODE_UNSAFE_FOR_PRODUCTION enable-asan enable-ec_explicit_curves enable-ubsan enable-rc5 enable-md2 enable-ec_nistp_64_gcc_128 enable-weak-ssl-ciphers enable-nextprotoneg && perl configdata.pm --dump |
| - name: make |
| run: make -s -j4 |
| - name: get cpu info |
| run: | |
| cat /proc/cpuinfo |
| ./util/opensslwrap.sh version -c |
| - name: make test |
| run: .github/workflows/make-test OPENSSL_TEST_RAND_ORDER=0 TESTS="test_fuzz*" |
| - name: save artifacts |
| if: success() || failure() |
| uses: actions/upload-artifact@v5 |
| with: |
| name: "ci@fuzz_tests" |
| path: artifacts.tar.gz |
| if-no-files-found: ignore |
| |
| fuzz_tests_mfail: |
| runs-on: ubuntu-latest |
| timeout-minutes: 15 |
| steps: |
| - uses: actions/checkout@v6 |
| with: |
| persist-credentials: false |
| - name: checkout fuzz/corpora submodule |
| run: git submodule update --init --depth 1 fuzz/corpora |
| - name: trim corpora to a few seeds per fuzzer |
| env: |
| FUZZ_CORPUS_KEEP: 5 |
| run: | |
| for d in fuzz/corpora/*/; do |
| find "$d" -maxdepth 1 -type f | tail -n +$((FUZZ_CORPUS_KEEP + 1)) | xargs -r rm -f |
| done |
| - name: Adjust ASLR for sanitizer |
| run: sudo sysctl -w vm.mmap_rnd_bits=28 |
| - name: config |
| run: | |
| ./config --strict-warnings --banner=Configured --debug \ |
| -DPEDANTIC -DFUZZING_BUILD_MODE_UNSAFE_FOR_PRODUCTION \ |
| enable-asan enable-ec_explicit_curves enable-ubsan \ |
| enable-rc5 enable-md2 enable-ec_nistp_64_gcc_128 \ |
| enable-weak-ssl-ciphers enable-nextprotoneg |
| perl configdata.pm --dump |
| - name: make |
| run: make -s -j4 |
| - name: make test (fuzz with mfail) |
| run: .github/workflows/make-test OPENSSL_TEST_RAND_ORDER=0 TESTS="test_fuzz*" |
| - name: save artifacts |
| if: success() || failure() |
| uses: actions/upload-artifact@v5 |
| with: |
| name: "ci@fuzz_tests_mfail" |
| path: artifacts.tar.gz |
| if-no-files-found: ignore |
| |
| memory_sanitizer: |
| runs-on: ubuntu-latest |
| steps: |
| - uses: actions/checkout@v6 |
| with: |
| persist-credentials: false |
| - name: checkout fuzz/corpora submodule |
| run: git submodule update --init --depth 1 fuzz/corpora |
| - name: Adjust ASLR for sanitizer |
| run: | |
| sudo cat /proc/sys/vm/mmap_rnd_bits |
| sudo sysctl -w vm.mmap_rnd_bits=28 |
| - name: config |
| # --debug -O1 is to produce a debug build that runs in a reasonable amount of time |
| run: CC=clang ./config --strict-warnings --banner=Configured --debug no-shared -O1 -fsanitize=memory -DOSSL_SANITIZE_MEMORY -fno-optimize-sibling-calls enable-rc5 enable-md2 enable-ec_nistp_64_gcc_128 enable-ec_explicit_curves enable-fips enable-lms no-slh-dsa && perl configdata.pm --dump |
| - name: make |
| run: make -s -j4 |
| - name: get cpu info |
| run: | |
| cat /proc/cpuinfo |
| ./util/opensslwrap.sh version -c |
| - name: make test |
| run: .github/workflows/make-test OPENSSL_TEST_RAND_ORDER=0 |
| - name: save artifacts |
| if: success() || failure() |
| uses: actions/upload-artifact@v5 |
| with: |
| name: "ci@memory_sanitizer" |
| path: artifacts.tar.gz |
| |
| threads_sanitizer: |
| runs-on: ubuntu-latest |
| steps: |
| - uses: actions/checkout@v6 |
| with: |
| persist-credentials: false |
| - name: checkout fuzz/corpora submodule |
| run: git submodule update --init --depth 1 fuzz/corpora |
| - name: Adjust ASLR for sanitizer |
| run: | |
| sudo cat /proc/sys/vm/mmap_rnd_bits |
| sudo sysctl -w vm.mmap_rnd_bits=28 |
| - name: config |
| run: CC=clang ./config --strict-warnings --banner=Configured no-shared no-fips -g -fsanitize=thread && perl configdata.pm --dump |
| - name: make |
| run: make -s -j4 |
| - name: get cpu info |
| run: | |
| cat /proc/cpuinfo |
| ./util/opensslwrap.sh version -c |
| - name: make test |
| run: .github/workflows/make-test V=1 TESTS="test_lhash test_threads test_internal_provider test_provfetch test_provider test_pbe test_evp_kdf test_pkcs12 test_store test_evp test_quic*" |
| - name: save artifacts |
| if: success() || failure() |
| uses: actions/upload-artifact@v5 |
| with: |
| name: "ci@threads_sanitizer" |
| path: artifacts.tar.gz |
| |
| enable_non-default_options: |
| runs-on: ubuntu-latest |
| steps: |
| - uses: actions/checkout@v6 |
| with: |
| persist-credentials: false |
| - name: checkout fuzz/corpora submodule |
| run: git submodule update --init --depth 1 fuzz/corpora |
| - name: modprobe tls |
| run: sudo modprobe tls |
| - name: config |
| run: ./config --strict-warnings --banner=Configured enable-demos enable-h3demo no-ec enable-ssl-trace enable-zlib enable-zlib-dynamic enable-crypto-mdebug enable-egd enable-ktls enable-fips enable-lms no-threads && perl configdata.pm --dump |
| - name: make |
| run: make -s -j4 |
| - name: get cpu info |
| run: | |
| cat /proc/cpuinfo |
| ./util/opensslwrap.sh version -c |
| - name: make test |
| run: .github/workflows/make-test |
| - name: save artifacts |
| if: success() || failure() |
| uses: actions/upload-artifact@v5 |
| with: |
| name: "ci@enable_non-default_options" |
| path: artifacts.tar.gz |
| |
| full_featured: |
| runs-on: ubuntu-latest |
| steps: |
| - uses: actions/checkout@v6 |
| with: |
| persist-credentials: false |
| - name: checkout fuzz/corpora submodule |
| run: git submodule update --init --depth 1 fuzz/corpora |
| - name: modprobe tls |
| run: sudo modprobe tls |
| - name: Enable sctp |
| run: sudo modprobe sctp |
| - name: Enable auth in sctp |
| run: sudo sysctl -w net.sctp.auth_enable=1 |
| - name: install extra config support |
| run: sudo apt-get -y install libsctp-dev abigail-tools libzstd-dev zstd |
| - name: config |
| run: ./config --strict-warnings --banner=Configured enable-demos enable-h3demo enable-ec_explicit_curves enable-ktls enable-fips enable-lms enable-egd enable-ec_nistp_64_gcc_128 enable-md2 enable-rc5 enable-sctp enable-weak-ssl-ciphers enable-trace enable-zlib enable-zstd && perl configdata.pm --dump |
| - name: make |
| run: make -s -j4 |
| - name: get cpu info |
| run: | |
| cat /proc/cpuinfo |
| ./util/opensslwrap.sh version -c |
| - name: make test |
| run: .github/workflows/make-test |
| - name: save artifacts |
| if: success() || failure() |
| uses: actions/upload-artifact@v5 |
| with: |
| name: "ci@full_featured" |
| path: artifacts.tar.gz |
| |
| no-legacy: |
| runs-on: ubuntu-latest |
| steps: |
| - uses: actions/checkout@v6 |
| with: |
| persist-credentials: false |
| - name: checkout fuzz/corpora submodule |
| run: git submodule update --init --depth 1 fuzz/corpora |
| - name: config |
| run: ./config --strict-warnings --banner=Configured enable-demos enable-h3demo no-legacy enable-fips enable-lms && perl configdata.pm --dump |
| - name: make |
| run: make -s -j4 |
| - name: get cpu info |
| run: | |
| cat /proc/cpuinfo |
| ./util/opensslwrap.sh version -c |
| - name: make test |
| run: .github/workflows/make-test |
| - name: save artifacts |
| if: success() || failure() |
| uses: actions/upload-artifact@v5 |
| with: |
| name: "ci@no-legacy" |
| path: artifacts.tar.gz |
| |
| legacy: |
| runs-on: ubuntu-latest |
| steps: |
| - uses: actions/checkout@v6 |
| with: |
| persist-credentials: false |
| - name: checkout fuzz/corpora submodule |
| run: git submodule update --init --depth 1 fuzz/corpora |
| - name: config |
| run: ./config --strict-warnings --banner=Configured --debug enable-demos enable-h3demo no-shared enable-crypto-mdebug enable-rc5 enable-md2 enable-weak-ssl-ciphers enable-zlib enable-ec_nistp_64_gcc_128 enable-ec_explicit_curves no-fips && perl configdata.pm --dump |
| - name: make |
| run: make -s -j4 |
| - name: get cpu info |
| run: | |
| cat /proc/cpuinfo |
| ./util/opensslwrap.sh version -c |
| - name: make test |
| run: .github/workflows/make-test |
| - name: save artifacts |
| if: success() || failure() |
| uses: actions/upload-artifact@v5 |
| with: |
| name: "ci@legacy" |
| path: artifacts.tar.gz |
| |
| external-tests-misc: |
| runs-on: ubuntu-latest |
| steps: |
| - uses: actions/checkout@v6 |
| with: |
| submodules: recursive |
| persist-credentials: false |
| - name: package installs |
| run: | |
| sudo apt-get update |
| sudo apt-get -yq install bison gettext keyutils ldap-utils libldap2-dev libkeyutils-dev python3 python3-paste python3-pyrad slapd tcsh python3-virtualenv virtualenv python3-kdcproxy gdb libtls-dev wget gpg |
| - name: setup hostname workaround |
| run: sudo hostname localhost |
| - name: config |
| run: ./config --strict-warnings --banner=Configured --debug enable-rc5 enable-md2 enable-weak-ssl-ciphers enable-zlib enable-ec_nistp_64_gcc_128 enable-external-tests no-fips && perl configdata.pm --dump |
| - name: make |
| run: make -s -j4 |
| - uses: dtolnay/rust-toolchain@0f44b27771c32bda9f458f75a1e241b09791b331 |
| with: |
| toolchain: stable |
| - name: get cpu info |
| run: | |
| cat /proc/cpuinfo |
| ./util/opensslwrap.sh version -c |
| - name: test failure when selecting non-existing test case |
| run: | |
| ! make test TESTS="test_external_gost_engine" |
| - name: test external krb5 |
| run: make test TESTS="test_external_krb5" |
| - name: test external tlsfuzzer |
| run: make test TESTS="test_external_tlsfuzzer" |
| - name: test external Cloudflare quiche |
| run: make test TESTS="test_external_cf_quiche" VERBOSE=1 |
| - name: test external rpki client |
| run: make test TESTS="test_external_rpki-client-portable" |
| - name: test ability to produce debuginfo files |
| run: | |
| make debuginfo |
| gdb < <(echo -e "file ./libcrypto.so.4\nquit") > ./results |
| grep -q "Reading symbols from.*libcrypto\.so\.4\.debug" results |
| |
| external-tests-oqs-provider: |
| runs-on: ubuntu-latest |
| steps: |
| - uses: actions/checkout@v6 |
| with: |
| submodules: recursive |
| persist-credentials: false |
| - name: config |
| run: ./config --strict-warnings --banner=Configured --debug enable-external-tests && perl configdata.pm --dump |
| - name: make |
| run: make -s -j4 |
| - name: get cpu info |
| run: | |
| cat /proc/cpuinfo |
| ./util/opensslwrap.sh version -c |
| - name: test external oqs-provider |
| run: make test TESTS="test_external_oqsprovider" |
| |
| external-tests-pkcs11-provider: |
| runs-on: ubuntu-latest |
| container: fedora:latest |
| steps: |
| - name: package installs |
| run: | |
| dnf install -y perl-FindBin perl-IPC-Cmd perl-File-Compare perl-File-Copy perl-Test-Simple perl-Test-Harness python3 make g++ perl git meson opensc expect kryoptic xxd |
| - uses: actions/checkout@v6 |
| with: |
| persist-credentials: false |
| - name: checkout fuzz/corpora and pkcs11-provider submodule |
| run: | |
| git config --global --add safe.directory "$GITHUB_WORKSPACE" |
| git submodule update --init --depth 1 fuzz/corpora |
| git submodule update --init --depth 1 pkcs11-provider |
| - name: config |
| run: ./config --strict-warnings --banner=Configured --debug enable-external-tests no-fips && perl configdata.pm --dump |
| - name: make |
| run: make -s -j4 |
| # Run all tests except external tests to make sure they work fine on Fedora because |
| # this is the only job running on Fedora, only then execute pkcs11-provider external |
| # test. |
| - name: test (except external tests) |
| run: make test TESTS="-test_external_*" |
| - name: test external pkcs11-provider |
| run: make test TESTS="test_external_pkcs11_provider" VERBOSE=1 |
| - name: get cpu info |
| run: | |
| cat /proc/cpuinfo |
| ./util/opensslwrap.sh version -c |
| |
| external-tests-pyca: |
| runs-on: ubuntu-latest |
| strategy: |
| matrix: |
| PYTHON: |
| - 3.9 |
| steps: |
| - uses: actions/checkout@v6 |
| with: |
| submodules: recursive |
| persist-credentials: false |
| - name: package installs |
| run: | |
| sudo apt-get update |
| sudo apt-get -yq install pkgconf libssl-dev |
| - name: Configure OpenSSL |
| run: ./config --strict-warnings --banner=Configured --debug enable-external-tests && perl configdata.pm --dump |
| - name: make |
| run: make -s -j4 |
| - name: Setup Python |
| uses: actions/setup-python@v6.0.0 |
| with: |
| python-version: ${{ matrix.PYTHON }} |
| - uses: dtolnay/rust-toolchain@0f44b27771c32bda9f458f75a1e241b09791b331 |
| with: |
| toolchain: stable |
| - name: get cpu info |
| run: | |
| cat /proc/cpuinfo |
| ./util/opensslwrap.sh version -c |
| - name: test external pyca |
| run: make test TESTS="test_external_pyca" VERBOSE=1 |
| |
| external-test-bssl: |
| runs-on: ubuntu-latest |
| steps: |
| - uses: actions/checkout@v6 |
| with: |
| persist-credentials: false |
| - name: Configure OpenSSL |
| run: ./config enable-external-tests |
| - name: Build OpenSSL |
| run: make -s -j4 |
| - name: Clone BoringSSL 0.20260211.0 |
| run: git clone --depth 1 --branch 0.20260211.0 https://boringssl.googlesource.com/boringssl |
| - name: Configure and Build BoringSSL |
| run: | |
| cd boringssl |
| mkdir build |
| cd build |
| cmake -DCMAKE_INSTALL_PREFIX=../../boringssl/.local .. |
| make -s -j4 |
| make install |
| cd ../.. |
| - name: Test ECH with BoringSSL |
| run: make test TESTS='test_external_ech_bssl' V=1 |
| |
| external-test-nss: |
| runs-on: ubuntu-latest |
| steps: |
| - uses: actions/checkout@v6 |
| with: |
| persist-credentials: false |
| - name: Configure OpenSSL |
| run: ./config enable-external-tests |
| - name: Build OpenSSL |
| run: make -s -j4 |
| - name: Clone and Build NSS |
| run: | |
| mkdir nss |
| cd nss |
| git clone --depth 1 --branch NSS_3_112_3_RTM https://github.com/nss-dev/nss.git |
| hg clone https://hg.mozilla.org/projects/nspr -r NSPR_4_36_BRANCH |
| cd nss |
| USE_64=1 make nss_build_all |
| USE_64=1 make install |
| cd ../.. |
| - name: Test ECH with NSS |
| run: make test TESTS='test_external_ech_nss' V=1 |