mirror of
https://github.com/kernelkit/infix.git
synced 2026-07-22 01:13:00 +02:00
Allow a workflow caller to run pre-build scripts though a workflow call variable. This is potentially dangerous as code can be injected here. If for example a malicious actor wants to run there C2 code in the context of someone else they could perhaps inject it here. I assume this is protected by the same mecahism as the workflow files themself. I.e. github users untrusted to the Infix org won't be able to trigger workflows before being explicitly allowed to do so. This patch also adds a checkout secret. This allows upstream callers to fetch there own spin / fork though the infix workflows, if they provide a checkout token with the correct permissions to do so. Signed-off-by: Richard Alpe <richard@bit42.se>
122 lines
3.7 KiB
YAML
122 lines
3.7 KiB
YAML
name: Test Infix
|
|
|
|
on:
|
|
workflow_dispatch:
|
|
inputs:
|
|
infix_repo:
|
|
description: 'Repo to checkout (for spin overrides)'
|
|
required: false
|
|
default: kernelkit/infix
|
|
type: string
|
|
|
|
workflow_call:
|
|
inputs:
|
|
target:
|
|
required: true
|
|
type: string
|
|
name:
|
|
required: true
|
|
type: string
|
|
infix_repo:
|
|
required: false
|
|
type: string
|
|
default: kernelkit/infix
|
|
ninepm-conf:
|
|
required: false
|
|
type: string
|
|
default: ''
|
|
test-path:
|
|
required: false
|
|
type: string
|
|
default: 'test'
|
|
secrets:
|
|
CHECKOUT_TOKEN:
|
|
required: false
|
|
description: 'Token for cross-repository access'
|
|
|
|
env:
|
|
TARGET: ${{ github.event_name == 'workflow_dispatch' && github.event.inputs.target || inputs.target }}
|
|
INFIX_REPO: ${{ github.event_name == 'workflow_dispatch' && github.event.inputs.infix_repo || inputs.infix_repo }}
|
|
NINEPM_CONF: ${{ github.event_name == 'workflow_dispatch' && github.event.inputs.ninepm-conf || inputs.ninepm-conf }}
|
|
TEST_PATH: ${{ github.event_name == 'workflow_dispatch' && github.event.inputs.test-path || inputs.test-path }}
|
|
|
|
jobs:
|
|
test:
|
|
name: Regression Test ${{ github.event_name == 'workflow_dispatch' && github.event.inputs.name || inputs.name }} ${{ github.event_name == 'workflow_dispatch' && github.event.inputs.target || inputs.target }}
|
|
runs-on: [self-hosted, regression]
|
|
steps:
|
|
- name: Cleanup podman state
|
|
run: |
|
|
set -x
|
|
podman ps -a || true
|
|
podman stop -a || true
|
|
podman rm -a -f || true
|
|
podman volume prune -f || true
|
|
podman system prune -a -f || true
|
|
podman system migrate || true
|
|
|
|
- name: Checkout infix repo
|
|
uses: actions/checkout@v4
|
|
with:
|
|
repository: ${{ env.INFIX_REPO }}
|
|
ref: ${{ github.ref }}
|
|
clean: true
|
|
fetch-depth: 0
|
|
submodules: recursive
|
|
token: ${{ secrets.CHECKOUT_TOKEN || github.token }}
|
|
|
|
- name: Set Build Variables
|
|
id: vars
|
|
run: |
|
|
if [ -n "${{ needs.build.outputs.build_id }}" ]; then
|
|
echo "INFIX_BUILD_ID=${{ needs.build.outputs.build_id }}" \
|
|
>>$GITHUB_ENV
|
|
fi
|
|
|
|
- name: Configure ${{ env.TARGET }}
|
|
run: |
|
|
make ${{ env.TARGET }}_defconfig
|
|
|
|
- uses: actions/download-artifact@v4
|
|
with:
|
|
pattern: "artifact-*"
|
|
merge-multiple: true
|
|
|
|
- name: Restore ${{ env.TARGET }} output/
|
|
run: |
|
|
target=${{ env.TARGET }}
|
|
name=${{ inputs.name }}
|
|
|
|
ls -l
|
|
mkdir -p output
|
|
mv ${name}-${target}.tar.gz output/
|
|
cd output/
|
|
tar xf ${name}-${target}.tar.gz
|
|
ln -s ${name}-${target} images
|
|
|
|
- name: Regression Test ${{ env.TARGET }}
|
|
run: |
|
|
if [ -n "$NINEPM_CONF" ]; then
|
|
export NINEPM_PROJ_CONFIG="${GITHUB_WORKSPACE}/$NINEPM_CONF"
|
|
echo "DEBUG: NINEPM_PROJ_CONFIG is '$NINEPM_PROJ_CONFIG'"
|
|
fi
|
|
make test
|
|
|
|
- name: Publish Test Result for ${{ env.TARGET }}
|
|
# Ensure this runs even if Regression Test fails
|
|
if: always()
|
|
run: |
|
|
cat $TEST_PATH/.log/last/result-gh.md >> $GITHUB_STEP_SUMMARY
|
|
|
|
- name: Generate Test Report for ${{ env.TARGET }}
|
|
# Ensure this runs even if Regression Test fails
|
|
if: always()
|
|
run: |
|
|
make test-dir="$(pwd)/$TEST_PATH" test-report
|
|
|
|
- name: Upload Test Report as Artifact
|
|
uses: actions/upload-artifact@v4
|
|
with:
|
|
name: test-report
|
|
path: output/images/test-report.pdf
|