Uh oh!
There was an error while loading. Please reload this page.
Uh oh!
There was an error while loading. Please reload this page.
- Notifications
You must be signed in to change notification settings - Fork 35.2k
gh-136728: Refactor build.yml CI config and multissltests.py#143940
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Uh oh!
There was an error while loading. Please reload this page.
Changes from all commits
a104f8a3fcbe0d5d8ec9a991c6b27b5149966381274e0a8ca1a90e0c1fcb49fdd969fb1edce1c334312082f1154056020308be1f2b2f353c31325c594a826d9113833942434af3f0824181e67685baf65File filter
Filter by extension
Conversations
Uh oh!
There was an error while loading. Please reload this page.
Jump to
Uh oh!
There was an error while loading. Please reload this page.
Diff view
Diff view
There are no files selected for viewing
| Original file line number | Diff line number | Diff line change | ||||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| @@ -248,78 +248,32 @@ jobs: | ||||||||||||||||||||||||||||
| free-threading: ${{ matrix.free-threading }} | ||||||||||||||||||||||||||||
| os: ${{ matrix.os }} | ||||||||||||||||||||||||||||
| build-ubuntu-ssltests-openssl: | ||||||||||||||||||||||||||||
| name: 'Ubuntu SSL tests with OpenSSL' | ||||||||||||||||||||||||||||
| runs-on: ${{ matrix.os }} | ||||||||||||||||||||||||||||
| build-ubuntu-ssltests: | ||||||||||||||||||||||||||||
| name: 'Ubuntu SSL tests' | ||||||||||||||||||||||||||||
| runs-on: ubuntu-24.04 | ||||||||||||||||||||||||||||
| timeout-minutes: 60 | ||||||||||||||||||||||||||||
| needs: build-context | ||||||||||||||||||||||||||||
| if: needs.build-context.outputs.run-ubuntu == 'true' | ||||||||||||||||||||||||||||
| strategy: | ||||||||||||||||||||||||||||
| fail-fast: false | ||||||||||||||||||||||||||||
| matrix: | ||||||||||||||||||||||||||||
| os: [ubuntu-24.04] | ||||||||||||||||||||||||||||
| # Keep 1.1.1w in our list despite it being upstream EOL and otherwise | ||||||||||||||||||||||||||||
| # unsupported as it most resembles other 1.1.1-work-a-like ssl APIs | ||||||||||||||||||||||||||||
| # supported by important vendors such as AWS-LC. | ||||||||||||||||||||||||||||
| openssl_ver: [1.1.1w, 3.0.19, 3.3.6, 3.4.4, 3.5.5, 3.6.1] | ||||||||||||||||||||||||||||
| include: | ||||||||||||||||||||||||||||
| # Keep 1.1.1w in our list despite it being upstream EOL and otherwise | ||||||||||||||||||||||||||||
| # unsupported as it most resembles other 1.1.1-work-a-like ssl APIs | ||||||||||||||||||||||||||||
| # supported by important vendors such as AWS-LC. | ||||||||||||||||||||||||||||
| - { ssl: openssl, ssl_ver: 1.1.1w } | ||||||||||||||||||||||||||||
| - { ssl: openssl, ssl_ver: 3.0.19 } | ||||||||||||||||||||||||||||
| - { ssl: openssl, ssl_ver: 3.3.6 } | ||||||||||||||||||||||||||||
| - { ssl: openssl, ssl_ver: 3.4.4 } | ||||||||||||||||||||||||||||
| - { ssl: openssl, ssl_ver: 3.5.5 } | ||||||||||||||||||||||||||||
| - { ssl: openssl, ssl_ver: 3.6.1 } | ||||||||||||||||||||||||||||
| - { ssl: awslc, ssl_ver: 1.55.0 } | ||||||||||||||||||||||||||||
| # See Tools/ssl/make_ssl_data.py for notes on adding a new version | ||||||||||||||||||||||||||||
| env: | ||||||||||||||||||||||||||||
| OPENSSL_VER: ${{ matrix.openssl_ver }} | ||||||||||||||||||||||||||||
| MULTISSL_DIR: ${{ github.workspace }}/multissl | ||||||||||||||||||||||||||||
| OPENSSL_DIR: ${{ github.workspace }}/multissl/openssl/${{ matrix.openssl_ver }} | ||||||||||||||||||||||||||||
| LD_LIBRARY_PATH: ${{ github.workspace }}/multissl/openssl/${{ matrix.openssl_ver }}/lib | ||||||||||||||||||||||||||||
| steps: | ||||||||||||||||||||||||||||
| - uses: actions/checkout@v6 | ||||||||||||||||||||||||||||
| with: | ||||||||||||||||||||||||||||
| persist-credentials: false | ||||||||||||||||||||||||||||
| - name: Runner image version | ||||||||||||||||||||||||||||
| run: echo "IMAGE_OS_VERSION=${ImageOS}-${ImageVersion}" >> "$GITHUB_ENV" | ||||||||||||||||||||||||||||
| - name: Register gcc problem matcher | ||||||||||||||||||||||||||||
| run: echo "::add-matcher::.github/problem-matchers/gcc.json" | ||||||||||||||||||||||||||||
| - name: Install dependencies | ||||||||||||||||||||||||||||
| run: sudo ./.github/workflows/posix-deps-apt.sh | ||||||||||||||||||||||||||||
| - name: Configure OpenSSL env vars | ||||||||||||||||||||||||||||
| run: | | ||||||||||||||||||||||||||||
| echo "MULTISSL_DIR=${GITHUB_WORKSPACE}/multissl" >> "$GITHUB_ENV" | ||||||||||||||||||||||||||||
| echo "OPENSSL_DIR=${GITHUB_WORKSPACE}/multissl/openssl/${OPENSSL_VER}" >> "$GITHUB_ENV" | ||||||||||||||||||||||||||||
| echo "LD_LIBRARY_PATH=${GITHUB_WORKSPACE}/multissl/openssl/${OPENSSL_VER}/lib" >> "$GITHUB_ENV" | ||||||||||||||||||||||||||||
| - name: 'Restore OpenSSL build' | ||||||||||||||||||||||||||||
| id: cache-openssl | ||||||||||||||||||||||||||||
| uses: actions/cache@v5 | ||||||||||||||||||||||||||||
| with: | ||||||||||||||||||||||||||||
| path: ./multissl/openssl/${{ env.OPENSSL_VER }} | ||||||||||||||||||||||||||||
| key: ${{ matrix.os }}-multissl-openssl-${{ env.OPENSSL_VER }} | ||||||||||||||||||||||||||||
| - name: Install OpenSSL | ||||||||||||||||||||||||||||
| if: steps.cache-openssl.outputs.cache-hit != 'true' | ||||||||||||||||||||||||||||
| run: python3 Tools/ssl/multissltests.py --steps=library --base-directory "$MULTISSL_DIR" --openssl "$OPENSSL_VER" --system Linux | ||||||||||||||||||||||||||||
| - name: Add ccache to PATH | ||||||||||||||||||||||||||||
| run: | | ||||||||||||||||||||||||||||
| echo "PATH=/usr/lib/ccache:$PATH" >> "$GITHUB_ENV" | ||||||||||||||||||||||||||||
| - name: Configure CPython | ||||||||||||||||||||||||||||
| run: ./configure CFLAGS="-fdiagnostics-format=json" --config-cache --enable-slower-safety --with-pydebug --with-openssl="$OPENSSL_DIR" | ||||||||||||||||||||||||||||
| - name: Build CPython | ||||||||||||||||||||||||||||
| run: make -j4 | ||||||||||||||||||||||||||||
| - name: Display build info | ||||||||||||||||||||||||||||
| run: make pythoninfo | ||||||||||||||||||||||||||||
| - name: SSL tests | ||||||||||||||||||||||||||||
| run: ./python Lib/test/ssltests.py | ||||||||||||||||||||||||||||
| build-ubuntu-ssltests-awslc: | ||||||||||||||||||||||||||||
| name: 'Ubuntu SSL tests with AWS-LC' | ||||||||||||||||||||||||||||
| runs-on: ${{ matrix.os }} | ||||||||||||||||||||||||||||
| timeout-minutes: 60 | ||||||||||||||||||||||||||||
| needs: build-context | ||||||||||||||||||||||||||||
| if: needs.build-context.outputs.run-ubuntu == 'true' | ||||||||||||||||||||||||||||
| strategy: | ||||||||||||||||||||||||||||
| fail-fast: false | ||||||||||||||||||||||||||||
| matrix: | ||||||||||||||||||||||||||||
| os: [ubuntu-24.04] | ||||||||||||||||||||||||||||
| awslc_ver: [1.55.0] | ||||||||||||||||||||||||||||
| env: | ||||||||||||||||||||||||||||
| AWSLC_VER: ${{ matrix.awslc_ver}} | ||||||||||||||||||||||||||||
| SSL_VER: ${{ matrix.ssl_ver }} | ||||||||||||||||||||||||||||
| MULTISSL_DIR: ${{ github.workspace }}/multissl | ||||||||||||||||||||||||||||
| OPENSSL_DIR: ${{ github.workspace }}/multissl/aws-lc/${{ matrix.awslc_ver }} | ||||||||||||||||||||||||||||
| LD_LIBRARY_PATH: ${{ github.workspace }}/multissl/aws-lc/${{ matrix.awslc_ver }}/lib | ||||||||||||||||||||||||||||
| SSL_DIR: ${{ github.workspace }}/multissl/${{ matrix.ssl }}/${{ matrix.ssl_ver }} | ||||||||||||||||||||||||||||
| LD_LIBRARY_PATH: ${{ github.workspace }}/multissl/${{ matrix.ssl }}/${{ matrix.ssl_ver }}/lib | ||||||||||||||||||||||||||||
| steps: | ||||||||||||||||||||||||||||
| - uses: actions/checkout@v6 | ||||||||||||||||||||||||||||
| with: | ||||||||||||||||||||||||||||
| @@ -333,39 +287,40 @@ jobs: | ||||||||||||||||||||||||||||
| - name: Configure SSL lib env vars | ||||||||||||||||||||||||||||
| run: | | ||||||||||||||||||||||||||||
| echo "MULTISSL_DIR=${GITHUB_WORKSPACE}/multissl" >> "$GITHUB_ENV" | ||||||||||||||||||||||||||||
| echo "OPENSSL_DIR=${GITHUB_WORKSPACE}/multissl/aws-lc/${AWSLC_VER}" >> "$GITHUB_ENV" | ||||||||||||||||||||||||||||
| echo "LD_LIBRARY_PATH=${GITHUB_WORKSPACE}/multissl/aws-lc/${AWSLC_VER}/lib" >> "$GITHUB_ENV" | ||||||||||||||||||||||||||||
| - name: 'Restore AWS-LC build' | ||||||||||||||||||||||||||||
| id: cache-aws-lc | ||||||||||||||||||||||||||||
| echo "SSL_DIR=${GITHUB_WORKSPACE}/multissl/${{ matrix.ssl }}/${SSL_VER}" >> "$GITHUB_ENV" | ||||||||||||||||||||||||||||
| echo "LD_LIBRARY_PATH=${GITHUB_WORKSPACE}/multissl/${{ matrix.ssl }}/${SSL_VER}/lib" >> "$GITHUB_ENV" | ||||||||||||||||||||||||||||
| - name: 'Restore SSL build' | ||||||||||||||||||||||||||||
| id: cache-ssl | ||||||||||||||||||||||||||||
| uses: actions/cache@v5 | ||||||||||||||||||||||||||||
| with: | ||||||||||||||||||||||||||||
| path: ./multissl/aws-lc/${{ matrix.awslc_ver }} | ||||||||||||||||||||||||||||
| key: ${{ matrix.os }}-multissl-aws-lc-${{ matrix.awslc_ver }} | ||||||||||||||||||||||||||||
| - name: Install AWS-LC | ||||||||||||||||||||||||||||
| if: steps.cache-aws-lc.outputs.cache-hit != 'true' | ||||||||||||||||||||||||||||
| path: ./multissl/${{ env.SSL }}/${{ env.SSL_VER }} | ||||||||||||||||||||||||||||
| key: ${{ env.IMAGE_OS_VERSION }}-multissl-${{ env.SSL }}-${{ env.SSL_VER }} | ||||||||||||||||||||||||||||
| - name: Install SSL | ||||||||||||||||||||||||||||
| if: steps.cache-ssl.outputs.cache-hit != 'true' | ||||||||||||||||||||||||||||
| run: | | ||||||||||||||||||||||||||||
| python3 Tools/ssl/multissltests.py \ | ||||||||||||||||||||||||||||
| --steps=library \ | ||||||||||||||||||||||||||||
| --base-directory "$MULTISSL_DIR" \ | ||||||||||||||||||||||||||||
| --awslc ${{ matrix.awslc_ver }} \ | ||||||||||||||||||||||||||||
| --ssl ${{ matrix.ssl }} \ | ||||||||||||||||||||||||||||
| --ssl-versions ${{ matrix.ssl_ver }} \ | ||||||||||||||||||||||||||||
| --system Linux | ||||||||||||||||||||||||||||
| - name: Add ccache to PATH | ||||||||||||||||||||||||||||
| run: | | ||||||||||||||||||||||||||||
| echo "PATH=/usr/lib/ccache:$PATH" >> "$GITHUB_ENV" | ||||||||||||||||||||||||||||
| - name: Configure CPython | ||||||||||||||||||||||||||||
| run: | | ||||||||||||||||||||||||||||
| ./configure CFLAGS="-fdiagnostics-format=json" \ | ||||||||||||||||||||||||||||
| --config-cache \ | ||||||||||||||||||||||||||||
| --enable-slower-safety \ | ||||||||||||||||||||||||||||
| --with-pydebug \ | ||||||||||||||||||||||||||||
| --with-openssl="$OPENSSL_DIR" \ | ||||||||||||||||||||||||||||
| --with-builtin-hashlib-hashes=blake2 \ | ||||||||||||||||||||||||||||
| --with-ssl-default-suites=openssl | ||||||||||||||||||||||||||||
| CMD=(./configure CFLAGS="-fdiagnostics-format=json" --config-cache --enable-slower-safety --with-pydebug --with-openssl="$SSL_DIR") | ||||||||||||||||||||||||||||
| if [ "${{ matrix.ssl }}" = "openssl" ]; then | ||||||||||||||||||||||||||||
Member There was a problem hiding this comment. Choose a reason for hiding this commentThe reason will be displayed to describe this comment to others. Learn more. Remember that interpolation in GHA is dangerous and Zizmor will be unhappy — such things must go into env vars. MemberAuthor There was a problem hiding this comment. Choose a reason for hiding this commentThe reason will be displayed to describe this comment to others. Learn more. Hmm, Zizmor was happy with this: https://github.com/python/cpython/actions/runs/22004982988/job/63586538110?pr=143940#step:3:151 Perhaps this is a feature request for Zizmor? | ||||||||||||||||||||||||||||
| "${CMD[@]}" | ||||||||||||||||||||||||||||
| else | ||||||||||||||||||||||||||||
| "${CMD[@]}" --with-builtin-hashlib-hashes=blake2 --with-ssl-default-suites=openssl | ||||||||||||||||||||||||||||
| fi | ||||||||||||||||||||||||||||
Comment on lines
+312
to
+317
| ||||||||||||||||||||||||||||
| CMD=(./configure CFLAGS="-fdiagnostics-format=json" --config-cache --enable-slower-safety --with-pydebug --with-openssl="$SSL_DIR") | |
| if [ "${{ matrix.ssl }}" = "openssl" ]; then | |
| "${CMD[@]}" | |
| else | |
| "${CMD[@]}"--with-builtin-hashlib-hashes=blake2 --with-ssl-default-suites=openssl | |
| fi | |
| ./configure | |
| CFLAGS="-fdiagnostics-format=json" | |
| --config-cache | |
| --enable-slower-safety | |
| --with-pydebug | |
| --with-openssl="$SSL_DIR" | |
| ${CONFIGURE_TRAILING_ARGS} |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
I prefer the if/else approach. I do not like the notion of 'trailing' args.
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Then the steps would need to be separate so the logs are usable/inspectable and it's surfaced.
| Original file line number | Diff line number | Diff line change | ||||
|---|---|---|---|---|---|---|
| @@ -57,7 +57,7 @@ jobs: | ||||||
| key: ${{ inputs.os }}-multissl-openssl-${{ env.OPENSSL_VER }} | ||||||
| - name: Install OpenSSL | ||||||
| if: steps.cache-openssl.outputs.cache-hit != 'true' | ||||||
| run: python3 Tools/ssl/multissltests.py --steps=library --base-directory "$MULTISSL_DIR" --openssl "$OPENSSL_VER" --system Linux | ||||||
| run: python3 Tools/ssl/multissltests.py --steps=library --base-directory "$MULTISSL_DIR" --ssl openssl --ssl-versions "$OPENSSL_VER" --system Linux | ||||||
Member There was a problem hiding this comment. Choose a reason for hiding this commentThe reason will be displayed to describe this comment to others. Learn more. I think a better UX would be something like
Suggested change
since the project and its version are coupled (maybe use | ||||||
| - name: Add ccache to PATH | ||||||
| run: | | ||||||
| echo "PATH=/usr/lib/ccache:$PATH" >> "$GITHUB_ENV" | ||||||
Uh oh!
There was an error while loading. Please reload this page.
Uh oh!
There was an error while loading. Please reload this page.
Uh oh!
There was an error while loading. Please reload this page.