Full validation #53
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
| name: Full validation | |
| on: | |
| push: | |
| branches: | |
| - main | |
| schedule: | |
| - cron: "17 3 * * *" | |
| release: | |
| types: | |
| - published | |
| workflow_dispatch: | |
| permissions: | |
| contents: read | |
| concurrency: | |
| group: full-validation-${{ github.event_name }}-${{ github.ref }} | |
| cancel-in-progress: true | |
| jobs: | |
| go: | |
| name: Go checks | |
| runs-on: ubuntu-latest | |
| timeout-minutes: 20 | |
| steps: | |
| - name: Check out repo | |
| uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 | |
| - name: Set up Go | |
| uses: actions/setup-go@b7ad1dad31e06c5925ef5d2fc7ad053ef454303e # v7.0.0 | |
| with: | |
| go-version-file: go.mod | |
| cache: true | |
| - name: Check formatting | |
| run: | | |
| files="$(gofmt -l .)" | |
| if [ -n "$files" ]; then | |
| echo "Go files need gofmt:" | |
| echo "$files" | |
| exit 1 | |
| fi | |
| - name: Check module tidiness | |
| run: | | |
| go mod tidy | |
| git diff --exit-code -- go.mod go.sum | |
| - name: Run go vet | |
| run: go vet ./... | |
| - name: Scan reachable Go vulnerabilities | |
| run: go run golang.org/x/vuln/cmd/govulncheck@v1.6.0 ./... | |
| - name: Run tests | |
| run: go test ./... | |
| kernel-race: | |
| name: Kernel race tests | |
| runs-on: ubuntu-latest | |
| timeout-minutes: 20 | |
| steps: | |
| - name: Check out repo | |
| uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 | |
| - name: Set up Go | |
| uses: actions/setup-go@b7ad1dad31e06c5925ef5d2fc7ad053ef454303e # v7.0.0 | |
| with: | |
| go-version-file: go.mod | |
| cache: true | |
| - name: Run kernel tests with the race detector | |
| run: go test -race -count=1 ./internal/kernel/... | |
| gatemolebench: | |
| name: GatemoleBench acceptance | |
| runs-on: ubuntu-latest | |
| timeout-minutes: 15 | |
| steps: | |
| - name: Check out repo | |
| uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 | |
| - name: Set up Go | |
| uses: actions/setup-go@b7ad1dad31e06c5925ef5d2fc7ad053ef454303e # v7.0.0 | |
| with: | |
| go-version-file: go.mod | |
| cache: true | |
| - name: Run GatemoleBench | |
| run: scripts/gatemolebench.sh --out /tmp/gatemolebench | |
| - name: Add benchmark summary | |
| if: always() | |
| run: | | |
| if [ -f /tmp/gatemolebench/gatemolebench.latest.md ]; then | |
| cat /tmp/gatemolebench/gatemolebench.latest.md >> "$GITHUB_STEP_SUMMARY" | |
| fi | |
| - name: Upload benchmark artifacts | |
| if: always() | |
| uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1 | |
| with: | |
| name: gatemolebench-results | |
| path: /tmp/gatemolebench | |
| if-no-files-found: ignore | |
| kernelbench: | |
| name: GatemoleKernelBench acceptance | |
| runs-on: ubuntu-latest | |
| timeout-minutes: 15 | |
| steps: | |
| - name: Check out repo | |
| uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 | |
| - name: Set up Go | |
| uses: actions/setup-go@b7ad1dad31e06c5925ef5d2fc7ad053ef454303e # v7.0.0 | |
| with: | |
| go-version-file: go.mod | |
| cache: true | |
| - name: Run GatemoleKernelBench | |
| run: scripts/gatemolekernelbench.sh --out /tmp/gatemolekernelbench | |
| - name: Add benchmark summary | |
| if: always() | |
| run: | | |
| if [ -f /tmp/gatemolekernelbench/gatemolekernelbench.latest.md ]; then | |
| cat /tmp/gatemolekernelbench/gatemolekernelbench.latest.md >> "$GITHUB_STEP_SUMMARY" | |
| fi | |
| - name: Upload benchmark artifacts | |
| if: always() | |
| uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1 | |
| with: | |
| name: gatemolekernelbench-results | |
| path: /tmp/gatemolekernelbench | |
| if-no-files-found: ignore | |
| transactionbench: | |
| name: GatemoleTransactionBench acceptance | |
| runs-on: ubuntu-latest | |
| timeout-minutes: 15 | |
| steps: | |
| - name: Check out repo | |
| uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 | |
| - name: Set up Go | |
| uses: actions/setup-go@b7ad1dad31e06c5925ef5d2fc7ad053ef454303e # v7.0.0 | |
| with: | |
| go-version-file: go.mod | |
| cache: true | |
| - name: Verify benchmark dependencies | |
| run: | | |
| command -v git | |
| command -v jq | |
| - name: Run GatemoleTransactionBench | |
| run: scripts/gatemoletransactionbench.sh | |
| runtimebench: | |
| name: GatemoleRuntimeBench acceptance | |
| runs-on: ubuntu-latest | |
| timeout-minutes: 15 | |
| steps: | |
| - name: Check out repo | |
| uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 | |
| - name: Set up Go | |
| uses: actions/setup-go@b7ad1dad31e06c5925ef5d2fc7ad053ef454303e # v7.0.0 | |
| with: | |
| go-version-file: go.mod | |
| cache: true | |
| - name: Verify benchmark dependencies | |
| run: | | |
| command -v git | |
| command -v jq | |
| - name: Run GatemoleRuntimeBench | |
| run: scripts/gatemoleruntimebench.sh | |
| production-acceptance: | |
| name: Production OCI acceptance | |
| runs-on: ubuntu-latest | |
| timeout-minutes: 30 | |
| steps: | |
| - name: Check out repo | |
| uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 | |
| - name: Set up Go | |
| uses: actions/setup-go@b7ad1dad31e06c5925ef5d2fc7ad053ef454303e # v7.0.0 | |
| with: | |
| go-version-file: go.mod | |
| cache: true | |
| - name: Verify Docker | |
| run: | | |
| docker version | |
| command -v curl | |
| command -v jq | |
| - name: Build local production fixture image | |
| id: fixture | |
| run: | | |
| image="$(scripts/gatemoleproductionfixture.sh --tag "gatemole-production-fixture:${GITHUB_SHA}")" | |
| echo "image=$image" >> "$GITHUB_OUTPUT" | |
| - name: Run production acceptance | |
| env: | |
| GATEMOLE_PRODUCTION_IMAGE: ${{ steps.fixture.outputs.image }} | |
| run: scripts/gatemoleproductionbench.sh | |
| - name: Run paired execution recovery demo | |
| run: scripts/gatemolepairedexecutiondemo.sh | |
| skylos: | |
| name: Skylos advisory | |
| runs-on: ubuntu-latest | |
| continue-on-error: true | |
| steps: | |
| - name: Check out repo | |
| uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 | |
| - name: Set up Python | |
| uses: actions/setup-python@5fda3b95a4ea91299a34e894583c3862153e4b97 # v7.0.0 | |
| with: | |
| python-version: "3.13" | |
| - name: Install Skylos | |
| continue-on-error: true | |
| run: python -m pip install --upgrade skylos | |
| - name: Run advisory scan | |
| continue-on-error: true | |
| run: | | |
| skylos . \ | |
| --all \ | |
| --severity high \ | |
| --github \ | |
| --summary \ | |
| --sarif skylos.sarif.json \ | |
| --no-upload \ | |
| --force \ | |
| --limit 50 | |
| - name: Upload Skylos SARIF artifact | |
| if: always() | |
| uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1 | |
| with: | |
| name: skylos-sarif | |
| path: skylos.sarif.json | |
| if-no-files-found: ignore |