Skip to content

Full validation

Full validation #53

Workflow file for this run

name: Full validation
on:
push:
branches:
- main
schedule:
- cron: "17 3 * * *"
release:
types:
- published
workflow_dispatch:
permissions:
contents: read
concurrency:
group: full-validation-${{ github.event_name }}-${{ github.ref }}
cancel-in-progress: true
jobs:
go:
name: Go checks
runs-on: ubuntu-latest
timeout-minutes: 20
steps:
- name: Check out repo
uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
- name: Set up Go
uses: actions/setup-go@b7ad1dad31e06c5925ef5d2fc7ad053ef454303e # v7.0.0
with:
go-version-file: go.mod
cache: true
- name: Check formatting
run: |
files="$(gofmt -l .)"
if [ -n "$files" ]; then
echo "Go files need gofmt:"
echo "$files"
exit 1
fi
- name: Check module tidiness
run: |
go mod tidy
git diff --exit-code -- go.mod go.sum
- name: Run go vet
run: go vet ./...
- name: Scan reachable Go vulnerabilities
run: go run golang.org/x/vuln/cmd/govulncheck@v1.6.0 ./...
- name: Run tests
run: go test ./...
kernel-race:
name: Kernel race tests
runs-on: ubuntu-latest
timeout-minutes: 20
steps:
- name: Check out repo
uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
- name: Set up Go
uses: actions/setup-go@b7ad1dad31e06c5925ef5d2fc7ad053ef454303e # v7.0.0
with:
go-version-file: go.mod
cache: true
- name: Run kernel tests with the race detector
run: go test -race -count=1 ./internal/kernel/...
gatemolebench:
name: GatemoleBench acceptance
runs-on: ubuntu-latest
timeout-minutes: 15
steps:
- name: Check out repo
uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
- name: Set up Go
uses: actions/setup-go@b7ad1dad31e06c5925ef5d2fc7ad053ef454303e # v7.0.0
with:
go-version-file: go.mod
cache: true
- name: Run GatemoleBench
run: scripts/gatemolebench.sh --out /tmp/gatemolebench
- name: Add benchmark summary
if: always()
run: |
if [ -f /tmp/gatemolebench/gatemolebench.latest.md ]; then
cat /tmp/gatemolebench/gatemolebench.latest.md >> "$GITHUB_STEP_SUMMARY"
fi
- name: Upload benchmark artifacts
if: always()
uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1
with:
name: gatemolebench-results
path: /tmp/gatemolebench
if-no-files-found: ignore
kernelbench:
name: GatemoleKernelBench acceptance
runs-on: ubuntu-latest
timeout-minutes: 15
steps:
- name: Check out repo
uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
- name: Set up Go
uses: actions/setup-go@b7ad1dad31e06c5925ef5d2fc7ad053ef454303e # v7.0.0
with:
go-version-file: go.mod
cache: true
- name: Run GatemoleKernelBench
run: scripts/gatemolekernelbench.sh --out /tmp/gatemolekernelbench
- name: Add benchmark summary
if: always()
run: |
if [ -f /tmp/gatemolekernelbench/gatemolekernelbench.latest.md ]; then
cat /tmp/gatemolekernelbench/gatemolekernelbench.latest.md >> "$GITHUB_STEP_SUMMARY"
fi
- name: Upload benchmark artifacts
if: always()
uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1
with:
name: gatemolekernelbench-results
path: /tmp/gatemolekernelbench
if-no-files-found: ignore
transactionbench:
name: GatemoleTransactionBench acceptance
runs-on: ubuntu-latest
timeout-minutes: 15
steps:
- name: Check out repo
uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
- name: Set up Go
uses: actions/setup-go@b7ad1dad31e06c5925ef5d2fc7ad053ef454303e # v7.0.0
with:
go-version-file: go.mod
cache: true
- name: Verify benchmark dependencies
run: |
command -v git
command -v jq
- name: Run GatemoleTransactionBench
run: scripts/gatemoletransactionbench.sh
runtimebench:
name: GatemoleRuntimeBench acceptance
runs-on: ubuntu-latest
timeout-minutes: 15
steps:
- name: Check out repo
uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
- name: Set up Go
uses: actions/setup-go@b7ad1dad31e06c5925ef5d2fc7ad053ef454303e # v7.0.0
with:
go-version-file: go.mod
cache: true
- name: Verify benchmark dependencies
run: |
command -v git
command -v jq
- name: Run GatemoleRuntimeBench
run: scripts/gatemoleruntimebench.sh
production-acceptance:
name: Production OCI acceptance
runs-on: ubuntu-latest
timeout-minutes: 30
steps:
- name: Check out repo
uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
- name: Set up Go
uses: actions/setup-go@b7ad1dad31e06c5925ef5d2fc7ad053ef454303e # v7.0.0
with:
go-version-file: go.mod
cache: true
- name: Verify Docker
run: |
docker version
command -v curl
command -v jq
- name: Build local production fixture image
id: fixture
run: |
image="$(scripts/gatemoleproductionfixture.sh --tag "gatemole-production-fixture:${GITHUB_SHA}")"
echo "image=$image" >> "$GITHUB_OUTPUT"
- name: Run production acceptance
env:
GATEMOLE_PRODUCTION_IMAGE: ${{ steps.fixture.outputs.image }}
run: scripts/gatemoleproductionbench.sh
- name: Run paired execution recovery demo
run: scripts/gatemolepairedexecutiondemo.sh
skylos:
name: Skylos advisory
runs-on: ubuntu-latest
continue-on-error: true
steps:
- name: Check out repo
uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
- name: Set up Python
uses: actions/setup-python@5fda3b95a4ea91299a34e894583c3862153e4b97 # v7.0.0
with:
python-version: "3.13"
- name: Install Skylos
continue-on-error: true
run: python -m pip install --upgrade skylos
- name: Run advisory scan
continue-on-error: true
run: |
skylos . \
--all \
--severity high \
--github \
--summary \
--sarif skylos.sarif.json \
--no-upload \
--force \
--limit 50
- name: Upload Skylos SARIF artifact
if: always()
uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1
with:
name: skylos-sarif
path: skylos.sarif.json
if-no-files-found: ignore