penguin/tinyproxy

An L4 proxy designed to act as a tiny transparent shim

.github/workflows/cmake-multi-platform.yml

raw ยท 8925 bytes

name: tinyproxy CI

on:
  workflow_dispatch:
  push:
    branches: ["main"]
    tags: ["v*"]
  pull_request:
    branches: ["main"]

concurrency:
  group: tinyproxy-${{ github.ref }}
  cancel-in-progress: false

env:
  ARTIFACT_RETENTION_DAYS: 30

jobs:
  linux-musl-x86_64:
    name: Linux musl x86_64 static
    runs-on: ubuntu-latest
    container:
      image: &alpine_image alpine:3.23

    steps:
      - &checkout
        uses: actions/checkout@v4

      - &install_linux_deps
        name: Install deps
        run: |
          apk add --no-cache \
            build-base \
            libevent-dev \
            libevent-static \
            python3 \
            strace \
            haproxy

      - &build_static
        name: Build
        shell: sh
        run: |
          set -eu

          mkdir -p dist/debug dist/prod

          make clean all CFLAGS="-Og -g3 -Wall -Wextra -Wpedantic" LDFLAGS=""
          cp bin/tinyproxy dist/debug/tinyproxy

          make clean all
          cp bin/tinyproxy dist/prod/tinyproxy
          strip dist/prod/tinyproxy

      - &verify_static
        name: Verify static binary
        shell: sh
        run: |
          set -eu

          apk add --no-cache pax-utils

          file dist/prod/tinyproxy
          scanelf -n dist/prod/tinyproxy

          if scanelf -n dist/prod/tinyproxy | grep -q 'lib'; then
            echo "prod binary has dynamic library dependencies"
            exit 1
          fi

          file dist/debug/tinyproxy
          scanelf -n dist/debug/tinyproxy

          if scanelf -n dist/debug/tinyproxy | grep -q 'lib'; then
            echo "debug binary has dynamic library dependencies"
            exit 1
          fi

      - &test
        name: Test
        run: make test

      - &package_name
        name: Set package names
        shell: sh
        run: |
          os="$(printf '%s' '${{ runner.os }}' | tr '[:upper:]' '[:lower:]')"
          arch="$(printf '%s' '${{ runner.arch }}' | tr '[:upper:]' '[:lower:]')"

          echo "TINYPROXY_PACKAGE=tinyproxy-${os}-${arch}" >> "$GITHUB_ENV"

      - &package_unix
        name: Package artifact
        shell: sh
        run: |
          mkdir -p dist/tinyproxy
          cp dist/prod/tinyproxy dist/tinyproxy/
          cp -r examples dist/tinyproxy/

          tar -C dist -czf "${TINYPROXY_PACKAGE}.tar.gz" tinyproxy

          mkdir -p dist/tinyproxy-debug
          cp dist/debug/tinyproxy dist/tinyproxy-debug/
          cp -r examples dist/tinyproxy-debug/

          tar -C dist -czf "${TINYPROXY_PACKAGE}-debug.tar.gz" tinyproxy-debug

      - &upload_unix
        name: Upload artifacts
        uses: actions/upload-artifact@v4
        with:
          name: ${{ env.TINYPROXY_PACKAGE }}
          path: |
            ${{ env.TINYPROXY_PACKAGE }}.tar.gz
            ${{ env.TINYPROXY_PACKAGE }}-debug.tar.gz
          if-no-files-found: error
          retention-days: ${{ env.ARTIFACT_RETENTION_DAYS }}

  linux-musl-arm64:
    name: Linux musl arm64 static
    runs-on: ubuntu-24.04-arm
    container:
      image: *alpine_image

    permissions:
      contents: read

    steps:
      - uses: laverdet/alpine-arm64@7f0f72ee2f71eb2324e5888e8b6e42b1b53e6160
        if: runner.arch == 'ARM64'

      - *checkout
      - *install_linux_deps
      - *build_static
      - *verify_static
      - *test
      - *package_name
      - *package_unix
      - *upload_unix

  macos:
    name: macOS build
    runs-on: macos-15

    steps:
      - *checkout

      - name: Install deps
        run: |
          brew update
          brew install libevent haproxy

      - name: Build
        run: make clean all STATIC=0

      - *test
      - *package_name
      - *package_unix
      - *upload_unix

  windows:
    name: Windows build
    runs-on: windows-2022
    continue-on-error: true

    steps:
      - *checkout

      - name: Set up MSYS2
        uses: msys2/setup-msys2@v2
        with:
          msystem: UCRT64
          update: true
          install: >-
            base-devel
            mingw-w64-ucrt-x86_64-gcc
            mingw-w64-ucrt-x86_64-pkgconf
            mingw-w64-ucrt-x86_64-libevent
            mingw-w64-ucrt-x86_64-python

      - name: Build
        shell: msys2 {0}
        run: |
          make clean
          make all

      - name: Test
        shell: msys2 {0}
        run: make test

      - name: Package artifact
        shell: msys2 {0}
        run: |
          mkdir -p dist/tinyproxy

          if [ -f bin/tinyproxy.exe ]; then
            cp bin/tinyproxy.exe dist/tinyproxy/
          else
            cp bin/tinyproxy dist/tinyproxy/tinyproxy.exe
          fi

          cp tinyproxy.conf dist/tinyproxy/

          powershell.exe -NoProfile -Command \
            "Compress-Archive -Path dist/tinyproxy -DestinationPath tinyproxy-windows-x64.zip -Force"

      - name: Upload CI artifact
        uses: actions/upload-artifact@v4
        with:
          name: tinyproxy-windows-x64
          path: tinyproxy-windows-x64.zip
          if-no-files-found: error
          retention-days: ${{ env.ARTIFACT_RETENTION_DAYS }}

  release:
    name: GitHub Release
    runs-on: ubuntu-latest

    if: startsWith(github.ref, 'refs/tags/v')

    needs:
      - linux-musl-x86_64
      - linux-musl-arm64
      - macos
      - windows

    permissions:
      contents: write

    steps:
      - name: Download CI artifacts
        uses: actions/download-artifact@v4
        with:
          path: release-assets
          pattern: tinyproxy-*
          merge-multiple: true

      - name: Show release assets
        run: |
          find release-assets -type f -maxdepth 2 -print

      - name: Create GitHub Release
        env:
          GH_TOKEN: ${{ github.token }}
          GH_REPO: ${{ github.repository }}
        run: |
          set -eu

          tag="${GITHUB_REF_NAME}"

          if ! gh release view "$tag" >/dev/null 2>&1; then
            gh release create "$tag" \
              --title "$tag" \
              --generate-notes
          fi

          echo "Assets currently on release:"
          gh release view "$tag" --json assets --jq '.assets[].name'

          for asset in release-assets/*; do
            name="$(basename "$asset")"

            existing="$(
              gh release view "$tag" --json assets --jq '.assets[].name' |
                awk -v target="$name" 'tolower($0) == tolower(target) { print; exit }'
            )"

            if [ -n "$existing" ]; then
              echo "Deleting existing release asset: $existing"
              gh release delete-asset "$tag" "$existing" -y
            fi

            echo "Uploading release asset: $name"
            gh release upload "$tag" "$asset"
          done

  docker:
    name: Docker image
    runs-on: ubuntu-latest

    if: startsWith(github.ref, 'refs/tags/v')

    needs:
      - linux-musl-x86_64
      - linux-musl-arm64

    permissions:
      contents: read
      packages: write

    steps:
      - uses: actions/checkout@v4

      - name: Download Linux artifacts
        uses: actions/download-artifact@v4
        with:
          path: docker-artifacts
          pattern: tinyproxy-linux-*
          merge-multiple: true

      - name: Prepare Docker rootfs
        run: |
          mkdir -p rootfs-amd64 rootfs-arm64

          mkdir -p tmp/amd64 tmp/arm64

          tar -xzf docker-artifacts/tinyproxy-linux-x64.tar.gz -C tmp/amd64
          tar -xzf docker-artifacts/tinyproxy-linux-arm64.tar.gz -C tmp/arm64

          mkdir -p rootfs-amd64/usr/bin rootfs-amd64/etc
          mkdir -p rootfs-arm64/usr/bin rootfs-arm64/etc

          cp tmp/amd64/tinyproxy/tinyproxy rootfs-amd64/usr/bin/tinyproxy

          cp tmp/arm64/tinyproxy/tinyproxy rootfs-arm64/usr/bin/tinyproxy

          chmod 0755 rootfs-amd64/usr/bin/tinyproxy
          chmod 0755 rootfs-arm64/usr/bin/tinyproxy

          file rootfs-amd64/usr/bin/tinyproxy
          file rootfs-arm64/usr/bin/tinyproxy

      - name: Set image name
        run: |
          image="ghcr.io/${GITHUB_REPOSITORY}"
          echo "IMAGE_NAME=${image,,}" >> "$GITHUB_ENV"

      - name: Set up Docker Buildx
        uses: docker/setup-buildx-action@v4

      - name: Login to GHCR
        uses: docker/login-action@v4
        with:
          registry: ghcr.io
          username: ${{ github.actor }}
          password: ${{ github.token }}

      - name: Build and push image
        uses: docker/build-push-action@v7
        with:
          context: .
          file: ./github.Dockerfile
          platforms: linux/amd64,linux/arm64
          push: true
          tags: |
            ${{ env.IMAGE_NAME }}:${{ github.ref_name }}
          labels: |
            org.opencontainers.image.source=${{ github.server_url }}/${{ github.repository }}
            org.opencontainers.image.version=${{ github.ref_name }}
            org.opencontainers.image.revision=${{ github.sha }}