ci: enable pre-release workflow with dispatch #709
Workflow file for this run
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
| # | |
| # Copyright (c) 2025, Trail of Bits, Inc. | |
| # | |
| # This source code is licensed in accordance with the terms specified in | |
| # the LICENSE file found in the root directory of this source tree. | |
| # | |
| name: CI | |
| on: | |
| push: | |
| branches: | |
| - 'main' | |
| tags: | |
| - '*' | |
| pull_request: | |
| branches: | |
| - '*' | |
| jobs: | |
| ghidra-script-tests: | |
| strategy: | |
| matrix: | |
| image-version: [22.04] | |
| runs-on: ubuntu-${{ matrix.image-version }} | |
| timeout-minutes: 30 | |
| env: | |
| CI: true | |
| steps: | |
| - name: Clone the Patchestry repository | |
| uses: actions/checkout@v4 | |
| with: | |
| submodules: true | |
| fetch-depth: 1 | |
| - name: Build the Ghidra testing Docker image and run tests via Gradle | |
| run: | | |
| DOCKER_BUILDKIT=1 docker build -t trailofbits/decompile-test:latest -f test/decompile-test.dockerfile . && \ | |
| docker run trailofbits/decompile-test | |
| - name: Clean up Docker artifacts | |
| if: always() | |
| run: | | |
| docker system prune -af --volumes | |
| llvm-build-and-test: | |
| strategy: | |
| matrix: | |
| llvm-version: [20] | |
| image-version: [22.04] | |
| build-type: [Release, Debug] | |
| sanitizers: [OFF] | |
| runs-on: ubuntu-${{ matrix.image-version }} | |
| timeout-minutes: 30 | |
| container: | |
| image: | |
| ghcr.io/lifting-bits/patchestry-ubuntu-${{ matrix.image-version }}-llvm-${{ matrix.llvm-version }}-dev:latest | |
| services: | |
| docker: | |
| image: docker:20.10-dind | |
| options: --privileged | |
| ports: | |
| - 12375:2375 | |
| env: | |
| CMAKE_PREFIX_PATH: "/usr/lib/llvm-${{ matrix.llvm-version }}/lib/cmake/mlir/;/usr/lib/llvm-${{ matrix.llvm-version }}/lib/cmake/clang/" | |
| LLVM_EXTERNAL_LIT: "/usr/local/bin/lit" | |
| ENABLE_SANITIZER_UNDEFINED_BEHAVIOR: ${{ matrix.sanitizers }} | |
| ENABLE_SANITIZER_ADDRESS: ${{ matrix.sanitizers }} | |
| CI: true | |
| steps: | |
| - name: Clone the Patchestry repository | |
| uses: actions/checkout@v4 | |
| with: | |
| submodules: true | |
| fetch-depth: 1 | |
| - name: Free up disk space | |
| run: | | |
| docker volume prune -f || true | |
| docker system prune -af --volumes || true | |
| sudo apt-get clean || true | |
| sudo rm -rf /var/lib/apt/lists/* /tmp/* /var/tmp/* | |
| rm -rf /gha-runner/usr/local/lib/android | |
| rm -rf /gha-runner/usr/local/share/boost | |
| df -h | |
| - name: Configure build - sanitizers ${{ matrix.sanitizers }} | |
| run: cmake --preset ci -DPE_USE_VENDORED_Z3=OFF -DLLVM_EXTERNAL_LIT=$(which lit) -DLLVM_Z3_INSTALL_DIR=/usr/local | |
| - name: Build ${{ matrix.build-type }} with sanitizers set ${{ matrix.sanitizers }} | |
| run: cmake --build --preset ci --config ${{ matrix.build-type }} -j$(nproc) | |
| - name: Build the intrinsic library | |
| run: | | |
| cd lib/patchestry/intrinsics | |
| cmake -B build_standalone -DCMAKE_BUILD_TYPE=Release | |
| cmake --build build_standalone -j$(nproc) | |
| cd - | |
| - name: Build the headless decompilation docker image | |
| run: | | |
| bash ./scripts/ghidra/build-headless-docker.sh | |
| - name: Test ${{ matrix.build-type }} with sanitizers set ${{ matrix.sanitizers }} | |
| run: | | |
| lit ./builds/ci/test -D BUILD_TYPE=${{ matrix.build-type }} -v -DCI_OUTPUT_FOLDER=${{ github.workspace }}/builds/ci/test/ghidra/Output |