Skip to content

ci: enable pre-release workflow with dispatch #710

ci: enable pre-release workflow with dispatch

ci: enable pre-release workflow with dispatch #710

Workflow file for this run

#
# Copyright (c) 2025, Trail of Bits, Inc.
#
# This source code is licensed in accordance with the terms specified in
# the LICENSE file found in the root directory of this source tree.
#
name: CI
on:
push:
branches:
- 'main'
tags:
- '*'
pull_request:
branches:
- '*'
jobs:
ghidra-script-tests:
strategy:
matrix:
image-version: [22.04]
runs-on: ubuntu-${{ matrix.image-version }}
timeout-minutes: 30
env:
CI: true
steps:
- name: Clone the Patchestry repository
uses: actions/checkout@v4
with:
submodules: true
fetch-depth: 1
- name: Build the Ghidra testing Docker image and run tests via Gradle
run: |
DOCKER_BUILDKIT=1 docker build -t trailofbits/decompile-test:latest -f test/decompile-test.dockerfile . && \
docker run trailofbits/decompile-test
- name: Clean up Docker artifacts
if: always()
run: |
docker system prune -af --volumes
llvm-build-and-test:
strategy:
matrix:
llvm-version: [20]
image-version: [22.04]
build-type: [Release, Debug]
sanitizers: [OFF]
runs-on: ubuntu-${{ matrix.image-version }}
timeout-minutes: 30
container:
image:
ghcr.io/lifting-bits/patchestry-ubuntu-${{ matrix.image-version }}-llvm-${{ matrix.llvm-version }}-dev:latest
services:
docker:
image: docker:20.10-dind
options: --privileged
ports:
- 12375:2375
env:
CMAKE_PREFIX_PATH: "/usr/lib/llvm-${{ matrix.llvm-version }}/lib/cmake/mlir/;/usr/lib/llvm-${{ matrix.llvm-version }}/lib/cmake/clang/"
LLVM_EXTERNAL_LIT: "/usr/local/bin/lit"
ENABLE_SANITIZER_UNDEFINED_BEHAVIOR: ${{ matrix.sanitizers }}
ENABLE_SANITIZER_ADDRESS: ${{ matrix.sanitizers }}
CI: true
steps:
- name: Clone the Patchestry repository
uses: actions/checkout@v4
with:
submodules: true
fetch-depth: 1
- name: Free up disk space
run: |
docker volume prune -f || true
docker system prune -af --volumes || true
sudo apt-get clean || true
sudo rm -rf /var/lib/apt/lists/* /tmp/* /var/tmp/*
rm -rf /gha-runner/usr/local/lib/android
rm -rf /gha-runner/usr/local/share/boost
df -h
- name: Configure build - sanitizers ${{ matrix.sanitizers }}
run: cmake --preset ci -DPE_USE_VENDORED_Z3=OFF -DLLVM_EXTERNAL_LIT=$(which lit) -DLLVM_Z3_INSTALL_DIR=/usr/local
- name: Build ${{ matrix.build-type }} with sanitizers set ${{ matrix.sanitizers }}
run: cmake --build --preset ci --config ${{ matrix.build-type }} -j$(nproc)
- name: Build the intrinsic library
run: |
cd lib/patchestry/intrinsics
cmake -B build_standalone -DCMAKE_BUILD_TYPE=Release
cmake --build build_standalone -j$(nproc)
cd -
- name: Build the headless decompilation docker image
run: |
bash ./scripts/ghidra/build-headless-docker.sh
- name: Test ${{ matrix.build-type }} with sanitizers set ${{ matrix.sanitizers }}
run: |
lit ./builds/ci/test -D BUILD_TYPE=${{ matrix.build-type }} -v -DCI_OUTPUT_FOLDER=${{ github.workspace }}/builds/ci/test/ghidra/Output