mirror of
https://github.com/speed47/spectre-meltdown-checker.git
synced 2026-04-01 12:47:07 +02:00
95 lines
3.0 KiB
YAML
95 lines
3.0 KiB
YAML
name: dev-build
|
|
|
|
on:
|
|
push:
|
|
branches:
|
|
- dev
|
|
|
|
jobs:
|
|
dev-build:
|
|
|
|
runs-on: ubuntu-latest
|
|
|
|
steps:
|
|
- uses: actions/checkout@v6
|
|
with:
|
|
persist-credentials: true
|
|
- name: install prerequisites
|
|
run: sudo apt-get update && sudo apt-get install -y shellcheck shfmt jq sqlite3 iucode-tool make
|
|
- name: build and check
|
|
run: make build fmt-check shellcheck
|
|
- name: check direct execution
|
|
run: |
|
|
expected=$(cat .github/workflows/expected_cve_count)
|
|
nb=$(sudo ./spectre-meltdown-checker.sh --batch json | jq '.[]|.CVE' | wc -l)
|
|
if [ "$nb" -ne "$expected" ]; then
|
|
echo "Invalid number of CVEs reported: $nb instead of $expected"
|
|
exit 1
|
|
else
|
|
echo "OK $nb CVEs reported"
|
|
fi
|
|
- name: check docker compose run execution
|
|
run: |
|
|
expected=$(cat .github/workflows/expected_cve_count)
|
|
docker compose build
|
|
nb=$(docker compose run --rm spectre-meltdown-checker --batch json | jq '.[]|.CVE' | wc -l)
|
|
if [ "$nb" -ne "$expected" ]; then
|
|
echo "Invalid number of CVEs reported: $nb instead of $expected"
|
|
exit 1
|
|
else
|
|
echo "OK $nb CVEs reported"
|
|
fi
|
|
- name: check docker run execution
|
|
run: |
|
|
expected=$(cat .github/workflows/expected_cve_count)
|
|
docker build -t spectre-meltdown-checker .
|
|
nb=$(docker run --rm --privileged -v /boot:/boot:ro -v /dev/cpu:/dev/cpu:ro -v /lib/modules:/lib/modules:ro spectre-meltdown-checker --batch json | jq '.[]|.CVE' | wc -l)
|
|
if [ "$nb" -ne "$expected" ]; then
|
|
echo "Invalid number of CVEs reported: $nb instead of $expected"
|
|
exit 1
|
|
else
|
|
echo "OK $nb CVEs reported"
|
|
fi
|
|
- name: check fwdb update (separated)
|
|
run: |
|
|
nbtmp1=$(find /tmp 2>/dev/null | wc -l)
|
|
./spectre-meltdown-checker.sh --update-fwdb; ret=$?
|
|
if [ "$ret" != 0 ]; then
|
|
echo "Non-zero return value: $ret"
|
|
exit 1
|
|
fi
|
|
nbtmp2=$(find /tmp 2>/dev/null | wc -l)
|
|
if [ "$nbtmp1" != "$nbtmp2" ]; then
|
|
echo "Left temporary files!"
|
|
exit 1
|
|
fi
|
|
if ! [ -e ~/.mcedb ]; then
|
|
echo "No .mcedb file found after updating fwdb"
|
|
exit 1
|
|
fi
|
|
- name: check fwdb update (builtin)
|
|
run: |
|
|
nbtmp1=$(find /tmp 2>/dev/null | wc -l)
|
|
./spectre-meltdown-checker.sh --update-builtin-fwdb; ret=$?
|
|
if [ "$ret" != 0 ]; then
|
|
echo "Non-zero return value: $ret"
|
|
exit 1
|
|
fi
|
|
nbtmp2=$(find /tmp 2>/dev/null | wc -l)
|
|
if [ "$nbtmp1" != "$nbtmp2" ]; then
|
|
echo "Left temporary files!"
|
|
exit 1
|
|
fi
|
|
- name: push artifact to the dev-build branch
|
|
run: |
|
|
tmpdir=$(mktemp -d)
|
|
cp ./spectre-meltdown-checker.sh $tmpdir/
|
|
cp -va ./dist/* $tmpdir/
|
|
if ! git checkout -f dev-build; then
|
|
git checkout -B dev-build;
|
|
fi
|
|
mv $tmpdir/* .
|
|
git add *
|
|
git status
|
|
git branch
|