# # Copyright (c) 2026, The OpenThread Authors. # All rights reserved. # # Redistribution and use in source and binary forms, with or without # modification, are permitted provided that the following conditions are met: # 1. Redistributions of source code must retain the above copyright # notice, this list of conditions and the following disclaimer. # 2. Redistributions in binary form must reproduce the above copyright # notice, this list of conditions and the following disclaimer in the # documentation and/or other materials provided with the distribution. # 3. Neither the name of the copyright holder nor the # names of its contributors may be used to endorse or promote products # derived from this software without specific prior written permission. # # THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS "AS IS" # AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE # IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE # ARE DISCLAIMED. IN NO EVENT SHALL THE COPYRIGHT HOLDER OR CONTRIBUTORS BE # LIABLE FOR ANY DIRECT, INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, OR # CONSEQUENTIAL DAMAGES (INCLUDING, BUT NOT LIMITED TO, PROCUREMENT OF # SUBSTITUTE GOODS OR SERVICES; LOSS OF USE, DATA, OR PROFITS; OR BUSINESS # INTERRUPTION) HOWEVER CAUSED AND ON ANY THEORY OF LIABILITY, WHETHER IN # CONTRACT, STRICT LIABILITY, OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE) # ARISING IN ANY WAY OUT OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED OF THE # POSSIBILITY OF SUCH DAMAGE. # name: Nexus on: push: branches-ignore: - 'dependabot/**' pull_request: branches: - 'main' concurrency: group: ${{ github.workflow }}-${{ github.event.pull_request.number || (github.repository == 'openthread/openthread' && github.run_id) || github.ref }} cancel-in-progress: true permissions: contents: read jobs: nexus-cert-tests: name: nexus-cert-tests runs-on: ubuntu-24.04 steps: - name: Harden Runner uses: step-security/harden-runner@bf7454d06d71f1098171f2acdf0cd4708d7b5920 # v2.20.0 with: egress-policy: audit - name: Free Disk Space (Ubuntu) uses: jlumbroso/free-disk-space@54081f138730dfa15788a46383842cd2f914a1be # main - uses: actions/checkout@08c6903cd8c0fde910a37f88322edcfb5dd907a8 # v5.0.0 with: submodules: recursive persist-credentials: false - name: Bootstrap timeout-minutes: 10 run: | sudo add-apt-repository -y ppa:wireshark-dev/stable sudo apt-get update sudo DEBIAN_FRONTEND=noninteractive apt-get --no-install-recommends install -y ninja-build tshark python3 -m pip install -r tests/scripts/thread-cert/requirements.txt - name: Build Nexus run: | mkdir -p build/nexus top_builddir=build/nexus ./tests/nexus/build.sh - name: Run Nexus Tests run: | top_builddir=build/nexus ./tests/nexus/run_nexus_tests.sh nexus-core-tests: name: nexus-core-tests runs-on: ubuntu-24.04 steps: - name: Harden Runner uses: step-security/harden-runner@bf7454d06d71f1098171f2acdf0cd4708d7b5920 # v2.20.0 with: egress-policy: audit # TODO: change to 'egress-policy: block' after couple of runs - name: Free Disk Space (Ubuntu) uses: jlumbroso/free-disk-space@54081f138730dfa15788a46383842cd2f914a1be # main - uses: actions/checkout@08c6903cd8c0fde910a37f88322edcfb5dd907a8 # v5.0.0 with: submodules: recursive persist-credentials: false - name: Bootstrap timeout-minutes: 10 env: PR_BODY: "${{ github.event.pull_request.body }}" run: | sudo apt-get update sudo apt-get --no-install-recommends install -y ninja-build lcov - name: Build Nexus run: | mkdir -p build/nexus top_builddir=build/nexus ./tests/nexus/build.sh - name: Run Core Tests run: | cd build/nexus && ctest -L core --output-on-failure - name: Run TREL Tests run: | cd build/nexus && ctest -L trel --output-on-failure nexus-long-routes-tests: name: nexus-long-routes-tests runs-on: ubuntu-24.04 steps: - name: Harden Runner uses: step-security/harden-runner@bf7454d06d71f1098171f2acdf0cd4708d7b5920 # v2.20.0 with: egress-policy: audit # TODO: change to 'egress-policy: block' after couple of runs - name: Free Disk Space (Ubuntu) uses: jlumbroso/free-disk-space@54081f138730dfa15788a46383842cd2f914a1be # main - uses: actions/checkout@08c6903cd8c0fde910a37f88322edcfb5dd907a8 # v5.0.0 with: submodules: recursive persist-credentials: false - name: Bootstrap timeout-minutes: 10 env: PR_BODY: "${{ github.event.pull_request.body }}" run: | sudo apt-get update sudo apt-get --no-install-recommends install -y ninja-build lcov - name: Build Nexus run: | mkdir -p build/nexus top_builddir=build/nexus ./tests/nexus/build.sh long_routes - name: Run LONG_ROUTES Tests run: | cd build/nexus && ctest -L long_routes --output-on-failure nexus-grpc-tests: name: nexus-grpc-tests runs-on: ubuntu-24.04 steps: - name: Harden Runner uses: step-security/harden-runner@bf7454d06d71f1098171f2acdf0cd4708d7b5920 # v2.20.0 with: egress-policy: audit - name: Free Disk Space (Ubuntu) uses: jlumbroso/free-disk-space@54081f138730dfa15788a46383842cd2f914a1be # main - uses: actions/checkout@08c6903cd8c0fde910a37f88322edcfb5dd907a8 # v5.0.0 with: submodules: recursive persist-credentials: false - name: Bootstrap timeout-minutes: 10 run: | sudo apt-get update sudo apt-get --no-install-recommends install -y ninja-build libgrpc++-dev libprotobuf-dev protobuf-compiler-grpc - name: Build Nexus run: | mkdir -p build/nexus OT_NEXUS_GRPC=ON top_builddir=build/nexus ./tests/nexus/build.sh - name: Run GRPC Tests run: | cd build/nexus && ./tests/nexus/nexus_grpc nexus-wasm-tests: name: nexus-wasm-tests runs-on: ubuntu-24.04 steps: - name: Harden Runner uses: step-security/harden-runner@bf7454d06d71f1098171f2acdf0cd4708d7b5920 # v2.20.0 with: egress-policy: audit - name: Free Disk Space (Ubuntu) uses: jlumbroso/free-disk-space@54081f138730dfa15788a46383842cd2f914a1be # main - uses: actions/checkout@08c6903cd8c0fde910a37f88322edcfb5dd907a8 # v5.0.0 with: submodules: recursive persist-credentials: false - name: Bootstrap timeout-minutes: 10 run: | sudo apt-get update sudo apt-get --no-install-recommends install -y ninja-build - name: Set up Emscripten uses: mymindstorm/setup-emsdk@6ab9eb1bda2574c4ddb79809fc9247783eaf9021 # v14 - name: Build Nexus WASM run: | mkdir -p build/nexus top_builddir=build/nexus ./tests/nexus/build.sh wasm - name: Run WASM Smoke Test run: | node tests/nexus/test_wasm_bindings.mjs build/nexus/tests/nexus/nexus_live_demo.js