# # Copyright (c) 2020, The OpenThread Authors. # All rights reserved. # # Redistribution and use in source and binary forms, with or without # modification, are permitted provided that the following conditions are met: # 1. Redistributions of source code must retain the above copyright # notice, this list of conditions and the following disclaimer. # 2. Redistributions in binary form must reproduce the above copyright # notice, this list of conditions and the following disclaimer in the # documentation and/or other materials provided with the distribution. # 3. Neither the name of the copyright holder nor the # names of its contributors may be used to endorse or promote products # derived from this software without specific prior written permission. # # THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS "AS IS" # AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE # IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE # ARE DISCLAIMED. IN NO EVENT SHALL THE COPYRIGHT HOLDER OR CONTRIBUTORS BE # LIABLE FOR ANY DIRECT, INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, OR # CONSEQUENTIAL DAMAGES (INCLUDING, BUT NOT LIMITED TO, PROCUREMENT OF # SUBSTITUTE GOODS OR SERVICES; LOSS OF USE, DATA, OR PROFITS; OR BUSINESS # INTERRUPTION) HOWEVER CAUSED AND ON ANY THEORY OF LIABILITY, WHETHER IN # CONTRACT, STRICT LIABILITY, OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE) # ARISING IN ANY WAY OUT OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED OF THE # POSSIBILITY OF SUCH DAMAGE. # name: POSIX on: push: branches-ignore: - 'dependabot/**' pull_request: branches: - 'main' concurrency: group: ${{ github.workflow }}-${{ github.event.pull_request.number || (github.repository == 'openthread/openthread' && github.run_id) || github.ref }} cancel-in-progress: true permissions: contents: read jobs: expects-linux: runs-on: ubuntu-22.04 env: CFLAGS: -DCLI_COAP_SECURE_USE_COAP_DEFAULT_HANDLER=1 -DOPENTHREAD_CONFIG_MLE_MAX_CHILDREN=15 CXXFLAGS: -DCLI_COAP_SECURE_USE_COAP_DEFAULT_HANDLER=1 -DOPENTHREAD_CONFIG_MLE_MAX_CHILDREN=15 steps: - name: Harden Runner uses: step-security/harden-runner@bf7454d06d71f1098171f2acdf0cd4708d7b5920 # v2.20.0 with: egress-policy: audit # TODO: change to 'egress-policy: block' after couple of runs - uses: actions/checkout@08c6903cd8c0fde910a37f88322edcfb5dd907a8 # v5.0.0 with: submodules: recursive persist-credentials: false - uses: actions/setup-python@a309ff8b426b58ec0e2a45f0f869d46889d02405 # v6.2.0 with: python-version: '3.12' cache: pip - name: Bootstrap timeout-minutes: 10 run: | sudo apt-get --no-install-recommends install -y expect ninja-build lcov sudo bash script/install_socat pip install bleak 'cryptography==43.0.0' - name: Run RCP Mode run: | ulimit -c unlimited ./script/test prepare_coredump_upload OT_OPTIONS='-DOT_READLINE=OFF -DOT_FULL_LOGS=ON -DOT_LOG_OUTPUT=PLATFORM_DEFINED' VIRTUAL_TIME=0 OT_NODE_TYPE=rcp ./script/test build expect - name: Run ot-fct run: | OT_CMAKE_NINJA_TARGET="ot-fct" script/cmake-build posix tests/scripts/expect/ot-fct.exp - name: Check Crash if: ${{ failure() }} run: | CRASHED=$(./script/test check_crash | tail -1) [[ $CRASHED -eq "1" ]] && echo "Crashed!" || echo "Not crashed." echo "CRASHED_RCP=$CRASHED" >> $GITHUB_ENV - uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1 if: ${{ failure() && env.CRASHED_RCP == '1' }} with: name: core-expect-rcp path: | ./ot-core-dump/* - name: Generate Coverage run: | ./script/test generate_coverage gcc - uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1 with: name: cov-expects-linux-1 path: tmp/coverage.info retention-days: 1 - name: Run TUN Mode run: | sudo apt-get update echo 0 | sudo tee /proc/sys/net/ipv6/conf/all/disable_ipv6 sudo apt-get install --no-install-recommends -y bind9-host ntp sudo bash script/install_socat sudo systemctl restart ntp sudo socat 'UDP6-LISTEN:53,fork,reuseaddr,bind=[::1]' UDP:127.0.0.53:53 & socat 'TCP6-LISTEN:2000,fork,reuseaddr' TCP:127.0.0.53:53 & host ipv6.google.com 127.0.0.53 host ipv6.google.com ::1 ulimit -c unlimited ./script/test prepare_coredump_upload OT_OPTIONS='-DOT_READLINE=OFF -DOT_FULL_LOGS=ON -DOT_LOG_OUTPUT=PLATFORM_DEFINED' OT_NATIVE_IP=1 VIRTUAL_TIME=0 OT_NODE_TYPE=rcp ./script/test clean build expect - name: Check Crash if: ${{ failure() }} run: | CRASHED=$(./script/test check_crash | tail -1) [[ $CRASHED -eq "1" ]] && echo "Crashed!" || echo "Not crashed." echo "CRASHED_TUN=$CRASHED" >> $GITHUB_ENV - uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1 if: ${{ failure() && env.CRASHED_TUN == '1' }} with: name: core-expect-linux path: | ./ot-core-dump/* - uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1 if: ${{ failure() }} with: name: syslog-expect-linux path: /var/log/syslog - name: Generate Coverage run: | ./script/test generate_coverage gcc - uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1 with: name: cov-expects-linux-2 path: tmp/coverage.info retention-days: 1 pty-linux: name: pty-linux OT_DAEMON=${{ matrix.OT_DAEMON }} runs-on: ubuntu-24.04 strategy: fail-fast: false matrix: OT_DAEMON: ['off', 'on'] env: COVERAGE: 1 OT_DAEMON: ${{ matrix.OT_DAEMON }} OT_READLINE: 'readline' steps: - name: Harden Runner uses: step-security/harden-runner@bf7454d06d71f1098171f2acdf0cd4708d7b5920 # v2.20.0 with: egress-policy: audit # TODO: change to 'egress-policy: block' after couple of runs - uses: actions/checkout@08c6903cd8c0fde910a37f88322edcfb5dd907a8 # v5.0.0 with: submodules: recursive persist-credentials: false - name: Bootstrap timeout-minutes: 10 run: | sudo apt-get update sudo apt-get --no-install-recommends install -y expect lcov libreadline-dev net-tools ninja-build sudo sysctl -w kernel.apparmor_restrict_unprivileged_userns=0 sudo bash script/install_socat cd /tmp wget --timeout=30 --tries=4 https://github.com/obgm/libcoap/archive/bsd-licensed.tar.gz tar xvf bsd-licensed.tar.gz cd libcoap-bsd-licensed ./autogen.sh ./configure --prefix= --exec-prefix=/usr --with-boost=internal --disable-tests --disable-documentation make -j2 sudo make install - name: Build run: | script/check-posix-pty build - name: Run run: | script/check-posix-pty check - name: Run (OT_DAEMON_ALLOW_ALL) if: matrix.OT_DAEMON == 'on' env: OT_DAEMON_ALLOW_ALL: 1 run: | script/check-posix-pty check - name: Generate Coverage run: | ./script/test generate_coverage gcc - uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1 with: name: cov-pty-linux-${{ matrix.OT_DAEMON }} path: tmp/coverage.info retention-days: 1 infra-if-index-changed-linux: name: infra-if-index-changed-linux runs-on: ubuntu-22.04 steps: - name: Harden Runner uses: step-security/harden-runner@bf7454d06d71f1098171f2acdf0cd4708d7b5920 # v2.20.0 with: egress-policy: audit # TODO: change to 'egress-policy: block' after couple of runs - uses: actions/checkout@08c6903cd8c0fde910a37f88322edcfb5dd907a8 # v5.0.0 with: submodules: recursive persist-credentials: false - name: Bootstrap timeout-minutes: 10 run: | sudo apt-get update sudo apt-get --no-install-recommends install -y net-tools ninja-build sudo sysctl -w kernel.apparmor_restrict_unprivileged_userns=0 - name: Build run: | script/check-infra-if-index-changed build - name: Run run: | script/check-infra-if-index-changed check pty-macos: name: pty-macos OT_DAEMON=${{ matrix.OT_DAEMON }} runs-on: macos-14 strategy: fail-fast: false matrix: OT_DAEMON: ['off', 'on'] env: OT_DAEMON: ${{ matrix.OT_DAEMON }} OT_READLINE: 'off' steps: - name: Harden Runner uses: step-security/harden-runner@bf7454d06d71f1098171f2acdf0cd4708d7b5920 # v2.20.0 with: egress-policy: audit # TODO: change to 'egress-policy: block' after couple of runs - uses: actions/checkout@08c6903cd8c0fde910a37f88322edcfb5dd907a8 # v5.0.0 with: submodules: recursive persist-credentials: false - name: Bootstrap timeout-minutes: 10 run: | rm -f /usr/local/bin/2to3 rm -f /usr/local/bin/2to3-3.11 rm -f /usr/local/bin/idle3 rm -f /usr/local/bin/idle3.11 rm -f /usr/local/bin/pydoc3 rm -f /usr/local/bin/pydoc3.11 rm -f /usr/local/bin/python3 rm -f /usr/local/bin/python3.11 rm -f /usr/local/bin/python3-config rm -f /usr/local/bin/python3.11-config brew update brew install ninja sudo bash script/install_socat - name: Build run: | script/check-posix-pty build - name: Run run: | script/check-posix-pty check rcp-stack-reset: runs-on: ubuntu-22.04 steps: - name: Harden Runner uses: step-security/harden-runner@bf7454d06d71f1098171f2acdf0cd4708d7b5920 # v2.20.0 with: egress-policy: audit # TODO: change to 'egress-policy: block' after couple of runs - uses: actions/checkout@08c6903cd8c0fde910a37f88322edcfb5dd907a8 # v5.0.0 with: submodules: recursive persist-credentials: false - name: Bootstrap timeout-minutes: 10 env: PR_BODY: "${{ github.event.pull_request.body }}" run: | sudo apt-get --no-install-recommends install -y expect ninja-build lcov sudo bash script/install_socat sudo python3 -m pip install git+https://github.com/openthread/pyspinel - name: Build run: | script/cmake-build simulation -DOT_CSL_RECEIVER=ON -DOT_FULL_LOGS=ON -DOT_LOG_OUTPUT=PLATFORM_DEFINED - name: Run run: | python3 tests/scripts/misc/test_rcp_reset.py build/simulation/examples/apps/ncp/ot-rcp - name: Generate Coverage run: | ./script/test generate_coverage gcc - uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1 with: name: cov-rcp-stack-reset path: tmp/coverage.info retention-days: 1 upload-coverage: needs: - expects-linux - pty-linux runs-on: ubuntu-22.04 steps: - name: Harden Runner uses: step-security/harden-runner@bf7454d06d71f1098171f2acdf0cd4708d7b5920 # v2.20.0 with: egress-policy: audit # TODO: change to 'egress-policy: block' after couple of runs - uses: actions/checkout@08c6903cd8c0fde910a37f88322edcfb5dd907a8 # v5.0.0 with: submodules: recursive persist-credentials: false - name: Bootstrap timeout-minutes: 10 run: | sudo apt-get --no-install-recommends install -y lcov - uses: actions/download-artifact@3e5f45b2cfb9172054b4087a40e8e0b5a5461e7c # v8.0.1 with: path: coverage/ pattern: cov-* merge-multiple: true - name: Combine Coverage run: | script/test combine_coverage - name: Upload Coverage uses: codecov/codecov-action@fb8b3582c8e4def4969c97caa2f19720cb33a72f # v7.0.0 env: CODECOV_TOKEN: ${{ secrets.CODECOV_TOKEN }} with: files: final.info fail_ci_if_error: ${{ github.repository == 'openthread/openthread' && (github.event_name != 'pull_request' || github.event.pull_request.head.repo.full_name == github.repository) }}