Repository navigation
Expand file tree
/
Copy pathbuild-test-osx-arm64.jsonnet
More file actions
142 lines (129 loc) · 3.82 KB
/
Copy pathbuild-test-osx-arm64.jsonnet
File metadata and controls
142 lines (129 loc) · 3.82 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
130
131
132
133
134
135
136
137
138
139
140
141
142
// This workflow builds and tests the semgrep-core binary for macOS arm64
// and generates the arm64-wheel for pypi.
// coupling: if you modify this file, modify also build-test-osx-x86.jsonnet
local osx_x86 = import 'build-test-osx-x86.jsonnet';
local actions = import 'libs/actions.libsonnet';
local semgrep = import 'libs/semgrep.libsonnet';
local wheel_name = 'osx-arm64-wheel';
// ----------------------------------------------------------------------------
// Helpers
// ----------------------------------------------------------------------------
local runs_on = [
'self-hosted',
'macOS',
'ARM64',
'ghcr.io/cirruslabs/macos-monterey-xcode:latest',
];
local setup_runner_step = {
name: 'Setup runner directory',
run: |||
sudo mkdir -p /Users/runner
sudo chown admin:staff /Users/runner
sudo chmod 750 /Users/runner
|||,
};
// Our self-hosted runner do not come with python pre-installed.
//
// Note that we can't reuse actions.setup_python because it comes with the
// cache: 'pipenv' which then trigger failures when we don't checkout any code
// and there's no code with a Pipfile.lock
local setup_python_step = {
uses: 'actions/setup-python@v4',
with: {
'python-version': '3.11',
}
};
// ----------------------------------------------------------------------------
// The jobs
// ----------------------------------------------------------------------------
// alt: we could factorize more with build-test-osx-x86.jsonnet by making
// the xxx_job functions, but let's copy paste a bit for now.
local artifact_name = 'semgrep-osx-arm64-${{ github.sha }}';
local build_core_job = {
'runs-on': runs_on,
steps: [
setup_runner_step,
setup_python_step,
actions.checkout_with_submodules(),
// TODO: like for osx-x86, we should use opam.lock
semgrep.cache_opam.step(
key=semgrep.opam_switch + "-${{hashFiles('semgrep.opam')}}")
+ semgrep.cache_opam.if_cache_inputs,
// exactly the same than in build-test-oxs-x86.jsonnet
{
name: 'Install dependencies',
run: './scripts/osx-setup-for-release.sh "%s"' % semgrep.opam_switch,
},
{
name: 'Compile semgrep',
run: "opam exec -- make core",
},
actions.make_artifact_step("./bin/semgrep-core"),
actions.upload_artifact_step(artifact_name),
{
name: 'Test semgrep-core',
run: 'opam exec -- make core-test',
}
],
};
local build_wheels_job = {
'runs-on': runs_on,
needs: [
'build-core',
],
steps: [
setup_runner_step,
setup_python_step,
// needed for ./script/build-wheels.sh below
actions.checkout_with_submodules(),
actions.download_artifact_step(artifact_name),
// the --plat-name is macosx_11_0_arm64 here!
{
run: |||
tar xvfz artifacts.tgz
cp artifacts/semgrep-core cli/src/semgrep/bin
./scripts/build-wheels.sh --plat-name macosx_11_0_arm64
|||,
},
{
uses: 'actions/upload-artifact@v4',
with: {
path: 'cli/dist.zip',
name: wheel_name,
},
},
],
};
local test_wheels_job = {
'runs-on': runs_on,
needs: [
'build-wheels',
],
steps: [
setup_runner_step,
setup_python_step,
actions.download_artifact_step(wheel_name),
{
run: 'unzip dist.zip',
},
{
name: 'install package',
run: 'pip3 install dist/*.whl',
},
] + osx_x86.export.test_semgrep_steps,
};
// ----------------------------------------------------------------------------
// The Workflow
// ----------------------------------------------------------------------------
{
name: 'build-test-osx-arm64',
on: {
workflow_dispatch: semgrep.cache_opam.inputs(required=true),
workflow_call: semgrep.cache_opam.inputs(required=false),
},
jobs: {
'build-core': build_core_job,
'build-wheels': build_wheels_job,
'test-wheels': test_wheels_job,
},
}