Merge pull request #578 from kareem-wolfssl/zd22360 #1111
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
| name: Ubuntu Build Test | |
| on: | |
| push: | |
| branches: [ 'master', 'main', 'release/**' ] | |
| pull_request: | |
| branches: [ '*' ] | |
| concurrency: | |
| group: ${{ github.workflow }}-${{ github.ref }} | |
| cancel-in-progress: true | |
| jobs: | |
| build: | |
| runs-on: ubuntu-22.04 | |
| # 10 min: this job runs 7 full configure/make/make-check cycles | |
| # (incl. a slow stress build); 5 min intermittently times out. | |
| timeout-minutes: 10 | |
| # Serialize across all workflows that exercise the hard-coded | |
| # "demoDevice" MQTT client ID against AWS IoT. Parallel runs from | |
| # different workflows (ubuntu-check, ubuntu-check-curl, this file's | |
| # aws-ca-regression) otherwise collide on the AWS side and produce | |
| # spurious "MQTT Connect/Subscribe: Error (Network) (-8)" failures. | |
| concurrency: | |
| group: wolfmqtt-awsiot-external | |
| cancel-in-progress: false | |
| steps: | |
| - name: Install dependencies | |
| run: | | |
| # Don't prompt for anything | |
| export DEBIAN_FRONTEND=noninteractive | |
| sudo apt-get update | |
| # Install mosquitto | |
| sudo apt-get install -y mosquitto bubblewrap | |
| - name: Setup mosquitto broker | |
| run: | | |
| # Disable default broker daemon | |
| sudo service mosquitto stop | |
| sleep 1 | |
| # This is some debug info useful if something goes wrong | |
| - name: Show network status | |
| run: | | |
| sudo ifconfig | |
| sudo route | |
| sudo netstat -tulpan | |
| - uses: actions/checkout@v4 | |
| - name: Build and install wolfSSL | |
| uses: ./.github/actions/build-wolfssl | |
| with: | |
| config: "--enable-enckeys" | |
| - name: wolfmqtt autogen | |
| run: ./autogen.sh | |
| - name: wolfmqtt configure | |
| run: ./configure | |
| - name: wolfmqtt make | |
| run: make | |
| # Note: this will run the external tests for this CI only | |
| - name: wolfmqtt make check | |
| run: make check | |
| - name: wolfmqtt configure without TLS | |
| env: | |
| WOLFMQTT_NO_EXTERNAL_BROKER_TESTS: 1 | |
| run: ./configure --enable-all --disable-tls | |
| - name: wolfmqtt make | |
| run: make | |
| - name: wolfmqtt make check | |
| run: make check | |
| - name: wolfmqtt configure with SN Enabled | |
| env: | |
| WOLFMQTT_NO_EXTERNAL_BROKER_TESTS: 1 | |
| run: ./configure --enable-sn | |
| - name: wolfmqtt make | |
| run: make | |
| - name: wolfmqtt make check | |
| run: make check | |
| - name: wolfmqtt configure with Non-Block | |
| env: | |
| WOLFMQTT_NO_EXTERNAL_BROKER_TESTS: 1 | |
| run: ./configure --enable-nonblock CFLAGS="-DWOLFMQTT_TEST_NONBLOCK" | |
| - name: wolfmqtt make | |
| run: make | |
| - name: wolfmqtt make check | |
| run: make check | |
| - name: wolfmqtt configure with Non-Block and Multi-threading | |
| env: | |
| WOLFMQTT_NO_EXTERNAL_BROKER_TESTS: 1 | |
| run: ./configure --enable-mt --enable-nonblock CFLAGS="-DWOLFMQTT_TEST_NONBLOCK" | |
| - name: wolfmqtt make | |
| run: make | |
| - name: wolfmqtt make check | |
| run: make check | |
| - name: configure with Multi-threading and WOLFMQTT_DYN_PROP | |
| env: | |
| WOLFMQTT_NO_EXTERNAL_BROKER_TESTS: 1 | |
| run: ./configure --enable-mt CFLAGS="-DWOLFMQTT_DYN_PROP" | |
| - name: make | |
| run: make | |
| - name: make check | |
| run: make check | |
| - name: wolfmqtt configure with Stress | |
| env: | |
| WOLFMQTT_NO_EXTERNAL_BROKER_TESTS: 1 | |
| run: ./configure --enable-stress | |
| - name: wolfmqtt make | |
| run: make | |
| - name: wolfmqtt make check | |
| run: make check | |
| # capture logs on failure | |
| - name: Show logs on failure | |
| if: failure() || cancelled() | |
| run: | | |
| cat test-suite.log | |
| cat scripts/*.log | |
| aws-ca-regression: | |
| # Exercises examples/aws/awsiot.c trust-anchor handling in three | |
| # configurations. Uses the real AWS IoT ATS endpoint hard-coded in | |
| # the demo, so this job needs external network access (same as the | |
| # `build` job's `make check`). | |
| # | |
| # `needs: build` serializes AWS IoT access within this workflow. | |
| # The repo-wide `concurrency:` group below serializes against other | |
| # workflows (e.g. ubuntu-check-curl) that also run awsiot.test | |
| # against the same hard-coded "demoDevice" client ID. Without both, | |
| # parallel jobs cause AWS IoT to drop connections with "MQTT | |
| # Connect/Subscribe: Error (Network) (-8)". | |
| needs: build | |
| concurrency: | |
| group: wolfmqtt-awsiot-external | |
| cancel-in-progress: false | |
| # | |
| # case 1: default bundle (Amazon Root CA 1 + Starfield G2), wolfSSL | |
| # built WITHOUT WOLFSSL_NO_ASN_STRICT. Strict ASN parsing | |
| # drops Starfield G2 (serial=0); the verify callback's | |
| # accept-anyway branch keeps the test passing. Expect PASS. | |
| # | |
| # case 2: default bundle, wolfSSL built WITH WOLFSSL_NO_ASN_STRICT. | |
| # Full bundle loads, chain verifies cleanly, callback | |
| # never has to mask an error. Expect PASS. | |
| # | |
| # case 3: legacy VeriSign G5 bundle (via | |
| # -DWOLFMQTT_AWSIOT_LEGACY_VERISIGN_CA), wolfSSL built WITH | |
| # WOLFSSL_NO_ASN_STRICT. The strict callback rejects the | |
| # unanchored chain. Expect FAIL. | |
| runs-on: ubuntu-22.04 | |
| # Headroom for two (uncached) wolfSSL builds plus the awsiot.test | |
| # transient-failure retry backoff. | |
| timeout-minutes: 15 | |
| steps: | |
| - name: Install dependencies | |
| run: | | |
| export DEBIAN_FRONTEND=noninteractive | |
| sudo apt-get update | |
| sudo apt-get install -y mosquitto bubblewrap | |
| - name: Setup mosquitto broker | |
| run: | | |
| sudo service mosquitto stop | |
| sleep 1 | |
| # Check out wolfMQTT first so the local build-wolfssl action is | |
| # available and so its source tree survives the wolfSSL rebuild | |
| # (the action clones wolfSSL under $HOME, not the workspace). | |
| - uses: actions/checkout@v4 | |
| # --- case 1: wolfSSL built with DEFAULT strict ASN parsing --- | |
| - name: Build and install wolfSSL (strict ASN default) | |
| uses: ./.github/actions/build-wolfssl | |
| with: | |
| config: "--enable-enckeys" | |
| - name: wolfmqtt autogen | |
| run: ./autogen.sh | |
| - name: case 1 - wolfmqtt configure (default bundle, strict ASN) | |
| run: ./configure --enable-tls --enable-examples | |
| - name: case 1 - wolfmqtt make | |
| run: make | |
| - name: case 1 - awsiot.test expect PASS | |
| run: ./scripts/awsiot.test | |
| # --- cases 2 + 3: wolfSSL rebuilt with WOLFSSL_NO_ASN_STRICT --- | |
| # The action reinstalls over /usr/local with the NO_ASN_STRICT build | |
| # (separate cache key from the strict build above). | |
| - name: Build and install wolfSSL (WOLFSSL_NO_ASN_STRICT) | |
| uses: ./.github/actions/build-wolfssl | |
| with: | |
| config: "--enable-enckeys" | |
| cflags: "-DWOLFSSL_NO_ASN_STRICT" | |
| - name: case 2 - wolfmqtt configure (default bundle, WOLFSSL_NO_ASN_STRICT) | |
| run: | | |
| make clean | |
| ./configure --enable-tls --enable-examples | |
| - name: case 2 - wolfmqtt make | |
| run: make | |
| - name: case 2 - awsiot.test expect PASS | |
| run: ./scripts/awsiot.test | |
| - name: case 3 - wolfmqtt configure (legacy VeriSign, WOLFSSL_NO_ASN_STRICT) | |
| run: | | |
| make clean | |
| ./configure --enable-tls --enable-examples \ | |
| CPPFLAGS=-DWOLFMQTT_AWSIOT_LEGACY_VERISIGN_CA | |
| - name: case 3 - wolfmqtt make | |
| run: make | |
| - name: case 3 - awsiot.test expect FAIL | |
| # Expected to fail (legacy trust anchor rejected), so disable the | |
| # transient-failure retry to keep the job fast. | |
| env: | |
| AWSIOT_RETRIES: 1 | |
| run: | | |
| if ./scripts/awsiot.test; then | |
| echo "case 3 unexpectedly PASSED - legacy VeriSign should not verify AWS IoT chain" | |
| exit 1 | |
| fi | |
| echo "case 3 FAILED as expected (legacy VeriSign trust anchor rejected)" | |
| - name: Show logs on failure | |
| if: failure() || cancelled() | |
| run: | | |
| cat test-suite.log || true | |
| cat scripts/*.log || true |