mirror of
https://github.com/netbirdio/netbird.git
synced 2026-09-26 16:49:08 +02:00
Nothing in CI compiles the files behind //go:build android or //go:build ios. The android bridge builds 7 of its 23 files on linux and skips client.go; the iOS SDK is not built at all. The linter matrix picks a GOOS by picking a runner OS, so it loads the same file set as the host build and never sees them either. A type error in client/android/client.go therefore passes every check on its PR, merges, and is discovered by netbirdio/android-client after sync-tag.yml fires trigger_android_bump on the release tag. The new Mobile workflow cross-compiles ./client/android/... for the GOARCH values gomobile ships and ./client/ios/..., and vets the android bridge. The new Android and iOS lint jobs run golangci-lint with GOOS/GOARCH in the job env. No NDK, Xcode or gomobile is needed: these are library packages, so the compiler type-checks them without a link step, and the dependency graph drags in the android/ios-tagged files across client/iface, client/internal/dns and client/internal/routemanager with them. Linting those files for the first time surfaces one gosec G101 on the SSH password-required marker. It is a sentinel string the Java side matches on, not a credential, so it is suppressed at the declaration.
129 lines
5.0 KiB
YAML
129 lines
5.0 KiB
YAML
name: Lint
|
|
on: [pull_request]
|
|
|
|
permissions:
|
|
contents: read
|
|
pull-requests: read
|
|
|
|
concurrency:
|
|
group: ${{ github.workflow }}-${{ github.ref }}-${{ github.head_ref || github.actor_id }}
|
|
cancel-in-progress: true
|
|
|
|
jobs:
|
|
codespell:
|
|
name: codespell
|
|
runs-on: ubuntu-latest
|
|
steps:
|
|
- name: Checkout code
|
|
uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 # v7.0.0
|
|
with:
|
|
persist-credentials: false
|
|
- name: codespell
|
|
uses: codespell-project/actions-codespell@8f01853be192eb0f849a5c7d721450e7a467c579 # v2.2
|
|
with:
|
|
ignore_words_list: erro,clienta,hastable,iif,groupd,testin,groupe,cros,ans,deriver,te,userA,ede,additionals,flate,recordin,unparseable
|
|
# Non-English UI translations trip codespell on real foreign words
|
|
# (de: "Sie", "oder", "ist"). Only en/common.json is the source of
|
|
# truth that should be spell-checked. List each translated locale
|
|
# dir below and add new ones as languages are added under
|
|
# client/ui/i18n/locales/. Single-star globs are matched per path
|
|
# segment by codespell and behave the same across versions; the
|
|
# recursive "**" form did not take effect with the codespell shipped
|
|
# by this action.
|
|
skip: go.mod,go.sum,*/proxy/web/*,*pnpm-lock.yaml,*package-lock.json,*/locales/de/*,*/locales/es/*,*/locales/fr/*,*/locales/hu/*,*/locales/it/*,*/locales/pt/*,*/locales/ru/*,*/locales/zh-CN/*,*/i18n/TRANSLATING.md
|
|
golangci:
|
|
strategy:
|
|
fail-fast: false
|
|
matrix:
|
|
os: [macos-latest, windows-latest, ubuntu-latest]
|
|
include:
|
|
- os: macos-latest
|
|
display_name: Darwin
|
|
- os: windows-latest
|
|
display_name: Windows
|
|
- os: ubuntu-latest
|
|
display_name: Linux
|
|
name: ${{ matrix.display_name }}
|
|
runs-on: ${{ matrix.os }}
|
|
timeout-minutes: 25
|
|
steps:
|
|
- name: Checkout code
|
|
uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 # v7.0.0
|
|
with:
|
|
persist-credentials: false
|
|
- name: Check for duplicate constants
|
|
if: matrix.os == 'ubuntu-latest'
|
|
run: |
|
|
! awk '/const \(/,/)/{print $0}' management/server/activity/codes.go | grep -o '= [0-9]*' | sort | uniq -d | grep .
|
|
- name: Install Go
|
|
uses: actions/setup-go@924ae3a1cded613372ab5595356fb5720e22ba16 # v6.5.0
|
|
with:
|
|
go-version-file: "go.mod"
|
|
cache: false
|
|
- name: Install dependencies
|
|
if: matrix.os == 'ubuntu-latest'
|
|
run: sudo apt update && sudo apt install -y -q libgtk-4-dev libwebkitgtk-6.0-dev libsoup-3.0-dev libgl1-mesa-dev xorg-dev libpcap-dev
|
|
- name: Stub Wails frontend bundle
|
|
# client/ui/main.go has //go:embed all:frontend/dist. The
|
|
# directory is produced by `pnpm run build` and is gitignored, so
|
|
# lint-only runs (no frontend toolchain) need a placeholder file
|
|
# for the embed pattern to match.
|
|
shell: bash
|
|
run: |
|
|
mkdir -p client/ui/frontend/dist
|
|
touch client/ui/frontend/dist/.embed-placeholder
|
|
- name: golangci-lint
|
|
uses: golangci/golangci-lint-action@82606bf257cbaff209d206a39f5134f0cfbfd2ee #v9.2.1
|
|
with:
|
|
version: latest
|
|
skip-cache: true
|
|
skip-save-cache: true
|
|
cache-invalidation-interval: 0
|
|
args: --timeout=20m
|
|
|
|
# Separate job rather than extra rows in the matrix above: those rows pick a
|
|
# GOOS by picking a runner OS, while android/ios are cross-compiled from
|
|
# ubuntu — an `include` entry with os: ubuntu-latest would merge into the
|
|
# Linux row instead of adding one. The package path is restricted because a
|
|
# whole-repo run under GOOS=android pulls *_linux.go files into packages that
|
|
# have no android counterpart.
|
|
golangci-mobile:
|
|
strategy:
|
|
fail-fast: false
|
|
matrix:
|
|
include:
|
|
- goos: android
|
|
goarch: arm64
|
|
packages: ./client/android/...
|
|
display_name: Android
|
|
- goos: ios
|
|
goarch: arm64
|
|
packages: ./client/ios/...
|
|
display_name: iOS
|
|
name: ${{ matrix.display_name }}
|
|
runs-on: ubuntu-latest
|
|
timeout-minutes: 25
|
|
env:
|
|
CGO_ENABLED: 0
|
|
GOOS: ${{ matrix.goos }}
|
|
GOARCH: ${{ matrix.goarch }}
|
|
steps:
|
|
- name: Checkout code
|
|
uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 # v7.0.0
|
|
with:
|
|
persist-credentials: false
|
|
- name: Install Go
|
|
uses: actions/setup-go@924ae3a1cded613372ab5595356fb5720e22ba16 # v6.5.0
|
|
with:
|
|
go-version-file: "go.mod"
|
|
cache: false
|
|
- name: golangci-lint
|
|
uses: golangci/golangci-lint-action@82606bf257cbaff209d206a39f5134f0cfbfd2ee #v9.2.1
|
|
with:
|
|
version: latest
|
|
install-mode: binary
|
|
skip-cache: true
|
|
skip-save-cache: true
|
|
cache-invalidation-interval: 0
|
|
args: --timeout=20m ${{ matrix.packages }}
|