Files
nvm/.github/workflows/tests-xenial.yml
T
Jordan Harband 5c05fb659c [actions] cache container images, verified against digests looked up live
Each container job now looks up the image's index, manifest,
and config digests from the registry,
keys an `actions/cache` entry on the config digest,
and only uses a cached image if its ID matches one of those digests;
otherwise it is discarded and the image is pulled (with retries) instead.
A poisoned or stale cache entry can therefore never be used,
and a cache hit needs only a couple of small manifest requests,
so this scales regardless of pull rate limits.
2026-10-09 14:14:20 -07:00

126 lines
4.2 KiB
YAML

name: 'Tests: xenial'
on: [push, pull_request]
permissions:
contents: read
jobs:
xenial:
permissions:
contents: read
name: 'xenial (${{ matrix.shell }})'
runs-on: ubuntu-latest
strategy:
fail-fast: false
matrix:
shell:
- sh
- bash
- dash
- zsh
# - ksh
steps:
- name: Harden Runner
uses: step-security/harden-runner@v2
with:
allowed-endpoints:
github.com:443
registry.npmjs.org:443
raw.githubusercontent.com:443
nodejs.org:443
iojs.org:443
azure.archive.ubuntu.com:80
packages.microsoft.com:443
archive.ubuntu.com:80
security.ubuntu.com:80
production.cloudflare.docker.com:443
production.cloudfront.docker.com:443
registry-1.docker.io:443
auth.docker.io:443
mirror.gcr.io:443
- uses: actions/checkout@v6
id: checkout
continue-on-error: true
with:
submodules: true
- name: 'nvmrc submodule fallback (forks without their own nvmrc)'
if: steps.checkout.outcome == 'failure'
shell: bash
run: |
git submodule set-url test/fixtures/nvmrc https://github.com/nvm-sh/nvmrc.git
git submodule sync --recursive
git submodule update --init --recursive
- uses: ljharb/actions/node/install@main
name: 'npm install && version checks'
with:
node-version: 'lts/*'
skip-ls-check: true
- run: npm ls urchin
- run: npx which urchin
# Pull through Google's Docker Hub mirror, which is not subject to Docker Hub's
# anonymous pull rate limits, and cache the image; a cached image is only used
# if it matches the digests the registry serves now
- name: Resolve the ubuntu:16.04 image digests
id: image
run: sh .github/scripts/docker-image.sh resolve mirror.gcr.io/library/ubuntu:16.04 >> "$GITHUB_OUTPUT"
- uses: actions/cache@v6
with:
path: ${{ runner.temp }}/docker-image.tar
key: docker-image-${{ runner.arch }}-${{ steps.image.outputs.key }}
- name: Load or pull the ubuntu:16.04 image
env:
DIGESTS: ${{ steps.image.outputs.digests }}
run: sh .github/scripts/docker-image.sh ensure mirror.gcr.io/library/ubuntu:16.04 "${RUNNER_TEMP}/docker-image.tar"
- name: Run xenial tests in container
run: |
docker run --rm \
-v "${{ github.workspace }}:/workspace" \
-w /workspace \
-e "TEST_SHELL=${{ matrix.shell }}" \
-e "TERM=xterm-256color" \
-e "DEBIAN_FRONTEND=noninteractive" \
-e "GITHUB_ACTIONS=true" \
mirror.gcr.io/library/ubuntu:16.04 \
bash -c '
set -ex
sh /workspace/.github/scripts/apt-install.sh git curl wget make build-essential python zsh libssl-dev
if [ "$TEST_SHELL" != "sh" ] && [ "$TEST_SHELL" != "bash" ]; then
sh /workspace/.github/scripts/apt-install.sh $TEST_SHELL || true
fi
# Use nvm to install Node.js for running urchin
# Node 16 is the last version supporting GLIBC 2.23 (Ubuntu 16.04)
export NVM_DIR="/workspace"
. /workspace/nvm.sh
nvm install 16
nvm use 16
npm ls urchin
URCHIN_PATH="$(npx which urchin)"
# Now clean up nvm state for the actual tests, but keep NVM_DIR set
nvm deactivate || true
nvm unalias default || true
unset NVM_CD_FLAGS NVM_BIN NVM_INC
export PATH="$(echo "$PATH" | tr ":" "\n" | grep -v "\.nvm" | grep -v "toolcache" | tr "\n" ":")"
# Clean any cached files from the nvm install above
rm -rf "$NVM_DIR/.cache" "$NVM_DIR/versions" "$NVM_DIR/alias"
make TEST_SUITE="xenial" SHELL="$TEST_SHELL" URCHIN="$URCHIN_PATH" test-$TEST_SHELL
'
all:
permissions:
contents: none
name: 'all xenial tests'
needs: [xenial]
runs-on: ubuntu-latest
steps:
- run: true