artifacts: - bench.txt environment: APK_REPO: alpine/v3.22/bigbes/x86_64 BENCH_ORIGIN: https://bench.srht.bigb.es BENCH_REPO: ~bigbes/sr-ht-bench BOOTSTRAP_REV: 779ad9f174ea5ab7e755f6df0ec9e5912d67dd16 BUILD_SUBMITTER: git.sr.ht CORE_VER: 0.84.5 GIT_REF: refs/heads/master REPO: sr-ht-bench S3_BUCKET: repo S3_ENDPOINT: https://s3.bigb.es image: alpine/edge packages: - abuild - go - git - curl - rclone - sassc - minify - postgresql - postgresql-client secrets: - e322d5a2-b6b5-4425-aa37-12b038282461 - 027afe52-297d-40c6-afd7-c19aba9e2f0d sources: - "https://git.srht.bigb.es/~bigbes/sr-ht-bench#080e429793fa04a52f7d1956d7620cb64d8849ca" submitter: git.sr.ht: allow-refs: - refs/heads/master tasks: - scss: | # Assemble the shared sourcehut partials no apk ships, the way # core.sr.ht's `make install-scss` would. No cacher stages, unlike the # siblings — the cache bucket's credentials are a secret this repository # does not have, so each build clones both upstreams shallowly and an # outage at either fails us. See docs/ci.md#scss. git clone --depth 1 --branch "$CORE_VER" \ https://git.sr.ht/~sircmpwn/core.sr.ht /tmp/core mkdir -p ~/scss/bootstrap cp /tmp/core/scss/*.scss /tmp/core/scss/*.css ~/scss/ git init -q /tmp/bootstrap git -C /tmp/bootstrap remote add origin https://github.com/twbs/bootstrap git -C /tmp/bootstrap fetch -q --depth 1 origin "$BOOTSTRAP_REV" git -C /tmp/bootstrap checkout -q FETCH_HEAD cp -r /tmp/bootstrap/scss ~/scss/bootstrap/scss sudo mkdir -p /usr/share/sourcehut sudo cp -r ~/scss /usr/share/sourcehut/scss - keygen: | # Throwaway signing key, and -i is not optional: docs/ci.md#keygen. SUDO=sudo abuild-keygen -a -n -i -q - version: | # 0.0., the scheme of the spec/dolt/compare siblings, this # repository having no tags. EXPORTED rather than sed-ed into the APKBUILD # (which reads $PKGVER) because rewriting a tracked file would flip the # VCS stamp Go records in the binary to dirty — do not "tidy" it into a # sed. The tree is printed because this is the last moment it is provably # clean. See docs/ci.md#version. cd "$REPO" echo "export PKGVER=0.0.$(git rev-list --count HEAD)" >> ~/.buildenv git status --porcelain - postgres: | # SPEC ch. 15's open question 6, answered: a real Postgres in the VM. # Measured: db/ covers 4.5% of its statements without it and 77.2% with # it, service/ 54.8% and 89.7%. Every flag below is load-bearing — # see docs/ci.md#postgres. sudo install -d -o postgres -g postgres /run/postgresql /var/lib/postgresql/data sudo -u postgres initdb -D /var/lib/postgresql/data sudo -u postgres pg_ctl -D /var/lib/postgresql/data -l /tmp/pg.log -w start \ -o "-k /run/postgresql -h 127.0.0.1 \ -c fsync=off -c full_page_writes=off -c synchronous_commit=off" sudo -u postgres createuser -s "$(id -un)" sudo -u postgres createdb -O "$(id -un)" benchsrht_test echo "export BENCHSRHT_TEST_PG='postgresql://$(id -un)@127.0.0.1/benchsrht_test?sslmode=disable'" \ >> ~/.buildenv - test: | cd "$REPO" # An empty DSN would skip every Postgres-backed suite and leave the build # green over untested code — that is the 4.5%-vs-77.2% gap. It also # catches a reordering of the two tasks. docs/ci.md#test. if [ -z "$BENCHSRHT_TEST_PG" ]; then echo "BENCHSRHT_TEST_PG is unset: the postgres task did not export it," >&2 echo "so every database suite would skip and this build would lie." >&2 exit 1 fi # `make test` and not a bare `go test ./...`: the Makefile is where this # repository's test command names its -timeout (sr-ht-bench-5b8.44), and a # second copy of that number here is a second copy to forget. # See docs/ci.md#test. make test - build: | cd "$REPO" # -d: makedepends come from `packages:`. The APKBUILD runs `make css` # before `make build` and asserts the result twice, on build()'s copy and # on package()'s. See docs/ci.md#build. REPODEST=$HOME/packages abuild -d find "$HOME/packages" -name '*.apk' - publish: | # The gate is the honest answer to a build that was handed no secrets, not # a fallback: with ~/.apk-ci.env absent every earlier task has still run # and a signed apk is sitting in $HOME/packages. On a push the secret is # there and this publishes. See docs/ci.md#publish. if [ ! -r ~/.apk-ci.env ]; then echo "no ~/.apk-ci.env: this build has no apk repo credentials" echo "the package was built and signed, and is not published" exit 0 fi set +x # never echo the S3 credentials into the build log . ~/.apk-ci.env export RCLONE_CONFIG_GARAGE_TYPE=s3 export RCLONE_CONFIG_GARAGE_PROVIDER=Other export RCLONE_CONFIG_GARAGE_ENDPOINT="$S3_ENDPOINT" export RCLONE_CONFIG_GARAGE_REGION=garage export RCLONE_CONFIG_GARAGE_FORCE_PATH_STYLE=true export RCLONE_CONFIG_GARAGE_ACCESS_KEY_ID="$APK_CI_S3_ACCESS_KEY" export RCLONE_CONFIG_GARAGE_SECRET_ACCESS_KEY="$APK_CI_S3_SECRET_KEY" set -x # Upload only, never delete. See docs/ci.md#publish. find "$HOME/packages" -name '*.apk' -print | while read -r f; do rclone copyto "$f" "garage:$S3_BUCKET/$APK_REPO/$(basename "$f")" echo "uploaded $(basename "$f")" done echo "published; apk-mirror on phoebe re-indexes within 15 minutes" - bench: | # Dogfooding, the last thing v1 owes (SPEC ch. 13): this service's own # benchmarks, uploaded to its own instance, parsed by the parser in this # very commit. Last and a task of its own on purpose, and a VM this small # measures a shape rather than a number — see docs/ci.md#bench. cd "$REPO" # BenchmarkSeries needs a database and SKIPS without the DSN, printing no # line at all — half the file would upload and look healthy, so the test # task's guard stands here too. docs/ci.md#the-dsn-guard-and-the-two-greps. if [ -z "$BENCHSRHT_TEST_PG" ]; then echo "BENCHSRHT_TEST_PG is unset: BenchmarkSeries would skip silently," >&2 echo "and this build would upload half a file without saying so." >&2 exit 1 fi # -s so make does not echo the recipe into the body; a redirect and a cat # and NOT `| tee`, which would hand the task tee's exit status and let a # failing benchmark pass. $HOME is where artifacts look. docs/ci.md#bench. make -s bench > "$HOME/bench.txt" cat "$HOME/bench.txt" # Both must be in there: a body the parser finds no results in is a 400 # (SPEC ch. 4.1), and a body with only one of them is a silent half. grep -q '^BenchmarkIngest' "$HOME/bench.txt" grep -q '^BenchmarkSeries' "$HOME/bench.txt" if [ ! -r ~/.bench-token ]; then echo "no ~/.bench-token: this build has no bench.sr.ht credentials" echo "the benchmarks ran and are above; nothing was uploaded" echo "the file is this build's bench.txt artifact, and can be POSTed by hand" exit 0 fi # GIT_REF is absent on a manually submitted build and ref is optional for # the API; key is SPEC ch. 4.1's idempotency key; visibility acts only on # the POST that creates $BENCH_REPO. See docs/ci.md#the-request. ref="${GIT_REF#refs/heads/}" url="$BENCH_ORIGIN/api/v1/repos/$BENCH_REPO/runs" url="$url?commit=$(git rev-parse HEAD)&ref=$ref&key=$JOB_ID&job_url=$JOB_URL" url="$url&visibility=public" echo "uploading bench.txt to $url" # Tracing off to the end: the Authorization header must not reach the log. # --fail-with-body prints the JSON error and still exits non-zero. # docs/ci.md#the-request. set +x curl -sS --fail-with-body -X POST \ -H "Authorization: Bearer $(cat ~/.bench-token)" \ --data-binary "@$HOME/bench.txt" \ "$url" echo