artifacts: - cover.out - bench.txt environment: BENCH_ORIGIN: https://bench.srht.bigb.es BENCH_REPO: ~bigbes/sr-ht-core BUILD_SUBMITTER: git.sr.ht COVER_ORIGIN: https://cov.srht.bigb.es COVER_REPO: ~bigbes/sr-ht-core GIT_REF: refs/heads/master REPO: sr-ht-core image: alpine/edge packages: - curl - git - go - golangci-lint secrets: - c7968415-1a6d-4ca0-a188-150fb7f57b65 sources: - "https://git.srht.bigb.es/~bigbes/sr-ht-core#b08bf2d6fdd2c5e3738b549cbe2ec10d50231cd9" submitter: git.sr.ht: allow-refs: - refs/heads/master - refs/tags/v* tasks: - lint: | cd "$REPO" golangci-lint run - build: | cd "$REPO" go build ./... - test: | cd "$REPO" # -covermode=atomic gives real hit counts instead of a set/unset bit, # which is what cov.sr.ht's line counts are made of. go test -covermode=atomic -coverprofile="$HOME/cover.out" ./... go tool cover -func="$HOME/cover.out" | tail -1 - coverage: | cd "$REPO" if [ ! -r ~/.srht-token ]; then echo "no ~/.srht-token: this build runs without cov.sr.ht credentials" echo "the profile is still available as this build's cover.out artifact" exit 0 fi # GIT_REF is absent on a manually submitted build, and ref is optional for # the API. key is the idempotency key. Both prefixes are stripped because # this pipeline builds tags too, and a tag build would otherwise report # ref=refs/tags/v0.1.0. ref="${GIT_REF#refs/heads/}" ref="${ref#refs/tags/}" url="$COVER_ORIGIN/api/v1/repos/$COVER_REPO/reports" url="$url?commit=$(git rev-parse HEAD)&ref=$ref&key=$JOB_ID&job_url=$JOB_URL" echo "uploading cover.out to $url" # Tracing off to the end of the task: the Authorization header must not # reach the log. No Content-Type — the service sniffs the body. # --fail-with-body prints the JSON error and still exits non-zero. set +x curl -sS --fail-with-body -X POST \ -H "Authorization: Bearer $(cat ~/.srht-token)" \ --data-binary "@$HOME/cover.out" \ "$url" echo - bench: | cd "$REPO" # A redirect and a cat, not `| tee`: tee's exit status would let a failing # benchmark pass. -run '^$' so no test runs a second time here, -benchmem # because the allocation counts are half of what these benchmarks are for. # # -count=10 because bench.sr.ht's confidence interval only becomes finite # at six repetitions and a comparison significant at four, so anything # under six uploads points the service can only mark "low n". -benchtime # pays for those ten repetitions: this suite has ~50 cases, and ten # repetitions at the default second apiece is a quarter of an hour on a # shared builder. 300ms still leaves millions of iterations for the # sub-microsecond cases and thousands for the Ed25519 ones. go test -run '^$' -bench . -benchmem -benchtime=300ms -count=10 \ -timeout 20m ./... > "$HOME/bench.txt" cat "$HOME/bench.txt" # `go test -bench` that matches nothing still prints ok and exits 0, and a # file with no result lines is valid benchfmt — it would upload nothing # and report success. Name one benchmark per package that has any, so a # package losing its benchmarks stops this build. grep -q '^BenchmarkDecodeBearerToken' "$HOME/bench.txt" grep -q '^BenchmarkBearerHMAC' "$HOME/bench.txt" grep -q '^BenchmarkCursorMarshalGQL' "$HOME/bench.txt" grep -q '^BenchmarkColumns' "$HOME/bench.txt" - benchmarks: | cd "$REPO" if [ ! -r ~/.srht-token ]; then echo "no ~/.srht-token: this build runs without bench.sr.ht credentials" echo "the benchmarks ran and are in the bench task's log above" echo "the file is this build's bench.txt artifact, and can be POSTed by hand" exit 0 fi # visibility acts only on the POST that first creates $BENCH_REPO; on # every later run it is ignored. ref="${GIT_REF#refs/heads/}" ref="${ref#refs/tags/}" url="$BENCH_ORIGIN/api/v1/repos/$BENCH_REPO/runs" url="$url?commit=$(git rev-parse HEAD)&ref=$ref&key=$JOB_ID&job_url=$JOB_URL" url="$url&visibility=public" echo "uploading bench.txt to $url" set +x curl -sS --fail-with-body -X POST \ -H "Authorization: Bearer $(cat ~/.srht-token)" \ --data-binary "@$HOME/bench.txt" \ "$url" echo