Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
107 changes: 107 additions & 0 deletions .github/workflows/custom-build.yml
Original file line number Diff line number Diff line change
@@ -0,0 +1,107 @@
name: NexaWrt custom component build

on:
workflow_dispatch:
inputs:
target:
description: Build target
required: true
type: choice
options:
- x86_64
- xiaomi_ax9000
flavor:
description: Build flavor (nss is valid only for xiaomi_ax9000)
required: true
type: choice
default: official
options:
- official
- nss
components:
description: Comma-separated component IDs from components/catalog.json
required: false
type: string
default: ''
catalog_version:
description: Exact catalog version displayed by the NexaWrt selector
required: true
type: string
request_hash:
description: Exact SHA256 request hash displayed by the NexaWrt selector
required: true
type: string

permissions: {}

jobs:
build:
name: Build ${{ inputs.target }} / ${{ inputs.flavor }}
if: github.event_name == 'workflow_dispatch'
runs-on: ubuntu-24.04
timeout-minutes: 360
permissions:
contents: read
env:
REQUESTED_TARGET: ${{ inputs.target }}
REQUESTED_FLAVOR: ${{ inputs.flavor }}
REQUESTED_COMPONENTS: ${{ inputs.components }}
REQUESTED_CATALOG_VERSION: ${{ inputs.catalog_version }}
REQUESTED_REQUEST_HASH: ${{ inputs.request_hash }}
steps:
- name: Check out the trusted workflow revision
uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683 # v4.2.2
with:
persist-credentials: false

- name: Enforce workflow and request policy
shell: bash
run: |
set -euo pipefail
test "$GITHUB_REPOSITORY" = 'tifycloud/NexaWrt'
test "$GITHUB_REF" = 'refs/heads/main'
test "$GITHUB_WORKFLOW_REF" = 'tifycloud/NexaWrt/.github/workflows/custom-build.yml@refs/heads/main'
test "$GITHUB_WORKFLOW_SHA" = "$GITHUB_SHA"
case "$REQUESTED_TARGET" in x86_64|xiaomi_ax9000) ;; *) exit 2 ;; esac
case "$REQUESTED_FLAVOR" in official|nss) ;; *) exit 2 ;; esac
if [[ "$REQUESTED_FLAVOR" = nss && "$REQUESTED_TARGET" != xiaomi_ax9000 ]]; then
exit 2
fi
[[ ${#REQUESTED_COMPONENTS} -le 1024 ]]
if [[ -n "$REQUESTED_COMPONENTS" ]]; then
[[ "$REQUESTED_COMPONENTS" =~ ^[a-z0-9][a-z0-9_-]{0,63}(,[a-z0-9][a-z0-9_-]{0,63})*$ ]]
fi
[[ "$REQUESTED_CATALOG_VERSION" =~ ^[0-9]{4}\.[0-9]{2}\.[0-9]{2}(\.[0-9]+)?$ ]]
[[ "$REQUESTED_REQUEST_HASH" =~ ^[0-9a-f]{64}$ ]]

- name: Install pinned build prerequisites
shell: bash
run: |
set -euo pipefail
sudo apt-get update
sudo apt-get install --yes --no-install-recommends \
build-essential clang flex bison g++ gawk gcc-multilib g++-multilib \
gettext git libncurses-dev libssl-dev python3 python3-setuptools \
python3-pyelftools python3-packaging rsync swig unzip zlib1g-dev \
file wget curl libelf-dev shellcheck subversion time xsltproc zstd

- name: Resolve catalog request and build
id: build
shell: bash
run: |
set -euo pipefail
./scripts/custom-build.sh \
"$REQUESTED_TARGET" \
"$REQUESTED_FLAVOR" \
"$REQUESTED_COMPONENTS" \
"$REQUESTED_CATALOG_VERSION" \
"$REQUESTED_REQUEST_HASH"

- name: Upload custom build artifact
uses: actions/upload-artifact@ea165f8d65b6e75b540449e92b4886f43607fa02 # v4.6.2
with:
name: ${{ steps.build.outputs.artifact_name }}
path: ${{ steps.build.outputs.artifact_dir }}
if-no-files-found: error
retention-days: 14
compression-level: 0
22 changes: 21 additions & 1 deletion .github/workflows/pages.yml
Original file line number Diff line number Diff line change
Expand Up @@ -5,13 +5,19 @@ on:
branches: [main]
paths:
- 'site/**'
- 'components/**'
- 'tests/test_pages_ui.js'
- 'tests/test_pages_policy.sh'
- 'devices/**'
- 'scripts/device_metadata.py'
- 'scripts/generate-pages-data.py'
- 'scripts/verify-pages-releases.py'
- 'scripts/verify-vm-esxi-evidence.py'
- 'schemas/vm-esxi-evidence.schema.json'
- 'evidence/vm-esxi/**'
- '.github/workflows/pages.yml'
workflow_run:
workflows: ['NexaWrt AX9000 reproducible RAM-test release', 'NexaWrt x86_64 VM release']
workflows: ['NexaWrt AX9000 reproducible RAM-test release', 'NexaWrt x86_64 VM release', 'Promote ESXi-accepted VM RC']
types: [completed]
schedule:
- cron: '17 */6 * * *'
Expand Down Expand Up @@ -70,6 +76,20 @@ jobs:
echo 'The Pages artifact must not contain symbolic or hard links.' >&2
exit 1
fi
- name: Stage component catalog for Pages
run: |
set -euo pipefail
test -f components/catalog.json
test ! -L components/catalog.json
mkdir -p site/components
cp components/catalog.json site/components/catalog.json
python3 -m json.tool site/components/catalog.json >/dev/null
test ! -L site/components/catalog.json
- name: Test Pages UI and policy
run: |
set -euo pipefail
node tests/test_pages_ui.js
bash tests/test_pages_policy.sh
- name: Configure GitHub Pages
uses: actions/configure-pages@45bfe0192ca1faeb007ade9deae92b16b8254a0d # v6.0.0
- name: Upload GitHub Pages artifact
Expand Down
Loading
Loading