1
0

test.yaml 27 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327328329330331332333334335336337338339340341342343344345346347348349350351352353354355356357358359360361362363364365366367368369370371372373374375376377378379380381382383384385386387388389390391392393394395396397398399400401402403404405406407408409410411412413414415416417418419420421422423424425426427428429430431432433434435436437438439440441442443444445446447448449450451452453454455456457458459460461462463464465466467468469470471472473474475476477478479480481482483484485486487488489490491492493494495496497498499500501502503504505506507508509510511512513514515516517518519520521522523524525526527528529530531532533534535536537538539540541542543544545546547548549550551552553554555556557558559560561562563564565566567568569570571572573574575576577578579580581582583584585586587588589590591592593594595596597598599600601602603604605606607608609610611612613614615616617618619620621622623624625626627628629
  1. name: test
  2. on:
  3. push:
  4. pull_request:
  5. workflow_dispatch:
  6. inputs:
  7. gtest_filter:
  8. description: 'Google Test filter'
  9. test_linux:
  10. description: 'Test on Linux'
  11. type: boolean
  12. default: true
  13. test_macos:
  14. description: 'Test on MacOS'
  15. type: boolean
  16. default: true
  17. test_windows:
  18. description: 'Test on Windows'
  19. type: boolean
  20. default: true
  21. concurrency:
  22. group: ${{ github.workflow }}-${{ github.ref || github.run_id }}
  23. cancel-in-progress: true
  24. env:
  25. # Exclude *_Online tests by default — they hit external services and flake on
  26. # CI runners. Run with workflow_dispatch + a custom filter to include them.
  27. GTEST_FILTER: ${{ github.event.inputs.gtest_filter || '-*_Online' }}
  28. jobs:
  29. style-check:
  30. # Uses the macOS runner's pre-installed Homebrew so clang-format tracks
  31. # whatever version `brew install clang-format` currently resolves to on
  32. # the maintainer's own Mac, instead of a version pinned in this file.
  33. runs-on: macos-latest
  34. if: github.event_name != 'pull_request' || github.event.pull_request.head.repo.full_name != github.event.pull_request.base.repo.full_name
  35. continue-on-error: true
  36. steps:
  37. - name: checkout
  38. uses: actions/checkout@v4
  39. - name: install clang-format
  40. run: |
  41. brew update
  42. brew install clang-format coreutils
  43. - name: run style check
  44. run: |
  45. clang-format --version
  46. cd test && make style_check
  47. build-and-test-on-32bit:
  48. runs-on: ubuntu-latest
  49. if: >
  50. (github.event_name == 'push') ||
  51. (github.event_name == 'pull_request' &&
  52. github.event.pull_request.head.repo.full_name != github.event.pull_request.base.repo.full_name) ||
  53. (github.event_name == 'workflow_dispatch' && github.event.inputs.test_linux == 'true')
  54. strategy:
  55. matrix:
  56. config:
  57. - arch_flags: -m32
  58. arch_suffix: :i386
  59. name: (32-bit)
  60. steps:
  61. - name: checkout
  62. uses: actions/checkout@v4
  63. - name: install libraries
  64. run: |
  65. sudo dpkg --add-architecture i386
  66. sudo apt-get update
  67. sudo apt-get install -y libc6-dev${{ matrix.config.arch_suffix }} libstdc++-13-dev${{ matrix.config.arch_suffix }} \
  68. libssl-dev${{ matrix.config.arch_suffix }} libcurl4-openssl-dev${{ matrix.config.arch_suffix }} \
  69. zlib1g-dev${{ matrix.config.arch_suffix }} libbrotli-dev${{ matrix.config.arch_suffix }} \
  70. libzstd-dev${{ matrix.config.arch_suffix }}
  71. - name: build and run tests
  72. run: cd test && make test EXTRA_CXXFLAGS="${{ matrix.config.arch_flags }}"
  73. ubuntu:
  74. runs-on: ubuntu-latest
  75. if: >
  76. (github.event_name == 'push') ||
  77. (github.event_name == 'pull_request' &&
  78. github.event.pull_request.head.repo.full_name != github.event.pull_request.base.repo.full_name) ||
  79. (github.event_name == 'workflow_dispatch' && github.event.inputs.test_linux == 'true')
  80. strategy:
  81. fail-fast: false
  82. matrix:
  83. tls_backend: [openssl, mbedtls, wolfssl]
  84. name: ubuntu (${{ matrix.tls_backend }})
  85. steps:
  86. - name: checkout
  87. uses: actions/checkout@v4
  88. - name: install common libraries
  89. run: |
  90. sudo apt-get update
  91. sudo apt-get install -y libcurl4-openssl-dev zlib1g-dev libbrotli-dev libzstd-dev
  92. - name: install OpenSSL
  93. if: matrix.tls_backend == 'openssl'
  94. run: sudo apt-get install -y libssl-dev
  95. - name: install Mbed TLS
  96. if: matrix.tls_backend == 'mbedtls'
  97. run: sudo apt-get install -y libmbedtls-dev
  98. - name: install wolfSSL
  99. if: matrix.tls_backend == 'wolfssl'
  100. run: sudo apt-get install -y libwolfssl-dev
  101. - name: build and run tests (OpenSSL)
  102. if: matrix.tls_backend == 'openssl'
  103. run: cd test && make test_split && make test_openssl_parallel
  104. env:
  105. LSAN_OPTIONS: suppressions=lsan_suppressions.txt
  106. - name: build and run tests (Mbed TLS)
  107. if: matrix.tls_backend == 'mbedtls'
  108. run: cd test && make test_split_mbedtls && make test_mbedtls_parallel
  109. - name: build and run tests (wolfSSL)
  110. if: matrix.tls_backend == 'wolfssl'
  111. run: cd test && make test_split_wolfssl && make test_wolfssl_parallel
  112. - name: run fuzz test target
  113. if: matrix.tls_backend == 'openssl'
  114. run: cd test && make fuzz_test
  115. - name: build and run WebSocket heartbeat test
  116. if: matrix.tls_backend == 'openssl'
  117. run: cd test && make test_websocket_heartbeat && ./test_websocket_heartbeat
  118. - name: build and run WebSocket TLS thread safety test
  119. if: matrix.tls_backend == 'openssl'
  120. run: cd test && make test_websocket_thread_safety && ./test_websocket_thread_safety
  121. - name: build and run ThreadPool test
  122. run: cd test && make test_thread_pool && ./test_thread_pool
  123. # Ubuntu 26.04's apt ships Mbed TLS 3.6, giving 3.x coverage that
  124. # ubuntu-latest (24.04 = 2.28) and macOS (Homebrew = 4.x) no longer provide.
  125. # Uses the 26.04 public-preview image; fold into the main ubuntu matrix once
  126. # ubuntu-latest moves to 26.04.
  127. ubuntu-2604-mbedtls:
  128. runs-on: ubuntu-26.04
  129. if: >
  130. (github.event_name == 'push') ||
  131. (github.event_name == 'pull_request' &&
  132. github.event.pull_request.head.repo.full_name != github.event.pull_request.base.repo.full_name) ||
  133. (github.event_name == 'workflow_dispatch' && github.event.inputs.test_linux == 'true')
  134. name: ubuntu-26.04 (mbedtls 3.x)
  135. steps:
  136. - name: checkout
  137. uses: actions/checkout@v4
  138. - name: install common libraries
  139. run: |
  140. sudo apt-get update
  141. sudo apt-get install -y libcurl4-openssl-dev zlib1g-dev libbrotli-dev libzstd-dev
  142. - name: install Mbed TLS
  143. run: sudo apt-get install -y libmbedtls-dev
  144. - name: build and run tests (Mbed TLS)
  145. run: cd test && make test_split_mbedtls && make test_mbedtls_parallel
  146. # BoringSSL is Google's fork of OpenSSL. It has no API stability guarantee
  147. # and is not packaged by distros, so we build it from source. cpp-httplib
  148. # treats it as an OpenSSL backend variant via the OPENSSL_IS_BORINGSSL
  149. # macro (see httplib.h). This job is best-effort: continue-on-error keeps
  150. # upstream API drift from blocking PRs while still surfacing breakage.
  151. ubuntu-boringssl:
  152. runs-on: ubuntu-latest
  153. if: >
  154. (github.event_name == 'push') ||
  155. (github.event_name == 'pull_request' &&
  156. github.event.pull_request.head.repo.full_name != github.event.pull_request.base.repo.full_name) ||
  157. (github.event_name == 'workflow_dispatch' && github.event.inputs.test_linux == 'true')
  158. continue-on-error: true
  159. name: ubuntu (boringssl, best-effort)
  160. env:
  161. # Tracking HEAD keeps us honest about upstream churn. If breakage
  162. # becomes routine, replace HEAD with a 40-char commit SHA; the
  163. # resolve step uses the SHA directly when it matches that shape.
  164. BORINGSSL_REF: HEAD
  165. BORINGSSL_PREFIX: ${{ github.workspace }}/boringssl-install
  166. steps:
  167. - name: checkout
  168. uses: actions/checkout@v4
  169. - name: install common libraries
  170. run: |
  171. sudo apt-get update
  172. sudo apt-get install -y libcurl4-openssl-dev zlib1g-dev libbrotli-dev libzstd-dev
  173. - name: resolve BoringSSL commit
  174. id: boringssl-rev
  175. # Accept either a ref name (resolved via git ls-remote) or a full
  176. # 40-char SHA used directly. ls-remote does not list arbitrary
  177. # commit SHAs, so pinning requires the second path.
  178. run: |
  179. if [[ "${BORINGSSL_REF}" =~ ^[0-9a-f]{40}$ ]]; then
  180. sha="${BORINGSSL_REF}"
  181. echo "Using pinned BoringSSL SHA: ${sha}"
  182. else
  183. sha=$(git ls-remote https://boringssl.googlesource.com/boringssl "${BORINGSSL_REF}" | awk '{print $1}')
  184. if [ -z "$sha" ]; then
  185. echo "Failed to resolve BoringSSL ref ${BORINGSSL_REF}" >&2
  186. exit 1
  187. fi
  188. echo "Resolved ${BORINGSSL_REF} -> ${sha}"
  189. fi
  190. echo "sha=${sha}" >> "$GITHUB_OUTPUT"
  191. - name: cache BoringSSL build
  192. id: boringssl-cache
  193. uses: actions/cache@v4
  194. with:
  195. path: ${{ env.BORINGSSL_PREFIX }}
  196. key: boringssl-${{ runner.os }}-${{ steps.boringssl-rev.outputs.sha }}
  197. - name: build BoringSSL
  198. if: steps.boringssl-cache.outputs.cache-hit != 'true'
  199. run: |
  200. set -e
  201. git clone https://boringssl.googlesource.com/boringssl boringssl
  202. cd boringssl
  203. git checkout "${{ steps.boringssl-rev.outputs.sha }}"
  204. cmake -S . -B build \
  205. -DCMAKE_BUILD_TYPE=Release \
  206. -DBUILD_SHARED_LIBS=OFF \
  207. -DCMAKE_POSITION_INDEPENDENT_CODE=ON \
  208. -DCMAKE_INSTALL_PREFIX="${BORINGSSL_PREFIX}"
  209. cmake --build build -j"$(nproc)" --target install
  210. - name: build and run tests (BoringSSL)
  211. # Override OPENSSL_SUPPORT to point the existing OpenSSL Makefile path
  212. # at BoringSSL's prefix. BoringSSL defines OPENSSL_IS_BORINGSSL in
  213. # <openssl/base.h>, which httplib.h and test.cc use to switch on API
  214. # differences (e.g. SAN-only hostname verification, no CN fallback).
  215. #
  216. # BoringSSL's public headers (<openssl/stack.h>) use std::enable_if_t,
  217. # so consumers must compile with C++14 or later. cpp-httplib itself
  218. # supports C++11, but anyone pairing it with BoringSSL inherits this
  219. # constraint. EXTRA_CXXFLAGS appends after the Makefile's -std=c++11
  220. # and the later flag wins.
  221. run: |
  222. cd test
  223. BORINGSSL_FLAGS="-DCPPHTTPLIB_OPENSSL_SUPPORT -I${BORINGSSL_PREFIX}/include -L${BORINGSSL_PREFIX}/lib -lssl -lcrypto -lpthread"
  224. make test_split OPENSSL_SUPPORT="${BORINGSSL_FLAGS}" EXTRA_CXXFLAGS="-std=c++17"
  225. make test_openssl_parallel OPENSSL_SUPPORT="${BORINGSSL_FLAGS}" EXTRA_CXXFLAGS="-std=c++17"
  226. env:
  227. LSAN_OPTIONS: suppressions=lsan_suppressions.txt
  228. # macOS counterpart of the BoringSSL job. Same best-effort posture; the
  229. # extra framework links cover the macOS Keychain integration that
  230. # httplib.h auto-enables for any TLS backend on macOS.
  231. macos-boringssl:
  232. runs-on: macos-latest
  233. if: >
  234. (github.event_name == 'push') ||
  235. (github.event_name == 'pull_request' &&
  236. github.event.pull_request.head.repo.full_name != github.event.pull_request.base.repo.full_name) ||
  237. (github.event_name == 'workflow_dispatch' && github.event.inputs.test_macos == 'true')
  238. continue-on-error: true
  239. name: macos (boringssl, best-effort)
  240. env:
  241. BORINGSSL_REF: HEAD
  242. BORINGSSL_PREFIX: ${{ github.workspace }}/boringssl-install
  243. steps:
  244. - name: checkout
  245. uses: actions/checkout@v4
  246. - name: resolve BoringSSL commit
  247. id: boringssl-rev
  248. # Accept either a ref name (resolved via git ls-remote) or a full
  249. # 40-char SHA used directly. ls-remote does not list arbitrary
  250. # commit SHAs, so pinning requires the second path.
  251. run: |
  252. if [[ "${BORINGSSL_REF}" =~ ^[0-9a-f]{40}$ ]]; then
  253. sha="${BORINGSSL_REF}"
  254. echo "Using pinned BoringSSL SHA: ${sha}"
  255. else
  256. sha=$(git ls-remote https://boringssl.googlesource.com/boringssl "${BORINGSSL_REF}" | awk '{print $1}')
  257. if [ -z "$sha" ]; then
  258. echo "Failed to resolve BoringSSL ref ${BORINGSSL_REF}" >&2
  259. exit 1
  260. fi
  261. echo "Resolved ${BORINGSSL_REF} -> ${sha}"
  262. fi
  263. echo "sha=${sha}" >> "$GITHUB_OUTPUT"
  264. - name: cache BoringSSL build
  265. id: boringssl-cache
  266. uses: actions/cache@v4
  267. with:
  268. path: ${{ env.BORINGSSL_PREFIX }}
  269. key: boringssl-${{ runner.os }}-${{ steps.boringssl-rev.outputs.sha }}
  270. - name: build BoringSSL
  271. if: steps.boringssl-cache.outputs.cache-hit != 'true'
  272. run: |
  273. set -e
  274. git clone https://boringssl.googlesource.com/boringssl boringssl
  275. cd boringssl
  276. git checkout "${{ steps.boringssl-rev.outputs.sha }}"
  277. cmake -S . -B build \
  278. -DCMAKE_BUILD_TYPE=Release \
  279. -DBUILD_SHARED_LIBS=OFF \
  280. -DCMAKE_POSITION_INDEPENDENT_CODE=ON \
  281. -DCMAKE_INSTALL_PREFIX="${BORINGSSL_PREFIX}"
  282. cmake --build build -j"$(sysctl -n hw.ncpu)" --target install
  283. - name: build and run tests (BoringSSL)
  284. run: |
  285. cd test
  286. # CoreFoundation/Security frameworks satisfy the Keychain integration
  287. # auto-enabled in httplib.h for macOS TLS builds.
  288. BORINGSSL_FLAGS="-DCPPHTTPLIB_OPENSSL_SUPPORT -I${BORINGSSL_PREFIX}/include -L${BORINGSSL_PREFIX}/lib -lssl -lcrypto -framework CoreFoundation -framework Security"
  289. make test_split OPENSSL_SUPPORT="${BORINGSSL_FLAGS}" EXTRA_CXXFLAGS="-std=c++17"
  290. make test_openssl_parallel OPENSSL_SUPPORT="${BORINGSSL_FLAGS}" EXTRA_CXXFLAGS="-std=c++17"
  291. env:
  292. LSAN_OPTIONS: suppressions=lsan_suppressions.txt
  293. # Reproducer for https://github.com/yhirose/cpp-httplib/issues/2431.
  294. # On Linux/glibc, getaddrinfo_with_timeout() schedules an asynchronous
  295. # DNS lookup with getaddrinfo_a(GAI_NOWAIT) using a stack-local gaicb.
  296. # When gai_suspend() hits the connection timeout, gai_cancel() is called
  297. # but does not block; the resolver worker can later write back into the
  298. # destroyed stack frame. To make the worker actually reach that write,
  299. # the test job runs a loopback UDP responder (test/dns_test_fixture.py)
  300. # that delays its reply past the test's 1s timeout, and uses an iptables
  301. # NAT rule so glibc's lookups land on that fixture instead of a real
  302. # nameserver. With ASAN's detect_stack_use_after_return enabled, the
  303. # late write-back is reported as a stack-use-after-return.
  304. issue-2431-repro:
  305. runs-on: ubuntu-latest
  306. if: >
  307. (github.event_name == 'push') ||
  308. (github.event_name == 'pull_request' &&
  309. github.event.pull_request.head.repo.full_name != github.event.pull_request.base.repo.full_name) ||
  310. (github.event_name == 'workflow_dispatch' && github.event.inputs.test_linux == 'true')
  311. name: issue-2431 repro (Linux + ASAN)
  312. # Bound the whole job in case anything in the test harness hangs
  313. # unexpectedly. With the fixture in place a normal run is well under
  314. # a minute either way (ASAN abort on broken HEAD, clean pass on fix).
  315. timeout-minutes: 5
  316. env:
  317. DNS_FIXTURE_PORT: "15353"
  318. DNS_FIXTURE_DELAY: "3"
  319. steps:
  320. - name: checkout
  321. uses: actions/checkout@v4
  322. - name: install libraries
  323. run: |
  324. sudo apt-get update
  325. sudo apt-get install -y libssl-dev zlib1g-dev libbrotli-dev \
  326. libzstd-dev libcurl4-openssl-dev iptables util-linux iproute2
  327. - name: start loopback DNS test fixture
  328. run: |
  329. # Force glibc through its DNS code path: Ubuntu's default
  330. # nsswitch short-circuits to NOTFOUND through mdns4_minimal,
  331. # which would skip the buggy code entirely.
  332. sudo sed -i 's/^hosts:.*/hosts: dns/' /etc/nsswitch.conf
  333. # Run the loopback fixture (delayed UDP responder).
  334. python3 test/dns_test_fixture.py "$DNS_FIXTURE_PORT" "$DNS_FIXTURE_DELAY" \
  335. >/tmp/dns_fixture.log 2>&1 &
  336. echo $! | sudo tee /tmp/dns_fixture.pid >/dev/null
  337. # Wait for the fixture to start listening.
  338. for _ in $(seq 1 50); do
  339. if ss -lun "( sport = :$DNS_FIXTURE_PORT )" | grep -q ":$DNS_FIXTURE_PORT"; then
  340. break
  341. fi
  342. sleep 0.1
  343. done
  344. ss -lun "( sport = :$DNS_FIXTURE_PORT )" | grep -q ":$DNS_FIXTURE_PORT" \
  345. || { echo "fixture failed to start"; cat /tmp/dns_fixture.log; exit 1; }
  346. # Send the test process's DNS lookups to the loopback fixture.
  347. # NAT only the local OUTPUT chain; conntrack handles the reply path.
  348. sudo iptables -t nat -I OUTPUT -p udp --dport 53 \
  349. -j REDIRECT --to-port "$DNS_FIXTURE_PORT"
  350. # Sanity check: a query must take at least the fixture delay
  351. # and resolve to NXDOMAIN (proving traffic reaches the fixture).
  352. start=$(date +%s)
  353. getent hosts unresolvable-host.invalid >/dev/null 2>&1 || true
  354. elapsed=$(( $(date +%s) - start ))
  355. if [ "$elapsed" -lt 2 ]; then
  356. echo "ERROR: lookup returned in ${elapsed}s; fixture not in path" >&2
  357. exit 1
  358. fi
  359. echo "[ok] DNS lookups are routed to the test fixture (took ${elapsed}s)"
  360. - name: build test binary
  361. run: cd test && make test
  362. - name: run GetAddrInfoAsyncCancelTest
  363. run: |
  364. cd test
  365. ARCH=$(uname -m)
  366. CPPHTTPLIB_TEST_ISSUE_2431=1 \
  367. ASAN_OPTIONS=detect_stack_use_after_return=1 \
  368. LSAN_OPTIONS=suppressions=lsan_suppressions.txt \
  369. setarch "$ARCH" -R \
  370. ./test --gtest_filter='GetAddrInfoAsyncCancelTest.*'
  371. - name: tear down test fixture
  372. if: always()
  373. run: |
  374. sudo iptables -t nat -F OUTPUT || true
  375. if [ -f /tmp/dns_fixture.pid ]; then
  376. sudo kill "$(cat /tmp/dns_fixture.pid)" 2>/dev/null || true
  377. fi
  378. macos:
  379. runs-on: macos-latest
  380. if: >
  381. (github.event_name == 'push') ||
  382. (github.event_name == 'pull_request' &&
  383. github.event.pull_request.head.repo.full_name != github.event.pull_request.base.repo.full_name) ||
  384. (github.event_name == 'workflow_dispatch' && github.event.inputs.test_macos == 'true')
  385. strategy:
  386. fail-fast: false
  387. matrix:
  388. tls_backend: [openssl, mbedtls, wolfssl]
  389. name: macos (${{ matrix.tls_backend }})
  390. steps:
  391. - name: checkout
  392. uses: actions/checkout@v4
  393. - name: install Mbed TLS
  394. if: matrix.tls_backend == 'mbedtls'
  395. run: brew install mbedtls
  396. - name: install wolfSSL
  397. if: matrix.tls_backend == 'wolfssl'
  398. run: brew install wolfssl
  399. - name: build and run tests (OpenSSL)
  400. if: matrix.tls_backend == 'openssl'
  401. run: cd test && make test_split && make test_openssl_parallel
  402. env:
  403. LSAN_OPTIONS: suppressions=lsan_suppressions.txt
  404. - name: build and run tests (Mbed TLS)
  405. if: matrix.tls_backend == 'mbedtls'
  406. run: cd test && make test_split_mbedtls && make test_mbedtls_parallel
  407. - name: build and run tests (wolfSSL)
  408. if: matrix.tls_backend == 'wolfssl'
  409. run: cd test && make test_split_wolfssl && make test_wolfssl_parallel
  410. - name: run fuzz test target
  411. if: matrix.tls_backend == 'openssl'
  412. run: cd test && make fuzz_test
  413. - name: build and run WebSocket heartbeat test
  414. if: matrix.tls_backend == 'openssl'
  415. run: cd test && make test_websocket_heartbeat && ./test_websocket_heartbeat
  416. - name: build and run WebSocket TLS thread safety test
  417. if: matrix.tls_backend == 'openssl'
  418. run: cd test && make test_websocket_thread_safety && ./test_websocket_thread_safety
  419. - name: build and run ThreadPool test
  420. run: cd test && make test_thread_pool && ./test_thread_pool
  421. ios-parse-check:
  422. runs-on: macos-latest
  423. if: >
  424. (github.event_name == 'push') ||
  425. (github.event_name == 'pull_request' &&
  426. github.event.pull_request.head.repo.full_name != github.event.pull_request.base.repo.full_name) ||
  427. (github.event_name == 'workflow_dispatch' && github.event.inputs.test_macos == 'true')
  428. name: ios header parse check (not officially supported)
  429. steps:
  430. - name: checkout
  431. uses: actions/checkout@v4
  432. - name: install OpenSSL headers
  433. run: brew install openssl@3
  434. - name: verify header parses on iOS target
  435. run: |
  436. IOS_SDK=$(xcrun --sdk iphoneos --show-sdk-path)
  437. OPENSSL_INC=$(brew --prefix openssl@3)/include
  438. echo "Using iOS SDK: $IOS_SDK"
  439. echo '#include "httplib.h"' | clang++ \
  440. -isysroot "$IOS_SDK" \
  441. -target arm64-apple-ios16.0 \
  442. -std=c++11 \
  443. -DCPPHTTPLIB_OPENSSL_SUPPORT \
  444. -I"$OPENSSL_INC" \
  445. -I. -Wall -Wextra \
  446. -fsyntax-only -x c++ -
  447. - name: verify CPPHTTPLIB_USE_CERTS_FROM_MACOSX_KEYCHAIN is rejected on iOS
  448. run: |
  449. IOS_SDK=$(xcrun --sdk iphoneos --show-sdk-path)
  450. OPENSSL_INC=$(brew --prefix openssl@3)/include
  451. out=$(echo '#include "httplib.h"' | clang++ \
  452. -isysroot "$IOS_SDK" \
  453. -target arm64-apple-ios16.0 \
  454. -std=c++11 \
  455. -DCPPHTTPLIB_OPENSSL_SUPPORT \
  456. -DCPPHTTPLIB_USE_CERTS_FROM_MACOSX_KEYCHAIN \
  457. -I"$OPENSSL_INC" \
  458. -I. \
  459. -fsyntax-only -x c++ - 2>&1 || true)
  460. if echo "$out" | grep -q "only supported on macOS"; then
  461. echo "OK: #error fired as expected"
  462. else
  463. echo "FAIL: expected #error did not fire"
  464. echo "--- compiler output ---"
  465. echo "$out"
  466. exit 1
  467. fi
  468. windows:
  469. runs-on: windows-latest
  470. permissions:
  471. contents: read
  472. if: >
  473. (github.event_name == 'push') ||
  474. (github.event_name == 'pull_request' &&
  475. github.event.pull_request.head.repo.full_name != github.event.pull_request.base.repo.full_name) ||
  476. (github.event_name == 'workflow_dispatch' && github.event.inputs.test_windows == 'true')
  477. strategy:
  478. fail-fast: false
  479. matrix:
  480. config:
  481. - with_ssl: false
  482. compiled: false
  483. run_tests: true
  484. name: without SSL
  485. - with_ssl: true
  486. compiled: false
  487. run_tests: true
  488. name: with SSL
  489. - with_ssl: false
  490. compiled: true
  491. run_tests: false
  492. name: compiled
  493. name: windows ${{ matrix.config.name }}
  494. steps:
  495. - name: Prepare Git for Checkout on Windows
  496. run: |
  497. git config --global core.autocrlf false
  498. git config --global core.eol lf
  499. - name: Checkout
  500. uses: actions/checkout@v4
  501. - name: Export GitHub Actions cache environment variables
  502. uses: actions/github-script@v7
  503. with:
  504. script: |
  505. core.exportVariable('ACTIONS_CACHE_URL', process.env.ACTIONS_CACHE_URL || '');
  506. core.exportVariable('ACTIONS_RUNTIME_TOKEN', process.env.ACTIONS_RUNTIME_TOKEN || '');
  507. - name: Setup msbuild on windows
  508. uses: microsoft/setup-msbuild@v2
  509. - name: Cache vcpkg packages
  510. id: vcpkg-cache
  511. uses: actions/cache@v4
  512. with:
  513. path: C:/vcpkg/installed
  514. key: vcpkg-installed-windows-gtest-curl-zlib-brotli-zstd
  515. - name: Install vcpkg dependencies
  516. if: steps.vcpkg-cache.outputs.cache-hit != 'true'
  517. run: vcpkg install gtest curl zlib brotli zstd
  518. - name: Install OpenSSL
  519. if: ${{ matrix.config.with_ssl }}
  520. shell: pwsh
  521. run: |
  522. # Chocolatey's openssl package hardcodes a versioned slproweb URL, and
  523. # slproweb keeps only the newest build of each branch. The package
  524. # therefore 404s on every OpenSSL release until someone respins it.
  525. # Read slproweb's own manifest instead: it is updated at the same time
  526. # as the downloads it points at, so the URL is always live.
  527. $ErrorActionPreference = 'Stop'
  528. $ProgressPreference = 'SilentlyContinue' # Invoke-WebRequest is slow with it
  529. $manifest = 'https://raw.githubusercontent.com/slproweb/opensslhashes/master/win32_openssl_hashes.json'
  530. $entry = (Invoke-RestMethod $manifest).files.PSObject.Properties.Value |
  531. Where-Object {
  532. $_.bits -eq 64 -and $_.arch -eq 'INTEL' -and
  533. -not $_.light -and $_.installer -eq 'exe' -and $_.basever -like '4.*'
  534. } |
  535. Sort-Object { [version]$_.basever } | Select-Object -Last 1
  536. if (-not $entry) { throw 'No 64-bit OpenSSL 4.x installer found in the manifest' }
  537. Write-Host "Installing OpenSSL $($entry.basever) from $($entry.url)"
  538. $installer = Join-Path $env:RUNNER_TEMP 'Win64OpenSSL.exe'
  539. Invoke-WebRequest $entry.url -OutFile $installer
  540. $actual = (Get-FileHash $installer -Algorithm SHA512).Hash.ToLower()
  541. if ($actual -ne $entry.sha512.ToLower()) {
  542. throw "SHA512 mismatch: expected $($entry.sha512), got $actual"
  543. }
  544. # Same silent flags the Chocolatey package used. The installer is Inno
  545. # Setup, so /DIR pins the location CMake already looks in. The inner
  546. # quotes matter: ArgumentList joins on spaces, so an unquoted /DIR
  547. # would install to C:\Program and only fail later, at load time.
  548. $dir = 'C:\Program Files\OpenSSL'
  549. $proc = Start-Process $installer -Wait -PassThru -ArgumentList `
  550. '/VERYSILENT', '/SUPPRESSMSGBOXES', '/NORESTART', '/SP-', "/DIR=`"$dir`""
  551. if ($proc.ExitCode -ne 0) { throw "Installer exited with $($proc.ExitCode)" }
  552. # Catch a misplaced install here rather than at link or load time.
  553. if (-not (Test-Path "$dir\lib\VC\x64\MD\libcrypto.lib")) {
  554. throw "OpenSSL import libraries missing under $dir"
  555. }
  556. if (-not (Get-ChildItem "$dir\bin\libcrypto-*.dll" -ErrorAction SilentlyContinue)) {
  557. throw "OpenSSL runtime DLLs missing under $dir\bin"
  558. }
  559. "$dir\bin" | Out-File $env:GITHUB_PATH -Append -Encoding utf8
  560. "OPENSSL_CONF=$dir\bin\openssl.cfg" | Out-File $env:GITHUB_ENV -Append -Encoding utf8
  561. - name: Configure CMake ${{ matrix.config.name }}
  562. run: >
  563. cmake -B build -S .
  564. -DCMAKE_BUILD_TYPE=Release
  565. -DCMAKE_TOOLCHAIN_FILE=${{ env.VCPKG_ROOT }}/scripts/buildsystems/vcpkg.cmake
  566. -DHTTPLIB_TEST=ON
  567. -DHTTPLIB_COMPILE=${{ matrix.config.compiled && 'ON' || 'OFF' }}
  568. -DHTTPLIB_USE_OPENSSL_IF_AVAILABLE=${{ matrix.config.with_ssl && 'ON' || 'OFF' }}
  569. -DHTTPLIB_REQUIRE_ZLIB=ON
  570. -DHTTPLIB_REQUIRE_BROTLI=ON
  571. -DHTTPLIB_REQUIRE_ZSTD=ON
  572. -DHTTPLIB_REQUIRE_OPENSSL=${{ matrix.config.with_ssl && 'ON' || 'OFF' }}
  573. - name: Build ${{ matrix.config.name }}
  574. run: cmake --build build --config Release -- /v:m /clp:ShowCommandLine
  575. - name: Run tests ${{ matrix.config.name }}
  576. if: ${{ matrix.config.run_tests }}
  577. shell: pwsh
  578. working-directory: build/test
  579. run: |
  580. $shards = 4
  581. $procs = @()
  582. for ($i = 0; $i -lt $shards; $i++) {
  583. $log = "shard_${i}.log"
  584. $procs += Start-Process -FilePath ./Release/httplib-test.exe `
  585. -ArgumentList "--gtest_color=yes","--gtest_filter=${{ github.event.inputs.gtest_filter || '-*_Online' }}" `
  586. -NoNewWindow -PassThru -RedirectStandardOutput $log -RedirectStandardError "${log}.err" `
  587. -Environment @{ GTEST_TOTAL_SHARDS="$shards"; GTEST_SHARD_INDEX="$i" }
  588. }
  589. $procs | Wait-Process
  590. $failed = $false
  591. for ($i = 0; $i -lt $shards; $i++) {
  592. $log = "shard_${i}.log"
  593. $proc = $procs[$i]
  594. $hasPassed = Select-String -Path $log -Pattern "\[ PASSED \]" -Quiet
  595. $hasFailed = Select-String -Path $log -Pattern "\[ FAILED \]" -Quiet
  596. if ($hasPassed -and -not $hasFailed -and $proc.ExitCode -eq 0) {
  597. $passed = (Select-String -Path $log -Pattern "\[ PASSED \]").Line
  598. Write-Host "Shard ${i}: $passed"
  599. } else {
  600. Write-Host "=== Shard $i FAILED (exit=$($proc.ExitCode)) ==="
  601. Get-Content $log
  602. if (Test-Path "${log}.err") { Get-Content "${log}.err" }
  603. $failed = $true
  604. }
  605. }
  606. if ($failed) { exit 1 }
  607. Write-Host "All shards passed."
  608. env:
  609. VCPKG_ROOT: "C:/vcpkg"
  610. VCPKG_BINARY_SOURCES: "clear;x-gha,readwrite"