test.yaml 25 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327328329330331332333334335336337338339340341342343344345346347348349350351352353354355356357358359360361362363364365366367368369370371372373374375376377378379380381382383384385386387388389390391392393394395396397398399400401402403404405406407408409410411412413414415416417418419420421422423424425426427428429430431432433434435436437438439440441442443444445446447448449450451452453454455456457458459460461462463464465466467468469470471472473474475476477478479480481482483484485486487488489490491492493494495496497498499500501502503504505506507508509510511512513514515516517518519520521522523524525526527528529530531532533534535536537538539540541542543544545546547548549550551552553554555556557558559560561562563564565566567568569570571572573574575576577578
  1. name: test
  2. on:
  3. push:
  4. pull_request:
  5. workflow_dispatch:
  6. inputs:
  7. gtest_filter:
  8. description: 'Google Test filter'
  9. test_linux:
  10. description: 'Test on Linux'
  11. type: boolean
  12. default: true
  13. test_macos:
  14. description: 'Test on MacOS'
  15. type: boolean
  16. default: true
  17. test_windows:
  18. description: 'Test on Windows'
  19. type: boolean
  20. default: true
  21. concurrency:
  22. group: ${{ github.workflow }}-${{ github.ref || github.run_id }}
  23. cancel-in-progress: true
  24. env:
  25. # Exclude *_Online tests by default — they hit external services and flake on
  26. # CI runners. Run with workflow_dispatch + a custom filter to include them.
  27. GTEST_FILTER: ${{ github.event.inputs.gtest_filter || '-*_Online' }}
  28. jobs:
  29. style-check:
  30. runs-on: ubuntu-latest
  31. if: github.event_name != 'pull_request' || github.event.pull_request.head.repo.full_name != github.event.pull_request.base.repo.full_name
  32. continue-on-error: true
  33. steps:
  34. - name: checkout
  35. uses: actions/checkout@v4
  36. - name: run style check
  37. run: |
  38. clang-format --version
  39. cd test && make style_check
  40. build-and-test-on-32bit:
  41. runs-on: ubuntu-latest
  42. if: >
  43. (github.event_name == 'push') ||
  44. (github.event_name == 'pull_request' &&
  45. github.event.pull_request.head.repo.full_name != github.event.pull_request.base.repo.full_name) ||
  46. (github.event_name == 'workflow_dispatch' && github.event.inputs.test_linux == 'true')
  47. strategy:
  48. matrix:
  49. config:
  50. - arch_flags: -m32
  51. arch_suffix: :i386
  52. name: (32-bit)
  53. steps:
  54. - name: checkout
  55. uses: actions/checkout@v4
  56. - name: install libraries
  57. run: |
  58. sudo dpkg --add-architecture i386
  59. sudo apt-get update
  60. sudo apt-get install -y libc6-dev${{ matrix.config.arch_suffix }} libstdc++-13-dev${{ matrix.config.arch_suffix }} \
  61. libssl-dev${{ matrix.config.arch_suffix }} libcurl4-openssl-dev${{ matrix.config.arch_suffix }} \
  62. zlib1g-dev${{ matrix.config.arch_suffix }} libbrotli-dev${{ matrix.config.arch_suffix }} \
  63. libzstd-dev${{ matrix.config.arch_suffix }}
  64. - name: build and run tests
  65. run: cd test && make test EXTRA_CXXFLAGS="${{ matrix.config.arch_flags }}"
  66. ubuntu:
  67. runs-on: ubuntu-latest
  68. if: >
  69. (github.event_name == 'push') ||
  70. (github.event_name == 'pull_request' &&
  71. github.event.pull_request.head.repo.full_name != github.event.pull_request.base.repo.full_name) ||
  72. (github.event_name == 'workflow_dispatch' && github.event.inputs.test_linux == 'true')
  73. strategy:
  74. fail-fast: false
  75. matrix:
  76. tls_backend: [openssl, mbedtls, wolfssl]
  77. name: ubuntu (${{ matrix.tls_backend }})
  78. steps:
  79. - name: checkout
  80. uses: actions/checkout@v4
  81. - name: install common libraries
  82. run: |
  83. sudo apt-get update
  84. sudo apt-get install -y libcurl4-openssl-dev zlib1g-dev libbrotli-dev libzstd-dev
  85. - name: install OpenSSL
  86. if: matrix.tls_backend == 'openssl'
  87. run: sudo apt-get install -y libssl-dev
  88. - name: install Mbed TLS
  89. if: matrix.tls_backend == 'mbedtls'
  90. run: sudo apt-get install -y libmbedtls-dev
  91. - name: install wolfSSL
  92. if: matrix.tls_backend == 'wolfssl'
  93. run: sudo apt-get install -y libwolfssl-dev
  94. - name: build and run tests (OpenSSL)
  95. if: matrix.tls_backend == 'openssl'
  96. run: cd test && make test_split && make test_openssl_parallel
  97. env:
  98. LSAN_OPTIONS: suppressions=lsan_suppressions.txt
  99. - name: build and run tests (Mbed TLS)
  100. if: matrix.tls_backend == 'mbedtls'
  101. # Run mbedTLS shards with reduced parallelism — under ASAN+mbedTLS the
  102. # default 4 shards overload CI runners enough that timing-sensitive
  103. # ServerTest cases flake on first-request keep-alive reuse.
  104. run: cd test && make test_split_mbedtls && SHARDS=2 make test_mbedtls_parallel
  105. - name: build and run tests (wolfSSL)
  106. if: matrix.tls_backend == 'wolfssl'
  107. run: cd test && make test_split_wolfssl && make test_wolfssl_parallel
  108. - name: run fuzz test target
  109. if: matrix.tls_backend == 'openssl'
  110. run: cd test && make fuzz_test
  111. - name: build and run WebSocket heartbeat test
  112. if: matrix.tls_backend == 'openssl'
  113. run: cd test && make test_websocket_heartbeat && ./test_websocket_heartbeat
  114. - name: build and run ThreadPool test
  115. run: cd test && make test_thread_pool && ./test_thread_pool
  116. # Ubuntu 26.04's apt ships Mbed TLS 3.6, giving 3.x coverage that
  117. # ubuntu-latest (24.04 = 2.28) and macOS (Homebrew = 4.x) no longer provide.
  118. # Uses the 26.04 public-preview image; fold into the main ubuntu matrix once
  119. # ubuntu-latest moves to 26.04.
  120. ubuntu-2604-mbedtls:
  121. runs-on: ubuntu-26.04
  122. if: >
  123. (github.event_name == 'push') ||
  124. (github.event_name == 'pull_request' &&
  125. github.event.pull_request.head.repo.full_name != github.event.pull_request.base.repo.full_name) ||
  126. (github.event_name == 'workflow_dispatch' && github.event.inputs.test_linux == 'true')
  127. name: ubuntu-26.04 (mbedtls 3.x)
  128. steps:
  129. - name: checkout
  130. uses: actions/checkout@v4
  131. - name: install common libraries
  132. run: |
  133. sudo apt-get update
  134. sudo apt-get install -y libcurl4-openssl-dev zlib1g-dev libbrotli-dev libzstd-dev
  135. - name: install Mbed TLS
  136. run: sudo apt-get install -y libmbedtls-dev
  137. - name: build and run tests (Mbed TLS)
  138. # Run mbedTLS shards with reduced parallelism — under ASAN+mbedTLS the
  139. # default 4 shards overload CI runners enough that timing-sensitive
  140. # ServerTest cases flake on first-request keep-alive reuse.
  141. run: cd test && make test_split_mbedtls && SHARDS=2 make test_mbedtls_parallel
  142. # BoringSSL is Google's fork of OpenSSL. It has no API stability guarantee
  143. # and is not packaged by distros, so we build it from source. cpp-httplib
  144. # treats it as an OpenSSL backend variant via the OPENSSL_IS_BORINGSSL
  145. # macro (see httplib.h). This job is best-effort: continue-on-error keeps
  146. # upstream API drift from blocking PRs while still surfacing breakage.
  147. ubuntu-boringssl:
  148. runs-on: ubuntu-latest
  149. if: >
  150. (github.event_name == 'push') ||
  151. (github.event_name == 'pull_request' &&
  152. github.event.pull_request.head.repo.full_name != github.event.pull_request.base.repo.full_name) ||
  153. (github.event_name == 'workflow_dispatch' && github.event.inputs.test_linux == 'true')
  154. continue-on-error: true
  155. name: ubuntu (boringssl, best-effort)
  156. env:
  157. # Tracking HEAD keeps us honest about upstream churn. If breakage
  158. # becomes routine, replace HEAD with a 40-char commit SHA; the
  159. # resolve step uses the SHA directly when it matches that shape.
  160. BORINGSSL_REF: HEAD
  161. BORINGSSL_PREFIX: ${{ github.workspace }}/boringssl-install
  162. steps:
  163. - name: checkout
  164. uses: actions/checkout@v4
  165. - name: install common libraries
  166. run: |
  167. sudo apt-get update
  168. sudo apt-get install -y libcurl4-openssl-dev zlib1g-dev libbrotli-dev libzstd-dev
  169. - name: resolve BoringSSL commit
  170. id: boringssl-rev
  171. # Accept either a ref name (resolved via git ls-remote) or a full
  172. # 40-char SHA used directly. ls-remote does not list arbitrary
  173. # commit SHAs, so pinning requires the second path.
  174. run: |
  175. if [[ "${BORINGSSL_REF}" =~ ^[0-9a-f]{40}$ ]]; then
  176. sha="${BORINGSSL_REF}"
  177. echo "Using pinned BoringSSL SHA: ${sha}"
  178. else
  179. sha=$(git ls-remote https://boringssl.googlesource.com/boringssl "${BORINGSSL_REF}" | awk '{print $1}')
  180. if [ -z "$sha" ]; then
  181. echo "Failed to resolve BoringSSL ref ${BORINGSSL_REF}" >&2
  182. exit 1
  183. fi
  184. echo "Resolved ${BORINGSSL_REF} -> ${sha}"
  185. fi
  186. echo "sha=${sha}" >> "$GITHUB_OUTPUT"
  187. - name: cache BoringSSL build
  188. id: boringssl-cache
  189. uses: actions/cache@v4
  190. with:
  191. path: ${{ env.BORINGSSL_PREFIX }}
  192. key: boringssl-${{ runner.os }}-${{ steps.boringssl-rev.outputs.sha }}
  193. - name: build BoringSSL
  194. if: steps.boringssl-cache.outputs.cache-hit != 'true'
  195. run: |
  196. set -e
  197. git clone https://boringssl.googlesource.com/boringssl boringssl
  198. cd boringssl
  199. git checkout "${{ steps.boringssl-rev.outputs.sha }}"
  200. cmake -S . -B build \
  201. -DCMAKE_BUILD_TYPE=Release \
  202. -DBUILD_SHARED_LIBS=OFF \
  203. -DCMAKE_POSITION_INDEPENDENT_CODE=ON \
  204. -DCMAKE_INSTALL_PREFIX="${BORINGSSL_PREFIX}"
  205. cmake --build build -j"$(nproc)" --target install
  206. - name: build and run tests (BoringSSL)
  207. # Override OPENSSL_SUPPORT to point the existing OpenSSL Makefile path
  208. # at BoringSSL's prefix. BoringSSL defines OPENSSL_IS_BORINGSSL in
  209. # <openssl/base.h>, which httplib.h and test.cc use to switch on API
  210. # differences (e.g. SAN-only hostname verification, no CN fallback).
  211. #
  212. # BoringSSL's public headers (<openssl/stack.h>) use std::enable_if_t,
  213. # so consumers must compile with C++14 or later. cpp-httplib itself
  214. # supports C++11, but anyone pairing it with BoringSSL inherits this
  215. # constraint. EXTRA_CXXFLAGS appends after the Makefile's -std=c++11
  216. # and the later flag wins.
  217. run: |
  218. cd test
  219. BORINGSSL_FLAGS="-DCPPHTTPLIB_OPENSSL_SUPPORT -I${BORINGSSL_PREFIX}/include -L${BORINGSSL_PREFIX}/lib -lssl -lcrypto -lpthread"
  220. make test_split OPENSSL_SUPPORT="${BORINGSSL_FLAGS}" EXTRA_CXXFLAGS="-std=c++17"
  221. make test_openssl_parallel OPENSSL_SUPPORT="${BORINGSSL_FLAGS}" EXTRA_CXXFLAGS="-std=c++17"
  222. env:
  223. LSAN_OPTIONS: suppressions=lsan_suppressions.txt
  224. # macOS counterpart of the BoringSSL job. Same best-effort posture; the
  225. # extra framework links cover the macOS Keychain integration that
  226. # httplib.h auto-enables for any TLS backend on macOS.
  227. macos-boringssl:
  228. runs-on: macos-latest
  229. if: >
  230. (github.event_name == 'push') ||
  231. (github.event_name == 'pull_request' &&
  232. github.event.pull_request.head.repo.full_name != github.event.pull_request.base.repo.full_name) ||
  233. (github.event_name == 'workflow_dispatch' && github.event.inputs.test_macos == 'true')
  234. continue-on-error: true
  235. name: macos (boringssl, best-effort)
  236. env:
  237. BORINGSSL_REF: HEAD
  238. BORINGSSL_PREFIX: ${{ github.workspace }}/boringssl-install
  239. steps:
  240. - name: checkout
  241. uses: actions/checkout@v4
  242. - name: resolve BoringSSL commit
  243. id: boringssl-rev
  244. # Accept either a ref name (resolved via git ls-remote) or a full
  245. # 40-char SHA used directly. ls-remote does not list arbitrary
  246. # commit SHAs, so pinning requires the second path.
  247. run: |
  248. if [[ "${BORINGSSL_REF}" =~ ^[0-9a-f]{40}$ ]]; then
  249. sha="${BORINGSSL_REF}"
  250. echo "Using pinned BoringSSL SHA: ${sha}"
  251. else
  252. sha=$(git ls-remote https://boringssl.googlesource.com/boringssl "${BORINGSSL_REF}" | awk '{print $1}')
  253. if [ -z "$sha" ]; then
  254. echo "Failed to resolve BoringSSL ref ${BORINGSSL_REF}" >&2
  255. exit 1
  256. fi
  257. echo "Resolved ${BORINGSSL_REF} -> ${sha}"
  258. fi
  259. echo "sha=${sha}" >> "$GITHUB_OUTPUT"
  260. - name: cache BoringSSL build
  261. id: boringssl-cache
  262. uses: actions/cache@v4
  263. with:
  264. path: ${{ env.BORINGSSL_PREFIX }}
  265. key: boringssl-${{ runner.os }}-${{ steps.boringssl-rev.outputs.sha }}
  266. - name: build BoringSSL
  267. if: steps.boringssl-cache.outputs.cache-hit != 'true'
  268. run: |
  269. set -e
  270. git clone https://boringssl.googlesource.com/boringssl boringssl
  271. cd boringssl
  272. git checkout "${{ steps.boringssl-rev.outputs.sha }}"
  273. cmake -S . -B build \
  274. -DCMAKE_BUILD_TYPE=Release \
  275. -DBUILD_SHARED_LIBS=OFF \
  276. -DCMAKE_POSITION_INDEPENDENT_CODE=ON \
  277. -DCMAKE_INSTALL_PREFIX="${BORINGSSL_PREFIX}"
  278. cmake --build build -j"$(sysctl -n hw.ncpu)" --target install
  279. - name: build and run tests (BoringSSL)
  280. run: |
  281. cd test
  282. # CoreFoundation/Security frameworks satisfy the Keychain integration
  283. # auto-enabled in httplib.h for macOS TLS builds.
  284. BORINGSSL_FLAGS="-DCPPHTTPLIB_OPENSSL_SUPPORT -I${BORINGSSL_PREFIX}/include -L${BORINGSSL_PREFIX}/lib -lssl -lcrypto -framework CoreFoundation -framework Security"
  285. make test_split OPENSSL_SUPPORT="${BORINGSSL_FLAGS}" EXTRA_CXXFLAGS="-std=c++17"
  286. make test_openssl_parallel OPENSSL_SUPPORT="${BORINGSSL_FLAGS}" EXTRA_CXXFLAGS="-std=c++17"
  287. env:
  288. LSAN_OPTIONS: suppressions=lsan_suppressions.txt
  289. # Reproducer for https://github.com/yhirose/cpp-httplib/issues/2431.
  290. # On Linux/glibc, getaddrinfo_with_timeout() schedules an asynchronous
  291. # DNS lookup with getaddrinfo_a(GAI_NOWAIT) using a stack-local gaicb.
  292. # When gai_suspend() hits the connection timeout, gai_cancel() is called
  293. # but does not block; the resolver worker can later write back into the
  294. # destroyed stack frame. To make the worker actually reach that write,
  295. # the test job runs a loopback UDP responder (test/dns_test_fixture.py)
  296. # that delays its reply past the test's 1s timeout, and uses an iptables
  297. # NAT rule so glibc's lookups land on that fixture instead of a real
  298. # nameserver. With ASAN's detect_stack_use_after_return enabled, the
  299. # late write-back is reported as a stack-use-after-return.
  300. issue-2431-repro:
  301. runs-on: ubuntu-latest
  302. if: >
  303. (github.event_name == 'push') ||
  304. (github.event_name == 'pull_request' &&
  305. github.event.pull_request.head.repo.full_name != github.event.pull_request.base.repo.full_name) ||
  306. (github.event_name == 'workflow_dispatch' && github.event.inputs.test_linux == 'true')
  307. name: issue-2431 repro (Linux + ASAN)
  308. # Bound the whole job in case anything in the test harness hangs
  309. # unexpectedly. With the fixture in place a normal run is well under
  310. # a minute either way (ASAN abort on broken HEAD, clean pass on fix).
  311. timeout-minutes: 5
  312. env:
  313. DNS_FIXTURE_PORT: "15353"
  314. DNS_FIXTURE_DELAY: "3"
  315. steps:
  316. - name: checkout
  317. uses: actions/checkout@v4
  318. - name: install libraries
  319. run: |
  320. sudo apt-get update
  321. sudo apt-get install -y libssl-dev zlib1g-dev libbrotli-dev \
  322. libzstd-dev libcurl4-openssl-dev iptables util-linux iproute2
  323. - name: start loopback DNS test fixture
  324. run: |
  325. # Force glibc through its DNS code path: Ubuntu's default
  326. # nsswitch short-circuits to NOTFOUND through mdns4_minimal,
  327. # which would skip the buggy code entirely.
  328. sudo sed -i 's/^hosts:.*/hosts: dns/' /etc/nsswitch.conf
  329. # Run the loopback fixture (delayed UDP responder).
  330. python3 test/dns_test_fixture.py "$DNS_FIXTURE_PORT" "$DNS_FIXTURE_DELAY" \
  331. >/tmp/dns_fixture.log 2>&1 &
  332. echo $! | sudo tee /tmp/dns_fixture.pid >/dev/null
  333. # Wait for the fixture to start listening.
  334. for _ in $(seq 1 50); do
  335. if ss -lun "( sport = :$DNS_FIXTURE_PORT )" | grep -q ":$DNS_FIXTURE_PORT"; then
  336. break
  337. fi
  338. sleep 0.1
  339. done
  340. ss -lun "( sport = :$DNS_FIXTURE_PORT )" | grep -q ":$DNS_FIXTURE_PORT" \
  341. || { echo "fixture failed to start"; cat /tmp/dns_fixture.log; exit 1; }
  342. # Send the test process's DNS lookups to the loopback fixture.
  343. # NAT only the local OUTPUT chain; conntrack handles the reply path.
  344. sudo iptables -t nat -I OUTPUT -p udp --dport 53 \
  345. -j REDIRECT --to-port "$DNS_FIXTURE_PORT"
  346. # Sanity check: a query must take at least the fixture delay
  347. # and resolve to NXDOMAIN (proving traffic reaches the fixture).
  348. start=$(date +%s)
  349. getent hosts unresolvable-host.invalid >/dev/null 2>&1 || true
  350. elapsed=$(( $(date +%s) - start ))
  351. if [ "$elapsed" -lt 2 ]; then
  352. echo "ERROR: lookup returned in ${elapsed}s; fixture not in path" >&2
  353. exit 1
  354. fi
  355. echo "[ok] DNS lookups are routed to the test fixture (took ${elapsed}s)"
  356. - name: build test binary
  357. run: cd test && make test
  358. - name: run GetAddrInfoAsyncCancelTest
  359. run: |
  360. cd test
  361. ARCH=$(uname -m)
  362. CPPHTTPLIB_TEST_ISSUE_2431=1 \
  363. ASAN_OPTIONS=detect_stack_use_after_return=1 \
  364. LSAN_OPTIONS=suppressions=lsan_suppressions.txt \
  365. setarch "$ARCH" -R \
  366. ./test --gtest_filter='GetAddrInfoAsyncCancelTest.*'
  367. - name: tear down test fixture
  368. if: always()
  369. run: |
  370. sudo iptables -t nat -F OUTPUT || true
  371. if [ -f /tmp/dns_fixture.pid ]; then
  372. sudo kill "$(cat /tmp/dns_fixture.pid)" 2>/dev/null || true
  373. fi
  374. macos:
  375. runs-on: macos-latest
  376. if: >
  377. (github.event_name == 'push') ||
  378. (github.event_name == 'pull_request' &&
  379. github.event.pull_request.head.repo.full_name != github.event.pull_request.base.repo.full_name) ||
  380. (github.event_name == 'workflow_dispatch' && github.event.inputs.test_macos == 'true')
  381. strategy:
  382. fail-fast: false
  383. matrix:
  384. tls_backend: [openssl, mbedtls, wolfssl]
  385. name: macos (${{ matrix.tls_backend }})
  386. steps:
  387. - name: checkout
  388. uses: actions/checkout@v4
  389. - name: install Mbed TLS
  390. if: matrix.tls_backend == 'mbedtls'
  391. run: brew install mbedtls
  392. - name: install wolfSSL
  393. if: matrix.tls_backend == 'wolfssl'
  394. run: brew install wolfssl
  395. - name: build and run tests (OpenSSL)
  396. if: matrix.tls_backend == 'openssl'
  397. run: cd test && make test_split && make test_openssl_parallel
  398. env:
  399. LSAN_OPTIONS: suppressions=lsan_suppressions.txt
  400. - name: build and run tests (Mbed TLS)
  401. if: matrix.tls_backend == 'mbedtls'
  402. # macOS runners under ASAN+mbedTLS still flake at SHARDS=2 (rapid
  403. # bind/connect on the fixture's fixed port races on the slower
  404. # macos-latest runner). Serialize fully here; ubuntu stays at 2.
  405. run: cd test && make test_split_mbedtls && SHARDS=1 make test_mbedtls_parallel
  406. - name: build and run tests (wolfSSL)
  407. if: matrix.tls_backend == 'wolfssl'
  408. run: cd test && make test_split_wolfssl && make test_wolfssl_parallel
  409. - name: run fuzz test target
  410. if: matrix.tls_backend == 'openssl'
  411. run: cd test && make fuzz_test
  412. - name: build and run WebSocket heartbeat test
  413. if: matrix.tls_backend == 'openssl'
  414. run: cd test && make test_websocket_heartbeat && ./test_websocket_heartbeat
  415. - name: build and run ThreadPool test
  416. run: cd test && make test_thread_pool && ./test_thread_pool
  417. ios-parse-check:
  418. runs-on: macos-latest
  419. if: >
  420. (github.event_name == 'push') ||
  421. (github.event_name == 'pull_request' &&
  422. github.event.pull_request.head.repo.full_name != github.event.pull_request.base.repo.full_name) ||
  423. (github.event_name == 'workflow_dispatch' && github.event.inputs.test_macos == 'true')
  424. name: ios header parse check (not officially supported)
  425. steps:
  426. - name: checkout
  427. uses: actions/checkout@v4
  428. - name: install OpenSSL headers
  429. run: brew install openssl@3
  430. - name: verify header parses on iOS target
  431. run: |
  432. IOS_SDK=$(xcrun --sdk iphoneos --show-sdk-path)
  433. OPENSSL_INC=$(brew --prefix openssl@3)/include
  434. echo "Using iOS SDK: $IOS_SDK"
  435. echo '#include "httplib.h"' | clang++ \
  436. -isysroot "$IOS_SDK" \
  437. -target arm64-apple-ios16.0 \
  438. -std=c++11 \
  439. -DCPPHTTPLIB_OPENSSL_SUPPORT \
  440. -I"$OPENSSL_INC" \
  441. -I. -Wall -Wextra \
  442. -fsyntax-only -x c++ -
  443. - name: verify CPPHTTPLIB_USE_CERTS_FROM_MACOSX_KEYCHAIN is rejected on iOS
  444. run: |
  445. IOS_SDK=$(xcrun --sdk iphoneos --show-sdk-path)
  446. OPENSSL_INC=$(brew --prefix openssl@3)/include
  447. out=$(echo '#include "httplib.h"' | clang++ \
  448. -isysroot "$IOS_SDK" \
  449. -target arm64-apple-ios16.0 \
  450. -std=c++11 \
  451. -DCPPHTTPLIB_OPENSSL_SUPPORT \
  452. -DCPPHTTPLIB_USE_CERTS_FROM_MACOSX_KEYCHAIN \
  453. -I"$OPENSSL_INC" \
  454. -I. \
  455. -fsyntax-only -x c++ - 2>&1 || true)
  456. if echo "$out" | grep -q "only supported on macOS"; then
  457. echo "OK: #error fired as expected"
  458. else
  459. echo "FAIL: expected #error did not fire"
  460. echo "--- compiler output ---"
  461. echo "$out"
  462. exit 1
  463. fi
  464. windows:
  465. runs-on: windows-latest
  466. if: >
  467. (github.event_name == 'push') ||
  468. (github.event_name == 'pull_request' &&
  469. github.event.pull_request.head.repo.full_name != github.event.pull_request.base.repo.full_name) ||
  470. (github.event_name == 'workflow_dispatch' && github.event.inputs.test_windows == 'true')
  471. strategy:
  472. fail-fast: false
  473. matrix:
  474. config:
  475. - with_ssl: false
  476. compiled: false
  477. run_tests: true
  478. name: without SSL
  479. - with_ssl: true
  480. compiled: false
  481. run_tests: true
  482. name: with SSL
  483. - with_ssl: false
  484. compiled: true
  485. run_tests: false
  486. name: compiled
  487. name: windows ${{ matrix.config.name }}
  488. steps:
  489. - name: Prepare Git for Checkout on Windows
  490. run: |
  491. git config --global core.autocrlf false
  492. git config --global core.eol lf
  493. - name: Checkout
  494. uses: actions/checkout@v4
  495. - name: Export GitHub Actions cache environment variables
  496. uses: actions/github-script@v7
  497. with:
  498. script: |
  499. core.exportVariable('ACTIONS_CACHE_URL', process.env.ACTIONS_CACHE_URL || '');
  500. core.exportVariable('ACTIONS_RUNTIME_TOKEN', process.env.ACTIONS_RUNTIME_TOKEN || '');
  501. - name: Setup msbuild on windows
  502. uses: microsoft/setup-msbuild@v2
  503. - name: Cache vcpkg packages
  504. id: vcpkg-cache
  505. uses: actions/cache@v4
  506. with:
  507. path: C:/vcpkg/installed
  508. key: vcpkg-installed-windows-gtest-curl-zlib-brotli-zstd
  509. - name: Install vcpkg dependencies
  510. if: steps.vcpkg-cache.outputs.cache-hit != 'true'
  511. run: vcpkg install gtest curl zlib brotli zstd
  512. - name: Install OpenSSL
  513. if: ${{ matrix.config.with_ssl }}
  514. run: choco install openssl
  515. - name: Configure CMake ${{ matrix.config.name }}
  516. run: >
  517. cmake -B build -S .
  518. -DCMAKE_BUILD_TYPE=Release
  519. -DCMAKE_TOOLCHAIN_FILE=${{ env.VCPKG_ROOT }}/scripts/buildsystems/vcpkg.cmake
  520. -DHTTPLIB_TEST=ON
  521. -DHTTPLIB_COMPILE=${{ matrix.config.compiled && 'ON' || 'OFF' }}
  522. -DHTTPLIB_USE_OPENSSL_IF_AVAILABLE=${{ matrix.config.with_ssl && 'ON' || 'OFF' }}
  523. -DHTTPLIB_REQUIRE_ZLIB=ON
  524. -DHTTPLIB_REQUIRE_BROTLI=ON
  525. -DHTTPLIB_REQUIRE_ZSTD=ON
  526. -DHTTPLIB_REQUIRE_OPENSSL=${{ matrix.config.with_ssl && 'ON' || 'OFF' }}
  527. - name: Build ${{ matrix.config.name }}
  528. run: cmake --build build --config Release -- /v:m /clp:ShowCommandLine
  529. - name: Run tests ${{ matrix.config.name }}
  530. if: ${{ matrix.config.run_tests }}
  531. shell: pwsh
  532. working-directory: build/test
  533. run: |
  534. $shards = 4
  535. $procs = @()
  536. for ($i = 0; $i -lt $shards; $i++) {
  537. $log = "shard_${i}.log"
  538. $procs += Start-Process -FilePath ./Release/httplib-test.exe `
  539. -ArgumentList "--gtest_color=yes","--gtest_filter=${{ github.event.inputs.gtest_filter || '-*_Online' }}" `
  540. -NoNewWindow -PassThru -RedirectStandardOutput $log -RedirectStandardError "${log}.err" `
  541. -Environment @{ GTEST_TOTAL_SHARDS="$shards"; GTEST_SHARD_INDEX="$i" }
  542. }
  543. $procs | Wait-Process
  544. $failed = $false
  545. for ($i = 0; $i -lt $shards; $i++) {
  546. $log = "shard_${i}.log"
  547. $proc = $procs[$i]
  548. $hasPassed = Select-String -Path $log -Pattern "\[ PASSED \]" -Quiet
  549. $hasFailed = Select-String -Path $log -Pattern "\[ FAILED \]" -Quiet
  550. if ($hasPassed -and -not $hasFailed -and $proc.ExitCode -eq 0) {
  551. $passed = (Select-String -Path $log -Pattern "\[ PASSED \]").Line
  552. Write-Host "Shard ${i}: $passed"
  553. } else {
  554. Write-Host "=== Shard $i FAILED (exit=$($proc.ExitCode)) ==="
  555. Get-Content $log
  556. if (Test-Path "${log}.err") { Get-Content "${log}.err" }
  557. $failed = $true
  558. }
  559. }
  560. if ($failed) { exit 1 }
  561. Write-Host "All shards passed."
  562. env:
  563. VCPKG_ROOT: "C:/vcpkg"
  564. VCPKG_BINARY_SOURCES: "clear;x-gha,readwrite"