Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
128 changes: 0 additions & 128 deletions .github/actions/build-macos-x86_64/action.yml

This file was deleted.

106 changes: 47 additions & 59 deletions .github/actions/build/action.yml
Original file line number Diff line number Diff line change
@@ -1,24 +1,26 @@
name: 'Maven Build'

description: 'Build the platform dependent Java library'
description: 'Build the native libraries of one platform and upload them as artifacts'

inputs:
java-version:
description: 'The Java build version.'
required: true
default: '17'

platform-name:
description: 'The target platform.'
required: true

maven-username:
description: 'The Maven username.'
required: true
profile:
description: 'The Maven profile that selects a cross compiled classifier. Empty for the runner''s own.'
required: false
default: ''

maven-password:
description: 'The Maven password.'
required: true
java-version:
description: 'The Java build version.'
required: false
default: '17'

retention-days:
description: 'How long the natives artifacts are kept.'
required: false
default: '1'

runs:
using: "composite"
Expand All @@ -28,9 +30,9 @@
shell: bash

# Restored here, saved right after the build below: the post step of
# actions/cache only saves when the whole job succeeds, so a failing test
# would otherwise throw away a WebRTC build that took the better part of an
# hour.
# actions/cache only saves when the whole job succeeds, so a failure in a
# later step would otherwise throw away a WebRTC build that took the better
# part of an hour.
- id: webrtc-cache
name: Restore WebRTC cache
uses: actions/cache/restore@v6
Expand All @@ -52,8 +54,8 @@
restore-keys: ffmpeg-${{ env.FFMPEG_VERSION }}-${{ inputs.platform-name }}-${{ hashFiles('webrtc-java-media/src/main/cpp/dependencies/ffmpeg/CMakeLists.txt') }}-

# One cache per OS: the dependencies do not differ between the platforms of
# an OS. The project's own artifacts, which mvn deploy installs, change with
# every build and stay out of it.
# an OS. The project's own artifacts change with every build and stay out
# of it.
- name: Set up Maven cache
uses: actions/cache@v6
with:
Expand All @@ -68,24 +70,14 @@
with:
java-version: ${{ inputs.java-version }}
distribution: 'temurin'
server-id: central
server-username: MAVEN_USERNAME
server-password: MAVEN_TOKEN

- name: Build
run: |
if [ "${{ inputs.platform-name }}" == "linux_arm" ]; then
mvn package -DskipTests -Plinux-aarch32
elif [ "${{ inputs.platform-name }}" == "linux_arm64" ]; then
mvn package -DskipTests -Plinux-aarch64
elif [ "${{ inputs.platform-name }}" == "windows_arm64" ]; then
mvn package -DskipTests -Pwindows-aarch64
else
mvn package -DskipTests
fi
env:
PROFILE: ${{ inputs.profile }}
run: mvn -B package -DskipTests ${PROFILE:+-P$PROFILE}
shell: bash

- name: Save WebRTC cache

Check failure

Code scanning / CodeQL

Cache Poisoning via execution of untrusted code High

Potential cache poisoning in the context of the default branch due to privilege checkout of untrusted code from
inputs.ref
. (
workflow_dispatch
).
Potential cache poisoning in the context of the default branch due to privilege checkout of untrusted code from
inputs.ref
. (
workflow_dispatch
).
if: steps.webrtc-cache.outputs.cache-hit != 'true'
uses: actions/cache/save@v6
with:
Expand All @@ -99,34 +91,30 @@
path: ~/ffmpeg
key: ${{ steps.ffmpeg-cache.outputs.cache-primary-key }}

- name: Test
if: ${{ inputs.platform-name != 'linux_arm' && inputs.platform-name != 'linux_arm64' && inputs.platform-name != 'windows_arm64' }}
run: mvn -B jar:jar surefire:test -Dsurefire.timeout=1800
shell: bash

# What failed, for runners that cannot be reproduced locally.
- name: Upload test reports
if: failure()
# The natives of every platform go to test-natives, which tests them on a
# runner of their own OS and architecture, and to the callers' publishing
# job, which attaches all of them to a single deployment. Both artifacts
# hold one flat jar each, so that a natives-* download with merge-multiple
# puts every jar into one directory.
- name: Upload native library jar
uses: actions/upload-artifact@v7
with:
name: test-reports-${{ inputs.platform-name }}
path: '**/target/surefire-reports/'
if-no-files-found: ignore
retention-days: 7

- name: Deploy
if: ${{ github.event_name != 'pull_request' && github.repository == 'devopvoid/webrtc-java' }}
env:
MAVEN_USERNAME: ${{ inputs.maven-username }}
MAVEN_TOKEN: ${{ inputs.maven-password }}
run: |
if [ "${{ inputs.platform-name }}" == "linux_arm" ]; then
mvn deploy -DskipTests -Plinux-aarch32
elif [ "${{ inputs.platform-name }}" == "linux_arm64" ]; then
mvn deploy -DskipTests -Plinux-aarch64
elif [ "${{ inputs.platform-name }}" == "windows_arm64" ]; then
mvn deploy -DskipTests -Pwindows-aarch64
else
mvn deploy -DskipTests
fi
shell: bash
name: natives-${{ inputs.platform-name }}
path: webrtc-jni/target/webrtc-java-*.jar
if-no-files-found: error
retention-days: ${{ inputs.retention-days }}
overwrite: true

# Only the classifier jar: the main jar is platform independent and the
# publishing job builds it itself.
- name: Upload media native library jar
uses: actions/upload-artifact@v7
with:
name: natives-media-${{ inputs.platform-name }}
path: |
webrtc-java-media/target/webrtc-java-media-*-windows-*.jar
webrtc-java-media/target/webrtc-java-media-*-linux-*.jar
webrtc-java-media/target/webrtc-java-media-*-macos-*.jar
if-no-files-found: error
retention-days: ${{ inputs.retention-days }}
overwrite: true
84 changes: 84 additions & 0 deletions .github/actions/publish/action.yml
Original file line number Diff line number Diff line change
@@ -0,0 +1,84 @@
name: 'Maven Publish'

description: 'Deploy one version with the native libraries of every platform attached, as a single deployment'

# Expects the checkout of the version to deploy, a JDK whose settings.xml has
# the "central" server, and MAVEN_USERNAME and MAVEN_TOKEN (plus
# MAVEN_GPG_PASSPHRASE for a release) in the environment of the calling step.

inputs:
version:
description: 'The version to deploy, as the natives jars are named.'
required: true

profiles:
description: 'Maven profiles to activate, comma separated. "release" adds sources, javadoc and signatures.'
required: false
default: ''

skip-publishing:
description: 'Build, sign and bundle everything, but upload nothing.'
required: false
default: 'false'

runs:
using: "composite"
steps:
- name: Download the native library jars of all platforms
uses: actions/download-artifact@v8
with:
pattern: natives-*
path: natives
merge-multiple: true

- name: Verify that every platform is present
env:
VERSION: ${{ inputs.version }}
run: |
status=0

for classifier in windows-x86_64 windows-aarch64 linux-x86_64 linux-aarch64 \
linux-aarch32 macos-x86_64 macos-aarch64; do
if [ ! -f "natives/webrtc-java-$VERSION-$classifier.jar" ]; then
echo "::error::Missing native library jar for $classifier"
status=1
fi
if [ ! -f "natives/webrtc-java-media-$VERSION-$classifier.jar" ]; then
echo "::error::Missing media native library jar for $classifier"
status=1
fi
done

exit $status
shell: bash

# The webrtc module depends on its own native library jar for the host
# platform. That dependency is normally installed by webrtc-jni, which is kept
# out of the reactor here to avoid rebuilding the native libraries.
- name: Seed the local repository with the host native library
env:
VERSION: ${{ inputs.version }}
run: |
mvn -B install:install-file \
-Dfile="natives/webrtc-java-$VERSION-linux-x86_64.jar" \
-DgroupId=dev.onvoid.webrtc \
-DartifactId=webrtc-java \
-Dversion="$VERSION" \
-Dclassifier=linux-x86_64 \
-Dpackaging=jar \
-DgeneratePom=false
shell: bash

# natives.dir makes webrtc and webrtc-java-media attach the jars of all
# platforms instead of the host's. skipPublishing suppresses both the
# bundling and the upload.
- name: Deploy
env:
PROFILES: ${{ inputs.profiles }}
SKIP_PUBLISHING: ${{ inputs.skip-publishing }}
run: >
mvn -B deploy -pl .,webrtc,webrtc-java-media -DskipTests
${PROFILES:+-P$PROFILES}
-Dnatives.dir="$PWD/natives"
-DskipPublishing="$SKIP_PUBLISHING"
shell: bash
Loading
Loading