From 9252ec2509a526988e898f2ca1bd373dedd26d76 Mon Sep 17 00:00:00 2001 From: Robert Vollmert Date: Mon, 11 Jul 2022 16:23:29 +0000 Subject: [PATCH] ci: verify that static executable is static --- .github/workflows/ci.yaml | 3 +++ nix/tools/tests.nix | 21 +++++++++++++++++++++ 2 files changed, 24 insertions(+) diff --git a/.github/workflows/ci.yaml b/.github/workflows/ci.yaml index cca70697a..c706abd73 100644 --- a/.github/workflows/ci.yaml +++ b/.github/workflows/ci.yaml @@ -113,9 +113,12 @@ jobs: uses: ./.github/actions/setup-nix with: authToken: '${{ secrets.CACHIX_AUTH_TOKEN }}' + tools: tests - name: Build static executable run: nix-build -A postgrestStatic + - name: Check static executable + run: postgrest-check-static result/bin/postgrest - name: Save built executable as artifact uses: actions/upload-artifact@v3 with: diff --git a/nix/tools/tests.nix b/nix/tools/tests.nix index bf534617c..28a2c2996 100644 --- a/nix/tools/tests.nix +++ b/nix/tools/tests.nix @@ -207,6 +207,26 @@ let sed -i 's|^module \(.*\):|module \1/|g' test/coverage.overlay ''; + checkStatic = + checkedShellScript + { + name = "postgrest-check-static"; + docs = "Verify that the argument is a static executable."; + args = [ "ARG_POSITIONAL_SINGLE([executable], [Executable])" ]; + inRootDir = true; + withEnv = postgrest.env; + } + '' + exe="$_arg_executable" + ldd_output=$(ldd "$exe" 2>&1 || true) + if ! grep -q "not a dynamic executable" <<< "$ldd_output"; then + echo "not a static executable, ldd output:" + echo "$ldd_output" + exit 1 + fi + "$exe" --help + ''; + in buildToolbox { @@ -221,5 +241,6 @@ buildToolbox dumpSchema coverage coverageDraftOverlay + checkStatic ]; }