docs: Update projects #16
Workflow file for this run
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
| # SPDX-FileCopyrightText: 2026 The RISE Project | |
| # SPDX-License-Identifier: MIT | |
| --- | |
| # This workflow is based on: https://github.com/pyauth/python-pkcs11/blob/v0.9.5/.github/workflows/release.yml | |
| # and https://github.com/pyauth/python-pkcs11/blob/v0.9.5/.github/workflows/tests.yml | |
| name: Build python-pkcs11 wheels (riscv64) | |
| on: | |
| workflow_dispatch: | |
| inputs: | |
| version: | |
| description: 'Version glob to (re)build; empty builds every version of docs/packages/python-pkcs11.yaml not released yet' | |
| required: false | |
| default: '' | |
| pull_request: | |
| branches: [main] | |
| paths: | |
| - '.github/workflows/build-python-pkcs11.yml' | |
| - 'docs/packages/python-pkcs11.yaml' | |
| push: | |
| branches: [main] | |
| paths: | |
| - '.github/workflows/build-python-pkcs11.yml' | |
| - 'docs/packages/python-pkcs11.yaml' | |
| concurrency: | |
| group: ${{ github.workflow }}-${{ github.head_ref || github.run_id }} | |
| cancel-in-progress: true | |
| permissions: | |
| contents: read # to fetch code (actions/checkout) | |
| env: | |
| MANYLINUX_RISCV64_IMAGE: quay.io/pypa/manylinux_2_39_riscv64 | |
| # Upstream tests against SoftHSMv2 main for ML-DSA; pinned here for reproducibility. | |
| SOFTHSM_REF: 884cb38f3d2012a0447bd5f50dbd29c429987c41 | |
| jobs: | |
| setup: | |
| uses: $/.github/workflows/_setup.yml | |
| with: | |
| package: python-pkcs11 | |
| version: ${{ inputs.version }} | |
| build_wheels: | |
| needs: [setup] | |
| if: needs.setup.outputs.versions != '[]' | |
| name: Build python-pkcs11 ${{ matrix.version }} ${{ matrix.python }}-manylinux_riscv64 | |
| runs-on: ubuntu-24.04-riscv | |
| timeout-minutes: 90 | |
| strategy: | |
| fail-fast: false | |
| matrix: | |
| version: ${{ fromJSON(needs.setup.outputs.versions) }} | |
| # Upstream's [tool.cibuildwheel] skips free-threaded builds. | |
| python: ["cp312", "cp313", "cp314"] | |
| env: | |
| PYTHON_PKCS11_VERSION: ${{ matrix.version }} | |
| steps: | |
| - name: Checkout python-pkcs11 v${{ env.PYTHON_PKCS11_VERSION }} | |
| uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 | |
| with: | |
| repository: pyauth/python-pkcs11 | |
| ref: v${{ env.PYTHON_PKCS11_VERSION }} | |
| persist-credentials: false | |
| - name: Build wheels | |
| uses: pypa/cibuildwheel@1828c10ab37f080699c7b81cea34097c684a7074 # v4.2.0 | |
| with: | |
| output-dir: wheelhouse/ | |
| only: ${{ matrix.python }}-manylinux_riscv64 | |
| env: | |
| CIBW_MANYLINUX_RISCV64_IMAGE: ${{ env.MANYLINUX_RISCV64_IMAGE }} | |
| CIBW_BEFORE_ALL_LINUX: | | |
| set -euo pipefail | |
| dnf install -y --setopt=install_weak_deps=False autoconf automake libtool openssl openssl-devel crypto-policies-scripts | |
| # Rocky's DEFAULT crypto policy refuses the SHA-1 signatures the RSA tests use. | |
| update-crypto-policies --set LEGACY | |
| curl -sSfL https://github.com/softhsm/SoftHSMv2/archive/${{ env.SOFTHSM_REF }}.tar.gz | tar xz -C /tmp | |
| cd /tmp/SoftHSMv2-${{ env.SOFTHSM_REF }} | |
| ./autogen.sh | |
| ./configure --prefix=/usr --disable-gost --enable-mldsa | |
| make -j"$(nproc)" | |
| make install | |
| mkdir -p /opt/softhsm_tokens | |
| echo "directories.tokendir = /opt/softhsm_tokens" > /opt/softhsm2.conf | |
| CIBW_ENVIRONMENT: >- | |
| SETUPTOOLS_SCM_PRETEND_VERSION_FOR_PYTHON_PKCS11=${{ env.PYTHON_PKCS11_VERSION }} | |
| PIP_EXTRA_INDEX_URL=https://pypi.riseproject.dev/simple/ | |
| SOFTHSM2_CONF=/opt/softhsm2.conf | |
| CIBW_BEFORE_TEST_LINUX: softhsm2-util --init-token --free --label TEST --pin 1234 --so-pin 5678 | |
| CIBW_TEST_ENVIRONMENT: >- | |
| PKCS11_MODULE=/usr/lib/softhsm/libsofthsm2.so | |
| PKCS11_TOKEN_LABEL=TEST | |
| PKCS11_TOKEN_PIN=1234 | |
| PKCS11_TOKEN_SO_PIN=5678 | |
| PIP_ONLY_BINARY=cryptography | |
| CIBW_TEST_GROUPS: testing | |
| CIBW_TEST_SOURCES: tests | |
| # Rocky's OpenSSL drops the P-192 curve this test uses. | |
| CIBW_TEST_COMMAND: pytest -v tests --deselect tests/test_ecc.py::ECCTests::test_derive_key | |
| - uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1 | |
| with: | |
| name: python-pkcs11-${{ env.PYTHON_PKCS11_VERSION }}-${{ matrix.python }}-manylinux_riscv64 | |
| path: wheelhouse/*.whl | |
| if-no-files-found: error | |
| publish: | |
| name: Publish python-pkcs11 ${{ matrix.version }} | |
| needs: [setup, build_wheels] | |
| if: needs.setup.outputs.versions != '[]' | |
| strategy: | |
| fail-fast: false | |
| matrix: | |
| version: ${{ fromJSON(needs.setup.outputs.versions) }} | |
| permissions: | |
| contents: write | |
| pull-requests: write | |
| uses: $/.github/workflows/_publish-wheel.yml | |
| secrets: | |
| app-private-key: ${{ secrets.RISEPROJECT_APP_PRIVATE_KEY }} | |
| with: | |
| artifact-pattern: python-pkcs11-${{ matrix.version }}-*-manylinux_riscv64 |