-
Notifications
You must be signed in to change notification settings - Fork 0
167 lines (148 loc) · 6.19 KB
/
Copy pathbuild-sqlcipher3.yml
File metadata and controls
167 lines (148 loc) · 6.19 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
130
131
132
133
134
135
136
137
138
139
140
141
142
143
144
145
146
147
148
149
150
151
152
153
154
155
156
157
158
159
160
161
162
163
164
165
166
167
# SPDX-FileCopyrightText: 2026 The RISE Project
# SPDX-License-Identifier: MIT
---
# Based on the `wheels` job of
# https://github.com/coleifer/sqlcipher3/blob/0.6.2/.github/workflows/wheels.yaml
name: Build sqlcipher3 wheels (riscv64)
on:
workflow_dispatch:
inputs:
version:
description: 'Version glob to (re)build; empty builds every version of docs/packages/sqlcipher3.yaml not released yet'
required: false
default: ''
pull_request:
branches: [main]
paths:
- '.github/workflows/build-sqlcipher3.yml'
- 'docs/packages/sqlcipher3.yaml'
- 'patches/sqlcipher3/**'
push:
branches: [main]
paths:
- '.github/workflows/build-sqlcipher3.yml'
- 'docs/packages/sqlcipher3.yaml'
- 'patches/sqlcipher3/**'
concurrency:
group: ${{ github.workflow }}-${{ github.head_ref || github.run_id }}
cancel-in-progress: true
permissions:
contents: read # to fetch code (actions/checkout)
env:
MANYLINUX_RISCV64_IMAGE: quay.io/pypa/manylinux_2_39_riscv64
MUSLLINUX_RISCV64_IMAGE: quay.io/pypa/musllinux_1_2_riscv64
jobs:
setup:
uses: $/.github/workflows/_setup.yml
with:
package: sqlcipher3
version: ${{ inputs.version }}
build_wheels:
needs: [setup]
if: needs.setup.outputs.versions != '[]'
name: Build sqlcipher3 ${{ matrix.version }} ${{ matrix.python }}-${{ matrix.libc }}_riscv64
runs-on: ubuntu-24.04-riscv
timeout-minutes: 120
strategy:
fail-fast: false
matrix:
version: ${{ fromJSON(needs.setup.outputs.versions) }}
python: ["cp312", "cp313", "cp314", "cp314t"]
libc: [manylinux, musllinux]
env:
SQLCIPHER3_VERSION: ${{ matrix.version }}
steps:
- name: Checkout sqlcipher3 ${{ env.SQLCIPHER3_VERSION }}
uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
with:
repository: coleifer/sqlcipher3
ref: ${{ env.SQLCIPHER3_VERSION }}
persist-credentials: false
- name: Checkout python-wheels
uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
with:
path: python-wheels
persist-credentials: false
- name: Patch sqlcipher3 source
run: git apply python-wheels/patches/sqlcipher3/${{ env.SQLCIPHER3_VERSION }}/*.patch
# Upstream's suite never sets a key, so check the statically linked OpenSSL and the
# licences of what the wheel bundles.
- name: Write encryption smoke test
run: |
cat > smoke_test.py <<'EOF'
import importlib.metadata
import os
import tempfile
from sqlcipher3 import dbapi2 as sqlite
licenses = sorted(
p.name for p in importlib.metadata.files("sqlcipher3") if ".dist-info/licenses/" in str(p)
)
assert licenses == ["LICENSE", "LICENSE.openssl", "LICENSE.sqlcipher"], licenses
with tempfile.TemporaryDirectory() as tmp:
path = os.path.join(tmp, "enc.db")
conn = sqlite.connect(path)
conn.execute("PRAGMA key = 'riscv64'")
provider = conn.execute("PRAGMA cipher_provider_version").fetchone()[0]
assert provider.startswith("OpenSSL 3."), provider
conn.execute("CREATE TABLE t (v TEXT)")
conn.execute("INSERT INTO t VALUES ('plaintext-marker')")
conn.commit()
conn.close()
with open(path, "rb") as fh:
assert b"plaintext-marker" not in fh.read()
conn = sqlite.connect(path)
conn.execute("PRAGMA key = 'riscv64'")
assert conn.execute("PRAGMA cipher_integrity_check").fetchall() == []
assert conn.execute("SELECT v FROM t").fetchall() == [("plaintext-marker",)]
conn.close()
conn = sqlite.connect(path)
conn.execute("PRAGMA key = 'wrong'")
try:
conn.execute("SELECT v FROM t").fetchall()
except sqlite.DatabaseError:
pass
else:
raise AssertionError("wrong key decrypted the database")
print(provider, "ok")
EOF
- uses: pypa/cibuildwheel@1828c10ab37f080699c7b81cea34097c684a7074 # v4.2.0
env:
CIBW_BUILD_FRONTEND: build
CIBW_ARCHS: riscv64
CIBW_BUILD: ${{ matrix.python }}-${{ matrix.libc }}_riscv64
CIBW_MANYLINUX_RISCV64_IMAGE: ${{ env.MANYLINUX_RISCV64_IMAGE }}
CIBW_MUSLLINUX_RISCV64_IMAGE: ${{ env.MUSLLINUX_RISCV64_IMAGE }}
# Conan's openssl recipe has no riscv64 entry and falls back to linux-generic32;
# linux64-riscv64's AES asm `jal`s a global symbol, which overflows R_RISCV_JAL here.
CIBW_ENVIRONMENT: >-
SQLCIPHER3_COMPILE_TARGET=riscv64
CONAN_OPENSSL_CONFIGURATION=linux-generic64
PIP_EXTRA_INDEX_URL=https://pypi.riseproject.dev/simple/
CIBW_BEFORE_ALL_LINUX: command -v yum >/dev/null && yum -y install perl-core || command -v apk >/dev/null && apk add perl || true
# -P keeps the build's {project}/sqlcipher3.egg-info from shadowing the installed metadata.
CIBW_TEST_COMMAND: >
mv {project}/sqlcipher3 {project}/sqlcipher3_ &&
python {project}/tests/ &&
python -P {project}/smoke_test.py &&
mv {project}/sqlcipher3_ {project}/sqlcipher3
- uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1
with:
name: sqlcipher3-${{ env.SQLCIPHER3_VERSION }}-${{ matrix.python }}-${{ matrix.libc }}_riscv64
path: ./wheelhouse/*.whl
if-no-files-found: error
publish:
name: Publish sqlcipher3 ${{ matrix.version }}
needs: [setup, build_wheels]
if: needs.setup.outputs.versions != '[]'
strategy:
fail-fast: false
matrix:
version: ${{ fromJSON(needs.setup.outputs.versions) }}
permissions:
contents: write
pull-requests: write
uses: $/.github/workflows/_publish-wheel.yml
secrets:
app-private-key: ${{ secrets.RISEPROJECT_APP_PRIVATE_KEY }}
with:
artifact-pattern: sqlcipher3-${{ matrix.version }}-*riscv64