diff --git a/.github/workflows/build-atheris.yml b/.github/workflows/build-atheris.yml new file mode 100644 index 00000000000..9b94e0cc8bf --- /dev/null +++ b/.github/workflows/build-atheris.yml @@ -0,0 +1,117 @@ +# SPDX-FileCopyrightText: 2026 The RISE Project +# SPDX-License-Identifier: MIT +--- +# This workflow is based on: https://github.com/google/atheris/blob/352d5f2/deployment/Dockerfile +# and https://github.com/google/atheris/blob/352d5f2/run_tests.sh +name: Build atheris wheels (riscv64) + +on: + workflow_dispatch: + inputs: + version: + description: 'Version glob to (re)build; empty builds every version of docs/packages/atheris.yaml not released yet' + required: false + default: '' + pull_request: + branches: [main] + paths: + - '.github/workflows/build-atheris.yml' + - 'docs/packages/atheris.yaml' + push: + branches: [main] + paths: + - '.github/workflows/build-atheris.yml' + - 'docs/packages/atheris.yaml' + +concurrency: + group: ${{ github.workflow }}-${{ github.head_ref || github.run_id }} + cancel-in-progress: true + +permissions: + contents: read # to fetch code (actions/checkout) + +env: + # Upstream cuts releases without git tags, so pin the release commit: this is + # "Bump Atheris to 3.1.0", whose Python sources are byte-identical to the 3.1.0 + # PyPI wheels. Update it alongside ATHERIS_VERSION. + ATHERIS_REF: 352d5f29d811e0b51807ca57ed5551dd08ece528 + MANYLINUX_RISCV64_IMAGE: quay.io/pypa/manylinux_2_39_riscv64 + +jobs: + setup: + uses: $/.github/workflows/_setup.yml + with: + package: atheris + version: ${{ inputs.version }} + + build_wheels: + needs: [setup] + if: needs.setup.outputs.versions != '[]' + name: Build atheris ${{ matrix.version }} ${{ matrix.python }}-manylinux_riscv64 + runs-on: ubuntu-24.04-riscv + timeout-minutes: 90 + strategy: + fail-fast: false + matrix: + version: ${{ fromJSON(needs.setup.outputs.versions) }} + python: ["cp312", "cp313", "cp314"] + + env: + ATHERIS_VERSION: ${{ matrix.version }} + + steps: + - name: Checkout atheris ${{ env.ATHERIS_VERSION }} + uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 + with: + repository: google/atheris + ref: ${{ env.ATHERIS_REF }} + persist-credentials: false + + - name: Build and test wheel + uses: pypa/cibuildwheel@1828c10ab37f080699c7b81cea34097c684a7074 # v4.2.0 + with: + output-dir: wheelhouse/ + only: ${{ matrix.python }}-manylinux_riscv64 + env: + CIBW_MANYLINUX_RISCV64_IMAGE: ${{ env.MANYLINUX_RISCV64_IMAGE }} + # Upstream builds libFuzzer from an LLVM 16 snapshot that predates riscv64 + # libFuzzer (added in LLVM 17); Rocky 10's compiler-rt ships it prebuilt. + CIBW_BEFORE_ALL: dnf install -y compiler-rt + CIBW_ENVIRONMENT: >- + LIBFUZZER_LIB=/usr/lib/clang/21/lib/riscv64-redhat-linux-gnu/libclang_rt.fuzzer_no_main.a + PIP_EXTRA_INDEX_URL=https://pypi.riseproject.dev/simple/ + CIBW_BEFORE_BUILD: pip install setuptools pybind11 + CIBW_BUILD_FRONTEND: "pip; args: --no-build-isolation" + CIBW_TEST_REQUIRES: PyInstaller + CIBW_TEST_SOURCES: src + # pyinstaller_coverage_test.py needs a shared libpython to build a + # onefile executable ("Python was built without a shared library"); + # this image's cp312/cp313/cp314 don't ship one. Every other test + # exercises atheris itself and stays in the loop. + CIBW_TEST_COMMAND: >- + cd src && for t in *_test.py; do + [ "$t" = "pyinstaller_coverage_test.py" ] && continue; + echo "Running test: $t" && python "$t" || exit 1; done + + - uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1 + with: + name: atheris-${{ env.ATHERIS_VERSION }}-${{ matrix.python }}-manylinux_riscv64 + path: wheelhouse/*.whl + if-no-files-found: error + + publish: + name: Publish atheris ${{ matrix.version }} + needs: [setup, build_wheels] + if: needs.setup.outputs.versions != '[]' + strategy: + fail-fast: false + matrix: + version: ${{ fromJSON(needs.setup.outputs.versions) }} + permissions: + contents: write + pull-requests: write + uses: $/.github/workflows/_publish-wheel.yml + secrets: + app-private-key: ${{ secrets.RISEPROJECT_APP_PRIVATE_KEY }} + with: + artifact-pattern: atheris-${{ matrix.version }}-*-manylinux_riscv64 diff --git a/docs/packages/atheris.yaml b/docs/packages/atheris.yaml new file mode 100644 index 00000000000..2844e2831e8 --- /dev/null +++ b/docs/packages/atheris.yaml @@ -0,0 +1,5 @@ +package-name: atheris +source-code: https://github.com/google/atheris/ +license: Apache-2.0 +versions: +- version: 3.1.0