summaryrefslogtreecommitdiff
path: root/.github/workflows/tests.yml
blob: dd5f5b106aabca9cbed40f4198e34f7100f074aa (plain)
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
130
131
132
133
134
135
136
137
138
139
140
141
142
143
144
145
146
147
148
149
150
151
152
153
154
155
156
157
158
159
160
161
162
163
164
165
166
167
168
169
170
171
172
173
174
175
176
177
178
179
180
181
182
183
184
185
186
187
188
189
190
191
192
193
194
195
196
197
198
199
200
201
202
203
204
205
206
207
208
209
210
211
212
213
214
215
216
217
218
219
220
221
222
223
224
225
226
227
228
229
230
231
232
233
234
235
236
237
238
239
240
241
242
243
244
245
246
247
248
249
250
251
252
253
254
255
256
257
258
259
260
261
262
263
264
265
266
267
268
269
270
271
272
273
274
275
276
277
278
279
280
281
282
283
284
285
286
287
288
289
290
291
292
293
294
295
296
297
298
299
300
301
302
303
304
305
306
307
308
309
310
311
312
313
314
315
316
317
318
319
320
321
322
323
324
325
326
327
328
329
330
331
332
333
334
335
336
337
338
339
340
341
342
343
344
345
346
347
348
349
350
351
352
353
354
355
356
357
358
359
360
361
362
363
364
365
366
367
368
369
370
371
372
373
374
375
376
377
378
379
380
381
382
383
384
385
386
387
388
389
390
391
392
393
394
395
396
397
398
399
400
401
402
403
404
405
406
407
408
409
410
411
412
413
414
415
416
417
418
419
420
421
422
423
424
425
426
427
428
429
430
431
432
433
434
435
436
437
438
439
440
441
442
443
444
445
446
447
448
449
450
451
452
453
454
455
456
457
458
459
460
461
# Generated from:
# https://github.com/zopefoundation/meta/tree/master/config/c-code
###
# Initially copied from
# https://github.com/actions/starter-workflows/blob/main/ci/python-package.yml
# And later based on the version jamadden updated at
# gevent/gevent, and then at zodb/relstorage and zodb/perfmetrics
#
# Original comment follows.
###
###
# This workflow will install Python dependencies, run tests and lint with a variety of Python versions
# For more information see: https://help.github.com/actions/language-and-framework-guides/using-python-with-github-actions
###

###
# Important notes on GitHub actions:
#
# - We only get 2,000 free minutes a month (private repos)
# - We only get 500MB of artifact storage
# - Cache storage is limited to 7 days and 5GB.
# - macOS minutes are 10x as expensive as Linux minutes
# - windows minutes are twice as expensive.
#
# So keep those workflows light. Note: Currently, they seem to be free
# and unlimited for open source projects. But for how long...
#
# In December 2020, github only supports x86/64. If we wanted to test
# on other architectures, we can use docker emulation, but there's no
# native support. It works, but is slow.
#
# Another major downside: You can't just re-run the job for one part
# of the matrix. So if there's a transient test failure that hit, say, 3.8,
# to get a clean run every version of Python runs again. That's bad.
# https://github.community/t/ability-to-rerun-just-a-single-job-in-a-workflow/17234/65

name: tests


# Triggers the workflow on push or pull request events and periodically
on:
  push:
  pull_request:
  schedule:
    - cron: '0 12 * * 0'  # run once a week on Sunday
  # Allow to run this workflow manually from the Actions tab
  workflow_dispatch:

env:
  # Weirdly, this has to be a top-level key, not ``defaults.env``
  PYTHONHASHSEED: 8675309
  PYTHONUNBUFFERED: 1
  PYTHONDONTWRITEBYTECODE: 1
  PYTHONDEVMODE: 1
  PYTHONFAULTHANDLER: 1
  ZOPE_INTERFACE_STRICT_IRO: 1

  PIP_UPGRADE_STRATEGY: eager
  # Don't get warnings about Python 2 support being deprecated. We
  # know. The env var works for pip 20.
  PIP_NO_PYTHON_VERSION_WARNING: 1
  PIP_NO_WARN_SCRIPT_LOCATION: 1

  CFLAGS: -Ofast -pipe
  CXXFLAGS: -Ofast -pipe
  # Uploading built wheels for releases.
  # TWINE_PASSWORD is encrypted and stored directly in the
  # github repo settings.
  TWINE_USERNAME: __token__

  ###
  # caching
  # This is where we'd set up ccache, but this compiles so fast its not worth it.
  ###


jobs:
  # Because sharing code/steps is so hard, and because it can be
  # extremely valuable to be able to get binary wheels without
  # uploading to PyPI and even if there is some failure, (e.g., for
  # other people to test/debug), the strategy is to divide the process
  # into several different jobs. The first builds and saves the binary
  # wheels. It has dependent jobs that download and install the wheel
  # to run tests, build docs, and perform linting. Building the
  # manylinux wheels is an independent set of jobs.
  #
  # This division is time-saving for projects that take awhile to
  # build, but somewhat less of a clear-cut win given how quick this
  # is to compile (at least at this writing).
  build-package:
    # Sigh. Note that the matrix must be kept in sync
    # with `test`, and `docs` must use a subset.
    runs-on: ${{ matrix.os }}
    strategy:
      fail-fast: false
      matrix:
        python-version:
          - "2.7"
          - "3.5"
          - "pypy-2.7"
          - "pypy-3.7"
          - "3.6"
          - "3.7"
          - "3.8"
          - "3.9"
          - "3.10"
          - "3.11.0-beta.1"
        os: [ubuntu-20.04, macos-latest]
        exclude:
          - os: macos-latest
            python-version: "pypy-2.7"
          - os: macos-latest
            python-version: "pypy-3.7"
          - os: macos-latest
            python-version: "3.5"

    steps:
      - name: checkout
        uses: actions/checkout@v2
      - name: Set up Python ${{ matrix.python-version }}
        uses: actions/setup-python@v2
        with:
          python-version: ${{ matrix.python-version }}
      ###
      # Caching.
      # This actually *restores* a cache and schedules a cleanup action
      # to save the cache. So it must come before the thing we want to use
      # the cache.
      ###
      - name: Get pip cache dir
        id: pip-cache
        run: |
          echo "::set-output name=dir::$(pip cache dir)"

      - name: pip cache
        uses: actions/cache@v2
        with:
          path: ${{ steps.pip-cache.outputs.dir }}
          key: ${{ runner.os }}-pip-${{ matrix.python-version }}
          restore-keys: |
            ${{ runner.os }}-pip-

      - name: Install Build Dependencies
        run: |
          pip install -U pip
          pip install -U setuptools wheel twine cffi

      - name: Build zope.security
        run: |
          # Next, build the wheel *in place*. This helps ccache, and also lets us cache the configure
          # output (pip install uses a random temporary directory, making this difficult).
          python setup.py build_ext -i
          python setup.py bdist_wheel
          # Also install it, so that we get dependencies in the (pip) cache.
          pip install -U 'faulthandler; python_version == "2.7" and platform_python_implementation == "CPython"'
          pip install --pre .[test]

      - name: Check zope.security build
        run: |
          ls -l dist
          twine check dist/*
      - name: Upload zope.security wheel
        uses: actions/upload-artifact@v2
        with:
          name: zope.security-${{ runner.os }}-${{ matrix.python-version }}.whl
          path: dist/*whl
      - name: Publish package to PyPI (mac)
        # We cannot 'uses: pypa/gh-action-pypi-publish@v1.4.1' because
        # that's apparently a container action, and those don't run on
        # the Mac.
        if: >
          github.event_name == 'push'
          && startsWith(github.ref, 'refs/tags')
          && startsWith(runner.os, 'Mac')
          && !startsWith(matrix.python-version, 'pypy')
          && !startsWith(matrix.python-version, '3.11.0-beta.1')
        env:
          TWINE_PASSWORD: ${{ secrets.TWINE_PASSWORD }}
        run: |
          twine upload --skip-existing dist/*

  test:
    needs: build-package
    runs-on: ${{ matrix.os }}
    strategy:
      fail-fast: false
      matrix:
        python-version:
          - "2.7"
          - "3.5"
          - "pypy-2.7"
          - "pypy-3.7"
          - "3.6"
          - "3.7"
          - "3.8"
          - "3.9"
          - "3.10"
          - "3.11.0-beta.1"
        os: [ubuntu-20.04, macos-latest]
        exclude:
          - os: macos-latest
            python-version: "pypy-2.7"
          - os: macos-latest
            python-version: "pypy-3.7"
          - os: macos-latest
            python-version: "3.5"

    steps:
      - name: checkout
        uses: actions/checkout@v2
      - name: Set up Python ${{ matrix.python-version }}
        uses: actions/setup-python@v2
        with:
          python-version: ${{ matrix.python-version }}
      ###
      # Caching.
      # This actually *restores* a cache and schedules a cleanup action
      # to save the cache. So it must come before the thing we want to use
      # the cache.
      ###
      - name: Get pip cache dir
        id: pip-cache
        run: |
          echo "::set-output name=dir::$(pip cache dir)"

      - name: pip cache
        uses: actions/cache@v2
        with:
          path: ${{ steps.pip-cache.outputs.dir }}
          key: ${{ runner.os }}-pip-${{ matrix.python-version }}
          restore-keys: |
            ${{ runner.os }}-pip-

      - name: Download zope.security wheel
        uses: actions/download-artifact@v2
        with:
          name: zope.security-${{ runner.os }}-${{ matrix.python-version }}.whl
          path: dist/
      - name: Install zope.security
        run: |
          pip install -U wheel setuptools
          # coverage has a wheel on PyPI for a future python version which is
          # not ABI compatible with the current one, so build it from sdist:
          pip install -U --no-binary :all: coverage
          pip install -U 'faulthandler; python_version == "2.7" and platform_python_implementation == "CPython"'
          # Unzip into src/ so that testrunner can find the .so files
          # when we ask it to load tests from that directory. This
          # might also save some build time?
          unzip -n dist/zope.security-*whl -d src
          pip install --pre -U -e .[test]
      - name: Run tests with C extensions
        if: ${{ !startsWith(matrix.python-version, 'pypy') }}
        run: |
          python -m coverage run -p -m zope.testrunner --test-path=src --auto-color --auto-progress
      - name: Run tests without C extensions
        run:
          # coverage makes PyPy run about 3x slower!
          PURE_PYTHON=1 python -m coverage run -p -m zope.testrunner --test-path=src --auto-color --auto-progress
      - name: Report Coverage
        run: |
          coverage combine
          coverage report -i
      - name: Submit to Coveralls
        # This is a container action, which only runs on Linux.
        if: ${{ startsWith(runner.os, 'Linux') }}
        uses: AndreMiras/coveralls-python-action@develop
        with:
          parallel: true

  coveralls_finish:
    needs: test
    runs-on: ubuntu-20.04
    steps:
    - name: Coveralls Finished
      uses: AndreMiras/coveralls-python-action@develop
      with:
        parallel-finished: true

  docs:
    needs: build-package
    runs-on: ${{ matrix.os }}
    strategy:
      matrix:
        python-version: ["3.9"]
        os: [ubuntu-20.04]

    steps:
      - name: checkout
        uses: actions/checkout@v2
      - name: Set up Python ${{ matrix.python-version }}
        uses: actions/setup-python@v2
        with:
          python-version: ${{ matrix.python-version }}
      ###
      # Caching.
      # This actually *restores* a cache and schedules a cleanup action
      # to save the cache. So it must come before the thing we want to use
      # the cache.
      ###
      - name: Get pip cache dir
        id: pip-cache
        run: |
          echo "::set-output name=dir::$(pip cache dir)"

      - name: pip cache
        uses: actions/cache@v2
        with:
          path: ${{ steps.pip-cache.outputs.dir }}
          key: ${{ runner.os }}-pip-${{ matrix.python-version }}
          restore-keys: |
            ${{ runner.os }}-pip-

      - name: Download zope.security wheel
        uses: actions/download-artifact@v2
        with:
          name: zope.security-${{ runner.os }}-${{ matrix.python-version }}.whl
          path: dist/
      - name: Install zope.security
        run: |
          pip install -U wheel
          pip install -U coverage
          pip install -U  "`ls dist/zope.security-*.whl`[docs]"
      - name: Build docs
        env:
          ZOPE_INTERFACE_STRICT_IRO: 1
        run: |
          sphinx-build -b html -d docs/_build/doctrees docs docs/_build/html
          sphinx-build -b doctest -d docs/_build/doctrees docs docs/_build/doctest

  lint:
    needs: build-package
    runs-on: ${{ matrix.os }}
    strategy:
      matrix:
        python-version: ["3.9"]
        os: [ubuntu-20.04]

    steps:
      - name: checkout
        uses: actions/checkout@v2
      - name: Set up Python ${{ matrix.python-version }}
        uses: actions/setup-python@v2
        with:
          python-version: ${{ matrix.python-version }}
      ###
      # Caching.
      # This actually *restores* a cache and schedules a cleanup action
      # to save the cache. So it must come before the thing we want to use
      # the cache.
      ###
      - name: Get pip cache dir
        id: pip-cache
        run: |
          echo "::set-output name=dir::$(pip cache dir)"

      - name: pip cache
        uses: actions/cache@v2
        with:
          path: ${{ steps.pip-cache.outputs.dir }}
          key: ${{ runner.os }}-pip-${{ matrix.python-version }}
          restore-keys: |
            ${{ runner.os }}-pip-

      - name: Download zope.security wheel
        uses: actions/download-artifact@v2
        with:
          name: zope.security-${{ runner.os }}-${{ matrix.python-version }}.whl
          path: dist/
      - name: Install zope.security
        run: |
          pip install -U pip
          pip install -U wheel
          pip install -U `ls dist/zope.security-*`[test]
      - name: Lint
        # We only need to do this on one version, and it should be Python 3, because
        # pylint has stopped updating for Python 2.
        # TODO: Pick a linter and configuration and make this step right.
        run: |
          pip install -U pylint
          # python -m pylint --limit-inference-results=1 --rcfile=.pylintrc zope.security -f parseable -r n

  manylinux:
    runs-on: ubuntu-20.04
    # We use a regular Python matrix entry to share as much code as possible.
    strategy:
      matrix:
        python-version: ["3.9"]
        image: [manylinux2010_x86_64, manylinux2010_i686, manylinux2014_aarch64]

    steps:
      - name: checkout
        uses: actions/checkout@v2
      - name: Set up Python ${{ matrix.python-version }}
        uses: actions/setup-python@v2
        with:
          python-version: ${{ matrix.python-version }}
      ###
      # Caching.
      # This actually *restores* a cache and schedules a cleanup action
      # to save the cache. So it must come before the thing we want to use
      # the cache.
      ###
      - name: Get pip cache dir
        id: pip-cache
        run: |
          echo "::set-output name=dir::$(pip cache dir)"

      - name: pip cache
        uses: actions/cache@v2
        with:
          path: ${{ steps.pip-cache.outputs.dir }}
          key: ${{ runner.os }}-pip_manylinux-${{ matrix.image }}-${{ matrix.python-version }}
          restore-keys: |
            ${{ runner.os }}-pip-

      - name: Update pip
        run: pip install -U pip
      - name: Build zope.security (x86_64)
        if: matrix.image == 'manylinux2010_x86_64'
        # An alternate way to do this is to run the container directly with a uses:
        # and then the script runs inside it. That may work better with caching.
        # See https://github.com/pyca/bcrypt/blob/f6b5ee2eda76d077c531362ac65e16f045cf1f29/.github/workflows/wheel-builder.yml
        # The 2010 image is the most recent spec that comes with Python 2.7,
        # and only up through the tag 2021-02-06-3d322a5
        env:
          DOCKER_IMAGE: quay.io/pypa/${{ matrix.image }}
        run: |
          bash .manylinux.sh
      - name: Build zope.security (i686)
        if: matrix.image == 'manylinux2010_i686'
        env:
          DOCKER_IMAGE: quay.io/pypa/${{ matrix.image }}
          PRE_CMD: linux32
        run: |
          bash .manylinux.sh
      - name: Build zope.security (aarch64)
        if: matrix.image == 'manylinux2014_aarch64'
        env:
          DOCKER_IMAGE: quay.io/pypa/${{ matrix.image }}
        run: |
          # First we must enable emulation
          docker run --rm --privileged hypriot/qemu-register
          bash .manylinux.sh

      - name: Upload zope.security wheels
        uses: actions/upload-artifact@v2
        with:
          path: wheelhouse/*whl
          name: manylinux_${{ matrix.image }}_wheels.zip
      - name: Restore pip cache permissions
        run: sudo chown -R $(whoami) ${{ steps.pip-cache.outputs.dir }}
      - name: Publish package to PyPI
        uses: pypa/gh-action-pypi-publish@v1.4.1
        if: >
          github.event_name == 'push'
          && startsWith(github.ref, 'refs/tags')
        with:
          user: __token__
          password: ${{ secrets.TWINE_PASSWORD }}
          skip_existing: true
          packages_dir: wheelhouse/