Skip to content
Draft
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
61 changes: 61 additions & 0 deletions .github/workflows/macos-packages.yml
Original file line number Diff line number Diff line change
@@ -0,0 +1,61 @@
name: Build MacOS community client pkg files

on:
workflow_dispatch:

permissions:
contents: read
pull-requests: read

jobs:
macos_package:
name: Build a CFEngine community agent pkg file for MacOS
strategy:
matrix:
os: [macos-26-intel, macos-latest]
runs-on: ${{ matrix.os }}
steps:
- name: Checkout Together Action
uses: actions/checkout@v3
with:
repository: cfengine/together-javascript-action
ref: main
ssh-key: ${{ secrets.GH_ACTIONS_SSH_DEPLOY_KEY_TOGETHER_REPO }}
ssh-known-hosts: github.com

- name: Action step
uses: ./
id: together
with:
myToken: ${{ secrets.GITHUB_TOKEN }}

- name: Checkout Core
uses: actions/checkout@v3
with:
repository: cfengine/core
path: core
ref: ${{steps.together.outputs.core || github.base_ref}}
submodules: recursive

- name: Checkout Masterfiles
uses: actions/checkout@v3
with:
repository: cfengine/masterfiles
path: masterfiles
ref: ${{steps.together.outputs.masterfiles || github.base_ref}}

- name: Checkout Buildscripts
uses: actions/checkout@v3
with:
path: buildscripts

- name: Build package natively
id: build_package
run: |
./buildscripts/ci/build-macos.sh

- name: Save artifacts
uses: actions/upload-artifact@v4
with:
name: macos-package-artifact
path: /Users/runner/work/buildscripts/buildscripts/cfengine-community
13 changes: 10 additions & 3 deletions build-scripts/compile-options
Original file line number Diff line number Diff line change
Expand Up @@ -74,6 +74,11 @@ solaris)
export CFLAGS
fi
;;
darwin)
# Apple's linker (ld64) doesn't understand the GNU/Solaris "-R" rpath
# spelling used in the default case below, it needs "-rpath" instead.
LDFLAGS="-L$BUILDPREFIX/lib -Wl,-rpath,$BUILDPREFIX/lib"
;;
*)
LDFLAGS="-L$BUILDPREFIX/lib -Wl,-R$BUILDPREFIX/lib"
;;
Expand Down Expand Up @@ -144,7 +149,7 @@ var_append DEPS "librsync" # Library for synchronization of file

# coreutils is only built for redhat/debian/windows for now
case "$OS_FAMILY" in
hpux | aix | solaris | freebsd) ;;
hpux | aix | solaris | freebsd | darwin) ;;
*)
var_append DEPS "coreutils" # Provides a standalone 'date' binary
;;
Expand All @@ -167,7 +172,7 @@ esac

# Non-exotics dependencies
case "$OS_FAMILY" in
hpux | aix | solaris | freebsd | mingw) ;;
hpux | aix | solaris | freebsd | mingw | darwin) ;;
*)
# Library for managing Extended Attributes (xattrs) on filesystems
var_append DEPS "libattr"
Expand Down Expand Up @@ -257,7 +262,9 @@ esac

# Determine whether or not to run tests
case "$OS_FAMILY" in
mingw | freebsd) TESTS=no ;;
# Test suites for the bundled dependencies aren't yet verified to pass on
# macOS, so play it safe like the other newer/less-trodden platforms.
mingw | freebsd | darwin) TESTS=no ;;
*) TESTS=all ;;
esac
export TESTS
Expand Down
21 changes: 20 additions & 1 deletion build-scripts/detect-environment
Original file line number Diff line number Diff line change
Expand Up @@ -70,6 +70,7 @@ detect_os() {
Darwin)
OS_FAMILY=darwin
OS=darwin
OS_VERSION=$(sw_vers -productVersion)
;;
FreeBSD)
OS_FAMILY=freebsd
Expand Down Expand Up @@ -236,7 +237,15 @@ detect_distribution() {
# detected, then the "pkg-build-rpm" script will be called from the
# "install-dependencies" script.
detect_packaging() {
if [ -f /bin/rpm ]; then
if [ "$UNAME_S" = Darwin ]; then
# macOS has no package manager suitable for the iterative
# build-then-install-locally workflow the other DEP_PACKAGING values
# use (rpm/dpkg/pkg_add/etc all maintain a real system package
# database). pkg-build-macos/pkg-find-macos/pkg-install-macos use a
# plain tarball format with their own lightweight file-registry
# instead, see deps-packaging/pkg-install-macos.
DEP_PACKAGING=macos
elif [ -f /bin/rpm ]; then
DEP_PACKAGING=rpm
elif [ -f /usr/bin/dpkg ]; then
DEP_PACKAGING=deb
Expand All @@ -262,6 +271,9 @@ detect_packaging() {
mingw)
PACKAGING=msi
;;
darwin)
PACKAGING=macos
;;
*)
PACKAGING=$DEP_PACKAGING
;;
Expand Down Expand Up @@ -302,6 +314,10 @@ detect_arch() {
hpux)
ARCH=$UNAME_M
;;
macos)
# arm64 on Apple Silicon, x86_64 on Intel Macs.
ARCH=$UNAME_M
;;
*)
log_error "Unknown packaging system"
exit 42
Expand Down Expand Up @@ -373,6 +389,9 @@ detect_cores() {
hpux)
NUM_CORES="$(ioscan -k -C processor | grep -c processor)"
;;
darwin)
NUM_CORES="$(sysctl -n hw.ncpu)"
;;
*)
log_debug "Detected OS family is UNKNOWN, defaulting amount of CPU cores to 1"
NUM_CORES=1
Expand Down
29 changes: 28 additions & 1 deletion build-scripts/functions
Original file line number Diff line number Diff line change
Expand Up @@ -221,6 +221,27 @@ uninstall_freebsd_pkgs() {
fi
}

# uninstall_macos_pkgs: Remove macOS build-dependency packages matching a
# pattern. There's no system package manager suitable for our iterative
# build/install-locally workflow on macOS, so pkg-build-macos/pkg-install-macos
# track installed files themselves in a flat-file registry (see
# deps-packaging/pkg-install-macos) instead of using a real package database.
# Args:
# $1 - Package name pattern (regex)
uninstall_macos_pkgs() {
REGISTRY="$BASEDIR/.cfbuild-macos-db"
[ -d "$REGISTRY" ] || return 0
for filelist in "$REGISTRY"/*.filelist; do
[ -e "$filelist" ] || continue
name=$(basename "$filelist" .filelist)
echo "$name" | grep_q "^$1\$" || continue
while IFS= read -r f; do
rm -f "/$f"
done <"$filelist"
rm -f "$filelist"
done
}

# uninstall_cfbuild: Remove all cfbuild packages (runtime and devel)
# Uses the appropriate uninstall function based on $DEP_PACKAGING
uninstall_cfbuild() {
Expand All @@ -230,6 +251,7 @@ uninstall_cfbuild() {
solaris) uninstall_solaris_pkgs 'cfbuild-.*' ;;
freebsd) uninstall_freebsd_pkgs 'cfbuild-.*' ;;
hpux) uninstall_hpux_pkgs 'cfbuild-.*' ;;
macos) uninstall_macos_pkgs 'cfbuild-.*' ;;
*)
log_error "Unknown packaging system: $DEP_PACKAGING"
exit 1
Expand All @@ -243,6 +265,7 @@ uninstall_cfbuild_devel() {
case "$DEP_PACKAGING" in
rpm) uninstall_rpms 'cfbuild-.*-devel' ;;
deb) uninstall_debs 'cfbuild-.*-devel' ;;
macos) uninstall_macos_pkgs 'cfbuild-.*-devel' ;;
solaris) uninstall_solaris_pkgs 'cfbuild-.*-devel' ;;
freebsd) uninstall_freebsd_pkgs 'cfbuild-.*-devel' ;;
hpux) uninstall_hpux_pkgs 'cfbuild-.*-devel' ;;
Expand Down Expand Up @@ -651,6 +674,7 @@ func_sha256() {
case "$UNAME_S" in
SunOS) digest -a sha256 "$@" ;;
AIX) openssl dgst -sha256 "$@" | cut -d ' ' -f 2 ;;
Darwin) shasum -a 256 "$@" | cut -d ' ' -f 1 ;;
*) fatal "Can't find command for computing SHA-256" ;;
esac
fi
Expand Down Expand Up @@ -700,8 +724,11 @@ retry_wrapper() {
else
err_ret=$?
# in case say dpkg locks are held by automatic updates or something
# -P is a GNU grep extension (missing on e.g. macOS' BSD grep), and
# this is diagnostic-only, so use portable -E and never let it trip
# "set -e" when nothing matches.
# shellcheck disable=SC2009
ps -efl | grep -P '(apt|dpkg|yum|dnf|zypper|rpm|pkg)'
ps -ef | grep -E '(apt|dpkg|yum|dnf|zypper|rpm|pkg)' || true
maxtries=$((maxtries - 1))
echo "* FAILURE $err_ret"
echo "* Sleeping for: $pause seconds"
Expand Down
Loading
Loading