Repository navigation
199 lines (195 loc) · 9.37 KB
/
Copy pathci.yaml
File metadata and controls
199 lines (195 loc) · 9.37 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
130
131
132
133
134
135
136
137
138
139
140
141
142
143
144
145
146
147
148
149
150
151
152
153
154
155
156
157
158
159
160
161
162
163
164
165
166
167
168
169
170
171
172
173
174
175
176
177
178
179
180
181
182
183
184
185
186
187
188
189
190
191
192
193
194
195
196
197
198
199
name: CI
on:
push:
branches: [main]
pull_request:
branches: [main]
jobs:
analyze-test:
runs-on: macos-14
steps:
- uses: actions/checkout@v4
- name: No audit tags or line citations in comments
run: tool/check_comment_tags.sh
- uses: subosito/flutter-action@v2
with:
# Pin to the Flutter version the consumer (work_canvas) ships against
# (its .fvmrc / custom engine), not floating `stable`. Floating stable
# breaks CI on every new framework interface method the pinned engine
# doesn't carry (e.g. TextInputClient.onFocusReceived, added after 3.41).
flutter-version: 3.38.8
channel: stable
- run: flutter --version
- name: Install dependencies
run: flutter pub get
- name: Analyze (package + sub-packages + example)
run: |
flutter analyze
(cd packages/flutter_cef_platform_interface && flutter pub get && flutter analyze)
(cd packages/flutter_cef_macos && flutter pub get && flutter analyze)
(cd packages/flutter_cef_windows && flutter pub get && flutter analyze)
(cd example && flutter pub get && flutter analyze)
- name: Test
run: flutter test
- name: Swift policy suites (CDP isolation filter, liveness, resize)
# Standalone swiftc suites that run without Xcode/CocoaPods. The CDP per-tile
# isolation filter is the security keystone; the rest cover the watchdogs.
# Every run_*.sh runs, so a new suite can't be left out.
run: |
set -e
for t in packages/flutter_cef_macos/test/run_*.sh; do
echo "== $t"
"$t"
done
- name: Windows policy suites (crash loop, payload caps, schemes, downloads, liveness)
# The Windows host's and plugin's pure policy headers need no Win32, so
# they are unit-tested here with the macOS toolchain.
run: |
set -e
for t in packages/flutter_cef_windows/test/native/run_*.sh; do
echo "== $t"
"$t"
done
# macOS native: compile cef_host (main.mm) and the plugin's Swift by building
# the host from source and the example app, so native changes don't merge
# unbuilt. Uses the stock CEF framework (the pinned patched variant needs a
# from-source Chromium build); publishing still requires the variant.
macos-build:
runs-on: macos-14
steps:
- uses: actions/checkout@v4
- uses: subosito/flutter-action@v2
with:
flutter-version: 3.38.8
channel: stable
- name: Cache the CEF SDK
uses: actions/cache@v4
with:
path: ~/.cache/flutter_cef/cef_binary_*
key: cef-sdk-${{ hashFiles('packages/flutter_cef_macos/native/build_cef_host.sh') }}
- name: Build cef_host from source (stock CEF framework)
run: |
brew install ninja
FLUTTER_CEF_STOCK_FRAMEWORK=1 packages/flutter_cef_macos/native/build_cef_host.sh
- name: Build example for macOS (compiles the plugin)
run: |
cd example
flutter pub get
FLUTTER_CEF_FROM_SOURCE=1 flutter build macos --debug
- name: Is a prebuilt published for these sources?
# Not a failure: a PR that changes native/ can't have one until it merges
# and someone runs `make publish-cef-host`. Consumers pinned to such a
# commit need it before a release build (FLUTTER_CEF_REQUIRE_PREBUILT).
run: |
cd packages/flutter_cef_macos
. tool/cef_host_hash.sh
HASH="$(cef_host_input_hash native)"
URL="https://github.com/FlutterFlow/flutter_cef/releases/download/cef-host-$HASH/cef_host-macos-arm64.tar.gz.sha256"
if curl -fsIL "$URL" >/dev/null; then
echo "prebuilt cef-host-$HASH is published"
else
echo "::warning::No prebuilt for cef_host input hash $HASH. Run make publish-cef-host after merging."
fi
# Windows: analyze the endorsed windows implementation + build the example so
# the ~5.5k lines of native plugin/cef_host/CDP-relay code (profiles, cookies,
# JS bridge, agent control) are actually compiled by CI, not merged blind.
windows-build:
runs-on: windows-latest
steps:
- uses: actions/checkout@v4
- uses: subosito/flutter-action@v2
with:
flutter-version: 3.38.8
channel: stable
- run: flutter --version
- name: Analyze (windows implementation package)
shell: bash
run: |
flutter pub get
flutter analyze
(cd packages/flutter_cef_windows && flutter pub get && flutter analyze)
- name: Dart tests (includes the Windows key/accelerator + verb twins)
run: flutter test
- name: Build example for Windows (compiles the plugin + cef_host)
shell: bash
# CEF (~200 MB) is fetched by the plugin CMake from the pinned dist; if
# the fetch/build is unavailable on the runner this step surfaces it
# rather than letting native regressions merge unbuilt.
run: |
cd example
flutter pub get
flutter build windows --debug
- name: Build and run pipe_probe (cef_host against a stub plugin)
# Reuses the cef_host build tree the example build just configured.
# pipe_probe drives the host over the pipe: handshake, create, first
# frame, a navigation, shutdown; then a host whose UI thread it
# suspends before kOpShutdown, which has to exit on its own. It serves
# its pages on 127.0.0.1, so the network can't slow it down. The
# second run turns the GPU off and checks the frames came through
# OnPaint, the software path.
shell: pwsh
timeout-minutes: 10
run: |
$build = (Resolve-Path "example\build\windows\x64\plugins\flutter_cef_windows\cef_host_build").Path
$runner = (Resolve-Path "example\build\windows\x64\runner\Debug").Path
& "packages\flutter_cef_windows\native\cef_host\build_cef_host.bat" "$build" "$build" pipe_probe
if ($LASTEXITCODE -ne 0) { exit $LASTEXITCODE }
& "$build\pipe_probe.exe" $runner
if ($LASTEXITCODE -ne 0) { exit $LASTEXITCODE }
Write-Output "== pipe_probe, software compositing"
$env:FLUTTER_CEF_SOFTWARE_COMPOSITING = "1"
$env:FLUTTER_CEF_DEBUG = "1"
$log = Join-Path $env:RUNNER_TEMP "pipe_probe_software.txt"
& "$build\pipe_probe.exe" $runner | Tee-Object -FilePath $log
if ($LASTEXITCODE -ne 0) { exit $LASTEXITCODE }
if (-not (Select-String -Path $log -Pattern "OnPaint \(software\)" -Quiet)) {
Write-Output "no software-painted frame: the GPU path was used"
exit 1
}
- name: Runtime smoke test (example app, real cef_host)
# Runs the app against the cef_host it just built: first frame, eval, a
# JS channel, resize, freeze/thaw, then a crash loop and a hung
# renderer on one of several tiles sharing a host, and a replaced GPU
# process. Once as the runner composites, once with the GPU off
# (software paint). The plugin's and hosts' log lines go to a file
# (FLUTTER_CEF_LOG_FILE); the crash-loop and liveness lines are
# printed, and the whole log when a mode fails. See
# example/lib/windows_smoke_probe.dart.
shell: pwsh
timeout-minutes: 20
run: |
cd example
flutter build windows --debug -t lib/windows_smoke_probe.dart
if ($LASTEXITCODE -ne 0) { exit $LASTEXITCODE }
$env:FLUTTER_CEF_SMOKE_CRASH_ROUNDS = "3"
$failed = $false
foreach ($mode in @("default", "software")) {
if ($mode -eq "software") { $env:FLUTTER_CEF_SOFTWARE_COMPOSITING = "1" }
$out = Join-Path $env:RUNNER_TEMP "windows_smoke_$mode.txt"
$log = Join-Path $env:RUNNER_TEMP "windows_smoke_$mode.log"
$env:FLUTTER_CEF_PROBE_OUT = $out
$env:FLUTTER_CEF_LOG_FILE = $log
$p = Start-Process -FilePath "build\windows\x64\runner\Debug\flutter_cef_example.exe" -PassThru
$timedOut = -not $p.WaitForExit(300000)
if ($timedOut) {
Stop-Process -Id $p.Id -Force -ErrorAction SilentlyContinue
Get-Process cef_host -ErrorAction SilentlyContinue | Stop-Process -Force -ErrorAction SilentlyContinue
}
Write-Output "== smoke test, $mode compositing"
if (Test-Path $out) { Get-Content $out }
$modeFailed = $false
if ($timedOut) { Write-Output "timed out after 300 s"; $modeFailed = $true }
elseif (-not (Test-Path $out)) { Write-Output "no result file at $out"; $modeFailed = $true }
elseif (-not (Select-String -Path $out -Pattern "CEF_PROBE_RESULT PASS" -Quiet)) { $modeFailed = $true }
if (Test-Path $log) {
if ($modeFailed) {
Write-Output "== plugin and host log, $mode compositing"
Get-Content $log
} else {
Write-Output "== host crash-loop and liveness lines, $mode compositing"
Select-String -Path $log -Pattern "renderer terminated|giving up|several browsers|browser gone|liveness ping" | ForEach-Object { $_.Line }
}
}
if ($modeFailed) { $failed = $true }
}
if ($failed) { exit 1 }