forked from GoogleCloudPlatform/scion
-
Notifications
You must be signed in to change notification settings - Fork 0
Expand file tree
/
Copy pathMakefile
More file actions
244 lines (210 loc) · 9.17 KB
/
Copy pathMakefile
File metadata and controls
244 lines (210 loc) · 9.17 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
130
131
132
133
134
135
136
137
138
139
140
141
142
143
144
145
146
147
148
149
150
151
152
153
154
155
156
157
158
159
160
161
162
163
164
165
166
167
168
169
170
171
172
173
174
175
176
177
178
179
180
181
182
183
184
185
186
187
188
189
190
191
192
193
194
195
196
197
198
199
200
201
202
203
204
205
206
207
208
209
210
211
212
213
214
215
216
217
218
219
220
221
222
223
224
225
226
227
228
229
230
231
232
233
234
235
236
237
238
239
240
241
242
243
244
# Scion Makefile
# Run 'make help' to see available targets.
BINARY := scion
BUILD_DIR := ./build
CONTAINER_DIR := ./.build/container
PREFIX ?= /usr/local
DESTDIR ?=
INSTALL_DIR := $(PREFIX)/bin
MAIN_PKG := ./cmd/scion
LDFLAGS := $(shell ./hack/version.sh)
SCIONTOOL_LDFLAGS := $(shell ./hack/version.sh github.com/GoogleCloudPlatform/scion/cmd/sciontool/commands)
CONTAINER_OS := linux
CONTAINER_ARCH := $(shell if [ "$$(uname -m)" = "x86_64" ]; then echo amd64; else echo arm64; fi)
GOLANGCI_LINT := $(shell command -v golangci-lint 2>/dev/null || echo $(shell go env GOPATH)/bin/golangci-lint)
.DEFAULT_GOAL := help
.PHONY: all build build-a2a-bridge test-a2a-integration install test test-fast vet lint compat-literals check-authz-guards check-conversation-upsert-guard check-security-marker-gates check-authorization-catalog check-custom golangci-lint web web-typecheck web-test fmt fmt-check tidy-extras ci ci-full clean help container-sciontool container-scion container-binaries proto proto-check
## all: Build the web frontend and compile the Go binary (run 'make install' separately to install)
all: web build
## build: Compile the scion binary into ./build/
build:
@echo "Building $(BINARY)..."
@mkdir -p $(BUILD_DIR)
@go build -buildvcs=false -ldflags "$(LDFLAGS)" -o $(BUILD_DIR)/$(BINARY) $(MAIN_PKG)
@echo "Binary: $(BUILD_DIR)/$(BINARY)"
## build-a2a-bridge: Build the A2A bridge binary into ./bin/
build-a2a-bridge:
@echo "Building scion-a2a-bridge..."
@mkdir -p bin
@go build -o bin/scion-a2a-bridge ./extras/scion-a2a-bridge/cmd/scion-a2a-bridge/
@echo "Binary: bin/scion-a2a-bridge"
## test-a2a-integration: Run the A2A bridge deterministic integration suite with fail-closed PostgreSQL
test-a2a-integration:
@./extras/scion-a2a-bridge/scripts/run-integration-ci.sh
## install: Install a pre-built binary (default: /usr/local/bin, override with PREFIX=~/.local). Run 'make build' first.
install:
@if [ ! -f $(BUILD_DIR)/$(BINARY) ]; then \
echo "Error: $(BUILD_DIR)/$(BINARY) not found. Run 'make build' (or 'make all') first."; \
exit 1; \
fi
@echo "Installing $(BINARY) to $(DESTDIR)$(INSTALL_DIR)..."
@mkdir -p $(DESTDIR)$(INSTALL_DIR)
@install $(BUILD_DIR)/$(BINARY) $(DESTDIR)$(INSTALL_DIR)/$(BINARY)
@echo ""
@echo "✔ Installed $(BINARY) to $(DESTDIR)$(INSTALL_DIR)/$(BINARY)"
@echo ""
@echo " Run 'scion version' to verify."
@echo ""
@case ":$$PATH:" in \
*":$(INSTALL_DIR):"* | *":$(INSTALL_DIR)/:"*) ;; \
*) echo " ⚠ WARNING: $(INSTALL_DIR) is not in your PATH."; \
echo " Add it with:"; \
echo ""; \
echo " export PATH=\"$(INSTALL_DIR):\$$PATH\""; \
echo "" ;; \
esac
## test: Run all tests
test:
@echo "Running tests..."
@go test ./...
## test-fast: Run tests without SQLite (lower memory usage)
test-fast:
@echo "Running tests (no SQLite)..."
@go test -tags no_sqlite ./...
## vet: Run go vet
vet:
@go vet ./...
## lint: Run go vet (no SQLite, memory-safe)
lint:
@go vet -tags no_sqlite ./...
## compat-literals: Check legacy grove literals stay in compatibility surfaces
compat-literals:
@./hack/check-project-compat-literals.sh
## check-authz-guards: Verify no authorization-bypass patterns exist in handler code
# NOTE: make reports its own failure code (2) rather than the recipe's, so the
# script's exit 1 (violations found) and exit 2 (nothing was analysed — skipped,
# not clean) are indistinguishable to anything reading this target's exit status.
# The messages still differ on stderr. Any caller that needs to tell those two
# apart must invoke ./hack/check-authz-guards.sh directly, as CI does.
check-authz-guards:
@./hack/check-authz-guards.sh
## check-conversation-upsert-guard: Verify UpsertConversationByExternalRef is only called from pkg/messaging and pkg/store
check-conversation-upsert-guard:
@./hack/check-conversation-upsert-guard.sh
## check-security-marker-gates: Verify security symbols (authenticatedSender, validateDefaultAgent, ActionAttach) remain in handler code
check-security-marker-gates:
@./hack/check-security-marker-gates.sh
## check-authorization-catalog: Validate authorization operation catalog, permission coverage, and generated report
check-authorization-catalog:
@./hack/check-authorization-catalog.sh
## check-custom: Run all custom CI lint checks (see hack/LINT-CONVENTIONS.md)
check-custom: compat-literals check-authz-guards check-conversation-upsert-guard check-security-marker-gates check-authorization-catalog
@echo "All custom checks passed."
## golangci-lint: Run golangci-lint on new issues only (install via: go install github.com/golangci/golangci-lint/v2/cmd/golangci-lint@latest)
golangci-lint:
@if [ ! -x "$(GOLANGCI_LINT)" ]; then \
echo "ERROR: golangci-lint not found. Install with: go install github.com/golangci/golangci-lint/v2/cmd/golangci-lint@latest"; \
exit 1; \
fi
@echo "Running golangci-lint (new issues vs main)..."
@GOGC=50 $(GOLANGCI_LINT) run --new-from-rev=main ./...
@echo "golangci-lint passed."
## web: Build the web frontend
web:
@echo "Building web frontend..."
@rm -rf web/dist
@cd web && npm install && npm run build
@mkdir -p web/dist/client && touch web/dist/client/.gitkeep
@echo "Web frontend built."
## container-sciontool: Cross-compile sciontool for Linux containers
container-sciontool:
@echo "Building sciontool for $(CONTAINER_OS)/$(CONTAINER_ARCH)..."
@mkdir -p $(CONTAINER_DIR)
@GOOS=$(CONTAINER_OS) GOARCH=$(CONTAINER_ARCH) CGO_ENABLED=0 \
go build -buildvcs=false -ldflags "$(SCIONTOOL_LDFLAGS)" \
-o $(CONTAINER_DIR)/sciontool ./cmd/sciontool
@echo "Built: $(CONTAINER_DIR)/sciontool"
## container-scion: Cross-compile scion CLI for Linux containers
container-scion:
@echo "Building scion for $(CONTAINER_OS)/$(CONTAINER_ARCH)..."
@mkdir -p $(CONTAINER_DIR)
@GOOS=$(CONTAINER_OS) GOARCH=$(CONTAINER_ARCH) CGO_ENABLED=0 \
go build -buildvcs=false -tags no_embed_web -ldflags "$(LDFLAGS)" \
-o $(CONTAINER_DIR)/scion ./cmd/scion
@echo "Built: $(CONTAINER_DIR)/scion"
## container-binaries: Build both scion and sciontool for Linux containers
container-binaries: container-sciontool container-scion
@echo ""
@echo "Dev binaries ready in $(CONTAINER_DIR)/"
@echo "Usage: export SCION_DEV_BINARIES=$(CONTAINER_DIR)"
## web-typecheck: Run TypeScript type checking on the web frontend
web-typecheck:
@echo "Type-checking web frontend..."
@cd web && npm run typecheck
@echo "Type check passed."
## web-test: Run the web frontend unit tests (vitest)
web-test:
@echo "Running web frontend tests..."
@cd web && npm test
@echo "Web tests passed."
## fmt: Auto-format Go source files
fmt:
@echo "Formatting Go source files..."
@gofmt -w .
@echo "Go formatting done."
## fmt-check: Check Go formatting without modifying files (mirrors GitHub Actions)
fmt-check:
@echo "Checking Go formatting..."
@UNFORMATTED=$$(gofmt -l .); \
if [ -n "$$UNFORMATTED" ]; then \
echo "Go formatting issues found. Run 'make fmt' to fix:"; \
echo "$$UNFORMATTED"; \
exit 1; \
fi
@echo "Go formatting OK."
## tidy-extras: Run go mod tidy in every extras/ module (fixes stale go.sum after root dep changes)
tidy-extras:
@echo "Tidying extras modules..."
@failed=0; \
for moddir in $$(find extras -maxdepth 2 -name go.mod -printf '%h\n' | sort); do \
echo " $$moddir"; \
(cd "$$moddir" && go mod tidy) || { echo " FAILED: $$moddir"; failed=$$((failed + 1)); }; \
done; \
if [ "$$failed" -gt 0 ]; then \
echo "$$failed module(s) failed to tidy."; \
exit 1; \
fi; \
echo "All extras modules tidied."
## ci: Run fast CI checks (format check, vet, custom lint checks, tests, build)
ci: fmt-check lint check-custom test-fast build
@echo ""
@echo "CI passed."
## ci-full: Run the full CI pipeline locally (mirrors GitHub Actions, includes web + golangci-lint)
ci-full: fmt-check web web-typecheck web-test lint check-custom golangci-lint test-fast build
@echo ""
@echo "CI (full) passed."
## proto: Generate Go code from .proto files
proto:
@echo "Generating protobuf Go code..."
@protoc \
--proto_path=proto \
--go_out=. --go_opt=module=github.com/GoogleCloudPlatform/scion \
--go-grpc_out=. --go-grpc_opt=module=github.com/GoogleCloudPlatform/scion \
proto/broker/v1/broker.proto
@echo "Proto generation done."
## proto-check: Verify generated protobuf code is up to date
proto-check:
@echo "Checking protobuf generated code is up to date..."
@TMP=$$(mktemp -d) && \
protoc \
--proto_path=proto \
--go_out=$$TMP --go_opt=module=github.com/GoogleCloudPlatform/scion \
--go-grpc_out=$$TMP --go-grpc_opt=module=github.com/GoogleCloudPlatform/scion \
proto/broker/v1/broker.proto && \
diff $$TMP/proto/broker/v1/broker.pb.go proto/broker/v1/broker.pb.go && \
diff $$TMP/proto/broker/v1/broker_grpc.pb.go proto/broker/v1/broker_grpc.pb.go && \
rm -rf $$TMP && \
echo "Proto generated code is up to date." || \
(rm -rf $$TMP; echo "Proto generated code is out of date. Run 'make proto' to regenerate."; exit 1)
## clean: Remove build artifacts
clean:
@echo "Cleaning..."
@rm -rf $(BUILD_DIR) .build web/dist
@mkdir -p web/dist/client && touch web/dist/client/.gitkeep
@rm -f $(BINARY)
@echo "Done."
## help: Show this help message
help:
@echo "Usage: make [target]"
@echo ""
@grep -E '^## ' $(MAKEFILE_LIST) | sed 's/^## / /' | column -t -s ':'