Release v0.9.5.2 #175
Workflow file for this run
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
| name: build | |
| run-name: ${{ startsWith(github.ref, 'refs/tags/v') && format('Release {0}', github.ref_name) || null }} | |
| on: | |
| workflow_dispatch: | |
| push: | |
| tags: | |
| - v[0-9]+* | |
| # branches: | |
| # - master | |
| # paths: | |
| # - 'ip2net/**' | |
| # - 'mdig/**' | |
| # - 'nfq2/**' | |
| jobs: | |
| build-linux: | |
| name: Linux ${{ matrix.arch }} | |
| runs-on: ubuntu-latest | |
| strategy: | |
| fail-fast: false | |
| matrix: | |
| include: | |
| - arch: arm64 | |
| tool: aarch64-unknown-linux-musl | |
| - arch: arm | |
| tool: armv6-unknown-linux-musleabi | |
| - arch: mips64 | |
| tool: mips64-unknown-linux-musl | |
| - arch: mipselsf | |
| tool: mipsel-unknown-linux-muslsf | |
| - arch: mipssf | |
| tool: mips-unknown-linux-muslsf | |
| - arch: ppc | |
| tool: powerpc-unknown-linux-musl | |
| - arch: x86 | |
| tool: i586-unknown-linux-musl | |
| - arch: x86_64 | |
| tool: x86_64-unknown-linux-musl | |
| - arch: riscv64 | |
| tool: riscv64-unknown-linux-musl | |
| - arch: lexra | |
| tool: mips-linux | |
| dir: rsdk-4.6.4-5281-EB-3.10-0.9.33-m32ub-20141001 | |
| env: | |
| CFLAGS: '-march=5281' | |
| LDFLAGS: '-lgcc_eh' | |
| repo: 'bol-van/build' | |
| steps: | |
| - name: Checkout | |
| uses: actions/checkout@v4 | |
| with: | |
| path: zapret2 | |
| - name: Set up build tools | |
| env: | |
| ARCH: ${{ matrix.arch }} | |
| TOOL: ${{ matrix.tool }} | |
| REPO: ${{ matrix.arch == 'lexra' && matrix.repo || 'bol-van/musl-cross' }} | |
| DIR: ${{ matrix.arch == 'lexra' && matrix.dir || matrix.tool }} | |
| run: | | |
| sudo dpkg --add-architecture i386 | |
| sudo apt update -qq | |
| if [[ "$ARCH" == lexra ]]; then | |
| sudo apt install -y pigz libcap-dev libc6:i386 zlib1g:i386 | |
| URL=https://github.com/$REPO/raw/refs/heads/master/$DIR.txz | |
| else | |
| # luajit buildvm requires 32 bit executable on host platform for 32 bit cross targets | |
| sudo apt install -y pigz libcap-dev libc6-dev gcc-multilib | |
| URL=https://github.com/$REPO/releases/download/latest/$TOOL.tar.xz | |
| fi | |
| mkdir -p $HOME/tools | |
| wget -qO- $URL | tar -C $HOME/tools -xJ || exit 1 | |
| [[ -d "$HOME/tools/$DIR/bin" ]] && echo "$HOME/tools/$DIR/bin" >> $GITHUB_PATH | |
| - name: Build | |
| env: | |
| ARCH: ${{ matrix.arch }} | |
| TARGET: ${{ matrix.tool }} | |
| CFLAGS: ${{ matrix.env.CFLAGS != '' && matrix.env.CFLAGS || null }} | |
| LDFLAGS: ${{ matrix.env.LDFLAGS != '' && matrix.env.LDFLAGS || null }} | |
| GH_TOKEN: ${{ secrets.GITHUB_TOKEN }} | |
| LUA_VER: 5.5 | |
| LUA_RELEASE: 5.5.0 | |
| LUAJIT_VER: 2.1 | |
| LUAJIT_RELEASE: 2.1-20250826 | |
| LUAJIT_LUAVER: 5.1 | |
| MINSIZE: -flto=auto -ffunction-sections -fdata-sections | |
| LDMINSIZE: -Wl,--gc-sections -flto=auto | |
| #current toolchain's musl is not PIC. will be broken by upx | |
| #PIC: -fpic | |
| run: | | |
| DEPS_DIR=$GITHUB_WORKSPACE/deps | |
| export CC="$TARGET-gcc" | |
| export LD=$TARGET-ld | |
| export AR=$TARGET-ar | |
| export NM=$TARGET-nm | |
| export STRIP=$TARGET-strip | |
| export PKG_CONFIG_PATH=$DEPS_DIR/lib/pkgconfig | |
| export STAGING_DIR=$RUNNER_TEMP | |
| OPTIMIZE=-Oz | |
| SYSMALLOC=-DLUAJIT_USE_SYSMALLOC | |
| case "$ARCH" in | |
| lexra) | |
| OPTIMIZE=-Os | |
| ;; | |
| arm) | |
| CPU="-mcpu=arm1176jzf-s -mthumb" | |
| ;; | |
| arm64|mips64) | |
| # not safe without GC64 | |
| SYSMALLOC= | |
| ;; | |
| esac | |
| MINSIZE="$OPTIMIZE $MINSIZE" | |
| if [[ "$ARCH" == lexra ]] || [[ "$ARCH" == riscv64 ]] || [[ "$ARCH" == x86 ]] ; then | |
| # use classic lua | |
| wget -qO- https://www.lua.org/ftp/lua-${LUA_RELEASE}.tar.gz | tar -xz | |
| ( | |
| cd lua-${LUA_RELEASE} | |
| make CC=$CC AR="$AR rc" CFLAGS="$CPU $MINSIZE $CFLAGS" LDFLAGS="$LDMINSIZE $LDFLAGS" linux -j$(nproc) | |
| make install INSTALL_TOP=$DEPS_DIR INSTALL_BIN=$DEPS_DIR/bin INSTALL_INC=$DEPS_DIR/include/lua${LUA_VER} INSTALL_LIB=$DEPS_DIR/lib | |
| ) | |
| LJIT=0 | |
| LCFLAGS="-I${DEPS_DIR}/include/lua${LUA_VER}" | |
| LLIB="-L${DEPS_DIR}/lib -llua" | |
| else | |
| # luajit | |
| wget -qO- https://github.com/openresty/luajit2/archive/refs/tags/v${LUAJIT_RELEASE}.tar.gz | tar -xz | |
| case "$ARCH" in | |
| *64*) | |
| HOSTCC="cc" | |
| ;; | |
| *) | |
| HOSTCC="cc -m32" | |
| esac | |
| echo ARCH=$ARCH SYSMALLOC=$SYSMALLOC | |
| ( | |
| cd luajit2-* | |
| make BUILDMODE=static XCFLAGS="$SYSMALLOC -DLUAJIT_DISABLE_FFI" HOST_CC="$HOSTCC" CROSS= CC="$CC" TARGET_AR="$AR rcus" TARGET_STRIP=$STRIP TARGET_CFLAGS="$CPU $MINSIZE $CFLAGS" TARGET_LDFLAGS="$CPU $LDMINSIZE $LDFLAGS" -j$(nproc) | |
| make install PREFIX= DESTDIR=$DEPS_DIR | |
| ) | |
| LJIT=1 | |
| LCFLAGS="-I${DEPS_DIR}/include/luajit-${LUAJIT_VER}" | |
| LLIB="-L${DEPS_DIR}/lib -lluajit-${LUAJIT_LUAVER}" | |
| fi | |
| # netfilter libs | |
| wget -qO- https://www.netfilter.org/pub/libnfnetlink/libnfnetlink-1.0.2.tar.bz2 | tar -xj | |
| wget -qO- https://www.netfilter.org/pub/libmnl/libmnl-1.0.5.tar.bz2 | tar -xj | |
| wget -qO- https://www.netfilter.org/pub/libnetfilter_queue/libnetfilter_queue-1.0.5.tar.bz2 | tar -xj | |
| for i in libmnl libnfnetlink libnetfilter_queue ; do | |
| ( | |
| cd $i-* | |
| CFLAGS="$CPU $MINSIZE $CFLAGS" \ | |
| LDFLAGS="$LDMINSIZE $LDFLAGS" \ | |
| ./configure --prefix= --host=$TARGET --enable-static --disable-shared --disable-dependency-tracking | |
| make install -j$(nproc) DESTDIR=$DEPS_DIR | |
| ) | |
| sed -i "s|^prefix=.*|prefix=$DEPS_DIR|g" $DEPS_DIR/lib/pkgconfig/$i.pc | |
| done | |
| # zlib | |
| gh api repos/madler/zlib/releases/latest --jq '.tag_name' |\ | |
| xargs -I{} wget -qO- https://github.com/madler/zlib/archive/refs/tags/{}.tar.gz | tar -xz | |
| ( | |
| cd zlib-* | |
| CFLAGS="$CPU $MINSIZE $CFLAGS" \ | |
| ./configure --prefix= --static | |
| make install -j$(nproc) DESTDIR=$DEPS_DIR | |
| ) | |
| # headers | |
| # wget https://git.alpinelinux.org/aports/plain/main/bsd-compat-headers/queue.h && \ | |
| # wget https://git.kernel.org/pub/scm/libs/libcap/libcap.git/plain/libcap/include/sys/capability.h && \ | |
| install -Dm644 -t $DEPS_DIR/include/sys /usr/include/x86_64-linux-gnu/sys/queue.h /usr/include/sys/capability.h | |
| # zapret2 | |
| OPTIMIZE=$OPTIMIZE \ | |
| CFLAGS="-DZAPRET_GH_VER=${{ github.ref_name }} -DZAPRET_GH_HASH=${{ github.sha }} -static-libgcc -I$DEPS_DIR/include $CPU $CFLAGS" \ | |
| LDFLAGS="-L$DEPS_DIR/lib $LDFLAGS" \ | |
| make -C zapret2 CFLAGS_PIC= LDFLAGS_PIE=-static LUA_JIT=$LJIT LUA_CFLAGS="$LCFLAGS" LUA_LIB="$LLIB" -j$(nproc) | |
| tar -C zapret2/binaries/my -cJf zapret2-linux-$ARCH.tar.xz . | |
| - name: Upload artifacts | |
| uses: actions/upload-artifact@v4 | |
| with: | |
| name: zapret2-linux-${{ matrix.arch }} | |
| path: zapret2-*.tar.xz | |
| if-no-files-found: error | |
| build-android: | |
| name: Android ${{ matrix.abi }} | |
| runs-on: ubuntu-latest | |
| strategy: | |
| matrix: | |
| include: | |
| - abi: armeabi-v7a | |
| target: armv7a-linux-androideabi | |
| - abi: arm64-v8a | |
| target: aarch64-linux-android | |
| - abi: x86 | |
| target: i686-linux-android | |
| - abi: x86_64 | |
| target: x86_64-linux-android | |
| steps: | |
| - name: Checkout | |
| uses: actions/checkout@v4 | |
| with: | |
| path: zapret2 | |
| - name: Set up build tools | |
| run: | | |
| sudo dpkg --add-architecture i386 | |
| sudo apt update -qq | |
| # luajit buildvm requires 32 bit executable on host platform for 32 bit cross targets | |
| sudo apt install -y gcc-multilib | |
| - name: Build | |
| env: | |
| ABI: ${{ matrix.abi }} | |
| API: 21 | |
| TARGET: ${{ matrix.target }} | |
| GH_TOKEN: ${{ github.token }} | |
| LUAJIT_VER: 2.1 | |
| LUAJIT_RELEASE: 2.1-20250826 | |
| LUAJIT_LUAVER: 5.1 | |
| MINSIZE: -Oz -flto=auto -ffunction-sections -fdata-sections | |
| LDMINSIZE: -Wl,--gc-sections -flto=auto | |
| run: | | |
| DEPS_DIR=$GITHUB_WORKSPACE/deps | |
| export TOOLCHAIN=$ANDROID_NDK_HOME/toolchains/llvm/prebuilt/linux-x86_64 | |
| export CC="$TOOLCHAIN/bin/clang --target=$TARGET$API" | |
| export AR=$TOOLCHAIN/bin/llvm-ar | |
| export AS=$CC | |
| export LD=$TOOLCHAIN/bin/ld | |
| export RANLIB=$TOOLCHAIN/bin/llvm-ranlib | |
| export STRIP=$TOOLCHAIN/bin/llvm-strip | |
| export PKG_CONFIG_PATH=$DEPS_DIR/lib/pkgconfig | |
| SYSMALLOC=-DLUAJIT_USE_SYSMALLOC | |
| case "$ABI" in | |
| armeabi-v7a) | |
| CPU="-mthumb" | |
| ;; | |
| arm64-v8a) | |
| # not safe without GC64 | |
| SYSMALLOC= | |
| PAGESIZE="-Wl,-z,max-page-size=16384" | |
| ;; | |
| esac | |
| # luajit | |
| wget -qO- https://github.com/openresty/luajit2/archive/refs/tags/v${LUAJIT_RELEASE}.tar.gz | tar -xz | |
| case "$ABI" in | |
| *64*) | |
| HOSTCC="cc" | |
| ;; | |
| *) | |
| HOSTCC="cc -m32" | |
| esac | |
| ( | |
| cd luajit2-* | |
| make BUILDMODE=static XCFLAGS="$SYSMALLOC -DLUAJIT_DISABLE_FFI" HOST_CC="$HOSTCC" CROSS= CC="$CC" TARGET_AR="$AR rcus" TARGET_STRIP=$STRIP TARGET_CFLAGS="$CPU $MINSIZE $CFLAGS" TARGET_LDFLAGS="$LDMINSIZE $LDFLAGS" -j$(nproc) | |
| make install PREFIX= DESTDIR=$DEPS_DIR | |
| ) | |
| LJIT=1 | |
| LCFLAGS="-I${DEPS_DIR}/include/luajit-${LUAJIT_VER}" | |
| LLIB="-L${DEPS_DIR}/lib -lluajit-${LUAJIT_LUAVER}" | |
| # netfilter libs | |
| wget -qO- https://www.netfilter.org/pub/libnfnetlink/libnfnetlink-1.0.2.tar.bz2 | tar -xj | |
| wget -qO- https://www.netfilter.org/pub/libmnl/libmnl-1.0.5.tar.bz2 | tar -xj | |
| wget -qO- https://www.netfilter.org/pub/libnetfilter_queue/libnetfilter_queue-1.0.5.tar.bz2 | tar -xj | |
| patch -p1 -d libnetfilter_queue-* -i ../zapret2/.github/workflows/libnetfilter_queue-android.patch | |
| for i in libmnl libnfnetlink libnetfilter_queue ; do | |
| ( | |
| cd $i-* | |
| CFLAGS="$CPU $MINSIZE -Wno-implicit-function-declaration $CFLAGS" \ | |
| LDFLAGS="$LDMINSIZE $LDFLAGS" \ | |
| ./configure --prefix= --host=$TARGET --enable-static --disable-shared --disable-dependency-tracking | |
| make install -j$(nproc) DESTDIR=$DEPS_DIR | |
| ) | |
| sed -i "s|^prefix=.*|prefix=$DEPS_DIR|g" $DEPS_DIR/lib/pkgconfig/$i.pc | |
| done | |
| # zapret2 | |
| CFLAGS="-DZAPRET_GH_VER=${{ github.ref_name }} -DZAPRET_GH_HASH=${{ github.sha }} -I$DEPS_DIR/include $CPU" \ | |
| LDFLAGS="-L$DEPS_DIR/lib $PAGESIZE" \ | |
| make -C zapret2 LUA_JIT=$LJIT LUA_CFLAGS="$LCFLAGS" LUA_LIB="$LLIB" -j$(nproc) android | |
| # strip unwanted ELF sections to prevent warnings on old Android versions | |
| gh api repos/termux/termux-elf-cleaner/releases/latest --jq '.tag_name' |\ | |
| xargs -I{} wget -O elf-cleaner https://github.com/termux/termux-elf-cleaner/releases/download/{}/termux-elf-cleaner | |
| chmod +x elf-cleaner | |
| ./elf-cleaner --api-level $API zapret2/binaries/my/* | |
| zip zapret2-android-$ABI.zip -j zapret2/binaries/my/* | |
| - name: Upload artifacts | |
| uses: actions/upload-artifact@v4 | |
| with: | |
| name: zapret2-android-${{ matrix.abi }} | |
| path: zapret2-*.zip | |
| if-no-files-found: error | |
| build-freebsd: | |
| name: FreeBSD ${{ matrix.arch }} | |
| runs-on: ubuntu-latest | |
| env: | |
| DEPS_DIR: /workdir/deps | |
| LUAJIT_VER: 2.1 | |
| LUAJIT_RELEASE: 2.1-20250826 | |
| LUAJIT_LUAVER: 5.1 | |
| strategy: | |
| matrix: | |
| include: | |
| - target: x86_64 | |
| arch: x86_64 | |
| # - target: i386 | |
| # arch: x86 | |
| container: | |
| image: empterdose/freebsd-cross-build:11.4 | |
| steps: | |
| - name: Checkout | |
| uses: actions/checkout@v4 | |
| - name: Install packages | |
| run: apk add xz tar build-base | |
| - name: Build luajit | |
| env: | |
| TARGET: ${{ matrix.target }} | |
| ARCH: ${{ matrix.arch }} | |
| PIC: -fpic | |
| CC: ${{ matrix.target }}-freebsd11-clang | |
| MINSIZE: -Os -flto=auto -ffunction-sections -fdata-sections | |
| LDMINSIZE: -Wl,--gc-sections -flto=auto | |
| run: | | |
| wget -qO- https://github.com/openresty/luajit2/archive/refs/tags/v${LUAJIT_RELEASE}.tar.gz | tar -xz | |
| ( | |
| cd luajit2-* | |
| make BUILDMODE=static XCFLAGS="$PIC -DLUAJIT_USE_SYSMALLOC -DLUAJIT_DISABLE_FFI" HOST_CC=gcc CC=$CC TARGET_CFLAGS="$MINSIZE $CFLAGS $PIC" TARGET_LDFLAGS="$LDMINSIZE $LDFLAGS" | |
| make install PREFIX= DESTDIR=$DEPS_DIR | |
| ) | |
| - name: Build zapret2 | |
| env: | |
| TARGET: ${{ matrix.target }} | |
| ARCH: ${{ matrix.arch }} | |
| CC: ${{ matrix.target }}-freebsd11-clang | |
| LJIT: 1 | |
| run: | | |
| export CFLAGS="-DZAPRET_GH_VER=${{ github.ref_name }} -DZAPRET_GH_HASH=${{ github.sha }}" | |
| LCFLAGS="-I${DEPS_DIR}/include/luajit-${LUAJIT_VER}" | |
| LLIB="-L${DEPS_DIR}/lib -lluajit-${LUAJIT_LUAVER}" | |
| settarget $TARGET-freebsd11 | |
| make CC=$CC LUA_JIT=$LJIT LUA_CFLAGS="$LCFLAGS" LUA_LIB="$LLIB" bsd -j$(nproc) | |
| tar -C binaries/my -cJf zapret2-freebsd-$ARCH.tar.xz . | |
| - name: Upload artifacts | |
| uses: actions/upload-artifact@v4 | |
| with: | |
| name: zapret2-freebsd-${{ matrix.arch }} | |
| path: zapret2-*.tar.xz | |
| if-no-files-found: error | |
| build-windows: | |
| name: Windows ${{ matrix.arch }} | |
| runs-on: windows-latest | |
| strategy: | |
| fail-fast: false | |
| matrix: | |
| arch: [ x86_64, x86 ] | |
| steps: | |
| - name: Checkout | |
| uses: actions/checkout@v4 | |
| with: | |
| path: zapret2 | |
| - name: Set up MinGW | |
| uses: msys2/setup-msys2@v2 | |
| with: | |
| msystem: ${{ matrix.arch == 'x86_64' && 'MINGW64' || 'MINGW32' }} | |
| install: >- | |
| ${{ matrix.arch == 'x86_64' && 'mingw-w64-x86_64-toolchain' || 'mingw-w64-i686-toolchain' }} | |
| - name: Build ip2net, mdig | |
| shell: msys2 {0} | |
| run: | | |
| export CFLAGS="-DZAPRET_GH_VER=${{ github.ref_name }} -DZAPRET_GH_HASH=${{ github.sha }}" | |
| mkdir -p output | |
| cd zapret2 | |
| mingw32-make -C ip2net win | |
| mingw32-make -C mdig win | |
| cp -a {ip2net/ip2net,mdig/mdig}.exe ../output | |
| - name: Restore psmisc from cache | |
| id: cache-restore-psmisc | |
| uses: actions/cache/restore@v4 | |
| with: | |
| path: ${{ github.workspace }}/psmisc | |
| key: psmisc-${{ matrix.arch }} | |
| - name: Set up Cygwin | |
| env: | |
| PACKAGES: ${{ steps.cache-restore-psmisc.outputs.cache-hit != 'true' && 'cygport gettext-devel libiconv-devel libncurses-devel' || null }} | |
| uses: cygwin/cygwin-install-action@v4 | |
| with: | |
| platform: ${{ matrix.arch }} | |
| site: ${{ matrix.arch == 'x86_64' && 'http://ctm.crouchingtigerhiddenfruitbat.org/pub/cygwin/circa/64bit/2024/01/30/231215' || 'http://ctm.crouchingtigerhiddenfruitbat.org/pub/cygwin/circa/2022/11/23/063457' }} | |
| check-sig: 'false' | |
| packages: >- | |
| gcc-core | |
| make | |
| zlib-devel | |
| zip | |
| unzip | |
| wget | |
| ${{ env.PACKAGES }} | |
| - name: Build psmisc | |
| if: steps.cache-restore-psmisc.outputs.cache-hit != 'true' | |
| env: | |
| URL: https://mirrors.kernel.org/sourceware/cygwin/x86_64/release/psmisc | |
| shell: C:\cygwin\bin\bash.exe -eo pipefail '{0}' | |
| run: >- | |
| export MAKEFLAGS=-j$(nproc) && | |
| mkdir -p psmisc && cd psmisc && | |
| wget -qO- ${URL} | grep -Po 'href=\"\Kpsmisc-(\d+\.)+\d+.+src\.tar\.xz(?=\")' | xargs -I{} wget -O- ${URL}/{} | tar -xJ && | |
| cd psmisc-*.src && | |
| echo CYGCONF_ARGS+=\" --disable-dependency-tracking --disable-nls\" >> psmisc.cygport && | |
| cygport psmisc.cygport prep compile install | |
| - name: Save psmisc to cache | |
| if: steps.cache-restore-psmisc.outputs.cache-hit != 'true' | |
| uses: actions/cache/save@v4 | |
| with: | |
| path: ${{ github.workspace }}/psmisc | |
| key: psmisc-${{ matrix.arch }} | |
| - name: Build luajit | |
| env: | |
| LUAJIT_RELEASE: 2.1-20250826 | |
| MINSIZE: -Os -flto=auto -ffunction-sections -fdata-sections | |
| LDMINSIZE: -Wl,--gc-sections -flto=auto | |
| shell: C:\cygwin\bin\bash.exe -eo pipefail '{0}' | |
| run: >- | |
| export MAKEFLAGS=-j$(nproc) && | |
| wget -q https://github.com/openresty/luajit2/archive/refs/tags/v${LUAJIT_RELEASE}.tar.gz && | |
| tar -xzf v${LUAJIT_RELEASE}.tar.gz && | |
| rm -f v${LUAJIT_RELEASE}.tar.gz && | |
| make -C luajit2-${LUAJIT_RELEASE} BUILDMODE=static XCFLAGS="-DLUAJIT_USE_SYSMALLOC -DLUAJIT_DISABLE_FFI -ffat-lto-objects" TARGET_CFLAGS="$MINSIZE $CFLAGS" TARGET_LDFLAGS="$LDMINSIZE $LDFLAGS" && | |
| make -C luajit2-${LUAJIT_RELEASE} install | |
| - name: Build winws | |
| env: | |
| TARGET: ${{ matrix.arch == 'x86_64' && 'cygwin' || 'cygwin32' }} | |
| shell: C:\cygwin\bin\bash.exe -eo pipefail '{0}' | |
| run: >- | |
| export MAKEFLAGS=-j$(nproc) && | |
| export CFLAGS="-DZAPRET_GH_VER=${{ github.ref_name }} -DZAPRET_GH_HASH=${{ github.sha }}" && | |
| cd zapret2 && | |
| make -C nfq2 ${TARGET} && | |
| cp -a nfq2/winws2.exe ../output | |
| - name: Create zip | |
| env: | |
| BITS: ${{ matrix.arch == 'x86_64' && '64' || '32' }} | |
| DIR: ${{ matrix.arch == 'x86_64' && 'x64' || 'x86' }} | |
| shell: C:\cygwin\bin\bash.exe -e '{0}' | |
| run: >- | |
| cp -a -t output psmisc/psmisc-*.src/psmisc-*/inst/usr/bin/killall.exe /usr/bin/cygwin1.dll && | |
| wget -O WinDivert.zip https://github.com/basil00/WinDivert/releases/download/v2.2.2/WinDivert-2.2.2-A.zip && | |
| unzip -j WinDivert.zip "*/${DIR}/WinDivert.dll" "*/${DIR}/WinDivert${BITS}.sys" -d output && | |
| ( [ "$BITS" = 64 ] && rebase -b 0x205c00000 output/WinDivert.dll || true ) && | |
| peflags --dynamicbase=true --high-entropy-va=true output/WinDivert.dll && | |
| zip zapret2-win-${{ matrix.arch }}.zip -j output/* | |
| - name: Upload artifacts | |
| uses: actions/upload-artifact@v4 | |
| with: | |
| name: zapret2-win-${{ matrix.arch }} | |
| path: zapret2-*.zip | |
| if-no-files-found: error | |
| release: | |
| if: github.event_name == 'push' && startsWith(github.ref, 'refs/tags/v') | |
| needs: [ build-linux, build-windows, build-freebsd, build-android ] | |
| permissions: | |
| contents: write | |
| runs-on: ubuntu-latest | |
| env: | |
| repo_dir: zapret2-${{ github.ref_name }} | |
| steps: | |
| - name: Checkout | |
| uses: actions/checkout@v4 | |
| with: | |
| path: ${{ env.repo_dir }} | |
| - name: Download artifacts | |
| uses: actions/download-artifact@v4 | |
| id: bins | |
| with: | |
| path: ${{ env.repo_dir }}/binaries | |
| pattern: zapret2-* | |
| - name: Install upx | |
| shell: bash | |
| env: | |
| VER_OLD: 4.2.4 | |
| VER_NEW: 5.1.0 | |
| run: | | |
| # old upx works for old kernels like 2.6.26 | |
| # new upx crashes on ~<3.10 but required for riscv64 | |
| curl -Lo - https://github.com/upx/upx/releases/download/v$VER_OLD/upx-$VER_OLD-amd64_linux.tar.xz | tar -Jx upx-$VER_OLD-amd64_linux/upx | |
| sudo cp upx-$VER_OLD-amd64_linux/upx /usr/local/bin/upx_old | |
| curl -Lo - https://github.com/upx/upx/releases/download/v$VER_NEW/upx-$VER_NEW-amd64_linux.tar.xz | tar -Jx upx-$VER_NEW-amd64_linux/upx | |
| sudo cp upx-$VER_NEW-amd64_linux/upx /usr/local/bin/upx_new | |
| rm -r upx-$VER_OLD-amd64_linux/upx upx-$VER_NEW-amd64_linux/upx | |
| - name: Prepare binaries | |
| shell: bash | |
| run: | | |
| cd ${{ steps.bins.outputs.download-path }} | |
| run_upx_old() { | |
| upx_old --best --lzma $@ || true | |
| } | |
| run_upx_new() { | |
| upx_new --best --lzma $@ || true | |
| } | |
| run_dir() { | |
| for f in $dir/* ; do | |
| # extract binaries | |
| case $f in | |
| *.tar.xz ) | |
| tar -C $dir -xvf $f && rm $f | |
| if [[ $dir = *-linux-riscv64 ]]; then | |
| run_upx_new $dir/* | |
| elif [[ $dir =~ linux ]] && [[ $dir != *-linux-mips64 ]] && [[ $dir != *-linux-lexra ]]; then | |
| run_upx_old $dir/* | |
| fi | |
| ;; | |
| *.zip ) | |
| unzip $f -d $dir && rm $f | |
| if [[ $dir =~ win ]]; then | |
| chmod -x $dir/* | |
| fi | |
| ;; | |
| esac | |
| done | |
| mv $dir $1 | |
| } | |
| for dir in * ; do | |
| if [ -d $dir ]; then | |
| echo "Processing $dir" | |
| case $dir in | |
| *-android-arm64-v8a ) run_dir android-arm64 ;; | |
| *-android-armeabi-v7a ) run_dir android-arm ;; | |
| *-android-x86 ) run_dir android-x86 ;; | |
| *-android-x86_64 ) run_dir android-x86_64 ;; | |
| *-freebsd-x86_64 ) run_dir freebsd-x86_64 ;; | |
| *-linux-arm ) run_dir linux-arm ;; | |
| *-linux-arm64 ) run_dir linux-arm64 ;; | |
| *-linux-mips64 ) run_dir linux-mips64 ;; | |
| *-linux-mipselsf ) run_dir linux-mipsel ;; | |
| *-linux-mipssf ) run_dir linux-mips ;; | |
| *-linux-ppc ) run_dir linux-ppc ;; | |
| *-linux-riscv64 ) run_dir linux-riscv64 ;; | |
| *-linux-x86 ) run_dir linux-x86 ;; | |
| *-linux-x86_64 ) run_dir linux-x86_64 ;; | |
| *-linux-lexra ) run_dir linux-lexra ;; | |
| *-win-x86 ) run_dir windows-x86 ;; | |
| *-win-x86_64 ) run_dir windows-x86_64 ;; | |
| esac | |
| fi | |
| done | |
| ls -lhR | |
| - name: Create release bundles | |
| run: | | |
| rm -rf ${{ env.repo_dir }}/.git* | |
| find ${{ env.repo_dir }}/binaries -type f -exec sha256sum {} \; >sha256sum.txt | |
| tar --owner=0 --group=0 -c ${{ env.repo_dir }} | pigz -11 >${{ env.repo_dir }}.tar.gz | |
| zip -9qr ${{ env.repo_dir }}.zip ${{ env.repo_dir }} | |
| ( | |
| cd ${{ env.repo_dir }} | |
| rm -rf binaries/{android*,freebsd*,win*} \ | |
| init.d/{openrc,pfsense,runit,s6,systemd,windivert.filter.examples} \ | |
| nfq2 ip2net mdig docs Makefile | |
| pigz -11 lua/*.lua | |
| ) | |
| tar --owner=0 --group=0 -c ${{ env.repo_dir }} | pigz -11 >${{ env.repo_dir }}-openwrt-embedded.tar.gz | |
| - name: Upload release assets | |
| uses: softprops/action-gh-release@v2 | |
| with: | |
| fail_on_unmatched_files: true | |
| prerelease: false | |
| draft: false | |
| body: | | |
| ### zapret2 ${{ github.ref_name }} | |
| files: | | |
| zapret2*.tar.gz | |
| zapret2*.zip | |
| sha256sum.txt |