Skip to content

Commit 759c11b

Browse files
authored
merge main to dev (#1005)
* check response status before version verification in config-sync (#989) * port updated CI workflows from main
1 parent a65908e commit 759c11b

2 files changed

Lines changed: 71 additions & 2 deletions

File tree

‎.github/workflows/release.yaml‎

Lines changed: 60 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -71,6 +71,7 @@ jobs:
7171
with:
7272
cache: true
7373
version: 11
74+
run_install: false
7475

7576
- name: Get pnpm store directory
7677
run: |
@@ -333,6 +334,65 @@ jobs:
333334
asset_path: dg-linux-${{ matrix.binary_arch }}-${{ github.ref_name }}.rpm
334335
asset_content_type: application/octet-stream
335336

337+
# Dedicated dg build for AlmaLinux 9 (and the RHEL 9 family: Rocky 9, RHEL 9).
338+
# The default dg RPM is built against a newer glibc/OpenSSL and fails to run on
339+
# Alma 9, so dg is compiled inside an almalinux:9 container to link Alma's
340+
# glibc 2.34 and OpenSSL 3, then packaged with fpm. x86_64 only.
341+
build-dg-alma9:
342+
needs:
343+
- create-release
344+
runs-on:
345+
- self-hosted
346+
- Linux
347+
- X64
348+
container:
349+
image: almalinux:9
350+
env:
351+
HOME: /root
352+
RUSTUP_HOME: /root/.rustup
353+
CARGO_HOME: /root/.cargo
354+
SQLX_OFFLINE: "true"
355+
steps:
356+
- name: Install build prerequisites
357+
run: |
358+
dnf -y install git gcc gcc-c++ make openssl-devel perl pkgconfig unzip
359+
git config --global --add safe.directory '*'
360+
- uses: actions/checkout@v6
361+
with:
362+
submodules: recursive
363+
- name: Write release version
364+
run: |
365+
VERSION=$(echo ${GITHUB_REF_NAME#v} | cut -d '-' -f1)
366+
echo Version: $VERSION
367+
echo "VERSION=$VERSION" >> ${GITHUB_ENV}
368+
- name: Install protoc
369+
run: |
370+
PB_REL='https://github.com/protocolbuffers/protobuf/releases'
371+
PB_VERSION='3.20.0'
372+
curl -LO $PB_REL/download/v$PB_VERSION/protoc-$PB_VERSION-linux-x86_64.zip
373+
unzip -o protoc-$PB_VERSION-linux-x86_64.zip bin/protoc 'include/google/*' -d /usr/local
374+
echo "PROTOC=/usr/local/bin/protoc" >> ${GITHUB_ENV}
375+
- name: Install Rust stable
376+
uses: dtolnay/rust-toolchain@stable
377+
- name: Build dg (AlmaLinux 9)
378+
run: cargo build --release --manifest-path src-tauri/Cargo.toml -p defguard-dg --bin dg
379+
- name: Rename dg binary
380+
run: mv src-tauri/target/release/dg dg-linux-x86_64-${{ github.ref_name }}
381+
- name: Build dg rpm
382+
uses: defGuard/fpm-action@main
383+
with:
384+
fpm_args: "dg-linux-x86_64-${{ github.ref_name }}=/usr/sbin/dg dg.service=/usr/lib/systemd/system/dg.service src-tauri/cli/.env=/etc/defguard/dg.conf"
385+
fpm_opts: "--architecture x86_64 --debug --output-type rpm --version ${{ env.VERSION }} --no-auto-depends --depends openssl-libs --depends wireguard-tools --package dg-linux-x86_64-${{ github.ref_name }}-el9.rpm"
386+
- name: Upload RPM
387+
uses: actions/upload-release-asset@v1.0.2
388+
env:
389+
GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }}
390+
with:
391+
upload_url: ${{ needs.create-release.outputs.upload_url }}
392+
asset_path: dg-linux-x86_64-${{ github.ref_name }}-el9.rpm
393+
asset_name: dg-linux-x86_64-${{ github.ref_name }}-el9.rpm
394+
asset_content_type: application/octet-stream
395+
336396
build-macos:
337397
needs:
338398
- create-release

‎src-tauri/enterprise/config-sync/src/lib.rs‎

Lines changed: 11 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -103,8 +103,6 @@ pub async fn fetch_instance_config(
103103
instance.name
104104
);
105105

106-
let version_mismatch = check_min_version(&response, instance);
107-
108106
// Return early if the enterprise features are disabled in the core
109107
if response.status() == StatusCode::PAYMENT_REQUIRED {
110108
debug!(
@@ -129,6 +127,17 @@ pub async fn fetch_instance_config(
129127
return Err(Error::CoreNotEnterprise);
130128
}
131129

130+
if !response.status().is_success() {
131+
return Err(Error::InternalError(format!(
132+
"Config polling failed for instance {}({}) with status {}",
133+
instance.name,
134+
instance.id,
135+
response.status(),
136+
)));
137+
}
138+
139+
let version_mismatch = check_min_version(&response, instance);
140+
132141
// Parse the response
133142
debug!(
134143
"Parsing the config response for instance {}.",

0 commit comments

Comments
 (0)