Files
tailscale/.github/workflows/natlab-basic.yml
T
Brad Fitzpatrick 574ef3b2a8 gokrazy, .github/workflows: build the natlab image with tool/go
The natlab-basic workflow builds the gokrazy natlab image in its own
step so that the test's rebuild of it (vmtest always rebuilds, so the
baked-in binaries match the source under test) is a build cache hit
rather than a cold build inside go test's -timeout budget. That never
worked: the Makefile ran whatever "go" was on $PATH, the runner's stock
Go, while the go command puts its own $GOROOT/bin first on the test
binary's $PATH, so the rebuild from inside "go test" used tailscale/go.
GOCACHE entries embed the compiler's build ID, so the step warmed
nothing. In practice the in-test rebuild took about 2.5 minutes of the
3 minute -timeout, leaving TestEasyEasy about 20 seconds for booting
two VMs, logging in, and pinging. A passing run on main took 167s. Any
hiccup in the remaining budget, such as the "tailscale up" hang fixed
separately, ended in go test's timeout panic with no useful output.

Make the natlab targets in gokrazy/Makefile use ../tool/go so the step
and the test use the same toolchain and cache. Fix the same mistake in
natlab-test.yml's cache warming step, whose comment documented the
wrong belief about which toolchain the in-test builds use. Raise
natlab-basic's -timeout to match natlab-test.yml so that a hang fails
through vmtest's own bounded waits (which dump the node's logs) instead
of through go test's timeout panic (which dumps nothing about the VMs).

Updates #13038
Updates #deflake

Signed-off-by: Brad Fitzpatrick <bradfitz@tailscale.com>
Change-Id: Iaa6085ec5aa029373204baf75b169ff375c2b355
2026-09-19 10:45:55 -07:00

75 lines
3.3 KiB
YAML

# Run a single natlab smoke test on every PR. The full natlab suite
# is opt-in and lives in .github/workflows/natlab-test.yml.
# See https://github.com/tailscale/tailscale/issues/13038
name: "natlab-basic"
concurrency:
group: ${{ github.workflow }}-${{ github.head_ref || github.run_id }}
cancel-in-progress: true
on:
push:
branches:
- "main"
- "release-branch/*"
pull_request:
# all PRs on all branches
merge_group:
branches:
- "main"
jobs:
EasyEasy:
runs-on: ubuntu-latest
steps:
- name: Check out code
uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2
# Go caches, keyed the same as natlab-test.yml's. Only that workflow's
# prepare job writes the build cache. A miss here just means a cold build.
- name: Cache tsgo toolchain
uses: actions/cache@668228422ae6a00e4ad889ee87cd7109ec5666a7 # zizmor: ignore[cache-poisoning] v5.0.4
with:
path: ~/.cache/tsgo
key: natlab-tsgo-${{ runner.os }}-${{ hashFiles('go.toolchain.rev') }}
- name: Cache Go modules
uses: actions/cache@668228422ae6a00e4ad889ee87cd7109ec5666a7 # zizmor: ignore[cache-poisoning] v5.0.4
with:
path: ~/go/pkg/mod
key: natlab-gomod-${{ runner.os }}-${{ hashFiles('go.mod', 'go.sum') }}
- name: Restore Go build cache
uses: actions/cache/restore@668228422ae6a00e4ad889ee87cd7109ec5666a7 # v5.0.4
with:
path: ~/.cache/go-build
key: natlab-gobuild-${{ runner.os }}-${{ hashFiles('go.sum') }}-${{ github.run_id }}
restore-keys: |
natlab-gobuild-${{ runner.os }}-${{ hashFiles('go.sum') }}-
natlab-gobuild-${{ runner.os }}-
- name: Enable KVM
run: |
echo 'KERNEL=="kvm", GROUP="kvm", MODE="0666", OPTIONS+="static_node=kvm"' | sudo tee /etc/udev/rules.d/99-kvm4all.rules
sudo udevadm control --reload-rules
sudo udevadm trigger --name-match=kvm
- name: Install qemu
run: |
sudo rm -f /var/lib/man-db/auto-update
sudo apt-get -y update
sudo apt-get -y remove man-db
sudo apt-get install -y qemu-system-x86 qemu-utils
- name: Build VM image
# The test always rebuilds this image itself (so the baked-in
# binaries match the source under test), but we build it here
# first so that rebuild is a build cache hit instead of a cold
# build that eats the go test -timeout budget, and so a broken
# image build fails earlier with a clearer error. The Makefile
# uses ./tool/go, the same toolchain the test's rebuild uses;
# a build with a different toolchain here would warm nothing.
run: |
make -C gokrazy natlab
- name: Run natlab integration tests
# With a warm build cache the test takes well under a minute.
# The timeout matches natlab-test.yml and exceeds vmtest's own
# 10 minute test context, so that a hung node fails through the
# test's bounded waits, which dump the node's logs, rather than
# through go test's timeout panic, which dumps nothing useful.
run: |
./tool/go test -v -run=^TestEasyEasy$ -timeout=15m -count=1 ./tstest/natlab/vmtest --run-vm-tests