name: 'Tests: installation_iojs'

on: [push, pull_request]

permissions:
  contents: read

jobs:
  installation_iojs_without_curl:
    permissions:
      contents: read

    name: 'installation_iojs without curl (${{ matrix.shell }})'
    runs-on: ubuntu-latest
    defaults:
      run:
        shell: 'script -q -e -c "${{ matrix.shell }} {0}"'

    strategy:
      fail-fast: false
      matrix:
        shell:
          - sh
          - bash
          - dash
          - zsh
          # - ksh

    steps:
      - name: Harden Runner
        uses: step-security/harden-runner@v2
        with:
          allowed-endpoints:
            github.com:443
            registry.npmjs.org:443
            raw.githubusercontent.com:443
            nodejs.org:443
            iojs.org:443
            azure.archive.ubuntu.com:80
            packages.microsoft.com:443
      - uses: actions/checkout@v6
        id: checkout
        continue-on-error: true
        with:
          submodules: true
      - name: 'nvmrc submodule fallback (forks without their own nvmrc)'
        if: steps.checkout.outcome == 'failure'
        shell: bash
        run: |
          git submodule set-url test/fixtures/nvmrc https://github.com/nvm-sh/nvmrc.git
          git submodule sync --recursive
          git submodule update --init --recursive
      - name: Install zsh and additional shells
        run: |
          sudo apt-get update
          sudo apt-get install -y zsh
          if [ "${{ matrix.shell }}" != "sh" ] && [ "${{ matrix.shell }}" != "bash" ] && [ "${{ matrix.shell }}" != "zsh" ]; then
            sudo apt-get install -y ${{ matrix.shell }}
          fi
        shell: bash
      - run: sudo ${{ matrix.shell }} --version 2> /dev/null || dpkg -s ${{ matrix.shell }} 2> /dev/null || which ${{ matrix.shell }}
      - run: wget --version
      - uses: ljharb/actions/node/install@main
        name: 'npm install && version checks'
        with:
          node-version: 'lts/*'
          skip-ls-check: true
      - run: npm ls urchin
      - run: npx which urchin
      - name: Remove curl
        run: sudo apt-get remove curl -y
        shell: bash
      - run: '! command -v curl'
        shell: bash
      - run: env
      - name: Hide system node
        run: |
          if [ -f /usr/local/bin/node ]; then sudo mv /usr/local/bin/node /usr/local/bin/node.bak; fi
          if [ -f /usr/local/bin/npm ]; then sudo mv /usr/local/bin/npm /usr/local/bin/npm.bak; fi
          if [ -f /usr/local/bin/npx ]; then sudo mv /usr/local/bin/npx /usr/local/bin/npx.bak; fi
        shell: bash
      - name: Run installation_iojs tests
        run: |
          URCHIN_PATH="$(npx which urchin)"
          unset NVM_CD_FLAGS NVM_BIN NVM_INC
          export NVM_DIR="${{ github.workspace }}"
          export PATH="$(echo "$PATH" | tr ':' '\n' | grep -v '\.nvm' | grep -v 'toolcache' | tr '\n' ':')"
          make TERM=xterm-256color TEST_SUITE="installation_iojs" SHELL="${{ matrix.shell }}" URCHIN="$URCHIN_PATH" test-${{ matrix.shell }}
      - name: Restore system node
        if: always()
        run: |
          if [ -f /usr/local/bin/node.bak ]; then sudo mv /usr/local/bin/node.bak /usr/local/bin/node; fi
          if [ -f /usr/local/bin/npm.bak ]; then sudo mv /usr/local/bin/npm.bak /usr/local/bin/npm; fi
          if [ -f /usr/local/bin/npx.bak ]; then sudo mv /usr/local/bin/npx.bak /usr/local/bin/npx; fi
        shell: bash
      - name: Restore curl
        if: always()
        run: sudo apt-get install curl -y
        shell: bash

  installation_iojs_source_compile:
    permissions:
      contents: read

    name: 'actually compile io.js from source (gcc 4.9 container)'
    runs-on: ubuntu-latest
    timeout-minutes: 60

    steps:
      - name: Harden Runner
        uses: step-security/harden-runner@v2
        with:
          allowed-endpoints:
            github.com:443
            mirror.gcr.io:443
            storage.googleapis.com:443
            iojs.org:443
      - uses: actions/checkout@v6
      # io.js requires python 2 and gcc <= 5 to compile; the gcc:4.9 image
      # (debian jessie) has both, plus curl/wget/xz and CA certificates that
      # still validate iojs.org - so the source-install tests run unmodified,
      # resolving, downloading, checksumming, and compiling for real.
      # The image is pulled through Google's Docker Hub mirror: it serves
      # manifests and blobs from a single stable hostname (Docker Hub's blob
      # CDN hostnames rotate, which the blocked-egress policy can not allow),
      # and it is not subject to Docker Hub's anonymous pull rate limits.
      - name: compile io.js from source, for real
        run: |
          docker run --rm -v "${PWD}:/nvm-under-test" -e NVM_DIR=/nvm-under-test mirror.gcr.io/library/gcc:4.9 bash -ec '
            cd "${NVM_DIR}/test/installation_iojs"
            sh "./install from source"
            sh "./install version specified in .nvmrc from source"
          '

  all:
    permissions:
      contents: none
    name: 'all installation_iojs tests'
    needs: [installation_iojs_without_curl, installation_iojs_source_compile]
    runs-on: ubuntu-latest
    steps:
      - run: true
