@@ -183,6 +183,12 @@ jobs:
183183 env :
184184 CC : " clang"
185185 CFLAGS : " -D__BLST_PORTABLE__"
186+ # On releases, emit line-table debug info so the MSVC linker produces a
187+ # separate .pdb (doesn't bloat the .pyd) for crash-stack symbolication.
188+ # line-tables-only maps addresses to function/file/line for post-mortem
189+ # triage while keeping link cost and PDB size down. Off otherwise, since
190+ # the extra link time isn't worth paying on every PR/push.
191+ CARGO_PROFILE_RELEASE_DEBUG : ${{ github.event_name == 'release' && 'line-tables-only' || '0' }}
186192 run : |
187193 maturin build -i python --release -m wheel/Cargo.toml
188194
@@ -210,6 +216,76 @@ jobs:
210216 name : packages-${{ matrix.os.name }}-${{ matrix.python.major-dot-minor }}-${{ matrix.arch.name }}
211217 path : ./target/wheels/
212218
219+ # Archive the .pdb under a per-matrix zip name (releases only, matching the
220+ # debug-info build above). Compress-Archive stores the entry by its leaf
221+ # name, chia_rs.pdb, which must be preserved: the .pyd embeds that name + a
222+ # GUID/age signature that debuggers use to locate symbols. Only the zip name
223+ # carries the matrix identity, keeping release-asset names unique.
224+ - name : Archive debug symbols (Windows)
225+ if : matrix.os.matrix == 'windows' && github.event_name == 'release'
226+ shell : pwsh
227+ run : |
228+ New-Item -ItemType Directory -Force -Path debug-symbols | Out-Null
229+ $name = "chia_rs-${{ matrix.os.name }}-${{ matrix.python.major-dot-minor }}-${{ matrix.arch.name }}.pdb.zip"
230+ Compress-Archive -Path target/release/chia_rs.pdb -DestinationPath "debug-symbols/$name"
231+
232+ # Artifact name must not start with "packages-", or the PyPI upload job
233+ # (pattern: packages-*) would ingest it.
234+ - name : Upload debug symbols artifact (Windows)
235+ if : matrix.os.matrix == 'windows' && github.event_name == 'release'
236+ uses : actions/upload-artifact@v4
237+ with :
238+ name : debug-symbols-${{ matrix.os.name }}-${{ matrix.python.major-dot-minor }}-${{ matrix.arch.name }}
239+ path : ./debug-symbols/
240+ if-no-files-found : error
241+ retention-days : 7
242+
243+ # Attach the .pdb archives to the release (release assets persist as long as the
244+ # release, unlike the retention-bounded build artifacts). This is the only job
245+ # with contents: write; it runs only on releases and compiles nothing, keeping
246+ # the write token's blast radius minimal.
247+ upload-debug-symbols :
248+ name : Attach debug symbols to release
249+ if : github.event_name == 'release'
250+ needs :
251+ - build-wheels
252+ runs-on : ubuntu-latest
253+ permissions :
254+ contents : write
255+ steps :
256+ # Set RELEASE / RELEASE_TAG env from the event payload, matching how the
257+ # PyPI upload job gates its publish steps.
258+ - name : Set Env
259+ uses : Chia-Network/actions/setjobenv@main
260+ env :
261+ GH_TOKEN : ${{ secrets.GITHUB_TOKEN }}
262+
263+ # The per-matrix .zip archives already have unique names, so flatten them
264+ # all into one directory with merge-multiple.
265+ - name : Download debug symbols
266+ uses : actions/download-artifact@v4
267+ with :
268+ merge-multiple : true
269+ pattern : debug-symbols-*
270+ path : ./debug-symbols
271+
272+ - name : Upload to release
273+ if : env.RELEASE == 'true'
274+ shell : bash
275+ env :
276+ GH_TOKEN : ${{ secrets.GITHUB_TOKEN }}
277+ run : |
278+ shopt -s nullglob
279+ zips=(debug-symbols/*.pdb.zip)
280+ if [ ${#zips[@]} -eq 0 ]; then
281+ echo "no debug-symbol archives found" >&2
282+ exit 1
283+ fi
284+ for zip_file in "${zips[@]}"; do
285+ gh release upload "${{ env.RELEASE_TAG }}" "${zip_file}" \
286+ --clobber --repo "${{ github.repository }}"
287+ done
288+
213289 check-typestubs :
214290 name : Check chia_rs.pyi
215291 runs-on : ubuntu-latest
0 commit comments