-
Notifications
You must be signed in to change notification settings - Fork 44
135 lines (135 loc) · 5.17 KB
/
Copy pathrelease.yml
File metadata and controls
135 lines (135 loc) · 5.17 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
130
131
132
133
134
135
name: Release
on:
push:
tags: ['v[0-9]*']
workflow_dispatch:
permissions:
contents: read
jobs:
hold:
# A release created before its binaries exist (`gh release create`) stays a
# draft until `publish` has uploaded them, so an updater never finds a
# latest release it cannot download, not even when a build fails.
if: startsWith(github.ref, 'refs/tags/v')
runs-on: ubuntu-22.04
permissions:
contents: write
steps:
- name: Hide a pre-created release until its assets exist
env:
GH_TOKEN: ${{ github.token }}
GH_REPO: ${{ github.repository }}
run: |
if [ "$(gh release view "$GITHUB_REF_NAME" --json isDraft --jq .isDraft 2>/dev/null)" = false ]; then
gh release edit "$GITHUB_REF_NAME" --draft=true
fi
build:
strategy:
fail-fast: false
matrix:
include:
- runner: macos-14
platform: macos-aarch64
binary: distill
asset_ext: ''
- runner: macos-15-intel
platform: macos-x86_64
binary: distill
asset_ext: ''
- runner: ubuntu-22.04
platform: linux-x86_64
binary: distill
asset_ext: ''
- runner: ubuntu-22.04-arm
platform: linux-aarch64
binary: distill
asset_ext: ''
- runner: windows-latest
platform: windows-x86_64
binary: distill.exe
asset_ext: '.exe'
runs-on: ${{ matrix.runner }}
env:
CARGO_PROFILE_RELEASE_DEBUG: 0
CARGO_TARGET_AARCH64_UNKNOWN_LINUX_GNU_RUSTFLAGS: '-C force-unwind-tables=yes'
steps:
- uses: actions/checkout@v4
- name: Install build dependencies (Linux)
if: runner.os == 'Linux'
run: sudo apt-get update && sudo apt-get install -y build-essential pkg-config cmake clang libssl-dev libasound2-dev libdbus-1-dev
- name: Install pinned Protocol Buffers compiler (Linux)
if: runner.os == 'Linux'
env:
DISTILL_PLATFORM: ${{ matrix.platform }}
run: |
python3 - <<'PYCODE'
import hashlib, io, json, os, pathlib, urllib.request, zipfile
spec = json.loads(pathlib.Path('bin/protoc').read_text().split('\n', 1)[1])['platforms'][os.environ['DISTILL_PLATFORM']]
data = urllib.request.urlopen(spec['providers'][0]['url']).read()
assert hashlib.sha256(data).hexdigest() == spec['digest'], 'protoc checksum mismatch'
root = pathlib.Path(os.environ['RUNNER_TEMP']) / 'protoc'
zipfile.ZipFile(io.BytesIO(data)).extractall(root)
protoc = root / 'bin/protoc'
protoc.chmod(0o755)
with open(os.environ['GITHUB_ENV'], 'a') as env:
env.write(f'PROTOC={protoc}\n')
PYCODE
- name: Install build dependencies (macOS)
if: runner.os == 'macOS'
run: brew install protobuf
- name: Install build dependencies (Windows)
if: runner.os == 'Windows'
run: choco install protoc -y --no-progress
- name: Validate install.ps1 syntax
if: runner.os == 'Windows'
shell: pwsh
run: |
$errors = $null
[void][System.Management.Automation.Language.Parser]::ParseFile('install.ps1', [ref]$null, [ref]$errors)
if ($errors.Count) { $errors; exit 1 }
- name: Test release installer
if: runner.os != 'Windows'
run: python3 tests/test_release_installer.py
- name: Install Rust
run: rustup show
- uses: Swatinem/rust-cache@v2
- name: Build and verify version
shell: bash
run: |
version=$(sed -n 's/^version = "\([^"]*\)"/\1/p' crates/codegen/distill-version/Cargo.toml)
if [[ "$GITHUB_REF_TYPE" == tag ]]; then
test "$GITHUB_REF_NAME" = "v$version"
fi
GROK_VERSION="$version" cargo build --locked --release -p distill-pager-bin --bin distill
"target/release/${{ matrix.binary }}" --version | grep -F "$version"
mkdir -p artifacts
cp "target/release/${{ matrix.binary }}" "artifacts/distill-${{ matrix.platform }}${{ matrix.asset_ext }}"
- uses: actions/upload-artifact@v4
with:
name: distill-${{ matrix.platform }}
path: artifacts/*
publish:
if: startsWith(github.ref, 'refs/tags/v')
needs: [hold, build]
runs-on: ubuntu-22.04
permissions:
contents: write
steps:
- uses: actions/checkout@v4
- uses: actions/download-artifact@v4
with:
path: artifacts
merge-multiple: true
- name: Publish verified release assets
env:
GH_TOKEN: ${{ github.token }}
run: |
cp install.sh install.ps1 LICENSE NOTICE THIRD-PARTY-NOTICES artifacts/
cd artifacts
sha256sum distill-* > SHA256SUMS
if gh release view "$GITHUB_REF_NAME" >/dev/null 2>&1; then
gh release upload "$GITHUB_REF_NAME" ./* --clobber
gh release edit "$GITHUB_REF_NAME" --draft=false --latest
else
gh release create "$GITHUB_REF_NAME" ./* --verify-tag --title "Distill $GITHUB_REF_NAME" --generate-notes
fi