-
Notifications
You must be signed in to change notification settings - Fork 65
230 lines (206 loc) · 7.93 KB
/
Copy pathrelease.yml
File metadata and controls
230 lines (206 loc) · 7.93 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
130
131
132
133
134
135
136
137
138
139
140
141
142
143
144
145
146
147
148
149
150
151
152
153
154
155
156
157
158
159
160
161
162
163
164
165
166
167
168
169
170
171
172
173
174
175
176
177
178
179
180
181
182
183
184
185
186
187
188
189
190
191
192
193
194
195
196
197
198
199
200
201
202
203
204
205
206
207
208
209
210
211
212
213
214
215
216
217
218
219
220
221
222
223
224
225
226
227
228
229
230
name: Release
on:
push:
tags:
- 'v*'
workflow_dispatch:
inputs:
tag:
description: 'Existing tag to release (for example, v0.4.0-beta.9)'
required: true
type: string
permissions:
contents: read
# One release run per tag at a time. A second run for the same tag waits; a
# release that is packaging or uploading is never cancelled.
concurrency:
group: ${{ github.workflow }}-${{ github.event_name == 'workflow_dispatch' && inputs.tag || github.ref_name }}
cancel-in-progress: false
env:
CARGO_TERM_COLOR: always
jobs:
release-info:
name: Validate release tag
runs-on: ubuntu-latest
outputs:
tag: ${{ steps.release.outputs.tag }}
version: ${{ steps.release.outputs.version }}
steps:
- name: Checkout code
uses: actions/checkout@v7
with:
ref: ${{ github.event_name == 'workflow_dispatch' && inputs.tag || github.ref }}
- name: Validate release tag
id: release
shell: bash
run: |
TAG="${{ github.event_name == 'workflow_dispatch' && inputs.tag || github.ref_name }}"
VERSION=$(python3 -c 'import pathlib, tomllib; print(tomllib.loads(pathlib.Path("Cargo.toml").read_text())["workspace"]["package"]["version"])')
EXPECTED_TAG="v${VERSION}"
if [ "$TAG" != "$EXPECTED_TAG" ]; then
echo "Release tag $TAG does not match workspace version $VERSION."
exit 1
fi
echo "tag=${TAG}" >> "$GITHUB_OUTPUT"
echo "version=${VERSION}" >> "$GITHUB_OUTPUT"
package-cli:
name: Package Morphir CLI (${{ matrix.target }})
needs: release-info
strategy:
fail-fast: false
matrix:
include:
- os: ubuntu-24.04
target: x86_64-unknown-linux-gnu
archive: tgz
- os: ubuntu-24.04-arm
target: aarch64-unknown-linux-gnu
archive: tgz
- os: macos-15-intel
target: x86_64-apple-darwin
archive: tgz
- os: macos-15
target: aarch64-apple-darwin
archive: tgz
- os: windows-2025
target: x86_64-pc-windows-msvc
archive: zip
- os: windows-11-arm
target: aarch64-pc-windows-msvc
archive: zip
runs-on: ${{ matrix.os }}
steps:
# Git must accept long submodule fixture names during checkout itself.
- name: Configure Windows Git paths
if: runner.os == 'Windows'
shell: pwsh
run: |
git config --global core.longpaths true
"CARGO_NET_GIT_FETCH_WITH_CLI=true" | Out-File -FilePath $env:GITHUB_ENV -Encoding utf8 -Append
- name: Checkout code
uses: actions/checkout@v7
with:
ref: ${{ needs.release-info.outputs.tag }}
fetch-depth: 0
submodules: recursive
- name: Install Rust toolchain
uses: dtolnay/rust-toolchain@stable
with:
targets: ${{ matrix.target }}
- name: Set up Rust CI
uses: ./.github/actions/setup-rust-ci
with:
install-mold: ${{ runner.os == 'Linux' }}
enable-sccache: ${{ runner.arch != 'ARM64' }}
shared-key: morphir-release-${{ matrix.target }}
save-cache: "true"
- name: Build CLI
run: cargo build --locked --release --package morphir --target ${{ matrix.target }}
- name: Package CLI
if: runner.os != 'Windows'
shell: bash
run: |
ARCHIVE="morphir-${{ needs.release-info.outputs.version }}-${{ matrix.target }}.${{ matrix.archive }}"
mkdir release-assets
tar -C "target/${{ matrix.target }}/release" -czf "release-assets/${ARCHIVE}" morphir
(
cd release-assets
shasum -a 256 "$ARCHIVE" > "$ARCHIVE.sha256"
)
- name: Package CLI
if: runner.os == 'Windows'
shell: pwsh
run: |
$archive = "morphir-${{ needs.release-info.outputs.version }}-${{ matrix.target }}.${{ matrix.archive }}"
New-Item -ItemType Directory -Path release-assets
Compress-Archive `
-Path "target/${{ matrix.target }}/release/morphir.exe" `
-DestinationPath "release-assets/$archive"
$hash = (Get-FileHash "release-assets/$archive" -Algorithm SHA256).Hash.ToLower()
"$hash $archive" | Set-Content "release-assets/$archive.sha256"
- name: Extract packaged CLI
if: runner.os != 'Windows'
shell: bash
run: |
mkdir release-smoke
tar -xzf "release-assets/morphir-${{ needs.release-info.outputs.version }}-${{ matrix.target }}.${{ matrix.archive }}" -C release-smoke
echo "MORPHIR_MCK_INSTALLED_CLI=${GITHUB_WORKSPACE}/release-smoke/morphir" >> "$GITHUB_ENV"
- name: Extract packaged CLI
if: runner.os == 'Windows'
shell: pwsh
run: |
Expand-Archive -Path "release-assets/morphir-${{ needs.release-info.outputs.version }}-${{ matrix.target }}.${{ matrix.archive }}" -DestinationPath release-smoke
$cli = (Resolve-Path "release-smoke/morphir.exe").Path
"MORPHIR_MCK_INSTALLED_CLI=$cli" | Out-File -FilePath $env:GITHUB_ENV -Encoding utf8 -Append
# The native harness doubles as a transcript adapter for IR and package
# suites. The copied CLI runs with an empty tool path against a managed IR
# kit and explicit package snapshots, using fixed recorded answers.
- name: Verify packaged MCK CLI
run: cargo test --locked --release --package morphir --target ${{ matrix.target }} --test mck_run installed_cli_runs_vendored_kit_without_tool_runtimes
- name: Upload CLI artifact
uses: actions/upload-artifact@v7
with:
name: morphir-cli-${{ matrix.target }}
path: release-assets/*
if-no-files-found: error
overwrite: true
retention-days: 7
publish-release:
name: Publish GitHub release
runs-on: ubuntu-latest
needs: [release-info, package-cli]
permissions:
contents: write
env:
GH_TOKEN: ${{ github.token }}
TAG: ${{ needs.release-info.outputs.tag }}
steps:
- name: Checkout release tooling
uses: actions/checkout@v7
with:
ref: ${{ needs.release-info.outputs.tag }}
sparse-checkout: .github/scripts
- name: Download artifacts
uses: actions/download-artifact@v8
with:
path: release-assets
pattern: morphir-*
merge-multiple: true
- name: Read published checksums
shell: bash
run: |
mkdir -p published-checksums
if gh release view "$TAG" --json assets --jq '.assets[].name' > published-assets.txt 2>/dev/null; then
gh release download "$TAG" --pattern '*.sha256' --dir published-checksums || true
else
: > published-assets.txt
fi
- name: Select changed artifacts
run: |
python3 .github/scripts/select_release_assets.py \
--release-assets release-assets \
--published-checksums published-checksums \
--published-assets published-assets.txt \
--upload-dir upload-assets
- name: Create GitHub release if needed
shell: bash
run: |
if gh release view "$TAG" >/dev/null 2>&1; then
echo "Release $TAG already exists."
exit 0
fi
CREATE_ARGS=("$TAG" --title "Release $TAG" --generate-notes)
if [[ "$TAG" == *-* ]]; then
CREATE_ARGS+=(--prerelease)
fi
gh release create "${CREATE_ARGS[@]}"
- name: Upload changed artifacts
shell: bash
run: |
shopt -s nullglob
ASSETS=(upload-assets/*)
if (( ${#ASSETS[@]} == 0 )); then
echo "All release artifacts already match their published hashes."
exit 0
fi
gh release upload "$TAG" "${ASSETS[@]}" --clobber