forked from jackpoison-prog/RingOut
-
Notifications
You must be signed in to change notification settings - Fork 1
198 lines (181 loc) · 8.97 KB
/
Copy pathdeck.yml
File metadata and controls
198 lines (181 loc) · 8.97 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
130
131
132
133
134
135
136
137
138
139
140
141
142
143
144
145
146
147
148
149
150
151
152
153
154
155
156
157
158
159
160
161
162
163
164
165
166
167
168
169
170
171
172
173
174
175
176
177
178
179
180
181
182
183
184
185
186
187
188
189
190
191
192
193
194
195
196
197
198
name: Steam Deck build
# The Deck package is the one release that ships PREBUILT binaries: SteamOS
# mounts /usr read-only and its compilers have no C library headers, so nothing
# can be built on the device. That makes the build environment part of the
# product -- the runtime has to be linked against a glibc older than SteamOS's
# ~2.37, because binaries run forward across glibc versions but never backward.
#
# So this job runs inside debian:12 (glibc 2.36) rather than on the ubuntu
# runner's own image, which is far too new. It is the same base build-deck.sh
# uses locally via podman, and package-deck.sh checks the resulting floor rather
# than trusting it.
on:
workflow_dispatch:
inputs:
publish:
description: 'Upload the release asset (default: build only)'
type: boolean
default: false
# DISPATCH ONLY, since 2026-08-17. There is no `push:` trigger any more.
#
# This job is ~25 minutes of recompiling vendored Dolphin, billed against 2,000
# included Actions minutes a month on a private repo -- and it was firing on
# essentially every commit, because `ModernGekko/**` matches nearly all of them.
# August spent ~2,312 minutes and ran out; the allowance was exhausted for days
# with every run failing in three seconds and no runner assigned.
#
# The checks it performed now run BEFORE the push instead, in .githooks/pre-push,
# on the same debian:12 container (same base image, same deck-deps.txt) in ~13
# seconds with a warm ccache. Paying a runner 25 minutes to repeat what already
# passed locally is the duplication this removes.
#
# What is left here is the part a local machine genuinely cannot do: build the
# release from a clean checkout and upload it with provenance. Run it by hand
# when you want a release; tick `publish` to actually upload one.
#
# TO RESTORE per-push builds, put back:
#
# push:
# branches: [main]
# paths: [ 'ModernGekko/**', 'DolRecomp/**', '.github/workflows/deck.yml',
# '.github/scripts/build-deck.sh', '.github/scripts/package-deck.sh',
# '.github/scripts/privacy-scan.sh',
# '.github/scripts/publish-release-asset.sh',
# '.github/scripts/deck-deps.txt', 'dist/RingOut-1.0-deck/**' ]
#
# Those paths were not arbitrary: the packaging scripts are part of what this
# workflow PRODUCES, so leaving them out once meant a packaging fix pushed
# cleanly, triggered nothing, and looked green against the previous run.
permissions:
contents: write
jobs:
build:
runs-on: ubuntu-latest
container: debian:12
timeout-minutes: 120
env:
# Inside the workspace on purpose: this is a CONTAINER job, and the
# workspace is the one path the cache action and the compiler both see.
CCACHE_DIR: ${{ github.workspace }}/.ccache
CCACHE_MAXSIZE: 1G
steps:
# actions/checkout needs git present, or it silently falls back to a
# tarball download and the working tree is not a repository. debian:12 is
# a bare base image, so this has to come first -- before the dependency
# list itself is available to read.
- name: Bootstrap checkout dependencies
run: |
apt-get update
apt-get install -y --no-install-recommends git ca-certificates
- name: Check out
uses: actions/checkout@v5
- name: Install build dependencies
# Read from the shared list so this cannot drift from the local podman
# image that build-deck.sh builds.
run: |
deps=$(grep -v '^#' .github/scripts/deck-deps.txt | grep -v '^[[:space:]]*$')
echo "$deps"
apt-get install -y --no-install-recommends $deps
# ~1,400 translation units of vendored Dolphin, recompiled from scratch
# every run -- 23.5 of the job's 25 minutes, against a finite monthly
# allowance. Measured locally (12 cores, same tree twice, build dir wiped
# between): 4m07s cold -> 0m08s warm, 1120/1120 cacheable compiles hit.
# The runner has far fewer cores so the wall times differ; the hit rate is
# what carries over.
#
# Actions CACHE is a separate allowance from the artifact/package storage
# that this repo has filled before -- different endpoint, not billed the
# same way -- so this cannot repeat the quota failure that broke unrelated
# workflows' uploads.
#
# Keyed by SHA with a prefix fallback, so every run restores the newest
# cache and saves its own; eviction is GitHub's problem.
- name: Restore compiler cache
uses: actions/cache@v4
with:
path: ${{ github.workspace }}/.ccache
key: ccache-deck-${{ github.sha }}
restore-keys: ccache-deck-
- name: Configure
# Qt and the tests pull in toolchain the container does not have, and the
# runtime is headless-capable, so both are off -- same set as build-deck.sh.
run: >
cmake -S ModernGekko -B build-deck -GNinja
-DCMAKE_BUILD_TYPE=Release
-DENABLE_QT=OFF
-DENABLE_TESTS=OFF
-DENABLE_ANALYTICS=OFF
-DENABLE_AUTOUPDATE=OFF
-DCMAKE_C_COMPILER_LAUNCHER=ccache
-DCMAKE_CXX_COMPILER_LAUNCHER=ccache
- name: Build runtime
run: cmake --build build-deck --target moderngekko-run
# Prints the hit rate, so a cache that silently stops working shows up as
# a number rather than as a slow job nobody looks at.
- name: Compiler cache stats
run: ccache -s
# ENABLE_TESTS above is DOLPHIN's suite, which needs toolchain this
# container does not have. These are ModernGekko's and DolRecomp's own,
# gated by BUILD_TESTING, which defaults on -- they were already being
# configured by every run here and simply never built or executed.
#
# That is not hypothetical: five of them had rotted out of compiling
# entirely (a stale sizeof(CPUState), a renamed field, a module ABI
# pinned two versions back, and one written against an unpushed
# RecompCore fork), and nothing reported it because nothing ran them.
- name: Build tests
run: cmake --build build-deck --target moderngekko-tests
# Before Package on purpose: a red suite must not be able to produce a
# publishable zip.
- name: Test
run: ctest --test-dir build-deck --output-on-failure -j"$(nproc)"
- name: Package
# NATIVE=1 because this job IS the Debian 12 environment; there is no
# podman on the runner and none is needed. The script resolves the
# runtime's library closure with this container's ldd, which is the
# whole point of running the job in here.
run: NATIVE=1 .github/scripts/package-deck.sh
- name: Publish release asset
# OPT-IN ONLY: a dispatch with publish=true. Merging to main used to
# publish this automatically, so "land the change" and "ship it to
# everyone" were one action -- and the packaging scripts are on the
# trigger paths, meaning a packaging fix alone would publish a build.
if: github.event_name == 'workflow_dispatch' && inputs.publish
# A GitHub RELEASE asset, not an Actions artifact. Actions artifact
# storage is one quota'd pool shared by every workflow, and exceeding it
# fails EVERY upload rather than the offending one -- a ~294 MB Windows
# bundle filled it and this 22 MB package was the collateral, failing for
# weeks with "Artifact storage quota has been hit". Release assets do not
# count against that pool and carry a stable download URL.
env:
GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }}
run: |
apt-get install -y --no-install-recommends curl
# Resolve the package the build step actually produced rather than
# naming a version here. This path was pinned to 1.1 and went stale
# the moment package-deck.sh's VERSION moved, which would have
# published nothing (or the wrong build) on the next dispatch.
shopt -s nullglob
zips=(dist/RingOut-*-steamdeck-x86_64.zip)
[ ${#zips[@]} -eq 1 ] || {
echo "expected exactly one Deck package, found ${#zips[@]}: ${zips[*]}" >&2
exit 1
}
.github/scripts/publish-release-asset.sh deck-latest \
"Steam Deck build (rolling)" "${zips[0]}"
# A failed configure/build leaves the useful detail in these logs rather
# than in the step output.
- name: Upload CMake logs on failure
if: failure()
# continue-on-error: this is diagnostics. When the artifact quota is full
# this upload fails too, and a FAILED upload of failure logs was itself
# being reported as the job's failure -- hiding the real one underneath.
continue-on-error: true
uses: actions/upload-artifact@v7
with:
name: deck-cmake-logs
retention-days: 7
path: |
build-deck/CMakeFiles/CMakeConfigureLog.yaml
build-deck/CMakeCache.txt
if-no-files-found: ignore