-
Notifications
You must be signed in to change notification settings - Fork 0
157 lines (152 loc) · 6.13 KB
/
Copy pathpreview.yml
File metadata and controls
157 lines (152 loc) · 6.13 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
130
131
132
133
134
135
136
137
138
139
140
141
142
143
144
145
146
147
148
149
150
151
152
153
154
155
156
157
name: preview
on:
push:
branches: [main]
permissions:
contents: read
jobs:
check:
runs-on: ubuntu-22.04
outputs:
version: ${{ steps.version.outputs.version }}
steps:
- uses: actions/checkout@v7
with:
fetch-depth: 0
- uses: astral-sh/setup-uv@v9.0.0
with:
python-version: "3.14"
enable-cache: true
- run: uv sync --locked
- name: Record source version
id: version
run: |
VERSION="$(uv run evdb --version)"
echo "version=${VERSION#evdb }" >> "${GITHUB_OUTPUT}"
- run: make check
build:
needs: check
strategy:
fail-fast: true
matrix:
include:
- runner: ubuntu-22.04
arch: amd64
- runner: ubuntu-22.04-arm
arch: arm64
runs-on: ${{ matrix.runner }}
steps:
- uses: actions/checkout@v7
with:
fetch-depth: 0
- uses: astral-sh/setup-uv@v9.0.0
with:
python-version: "3.14"
enable-cache: true
- run: uv sync --locked
- run: make binary
- name: Smoke test standalone executable
run: |
uv run pyi-archive_viewer -r -b dist/evdb > binary-members.txt
grep -F "evdb/units/evdb-backup.service" binary-members.txt
grep -F "evdb/units/evdb-backup.timer" binary-members.txt
grep -Fx " rich.console" binary-members.txt
grep -Fx " prompt_toolkit.shortcuts.prompt" binary-members.txt
- name: Assemble preview executable
env:
VERSION: ${{ needs.check.outputs.version }}
ARCH: ${{ matrix.arch }}
run: |
ASSET="evdb_linux_${ARCH}_${GITHUB_SHA}_${GITHUB_RUN_NUMBER}_${GITHUB_RUN_ATTEMPT}"
install -d -m 0755 artifacts
install -m 0755 dist/evdb "artifacts/${ASSET}"
(cd artifacts && sha256sum "${ASSET}" > "${ASSET}.sha256")
uv run python tools/check_release.py "artifacts/${ASSET}" "${VERSION}" --preview
- uses: actions/upload-artifact@v7
with:
name: preview-${{ matrix.arch }}
path: artifacts/*
if-no-files-found: error
retention-days: 1
publish:
needs: [check, build]
runs-on: ubuntu-22.04
concurrency:
group: preview-publication
cancel-in-progress: false
queue: max
permissions:
contents: write
id-token: write
attestations: write
steps:
- uses: actions/checkout@v7
with:
persist-credentials: false
- uses: actions/download-artifact@v8
with:
pattern: preview-*
path: release
merge-multiple: true
- name: Attest preview executables
uses: actions/attest@v4
with:
subject-path: release/evdb_linux_*
- name: Publish rolling preview
env:
GH_TOKEN: ${{ github.token }}
VERSION: ${{ needs.check.outputs.version }}
run: |
TITLE="v${VERSION%%+*}"
# Track publication in a hidden note, independently of the display title.
if PREVIOUS_RUN="$(gh release view preview --json name,body --jq \
'(.body | capture("<!-- preview-run: (?<run>[0-9]+) -->").run) // (.name | ltrimstr("Preview run "))')"; then
[[ "${PREVIOUS_RUN}" =~ ^[0-9]+$ ]]
if (( PREVIOUS_RUN > GITHUB_RUN_NUMBER )); then
echo "A newer run already owns preview; skipping."
exit 0
fi
else
gh release create preview --draft --prerelease --latest=false \
--target "${GITHUB_SHA}" --title "${TITLE}" --notes "<!-- preview-run: 0 -->"
fi
gh release view preview --json assets --jq '.assets[].name' > previous-assets.txt
BUILD="${GITHUB_SHA}_${GITHUB_RUN_NUMBER}_${GITHUB_RUN_ATTEMPT}"
PREVIOUS_BUILD=
if grep -Fxq preview.txt previous-assets.txt; then
gh release download preview --pattern preview.txt --dir previous
read -r PREVIOUS_COMMIT PREVIOUS_VERSION PUBLISHED_RUN PUBLISHED_ATTEMPT < previous/preview.txt
[[ "${PREVIOUS_COMMIT}" =~ ^[0-9a-f]{40}$ ]]
[[ "${PUBLISHED_RUN}" =~ ^[1-9][0-9]*$ ]]
[[ "${PUBLISHED_ATTEMPT}" =~ ^[1-9][0-9]*$ ]]
PREVIOUS_BUILD="${PREVIOUS_COMMIT}_${PUBLISHED_RUN}_${PUBLISHED_ATTEMPT}"
fi
printf '%s\n\n%s\n' 'Preparing preview.' \
"<!-- preview-run: ${GITHUB_RUN_NUMBER} -->" > release/notes.md
gh release edit preview --title "${TITLE}" --notes-file release/notes.md --prerelease --latest=false
if test "${PREVIOUS_BUILD}" != "${BUILD}"; then
# Run/attempt suffixes also keep rebuilds of the same commit immutable.
gh release upload preview release/evdb_linux_*
install -m 0755 install.sh release/install.sh
gh release upload preview release/install.sh --clobber
printf '%s %s %s %s\n' "${GITHUB_SHA}" "${VERSION}" \
"${GITHUB_RUN_NUMBER}" "${GITHUB_RUN_ATTEMPT}" > release/preview.txt
gh release upload preview release/preview.txt --clobber
fi
printf '%s\n\n%s\n' \
"Latest successful main build: ${VERSION} (${GITHUB_SHA}). Install with --preview." \
"<!-- preview-run: ${GITHUB_RUN_NUMBER} -->" > release/notes.md
gh release edit preview --draft=false --prerelease --latest=false --target "${GITHUB_SHA}" \
--notes-file release/notes.md
gh api --method PATCH "repos/${GITHUB_REPOSITORY}/git/refs/tags/preview" \
-f sha="${GITHUB_SHA}" -F force=true
# Keep the previous generation for installers that already fetched its manifest.
if test -n "${PREVIOUS_BUILD}" && test "${PREVIOUS_BUILD}" != "${BUILD}"; then
while read -r ASSET; do
case "${ASSET}" in
evdb_linux_*_"${BUILD}"|evdb_linux_*_"${BUILD}".sha256) ;;
evdb_linux_*_"${PREVIOUS_BUILD}"|evdb_linux_*_"${PREVIOUS_BUILD}".sha256) ;;
evdb_linux_*) gh release delete-asset preview "${ASSET}" --yes ;;
esac
done < previous-assets.txt
fi