Files
Bendik Aagaard LynghaugandClaude Opus 4.8 8e35af8c99
Test / test (push) Successful in 10s
ci: v4 builtin:checkout instead of hand-rolled git with token-in-URL
builtin:checkout is native Go (no Node — the aarch64 klokka leg has none) and
keeps the job token out of the fetch URL (it was visible in process args on the
host runner).

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
2026-09-28 13:35:48 +02:00

90 lines
3.7 KiB
YAML

name: Publish release
# A `v*` tag builds the package on each architecture's own runner
# (x86_64 on ergo's bare runner, aarch64 on klokka's) and uploads it
# to the [uhhm] Arch registry, like uhhm/corp and cnats. Hosts then
# `pacman -S gdo`. The tag has to agree with PKGBUILD's pkgver, and
# CHANGELOG.md has to have the section; a release with the tag's notes
# is created from the x86_64 job for the record, with no asset.
on:
push:
tags: ["v*"]
jobs:
package:
strategy:
matrix:
include:
- arch: x86_64
runs-on: bare
# The bare runner's shared toolchain and caches, with the
# writable cargo home uhhm/iris uses.
cargo_home: /var/local/cargo-target/iris-cargo-home
rustc_wrapper: /usr/bin/sccache
rustup_home: /var/local/rustup
target_dir: /var/local/cargo-target
- arch: aarch64
runs-on: aarch64
# klokka's host runner: the system cargo, defaults everywhere.
cargo_home: ""
rustc_wrapper: ""
rustup_home: ""
target_dir: ""
runs-on: ${{ matrix.runs-on }}
env:
CARGO_HOME: ${{ matrix.cargo_home }}
RUSTC_WRAPPER: ${{ matrix.rustc_wrapper }}
RUSTUP_HOME: ${{ matrix.rustup_home }}
CARGO_TARGET_DIR: ${{ matrix.target_dir }}
PATH: /var/local/cargo/bin:/usr/local/sbin:/usr/local/bin:/usr/bin
SCCACHE_DIR: /var/local/sccache
SCCACHE_SERVER_PORT: "4228"
steps:
# v4 built-in checkout: native Go, needs no Node (the aarch64 host runner
# has none) and keeps the token out of a fetch URL.
- name: Checkout
uses: builtin:checkout
- name: Check tag matches pkgver
run: |
want="${GITHUB_REF_NAME#v}"
have=$(sed -n 's/^pkgver=//p' PKGBUILD)
[ "$want" = "$have" ] || { echo "tag $GITHUB_REF_NAME != pkgver $have" >&2; exit 1; }
notes=$(awk -v v="$want" '/^## /{p = ($2 == v)} p' CHANGELOG.md | tail -n +2)
[ -n "$(printf "%s" "$notes" | tr -d "[:space:]")" ] || { echo "CHANGELOG.md has no section for $GITHUB_REF_NAME" >&2; exit 1; }
# -d: cargo is the shared toolchain, not a pacman package the
# runner could verify. Builds and tests from the checkout. Empty
# env values above are unset here so cargo's defaults apply.
- name: Build package
run: |
for v in CARGO_HOME RUSTC_WRAPPER RUSTUP_HOME CARGO_TARGET_DIR; do
eval "[ -n \"\$$v\" ]" || unset "$v"
done
makepkg -f -d --noconfirm
# REGISTRY_TOKEN is a write:package token for bl, a secret on this
# repo (org repos do not inherit bl's). The registry namespace is
# always bl: pacman.conf's [uhhm] points at /api/packages/bl/arch/uhhm.
- name: Publish to the Arch package registry
run: |
for pkg in $(makepkg --packagelist); do
echo "==> $pkg"
curl --fail-with-body --user "bl:${{ secrets.REGISTRY_TOKEN }}" \
--upload-file "$pkg" \
"${{ gitea.server_url }}/api/packages/bl/arch/uhhm"
done
- name: Release notes
if: matrix.arch == 'x86_64'
run: |
set -euo pipefail
tag="${{ github.ref_name }}"
api="${{ github.server_url }}/api/v1/repos/${{ github.repository }}"
auth="Authorization: token ${{ secrets.GITHUB_TOKEN }}"
notes=$(awk -v v="${tag#v}" '/^## /{p = ($2 == v)} p' CHANGELOG.md | tail -n +2)
body=$(jq -n --arg tag "$tag" --arg notes "$notes" '{tag_name: $tag, name: $tag, body: $notes}')
curl -sf -X POST -H "$auth" -H 'Content-Type: application/json' -d "$body" "$api/releases" > /dev/null \
|| echo "release $tag exists"