-
Notifications
You must be signed in to change notification settings - Fork 3
346 lines (314 loc) · 14.9 KB
/
Copy pathrelease.yml
File metadata and controls
346 lines (314 loc) · 14.9 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
130
131
132
133
134
135
136
137
138
139
140
141
142
143
144
145
146
147
148
149
150
151
152
153
154
155
156
157
158
159
160
161
162
163
164
165
166
167
168
169
170
171
172
173
174
175
176
177
178
179
180
181
182
183
184
185
186
187
188
189
190
191
192
193
194
195
196
197
198
199
200
201
202
203
204
205
206
207
208
209
210
211
212
213
214
215
216
217
218
219
220
221
222
223
224
225
226
227
228
229
230
231
232
233
234
235
236
237
238
239
240
241
242
243
244
245
246
247
248
249
250
251
252
253
254
255
256
257
258
259
260
261
262
263
264
265
266
267
268
269
270
271
272
273
274
275
276
277
278
279
280
281
282
283
284
285
286
287
288
289
290
291
292
293
294
295
296
297
298
299
300
301
302
303
304
305
306
307
308
309
310
311
312
313
314
315
316
317
318
319
320
321
322
323
324
325
326
327
328
329
330
331
332
333
334
335
336
337
338
339
340
341
342
343
344
345
346
name: Release
# Per-crate release. Tag format: `<crate>-v<version>` (for example,
# `subc-transport-v0.1.0`). `subc-core` is publish=false: its tags publish the
# installable subconscious archives below rather than a crates.io package.
on:
push:
tags:
- "*-v*"
concurrency:
# A retag at a different commit must not wait behind a stale release run.
group: release-${{ github.ref }}-${{ github.sha }}
cancel-in-progress: false
permissions:
contents: read
env:
CARGO_TERM_COLOR: always
jobs:
# Use the same verification matrix as pull requests before publishing any
# release asset.
verify:
uses: ./.github/workflows/ci.yml
create-subconscious-release:
name: Create subconscious release
if: startsWith(github.ref_name, 'subc-core-v')
needs: verify
runs-on: ubuntu-latest
permissions:
contents: write
steps:
- uses: actions/checkout@v5
- name: Verify tag version and create release
env:
GH_TOKEN: ${{ github.token }}
run: |
TAG="${GITHUB_REF_NAME}"
VERSION="${TAG#subc-core-v}"
CARGO_VERSION=$(grep '^version' crates/subc-core/Cargo.toml | head -1 | sed -E 's/version *= *"([^"]+)"/\1/')
if [ "$VERSION" != "$CARGO_VERSION" ]; then
echo "::error::Tag wants ${VERSION} but crates/subc-core/Cargo.toml has ${CARGO_VERSION}"
exit 1
fi
# Created as a DRAFT and published only after every platform leg has
# uploaded. A release that is public while legs are still running is
# ingested by the release index the moment the first asset lands,
# and a leg that fails leaves a public release missing a platform —
# which the index then serves as "not yet published" for that
# platform, honestly and wrongly. Draft until complete means a failed
# leg leaves nothing an installer can see.
if gh release view "$TAG" --repo "$GITHUB_REPOSITORY" >/dev/null 2>&1; then
echo "release ${TAG} already exists"
else
gh release create "$TAG" --repo "$GITHUB_REPOSITORY" \
--draft \
--title "$TAG" \
--notes "Subconscious alpha archives: ck, ck-subc, and ck-subc-mcp."
fi
linux-binaries:
name: Subconscious archives (linux-${{ matrix.arch }})
if: startsWith(github.ref_name, 'subc-core-v')
needs: create-subconscious-release
# arm64 rides GitHub's hosted arm runners: real ARM VPS users (and ARM
# Linux VMs on Apple hosts) cannot execute the x64 assets.
strategy:
matrix:
include:
- runner: ubuntu-latest
arch: x64
target: x86_64-unknown-linux-gnu
- runner: ubuntu-24.04-arm
arch: arm64
target: aarch64-unknown-linux-gnu
runs-on: ${{ matrix.runner }}
permissions:
contents: write
steps:
- uses: actions/checkout@v5
- uses: dtolnay/rust-toolchain@stable
with:
targets: ${{ matrix.target }}
- uses: actions/setup-python@v6
with:
python-version: '3.12'
- name: Install pinned Linux cross-linker
run: |
python -m venv "$RUNNER_TEMP/zigbuild"
"$RUNNER_TEMP/zigbuild/bin/pip" install cargo-zigbuild==0.23.4 ziglang==0.16.0
# Expose the pinned Zig, rather than any newer runner-provided linker.
ZIG_PATH=$("$RUNNER_TEMP/zigbuild/bin/python" -c 'import pathlib, ziglang; print(pathlib.Path(ziglang.__file__).parent / "zig")')
ln -s "$ZIG_PATH" "$RUNNER_TEMP/zigbuild/bin/zig"
echo "$RUNNER_TEMP/zigbuild/bin" >> "$GITHUB_PATH"
sudo apt-get update
sudo apt-get install -y binutils
- name: Build release binaries for glibc 2.28
run: cargo zigbuild --release --locked --target ${{ matrix.target }}.2.28 -p subc-core -p subc-mcp --bin ck --bin ck-subc --bin ck-subc-mcp
- name: Enforce glibc 2.28 ceiling
run: bash scripts/release/check-glibc.sh target/${{ matrix.target }}/release
- name: Smoke version probes on Debian 10
run: |
# Native runners exercise each architecture's loader and shared libraries.
# A timeout also refuses a version probe that accidentally starts a daemon.
docker run --rm --network none \
-v "$PWD/target/${{ matrix.target }}/release:/binaries:ro" \
debian:10 sh -ec '
for binary in ck ck-subc ck-subc-mcp; do
timeout 15s "/binaries/$binary" --version
done
'
- name: Package convention-named archives and digest sidecars
run: bash scripts/release/package-unix-archives.sh linux ${{ matrix.arch }} target/${{ matrix.target }}/release dist
- name: Upload release archives
env:
GH_TOKEN: ${{ github.token }}
run: gh release upload "$GITHUB_REF_NAME" dist/* --repo "$GITHUB_REPOSITORY" --clobber
windows-binaries:
name: Subconscious archives (windows-${{ matrix.arch }})
if: startsWith(github.ref_name, 'subc-core-v')
needs: create-subconscious-release
runs-on: windows-latest
permissions:
contents: write
strategy:
fail-fast: false
matrix:
include:
# An explicit --target puts every build under target/<triple>/, the
# host triple included; target/release is only where an untargeted
# build lands.
- arch: x64
target: x86_64-pc-windows-msvc
source: target/x86_64-pc-windows-msvc/release
# Windows on ARM (every Windows VM on Apple silicon, and the Snapdragon
# laptops) cannot install from an x64 archive: the bootstrap refuses
# by tuple rather than relying on emulation. Cross-built on the x64
# runner; the MSVC ARM64 toolchain ships with the image.
- arch: arm64
target: aarch64-pc-windows-msvc
source: target/aarch64-pc-windows-msvc/release
steps:
- uses: actions/checkout@v5
- uses: dtolnay/rust-toolchain@stable
with:
targets: ${{ matrix.target }}
- name: Build release binaries
run: cargo build --release --locked --target ${{ matrix.target }} -p subc-core -p subc-mcp --bin ck --bin ck-subc --bin ck-subc-mcp
# Alpha deliberately ships these native Windows binaries unsigned. This is
# an accepted alpha limitation, not a fallback to a development certificate.
- name: Package unsigned convention-named archives and digest sidecars
shell: pwsh
run: ./scripts/release/package-windows-archives.ps1 -SourceDirectory ${{ matrix.source }} -DistDirectory dist -Arch ${{ matrix.arch }}
- name: Upload release archives
shell: pwsh
env:
GH_TOKEN: ${{ github.token }}
run: gh release upload "$env:GITHUB_REF_NAME" dist/* --repo "$env:GITHUB_REPOSITORY" --clobber
macos-binaries:
name: Signed and notarized subconscious archives (darwin-arm64)
if: startsWith(github.ref_name, 'subc-core-v')
needs: create-subconscious-release
runs-on: macos-14
permissions:
contents: write
steps:
- uses: actions/checkout@v5
- uses: dtolnay/rust-toolchain@stable
- name: Build release binaries
run: cargo build --release --locked -p subc-core -p subc-mcp --bin ck --bin ck-subc --bin ck-subc-mcp
# Alpha arm, explicit by repository variable: package adhoc-signed archives
# when the Developer ID secrets are not provisioned in this repo. The
# Developer ID identity currently lives only in magic-context's CI; signed
# and notarized replacements are produced through its sign-notarize
# dispatch workflow and re-uploaded over these assets. This arm never
# engages silently: it requires ALPHA_DARWIN_UNSIGNED=true and stamps the
# asset provenance into the release notes.
- name: Package adhoc-signed archives (declared alpha arm)
if: vars.ALPHA_DARWIN_UNSIGNED == 'true'
env:
GH_TOKEN: ${{ github.token }}
run: |
mkdir -p dist
for bin in ck ck-subc ck-subc-mcp; do
codesign --force --sign - --identifier "$bin" "target/release/$bin"
(cd target/release && zip -q -X "../../dist/$bin-darwin-arm64.zip" "$bin")
# shasum output format (hex, two spaces, filename) per the sidecar
# grammar; bare hex breaks `shasum -c` consumers.
(cd dist && shasum -a 256 "$bin-darwin-arm64.zip" > "$bin-darwin-arm64.zip.sha256")
done
ls -la dist/
gh release upload "$GITHUB_REF_NAME" dist/* --repo "$GITHUB_REPOSITORY" --clobber
gh release edit "$GITHUB_REF_NAME" --repo "$GITHUB_REPOSITORY" \
--notes "Subconscious alpha archives: ck, ck-subc, and ck-subc-mcp. darwin-arm64 assets are adhoc-signed pending notarized replacements via the signing dispatch."
- name: Import Developer ID Application certificate
if: vars.ALPHA_DARWIN_UNSIGNED != 'true'
env:
DEVELOPER_ID_APPLICATION_CERTIFICATE_BASE64: ${{ secrets.DEVELOPER_ID_APPLICATION_CERTIFICATE_BASE64 }}
DEVELOPER_ID_APPLICATION_CERTIFICATE_PASSWORD: ${{ secrets.DEVELOPER_ID_APPLICATION_CERTIFICATE_PASSWORD }}
run: |
if [ -z "$DEVELOPER_ID_APPLICATION_CERTIFICATE_BASE64" ]; then
echo "::error::Developer ID Application certificate secret is required"
exit 1
fi
if [ -z "$DEVELOPER_ID_APPLICATION_CERTIFICATE_PASSWORD" ]; then
echo "::error::Developer ID Application certificate password secret is required"
exit 1
fi
CERTIFICATE_PATH="$RUNNER_TEMP/developer-id-application.p12"
KEYCHAIN_PATH="$RUNNER_TEMP/developer-id-application.keychain-db"
KEYCHAIN_PASSWORD="$(uuidgen)"
export CERTIFICATE_PATH DEVELOPER_ID_APPLICATION_CERTIFICATE_BASE64
python3 - <<'PY'
import base64
import os
from pathlib import Path
Path(os.environ["CERTIFICATE_PATH"]).write_bytes(
base64.b64decode(os.environ["DEVELOPER_ID_APPLICATION_CERTIFICATE_BASE64"])
)
PY
security create-keychain -p "$KEYCHAIN_PASSWORD" "$KEYCHAIN_PATH"
security set-keychain-settings -lut 21600 "$KEYCHAIN_PATH"
security unlock-keychain -p "$KEYCHAIN_PASSWORD" "$KEYCHAIN_PATH"
security import "$CERTIFICATE_PATH" -k "$KEYCHAIN_PATH" \
-P "$DEVELOPER_ID_APPLICATION_CERTIFICATE_PASSWORD" -A
security list-keychain -d user -s "$KEYCHAIN_PATH"
security set-key-partition-list -S apple-tool:,apple:,codesign: -s \
-k "$KEYCHAIN_PASSWORD" "$KEYCHAIN_PATH"
- name: Write App Store Connect API key
if: vars.ALPHA_DARWIN_UNSIGNED != 'true'
env:
APP_STORE_CONNECT_API_KEY: ${{ secrets.APP_STORE_CONNECT_API_KEY }}
APP_STORE_CONNECT_API_KEY_ID: ${{ secrets.APP_STORE_CONNECT_API_KEY_ID }}
APP_STORE_CONNECT_API_ISSUER_ID: ${{ secrets.APP_STORE_CONNECT_API_ISSUER_ID }}
run: |
if [ -z "$APP_STORE_CONNECT_API_KEY" ] || [ -z "$APP_STORE_CONNECT_API_KEY_ID" ] || [ -z "$APP_STORE_CONNECT_API_ISSUER_ID" ]; then
echo "::error::App Store Connect API-key credentials are required for notarization"
exit 1
fi
umask 077
printf '%s' "$APP_STORE_CONNECT_API_KEY" > "$RUNNER_TEMP/AuthKey_${APP_STORE_CONNECT_API_KEY_ID}.p8"
- name: Sign, notarize, and package macOS archives
if: vars.ALPHA_DARWIN_UNSIGNED != 'true'
env:
APP_STORE_CONNECT_API_KEY_PATH: ${{ runner.temp }}/AuthKey_${{ secrets.APP_STORE_CONNECT_API_KEY_ID }}.p8
APP_STORE_CONNECT_API_KEY_ID: ${{ secrets.APP_STORE_CONNECT_API_KEY_ID }}
APP_STORE_CONNECT_API_ISSUER_ID: ${{ secrets.APP_STORE_CONNECT_API_ISSUER_ID }}
run: bash scripts/release/macos-sign-notarize.sh target/release dist
- name: Upload release archives
if: vars.ALPHA_DARWIN_UNSIGNED != 'true'
env:
GH_TOKEN: ${{ github.token }}
run: gh release upload "$GITHUB_REF_NAME" dist/* --repo "$GITHUB_REPOSITORY" --clobber
# ck-aft is intentionally absent: its publication is a named cross-repository
# dependency owned by the AFT repository's release lane.
publish-subconscious-release:
name: Publish subconscious release (all legs uploaded)
if: startsWith(github.ref_name, 'subc-core-v')
needs: [linux-binaries, windows-binaries, macos-binaries]
runs-on: ubuntu-latest
permissions:
contents: write
steps:
- name: Verify the asset inventory, then undraft
env:
GH_TOKEN: ${{ github.token }}
run: |
TAG="${GITHUB_REF_NAME}"
# Every tuple the lanes above build, times the three binaries, plus
# a sidecar each. A missing name refuses the publish by name; the
# draft stays for inspection and nothing reaches an installer.
expected=0; missing=""
assets=$(gh release view "$TAG" --repo "$GITHUB_REPOSITORY" --json assets --jq '.assets[].name')
for tuple in darwin-arm64 linux-x64 linux-arm64 windows-x64 windows-arm64; do
for bin in ck ck-subc ck-subc-mcp; do
for name in "$bin-$tuple.zip" "$bin-$tuple.zip.sha256"; do
expected=$((expected+1))
if ! printf '%s\n' "$assets" | grep -qxF "$name"; then missing="$missing $name"; fi
done
done
done
if [ -n "$missing" ]; then
echo "::error::release ${TAG} is missing assets:${missing}"
exit 1
fi
echo "inventory complete: ${expected} assets"
gh release edit "$TAG" --repo "$GITHUB_REPOSITORY" --draft=false
resolve-publish-tag:
name: Resolve crate publish tag
# subc-core tags cut binary releases (above), never a crates.io publish.
if: ${{ !startsWith(github.ref_name, 'subc-core-v') }}
needs: verify
runs-on: ubuntu-latest
outputs:
crate: ${{ steps.tag.outputs.crate }}
version: ${{ steps.tag.outputs.version }}
steps:
# Parse `<crate>-v<version>` here so the reusable workflow has the same
# explicit crate and version inputs as the publish-on-bump path.
- name: Resolve crate + version from tag
id: tag
run: |
TAG="${GITHUB_REF_NAME}"
if [[ ! "$TAG" =~ ^(.+)-v([0-9].*)$ ]]; then
echo "::error::Tag '$TAG' must be '<crate>-v<version>', e.g. subc-transport-v0.1.0"
exit 1
fi
echo "crate=${BASH_REMATCH[1]}" >> "$GITHUB_OUTPUT"
echo "version=${BASH_REMATCH[2]}" >> "$GITHUB_OUTPUT"
publish:
name: Publish to crates.io
needs: resolve-publish-tag
uses: ./.github/workflows/publish-crate.yml
with:
crate: ${{ needs.resolve-publish-tag.outputs.crate }}
version: ${{ needs.resolve-publish-tag.outputs.version }}
secrets:
CARGO_REGISTRY_TOKEN: ${{ secrets.CARGO_REGISTRY_TOKEN }}