Skip to content
Closed
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
97 changes: 97 additions & 0 deletions .github/workflows/auto-release.yml
Original file line number Diff line number Diff line change
@@ -0,0 +1,97 @@
name: Autonomous Release

on:
push:
branches: [main]
paths:
- Cargo.toml
- pyproject.toml
- python/kernal_api/__init__.py
workflow_dispatch:
inputs:
dry_run:
description: Report the release decision without creating a release.
type: boolean
default: false

permissions:
contents: write
actions: write

concurrency:
group: kernal-api-auto-release-${{ github.ref_name }}
cancel-in-progress: false

jobs:
prepare:
name: Detect version bump
runs-on: ubuntu-latest
outputs:
should_release: ${{ steps.version.outputs.should_release }}
tag: ${{ steps.version.outputs.tag }}
steps:
- uses: actions/checkout@11d5960a326750d5838078e36cf38b85af677262 # v4
with:
fetch-depth: 0
- name: Validate synchronized version and detect a missing release
id: version
env:
GH_TOKEN: ${{ github.token }}
shell: bash
run: |
set -euo pipefail
version="$(python3 - <<'PY'
import tomllib
from pathlib import Path

cargo = tomllib.loads(Path('Cargo.toml').read_text())['package']['version']
pyproject = tomllib.loads(Path('pyproject.toml').read_text())['project']['version']
init = Path('python/kernal_api/__init__.py').read_text()
if cargo == '0.0.0':
raise SystemExit('0.0.0 is a migration-only version and cannot be released')
if cargo != pyproject or f'__version__ = "{cargo}"' not in init:
raise SystemExit('Cargo, pyproject, and Python companion versions must agree')
print(cargo)
PY
)"
tag="v${version}"
if gh release view "${tag}" --repo "${GITHUB_REPOSITORY}" >/dev/null 2>&1; then
release_state="$(gh release view "${tag}" --repo "${GITHUB_REPOSITORY}" --json isDraft,isPrerelease --jq 'if .isDraft then "draft" elif .isPrerelease then "prerelease" else "published" end')"
if [ "${release_state}" != "published" ]; then
echo "${tag} already has a ${release_state} release; resolve it before automatic release" >&2
exit 1
fi
should_release=false
echo "${tag} is already published from this commit"
else
should_release=true
echo "${tag} is not published"
fi
if [ "${should_release}" = true ] && git rev-parse -q --verify "refs/tags/${tag}" >/dev/null; then
tag_commit="$(git rev-parse "refs/tags/${tag}^{}")"
if [ "${tag_commit}" != "${GITHUB_SHA}" ]; then
echo "${tag} points at ${tag_commit}, not this release candidate ${GITHUB_SHA}" >&2
exit 1
fi
fi
echo "tag=${tag}" >> "$GITHUB_OUTPUT"
echo "should_release=${should_release}" >> "$GITHUB_OUTPUT"

release:
needs: prepare
if: needs.prepare.outputs.should_release == 'true' && !(github.event_name == 'workflow_dispatch' && inputs.dry_run)
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@11d5960a326750d5838078e36cf38b85af677262 # v4
- name: Create immutable GitHub release from this exact commit
env:
GH_TOKEN: ${{ github.token }}
TAG: ${{ needs.prepare.outputs.tag }}
run: >-
gh release create "$TAG" --repo "$GITHUB_REPOSITORY"
--target "$GITHUB_SHA" --generate-notes --title "kernal-api $TAG"
- name: Dispatch release verification and asset packaging
env:
GH_TOKEN: ${{ github.token }}
TAG: ${{ needs.prepare.outputs.tag }}
run: gh workflow run release.yml --repo "$GITHUB_REPOSITORY" --ref "$TAG" -f tag="$TAG"
6 changes: 6 additions & 0 deletions .github/workflows/ci.yml
Original file line number Diff line number Diff line change
Expand Up @@ -178,6 +178,7 @@ jobs:
- text-similarity
- command-arguments
- config-toml
- json
- source-cpp
- terminal-style
- terminal-input
Expand Down Expand Up @@ -210,6 +211,11 @@ jobs:
- run: >-
soldr cargo check
--locked --no-default-features --features ${{ matrix.feature }}
- name: Test JSON with unified arbitrary-precision backend feature
if: matrix.feature == 'json'
run: >-
soldr cargo test --locked --no-default-features
--features json,serde_json/arbitrary_precision --test json_documents

# A unit test does not own process main on every test harness, while Tauri
# requires its event loop to start there. These executable proofs
Expand Down
31 changes: 20 additions & 11 deletions .github/workflows/release.yml
Original file line number Diff line number Diff line change
Expand Up @@ -3,22 +3,29 @@ name: Release
on:
release:
types: [published]
workflow_dispatch:
inputs:
tag:
description: Existing v-prefixed release tag to verify and package.
required: true
type: string

permissions:
contents: write
actions: write

env:
SOURCE_DATE_EPOCH: "0"
RELEASE_TAG: ${{ github.event.release.tag_name || inputs.tag }}

jobs:
release-guard:
if: startsWith(github.event.release.tag_name, 'v')
if: startsWith(github.event.release.tag_name || inputs.tag, 'v')
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@11d5960a326750d5838078e36cf38b85af677262 # v4
with:
ref: ${{ github.event.release.tag_name }}
ref: ${{ env.RELEASE_TAG }}
lfs: true
- uses: astral-sh/setup-uv@d0d8abe699bfb85fec6de9f7adb5ae17292296ff # v6
- name: Reject migration-only running-process paths
Expand All @@ -28,13 +35,13 @@ jobs:

validate-and-package:
needs: release-guard
if: startsWith(github.event.release.tag_name, 'v')
if: startsWith(github.event.release.tag_name || inputs.tag, 'v')
runs-on: ubuntu-latest
environment: release
steps:
- uses: actions/checkout@11d5960a326750d5838078e36cf38b85af677262 # v4
with:
ref: ${{ github.event.release.tag_name }}
ref: ${{ env.RELEASE_TAG }}
lfs: true
- uses: astral-sh/setup-uv@d0d8abe699bfb85fec6de9f7adb5ae17292296ff # v6
- uses: zackees/setup-soldr@bb28e96d2dc32c058242f56722297caf1efcbd90
Expand All @@ -49,7 +56,7 @@ jobs:
shell: bash
run: |
manifest_version="$(sed -n 's/^version = "\([^"]*\)"/\1/p' Cargo.toml | head -n1)"
test "v${manifest_version}" = "${{ github.event.release.tag_name }}"
test "v${manifest_version}" = "${{ env.RELEASE_TAG }}"
test "${manifest_version}" != "0.0.0"
grep -q "version = \"${manifest_version}\"" pyproject.toml
grep -q "__version__ = \"${manifest_version}\"" python/kernal_api/__init__.py
Expand Down Expand Up @@ -82,7 +89,7 @@ jobs:

symbolizer-workers:
needs: release-guard
if: startsWith(github.event.release.tag_name, 'v')
if: startsWith(github.event.release.tag_name || inputs.tag, 'v')
strategy:
fail-fast: false
matrix:
Expand Down Expand Up @@ -115,7 +122,7 @@ jobs:
steps:
- uses: actions/checkout@11d5960a326750d5838078e36cf38b85af677262 # v4
with:
ref: ${{ github.event.release.tag_name }}
ref: ${{ env.RELEASE_TAG }}
- if: ${{ !matrix.cross }}
uses: zackees/setup-soldr@bb28e96d2dc32c058242f56722297caf1efcbd90
- if: ${{ matrix.cross }}
Expand Down Expand Up @@ -143,12 +150,13 @@ jobs:

publish-crates:
needs: [release-guard, validate-and-package]
if: needs.release-guard.result == 'success' && needs.validate-and-package.result == 'success' && vars.ENABLE_REGISTRY_PUBLISH == 'true'
runs-on: ubuntu-latest
environment: release
steps:
- uses: actions/checkout@11d5960a326750d5838078e36cf38b85af677262 # v4
with:
ref: ${{ github.event.release.tag_name }}
ref: ${{ env.RELEASE_TAG }}
lfs: true
- uses: zackees/setup-soldr@bb28e96d2dc32c058242f56722297caf1efcbd90
- uses: actions/download-artifact@d3f86a106a0bac45b974a628896c90dbdf5c8093 # v4
Expand All @@ -160,7 +168,7 @@ jobs:
env:
CARGO_REGISTRY_TOKEN: ${{ secrets.CARGO_REGISTRY_TOKEN }}
run: |
version="${{ github.event.release.tag_name }}"
version="${{ env.RELEASE_TAG }}"
version="${version#v}"
crate_file="$(find release-packages -name "kernal-api-${version}.crate" -print -quit)"
local_sha="$(sha256sum "${crate_file}" | awk '{print $1}')"
Expand All @@ -179,6 +187,7 @@ jobs:

publish-pypi:
needs: validate-and-package
if: needs.validate-and-package.result == 'success' && vars.ENABLE_PYPI_PUBLISH == 'true'
runs-on: ubuntu-latest
environment: release
steps:
Expand All @@ -193,7 +202,7 @@ jobs:
TWINE_USERNAME: __token__
TWINE_PASSWORD: ${{ secrets.PYPI_API_TOKEN }}
run: |
version="${{ github.event.release.tag_name }}"
version="${{ env.RELEASE_TAG }}"
version="${version#v}"
status="$(curl -sS -o pypi.json -w '%{http_code}' \
"https://pypi.org/pypi/kernal-api/${version}/json")"
Expand Down Expand Up @@ -223,7 +232,7 @@ jobs:
env:
GH_TOKEN: ${{ github.token }}
run: >-
gh release upload "${{ github.event.release.tag_name }}"
gh release upload "${{ env.RELEASE_TAG }}"
release-assets/conpty-sidecar-*.tar.zst
release-assets/kernal-symbolize-*
--repo "${{ github.repository }}" --clobber
Loading
Loading