Skip to content

Merge pull request #14 from Commanderx-code/dependabot/npm_and_yarn/n… #45

Merge pull request #14 from Commanderx-code/dependabot/npm_and_yarn/n…

Merge pull request #14 from Commanderx-code/dependabot/npm_and_yarn/n… #45

name: Linux packages
on:
push:
branches: [main]
tags: ["v*"]
pull_request:
workflow_dispatch:
inputs:
arch_release:
description: Build the Arch package from the release tag named in PKGBUILD, for attaching to that release
type: boolean
default: false
permissions:
contents: read
# Manual runs never share a group with pushes, and only superseded pull request runs are
# cancelled, so every commit on main and every tag keeps a complete result.
concurrency:
group: linux-packages-${{ github.event_name }}-${{ github.ref }}
cancel-in-progress: ${{ github.event_name == 'pull_request' }}
jobs:
# Rust tests run as a normal user; containers run as root, which masks permission checks.
tests:
runs-on: ubuntu-24.04
timeout-minutes: 35
steps:
- uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
- uses: actions/setup-node@820762786026740c76f36085b0efc47a31fe5020 # v7.0.0
with:
node-version: "22.23.2"
cache: npm
- uses: dtolnay/rust-toolchain@6bed0761d98439e5a578e2877258200ad565ba87 # stable
with:
toolchain: stable
components: clippy
- name: Install build dependencies
run: |
# Mirrors can briefly 404 a package just replaced by an update; refresh and retry.
for attempt in 1 2 3; do
sudo apt-get update && sudo apt-get install -y libwebkit2gtk-4.1-dev build-essential libssl-dev libayatana-appindicator3-dev librsvg2-dev && exit 0
echo "apt attempt $attempt failed; retrying in 30 seconds" >&2
sleep 30
done
exit 1
- name: Install checksum-pinned Restic for restore integration tests
run: |
curl -fsSL https://github.com/restic/restic/releases/download/v0.19.1/restic_0.19.1_linux_amd64.bz2 -o /tmp/restic-ci.bz2
echo 'f415415624dcc452f2a02b8c33641791a8c6d6d3b65bbb3543fcf9a25151585c /tmp/restic-ci.bz2' | sha256sum -c -
bzip2 -dk /tmp/restic-ci.bz2
sudo install -m755 /tmp/restic-ci /usr/local/bin/restic
restic version
- run: npm ci
- run: npm run check && npm test && npm run test:rust
- run: cargo clippy --manifest-path src-tauri/Cargo.toml --all-targets -- -D warnings
# Build once on the oldest supported base so one binary serves every distribution.
# Ubuntu 22.04 provides glibc 2.35, the floor declared in tauri.conf.json.
build:
runs-on: ubuntu-24.04
container: ubuntu:22.04
timeout-minutes: 40
env:
DEBIAN_FRONTEND: noninteractive
steps:
- name: Install build tools
run: |
# Mirrors can briefly 404 a package just replaced by an update; refresh and retry.
for attempt in 1 2 3; do
apt-get update && apt-get install -y curl ca-certificates git build-essential pkg-config file libssl-dev libwebkit2gtk-4.1-dev libayatana-appindicator3-dev librsvg2-dev patchelf python3 binutils libarchive-tools && exit 0
echo "apt attempt $attempt failed; retrying in 30 seconds" >&2
sleep 30
done
exit 1
- uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
- uses: actions/setup-node@820762786026740c76f36085b0efc47a31fe5020 # v7.0.0
with:
node-version: "22.23.2"
- uses: dtolnay/rust-toolchain@6bed0761d98439e5a578e2877258200ad565ba87 # stable
with:
toolchain: stable
- run: npm ci && npm run check && npm test
- run: npm run desktop:package
- run: python3 scripts/verify-packages.py
- uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1
with:
name: packages
path: artifacts/release/*
if-no-files-found: error
# Install the same packages on each supported family and launch them as a normal user.
install-deb:
needs: build
runs-on: ubuntu-24.04
strategy:
fail-fast: false
matrix:
image: ["ubuntu:22.04", "debian:12", "ubuntu:24.04"]
container: ${{ matrix.image }}
timeout-minutes: 20
env:
DEBIAN_FRONTEND: noninteractive
steps:
- uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
- uses: actions/download-artifact@3e5f45b2cfb9172054b4087a40e8e0b5a5461e7c # v8.0.1
with:
name: packages
path: packages
- name: Verify checksums
run: cd packages && sha256sum --check SHA256SUMS
- name: Install package and launch-test tools
run: |
# Mirrors can briefly 404 a package just replaced by an update; refresh and retry.
for attempt in 1 2 3; do
apt-get update && apt-get install -y ./packages/*.deb xvfb xauth dbus dbus-x11 libnotify-bin && exit 0
echo "apt attempt $attempt failed; retrying in 30 seconds" >&2
sleep 30
done
exit 1
- name: Launch installed application as a normal user
run: useradd -m smoke && runuser -u smoke -- bash scripts/smoke-desktop.sh /usr/bin/command-center
install-rpm:
needs: build
runs-on: ubuntu-24.04
container: fedora:43
timeout-minutes: 20
steps:
- uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
- uses: actions/download-artifact@3e5f45b2cfb9172054b4087a40e8e0b5a5461e7c # v8.0.1
with:
name: packages
path: packages
- name: Verify checksums
run: cd packages && sha256sum --check SHA256SUMS
- name: Install package and launch-test tools
run: dnf install -y ./packages/*.rpm xorg-x11-server-Xvfb xorg-x11-xauth dbus-daemon shadow-utils libnotify
- name: Launch installed application as a normal user
run: useradd -m smoke && runuser -u smoke -- bash scripts/smoke-desktop.sh /usr/bin/command-center
# Build the Arch recipe in a clean container, lint it, install it and launch it. Tag pushes
# (and arch_release dispatches) build the recipe unmodified from its release tag, exactly as
# AUR users will; other pushes build this commit.
arch:
runs-on: ubuntu-24.04
container: archlinux:base-devel
timeout-minutes: 45
steps:
- name: Install build, lint and launch-test tools
run: pacman -Syu --noconfirm --needed git nodejs npm rust webkit2gtk-4.1 gtk3 libappindicator-gtk3 namcap xorg-server-xvfb xorg-xauth dbus
- uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
- name: Build package
env:
RELEASE_BUILD: ${{ github.ref_type == 'tag' || inputs.arch_release }}
run: |
useradd -m builder
git config --system --add safe.directory '*'
mkdir /build && cp packaging/aur/PKGBUILD /build/
if [ "$RELEASE_BUILD" = true ]; then
. /build/PKGBUILD
if [ "$GITHUB_REF_TYPE" = tag ] && [ "v$pkgver" != "$GITHUB_REF_NAME" ]; then
echo "PKGBUILD pkgver $pkgver does not match tag $GITHUB_REF_NAME" >&2; exit 1
fi
else
sed -i "s|^source=.*|source=(\"command-center::git+file://$GITHUB_WORKSPACE#commit=$GITHUB_SHA\")|" /build/PKGBUILD
fi
chown -R builder /build
cd /build && runuser -u builder -- makepkg --noconfirm
- name: Lint recipe and package
run: cd /build && namcap PKGBUILD && namcap ./*.pkg.tar.zst
- name: Install package and launch as a normal user
run: pacman -U --noconfirm /build/*.pkg.tar.zst && runuser -u builder -- bash scripts/smoke-desktop.sh /usr/bin/command-center
- name: Prepare release asset
run: |
mkdir /arch-release
cp /build/command-center-[0-9]*-x86_64.pkg.tar.zst /arch-release/
cd /arch-release && test "$(ls | wc -l)" -eq 1 && sha256sum -- *.pkg.tar.zst > SHA256SUMS && cat SHA256SUMS
- uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1
with:
name: arch-package
path: /arch-release/*
if-no-files-found: error