-
Notifications
You must be signed in to change notification settings - Fork 0
213 lines (208 loc) · 9.16 KB
/
Copy pathlinux-packages.yml
File metadata and controls
213 lines (208 loc) · 9.16 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
130
131
132
133
134
135
136
137
138
139
140
141
142
143
144
145
146
147
148
149
150
151
152
153
154
155
156
157
158
159
160
161
162
163
164
165
166
167
168
169
170
171
172
173
174
175
176
177
178
179
180
181
182
183
184
185
186
187
188
189
190
191
192
193
194
195
196
197
198
199
200
201
202
203
204
205
206
207
208
209
210
211
212
213
name: Linux packages
on:
push:
branches: [main]
tags: ["v*"]
pull_request:
workflow_dispatch:
inputs:
arch_release:
description: Build the Arch package from the release tag named in PKGBUILD, for attaching to that release
type: boolean
default: false
permissions:
contents: read
# Manual runs never share a group with pushes, and only superseded pull request runs are
# cancelled, so every commit on main and every tag keeps a complete result.
concurrency:
group: linux-packages-${{ github.event_name }}-${{ github.ref }}
cancel-in-progress: ${{ github.event_name == 'pull_request' }}
jobs:
# Rust tests run as a normal user; containers run as root, which masks permission checks.
tests:
runs-on: ubuntu-24.04
timeout-minutes: 35
steps:
- uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
- uses: actions/setup-node@820762786026740c76f36085b0efc47a31fe5020 # v7.0.0
with:
node-version: "22.23.2"
cache: npm
- uses: dtolnay/rust-toolchain@6bed0761d98439e5a578e2877258200ad565ba87 # stable
with:
toolchain: stable
components: clippy
- name: Install build dependencies
run: |
# Mirrors can briefly 404 a package just replaced by an update; refresh and retry.
for attempt in 1 2 3; do
sudo apt-get update && sudo apt-get install -y libwebkit2gtk-4.1-dev build-essential libssl-dev libayatana-appindicator3-dev librsvg2-dev && exit 0
echo "apt attempt $attempt failed; retrying in 30 seconds" >&2
sleep 30
done
exit 1
- name: Install checksum-pinned Restic for restore integration tests
run: |
curl -fsSL https://github.com/restic/restic/releases/download/v0.19.1/restic_0.19.1_linux_amd64.bz2 -o /tmp/restic-ci.bz2
echo 'f415415624dcc452f2a02b8c33641791a8c6d6d3b65bbb3543fcf9a25151585c /tmp/restic-ci.bz2' | sha256sum -c -
bzip2 -dk /tmp/restic-ci.bz2
sudo install -m755 /tmp/restic-ci /usr/local/bin/restic
restic version
- run: npm ci
- run: npm run check && npm test && npm run test:rust
- run: cargo clippy --manifest-path src-tauri/Cargo.toml --all-targets -- -D warnings
# Build once on the oldest supported base so one binary serves every distribution.
# Ubuntu 22.04 provides glibc 2.35, the floor declared in tauri.conf.json.
build:
runs-on: ubuntu-24.04
container: ubuntu:22.04
timeout-minutes: 40
env:
DEBIAN_FRONTEND: noninteractive
steps:
- name: Install build tools
run: |
# Mirrors can briefly 404 a package just replaced by an update; refresh and retry.
for attempt in 1 2 3; do
apt-get update && apt-get install -y curl ca-certificates git build-essential pkg-config file libssl-dev libwebkit2gtk-4.1-dev libayatana-appindicator3-dev librsvg2-dev patchelf python3 binutils libarchive-tools && exit 0
echo "apt attempt $attempt failed; retrying in 30 seconds" >&2
sleep 30
done
exit 1
- uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
- uses: actions/setup-node@820762786026740c76f36085b0efc47a31fe5020 # v7.0.0
with:
node-version: "22.23.2"
- uses: dtolnay/rust-toolchain@6bed0761d98439e5a578e2877258200ad565ba87 # stable
with:
toolchain: stable
- run: npm ci && npm run check && npm test
- run: npm run desktop:package
- run: python3 scripts/verify-packages.py
- uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1
with:
name: packages
path: artifacts/release/*
if-no-files-found: error
# Install the same packages on each supported family and launch them as a normal user.
install-deb:
needs: build
runs-on: ubuntu-24.04
strategy:
fail-fast: false
matrix:
image: ["ubuntu:22.04", "debian:12", "ubuntu:24.04"]
container: ${{ matrix.image }}
timeout-minutes: 20
env:
DEBIAN_FRONTEND: noninteractive
steps:
- uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
- uses: actions/download-artifact@3e5f45b2cfb9172054b4087a40e8e0b5a5461e7c # v8.0.1
with:
name: packages
path: packages
- name: Verify checksums
run: cd packages && sha256sum --check SHA256SUMS
- name: Install package and launch-test tools
run: |
# Mirrors can briefly 404 a package just replaced by an update; refresh and retry.
for attempt in 1 2 3; do
apt-get update && apt-get install -y ./packages/*.deb xvfb xauth dbus dbus-x11 libnotify-bin && exit 0
echo "apt attempt $attempt failed; retrying in 30 seconds" >&2
sleep 30
done
exit 1
- name: Launch installed application as a normal user
run: useradd -m smoke && runuser -u smoke -- bash scripts/smoke-desktop.sh /usr/bin/command-center
install-rpm:
needs: build
runs-on: ubuntu-24.04
container: fedora:43
timeout-minutes: 20
steps:
- uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
- uses: actions/download-artifact@3e5f45b2cfb9172054b4087a40e8e0b5a5461e7c # v8.0.1
with:
name: packages
path: packages
- name: Verify checksums
run: cd packages && sha256sum --check SHA256SUMS
- name: Install package and launch-test tools
run: dnf install -y ./packages/*.rpm xorg-x11-server-Xvfb xorg-x11-xauth dbus-daemon shadow-utils libnotify
- name: Launch installed application as a normal user
run: useradd -m smoke && runuser -u smoke -- bash scripts/smoke-desktop.sh /usr/bin/command-center
# Build the Arch recipe in a clean container, lint it, install it and launch it. Tag pushes
# (and arch_release dispatches) build the recipe unmodified from its release tag, exactly as
# AUR users will; other pushes build this commit.
arch:
runs-on: ubuntu-24.04
container: archlinux:base-devel
timeout-minutes: 45
steps:
- name: Install build, lint and launch-test tools
run: pacman -Syu --noconfirm --needed git nodejs npm rust webkit2gtk-4.1 gtk3 libappindicator-gtk3 namcap xorg-server-xvfb xorg-xauth dbus
- uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
- name: Build package
env:
RELEASE_BUILD: ${{ github.ref_type == 'tag' || inputs.arch_release }}
run: |
useradd -m builder
git config --system --add safe.directory '*'
mkdir /build && cp packaging/aur/PKGBUILD /build/
if [ "$RELEASE_BUILD" = true ]; then
. /build/PKGBUILD
if [ "$GITHUB_REF_TYPE" = tag ] && [ "v$pkgver" != "$GITHUB_REF_NAME" ]; then
echo "PKGBUILD pkgver $pkgver does not match tag $GITHUB_REF_NAME" >&2; exit 1
fi
else
sed -i "s|^source=.*|source=(\"command-center::git+file://$GITHUB_WORKSPACE#commit=$GITHUB_SHA\")|" /build/PKGBUILD
fi
chown -R builder /build
cd /build && runuser -u builder -- makepkg --noconfirm
- name: Lint recipe and package
run: cd /build && namcap PKGBUILD && namcap ./*.pkg.tar.zst
- name: Install package and launch as a normal user
run: pacman -U --noconfirm /build/*.pkg.tar.zst && runuser -u builder -- bash scripts/smoke-desktop.sh /usr/bin/command-center
- name: Prepare release asset
run: |
mkdir /arch-release
cp /build/command-center-[0-9]*-x86_64.pkg.tar.zst /arch-release/
cd /arch-release && test "$(ls | wc -l)" -eq 1 && sha256sum -- *.pkg.tar.zst > SHA256SUMS && cat SHA256SUMS
- uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1
with:
name: arch-package
path: /arch-release/*
if-no-files-found: error
# Sign SLSA build provenance for the exact packages a release is drafted from, once they
# have built and passed every install test. Only tag runs attest, and only this job gets
# the signing permissions. release:draft verifies these attestations before drafting.
attest:
if: github.ref_type == 'tag'
needs: [build, install-deb, install-rpm, arch]
runs-on: ubuntu-24.04
timeout-minutes: 10
permissions:
contents: read
id-token: write
attestations: write
artifact-metadata: write
steps:
- uses: actions/download-artifact@3e5f45b2cfb9172054b4087a40e8e0b5a5461e7c # v8.0.1
with:
name: packages
path: packages
- uses: actions/download-artifact@3e5f45b2cfb9172054b4087a40e8e0b5a5461e7c # v8.0.1
with:
name: arch-package
path: arch-package
- name: Verify checksums
run: |
(cd packages && sha256sum --check --strict SHA256SUMS)
(cd arch-package && sha256sum --check --strict SHA256SUMS)
- uses: actions/attest@1e69f48acb82d1966a394da916b4c1698aa569d6 # v4.2.2
with:
subject-path: |
packages/*.deb
packages/*.rpm
arch-package/*.pkg.tar.zst