core-release #10
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
| name: core-release | |
| on: | |
| push: | |
| tags: ['v*'] | |
| workflow_dispatch: | |
| inputs: | |
| ref: | |
| description: Full source commit SHA to build | |
| required: true | |
| type: string | |
| offline: | |
| description: Also create the full offline archive | |
| default: false | |
| type: boolean | |
| draft_release: | |
| description: Upload files to a new draft release; never publish | |
| default: false | |
| type: boolean | |
| permissions: | |
| contents: read | |
| concurrency: | |
| group: core-release-${{ inputs.ref || github.sha }} | |
| cancel-in-progress: false | |
| jobs: | |
| build: | |
| runs-on: ubuntu-22.04 | |
| timeout-minutes: 120 | |
| outputs: | |
| revision: ${{ steps.source.outputs.revision }} | |
| release_tag: ${{ steps.source.outputs.release_tag }} | |
| steps: | |
| - uses: actions/checkout@v7 | |
| with: | |
| ref: ${{ inputs.ref || github.sha }} | |
| persist-credentials: false | |
| - name: Pin source identity | |
| id: source | |
| env: | |
| REQUESTED_REF: ${{ inputs.ref }} | |
| run: | | |
| if [[ -n "$REQUESTED_REF" && ! "$REQUESTED_REF" =~ ^[0-9a-f]{40}$ ]]; then | |
| echo 'Manual releases require a full commit SHA' >&2 | |
| exit 1 | |
| fi | |
| revision="$(git rev-parse HEAD)" | |
| if [[ -n "$REQUESTED_REF" && "$REQUESTED_REF" != "$revision" ]]; then exit 1; fi | |
| echo "revision=$revision" >> "$GITHUB_OUTPUT" | |
| release_tag="build-$revision" | |
| if [[ "$GITHUB_EVENT_NAME" == push ]]; then release_tag="$GITHUB_REF_NAME"; fi | |
| echo "release_tag=$release_tag" >> "$GITHUB_OUTPUT" | |
| - name: Reserve disk space for distribution archives | |
| run: | | |
| # The hosted runner needs room for Docker images, tar exports and the | |
| # microsandbox import. This job does not use these preinstalled SDKs. | |
| df -h / | |
| sudo rm -rf /usr/local/lib/android /usr/share/dotnet /usr/local/.ghcup | |
| df -h / | |
| - uses: actions/setup-go@v7 | |
| with: | |
| go-version-file: go.mod | |
| - uses: actions/setup-node@v6 | |
| with: | |
| node-version: '22' | |
| - name: Install build prerequisites | |
| run: | | |
| npm install --global pnpm@10.30.3 | |
| sudo apt-get update | |
| sudo apt-get install -y build-essential pkg-config libssl-dev | |
| rustup toolchain install 1.95.0 --profile minimal | |
| - uses: actions/cache@v6 | |
| with: | |
| path: | | |
| ~/.parsar/cache/go-build | |
| ~/.parsar/cache/go-mod | |
| ~/.parsar/cache/executor-cargo | |
| ~/.parsar/cache/executor-target | |
| key: core-release-${{ runner.os }}-${{ hashFiles('go.sum', 'packages/codex-executor/Cargo.lock') }} | |
| - name: Check release metadata and prepare pinned harnesses | |
| run: | | |
| PYTHONDONTWRITEBYTECODE=1 python3 scripts/core-distribution-manifest.test.py | |
| bash scripts/prepare-release-runtimes.sh | |
| - name: Build matched artifacts | |
| env: | |
| RELEASE_REVISION: ${{ steps.source.outputs.revision }} | |
| RELEASE_TAG: ${{ steps.source.outputs.release_tag }} | |
| RELEASE_REPOSITORY: ${{ github.repository }} | |
| CORE_DISTRIBUTION_OFFLINE: ${{ inputs.offline && '1' || '0' }} | |
| run: | | |
| inputs="$HOME/.parsar/build/release-inputs/inputs.json" | |
| AGENTS_RUNTIME_CODEX_PACKAGE="$(python3 -c 'import json,sys; print(json.load(open(sys.argv[1]))["codex"])' "$inputs")" | |
| MCODE_HARNESS_BUILD_DIR="$(python3 -c 'import json,sys; print(json.load(open(sys.argv[1]))["mcode"])' "$inputs")" | |
| export AGENTS_RUNTIME_CODEX_PACKAGE MCODE_HARNESS_BUILD_DIR | |
| export CORE_DISTRIBUTION_RELEASE_BASE_URL="https://github.com/$RELEASE_REPOSITORY/releases/download/$RELEASE_TAG" | |
| bash scripts/build-core-distribution.sh | |
| mkdir -p "$HOME/.parsar/build/release-upload" | |
| for asset in "$HOME/.parsar/build/core-distribution/"*; do | |
| if [[ -f "$asset" ]]; then ln "$asset" "$HOME/.parsar/build/release-upload/"; fi | |
| done | |
| - uses: actions/upload-artifact@v6 | |
| with: | |
| name: core-release-${{ steps.source.outputs.revision }} | |
| path: ~/.parsar/build/release-upload/* | |
| compression-level: 0 | |
| if-no-files-found: error | |
| draft: | |
| if: github.event_name == 'workflow_dispatch' && inputs.draft_release | |
| needs: build | |
| runs-on: ubuntu-22.04 | |
| permissions: | |
| contents: write | |
| steps: | |
| - uses: actions/download-artifact@v6 | |
| with: | |
| name: core-release-${{ needs.build.outputs.revision }} | |
| path: release-upload | |
| - name: Create an unpublished draft | |
| env: | |
| GH_TOKEN: ${{ github.token }} | |
| GH_REPO: ${{ github.repository }} | |
| RELEASE_REVISION: ${{ needs.build.outputs.revision }} | |
| RELEASE_TAG: ${{ needs.build.outputs.release_tag }} | |
| run: | | |
| printf 'Matched Linux amd64 artifacts from commit %s. Build output is not live execution qualification.\n' "$RELEASE_REVISION" > release-notes.md | |
| gh release create "$RELEASE_TAG" --draft --target "$RELEASE_REVISION" \ | |
| --title "Parsar Core $RELEASE_REVISION" --notes-file release-notes.md release-upload/* |