Skip to content

core-release

core-release #31

Workflow file for this run

name: core-release
on:
push:
tags: ['v*']
workflow_dispatch:
inputs:
ref:
description: Full source commit SHA to build
required: true
type: string
offline:
description: Also create the full offline archive
default: true
type: boolean
draft_release:
description: Upload files to a new draft release; never publish
default: false
type: boolean
permissions:
contents: read
concurrency:
group: core-release-${{ github.event_name == 'push' && github.ref || inputs.ref }}
cancel-in-progress: false
jobs:
check:
uses: ./.github/workflows/check.yml
with:
ref: ${{ inputs.ref || github.sha }}
native:
uses: ./.github/workflows/native.yml
with:
ref: ${{ inputs.ref || github.sha }}
build:
needs: native
runs-on: ${{ vars.OAC_USE_GITHUB_RUNNERS == 'true' && 'ubuntu-22.04' || 'blacksmith-2vcpu-ubuntu-2204' }}
timeout-minutes: 120
outputs:
revision: ${{ steps.source.outputs.revision }}
release_tag: ${{ steps.source.outputs.release_tag }}
steps:
- uses: actions/checkout@v7
with:
ref: ${{ inputs.ref || github.sha }}
persist-credentials: false
- name: Pin source identity
id: source
env:
REQUESTED_REF: ${{ inputs.ref }}
run: |
if [[ -n "$REQUESTED_REF" && ! "$REQUESTED_REF" =~ ^[0-9a-f]{40}$ ]]; then
echo 'Manual releases require a full commit SHA' >&2
exit 1
fi
revision="$(git rev-parse HEAD)"
if [[ -n "$REQUESTED_REF" && "$REQUESTED_REF" != "$revision" ]]; then exit 1; fi
echo "revision=$revision" >> "$GITHUB_OUTPUT"
release_tag="build-$revision"
if [[ "$GITHUB_EVENT_NAME" == push ]]; then release_tag="$GITHUB_REF_NAME"; fi
echo "release_tag=$release_tag" >> "$GITHUB_OUTPUT"
- name: Reserve disk space for distribution archives
run: |
# The hosted runner needs room for Docker images, tar exports and the
# microsandbox import. This job does not use these preinstalled SDKs.
df -h /
sudo rm -rf /usr/local/lib/android /usr/share/dotnet /usr/local/.ghcup
df -h /
- name: Select shared Go caches
run: |
echo "GOCACHE=$HOME/.oac/cache/go-build" >> "$GITHUB_ENV"
echo "GOMODCACHE=$HOME/.oac/cache/go-mod" >> "$GITHUB_ENV"
- uses: actions/setup-go@v7
with:
go-version-file: go.mod
cache: false
- uses: actions/cache@v6
with:
path: |
~/.oac/cache/go-build
~/.oac/cache/go-mod
key: core-go-v2-${{ runner.os }}-${{ runner.arch }}-${{ hashFiles('**/go.mod', '**/go.sum') }}-release-${{ steps.source.outputs.revision }}
restore-keys: |
core-go-v2-${{ runner.os }}-${{ runner.arch }}-${{ hashFiles('**/go.mod', '**/go.sum') }}-release-
core-go-v2-${{ runner.os }}-${{ runner.arch }}-${{ hashFiles('**/go.mod', '**/go.sum') }}-backend-
core-go-v1-${{ runner.os }}-${{ runner.arch }}-${{ hashFiles('**/go.mod', '**/go.sum') }}-
- uses: actions/setup-node@v6
with:
node-version: '22'
- name: Install build prerequisites
run: |
npm install --global pnpm@10.30.3
sudo apt-get update
sudo apt-get install -y build-essential pkg-config libssl-dev
- name: Check release metadata and prepare pinned harnesses
run: |
PYTHONDONTWRITEBYTECODE=1 python3 scripts/core-distribution-manifest.test.py
bash scripts/prepare-release-runtimes.sh
- uses: actions/download-artifact@v6
with:
pattern: oac-native-installer-*
merge-multiple: true
path: ${{ runner.temp }}/native-artifacts
- name: Assemble the native installation catalog
run: node scripts/build-native-catalog.mjs "$RUNNER_TEMP/native-artifacts" "$RUNNER_TEMP/native-installers"
- name: Build matched artifacts
env:
OAC_NATIVE_INSTALLER_BUILD_DIR: ${{ runner.temp }}/native-installers
RELEASE_REVISION: ${{ steps.source.outputs.revision }}
RELEASE_TAG: ${{ steps.source.outputs.release_tag }}
RELEASE_REPOSITORY: ${{ github.repository }}
CORE_DISTRIBUTION_OFFLINE: ${{ (github.event_name == 'push' || inputs.offline) && '1' || '0' }}
run: |
inputs="$HOME/.oac/build/release-inputs/inputs.json"
AGENTS_RUNTIME_CODEX_PACKAGE="$(python3 -c 'import json,sys; print(json.load(open(sys.argv[1]))["codex"])' "$inputs")"
MCODE_HARNESS_BUILD_DIR="$(python3 -c 'import json,sys; print(json.load(open(sys.argv[1]))["mcode"])' "$inputs")"
export AGENTS_RUNTIME_CODEX_PACKAGE MCODE_HARNESS_BUILD_DIR
export CORE_DISTRIBUTION_RELEASE_BASE_URL="https://github.com/$RELEASE_REPOSITORY/releases/download/$RELEASE_TAG"
bash scripts/build-core-distribution.sh
mkdir -p "$HOME/.oac/build/release-upload"
for asset in "$HOME/.oac/build/core-distribution/"*; do
if [[ -f "$asset" ]]; then ln "$asset" "$HOME/.oac/build/release-upload/"; fi
done
cp deploy/install-release.sh "$HOME/.oac/build/release-upload/install.sh"
(cd "$HOME/.oac/build/release-upload" && sha256sum install.sh > install.sh.sha256)
- uses: actions/upload-artifact@v6
with:
name: core-release-${{ steps.source.outputs.revision }}
path: ~/.oac/build/release-upload/*
compression-level: 0
if-no-files-found: error
release:
if: github.event_name == 'push' || inputs.draft_release
needs: [check, build]
runs-on: ${{ vars.OAC_USE_GITHUB_RUNNERS == 'true' && 'ubuntu-22.04' || 'blacksmith-2vcpu-ubuntu-2204' }}
permissions:
contents: write
steps:
- uses: actions/checkout@v7
with:
ref: ${{ needs.build.outputs.revision }}
persist-credentials: false
- uses: actions/download-artifact@v6
with:
name: core-release-${{ needs.build.outputs.revision }}
path: release-upload
- name: Publish the version tag or create a manual draft
env:
GH_TOKEN: ${{ github.token }}
GH_REPO: ${{ github.repository }}
RELEASE_REVISION: ${{ needs.build.outputs.revision }}
RELEASE_TAG: ${{ needs.build.outputs.release_tag }}
RELEASE_MODE: ${{ github.event_name == 'push' && 'publish' || 'draft' }}
run: python3 scripts/publish-core-release.py --assets release-upload