-
Notifications
You must be signed in to change notification settings - Fork 8
163 lines (157 loc) · 7.01 KB
/
Copy pathrelease.yml
File metadata and controls
163 lines (157 loc) · 7.01 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
130
131
132
133
134
135
136
137
138
139
140
141
142
143
144
145
146
147
148
149
150
151
152
153
154
155
156
157
158
159
160
161
162
163
name: core-release
on:
push:
tags: ['v*']
workflow_dispatch:
inputs:
ref:
description: Full source commit SHA to build
required: true
type: string
offline:
description: Also create the full offline archive
default: true
type: boolean
draft_release:
description: Upload files to a new draft release; never publish
default: false
type: boolean
permissions:
contents: read
concurrency:
group: core-release-${{ github.event_name == 'push' && github.ref || inputs.ref }}
cancel-in-progress: false
jobs:
check:
uses: ./.github/workflows/check.yml
with:
ref: ${{ inputs.ref || github.sha }}
native-artifacts: true
build:
needs: check
runs-on: blacksmith-4vcpu-ubuntu-2204
timeout-minutes: 120
permissions:
contents: write
packages: write
steps:
- uses: actions/checkout@v7
with:
ref: ${{ inputs.ref || github.sha }}
persist-credentials: false
- name: Pin source identity
id: source
env:
REQUESTED_REF: ${{ inputs.ref }}
run: |
if [[ -n "$REQUESTED_REF" && ! "$REQUESTED_REF" =~ ^[0-9a-f]{40}$ ]]; then
echo 'Manual releases require a full commit SHA' >&2
exit 1
fi
revision="$(git rev-parse HEAD)"
if [[ -n "$REQUESTED_REF" && "$REQUESTED_REF" != "$revision" ]]; then exit 1; fi
echo "revision=$revision" >> "$GITHUB_OUTPUT"
release_tag="build-$revision"
if [[ "$GITHUB_EVENT_NAME" == push ]]; then release_tag="$GITHUB_REF_NAME"; fi
echo "release_tag=$release_tag" >> "$GITHUB_OUTPUT"
- name: Reserve disk space for distribution archives
run: |
# The hosted runner needs room for Docker images, tar exports and the
# microsandbox import. This job does not use these preinstalled SDKs.
df -h /
sudo rm -rf /usr/local/lib/android /usr/share/dotnet /usr/local/.ghcup
df -h /
- name: Select shared Go caches
run: |
echo "GOCACHE=$HOME/.oac/cache/go-build" >> "$GITHUB_ENV"
echo "GOMODCACHE=$HOME/.oac/cache/go-mod" >> "$GITHUB_ENV"
- uses: actions/setup-go@v7
with:
go-version-file: go.mod
cache: false
- uses: actions/cache@v6
with:
path: |
~/.oac/cache/go-build
~/.oac/cache/go-mod
key: core-go-v2-${{ runner.os }}-${{ runner.arch }}-${{ hashFiles('**/go.mod', '**/go.sum') }}-release-${{ steps.source.outputs.revision }}
restore-keys: |
core-go-v2-${{ runner.os }}-${{ runner.arch }}-${{ hashFiles('**/go.mod', '**/go.sum') }}-release-
core-go-v2-${{ runner.os }}-${{ runner.arch }}-${{ hashFiles('**/go.mod', '**/go.sum') }}-backend-
core-go-v1-${{ runner.os }}-${{ runner.arch }}-${{ hashFiles('**/go.mod', '**/go.sum') }}-
- uses: ./.github/actions/node
with:
lockfiles: |
apps/web/pnpm-lock.yaml
packages/agents-client/pnpm-lock.yaml
packages/claude-sdk-adapter/pnpm-lock.yaml
- name: Install build prerequisites
run: |
sudo apt-get update
sudo apt-get install -y build-essential pkg-config libssl-dev pigz
- name: Cache pinned release downloads
uses: actions/cache@v6
with:
path: |
~/.npm/_cacache
~/.oac/cache/microsandbox-v0.7.2-linux-x86_64.tar.gz
key: release-downloads-v1-${{ runner.os }}-${{ runner.arch }}-${{ hashFiles('scripts/prepare-release-runtimes.sh', 'packages/mcode-harness/source.json', 'scripts/core-distribution-manifest.py') }}
restore-keys: |
release-downloads-v1-${{ runner.os }}-${{ runner.arch }}-
- name: Check release metadata and prepare pinned harnesses
run: |
PYTHONDONTWRITEBYTECODE=1 python3 scripts/core-distribution-manifest.test.py
bash scripts/prepare-release-runtimes.sh
- uses: actions/download-artifact@v6
with:
pattern: oac-native-installer-*
merge-multiple: true
path: ${{ runner.temp }}/native-artifacts
- name: Assemble the native installation catalog
run: node scripts/build-native-catalog.mjs "$RUNNER_TEMP/native-artifacts" "$RUNNER_TEMP/native-installers"
- name: Build matched artifacts
env:
OAC_NATIVE_INSTALLER_BUILD_DIR: ${{ runner.temp }}/native-installers
RELEASE_REVISION: ${{ steps.source.outputs.revision }}
RELEASE_TAG: ${{ steps.source.outputs.release_tag }}
RELEASE_REPOSITORY: ${{ github.repository }}
CORE_DISTRIBUTION_OFFLINE: ${{ (github.event_name == 'push' || inputs.offline) && '1' || '0' }}
run: |
inputs="$HOME/.oac/build/release-inputs/inputs.json"
AGENTS_RUNTIME_CODEX_PACKAGE="$(python3 -c 'import json,sys; print(json.load(open(sys.argv[1]))["codex"])' "$inputs")"
MCODE_HARNESS_BUILD_DIR="$(python3 -c 'import json,sys; print(json.load(open(sys.argv[1]))["mcode"])' "$inputs")"
export AGENTS_RUNTIME_CODEX_PACKAGE MCODE_HARNESS_BUILD_DIR
export CORE_DISTRIBUTION_RELEASE_BASE_URL="https://github.com/$RELEASE_REPOSITORY/releases/download/$RELEASE_TAG"
bash scripts/build-core-distribution.sh
mkdir -p "$HOME/.oac/build/release-upload"
for asset in "$HOME/.oac/build/core-distribution/"*; do
if [[ -f "$asset" ]]; then ln "$asset" "$HOME/.oac/build/release-upload/"; fi
done
cp deploy/install-release.sh "$HOME/.oac/build/release-upload/install.sh"
(cd "$HOME/.oac/build/release-upload" && sha256sum install.sh > install.sh.sha256)
- uses: actions/upload-artifact@v6
with:
name: core-release-${{ steps.source.outputs.revision }}
path: ~/.oac/build/release-upload/*
compression-level: 0
if-no-files-found: error
- name: Sign in to GHCR for version releases
if: github.event_name == 'push'
env:
GHCR_TOKEN: ${{ secrets.GITHUB_TOKEN }}
run: |
export DOCKER_CONFIG="$RUNNER_TEMP/oac-release-docker"
echo "DOCKER_CONFIG=$DOCKER_CONFIG" >> "$GITHUB_ENV"
printf '%s' "$GHCR_TOKEN" | docker login ghcr.io --username "$GITHUB_ACTOR" --password-stdin
- name: Publish the version tag or create a manual draft
if: github.event_name == 'push' || inputs.draft_release
env:
GH_TOKEN: ${{ github.token }}
GH_REPO: ${{ github.repository }}
RELEASE_REVISION: ${{ steps.source.outputs.revision }}
RELEASE_TAG: ${{ steps.source.outputs.release_tag }}
RELEASE_MODE: ${{ github.event_name == 'push' && 'publish' || 'draft' }}
run: python3 scripts/publish-core-release.py --assets "$HOME/.oac/build/release-upload"
- name: Remove registry credentials
if: always() && github.event_name == 'push'
run: rm -f "$RUNNER_TEMP/oac-release-docker/config.json"