name: release # Native aarch64 build on the Pi runner, published to the Forgejo release. # x86_64 is NOT built here: there is no x86_64 runner on this instance — build # it on an x86_64 host with scripts/build-release-local.sh (same release, same # asset naming), or the release will carry aarch64 only. on: push: tags: - "v*.*.*" workflow_dispatch: inputs: tag: description: Existing tag to (re)build and publish required: true env: CARGO_TERM_COLOR: never TARGET: aarch64-unknown-linux-gnu # Job steps run inside node:20-bullseye (the runner's docker label image) with # the host docker socket mounted, so builds happen in a sibling rust container. RUST_IMAGE: rust:1.91-bookworm CARGO_REGISTRY_VOLUME: onionwire-cargo-registry CARGO_TARGET_VOLUME: onionwire-target-aarch64 BUILD_CONTAINER: onionwire-release-build jobs: aarch64: runs-on: docker timeout-minutes: 120 steps: - name: Checkout the source tag uses: https://code.forgejo.org/actions/checkout@v4 with: # A tag push builds that tag; a manual dispatch builds the tag the # caller named (otherwise the binary version would not match the # release it is attached to). ref: ${{ github.event.inputs.tag || github.ref_name }} - name: Checkout the CI tooling uses: https://code.forgejo.org/actions/checkout@v4 with: # scripts/ and .forgejo/ only exist on the branch (older tags predate # them), and the workflow itself is read from the dispatched ref — so # fetch the same ref into .ci-tools and run the scripts from there. ref: ${{ github.ref_name }} path: .ci-tools - name: Build ${{ env.TARGET }} in a rust container run: | set -euo pipefail cd "${GITHUB_WORKSPACE}" echo "workspace: $GITHUB_WORKSPACE" docker volume create "$CARGO_REGISTRY_VOLUME" > /dev/null docker volume create "$CARGO_TARGET_VOLUME" > /dev/null docker rm -f "$BUILD_CONTAINER" > /dev/null 2>&1 || true # The workspace lives in a per-task volume the host daemon cannot # resolve, so pipe the source tree in over stdin (tar) and pull the # binary back out with docker cp. docker create --name "$BUILD_CONTAINER" -i \ -e CARGO_TARGET_DIR=/target \ -e CARGO_BUILD_JOBS=2 \ -e CARGO_TERM_COLOR=never \ -v "$CARGO_REGISTRY_VOLUME":/usr/local/cargo/registry \ -v "$CARGO_TARGET_VOLUME":/target \ -w /src \ "$RUST_IMAGE" \ sh -euxc 'mkdir -p /src && tar xzf - -C /src && cd /src \ && apt-get update \ && apt-get install -y --no-install-recommends pkg-config libssl-dev \ && cargo build --release --locked \ && strip /target/release/onionwire \ && ls -l /target/release/onionwire' tar czf - --exclude=./target --exclude=./.git --exclude=./.worktrees \ --exclude=./.ci-tools . \ | docker start -a -i "$BUILD_CONTAINER" mkdir -p dist docker cp "$BUILD_CONTAINER:/target/release/onionwire" "dist/onionwire-$TARGET" docker rm -f "$BUILD_CONTAINER" > /dev/null - name: Pack and checksum run: | set -euo pipefail cd "${GITHUB_WORKSPACE}/dist" file "onionwire-$TARGET" sha256sum "onionwire-$TARGET" > "onionwire-$TARGET.sha256" sha256sum -c "onionwire-$TARGET.sha256" ls -l - name: Publish to the Forgejo release env: FORGEJO_TOKEN: ${{ secrets.FORGEJO_TOKEN }} REPO_API: ${{ github.server_url }}/api/v1/repos/${{ github.repository }} EVENT_NAME: ${{ github.event_name }} EVENT_SHA: ${{ github.sha }} REF: ${{ github.ref_name }} INPUT_TAG: ${{ github.event.inputs.tag }} run: | set -euo pipefail cd "${GITHUB_WORKSPACE}" echo "pwd=$PWD workspace=$GITHUB_WORKSPACE" ls -l dist/ 2>&1 || true for f in dist/*; do printf 'on disk: %s %s bytes\n' "$f" "$(wc -c < "$f")"; done tag="${INPUT_TAG:-$REF}" # Only a tag push may create the tag; a re-publish must not move it. if [ "$EVENT_NAME" = "push" ]; then export TARGET_COMMITISH="$EVENT_SHA"; fi echo "publishing $tag from $REPO_API (event=$EVENT_NAME)" .ci-tools/scripts/publish-release.sh \ "$tag" "OnionWire $tag" \ .ci-tools/scripts/release-body.md \ "dist/onionwire-$TARGET" "dist/onionwire-$TARGET.sha256"