onionwire/.forgejo/workflows/release.yml
Sirius DevOps 154bed7823
Some checks failed
ci / test (push) Successful in 3m47s
release / aarch64 (push) Failing after 5m25s
fix(ci): clippy clean on tests/hs.rs + pin step cwd to GITHUB_WORKSPACE
Two separate breakages from the first green-ish CI run:

1. tests/hs.rs asserted on a constant, which clippy rejects under
   -D warnings (clippy::assertions_on_constants) because the compiler
   folds the assert away. Compare through a runtime binding instead.

2. The release workflow built the aarch64 binary fine (13m02s, verified
   ARM ELF) but the publish step died with:
       /var/run/act/workflow/3: line 6: scripts/publish-release.sh: No such file or directory
   run: steps execute with act's cwd, not the repo root, so relative
   paths miss. Pin every run step with cd "${GITHUB_WORKSPACE}" (the
   pattern the osint-dashboard workflow already relies on).

Verified locally before pushing: cargo test 41 passed, cargo clippy
--all-targets -- -D warnings clean.
2026-09-10 13:50:57 -04:00

95 lines
3.7 KiB
YAML

name: release
# Native aarch64 build on the Pi runner, published to the Forgejo release.
# x86_64 is NOT built here: there is no x86_64 runner on this instance — build
# it on an x86_64 host with scripts/build-release-local.sh (same release, same
# asset naming), or the release will carry aarch64 only.
on:
push:
tags:
- "v*.*.*"
workflow_dispatch:
inputs:
tag:
description: Existing tag to (re)build and publish
required: true
env:
CARGO_TERM_COLOR: never
TARGET: aarch64-unknown-linux-gnu
# Job steps run inside node:20-bullseye (the runner's docker label image) with
# the host docker socket mounted, so builds happen in a sibling rust container.
RUST_IMAGE: rust:1.91-bookworm
CARGO_REGISTRY_VOLUME: onionwire-cargo-registry
CARGO_TARGET_VOLUME: onionwire-target-aarch64
BUILD_CONTAINER: onionwire-release-build
jobs:
aarch64:
runs-on: docker
timeout-minutes: 120
steps:
- name: Checkout
uses: https://code.forgejo.org/actions/checkout@v4
with:
# A tag push builds that tag; a manual dispatch builds the tag the
# caller named (otherwise the binary version would not match the
# release it is attached to).
ref: ${{ github.event.inputs.tag || github.ref_name }}
- name: Build ${{ env.TARGET }} in a rust container
run: |
set -euo pipefail
cd "${GITHUB_WORKSPACE}"
echo "workspace: $GITHUB_WORKSPACE"
docker volume create "$CARGO_REGISTRY_VOLUME" > /dev/null
docker volume create "$CARGO_TARGET_VOLUME" > /dev/null
docker rm -f "$BUILD_CONTAINER" > /dev/null 2>&1 || true
# The workspace lives in a per-task volume the host daemon cannot
# resolve, so pipe the source tree in over stdin (tar) and pull the
# binary back out with docker cp.
docker create --name "$BUILD_CONTAINER" -i \
-e CARGO_TARGET_DIR=/target \
-e CARGO_BUILD_JOBS=2 \
-e CARGO_TERM_COLOR=never \
-v "$CARGO_REGISTRY_VOLUME":/usr/local/cargo/registry \
-v "$CARGO_TARGET_VOLUME":/target \
-w /src \
"$RUST_IMAGE" \
sh -euxc 'mkdir -p /src && tar xzf - -C /src && cd /src \
&& apt-get update \
&& apt-get install -y --no-install-recommends pkg-config libssl-dev \
&& cargo build --release --locked \
&& strip /target/release/onionwire \
&& ls -l /target/release/onionwire'
tar czf - --exclude=./target --exclude=./.git --exclude=./.worktrees . \
| docker start -a -i "$BUILD_CONTAINER"
mkdir -p dist
docker cp "$BUILD_CONTAINER:/target/release/onionwire" "dist/onionwire-$TARGET"
docker rm -f "$BUILD_CONTAINER" > /dev/null
- name: Pack and checksum
run: |
set -euo pipefail
cd "${GITHUB_WORKSPACE}/dist"
file "onionwire-$TARGET"
sha256sum "onionwire-$TARGET" > "onionwire-$TARGET.sha256"
sha256sum -c "onionwire-$TARGET.sha256"
ls -l
- name: Publish to the Forgejo release
env:
FORGEJO_TOKEN: ${{ secrets.FORGEJO_TOKEN }}
TARGET_COMMITISH: ${{ github.sha }}
REPO_API: ${{ github.server_url }}/api/v1/repos/${{ github.repository }}
REF: ${{ github.ref_name }}
INPUT_TAG: ${{ github.event.inputs.tag }}
run: |
set -euo pipefail
cd "${GITHUB_WORKSPACE}"
tag="${INPUT_TAG:-$REF}"
echo "publishing $tag from $REPO_API"
scripts/publish-release.sh \
"$tag" "OnionWire $tag" \
scripts/release-body.md \
"dist/onionwire-$TARGET" "dist/onionwire-$TARGET.sha256"