794b840cdc
The previous commit had a literal '***' placeholder where the GitHub
Actions expression ${{ secrets.HOMEBREW_GITHUB_TOKEN }} should have
been. The workflow couldn't parse, so runs showed as 'failure' with
zero jobs and the display name fell back to the file path.
Fixed by writing the correct expression directly.
336 lines
13 KiB
YAML
336 lines
13 KiB
YAML
name: Distribute Release
|
|
|
|
# Auto-pushes new releases to package managers. Triggers on:
|
|
# - tag push (e.g. v5.9.21) — the normal release flow
|
|
# - workflow_dispatch — manual run for testing or backports
|
|
#
|
|
# Each step that needs a secret checks for it and skips gracefully with a
|
|
# clear warning if it's not set, so the workflow can be merged and tested
|
|
# before secrets are configured.
|
|
|
|
on:
|
|
push:
|
|
tags: ['v*']
|
|
workflow_dispatch:
|
|
inputs:
|
|
version:
|
|
description: 'Override version (e.g. 5.9.21). Leave blank to use tag.'
|
|
required: false
|
|
type: string
|
|
|
|
permissions:
|
|
contents: read
|
|
|
|
jobs:
|
|
version:
|
|
name: Resolve version
|
|
runs-on: ubuntu-22.04
|
|
if: github.event_name == 'workflow_dispatch' || startsWith(github.ref, 'refs/tags/v')
|
|
outputs:
|
|
version: ${{ steps.v.outputs.version }}
|
|
steps:
|
|
- id: v
|
|
run: |
|
|
if [ "${{ github.event_name }}" = "workflow_dispatch" ] && [ -n "${{ inputs.version }}" ]; then
|
|
echo "version=${{ inputs.version }}" >> $GITHUB_OUTPUT
|
|
else
|
|
echo "version=${GITHUB_REF_NAME#v}" >> $GITHUB_OUTPUT
|
|
fi
|
|
- run: echo "Distributing v${{ steps.v.outputs.version }}"
|
|
|
|
docker:
|
|
name: Docker Hub
|
|
needs: version
|
|
if: github.event_name == 'workflow_dispatch' || startsWith(github.ref, 'refs/tags/v')
|
|
runs-on: ubuntu-22.04
|
|
permissions:
|
|
contents: read
|
|
packages: write
|
|
env:
|
|
DOCKERHUB_TOKEN: ${{ secrets.DOCKERHUB_TOKEN }}
|
|
VERSION: ${{ needs.version.outputs.version }}
|
|
steps:
|
|
- uses: actions/checkout@v4
|
|
|
|
- name: Set up Docker Buildx
|
|
uses: docker/setup-buildx-action@v3
|
|
|
|
- name: Login to Docker Hub
|
|
run: |
|
|
if [ -z "$DOCKERHUB_TOKEN" ]; then
|
|
echo "::warning::DOCKERHUB_TOKEN secret not set — skipping Docker push. Add it at Settings → Secrets → Actions."
|
|
exit 0
|
|
fi
|
|
echo "$DOCKERHUB_TOKEN" | docker login -u samiahmed7777 --password-stdin
|
|
|
|
- name: Build and push
|
|
run: |
|
|
if [ -z "$DOCKERHUB_TOKEN" ]; then exit 0; fi
|
|
docker buildx build \
|
|
--push \
|
|
--tag samiahmed7777/trianglesd:$VERSION \
|
|
--tag samiahmed7777/trianglesd:latest \
|
|
--cache-from type=gha \
|
|
--cache-to type=gha,mode=max \
|
|
--provenance=false \
|
|
./packaging/docker
|
|
|
|
- name: Verify pushed image
|
|
run: |
|
|
if [ -z "$DOCKERHUB_TOKEN" ]; then exit 0; fi
|
|
docker pull samiahmed7777/trianglesd:$VERSION
|
|
echo "--- trianglesd -version ---"
|
|
docker run --rm samiahmed7777/trianglesd:$VERSION trianglesd -version 2>&1 | head -3
|
|
echo "--- triangles-cli getinfo (will fail without RPC, expected) ---"
|
|
docker run --rm samiahmed7777/trianglesd:$VERSION triangles-cli getinfo 2>&1 | head -3
|
|
|
|
aur:
|
|
name: AUR (triangles-qt-bin)
|
|
needs: version
|
|
if: github.event_name == 'workflow_dispatch' || startsWith(github.ref, 'refs/tags/v')
|
|
runs-on: ubuntu-22.04
|
|
container:
|
|
image: archlinux:latest
|
|
options: --privileged
|
|
env:
|
|
AUR_SSH_KEY: ${{ secrets.AUR_SSH_KEY }}
|
|
VERSION: ${{ needs.version.outputs.version }}
|
|
steps:
|
|
- uses: actions/checkout@v4
|
|
|
|
- name: Check AUR_SSH_KEY
|
|
run: |
|
|
if [ -z "$AUR_SSH_KEY" ]; then
|
|
echo "::warning::AUR_SSH_KEY secret not set — skipping AUR push. Add it at Settings → Secrets → Actions."
|
|
echo "::warning::The key should be the contents of ~/.ssh/aur_key (private key, not .pub)."
|
|
fi
|
|
|
|
- name: Install build tools + create non-root user
|
|
if: env.AUR_SSH_KEY != ''
|
|
run: |
|
|
pacman -Syu --noconfirm --needed git openssh base-devel python sudo
|
|
# makepkg refuses to run as root — create a build user
|
|
useradd -m -s /bin/bash build
|
|
echo 'build ALL=(ALL) NOPASSWD: ALL' >> /etc/sudoers
|
|
chown -R build:build "$GITHUB_WORKSPACE"
|
|
|
|
- name: Wait for release artifacts
|
|
if: env.AUR_SSH_KEY != ''
|
|
run: |
|
|
for i in {1..30}; do
|
|
URL="https://github.com/SamiAhmed7777/triangles_v5/releases/download/v${VERSION}/cryptographic-triangles_${VERSION}_amd64.deb"
|
|
if curl -fsSL --head "$URL" >/dev/null 2>&1; then
|
|
echo "✓ Release .deb available: $URL"
|
|
exit 0
|
|
fi
|
|
echo " waiting for release v${VERSION}... ($i/30)"
|
|
sleep 20
|
|
done
|
|
echo "::error::Release v${VERSION} .deb never became available after 10 minutes"
|
|
exit 1
|
|
|
|
- name: Download source .debs
|
|
if: env.AUR_SSH_KEY != ''
|
|
run: |
|
|
cd /tmp
|
|
curl -fsSL -o full.deb "https://github.com/SamiAhmed7777/triangles_v5/releases/download/v${VERSION}/cryptographic-triangles_${VERSION}_amd64.deb"
|
|
curl -fsSL -o daemon.deb "https://github.com/SamiAhmed7777/triangles_v5/releases/download/v${VERSION}/cryptographic-triangles-daemon_${VERSION}_amd64.deb"
|
|
ls -la /tmp/*.deb
|
|
sha256sum /tmp/full.deb /tmp/daemon.deb
|
|
|
|
- name: Update PKGBUILD with version + SHA256s
|
|
if: env.AUR_SSH_KEY != ''
|
|
run: |
|
|
cp "$GITHUB_WORKSPACE/packaging/aur/PKGBUILD" /tmp/PKGBUILD
|
|
chown build:build /tmp/PKGBUILD /tmp/full.deb /tmp/daemon.deb
|
|
sudo -u build bash -c '
|
|
set -e
|
|
cd /tmp
|
|
FULL_SHA=$(sha256sum full.deb | awk "{print \$1}")
|
|
DAEMON_SHA=$(sha256sum daemon.deb | awk "{print \$1}")
|
|
echo "version='"$VERSION"' full=$FULL_SHA daemon=$DAEMON_SHA"
|
|
python3 - <<PYEOF
|
|
import re
|
|
with open("/tmp/PKGBUILD") as f:
|
|
content = f.read()
|
|
content = re.sub(r"^pkgver=.*", "pkgver='"$VERSION"'", content, count=1, flags=re.MULTILINE)
|
|
new_shas = """sha256sums=(
|
|
'"'"'$FULL_SHA'"'"'
|
|
'"'"'$DAEMON_SHA'"'"'
|
|
'"'"'SKIP'"'"'
|
|
)"""
|
|
content = re.sub(r"sha256sums=\(.*?\)", new_shas, content, count=1, flags=re.DOTALL)
|
|
with open("/tmp/PKGBUILD", "w") as f:
|
|
f.write(content)
|
|
PYEOF
|
|
echo "--- updated PKGBUILD (pkgver + sha256sums) ---"
|
|
grep -E "^(pkgver|sha256sums)" /tmp/PKGBUILD
|
|
'
|
|
|
|
- name: Generate .SRCINFO via makepkg
|
|
if: env.AUR_SSH_KEY != ''
|
|
run: |
|
|
cp /tmp/full.deb "/tmp/cryptographic-triangles_${VERSION}_amd64.deb"
|
|
cp /tmp/daemon.deb "/tmp/cryptographic-triangles-daemon_${VERSION}_amd64.deb"
|
|
chown build:build /tmp/PKGBUILD /tmp/cryptographic-triangles-*.deb
|
|
sudo -u build bash -c '
|
|
cd /tmp
|
|
makepkg --printsrcinfo > .SRCINFO
|
|
echo "--- generated .SRCINFO ---"
|
|
cat .SRCINFO
|
|
'
|
|
|
|
- name: Setup SSH key for AUR
|
|
if: env.AUR_SSH_KEY != ''
|
|
run: |
|
|
mkdir -p /home/build/.ssh
|
|
printf '%s\n' "$AUR_SSH_KEY" > /home/build/.ssh/aur_key
|
|
chmod 600 /home/build/.ssh/aur_key
|
|
ssh-keyscan -t ed25519 aur.archlinux.org > /home/build/.ssh/known_hosts 2>/dev/null
|
|
chown -R build:build /home/build/.ssh
|
|
|
|
- name: Clone AUR repo
|
|
if: env.AUR_SSH_KEY != ''
|
|
run: |
|
|
sudo -u build bash -c '
|
|
cd /tmp
|
|
GIT_SSH_COMMAND="ssh -i ~/.ssh/aur_key -o IdentitiesOnly=yes" \
|
|
git clone ssh://aur@aur.archlinux.org/triangles-qt-bin.git
|
|
ls -la /tmp/triangles-qt-bin
|
|
'
|
|
|
|
- name: Stage updated files
|
|
if: env.AUR_SSH_KEY != ''
|
|
run: |
|
|
cp /tmp/PKGBUILD /tmp/triangles-qt-bin/PKGBUILD
|
|
cp /tmp/.SRCINFO /tmp/triangles-qt-bin/.SRCINFO
|
|
cp "$GITHUB_WORKSPACE/packaging/aur/triangles-qt.desktop" /tmp/triangles-qt-bin/triangles-qt.desktop
|
|
chown -R build:build /tmp/triangles-qt-bin
|
|
sudo -u build bash -c '
|
|
cd /tmp/triangles-qt-bin
|
|
git --no-pager diff --stat
|
|
'
|
|
|
|
- name: Commit and push to AUR
|
|
if: env.AUR_SSH_KEY != ''
|
|
run: |
|
|
sudo -u build bash -c '
|
|
cd /tmp/triangles-qt-bin
|
|
git config user.name "Sami Ahmed"
|
|
git config user.email "SamiAhmed7777@users.noreply.github.com"
|
|
git add PKGBUILD .SRCINFO triangles-qt.desktop
|
|
if git diff --cached --quiet; then
|
|
echo "No changes to commit (AUR already at this version)"
|
|
exit 0
|
|
fi
|
|
git commit -m "triangles-qt-bin '"$VERSION"'-1"
|
|
GIT_SSH_COMMAND="ssh -i ~/.ssh/aur_key -o IdentitiesOnly=yes" \
|
|
git push origin master
|
|
'
|
|
|
|
- name: ✓ Summary
|
|
if: always()
|
|
run: |
|
|
if [ -z "$AUR_SSH_KEY" ]; then
|
|
echo "::notice::AUR job was skipped because AUR_SSH_KEY is not set."
|
|
else
|
|
echo "::notice::AUR distribution completed."
|
|
fi
|
|
|
|
homebrew:
|
|
name: Homebrew tap (SamiAhmed7777/homebrew-triangles)
|
|
needs: version
|
|
if: github.event_name == 'workflow_dispatch' || startsWith(github.ref, 'refs/tags/v')
|
|
runs-on: ubuntu-22.04
|
|
env:
|
|
HOMEBREW_GITHUB_TOKEN: ${{ secrets.HOMEBREW_GITHUB_TOKEN }}
|
|
VERSION: ${{ needs.version.outputs.version }}
|
|
steps:
|
|
- name: Check HOMEBREW_GITHUB_TOKEN
|
|
run: |
|
|
if [ -z "$HOMEBREW_GITHUB_TOKEN" ]; then
|
|
echo "::warning::HOMEBREW_GITHUB_TOKEN secret not set — skipping Homebrew push. Add it at Settings → Secrets → Actions."
|
|
echo "::warning::Use a GitHub PAT with 'repo' scope for SamiAhmed7777/homebrew-triangles."
|
|
fi
|
|
|
|
- name: Wait for release artifacts
|
|
if: env.HOMEBREW_GITHUB_TOKEN != ''
|
|
run: |
|
|
for i in {1..30}; do
|
|
URL="https://github.com/SamiAhmed7777/triangles_v5/releases/download/v${VERSION}/Cryptographic-Triangles-v${VERSION}-macos-arm64.dmg"
|
|
if curl -fsSL --head "$URL" >/dev/null 2>&1; then
|
|
echo "✓ Release .dmg available: $URL"
|
|
exit 0
|
|
fi
|
|
echo " waiting for release v${VERSION}... ($i/30)"
|
|
sleep 20
|
|
done
|
|
echo "::error::Release v${VERSION} macOS .dmg never became available"
|
|
exit 1
|
|
|
|
- name: Compute macOS .dmg SHA256
|
|
if: env.HOMEBREW_GITHUB_TOKEN != ''
|
|
id: sha
|
|
run: |
|
|
curl -fsSL -o /tmp/triangles.dmg \
|
|
"https://github.com/SamiAhmed7777/triangles_v5/releases/download/v${VERSION}/Cryptographic-Triangles-v${VERSION}-macos-arm64.dmg"
|
|
SHA=$(sha256sum /tmp/triangles.dmg | awk '{print $1}')
|
|
echo "sha=$SHA" >> $GITHUB_OUTPUT
|
|
echo "macOS .dmg SHA256: $SHA"
|
|
|
|
- name: Clone homebrew-triangles
|
|
if: env.HOMEBREW_GITHUB_TOKEN != ''
|
|
run: |
|
|
git clone https://x-access-token:$HOMEBREW_GITHUB_TOKEN@github.com/SamiAhmed7777/homebrew-triangles.git /tmp/homebrew-triangles
|
|
cd /tmp/homebrew-triangles
|
|
git --no-pager log --oneline | head -3
|
|
|
|
- name: Update Formula and Cask
|
|
if: env.HOMEBREW_GITHUB_TOKEN != ''
|
|
env:
|
|
VERSION: ${{ needs.version.outputs.version }}
|
|
SHA: ${{ steps.sha.outputs.sha }}
|
|
run: |
|
|
cd /tmp/homebrew-triangles
|
|
# Update Casks/cryptographic-triangles.rb
|
|
python3 - <<PYEOF
|
|
import re
|
|
for path, old_v_pat, old_sha_pat in [
|
|
('Casks/cryptographic-triangles.rb', r'^\s*version\s+"[\d.]+"', r'^\s*sha256\s+"[a-f0-9]+"'),
|
|
('Formula/triangles.rb', r'^\s*version\s+"[\d.]+"', r'^\s*sha256\s+"[a-f0-9]+"'),
|
|
]:
|
|
with open(path) as f: content = f.read()
|
|
content = re.sub(old_v_pat, f' version "$VERSION"', content, count=1, flags=re.MULTILINE)
|
|
content = re.sub(old_sha_pat, f' sha256 "$SHA"', content, count=1, flags=re.MULTILINE)
|
|
with open(path, 'w') as f: f.write(content)
|
|
PYEOF
|
|
cat Formula/triangles.rb | head -5
|
|
echo "---"
|
|
cat Casks/cryptographic-triangles.rb | head -5
|
|
git --no-pager diff --stat
|
|
|
|
- name: Commit and push
|
|
if: env.HOMEBREW_GITHUB_TOKEN != ''
|
|
env:
|
|
VERSION: ${{ needs.version.outputs.version }}
|
|
run: |
|
|
cd /tmp/homebrew-triangles
|
|
git config user.name "Sami Ahmed"
|
|
git config user.email "SamiAhmed7777@users.noreply.github.com"
|
|
git add Formula/triangles.rb Casks/cryptographic-triangles.rb
|
|
if git diff --cached --quiet; then
|
|
echo "No changes to commit (Homebrew tap already at this version)"
|
|
exit 0
|
|
fi
|
|
git commit -m "triangles ${VERSION}"
|
|
git push origin main
|
|
|
|
- name: ✓ Summary
|
|
if: always()
|
|
run: |
|
|
if [ -z "$HOMEBREW_GITHUB_TOKEN" ]; then
|
|
echo "::notice::Homebrew job was skipped because HOMEBREW_GITHUB_TOKEN is not set."
|
|
else
|
|
echo "::notice::Homebrew distribution completed."
|
|
fi
|