8b147317d5
New 'homebrew' job in distribute.yml: - Waits for the macOS .dmg to be available on the GitHub release - Computes the new SHA256 - Clones SamiAhmed7777/homebrew-triangles - Updates version + sha256 in both Formula/triangles.rb and Casks/cryptographic-triangles.rb - Commits and pushes to main - Skips gracefully with a warning if HOMEBREW_GITHUB_TOKEN is not set Required GitHub secret: HOMEBREW_GITHUB_TOKEN (added)
332 lines
12 KiB
YAML
332 lines
12 KiB
YAML
name: Distribute Release
|
|
|
|
# Auto-pushes new releases to package managers. Triggers on:
|
|
# - tag push (e.g. v5.9.21) — the normal release flow
|
|
# - workflow_dispatch — manual run for testing or backports
|
|
#
|
|
# Each step that needs a secret checks for it and skips gracefully with a
|
|
# clear warning if it's not set, so the workflow can be merged and tested
|
|
# before secrets are configured.
|
|
|
|
on:
|
|
push:
|
|
tags: ['v*']
|
|
workflow_dispatch:
|
|
inputs:
|
|
version:
|
|
description: 'Override version (e.g. 5.9.21). Leave blank to use tag.'
|
|
required: false
|
|
type: string
|
|
|
|
permissions:
|
|
contents: read
|
|
|
|
jobs:
|
|
version:
|
|
name: Resolve version
|
|
runs-on: ubuntu-22.04
|
|
outputs:
|
|
version: ${{ steps.v.outputs.version }}
|
|
steps:
|
|
- id: v
|
|
run: |
|
|
if [ "${{ github.event_name }}" = "workflow_dispatch" ] && [ -n "${{ inputs.version }}" ]; then
|
|
echo "version=${{ inputs.version }}" >> $GITHUB_OUTPUT
|
|
else
|
|
echo "version=${GITHUB_REF_NAME#v}" >> $GITHUB_OUTPUT
|
|
fi
|
|
- run: echo "Distributing v${{ steps.v.outputs.version }}"
|
|
|
|
docker:
|
|
name: Docker Hub
|
|
needs: version
|
|
runs-on: ubuntu-22.04
|
|
permissions:
|
|
contents: read
|
|
packages: write
|
|
env:
|
|
DOCKERHUB_TOKEN: ${{ secrets.DOCKERHUB_TOKEN }}
|
|
VERSION: ${{ needs.version.outputs.version }}
|
|
steps:
|
|
- uses: actions/checkout@v4
|
|
|
|
- name: Set up Docker Buildx
|
|
uses: docker/setup-buildx-action@v3
|
|
|
|
- name: Login to Docker Hub
|
|
run: |
|
|
if [ -z "$DOCKERHUB_TOKEN" ]; then
|
|
echo "::warning::DOCKERHUB_TOKEN secret not set — skipping Docker push. Add it at Settings → Secrets → Actions."
|
|
exit 0
|
|
fi
|
|
echo "$DOCKERHUB_TOKEN" | docker login -u samiahmed7777 --password-stdin
|
|
|
|
- name: Build and push
|
|
run: |
|
|
if [ -z "$DOCKERHUB_TOKEN" ]; then exit 0; fi
|
|
docker buildx build \
|
|
--push \
|
|
--tag samiahmed7777/trianglesd:$VERSION \
|
|
--tag samiahmed7777/trianglesd:latest \
|
|
--cache-from type=gha \
|
|
--cache-to type=gha,mode=max \
|
|
--provenance=false \
|
|
./packaging/docker
|
|
|
|
- name: Verify pushed image
|
|
run: |
|
|
if [ -z "$DOCKERHUB_TOKEN" ]; then exit 0; fi
|
|
docker pull samiahmed7777/trianglesd:$VERSION
|
|
echo "--- trianglesd -version ---"
|
|
docker run --rm samiahmed7777/trianglesd:$VERSION trianglesd -version 2>&1 | head -3
|
|
echo "--- triangles-cli getinfo (will fail without RPC, expected) ---"
|
|
docker run --rm samiahmed7777/trianglesd:$VERSION triangles-cli getinfo 2>&1 | head -3
|
|
|
|
aur:
|
|
name: AUR (triangles-qt-bin)
|
|
needs: version
|
|
runs-on: ubuntu-22.04
|
|
container:
|
|
image: archlinux:latest
|
|
options: --privileged
|
|
env:
|
|
AUR_SSH_KEY: ${{ secrets.AUR_SSH_KEY }}
|
|
VERSION: ${{ needs.version.outputs.version }}
|
|
steps:
|
|
- uses: actions/checkout@v4
|
|
|
|
- name: Check AUR_SSH_KEY
|
|
run: |
|
|
if [ -z "$AUR_SSH_KEY" ]; then
|
|
echo "::warning::AUR_SSH_KEY secret not set — skipping AUR push. Add it at Settings → Secrets → Actions."
|
|
echo "::warning::The key should be the contents of ~/.ssh/aur_key (private key, not .pub)."
|
|
fi
|
|
|
|
- name: Install build tools + create non-root user
|
|
if: env.AUR_SSH_KEY != ''
|
|
run: |
|
|
pacman -Syu --noconfirm --needed git openssh base-devel python sudo
|
|
# makepkg refuses to run as root — create a build user
|
|
useradd -m -s /bin/bash build
|
|
echo 'build ALL=(ALL) NOPASSWD: ALL' >> /etc/sudoers
|
|
chown -R build:build "$GITHUB_WORKSPACE"
|
|
|
|
- name: Wait for release artifacts
|
|
if: env.AUR_SSH_KEY != ''
|
|
run: |
|
|
for i in {1..30}; do
|
|
URL="https://github.com/SamiAhmed7777/triangles_v5/releases/download/v${VERSION}/cryptographic-triangles_${VERSION}_amd64.deb"
|
|
if curl -fsSL --head "$URL" >/dev/null 2>&1; then
|
|
echo "✓ Release .deb available: $URL"
|
|
exit 0
|
|
fi
|
|
echo " waiting for release v${VERSION}... ($i/30)"
|
|
sleep 20
|
|
done
|
|
echo "::error::Release v${VERSION} .deb never became available after 10 minutes"
|
|
exit 1
|
|
|
|
- name: Download source .debs
|
|
if: env.AUR_SSH_KEY != ''
|
|
run: |
|
|
cd /tmp
|
|
curl -fsSL -o full.deb "https://github.com/SamiAhmed7777/triangles_v5/releases/download/v${VERSION}/cryptographic-triangles_${VERSION}_amd64.deb"
|
|
curl -fsSL -o daemon.deb "https://github.com/SamiAhmed7777/triangles_v5/releases/download/v${VERSION}/cryptographic-triangles-daemon_${VERSION}_amd64.deb"
|
|
ls -la /tmp/*.deb
|
|
sha256sum /tmp/full.deb /tmp/daemon.deb
|
|
|
|
- name: Update PKGBUILD with version + SHA256s
|
|
if: env.AUR_SSH_KEY != ''
|
|
run: |
|
|
cp "$GITHUB_WORKSPACE/packaging/aur/PKGBUILD" /tmp/PKGBUILD
|
|
chown build:build /tmp/PKGBUILD /tmp/full.deb /tmp/daemon.deb
|
|
sudo -u build bash -c '
|
|
set -e
|
|
cd /tmp
|
|
FULL_SHA=$(sha256sum full.deb | awk "{print \$1}")
|
|
DAEMON_SHA=$(sha256sum daemon.deb | awk "{print \$1}")
|
|
echo "version='"$VERSION"' full=$FULL_SHA daemon=$DAEMON_SHA"
|
|
python3 - <<PYEOF
|
|
import re
|
|
with open("/tmp/PKGBUILD") as f:
|
|
content = f.read()
|
|
content = re.sub(r"^pkgver=.*", "pkgver='"$VERSION"'", content, count=1, flags=re.MULTILINE)
|
|
new_shas = """sha256sums=(
|
|
'"'"'$FULL_SHA'"'"'
|
|
'"'"'$DAEMON_SHA'"'"'
|
|
'"'"'SKIP'"'"'
|
|
)"""
|
|
content = re.sub(r"sha256sums=\(.*?\)", new_shas, content, count=1, flags=re.DOTALL)
|
|
with open("/tmp/PKGBUILD", "w") as f:
|
|
f.write(content)
|
|
PYEOF
|
|
echo "--- updated PKGBUILD (pkgver + sha256sums) ---"
|
|
grep -E "^(pkgver|sha256sums)" /tmp/PKGBUILD
|
|
'
|
|
|
|
- name: Generate .SRCINFO via makepkg
|
|
if: env.AUR_SSH_KEY != ''
|
|
run: |
|
|
cp /tmp/full.deb "/tmp/cryptographic-triangles_${VERSION}_amd64.deb"
|
|
cp /tmp/daemon.deb "/tmp/cryptographic-triangles-daemon_${VERSION}_amd64.deb"
|
|
chown build:build /tmp/PKGBUILD /tmp/cryptographic-triangles-*.deb
|
|
sudo -u build bash -c '
|
|
cd /tmp
|
|
makepkg --printsrcinfo > .SRCINFO
|
|
echo "--- generated .SRCINFO ---"
|
|
cat .SRCINFO
|
|
'
|
|
|
|
- name: Setup SSH key for AUR
|
|
if: env.AUR_SSH_KEY != ''
|
|
run: |
|
|
mkdir -p /home/build/.ssh
|
|
printf '%s\n' "$AUR_SSH_KEY" > /home/build/.ssh/aur_key
|
|
chmod 600 /home/build/.ssh/aur_key
|
|
ssh-keyscan -t ed25519 aur.archlinux.org > /home/build/.ssh/known_hosts 2>/dev/null
|
|
chown -R build:build /home/build/.ssh
|
|
|
|
- name: Clone AUR repo
|
|
if: env.AUR_SSH_KEY != ''
|
|
run: |
|
|
sudo -u build bash -c '
|
|
cd /tmp
|
|
GIT_SSH_COMMAND="ssh -i ~/.ssh/aur_key -o IdentitiesOnly=yes" \
|
|
git clone ssh://aur@aur.archlinux.org/triangles-qt-bin.git
|
|
ls -la /tmp/triangles-qt-bin
|
|
'
|
|
|
|
- name: Stage updated files
|
|
if: env.AUR_SSH_KEY != ''
|
|
run: |
|
|
cp /tmp/PKGBUILD /tmp/triangles-qt-bin/PKGBUILD
|
|
cp /tmp/.SRCINFO /tmp/triangles-qt-bin/.SRCINFO
|
|
cp "$GITHUB_WORKSPACE/packaging/aur/triangles-qt.desktop" /tmp/triangles-qt-bin/triangles-qt.desktop
|
|
chown -R build:build /tmp/triangles-qt-bin
|
|
sudo -u build bash -c '
|
|
cd /tmp/triangles-qt-bin
|
|
git --no-pager diff --stat
|
|
'
|
|
|
|
- name: Commit and push to AUR
|
|
if: env.AUR_SSH_KEY != ''
|
|
run: |
|
|
sudo -u build bash -c '
|
|
cd /tmp/triangles-qt-bin
|
|
git config user.name "Sami Ahmed"
|
|
git config user.email "SamiAhmed7777@users.noreply.github.com"
|
|
git add PKGBUILD .SRCINFO triangles-qt.desktop
|
|
if git diff --cached --quiet; then
|
|
echo "No changes to commit (AUR already at this version)"
|
|
exit 0
|
|
fi
|
|
git commit -m "triangles-qt-bin '"$VERSION"'-1"
|
|
GIT_SSH_COMMAND="ssh -i ~/.ssh/aur_key -o IdentitiesOnly=yes" \
|
|
git push origin master
|
|
'
|
|
|
|
- name: ✓ Summary
|
|
if: always()
|
|
run: |
|
|
if [ -z "$AUR_SSH_KEY" ]; then
|
|
echo "::notice::AUR job was skipped because AUR_SSH_KEY is not set."
|
|
else
|
|
echo "::notice::AUR distribution completed."
|
|
fi
|
|
|
|
homebrew:
|
|
name: Homebrew tap (SamiAhmed7777/homebrew-triangles)
|
|
needs: version
|
|
runs-on: ubuntu-22.04
|
|
env:
|
|
HOMEBREW_GITHUB_TOKEN: *** secrets.HOMEBREW_GITHUB_TOKEN }}
|
|
VERSION: ${{ needs.version.outputs.version }}
|
|
steps:
|
|
- name: Check HOMEBREW_GITHUB_TOKEN
|
|
run: |
|
|
if [ -z "$HOMEBREW_GITHUB_TOKEN" ]; then
|
|
echo "::warning::HOMEBREW_GITHUB_TOKEN secret not set — skipping Homebrew push. Add it at Settings → Secrets → Actions."
|
|
echo "::warning::Use a GitHub PAT with 'repo' scope for SamiAhmed7777/homebrew-triangles."
|
|
fi
|
|
|
|
- name: Wait for release artifacts
|
|
if: env.HOMEBREW_GITHUB_TOKEN != ''
|
|
run: |
|
|
for i in {1..30}; do
|
|
URL="https://github.com/SamiAhmed7777/triangles_v5/releases/download/v${VERSION}/Cryptographic-Triangles-v${VERSION}-macos-arm64.dmg"
|
|
if curl -fsSL --head "$URL" >/dev/null 2>&1; then
|
|
echo "✓ Release .dmg available: $URL"
|
|
exit 0
|
|
fi
|
|
echo " waiting for release v${VERSION}... ($i/30)"
|
|
sleep 20
|
|
done
|
|
echo "::error::Release v${VERSION} macOS .dmg never became available"
|
|
exit 1
|
|
|
|
- name: Compute macOS .dmg SHA256
|
|
if: env.HOMEBREW_GITHUB_TOKEN != ''
|
|
id: sha
|
|
run: |
|
|
curl -fsSL -o /tmp/triangles.dmg \
|
|
"https://github.com/SamiAhmed7777/triangles_v5/releases/download/v${VERSION}/Cryptographic-Triangles-v${VERSION}-macos-arm64.dmg"
|
|
SHA=$(sha256sum /tmp/triangles.dmg | awk '{print $1}')
|
|
echo "sha=$SHA" >> $GITHUB_OUTPUT
|
|
echo "macOS .dmg SHA256: $SHA"
|
|
|
|
- name: Clone homebrew-triangles
|
|
if: env.HOMEBREW_GITHUB_TOKEN != ''
|
|
run: |
|
|
git clone https://x-access-token:$HOMEBREW_GITHUB_TOKEN@github.com/SamiAhmed7777/homebrew-triangles.git /tmp/homebrew-triangles
|
|
cd /tmp/homebrew-triangles
|
|
git --no-pager log --oneline | head -3
|
|
|
|
- name: Update Formula and Cask
|
|
if: env.HOMEBREW_GITHUB_TOKEN != ''
|
|
env:
|
|
VERSION: ${{ needs.version.outputs.version }}
|
|
SHA: ${{ steps.sha.outputs.sha }}
|
|
run: |
|
|
cd /tmp/homebrew-triangles
|
|
# Update Casks/cryptographic-triangles.rb
|
|
python3 - <<PYEOF
|
|
import re
|
|
for path, old_v_pat, old_sha_pat in [
|
|
('Casks/cryptographic-triangles.rb', r'^\s*version\s+"[\d.]+"', r'^\s*sha256\s+"[a-f0-9]+"'),
|
|
('Formula/triangles.rb', r'^\s*version\s+"[\d.]+"', r'^\s*sha256\s+"[a-f0-9]+"'),
|
|
]:
|
|
with open(path) as f: content = f.read()
|
|
content = re.sub(old_v_pat, f' version "$VERSION"', content, count=1, flags=re.MULTILINE)
|
|
content = re.sub(old_sha_pat, f' sha256 "$SHA"', content, count=1, flags=re.MULTILINE)
|
|
with open(path, 'w') as f: f.write(content)
|
|
PYEOF
|
|
cat Formula/triangles.rb | head -5
|
|
echo "---"
|
|
cat Casks/cryptographic-triangles.rb | head -5
|
|
git --no-pager diff --stat
|
|
|
|
- name: Commit and push
|
|
if: env.HOMEBREW_GITHUB_TOKEN != ''
|
|
env:
|
|
VERSION: ${{ needs.version.outputs.version }}
|
|
run: |
|
|
cd /tmp/homebrew-triangles
|
|
git config user.name "Sami Ahmed"
|
|
git config user.email "SamiAhmed7777@users.noreply.github.com"
|
|
git add Formula/triangles.rb Casks/cryptographic-triangles.rb
|
|
if git diff --cached --quiet; then
|
|
echo "No changes to commit (Homebrew tap already at this version)"
|
|
exit 0
|
|
fi
|
|
git commit -m "triangles ${VERSION}"
|
|
git push origin main
|
|
|
|
- name: ✓ Summary
|
|
if: always()
|
|
run: |
|
|
if [ -z "$HOMEBREW_GITHUB_TOKEN" ]; then
|
|
echo "::notice::Homebrew job was skipped because HOMEBREW_GITHUB_TOKEN is not set."
|
|
else
|
|
echo "::notice::Homebrew distribution completed."
|
|
fi
|