chore: consolidate and harden release workflows (#10447)
This commit is contained in:
@@ -0,0 +1,191 @@
|
||||
on:
|
||||
workflow_dispatch:
|
||||
workflow_call:
|
||||
inputs:
|
||||
version:
|
||||
required: false
|
||||
default: ""
|
||||
type: string
|
||||
ref:
|
||||
type: string
|
||||
required: false
|
||||
default: ""
|
||||
|
||||
name: "Build CLI for Linux"
|
||||
|
||||
permissions:
|
||||
contents: read
|
||||
|
||||
jobs:
|
||||
build-cli-linux:
|
||||
name: Build CLI
|
||||
runs-on: ${{ matrix.build-on }}
|
||||
container: ${{ matrix.container }}
|
||||
strategy:
|
||||
fail-fast: false
|
||||
matrix:
|
||||
include:
|
||||
- architecture: x86_64
|
||||
target-suffix: unknown-linux-gnu
|
||||
build-on: ubuntu-22.04
|
||||
# Pinned by digest for reproducible builds; bump explicitly when newer manylinux_2_28 images ship.
|
||||
container: quay.io/pypa/manylinux_2_28_x86_64@sha256:441c35fdc6ee809ff9260894f8468ab4fea8c15dc880f8700a3f81b7922c1cda
|
||||
variant: standard
|
||||
- architecture: aarch64
|
||||
target-suffix: unknown-linux-gnu
|
||||
build-on: ubuntu-22.04-arm
|
||||
# Pinned by digest for reproducible builds; bump explicitly when newer manylinux_2_28 images ship.
|
||||
container: quay.io/pypa/manylinux_2_28_aarch64@sha256:8b5f2b4e8c072ae5aefeb659f22c03e1ff46e6a82f154b6c904b106c87e65ff7
|
||||
variant: standard
|
||||
- architecture: x86_64
|
||||
target-suffix: unknown-linux-musl
|
||||
build-on: ubuntu-22.04
|
||||
variant: musl
|
||||
- architecture: aarch64
|
||||
target-suffix: unknown-linux-musl
|
||||
build-on: ubuntu-22.04-arm
|
||||
variant: musl
|
||||
- architecture: x86_64
|
||||
target-suffix: unknown-linux-gnu
|
||||
build-on: ubuntu-24.04
|
||||
variant: vulkan
|
||||
- architecture: aarch64
|
||||
target-suffix: unknown-linux-gnu
|
||||
build-on: ubuntu-24.04-arm
|
||||
variant: vulkan
|
||||
|
||||
steps:
|
||||
- name: Checkout code
|
||||
uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 # v7.0.0
|
||||
with:
|
||||
ref: ${{ inputs.ref }}
|
||||
|
||||
- name: Update version in Cargo.toml
|
||||
if: ${{ inputs.version != '' }}
|
||||
shell: bash
|
||||
env:
|
||||
VERSION: ${{ inputs.version }}
|
||||
run: bash scripts/set-cargo-version.sh "$VERSION"
|
||||
|
||||
- name: Install Linux build dependencies (host runner)
|
||||
if: matrix.container == ''
|
||||
run: |
|
||||
sudo apt-get update
|
||||
sudo apt-get install -y \
|
||||
build-essential \
|
||||
pkg-config \
|
||||
libssl-dev \
|
||||
libdbus-1-dev \
|
||||
libxcb1-dev
|
||||
|
||||
if [ "${{ matrix.variant }}" = "vulkan" ]; then
|
||||
sudo apt-get install -y \
|
||||
libvulkan-dev \
|
||||
libvulkan1 \
|
||||
glslc
|
||||
fi
|
||||
|
||||
if [ "${{ matrix.variant }}" = "musl" ]; then
|
||||
sudo apt-get install -y musl-tools
|
||||
fi
|
||||
|
||||
- name: Install Linux build dependencies (manylinux container)
|
||||
if: matrix.container != ''
|
||||
run: |
|
||||
# perl-core provides FindBin, File::Compare, etc. that openssl-sys's
|
||||
# vendored openssl build needs; in AlmaLinux 8 these aren't standalone packages.
|
||||
# clang provides libclang.so for bindgen (used by llama-cpp-sys-2).
|
||||
# Defensive: avoid actions/checkout falling back to a tarball download if base image changes.
|
||||
dnf install -y --setopt=install_weak_deps=False \
|
||||
openssl-devel \
|
||||
dbus-devel \
|
||||
libxcb-devel \
|
||||
cmake \
|
||||
perl-core \
|
||||
clang \
|
||||
git \
|
||||
tar
|
||||
|
||||
- name: Cache Cargo artifacts
|
||||
uses: Swatinem/rust-cache@c19371144df3bb44fab255c43d04cbc2ab54d1c4 # v2.9.1
|
||||
with:
|
||||
key: ${{ matrix.architecture }}-${{ matrix.target-suffix }}-${{ matrix.build-on }}-${{ matrix.container || 'native' }}
|
||||
|
||||
- name: Build CLI (host runner)
|
||||
if: matrix.container == ''
|
||||
env:
|
||||
RUST_LOG: debug
|
||||
RUST_BACKTRACE: 1
|
||||
run: |
|
||||
source ./bin/activate-hermit
|
||||
export TARGET="${{ matrix.architecture }}-${{ matrix.target-suffix }}"
|
||||
rustup target add "${TARGET}"
|
||||
echo "Building for target: ${TARGET}"
|
||||
echo "Rust toolchain info:"
|
||||
rustup show
|
||||
|
||||
FEATURE_ARGS=()
|
||||
if [ "${{ matrix.variant }}" = "vulkan" ]; then
|
||||
FEATURE_ARGS=(--features vulkan)
|
||||
fi
|
||||
|
||||
if [ "${{ matrix.variant }}" = "musl" ]; then
|
||||
cargo build --release --target ${TARGET} -p goose-cli --bin goose \
|
||||
--no-default-features \
|
||||
--features portable-default
|
||||
else
|
||||
cargo build --release --target ${TARGET} -p goose-cli --bin goose "${FEATURE_ARGS[@]}"
|
||||
fi
|
||||
|
||||
- name: Build CLI (manylinux container)
|
||||
if: matrix.container != ''
|
||||
env:
|
||||
RUST_BACKTRACE: 1
|
||||
run: |
|
||||
# Hermit's tool cache is host-runner-scoped; inside the container we
|
||||
# bootstrap rustup directly and let rust-toolchain.toml pin the channel.
|
||||
curl --proto '=https' --tlsv1.2 -sSf https://sh.rustup.rs \
|
||||
| sh -s -- -y --default-toolchain none --profile minimal --no-modify-path
|
||||
export PATH="$HOME/.cargo/bin:$PATH"
|
||||
TARGET="${{ matrix.architecture }}-${{ matrix.target-suffix }}"
|
||||
RUST_CHANNEL=$(grep '^channel' rust-toolchain.toml | cut -d'"' -f2)
|
||||
if [ -z "$RUST_CHANNEL" ]; then
|
||||
echo "Could not parse channel from rust-toolchain.toml" >&2
|
||||
exit 1
|
||||
fi
|
||||
rustup toolchain install "$RUST_CHANNEL" --profile minimal \
|
||||
--component rustc,cargo --target "$TARGET"
|
||||
rustup show
|
||||
cargo build --release --target "$TARGET" -p goose-cli --bin goose
|
||||
|
||||
- name: Package CLI
|
||||
run: |
|
||||
# Hermit isn't installed in the manylinux container; tar is all this step needs.
|
||||
if [ "${{ matrix.container }}" = '' ]; then
|
||||
source ./bin/activate-hermit
|
||||
fi
|
||||
export TARGET="${{ matrix.architecture }}-${{ matrix.target-suffix }}"
|
||||
export VARIANT_SUFFIX=""
|
||||
if [ "${{ matrix.variant }}" = "vulkan" ]; then
|
||||
VARIANT_SUFFIX="-vulkan"
|
||||
fi
|
||||
|
||||
# Create a directory for the package contents
|
||||
mkdir -p "target/${TARGET}/release/goose-package"
|
||||
|
||||
# Copy the goose binary
|
||||
cp "target/${TARGET}/release/goose" "target/${TARGET}/release/goose-package/"
|
||||
|
||||
cd "target/${TARGET}/release"
|
||||
tar -cjf "goose-${TARGET}${VARIANT_SUFFIX}.tar.bz2" -C goose-package .
|
||||
tar -czf "goose-${TARGET}${VARIANT_SUFFIX}.tar.gz" -C goose-package .
|
||||
echo "ARTIFACT_BZ2=target/${TARGET}/release/goose-${TARGET}${VARIANT_SUFFIX}.tar.bz2" >> $GITHUB_ENV
|
||||
echo "ARTIFACT_GZ=target/${TARGET}/release/goose-${TARGET}${VARIANT_SUFFIX}.tar.gz" >> $GITHUB_ENV
|
||||
|
||||
- name: Upload CLI artifact
|
||||
uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1
|
||||
with:
|
||||
name: goose-${{ matrix.architecture }}-${{ matrix.target-suffix }}${{ matrix.variant != 'standard' && matrix.variant != 'musl' && format('-{0}', matrix.variant) || '' }}
|
||||
path: |
|
||||
${{ env.ARTIFACT_BZ2 }}
|
||||
${{ env.ARTIFACT_GZ }}
|
||||
Reference in New Issue
Block a user