184 lines
7.0 KiB
YAML
184 lines
7.0 KiB
YAML
# Release, Go library. Runs on version tags (v1.2.3) pushed to main.
|
|
#
|
|
# A library ships no build assets, so there is no build matrix and no smoke test: the
|
|
# gate set minus race runs once at the tag, then the release is created from the
|
|
# matching CHANGELOG section. Race never runs on a push path or a tag; the local gate
|
|
# raced this tree before the tag was cut. Nothing is injected; the toolchain records
|
|
# the tag into the module's build information because the build simply happens there.
|
|
# The version contract these steps implement is in the `release` skill.
|
|
#
|
|
# Every scripted step is Perl with builtins only, and Perl drives curl through a list,
|
|
# so no argument is ever word-split, globbed or quoted wrong.
|
|
name: Release
|
|
|
|
on:
|
|
push:
|
|
tags: ["v*"]
|
|
|
|
env:
|
|
# One core: parallelism buys no speed here and costs memory the box does not have.
|
|
GOFLAGS: -p=1
|
|
GOMAXPROCS: "2"
|
|
|
|
jobs:
|
|
gates:
|
|
runs-on: fedora
|
|
timeout-minutes: 10
|
|
steps:
|
|
- name: Install git and Perl
|
|
# Both are no-ops where present. gcc existed for the race detector,
|
|
# which no longer runs in this pipeline.
|
|
run: dnf install -y git perl
|
|
|
|
- uses: actions/checkout@v7
|
|
|
|
- uses: actions/setup-go@v6
|
|
with:
|
|
go-version-file: go.mod
|
|
cache: true
|
|
|
|
- name: Validate the tag
|
|
env:
|
|
VERSION: ${{ gitea.ref_name }}
|
|
run: |
|
|
perl -e '
|
|
my $v = $ENV{VERSION} // q{};
|
|
$v =~ m{^v[0-9]+(\.[0-9]+){0,2}([-+].*)?$}
|
|
or die qq{ERROR: expected a semver tag like v1.2.3, got: $v\n};
|
|
print qq{tag $v\n};
|
|
'
|
|
|
|
- name: Format
|
|
run: |
|
|
perl -e '
|
|
open(my $g, q{-|}, q{gofmt}, q{-l}, q{.}) or die qq{gofmt: $!};
|
|
my @bad = <$g>;
|
|
close($g);
|
|
print @bad;
|
|
exit(@bad ? 1 : 0);
|
|
'
|
|
|
|
- name: Vet
|
|
run: go vet ./...
|
|
|
|
- name: Modernise
|
|
run: go fix -diff ./...
|
|
|
|
- name: Build
|
|
run: go build ./...
|
|
|
|
- name: Tests
|
|
# Equal to `packages` in the project's justfile, so the floor is the same
|
|
# number the local gate reports.
|
|
run: go test -count=1 -timeout 10m -coverprofile=coverage.out . ./internal/... ./grad/... ./integrate/... ./io/... ./linalg/... ./optim/... ./signal/... ./stats/...
|
|
|
|
- name: Coverage floor
|
|
run: |
|
|
perl -e '
|
|
open(my $c, q{-|}, q{go}, q{tool}, q{cover}, q{-func=coverage.out}) or die qq{cover: $!};
|
|
my $total;
|
|
while (my $l = <$c>) { $total = $1 if $l =~ m{^total:\s+\S+\s+([0-9.]+)%} }
|
|
close($c);
|
|
die qq{no total line in coverage.out\n} unless defined $total;
|
|
printf qq{Total coverage: %s%%\n}, $total;
|
|
exit($total < 80 ? 1 : 0);
|
|
'
|
|
|
|
release:
|
|
runs-on: fedora
|
|
timeout-minutes: 15
|
|
needs: gates
|
|
permissions:
|
|
# contents: read is required for the checkout: a job that declares any
|
|
# permissions gets a token scoped to exactly those, and releases: write
|
|
# alone leaves the fetch with no read access, which Gitea answers with
|
|
# a 404 "Repository not found". Verified on the instance 2026-09-16.
|
|
contents: read
|
|
releases: write
|
|
steps:
|
|
- name: Install Perl
|
|
run: dnf install -y perl
|
|
|
|
- uses: actions/checkout@v7
|
|
|
|
- name: Extract the CHANGELOG section
|
|
env:
|
|
VERSION: ${{ gitea.ref_name }}
|
|
run: |
|
|
# Each step derives what it needs from the tag, so no value has to travel
|
|
# between jobs.
|
|
perl -e '
|
|
my $v = $ENV{VERSION} // q{};
|
|
$v =~ s{^v}{};
|
|
open(my $vout, q{>}, q{version-no-v.txt}) or die qq{version-no-v.txt: $!};
|
|
print $vout $v;
|
|
close($vout);
|
|
open(my $in, q{<}, q{CHANGELOG.md}) or die qq{CHANGELOG.md: $!};
|
|
my @lines = <$in>;
|
|
close($in);
|
|
my ($start, $end) = (-1, scalar @lines);
|
|
for my $i (0 .. $#lines) {
|
|
if ($start < 0) { $start = $i if $lines[$i] =~ m{^##\s+\[\Q$v\E\]} }
|
|
elsif ($lines[$i] =~ m{^##\s+\[}) { $end = $i; last }
|
|
}
|
|
$start >= 0 or die qq{ERROR: no CHANGELOG section for $v, expected a heading like: ## [$v] - YYYY-MM-DD\n};
|
|
my @body = grep { m{\S} } @lines[$start + 1 .. $end - 1];
|
|
@body or die qq{ERROR: the CHANGELOG section for $v is empty\n};
|
|
open(my $out, q{>}, q{release-body.md}) or die qq{release-body.md: $!};
|
|
print $out @body;
|
|
close($out);
|
|
printf qq{notes for %s: %d lines\n}, $v, scalar @body;
|
|
'
|
|
|
|
- name: Build the release request
|
|
run: |
|
|
perl -e '
|
|
open(my $vin, q{<}, q{version-no-v.txt}) or die qq{version-no-v.txt: $!};
|
|
my $v = <$vin>;
|
|
close($vin);
|
|
chomp $v;
|
|
open(my $in, q{<:raw}, q{release-body.md}) or die qq{release-body.md: $!};
|
|
my $body = do { local $/; <$in> };
|
|
close($in);
|
|
# Byte-oriented escaping: JSON is UTF-8, so non-ASCII passes through and
|
|
# only the characters JSON forbids are rewritten.
|
|
$body =~ s/([\\"])/\\$1/g;
|
|
$body =~ s/\t/\\t/g;
|
|
$body =~ s/\r//g;
|
|
$body =~ s/\n/\\n/g;
|
|
$body =~ s/([\x00-\x08\x0b\x0c\x0e-\x1f])/sprintf(q{\u%04x}, ord($1))/ge;
|
|
my $json = sprintf(qq{{"tag_name":"v%s","name":"v%s","body":"%s","draft":false,"prerelease":false}}, $v, $v, $body);
|
|
open(my $out, q{>}, q{release.json}) or die qq{release.json: $!};
|
|
print $out $json;
|
|
close($out);
|
|
print qq{release.json written for v$v\n};
|
|
'
|
|
|
|
- name: Create the release
|
|
env:
|
|
GITEA_TOKEN: ${{ secrets.GITEA_TOKEN }}
|
|
GITEA_SERVER_URL: ${{ gitea.server_url }}
|
|
GITEA_REPOSITORY: ${{ gitea.repository }}
|
|
VERSION: ${{ gitea.ref_name }}
|
|
run: |
|
|
perl -e '
|
|
my @cmd = (q{curl}, q{-sS}, q{-o}, q{response.json}, q{-w}, q{%{http_code}},
|
|
q{-H}, qq{Authorization: token $ENV{GITEA_TOKEN}},
|
|
q{-H}, q{Content-Type: application/json},
|
|
q{-X}, q{POST},
|
|
qq{$ENV{GITEA_SERVER_URL}/api/v1/repos/$ENV{GITEA_REPOSITORY}/releases},
|
|
q{--data-binary}, q{@release.json});
|
|
open(my $curl, q{-|}, @cmd) or die qq{curl: $!};
|
|
my $code = <$curl>;
|
|
my $ok = close($curl);
|
|
my $exit = $? >> 8;
|
|
$code = defined $code ? $code : q{};
|
|
$ok or die qq{ERROR: curl failed (exit $exit) calling $ENV{GITEA_SERVER_URL}\n};
|
|
open(my $r, q{<:raw}, q{response.json}) or die qq{response.json: $!};
|
|
my $body = do { local $/; <$r> };
|
|
close($r);
|
|
$code eq q{201} or die qq{ERROR: the release was not created, HTTP $code: $body\n};
|
|
$body =~ m{"id"\s*:\s*([0-9]+)} or die qq{ERROR: no release id in the response: $body\n};
|
|
print qq{release v$ENV{VERSION} is live (id $1)\n};
|
|
'
|