All checks were successful
check / check (push) Successful in 26s
Same fix as breadpad: build inside the shared pinned Arch container (bread-ecosystem/ci/, cloned at the sha in ci/bread-ecosystem.rev) instead of building natively against whatever's on the runner host. Adds check.yml (clippy + test on feature/**/fix/**) as a fast-fail gate before anything reaches main. Turning on clippy -D warnings for the first time surfaced 10 pre-existing warnings (int_plus_one, ptr_arg on &mut Vec params, collapsible_if, collapsible_match) across layout.rs, mirror.rs, profile.rs, and the config/mirror TUI views — all fixed exactly per clippy's suggested diffs, verified behavior-preserving (the mirror_view.rs collapse in particular: confirmed the "do nothing" fallthrough when mirror.result is None is unchanged, since that was already the fallthrough behavior of the original nested if with no matching else on the outer condition). Verified locally: build, clippy, and test all pass through the new container path.
56 lines
2.4 KiB
YAML
56 lines
2.4 KiB
YAML
name: beta (rc) release
|
|
|
|
# Publishes a beta-track build for any `vX.Y.Z-rc.N` prerelease tag
|
|
# pushed to `main` — there is no separate `beta` branch; "freezing" is
|
|
# just pausing pushes to main while an RC gets tested. See
|
|
# bread-ecosystem's docs/release-channels.md for the release-track policy.
|
|
on:
|
|
push:
|
|
tags: ['v*']
|
|
|
|
jobs:
|
|
build:
|
|
if: ${{ contains(github.ref_name, '-rc.') }}
|
|
runs-on: [self-hosted, hestia]
|
|
steps:
|
|
- name: checkout
|
|
run: |
|
|
set -euo pipefail
|
|
rm -rf src && mkdir src
|
|
git clone --branch "${GITHUB_REF_NAME}" --depth 1 \
|
|
"https://git.breadway.dev/${GITHUB_REPOSITORY}.git" src
|
|
|
|
- name: build
|
|
run: cd src && bash ci/build.sh cargo build --release --locked
|
|
|
|
- name: prepare artifacts
|
|
run: |
|
|
set -euo pipefail
|
|
VERSION="${GITHUB_REF_NAME#v}"
|
|
PKG_DIR="/srv/breadway-dl/beta/breadmon/${VERSION}"
|
|
mkdir -p "${PKG_DIR}"
|
|
cp "src/target/release/breadmon" "${PKG_DIR}/breadmon-x86_64"
|
|
strip "${PKG_DIR}/breadmon-x86_64"
|
|
sha256sum "${PKG_DIR}/breadmon-x86_64" | awk '{print $1}' \
|
|
> "${PKG_DIR}/breadmon-x86_64.sha256"
|
|
cp src/bakery.toml "${PKG_DIR}/bakery.toml"
|
|
ln -sfn "${VERSION}" "/srv/breadway-dl/beta/breadmon/latest"
|
|
|
|
# No GitHub Release upload — beta, like dev, is only distributed via
|
|
# dl.breadway.dev/beta/.
|
|
- name: regenerate beta index.json
|
|
env:
|
|
MINISIGN_SEC_KEY: ${{ secrets.BAKERY_MINISIGN_SEC_KEY_PATH }}
|
|
run: |
|
|
set -euo pipefail
|
|
if [ -z "${MINISIGN_SEC_KEY:-}" ]; then
|
|
echo "::error::BAKERY_MINISIGN_SEC_KEY_PATH secret not set — refusing to regenerate beta index.json unsigned (would leave a stale signature mismatched against fresh content and break bakery for everyone on the beta track)"
|
|
exit 1
|
|
fi
|
|
rm -rf /tmp/bread-ecosystem-ci-* 2>/dev/null || true
|
|
# mktemp: a fixed clone path races when multiple repos' dev/beta
|
|
# workflows run close together on the same self-hosted runner.
|
|
ECOSYSTEM_CI_DIR="$(mktemp -d /tmp/bread-ecosystem-ci-XXXXXX)"
|
|
git clone https://git.breadway.dev/Breadway/bread-ecosystem.git "${ECOSYSTEM_CI_DIR}"
|
|
TRACK=beta bash "${ECOSYSTEM_CI_DIR}/scripts/gen-index.sh"
|
|
rm -rf "${ECOSYSTEM_CI_DIR}"
|