diff --git a/CONTRIBUTING.md b/CONTRIBUTING.md index 93077a9..ac30b30 100644 --- a/CONTRIBUTING.md +++ b/CONTRIBUTING.md @@ -76,14 +76,19 @@ cargo test --release --workspace - `release.yml` — triggered on any other `v*` tag push, cuts the actual stable release. -All of these build inside a pinned Arch Linux container (`ci/Containerfile`, -run via `ci/build.sh`) on a self-hosted runner — not the runner host's -native environment. Arch's repos carry current `gtk4`/`libadwaita`/ -`gtk4-layer-shell` as prebuilt packages, so there's no from-source library -build to go stale. The image is rebuilt (and re-cached by Docker) only when -`ci/Containerfile` changes, so a plain push doesn't refetch or recompile -the toolchain. Nothing runs automatically on plain commits or PRs beyond -the jobs listed above. See +All of these build inside a pinned Arch Linux container on a self-hosted +runner — not the runner host's native environment. Arch's repos carry +current `gtk4`/`libadwaita`/`gtk4-layer-shell` as prebuilt packages, so +there's no from-source library build to go stale. The Containerfile and +build script are shared across bread-ecosystem GTK4 products, living in +`bread-ecosystem/ci/`; `ci/build.sh` here is a thin wrapper that clones +that repo at the commit pinned in `ci/bread-ecosystem.rev` (not `main` — +an unrelated change there shouldn't silently affect this repo's release +builds) and delegates to it. Bump the pin deliberately when you want the +shared image or build logic updated. A `ci/deps.txt` here (currently +absent — breadpad needs nothing beyond the shared base) would layer on +extra pacman packages if that ever changes. Nothing runs automatically on +plain commits or PRs beyond the jobs listed above. See [bread-ecosystem's docs/release-channels.md](https://git.breadway.dev/Breadway/bread-ecosystem/src/branch/main/docs/release-channels.md) for the full policy, including how a new product gets wired onto these tracks. diff --git a/ci/Containerfile b/ci/Containerfile deleted file mode 100644 index 45b0ba4..0000000 --- a/ci/Containerfile +++ /dev/null @@ -1,22 +0,0 @@ -# Pinned CI build environment for breadpad. -# -# Arch instead of Fedora because breadpad targets BOS/Arch only, and Arch's -# repos already carry current libadwaita/gtk4/gtk4-layer-shell as prebuilt -# packages — no from-source libadwaita build needed (that from-source build -# was the repeated CI breakage: rust dep mismatches, libadwaita ABI -# mismatches, and finally a removed meson option). -# -# Base image pinned by digest, package set frozen at build time: this image -# only changes when someone deliberately rebuilds it, not on every push. -FROM archlinux@sha256:fae033b815a16f930325c2697e620362be4d2e5d739a301b10ad1fc9c8643a06 - -RUN pacman -Syu --noconfirm --needed \ - base-devel \ - git \ - pkgconf \ - rust \ - gtk4 \ - libadwaita \ - gtk4-layer-shell \ - graphene \ - && pacman -Scc --noconfirm diff --git a/ci/bread-ecosystem.rev b/ci/bread-ecosystem.rev new file mode 100644 index 0000000..aea22a3 --- /dev/null +++ b/ci/bread-ecosystem.rev @@ -0,0 +1 @@ +cd5da468b3782fddcb52b4eaff0755ff933524be diff --git a/ci/build.sh b/ci/build.sh index fbaac36..c0ab6f2 100755 --- a/ci/build.sh +++ b/ci/build.sh @@ -1,31 +1,21 @@ #!/usr/bin/env bash -# Builds (or reuses, via docker's own layer cache) the pinned Arch CI image -# from ci/Containerfile, then runs the given cargo command inside it against -# this repo checkout. -# -# Cargo's registry/git caches and CARGO_TARGET_DIR are persisted in named -# docker volumes so they survive across runs even though the repo checkout -# itself (a fresh --depth 1 clone per workflow run) does not. +# Delegates to bread-ecosystem's shared CI build image/script, pinned to +# the commit in ci/bread-ecosystem.rev — not `main`. bread-ecosystem's CI +# files now affect every product's release pipeline, so bumping the pin +# is a deliberate act instead of silent drift (see the bread-theme test +# that broke here for exactly that reason, before it was pinned by rev). # # Usage: ci/build.sh cargo build --release --locked set -euo pipefail ROOT="$(cd "$(dirname "${BASH_SOURCE[0]}")/.." && pwd)" -cd "$ROOT" +REV="$(cat "${ROOT}/ci/bread-ecosystem.rev")" -docker build -t breadpad-ci:archlinux -f ci/Containerfile ci +CACHE_DIR="/tmp/bread-ecosystem-ci-${REV}" +if [ ! -d "$CACHE_DIR" ]; then + rm -rf /tmp/bread-ecosystem-ci-* + git clone https://git.breadway.dev/Breadway/bread-ecosystem.git "$CACHE_DIR" + git -C "$CACHE_DIR" checkout --quiet "$REV" +fi -docker run --rm \ - -v "${ROOT}:/workspace" \ - -v breadpad-cargo-registry:/root/.cargo/registry \ - -v breadpad-cargo-git:/root/.cargo/git \ - -v breadpad-cargo-target:/cargo-target \ - -w /workspace \ - -e CARGO_TARGET_DIR=/cargo-target \ - breadpad-ci:archlinux \ - bash -c ' - set -euo pipefail - "$@" - mkdir -p /workspace/target - cp -a /cargo-target/. /workspace/target/ - ' bash "$@" +bash "${CACHE_DIR}/ci/build.sh" "$ROOT" "$@"