Public Access
CI / build (push) Successful in 11m26s
The workflow runs on the runner's host and builds in the project's Docker image through scripts/ci.sh, as on a developer's machine. A tag v*, or a run by hand for an older tag, builds that tag's sources, signs the Update File with the key held in the repository's secrets, checks the signature against the public key in the sources, and publishes a Gitea release with the .ota, the factory image, the ELF and checksums. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01EhqxQ49eCju4CzKYNjZzwT
70 lines
2.6 KiB
YAML
70 lines
2.6 KiB
YAML
# CI and releases (docs/milestones/R1.md).
|
|
# Any push: host tests, then the release firmware and the Debug Build.
|
|
# A tag v*: the same, then a Gitea release with the signed Update File.
|
|
# Run by hand: the release of a tag that exists already (the ones from before CI).
|
|
#
|
|
# The runner executes jobs on its own host, where Docker is: the steps are plain shell and the build
|
|
# runs in the project's image, exactly as scripts/ci.sh does on a developer's machine. No JavaScript
|
|
# actions (the host has no Node), so the checkout is done with git.
|
|
name: CI
|
|
on:
|
|
push:
|
|
branches: ['**']
|
|
tags: ['v*']
|
|
workflow_dispatch:
|
|
inputs:
|
|
tag:
|
|
description: An existing tag to build and publish as a release
|
|
required: true
|
|
|
|
jobs:
|
|
build:
|
|
runs-on: "ubuntu://docker:ubuntu:resolute"
|
|
steps:
|
|
- name: Check out
|
|
run: |
|
|
find . -mindepth 1 -maxdepth 1 -exec rm -rf {} +
|
|
git init -q .
|
|
git remote add origin "${{ github.server_url }}/${{ github.repository }}.git"
|
|
git fetch -q --tags origin '+refs/heads/*:refs/remotes/origin/*'
|
|
git checkout -q --detach "${{ github.sha }}"
|
|
git describe --tags --always
|
|
|
|
- name: Host tests and both builds
|
|
if: github.event_name == 'push'
|
|
run: scripts/ci.sh
|
|
|
|
- name: Which release
|
|
id: release
|
|
run: |
|
|
if [ "${{ github.event_name }}" = workflow_dispatch ]; then
|
|
echo "tag=${{ inputs.tag }}" >> "$GITHUB_OUTPUT"
|
|
elif [ "${{ github.ref_type }}" = tag ]; then
|
|
echo "tag=${{ github.ref_name }}" >> "$GITHUB_OUTPUT"
|
|
fi
|
|
|
|
- name: Build and sign the release
|
|
if: steps.release.outputs.tag != ''
|
|
env:
|
|
OTA_SIGNING_KEY: ${{ secrets.OTA_SIGNING_KEY }}
|
|
run: |
|
|
# The sources of the tag in a clone of their own; the tools are this commit's.
|
|
rm -rf ../release-src dist
|
|
git clone -q . ../release-src
|
|
git -C ../release-src checkout -q --detach "refs/tags/${{ steps.release.outputs.tag }}"
|
|
# The key exists as a file only while this step runs.
|
|
umask 077
|
|
export RORO_OTA_KEY="$(mktemp)"
|
|
trap 'rm -f "$RORO_OTA_KEY"' EXIT
|
|
printf '%s\n' "$OTA_SIGNING_KEY" > "$RORO_OTA_KEY"
|
|
umask 022
|
|
scripts/release_build.sh ../release-src dist
|
|
|
|
- name: Publish the release
|
|
if: steps.release.outputs.tag != ''
|
|
env:
|
|
GITEA_API: ${{ github.server_url }}/api/v1
|
|
GITEA_REPO: ${{ github.repository }}
|
|
GITEA_TOKEN: ${{ secrets.GITEA_TOKEN }}
|
|
run: scripts/release_publish.py dist
|