docs: clean public launch messaging #7
Workflow file for this run
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
| name: Release | |
| on: | |
| workflow_dispatch: | |
| pull_request: | |
| branches: [main] | |
| paths: | |
| - ".github/workflows/release.yml" | |
| - "install.sh" | |
| - "install.ps1" | |
| - "tools/package-release.sh" | |
| - "tools/package-release.ps1" | |
| - "README.md" | |
| - "docs/installation.md" | |
| push: | |
| tags: | |
| - "v[0-9]+.[0-9]+.[0-9]+" | |
| permissions: | |
| contents: read | |
| jobs: | |
| validate: | |
| name: validate release metadata | |
| runs-on: ubuntu-latest | |
| steps: | |
| - uses: actions/checkout@v7 | |
| - name: Match tag and crate version | |
| if: startsWith(github.ref, 'refs/tags/v') | |
| shell: bash | |
| run: | | |
| expected="${GITHUB_REF_NAME#v}" | |
| actual="$(cargo metadata --locked --no-deps --format-version 1 | jq -r '.packages[] | select(.name == "flect-cli") | .version')" | |
| test "$actual" = "$expected" || { echo "tag v$expected does not match flect-cli $actual"; exit 1; } | |
| build: | |
| name: build (${{ matrix.target }}) | |
| needs: validate | |
| strategy: | |
| fail-fast: false | |
| matrix: | |
| include: | |
| - target: x86_64-unknown-linux-gnu | |
| os: ubuntu-latest | |
| archive: tar.gz | |
| installer_smoke: true | |
| - target: aarch64-unknown-linux-gnu | |
| os: ubuntu-latest | |
| archive: tar.gz | |
| installer_smoke: false | |
| - target: x86_64-apple-darwin | |
| os: macos-15-intel | |
| archive: tar.gz | |
| installer_smoke: true | |
| - target: aarch64-apple-darwin | |
| os: macos-14 | |
| archive: tar.gz | |
| installer_smoke: true | |
| - target: x86_64-pc-windows-msvc | |
| os: windows-latest | |
| archive: zip | |
| installer_smoke: true | |
| runs-on: ${{ matrix.os }} | |
| env: | |
| RELEASE_VERSION: ${{ startsWith(github.ref, 'refs/tags/') && github.ref_name || format('dev-{0}', github.run_number) }} | |
| steps: | |
| - uses: actions/checkout@v7 | |
| - uses: houseabsolute/actions-rust-cross@v1 | |
| with: | |
| command: build | |
| target: ${{ matrix.target }} | |
| args: "--locked --release -p flect-cli" | |
| strip: true | |
| - name: Package Unix artifact | |
| if: runner.os != 'Windows' | |
| shell: bash | |
| run: ./tools/package-release.sh "${{ matrix.target }}" "$RELEASE_VERSION" | |
| - name: Package Windows artifact | |
| if: runner.os == 'Windows' | |
| shell: powershell | |
| run: powershell -NoProfile -ExecutionPolicy Bypass -File ./tools/package-release.ps1 -Target "${{ matrix.target }}" -Version "$env:RELEASE_VERSION" | |
| - name: Smoke-check native executable (Unix) | |
| if: runner.os != 'Windows' && !startsWith(matrix.target, 'aarch64-unknown-linux') | |
| shell: bash | |
| run: target/${{ matrix.target }}/release/flect --version | |
| - name: Smoke-check native executable (Windows) | |
| if: runner.os == 'Windows' | |
| shell: powershell | |
| run: .\target\${{ matrix.target }}\release\flect.exe --version | |
| - name: Validate Unix archive contents | |
| if: runner.os != 'Windows' | |
| shell: bash | |
| run: | | |
| archive="dist/flect-${RELEASE_VERSION}-${{ matrix.target }}.tar.gz" | |
| test -f "$archive" | |
| listing="$(tar -tzf "$archive")" | |
| for expected in flect LICENSE README.md; do | |
| printf '%s\n' "$listing" | grep -Fx "flect-${RELEASE_VERSION}-${{ matrix.target }}/$expected" | |
| done | |
| - name: Smoke-test local Unix installer | |
| if: runner.os != 'Windows' && matrix.installer_smoke | |
| shell: bash | |
| run: | | |
| archive="dist/flect-${RELEASE_VERSION}-${{ matrix.target }}.tar.gz" | |
| checksum="$RUNNER_TEMP/SHA256SUMS" | |
| archive_dir="$(dirname "$archive")" | |
| archive_name="$(basename "$archive")" | |
| if command -v sha256sum >/dev/null 2>&1; then | |
| (cd "$archive_dir" && sha256sum "$archive_name") > "$checksum" | |
| else | |
| (cd "$archive_dir" && shasum -a 256 "$archive_name") > "$checksum" | |
| fi | |
| install_dir="$RUNNER_TEMP/flect-install" | |
| sh ./install.sh --version latest --bin-dir "$install_dir" --archive "$archive" --checksum-file "$checksum" | |
| "$install_dir/flect" --version | |
| if sh ./install.sh --archive "$archive" >/dev/null 2>&1; then | |
| echo 'installer accepted an incomplete offline input pair' | |
| exit 1 | |
| fi | |
| printf '%064d %s\n' 0 "$(basename "$archive")" > "$RUNNER_TEMP/BAD-SHA256SUMS" | |
| if sh ./install.sh --version latest --bin-dir "$install_dir" --archive "$archive" --checksum-file "$RUNNER_TEMP/BAD-SHA256SUMS" >/dev/null 2>&1; then | |
| echo 'installer accepted an invalid checksum' | |
| exit 1 | |
| fi | |
| - name: Validate Windows archive contents | |
| if: runner.os == 'Windows' | |
| shell: powershell | |
| run: | | |
| $archive = "dist/flect-$env:RELEASE_VERSION-${{ matrix.target }}.zip" | |
| if (-not (Test-Path -LiteralPath $archive)) { throw "missing $archive" } | |
| Add-Type -AssemblyName System.IO.Compression.FileSystem | |
| $entries = [IO.Compression.ZipFile]::OpenRead($archive).Entries.FullName | |
| foreach ($expected in @("flect.exe", "LICENSE", "README.md")) { | |
| $name = "flect-$env:RELEASE_VERSION-${{ matrix.target }}/$expected" | |
| if ($entries -notcontains $name) { throw "archive missing $name" } | |
| } | |
| - name: Smoke-test local Windows installer | |
| if: runner.os == 'Windows' && matrix.installer_smoke | |
| shell: powershell | |
| run: | | |
| $archive = "dist/flect-$env:RELEASE_VERSION-${{ matrix.target }}.zip" | |
| $checksum = Join-Path $env:RUNNER_TEMP 'SHA256SUMS' | |
| $hash = (Get-FileHash -LiteralPath $archive -Algorithm SHA256).Hash.ToLowerInvariant() | |
| "$hash $(Split-Path -Leaf $archive)" | Set-Content -LiteralPath $checksum -Encoding ascii | |
| $installDir = Join-Path $env:RUNNER_TEMP 'flect-install' | |
| & .\install.ps1 -Version latest -BinDir $installDir -Archive $archive -ChecksumFile $checksum | |
| & (Join-Path $installDir 'flect.exe') --version | |
| try { | |
| & .\install.ps1 -Archive $archive | |
| throw 'installer accepted an incomplete offline input pair' | |
| } | |
| catch { | |
| if ($_.Exception.Message -like '*incomplete offline input pair*') { throw } | |
| } | |
| $badChecksum = Join-Path $env:RUNNER_TEMP 'BAD-SHA256SUMS' | |
| ('0' * 64 + " $(Split-Path -Leaf $archive)") | Set-Content -LiteralPath $badChecksum -Encoding ascii | |
| try { | |
| & .\install.ps1 -Version latest -BinDir $installDir -Archive $archive -ChecksumFile $badChecksum | |
| throw 'installer accepted an invalid checksum' | |
| } | |
| catch { | |
| if ($_.Exception.Message -like '*invalid checksum*') { throw } | |
| } | |
| - uses: actions/upload-artifact@v7 | |
| with: | |
| name: flect-${{ matrix.target }} | |
| path: dist/flect-*-${{ matrix.target }}.${{ matrix.archive }} | |
| if-no-files-found: error | |
| checksums: | |
| name: checksums | |
| needs: build | |
| runs-on: ubuntu-latest | |
| steps: | |
| - uses: actions/checkout@v7 | |
| - uses: actions/download-artifact@v8 | |
| with: | |
| path: dist | |
| merge-multiple: true | |
| - name: Add installer scripts | |
| shell: bash | |
| run: | | |
| cp install.sh install.ps1 dist/ | |
| - name: Generate and verify exact SHA256SUMS | |
| working-directory: dist | |
| shell: bash | |
| run: | | |
| mapfile -t artifacts < <(find . -maxdepth 1 -type f \( -name 'flect-*.tar.gz' -o -name 'flect-*.zip' -o -name 'install.sh' -o -name 'install.ps1' \) -printf '%f\n' | sort) | |
| test "${#artifacts[@]}" -eq 7 | |
| sha256sum "${artifacts[@]}" > SHA256SUMS | |
| test "$(wc -l < SHA256SUMS)" -eq "${#artifacts[@]}" | |
| sha256sum --check SHA256SUMS | |
| - uses: actions/upload-artifact@v7 | |
| with: | |
| name: flect-release | |
| path: dist/* | |
| publish: | |
| name: publish GitHub release | |
| if: startsWith(github.ref, 'refs/tags/v') | |
| needs: checksums | |
| runs-on: ubuntu-latest | |
| permissions: | |
| contents: write | |
| steps: | |
| - uses: actions/download-artifact@v8 | |
| with: | |
| name: flect-release | |
| path: dist | |
| - name: Publish GitHub release | |
| uses: softprops/action-gh-release@v3 | |
| with: | |
| fail_on_unmatched_files: true | |
| generate_release_notes: true | |
| files: dist/* | |
| env: | |
| GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }} |