|
@@ -1,12 +1,12 @@
|
|
|
name: Release
|
|
name: Release
|
|
|
|
|
|
|
|
# Produces versioned distributables for ALL targets a host can build, into a GitHub Release.
|
|
# Produces versioned distributables for ALL targets a host can build, into a GitHub Release.
|
|
|
-# Each format is built independently so one failing format never blocks the others, and the
|
|
|
|
|
-# collect step uploads whatever actually got produced (partial success is still published).
|
|
|
|
|
-# linux (deb/rpm/AppImage) + android (apk) + iso -> ubuntu-latest
|
|
|
|
|
|
|
+# Each target verifies its own required artifacts. Publishing uses every successful target, so
|
|
|
|
|
+# apk/exe are not held hostage by Linux-only packaging dependencies.
|
|
|
|
|
+# linux (deb/rpm/AppImage) + iso -> ubuntu-latest
|
|
|
|
|
+# android (apk) -> ubuntu-latest
|
|
|
# windows (exe) -> windows-latest
|
|
# windows (exe) -> windows-latest
|
|
|
# macos (dmg) -> macos-latest
|
|
# macos (dmg) -> macos-latest
|
|
|
-# Skipped/failed formats are logged as ::warning:: and never fail the whole release.
|
|
|
|
|
# NOTE: iOS cannot be produced — the project has no iOS Kotlin target (commonMain uses
|
|
# NOTE: iOS cannot be produced — the project has no iOS Kotlin target (commonMain uses
|
|
|
# JVM-only libs); there is no iOS step.
|
|
# JVM-only libs); there is no iOS step.
|
|
|
|
|
|
|
@@ -31,7 +31,9 @@ jobs:
|
|
|
matrix:
|
|
matrix:
|
|
|
include:
|
|
include:
|
|
|
- os: ubuntu-latest
|
|
- os: ubuntu-latest
|
|
|
- target: linux-android-iso
|
|
|
|
|
|
|
+ target: linux-iso
|
|
|
|
|
+ - os: ubuntu-latest
|
|
|
|
|
+ target: android
|
|
|
- os: windows-latest
|
|
- os: windows-latest
|
|
|
target: windows
|
|
target: windows
|
|
|
- os: macos-latest
|
|
- os: macos-latest
|
|
@@ -63,7 +65,7 @@ jobs:
|
|
|
# Decode the Android release keystore from a base64 secret (optional). Without the
|
|
# Decode the Android release keystore from a base64 secret (optional). Without the
|
|
|
# secret the APK is debug-signed by the build fallback — still installable.
|
|
# secret the APK is debug-signed by the build fallback — still installable.
|
|
|
- name: Decode Android keystore
|
|
- name: Decode Android keystore
|
|
|
- if: matrix.os == 'ubuntu-latest'
|
|
|
|
|
|
|
+ if: matrix.target == 'android'
|
|
|
shell: bash
|
|
shell: bash
|
|
|
env:
|
|
env:
|
|
|
ANDROID_KEYSTORE_BASE64: ${{ secrets.ANDROID_KEYSTORE_BASE64 }}
|
|
ANDROID_KEYSTORE_BASE64: ${{ secrets.ANDROID_KEYSTORE_BASE64 }}
|
|
@@ -76,48 +78,74 @@ jobs:
|
|
|
echo "::warning::no ANDROID_KEYSTORE_BASE64 secret — APK will be debug-signed"
|
|
echo "::warning::no ANDROID_KEYSTORE_BASE64 secret — APK will be debug-signed"
|
|
|
fi
|
|
fi
|
|
|
|
|
|
|
|
- # ---------- linux desktop formats + android apk + reports (ubuntu) ----------
|
|
|
|
|
- # One invocation with --continue so deb/rpm/AppImage/apk/reports each build to
|
|
|
|
|
- # completion independently: a failure in one does NOT abort the others.
|
|
|
|
|
- - name: Build linux desktop + android + reports
|
|
|
|
|
- if: matrix.os == 'ubuntu-latest'
|
|
|
|
|
|
|
+ # Compositor build headers/tools are required for :compositor:stageSession ->
|
|
|
|
|
+ # packageFullDeb -> collectReleases. Ubuntu 24.04 has wayland-scanner in
|
|
|
|
|
+ # libwayland-bin but does not ship wlroots 0.18, so install that ABI-pinned package
|
|
|
|
|
+ # from the catalog URL instead of letting apt fail the whole dependency transaction.
|
|
|
|
|
+ - name: Install Linux build dependencies
|
|
|
|
|
+ if: matrix.target == 'linux-iso'
|
|
|
shell: bash
|
|
shell: bash
|
|
|
- continue-on-error: true
|
|
|
|
|
- env:
|
|
|
|
|
- # ANDROID_KEYSTORE_FILE is exported by the decode step above (if present)
|
|
|
|
|
- ANDROID_KEYSTORE_PASSWORD: ${{ secrets.ANDROID_KEYSTORE_PASSWORD }}
|
|
|
|
|
- ANDROID_KEY_ALIAS: ${{ secrets.ANDROID_KEY_ALIAS }}
|
|
|
|
|
- ANDROID_KEY_PASSWORD: ${{ secrets.ANDROID_KEY_PASSWORD }}
|
|
|
|
|
run: |
|
|
run: |
|
|
|
|
|
+ set -euo pipefail
|
|
|
sudo apt-get update
|
|
sudo apt-get update
|
|
|
- sudo apt-get install -y rpm || echo "::warning::rpm tools missing — .rpm may be skipped"
|
|
|
|
|
- ./gradlew packageFullDeb :desktopApp:packageReleaseRpm packageAppImageFile \
|
|
|
|
|
- :androidApp:assembleRelease postBuildCodeCheck \
|
|
|
|
|
- -PdepCheck=false --continue --stacktrace \
|
|
|
|
|
- || echo "::warning::one or more linux/android formats failed — others still collected"
|
|
|
|
|
-
|
|
|
|
|
- # ---------- bootable live ISO (ubuntu, needs root) ----------
|
|
|
|
|
- # Separate step because makeIso needs root (debootstrap/chroot/mksquashfs); on CI it
|
|
|
|
|
- # runs via passwordless sudo. Isolated so a failed/slow ISO can't drop the other formats.
|
|
|
|
|
- - name: Build live ISO
|
|
|
|
|
- if: matrix.os == 'ubuntu-latest'
|
|
|
|
|
|
|
+ sudo apt-get install -y \
|
|
|
|
|
+ ca-certificates curl rpm debootstrap squashfs-tools xorriso mtools dpkg-dev \
|
|
|
|
|
+ grub-common grub-pc-bin grub-efi-amd64-bin debian-archive-keyring zip \
|
|
|
|
|
+ pkg-config libwayland-dev libwayland-bin wayland-protocols \
|
|
|
|
|
+ libxkbcommon-dev libcairo2-dev libcairo2 libpixman-1-dev libdrm-dev \
|
|
|
|
|
+ libinput-dev libseat-dev libgbm-dev libegl1-mesa-dev libgles2-mesa-dev \
|
|
|
|
|
+ libcap-dev liblcms2-dev libsystemd-dev libudev-dev libvulkan-dev \
|
|
|
|
|
+ libxcb1-dev libxcb-composite0-dev libxcb-dri3-dev libxcb-ewmh-dev \
|
|
|
|
|
+ libxcb-icccm4-dev libxcb-image0-dev libxcb-present-dev libxcb-render0-dev \
|
|
|
|
|
+ libxcb-render-util0-dev libxcb-res0-dev libxcb-shm0-dev libxcb-xfixes0-dev \
|
|
|
|
|
+ libxcb-xinput-dev libx11-xcb-dev
|
|
|
|
|
+
|
|
|
|
|
+ read_catalog_url() {
|
|
|
|
|
+ grep -E "^$1" gradle/libs.versions.toml | sed -E 's/.*"(.*)".*/\1/'
|
|
|
|
|
+ }
|
|
|
|
|
+ mkdir -p "$RUNNER_TEMP/wlroots"
|
|
|
|
|
+ for key in \
|
|
|
|
|
+ ci-ubuntu-libdisplay-info-runtime-deb-url \
|
|
|
|
|
+ ci-ubuntu-libdisplay-info-dev-deb-url \
|
|
|
|
|
+ ci-ubuntu-libliftoff-runtime-deb-url \
|
|
|
|
|
+ ci-ubuntu-libliftoff-dev-deb-url \
|
|
|
|
|
+ ci-ubuntu-libxcb-errors-runtime-deb-url \
|
|
|
|
|
+ ci-ubuntu-libxcb-errors-dev-deb-url \
|
|
|
|
|
+ ci-ubuntu-wlroots-runtime-deb-url \
|
|
|
|
|
+ ci-ubuntu-wlroots-dev-deb-url
|
|
|
|
|
+ do
|
|
|
|
|
+ url="$(read_catalog_url "$key")"
|
|
|
|
|
+ curl -fsSL "$url" -o "$RUNNER_TEMP/wlroots/${key}.deb"
|
|
|
|
|
+ done
|
|
|
|
|
+ sudo apt-get install -y "$RUNNER_TEMP"/wlroots/*.deb
|
|
|
|
|
+
|
|
|
|
|
+ wayland-scanner --version
|
|
|
|
|
+ pkg-config --modversion wlroots-0.18
|
|
|
|
|
+
|
|
|
|
|
+ # ---------- linux + iso + reports (ubuntu) ----------
|
|
|
|
|
+ - name: Build linux + iso + reports
|
|
|
|
|
+ if: matrix.target == 'linux-iso'
|
|
|
shell: bash
|
|
shell: bash
|
|
|
- continue-on-error: true
|
|
|
|
|
run: |
|
|
run: |
|
|
|
- sudo apt-get install -y debootstrap squashfs-tools xorriso mtools dpkg-dev \
|
|
|
|
|
- grub-common grub-pc-bin grub-efi-amd64-bin debian-archive-keyring \
|
|
|
|
|
- || echo "::warning::iso toolchain missing — .iso may be skipped"
|
|
|
|
|
- ./gradlew makeIso -PdepCheck=false --stacktrace \
|
|
|
|
|
- || echo "::warning::makeIso failed — .iso skipped"
|
|
|
|
|
- ls -la releases/*.iso 2>/dev/null && echo "ISO produced" \
|
|
|
|
|
- || echo "::warning::no .iso in releases/ — makeIso skipped or failed"
|
|
|
|
|
|
|
+ ./gradlew :desktopApp:packageReleaseDistributionForCurrentOS packageAppImageFile packageFullDeb makeIso -PdepCheck=false --stacktrace
|
|
|
|
|
+ echo "=== releases/ ==="
|
|
|
|
|
+ ls -la releases/
|
|
|
|
|
+
|
|
|
|
|
+ # ---------- android (.apk) ----------
|
|
|
|
|
+ - name: Build android .apk
|
|
|
|
|
+ if: matrix.target == 'android'
|
|
|
|
|
+ shell: bash
|
|
|
|
|
+ env:
|
|
|
|
|
+ ANDROID_KEYSTORE_PASSWORD: ${{ secrets.ANDROID_KEYSTORE_PASSWORD }}
|
|
|
|
|
+ ANDROID_KEY_ALIAS: ${{ secrets.ANDROID_KEY_ALIAS }}
|
|
|
|
|
+ ANDROID_KEY_PASSWORD: ${{ secrets.ANDROID_KEY_PASSWORD }}
|
|
|
|
|
+ run: ./gradlew :androidApp:assembleRelease -PdepCheck=false --stacktrace
|
|
|
|
|
|
|
|
# ---------- windows (.exe) ----------
|
|
# ---------- windows (.exe) ----------
|
|
|
- name: Build windows .exe
|
|
- name: Build windows .exe
|
|
|
if: matrix.os == 'windows-latest'
|
|
if: matrix.os == 'windows-latest'
|
|
|
shell: bash
|
|
shell: bash
|
|
|
- continue-on-error: true
|
|
|
|
|
- run: ./gradlew :desktopApp:packageReleaseExe -PdepCheck=false --stacktrace || echo "::warning::windows .exe failed — skipped"
|
|
|
|
|
|
|
+ run: ./gradlew :desktopApp:packageReleaseExe -PdepCheck=false --stacktrace
|
|
|
|
|
|
|
|
# ---------- macos (.dmg) ----------
|
|
# ---------- macos (.dmg) ----------
|
|
|
# Signing/notarization activate only when the Apple Developer ID secrets are present
|
|
# Signing/notarization activate only when the Apple Developer ID secrets are present
|
|
@@ -125,52 +153,91 @@ jobs:
|
|
|
- name: Build macOS .dmg
|
|
- name: Build macOS .dmg
|
|
|
if: matrix.os == 'macos-latest'
|
|
if: matrix.os == 'macos-latest'
|
|
|
shell: bash
|
|
shell: bash
|
|
|
- continue-on-error: true
|
|
|
|
|
env:
|
|
env:
|
|
|
MACOS_SIGN_IDENTITY: ${{ secrets.MACOS_SIGN_IDENTITY }}
|
|
MACOS_SIGN_IDENTITY: ${{ secrets.MACOS_SIGN_IDENTITY }}
|
|
|
MACOS_BUNDLE_ID: ${{ secrets.MACOS_BUNDLE_ID }}
|
|
MACOS_BUNDLE_ID: ${{ secrets.MACOS_BUNDLE_ID }}
|
|
|
MACOS_NOTARY_APPLE_ID: ${{ secrets.MACOS_NOTARY_APPLE_ID }}
|
|
MACOS_NOTARY_APPLE_ID: ${{ secrets.MACOS_NOTARY_APPLE_ID }}
|
|
|
MACOS_NOTARY_PASSWORD: ${{ secrets.MACOS_NOTARY_PASSWORD }}
|
|
MACOS_NOTARY_PASSWORD: ${{ secrets.MACOS_NOTARY_PASSWORD }}
|
|
|
MACOS_NOTARY_TEAM_ID: ${{ secrets.MACOS_NOTARY_TEAM_ID }}
|
|
MACOS_NOTARY_TEAM_ID: ${{ secrets.MACOS_NOTARY_TEAM_ID }}
|
|
|
- run: ./gradlew :desktopApp:packageReleaseDmg -PdepCheck=false --stacktrace || echo "::warning::macOS .dmg failed — skipped"
|
|
|
|
|
|
|
+ run: ./gradlew :desktopApp:packageReleaseDmg -PdepCheck=false --stacktrace
|
|
|
|
|
|
|
|
# ---------- collect whatever got produced (versioned names) ----------
|
|
# ---------- collect whatever got produced (versioned names) ----------
|
|
|
- # Copies from every known jpackage/build output dir; dirs absent on this OS are simply
|
|
|
|
|
- # skipped. Mirrors the rename scheme of the :collectReleases Gradle task but tolerates
|
|
|
|
|
- # partial builds so we never lose the formats that DID succeed.
|
|
|
|
|
|
|
+ # Primary source is releases/ (collectReleases + makeIso). Fall back to jpackage output
|
|
|
|
|
+ # dirs for partial builds and for platform-specific runners (exe/dmg).
|
|
|
- name: Collect artifacts
|
|
- name: Collect artifacts
|
|
|
shell: bash
|
|
shell: bash
|
|
|
run: |
|
|
run: |
|
|
|
|
|
+ set -euo pipefail
|
|
|
VER='${{ steps.meta.outputs.version }}'
|
|
VER='${{ steps.meta.outputs.version }}'
|
|
|
APP='${{ steps.meta.outputs.appname }}'
|
|
APP='${{ steps.meta.outputs.appname }}'
|
|
|
BASE="$APP-$VER"
|
|
BASE="$APP-$VER"
|
|
|
PKG=packages/main-release
|
|
PKG=packages/main-release
|
|
|
mkdir -p upload
|
|
mkdir -p upload
|
|
|
- copy() { # <glob-dir> <ext>
|
|
|
|
|
- for f in "$1"/*."$2"; do
|
|
|
|
|
- [ -e "$f" ] && cp -v "$f" "upload/$BASE.$2" && return 0
|
|
|
|
|
|
|
+
|
|
|
|
|
+ copy_pkg() {
|
|
|
|
|
+ local dir="$1" ext="$2"
|
|
|
|
|
+ for f in "$dir"/*."$ext"; do
|
|
|
|
|
+ if [ -e "$f" ]; then
|
|
|
|
|
+ cp -v "$f" "upload/$BASE.$ext"
|
|
|
|
|
+ return 0
|
|
|
|
|
+ fi
|
|
|
done
|
|
done
|
|
|
return 0
|
|
return 0
|
|
|
}
|
|
}
|
|
|
- copy "$PKG/deb" deb
|
|
|
|
|
- copy "$PKG/rpm" rpm
|
|
|
|
|
- copy "$PKG/appimage" AppImage
|
|
|
|
|
- copy "$PKG/exe" exe
|
|
|
|
|
- copy "$PKG/dmg" dmg
|
|
|
|
|
- for f in androidApp/build/outputs/apk/release/*.apk; do
|
|
|
|
|
- [ -e "$f" ] && cp -v "$f" "upload/$BASE.apk" && break
|
|
|
|
|
- done
|
|
|
|
|
- for f in releases/*.iso; do
|
|
|
|
|
- [ -e "$f" ] && cp -v "$f" "upload/$BASE.iso" && break
|
|
|
|
|
- done
|
|
|
|
|
- # reports tree zipped into the release
|
|
|
|
|
|
|
+
|
|
|
|
|
+ if compgen -G "releases/*" > /dev/null; then
|
|
|
|
|
+ cp -av releases/* upload/
|
|
|
|
|
+ fi
|
|
|
|
|
+
|
|
|
|
|
+ copy_pkg "$PKG/exe" exe
|
|
|
|
|
+ copy_pkg "$PKG/dmg" dmg
|
|
|
|
|
+ [ -f "upload/$BASE.deb" ] || copy_pkg "$PKG/deb" deb
|
|
|
|
|
+ [ -f "upload/$BASE.rpm" ] || copy_pkg "$PKG/rpm" rpm
|
|
|
|
|
+ [ -f "upload/$BASE.AppImage" ] || copy_pkg "$PKG/appimage" AppImage
|
|
|
|
|
+ if [ ! -f "upload/$BASE.apk" ]; then
|
|
|
|
|
+ for f in androidApp/build/outputs/apk/release/*.apk; do
|
|
|
|
|
+ [ -e "$f" ] && cp -v "$f" "upload/$BASE.apk" && break
|
|
|
|
|
+ done
|
|
|
|
|
+ fi
|
|
|
|
|
+ if [ ! -f "upload/$BASE.iso" ]; then
|
|
|
|
|
+ for f in releases/*.iso; do
|
|
|
|
|
+ [ -e "$f" ] && cp -v "$f" "upload/$BASE.iso" && break
|
|
|
|
|
+ done
|
|
|
|
|
+ fi
|
|
|
|
|
+
|
|
|
if [ -d reports ] && [ -n "$(ls -A reports 2>/dev/null)" ]; then
|
|
if [ -d reports ] && [ -n "$(ls -A reports 2>/dev/null)" ]; then
|
|
|
- (cd reports && zip -r "../upload/$BASE-reports.zip" .) || echo "::warning::reports zip failed"
|
|
|
|
|
|
|
+ (cd reports && zip -r "../upload/$BASE-reports.zip" .)
|
|
|
fi
|
|
fi
|
|
|
- echo "=== produced for ${{ matrix.target }} ==="; ls -la upload/ || true
|
|
|
|
|
|
|
+ echo "=== produced for ${{ matrix.target }} ==="
|
|
|
|
|
+ ls -la upload/
|
|
|
|
|
+
|
|
|
|
|
+ require_artifact() {
|
|
|
|
|
+ local file="upload/$1"
|
|
|
|
|
+ if [ ! -s "$file" ]; then
|
|
|
|
|
+ echo "::error::required release artifact is missing or empty: $1"
|
|
|
|
|
+ exit 1
|
|
|
|
|
+ fi
|
|
|
|
|
+ }
|
|
|
|
|
+
|
|
|
|
|
+ case '${{ matrix.target }}' in
|
|
|
|
|
+ linux-iso)
|
|
|
|
|
+ require_artifact "$BASE.deb"
|
|
|
|
|
+ require_artifact "$BASE.rpm"
|
|
|
|
|
+ require_artifact "$BASE.AppImage"
|
|
|
|
|
+ require_artifact "$BASE.iso"
|
|
|
|
|
+ ;;
|
|
|
|
|
+ android)
|
|
|
|
|
+ require_artifact "$BASE.apk"
|
|
|
|
|
+ ;;
|
|
|
|
|
+ windows)
|
|
|
|
|
+ require_artifact "$BASE.exe"
|
|
|
|
|
+ ;;
|
|
|
|
|
+ macos)
|
|
|
|
|
+ require_artifact "$BASE.dmg"
|
|
|
|
|
+ ;;
|
|
|
|
|
+ esac
|
|
|
|
|
|
|
|
- name: Upload build artifacts
|
|
- name: Upload build artifacts
|
|
|
- if: always()
|
|
|
|
|
uses: actions/upload-artifact@v4
|
|
uses: actions/upload-artifact@v4
|
|
|
with:
|
|
with:
|
|
|
name: dist-${{ matrix.target }}
|
|
name: dist-${{ matrix.target }}
|
|
@@ -210,4 +277,4 @@ jobs:
|
|
|
files: dist/**
|
|
files: dist/**
|
|
|
fail_on_unmatched_files: false
|
|
fail_on_unmatched_files: false
|
|
|
env:
|
|
env:
|
|
|
- GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }}
|
|
|
|
|
|
|
+ GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }}
|