Repository navigation
49.1.0 #73
Workflow file for this run
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
| # Cut a release whenever a new tag is pushed or via workflow_dispatch. | |
| # Uses bazel-contrib release ruleset: build, attest, and publish to GitHub Releases. | |
| # A separate matrix job attaches host-native Rust CLI binaries to the draft release. | |
| # | |
| # Unit, lint, and tooling tests gate the release from inside the reusable | |
| # workflow's build job (`bazel_test_command` below). The nested-Bazel e2e suite | |
| # (`//tests:e2e_test`) does not: it runs on PRs and master in ci.yaml | |
| # (`rust-candidate-e2e`), where it has a JDK, per-case timeouts, and its own | |
| # runner. Putting it here blocked the rest of the release for hours (#499). | |
| name: Release | |
| on: | |
| workflow_dispatch: | |
| inputs: | |
| tag_name: | |
| description: Git tag being released | |
| required: true | |
| type: string | |
| push: | |
| tags: | |
| - "v*.*.*" | |
| permissions: | |
| id-token: write | |
| attestations: write | |
| contents: write | |
| jobs: | |
| release: | |
| uses: bazel-contrib/.github/.github/workflows/release_ruleset.yaml@v7.4.0 | |
| with: | |
| release_files: archives/*.* | |
| # Replaces the reusable workflow's default (`bazel test //...`), which | |
| # would pull in //tests:e2e_test. Substituted into a `run:` step | |
| # verbatim; the workflow appends its own --disk_cache/--repository_cache | |
| # flags after the command, so do not put a `--` target terminator here. | |
| # | |
| # //src/... and //tools/... are the unit/tooling tests. The clippy and | |
| # rustfmt gates compile the e2e crate as a lint root; they do not run it. | |
| # --build_tests_only: build what those tests need -- the release binary | |
| # itself comes from the rust-binaries matrix below. | |
| # --test_output=errors: the failing test's log goes to the job output, | |
| # which is the only place it can go from inside the reusable workflow. | |
| bazel_test_command: >- | |
| bazel test //src/... //tools/... //:rust_clippy_check //:rust_format_check | |
| --build_tests_only --test_output=errors | |
| prerelease: false | |
| draft: true | |
| tag_name: ${{ inputs.tag_name || github.ref_name }} | |
| permissions: | |
| id-token: write # Needed to attest provenance | |
| attestations: write # Needed to attest provenance | |
| contents: write # Needed to upload release files | |
| secrets: {} | |
| publish: | |
| needs: release | |
| uses: ./.github/workflows/publish.yaml | |
| with: | |
| tag_name: ${{ inputs.tag_name || github.ref_name }} | |
| secrets: | |
| BCR_PUBLISH_TOKEN: ${{ secrets.BCR_PUBLISH_TOKEN }} | |
| rust-binaries: | |
| needs: release | |
| runs-on: ${{ matrix.os }} | |
| permissions: | |
| contents: write | |
| strategy: | |
| fail-fast: false | |
| matrix: | |
| # bazel_startup_flags shortens the output root on Windows because MSVC's | |
| # link.exe is MAX_PATH-bound (260): under the default root the Rust | |
| # stdlib rlib ...\librustc_std_workspace_alloc-<hash>.rlib comes to 263 | |
| # characters and the link fails with LNK1181. Keep in sync with the | |
| # `release-artifacts` job in ci.yaml, which is where this gets exercised | |
| # per-PR -- including release_config, which builds the Linux assets | |
| # statically against musl so they run on any distribution rather than | |
| # requiring the runner's glibc or newer. linux-arm64 is a second Ubuntu | |
| # row here (jobs are named by asset) but extra steps in the same CI job | |
| # so that check name does not change. | |
| include: | |
| - os: ubuntu-latest | |
| asset: bazel-diff-rust-linux-amd64 | |
| release_config: release-musl | |
| bazel_startup_flags: "" | |
| bazel_extra_flags: "" | |
| - os: ubuntu-latest | |
| asset: bazel-diff-rust-linux-arm64 | |
| release_config: release-musl-arm64 | |
| bazel_startup_flags: "" | |
| bazel_extra_flags: "" | |
| - os: macos-latest | |
| asset: bazel-diff-rust-macos-arm64 | |
| release_config: release | |
| bazel_startup_flags: "" | |
| bazel_extra_flags: "" | |
| - os: windows-latest | |
| asset: bazel-diff-rust-windows-amd64.exe | |
| release_config: release | |
| bazel_startup_flags: "--output_user_root=C:/b" | |
| bazel_extra_flags: "--legacy_external_runfiles" | |
| steps: | |
| - name: Checkout | |
| uses: actions/checkout@v4 | |
| with: | |
| ref: ${{ inputs.tag_name || github.ref_name }} | |
| - name: Setup Go environment | |
| uses: actions/setup-go@v5 | |
| with: | |
| go-version: ^1.17 | |
| - name: Setup Bazelisk (Linux/macOS) | |
| if: runner.os != 'Windows' | |
| run: | | |
| go install github.com/bazelbuild/bazelisk@latest | |
| echo "$(go env GOPATH)/bin" >> "$GITHUB_PATH" | |
| - name: Setup Bazelisk (Windows) | |
| if: runner.os == 'Windows' | |
| shell: pwsh | |
| run: | | |
| go install github.com/bazelbuild/bazelisk@latest | |
| echo "$(go env GOPATH)\bin" | Out-File -FilePath $env:GITHUB_PATH -Encoding utf8 -Append | |
| # //release:bazel-diff-rust names the binary for the platform Bazel built | |
| # it for, so nothing here renames or relocates it: bazel-bin/release/ holds | |
| # the published asset, and `gh release upload` keeps that file name. The | |
| # build flags live in .bazelrc under matrix.release_config. | |
| - name: Build Rust binary | |
| shell: bash | |
| env: | |
| # Windows runs this under Git bash, whose MSYS runtime rewrites any | |
| # argument starting with `//package` into a `/package` Windows path -- | |
| # Bazel then rejects "invalid package name '/release'". (`//:target` | |
| # survived only because it has no path-like segment to convert.) | |
| MSYS2_ARG_CONV_EXCL: '//' | |
| run: bazelisk ${{ matrix.bazel_startup_flags }} build //release:bazel-diff-rust --config=${{ matrix.release_config }} ${{ matrix.bazel_extra_flags }} | |
| # Last gate before the asset is published: a glibc-linked binary here | |
| # would strand every user on an older distribution than the runner. | |
| - name: Assert Linux binary is statically linked | |
| if: runner.os == 'Linux' | |
| run: .github/workflows/assert_static_binary.sh "bazel-bin/release/${{ matrix.asset }}" | |
| - name: Upload release asset | |
| shell: bash | |
| env: | |
| TAG: ${{ inputs.tag_name || github.ref_name }} | |
| GH_TOKEN: ${{ github.token }} | |
| run: | | |
| gh release upload "$TAG" "bazel-bin/release/${{ matrix.asset }}" \ | |
| --clobber \ | |
| --repo "$GITHUB_REPOSITORY" | |
| finalize: | |
| needs: [publish, rust-binaries] | |
| runs-on: ubuntu-latest | |
| permissions: | |
| contents: write | |
| steps: | |
| - run: gh release edit "$TAG" --draft=false --repo "$GITHUB_REPOSITORY" | |
| env: | |
| TAG: ${{ inputs.tag_name || github.ref_name }} | |
| GH_TOKEN: ${{ github.token }} |