Repository navigation
134 lines (124 loc) · 5.97 KB
/
Copy pathmacos-release.yml
File metadata and controls
134 lines (124 loc) · 5.97 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
130
131
132
133
134
name: macOS Release
on:
release:
types: [published]
permissions: {}
concurrency:
group: ${{ github.workflow }}-${{ github.ref }}
cancel-in-progress: true
jobs:
build-and-upload:
# Runner must be darwin/arm64 with Rosetta 2, Xcode CLT, Homebrew, rustup, and zstd.
runs-on: [self-hosted, macOS, ARM64]
timeout-minutes: 120
permissions:
contents: write
defaults:
run:
shell: bash
steps:
- name: clean workspace
run: rm -rf .build dist
- uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
- name: write version files
env:
# github.ref_name (evaluated by Actions) instead of $GITHUB_REF_NAME,
# which is only injected by runner >= 2.290 — empty on older
# self-hosted runners.
REF_NAME: ${{ github.ref_name }}
run: |
if [ -z "${REF_NAME:-}" ]; then
echo "REF_NAME is not set" >&2
exit 1
fi
VERSION="${REF_NAME#v}"
printf '{ "version": "%s" }\n' "$VERSION" > static/version.json
sed -i '' "s/^version = \".*\"/version = \"$VERSION\"/" desktop/src-tauri/Cargo.toml
sed -i '' "s/\"version\": \"[^\"]*\"/\"version\": \"$VERSION\"/" desktop/src-tauri/tauri.conf.json
sed -i '' "s/^version = \".*\"/version = \"$VERSION\"/" pyproject.toml
sed -i '' "s/\"version\": \"[^\"]*\"/\"version\": \"$VERSION\"/" desktop/package.json
echo "VERSION=$VERSION" >> "$GITHUB_ENV"
echo "Wrote version $VERSION to all version files"
- name: build macOS arm64
env:
SSL_CERT_FILE: /etc/ssl/cert.pem
REQUESTS_CA_BUNDLE: /etc/ssl/cert.pem
run: |
command -v zstd
command -v uv >/dev/null 2>&1 || brew install uv
uv python install cpython-3.12-macos-aarch64-none
ARM64_PYTHON="$(uv python find cpython-3.12-macos-aarch64-none)"
scripts/macos/make-iconset.sh
ARCH=arm64 VERSION="$VERSION" PYTHON_BIN="$ARM64_PYTHON" scripts/macos/make-runtime-pack.sh
ARCH=arm64 VERSION="$VERSION" scripts/macos/make-app.sh
ARCH=arm64 VERSION="$VERSION" scripts/macos/make-dmg.sh
- name: build macOS x64
env:
SSL_CERT_FILE: /etc/ssl/cert.pem
REQUESTS_CA_BUNDLE: /etc/ssl/cert.pem
run: |
command -v zstd
if ! arch -x86_64 /usr/bin/true >/dev/null 2>&1; then
echo "ERROR: Rosetta 2 is required to build the x64 runtime on this agent." >&2
exit 1
fi
rustup default stable
rustup target add x86_64-apple-darwin
command -v uv >/dev/null 2>&1 || brew install uv
uv python install cpython-3.12-macos-x86_64-none
X64_PYTHON="$(uv python find cpython-3.12-macos-x86_64-none)"
ARCH=x64 VERSION="$VERSION" PYTHON_BIN="$X64_PYTHON" scripts/macos/make-runtime-pack.sh
ARCH=x64 VERSION="$VERSION" scripts/macos/make-app.sh
ARCH=x64 VERSION="$VERSION" scripts/macos/make-dmg.sh
- name: inspect artifacts
run: |
test -f .build/macos-dist/StemDeck-macOS-arm64.dmg
test -f .build/StemDeck-runtime-macOS-arm64.tar.zst
test -f .build/macos-dist/SHA256SUMS-macOS-arm64.txt
test -f .build/macos-dist/StemDeck-macOS-x64.dmg
test -f .build/StemDeck-runtime-macOS-x64.tar.zst
test -f .build/macos-dist/SHA256SUMS-macOS-x64.txt
cat .build/macos-dist/SHA256SUMS-macOS-arm64.txt
cat .build/macos-dist/SHA256SUMS-macOS-x64.txt
du -sh .build/macos-dist/StemDeck-macOS-arm64.dmg .build/StemDeck-runtime-macOS-arm64.tar.zst
du -sh .build/macos-dist/StemDeck-macOS-x64.dmg .build/StemDeck-runtime-macOS-x64.tar.zst
if find desktop/src-tauri/target/aarch64-apple-darwin/release/bundle/macos/StemDeck.app \
\( -iname '*python*' -o -iname '*torch*' -o -iname '*ffmpeg*' -o -iname '*ffprobe*' \) |
grep -q .; then
echo "arm64 StemDeck.app contains runtime binaries that should stay outside the DMG." >&2
exit 1
fi
if find desktop/src-tauri/target/x86_64-apple-darwin/release/bundle/macos/StemDeck.app \
\( -iname '*python*' -o -iname '*torch*' -o -iname '*ffmpeg*' -o -iname '*ffprobe*' \) |
grep -q .; then
echo "x64 StemDeck.app contains runtime binaries that should stay outside the DMG." >&2
exit 1
fi
for arch in arm64 x64; do
mountpoint="$(mktemp -d /tmp/stemdeck-dmg.XXXXXX)"
hdiutil attach ".build/macos-dist/StemDeck-macOS-$arch.dmg" -readonly -nobrowse -mountpoint "$mountpoint"
trap 'hdiutil detach "$mountpoint" >/dev/null 2>&1 || true; rmdir "$mountpoint" >/dev/null 2>&1 || true' EXIT
test -d "$mountpoint/StemDeck.app"
test -L "$mountpoint/Applications"
test -f "$mountpoint/README-macOS.txt"
test -f "$mountpoint/THIRD_PARTY_NOTICES.txt"
hdiutil detach "$mountpoint"
rmdir "$mountpoint"
trap - EXIT
done
- name: upload artifacts
uses: softprops/action-gh-release@efb35369e0ad2afab669f228072c1b0d510eae64 # v3.0.3
with:
# Carry the release's own flag. The action defaults `prerelease` to
# false and writes it back, so attaching assets silently promoted a
# pre-release to the latest release -- which also fires `released`,
# pushing :latest to GHCR, and makes the in-app updater offer a build
# that was never verified.
prerelease: ${{ github.event.release.prerelease }}
files: |
.build/macos-dist/StemDeck-macOS-arm64.dmg
.build/StemDeck-runtime-macOS-arm64.tar.zst
.build/macos-dist/SHA256SUMS-macOS-arm64.txt
.build/macos-dist/StemDeck-macOS-x64.dmg
.build/StemDeck-runtime-macOS-x64.tar.zst
.build/macos-dist/SHA256SUMS-macOS-x64.txt