Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
92 changes: 35 additions & 57 deletions .github/workflows/publish.yml
Original file line number Diff line number Diff line change
@@ -1,76 +1,54 @@
name: Publish

# Bumping `version` in Cargo.toml in a normal PR is the whole release: when it
# merges to master, this publishes whatever version crates.io does not have
# yet. endpoint-gen-macros goes first, since endpoint-gen depends on it by
# version. A merge that changes code but no version finds both published and
# exits green.
# House scheme, as nago-wss: a version bump on the default branch is the
# release. No tags, no manual step. Publishing is irreversible, so the trigger
# has to be something you cannot do by accident, and editing the version field
# is that.
#
# This exists because 1.14.0 merged and sat unpublished until someone ran
# `cargo publish` by hand, while four repos already declared it in
# config/version.toml.
# Two crates: endpoint-gen-macros is published first, because endpoint-gen
# depends on it by version. Each is checked and published on its own.
on:
push:
branches: [master]
paths:
- Cargo.toml
- build.rs
- src/**
- endpoint-gen-macros/**
paths: ['Cargo.toml', 'endpoint-gen-macros/Cargo.toml']
# A release that was merged before this gate was fixed has no Cargo.toml
# change left to make, so it cannot be triggered by the push rule alone.
workflow_dispatch:
inputs:
dry_run:
description: 'Package and verify, but do not upload'
required: false
type: boolean
default: false

concurrency:
group: ${{ github.workflow }}
cancel-in-progress: false

jobs:
publish:
name: crates.io
runs-on: ubicloud-standard-2
timeout-minutes: 30
steps:
- uses: actions/checkout@v6

- uses: actions/checkout@v4
- uses: dtolnay/rust-toolchain@stable

- uses: Swatinem/rust-cache@v2

- name: Test
run: cargo test --release

- name: Publish what is new
# Checked before the upload rather than during it: an absent token
# surfaces as an authentication error from `cargo publish` after the
# package is built, which reads like a registry problem.
- run: |
if [ -z "${CARGO_REGISTRY_TOKEN:-}" ]; then
echo "CARGO_REGISTRY_TOKEN is empty. Set it on pathscale/EndpointGen:"
echo " gh secret set CARGO_REGISTRY_TOKEN --repo pathscale/EndpointGen"
exit 1
fi
env:
CARGO_REGISTRY_TOKEN: ${{ secrets.CARGO_REGISTRY_TOKEN }}
DRY_RUN: ${{ inputs.dry_run }}

- run: cargo test --release

# The registry is the only authority on what is already released.
- name: Publish each crate whose version is not on crates.io
run: |
published() {
curl -sS -H 'User-Agent: pathscale-ci' "https://crates.io/api/v1/crates/$1/versions" \
| jq -r --arg v "$2" '.versions[]? | select(.num == $v) | .num'
}
for dir in endpoint-gen-macros .; do
name=$(cargo metadata --no-deps --format-version 1 --manifest-path "$dir/Cargo.toml" \
| jq -r --arg m "$(cd "$dir" && pwd)/Cargo.toml" '.packages[] | select(.manifest_path == $m) | .name')
version=$(cargo metadata --no-deps --format-version 1 --manifest-path "$dir/Cargo.toml" \
| jq -r --arg n "$name" '.packages[] | select(.name == $n) | .version')
if [ -n "$(published "$name" "$version")" ]; then
echo "$name $version is already on crates.io" | tee -a "$GITHUB_STEP_SUMMARY"
continue
fi
if [ "$DRY_RUN" = "true" ]; then
cargo package --manifest-path "$dir/Cargo.toml"
echo "Dry run: packaged $name $version" | tee -a "$GITHUB_STEP_SUMMARY"
continue
fi
if [ -z "$CARGO_REGISTRY_TOKEN" ]; then
echo "CARGO_REGISTRY_TOKEN is not set on this repository (Settings -> Secrets -> Actions)" >&2
exit 1
set -eu
for manifest in endpoint-gen-macros/Cargo.toml Cargo.toml; do
name=$(cargo read-manifest --manifest-path "$manifest" | jq -er '.name')
version=$(cargo read-manifest --manifest-path "$manifest" | jq -er '.version')
if cargo info --registry crates-io "$name@$version" >/dev/null 2>&1; then
echo "$name $version is already on crates.io, nothing to publish"
else
echo "$name $version is not on crates.io, publishing"
cargo publish --manifest-path "$manifest" --token "$CARGO_REGISTRY_TOKEN"
fi
cargo publish --manifest-path "$dir/Cargo.toml"
echo "Published $name $version" | tee -a "$GITHUB_STEP_SUMMARY"
done
env:
CARGO_REGISTRY_TOKEN: ${{ secrets.CARGO_REGISTRY_TOKEN }}
8 changes: 0 additions & 8 deletions .github/workflows/rust.yml
Original file line number Diff line number Diff line change
Expand Up @@ -99,11 +99,3 @@ jobs:

- name: Check formatting
run: cargo fmt --all -- --check

security_audit:
runs-on: ubicloud-standard-2
steps:
- uses: actions/checkout@v4
- uses: rustsec/audit-check@v2
with:
token: ${{ secrets.GITHUB_TOKEN }}
Loading