Trusted publishing is GitHub-Actions-only, so authentication goes through a crates.io API token stored as the CARGO_REGISTRY_TOKEN secret, scoped to the pkh crate. The job gates on the build job and fails loudly when the tag does not match the version in Cargo.toml, since cargo publish ships the declared version regardless of the tag name.
163 lines
5.4 KiB
YAML
163 lines
5.4 KiB
YAML
name: CI
|
|
|
|
on:
|
|
push:
|
|
branches: [ "main", "ci-test" ]
|
|
tags: [ "v*" ]
|
|
pull_request:
|
|
branches: [ "main" ]
|
|
|
|
env:
|
|
CARGO_TERM_COLOR: always
|
|
|
|
jobs:
|
|
build:
|
|
runs-on: ubuntu-latest
|
|
container:
|
|
image: ubuntu:26.04
|
|
options: --privileged --cap-add SYS_ADMIN --security-opt apparmor:unconfined
|
|
steps:
|
|
- name: Set up container image
|
|
run: |
|
|
apt-get update
|
|
apt-get install -y nodejs sudo curl wget ca-certificates build-essential
|
|
- uses: actions/checkout@v6
|
|
- uses: dtolnay/rust-toolchain@stable
|
|
with:
|
|
components: rustfmt, clippy
|
|
- name: Check format
|
|
run: cargo fmt --check
|
|
- name: Install build dependencies
|
|
run: |
|
|
sudo apt-get update
|
|
sudo apt-get install -y pkg-config libssl-dev libgpg-error-dev libgpgme-dev
|
|
- name: Restore cargo/target cache
|
|
uses: actions/cache@v4
|
|
with:
|
|
path: |
|
|
~/.cargo/registry
|
|
~/.cargo/git
|
|
target
|
|
key: ci-build-${{ github.sha }}
|
|
restore-keys: |
|
|
ci-build-
|
|
- name: Build
|
|
run: cargo build
|
|
env:
|
|
RUSTFLAGS: -Dwarnings
|
|
- name: Lint
|
|
run: cargo clippy --all-targets --all-features
|
|
env:
|
|
RUSTFLAGS: -Dwarnings
|
|
|
|
test:
|
|
# Disabled: test suite is too heavy for current CI infra (CPU/RAM exhaustion).
|
|
# Re-enable by removing the `if: false` line below.
|
|
if: false
|
|
needs: build
|
|
runs-on: ubuntu-latest
|
|
container:
|
|
image: ubuntu:26.04
|
|
options: --privileged --cap-add SYS_ADMIN --security-opt apparmor:unconfined
|
|
steps:
|
|
- name: Set up container image
|
|
run: |
|
|
apt-get update
|
|
apt-get install -y nodejs sudo curl wget ca-certificates build-essential
|
|
- uses: actions/checkout@v6
|
|
- uses: dtolnay/rust-toolchain@stable
|
|
- name: Restore cargo/target cache
|
|
uses: actions/cache@v4
|
|
with:
|
|
path: |
|
|
~/.cargo/registry
|
|
~/.cargo/git
|
|
target
|
|
key: ci-build-${{ github.sha }}
|
|
restore-keys: |
|
|
ci-build-
|
|
- name: Install build dependencies
|
|
run: |
|
|
sudo apt-get update
|
|
sudo apt-get install -y pkg-config libssl-dev libgpg-error-dev libgpgme-dev
|
|
- name: Install runtime system dependencies
|
|
run: |
|
|
sudo apt-get update
|
|
sudo apt-get install -y git pristine-tar mmdebstrap util-linux dpkg-dev
|
|
- name: Setup subuid/subgid
|
|
run: |
|
|
usermod --add-subuids 100000-200000 --add-subgids 100000-200000 ${USER:-root}
|
|
- name: Run tests with verbose logging (timeout 30min)
|
|
env:
|
|
RUST_LOG: debug
|
|
run: timeout 30m cargo test -- --nocapture
|
|
|
|
snap:
|
|
needs: build
|
|
runs-on: ubuntu-latest
|
|
container:
|
|
# Official snapcraft image: an Ubuntu userland matching the snap base,
|
|
# with snapcraft preinstalled (no snapd/systemd/LXD required).
|
|
image: ghcr.io/canonical/snapcraft:8_core24
|
|
steps:
|
|
- name: Install build prerequisites
|
|
run: |
|
|
apt-get update -q
|
|
apt-get install -y -q --no-install-recommends git curl nodejs
|
|
- uses: actions/checkout@v6
|
|
- name: Build snap
|
|
run: |
|
|
# GitHub Actions overrides the image entrypoint (pebble), which is
|
|
# what normally puts craftctl on PATH; restore it, allow git to run
|
|
# in the checked-out tree, and provide rustup for the rust plugin.
|
|
git config --global --add safe.directory '*'
|
|
curl --proto '=https' --tlsv1.2 -sSf https://sh.rustup.rs | sh -s -- -y --profile minimal --default-toolchain stable
|
|
export PATH="/usr/libexec/snapcraft:$HOME/.cargo/bin:$PATH"
|
|
snapcraft pack --destructive-mode
|
|
- name: Upload snap artifact
|
|
# v4 refuses to run outside github.com (GHESNotSupportedError); Gitea
|
|
# implements the artifact API used by v3, so v3 is the supported choice.
|
|
uses: actions/upload-artifact@v3
|
|
with:
|
|
name: snap
|
|
path: ./*.snap
|
|
if-no-files-found: error
|
|
|
|
publish:
|
|
# Publishes the crate to crates.io on a v* tag. Trusted publishing
|
|
# (OIDC) is GitHub-Actions-only, so authentication goes through a
|
|
# crates.io API token stored as the CARGO_REGISTRY_TOKEN secret,
|
|
# scoped to the pkh crate.
|
|
if: startsWith(github.ref, 'refs/tags/v')
|
|
needs: build
|
|
runs-on: ubuntu-latest
|
|
container:
|
|
image: ubuntu:26.04
|
|
options: --privileged --cap-add SYS_ADMIN --security-opt apparmor:unconfined
|
|
steps:
|
|
- name: Set up container image
|
|
run: |
|
|
apt-get update
|
|
apt-get install -y nodejs sudo curl wget ca-certificates
|
|
- uses: actions/checkout@v6
|
|
- uses: dtolnay/rust-toolchain@stable
|
|
- name: Install build dependencies
|
|
run: |
|
|
sudo apt-get update
|
|
sudo apt-get install -y pkg-config libssl-dev libgpg-error-dev libgpgme-dev
|
|
- name: Check the tag matches the crate version
|
|
# cargo publish ships whatever version Cargo.toml declares,
|
|
# regardless of the tag: a mismatch must fail loudly instead of
|
|
# publishing the wrong version under the release tag.
|
|
run: |
|
|
crate_version="$(awk -F'"' '/^version =/{print $2; exit}' Cargo.toml)"
|
|
tag_version="${GITHUB_REF_NAME#v}"
|
|
if [ "$crate_version" != "$tag_version" ]; then
|
|
echo "tag $GITHUB_REF_NAME does not match crate version $crate_version" >&2
|
|
exit 1
|
|
fi
|
|
- name: Publish
|
|
run: cargo publish
|
|
env:
|
|
CARGO_REGISTRY_TOKEN: ${{ secrets.CARGO_REGISTRY_TOKEN }}
|