# The Steamify ISO's release, step 2 of 2 (the Gitea mirror, git.upriser.nl, on its own runner): builds the # ISO for a release tag that iso-1-github-tag.yml created on GitHub (it comes in with the mirror's sync, and a # release on the mirror only survives its syncs when its tag comes from GitHub), then attaches the ISO, its # checksums and package list to the mirror's release for that tag. The tag names the Steamify version and # the time: v-- (master) or v-dev.<...> (feat/steamify, a pre-release); # the ISO gets exactly that Steamify release, and its label the same moment. GitHub skips it. # Four jobs: build the ISO -> test it (the boot loader test of steamify-cachyos-dev, one job per loader, in # parallel when the runner's capacity allows) -> the vmtest.sh suites -> release, only when every test passed. # The runner needs /dev/kvm, privileged containers (archiso mounts loop devices) and ~20 GB of disk; Gitea's # [repository.release] FILE_MAX_SIZE must allow the ISO (default 2 GB). name: ISO 2/2 ยท Build, test and publish (Gitea) on: push: tags: ['v*'] workflow_dispatch: # One run at a time for the whole workflow (not per tag): a new run stops the running one and takes over. concurrency: group: steamify-iso cancel-in-progress: true jobs: build: name: Build the ISO if: github.server_url != 'https://github.com' runs-on: ubuntu-latest container: image: docker.io/cachyos/cachyos:latest options: --privileged defaults: run: shell: bash outputs: steamify: ${{ steps.tag.outputs.steamify }} steps: # First only what the cache action needs (node, git), then the caches, then the rest from the restored cache. - name: Node and git id: node run: | pacman-key --init && pacman-key --populate pacman -Syu --noconfirm --needed nodejs git # The caches' keys: one entry per ISO week (an exact hit saves nothing, a new week restores the old one and saves once). echo "week=$(date -u +%G-%V)" >> "$GITHUB_OUTPUT" - name: Cache - pacman packages uses: actions/cache@v4 with: path: /var/cache/pacman/pkg key: pacman-build-${{ steps.node.outputs.week }} restore-keys: pacman-build- - name: Tools run: pacman -S --noconfirm --needed archiso mkinitcpio-archiso squashfs-tools grub sudo curl jq - uses: actions/checkout@v4 with: fetch-depth: 0 - name: Version and time from the tag id: tag run: | tag="${{ github.ref_name }}" [[ "$tag" =~ ^v([0-9]+\.[0-9]+\.[0-9]+)-(dev\.)?([0-9]{4})\.([0-9]{2})\.([0-9]{2})-([0-9]{4})$ ]] || { echo "::error::$tag is not a Steamify ISO release tag (v-[dev.]-)"; exit 1; } m=("${BASH_REMATCH[@]}") { echo "STEAMIFY_VERSION=${m[1]}" # One moment for the ISO's label (profiledef.sh) and the release's name: the tag's (UTC). echo "STEAMIFY_BUILD_STAMP=${m[3]}${m[4]}${m[5]}_${m[6]}" echo "ISO_PRERELEASE=$([ -n "${m[2]}" ] && echo true || echo false)" # The ISO's file name: the tag without its v (profiledef.sh). echo "STEAMIFY_ISO_VERSION=${tag#v}" } >> "$GITHUB_ENV" echo "steamify=${m[1]}" >> "$GITHUB_OUTPUT" - name: Steamify on the ISO (the version the tag names) run: ./steamify-prepare.sh - name: Build run: | ./build-live-modules.sh ./build-calamares-modules.sh ./buildiso.sh -p desktop -w || ./buildiso.sh -p desktop -c -w - name: Keep the ISO for the tests and the release uses: christopherhx/gitea-upload-artifact@v4 with: name: iso path: | out/desktop/*.iso out/desktop/*.iso.sha256 out/desktop/*.iso.sha1 out/desktop/*.pkgs.txt retention-days: 3 test: name: Test ${{ matrix.loader }} needs: build runs-on: ubuntu-latest timeout-minutes: 90 container: image: docker.io/cachyos/cachyos:latest options: --privileged strategy: fail-fast: false # The runner has ~20 GB of RAM for this: an install VM takes 6 GB (4 GB once installed), so two at a time (needs the # runner's `capacity: 2`; with 1 they run one after the other). max-parallel: 2 matrix: loader: [limine, systemd-boot, grub] defaults: run: shell: bash steps: # First only what the cache action needs (node, git), then the caches, then the rest from the restored cache. - name: Node and git id: node run: | pacman-key --init && pacman-key --populate pacman -Syu --noconfirm --needed nodejs git # The caches' keys: one entry per ISO week (an exact hit saves nothing, a new week restores the old one and saves once). echo "week=$(date -u +%G-%V)" >> "$GITHUB_OUTPUT" - name: Cache - pacman packages uses: actions/cache@v4 with: path: /var/cache/pacman/pkg key: pacman-test-${{ steps.node.outputs.week }} restore-keys: pacman-test- # The guests' packages (VM_CACHE, shared into the VMs): downloaded once for every run. - name: Cache - the VMs' packages uses: actions/cache@v4 with: path: /root/vms/pkg-cache key: vmpkg-${{ needs.build.outputs.steamify }}-${{ steps.node.outputs.week }} restore-keys: | vmpkg-${{ needs.build.outputs.steamify }}- vmpkg- - name: Tools and KVM run: | pacman -S --noconfirm --needed qemu-desktop edk2-ovmf openssh libarchive procps-ng util-linux python git sudo # Fail at once, with a reason, when the runner cannot run a VM with KVM. [ -c /dev/kvm ] || { echo "::error::no /dev/kvm in this container: the runner needs KVM (and privileged containers)"; exit 1; } nproc; free -g | sed -n 2p; df -h . | tail -n 1 # The test scripts expect their repos side by side: steamify-cachyos-dev (the scripts), # steamify-cachyos at the Steamify version the ISO has (shared into the VM, 9p `repo`). - uses: actions/checkout@v4 with: repository: theupriser/steamify-cachyos-dev path: steamify-cachyos-dev - uses: actions/checkout@v4 with: repository: theupriser/steamify-cachyos ref: v${{ needs.build.outputs.steamify }} path: steamify-cachyos - uses: christopherhx/gitea-download-artifact@v4 with: name: iso path: iso - name: Boot loader test (${{ matrix.loader }}) env: CI: "1" VM_TIMEZONE: UTC # The runner is 4 cores / 8 threads: two VMs with 2 vCPUs leave 4 threads for the host and the runner. VM_CPUS: "2" # RAM of the live installer VM (the ISO is read from its cdrom, only the overlay and the installer use RAM); 8 GB is the local default, lean with headroom: lower it only after a run shows the install stays well under VM_INSTALL_MEM: 6G VM_ISO_DIR: ${{ github.workspace }}/iso run: | mkdir -p ~/.ssh ~/vms/pkg-cache ssh-keygen -q -t ed25519 -N "" -C steamify-vm -f ~/.ssh/steamify-vm_ed25519 iso="$(ls "$VM_ISO_DIR"/*.iso | head -n 1)" cd steamify-cachyos-dev VM_ISO="$iso" scripts/vmbootloadertest.sh "${{ matrix.loader }}" --install - name: Logs if: always() uses: christopherhx/gitea-upload-artifact@v4 with: name: test-${{ matrix.loader }} path: | /root/vms/bl-${{ matrix.loader }}.test.log /root/vms/bl-${{ matrix.loader }}/vm.log retention-days: 7 if-no-files-found: ignore suites: name: Test suites (vmtest.sh) # After the boot loader tests, not next to them: the runner is small, and a broken ISO needs no suites. needs: [build, test] runs-on: ubuntu-latest timeout-minutes: 150 container: image: docker.io/cachyos/cachyos:latest options: --privileged defaults: run: shell: bash steps: # First only what the cache action needs (node, git), then the caches, then the rest from the restored cache. - name: Node and git id: node run: | pacman-key --init && pacman-key --populate pacman -Syu --noconfirm --needed nodejs git # The caches' keys: one entry per ISO week (an exact hit saves nothing, a new week restores the old one and saves once). echo "week=$(date -u +%G-%V)" >> "$GITHUB_OUTPUT" - name: Cache - pacman packages uses: actions/cache@v4 with: path: /var/cache/pacman/pkg key: pacman-test-${{ steps.node.outputs.week }} restore-keys: pacman-test- # The guests' packages (VM_CACHE, shared into the VMs): downloaded once for every run. - name: Cache - the VMs' packages uses: actions/cache@v4 with: path: /root/vms/pkg-cache key: vmpkg-${{ needs.build.outputs.steamify }}-${{ steps.node.outputs.week }} restore-keys: | vmpkg-${{ needs.build.outputs.steamify }}- vmpkg- - name: Tools and KVM run: | pacman -S --noconfirm --needed qemu-desktop edk2-ovmf openssh libarchive procps-ng util-linux python git sudo # Fail at once, with a reason, when the runner cannot run a VM with KVM. [ -c /dev/kvm ] || { echo "::error::no /dev/kvm in this container: the runner needs KVM (and privileged containers)"; exit 1; } nproc; free -g | sed -n 2p; df -h . | tail -n 1 # vmtest.sh wants its repos side by side: steamify-cachyos-dev (the scripts), steamify-cachyos at the # ISO's Steamify version (shared into the VMs) and this repository (which boot loaders the ISO advertises). - uses: actions/checkout@v4 with: path: steamify-cachyos-live-iso - uses: actions/checkout@v4 with: repository: theupriser/steamify-cachyos-dev path: steamify-cachyos-dev - uses: actions/checkout@v4 with: repository: theupriser/steamify-cachyos ref: v${{ needs.build.outputs.steamify }} path: steamify-cachyos # The suites run on a plain CachyOS VM (Plasma, no Steamify): the newest CachyOS ISO, installed once; # every block then starts from a fresh overlay of that VM. # The CachyOS ISO (~3 GB) is cached per release (the release get-iso.sh would download). - name: CachyOS release id: cachyos run: | rel="$(curl -fsL https://cachyos.org/download/ | grep -oE 'cachyos-desktop-linux-[0-9]+' | head -n 1)" echo "release=${rel:?no CachyOS release found}" >> "$GITHUB_OUTPUT" - name: Cache - the CachyOS ISO uses: actions/cache@v4 with: path: | steamify-cachyos-dev/cachyos.iso steamify-cachyos-dev/cachyos.iso.version key: cachyos-iso-${{ steps.cachyos.outputs.release }} - name: Plain CachyOS VM env: CI: "1" VM_TIMEZONE: UTC VM_CPUS: "2" VM_INSTALL_MEM: 6G VM_STEAMIFY: skip run: | mkdir -p ~/.ssh ~/vms/pkg-cache ssh-keygen -q -t ed25519 -N "" -C steamify-vm -f ~/.ssh/steamify-vm_ed25519 cd steamify-cachyos-dev ./get-iso.sh # does nothing when the cached ISO is the current release VM_DIR="$HOME/vms/steamify-vm" scripts/vminstall.sh --iso cachyos.iso # Two suites at a time, 4 GB and 2 vCPUs each (vmsuite.sh). - name: vmtest.sh (every suite) env: CI: "1" VM_CPUS: "2" MAX_PARALLEL: "2" run: | cd steamify-cachyos-dev scripts/vmtest.sh cli menu hw installer toggles - name: Logs if: always() uses: christopherhx/gitea-upload-artifact@v4 with: name: test-suites path: | /root/vms/last-test.txt /root/vms/run-*.log retention-days: 7 if-no-files-found: ignore release: name: Release needs: [build, test, suites] runs-on: ubuntu-latest container: image: docker.io/cachyos/cachyos:latest defaults: run: shell: bash steps: - name: Tools run: | pacman-key --init && pacman-key --populate # nodejs: the actions below run in this container pacman -Syu --noconfirm --needed git nodejs curl jq - uses: actions/checkout@v4 with: fetch-depth: 0 - name: Version and time from the tag run: | tag="${{ github.ref_name }}" [[ "$tag" =~ ^v([0-9]+\.[0-9]+\.[0-9]+)-(dev\.)?([0-9]{4})\.([0-9]{2})\.([0-9]{2})-([0-9]{4})$ ]] || { echo "::error::$tag is not a Steamify ISO release tag (v-[dev.]-)"; exit 1; } m=("${BASH_REMATCH[@]}") { echo "STEAMIFY_VERSION=${m[1]}" # One moment for the ISO's label (profiledef.sh) and the release's name: the tag's (UTC). echo "STEAMIFY_BUILD_STAMP=${m[3]}${m[4]}${m[5]}_${m[6]}" echo "ISO_PRERELEASE=$([ -n "${m[2]}" ] && echo true || echo false)" # The ISO's file name: the tag without its v (profiledef.sh). echo "STEAMIFY_ISO_VERSION=${tag#v}" } >> "$GITHUB_ENV" - uses: christopherhx/gitea-download-artifact@v4 with: name: iso path: out/desktop - name: Release name and notes id: rel env: TOKEN: ${{ github.token }} run: | iso="$(ls out/desktop/*.iso | head -n 1)" [ -f "$iso" ] || { echo "::error::no ISO in out/desktop"; exit 1; } tag="${{ github.ref_name }}" b="$STEAMIFY_BUILD_STAMP" stamp="${b:0:4}.${b:4:2}.${b:6:2}-${b:9:4}" if [ "$ISO_PRERELEASE" = true ]; then name="CachyOS with Steamify Live ISO $STEAMIFY_VERSION (test build $stamp UTC)" else name="CachyOS with Steamify Live ISO $STEAMIFY_VERSION ($stamp UTC)" fi # Never overwritten: a release for this tag that already has the ISO is left alone. api="${{ github.server_url }}/api/v1/repos/${{ github.repository }}" if curl -fsS -H "Authorization: token $TOKEN" "$api/releases/tags/$tag" -o /tmp/rel.json && [ "$(jq '[.assets[] | select(.name | endswith(".iso"))] | length' /tmp/rel.json)" -gt 0 ]; then echo "::warning::$tag already has its ISO and won't be overwritten." echo "publish=false" >> "$GITHUB_OUTPUT"; exit 0 fi { echo "publish=true"; echo "name=$name"; } >> "$GITHUB_OUTPUT" section="$(awk '/^## CachyOS with Steamify Live ISO/ {found = 1; next} found && /^#/ {exit} found' CHANGELOG.md)" { echo "Built from \`$(git rev-parse --short HEAD)\` ($tag) with Steamify $STEAMIFY_VERSION." echo echo "SHA-256: \`$(cut -d' ' -f1 "$iso.sha256")\`, label \`STEAMIFY_${STEAMIFY_VERSION//./_}_$b\`" echo echo "Sources: [Steamify](https://github.com/theupriser/steamify-cachyos/tree/v$STEAMIFY_VERSION), this repository at this tag, and the packages' sources at [CachyOS](https://github.com/CachyOS) and [Arch Linux](https://archlinux.org/packages/)." echo echo "$section" } > release-notes.md cat release-notes.md - name: Publish ${{ github.ref_name }} if: steps.rel.outputs.publish == 'true' uses: akkuman/gitea-release-action@v1.3.7 with: token: ${{ github.token }} tag_name: ${{ github.ref_name }} name: ${{ steps.rel.outputs.name }} body_path: release-notes.md prerelease: ${{ env.ISO_PRERELEASE }} files: | out/desktop/*.iso out/desktop/*.iso.sha256 out/desktop/*.iso.sha1 out/desktop/*.pkgs.txt