mirror of
https://github.com/theupriser/steamify-cachyos-live-iso.git
synced 2026-10-02 15:10:26 +02:00
248 lines
11 KiB
YAML
248 lines
11 KiB
YAML
# The Steamify ISO's release, step 2 of 2 (the Gitea mirror, git.upriser.nl, on its own runner): builds the
|
|
# ISO for a release tag that iso-1-github-tag.yml created on GitHub (it comes in with the mirror's sync, and a
|
|
# release on the mirror only survives its syncs when its tag comes from GitHub), then attaches the ISO, its
|
|
# checksums and package list to the mirror's release for that tag. The tag names the Steamify version and
|
|
# the time: v<steamify>-<YYYY.MM.DD>-<HHMM> (master) or v<steamify>-dev.<...> (feat/steamify, a pre-release);
|
|
# the ISO gets exactly that Steamify release, and its label the same moment. GitHub skips it.
|
|
# Two jobs: build the ISO -> release it. The VM tests run on GitHub (steamify-cachyos vmtest.yml, the newest ISO release of
|
|
# this mirror), where the runners are bigger.
|
|
# The runner needs privileged containers (archiso mounts loop devices) and ~20 GB of disk; Gitea's
|
|
# [repository.release] FILE_MAX_SIZE must allow the ISO (default 2 GB).
|
|
name: ISO 2/2 · Build and publish (Gitea)
|
|
|
|
# Started by iso-1-github-tag.yml through the mirror's dispatch API, with the tag as the ref (a replaced tag starts no
|
|
# run by itself, so nothing is triggered by tag pushes).
|
|
on:
|
|
workflow_dispatch:
|
|
inputs:
|
|
steamify_ref:
|
|
description: "Steamify branch or tag to build with (set by iso-1; empty: the release the tag names)"
|
|
type: string
|
|
default: ""
|
|
|
|
# One run at a time for the whole workflow (not per tag): a new run stops the running one and takes over.
|
|
concurrency:
|
|
group: steamify-iso
|
|
cancel-in-progress: true
|
|
|
|
jobs:
|
|
build:
|
|
name: Build the ISO
|
|
if: github.server_url != 'https://github.com'
|
|
runs-on: ubuntu-latest
|
|
container:
|
|
image: docker.io/cachyos/cachyos:latest
|
|
options: --privileged
|
|
defaults:
|
|
run:
|
|
shell: bash
|
|
outputs:
|
|
steamify: ${{ steps.tag.outputs.steamify }}
|
|
steps:
|
|
# First only what the cache action needs (node, git), then the caches, then the rest from the restored cache.
|
|
- name: Node and git
|
|
id: node
|
|
run: |
|
|
pacman-key --init && pacman-key --populate
|
|
pacman -Syu --noconfirm --needed nodejs git
|
|
# The caches' keys: one entry per ISO week (an exact hit saves nothing, a new week restores the old one and saves once).
|
|
echo "week=$(date -u +%G-%V)" >> "$GITHUB_OUTPUT"
|
|
- name: Cache - pacman packages
|
|
uses: actions/cache@v4
|
|
with:
|
|
path: /var/cache/pacman/pkg
|
|
key: pacman-build-${{ steps.node.outputs.week }}
|
|
restore-keys: pacman-build-
|
|
- name: Tools
|
|
run: pacman -S --noconfirm --needed archiso mkinitcpio-archiso squashfs-tools grub sudo curl jq
|
|
|
|
|
|
- uses: actions/checkout@v4
|
|
with:
|
|
fetch-depth: 0
|
|
|
|
- name: Version and time from the tag
|
|
id: tag
|
|
run: |
|
|
tag="${{ github.ref_name }}"
|
|
[[ "$tag" =~ ^v([0-9]+\.[0-9]+\.[0-9]+)-(dev-)?([0-9]{6})$ ]] ||
|
|
{ echo "::error::$tag is not a Steamify ISO release tag (v<steamify>-[dev-]<YYMMDD>)"; exit 1; }
|
|
m=("${BASH_REMATCH[@]}")
|
|
{
|
|
echo "STEAMIFY_VERSION=${m[1]}"
|
|
# The day (YYMMDD, UTC) for the ISO's label (profiledef.sh) and the release's name: the tag's.
|
|
echo "STEAMIFY_BUILD_STAMP=${m[3]}"
|
|
echo "ISO_PRERELEASE=$([ -n "${m[2]}" ] && echo true || echo false)"
|
|
# The ISO's file name: the tag without its v (profiledef.sh).
|
|
echo "STEAMIFY_ISO_VERSION=${tag#v}"
|
|
} >> "$GITHUB_ENV"
|
|
|
|
echo "steamify=${m[1]}" >> "$GITHUB_OUTPUT"
|
|
|
|
- name: Steamify on the ISO (the version the tag names)
|
|
run: |
|
|
ref="${{ inputs.steamify_ref }}"
|
|
if [ -n "$ref" ]; then
|
|
# A branch (a release branch before its release): its checkout goes on the ISO.
|
|
git clone -q --depth 1 --branch "$ref" https://github.com/theupriser/steamify-cachyos.git /tmp/steamify-src
|
|
./steamify-prepare.sh /tmp/steamify-src
|
|
else
|
|
./steamify-prepare.sh
|
|
fi
|
|
|
|
- name: Build
|
|
run: |
|
|
./build-live-modules.sh
|
|
./build-calamares-modules.sh
|
|
./buildiso.sh -p desktop -w || ./buildiso.sh -p desktop -c -w
|
|
|
|
|
|
- name: Keep the ISO for the tests and the release
|
|
uses: christopherhx/gitea-upload-artifact@v4
|
|
with:
|
|
name: iso
|
|
path: |
|
|
out/desktop/*.iso
|
|
out/desktop/*.iso.sha256
|
|
out/desktop/*.iso.sha1
|
|
out/desktop/*.pkgs.txt
|
|
retention-days: 3
|
|
|
|
release:
|
|
name: Release
|
|
needs: build
|
|
runs-on: ubuntu-latest
|
|
container:
|
|
image: docker.io/cachyos/cachyos:latest
|
|
defaults:
|
|
run:
|
|
shell: bash
|
|
steps:
|
|
- name: Tools
|
|
run: |
|
|
pacman-key --init && pacman-key --populate
|
|
# nodejs: the actions below run in this container
|
|
pacman -Syu --noconfirm --needed git nodejs curl jq
|
|
|
|
|
|
- uses: actions/checkout@v4
|
|
with:
|
|
fetch-depth: 0
|
|
|
|
- name: Version and time from the tag
|
|
run: |
|
|
tag="${{ github.ref_name }}"
|
|
[[ "$tag" =~ ^v([0-9]+\.[0-9]+\.[0-9]+)-(dev-)?([0-9]{6})$ ]] ||
|
|
{ echo "::error::$tag is not a Steamify ISO release tag (v<steamify>-[dev-]<YYMMDD>)"; exit 1; }
|
|
m=("${BASH_REMATCH[@]}")
|
|
{
|
|
echo "STEAMIFY_VERSION=${m[1]}"
|
|
# The day (YYMMDD, UTC) for the ISO's label (profiledef.sh) and the release's name: the tag's.
|
|
echo "STEAMIFY_BUILD_STAMP=${m[3]}"
|
|
echo "ISO_PRERELEASE=$([ -n "${m[2]}" ] && echo true || echo false)"
|
|
# The ISO's file name: the tag without its v (profiledef.sh).
|
|
echo "STEAMIFY_ISO_VERSION=${tag#v}"
|
|
} >> "$GITHUB_ENV"
|
|
|
|
|
|
- uses: christopherhx/gitea-download-artifact@v4
|
|
with:
|
|
name: iso
|
|
path: out/desktop
|
|
|
|
- name: Release name and notes
|
|
id: rel
|
|
env:
|
|
TOKEN: ${{ github.token }}
|
|
run: |
|
|
iso="$(ls out/desktop/*.iso | head -n 1)"
|
|
[ -f "$iso" ] || { echo "::error::no ISO in out/desktop"; exit 1; }
|
|
tag="${{ github.ref_name }}" b="$STEAMIFY_BUILD_STAMP"
|
|
stamp="20${b:0:2}.${b:2:2}.${b:4:2}"
|
|
base="$(head -n 1 CHANGELOG.md | sed 's/^# *//')" # the CachyOS version, as in the GitHub release's title
|
|
if [ "$ISO_PRERELEASE" = true ]; then
|
|
name="CachyOS $base with Steamify $STEAMIFY_VERSION (test build $stamp UTC)"
|
|
else
|
|
name="CachyOS $base with Steamify $STEAMIFY_VERSION ($stamp UTC)"
|
|
fi
|
|
# One ISO per day and kind: a release of this tag from an earlier build of the day is replaced.
|
|
api="${{ github.server_url }}/api/v1/repos/${{ github.repository }}"
|
|
if curl -fsS -H "Authorization: token $TOKEN" "$api/releases/tags/$tag" -o /tmp/rel.json; then
|
|
echo "Replacing the earlier release of $tag"
|
|
curl -fsS -X DELETE -H "Authorization: token $TOKEN" "$api/releases/$(jq -r .id /tmp/rel.json)" || true
|
|
fi
|
|
{ echo "publish=true"; echo "name=$name"; } >> "$GITHUB_OUTPUT"
|
|
section="$(awk '/^## CachyOS with Steamify Live ISO/ {found = 1; next} found && /^#/ {exit} found' CHANGELOG.md)"
|
|
src="${{ inputs.steamify_ref }}"; src="${src:-v$STEAMIFY_VERSION}"
|
|
# The same notes as the GitHub release (one source: iso-1 generated them), without its badge line; the
|
|
# checksum line is added here. Fallback: a short text.
|
|
if curl -fsS "https://api.github.com/repos/theupriser/steamify-cachyos-live-iso/releases/tags/$tag" -o /tmp/ghrel.json; then
|
|
jq -r '.body // ""' /tmp/ghrel.json | sed '/ISO build\]/d' > release-notes.md
|
|
else
|
|
echo "Built from \`$(git rev-parse --short HEAD)\` ($tag) with Steamify $STEAMIFY_VERSION." > release-notes.md # fallback when GitHub cannot be reached
|
|
fi
|
|
{
|
|
echo
|
|
echo "### Checksum"
|
|
echo "SHA-256 of the ISO: \`$(cut -d' ' -f1 "$iso.sha256")\` (label \`STEAMIFY_${STEAMIFY_VERSION//./_}_$b\`)."
|
|
} >> release-notes.md
|
|
cat release-notes.md
|
|
|
|
- name: Publish ${{ github.ref_name }}
|
|
if: steps.rel.outputs.publish == 'true'
|
|
uses: akkuman/gitea-release-action@v1.3.7
|
|
with:
|
|
token: ${{ github.token }}
|
|
tag_name: ${{ github.ref_name }}
|
|
name: ${{ steps.rel.outputs.name }}
|
|
body_path: release-notes.md
|
|
prerelease: ${{ env.ISO_PRERELEASE }}
|
|
files: |
|
|
out/desktop/*.iso
|
|
out/desktop/*.iso.sha256
|
|
out/desktop/*.iso.sha1
|
|
out/desktop/*.pkgs.txt
|
|
|
|
# The result goes back to GitHub: the badge at the top of the GitHub release (started as "running" by iso-1) becomes
|
|
# succeeded / failed / cancelled and links to this run. Needs a GitHub token as the secret GH_RELEASE_TOKEN here on the
|
|
# mirror (fine-grained, this repository only, Contents: read and write); without it the badge stays "running".
|
|
report:
|
|
name: Report the result to GitHub
|
|
needs: [build, release]
|
|
if: ${{ always() && github.server_url != 'https://github.com' }}
|
|
runs-on: ubuntu-latest
|
|
container:
|
|
image: docker.io/cachyos/cachyos:latest
|
|
steps:
|
|
- name: Badge in the GitHub release
|
|
env:
|
|
GH_TOKEN: ${{ secrets.GH_RELEASE_TOKEN }}
|
|
BUILD: ${{ needs.build.result }}
|
|
RELEASE: ${{ needs.release.result }}
|
|
run: |
|
|
[ -n "$GH_TOKEN" ] || { echo "No GH_RELEASE_TOKEN: GitHub's release keeps its 'running' badge."; exit 0; }
|
|
pacman -Sy --noconfirm --needed curl python > /dev/null
|
|
tag="${{ github.ref_name }}"
|
|
if [ "$BUILD" = success ] && [ "$RELEASE" = success ]; then st=succeeded col=brightgreen
|
|
elif [ "$BUILD" = cancelled ] || [ "$RELEASE" = cancelled ]; then st=cancelled col=lightgrey
|
|
else st=failed col=red; fi
|
|
run="${{ github.server_url }}/${{ github.repository }}/actions/runs/${{ github.run_id }}"
|
|
api="https://api.github.com/repos/theupriser/steamify-cachyos-live-iso/releases"
|
|
curl -fsS -H "Authorization: Bearer $GH_TOKEN" "$api/tags/$tag" -o /tmp/rel.json || { echo "::warning::no GitHub release for $tag"; exit 0; }
|
|
ST="$st" COL="$col" RUN="$run" RUN_ID="${{ github.run_id }}" python3 - << 'PY'
|
|
import json, os, re
|
|
d = json.load(open("/tmp/rel.json"))
|
|
body = d.get("body") or ""
|
|
# This runner reports its internal address (http://server:3000) as the server URL: the public one is in the
|
|
# release page link that iso-1 wrote into the notes.
|
|
m = re.search(r"\]\((https?://[^)\s]+)/releases/tag/", body)
|
|
run = f"{m.group(1)}/actions/runs/{os.environ['RUN_ID']}" if m else os.environ["RUN"]
|
|
badge = f"[]({run})"
|
|
pat = re.compile(r"\[?!\[ISO build\]\([^)]*\)(\]\([^)]*\))?")
|
|
body = pat.sub(lambda m: badge, body, count=1) if pat.search(body) else badge + "\n\n" + body
|
|
json.dump({"body": body}, open("/tmp/patch.json", "w"))
|
|
open("/tmp/rel.id", "w").write(str(d["id"]))
|
|
PY
|
|
curl -fsS -X PATCH -H "Authorization: Bearer $GH_TOKEN" -H "Content-Type: application/json" -d @/tmp/patch.json "$api/$(cat /tmp/rel.id)" > /dev/null
|
|
echo "GitHub release $tag: ISO build $st"
|