233 lines
7.8 KiB
YAML
233 lines
7.8 KiB
YAML
name: Build (reusable)
|
|
|
|
on:
|
|
workflow_call:
|
|
|
|
env:
|
|
FORCE_JAVASCRIPT_ACTIONS_TO_NODE24: true
|
|
# sccache caches compiled objects across Cargo.lock changes (rust-cache alone
|
|
# invalidates fully on dep changes). Valuable here: each job compiles several
|
|
# release targets.
|
|
SCCACHE_GHA_ENABLED: "true"
|
|
RUSTC_WRAPPER: sccache
|
|
|
|
jobs:
|
|
build-linux:
|
|
runs-on: ubuntu-latest
|
|
steps:
|
|
- name: Setup repo
|
|
uses: actions/checkout@v4
|
|
with:
|
|
fetch-depth: 0
|
|
fetch-tags: true
|
|
|
|
- name: Setup Node.js
|
|
uses: actions/setup-node@v4
|
|
with:
|
|
node-version-file: ".nvmrc"
|
|
|
|
- name: Setup Rust (linux musl + windows-gnu + freebsd targets)
|
|
uses: dtolnay/rust-toolchain@stable
|
|
with:
|
|
targets: x86_64-unknown-linux-musl,aarch64-unknown-linux-musl,armv7-unknown-linux-musleabihf,x86_64-pc-windows-gnu,x86_64-unknown-freebsd
|
|
|
|
- uses: Swatinem/rust-cache@v2
|
|
with:
|
|
key: linux-cross
|
|
|
|
- name: Setup sccache
|
|
uses: mozilla-actions/sccache-action@v0.0.10
|
|
|
|
# GHA Cache occasionally returns Azure edge errors; if the sccache daemon
|
|
# can't reach the backend it refuses to start, failing every rustc call.
|
|
# Probe once and disable for this job on outage — a slow build beats a
|
|
# failed release.
|
|
- name: Probe sccache backend, disable on outage
|
|
shell: bash
|
|
run: |
|
|
if sccache --start-server; then
|
|
echo "sccache backend reachable"
|
|
else
|
|
echo "::warning::sccache backend unreachable — disabling for this job"
|
|
echo "RUSTC_WRAPPER=" >> "$GITHUB_ENV"
|
|
echo "SCCACHE_GHA_ENABLED=false" >> "$GITHUB_ENV"
|
|
fi
|
|
|
|
- name: Install cross-toolchains
|
|
run: |
|
|
sudo apt-get update
|
|
# apt-only C cross-compilers; Rust supplies the static musl libc itself.
|
|
# clang/lld/llvm are for the FreeBSD cross-build (no apt freebsd gcc).
|
|
# (linker/CC wiring lives in .cargo/config.toml)
|
|
sudo apt-get install -y musl-tools gcc-aarch64-linux-gnu \
|
|
gcc-arm-linux-gnueabihf gcc-mingw-w64-x86-64 \
|
|
clang lld llvm
|
|
|
|
- name: Install npm dependencies
|
|
run: npm ci
|
|
|
|
- name: Build linux/windows binaries (compile once → raw + zips)
|
|
run: make build-linux-ci
|
|
|
|
- name: Build FreeBSD sb CLI
|
|
# FreeBSD cross is fiddly (clang + sysroot): this step fetches a FreeBSD
|
|
# base sysroot and cross-builds the `sb` CLI against it. It's a
|
|
# first-class build like the others — a failure here fails the job.
|
|
run: |
|
|
sudo mkdir -p /opt/freebsd-sysroot
|
|
VER=$(curl -fsSL https://download.freebsd.org/releases/amd64/ \
|
|
| grep -oE '[0-9]+\.[0-9]+-RELEASE' | sort -V | uniq | tail -1)
|
|
echo "Latest FreeBSD release: $VER"
|
|
curl -fsSL "https://download.freebsd.org/releases/amd64/$VER/base.txz" \
|
|
| sudo tar -xJf - -C /opt/freebsd-sysroot ./lib ./usr/lib ./usr/include
|
|
make build-cli-releases-freebsd
|
|
|
|
- name: Upload release zips (linux/windows/freebsd)
|
|
uses: actions/upload-artifact@v4
|
|
with:
|
|
name: release-zips-linux
|
|
path: |
|
|
silverbullet-server-*.zip
|
|
sb-*.zip
|
|
if-no-files-found: error
|
|
|
|
- name: Upload raw docker binaries
|
|
uses: actions/upload-artifact@v4
|
|
with:
|
|
name: docker-binaries
|
|
path: |
|
|
silverbullet-amd64
|
|
silverbullet-arm64
|
|
silverbullet-arm
|
|
if-no-files-found: error
|
|
|
|
build-macos:
|
|
runs-on: macos-latest
|
|
steps:
|
|
- name: Setup repo
|
|
uses: actions/checkout@v4
|
|
with:
|
|
fetch-depth: 0
|
|
fetch-tags: true
|
|
|
|
- name: Setup Node.js
|
|
uses: actions/setup-node@v4
|
|
with:
|
|
node-version-file: ".nvmrc"
|
|
|
|
- name: Setup Rust
|
|
uses: dtolnay/rust-toolchain@stable
|
|
|
|
- uses: Swatinem/rust-cache@v2
|
|
with:
|
|
key: macos
|
|
|
|
- name: Setup sccache
|
|
uses: mozilla-actions/sccache-action@v0.0.10
|
|
|
|
- name: Probe sccache backend, disable on outage
|
|
shell: bash
|
|
run: |
|
|
if sccache --start-server; then
|
|
echo "sccache backend reachable"
|
|
else
|
|
echo "::warning::sccache backend unreachable — disabling for this job"
|
|
echo "RUSTC_WRAPPER=" >> "$GITHUB_ENV"
|
|
echo "SCCACHE_GHA_ENABLED=false" >> "$GITHUB_ENV"
|
|
fi
|
|
|
|
- name: Install npm dependencies
|
|
run: npm ci
|
|
|
|
- name: Build server + CLI release archives (darwin x2)
|
|
run: |
|
|
make build-server-releases-macos
|
|
make build-cli-releases-rust-macos
|
|
|
|
- name: Import certificate into keychain
|
|
env:
|
|
APPLE_CERTIFICATE_P12_BASE64: ${{ secrets.APPLE_CERTIFICATE_P12_BASE64 }}
|
|
APPLE_CERTIFICATE_PASSWORD: ${{ secrets.APPLE_CERTIFICATE_PASSWORD }}
|
|
run: |
|
|
echo "$APPLE_CERTIFICATE_P12_BASE64" | base64 --decode > certificate.p12
|
|
|
|
KEYCHAIN_PATH="$RUNNER_TEMP/signing.keychain-db"
|
|
KEYCHAIN_PASSWORD="$(openssl rand -hex 20)"
|
|
security create-keychain -p "$KEYCHAIN_PASSWORD" "$KEYCHAIN_PATH"
|
|
security set-keychain-settings -lut 21600 "$KEYCHAIN_PATH"
|
|
security unlock-keychain -p "$KEYCHAIN_PASSWORD" "$KEYCHAIN_PATH"
|
|
|
|
security import certificate.p12 \
|
|
-P "$APPLE_CERTIFICATE_PASSWORD" \
|
|
-A \
|
|
-t cert \
|
|
-f pkcs12 \
|
|
-k "$KEYCHAIN_PATH"
|
|
|
|
security list-keychain -d user -s "$KEYCHAIN_PATH"
|
|
|
|
security set-key-partition-list -S apple-tool:,apple:,codesign: \
|
|
-s -k "$KEYCHAIN_PASSWORD" "$KEYCHAIN_PATH"
|
|
|
|
rm certificate.p12
|
|
|
|
- name: Sign and notarize macOS binaries
|
|
env:
|
|
APPLE_TEAM_ID: ${{ secrets.APPLE_TEAM_ID }}
|
|
APPLE_API_KEY_ID: ${{ secrets.APPLE_API_KEY_ID }}
|
|
APPLE_API_KEY_ISSUER_ID: ${{ secrets.APPLE_API_KEY_ISSUER_ID }}
|
|
APPLE_API_KEY_P8_BASE64: ${{ secrets.APPLE_API_KEY_P8_BASE64 }}
|
|
run: |
|
|
mkdir -p "$HOME/private_keys"
|
|
echo "$APPLE_API_KEY_P8_BASE64" | base64 --decode \
|
|
> "$HOME/private_keys/AuthKey_${APPLE_API_KEY_ID}.p8"
|
|
|
|
IDENTITY="Developer ID Application: Zef Hemel ($APPLE_TEAM_ID)"
|
|
|
|
# Both the server and the `sb` CLI darwin archives.
|
|
for zip_file in *-darwin-*.zip; do
|
|
echo "=== Processing $zip_file ==="
|
|
zip_file="$(pwd)/$zip_file"
|
|
|
|
WORK_DIR=$(mktemp -d)
|
|
unzip -o "$zip_file" -d "$WORK_DIR"
|
|
BINARY=$(ls "$WORK_DIR")
|
|
|
|
codesign --force --options runtime \
|
|
--sign "$IDENTITY" \
|
|
--timestamp \
|
|
"$WORK_DIR/$BINARY"
|
|
|
|
codesign --verify --verbose "$WORK_DIR/$BINARY"
|
|
|
|
NOTARIZE_ZIP="$WORK_DIR/notarize.zip"
|
|
ditto -c -k --keepParent "$WORK_DIR/$BINARY" "$NOTARIZE_ZIP"
|
|
|
|
xcrun notarytool submit "$NOTARIZE_ZIP" \
|
|
--key "$HOME/private_keys/AuthKey_${APPLE_API_KEY_ID}.p8" \
|
|
--key-id "$APPLE_API_KEY_ID" \
|
|
--issuer "$APPLE_API_KEY_ISSUER_ID" \
|
|
--wait --timeout 10m
|
|
|
|
rm "$zip_file"
|
|
(cd "$WORK_DIR" && zip "$zip_file" "$BINARY")
|
|
|
|
rm -rf "$WORK_DIR"
|
|
done
|
|
|
|
rm -rf "$HOME/private_keys"
|
|
|
|
- name: Clean up keychain
|
|
if: always()
|
|
run: |
|
|
security delete-keychain "$RUNNER_TEMP/signing.keychain-db" 2>/dev/null || true
|
|
|
|
- name: Upload macOS release zips
|
|
uses: actions/upload-artifact@v4
|
|
with:
|
|
name: release-zips-macos
|
|
path: |
|
|
silverbullet-server-darwin-*.zip
|
|
sb-darwin-*.zip
|
|
if-no-files-found: error
|