Fix release validation and packaging with latest sources
This commit is contained in:
parent
123205c97d
commit
4ad0faf307
5 changed files with 67 additions and 46 deletions
|
|
@ -10,14 +10,15 @@ export TENSAMIN_CHANNEL=$channel ELECTRON_SKIP_BINARY_DOWNLOAD=1
|
|||
export TENSAMIN_ANDROID_VERSION_CODE=${RELEASE_SEQUENCE:?Release sequence required}
|
||||
system=${3:-$(nix eval --impure --raw --expr 'builtins.currentSystem')}
|
||||
expr="import $root/scripts/release-env.nix { root = builtins.toPath \"$root\"; kind = \"packages\"; channel = \"$channel\"; system = \"$system\"; }"
|
||||
packages=$(nix build --impure --no-link --print-out-paths --expr "$expr")
|
||||
nix build --impure --no-link --expr "import $root/scripts/release-env.nix { root = builtins.toPath \"$root\"; kind = \"checks\"; system = \"$system\"; }"
|
||||
packages=$(nix build --impure --no-link --print-out-paths --expr "$expr")
|
||||
arch=$system
|
||||
arch=${arch%-linux}
|
||||
printf '%s\n' "$packages" > "$out/packages-$arch.txt"
|
||||
for name in iota iota-daemon iota-ui omikron omega client client-web mtp-sdk; do
|
||||
# Nix closures, unlike a plain copy of a Nix binary, retain runtime libraries.
|
||||
mapfile -t closure < <(nix-store --query --requisites "$packages/$name")
|
||||
package=$(realpath "$packages/$name")
|
||||
mapfile -t closure < <(nix-store --query --requisites "$package")
|
||||
nix-store --export "${closure[@]}" | gzip -n > "$out/$name-linux-$arch.nar.gz"
|
||||
done
|
||||
for binary in iota iota-daemon iota-updater; do
|
||||
|
|
@ -30,6 +31,7 @@ cp -L "$packages/omega-container" "$out/omega-image-linux-$arch.tar.gz"
|
|||
cp "$packages/iota-portable/bin/iota-release" "$out/iota-release-linux-$arch"
|
||||
cp "$packages/iota-portable/bin/iota-bundle" "$out/iota-bundle-linux-$arch"
|
||||
cp -rL "$packages/iota-bundle/share/iota" "$out/iota-contract"
|
||||
chmod -R u+w "$out/iota-contract"
|
||||
# The helpers' relative script paths are part of the Iota contract.
|
||||
mkdir -p "$out/iota-contract/iota-updater" "$out/iota-contract/iota-installer"
|
||||
mv "$out/iota-contract/artifacts.tsv" "$out/iota-contract/iota-updater/"
|
||||
|
|
@ -37,8 +39,13 @@ mv "$out/iota-contract/bundle-files.txt" "$out/iota-contract/iota-installer/"
|
|||
mkdir -p "$out/iota-contract/static"
|
||||
mv "$out/iota-contract/static-web" "$out/iota-contract/static/web"
|
||||
|
||||
work=$(mktemp -d)
|
||||
trap 'rm -rf "$work"' EXIT
|
||||
work_root=$(mktemp -d)
|
||||
trap 'rm -rf "$work_root"' EXIT
|
||||
work=$work_root/tensamin/client
|
||||
mkdir -p "$work"
|
||||
mtp_source=$(nix build --no-link --print-out-paths ".#packages.$system.mtp-source")
|
||||
cp -r "$mtp_source" "$work_root/mtp"
|
||||
chmod -R u+w "$work_root/mtp"
|
||||
source=$(nix build --no-link --print-out-paths ".#packages.$system.client-source")
|
||||
cp -r "$source/." "$work/"
|
||||
chmod -R u+w "$work"
|
||||
|
|
|
|||
|
|
@ -7,7 +7,10 @@ case ${1:?} in
|
|||
pnpm run ci
|
||||
electron_arch=x64
|
||||
[[ $RELEASE_ARCH != aarch64 ]] || electron_arch=arm64
|
||||
package_name=tensamin
|
||||
[[ $TENSAMIN_CHANNEL == stable ]] || package_name="tensamin-$TENSAMIN_CHANNEL"
|
||||
pnpm --dir apps/electron exec electron-builder --config electron-builder.config.cjs \
|
||||
--config.deb.packageName="$package_name" --config.rpm.packageName="$package_name" \
|
||||
--linux --"$electron_arch" --publish never
|
||||
pnpm run copy-releases
|
||||
for asset in releases/*; do
|
||||
|
|
|
|||
|
|
@ -1,36 +1,40 @@
|
|||
{ root, kind ? "tools", channel ? "canary", system ? builtins.currentSystem }:
|
||||
{ root, kind ? "tools", channel ? "canary", system ? builtins.currentSystem, sources ? {} }:
|
||||
let
|
||||
central = builtins.getFlake (toString root);
|
||||
pkgs = import central.inputs.nixpkgs {
|
||||
inherit system;
|
||||
overlays = [ central.inputs.rust-overlay.overlays.default ];
|
||||
};
|
||||
project = central.lib.mkPackages { inherit system; };
|
||||
project = central.lib.mkPackages { inherit system sources; };
|
||||
# Reuse only the client's tool shells, with central nixpkgs and Rust inputs.
|
||||
# Client builds below always consume client-source and mtp-sdk from prod-pins.
|
||||
clientTools = (import (central.inputs.client + "/flake.nix")).outputs {
|
||||
self = central.inputs.client;
|
||||
nixpkgs = central.inputs.nixpkgs // {
|
||||
# The client's old SDK platform-tools pin is absent in central nixpkgs.
|
||||
outPath = pkgs.runCommand "release-client-nixpkgs" {} ''
|
||||
mkdir -p "$out"
|
||||
cat > "$out/default.nix" <<'EOF'
|
||||
args: let
|
||||
pkgs = import ${central.inputs.nixpkgs} args;
|
||||
in pkgs // { androidenv = pkgs.androidenv // {
|
||||
composeAndroidPackages = options: pkgs.androidenv.composeAndroidPackages
|
||||
(options // { platformToolsVersion = "37.0.1"; });
|
||||
}; }
|
||||
EOF
|
||||
'';
|
||||
prod-pins = central // {
|
||||
inputs = central.inputs // {
|
||||
nixpkgs = central.inputs.nixpkgs // {
|
||||
# Use the platform-tools version available in central nixpkgs.
|
||||
outPath = pkgs.runCommand "release-client-nixpkgs" {} ''
|
||||
mkdir -p "$out"
|
||||
cat > "$out/default.nix" <<'EOF'
|
||||
args: let
|
||||
pkgs = import ${central.inputs.nixpkgs} args;
|
||||
in pkgs // { androidenv = pkgs.androidenv // {
|
||||
composeAndroidPackages = options: pkgs.androidenv.composeAndroidPackages
|
||||
(options // { platformToolsVersion = "37.0.1"; });
|
||||
}; }
|
||||
EOF
|
||||
'';
|
||||
};
|
||||
};
|
||||
};
|
||||
rust-overlay = central.inputs.rust-overlay;
|
||||
};
|
||||
branded = name: project.packages.${name}.overrideAttrs {
|
||||
TENSAMIN_CHANNEL = channel;
|
||||
};
|
||||
checked = name: project.packages.${name}.overrideAttrs (old: {
|
||||
doCheck = true;
|
||||
SSL_CERT_FILE = "${pkgs.cacert}/etc/ssl/certs/ca-bundle.crt";
|
||||
installPhase = ''mkdir -p "$out"'';
|
||||
nativeBuildInputs = old.nativeBuildInputs ++ project.devShells.${name}.nativeBuildInputs;
|
||||
preBuild = (old.preBuild or "") + ''
|
||||
|
|
@ -43,20 +47,27 @@ let
|
|||
pname = "mtp-checks";
|
||||
src = project.packages.mtp-sdk.src;
|
||||
cargoDeps = project.packages.mtp-vendor;
|
||||
cargoBuildFlags = [ "--workspace" ];
|
||||
cargoTestFlags = [ "--workspace" ];
|
||||
cargoBuildFlags = [ "--workspace" "--exclude" "mtp-wasm" ];
|
||||
cargoTestFlags = [ "--workspace" "--exclude" "mtp-wasm" ];
|
||||
doCheck = true;
|
||||
MTP_TYPE_MAPS = "${project.packages.mtp-sdk.src}/tests/fixtures/example/type-maps.yaml";
|
||||
installPhase = ''mkdir -p "$out"'';
|
||||
nativeBuildInputs = old.nativeBuildInputs ++ project.devShells.mtp.nativeBuildInputs;
|
||||
preBuild = ''
|
||||
cargo fmt --all --check
|
||||
cargo clippy --locked --offline --workspace --all-targets -- -D warnings
|
||||
cargo clippy --locked --offline --workspace --exclude mtp-wasm --all-targets -- -D warnings
|
||||
'';
|
||||
});
|
||||
in
|
||||
if kind == "tools" then pkgs.mkShell {
|
||||
packages = with pkgs; [ nix git (python3.withPackages (p: [ p.pyyaml ])) bash coreutils jq zip gnutar gzip openssh skopeo shellcheck ruff ];
|
||||
} else if kind == "electron" || kind == "tauri" then clientTools.devShells.${system}.${kind}
|
||||
} else if kind == "electron" || kind == "tauri" then
|
||||
clientTools.devShells.${system}.${kind}.overrideAttrs (old: {
|
||||
shellHook = builtins.replaceStrings
|
||||
[ ''cd "$workRoot/tensamin/client"'' ]
|
||||
[ ''cd "''${RELEASE_WORK:-$workRoot/tensamin/client}"'' ]
|
||||
old.shellHook;
|
||||
})
|
||||
else if kind == "checks" then pkgs.linkFarm "release-checks" (map (name: {
|
||||
inherit name;
|
||||
path = checked name;
|
||||
|
|
|
|||
|
|
@ -1,15 +1,15 @@
|
|||
"""Refresh the shared sources, transformed locks, and fixed-output hashes."""
|
||||
|
||||
import argparse
|
||||
from pathlib import Path
|
||||
import re
|
||||
import shutil
|
||||
import subprocess
|
||||
import tempfile
|
||||
from pathlib import Path
|
||||
|
||||
|
||||
def run(*args, **kwargs):
|
||||
result = subprocess.run(args, text=True, **kwargs)
|
||||
result = subprocess.run(args, text=True, check=False, **kwargs)
|
||||
if result.returncode:
|
||||
raise SystemExit(result.stderr if kwargs.get("capture_output") else result.returncode)
|
||||
return result
|
||||
|
|
@ -60,7 +60,7 @@ for key, output in [(n, f"{n}-vendor") for n in ["mtp", "iota", "omikron", "omeg
|
|||
text = re.sub(rf'({key} = ")[^"]+', rf'\g<1>sha256-{"A" * 43}=', text)
|
||||
hash_file.write_text(text)
|
||||
result = subprocess.run(["nix", "build", f"path:{root}#packages.{system}.{output}",
|
||||
"--no-link", "--print-out-paths", *overrides], text=True, capture_output=True)
|
||||
"--no-link", "--print-out-paths", *overrides], text=True, capture_output=True, check=False)
|
||||
match = re.search(r"got:\s+(sha256-[A-Za-z0-9+/=]+)", result.stderr)
|
||||
if not match:
|
||||
hash_file.write_text(original)
|
||||
|
|
|
|||
Loading…
Reference in a new issue