.gitbay/release.sh
61 lines · 2626 bytes · executable
1#!/bin/sh
2# The tag push is the release. Builds the Linux binaries, creates the gitbay
3# release with the tag's own annotation as its notes, attaches the tarballs, and
4# publishes to crates.io.
5#
6# The two darwin tarballs are not built here: this runner is Linux, and gitbay's
7# `runner next` claims the oldest pending build with no platform targeting, so a
8# Mac runner could not be aimed at them. .githooks/pre-push builds them on a Mac
9# before the tag is pushed and uploads them to this release once it exists.
10#
11# crates.io is the one step that cannot be undone — a version can be yanked but
12# never replaced — so it runs last, after the release exists and the binaries are
13# attached. CARGO_REGISTRY_TOKEN is a repository secret (`gitbay repo secret set`).
14set -eu
15
16tag="${GITBAY_REF:?no tag in GITBAY_REF}"
17repo="${GITBAY_REPO:?no repository in GITBAY_REPO}"
18: "${CARGO_REGISTRY_TOKEN:?CARGO_REGISTRY_TOKEN secret is not set}"
19
20# The tag is the source of truth for the version, checked rather than trusted: a
21# release tagged v0.18.0 whose binary reports 0.17.0 is the kind of thing nobody
22# notices for months.
23version=$(cargo pkgid | sed 's/.*[#@]//')
24if [ "$tag" != "v$version" ]; then
25 echo "tag $tag does not match Cargo.toml version $version" >&2
26 exit 1
27fi
28
29dist=dist
30mkdir -p "$dist"
31
32# glibc for ordinary distributions, musl for containers and anything older than
33# the runner's glibc — a dynamically linked binary is the usual reason a download
34# does not run.
35for target in x86_64-unknown-linux-gnu x86_64-unknown-linux-musl; do
36 cargo build --release --locked --target "$target"
37 # A tarball rather than a bare binary: it keeps the executable bit through the
38 # download path, and carries the licence with the thing it licenses.
39 staging="orgo-$tag-$target"
40 rm -rf "$staging"
41 mkdir "$staging"
42 cp "target/$target/release/orgo" README.md LICENSE "$staging/"
43 tar czf "$dist/$staging.tar.gz" "$staging"
44 rm -rf "$staging"
45 (cd "$dist" && sha256sum "$staging.tar.gz" >"$staging.tar.gz.sha256")
46done
47
48# Notes come from the annotated tag, so the person cutting the release writes
49# them at the moment they decide to cut it (`git tag -a "$tag" -F notes.md`).
50git tag -l --format='%(contents)' "$tag" |
51 ssh git@gitbay.org release create "$repo" "$tag" --title "${tag#v}" --file -
52
53for f in "$dist"/*; do
54 ssh git@gitbay.org release asset add "$repo" "$tag" "$(basename "$f")" <"$f"
55 echo "attached $(basename "$f")"
56done
57
58# --locked publishes exactly the dependency versions the tests ran against,
59# rather than whatever resolves at publish time.
60cargo publish --locked
61echo "published $tag to crates.io"