krz/orgo

Lightning fast org-mode static site generator. fast go org-mode static-site-generator

.gitbay/release.sh

65 lines · 2803 bytes · executable

 1#!/bin/sh
 2# The tag push is the release. Builds the Linux binaries, creates the gitbay
 3# release with the tag's own annotation as its notes, attaches the tarballs, and
 4# publishes to crates.io.
 5#
 6# The two darwin tarballs are not built here: this runner is Linux, and gitbay's
 7# `runner next` claims the oldest pending build with no platform targeting, so a
 8# Mac runner could not be aimed at them. .githooks/pre-push builds them on a Mac
 9# before the tag is pushed and uploads them to this release once it exists.
10#
11# crates.io is the one step that cannot be undone — a version can be yanked but
12# never replaced — so it runs last, after the release exists and the binaries are
13# attached. CARGO_REGISTRY_TOKEN is a repository secret (`gitbay repo secret set`).
14set -eu
15
16tag="${GITBAY_REF:?no tag in GITBAY_REF}"
17repo="${GITBAY_REPO:?no repository in GITBAY_REPO}"
18: "${CARGO_REGISTRY_TOKEN:?CARGO_REGISTRY_TOKEN secret is not set}"
19
20# The tag is the source of truth for the version, checked rather than trusted: a
21# release tagged v0.18.0 whose binary reports 0.17.0 is the kind of thing nobody
22# notices for months.
23version=$(cargo pkgid | sed 's/.*[#@]//')
24if [ "$tag" != "v$version" ]; then
25	echo "tag $tag does not match Cargo.toml version $version" >&2
26	exit 1
27fi
28
29# Reach the forge on whatever host the runner cloned from, rather than a name it
30# may not have in known_hosts.
31host=$(git remote get-url origin | sed 's#.*://[^@]*@##; s#[:/].*##')
32
33dist=dist
34mkdir -p "$dist"
35
36# glibc for ordinary distributions, musl for containers and anything older than
37# the runner's glibc — a dynamically linked binary is the usual reason a download
38# does not run.
39for target in x86_64-unknown-linux-gnu x86_64-unknown-linux-musl; do
40	cargo build --release --locked --target "$target"
41	# A tarball rather than a bare binary: it keeps the executable bit through the
42	# download path, and carries the licence with the thing it licenses.
43	staging="orgo-$tag-$target"
44	rm -rf "$staging"
45	mkdir "$staging"
46	cp "target/$target/release/orgo" README.md LICENSE "$staging/"
47	tar czf "$dist/$staging.tar.gz" "$staging"
48	rm -rf "$staging"
49	(cd "$dist" && sha256sum "$staging.tar.gz" >"$staging.tar.gz.sha256")
50done
51
52# Notes come from the annotated tag, so the person cutting the release writes
53# them at the moment they decide to cut it (`git tag -a "$tag" -F notes.md`).
54git tag -l --format='%(contents)' "$tag" |
55	ssh "git@$host" release create "$repo" "$tag" --title "${tag#v}" --file -
56
57for f in "$dist"/*; do
58	ssh "git@$host" release asset add "$repo" "$tag" "$(basename "$f")" <"$f"
59	echo "attached $(basename "$f")"
60done
61
62# --locked publishes exactly the dependency versions the tests ran against,
63# rather than whatever resolves at publish time.
64cargo publish --locked
65echo "published $tag to crates.io"