diff --git a/.github/actions/release-info/action.yml b/.github/actions/release-info/action.yml index d32d937ab1..e03170b2c8 100644 --- a/.github/actions/release-info/action.yml +++ b/.github/actions/release-info/action.yml @@ -9,7 +9,7 @@ outputs: description: "The release channel this build belongs to." value: ${{ steps.release_info.outputs.channel }} pkg_release: - description: "The package release number: 1 for a tag, the run number otherwise." + description: "The package release number: 1 for a tag, .git otherwise." value: ${{ steps.release_info.outputs.pkg_release }} runs: @@ -41,4 +41,4 @@ runs: - name: Determine release channel and package release id: release_info - uses: XRPLF/actions/release-info@7f956517847fb9e0b56070f72e1280f4e7404a09 + uses: XRPLF/actions/release-info@7cc0e4a8d9d0b838f92c48d312856b190341bbba diff --git a/.github/scripts/strategy-matrix/linux.json b/.github/scripts/strategy-matrix/linux.json index 731536a748..d8cdbdfa52 100644 --- a/.github/scripts/strategy-matrix/linux.json +++ b/.github/scripts/strategy-matrix/linux.json @@ -74,7 +74,7 @@ "extra_cmake_args": "-Dvalidator_keys=ON", "package": { "type": "deb", - "image": "ghcr.io/xrplf/xrpld/packaging-debian:sha-45e4b88" + "image": "ghcr.io/xrplf/xrpld/packaging-debian:sha-b6a8995" } } ], @@ -88,7 +88,7 @@ "extra_cmake_args": "-Dvalidator_keys=ON", "package": { "type": "rpm", - "image": "ghcr.io/xrplf/xrpld/packaging-rhel:sha-45e4b88" + "image": "ghcr.io/xrplf/xrpld/packaging-rhel:sha-b6a8995" } } ] diff --git a/.github/workflows/reusable-package.yml b/.github/workflows/reusable-package.yml index 951b9b18dd..2a5e6a8c04 100644 --- a/.github/workflows/reusable-package.yml +++ b/.github/workflows/reusable-package.yml @@ -2,8 +2,8 @@ # # - one job per config that carries a "package" map in linux.json # - that map names the container image and the format it builds there -# - with 'publish: true' a job also uploads what it built -# (see package/docker/publish_pkg.py) +# - every job ends with the image's publish_pkg.py, uploading what it built +# with 'publish: true' and doing a --dry-run otherwise # # Only linux/amd64 is supported; the runner is hardcoded in the job below. name: Package @@ -76,6 +76,11 @@ jobs: - name: Checkout repository uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 + - name: Prepare runner + uses: XRPLF/actions/prepare-runner@7bf7ceca5932114abdd0d43493c3c30c5a654e13 + with: + enable_ccache: false + - name: Download pre-built xrpld binary uses: actions/download-artifact@3e5f45b2cfb9172054b4087a40e8e0b5a5461e7c # v8.0.1 with: @@ -126,14 +131,15 @@ jobs: if-no-files-found: error - name: Publish package - if: ${{ inputs.publish }} env: CHANNEL: ${{ steps.release_info.outputs.channel }} + DRY_RUN_OPTION: ${{ !inputs.publish && '--dry-run' || '' }} NEXUS_URL: ${{ inputs.nexus_url }} - NEXUS_USERNAME: ${{ secrets.remote_username }} - NEXUS_PASSWORD: ${{ secrets.remote_password }} + NEXUS_USERNAME: ${{ inputs.publish && secrets.remote_username || '' }} + NEXUS_PASSWORD: ${{ inputs.publish && secrets.remote_password || '' }} run: | - ./package/docker/publish_pkg.py \ + publish_pkg.py \ --channel "${CHANNEL}" \ --package-dir "${BUILD_DIR}" \ - --nexus-url "${NEXUS_URL}" + --nexus-url "${NEXUS_URL}" \ + ${DRY_RUN_OPTION} diff --git a/.github/workflows/reusable-upload-recipe.yml b/.github/workflows/reusable-upload-recipe.yml index 608a5ea988..6fa289665a 100644 --- a/.github/workflows/reusable-upload-recipe.yml +++ b/.github/workflows/reusable-upload-recipe.yml @@ -49,6 +49,11 @@ jobs: - name: Checkout repository uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 + - name: Prepare runner + uses: XRPLF/actions/prepare-runner@7bf7ceca5932114abdd0d43493c3c30c5a654e13 + with: + enable_ccache: false + - name: Determine release info id: release_info uses: ./.github/actions/release-info diff --git a/docs/install.md b/docs/install.md index 01cfc144a1..4c52b587b6 100644 --- a/docs/install.md +++ b/docs/install.md @@ -13,7 +13,7 @@ To build from source instead, see [BUILD.md](../BUILD.md). Packages are published to four channels: -- `stable` - the latest production release +- `stable` - production releases - `rc` - release candidates - `beta` - beta builds - `develop` - every push to the [`develop` branch](https://github.com/XRPLF/rippled/tree/develop) diff --git a/package/README.md b/package/README.md index 645725c976..027a374898 100644 --- a/package/README.md +++ b/package/README.md @@ -149,15 +149,21 @@ Versions sort in row order, so moving to a more mature channel never downgrades. The action decides the package release number on the same split: a tag's version is unique, so its packages are release 1, while develop repeats the same version -and takes `github.run_number` so each push supersedes the last. Both reach the -packaging scripts as arguments, so neither script derives anything itself. +and takes `.git`, e.g. +`857.20260826gitb6a8995` — the leading run number keeps each push superseding +the last, and the date and hash say which commit a package on +`packages.xrplf.org` came from. Both reach the packaging scripts as arguments, +so neither script derives anything itself. Publishing is the last step of each packaging job, uploading from the container -that built the packages. It runs when the caller passes `publish: true`: -`on-trigger.yml` for develop pushes in `XRPLF/rippled`, `on-tag.yml` for tags in -any `XRPLF` repository, `on-pr.yml` never. Both authenticate with the +that built the packages with the `publish_pkg.py` shipped in the image — the +same copy other repositories run. Without `publish: true` the step is a +`--dry-run`, listing the uploads it would make without needing credentials, so +any run that builds packages also exercises the upload routing. `on-trigger.yml` +passes `publish: true` for develop pushes in `XRPLF/rippled` and `on-tag.yml` +for tags in any `XRPLF` repository, both authenticating with the `NEXUS_REMOTE_USERNAME` / `NEXUS_REMOTE_PASSWORD` secrets already used for the -Conan remote. +Conan remote; `on-pr.yml` never publishes. Nexus owns the repository metadata; nothing here indexes anything. Worth knowing: