From a9027bb9977f0c678ce96ba22dbace024b643f15 Mon Sep 17 00:00:00 2001 From: Ayaz Salikhov Date: Fri, 2 Oct 2026 19:02:46 +0000 Subject: [PATCH] ci: Make release always go into stable channel (#8469) --- .github/actions/release-info/action.yml | 2 +- .github/workflows/reusable-package.yml | 15 ++++++++++++--- package/README.md | 10 ++++++---- 3 files changed, 19 insertions(+), 8 deletions(-) diff --git a/.github/actions/release-info/action.yml b/.github/actions/release-info/action.yml index a3c233a387..a50e847651 100644 --- a/.github/actions/release-info/action.yml +++ b/.github/actions/release-info/action.yml @@ -36,4 +36,4 @@ runs: - name: Determine release channel and package release id: release_info - uses: XRPLF/actions/release-info@ebcf6cea14eee258697308a51fea55cad777581b + uses: XRPLF/actions/release-info@a9f2eeca6fb3980ba3a84cf68566f1c69ad30674 diff --git a/.github/workflows/reusable-package.yml b/.github/workflows/reusable-package.yml index 13181978d5..91e1e5dbb2 100644 --- a/.github/workflows/reusable-package.yml +++ b/.github/workflows/reusable-package.yml @@ -269,14 +269,23 @@ jobs: env: CONTEXT: image-context IMAGE: ${{ matrix.target == 'voidstar' && 'xrpld-voidstar' || 'xrplf/xrpld' }}:${{ github.ref_type == 'tag' && github.ref_name || 'develop' }} - # Docker Hub is public, so a private build never reaches it; - # the Antithesis registry is not. - PUSH: ${{ inputs.publish && (matrix.target == 'voidstar' || github.event.repository.visibility == 'public') }} steps: - name: Checkout repository uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 + - name: Determine release info + id: release_info + uses: ./.github/actions/release-info + + # Docker Hub is public, so it only gets builds whose packages are public: + # those of a public codebase, and stable releases. + # The Antithesis registry is private, so it gets every build. + - name: Decide whether to push + env: + PUSH: ${{ inputs.publish && (matrix.target == 'voidstar' || github.event.repository.visibility == 'public' || steps.release_info.outputs.channel == 'stable') }} + run: echo "PUSH=${PUSH}" | tee -a "${GITHUB_ENV}" + - name: Download package artifacts uses: actions/download-artifact@3e5f45b2cfb9172054b4087a40e8e0b5a5461e7c # v8.0.1 with: diff --git a/package/README.md b/package/README.md index 007e4a7dae..8ddbba049f 100644 --- a/package/README.md +++ b/package/README.md @@ -217,12 +217,13 @@ The `release-info` action decides the channel from the event, and | tag | `X.Y.Z-bN` | `beta` | `deb-beta` | `rpm-beta-hosted` | | tag, any other | `xrpld --version` | `custom` | `deb-custom` | `rpm-custom-hosted` | | push to `develop` | `0.0.0-dev+` | `develop` | `deb-develop` | `rpm-develop-hosted` | -| tag, non-public codebase | _any_ | `private` | `deb-private` | `rpm-private-hosted` | +| tag, non-public codebase | _any but `X.Y.Z`_ | `private` | `deb-private` | `rpm-private-hosted` | A variant is published to the same channel under its own name, so `xrpld-assert` never overwrites `xrpld`. -Only a tag picks a release channel. Versions sort in row order, so moving to a +Only a tag picks a release channel. A final release, `X.Y.Z`, goes to `stable` +even from a non-public codebase. Versions sort in row order, so moving to a more mature channel never downgrades. A tag matching none of the release patterns, such as `X.Y.Z-hotfix1`, publishes to `custom`, which sits outside that order. @@ -284,8 +285,9 @@ checks that the server starts in each image. A tag's images are tagged with the tag name, a develop image as `develop`. With `publish: true`: - `xrpld` is pushed to `xrplf/xrpld` on Docker Hub using the `DOCKERHUB_TOKEN` - secret, an organization access token for `xrplf`. Private builds are never - pushed there. + secret, an organization access token for `xrplf`. Builds of a non-public + codebase are pushed there only for `stable` releases, whose packages are + public too. - `voidstar` replaces `/usr/bin/xrpld` with the binary of the `voidstar` build config, adds `libvoidstar.so` and links the binary into `/symbols`, as Antithesis expects. It is pushed as `xrpld-voidstar` to the Antithesis