diff --git a/.github/actions/release-info/action.yml b/.github/actions/release-info/action.yml index ab69a35f68..d32d937ab1 100644 --- a/.github/actions/release-info/action.yml +++ b/.github/actions/release-info/action.yml @@ -7,10 +7,10 @@ outputs: value: ${{ steps.version.outputs.version }} channel: description: "The release channel this build belongs to." - value: ${{ steps.channel.outputs.channel }} + value: ${{ steps.release_info.outputs.channel }} pkg_release: description: "The package release number: 1 for a tag, the run number otherwise." - value: ${{ steps.pkg_release.outputs.pkg_release }} + value: ${{ steps.release_info.outputs.pkg_release }} runs: using: composite @@ -39,52 +39,6 @@ runs: echo "version=${version}" | tee -a "${GITHUB_OUTPUT}" - # Only a tag says how mature a build is: a push is a develop build whatever - # its version, and a non-public codebase keeps its packages to itself. - - name: Determine release channel - id: channel - shell: bash - env: - IS_TAG: ${{ startsWith(github.ref, 'refs/tags/') }} - REF_NAME: ${{ github.ref_name }} - VISIBILITY: ${{ github.event.repository.visibility }} - run: | - pre_release="" - if [[ "${REF_NAME}" == *-* ]]; then - pre_release="${REF_NAME#*-}" - fi - - if [[ "${VISIBILITY}" != "public" ]]; then - channel=private - elif [[ "${IS_TAG}" != "true" ]]; then - channel=develop - elif [[ -z "${pre_release}" ]]; then - channel=stable - elif [[ "${pre_release}" =~ ^rc[0-9]+(\+.*)?$ ]]; then - channel=rc - elif [[ "${pre_release}" =~ ^b(0|[1-9][0-9]*)(\+.*)?$ ]]; then - channel=beta - else - echo "Unsupported pre-release in tag '${REF_NAME}'. Use bN or rcN." >&2 - exit 1 - fi - - echo "channel=${channel}" | tee -a "${GITHUB_OUTPUT}" - - # A tag is packaged once, so its release number is fixed at 1. Develop builds - # repeat the same version, so the run number is what makes each push an - # upgrade rather than a reinstall. - - name: Determine package release - id: pkg_release - shell: bash - env: - IS_TAG: ${{ startsWith(github.ref, 'refs/tags/') }} - RUN_NUMBER: ${{ github.run_number }} - run: | - if [[ "${IS_TAG}" == "true" ]]; then - pkg_release=1 - else - pkg_release="${RUN_NUMBER}" - fi - - echo "pkg_release=${pkg_release}" | tee -a "${GITHUB_OUTPUT}" + - name: Determine release channel and package release + id: release_info + uses: XRPLF/actions/release-info@7f956517847fb9e0b56070f72e1280f4e7404a09 diff --git a/.github/workflows/build-packaging-images.yml b/.github/workflows/build-packaging-images.yml index fd04eae995..e099decc12 100644 --- a/.github/workflows/build-packaging-images.yml +++ b/.github/workflows/build-packaging-images.yml @@ -6,13 +6,13 @@ on: - develop paths: - ".github/workflows/build-packaging-images.yml" - - "package/Dockerfile" - - "package/install-packaging-tools.sh" + - "bin/install-packaging-tools.sh" + - "package/docker/**" pull_request: paths: - ".github/workflows/build-packaging-images.yml" - - "package/Dockerfile" - - "package/install-packaging-tools.sh" + - "bin/install-packaging-tools.sh" + - "package/docker/**" workflow_dispatch: concurrency: @@ -44,6 +44,6 @@ jobs: uses: XRPLF/actions/.github/workflows/build-multiarch-image.yml@65d5a0bd72be4ecea95cff0673a6e0672ab5243a with: image_name: xrpld/packaging-${{ matrix.distro.name }} - dockerfile: package/Dockerfile + dockerfile: package/docker/Dockerfile base_image: ${{ matrix.distro.base_image }} push: ${{ github.event_name == 'push' }} diff --git a/.github/workflows/reusable-package.yml b/.github/workflows/reusable-package.yml index aa9183be37..951b9b18dd 100644 --- a/.github/workflows/reusable-package.yml +++ b/.github/workflows/reusable-package.yml @@ -3,7 +3,7 @@ # - one job per config that carries a "package" map in linux.json # - that map names the container image and the format it builds there # - with 'publish: true' a job also uploads what it built -# (see package/publish_pkg.py) +# (see package/docker/publish_pkg.py) # # Only linux/amd64 is supported; the runner is hardcoded in the job below. name: Package @@ -133,7 +133,7 @@ jobs: NEXUS_USERNAME: ${{ secrets.remote_username }} NEXUS_PASSWORD: ${{ secrets.remote_password }} run: | - ./package/publish_pkg.py \ + ./package/docker/publish_pkg.py \ --channel "${CHANNEL}" \ --package-dir "${BUILD_DIR}" \ --nexus-url "${NEXUS_URL}" diff --git a/package/install-packaging-tools.sh b/bin/install-packaging-tools.sh similarity index 100% rename from package/install-packaging-tools.sh rename to bin/install-packaging-tools.sh diff --git a/package/Dockerfile b/package/Dockerfile deleted file mode 100644 index 978b569bd8..0000000000 --- a/package/Dockerfile +++ /dev/null @@ -1,7 +0,0 @@ -ARG BASE_IMAGE=debian:bookworm - -FROM ${BASE_IMAGE} - -COPY package/install-packaging-tools.sh /tmp/install-packaging-tools.sh - -RUN /tmp/install-packaging-tools.sh diff --git a/package/README.md b/package/README.md index 8295a8a38e..645725c976 100644 --- a/package/README.md +++ b/package/README.md @@ -10,7 +10,9 @@ a build configured with `-Dvalidator_keys=ON`. package/ build_pkg.py Staging and build script (called by the CMake `package` target and CI) sign_rpm.py Signs the built RPMs (called by CI when publishing) - publish_pkg.py Uploads built packages to the XRPLF Nexus repositories (called by CI) + docker/ + Dockerfile Packaging image, built by `build-packaging-images.yml`; installs its tooling with `bin/install-packaging-tools.sh` + publish_pkg.py Uploads built packages to the XRPLF Nexus repositories (called by CI, and shipped in that image) rpm/ xrpld.spec RPM spec debian/ Debian control files (control, rules, copyright, xrpld.docs, xrpld.links, source/format) @@ -176,6 +178,12 @@ Nexus owns the repository metadata; nothing here indexes anything. Worth knowing - The `develop` repositories gain a package per push, so they need a cleanup policy to stay bounded; tagged channels publish each version once. +### Publishing from other repositories + +`publish_pkg.py` knows nothing about `xrpld`, so the packaging image +installs it at `/usr/local/bin/publish_pkg.py` for other XRPLF repositories that +build their packages elsewhere. + ## How `build_pkg.py` works `build_pkg.py` derives the `xrpld` software version from diff --git a/package/docker/Dockerfile b/package/docker/Dockerfile new file mode 100644 index 0000000000..b55c37b02a --- /dev/null +++ b/package/docker/Dockerfile @@ -0,0 +1,10 @@ +ARG BASE_IMAGE=debian:trixie + +FROM ${BASE_IMAGE} + +COPY bin/install-packaging-tools.sh /tmp/install-packaging-tools.sh + +RUN /tmp/install-packaging-tools.sh + +# See ../README.md, "Publishing from other repositories". +COPY package/docker/publish_pkg.py /usr/local/bin/publish_pkg.py diff --git a/package/publish_pkg.py b/package/docker/publish_pkg.py similarity index 96% rename from package/publish_pkg.py rename to package/docker/publish_pkg.py index 0bd39d0845..c9a6d3db1e 100755 --- a/package/publish_pkg.py +++ b/package/docker/publish_pkg.py @@ -1,5 +1,8 @@ #!/usr/bin/env python3 -"""Publish the packages built by build_pkg.py to the XRPLF repositories on Nexus. +"""Publish built DEB and RPM packages to the XRPLF repositories on Nexus. + +Takes packages and a channel, and nothing else, so it publishes whatever built +them; see package/README.md, "Publishing from other repositories". RPMs are uploaded to the hosted repository, but yum clients install from the 'rpm-' group repository in front of it, which serves signed metadata.