mirror of
https://github.com/XRPLF/rippled.git
synced 2026-09-27 15:28:03 +00:00
310 lines
11 KiB
YAML
310 lines
11 KiB
YAML
# Build, verify and publish Linux packages from the pre-built xrpld and
|
|
# validator-keys artifacts, in three stages:
|
|
#
|
|
# - 'package' builds and signs one format per config that carries a "package"
|
|
# map in linux.json; that map names the container image and the format
|
|
# - 'test-install' installs what was built on a range of distros and runs the
|
|
# binaries there, so a package that cannot be installed never reaches Nexus
|
|
# - 'publish' uploads with the image's publish_pkg.py, doing a --dry-run
|
|
# unless 'publish: true'
|
|
#
|
|
# Only linux/amd64 is supported; the runner is hardcoded in the jobs below.
|
|
name: Package
|
|
|
|
on:
|
|
workflow_call:
|
|
inputs:
|
|
publish:
|
|
description: "Whether to publish the packages after building them."
|
|
required: false
|
|
type: boolean
|
|
default: false
|
|
nexus_url:
|
|
description: "The base URL of the Nexus instance hosting the deb and rpm repositories."
|
|
required: false
|
|
type: string
|
|
default: https://packages.xrplf.org
|
|
|
|
secrets:
|
|
remote_username:
|
|
description: "The username of a Nexus account with write access to the repositories."
|
|
required: false
|
|
remote_password:
|
|
description: "The password or token for that Nexus account."
|
|
required: false
|
|
signing_key:
|
|
description: "Armoured PGP private key used to sign the RPMs. Required when publishing."
|
|
required: false
|
|
|
|
defaults:
|
|
run:
|
|
shell: bash
|
|
|
|
env:
|
|
BUILD_DIR: build
|
|
PACKAGE_DIR: packages
|
|
|
|
jobs:
|
|
generate-matrix:
|
|
runs-on: ubuntu-latest
|
|
outputs:
|
|
matrix: ${{ steps.generate.outputs.matrix }}
|
|
steps:
|
|
- name: Checkout repository
|
|
uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
|
|
|
|
- name: Set up Python
|
|
uses: actions/setup-python@5fda3b95a4ea91299a34e894583c3862153e4b97 # v7.0.0
|
|
with:
|
|
python-version: "3.13"
|
|
|
|
- name: Generate packaging matrix
|
|
id: generate
|
|
working-directory: .github/scripts/strategy-matrix
|
|
run: ./generate.py --packaging >>"${GITHUB_OUTPUT}"
|
|
|
|
package:
|
|
needs: [generate-matrix]
|
|
if: ${{ github.event.repository.visibility == 'public' || startsWith(github.ref, 'refs/tags/') }}
|
|
strategy:
|
|
fail-fast: false
|
|
matrix: ${{ fromJson(needs.generate-matrix.outputs.matrix) }}
|
|
name: "${{ matrix.xrpld_artifact_name }}"
|
|
permissions:
|
|
contents: read
|
|
runs-on: ["self-hosted", "Linux", "X64", "heavy"]
|
|
container: ${{ matrix.image }}
|
|
timeout-minutes: 10
|
|
|
|
steps:
|
|
- name: Checkout repository
|
|
uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
|
|
|
|
- name: Prepare runner
|
|
uses: XRPLF/actions/prepare-runner@b3e255d74d785d053e4903da8ac90983cd7d9e82
|
|
with:
|
|
enable_ccache: false
|
|
|
|
- name: Download pre-built xrpld binary
|
|
uses: actions/download-artifact@3e5f45b2cfb9172054b4087a40e8e0b5a5461e7c # v8.0.1
|
|
with:
|
|
name: ${{ matrix.xrpld_artifact_name }}
|
|
path: ${{ env.BUILD_DIR }}
|
|
|
|
- name: Download pre-built validator-keys binary
|
|
uses: actions/download-artifact@3e5f45b2cfb9172054b4087a40e8e0b5a5461e7c # v8.0.1
|
|
with:
|
|
name: ${{ matrix.validator_keys_artifact_name }}
|
|
path: ${{ env.BUILD_DIR }}
|
|
|
|
- name: Make binaries executable
|
|
run: chmod +x "${BUILD_DIR}/xrpld" "${BUILD_DIR}/validator-keys"
|
|
|
|
- name: Determine release info
|
|
id: release_info
|
|
uses: ./.github/actions/release-info
|
|
|
|
- name: Build package
|
|
env:
|
|
PACKAGE_TYPE: ${{ matrix.package_type }}
|
|
PKG_RELEASE: ${{ steps.release_info.outputs.pkg_release }}
|
|
CHANNEL: ${{ steps.release_info.outputs.channel }}
|
|
run: |
|
|
./package/build_pkg.py \
|
|
--package-type "${PACKAGE_TYPE}" \
|
|
--build-dir "${BUILD_DIR}" \
|
|
--pkg-release "${PKG_RELEASE}" \
|
|
--channel "${CHANNEL}"
|
|
|
|
# Before the upload, so the artifact, the tested package and the published
|
|
# package are the same bytes.
|
|
- name: Sign RPM
|
|
if: ${{ inputs.publish && matrix.package_type == 'rpm' }}
|
|
env:
|
|
PKG_SIGNING_KEY: ${{ secrets.signing_key }}
|
|
run: ./package/sign_rpm.py --package-dir "${BUILD_DIR}"
|
|
|
|
# Split from the debug symbols, which are an order of magnitude larger, so
|
|
# that test-install downloads only what it installs.
|
|
- name: Upload package artifact
|
|
uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1
|
|
with:
|
|
name: ${{ matrix.xrpld_artifact_name }}-pkg
|
|
path: |
|
|
${{ env.BUILD_DIR }}/debbuild/xrpld_*.deb
|
|
${{ env.BUILD_DIR }}/rpmbuild/RPMS/**/xrpld-[0-9]*.rpm
|
|
if-no-files-found: error
|
|
|
|
- name: Upload debug symbol artifact
|
|
uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1
|
|
with:
|
|
name: ${{ matrix.xrpld_artifact_name }}-pkg-debug
|
|
path: |
|
|
${{ env.BUILD_DIR }}/debbuild/xrpld-dbgsym_*.deb
|
|
${{ env.BUILD_DIR }}/debbuild/xrpld-dbgsym_*.ddeb
|
|
${{ env.BUILD_DIR }}/rpmbuild/RPMS/**/xrpld-debuginfo-*.rpm
|
|
if-no-files-found: error
|
|
|
|
# Every distro family the packages target, oldest release first, so both ends
|
|
# of the dependency range they declare are exercised.
|
|
test-install:
|
|
needs: [package]
|
|
strategy:
|
|
fail-fast: false
|
|
matrix:
|
|
include:
|
|
- package_type: deb
|
|
image: debian:11
|
|
- package_type: deb
|
|
image: debian:12
|
|
- package_type: deb
|
|
image: debian:13
|
|
- package_type: deb
|
|
image: ubuntu:20.04
|
|
- package_type: deb
|
|
image: ubuntu:22.04
|
|
- package_type: deb
|
|
image: ubuntu:24.04
|
|
- package_type: deb
|
|
image: ubuntu:26.04
|
|
|
|
- package_type: rpm
|
|
image: almalinux:9
|
|
- package_type: rpm
|
|
image: almalinux:10
|
|
- package_type: rpm
|
|
image: rockylinux/rockylinux:9
|
|
- package_type: rpm
|
|
image: rockylinux/rockylinux:10
|
|
- package_type: rpm
|
|
image: registry.access.redhat.com/ubi9/ubi
|
|
- package_type: rpm
|
|
image: registry.access.redhat.com/ubi10/ubi
|
|
name: "install ${{ matrix.package_type }} on ${{ matrix.image }}"
|
|
permissions:
|
|
contents: read
|
|
runs-on: ubuntu-latest
|
|
container: ${{ matrix.image }}
|
|
timeout-minutes: 5
|
|
|
|
steps:
|
|
# Both formats land in one directory; the step below picks its own by
|
|
# extension, so this stays independent of the artifact names.
|
|
- name: Download package artifacts
|
|
uses: actions/download-artifact@3e5f45b2cfb9172054b4087a40e8e0b5a5461e7c # v8.0.1
|
|
with:
|
|
pattern: "*-pkg"
|
|
merge-multiple: true
|
|
path: ${{ env.PACKAGE_DIR }}
|
|
|
|
- name: Find the package
|
|
id: find
|
|
env:
|
|
PACKAGE_TYPE: ${{ matrix.package_type }}
|
|
run: |
|
|
package="$(find "${PACKAGE_DIR}" -type f -name "*.${PACKAGE_TYPE}" -print -quit)"
|
|
test -n "${package}" || {
|
|
echo "no .${PACKAGE_TYPE} found in ${PACKAGE_DIR}" >&2
|
|
exit 1
|
|
}
|
|
echo "package=${package}" >>"${GITHUB_OUTPUT}"
|
|
|
|
# Debian 11 went end-of-life on 2026-08-31
|
|
# (https://www.debian.org/News/2026/20260831) and its packages are
|
|
# already partly gone from deb.debian.org, so switch to the
|
|
# snapshot.debian.org entries the image ships commented out in its
|
|
# sources.list: they are pinned to the snapshot the image was built
|
|
# from, so they serve every version it needs and never go away.
|
|
# Snapshots keep their original, long-passed Valid-Until, hence the
|
|
# disabled check; the retries absorb snapshot.debian.org's throttling.
|
|
- name: Switch Debian 11 to snapshot.debian.org
|
|
if: ${{ matrix.image == 'debian:11' }}
|
|
run: |
|
|
sed -i 's|^deb |# deb |; s|^# deb http://snapshot|deb http://snapshot|' /etc/apt/sources.list
|
|
printf '%s\n' \
|
|
'Acquire::Check-Valid-Until "false";' \
|
|
'Acquire::Retries "3";' \
|
|
>/etc/apt/apt.conf.d/99snapshot
|
|
|
|
- name: Install the DEB
|
|
if: ${{ matrix.package_type == 'deb' }}
|
|
env:
|
|
DEBIAN_FRONTEND: noninteractive
|
|
PACKAGE: ${{ steps.find.outputs.package }}
|
|
run: |
|
|
# Stock Debian and Ubuntu images carry no package lists, so apt has
|
|
# nothing to resolve the systemd dependency from until it fetches them.
|
|
apt-get update -qq
|
|
apt-get install -y "./${PACKAGE}"
|
|
|
|
- name: Install the RPM
|
|
if: ${{ matrix.package_type == 'rpm' }}
|
|
env:
|
|
PACKAGE: ${{ steps.find.outputs.package }}
|
|
run: dnf install -y "./${PACKAGE}"
|
|
|
|
- name: Run xrpld
|
|
run: xrpld --version
|
|
|
|
- name: Run validator-keys
|
|
run: validator-keys --version
|
|
|
|
- name: Run rippled, the legacy compatibility symlink
|
|
run: rippled --version
|
|
|
|
- name: Check the service account
|
|
run: id xrpld
|
|
|
|
- name: Check the state directory
|
|
run: test -d /var/lib/xrpld
|
|
|
|
- name: Check the log directory
|
|
run: test -d /var/log/xrpld
|
|
|
|
publish:
|
|
needs: [generate-matrix, package, test-install]
|
|
strategy:
|
|
fail-fast: false
|
|
matrix: ${{ fromJson(needs.generate-matrix.outputs.matrix) }}
|
|
name: "publish ${{ matrix.xrpld_artifact_name }}"
|
|
permissions:
|
|
contents: read
|
|
runs-on: ["self-hosted", "Linux", "X64", "heavy"]
|
|
container: ${{ matrix.image }}
|
|
timeout-minutes: 30
|
|
|
|
steps:
|
|
- name: Checkout repository
|
|
uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
|
|
|
|
- name: Prepare runner
|
|
uses: XRPLF/actions/prepare-runner@b3e255d74d785d053e4903da8ac90983cd7d9e82
|
|
with:
|
|
enable_ccache: false
|
|
|
|
# Both artifacts, so the debug symbols are published alongside the package.
|
|
- name: Download package artifacts
|
|
uses: actions/download-artifact@3e5f45b2cfb9172054b4087a40e8e0b5a5461e7c # v8.0.1
|
|
with:
|
|
pattern: ${{ matrix.xrpld_artifact_name }}-pkg*
|
|
merge-multiple: true
|
|
path: ${{ env.PACKAGE_DIR }}
|
|
|
|
- name: Determine release info
|
|
id: release_info
|
|
uses: ./.github/actions/release-info
|
|
|
|
- name: Publish package
|
|
env:
|
|
CHANNEL: ${{ steps.release_info.outputs.channel }}
|
|
DRY_RUN_OPTION: ${{ !inputs.publish && '--dry-run' || '' }}
|
|
NEXUS_URL: ${{ inputs.nexus_url }}
|
|
NEXUS_USERNAME: ${{ inputs.publish && secrets.remote_username || '' }}
|
|
NEXUS_PASSWORD: ${{ inputs.publish && secrets.remote_password || '' }}
|
|
run: |
|
|
publish_pkg.py \
|
|
--channel "${CHANNEL}" \
|
|
--package-dir "${PACKAGE_DIR}" \
|
|
--nexus-url "${NEXUS_URL}" \
|
|
${DRY_RUN_OPTION}
|