Files
oh-my-pi/.github/workflows/ci.yml
T
can1357 ed4c78bc0f feat: streamlined native addon builds and caching in ci workflows
- Enhance CI workflows to build and reuse native addon artifacts instead of recompiling.
- Update bazel cache actions with selective backend detection and separate remote and disk modes.
- Add `--source` CLI option to install prebuilt native targets without requiring Bazel.
- Increase Kata runner memory configuration from 12Gi to 24Gi.
2026-07-28 02:06:13 +02:00

679 lines
32 KiB
YAML

name: CI
on:
push:
branches: [main]
paths:
- "packages/**"
- "crates/**"
- "scripts/**"
- "bazel/**"
- "MODULE.bazel"
- "BUILD.bazel"
- ".bazelrc"
- ".bazelversion"
- "Cargo.toml"
- "Cargo.lock"
- "Cargo.Bazel.lock"
- ".github/**"
pull_request:
branches: [main]
paths:
- "packages/**"
- "crates/**"
- "scripts/**"
- "bazel/**"
- "MODULE.bazel"
- "BUILD.bazel"
- ".bazelrc"
- ".bazelversion"
- "Cargo.toml"
- "Cargo.lock"
- "Cargo.Bazel.lock"
- ".github/**"
workflow_dispatch:
inputs:
skip_npm:
description: "Skip npm publish"
type: boolean
default: false
# Release runs publish a `v*` tag pushed atomically with main HEAD; sharing
# the cheap branch-wide `CI-refs/heads/main` group meant a later main push
# silently cancelled the in-flight release and left the tag without a GitHub
# Release or npm publish (#2564). Detect release runs at workflow-scheduling
# time via the release-script commit subject (`chore: bump version to vX.Y.Z`),
# via `v*` tag-ref dispatches, and via manual dispatches whose tag-on-HEAD
# status is only known after checkout; scope them to a per-sha group with no
# cancellation. Every other event keeps branch-wide cancellation for PR/main churn.
concurrency:
group: "${{ github.workflow }}-${{ (startsWith(github.event.head_commit.message, 'chore: bump version to ') || startsWith(github.ref, 'refs/tags/v') || github.event_name == 'workflow_dispatch') && format('release-{0}', github.sha) || github.ref }}"
cancel-in-progress: "${{ !(startsWith(github.event.head_commit.message, 'chore: bump version to ') || startsWith(github.ref, 'refs/tags/v') || github.event_name == 'workflow_dispatch') }}"
env:
FORCE_JAVASCRIPT_ACTIONS_TO_NODE24: true
permissions:
contents: read
jobs:
# scripts/release.ts pushes the version-bump commit and its `v*` tag
# atomically (`git push --atomic origin refs/heads/main:refs/heads/main
# <sha>:refs/tags/v<version>`), so a release now arrives as a single `push` to
# `refs/heads/main` — we no longer trigger on the tag ref at all (see
# `on.push`). This one branch-push run is therefore authoritative: it runs the
# full build AND, when HEAD carries a release tag, the release/publish jobs.
# `release_metadata` resolves that tag once so downstream jobs switch on
# `is-release` and address the tag by name — `github.ref` is
# `refs/heads/main` here, not the tag. A `workflow_dispatch` from a `v*` tag
# ref (or from a tagged main HEAD) is also treated as a release.
release_metadata:
name: Resolve release metadata
runs-on: ${{ github.event_name == 'pull_request' && 'ubuntu-22.04' || 'omp-kata' }}
outputs:
is-release: ${{ steps.detect.outputs.is-release }}
release-tag: ${{ steps.detect.outputs.release-tag }}
steps:
# Only a main-branch run needs tags fetched, so `git tag --points-at
# HEAD` can see the freshly-pushed `v*`. A tag-ref dispatch reads the
# tag straight from `github.ref_name`, and fetching `--tags` while
# checkout uses an explicit tag refspec makes git refuse — so scope
# fetch-tags to main refs.
- uses: actions/checkout@v4
with:
fetch-tags: ${{ github.ref == 'refs/heads/main' }}
- name: Detect release tag at HEAD
id: detect
shell: bash
run: |
is_release=false
release_tag=""
case "${{ github.ref }}" in
refs/tags/v[0-9]*)
release_tag="${{ github.ref_name }}"
;;
refs/heads/main)
if [ "${{ github.event_name }}" != "pull_request" ]; then
release_tag=$(git tag --points-at HEAD | grep -E '^v[0-9]' | head -n1 || true)
fi
;;
esac
if [ -n "$release_tag" ]; then
echo "HEAD carries release tag $release_tag; this run builds and publishes the release."
is_release=true
fi
{
echo "is-release=$is_release"
echo "release-tag=$release_tag"
} >> "$GITHUB_OUTPUT"
check:
name: Lint, type check & web build
runs-on: ${{ github.event_name == 'pull_request' && 'ubuntu-22.04' || 'omp-kata' }}
steps:
- uses: actions/checkout@v4
- uses: ./.github/actions/bun-install
- name: Type check workspace
run: bun run ci:check:full
- name: Build collab web
run: bun run collab:web:build
# One Bazel job validates Rust changes and builds native addons for every
# downstream job. Main builds all Linux-hosted targets. Pull requests build
# only the Linux x64 pair required by tests.
rust:
name: Validate Rust workspace (bazel)
runs-on: ${{ github.event_name == 'pull_request' && 'ubuntu-22.04' || 'omp-kata' }}
steps:
- uses: actions/checkout@v4
# TS-only PRs skip Rust validation. They still materialize the Linux
# x64 addons once from the main-exported disk cache.
- name: Detect Rust-affecting changes
id: changes
shell: bash
env:
GH_TOKEN: ${{ github.token }}
run: |
if [ "${{ github.event_name }}" != "pull_request" ]; then
echo "rust=true" >> "$GITHUB_OUTPUT"
exit 0
fi
if gh pr diff ${{ github.event.pull_request.number }} --name-only \
| grep -qE '^(crates/|Cargo\.(toml|lock)|Cargo\.Bazel\.lock|MODULE\.bazel|BUILD\.bazel|\.bazelrc|\.bazelversion|bazel/|rust-toolchain\.toml|rustfmt\.toml|scripts/bazel-natives|\.github/actions/bazel-|\.github/workflows/ci\.yml)'; then
echo "rust=true" >> "$GITHUB_OUTPUT"
else
echo "No Rust-affecting changes; skipping validation."
echo "rust=false" >> "$GITHUB_OUTPUT"
fi
- if: steps.changes.outputs.rust == 'true'
uses: ./.github/actions/bun-install
- id: cache
uses: ./.github/actions/bazel-cache
with:
scope: linux
# Main pushes export the disk cache PRs restore (once per
# lockfile change; no-op otherwise).
export: ${{ github.event_name != 'pull_request' }}
- name: Rust tests
if: steps.changes.outputs.rust == 'true'
# The ulimit guard runs in the step that launches the bazel server
# (limits are per-process and the server persists across steps).
run: |
if [ "$(ulimit -Sn)" != unlimited ] && [ "$(ulimit -Sn)" -lt 65536 ]; then ulimit -Sn 65536 || true; fi
bazelisk --bazelrc="${{ steps.cache.outputs.rc }}" test //crates/...
# Clippy scope mirrors `cargo clippy --workspace` (libraries only, no
# test targets) plus the strict/default split: crates with
# `[lints] workspace = true` get the workspace policy, the vendored
# brush fork is exempt (same as run-rs-task.ts's cargo excludes).
- name: Clippy (workspace lint policy on opted-in crates)
if: steps.changes.outputs.rust == 'true'
run: |
bazelisk query "kind('rust_library|rust_shared_library', //crates/pi-ast/... + //crates/pi-iso/... + //crates/pi-natives/... + //crates/pi-shell/... + //crates/pi-walker/...)" \
| xargs bazelisk --bazelrc="${{ steps.cache.outputs.rc }}" build --config=clippy-strict --
- name: Clippy (default lints elsewhere)
if: steps.changes.outputs.rust == 'true'
run: |
bazelisk query "kind('rust_library|rust_shared_library', //crates/... - (//crates/pi-ast/... + //crates/pi-iso/... + //crates/pi-natives/... + //crates/pi-shell/... + //crates/pi-walker/...) - //crates/vendor/brush-core/... - //crates/vendor/brush-builtins/...)" \
| xargs bazelisk --bazelrc="${{ steps.cache.outputs.rc }}" build --config=clippy --
- name: Rustfmt
if: steps.changes.outputs.rust == 'true'
run: bazelisk --bazelrc="${{ steps.cache.outputs.rc }}" build --config=rustfmt //crates/...
- name: Build native addons once
env:
EVENT_NAME: ${{ github.event_name }}
run: |
set -euo pipefail
if [ "$(ulimit -Sn)" != unlimited ] && [ "$(ulimit -Sn)" -lt 65536 ]; then ulimit -Sn 65536 || true; fi
targets=(//:natives-linux-x64-baseline //:natives-linux-x64-modern)
if [ "$EVENT_NAME" != "pull_request" ]; then
targets=(//:natives-linux-all)
fi
bazelisk --bazelrc="${{ steps.cache.outputs.rc }}" build "${targets[@]}"
- name: Save Bazel disk cache
if: steps.cache.outputs.save-needed == 'true'
uses: actions/cache/save@0057852bfaa89a56745cba8c7296529d2fc39830 # v4.3.0
with:
path: ~/.cache/omp-bazel-disk
key: ${{ steps.cache.outputs.cache-key }}
- name: Upload native addon artifacts
uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1
with:
name: native-addons
path: bazel-bin/natives-*/*.node
if-no-files-found: error
retention-days: 1
test_workspace:
name: Test TS workspace fast
runs-on: ${{ github.event_name == 'pull_request' && 'ubuntu-22.04' || 'omp-kata' }}
needs: [rust]
if: ${{ !cancelled() && needs.rust.result == 'success' }}
timeout-minutes: 20
steps:
- uses: actions/checkout@v4
- uses: ./.github/actions/setup-system-deps
- uses: ./.github/actions/bun-install
- uses: ./.github/actions/native-artifacts
with:
targets: linux-x64-baseline linux-x64-modern
- name: Test workspace packages and repo scripts (TS)
env:
OMP_TEST_CONCURRENCY: "4"
run: bun run ci:test:ts:workspace
test_coding_agent_singleton:
name: Test coding-agent singleton/global-state (TS)
runs-on: ${{ github.event_name == 'pull_request' && 'ubuntu-22.04' || 'omp-kata' }}
needs: [rust]
if: ${{ !cancelled() && needs.rust.result == 'success' }}
timeout-minutes: 20
steps:
- uses: actions/checkout@v4
- uses: ./.github/actions/setup-system-deps
- uses: ./.github/actions/bun-install
- uses: ./.github/actions/native-artifacts
with:
targets: linux-x64-baseline linux-x64-modern
- name: Test coding-agent singleton/global-state bucket
# Keep global Settings/env/fake-timer tests serial; native addon
# artifacts are still available like every other coding-agent bucket.
run: bun run ci:test:coding-agent:singleton
test_ts_native:
name: Test TS native/integration packages
runs-on: ${{ github.event_name == 'pull_request' && 'ubuntu-22.04' || 'omp-kata' }}
needs: [rust]
if: ${{ !cancelled() && needs.rust.result == 'success' }}
timeout-minutes: 25
steps:
- uses: actions/checkout@v4
- uses: ./.github/actions/setup-system-deps
- uses: ./.github/actions/bun-install
- uses: ./.github/actions/native-artifacts
with:
targets: linux-x64-baseline linux-x64-modern
- name: Test native/TUI/browser-ish packages (TS)
env:
OMP_TEST_CONCURRENCY: "4"
run: bun run ci:test:ts:native
test_coding_agent_ui:
name: Test coding-agent UI/TUI (TS)
runs-on: ${{ github.event_name == 'pull_request' && 'ubuntu-22.04' || 'omp-kata' }}
needs: [rust]
if: ${{ !cancelled() && needs.rust.result == 'success' }}
timeout-minutes: 25
steps:
- uses: actions/checkout@v4
- uses: ./.github/actions/setup-system-deps
- uses: ./.github/actions/bun-install
- uses: ./.github/actions/native-artifacts
with:
targets: linux-x64-baseline linux-x64-modern
- name: Test coding-agent UI/TUI bucket
env:
OMP_TEST_CONCURRENCY: "2"
run: bun run ci:test:coding-agent:ui
test_coding_agent_runtime:
name: Test coding-agent runtime/session (TS)
runs-on: ${{ github.event_name == 'pull_request' && 'ubuntu-22.04' || 'omp-kata' }}
needs: [rust]
if: ${{ !cancelled() && needs.rust.result == 'success' }}
timeout-minutes: 25
steps:
- uses: actions/checkout@v4
- uses: ./.github/actions/setup-system-deps
- uses: ./.github/actions/bun-install
- uses: ./.github/actions/native-artifacts
with:
targets: linux-x64-baseline linux-x64-modern
- name: Test coding-agent runtime bucket
# Runtime/session tests import native-backed barrels too; keep this
# separate for concurrency, not as a native-free guardrail.
env:
OMP_TEST_CONCURRENCY: "4"
run: bun run ci:test:coding-agent:runtime
test_coding_agent_native:
name: Test coding-agent native/unit (TS)
runs-on: ${{ github.event_name == 'pull_request' && 'ubuntu-22.04' || 'omp-kata' }}
needs: [rust]
if: ${{ !cancelled() && needs.rust.result == 'success' }}
timeout-minutes: 25
steps:
- uses: actions/checkout@v4
- uses: ./.github/actions/setup-system-deps
- uses: ./.github/actions/bun-install
- uses: ./.github/actions/native-artifacts
with:
targets: linux-x64-baseline linux-x64-modern
- name: Test coding-agent native/unit bucket
env:
OMP_TEST_CONCURRENCY: "4"
run: bun run ci:test:coding-agent:native
test_smoke:
name: Test CLI smoke (TS)
runs-on: ${{ github.event_name == 'pull_request' && 'ubuntu-22.04' || 'omp-kata' }}
needs: [rust]
if: ${{ !cancelled() && needs.rust.result == 'success' }}
timeout-minutes: 15
steps:
- uses: actions/checkout@v4
- uses: ./.github/actions/setup-system-deps
- uses: ./.github/actions/bun-install
- uses: ./.github/actions/native-artifacts
with:
targets: linux-x64-baseline linux-x64-modern
- name: CLI smoke test
run: bun run ci:test:smoke
install_methods:
name: Install method smoke tests
runs-on: ${{ github.event_name == 'pull_request' && 'ubuntu-22.04' || 'omp-kata' }}
needs: [rust]
if: ${{ !cancelled() && needs.rust.result == 'success' }}
steps:
- uses: actions/checkout@v4
- uses: ./.github/actions/setup-system-deps
- uses: ./.github/actions/bun-install
- uses: ./.github/actions/native-artifacts
with:
targets: linux-x64-baseline linux-x64-modern
- name: Install method smoke tests
env:
OMP_INSTALL_TEST_SKIP_NATIVE_BUILD: "1"
run: bun run ci:test:install-methods
release_binary:
name: "Release binary: ${{ matrix.target_id }}"
if: ${{ needs.release_metadata.outputs.is-release == 'true' && !cancelled() &&
needs.rust.result == 'success' &&
needs.test_workspace.result == 'success' &&
needs.test_coding_agent_singleton.result == 'success' &&
needs.test_ts_native.result == 'success' &&
needs.test_coding_agent_ui.result == 'success' &&
needs.test_coding_agent_runtime.result == 'success' &&
needs.test_coding_agent_native.result == 'success' &&
needs.test_smoke.result == 'success' && needs.check.result == 'success' &&
needs.install_methods.result == 'success' }}
needs: [release_metadata, check, rust, test_workspace, test_coding_agent_singleton, test_ts_native, test_coding_agent_ui, test_coding_agent_runtime, test_coding_agent_native, test_smoke, install_methods]
strategy:
fail-fast: false
matrix:
include:
- {
os: ubuntu-22.04,
platform: linux,
arch: x64,
target_id: linux-x64,
binary_path: packages/coding-agent/binaries/omp-linux-x64,
native_targets: linux-x64-baseline linux-x64-modern,
}
- {
os: ubuntu-22.04,
platform: linux,
libc: musl,
arch: x64,
target_id: linux-musl-x64,
binary_path: packages/coding-agent/binaries/omp-linux-musl-x64,
native_targets: linux-musl-x64-baseline,
}
- {
os: ubuntu-24.04-arm,
platform: linux,
arch: arm64,
target_id: linux-arm64,
binary_path: packages/coding-agent/binaries/omp-linux-arm64,
native_targets: linux-arm64,
}
- {
os: ubuntu-24.04-arm,
platform: linux,
libc: musl,
arch: arm64,
target_id: linux-musl-arm64,
binary_path: packages/coding-agent/binaries/omp-linux-musl-arm64,
native_targets: linux-musl-arm64,
}
- {
os: macos-15-intel,
platform: darwin,
arch: x64,
target_id: darwin-x64,
binary_path: packages/coding-agent/binaries/omp-darwin-x64,
native_targets: darwin-x64-baseline,
}
- {
os: macos-14,
platform: darwin,
arch: arm64,
target_id: darwin-arm64,
binary_path: packages/coding-agent/binaries/omp-darwin-arm64,
native_targets: darwin-arm64,
}
- {
os: ubuntu-22.04,
platform: win32,
arch: x64,
target_id: win32-x64,
binary_path: packages/coding-agent/binaries/omp-windows-x64.exe,
native_targets: win32-x64-baseline,
}
runs-on: ${{ matrix.os }}
permissions:
contents: read
id-token: write
env:
MACOS_SIGNING: ${{ secrets.APPLE_CERTIFICATE_P12 != '' && secrets.APPLE_CERTIFICATE_PASSWORD != '' && secrets.APPLE_API_KEY_ID != '' && secrets.APPLE_API_ISSUER_ID != '' && secrets.APPLE_API_KEY != '' }}
steps:
- uses: actions/checkout@df4cb1c069e1874edd31b4311f1884172cec0e10 # v6.0.3
- uses: oven-sh/setup-bun@0c5077e51419868618aeaa5fe8019c62421857d6 # v2.2.0
with:
bun-version: "1.3"
- uses: actions/setup-node@48b55a011bda9f5d6aeb4c2d9c7362e8dae4041e # v6.4.0
with:
node-version: "24"
registry-url: "https://registry.npmjs.org"
# npm runs under Bun when invoked by the release script; npm 12
# requires a newer emulated Node version than Bun 1.3 provides.
- name: Ensure npm supports trusted publishing
if: ${{ !inputs.skip_npm }}
run: npm install -g npm@11.17.0
- name: Cache bun dependencies
uses: actions/cache@0057852bfaa89a56745cba8c7296529d2fc39830 # v4.3.0
with:
path: ~/.bun/install/cache
key: bun-${{ runner.os }}-${{ hashFiles('**/bun.lock') }}
- run: bun install --frozen-lockfile
# Linux and Windows addons come from the Rust job. Darwin runners
# build only their own architecture because cross-hosted artifacts do
# not exist for macOS.
- name: Install prebuilt native addon(s)
if: matrix.platform != 'darwin'
uses: ./.github/actions/native-artifacts
with:
targets: ${{ matrix.native_targets }}
- name: Build native addon (bazel)
if: matrix.platform == 'darwin'
uses: ./.github/actions/bazel-natives
with:
targets: ${{ matrix.native_targets }}
cache-scope: release-${{ matrix.target_id }}
- name: Build release binary
env:
RELEASE_TARGETS: ${{ matrix.target_id }}
run: bun run ci:release:build-binaries
- name: Sign and notarize macOS binary (Developer ID)
# Replaces the ad-hoc signature with a Developer ID + hardened-runtime
# one (+JIT/library-validation entitlements; omp dlopens its
# runtime-extracted native addon, which has a different Team ID) and
# notarizes. Auto-skips until the APPLE_* secrets are configured.
if: matrix.platform == 'darwin' && env.MACOS_SIGNING == 'true'
env:
APPLE_CERTIFICATE_P12: ${{ secrets.APPLE_CERTIFICATE_P12 }}
APPLE_CERTIFICATE_PASSWORD: ${{ secrets.APPLE_CERTIFICATE_PASSWORD }}
APPLE_API_KEY_ID: ${{ secrets.APPLE_API_KEY_ID }}
APPLE_API_ISSUER_ID: ${{ secrets.APPLE_API_ISSUER_ID }}
APPLE_API_KEY: ${{ secrets.APPLE_API_KEY }}
run: bash scripts/ci-macos-sign.sh "${{ matrix.binary_path }}"
# Windows binary is cross-built on Linux, so we have no Windows runner
# to smoke it on. Cross-build correctness is verified via the bun
# `--compile --target=bun-windows-x64-*` cross-compile. Musl binaries
# need the musl loader, which glibc runners lack — they are smoked in
# the Alpine container step below instead.
- name: Smoke release binary
if: matrix.platform != 'win32' && matrix.libc != 'musl'
run: |
runtime_dir="$(mktemp -d)"
HOME="$runtime_dir/home" XDG_DATA_HOME="$runtime_dir/xdg" "${{ matrix.binary_path }}" --version
HOME="$runtime_dir/home" XDG_DATA_HOME="$runtime_dir/xdg" "${{ matrix.binary_path }}" --smoke-test
- name: Smoke musl release binary on Alpine
if: matrix.libc == 'musl'
run: |
binary="$(realpath "${{ matrix.binary_path }}")"
# Bun's musl-target binaries link libstdc++/libgcc dynamically;
# Alpine users install them alongside the binary (same as bun itself).
docker run --rm -v "$binary:/usr/local/bin/omp:ro" alpine:3.22 sh -ec '
apk add --no-cache libstdc++ libgcc >/dev/null
runtime_dir="$(mktemp -d)"
HOME="$runtime_dir/home" XDG_DATA_HOME="$runtime_dir/xdg" omp --version
HOME="$runtime_dir/home" XDG_DATA_HOME="$runtime_dir/xdg" omp --smoke-test
'
- name: Publish native addon package
if: ${{ !inputs.skip_npm && matrix.libc != 'musl' }}
env:
# Fallback auth: setup-node wrote an .npmrc referencing
# NODE_AUTH_TOKEN; npm uses it only when OIDC has no trusted
# publisher for the package (or on a first publish).
NODE_AUTH_TOKEN: ${{ secrets.NPM_TOKEN }}
run: bun run ci:release:publish-native-leaf ${{ matrix.target_id }}
- name: Upload release binary artifact
uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1
with:
name: omp-binary-${{ matrix.target_id }}
path: ${{ matrix.binary_path }}
release_github:
name: Publish GitHub release
if: ${{ needs.release_metadata.outputs.is-release == 'true' && !cancelled() &&
needs.release_binary.result == 'success' }}
needs: [release_metadata, release_binary]
runs-on: ubuntu-22.04
permissions:
contents: write
steps:
- uses: actions/checkout@df4cb1c069e1874edd31b4311f1884172cec0e10 # v6.0.3
- uses: oven-sh/setup-bun@0c5077e51419868618aeaa5fe8019c62421857d6 # v2.2.0
with:
bun-version: "1.3"
- name: Generate release notes from CHANGELOGs
env:
# `gh release list` (used to find the latest published GitHub
# Release tag below the target so silent-tag changelog sections
# roll forward — #2596) requires GH_TOKEN in Actions. Without
# it gh exits non-zero and the script would degrade to legacy
# single-version notes, defeating the recovery.
GH_TOKEN: ${{ secrets.GITHUB_TOKEN }}
run: bun scripts/ci-release-notes.ts ${{ needs.release_metadata.outputs.release-tag }}
- name: Download release binaries
uses: actions/download-artifact@3e5f45b2cfb9172054b4087a40e8e0b5a5461e7c # v8.0.1
with:
pattern: omp-binary-*
path: packages/coding-agent/binaries
merge-multiple: true
- name: Create GitHub Release
uses: softprops/action-gh-release@3bb12739c298aeb8a4eeaf626c5b8d85266b0e65 # v2.6.2
with:
tag_name: ${{ needs.release_metadata.outputs.release-tag }}
files: |
packages/coding-agent/binaries/omp-*
body_path: release-notes.md
generate_release_notes: true
release_github_verify:
name: Verify published release (macOS)
if: ${{ needs.release_metadata.outputs.is-release == 'true' && !cancelled() &&
needs.release_github.result == 'success' }}
needs: [release_metadata, release_github]
runs-on: macos-14
permissions:
contents: read
env:
MACOS_SIGNING: ${{ secrets.APPLE_CERTIFICATE_P12 != '' && secrets.APPLE_CERTIFICATE_PASSWORD != '' && secrets.APPLE_API_KEY_ID != '' && secrets.APPLE_API_ISSUER_ID != '' && secrets.APPLE_API_KEY != '' }}
steps:
- name: Download published macOS arm64 binary
run: |
curl -fsSL -o omp-darwin-arm64 "https://github.com/${{ github.repository }}/releases/download/${{ needs.release_metadata.outputs.release-tag }}/omp-darwin-arm64"
chmod +x omp-darwin-arm64
- name: Verify published macOS arm64 binary
run: |
codesign -dvvv ./omp-darwin-arm64
codesign --verify --strict --verbose=4 ./omp-darwin-arm64
runtime_dir="$(mktemp -d)"
HOME="$runtime_dir/home" XDG_DATA_HOME="$runtime_dir/xdg" ./omp-darwin-arm64 --version
HOME="$runtime_dir/home" XDG_DATA_HOME="$runtime_dir/xdg" ./omp-darwin-arm64 --smoke-test
- name: Assert signed release is not ad-hoc
if: env.MACOS_SIGNING == 'true'
run: |
if codesign -dvvv ./omp-darwin-arm64 2>&1 | grep -qE "flags=.*adhoc|Signature=adhoc"; then
echo "published binary is still ad-hoc signed (Developer ID signing did not run)" >&2
exit 1
fi
# Gatekeeper assessment: a notarized Developer ID binary is accepted.
# Informational — a bare (unstapled) Mach-O relies on the online ticket
# lookup, so surface the result without gating the release on it.
spctl -a -t exec -vv ./omp-darwin-arm64 || echo "spctl non-zero (expected for unstapled bare binary; ticket served online)"
release_npm:
name: Publish to npm
if: ${{ needs.release_metadata.outputs.is-release == 'true' && !cancelled() &&
needs.release_binary.result == 'success' &&
needs.release_github_verify.result == 'success' &&
!inputs.skip_npm }}
needs: [release_metadata, release_binary, release_github_verify]
runs-on: ubuntu-22.04
# `id-token: write` lets npm mint the GitHub OIDC token it exchanges for a
# short-lived publish token (trusted publishing + provenance). When a
# package has no matching trusted publisher configured, npm silently falls
# back to NODE_AUTH_TOKEN below — which also covers first-ever publishes.
permissions:
id-token: write
contents: read
steps:
- uses: actions/checkout@df4cb1c069e1874edd31b4311f1884172cec0e10 # v6.0.3
- uses: oven-sh/setup-bun@0c5077e51419868618aeaa5fe8019c62421857d6 # v2.2.0
with:
bun-version: "1.3"
- uses: actions/setup-node@48b55a011bda9f5d6aeb4c2d9c7362e8dae4041e # v6.4.0
with:
node-version: "24"
registry-url: "https://registry.npmjs.org"
# npm runs under Bun when invoked by the release script; npm 12
# requires a newer emulated Node version than Bun 1.3 provides.
- name: Ensure npm supports trusted publishing
run: npm install -g npm@11.17.0
- name: Cache bun dependencies
uses: actions/cache@0057852bfaa89a56745cba8c7296529d2fc39830 # v4.3.0
with:
path: ~/.bun/install/cache
key: bun-${{ runner.os }}-${{ hashFiles('**/bun.lock') }}
- run: bun install --frozen-lockfile
# The prepack executes workspace code which loads the Linux x64
# addon, so install the Rust job's artifact before publishing.
- name: Install prebuilt native addons
uses: ./.github/actions/native-artifacts
with:
targets: linux-x64-baseline linux-x64-modern
- name: Publish to npm
env:
# Fallback auth: setup-node wrote an .npmrc referencing
# NODE_AUTH_TOKEN; npm uses it only when OIDC has no trusted
# publisher for the package (or on a first publish).
NODE_AUTH_TOKEN: ${{ secrets.NPM_TOKEN }}
run: bun run ci:release:publish
# Regenerate the Homebrew tap formula (can1357/homebrew-tap) from the freshly
# published release assets and push it. Gated on release_github_verify so the
# tap only cuts over to a release whose published binary was verified (matches
# how release_npm is gated). No-ops when HOMEBREW_TAP_DEPLOY_KEY is unset, so a
# release never blocks on tap access.
release_brew:
name: Update Homebrew tap
if: ${{ needs.release_metadata.outputs.is-release == 'true' && !cancelled() &&
needs.release_github_verify.result == 'success' }}
needs: [release_metadata, release_github_verify]
runs-on: ubuntu-22.04
env:
HAS_TAP_KEY: ${{ secrets.HOMEBREW_TAP_DEPLOY_KEY != '' }}
steps:
- uses: actions/checkout@df4cb1c069e1874edd31b4311f1884172cec0e10 # v6.0.3
if: env.HAS_TAP_KEY == 'true'
- uses: oven-sh/setup-bun@0c5077e51419868618aeaa5fe8019c62421857d6 # v2.2.0
if: env.HAS_TAP_KEY == 'true'
with:
bun-version: "1.3"
- name: Check out the Homebrew tap
if: env.HAS_TAP_KEY == 'true'
uses: actions/checkout@df4cb1c069e1874edd31b4311f1884172cec0e10 # v6.0.3
with:
repository: can1357/homebrew-tap
ssh-key: ${{ secrets.HOMEBREW_TAP_DEPLOY_KEY }}
path: homebrew-tap
- name: Regenerate and push the formula
if: env.HAS_TAP_KEY == 'true'
env:
GH_TOKEN: ${{ secrets.GITHUB_TOKEN }}
run: |
bun scripts/ci-update-brew-formula.ts "${{ needs.release_metadata.outputs.release-tag }}" --out homebrew-tap/Formula/omp.rb
cd homebrew-tap
if git diff --quiet -- Formula/omp.rb; then
echo "formula already up to date for ${{ needs.release_metadata.outputs.release-tag }}"
exit 0
fi
git -c user.name="github-actions[bot]" \
-c user.email="41898282+github-actions[bot]@users.noreply.github.com" \
commit -m "omp ${{ needs.release_metadata.outputs.release-tag }}" -- Formula/omp.rb
git push origin HEAD:main