fix(release): per-artifact checksums so a release can span hosts
build_artifacts wrote a single dist/SHA256SUMS covering whatever that host happened to build. But a release is assembled from more than one machine — the Linux runner cannot produce the darwin-arm64 toolchain — and forgejo_upload_assets deliberately skips an asset whose name is already attached. So the first host to publish wrote SHA256SUMS, and every artifact added later was silently left uncovered by it. Emit one <artifact>.sha256 per tarball instead. The names are unique, so each host's contribution stands on its own and nothing goes stale. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
This commit is contained in:
parent
f81ca5c3c1
commit
80da7e6275
4 changed files with 41 additions and 6 deletions
|
|
@ -93,17 +93,28 @@ git push origin main --follow-tags
|
|||
**Pushing the tag is what publishes.** The `release` workflow builds the
|
||||
toolchain from the IR seed, runs `x test`, `x test-tools` and `x bootstrap-cfree`
|
||||
against the tagged tree, and only then creates the Forgejo release — with the
|
||||
source tarball, a Linux toolchain build, `SHA256SUMS`, and that version's
|
||||
source tarball, a Linux toolchain build, a `.sha256` beside each, and that version's
|
||||
`CHANGELOG.md` section as the notes. It refuses to publish if the tag and
|
||||
`VERSION` disagree or the changelog has no section for it.
|
||||
|
||||
macOS artifacts cannot be produced on the Linux runner. To attach one, run the
|
||||
same command CI runs from a Mac — it only adds assets the release is missing:
|
||||
macOS artifacts cannot be produced on the Linux runner — a `darwin-arm64` build
|
||||
needs a macOS host, and there is no cross-compile path (it would need the Xcode
|
||||
SDK and a Mach-O linker). Attaching one therefore means either registering a
|
||||
macOS runner and giving it a job, or running the same command CI runs from a
|
||||
Mac. Either way it is `x publish`, which only adds assets the release is missing:
|
||||
|
||||
```bash
|
||||
FORGEJO_TOKEN=… x publish v0.4.0
|
||||
```
|
||||
|
||||
Checksums are one `.sha256` file per artifact rather than a single `SHA256SUMS`,
|
||||
precisely because a release can be assembled from more than one host and an
|
||||
asset that already exists is never overwritten. Verify one with:
|
||||
|
||||
```bash
|
||||
shasum -a 256 -c ludic-0.4.0-src.tar.gz.sha256
|
||||
```
|
||||
|
||||
The tag doubles as the reproducible bootstrap point: the source archive plus its
|
||||
checked-in seed rebuild that exact toolchain.
|
||||
|
||||
|
|
|
|||
Loading…
Add table
Add a link
Reference in a new issue