ludic/.forgejo/workflows/release.yml
Orkuncakilkaya e175619543 refactor(cli)!: split the contributor tool out of the ludic CLI
`ludic help` ended with a section titled "contributing to the toolchain itself",
listing bootstrap, reseed, docs-gen and release tasks. None of that is available
to someone who installed the language — those tasks need the repository — so the
shipped tool was advertising work its user cannot do, in a namespace they have to
read past to find `new` and `run`.

The tasks move to a second program, dev.ludic -> bin/ludic-dev, built from a
checkout and excluded from every release artifact. `ludic` keeps the project and
package commands and nothing else; `ludic dev …` now explains where the tasks
went instead of failing as an unknown command.

What this shook out: the two programs share prelude/build/project/pkg, so the
helpers each had accreted in whichever file first needed them — cc(),
ensure_ludicc, the string functions, title_case, cmd_version — moved to where
both can see them. The argument-shift indirection added for the `dev` namespace
is gone with the namespace, so commands read argv directly again.

`ludic-dev test` asserts the split rather than trusting it: the staged install
must build a project, and `ludic dev build` there must fail while naming
ludic-dev. install.sh keeps building older tags, whose bootstrap goes through
main.ludic.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
2026-09-05 23:15:12 +03:00

99 lines
3.8 KiB
YAML

name: release
# Cutting a release is `ludic-dev release` + `git push --tags`; everything after that
# happens here. Before this workflow existed the artifacts were built on whatever
# machine the maintainer happened to be sitting at, from whatever was in bin/ at
# the time, with no checksums and nothing proving the tagged tree even passed its
# tests. Now the tag is the trigger and CI is the only thing that publishes.
#
# The job refuses to publish unless:
# * the tag matches the VERSION file in the tagged tree,
# * CHANGELOG.md has a section for that version (it becomes the release notes),
# * the toolchain builds from the IR seed and the whole suite passes,
# * the C-free bootstrap still reproduces the seed byte-for-byte.
#
# Needs a repository secret FORGEJO_TOKEN with write access to releases.
on:
push:
tags: ['v*']
workflow_dispatch:
inputs:
tag:
description: 'Tag to publish (e.g. v0.4.0)'
required: true
jobs:
publish:
runs-on: docker
container: node:20-bookworm
steps:
- name: Install clang-16
run: |
set -eu
export DEBIAN_FRONTEND=noninteractive
apt-get update -qq
apt-get install -y -qq --no-install-recommends clang-16 git ca-certificates curl
clang-16 --version | head -1
- name: Check out the tag
env:
REPO_URL: ${{ github.server_url }}/${{ github.repository }}.git
INPUT_TAG: ${{ github.event.inputs.tag }}
run: |
set -eu
git config --global --add safe.directory '*'
# A full clone: `git archive` needs the tag object, and the tarball is
# built from the tag rather than from the working tree.
git clone "$REPO_URL" .
TAG="${INPUT_TAG:-${GITHUB_REF_NAME}}"
git checkout "$TAG"
echo "TAG=$TAG" >> "$GITHUB_ENV"
# See ci.yml for why the Linux build injects the stdio shim via LUDIC_CC.
echo "LUDIC_CC=clang-16 $(pwd)/tools/ci/linux_stdio_shim.ll" >> "$GITHUB_ENV"
echo "LUDIC_HOME=$(pwd)" >> "$GITHUB_ENV"
- name: The tag, VERSION and CHANGELOG must agree
run: |
set -eu
VERSION="$(cat VERSION)"
if [ "$TAG" != "v${VERSION}" ]; then
echo "::error::tag ${TAG} does not match VERSION (${VERSION})"
exit 1
fi
if ! grep -q "^## v${VERSION} " CHANGELOG.md; then
echo "::error::CHANGELOG.md has no '## v${VERSION}' section to use as release notes"
exit 1
fi
echo "publishing ${TAG}"
- name: Build the toolchain from the IR seed (clang only)
run: |
set -eu
mkdir -p bin
clang-16 tools/ci/linux_stdio_shim.ll selfhost/ludicc.seed.ll -o bin/ludicc
bin/ludicc tools/ludic-cli/dev.ludic -o bin/ludic-dev
bin/ludic-dev build
- name: The tagged tree must pass its own suites
run: |
set -eu
bin/ludic-dev test
bin/ludic-dev test-tools
bin/ludic-dev bootstrap-cfree
- name: Publish the release
env:
FORGEJO_TOKEN: ${{ secrets.FORGEJO_TOKEN }}
LUDIC_FORGEJO_API: ${{ github.server_url }}/api/v1/repos/${{ github.repository }}
run: |
set -eu
if [ -z "${FORGEJO_TOKEN:-}" ]; then
echo "::error::No FORGEJO_TOKEN secret; cannot create the release."
exit 1
fi
# ludic-dev publish builds dist/ (source tarball from the tag, this host's
# toolchain, SHA256SUMS), takes the notes from the CHANGELOG section,
# and creates the release. Re-running it only adds missing assets, so
# a maintainer can afterwards attach the macOS toolchain from a Mac
# with the same command.
bin/ludic-dev publish "$TAG"