Skip to content
Merged
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
26 changes: 20 additions & 6 deletions .github/workflows/create_release.yml
Original file line number Diff line number Diff line change
@@ -1,15 +1,21 @@
name: Create Release

# LLGo releases are cut only from the tested llgo branch.
# Validate release packages on PRs; publish tags only from the tested llgo branch.

on:
pull_request:
branches:
- llgo
push:
tags:
- "llgo-v*"

permissions:
contents: write

env:
LLGO_PACKAGE_VERSION: ${{ github.event_name == 'pull_request' && format('pr-{0}', github.event.pull_request.number) || github.ref_name }}

jobs:
verify-source:
runs-on: ubuntu-latest
Expand All @@ -18,6 +24,7 @@ jobs:
with:
fetch-depth: 0
- name: Require tag at llgo branch tip
if: github.event_name == 'push'
run: |
git fetch origin llgo
test "$(git rev-parse HEAD)" = "$(git rev-parse origin/llgo)"
Expand Down Expand Up @@ -61,7 +68,7 @@ jobs:

- name: cmake (win arm64)
# -G "Visual Studio 15 2017"
run: cmake -S . -B out -DCMAKE_INSTALL_PREFIX=out-arm64/install
run: cmake -S . -B out-arm64 -DCMAKE_INSTALL_PREFIX=out-arm64/install
if: matrix.os == 'windows-11-arm'

- name: build
Expand All @@ -81,7 +88,7 @@ jobs:
run: |
# Ignore all but the first component of the os name
OSNAME=$(echo ${{ matrix.os }} | sed 's/-.*//')
VERSION=$GITHUB_REF_NAME
VERSION=$LLGO_PACKAGE_VERSION
PKGNAME="binaryen-$VERSION-x86_64-$OSNAME"
TARBALL=$PKGNAME.tar.gz
SHASUM=$PKGNAME.tar.gz.sha256
Expand All @@ -100,7 +107,7 @@ jobs:
run: |
# Ignore all but the first component of the os name
OSNAME=$(echo ${{ matrix.os }} | sed 's/-.*//')
VERSION=$GITHUB_REF_NAME
VERSION=$LLGO_PACKAGE_VERSION
PKGNAME="binaryen-$VERSION-arm64-$OSNAME"
TARBALL=$PKGNAME.tar.gz
SHASUM=$PKGNAME.tar.gz.sha256
Expand All @@ -115,6 +122,7 @@ jobs:
if: ${{ matrix.os == 'macos-14' || matrix.os == 'windows-11-arm' }}

- name: upload tarball
if: github.event_name == 'push'
uses: softprops/action-gh-release@v2
with:
draft: true
Expand Down Expand Up @@ -180,12 +188,15 @@ jobs:
- name: archive
id: archive
run: |
VERSION=$GITHUB_REF_NAME
VERSION=$LLGO_PACKAGE_VERSION
ARCH=$(./alpine.sh uname -m)
PKGNAME="binaryen-$VERSION-$ARCH-linux"
TARBALL=$PKGNAME.tar.gz
SHASUM=$PKGNAME.tar.gz.sha256
./alpine.sh find install/ -type f -perm -u=x -exec strip {} +
# The container installs as root into the bind-mounted workspace.

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

[P3] Optional: clarify that chown runs inside the container

Nit / optional. The comment reads as if chown runs on the host, but ./alpine.sh is docker exec alpine "$@", so the chown executes inside the container as root — it works because $(id -u):$(id -g) is expanded by the host shell to numeric IDs. A future maintainer might mistakenly rewrite this as a username (e.g. $(whoami)), which would fail since that account doesn't exist in node:lts-alpine. Consider a one-line note that numeric host IDs are intentional and the command runs in the container, e.g.:

# Run chown in the container (as root), targeting the host runner's
# numeric UID:GID so it works even without a matching account in Alpine.

No change required for correctness.

# Give the host runner ownership before it adds LLGo notices and packs.
./alpine.sh chown -R "$(id -u):$(id -g)" install
mv install binaryen-$VERSION
bash scripts/llgo-copy-notices.sh binaryen-$VERSION
tar -czf $TARBALL binaryen-$VERSION
Expand All @@ -194,6 +205,7 @@ jobs:
echo "SHASUM=$SHASUM" >> $GITHUB_OUTPUT

- name: upload tarball
if: github.event_name == 'push'
uses: softprops/action-gh-release@v2
with:
draft: true
Expand Down Expand Up @@ -249,7 +261,7 @@ jobs:
- name: archive
id: archive
run: |
VERSION=$GITHUB_REF_NAME
VERSION=$LLGO_PACKAGE_VERSION
PKGNAME="binaryen-$VERSION-node"
TARBALL=$PKGNAME.tar.gz
SHASUM=$PKGNAME.tar.gz.sha256
Expand All @@ -262,6 +274,7 @@ jobs:
echo "SHASUM=$SHASUM" >> $GITHUB_OUTPUT

- name: upload tarball
if: github.event_name == 'push'
uses: softprops/action-gh-release@v2
with:
draft: true
Expand All @@ -271,6 +284,7 @@ jobs:

publish:
name: publish validated release
if: github.event_name == 'push'
needs: [build, build-alpine, build-node]
runs-on: ubuntu-latest
env:
Expand Down
Loading