Files
Modrinth-Enhanced/.github/workflows/upstream-release.yml
T

256 lines
9.2 KiB
YAML

name: Upstream release
# Watches Modrinth for a new Modrinth App release, rebuilds Modrinth Enhanced
# on top of it, and publishes a release of our own if everything still works.
# When the patches changed since our last release of that upstream version,
# it publishes them again as a revision: v1.2.3-2, v1.2.3-3, ...
#
# Nothing is published unless the patches applied, the checks passed and all
# three platforms built, so an upstream change that breaks a patch stops here
# and reports a failure instead of shipping a broken build.
on:
schedule:
- cron: '17 6 * * *'
workflow_dispatch:
inputs:
upstream-ref:
description: Build this upstream tag instead of the newest one
type: string
required: false
permissions:
contents: write
concurrency:
group: upstream-release
cancel-in-progress: false
jobs:
detect:
name: Detect
runs-on: ubuntu-latest
outputs:
upstream: ${{ steps.check.outputs.upstream }}
tag: ${{ steps.check.outputs.tag }}
revision: ${{ steps.check.outputs.revision }}
proceed: ${{ steps.check.outputs.proceed }}
steps:
- uses: actions/checkout@v4
- name: Decide what to release
id: check
env:
REQUESTED: ${{ inputs.upstream-ref }}
run: |
set -euo pipefail
current="$(tr -d '[:space:]' < upstream.txt)"
upstream="${REQUESTED:-$(scripts/latest-upstream.sh)}"
echo "upstream=$upstream" >> "$GITHUB_OUTPUT"
echo "Upstream release: $upstream (we are on $current)"
# Our newest release of it, as "<revision> <tag>". The plain tag is
# revision 1.
last="$(
git ls-remote --tags --refs origin "$upstream" "$upstream-*" |
sed 's#.*refs/tags/##' |
awk -v up="$upstream" '
$0 == up { print 1, $0; next }
index($0, up "-") == 1 {
n = substr($0, length(up) + 2)
if (n ~ /^[0-9]+$/) print n, $0
}' |
sort -n |
tail -1
)"
if [ -z "$last" ]; then
revision=1
tag="$upstream"
else
last_tag="${last#* }"
git fetch --no-tags --depth=1 origin "refs/tags/$last_tag:refs/tags/$last_tag"
# Only what goes into the build counts, not docs or CI.
if git diff --quiet "$last_tag" HEAD -- patches scripts updater.pub; then
echo "$last_tag already ships the current patches; nothing to do."
echo "proceed=false" >> "$GITHUB_OUTPUT"
exit 0
fi
revision="$(( ${last%% *} + 1 ))"
tag="$upstream-$revision"
fi
echo "revision=$revision" >> "$GITHUB_OUTPUT"
echo "tag=$tag" >> "$GITHUB_OUTPUT"
echo "proceed=true" >> "$GITHUB_OUTPUT"
echo "Releasing $tag"
build:
name: Build
needs: detect
if: needs.detect.outputs.proceed == 'true'
uses: ./.github/workflows/build.yml
with:
upstream-ref: ${{ needs.detect.outputs.upstream }}
revision: ${{ needs.detect.outputs.revision }}
secrets: inherit
release:
name: Release
needs: [detect, build]
runs-on: ubuntu-latest
steps:
# The whole history: the release notes are the commits since the last one.
- uses: actions/checkout@v4
with:
fetch-depth: 0
- name: Record the upstream release we build against
env:
UPSTREAM: ${{ needs.detect.outputs.upstream }}
run: |
set -euo pipefail
printf '%s\n' "$UPSTREAM" > upstream.txt
if git diff --quiet -- upstream.txt; then
echo "upstream.txt already points at $UPSTREAM"
exit 0
fi
git config user.name 'github-actions[bot]'
git config user.email '41898282+github-actions[bot]@users.noreply.github.com'
git commit -m "Track upstream $UPSTREAM" -- upstream.txt
git push origin HEAD:${{ github.event.repository.default_branch }}
- name: Download installers
uses: actions/download-artifact@v4
with:
path: artifacts
merge-multiple: true
# The app looks for updates in releases/latest/download/latest.json.
# Spaces in asset names become dots first, as GitHub would make them, so
# the addresses written into it are exact. A release without signatures
# stops here: every install it reached could never update again.
- name: Write the update manifest
env:
TAG: ${{ needs.detect.outputs.tag }}
UPSTREAM: ${{ needs.detect.outputs.upstream }}
REVISION: ${{ needs.detect.outputs.revision }}
run: |
set -euo pipefail
for file in artifacts/*' '*; do
if [ -e "$file" ]; then mv "$file" "${file// /.}"; fi
done
python3 - <<'EOF'
import datetime, json, os, pathlib
artifacts = pathlib.Path("artifacts")
tag = os.environ["TAG"]
repository = os.environ["GITHUB_REPOSITORY"]
# The app's version is the upstream one. A revision comes along as
# build metadata, which the app compares itself.
version = os.environ["UPSTREAM"].removeprefix("v")
if int(os.environ["REVISION"]) > 1:
version += "+" + os.environ["REVISION"]
def signed(suffix):
matches = [p for p in artifacts.iterdir() if p.name.endswith(suffix)]
if len(matches) != 1:
raise SystemExit(f"Expected one *{suffix}, found {[p.name for p in matches]}")
signature = pathlib.Path(f"{matches[0]}.sig")
if not signature.is_file():
raise SystemExit(f"{matches[0].name} is not signed: is TAURI_SIGNING_PRIVATE_KEY set?")
return {
"signature": signature.read_text().strip(),
"url": f"https://github.com/{repository}/releases/download/{tag}/{matches[0].name}",
}
macos = signed(".app.tar.gz")
manifest = {
"version": version,
"notes": f"Modrinth Enhanced {tag}",
"pub_date": datetime.datetime.now(datetime.timezone.utc).strftime("%Y-%m-%dT%H:%M:%SZ"),
"platforms": {
"linux-x86_64": signed(".AppImage"),
"windows-x86_64": signed("-setup.exe"),
"darwin-x86_64": macos,
"darwin-aarch64": macos,
},
}
(artifacts / "latest.json").write_text(json.dumps(manifest, indent=2) + "\n")
print((artifacts / "latest.json").read_text())
EOF
- name: Publish the release
env:
GH_TOKEN: ${{ github.token }}
TAG: ${{ needs.detect.outputs.tag }}
UPSTREAM: ${{ needs.detect.outputs.upstream }}
run: |
set -euo pipefail
ls -la artifacts
# Every patch by its subject, so the list never falls behind.
patches="$(
for patch in patches/0*.patch; do
awk '/^Subject: /{
s = $0
sub(/^Subject: (\[PATCH[^]]*\] )?/, "", s)
while ((getline line) > 0 && line ~ /^ /) s = s line
print "- " s
exit
}' "$patch"
done
)"
patch_count="$(printf '%s\n' "$patches" | grep -c '^- ' || true)"
# What changed here since the last release, as its commit subjects.
# The bump of upstream.txt is left out: the line above already says
# which Modrinth App this is built from.
previous="$(gh release view --json tagName --jq .tagName 2>/dev/null || true)"
changes=""
if [ -n "$previous" ]; then
changes="$(
git log --reverse --no-merges --pretty='- %s' "$previous..HEAD" |
grep -v '^- Track upstream ' || true
)"
fi
if [ -z "$changes" ]; then
changes="- Rebuilt on Modrinth App $UPSTREAM, with the patches unchanged."
fi
if [ -n "$previous" ]; then
changes="$changes
[Everything since $previous](https://github.com/$GITHUB_REPOSITORY/compare/$previous...$TAG)"
fi
notes="$(cat <<EOF
Modrinth Enhanced $TAG, built from [Modrinth App $UPSTREAM](https://github.com/modrinth/code/releases/tag/$UPSTREAM).
## What changed
$changes
Modrinth's own changes are in the [Modrinth App $UPSTREAM release notes](https://github.com/modrinth/code/releases/tag/$UPSTREAM).
<details>
<summary>The $patch_count patches in this build</summary>
$patches
</details>
It keeps using the same data directory as the official Modrinth App,
so instances, settings and accounts carry over. Do not run both at
the same time.
EOF
)"
# The tag goes on the commit that was built, not on whatever main is
# by now, so the next run compares against the patches it shipped.
gh release create "$TAG" \
--target "$(git rev-parse HEAD)" \
--title "Modrinth Enhanced $TAG" \
--notes "$notes" \
artifacts/*