296 lines
10 KiB
YAML
296 lines
10 KiB
YAML
name: release
|
|
|
|
on:
|
|
push:
|
|
tags: ['v*']
|
|
workflow_dispatch:
|
|
inputs:
|
|
dry_run:
|
|
description: >-
|
|
Build the repositories with a throwaway key and install from them,
|
|
without publishing anything.
|
|
type: boolean
|
|
default: false
|
|
|
|
permissions:
|
|
contents: write
|
|
|
|
jobs:
|
|
deb:
|
|
name: Debian package (${{ matrix.name }})
|
|
runs-on: ubuntu-latest
|
|
# The package depends on the exact Qt it was built against, so each
|
|
# distribution gets a build and an APT repository of its own.
|
|
strategy:
|
|
matrix:
|
|
include:
|
|
# Plasma 6 arrived in Debian with trixie.
|
|
- name: Debian 13
|
|
image: debian:trixie
|
|
codename: trixie
|
|
suffix: "~deb13"
|
|
- name: Kubuntu 26.04
|
|
image: ubuntu:26.04
|
|
codename: resolute
|
|
suffix: "~ubuntu26.04"
|
|
container: ${{ matrix.image }}
|
|
env:
|
|
DEBIAN_FRONTEND: noninteractive
|
|
steps:
|
|
- name: Install the build tools
|
|
run: |
|
|
apt-get update -qq
|
|
# Older Qt has the Wayland client tools in a package of their own.
|
|
extra=""
|
|
[ -n "$(apt-cache madison qt6-wayland-dev-tools)" ] && extra="qt6-wayland-dev-tools"
|
|
apt-get install -y --no-install-recommends \
|
|
ca-certificates curl git make cmake g++ pkg-config gettext scdoc dpkg-dev \
|
|
qt6-base-dev qt6-base-dev-tools qt6-base-private-dev qt6-declarative-dev \
|
|
qt6-wayland-dev qt6-wayland-private-dev $extra \
|
|
liblayershellqtinterface-dev libkf6i18n-dev \
|
|
libopencv-dev libpam0g-dev libsystemd-dev
|
|
|
|
- uses: actions/checkout@v7
|
|
|
|
- name: Check the tag against the Makefile
|
|
run: packaging/check-version.sh "${{ github.ref_name }}"
|
|
|
|
- name: Check CHANGELOG.md has this release
|
|
if: startsWith(github.ref, 'refs/tags/v')
|
|
run: .github/release-notes.sh --title "${{ github.ref_name }}"
|
|
|
|
- run: packaging/build-deb.sh
|
|
env:
|
|
DEB_SUFFIX: ${{ matrix.suffix }}
|
|
|
|
- name: Look inside what was built
|
|
run: |
|
|
dpkg-deb --info dist/*.deb
|
|
dpkg-deb --contents dist/*.deb
|
|
|
|
- uses: actions/upload-artifact@v7
|
|
with:
|
|
name: deb-${{ matrix.codename }}
|
|
path: dist/*.deb
|
|
if-no-files-found: error
|
|
|
|
rpm:
|
|
name: RPM package
|
|
runs-on: ubuntu-latest
|
|
container: fedora:latest
|
|
steps:
|
|
- name: Install the build tools
|
|
run: |
|
|
dnf install -y --setopt=install_weak_deps=False \
|
|
git make cmake gcc-c++ gettext scdoc tar curl rpm-build rpm-sign systemd-rpm-macros \
|
|
'pkgconfig(systemd)' 'pkgconfig(libsystemd)' pam-devel opencv-devel \
|
|
qt6-qtbase-devel qt6-qtbase-private-devel qt6-qtdeclarative-devel qt6-qtwayland-devel \
|
|
layer-shell-qt-devel kf6-ki18n-devel
|
|
|
|
- uses: actions/checkout@v7
|
|
|
|
- name: Check the tag against the Makefile
|
|
run: packaging/check-version.sh "${{ github.ref_name }}"
|
|
|
|
- run: packaging/build-rpm.sh
|
|
|
|
- name: Sign the package
|
|
env:
|
|
GPG_PRIVATE_KEY: ${{ secrets.GPG_PRIVATE_KEY }}
|
|
DRY_RUN: ${{ inputs.dry_run }}
|
|
run: |
|
|
if [ "$DRY_RUN" = "true" ]; then
|
|
gpg --batch --passphrase '' --quick-generate-key \
|
|
'dry run <dry-run@example.invalid>' rsa2048 sign never
|
|
elif [ -n "${GPG_PRIVATE_KEY:-}" ]; then
|
|
printf '%s' "$GPG_PRIVATE_KEY" | gpg --batch --import
|
|
else
|
|
echo "No GPG_PRIVATE_KEY secret; leaving the package unsigned."
|
|
exit 0
|
|
fi
|
|
keyid="$(gpg --list-secret-keys --with-colons | awk -F: '/^sec:/ { print $5; exit }')"
|
|
rpmsign --define "_gpg_name $keyid" --addsign dist/*.rpm
|
|
gpg --armor --export "$keyid" > dist/rpm-signer.asc
|
|
rpm --import dist/rpm-signer.asc
|
|
rpm --checksig dist/*.rpm
|
|
|
|
- name: Look inside what was built
|
|
run: |
|
|
rpm -qip dist/plasma-face-unlock-[0-9]*.rpm
|
|
rpm -qlp dist/plasma-face-unlock-[0-9]*.rpm
|
|
|
|
- uses: actions/upload-artifact@v7
|
|
with:
|
|
name: rpm
|
|
path: |
|
|
dist/*.rpm
|
|
dist/rpm-signer.asc
|
|
if-no-files-found: error
|
|
|
|
publish:
|
|
name: Release and repositories
|
|
needs: [deb, rpm]
|
|
if: startsWith(github.ref, 'refs/tags/v') || inputs.dry_run
|
|
runs-on: ubuntu-latest
|
|
steps:
|
|
- uses: actions/checkout@v7
|
|
with:
|
|
# All tags, for the link to the changes since the last release.
|
|
fetch-depth: 0
|
|
|
|
- uses: actions/download-artifact@v8
|
|
with:
|
|
path: incoming
|
|
merge-multiple: true
|
|
|
|
- name: Attach the packages to the release
|
|
if: ${{ !inputs.dry_run }}
|
|
env:
|
|
GH_TOKEN: ${{ github.token }}
|
|
run: |
|
|
.github/release-notes.sh "${{ github.ref_name }}" > notes.md
|
|
gh release create "${{ github.ref_name }}" \
|
|
--title "$(.github/release-notes.sh --title "${{ github.ref_name }}")" \
|
|
--notes-file notes.md \
|
|
incoming/*.deb incoming/*.rpm \
|
|
|| gh release upload "${{ github.ref_name }}" \
|
|
incoming/*.deb incoming/*.rpm --clobber
|
|
|
|
- name: Install the repository tools
|
|
run: |
|
|
sudo apt-get update -qq
|
|
sudo apt-get install -y --no-install-recommends \
|
|
dpkg-dev apt-utils createrepo-c
|
|
|
|
- name: Get a signing key
|
|
id: key
|
|
env:
|
|
GPG_PRIVATE_KEY: ${{ secrets.GPG_PRIVATE_KEY }}
|
|
DRY_RUN: ${{ inputs.dry_run }}
|
|
run: |
|
|
if [ "$DRY_RUN" = "true" ]; then
|
|
gpg --batch --passphrase '' --quick-generate-key \
|
|
'dry run <dry-run@example.invalid>' rsa2048 sign never
|
|
elif [ -n "${GPG_PRIVATE_KEY:-}" ]; then
|
|
printf '%s' "$GPG_PRIVATE_KEY" | gpg --batch --import
|
|
else
|
|
echo "present=no" >> "$GITHUB_OUTPUT"
|
|
echo "::warning::No GPG_PRIVATE_KEY secret, so the apt and dnf repositories were not updated. The packages are on the release."
|
|
exit 0
|
|
fi
|
|
echo "present=yes" >> "$GITHUB_OUTPUT"
|
|
|
|
- name: Check out the published repositories
|
|
if: steps.key.outputs.present == 'yes' && !inputs.dry_run
|
|
uses: actions/checkout@v7
|
|
with:
|
|
ref: gh-pages
|
|
path: pages
|
|
continue-on-error: true
|
|
|
|
- name: Update the repositories
|
|
if: steps.key.outputs.present == 'yes'
|
|
run: |
|
|
if [ ! -d pages/.git ]; then
|
|
rm -rf pages && mkdir pages
|
|
git -C pages init -q -b gh-pages
|
|
git -C pages remote add origin "https://github.com/${{ github.repository }}.git"
|
|
fi
|
|
rm -f incoming/rpm-signer.asc
|
|
packaging/publish-repos.sh pages incoming
|
|
|
|
- name: Check that what was written can be verified
|
|
if: steps.key.outputs.present == 'yes'
|
|
run: |
|
|
for suite in pages/deb/*/; do
|
|
gpg --verify "$suite/InRelease"
|
|
gpg --verify "$suite/Release.gpg" "$suite/Release"
|
|
done
|
|
gpg --verify pages/rpm/repodata/repomd.xml.asc pages/rpm/repodata/repomd.xml
|
|
|
|
- uses: actions/upload-artifact@v7
|
|
if: inputs.dry_run
|
|
with:
|
|
name: pages
|
|
path: pages
|
|
include-hidden-files: true
|
|
|
|
- name: Push them
|
|
if: steps.key.outputs.present == 'yes' && !inputs.dry_run
|
|
env:
|
|
GH_TOKEN: ${{ github.token }}
|
|
run: |
|
|
cd pages
|
|
git config user.name "github-actions[bot]"
|
|
git config user.email "41898282+github-actions[bot]@users.noreply.github.com"
|
|
git add -A
|
|
git diff --quiet --cached && { echo "nothing changed"; exit 0; }
|
|
git commit -q -m "Publish ${{ github.ref_name }}"
|
|
git push "https://x-access-token:${GH_TOKEN}@github.com/${{ github.repository }}.git" HEAD:gh-pages
|
|
|
|
verify-apt:
|
|
name: Install from the APT repository (${{ matrix.name }})
|
|
needs: publish
|
|
if: inputs.dry_run
|
|
runs-on: ubuntu-latest
|
|
strategy:
|
|
matrix:
|
|
include:
|
|
- name: Debian 13
|
|
image: debian:trixie
|
|
codename: trixie
|
|
- name: Kubuntu 26.04
|
|
image: ubuntu:26.04
|
|
codename: resolute
|
|
container: ${{ matrix.image }}
|
|
env:
|
|
DEBIAN_FRONTEND: noninteractive
|
|
steps:
|
|
- uses: actions/download-artifact@v8
|
|
with:
|
|
name: pages
|
|
path: pages
|
|
- name: Install from the repository that was just built
|
|
run: |
|
|
apt-get update -qq && apt-get install -y --no-install-recommends gpg
|
|
install -d -m 0755 /etc/apt/keyrings
|
|
gpg --dearmor -o /etc/apt/keyrings/plasma-face-unlock.gpg < pages/KEY.gpg
|
|
echo "deb [signed-by=/etc/apt/keyrings/plasma-face-unlock.gpg] file://$PWD/pages/deb/${{ matrix.codename }} ./" \
|
|
> /etc/apt/sources.list.d/plasma-face-unlock.list
|
|
apt-get update
|
|
apt-get install -y plasma-face-unlock
|
|
useradd -m tester
|
|
runuser -u tester -- plasma-face-unlock --version
|
|
|
|
verify-dnf:
|
|
name: Install from the RPM repository
|
|
needs: publish
|
|
if: inputs.dry_run
|
|
runs-on: ubuntu-latest
|
|
container: fedora:latest
|
|
steps:
|
|
- uses: actions/download-artifact@v8
|
|
with:
|
|
name: pages
|
|
path: pages
|
|
- uses: actions/download-artifact@v8
|
|
with:
|
|
name: rpm
|
|
path: signer
|
|
- name: Install from the repository that was just built
|
|
run: |
|
|
rpm --import pages/KEY.gpg
|
|
rpm --import signer/rpm-signer.asc
|
|
cat > /etc/yum.repos.d/plasma-face-unlock.repo <<EOF
|
|
[plasma-face-unlock]
|
|
name=plasma-face-unlock
|
|
baseurl=file://$PWD/pages/rpm
|
|
enabled=1
|
|
gpgcheck=1
|
|
repo_gpgcheck=1
|
|
gpgkey=file://$PWD/pages/KEY.gpg
|
|
EOF
|
|
dnf install -y plasma-face-unlock util-linux
|
|
useradd -m tester
|
|
runuser -u tester -- plasma-face-unlock --version
|