diff --git a/.github/workflows/release.yml b/.github/workflows/release.yml index 7a18305..a6d8991 100644 --- a/.github/workflows/release.yml +++ b/.github/workflows/release.yml @@ -6,7 +6,9 @@ name: release # Fires only on a version tag, so nothing is published by an ordinary -# push. `workflow_dispatch` is the manual escape hatch for a re-run. +# push. `workflow_dispatch` is a DRY RUN: it builds, verifies and reports +# the glibc floor, but skips the tag guard (there is no tag) and skips +# publishing. Use it to rehearse before tagging anything. on: push: tags: @@ -46,6 +48,7 @@ jobs: # nobody can install. mkdist.sh already guards VERSION against the # binaries; this guards the tag against VERSION. - name: Tag must match VERSION + if: github.event_name == 'push' run: | tag="${GITHUB_REF_NAME#v}" ver="$(cat VERSION)" @@ -107,7 +110,9 @@ jobs: # gh is preinstalled on GitHub runners and reads GH_TOKEN from the # environment, so there is no `gh auth login` anywhere in this file. + # Skipped on workflow_dispatch: a dry run must never publish. - name: Publish + if: github.event_name == 'push' env: GH_TOKEN: ${{ github.token }} run: | diff --git a/docs/guides/releasing.md b/docs/guides/releasing.md index c71583a..c1fa4f2 100644 --- a/docs/guides/releasing.md +++ b/docs/guides/releasing.md @@ -52,18 +52,16 @@ ignored by this workflow. publish step later fails with 403, come back and select "Read and write permissions". - 5 REHEARSE before a real tag. Add --draft to the gh release create - line in .github/workflows/release.yml, commit, push. + 5 REHEARSE with a dry run — no tag, no publish, no cleanup. + Actions tab -> "release" -> "Run workflow" -> master. + A workflow_dispatch run skips the tag guard and the publish step, + so it builds, verifies, smoke-tests the extracted tarball and + reports the glibc floor, and stops there. - 6 Fire it with a throwaway tag: - git tag -a v0.0.0-test -m "pipeline rehearsal" - git push origin v0.0.0-test - Note: the tag guard compares the tag to VERSION, so this run is - EXPECTED to fail at step "Tag must match VERSION". That is the - cheapest proof the guard works. To rehearse the whole job, set - VERSION to 0.0.0-test on a scratch branch and tag that instead. + 6 (nothing to undo — a dry run creates no tag and no release) - 7 Watch it: Actions tab, or `gh run watch` once gh is authenticated. + 7 Watch it: the Actions tab, or `gh run watch` once gh is + authenticated. 8 Read the "Report the glibc floor" step. It prints what the RUNNER-built binaries actually require. Expect 2.35-ish from