ci: workflow_dispatch is a real dry run

- manual runs skip the tag guard (there is no tag on a dispatch, so
  GITHUB_REF_NAME is the branch and the guard always failed) and skip
  publishing
- a dispatch now builds, verifies the digest, smoke-tests the
  extracted toolchain and reports the glibc floor, then stops
- replaces the throwaway-tag rehearsal in the checklist: no tag to
  delete, no draft release to clean up

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
This commit is contained in:
shoney.arickathil 2026-08-25 06:01:26 +02:00
parent c47d91c153
commit 72cd510676
2 changed files with 14 additions and 11 deletions

View file

@ -6,7 +6,9 @@
name: release name: release
# Fires only on a version tag, so nothing is published by an ordinary # Fires only on a version tag, so nothing is published by an ordinary
# push. `workflow_dispatch` is the manual escape hatch for a re-run. # push. `workflow_dispatch` is a DRY RUN: it builds, verifies and reports
# the glibc floor, but skips the tag guard (there is no tag) and skips
# publishing. Use it to rehearse before tagging anything.
on: on:
push: push:
tags: tags:
@ -46,6 +48,7 @@ jobs:
# nobody can install. mkdist.sh already guards VERSION against the # nobody can install. mkdist.sh already guards VERSION against the
# binaries; this guards the tag against VERSION. # binaries; this guards the tag against VERSION.
- name: Tag must match VERSION - name: Tag must match VERSION
if: github.event_name == 'push'
run: | run: |
tag="${GITHUB_REF_NAME#v}" tag="${GITHUB_REF_NAME#v}"
ver="$(cat VERSION)" ver="$(cat VERSION)"
@ -107,7 +110,9 @@ jobs:
# gh is preinstalled on GitHub runners and reads GH_TOKEN from the # gh is preinstalled on GitHub runners and reads GH_TOKEN from the
# environment, so there is no `gh auth login` anywhere in this file. # environment, so there is no `gh auth login` anywhere in this file.
# Skipped on workflow_dispatch: a dry run must never publish.
- name: Publish - name: Publish
if: github.event_name == 'push'
env: env:
GH_TOKEN: ${{ github.token }} GH_TOKEN: ${{ github.token }}
run: | run: |

View file

@ -52,18 +52,16 @@ ignored by this workflow.
publish step later fails with 403, come back and select publish step later fails with 403, come back and select
"Read and write permissions". "Read and write permissions".
5 REHEARSE before a real tag. Add --draft to the gh release create 5 REHEARSE with a dry run — no tag, no publish, no cleanup.
line in .github/workflows/release.yml, commit, push. Actions tab -> "release" -> "Run workflow" -> master.
A workflow_dispatch run skips the tag guard and the publish step,
so it builds, verifies, smoke-tests the extracted tarball and
reports the glibc floor, and stops there.
6 Fire it with a throwaway tag: 6 (nothing to undo — a dry run creates no tag and no release)
git tag -a v0.0.0-test -m "pipeline rehearsal"
git push origin v0.0.0-test
Note: the tag guard compares the tag to VERSION, so this run is
EXPECTED to fail at step "Tag must match VERSION". That is the
cheapest proof the guard works. To rehearse the whole job, set
VERSION to 0.0.0-test on a scratch branch and tag that instead.
7 Watch it: Actions tab, or `gh run watch` once gh is authenticated. 7 Watch it: the Actions tab, or `gh run watch` once gh is
authenticated.
8 Read the "Report the glibc floor" step. It prints what the 8 Read the "Report the glibc floor" step. It prints what the
RUNNER-built binaries actually require. Expect 2.35-ish from RUNNER-built binaries actually require. Expect 2.35-ish from