ci: workflow_dispatch is a real dry run
- manual runs skip the tag guard (there is no tag on a dispatch, so GITHUB_REF_NAME is the branch and the guard always failed) and skip publishing - a dispatch now builds, verifies the digest, smoke-tests the extracted toolchain and reports the glibc floor, then stops - replaces the throwaway-tag rehearsal in the checklist: no tag to delete, no draft release to clean up Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
This commit is contained in:
parent
c47d91c153
commit
72cd510676
2 changed files with 14 additions and 11 deletions
7
.github/workflows/release.yml
vendored
7
.github/workflows/release.yml
vendored
|
|
@ -6,7 +6,9 @@
|
||||||
name: release
|
name: release
|
||||||
|
|
||||||
# Fires only on a version tag, so nothing is published by an ordinary
|
# Fires only on a version tag, so nothing is published by an ordinary
|
||||||
# push. `workflow_dispatch` is the manual escape hatch for a re-run.
|
# push. `workflow_dispatch` is a DRY RUN: it builds, verifies and reports
|
||||||
|
# the glibc floor, but skips the tag guard (there is no tag) and skips
|
||||||
|
# publishing. Use it to rehearse before tagging anything.
|
||||||
on:
|
on:
|
||||||
push:
|
push:
|
||||||
tags:
|
tags:
|
||||||
|
|
@ -46,6 +48,7 @@ jobs:
|
||||||
# nobody can install. mkdist.sh already guards VERSION against the
|
# nobody can install. mkdist.sh already guards VERSION against the
|
||||||
# binaries; this guards the tag against VERSION.
|
# binaries; this guards the tag against VERSION.
|
||||||
- name: Tag must match VERSION
|
- name: Tag must match VERSION
|
||||||
|
if: github.event_name == 'push'
|
||||||
run: |
|
run: |
|
||||||
tag="${GITHUB_REF_NAME#v}"
|
tag="${GITHUB_REF_NAME#v}"
|
||||||
ver="$(cat VERSION)"
|
ver="$(cat VERSION)"
|
||||||
|
|
@ -107,7 +110,9 @@ jobs:
|
||||||
|
|
||||||
# gh is preinstalled on GitHub runners and reads GH_TOKEN from the
|
# gh is preinstalled on GitHub runners and reads GH_TOKEN from the
|
||||||
# environment, so there is no `gh auth login` anywhere in this file.
|
# environment, so there is no `gh auth login` anywhere in this file.
|
||||||
|
# Skipped on workflow_dispatch: a dry run must never publish.
|
||||||
- name: Publish
|
- name: Publish
|
||||||
|
if: github.event_name == 'push'
|
||||||
env:
|
env:
|
||||||
GH_TOKEN: ${{ github.token }}
|
GH_TOKEN: ${{ github.token }}
|
||||||
run: |
|
run: |
|
||||||
|
|
|
||||||
|
|
@ -52,18 +52,16 @@ ignored by this workflow.
|
||||||
publish step later fails with 403, come back and select
|
publish step later fails with 403, come back and select
|
||||||
"Read and write permissions".
|
"Read and write permissions".
|
||||||
|
|
||||||
5 REHEARSE before a real tag. Add --draft to the gh release create
|
5 REHEARSE with a dry run — no tag, no publish, no cleanup.
|
||||||
line in .github/workflows/release.yml, commit, push.
|
Actions tab -> "release" -> "Run workflow" -> master.
|
||||||
|
A workflow_dispatch run skips the tag guard and the publish step,
|
||||||
|
so it builds, verifies, smoke-tests the extracted tarball and
|
||||||
|
reports the glibc floor, and stops there.
|
||||||
|
|
||||||
6 Fire it with a throwaway tag:
|
6 (nothing to undo — a dry run creates no tag and no release)
|
||||||
git tag -a v0.0.0-test -m "pipeline rehearsal"
|
|
||||||
git push origin v0.0.0-test
|
|
||||||
Note: the tag guard compares the tag to VERSION, so this run is
|
|
||||||
EXPECTED to fail at step "Tag must match VERSION". That is the
|
|
||||||
cheapest proof the guard works. To rehearse the whole job, set
|
|
||||||
VERSION to 0.0.0-test on a scratch branch and tag that instead.
|
|
||||||
|
|
||||||
7 Watch it: Actions tab, or `gh run watch` once gh is authenticated.
|
7 Watch it: the Actions tab, or `gh run watch` once gh is
|
||||||
|
authenticated.
|
||||||
|
|
||||||
8 Read the "Report the glibc floor" step. It prints what the
|
8 Read the "Report the glibc floor" step. It prints what the
|
||||||
RUNNER-built binaries actually require. Expect 2.35-ish from
|
RUNNER-built binaries actually require. Expect 2.35-ish from
|
||||||
|
|
|
||||||
Loading…
Reference in a new issue