ci: workflow_dispatch is a real dry run

- manual runs skip the tag guard (there is no tag on a dispatch, so
  GITHUB_REF_NAME is the branch and the guard always failed) and skip
  publishing
- a dispatch now builds, verifies the digest, smoke-tests the
  extracted toolchain and reports the glibc floor, then stops
- replaces the throwaway-tag rehearsal in the checklist: no tag to
  delete, no draft release to clean up

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
This commit is contained in:
shoney.arickathil 2026-08-25 06:01:26 +02:00
parent 11f7995a31
commit e101341f0f
2 changed files with 14 additions and 11 deletions

View file

@ -6,7 +6,9 @@
name: release
# Fires only on a version tag, so nothing is published by an ordinary
# push. `workflow_dispatch` is the manual escape hatch for a re-run.
# push. `workflow_dispatch` is a DRY RUN: it builds, verifies and reports
# the glibc floor, but skips the tag guard (there is no tag) and skips
# publishing. Use it to rehearse before tagging anything.
on:
push:
tags:
@ -46,6 +48,7 @@ jobs:
# nobody can install. mkdist.sh already guards VERSION against the
# binaries; this guards the tag against VERSION.
- name: Tag must match VERSION
if: github.event_name == 'push'
run: |
tag="${GITHUB_REF_NAME#v}"
ver="$(cat VERSION)"
@ -107,7 +110,9 @@ jobs:
# gh is preinstalled on GitHub runners and reads GH_TOKEN from the
# environment, so there is no `gh auth login` anywhere in this file.
# Skipped on workflow_dispatch: a dry run must never publish.
- name: Publish
if: github.event_name == 'push'
env:
GH_TOKEN: ${{ github.token }}
run: |

View file

@ -52,18 +52,16 @@ ignored by this workflow.
publish step later fails with 403, come back and select
"Read and write permissions".
5 REHEARSE before a real tag. Add --draft to the gh release create
line in .github/workflows/release.yml, commit, push.
5 REHEARSE with a dry run — no tag, no publish, no cleanup.
Actions tab -> "release" -> "Run workflow" -> master.
A workflow_dispatch run skips the tag guard and the publish step,
so it builds, verifies, smoke-tests the extracted tarball and
reports the glibc floor, and stops there.
6 Fire it with a throwaway tag:
git tag -a v0.0.0-test -m "pipeline rehearsal"
git push origin v0.0.0-test
Note: the tag guard compares the tag to VERSION, so this run is
EXPECTED to fail at step "Tag must match VERSION". That is the
cheapest proof the guard works. To rehearse the whole job, set
VERSION to 0.0.0-test on a scratch branch and tag that instead.
6 (nothing to undo — a dry run creates no tag and no release)
7 Watch it: Actions tab, or `gh run watch` once gh is authenticated.
7 Watch it: the Actions tab, or `gh run watch` once gh is
authenticated.
8 Read the "Report the glibc floor" step. It prints what the
RUNNER-built binaries actually require. Expect 2.35-ish from