Commit graph

4 commits

Author SHA1 Message Date
3f9ce2bf32 fix(ci): do not pin dune — use whatever setup-ocaml provides
Some checks are pending
release / release (push) Waiting to run
The pinned `opam install dune.3.14.0` failed. setup-ocaml installs a
dune of its own for caching, so requesting an exact older version is a
downgrade the solver refuses — which also means run 1's
`dune: command not found` was only ever a PATH problem, fixed by
`opam exec --`.

- probe with `opam exec -- dune --version`, install only if absent
- echo the resolved version so the log says what built the release
- any dune >= 3.14 satisfies `(lang dune 3.14)`

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
2026-08-25 07:39:51 +02:00
4f89d42948 fix(ci): install dune and build inside the opam env
First run failed with `dune: command not found`.

- ocaml/setup-ocaml provides a compiler and opam, not dune. dune is an
  ordinary opam package and this project has no .opam file for the
  action to infer one from, so nothing pulled it in
- add `opam install -y dune.3.14.0`, pinned to the version
  compiler/dune-project targets (`(lang dune 3.14)`)
- run the build as `opam exec -- ./scripts/mkdist.sh`: the script calls
  dune internally, so it needs the opam environment on PATH

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
2026-08-25 07:17:59 +02:00
72cd510676 ci: workflow_dispatch is a real dry run
- manual runs skip the tag guard (there is no tag on a dispatch, so
  GITHUB_REF_NAME is the branch and the guard always failed) and skip
  publishing
- a dispatch now builds, verifies the digest, smoke-tests the
  extracted toolchain and reports the glibc floor, then stops
- replaces the throwaway-tag rehearsal in the checklist: no tag to
  delete, no draft release to clean up

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
2026-08-25 06:01:26 +02:00
463f897e5f ci: release workflow — no gh auth login, tag-triggered
- .github/workflows/release.yml: builds, verifies and publishes on a
  `v*` tag. `permissions: contents: write` on the injected
  GITHUB_TOKEN replaces `gh auth login`; no PAT, nothing to rotate
- runs-on ubuntu-22.04 DELIBERATELY: the build host's glibc caps which
  symbol versions the binaries import, and that cap is the floor every
  user needs. 22.04 (2.35) includes Ubuntu 22.04 / Debian 12 / RHEL 9;
  24.04 (2.39) would exclude them
- guards that fail instead of publishing: tag vs VERSION, produced
  asset name vs the filename /install links, sha256, and a smoke test
  that builds a hello project with the binaries INSIDE the tarball
- reports the shipped glibc floor so the claim on /install is checkable
  from a build log
- releasing.md: pipeline route up front, manual route kept; GH_TOKEN
  recipe for non-GitHub CI

Not run — this repo has no CI history and Actions cannot execute
locally. Every guard's shell was dry-run here against the real dist.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
2026-08-25 04:58:40 +02:00