feat: preflight as a release asset - download, verify, unpack, then run the tree preflight (#151, C)
CI / verify (push) Successful in 2m26s
CI / pwsh (push) Failing after 11s
Release / release (push) Successful in 37s

Files changed:
- .gitea/workflows/release.yml
- CHANGES.md
- INSTALL.md
- README.md
- VERSION
- instructions/dev/testing-conventions.md
- instructions/preflight.md
- tools/CONTRACT.md
- tools/README.md
- tools/chemenu/tests/test_preflight.py
- tools/chemenu/tests/test_preflight_pwsh.py
- tools/preflight.ps1
- tools/preflight.sh
This commit is contained in:
torben committed 2026-10-01 13:39:56 +02:00
1 parent 210e0c8286
commit c33e8cdfb1
13 files changed
+1020 -88

No files matched your search

+26 -2
View File
@@ -3,7 +3,9 @@
# The release artifact is exactly a `dist export` tree, packed with a top-level
# directory: unpack it, run instructions/setup-instance.md, and there is a
# working wiki instance - no checkout of this repo required. CI already proved
# that path works before this workflow ever runs.
# that path works before this workflow ever runs. Beside it the release carries
# tools/preflight.sh and tools/preflight.ps1 as assets, which download and unpack
# that tarball themselves.
#
# The tag is created here, by CI, and never by an agent: AGENTS.md invariant 5
# ("never call raw git commit/push") stays intact because nothing in a session
@@ -149,6 +151,28 @@ jobs:
cat "${BUILD_DIR}/${name}.tar.gz.sha256"
echo "name=${name}" >> "$GITHUB_OUTPUT"
# The two preflight scripts are attached to the release as well: the first
# thing a new user runs, before there is any tree to run it from. Each copy
# is the tree's script with the download address of *this* release written
# into its two placeholder lines (the tree copy keeps them empty, which is
# how a script knows it is not a release asset). The address is the public
# one, for the same reason as the URLs in `dist export` above.
download="${PUBLIC_BASE_URL}/${GITHUB_REPOSITORY}/releases/download/${TAG}"
sed \
-e "s|^RELEASE_ARCHIVE_URL=''|RELEASE_ARCHIVE_URL='${download}/${name}.tar.gz'|" \
-e "s|^RELEASE_CHECKSUM_URL=''|RELEASE_CHECKSUM_URL='${download}/${name}.tar.gz.sha256'|" \
tools/preflight.sh > "${BUILD_DIR}/preflight.sh"
sed \
-e "s|^\$ReleaseArchiveUrl = ''|\$ReleaseArchiveUrl = '${download}/${name}.tar.gz'|" \
-e "s|^\$ReleaseChecksumUrl = ''|\$ReleaseChecksumUrl = '${download}/${name}.tar.gz.sha256'|" \
tools/preflight.ps1 > "${BUILD_DIR}/preflight.ps1"
# A placeholder that did not match would ship a script that refuses to run.
grep -qF "RELEASE_ARCHIVE_URL='${download}/${name}.tar.gz'" "${BUILD_DIR}/preflight.sh"
grep -qF "RELEASE_CHECKSUM_URL='${download}/${name}.tar.gz.sha256'" "${BUILD_DIR}/preflight.sh"
grep -qF "ReleaseArchiveUrl = '${download}/${name}.tar.gz'" "${BUILD_DIR}/preflight.ps1"
grep -qF "ReleaseChecksumUrl = '${download}/${name}.tar.gz.sha256'" "${BUILD_DIR}/preflight.ps1"
chmod +x "${BUILD_DIR}/preflight.sh"
- name: Publish the release
if: steps.version.outputs.skip != 'true'
env:
@@ -174,7 +198,7 @@ jobs:
id="$(printf '%s' "$release" | jq -r '.id')"
echo "Created release ${TAG} (id ${id})."
for asset in "${NAME}.tar.gz" "${NAME}.tar.gz.sha256"; do
for asset in "${NAME}.tar.gz" "${NAME}.tar.gz.sha256" preflight.sh preflight.ps1; do
curl -sS -f -X POST "${API}/releases/${id}/assets?name=${asset}" \
-H "Authorization: token ${TOKEN}" \
-F "attachment=@${BUILD_DIR}/${asset}" > /dev/null