diff --git a/.github/workflows/create_release.yml b/.github/workflows/create_release.yml index 2110a06fc22..5157fad809e 100644 --- a/.github/workflows/create_release.yml +++ b/.github/workflows/create_release.yml @@ -1,8 +1,11 @@ name: Create Release -# LLGo releases are cut only from the tested llgo branch. +# Validate release packages on PRs; publish tags only from the tested llgo branch. on: + pull_request: + branches: + - llgo push: tags: - "llgo-v*" @@ -10,6 +13,9 @@ on: permissions: contents: write +env: + LLGO_PACKAGE_VERSION: ${{ github.event_name == 'pull_request' && format('pr-{0}', github.event.pull_request.number) || github.ref_name }} + jobs: verify-source: runs-on: ubuntu-latest @@ -18,6 +24,7 @@ jobs: with: fetch-depth: 0 - name: Require tag at llgo branch tip + if: github.event_name == 'push' run: | git fetch origin llgo test "$(git rev-parse HEAD)" = "$(git rev-parse origin/llgo)" @@ -61,7 +68,7 @@ jobs: - name: cmake (win arm64) # -G "Visual Studio 15 2017" - run: cmake -S . -B out -DCMAKE_INSTALL_PREFIX=out-arm64/install + run: cmake -S . -B out-arm64 -DCMAKE_INSTALL_PREFIX=out-arm64/install if: matrix.os == 'windows-11-arm' - name: build @@ -81,7 +88,7 @@ jobs: run: | # Ignore all but the first component of the os name OSNAME=$(echo ${{ matrix.os }} | sed 's/-.*//') - VERSION=$GITHUB_REF_NAME + VERSION=$LLGO_PACKAGE_VERSION PKGNAME="binaryen-$VERSION-x86_64-$OSNAME" TARBALL=$PKGNAME.tar.gz SHASUM=$PKGNAME.tar.gz.sha256 @@ -100,7 +107,7 @@ jobs: run: | # Ignore all but the first component of the os name OSNAME=$(echo ${{ matrix.os }} | sed 's/-.*//') - VERSION=$GITHUB_REF_NAME + VERSION=$LLGO_PACKAGE_VERSION PKGNAME="binaryen-$VERSION-arm64-$OSNAME" TARBALL=$PKGNAME.tar.gz SHASUM=$PKGNAME.tar.gz.sha256 @@ -115,6 +122,7 @@ jobs: if: ${{ matrix.os == 'macos-14' || matrix.os == 'windows-11-arm' }} - name: upload tarball + if: github.event_name == 'push' uses: softprops/action-gh-release@v2 with: draft: true @@ -180,12 +188,15 @@ jobs: - name: archive id: archive run: | - VERSION=$GITHUB_REF_NAME + VERSION=$LLGO_PACKAGE_VERSION ARCH=$(./alpine.sh uname -m) PKGNAME="binaryen-$VERSION-$ARCH-linux" TARBALL=$PKGNAME.tar.gz SHASUM=$PKGNAME.tar.gz.sha256 ./alpine.sh find install/ -type f -perm -u=x -exec strip {} + + # The container installs as root into the bind-mounted workspace. + # Give the host runner ownership before it adds LLGo notices and packs. + ./alpine.sh chown -R "$(id -u):$(id -g)" install mv install binaryen-$VERSION bash scripts/llgo-copy-notices.sh binaryen-$VERSION tar -czf $TARBALL binaryen-$VERSION @@ -194,6 +205,7 @@ jobs: echo "SHASUM=$SHASUM" >> $GITHUB_OUTPUT - name: upload tarball + if: github.event_name == 'push' uses: softprops/action-gh-release@v2 with: draft: true @@ -249,7 +261,7 @@ jobs: - name: archive id: archive run: | - VERSION=$GITHUB_REF_NAME + VERSION=$LLGO_PACKAGE_VERSION PKGNAME="binaryen-$VERSION-node" TARBALL=$PKGNAME.tar.gz SHASUM=$PKGNAME.tar.gz.sha256 @@ -262,6 +274,7 @@ jobs: echo "SHASUM=$SHASUM" >> $GITHUB_OUTPUT - name: upload tarball + if: github.event_name == 'push' uses: softprops/action-gh-release@v2 with: draft: true @@ -271,6 +284,7 @@ jobs: publish: name: publish validated release + if: github.event_name == 'push' needs: [build, build-alpine, build-node] runs-on: ubuntu-latest env: