From d022c0934583e66f0069f978be24abdd34c5d2ed Mon Sep 17 00:00:00 2001 From: Li Jie Date: Wed, 23 Sep 2026 20:40:44 +0800 Subject: [PATCH 1/3] ci: restore host ownership before packaging Alpine releases --- .github/workflows/create_release.yml | 3 +++ 1 file changed, 3 insertions(+) diff --git a/.github/workflows/create_release.yml b/.github/workflows/create_release.yml index 2110a06fc22..f94df736f0d 100644 --- a/.github/workflows/create_release.yml +++ b/.github/workflows/create_release.yml @@ -186,6 +186,9 @@ jobs: TARBALL=$PKGNAME.tar.gz SHASUM=$PKGNAME.tar.gz.sha256 ./alpine.sh find install/ -type f -perm -u=x -exec strip {} + + # The container installs as root into the bind-mounted workspace. + # Give the host runner ownership before it adds LLGo notices and packs. + ./alpine.sh chown -R "$(id -u):$(id -g)" install mv install binaryen-$VERSION bash scripts/llgo-copy-notices.sh binaryen-$VERSION tar -czf $TARBALL binaryen-$VERSION From 699b2c43e48393fc7d87b0eb2743a60af69a09aa Mon Sep 17 00:00:00 2001 From: Li Jie Date: Wed, 23 Sep 2026 20:49:11 +0800 Subject: [PATCH 2/3] ci: configure Windows ARM64 in its build directory --- .github/workflows/create_release.yml | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/.github/workflows/create_release.yml b/.github/workflows/create_release.yml index f94df736f0d..30bdaa598a4 100644 --- a/.github/workflows/create_release.yml +++ b/.github/workflows/create_release.yml @@ -61,7 +61,7 @@ jobs: - name: cmake (win arm64) # -G "Visual Studio 15 2017" - run: cmake -S . -B out -DCMAKE_INSTALL_PREFIX=out-arm64/install + run: cmake -S . -B out-arm64 -DCMAKE_INSTALL_PREFIX=out-arm64/install if: matrix.os == 'windows-11-arm' - name: build From abdfed959393c0b6626f1c05641c21326a9c6d72 Mon Sep 17 00:00:00 2001 From: Li Jie Date: Wed, 23 Sep 2026 21:16:23 +0800 Subject: [PATCH 3/3] Run release packaging on llgo pull requests --- .github/workflows/create_release.yml | 21 ++++++++++++++++----- 1 file changed, 16 insertions(+), 5 deletions(-) diff --git a/.github/workflows/create_release.yml b/.github/workflows/create_release.yml index 30bdaa598a4..5157fad809e 100644 --- a/.github/workflows/create_release.yml +++ b/.github/workflows/create_release.yml @@ -1,8 +1,11 @@ name: Create Release -# LLGo releases are cut only from the tested llgo branch. +# Validate release packages on PRs; publish tags only from the tested llgo branch. on: + pull_request: + branches: + - llgo push: tags: - "llgo-v*" @@ -10,6 +13,9 @@ on: permissions: contents: write +env: + LLGO_PACKAGE_VERSION: ${{ github.event_name == 'pull_request' && format('pr-{0}', github.event.pull_request.number) || github.ref_name }} + jobs: verify-source: runs-on: ubuntu-latest @@ -18,6 +24,7 @@ jobs: with: fetch-depth: 0 - name: Require tag at llgo branch tip + if: github.event_name == 'push' run: | git fetch origin llgo test "$(git rev-parse HEAD)" = "$(git rev-parse origin/llgo)" @@ -81,7 +88,7 @@ jobs: run: | # Ignore all but the first component of the os name OSNAME=$(echo ${{ matrix.os }} | sed 's/-.*//') - VERSION=$GITHUB_REF_NAME + VERSION=$LLGO_PACKAGE_VERSION PKGNAME="binaryen-$VERSION-x86_64-$OSNAME" TARBALL=$PKGNAME.tar.gz SHASUM=$PKGNAME.tar.gz.sha256 @@ -100,7 +107,7 @@ jobs: run: | # Ignore all but the first component of the os name OSNAME=$(echo ${{ matrix.os }} | sed 's/-.*//') - VERSION=$GITHUB_REF_NAME + VERSION=$LLGO_PACKAGE_VERSION PKGNAME="binaryen-$VERSION-arm64-$OSNAME" TARBALL=$PKGNAME.tar.gz SHASUM=$PKGNAME.tar.gz.sha256 @@ -115,6 +122,7 @@ jobs: if: ${{ matrix.os == 'macos-14' || matrix.os == 'windows-11-arm' }} - name: upload tarball + if: github.event_name == 'push' uses: softprops/action-gh-release@v2 with: draft: true @@ -180,7 +188,7 @@ jobs: - name: archive id: archive run: | - VERSION=$GITHUB_REF_NAME + VERSION=$LLGO_PACKAGE_VERSION ARCH=$(./alpine.sh uname -m) PKGNAME="binaryen-$VERSION-$ARCH-linux" TARBALL=$PKGNAME.tar.gz @@ -197,6 +205,7 @@ jobs: echo "SHASUM=$SHASUM" >> $GITHUB_OUTPUT - name: upload tarball + if: github.event_name == 'push' uses: softprops/action-gh-release@v2 with: draft: true @@ -252,7 +261,7 @@ jobs: - name: archive id: archive run: | - VERSION=$GITHUB_REF_NAME + VERSION=$LLGO_PACKAGE_VERSION PKGNAME="binaryen-$VERSION-node" TARBALL=$PKGNAME.tar.gz SHASUM=$PKGNAME.tar.gz.sha256 @@ -265,6 +274,7 @@ jobs: echo "SHASUM=$SHASUM" >> $GITHUB_OUTPUT - name: upload tarball + if: github.event_name == 'push' uses: softprops/action-gh-release@v2 with: draft: true @@ -274,6 +284,7 @@ jobs: publish: name: publish validated release + if: github.event_name == 'push' needs: [build, build-alpine, build-node] runs-on: ubuntu-latest env: