diff --git a/.github/workflows/publish-rust.yml b/.github/workflows/publish-rust.yml deleted file mode 100644 index cdd70c7..0000000 --- a/.github/workflows/publish-rust.yml +++ /dev/null @@ -1,216 +0,0 @@ -name: Publish Crate - -on: - workflow_dispatch: - inputs: - package_path: - description: Path to directory with package to release - required: true - type: string - level: - description: Level - required: true - default: patch - type: choice - options: - - patch - - minor - - major - - version - version: - description: Version (used with level "version") - required: false - type: string - dry_run: - description: Dry run - required: true - default: true - type: boolean - create_release: - description: Create a GitHub release - required: true - type: boolean - default: true - dependent_version: - description: | - How workspace dependencies should be handled. - - "fix": (Default) Only bumps the workspace for semver-breakage - prefer this option - - "upgrade": Bumps workspace version regardless - only use if another crate requires new code - required: true - default: fix - type: choice - options: - - fix - - upgrade - run_semver: - description: | - Run semver checks. - Only disable checks if you are sure of the semver impact of your change and have a good reason - to skip it. - required: true - type: boolean - default: true - -jobs: - format: - name: Format - runs-on: ubuntu-latest - steps: - - name: Git Checkout - uses: actions/checkout@v4 - - - name: Install Rust - uses: dtolnay/rust-toolchain@nightly - with: - components: rustfmt - - - name: Cache - uses: Swatinem/rust-cache@v2 - - - name: Check formatting - run: cargo fmt --all -- --check - - clippy: - name: Clippy - runs-on: ubuntu-latest - steps: - - name: Git Checkout - uses: actions/checkout@v4 - - - name: Install Rust - uses: dtolnay/rust-toolchain@stable - with: - components: clippy - - - name: Cache - uses: Swatinem/rust-cache@v2 - - - name: Run clippy - run: cargo clippy --workspace --all-targets -- -D warnings - - semver: - name: Check Semver - runs-on: ubuntu-latest - steps: - - name: Git checkout - uses: actions/checkout@v4 - - - name: Install Rust - uses: dtolnay/rust-toolchain@stable - - - name: Cache - uses: Swatinem/rust-cache@v2 - - - name: Install tools - uses: taiki-e/install-action@v2 - with: - tool: toml-cli,cargo-semver-checks,cargo-release - - - name: Check if crate is a procedural macro - id: is_proc_macro - shell: bash - run: | - set +e # toml crashes the whole shell if it fails to find the key - result=$(toml get "${{ inputs.package_path }}/Cargo.toml" lib.proc-macro) - if [[ "$result" == *"true"* ]]; then - echo "is_proc_macro=true" >> "$GITHUB_OUTPUT" - else - echo "is_proc_macro=false" >> "$GITHUB_OUTPUT" - fi - - - name: Set Git Author (required for cargo-release) - if: ${{ steps.is_proc_macro.outputs.is_proc_macro == 'false' }} - run: | - git config --global user.email "41898282+github-actions[bot]@users.noreply.github.com" - git config --global user.name "github-actions[bot]" - - - name: Set Version - if: ${{ steps.is_proc_macro.outputs.is_proc_macro == 'false' }} - run: | - if [ "${{ inputs.level }}" == "version" ]; then - LEVEL=${{ inputs.version }} - else - LEVEL=${{ inputs.level }} - fi - cargo release $LEVEL --manifest-path "${{ inputs.package_path }}/Cargo.toml" --no-tag --no-publish --no-push --no-confirm --execute - - - name: Check semver - if: ${{ steps.is_proc_macro.outputs.is_proc_macro == 'false' && github.event.inputs.run_semver == 'true'}} - run: cargo semver-checks --manifest-path "${{ inputs.package_path }}/Cargo.toml" - - publish-crate: - name: Publish crate - runs-on: ubuntu-latest - needs: [format, clippy, semver] - permissions: - contents: write - steps: - - name: Git Checkout - uses: actions/checkout@v4 - with: - token: ${{ secrets.ANZA_TEAM_PAT }} - fetch-depth: 0 # get the whole history for git-cliff - - - name: Install Rust - uses: dtolnay/rust-toolchain@stable - - - name: Cache - uses: Swatinem/rust-cache@v2 - - - name: Install cargo-release - uses: taiki-e/install-action@v2 - with: - tool: cargo-release - - - name: Ensure CARGO_REGISTRY_TOKEN variable is set - env: - token: ${{ secrets.CARGO_REGISTRY_TOKEN }} - if: ${{ env.token == '' }} - run: | - echo "The CARGO_REGISTRY_TOKEN secret variable is not set" - echo "Go to \"Settings\" -> \"Secrets and variables\" -> \"Actions\" -> \"New repository secret\"." - exit 1 - - - name: Set Git Author - run: | - git config --global user.email "41898282+github-actions[bot]@users.noreply.github.com" - git config --global user.name "github-actions[bot]" - - - name: Rebase (in case any changes landed after) - run: git pull --rebase origin - - - name: Publish Crate - id: publish - env: - CARGO_REGISTRY_TOKEN: ${{ secrets.CARGO_REGISTRY_TOKEN }} - run: | - if [ "${{ inputs.level }}" == "version" ]; then - LEVEL=${{ inputs.version }} - else - LEVEL=${{ inputs.level }} - fi - - if [ "${{ inputs.dry_run }}" == "true" ]; then - OPTIONS="--dry-run" - else - OPTIONS="" - fi - - ./scripts/publish-rust.sh "${{ inputs.package_path }}" $LEVEL "${{ inputs.dependent_version }}" $OPTIONS - - - name: Generate a changelog - if: github.event.inputs.create_release == 'true' - uses: orhun/git-cliff-action@v4 - with: - config: "scripts/cliff.toml" - args: ${{ steps.publish.outputs.old_git_tag }}..HEAD --include-path "${{ inputs.package_path }}/**" --github-repo ${{ github.repository }} - env: - OUTPUT: TEMP_CHANGELOG.md - GITHUB_REPO: ${{ github.repository }} - - - name: Create GitHub release - if: github.event.inputs.create_release == 'true' && github.event.inputs.dry_run != 'true' - uses: ncipollo/release-action@v1 - with: - tag: ${{ steps.publish.outputs.new_git_tag }} - bodyFile: TEMP_CHANGELOG.md diff --git a/.github/workflows/release.yml b/.github/workflows/release.yml new file mode 100644 index 0000000..ec8f8bc --- /dev/null +++ b/.github/workflows/release.yml @@ -0,0 +1,138 @@ +name: Release + +on: + workflow_dispatch: + inputs: + crate: + description: "Crate to release" + required: true + type: choice + options: + - "" + - solana-curve25519-cuda + - solana-ed25519 + - ed25519-pokos + - solana-bls12-381-syscall + ref: + description: "git ref to tag (can be a branch or a commit hash)" + required: true + default: "master" + type: string + +jobs: + check: + runs-on: ubuntu-latest + outputs: + tag: ${{ steps.meta.outputs.tag }} + ref: ${{ steps.meta.outputs.ref }} + steps: + - uses: actions/checkout@v6 + with: + ref: ${{ inputs.ref }} + persist-credentials: false + + - name: Compute metadata + id: meta + run: | + + version="$(cargo metadata --format-version 1 --no-deps | jq -r '.packages[] | select(.name == "'"${CRATE_NAME}"'") | .version')" + if [ -z "${version}" ] || [ "${version}" = "null" ]; then + echo "Could not resolve version for crate: ${CRATE_NAME}" + exit 1 + fi + + tag="${CRATE_NAME}@v${version}" + ref="$(git rev-parse HEAD)" + + echo "tag=${tag}" >> "${GITHUB_OUTPUT}" + echo "ref=${ref}" >> "${GITHUB_OUTPUT}" + env: + CRATE_NAME: ${{ inputs.crate }} + + - name: Check tag does not exist + run: | + echo "checking: refs/tags/${TAG}" + if git ls-remote --exit-code --tags origin "refs/tags/${TAG}" >/dev/null 2>&1; then + echo "Tag already exists: ${TAG}. Please bump the version first (or delete the existing tag) and retry." + echo "Tag exists: ${TAG}" >> "${GITHUB_STEP_SUMMARY}" + exit 1 + fi + env: + TAG: ${{ steps.meta.outputs.tag }} + + - name: Cargo publish dry run + run: | + cargo publish -p "${CRATE_NAME}" --dry-run + env: + CRATE_NAME: ${{ inputs.crate }} + + - name: Summary + run: | + echo "Tag: ${TAG}" >> "${GITHUB_STEP_SUMMARY}" + echo "Ref: ${REF} (https://github.com/${{ github.repository }}/commit/${REF})" >> "${GITHUB_STEP_SUMMARY}" + env: + TAG: ${{ steps.meta.outputs.tag }} + REF: ${{ steps.meta.outputs.ref }} + + publish: + runs-on: ubuntu-latest + environment: prod + needs: check + permissions: + id-token: write + contents: write + attestations: write + artifact-metadata: write + steps: + - uses: actions/create-github-app-token@v3 + id: app-token + with: + app-id: ${{ vars.APP_ID }} + private-key: ${{ secrets.PRIVATE_KEY }} + + - name: Set git config + run: | + git config --global user.email "${APP_ID}+${APP_SLUG}[bot]@users.noreply.github.com" + git config --global user.name "${APP_SLUG}[bot]" + git config --global url."https://x-access-token:${GITHUB_TOKEN}@github.com/".insteadOf https://github.com/ + env: + GITHUB_TOKEN: ${{ steps.app-token.outputs.token }} + APP_ID: ${{ vars.APP_ID }} + APP_SLUG: ${{ steps.app-token.outputs.app-slug }} + + - uses: actions/checkout@v6 + with: + token: ${{ steps.app-token.outputs.token }} + persist-credentials: false + ref: ${{ needs.check.outputs.ref }} + + - run: | + git tag -a "${TAG}" -m "Release ${TAG}" + git push --tags + env: + TAG: ${{ needs.check.outputs.tag }} + + - name: Package crate + run: cargo package -p "${CRATE_NAME}" + env: + CRATE_NAME: ${{ inputs.crate }} + + - name: Generate SLSA provenance + uses: actions/attest-build-provenance@v4 + with: + subject-path: target/package/*.crate + + - uses: rust-lang/crates-io-auth-action@v1 + id: auth + + - run: cargo publish -p "${CRATE_NAME}" + env: + CRATE_NAME: ${{ inputs.crate }} + CARGO_REGISTRY_TOKEN: ${{ steps.auth.outputs.token }} + + - name: Create Github Release + run: | + gh release create "${TAG}" --title "${TAG}" --generate-notes + env: + TAG: ${{ needs.check.outputs.tag }} + GITHUB_TOKEN: ${{ steps.app-token.outputs.token }}