Files
2025-10-18 00:36:55 -05:00

457 lines
14 KiB
YAML

# Multi-platform build + packaging workflow
# - Builds a pyinstaller executable on Windows, Debian, Arch, Fedora.
# - Packages using fpm into .deb, .rpm, and pacman (.pkg.tar.zst) files with explicit filenames.
# - Creates a GitHub Release with the produced artifacts.
#
# Notes:
# - Poetry is installed via snok/install-poetry@v1 in all jobs.
# - fpm gem is pinned to 1.16.0 in the examples; change as needed.
# - Fedora job uses tarball downloads for pyenv and python-build (non-interactive, CI-friendly).
name: Build Multi-Platform Binaries
on:
workflow_dispatch:
permissions:
contents: read
packages: read
# Prevent multiple release workflows from running simultaneously
# This is critical to prevent concurrent rollbacks
concurrency:
group: release-workflow
cancel-in-progress: true
env:
# change this if you prefer a different pinned fpm version
FPM_VERSION: "1.16.0"
# Personal Access Token for HTTPS git operations (populate in repository secrets)
CI_CD_PAT: ${{ secrets.CI_CD_PAT }}
CI_CD: true
jobs:
build-windows:
runs-on: windows-latest
steps:
- name: Checkout code
uses: actions/checkout@v4
with:
ref: main
- name: Set up Python 3.13
uses: actions/setup-python@v5
with:
python-version: '3.13'
- name: Install Poetry
uses: snok/install-poetry@v1
with:
version: latest
virtualenvs-create: true
virtualenvs-in-project: true
- name: Ensure Poetry is on PATH (Windows)
shell: pwsh
run: |
# Add Poetry user bin to PATH for subsequent steps in this job
$poetryPath = Join-Path $env:USERPROFILE ".local\bin"
Write-Output $poetryPath >> $Env:GITHUB_PATH
- name: Install dependencies
run: |
poetry install
- name: Build Windows executable
run: |
# Use the Windows spec file so packaging is consistent and reproducible
poetry run pyinstaller scripts/spec_scripts/android-file-handler-windows.spec
- name: Import GPG key
shell: pwsh
run: |
$env:GPG_TTY = "not a tty"
echo "${{ secrets.GPG_PRIVATE_KEY }}" | gpg --batch --import
gpg --list-secret-keys
- name: Sign and hash Windows executable
shell: pwsh
run: |
$exePath = Get-ChildItem -Path dist -Filter "android-file-handler.exe" -Recurse | Select-Object -First 1 -ExpandProperty FullName
if (-not $exePath) {
Write-Error "Executable not found"
exit 1
}
Write-Output "Found executable: $exePath"
# Create temporary file for passphrase
$passphraseFile = New-TemporaryFile
try {
"${{ secrets.GPG_PASSPHRASE }}" | Out-File -FilePath $passphraseFile -Encoding ASCII -NoNewline
# Sign with GPG using passphrase file
gpg --batch --yes --passphrase-file "$passphraseFile" --detach-sign --armor "$exePath"
}
finally {
# Clean up passphrase file
if (Test-Path $passphraseFile) {
Remove-Item $passphraseFile -Force
}
}
# Generate SHA-256 hash
$hash = (Get-FileHash -Path "$exePath" -Algorithm SHA256).Hash.ToLower()
$hashFile = "dist/android-file-handler-windows.sha256"
"$hash $(Split-Path -Leaf $exePath)" | Out-File -FilePath $hashFile -Encoding ASCII -NoNewline
Write-Output "SHA-256: $hash"
- name: Upload Windows artifact
uses: actions/upload-artifact@v4
with:
name: windows-binary
path: |
dist/**/android-file-handler*.exe
dist/**/android-file-handler*.exe.asc
dist/android-file-handler.exe
dist/android-file-handler.exe.asc
dist/android-file-handler-windows.sha256
build-debian:
permissions:
contents: read
packages: read
env:
DISTRO_TYPE: debian
runs-on: ubuntu-latest
container:
image: ghcr.io/jmr-dev/android-file-handler-debian-builder:debian13-trixie
credentials:
username: ${{ github.actor }}
password: ${{ secrets.GITHUB_TOKEN }}
steps:
- name: Checkout code
uses: actions/checkout@v4
with:
ref: main
- name: Build and package Debian
run: |
# Container has Poetry and all dependencies pre-installed
# Python build script handles both PyInstaller build and fpm packaging
poetry install --no-interaction
poetry run python scripts/build_package_linux.py
- name: Import GPG key
shell: bash
run: |
export GPG_TTY=$(tty) || true
echo "${{ secrets.GPG_PRIVATE_KEY }}" | gpg --batch --import
gpg --list-secret-keys
- name: Sign and hash Debian package
shell: bash
run: |
set -euo pipefail
DEB_FILE=$(find dist -name "android-file-handler_*.deb" -type f | head -n 1)
if [ -z "$DEB_FILE" ]; then
echo "Error: .deb file not found"
exit 1
fi
echo "Found package: $DEB_FILE"
# Create temporary file for passphrase
PASSPHRASE_FILE=$(mktemp)
trap "rm -f '$PASSPHRASE_FILE'" EXIT
# Write passphrase to temporary file
echo "${{ secrets.GPG_PASSPHRASE }}" > "$PASSPHRASE_FILE"
# Sign with GPG using passphrase file
gpg --batch --yes --passphrase-file "$PASSPHRASE_FILE" --detach-sign --armor "$DEB_FILE"
# Clean up passphrase file
rm -f "$PASSPHRASE_FILE"
# Generate SHA-256 hash
sha256sum "$DEB_FILE" | awk '{print $1 " " $2}' > dist/android-file-handler-debian.sha256
echo "SHA-256: $(cat dist/android-file-handler-debian.sha256)"
- name: Upload Debian .deb
uses: actions/upload-artifact@v4
with:
name: debian-package
path: |
dist/android-file-handler_*.deb
dist/android-file-handler_*.deb.asc
dist/android-file-handler-debian.sha256
pkg_dist_debian/**
build-arch:
permissions:
contents: read
packages: read
env:
DISTRO_TYPE: arch
runs-on: ubuntu-latest
steps:
- name: Checkout code
uses: actions/checkout@v4
with:
ref: main
- name: Log in to GitHub Container Registry
uses: docker/login-action@v2
with:
registry: ghcr.io
username: ${{ github.actor }}
password: ${{ secrets.CI_CD_PAT }}
- name: Pull Docker image
run: docker pull ghcr.io/jmr-dev/android-file-handler-arch-builder:latest
- name: Build and package Arch
run: |
docker run --rm \
-v ${{ github.workspace }}:/workspace \
-w /workspace \
-e DISTRO_TYPE=${{ env.DISTRO_TYPE }} \
-e FPM_VERSION=${{ env.FPM_VERSION }} \
-e CI_CD=${{ env.CI_CD }} \
ghcr.io/jmr-dev/android-file-handler-arch-builder:latest \
sh -c "poetry install --no-interaction && poetry run python scripts/build_package_linux.py"
- name: Import GPG key
shell: bash
run: |
export GPG_TTY=$(tty) || true
echo "${{ secrets.GPG_PRIVATE_KEY }}" | gpg --batch --import
gpg --list-secret-keys
- name: Sign and hash Arch package
shell: bash
run: |
set -euo pipefail
PKG_FILE=$(find dist -name "android-file-handler-*.pkg.tar.zst" -type f | head -n 1)
if [ -z "$PKG_FILE" ]; then
echo "Error: .pkg.tar.zst file not found"
exit 1
fi
echo "Found package: $PKG_FILE"
# Create temporary file for passphrase
PASSPHRASE_FILE=$(mktemp)
trap "rm -f '$PASSPHRASE_FILE'" EXIT
# Write passphrase to temporary file
echo "${{ secrets.GPG_PASSPHRASE }}" > "$PASSPHRASE_FILE"
# Sign with GPG using passphrase file
gpg --batch --yes --passphrase-file "$PASSPHRASE_FILE" --detach-sign --armor "$PKG_FILE"
# Clean up passphrase file
rm -f "$PASSPHRASE_FILE"
# Generate SHA-256 hash
sha256sum "$PKG_FILE" | awk '{print $1 " " $2}' > dist/android-file-handler-arch.sha256
echo "SHA-256: $(cat dist/android-file-handler-arch.sha256)"
- name: Upload Arch package
uses: actions/upload-artifact@v4
with:
name: arch-package
path: |
dist/*.pkg.tar.*
dist/android-file-handler-arch.sha256
pkg_dist_arch/**
build-rhel:
permissions:
contents: read
packages: read
env:
DISTRO_TYPE: rhel
runs-on: ubuntu-latest
container:
image: ghcr.io/jmr-dev/android-file-handler-rhel-builder:fedora42
credentials:
username: ${{ github.actor }}
password: ${{ secrets.GITHUB_TOKEN }}
steps:
- name: Checkout code
uses: actions/checkout@v4
with:
ref: main
- name: Build and package RHEL
run: |
# Container has Poetry and all dependencies pre-installed
# Python build script handles both PyInstaller build and fpm packaging
poetry install --no-interaction
poetry run python scripts/build_package_linux.py
- name: Import GPG key
shell: bash
run: |
export GPG_TTY=$(tty) || true
echo "${{ secrets.GPG_PRIVATE_KEY }}" | gpg --batch --import
gpg --list-secret-keys
- name: Sign and hash RHEL package
shell: bash
run: |
set -euo pipefail
RPM_FILE=$(find dist -name "android-file-handler-*.rpm" -type f | head -n 1)
if [ -z "$RPM_FILE" ]; then
echo "Error: .rpm file not found"
exit 1
fi
echo "Found package: $RPM_FILE"
# Create temporary file for passphrase
PASSPHRASE_FILE=$(mktemp)
trap "rm -f '$PASSPHRASE_FILE'" EXIT
# Write passphrase to temporary file
echo "${{ secrets.GPG_PASSPHRASE }}" > "$PASSPHRASE_FILE"
# Sign with GPG using passphrase file
gpg --batch --yes --passphrase-file "$PASSPHRASE_FILE" --detach-sign --armor "$RPM_FILE"
# Clean up passphrase file
rm -f "$PASSPHRASE_FILE"
# Generate SHA-256 hash
sha256sum "$RPM_FILE" | awk '{print $1 " " $2}' > dist/android-file-handler-rhel.sha256
echo "SHA-256: $(cat dist/android-file-handler-rhel.sha256)"
- name: Upload RHEL artifacts
uses: actions/upload-artifact@v4
with:
name: rhel-package
path: |
dist/*.rpm
dist/*.rpm.asc
dist/android-file-handler-rhel.sha256
pkg_dist_rhel/**
do-release:
needs:
- build-windows
- build-debian
- build-arch
- build-rhel
runs-on: ubuntu-latest
steps:
- name: Checkout code
uses: actions/checkout@v4
with:
ref: main
- name: Install Poetry
uses: snok/install-poetry@v1
- name: Get version
id: version
run: |
if ! VERSION="$(poetry version -s 2>&1)"; then
echo "::error::Failed to read version from pyproject.toml"
echo "::error::Poetry output: $VERSION"
exit 1
fi
if [ -z "$VERSION" ]; then
echo "::error::Version is empty in pyproject.toml"
exit 1
fi
# Validate semver format
if ! [[ "$VERSION" =~ ^[0-9]+\.[0-9]+\.[0-9]+(-[a-zA-Z0-9]+(\.[a-zA-Z0-9]+)*)?(\+[a-zA-Z0-9]+(\.[a-zA-Z0-9]+)*)?$ ]]; then
echo "::error::Invalid version format in pyproject.toml: $VERSION"
echo "::error::Expected semantic version format (e.g., 1.2.3, 1.2.3-beta.1, 1.2.3+build.123)"
exit 1
fi
echo "Using version: $VERSION"
echo "version=$VERSION" >> $GITHUB_OUTPUT
- name: Download all artifacts
uses: actions/download-artifact@v4
with:
merge-multiple: true
path: ./binaries
- name: Prepare release files
run: |
mkdir -p ./release-files
# Copy binary packages
find ./binaries -name "*.exe" -exec cp {} ./release-files/ \; || true
find ./binaries -name "*.deb" -exec cp {} ./release-files/ \; || true
find ./binaries -name "*.rpm" -exec cp {} ./release-files/ \; || true
find ./binaries -name "*.pkg.tar.*" -exec cp {} ./release-files/ \; || true
# Copy GPG signatures
find ./binaries -name "*.asc" -exec cp {} ./release-files/ \; || true
# Copy SHA-256 hashes
find ./binaries -name "*.sha256" -exec cp {} ./release-files/ \; || true
echo "Release files prepared:"
ls -lh ./release-files/
- name: Create Release
uses: softprops/action-gh-release@v1
with:
tag_name: v${{ steps.version.outputs.version }}
name: Release v${{ steps.version.outputs.version }}
files: ./release-files/*
draft: false
prerelease: false
env:
GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }}
upload-s3:
runs-on: ubuntu-latest
needs: do-release
if: needs.do-release.result == 'success'
steps:
- name: Checkout code
uses: actions/checkout@v4
with:
ref: main
- name: Install AWS CLI
run: |
python -m pip install --upgrade pip awscli
- name: Download build artifacts
uses: actions/download-artifact@v4
with:
merge-multiple: true
path: ./binaries
- name: Configure AWS credentials
uses: aws-actions/configure-aws-credentials@v2
with:
aws-access-key-id: ${{ secrets.AWS_ACCESS_KEY_ID }}
aws-secret-access-key: ${{ secrets.AWS_SECRET_ACCESS_KEY }}
aws-region: ${{ secrets.AWS_REGION }}
- name: Upload artifacts to S3
run: |
set -euo pipefail
if [ -z "${{ secrets.S3_BUCKET }}" ]; then
echo "S3_BUCKET secret not set; skipping upload"
exit 0
fi
aws s3 sync ./binaries s3://${{ secrets.S3_BUCKET }}/builds/${{ github.run_id }}/ --acl private
env:
AWS_PAGER: ""
sync-wiki:
needs: do-release
if: needs.do-release.result == 'success'
permissions:
contents: write
pull-requests: write
uses: ./.github/workflows/sync-wiki.yml
with:
branch: main
secrets: inherit