diff --git a/.github/workflows/release-matrix-check.yml b/.github/workflows/release-matrix-check.yml index 7135158..fd0d03b 100644 --- a/.github/workflows/release-matrix-check.yml +++ b/.github/workflows/release-matrix-check.yml @@ -1,13 +1,15 @@ # Builds every target the release matrix builds, without releasing anything. # -# The release build only runs on a `v*` tag push, so a dependency that breaks a -# cross-compiled target is discovered while cutting the release. That is the -# wrong moment: the tag exists, and the fix lands after a failed publish. +# A release compiles its binaries once, on the `v*` tag push. What breaks a +# cross-compiled target is a change to the dependency graph or the toolchain +# pin, so a pull request to `dev` that makes one pays this matrix, and the tag +# builds a graph every such change already built. # -# This runs the same seven targets at the two moments that matter: when the -# dependency graph or toolchain pin changes, which is what breaks a cross -# build, and on every release branch, which is the last point before a tag -# exists. +# Nothing here runs for a release. A release pull request targets `main`, and +# its version bump would match the paths below; the backport of that bump to +# `dev` matches them too and changes no dependency. `workflow_dispatch` runs +# the matrix on any ref, a release branch included, when a release wants a +# rehearsal. # # The matrix and its build steps live in the shared workflow this calls, beside # the release workflow whose matrix they mirror. Every row is hard-fail there, @@ -18,20 +20,14 @@ name: Release matrix check on: workflow_dispatch: - # Dependency and toolchain changes are what break a cross-compiled target, - # so those PRs pay the matrix and nothing else does. pull_request: + branches: + - dev paths: - Cargo.toml - Cargo.lock - rust-toolchain.toml - .github/workflows/release-matrix-check.yml - # Every release branch runs the full matrix regardless of what changed. This - # is the last point before a tag exists, and a release carries commits the - # path filter above may never have seen together. - push: - branches: - - 'release/**' permissions: contents: read @@ -42,4 +38,6 @@ concurrency: jobs: check: + # `scripts/sync-dev-after-release.sh` names the backport's branch. + if: ${{ !startsWith(github.head_ref, 'chore/sync-dev') }} uses: brettdavies/.github/.github/workflows/rust-release-matrix-check.yml@main diff --git a/RELEASES-PREFLIGHT.md b/RELEASES-PREFLIGHT.md index 4c45fdd..a2df848 100644 --- a/RELEASES-PREFLIGHT.md +++ b/RELEASES-PREFLIGHT.md @@ -196,9 +196,12 @@ These items duplicate steps in `RELEASES.md` deliberately: easy to skip, expensi or revert it before tagging. - [ ] No unmerged dependency advisories from `cargo deny check advisories`. The full local pre-push check (`scripts/hooks/pre-push`) mirrors CI; run it explicitly before pushing the release branch. -- [ ] Every row of the `Release matrix check` run on the release branch is green. It is the only build of the - cross-compiled targets before the tag, and no ruleset can require it: the check is path-filtered on PRs, and a - required context that never reports leaves a PR pending. +- [ ] The latest `Release matrix check` run on a PR to `dev` is green (`gh run list --workflow + release-matrix-check.yml --event pull_request --limit 5`). The tag's build is the release's one build of the + cross-compiled targets, and nothing builds them for the release branch. No ruleset can require the check: it is + path-filtered on PRs, and a required context that never reports leaves a PR pending, so a dependency or toolchain PR + can merge with it red. `gh workflow run release-matrix-check.yml --ref release/v` rehearses the matrix on + the release branch when the release wants one. - [ ] `scripts/release/cut-release-branch.sh` exited 0, so its check A held: the staged tree equals `origin/dev`'s apart from the version carriers and the guarded paths. A cherry-pick release runs the triple diff in `RELEASES.md` § Exception: cherry-pick instead, with `HEAD..origin/dev` filtered by the guarded set (not all of `docs/`, since a diff --git a/RELEASES.md b/RELEASES.md index a0a5802..f9960e5 100644 --- a/RELEASES.md +++ b/RELEASES.md @@ -460,9 +460,11 @@ changelog check that reads a PR's files, and uses no extra secrets. Seven targets, listed in the `build` row of [§ Tagging and publishing](#tagging-and-publishing). The two musl rows are hard-blocking (`linux_musl_required: true`) and the x86_64-musl binary is exec-verified inside `alpine:latest` -(`linux_musl_verify_alpine: true`). `release-matrix-check.yml` builds the same seven rows on every push to a `release/*` -branch, and on a PR that changes `Cargo.toml`, `Cargo.lock`, or `rust-toolchain.toml`, so a broken row surfaces before -the tag. +(`linux_musl_verify_alpine: true`). A release compiles the seven rows once, on the tag push. `release-matrix-check.yml` +builds the same rows on a PR to `dev` that changes `Cargo.toml`, `Cargo.lock`, or `rust-toolchain.toml`, since those +are the changes that break a cross-compiled row, so a broken row surfaces on the change that broke it. It does not run +for a release branch, a release PR, or the backport of a release's version bump; `gh workflow run +release-matrix-check.yml --ref release/v` runs it on a release branch when a release wants a rehearsal. Four of the archives are also what Homebrew installs. `Formula/agentnative.rb` in `brettdavies/homebrew-tap` names `agentnative-aarch64-apple-darwin.tar.gz`, `agentnative-x86_64-apple-darwin.tar.gz`,