Skip to content
Open
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
28 changes: 13 additions & 15 deletions .github/workflows/release-matrix-check.yml
Original file line number Diff line number Diff line change
@@ -1,13 +1,15 @@
# Builds every target the release matrix builds, without releasing anything.
#
# The release build only runs on a `v*` tag push, so a dependency that breaks a
# cross-compiled target is discovered while cutting the release. That is the
# wrong moment: the tag exists, and the fix lands after a failed publish.
# A release compiles its binaries once, on the `v*` tag push. What breaks a
# cross-compiled target is a change to the dependency graph or the toolchain
# pin, so a pull request to `dev` that makes one pays this matrix, and the tag
# builds a graph every such change already built.
#
# This runs the same seven targets at the two moments that matter: when the
# dependency graph or toolchain pin changes, which is what breaks a cross
# build, and on every release branch, which is the last point before a tag
# exists.
# Nothing here runs for a release. A release pull request targets `main`, and
# its version bump would match the paths below; the backport of that bump to
# `dev` matches them too and changes no dependency. `workflow_dispatch` runs
# the matrix on any ref, a release branch included, when a release wants a
# rehearsal.
#
# The matrix and its build steps live in the shared workflow this calls, beside
# the release workflow whose matrix they mirror. Every row is hard-fail there,
Expand All @@ -18,20 +20,14 @@ name: Release matrix check

on:
workflow_dispatch:
# Dependency and toolchain changes are what break a cross-compiled target,
# so those PRs pay the matrix and nothing else does.
pull_request:
branches:
- dev
paths:
- Cargo.toml
- Cargo.lock
- rust-toolchain.toml
- .github/workflows/release-matrix-check.yml
# Every release branch runs the full matrix regardless of what changed. This
# is the last point before a tag exists, and a release carries commits the
# path filter above may never have seen together.
push:
branches:
- 'release/**'

permissions:
contents: read
Expand All @@ -42,4 +38,6 @@ concurrency:

jobs:
check:
# `scripts/sync-dev-after-release.sh` names the backport's branch.
if: ${{ !startsWith(github.head_ref, 'chore/sync-dev') }}
uses: brettdavies/.github/.github/workflows/rust-release-matrix-check.yml@main
9 changes: 6 additions & 3 deletions RELEASES-PREFLIGHT.md
Original file line number Diff line number Diff line change
Expand Up @@ -196,9 +196,12 @@ These items duplicate steps in `RELEASES.md` deliberately: easy to skip, expensi
or revert it before tagging.
- [ ] No unmerged dependency advisories from `cargo deny check advisories`. The full local pre-push check
(`scripts/hooks/pre-push`) mirrors CI; run it explicitly before pushing the release branch.
- [ ] Every row of the `Release matrix check` run on the release branch is green. It is the only build of the
cross-compiled targets before the tag, and no ruleset can require it: the check is path-filtered on PRs, and a
required context that never reports leaves a PR pending.
- [ ] The latest `Release matrix check` run on a PR to `dev` is green (`gh run list --workflow
release-matrix-check.yml --event pull_request --limit 5`). The tag's build is the release's one build of the
cross-compiled targets, and nothing builds them for the release branch. No ruleset can require the check: it is
path-filtered on PRs, and a required context that never reports leaves a PR pending, so a dependency or toolchain PR
can merge with it red. `gh workflow run release-matrix-check.yml --ref release/v<version>` rehearses the matrix on
the release branch when the release wants one.
- [ ] `scripts/release/cut-release-branch.sh` exited 0, so its check A held: the staged tree equals `origin/dev`'s apart
from the version carriers and the guarded paths. A cherry-pick release runs the triple diff in `RELEASES.md` §
Exception: cherry-pick instead, with `HEAD..origin/dev` filtered by the guarded set (not all of `docs/`, since a
Expand Down
8 changes: 5 additions & 3 deletions RELEASES.md
Original file line number Diff line number Diff line change
Expand Up @@ -460,9 +460,11 @@ changelog check that reads a PR's files, and uses no extra secrets.

Seven targets, listed in the `build` row of [§ Tagging and publishing](#tagging-and-publishing). The two musl rows are
hard-blocking (`linux_musl_required: true`) and the x86_64-musl binary is exec-verified inside `alpine:latest`
(`linux_musl_verify_alpine: true`). `release-matrix-check.yml` builds the same seven rows on every push to a `release/*`
branch, and on a PR that changes `Cargo.toml`, `Cargo.lock`, or `rust-toolchain.toml`, so a broken row surfaces before
the tag.
(`linux_musl_verify_alpine: true`). A release compiles the seven rows once, on the tag push. `release-matrix-check.yml`
builds the same rows on a PR to `dev` that changes `Cargo.toml`, `Cargo.lock`, or `rust-toolchain.toml`, since those
are the changes that break a cross-compiled row, so a broken row surfaces on the change that broke it. It does not run
for a release branch, a release PR, or the backport of a release's version bump; `gh workflow run
release-matrix-check.yml --ref release/v<version>` runs it on a release branch when a release wants a rehearsal.

Four of the archives are also what Homebrew installs. `Formula/agentnative.rb` in `brettdavies/homebrew-tap` names
`agentnative-aarch64-apple-darwin.tar.gz`, `agentnative-x86_64-apple-darwin.tar.gz`,
Expand Down
Loading