Files
simplex-chat/.github/workflows/build.yml
T

299 lines
11 KiB
YAML

name: build
# Only the ubuntu-22.04-aarch64 (CLI,Desktop) job is kept on this branch, every other job
# and trigger is removed, so that pushing here rebuilds nothing but the 7.0.1 assets that
# are missing from the release.
on:
push:
branches:
- sh/desktop-rebuild
workflow_dispatch:
concurrency:
group: ${{ github.workflow }}-${{ github.ref }}
cancel-in-progress: true
# Important!
# Do not use always(), it makes build unskippable.
# See: https://github.com/actions/runner/issues/1846#issuecomment-1246102753
jobs:
# =============================
# Global variables
# =============================
# That is the only and less hacky way to setup global variables
# to use in strategy matrix (env:/YAML anchors doesn't work).
# See: https://github.com/orgs/community/discussions/56787#discussioncomment-6041789
# https://github.com/actions/runner/issues/1182
# https://stackoverflow.com/a/77549656
variables:
runs-on: ubuntu-latest
outputs:
GHC_VER: 9.6.3
JAVA_VER: 17
steps:
- name: Dummy job when we have just simple variables
if: false
run: echo
# =========================
# Linux Build
# =========================
build-linux:
name: "ubuntu-${{ matrix.os }}-${{ matrix.arch }} (CLI,Desktop), GHC: ${{ matrix.ghc }}"
needs: [variables]
runs-on: ${{ matrix.runner }}
strategy:
fail-fast: false
matrix:
include:
- os: 22.04
os_underscore: 22_04
arch: aarch64
runner: "ubuntu-22.04-arm"
should_run: true
ghc: ${{ needs.variables.outputs.GHC_VER }}
hash: 'sha256:6a62a4157b8775eaf4959cb629e757d32d39d1f4c8ac1b0ddc2510b555cf72f3'
steps:
- name: Checkout Code
if: matrix.should_run == true
uses: actions/checkout@v3
- name: Setup swap
if: matrix.ghc == '8.10.7' && matrix.should_run == true
uses: ./.github/actions/swap
with:
swap-size-gb: 30
- name: Get UID and GID
id: ids
run: |
echo "uid=$(id -u)" >> $GITHUB_OUTPUT
echo "gid=$(id -g)" >> $GITHUB_OUTPUT
# Otherwise we run out of disk space with Docker build
- name: Free disk space
if: matrix.should_run == true
shell: bash
run: ./scripts/ci/linux_util_free_space.sh
- name: Restore cached build
if: matrix.should_run == true
uses: actions/cache@v4
with:
path: |
~/.cabal/store
dist-newstyle
key: ubuntu-${{ matrix.os }}-${{ matrix.arch }}-ghc${{ matrix.ghc }}-${{ hashFiles('cabal.project', 'simplex-chat.cabal') }}
- name: Set up Docker Buildx
if: matrix.should_run == true
uses: simplex-chat/docker-setup-buildx-action@v3
- name: Build and cache Docker image
if: matrix.should_run == true
uses: simplex-chat/docker-build-push-action@v6
with:
context: .
load: true
file: Dockerfile.build
tags: build/${{ matrix.os }}:latest
build-args: |
TAG=${{ matrix.os }}
HASH=${{ matrix.hash }}
GHC=${{ matrix.ghc }}
USER_UID=${{ steps.ids.outputs.uid }}
USER_GID=${{ steps.ids.outputs.gid }}
# Docker needs these flags for AppImage build:
# --device /dev/fuse
# --cap-add SYS_ADMIN
# --security-opt apparmor:unconfined
- name: Start container
if: matrix.should_run == true
shell: bash
run: |
docker run -t -d \
--device /dev/fuse \
--cap-add SYS_ADMIN \
--security-opt apparmor:unconfined \
--name builder \
-v ~/.cabal:/root/.cabal \
-v /home/runner/work/_temp:/home/runner/work/_temp \
-v ${{ github.workspace }}:/project \
build/${{ matrix.os }}:latest
- name: Prepare cabal.project.local
if: matrix.should_run == true
shell: bash
run: |
echo "ignore-project: False" >> cabal.project.local
echo "package direct-sqlcipher" >> cabal.project.local
echo " flags: +openssl" >> cabal.project.local
# chmod/git commands are used to workaround permission issues when cache is restored
- name: Build CLI
if: matrix.should_run == true
shell: docker exec -t builder sh -eu {0}
run: |
cabal clean
cabal update
cabal build -j --enable-tests
mkdir -p /out
for i in simplex-chat simplex-chat-test; do
bin=$(find /project/dist-newstyle -name "$i" -type f -executable)
chmod +x "$bin"
mv "$bin" /out/
done
strip /out/simplex-chat
- name: Build CLI deb
if: matrix.should_run == true
shell: docker exec -t builder sh -eu {0}
run: |
# Built from a branch, not from a tag, so take the version from the app itself
version=$(sed -n 's/^android.version_name=//p' apps/multiplatform/gradle.properties)
./scripts/desktop/build-cli-deb.sh "$version"
- name: Copy tests from container
if: matrix.should_run == true
shell: bash
run: |
docker cp builder:/out/simplex-chat-test .
- name: Copy CLI from container and prepare it
id: linux_cli_prepare
if: matrix.should_run == true
shell: bash
run: |
cli_name="simplex-chat-ubuntu-${{ matrix.os_underscore }}-${{ matrix.arch }}"
cli_deb_name="${cli_name}.deb"
cli_path="${{ github.workspace }}"
docker cp builder:/out/simplex-chat "./${cli_name}"
docker cp builder:/out/deb-build/simplex-chat.deb "./${cli_deb_name}"
echo "bin_name=${cli_name}" >> $GITHUB_OUTPUT
echo "bin_path=${cli_path}/${cli_name}" >> $GITHUB_OUTPUT
echo "bin_hash=$(echo SHA2-256\(${cli_name}\)= $(openssl sha256 "${cli_path}/${cli_name}" | cut -d' ' -f 2))" >> $GITHUB_OUTPUT
echo "deb_name=${cli_deb_name}" >> $GITHUB_OUTPUT
echo "deb_path=${cli_path}/${cli_deb_name}" >> $GITHUB_OUTPUT
echo "deb_hash=$(echo SHA2-256\(${cli_deb_name}\)= $(openssl sha256 "${cli_path}/${cli_deb_name}" | cut -d' ' -f 2))" >> $GITHUB_OUTPUT
# Nothing is attached to the release from a branch, the assets are uploaded as workflow
# artifacts, each named after the release asset it has to replace
- name: Upload CLI
if: matrix.should_run == true
uses: actions/upload-artifact@v4
with:
name: ${{ steps.linux_cli_prepare.outputs.bin_name }}
path: ${{ steps.linux_cli_prepare.outputs.bin_path }}
if-no-files-found: error
- name: Upload CLI deb
if: matrix.should_run == true
uses: actions/upload-artifact@v4
with:
name: ${{ steps.linux_cli_prepare.outputs.deb_name }}
path: ${{ steps.linux_cli_prepare.outputs.deb_path }}
if-no-files-found: error
- name: Build Desktop
if: matrix.should_run == true
shell: docker exec -t builder sh -eu {0}
run: |
export ASSETS_DIR='../../assets'
scripts/desktop/make-deb-linux.sh
- name: Prepare Desktop
id: linux_desktop_build
if: matrix.should_run == true
shell: bash
run: |
path=$(echo ${{ github.workspace }}/apps/multiplatform/release/main/deb/simplex_${{ matrix.arch }}.deb )
echo "package_name=simplex-desktop-ubuntu-${{ matrix.os_underscore }}-${{ matrix.arch }}.deb" >> $GITHUB_OUTPUT
echo "package_path=$path" >> $GITHUB_OUTPUT
echo "package_hash=$(echo SHA2-256\(simplex-desktop-ubuntu-${{ matrix.os_underscore }}-${{ matrix.arch }}.deb\)= $(openssl sha256 $path | cut -d' ' -f 2))" >> $GITHUB_OUTPUT
- name: Upload Desktop
uses: actions/upload-artifact@v4
if: matrix.should_run == true
with:
name: ${{ steps.linux_desktop_build.outputs.package_name }}
path: ${{ steps.linux_desktop_build.outputs.package_path }}
if-no-files-found: error
- name: Build AppImage
if: matrix.os == '22.04' && matrix.should_run == true
shell: docker exec -t builder sh -eu {0}
run: |
export ASSETS_DIR='../../assets'
scripts/desktop/make-appimage-linux.sh
- name: Prepare AppImage
id: linux_appimage_build
if: matrix.os == '22.04' && matrix.should_run == true
shell: bash
run: |
path=$(echo ${{ github.workspace }}/apps/multiplatform/release/main/*imple*.AppImage)
echo "appimage_name=simplex-desktop-${{ matrix.arch }}.AppImage" >> $GITHUB_OUTPUT
echo "appimage_path=$path" >> $GITHUB_OUTPUT
echo "appimage_hash=$(echo SHA2-256\(simplex-desktop-${{ matrix.arch }}.AppImage\)= $(openssl sha256 $path | cut -d' ' -f 2))" >> $GITHUB_OUTPUT
- name: Upload AppImage
if: matrix.os == '22.04' && matrix.should_run == true
uses: actions/upload-artifact@v4
with:
name: ${{ steps.linux_appimage_build.outputs.appimage_name }}
path: ${{ steps.linux_appimage_build.outputs.appimage_path }}
if-no-files-found: error
# The hashes in the release notes are of the bare files, not of the artifact zips
- name: Print hashes
if: matrix.should_run == true
shell: bash
run: |
{
echo '```'
echo "${{ steps.linux_cli_prepare.outputs.bin_hash }}"
echo "${{ steps.linux_cli_prepare.outputs.deb_hash }}"
echo "${{ steps.linux_desktop_build.outputs.package_hash }}"
echo "${{ steps.linux_appimage_build.outputs.appimage_hash }}"
echo '```'
} >> $GITHUB_STEP_SUMMARY
- name: Fix permissions for cache
if: matrix.should_run == true
shell: bash
run: |
sudo chmod -R 777 dist-newstyle ~/.cabal
sudo chown -R $(id -u):$(id -g) dist-newstyle ~/.cabal
- name: Run tests
if: matrix.should_run == true && matrix.arch == 'x86_64'
timeout-minutes: 120
shell: bash
run: |
i=1
attempts=1
${{ (github.ref == 'refs/heads/stable' || startsWith(github.ref, 'refs/tags/v')) }} && attempts=3
while [ "$i" -le "$attempts" ]; do
if ./simplex-chat-test; then
break
else
echo "Attempt $i failed, retrying..."
i=$((i + 1))
sleep 1
fi
done
if [ "$i" -gt "$attempts" ]; then
echo "All "$attempts" attempts failed."
exit 1
fi