mirror of
https://relay.ngit.dev/npub15qydau2hjma6ngxkl2cyar74wzyjshvl65za5k5rl69264ar2exs5cyejr/ngit-grasp.git
synced 2026-10-05 15:08:24 +00:00
Crates.io publication is a manual release step even though Nostr CI already validates tagged commits. Publish after the existing lint, formatting and test steps succeed, using a repository-scoped CARGO_REGISTRY_TOKEN secret only in the publication step. Require a push event on a v-prefixed tag and an exact manifest-version match. Use Cargo package verification and --locked against the explicit crates-io registry. Only ngit-grasp is selected; grasp-audit remains unpublished. This assumes the coordinator has the scoped token configured and the tagged commit contains this workflow. It does not change archive/NIP-82 publication, stable promotion, documentation sync or registry versions; no live crate was uploaded during development. Validated workflow syntax with actionlint, matching/mismatched tag and missing-secret cases with an intercepted publish command, Cargo packaging without upload, cargo fmt --all -- --check, and git diff --cached --check.
82 lines
3.8 KiB
YAML
82 lines
3.8 KiB
YAML
# Docs-only pushes are skipped: a push runs only when at least one changed
|
|
# file falls outside the ignore list, so mixed code+docs pushes still run.
|
|
# Tag pushes always run regardless of path filters, and pull_request stays
|
|
# unfiltered because ngit-ci does not evaluate PR path filters yet (filtered
|
|
# PR triggers would run unconditionally anyway).
|
|
on:
|
|
push:
|
|
paths-ignore:
|
|
- "docs/**"
|
|
- "**/*.md"
|
|
- "work/**"
|
|
pull_request:
|
|
|
|
name: Rust CI
|
|
|
|
jobs:
|
|
ci:
|
|
runs-on: ubuntu-latest
|
|
timeout-minutes: 30
|
|
steps:
|
|
- uses: actions/checkout@v5
|
|
- uses: cachix/install-nix-action@v31
|
|
with:
|
|
nix_path: nixpkgs=channel:nixos-unstable
|
|
- name: Restore Nix store cache
|
|
continue-on-error: true
|
|
uses: nix-community/cache-nix-action@v7
|
|
with:
|
|
primary-key: nix-${{ runner.os }}-${{ hashFiles('**/*.nix', 'flake.lock') }}
|
|
restore-prefixes-first-match: nix-${{ runner.os }}-
|
|
# cache-nix-action requires a token even with purge disabled;
|
|
# github.token is empty under ngit-ci, so any non-empty value works.
|
|
token: unused
|
|
- name: Restore Rust build cache
|
|
continue-on-error: true
|
|
uses: actions/cache@v4
|
|
with:
|
|
path: |
|
|
~/.cargo/git
|
|
~/.cargo/registry
|
|
target
|
|
key: rust-${{ runner.os }}-${{ hashFiles('**/Cargo.toml', 'Cargo.lock', 'flake.lock') }}
|
|
restore-keys: |
|
|
rust-${{ runner.os }}-
|
|
# The suite must be hermetic with respect to ambient git configuration,
|
|
# so CI always runs it under a deliberately hostile global config: a
|
|
# failing pre-commit hook delivered via both core.hooksPath and
|
|
# init.templateDir, plus the settings that have bitten before. The
|
|
# settings target test-side git only: the relay never runs `git commit`,
|
|
# so its server-side operations are unaffected except for
|
|
# init.defaultBranch, which is exactly the regression being guarded.
|
|
# (The hermetic helpers make the tests themselves config-blind, so this
|
|
# single run also covers hosts where these settings are unset.)
|
|
- name: Install hostile git configuration
|
|
run: |
|
|
mkdir -p /tmp/hostile-git/hooks /tmp/hostile-git/template/hooks
|
|
printf '#!/bin/sh\necho "hostile hook: ambient git config leaked into a test" >&2\nexit 1\n' \
|
|
| tee /tmp/hostile-git/hooks/pre-commit > /tmp/hostile-git/template/hooks/pre-commit
|
|
chmod +x /tmp/hostile-git/hooks/pre-commit /tmp/hostile-git/template/hooks/pre-commit
|
|
git config --global init.defaultBranch main
|
|
git config --global core.hooksPath /tmp/hostile-git/hooks
|
|
git config --global init.templateDir /tmp/hostile-git/template
|
|
git config --global commit.gpgsign true
|
|
git config --global core.autocrlf true
|
|
- run: nix develop --command cargo fmt --all -- --check
|
|
- run: nix develop --command cargo clippy --workspace --all-targets -- -D warnings
|
|
- run: nix develop --command cargo test --locked
|
|
- run: nix develop --command cargo test -p grasp-audit --locked
|
|
- name: Publish release tag to crates.io
|
|
if: github.event_name == 'push' && startsWith(github.ref, 'refs/tags/v')
|
|
env:
|
|
CARGO_REGISTRY_TOKEN: ${{ secrets.CARGO_REGISTRY_TOKEN }}
|
|
run: |
|
|
set -euo pipefail
|
|
version="$(nix eval --impure --raw --expr '(builtins.fromTOML (builtins.readFile ./Cargo.toml)).package.version')"
|
|
if [[ "$GITHUB_REF" != "refs/tags/v$version" ]]; then
|
|
echo "release tag must match Cargo.toml version v$version" >&2
|
|
exit 1
|
|
fi
|
|
: "${CARGO_REGISTRY_TOKEN:?Configure the repository CARGO_REGISTRY_TOKEN secret in ngit-ci}"
|
|
nix develop --command cargo publish --locked --registry crates-io --package ngit-grasp
|