Three independent pg-tools step failures on the 5th release run: - Linux: 'ar: libpgcommon_srv.a: file format not recognized' — parallel `make -C` tool builds race each other's recursion into src/common (rm -f / ar crs on the same archive). Pre-build generated-headers + libpq (which pulls in common/port) serially so the -j tool builds find the archives up to date. - macOS x86_64: strchrnul marked 'introduced in macOS 15.4' by Xcode 16.4 fails -Werror=unguarded-availability-new and would crash at runtime on macOS < 15.4. Force ac_cv_func_strchrnul=no and rename PG16's inline fallback (pg_strchrnul) so it compiles on any SDK without touching the system symbol. - Windows: EDB pg_dump.exe needs libcrypto/libssl/libiconv/libintl/ libwinpthread/liblz4/libzstd/ICU DLLs; copy every bin/*.dll, not just libpq.dll. All three verified locally (macOS: full build + tools run from resource dir; YAML + bash -n for all platform variants).
184 lines
8.7 KiB
YAML
184 lines
8.7 KiB
YAML
name: Release
|
|
|
|
# Builds Gridline installers for macOS (Apple Silicon + Intel), Windows, and
|
|
# Linux, then uploads them to a draft GitHub Release.
|
|
#
|
|
# Trigger: push a version tag from the `prod` branch (production), e.g.
|
|
# git checkout prod && git pull
|
|
# git tag v0.5.0 && git push origin v0.5.0
|
|
#
|
|
# SIGNING STATUS: builds are UNSIGNED for now (no code-signing certs yet —
|
|
# see README "Download a release"). tauri-action automatically signs +
|
|
# notarizes when the signing secrets are present, so the moment we add
|
|
# APPLE_CERTIFICATE / APPLE_API_KEY / WINDOWS_CERTIFICATE (or Azure Trusted
|
|
# Signing) to repo secrets, future builds are signed — no changes to this
|
|
# file required.
|
|
|
|
on:
|
|
push:
|
|
tags:
|
|
- 'v*'
|
|
|
|
permissions:
|
|
contents: write
|
|
|
|
jobs:
|
|
publish:
|
|
strategy:
|
|
fail-fast: false
|
|
matrix:
|
|
include:
|
|
- platform: macos-latest # Apple Silicon (M1/M2/M3+)
|
|
args: --target aarch64-apple-darwin
|
|
- platform: macos-15-intel # Intel Macs (last Intel runner; retired ~Aug 2027)
|
|
args: --target x86_64-apple-darwin
|
|
- platform: ubuntu-22.04 # Linux x86_64 (.deb / .rpm / .AppImage)
|
|
args: ''
|
|
- platform: windows-latest # Windows x86_64 (NSIS .exe + .msi)
|
|
args: ''
|
|
runs-on: ${{ matrix.platform }}
|
|
steps:
|
|
- name: Checkout
|
|
uses: actions/checkout@v4
|
|
|
|
- name: Install Linux dependencies
|
|
if: matrix.platform == 'ubuntu-22.04'
|
|
run: |
|
|
sudo apt-get update
|
|
sudo apt-get install -y libwebkit2gtk-4.1-dev libappindicator3-dev librsvg2-dev patchelf
|
|
|
|
- name: Set up Bun
|
|
uses: oven-sh/setup-bun@v2
|
|
|
|
- name: Set up Rust
|
|
uses: dtolnay/rust-toolchain@stable
|
|
with:
|
|
targets: aarch64-apple-darwin, x86_64-apple-darwin
|
|
|
|
- name: Cache Rust build artifacts
|
|
uses: swatinem/rust-cache@v2
|
|
with:
|
|
workspaces: './src-tauri -> target'
|
|
|
|
- name: Install frontend dependencies
|
|
run: bun install --frozen-lockfile
|
|
|
|
- name: Build PostgreSQL client tools (bundled)
|
|
shell: bash
|
|
run: |
|
|
set -euo pipefail
|
|
PG_VER="16.4"
|
|
OUT="${GITHUB_WORKSPACE}/src-tauri/resources/pg_tools"
|
|
mkdir -p "$OUT"
|
|
case "${{ matrix.platform }}" in
|
|
ubuntu-22.04)
|
|
sudo apt-get update -y
|
|
sudo apt-get install -y build-essential libreadline-dev zlib1g-dev flex bison patchelf
|
|
curl -fsSL "https://ftp.postgresql.org/pub/source/v${PG_VER}/postgresql-${PG_VER}.tar.bz2" -o /tmp/pg.tar.bz2
|
|
tar -xf /tmp/pg.tar.bz2 -C /tmp
|
|
cd /tmp/postgresql-${PG_VER}
|
|
./configure --prefix=/tmp/pgbuild --without-readline --without-icu CFLAGS="-O2"
|
|
# Build the shared prerequisites (catalog headers + libpq/common/
|
|
# port archives) SERIALLY FIRST. Parallel `make -C` runs recurse
|
|
# into src/common concurrently and race `rm -f` / `ar crs` on the
|
|
# same .a — intermittently failing with 'ar: libpgcommon_srv.a:
|
|
# file format not recognized'. Once the archives exist, the tools'
|
|
# -j builds find them up to date and those recursions are no-ops.
|
|
make -C src/backend generated-headers
|
|
make -C src/interfaces/libpq all
|
|
make -j"$(nproc)" -C src/bin/pg_dump all
|
|
make -j"$(nproc)" -C src/bin/psql all
|
|
cp src/bin/pg_dump/pg_dump src/bin/pg_dump/pg_restore "$OUT"/
|
|
cp src/bin/psql/psql "$OUT"/
|
|
# pg_dump links shared libpq (PG16 has no --disable-shared for the
|
|
# client tools); bundle libpq.so alongside and point the loader at
|
|
# the app's resource dir via $ORIGIN rpath.
|
|
cp src/interfaces/libpq/libpq.so.5 "$OUT"/libpq.so.5
|
|
for b in pg_dump pg_restore psql; do
|
|
patchelf --set-rpath '$ORIGIN' "$OUT/$b"
|
|
done
|
|
;;
|
|
macos-latest|macos-15-intel)
|
|
curl -fsSL "https://ftp.postgresql.org/pub/source/v${PG_VER}/postgresql-${PG_VER}.tar.bz2" -o /tmp/pg.tar.bz2
|
|
tar -xf /tmp/pg.tar.bz2 -C /tmp
|
|
cd /tmp/postgresql-${PG_VER}
|
|
# ac_cv_func_strchrnul=no: Xcode 16.4's SDK marks strchrnul as
|
|
# introduced in macOS 15.4, so configure detects it and PG's
|
|
# snprintf.c calls the system symbol — which fails to compile
|
|
# (-Werror=unguarded-availability-new) and would crash at runtime
|
|
# on macOS < 15.4. Forcing the check off makes PG use its own
|
|
# inline fallback instead.
|
|
ac_cv_func_strchrnul=no ./configure --prefix=/tmp/pgbuild --without-readline --without-icu CFLAGS="-O2"
|
|
# macOS SDKs always declare strchrnul in <string.h> (Xcode 16.4
|
|
# marks it 'introduced in macOS 15.4'), so even with HAVE_STRCHRNUL
|
|
# disabled PG16's static-inline fallback would collide with the
|
|
# header declaration on newer SDKs. Rename PG's fallback so the
|
|
# tools compile on any SDK and never touch the (15.4+ only)
|
|
# system symbol.
|
|
sed -i '' 's/strchrnul/pg_strchrnul/g' src/port/snprintf.c
|
|
# Serial shared-prerequisite build first (see the Linux block: the
|
|
# archives must exist before the -j tool builds recurse into
|
|
# src/common).
|
|
make -C src/backend generated-headers
|
|
make -C src/interfaces/libpq all
|
|
make -j"$(sysctl -n hw.ncpu)" -C src/bin/pg_dump all
|
|
make -j"$(sysctl -n hw.ncpu)" -C src/bin/psql all
|
|
cp src/bin/pg_dump/pg_dump src/bin/pg_dump/pg_restore "$OUT"/
|
|
cp src/bin/psql/psql "$OUT"/
|
|
cp src/interfaces/libpq/libpq.5.dylib "$OUT"/libpq.5.dylib
|
|
# Rewrite the absolute /tmp/pgbuild libpq install_name to a
|
|
# relative @loader_path so the tools find libpq next to themselves.
|
|
for b in pg_dump pg_restore psql; do
|
|
libpq=$(otool -L "$OUT/$b" | awk '/libpq/ {print $1; exit}')
|
|
install_name_tool -change "$libpq" "@loader_path/libpq.5.dylib" "$OUT/$b"
|
|
done
|
|
;;
|
|
windows-latest)
|
|
URL="https://get.enterprisedb.com/postgresql/postgresql-${PG_VER}-1-windows-x64-binaries.zip"
|
|
curl -fsSL "$URL" -o /tmp/pg.zip
|
|
EXPECTED="3508d8f085bc3980f38211a82e3f31e5fcae9952105d3dc2f8be67b64a822baa"
|
|
echo "$EXPECTED /tmp/pg.zip" | sha256sum -c -
|
|
sha256sum /tmp/pg.zip
|
|
unzip -o /tmp/pg.zip -d /tmp/pg
|
|
cp /tmp/pg/pgsql/bin/pg_dump.exe /tmp/pg/pgsql/bin/pg_restore.exe /tmp/pg/pgsql/bin/psql.exe "$OUT"/
|
|
# pg_dump.exe needs far more than libpq.dll (libcrypto-3-x64.dll,
|
|
# libssl-3-x64.dll, libiconv-2.dll, libintl-9.dll,
|
|
# libwinpthread-1.dll, liblz4.dll, libzstd.dll, ICU DLLs, ...);
|
|
# copy every DLL next to the tools.
|
|
cp /tmp/pg/pgsql/bin/*.dll "$OUT"/
|
|
;;
|
|
esac
|
|
(cd "$OUT" && sha256sum * | tee checksums.txt)
|
|
# Resolve the per-platform binary suffix WITHOUT a command
|
|
# substitution: `$( [ ... ] && echo .exe )` returns exit 1 when the
|
|
# test is false, and under `set -e` that aborts the whole step.
|
|
if [ "${{ matrix.platform }}" = windows-latest ]; then
|
|
BIN_EXT=".exe"
|
|
else
|
|
BIN_EXT=""
|
|
fi
|
|
for b in pg_dump pg_restore psql; do
|
|
f="$OUT/${b}${BIN_EXT}"
|
|
test -f "$f" || { echo "missing $f"; exit 1; }
|
|
done
|
|
# Sanity: every tool must run (loader path is correct) — this catches
|
|
# a wrong @loader_path / rpath before we ship a broken bundle.
|
|
for b in pg_dump pg_restore psql; do
|
|
"$OUT/${b}${BIN_EXT}" --version >/dev/null 2>&1 || { echo "$b failed to run from resource dir"; exit 1; }
|
|
done
|
|
|
|
- name: Build and upload to GitHub Release
|
|
uses: tauri-apps/tauri-action@v0
|
|
env:
|
|
GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }}
|
|
with:
|
|
tagName: ${{ github.ref_name }}
|
|
releaseName: 'Gridline ${{ github.ref_name }}'
|
|
releaseDraft: true
|
|
args: ${{ matrix.args }}
|
|
# Version-free asset names (see README Download section): the README
|
|
# links via GitHub's releases/latest/download/<file> redirect, which
|
|
# only works if filenames are identical across releases. Omitting
|
|
# [version] gives stable names: Gridline_darwin_aarch64.dmg,
|
|
# Gridline_windows_x64-setup.exe, Gridline_linux_amd64.deb, etc.
|
|
releaseAssetNamePattern: '[name]_[platform]_[arch][setup][ext]' |