Files
MetaCrate/.gitea/workflows/artifact-audit.yml
Chili Palmer b399645430
Some checks failed
API and SemVer surface / api-surface (push) Has been cancelled
Native release artifact audit / audit (push) Has been cancelled
Native code generation / deterministic (push) Has been cancelled
Concurrency and resource soak audit / soak (push) Has been cancelled
Documentation / documentation (push) Has been cancelled
performance evidence / audit (push) Has been cancelled
First release candidate / non-fuzz-release-gate (push) Has been cancelled
Release platform and feature matrix / audit (push) Has been cancelled
Release platform and feature matrix / matrix (false, linux-stable-minimal, x86_64-unknown-linux-gnu, stable) (push) Has been cancelled
Release platform and feature matrix / matrix (false, macos-stable-portable, x86_64-apple-darwin, stable) (push) Has been cancelled
Release platform and feature matrix / matrix (false, windows-stable-portable, x86_64-pc-windows-gnu, stable) (push) Has been cancelled
Release platform and feature matrix / matrix (true, linux-msrv-portable, x86_64-unknown-linux-gnu, 1.96.0) (push) Has been cancelled
Release platform and feature matrix / matrix (true, linux-stable-default, x86_64-unknown-linux-gnu, stable) (push) Has been cancelled
Release platform and feature matrix / matrix (true, linux-stable-features, x86_64-unknown-linux-gnu, stable) (push) Has been cancelled
Release platform and feature matrix / matrix (true, linux-stable-release-surface, x86_64-unknown-linux-gnu, stable) (push) Has been cancelled
Dependency and supply-chain audit / audit (push) Has been cancelled
Repair Gitea release workflows (#107)
2026-08-12 14:57:10 +00:00

96 lines
3.4 KiB
YAML

name: Native release artifact audit
on:
push:
paths:
- ".gitea/workflows/artifact-audit.yml"
- "ci/artifact-policy.json"
- "ci/dependency-policy.json"
- "ci/provenance-policy.json"
- "tools/ci-matrix/**"
- "tools/install_openjpeg_2_5_4.sh"
- "docs/release-artifacts.md"
- "Cargo.toml"
- "Cargo.lock"
- "crates/**"
- "programs/**"
pull_request:
paths:
- ".gitea/workflows/artifact-audit.yml"
- "ci/artifact-policy.json"
- "ci/dependency-policy.json"
- "ci/provenance-policy.json"
- "tools/ci-matrix/**"
- "tools/install_openjpeg_2_5_4.sh"
- "docs/release-artifacts.md"
- "Cargo.toml"
- "Cargo.lock"
- "crates/**"
- "programs/**"
workflow_dispatch:
env:
CARGO_BUILD_JOBS: 1
CARGO_INCREMENTAL: 0
CARGO_PROFILE_RELEASE_OPT_LEVEL: 0
FORCE_SKIA_BINARIES_DOWNLOAD: 1
OPENJPEG_PREFIX: /tmp/metacrate-openjpeg-artifact-audit
PKG_CONFIG_PATH: /tmp/metacrate-openjpeg-artifact-audit/lib/pkgconfig
LD_LIBRARY_PATH: /tmp/metacrate-openjpeg-artifact-audit/lib
jobs:
audit:
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@v4
- uses: dtolnay/rust-toolchain@master
with:
toolchain: 1.97.1
- name: Install documented native prerequisites
run: |
sudo apt-get update
sudo apt-get install --yes build-essential clang cmake curl ninja-build pkg-config python3 libfontconfig1-dev libfreetype6-dev libopus-dev
tools/install_openjpeg_2_5_4.sh "$OPENJPEG_PREFIX"
pkg-config --exact-version 2.5.4 libopenjp2
pkg-config --modversion opus
- name: Record source identity without a shipped build helper
run: echo "METACRATE_RUST_COMMIT=$(git rev-parse --verify HEAD)" >>"$GITHUB_ENV"
- name: Fetch the locked dependency graph
run: cargo fetch --locked
- name: Create every release source package atomically
run: |
cargo package --locked --no-verify \
-p libremetaverse-types \
-p libremetaverse-structured-data \
-p libremetaverse-imaging \
-p libremetaverse-imaging-skia \
-p libremetaverse-openjpeg \
-p libremetaverse-opus \
-p libremetaverse-prim-mesher \
-p libremetaverse-lsl-tools \
-p libremetaverse \
-p libremetaverse-rendering-simple \
-p libremetaverse-rendering-mesh-foundry \
-p libremetaverse-rlv \
-p libremetaverse-utilities \
-p libremetaverse-voice-vivox \
-p libremetaverse-voice-webrtc \
-p libremetaverse-programs
- name: Build every shipped native executable
run: cargo build --locked --release -j 1 -p libremetaverse-programs --bins
- name: Inspect packages, binaries, links, and offline runtime behavior
run: |
cargo run --locked -p metacrate-ci-matrix -- artifact-audit \
--artifact-dir target/release \
--package-dir target/package \
--evidence artifacts/release/artifact-audit.json
- name: Upload immutable audit evidence and source packages
if: always()
uses: actions/upload-artifact@v3
with:
name: native-release-artifact-audit
path: |
artifacts/release/artifact-audit.json
target/package/*.crate
if-no-files-found: error