Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
10 changes: 9 additions & 1 deletion .github/moon.yml
Original file line number Diff line number Diff line change
Expand Up @@ -35,11 +35,16 @@ tasks:
cache: true
runFromWorkspaceRoot: true
check:
tags: ["policy", "assertion", "quality", "static", "requires-maintainer-tools"]
tags: ["policy", "assertion", "quality", "static", "requires-maintainer-tools", "requires-rust"]
command: "bash tools/ci/check-workflows.sh"
inputs:
- "/.moon/toolchains.yml"
- "/.moon/tasks/**/*"
- "/**/moon.yml"
- "/.prototools"
- "/rust-toolchain.toml"
- "/Cargo.lock"
- "/**/Cargo.toml"
- "/.github/actions/**/*"
- "/.github/scripts/**/*"
- "/.github/workflows/**/*"
Expand Down Expand Up @@ -69,6 +74,9 @@ tasks:
- "/tools/ci/affected.mts"
- "/tools/ci/ci_plan.mts"
- "/tools/ci/ci-plan.sh"
- "@group(package-test-metadata)"
- "/tools/release/product-version.mts"
- "/tools/release/with-product-history.sh"
- "/src/native/sdks/ts/tools/published-consumer.mts"
- "/src/native/sdks/ts/package.json"
- "/src/native/sdks/swift/tools/ios-carrier-manifest.mts"
Expand Down
44 changes: 28 additions & 16 deletions .github/workflows/ci.yml
Original file line number Diff line number Diff line change
Expand Up @@ -181,6 +181,11 @@ jobs:
restore-keys: |
ios-carrier-v1-${{ hashFiles('src/native/runtime/VERSION', 'src/native/sdks/swift/tools/ios-carrier-manifest.mts', 'tools/packaging/**', 'tools/release/**') }}-

- name: Set up Cargo for dependency metadata
uses: ./.github/actions/setup-rust
with:
cache: "false"

- name: Plan artifact builder jobs
id: plan
env:
Expand Down Expand Up @@ -242,6 +247,11 @@ jobs:
task-cache: "false"
install-workspace: "false"

- name: Set up Cargo for dependency metadata
uses: ./.github/actions/setup-rust
with:
cache: "false"

- name: Check release intent
env:
PR_TITLE: ${{ github.event.pull_request.title }}
Expand Down Expand Up @@ -1533,6 +1543,7 @@ jobs:

- name: Build Swift SDK package artifacts
env:
GH_TOKEN: ${{ github.token }}
OLIPHAUNT_SWIFT_RELEASE_ASSET_DIR: ${{ github.workspace }}/target/liboliphaunt/abi-compatible-release-assets/ios-datum64
OLIPHAUNT_MOON_TRANSFERRED_DEPS_JSON: '["liboliphaunt-native:finalize-runtime-ios-abi", "oliphaunt-swift:package-bindings"]'
run: OLIPHAUNT_CI_JOB_TARGETS_JSON='${{ needs.affected.outputs.job_targets }}' .github/scripts/run-planned-moon-job.sh swift-sdk-package
Expand Down Expand Up @@ -1659,6 +1670,7 @@ jobs:

- name: Build React Native SDK package artifacts
env:
GH_TOKEN: ${{ github.token }}
OLIPHAUNT_REACT_NATIVE_IOS_BASE_CARRIER: ${{ needs.affected.outputs.reuse_ios_carrier == 'true' && 'target/ci/ios-carrier/manifest.json' || '' }}
OLIPHAUNT_REACT_NATIVE_IOS_RELEASE_ASSET_DIR: ${{ github.workspace }}/target/liboliphaunt/abi-compatible-release-assets/ios-datum64
OLIPHAUNT_MOON_TRANSFERRED_DEPS_JSON: '["liboliphaunt-native:finalize-runtime-ios-abi"]'
Expand Down Expand Up @@ -2957,6 +2969,9 @@ jobs:
name: oliphaunt-mobile-extension-package-artifacts-android
path: target/extension-artifacts

- name: Stage workspace mobile qualification
run: tools/dev/bun.sh src/native/sdks/react-native/tools/stage-mobile-qualification.mts android target/extension-artifacts target/qualification/mobile-android

- name: Build Android mobile app
env:
OLIPHAUNT_EXPO_ALLOW_NATIVE_BUILDS: "0"
Expand All @@ -2967,7 +2982,7 @@ jobs:
OLIPHAUNT_EXPO_ANDROID_EXTENSIONS: ${{ needs.affected.outputs.extension_package_sql_names_csv }}
OLIPHAUNT_EXPO_ANDROID_ICU: "1"
OLIPHAUNT_EXPO_REQUIRE_PREBUILT_EXTENSIONS: "1"
OLIPHAUNT_EXPO_EXTENSION_ARTIFACT_ROOT: ${{ github.workspace }}/target/extension-artifacts
OLIPHAUNT_EXPO_EXTENSION_ARTIFACT_ROOT: ${{ github.workspace }}/target/qualification/mobile-android/extensions
OLIPHAUNT_EXPO_ANDROID_OLIPHAUNT_SO: ${{ github.workspace }}/${{ matrix.build-root }}/out/liboliphaunt.so
OLIPHAUNT_EXPO_ANDROID_RUNTIME_DIR: ${{ github.workspace }}/target/liboliphaunt-mobile-host/${{ matrix.target }}/install
OLIPHAUNT_MOON_TRANSFERRED_DEPS_JSON: '["oliphaunt-query-ts:package", "database-resources:package-icu", "database-resources:build-native-android-icu", "extension-packages:package-mobile", "liboliphaunt-native:package-runtime-android-x86_64", "liboliphaunt-native:finalize-runtime-android-abi", "oliphaunt-kotlin:package", "oliphaunt-react-native:package"]'
Expand Down Expand Up @@ -3007,7 +3022,7 @@ jobs:
runs-on: macos-26
timeout-minutes: 180
env:
OLIPHAUNT_EXTENSION_ARTIFACT_ROOT: ${{ github.workspace }}/target/mobile-extension-artifacts
OLIPHAUNT_EXTENSION_ARTIFACT_ROOT: ${{ github.workspace }}/target/qualification/mobile-ios/extensions
steps:
- name: Checkout repository
uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd
Expand Down Expand Up @@ -3114,17 +3129,12 @@ jobs:
name: oliphaunt-mobile-extension-package-artifacts-ios
path: target/mobile-extension-artifacts

- name: Render exact-SHA cache-warm iOS carrier manifest
run: |
tools/dev/bun.sh src/native/sdks/swift/tools/ios-carrier-manifest.mts \
--base-asset-dir target/liboliphaunt/release-assets \
--extension-root target/mobile-extension-artifacts \
--output target/release/ios-carriers/oliphaunt-react-native-ios-carriers.json \
--local-urls
- name: Stage workspace mobile qualification
run: tools/dev/bun.sh src/native/sdks/react-native/tools/stage-mobile-qualification.mts ios target/mobile-extension-artifacts target/qualification/mobile-ios

- name: Qualify every exact iOS carrier
env:
IOS_CARRIER_MANIFEST: target/release/ios-carriers/oliphaunt-react-native-ios-carriers.json
IOS_CARRIER_MANIFEST: target/qualification/mobile-ios/ios-carriers/oliphaunt-react-native-ios-carriers.json
IOS_CARRIER_STAGE: target/qualification/react-native-ios-all-carriers
IOS_CARRIER_CACHE: target/qualification/react-native-ios-carrier-cache
PLANNED_EXTENSION_SQL_NAMES: ${{ needs.affected.outputs.extension_package_sql_names_csv }}
Expand All @@ -3135,15 +3145,16 @@ jobs:
env:
CI_HEAD_SHA: ${{ github.event.pull_request.head.sha || github.sha }}
OLIPHAUNT_SWIFT_NATIVE_ASSET_DIR: ${{ github.workspace }}/target/liboliphaunt/release-assets
OLIPHAUNT_SWIFT_SDK_ARTIFACT_DIR: ${{ github.workspace }}/target/sdk-artifacts/oliphaunt-swift
OLIPHAUNT_SWIFT_SDK_ARTIFACT_DIR: ${{ github.workspace }}/target/qualification/mobile-ios/swift-sdk
PLANNED_EXTENSION_PRODUCTS: ${{ needs.affected.outputs.extension_package_products_csv }}
run: |
source_carrier=target/sdk-artifacts/oliphaunt-swift/release-tree/src/sdks/swift/Carriers/oliphaunt-react-native-ios-carriers.json
published_source_carrier=target/sdk-artifacts/oliphaunt-swift/release-tree/src/sdks/swift/Carriers/oliphaunt-react-native-ios-carriers.json
source_carrier="$OLIPHAUNT_SWIFT_SDK_ARTIFACT_DIR/release-tree/src/sdks/swift/Carriers/oliphaunt-react-native-ios-carriers.json"
react_native_source_carrier=target/sdk-artifacts/oliphaunt-react-native/ios-carriers/oliphaunt-react-native-ios-carriers.json
cache_warm_carrier=target/release/ios-carriers/oliphaunt-react-native-ios-carriers.json
if ! cmp -s "$source_carrier" "$react_native_source_carrier"; then
cache_warm_carrier=target/qualification/mobile-ios/ios-carriers/oliphaunt-react-native-ios-carriers.json
if ! cmp -s "$published_source_carrier" "$react_native_source_carrier"; then
echo 'Swift and React Native package artifacts disagree on the selection-neutral source carrier.' >&2
diff -u "$source_carrier" "$react_native_source_carrier" || true
diff -u "$published_source_carrier" "$react_native_source_carrier" || true
exit 1
fi
consumer_args=(
Expand All @@ -3153,6 +3164,7 @@ jobs:
evidence_dir=target/release/ios-carriers/qualification/swift-independent-carriers
mkdir -p "$evidence_dir"
cp "$source_carrier" "$evidence_dir/selection-neutral-source-carrier.json"
cp "$published_source_carrier" "$evidence_dir/swift-published-selection-neutral-source-carrier.json"
cp "$react_native_source_carrier" "$evidence_dir/react-native-selection-neutral-source-carrier.json"

product_count=0
Expand Down Expand Up @@ -3199,7 +3211,7 @@ jobs:
OLIPHAUNT_EXPO_REQUIRE_PREBUILT_EXTENSIONS: "1"
OLIPHAUNT_EXPO_IOS_OLIPHAUNT_XCFRAMEWORK: ${{ github.workspace }}/target/liboliphaunt-ios-xcframework/out/liboliphaunt.xcframework
OLIPHAUNT_EXPO_IOS_RUNTIME_DIR: ${{ github.workspace }}/target/liboliphaunt-mobile-host/ios-xcframework/install
OLIPHAUNT_REACT_NATIVE_IOS_BASE_CARRIER: ${{ github.workspace }}/target/release/ios-carriers/oliphaunt-react-native-ios-carriers.json
OLIPHAUNT_REACT_NATIVE_IOS_BASE_CARRIER: ${{ github.workspace }}/target/qualification/mobile-ios/ios-carriers/oliphaunt-react-native-ios-carriers.json
OLIPHAUNT_MOON_TRANSFERRED_DEPS_JSON: '["oliphaunt-query-ts:package", "database-resources:package-icu", "database-resources:build-native-ios-icu", "extension-packages:package-mobile", "liboliphaunt-native:package-runtime-ios-xcframework", "oliphaunt-react-native:package", "oliphaunt-swift:package"]'
run: OLIPHAUNT_CI_JOB_TARGETS_JSON='${{ needs.affected.outputs.job_targets }}' .github/scripts/run-planned-moon-job.sh mobile-build-ios

Expand Down
11 changes: 8 additions & 3 deletions .github/workflows/release.yml
Original file line number Diff line number Diff line change
Expand Up @@ -113,14 +113,15 @@ jobs:
with:
task-cache: "false"
install-workspace: "true"
- name: Set up Rust for dependency metadata and manifest synchronization
uses: ./.github/actions/setup-rust
with:
cache: "false"
- name: Generate the Release Please candidate locally
id: prepare_candidate
env:
GH_TOKEN: ${{ steps.release_pr_token.outputs.token }}
run: bash tools/release/prepare-release-pr.sh "$RUNNER_TEMP/release-candidate"
- name: Set up Rust for release manifest synchronization
if: ${{ steps.prepare_candidate.outputs.required == 'true' }}
uses: ./.github/actions/setup-rust
- name: Close and validate the local release candidate
if: ${{ steps.prepare_candidate.outputs.required == 'true' }}
run: bash tools/release/close-release-candidate.sh "$RUNNER_TEMP/release-candidate"
Expand Down Expand Up @@ -160,6 +161,10 @@ jobs:
with:
task-cache: "false"
install-workspace: "true"
- name: Set up Cargo for dependency metadata
uses: ./.github/actions/setup-rust
with:
cache: "false"
- name: Plan product releases
id: release_plan
run: |
Expand Down
4 changes: 3 additions & 1 deletion .moon/tasks/cargo.yml
Original file line number Diff line number Diff line change
Expand Up @@ -6,7 +6,9 @@ inheritedBy:
fileGroups:
cargo-sources:
- "src/**/*"
- "{Cargo.toml,build.rs}"
- "**/*.rs"
- "!**/{tests,benches,examples}/**"
- "Cargo.toml"

tasks:
# Cargo owns compilation. This command-free node only carries source hashes
Expand Down
51 changes: 51 additions & 0 deletions src/docs/maintainers/release.md
Original file line number Diff line number Diff line change
Expand Up @@ -155,6 +155,37 @@ contrib inputs may select both runtime owners because those source files are
physically bundled into both products. No Moon dependency edge creates another
release candidate.

Binary products declare `embedded_cargo_manifests` in their `release.toml`.
Release planning reads Cargo's versioned `metadata --no-deps --frozen` output
and follows local runtime, build, and target dependencies through independent
product boundaries. Cargo resolves workspace inheritance, renamed dependencies,
and custom library, binary, and build-script source paths. All optional and
target dependencies participate, so adding a platform does not require another
release-planner branch. Development dependencies stay local. This read requires
the pinned Cargo toolchain but never compiles, fetches registries, or changes a
lockfile; source planning and release preparation declare that capability.
The workspace Cargo manifest and lockfile conservatively select these binaries,
since dependency resolution and build settings also determine their shipped bytes.
This covers both Node addons, the native broker, and Swift/Kotlin native
bindings. Generated assets use `embedded_payload_products`: changes to an
embedded producer's sources, pins, or recipes also select the embedding binary.
Source-only facades and dynamically loaded runtimes retain independent releases.

For a new compiled SDK, declare its shipped Cargo root once. Dependencies then
follow the Cargo manifests, including new targets. Declare generated payload
producers separately because Cargo cannot infer external artifact generation.
Non-Cargo shared inputs belong in `shared_source_paths`. New source-only SDKs
need compatibility pins and package qualification without a compiled-source
root. The shared version-drift gate discovers producer products from every SDK's
compatibility declarations, so a new dependency enters the fixture automatically.
Every SDK must test its packager with an independently advanced producer; release
packaging preserves the consumer's exact pin, while a source fixture that uses
newer workspace bytes must identify those bytes and remain unpublishable.
Moon's shared Cargo source group includes Rust files throughout each project,
including custom source directories and build helpers. Inputs outside the Cargo
project, such as resources read by a build script, still need explicit Moon
inputs and release ownership.

Moon `production` and `peer` edges describe source and qualification impact.
Product-local `compatibility_versions` describe the exact published product
versions a carrier consumes. A native runtime can therefore be published
Expand All @@ -170,6 +201,26 @@ its exact product tag and registry/GitHub carriers. Selecting a newer dependency
does not satisfy an older consumer pin. Structured release-commit verification
also rejects source changes hidden inside compatibility-only edits.

Source qualification uses current workspace producers and identifies the
runtime actually compiled. If those producers differ from immutable release
pins, npm fixtures carry `qualificationOnly` and publication rejects them.
Release package tests retain their declared pins: Cargo uses a local source
patch only at the matching exact version and otherwise resolves the published
dependency. A WASIX TypeScript release must pair the portable runtime with an
addon embedding the same runtime version.
WASIX source builds resolve local extension archive versions from each staged
extension product manifest. External extension versions are independent of the
runtime; contrib manifests carry their owning runtime's version. Cargo tracks
those manifests so a changed extension identity refreshes its embedded bytes.
Swift and React Native carrier staging also retains the exact native pin.
React Native resolves that pin through its declared Swift release, including
immutable historical metadata when Swift has advanced. Older runtime pins use
verified published Apple archives; current pins require same-run producer assets.
Mobile app qualification stages private extension and Swift carrier fixtures
under `target/qualification` against the current workspace runtimes. It leaves
the release packages intact, retains payload hashes and exact runtime validation,
and marks extension fixtures `qualificationOnly` so publication rejects them.

PR CI recognizes generated `chore(release):` changes only on the generated
Release Please branch. Before merge it requires the release commit's parent to
equal the exact base SHA, derives the product set from the manifest diff, and
Expand Down
2 changes: 2 additions & 0 deletions src/examples/moon.yml
Original file line number Diff line number Diff line change
Expand Up @@ -84,6 +84,7 @@ tasks:
- project: "extensions"
group: "build"
- "/target/mobile-extension-artifacts/**/*"
- "/target/qualification/mobile-android/**/*"
- "/target/sdk-artifacts/oliphaunt-kotlin/**/*"
- "/target/sdk-artifacts/oliphaunt-react-native/**/*"
- "/src/native/runtime/packaging/**/*"
Expand Down Expand Up @@ -145,6 +146,7 @@ tasks:
- project: "extensions"
group: "build"
- "/target/mobile-extension-artifacts/**/*"
- "/target/qualification/mobile-ios/**/*"
- "/target/sdk-artifacts/oliphaunt-react-native/**/*"
- "/target/sdk-artifacts/oliphaunt-swift/**/*"
- "/src/native/runtime/packaging/**/*"
Expand Down
2 changes: 2 additions & 0 deletions src/extensions/artifacts/packages/moon.yml
Original file line number Diff line number Diff line change
Expand Up @@ -141,6 +141,8 @@ tasks:
- requires-rust
command: bash src/extensions/artifacts/packages/tools/test.sh
inputs:
- /src/native/sdks/swift/tools/ios-carrier-manifest.mts
- /src/native/sdks/swift/tools/swift-source-carrier-contract.mts
- /src/native/sdks/rust/crates/oliphaunt-build/src/**/*.rs
- /src/native/sdks/rust/crates/oliphaunt-build/Cargo.toml
- "@group(cargo-workspace)"
Expand Down
1 change: 1 addition & 0 deletions src/native/broker/release.toml
Original file line number Diff line number Diff line change
Expand Up @@ -14,6 +14,7 @@ registry_packages = [
"npm:@oliphaunt/broker-win32-x64-msvc",
]
release_artifacts = ["broker-helper-binary", "cargo-crate"]
embedded_cargo_manifests = ["src/native/broker/Cargo.toml"]

[compatibility_versions.broker_native_bindings]
source_product = "liboliphaunt-native-bindings"
Expand Down
1 change: 1 addition & 0 deletions src/native/node-addon/release.toml
Original file line number Diff line number Diff line change
Expand Up @@ -9,6 +9,7 @@ registry_packages = [
"npm:@oliphaunt/node-direct-win32-x64-msvc",
]
release_artifacts = ["node-api-prebuilds", "npm-optional-platform-packages"]
embedded_cargo_manifests = ["src/native/node-addon/Cargo.toml"]

[compatibility_versions.oliphaunt-node-direct-liboliphaunt]
source_product = "liboliphaunt-native"
Expand Down
1 change: 1 addition & 0 deletions src/native/sdks/kotlin/release.toml
Original file line number Diff line number Diff line change
Expand Up @@ -15,6 +15,7 @@ release_artifacts = [
"maven-publication",
"runtime-assets-external",
]
embedded_cargo_manifests = ["src/native/mobile-bindings/Cargo.toml"]

[compatibility_versions.oliphaunt-kotlin-liboliphaunt]
source_product = "liboliphaunt-native"
Expand Down
23 changes: 23 additions & 0 deletions src/native/sdks/react-native/moon.yml
Original file line number Diff line number Diff line change
Expand Up @@ -121,7 +121,16 @@ tasks:
- /src/native/sdks/react-native/tools/check-package.mts
- /src/extensions/artifacts/packages/tools/contrib-carriers.mts
- /src/native/sdks/swift/tools/ios-carrier-manifest.mts
- /src/native/sdks/swift/tools/pinned-native-carrier.mts
- /tools/release/github-read.mts
- /tools/release/github-core-request-journal.mts
- /src/native/sdks/swift/tools/swift-carrier-resolver.mts
- /src/native/sdks/swift/tools/render_swiftpm_release_package.mts
- /src/native/sdks/swift/tools/swift-source-carrier-contract.mts
- /tools/release/release-graph.mts
- /tools/release/product-version.mts
- /tools/release/with-product-history.sh
- /tools/release/release-history.mts
- /tools/packaging/npm-package.mts
- /src/native/sdks/react-native/tools/stage-release-artifacts.mts
- /src/native/sdks/react-native/tools/stage-release-artifacts.sh
Expand Down Expand Up @@ -184,6 +193,20 @@ tasks:
- "/tools/dev/bun.sh"
- /src/examples/native/react-native-expo/package.json
- /tools/packaging/portable-archive.mts
- /tools/packaging/archive-directory.mts
- "@group(release-archive-contract)"
- "@group(legal-files)"
- /src/extensions/tools/extension-upstream-licenses.mts
- /src/native/sdks/swift/tools/ios-carrier-manifest.mts
- /src/native/sdks/swift/tools/swift-source-carrier-contract.mts
- /src/native/sdks/swift/tools/pinned-native-carrier.mts
- /src/native/sdks/swift/tools/swift-carrier-resolver.mts
- /src/native/sdks/swift/tools/render_swiftpm_release_package.mts
- /src/native/sdks/swift/tools/prepare-swift-release-consumer.mts
- /src/native/sdks/swift/tools/swift-extension-release-consumer-inputs.mts
- /src/native/runtime/VERSION
- /src/wasix/runtime/VERSION
- /tools/release/*.{mts,sh}
- project: oliphaunt-query-ts
group: sources
- "@group(bun-workspace)"
Expand Down
Loading
Loading