-
Notifications
You must be signed in to change notification settings - Fork 1
222 lines (213 loc) · 12.3 KB
/
Copy pathrelease.yml
File metadata and controls
222 lines (213 loc) · 12.3 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
130
131
132
133
134
135
136
137
138
139
140
141
142
143
144
145
146
147
148
149
150
151
152
153
154
155
156
157
158
159
160
161
162
163
164
165
166
167
168
169
170
171
172
173
174
175
176
177
178
179
180
181
182
183
184
185
186
187
188
189
190
191
192
193
194
195
196
197
198
199
200
201
202
203
204
205
206
207
208
209
210
211
212
213
214
215
216
217
218
219
220
221
222
name: Draft desktop release
on:
workflow_dispatch:
inputs:
tag:
description: Existing release tag to build
required: true
default: v0.1.0
permissions:
contents: read
concurrency:
group: release-${{ inputs.tag }}
cancel-in-progress: false
env:
RELEASE_TAG: ${{ inputs.tag }}
PYDESKUI_REF: ac199c4f5ab0c5320818bcd5f10494395c5cd1b8
jobs:
validate:
runs-on: ubuntu-22.04
steps:
- uses: actions/checkout@11d5960a326750d5838078e36cf38b85af677262
with:
ref: ${{ inputs.tag }}
fetch-depth: 0
- uses: actions/setup-python@a26af69be951a213d495a4c3e4e4022e16d87065
with: {python-version: '3.13.15'}
- run: test "$(git describe --tags --exact-match)" = "$RELEASE_TAG"
- run: python scripts/validate_release.py --tag "$RELEASE_TAG"
macos:
needs: validate
runs-on: macos-14
permissions: {contents: read, id-token: write, attestations: write}
steps:
- uses: actions/checkout@11d5960a326750d5838078e36cf38b85af677262
with: {ref: "${{ inputs.tag }}"}
- uses: actions/checkout@11d5960a326750d5838078e36cf38b85af677262
with:
repository: openHacking/PyDeskUI
ref: ${{ env.PYDESKUI_REF }}
path: vendor/PyDeskUI
- run: brew install python@3.13 python-tk@3.13
- run: |
"$(brew --prefix python@3.13)/bin/python3.13" -m venv .venv
echo "$PWD/.venv/bin" >> "$GITHUB_PATH"
- run: python -m pip install -e vendor/PyDeskUI -e packages/pydesktools-sdk -e packages/pydesktools-runtime -e plugins/json-tools -e plugins/image-compressor -e '.[dev]'
- run: python -c "import platform, tkinter; assert platform.machine() == 'arm64'; assert tkinter.TkVersion >= 9"
- run: python scripts/fetch_runtime.py --target macos-arm64 --output build/plugin-runtime/macos-arm64
- run: python scripts/build_bundles.py --target macos-arm64 --runtime-source build/plugin-runtime/macos-arm64/python
- name: Configure Developer ID
env:
APPLE_CERTIFICATE_P12: ${{ secrets.APPLE_CERTIFICATE_P12 }}
APPLE_CERTIFICATE_PASSWORD: ${{ secrets.APPLE_CERTIFICATE_PASSWORD }}
run: |
test -n "$APPLE_CERTIFICATE_P12"
export RELEASE_KEYCHAIN="$RUNNER_TEMP/pydesk-release.keychain-db"
export RELEASE_KEYCHAIN_PASSWORD="$(openssl rand -hex 24)"
echo "RELEASE_KEYCHAIN=$RELEASE_KEYCHAIN" >> "$GITHUB_ENV"
echo "RELEASE_KEYCHAIN_PASSWORD=$RELEASE_KEYCHAIN_PASSWORD" >> "$GITHUB_ENV"
python -c 'import base64,os,pathlib; pathlib.Path(os.environ["RUNNER_TEMP"],"certificate.p12").write_bytes(base64.b64decode(os.environ["APPLE_CERTIFICATE_P12"]))'
security create-keychain -p "$RELEASE_KEYCHAIN_PASSWORD" "$RELEASE_KEYCHAIN"
security unlock-keychain -p "$RELEASE_KEYCHAIN_PASSWORD" "$RELEASE_KEYCHAIN"
security import "$RUNNER_TEMP/certificate.p12" -k "$RELEASE_KEYCHAIN" -P "$APPLE_CERTIFICATE_PASSWORD" -T /usr/bin/codesign
security set-key-partition-list -S apple-tool:,apple: -s -k "$RELEASE_KEYCHAIN_PASSWORD" "$RELEASE_KEYCHAIN"
security list-keychains -d user -s "$RELEASE_KEYCHAIN"
- name: Build, sign, and verify
env:
APPLE_SIGNING_IDENTITY: ${{ secrets.APPLE_SIGNING_IDENTITY }}
run: |
test -n "$APPLE_SIGNING_IDENTITY"
python scripts/build_macos.py --runtime-source build/plugin-runtime/macos-arm64/python --identity "$APPLE_SIGNING_IDENTITY"
codesign --verify --deep --strict --verbose=2 dist/PyDeskTools.app
codesign --verify --verbose=2 dist/PyDeskTools-*-macos-arm64.dmg
dist/PyDeskTools.app/Contents/MacOS/PyDeskTools --data-dir "$RUNNER_TEMP/PyDesk Profile" --verify-installation "$RUNNER_TEMP/macos-verification.json"
python -c 'import json,os; assert json.load(open(os.path.join(os.environ["RUNNER_TEMP"],"macos-verification.json")))["passed"]'
- uses: actions/attest@1e69f48acb82d1966a394da916b4c1698aa569d6
with: {subject-path: dist/PyDeskTools-*-macos-arm64.dmg}
- uses: actions/upload-artifact@ea165f8d65b6e75b540449e92b4886f43607fa02
with:
name: release-macos
path: |
dist/PyDeskTools-*-macos-arm64.dmg
dist/build-manifest-macos-arm64.json
retention-days: 1
if-no-files-found: error
- if: always()
run: |
rm -f "$RUNNER_TEMP/certificate.p12"
if test -n "${RELEASE_KEYCHAIN:-}"; then security delete-keychain "$RELEASE_KEYCHAIN" || true; fi
windows:
needs: validate
runs-on: windows-2022
permissions: {contents: read, id-token: write, attestations: write}
steps:
- uses: actions/checkout@11d5960a326750d5838078e36cf38b85af677262
with: {ref: "${{ inputs.tag }}"}
- uses: actions/checkout@11d5960a326750d5838078e36cf38b85af677262
with:
repository: openHacking/PyDeskUI
ref: ${{ env.PYDESKUI_REF }}
path: vendor/PyDeskUI
- uses: actions/setup-python@a26af69be951a213d495a4c3e4e4022e16d87065
with: {python-version: '3.14.7'}
- run: python -m pip install -e vendor/PyDeskUI -e packages/pydesktools-sdk -e packages/pydesktools-runtime -e plugins/json-tools -e plugins/image-compressor -e '.[dev]'
- run: python -c "import platform, tkinter; print(platform.python_version(), platform.machine(), 'Tk', tkinter.TkVersion); assert platform.machine() == 'AMD64'; assert tkinter.TkVersion >= 9"
- run: python scripts/build_brand_assets.py
- run: python scripts/fetch_runtime.py --target windows-x86_64 --output build/plugin-runtime/windows-x86_64
- run: python scripts/build_bundles.py --target windows-x86_64 --runtime-source build/plugin-runtime/windows-x86_64/python
- run: python scripts/build_windows.py --runtime-source build/plugin-runtime/windows-x86_64/python
- name: Install, diagnose, and uninstall
shell: pwsh
run: |
$install = Join-Path $env:RUNNER_TEMP 'PyDesk Tools ü'
$profile = Join-Path $env:RUNNER_TEMP 'Profile ü'
$report = Join-Path $env:RUNNER_TEMP 'windows-verification.json'
$installer = (Get-Item 'dist/PyDeskTools-*-windows-x64-unsigned.exe').FullName
$installProcess = Start-Process $installer -ArgumentList '/VERYSILENT','/SUPPRESSMSGBOXES','/NORESTART',("/DIR=`"$install`"") -Wait -PassThru
if ($installProcess.ExitCode -ne 0) { throw "installer exited with $($installProcess.ExitCode)" }
$startInfo = [System.Diagnostics.ProcessStartInfo]::new()
$startInfo.FileName = Join-Path $install 'PyDeskTools.exe'
$startInfo.UseShellExecute = $false
$startInfo.ArgumentList.Add('--data-dir')
$startInfo.ArgumentList.Add($profile)
$startInfo.ArgumentList.Add('--verify-installation')
$startInfo.ArgumentList.Add($report)
$appProcess = [System.Diagnostics.Process]::Start($startInfo)
if (-not $appProcess.WaitForExit(300000)) {
Get-CimInstance Win32_Process -Filter "ProcessId = $($appProcess.Id)" |
Select-Object ProcessId, ParentProcessId, CommandLine | Format-List
Stop-Process -Id $appProcess.Id -Force -ErrorAction SilentlyContinue
if (Test-Path $report) { Get-Content $report }
$diagnostics = Join-Path $profile 'logs/diagnostics.log'
if (Test-Path $diagnostics) { Get-Content $diagnostics }
throw 'application diagnostic timed out after 5 minutes'
}
if ($appProcess.ExitCode -ne 0) { throw "application diagnostic exited with $($appProcess.ExitCode)" }
if (-not (Test-Path $report)) { throw 'verification report missing' }
$result = Get-Content $report | ConvertFrom-Json
if (-not $result.passed) { throw ($result | ConvertTo-Json -Depth 8) }
$uninstallProcess = Start-Process (Join-Path $install 'unins000.exe') -ArgumentList '/VERYSILENT','/SUPPRESSMSGBOXES','/NORESTART' -Wait -PassThru
if ($uninstallProcess.ExitCode -ne 0) { throw "uninstaller exited with $($uninstallProcess.ExitCode)" }
if (Test-Path (Join-Path $install 'PyDeskTools.exe')) { throw 'uninstall left executable behind' }
- uses: actions/attest@1e69f48acb82d1966a394da916b4c1698aa569d6
with: {subject-path: dist/PyDeskTools-*-windows-x64-unsigned.exe}
- uses: actions/upload-artifact@ea165f8d65b6e75b540449e92b4886f43607fa02
with:
name: release-windows
path: |
dist/PyDeskTools-*-windows-x64-unsigned.exe
dist/build-manifest-windows-x86_64.json
retention-days: 1
if-no-files-found: error
linux:
needs: validate
runs-on: ubuntu-22.04
permissions: {contents: read, id-token: write, attestations: write}
steps:
- uses: actions/checkout@11d5960a326750d5838078e36cf38b85af677262
with: {ref: "${{ inputs.tag }}"}
- uses: actions/checkout@11d5960a326750d5838078e36cf38b85af677262
with:
repository: openHacking/PyDeskUI
ref: ${{ env.PYDESKUI_REF }}
path: vendor/PyDeskUI
- run: sudo apt-get update && sudo apt-get install -y build-essential curl libfontconfig1-dev libx11-dev libxext-dev libxft-dev libxrender-dev libxss-dev libssl-dev libbz2-dev libffi-dev liblzma-dev libreadline-dev libsqlite3-dev libncurses-dev pkg-config uuid-dev xvfb zlib1g-dev
- uses: actions/cache@0057852bfaa89a56745cba8c7296529d2fc39830
with:
path: build/linux-gui
key: linux-gui-python-3.14.6-tk-9.0.4-shared-v2
- run: bash scripts/bootstrap_linux_gui_python.sh "$PWD/build/linux-gui"
- run: |
build/linux-gui/bin/python3.14 -m venv .venv
echo "$PWD/.venv/bin" >> "$GITHUB_PATH"
- run: python -m pip install -e vendor/PyDeskUI -e packages/pydesktools-sdk -e packages/pydesktools-runtime -e plugins/json-tools -e plugins/image-compressor -e '.[dev]'
- run: python -c "import platform, tkinter; assert platform.machine() == 'x86_64'; assert tkinter.TkVersion >= 9"
- run: python scripts/fetch_runtime.py --target linux-x86_64 --output build/plugin-runtime/linux-x86_64
- run: python scripts/build_bundles.py --target linux-x86_64 --runtime-source build/plugin-runtime/linux-x86_64/python
- name: Fetch pinned appimagetool
run: |
curl --fail --location --retry 3 --output build/appimagetool https://github.com/AppImage/appimagetool/releases/download/1.9.1/appimagetool-x86_64.AppImage
echo 'ed4ce84f0d9caff66f50bcca6ff6f35aae54ce8135408b3fa33abfc3cb384eb0 build/appimagetool' | sha256sum --check
- run: python scripts/build_linux.py --runtime-source build/plugin-runtime/linux-x86_64/python --appimagetool build/appimagetool
- run: |
xvfb-run -a env APPIMAGE_EXTRACT_AND_RUN=1 dist/PyDeskTools-*-linux-x86_64.AppImage --data-dir "$RUNNER_TEMP/PyDesk Profile ü" --verify-installation "$RUNNER_TEMP/linux-verification.json"
python -c 'import json,os; assert json.load(open(os.path.join(os.environ["RUNNER_TEMP"],"linux-verification.json")))["passed"]'
- uses: actions/attest@1e69f48acb82d1966a394da916b4c1698aa569d6
with: {subject-path: dist/PyDeskTools-*-linux-x86_64.AppImage}
- uses: actions/upload-artifact@ea165f8d65b6e75b540449e92b4886f43607fa02
with:
name: release-linux
path: |
dist/PyDeskTools-*-linux-x86_64.AppImage
dist/build-manifest-linux-x86_64.json
retention-days: 1
if-no-files-found: error
draft-release:
needs: [macos, windows, linux]
runs-on: ubuntu-22.04
permissions: {contents: write}
steps:
- uses: actions/checkout@11d5960a326750d5838078e36cf38b85af677262
with: {ref: "${{ inputs.tag }}"}
- uses: actions/download-artifact@d3f86a106a0bac45b974a628896c90dbdf5c8093
with:
pattern: release-*
path: release-assets
merge-multiple: true
- run: |
cd release-assets
sha256sum PyDeskTools-* build-manifest-*.json > SHA256SUMS.txt
test "$(find . -maxdepth 1 -type f -name 'PyDeskTools-*' | wc -l)" -eq 3
- env:
GH_TOKEN: ${{ github.token }}
run: gh release create "$RELEASE_TAG" release-assets/* --verify-tag --draft --prerelease --title "PyDeskTools ${RELEASE_TAG#v}" --notes-file docs/release-notes-v0.1.0.md