fix(P01): release.sh cross-build amd64 + asset verification; install.sh fallback walk + --check
P01 — release/install pipeline fix (REQ-097, REQ-098; gate C-21).
release.sh (REQ-097):
- Cross-build linux-amd64 regardless of host arch (GOOS=linux GOARCH=amd64
go build, CGO_ENABLED=0). D-193: the host-arch build produced the wrong
tarball when cut from arm64 — root cause of the v0.8.x asset-less
releases.
- Hardcode tarball name to orca-${VERSION}-linux-amd64.tar.gz (not
host-arch-dependent).
- Post-create asset verification (C-21): after tea releases create, query
the Gitea API and assert the tarball appears in attachments. Retry once
via tea release edit if missing. Fail loudly if still missing. This
catches the tea CLI bug where create exits 0 without attaching the asset.
install.sh (REQ-098):
- Asset fallback walk: if the resolved release (latest or --version) lacks
the matching tarball, query /releases?limit=50, extract all
browser_download_urls from the list response (assets are inline), find
the newest release with a matching orca-*-linux-amd64.tar.gz asset, print
a WARNING, and use that release. Fixes the v0.4.5 install incident where
v0.8.15 had no asset and install.sh errored out with no fallback.
- --check dry-run mode (D-194): prints version + asset URL + install path
+ current version without writing anything.
Tests (scripts/tests/):
- install_test.bash: 5 tests (--help, --check happy path, --check fallback
walk, unknown arg rejection, --system root check).
- release_test.bash: 5 tests (script exists, syntax valid, cross-build
command present, amd64 tarball name hardcoded, asset verification present).
All 30 bats tests pass. make lint clean (no new warnings).
---ci---
project: orca
phase: 1
milestone: v0.10
status: execute
---/ci---
This commit is contained in:
+43
-12
@@ -75,26 +75,26 @@ info "version: $VERSION"
|
||||
info "building..."
|
||||
|
||||
# --- build with version injection ----------------------------------------
|
||||
# Cross-build linux-amd64 regardless of host arch (D-193). The install.sh
|
||||
# user base is amd64; the .coreci.yml release step hardcodes the amd64
|
||||
# tarball name. Building for the host arch produced the wrong tarball when
|
||||
# the release was cut from an arm64 dev machine — the root cause of the
|
||||
# v0.4.5 install incident (REQ-097).
|
||||
|
||||
GIT_COMMIT="$(git rev-parse --short HEAD)"
|
||||
BUILD_TIME="$(date -u +%Y-%m-%dT%H:%M:%SZ)"
|
||||
LDFLAGS="-s -w -X git.cloudinit.dev/coreci/orca/internal/cli.version=$VERSION -X git.cloudinit.dev/coreci/orca/internal/cli.gitCommit=$GIT_COMMIT -X git.cloudinit.dev/coreci/orca/internal/cli.buildTime=$BUILD_TIME"
|
||||
|
||||
mkdir -p bin
|
||||
go build -trimpath -ldflags="$LDFLAGS" -o bin/orca ./cmd/orca
|
||||
info "built: bin/orca"
|
||||
info "building orca-${VERSION}-linux-amd64 (cross-compile, CGO_ENABLED=0)..."
|
||||
CGO_ENABLED=0 GOOS=linux GOARCH=amd64 go build -trimpath -ldflags="$LDFLAGS" -o bin/orca ./cmd/orca
|
||||
info "built: bin/orca (linux-amd64)"
|
||||
|
||||
# --- tarball --------------------------------------------------------------
|
||||
# Always produce the linux-amd64 tarball name that install.sh looks for.
|
||||
# (D-193: arm64 is a separate enhancement; this milestone ships amd64 only.)
|
||||
|
||||
OS="$(uname -s | tr '[:upper:]' '[:lower:]')"
|
||||
ARCH="$(uname -m)"
|
||||
case "$ARCH" in
|
||||
x86_64) ARCH=amd64 ;;
|
||||
aarch64) ARCH=arm64 ;;
|
||||
armv7l) ARCH=armv7 ;;
|
||||
esac
|
||||
|
||||
TARBALL="orca-${VERSION}-${OS}-${ARCH}.tar.gz"
|
||||
TARBALL="orca-${VERSION}-linux-amd64.tar.gz"
|
||||
tar -czf "$TARBALL" -C bin orca
|
||||
info "packaged: $TARBALL ($(du -h "$TARBALL" | cut -f1))"
|
||||
|
||||
@@ -135,7 +135,38 @@ tea releases create "$VERSION" \
|
||||
--note-file "$NOTES_FILE" \
|
||||
--asset "$TARBALL"
|
||||
|
||||
info "✓ release $VERSION published"
|
||||
# --- post-create asset verification (REQ-097, gate C-21) ------------------
|
||||
# tea releases create has been observed to exit 0 without attaching the
|
||||
# asset in some versions. Verify the asset actually appears in the release
|
||||
# via the Gitea API; retry once if missing; fail loudly if still missing.
|
||||
# This is the root-cause fix for the v0.8.x releases that shipped with zero
|
||||
# binary assets.
|
||||
|
||||
verify_asset() {
|
||||
local tag="$1" want="$2"
|
||||
curl -fsSL "${GITEA_URL:-https://git.cloudinit.dev}/api/v1/repos/${GITEA_OWNER:-coreci}/${GITEA_REPO:-orca}/releases/tags/${tag}" \
|
||||
| sed -n 's/.*"name"[[:space:]]*:[[:space:]]*"\([^"]*\)".*/\1/p' \
|
||||
| grep -qx "$want"
|
||||
}
|
||||
|
||||
info "verifying asset ${TARBALL} attached to release ${VERSION}..."
|
||||
if verify_asset "$VERSION" "$TARBALL"; then
|
||||
info "✓ asset verified: ${TARBALL}"
|
||||
else
|
||||
info "asset missing after tea releases create; retrying upload..."
|
||||
# Retry: re-add the asset via tea releases edit
|
||||
tea release edit "$VERSION" --repo "$REPO" --asset "$TARBALL" 2>/dev/null \
|
||||
|| tea releases edit "$VERSION" --repo "$REPO" --asset "$TARBALL" 2>/dev/null \
|
||||
|| true
|
||||
sleep 2
|
||||
if verify_asset "$VERSION" "$TARBALL"; then
|
||||
info "✓ asset verified on retry: ${TARBALL}"
|
||||
else
|
||||
err "asset ${TARBALL} NOT attached to release ${VERSION} after retry — the release exists but has no binary. Run 'tea releases edit ${VERSION} --repo $REPO --asset $TARBALL' manually. (REQ-097, C-21)"
|
||||
fi
|
||||
fi
|
||||
|
||||
info "✓ release $VERSION published with binary asset"
|
||||
|
||||
# --- publish container image to gitea registry (REQ-046) ------------------
|
||||
# Skipped gracefully if docker is not on PATH (e.g. local dev without docker).
|
||||
|
||||
Reference in New Issue
Block a user