ci: harden the release workflow and keep native caches warm - #302
Merged
Merged
Conversation
Pass the release notes and the development version to the scripts through the environment instead of expanding them into the script text. The notes are commit subjects, so a quote or a backtick in one broke the release step and ran as shell code. Take the release version from the pom, which is what release:prepare tags, instead of letting git-cliff bump it from the commit types. The GitHub release now always matches the Maven tag, and --verify-tag makes a mismatch fail instead of creating an unbuilt tag on main. Grant write access only to the jobs that push, and keep two releases from running at once.
Build on every push to main that can change a build, not only on source changes. A PR can restore caches only from its own ref and from main, so when main skipped a build change, every following PR compiled WebRTC from scratch under a key that already existed on another PR's ref. Pom, CMake and submodule changes now also deploy a snapshot. Save the WebRTC and FFmpeg caches right after the build instead of in the post step of actions/cache, which saves only when the whole job succeeds; a failing test threw the finished native build away. Cancel a PR's running build when a newer push supersedes it, and give the workflow a read-only token.
Fold the changelog job into prepare-release and commit CHANGELOG.md locally, before release:prepare. The changelog commit, the release commit, the tag and the development commit now go out in one atomic push at the end, so a failure on the way leaves main untouched instead of carrying a changelog for a release that never happened. Check the input before anything else: developmentVersion must be a SNAPSHOT that differs from the release version, the release tag must not exist yet, and release:prepare must choose the version the changelog was written for. Hand the pushed tag to the platform and publish jobs as an output instead of having each of them guess the newest tag in the repository. Run release:prepare with "clean validate" as its preparation goals. The default "clean verify" compiled WebRTC and FFmpeg on an uncached runner, about 35 of the 52 minutes of the last release, only for the platform jobs to build the tagged tree again.
Leave docs-only PRs out of the native build and build the docs site on PRs that touch it instead, without deploying, so a broken VitePress build shows up before the merge. Cache the Chromium Clang package and stop listing every file it extracts, keep Homebrew from updating itself before each install, and drop the two disabled steps of the Windows preparation. Give every test run a 30 minute Surefire timeout, and test-natives a job timeout, so a hung test no longer holds a runner for six hours. Composite action steps have no timeout-minutes, and macOS has no timeout command. Upload the Surefire reports when a job fails.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Release workflow
publish-releaseexpanded the git-cliff notes (commit subjects) straight into its script, so a quote or backtick in a commit subject broke the step and ran as shell code. The notes, anddevelopmentVersionelsewhere, now go throughenv:, and the notes reachgh release createas a file.--bumpfrom the commit types, whilerelease:preparetags the pom's version. A breaking-change commit would have made them differ, andgh release createwould have created an unbuilt tag onmain. git-cliff now gets--tag v<pom version>, and--verify-tagmakes any mismatch fail.mainuntil the release is prepared. Thechangelogjob is merged intoprepare-release, which commitsCHANGELOG.mdlocally beforerelease:prepare. The changelog commit, the release commit, the tag and the development commit then go out in onegit push --atomic. Before, the changelog was pushed first, so a failed release leftmainwith a changelog entry for a release that never happened.developmentVersionmust look like1.2.3-SNAPSHOTand differ from the release version, the tag must not already exist, andrelease:preparemust choose the version the changelog was written for.git rev-list --tags. They now check out the tagprepare-releasepushed, taken from its job output.release:preparerunsclean validateinstead of the defaultclean verify. That compiled WebRTC and FFmpeg on an uncached runner (about 35 of the 52 minutes of the last release), and the platform jobs build the tagged tree again anyway.prepare-releaseandpublish-releasegetcontents: write. Areleaseconcurrency group stops two releases running at once.Build workflow
mainbuild. The push trigger used to match only.cpp,.hand.java. Now it runs for everything except docs,*.md, issue templates andpages.yml. PRs can only restore caches from their own ref and frommain. After build: sync the WebRTC checkout without git history #298 changed the WebRTC CMakeLists andmaindidn't rebuild, fix: repair the release pipeline and publish the media module #299 compiled WebRTC again under the same key: 24–52 min per platform instead of 4–6. Pom, CMake and submodule changes also deploy a snapshot now.actions/cache/restoreand saved withactions/cache/saveright after the Build step, in all four build/release actions. Before,actions/cachesaved only when the whole job succeeded, so one failing test threw away a finished native build.mainare never cancelled.pages.ymlnow builds the site, without deploying, on PRs that touchdocs/.-Dsurefire.timeout=1800), andtest-nativesgets a 30-minute job timeout. Composite action steps can't settimeout-minutes, and macOS has notimeoutcommand.tarno longer lists every extracted file.Behavior changes
main.github-actions[bot].prepare-releaseuses JDK 17, like the platform builds, instead of 21.Testing
X.Y.Z-SNAPSHOT,0.21.0and0.20.0-SNAPSHOTare rejected,0.21.0-SNAPSHOTpasses, and an existing tag is detected.mainand saved the WebRTC and FFmpeg builds right after compiling.