ci: share one platform matrix and deploy snapshots once - #306
Merged
Merged
Conversation
The seven platform builds were defined twice, in build.yml and in release.yml, and ran through four composite actions that were copies of each other: build and release, each with a macOS Intel variant. A cache key or runner change had to be made in up to six places. Move the matrix into the reusable platforms.yml, which both workflows call, and fold the four actions into one build action. The macOS Intel cross build becomes a matrix entry with its own JDK architectures, and the if/elif chains that mapped platforms to profiles become a matrix column. Releases now also run the ARM tests in test-natives before publishing. Every platform uploads its natives, and the build no longer deploys. On main, one deploy-snapshot job attaches the natives of all platforms to a single deployment once every platform has been built and tested, the way release.yml publishes a release. The seven jobs that each deployed the whole reactor raced on the snapshot metadata. Snapshots are deployed only from main, no longer from a manually dispatched build of another branch. The download, check and deploy steps shared by both publishing jobs move into a publish action.
test-natives tested only the three ARM platforms, the ones cross compiled for a runner that could not load them. The other four ran their tests in the build job, and the macOS Intel natives only under Rosetta, on the Apple Silicon runner that cross compiled them. Test all seven platforms in test-natives instead, each on a runner of its own OS and architecture and against the natives the build job uploaded, which are the ones that get published. The macOS Intel natives are now tested on an Intel runner. The build job only builds, so it no longer sets up a second JDK or runs the tests.
The macOS test lanes installed the natives as webrtc-java::<classifier>, without a version, and then could not resolve them. The version came from sed's 0,/re/ address, which only GNU sed knows; the Linux and Windows runners have GNU sed, macOS has BSD sed. Take the first <version> of the root pom with plain sed and head instead, and fail right there when it comes out empty. Also drop the step that downloaded Maven when a runner had none. Every runner test-natives uses ships with Maven, the ARM partner images included, and none of them took that branch.
devopvoid
added this pull request to stack #305
September 29, 2026 10:42
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Stacked on #304, which is stacked on #302. It targets #304's branch and should be retargeted to
mainonce both merge.Why
The seven platform builds were defined twice, in
build.ymland inrelease.yml, and ran through four composite actions that were copies of each other:buildandrelease, each with a macOS Intel variant. A cache key or runner change had to be made in up to six places. Onmain, each of the seven jobs also deployed the whole reactor as a snapshot, racing on the snapshot metadata.Changes
platforms.yml(new, reusable) holds the only 7-platform matrix.build.ymlcalls it for pushes and PRs.release.ymlcalls it with the tag it releases.test-nativestests all 7 platforms, each on a runner of its own OS and architecture, against the natives the build job uploaded. Those are exactly the ones that get published. The macOS Intel natives now run onmacos-15-intel, a real Intel runner, instead of under Rosetta on the Apple Silicon runner that cross compiles them. Before, only the 3 ARM platforms were tested this way, and the other 4 ran their tests inside the build job.actions/buildis now the only build action.if/elifchains and the separate macOS actions.natives-<platform>andnatives-media-<platform>on every platform, runs no tests, and no longer deploys.actions/release,actions/build-macos-x86_64andactions/release-macos-x86_64are deleted.actions/publish(new) downloads the natives of all platforms, checks that all 7 are there, installs the host jar and runsmvn deploy -pl .,webrtc,webrtc-java-media -Dnatives.dir=…. Both publishing jobs use it.deploy-snapshot(new, inbuild.yml) makes one snapshot deployment frommainwith every platform's natives attached. It runs after every platform has been built and tested, the same waypublish-centralpublishes a release. It fails ifmainisn't at a SNAPSHOT version.Behavior changes
macos-15-intelis GitHub's last Intel macOS image, so that lane will need a new home when GitHub retires it.main. A manually started Build of another branch no longer deploys.platforms / build (linux_arm).mainhas no required checks, so nothing breaks.Testing
deploy-snapshotonly runs onmain, so it's first exercised by the first push after merge.