name: Release on: workflow_dispatch: inputs: version: description: "Release version (e.g. 0.2.0)" required: true type: string changelog: description: "Release notes (markdown, shown on the release page). Single-line field — use literal \\n for line breaks." required: false type: string jobs: gateway: name: Gateway plugin tests runs-on: ubuntu-latest steps: - uses: actions/checkout@v4 - name: Install uv run: curl -LsSf https://astral.sh/uv/install.sh | sh - name: Clone hermes-agent (pinned) run: | git clone https://github.com/NousResearch/hermes-agent.git hermes-agent git -C hermes-agent fetch --depth 1 origin 31f62d76af068abde3c699f91190e8ded07fd05b git -C hermes-agent checkout 31f62d76af068abde3c699f91190e8ded07fd05b - name: Sync venv run: | echo "$HOME/.local/bin" >> "$GITHUB_PATH" cd hermes-agent # pytest lives in the `dev` extra — a plain `uv sync` leaves the # venv without it and run_tests.sh refuses to run. uv sync --extra dev - name: Run android gateway tests run: | cp gateway-plugin/tests/test_android.py hermes-agent/tests/gateway/test_android.py cd hermes-agent IRIS_PLUGIN_DIR="$GITHUB_WORKSPACE/gateway-plugin" \ scripts/run_tests.sh tests/gateway/test_android.py kotlin: name: Kotlin tests (android host + desktop) runs-on: ubuntu-latest steps: - uses: actions/checkout@v4 - uses: actions/setup-java@v4 with: distribution: temurin java-version: "21" - name: Strip local JDK pin run: sed -i '/^org\.gradle\.java\.home/d' app/gradle.properties - name: Install Android SDK run: | export ANDROID_HOME="$HOME/android-sdk" mkdir -p "$ANDROID_HOME/cmdline-tools" curl -fsSL -o /tmp/ct.zip \ https://dl.google.com/android/repository/commandlinetools-linux-11076708_latest.zip unzip -q /tmp/ct.zip -d "$ANDROID_HOME/cmdline-tools" mv "$ANDROID_HOME/cmdline-tools/cmdline-tools" "$ANDROID_HOME/cmdline-tools/latest" # Finite input from a file: `yes | sdkmanager` dies with SIGPIPE # (exit 141) under Gitea's `bash -e -o pipefail` once sdkmanager # exits before `yes` is done writing. for i in $(seq 100); do echo y; done > /tmp/sdk_licenses_yes.txt "$ANDROID_HOME/cmdline-tools/latest/bin/sdkmanager" --licenses < /tmp/sdk_licenses_yes.txt > /dev/null echo "ANDROID_HOME=$ANDROID_HOME" >> "$GITHUB_ENV" echo "sdk.dir=$ANDROID_HOME" > app/local.properties - name: Run host tests working-directory: app run: ./gradlew :shared:testAndroidHostTest :shared:desktopTest # Gitea/act_runner does not implement the GitHub artifacts API # (upload-artifact@v4+ fails with GHESNotSupportedError), so the builds and # the release creation happen in ONE job — no artifact handoff between jobs. release: name: Build + create Gitea release runs-on: ubuntu-latest needs: [gateway, kotlin] steps: - uses: actions/checkout@v4 - uses: actions/setup-java@v4 with: distribution: temurin java-version: "21" - name: Strip local JDK pin run: sed -i '/^org\.gradle\.java\.home/d' app/gradle.properties - name: Install Android SDK run: | export ANDROID_HOME="$HOME/android-sdk" mkdir -p "$ANDROID_HOME/cmdline-tools" curl -fsSL -o /tmp/ct.zip \ https://dl.google.com/android/repository/commandlinetools-linux-11076708_latest.zip unzip -q /tmp/ct.zip -d "$ANDROID_HOME/cmdline-tools" mv "$ANDROID_HOME/cmdline-tools/cmdline-tools" "$ANDROID_HOME/cmdline-tools/latest" # Finite input from a file: `yes | sdkmanager` dies with SIGPIPE # (exit 141) under Gitea's `bash -e -o pipefail` once sdkmanager # exits before `yes` is done writing. for i in $(seq 100); do echo y; done > /tmp/sdk_licenses_yes.txt "$ANDROID_HOME/cmdline-tools/latest/bin/sdkmanager" --licenses < /tmp/sdk_licenses_yes.txt > /dev/null echo "ANDROID_HOME=$ANDROID_HOME" >> "$GITHUB_ENV" echo "sdk.dir=$ANDROID_HOME" > app/local.properties # jpackage --type deb shells out to fakeroot, which the runner image # does not ship. - name: Install fakeroot (for jpackage --type deb) run: sudo apt-get update -qq && sudo apt-get install -y -qq fakeroot - name: Restore release keystore (from Gitea secrets) env: KS_B64: ${{ secrets.ANDROID_KEYSTORE_BASE64 }} run: | if [ -n "$KS_B64" ]; then echo "$KS_B64" | base64 -d > app/release.keystore echo "ANDROID_KEYSTORE_FILE=$GITHUB_WORKSPACE/app/release.keystore" >> "$GITHUB_ENV" echo "ANDROID_KEYSTORE_PASSWORD=${{ secrets.ANDROID_KEYSTORE_PASSWORD }}" >> "$GITHUB_ENV" echo "ANDROID_KEY_ALIAS=${{ secrets.ANDROID_KEY_ALIAS }}" >> "$GITHUB_ENV" echo "ANDROID_KEY_PASSWORD=${{ secrets.ANDROID_KEY_PASSWORD }}" >> "$GITHUB_ENV" echo "Building SIGNED release APK" else echo "::warning::ANDROID_KEYSTORE_BASE64 secret not set — falling back to a DEBUG apk (see CI-SETUP.md §5)" fi - name: Build APK + AAB run: | VERSION=$(jq -r '.inputs.version' "$GITHUB_EVENT_PATH") cd app if [ -n "$ANDROID_KEYSTORE_FILE" ]; then # APK for direct sideloading, AAB for Play Store uploads. ./gradlew :androidApp:assembleRelease :androidApp:bundleRelease -PappVersion="$VERSION" cp androidApp/build/outputs/apk/release/androidApp-release.apk \ "$GITHUB_WORKSPACE/iris-android-v$VERSION.apk" cp androidApp/build/outputs/bundle/release/androidApp-release.aab \ "$GITHUB_WORKSPACE/iris-android-v$VERSION.aab" else ./gradlew :androidApp:assembleDebug :androidApp:bundleDebug -PappVersion="$VERSION" cp androidApp/build/outputs/apk/debug/androidApp-debug.apk \ "$GITHUB_WORKSPACE/iris-android-v$VERSION-debug.apk" cp androidApp/build/outputs/bundle/debug/androidApp-debug.aab \ "$GITHUB_WORKSPACE/iris-android-v$VERSION-debug.aab" fi # jpackage cannot cross-compile: this only produces Linux packages. # When a Windows / macOS runner exists later, add a second build job # for it (jpackage picks the native type: msi on Windows, dmg on macOS). - name: Build desktop app-image + deb run: | VERSION=$(jq -r '.inputs.version' "$GITHUB_EVENT_PATH") cd app # Self-contained app image (JRE bundled via jlink). ./gradlew :desktopApp:jpackage -PappVersion="$VERSION" (cd desktopApp/build/jpackage && zip -qr \ "$GITHUB_WORKSPACE/iris-desktop-linux-x64-v$VERSION.zip" iris) # .deb package (dpkg-deb ships with Ubuntu; fakeroot installed above). ./gradlew :desktopApp:jpackage -PjpackageType=deb -PappVersion="$VERSION" cp desktopApp/build/jpackage/*.deb \ "$GITHUB_WORKSPACE/iris-desktop-linux-x64-v$VERSION.deb" - name: Create release + upload artifacts env: # Optional: create a personal access token (scope: Releases: write) # and store it as secret GITEA_TOKEN. Without it the workflow uses # the automatic GITHUB_TOKEN that Gitea Actions provides. RELEASE_TOKEN: ${{ secrets.GITEA_TOKEN }} run: | set -euo pipefail SERVER="${GITEA_SERVER_URL:-$GITHUB_SERVER_URL}" REPO="${GITEA_REPOSITORY:-$GITHUB_REPOSITORY}" TOKEN="${RELEASE_TOKEN:-$GITHUB_TOKEN}" VERSION=$(jq -r '.inputs.version' "$GITHUB_EVENT_PATH") # The dispatch input is a single-line field; turn literal \n into real newlines. CHANGELOG=$(jq -r '.inputs.changelog // ""' "$GITHUB_EVENT_PATH" | sed 's/\\n/\n/g') TAG="v$VERSION" API="$SERVER/api/v1/repos/$REPO" AUTH="Authorization: token $TOKEN" # curl wrapper: on HTTP >= 400, print the response body (Gitea's error # message) before failing — plain `curl -f` hides it (exit 22). api() { local code body body=$(mktemp) code=$(curl -s -o "$body" -w '%{http_code}' "$@") || { cat "$body"; rm -f "$body"; return 1; } if [ "${code:0:1}" != "2" ]; then echo "API error $code: $(cat "$body")" >&2 rm -f "$body" return 1 fi cat "$body" rm -f "$body" } # Re-run safety: drop a previous release AND its tag for this version. # (Gitea's DELETE /releases/:id does NOT remove the tag; a leftover tag # makes the POST below fail with 409.) OLD_ID=$(api -H "$AUTH" "$API/releases/tags/$TAG" | jq -r '.id // empty') || true if [ -n "$OLD_ID" ]; then api -X DELETE -H "$AUTH" "$API/releases/$OLD_ID" > /dev/null fi api -X DELETE -H "$AUTH" "$API/git/refs/tags/$TAG" > /dev/null || true # Gitea creates the tag at the default branch HEAD automatically. RELEASE_ID=$(api -X POST -H "$AUTH" -H "Content-Type: application/json" \ "$API/releases" \ -d "$(jq -n --arg tag "$TAG" --arg title "Iris $VERSION" --arg body "$CHANGELOG" \ '{tag_name:$tag, title:$title, body:$body}')" \ | jq -r .id) echo "Created release $TAG (id $RELEASE_ID)" for f in "$GITHUB_WORKSPACE"/iris-android-v* "$GITHUB_WORKSPACE"/iris-desktop-*; do [ -f "$f" ] || continue echo "Uploading $(basename "$f")" api -X POST -H "$AUTH" -F "attachment=@$f" \ "$API/releases/$RELEASE_ID/attachments" > /dev/null done echo "Done: $SERVER/$REPO/releases/tag/$TAG"