- release.yml android job: build APK + AAB (bundleRelease/bundleDebug) - androidApp: versionCode overridable via -PappVersionCode (Play requires an incrementing versionCode per upload) - make_release_keystore.sh: PKCS12 has no separate key password (keytool ignores -keypass) — print the store password for ANDROID_KEY_PASSWORD
228 lines
8.7 KiB
YAML
228 lines
8.7 KiB
YAML
name: Release
|
|
|
|
on:
|
|
workflow_dispatch:
|
|
inputs:
|
|
version:
|
|
description: "Release version (e.g. 0.2.0)"
|
|
required: true
|
|
type: string
|
|
changelog:
|
|
description: "Release notes (markdown, shown on the release page)"
|
|
required: false
|
|
type: string
|
|
|
|
jobs:
|
|
gateway:
|
|
name: Gateway plugin tests
|
|
runs-on: ubuntu-latest
|
|
steps:
|
|
- uses: actions/checkout@v4
|
|
|
|
- name: Install uv
|
|
run: curl -LsSf https://astral.sh/uv/install.sh | sh
|
|
|
|
- name: Clone hermes-agent (pinned)
|
|
run: |
|
|
git clone https://github.com/NousResearch/hermes-agent.git hermes-agent
|
|
git -C hermes-agent fetch --depth 1 origin 31f62d76af068abde3c699f91190e8ded07fd05b
|
|
git -C hermes-agent checkout 31f62d76af068abde3c699f91190e8ded07fd05b
|
|
|
|
- name: Sync venv
|
|
run: |
|
|
echo "$HOME/.local/bin" >> "$GITHUB_PATH"
|
|
cd hermes-agent
|
|
uv sync
|
|
|
|
- name: Run android gateway tests
|
|
run: |
|
|
cp gateway-plugin/tests/test_android.py hermes-agent/tests/gateway/test_android.py
|
|
cd hermes-agent
|
|
ANDROID_PLUGIN_DIR="$GITHUB_WORKSPACE/gateway-plugin" \
|
|
scripts/run_tests.sh tests/gateway/test_android.py
|
|
|
|
kotlin:
|
|
name: Kotlin tests (android host + desktop)
|
|
runs-on: ubuntu-latest
|
|
steps:
|
|
- uses: actions/checkout@v4
|
|
|
|
- uses: actions/setup-java@v4
|
|
with:
|
|
distribution: temurin
|
|
java-version: "21"
|
|
|
|
- name: Strip local JDK pin
|
|
run: sed -i '/^org\.gradle\.java\.home/d' app/gradle.properties
|
|
|
|
- name: Install Android SDK
|
|
run: |
|
|
export ANDROID_HOME="$HOME/android-sdk"
|
|
mkdir -p "$ANDROID_HOME/cmdline-tools"
|
|
curl -fsSL -o /tmp/ct.zip \
|
|
https://dl.google.com/android/repository/commandlinetools-linux-11076708_latest.zip
|
|
unzip -q /tmp/ct.zip -d "$ANDROID_HOME/cmdline-tools"
|
|
mv "$ANDROID_HOME/cmdline-tools/cmdline-tools" "$ANDROID_HOME/cmdline-tools/latest"
|
|
yes | "$ANDROID_HOME/cmdline-tools/latest/bin/sdkmanager" --licenses > /dev/null
|
|
echo "ANDROID_HOME=$ANDROID_HOME" >> "$GITHUB_ENV"
|
|
echo "sdk.dir=$ANDROID_HOME" > app/local.properties
|
|
|
|
- name: Run host tests
|
|
working-directory: app
|
|
run: ./gradlew :shared:testAndroidHostTest :shared:desktopTest
|
|
|
|
android:
|
|
name: Build Android APK
|
|
runs-on: ubuntu-latest
|
|
needs: [gateway, kotlin]
|
|
steps:
|
|
- uses: actions/checkout@v4
|
|
|
|
- uses: actions/setup-java@v4
|
|
with:
|
|
distribution: temurin
|
|
java-version: "21"
|
|
|
|
- name: Strip local JDK pin
|
|
run: sed -i '/^org\.gradle\.java\.home/d' app/gradle.properties
|
|
|
|
- name: Install Android SDK
|
|
run: |
|
|
export ANDROID_HOME="$HOME/android-sdk"
|
|
mkdir -p "$ANDROID_HOME/cmdline-tools"
|
|
curl -fsSL -o /tmp/ct.zip \
|
|
https://dl.google.com/android/repository/commandlinetools-linux-11076708_latest.zip
|
|
unzip -q /tmp/ct.zip -d "$ANDROID_HOME/cmdline-tools"
|
|
mv "$ANDROID_HOME/cmdline-tools/cmdline-tools" "$ANDROID_HOME/cmdline-tools/latest"
|
|
yes | "$ANDROID_HOME/cmdline-tools/latest/bin/sdkmanager" --licenses > /dev/null
|
|
echo "ANDROID_HOME=$ANDROID_HOME" >> "$GITHUB_ENV"
|
|
echo "sdk.dir=$ANDROID_HOME" > app/local.properties
|
|
|
|
- name: Restore release keystore (from Gitea secrets)
|
|
env:
|
|
KS_B64: ${{ secrets.ANDROID_KEYSTORE_BASE64 }}
|
|
run: |
|
|
if [ -n "$KS_B64" ]; then
|
|
echo "$KS_B64" | base64 -d > app/release.keystore
|
|
echo "ANDROID_KEYSTORE_FILE=$GITHUB_WORKSPACE/app/release.keystore" >> "$GITHUB_ENV"
|
|
echo "ANDROID_KEYSTORE_PASSWORD=${{ secrets.ANDROID_KEYSTORE_PASSWORD }}" >> "$GITHUB_ENV"
|
|
echo "ANDROID_KEY_ALIAS=${{ secrets.ANDROID_KEY_ALIAS }}" >> "$GITHUB_ENV"
|
|
echo "ANDROID_KEY_PASSWORD=${{ secrets.ANDROID_KEY_PASSWORD }}" >> "$GITHUB_ENV"
|
|
echo "Building SIGNED release APK"
|
|
else
|
|
echo "::warning::ANDROID_KEYSTORE_BASE64 secret not set — falling back to a DEBUG apk (see CI-SETUP.md §5)"
|
|
fi
|
|
|
|
- name: Build APK + AAB
|
|
run: |
|
|
VERSION=$(jq -r '.inputs.version' "$GITHUB_EVENT_PATH")
|
|
cd app
|
|
if [ -n "$ANDROID_KEYSTORE_FILE" ]; then
|
|
# APK for direct sideloading, AAB for Play Store uploads.
|
|
./gradlew :androidApp:assembleRelease :androidApp:bundleRelease -PappVersion="$VERSION"
|
|
cp androidApp/build/outputs/apk/release/androidApp-release.apk \
|
|
"$GITHUB_WORKSPACE/iris-android-v$VERSION.apk"
|
|
cp androidApp/build/outputs/bundle/release/androidApp-release.aab \
|
|
"$GITHUB_WORKSPACE/iris-android-v$VERSION.aab"
|
|
else
|
|
./gradlew :androidApp:assembleDebug :androidApp:bundleDebug -PappVersion="$VERSION"
|
|
cp androidApp/build/outputs/apk/debug/androidApp-debug.apk \
|
|
"$GITHUB_WORKSPACE/iris-android-v$VERSION-debug.apk"
|
|
cp androidApp/build/outputs/bundle/debug/androidApp-debug.aab \
|
|
"$GITHUB_WORKSPACE/iris-android-v$VERSION-debug.aab"
|
|
fi
|
|
|
|
- uses: actions/upload-artifact@v4
|
|
with:
|
|
name: android
|
|
path: |
|
|
iris-android-*.apk
|
|
iris-android-*.aab
|
|
|
|
desktop:
|
|
name: Build desktop (Linux, jpackage)
|
|
runs-on: ubuntu-latest
|
|
needs: [gateway, kotlin]
|
|
steps:
|
|
- uses: actions/checkout@v4
|
|
|
|
- uses: actions/setup-java@v4
|
|
with:
|
|
distribution: temurin
|
|
java-version: "21"
|
|
|
|
- name: Strip local JDK pin
|
|
run: sed -i '/^org\.gradle\.java\.home/d' app/gradle.properties
|
|
|
|
# jpackage cannot cross-compile: this job only produces Linux packages.
|
|
# When a Windows / macOS runner exists later, copy this job, change
|
|
# runs-on, and drop the -x64-linux suffix (jpackage picks the native
|
|
# type: msi on Windows, dmg on macOS).
|
|
- name: Build app-image + deb
|
|
run: |
|
|
VERSION=$(jq -r '.inputs.version' "$GITHUB_EVENT_PATH")
|
|
cd app
|
|
# Self-contained app image (JRE bundled via jlink).
|
|
./gradlew :desktopApp:jpackage -PappVersion="$VERSION"
|
|
(cd desktopApp/build/jpackage && zip -qr \
|
|
"$GITHUB_WORKSPACE/iris-desktop-linux-x64-v$VERSION.zip" iris)
|
|
# .deb package (dpkg-deb ships with Ubuntu).
|
|
./gradlew :desktopApp:jpackage -PjpackageType=deb -PappVersion="$VERSION"
|
|
cp desktopApp/build/jpackage/*.deb \
|
|
"$GITHUB_WORKSPACE/iris-desktop-linux-x64-v$VERSION.deb"
|
|
|
|
- uses: actions/upload-artifact@v4
|
|
with:
|
|
name: desktop
|
|
path: |
|
|
iris-desktop-linux-x64-*.zip
|
|
iris-desktop-linux-x64-*.deb
|
|
|
|
release:
|
|
name: Create Gitea release
|
|
runs-on: ubuntu-latest
|
|
needs: [android, desktop]
|
|
steps:
|
|
- uses: actions/download-artifact@v4
|
|
with:
|
|
path: artifacts
|
|
|
|
- name: Create release + upload artifacts
|
|
env:
|
|
# Optional: create a personal access token (scope: Releases: write)
|
|
# and store it as secret GITEA_TOKEN. Without it the workflow uses
|
|
# the automatic GITHUB_TOKEN that Gitea Actions provides.
|
|
RELEASE_TOKEN: ${{ secrets.GITEA_TOKEN }}
|
|
run: |
|
|
set -euo pipefail
|
|
SERVER="${GITEA_SERVER_URL:-$GITHUB_SERVER_URL}"
|
|
REPO="${GITEA_REPOSITORY:-$GITHUB_REPOSITORY}"
|
|
TOKEN="${RELEASE_TOKEN:-$GITHUB_TOKEN}"
|
|
VERSION=$(jq -r '.inputs.version' "$GITHUB_EVENT_PATH")
|
|
CHANGELOG=$(jq -r '.inputs.changelog // ""' "$GITHUB_EVENT_PATH")
|
|
TAG="v$VERSION"
|
|
API="$SERVER/api/v1/repos/$REPO"
|
|
AUTH="Authorization: token $TOKEN"
|
|
|
|
# Re-run safety: drop a previous release (and its tag) for this version.
|
|
OLD_ID=$(curl -sf -H "$AUTH" "$API/releases/tags/$TAG" | jq -r '.id // empty')
|
|
if [ -n "$OLD_ID" ]; then
|
|
curl -sf -X DELETE -H "$AUTH" "$API/releases/$OLD_ID" > /dev/null
|
|
fi
|
|
|
|
# Gitea creates the tag at the default branch HEAD automatically.
|
|
RELEASE_ID=$(curl -sf -X POST -H "$AUTH" -H "Content-Type: application/json" \
|
|
"$API/releases" \
|
|
-d "$(jq -n --arg tag "$TAG" --arg title "Iris $VERSION" --arg body "$CHANGELOG" \
|
|
'{tag_name:$tag, title:$title, body:$body}')" \
|
|
| jq -r .id)
|
|
echo "Created release $TAG (id $RELEASE_ID)"
|
|
|
|
for f in artifacts/*/*; do
|
|
[ -f "$f" ] || continue
|
|
echo "Uploading $(basename "$f")"
|
|
curl -sf -X POST -H "$AUTH" -F "attachment=@$f" \
|
|
"$API/releases/$RELEASE_ID/attachments" > /dev/null
|
|
done
|
|
echo "Done: $SERVER/$REPO/releases/tag/$TAG"
|