Pick any line to see why it is the way it is: the commit, the pull request and issue it came from, and what the agent was thinking.
| The g1t CLI 0.1.0 is downloadable: g1t.sh/downloads/cli/latest/, five platforms with SHA256SUMS | 1 | #!/usr/bin/env node |
| 2 | // Releases of the g1t CLI (crates/g1t): built for every platform, | |
| 3 | // checksummed, and published to the g1t-downloads R2 bucket that g1t.sh | |
| 4 | // serves at /downloads/cli/ (apps/web/app/routes/downloads-runner.ts). | |
| 5 | // | |
| 6 | // node scripts/cli-release.mjs build # every platform, in the cargo-zigbuild image (Docker) | |
| 7 | // node scripts/cli-release.mjs publish [--dry-run] | |
| 8 | // | |
| 9 | // At cli/<version>/ in the bucket: g1t-linux-x64, -linux-arm64, | |
| 10 | // -macos-x64, -macos-arm64, -windows-x64.exe, SHA256SUMS and | |
| 11 | // manifest.json; at cli/: latest.json, the newest release's manifest. | |
| 12 | // Unlike the runner, the CLI does not update itself, so nothing is signed: | |
| 13 | // SHA256SUMS is what to check a download against. | |
| 14 | ||
| 15 | import { spawnSync } from "node:child_process"; | |
| 16 | import { createHash } from "node:crypto"; | |
| 17 | import { existsSync, mkdirSync, readFileSync, writeFileSync } from "node:fs"; | |
| 18 | import { dirname, join } from "node:path"; | |
| 19 | import { fileURLToPath } from "node:url"; | |
| 20 | ||
| 21 | const ROOT = join(dirname(fileURLToPath(import.meta.url)), ".."); | |
| 22 | const BUCKET = "g1t-downloads"; | |
| 23 | const BUILDER = "ghcr.io/rust-cross/cargo-zigbuild:latest"; | |
| 24 | export const TARGETS = { | |
| 25 | "linux-x64": { triple: "x86_64-unknown-linux-musl", file: "g1t-linux-x64" }, | |
| 26 | "linux-arm64": { triple: "aarch64-unknown-linux-musl", file: "g1t-linux-arm64" }, | |
| 27 | "macos-x64": { triple: "x86_64-apple-darwin", file: "g1t-macos-x64" }, | |
| 28 | "macos-arm64": { triple: "aarch64-apple-darwin", file: "g1t-macos-arm64" }, | |
| 29 | "windows-x64": { triple: "x86_64-pc-windows-gnu", file: "g1t-windows-x64.exe", exe: true }, | |
| 30 | }; | |
| 31 | ||
| 32 | export function version() { | |
| 33 | const found = /^version\s*=\s*"([^"]+)"/m.exec(readFileSync(join(ROOT, "crates/g1t/Cargo.toml"), "utf8")); | |
| 34 | if (!found) throw new Error("crates/g1t/Cargo.toml has no version"); | |
| 35 | return found[1]; | |
| 36 | } | |
| 37 | ||
| 38 | const outDir = (v = version()) => join(ROOT, "target", "cli-release", v); | |
| 39 | const sha256 = (bytes) => createHash("sha256").update(bytes).digest("hex"); | |
| 40 | ||
| 41 | function run(command, args, options = {}) { | |
| 42 | const done = spawnSync(command, args, { stdio: "inherit", cwd: ROOT, ...options }); | |
| 43 | if (done.status !== 0) throw new Error(`${command} ${args.join(" ")} failed`); | |
| 44 | } | |
| 45 | ||
| 46 | function build() { | |
| 47 | const v = version(); | |
| 48 | const dir = outDir(v); | |
| 49 | mkdirSync(dir, { recursive: true }); | |
| 50 | const triples = Object.values(TARGETS).map((t) => t.triple).join(" "); | |
| 51 | // One container builds every platform; its target folder is kept apart | |
| 52 | // from the host's so the two never mix. | |
| 53 | run("docker", [ | |
| 54 | "run", "--rm", | |
| 55 | "-e", "CARGO_TARGET_DIR=/src/target/zig", | |
| 56 | "-v", `${ROOT.replaceAll("\\", "/")}:/src`, | |
| 57 | "-v", "g1t-cargo-registry:/usr/local/cargo/registry", | |
| 58 | "-w", "/src", BUILDER, "sh", "-c", | |
| 59 | `set -e; for t in ${triples}; do rustup target add $t >/dev/null 2>&1; cargo zigbuild --release --locked --package g1t --target $t; done`, | |
| 60 | ], { env: { ...process.env, MSYS_NO_PATHCONV: "1" } }); | |
| 61 | const files = {}; | |
| 62 | for (const [platform, target] of Object.entries(TARGETS)) { | |
| 63 | const built = join(ROOT, "target", "zig", target.triple, "release", target.exe ? "g1t.exe" : "g1t"); | |
| 64 | const bytes = readFileSync(built); | |
| 65 | writeFileSync(join(dir, target.file), bytes); | |
| 66 | files[platform] = { name: target.file, sha256: sha256(bytes) }; | |
| 67 | } | |
| 68 | const manifest = { version: v, published_at: new Date().toISOString(), files }; | |
| 69 | writeFileSync(join(dir, "manifest.json"), `${JSON.stringify(manifest, null, 2)}\n`); | |
| 70 | writeFileSync(join(dir, "latest.json"), `${JSON.stringify(manifest, null, 2)}\n`); | |
| 71 | writeFileSync(join(dir, "SHA256SUMS"), Object.values(files).map((f) => `${f.sha256} ${f.name}`).join("\n") + "\n"); | |
| 72 | console.log(`built ${Object.keys(files).length} binaries of g1t ${v} into ${dir}`); | |
| 73 | } | |
| 74 | ||
| 75 | function publish(dryRun) { | |
| 76 | const v = version(); | |
| 77 | const dir = outDir(v); | |
| 78 | if (!existsSync(join(dir, "manifest.json"))) throw new Error(`nothing built for ${v}: node scripts/cli-release.mjs build`); | |
| 79 | const put = (key, file, type) => { | |
| 80 | if (dryRun) return console.log(`would put ${key}`); | |
| 81 | run("npx", ["wrangler", "r2", "object", "put", `${BUCKET}/${key}`, "--file", file, "--remote", "--content-type", type], { | |
| 82 | shell: process.platform === "win32", | |
| 83 | // Away from the repository's .env, which may hold a token meant for | |
| 84 | // something else (as scripts/deploy does). | |
| 85 | cwd: join(ROOT, "apps/web"), | |
| 86 | }); | |
| 87 | }; | |
| 88 | for (const target of Object.values(TARGETS)) put(`cli/${v}/${target.file}`, join(dir, target.file), "application/octet-stream"); | |
| 89 | put(`cli/${v}/manifest.json`, join(dir, "manifest.json"), "application/json"); | |
| 90 | put(`cli/${v}/SHA256SUMS`, join(dir, "SHA256SUMS"), "text/plain"); | |
| 91 | // Last, so `latest` never names a version whose files are not up yet. | |
| 92 | put("cli/latest.json", join(dir, "latest.json"), "application/json"); | |
| 93 | } | |
| 94 | ||
| 95 | if (process.argv[1]?.replaceAll("\\", "/").endsWith("scripts/cli-release.mjs")) { | |
| 96 | const [command, ...rest] = process.argv.slice(2); | |
| 97 | if (command === "build") build(); | |
| 98 | else if (command === "publish") publish(rest.includes("--dry-run")); | |
| 99 | else { | |
| 100 | console.error("usage: node scripts/cli-release.mjs build|publish [--dry-run]"); | |
| 101 | process.exit(2); | |
| 102 | } | |
| 103 | } |