-
Notifications
You must be signed in to change notification settings - Fork 1
318 lines (290 loc) · 12.3 KB
/
Copy pathpublish-python.yml
File metadata and controls
318 lines (290 loc) · 12.3 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
130
131
132
133
134
135
136
137
138
139
140
141
142
143
144
145
146
147
148
149
150
151
152
153
154
155
156
157
158
159
160
161
162
163
164
165
166
167
168
169
170
171
172
173
174
175
176
177
178
179
180
181
182
183
184
185
186
187
188
189
190
191
192
193
194
195
196
197
198
199
200
201
202
203
204
205
206
207
208
209
210
211
212
213
214
215
216
217
218
219
220
221
222
223
224
225
226
227
228
229
230
231
232
233
234
235
236
237
238
239
240
241
242
243
244
245
246
247
248
249
250
251
252
253
254
255
256
257
258
259
260
261
262
263
264
265
266
267
268
269
270
271
272
273
274
275
276
277
278
279
280
281
282
283
284
285
286
287
288
289
290
291
292
293
294
295
296
297
298
299
300
301
302
303
304
305
306
307
308
309
310
311
312
313
314
315
316
317
318
name: Publish Python SDK
on:
workflow_dispatch:
inputs:
version:
description: "Version bump type"
required: true
type: choice
options:
- patch
- minor
- major
- prepatch
- preminor
- premajor
- prerelease
custom_version:
description: "Custom version (optional, overrides version type)"
required: false
type: string
dry_run:
description: "Dry run (do not actually publish)"
required: false
type: boolean
default: false
concurrency:
group: publish-python-sdk
cancel-in-progress: false
permissions:
contents: write
id-token: write
jobs:
publish:
name: Build, Test & Publish relayfile-sdk
runs-on: ubuntu-latest
defaults:
run:
working-directory: packages/sdk/python
steps:
- name: Checkout
uses: actions/checkout@v4
with:
token: ${{ secrets.GITHUB_TOKEN }}
ref: ${{ github.sha }}
fetch-depth: 0
- name: Set up uv
uses: astral-sh/setup-uv@v8.1.0
with:
enable-cache: true
python-version: "3.12"
- name: Check SDK parity
working-directory: ${{ github.workspace }}
run: node scripts/check-sdk-parity.mjs
- name: Determine and set version
id: bump
shell: bash
env:
# Bind inputs through env so free-form custom_version is never
# interpolated into the shell script body.
CUSTOM_VERSION: ${{ github.event.inputs.custom_version }}
VERSION_TYPE: ${{ github.event.inputs.version }}
GH_TOKEN: ${{ secrets.GITHUB_TOKEN }}
SOURCE_SHA: ${{ github.sha }}
WORKFLOW_RUN_ID: ${{ github.run_id }}
RELEASE_REPOSITORY: ${{ github.repository }}
OFFLINE_BASELINE: ${{ github.ref != 'refs/heads/main' || github.event.inputs.dry_run == 'true' }}
run: |
set -euo pipefail
PYPROJECT="pyproject.toml"
MANIFEST_VERSION=$(awk -F '"' '/^version = / { print $2; exit }' "$PYPROJECT")
BASELINE_INFO=$(node "$GITHUB_WORKSPACE/scripts/release/resolve-python-release-baseline.mjs" \
--source-sha "$SOURCE_SHA" \
--cwd "$GITHUB_WORKSPACE" \
--current-version "$MANIFEST_VERSION" \
--workflow-run-id "$WORKFLOW_RUN_ID" \
--offline "$OFFLINE_BASELINE" \
--repository "$RELEASE_REPOSITORY")
CURRENT_VERSION=$(printf '%s\n' "$BASELINE_INFO" | awk -F= '$1 == "baseline_version" { print $2 }')
LATEST_TAG=$(printf '%s\n' "$BASELINE_INFO" | awk -F= '$1 == "latest_tag" { print $2 }')
RESUMABLE_VERSION=$(printf '%s\n' "$BASELINE_INFO" | awk -F= '$1 == "resumable_version" { print $2 }')
test -n "$CURRENT_VERSION"
echo "Manifest version: $MANIFEST_VERSION"
if [ -n "$LATEST_TAG" ]; then
echo "Release baseline: $CURRENT_VERSION ($LATEST_TAG)"
else
echo "No attested Python release tag found; using the manifest as the initial baseline"
fi
bump_semver() {
local current="$1"
local kind="$2"
# Canonical PEP 440 release with optional a/b/rc prerelease.
if [[ ! "$current" =~ ^(0|[1-9][0-9]*)\.(0|[1-9][0-9]*)\.(0|[1-9][0-9]*)((a|b|rc)(0|[1-9][0-9]*))?$ ]]; then
echo "Invalid version (expected canonical PEP 440 MAJOR.MINOR.PATCH or prerelease): $current" >&2
return 1
fi
local major="${BASH_REMATCH[1]}"
local minor="${BASH_REMATCH[2]}"
local patch="${BASH_REMATCH[3]}"
local pre_kind="${BASH_REMATCH[5]}"
local pre_num="${BASH_REMATCH[6]}"
case "$kind" in
patch)
patch=$((patch + 1)); pre_num="" ;;
minor)
minor=$((minor + 1)); patch=0; pre_num="" ;;
major)
major=$((major + 1)); minor=0; patch=0; pre_num="" ;;
prepatch)
patch=$((patch + 1)); pre_kind="b"; pre_num="0" ;;
preminor)
minor=$((minor + 1)); patch=0; pre_kind="b"; pre_num="0" ;;
premajor)
major=$((major + 1)); minor=0; patch=0; pre_kind="b"; pre_num="0" ;;
prerelease)
if [[ -n "$pre_num" ]]; then
pre_num=$((pre_num + 1))
else
patch=$((patch + 1)); pre_kind="b"; pre_num="0"
fi
;;
*)
echo "Unsupported version bump type: $kind" >&2
return 1 ;;
esac
if [ -n "$pre_num" ]; then
echo "${major}.${minor}.${patch}${pre_kind}${pre_num}"
else
echo "${major}.${minor}.${patch}"
fi
}
if [ -n "$RESUMABLE_VERSION" ]; then
NEW_VERSION="$RESUMABLE_VERSION"
echo "Reusing completed Python SDK release from workflow run $WORKFLOW_RUN_ID: $NEW_VERSION"
elif [ -n "$CUSTOM_VERSION" ]; then
if [[ ! "$CUSTOM_VERSION" =~ ^(0|[1-9][0-9]*)\.(0|[1-9][0-9]*)\.(0|[1-9][0-9]*)((a|b|rc)(0|[1-9][0-9]*))?$ ]]; then
echo "Invalid custom_version (must be canonical PEP 440 MAJOR.MINOR.PATCH or prerelease): $CUSTOM_VERSION"
exit 1
fi
NEW_VERSION="$CUSTOM_VERSION"
echo "Using custom version: $NEW_VERSION"
else
NEW_VERSION=$(bump_semver "$CURRENT_VERSION" "$VERSION_TYPE")
echo "Bumped version: $VERSION_TYPE -> $NEW_VERSION"
fi
RELEASE_TAG="sdk-python-v${NEW_VERSION}"
RELEASE_RECOVERY=false
if git show-ref --verify --quiet "refs/tags/${RELEASE_TAG}"; then
node "${GITHUB_WORKSPACE:-.}/scripts/release/resolve-python-release-baseline.mjs" \
--verify-tag "$RELEASE_TAG" \
--source-sha "$SOURCE_SHA" \
--exact-source true \
--cwd "$GITHUB_WORKSPACE"
RELEASE_RECOVERY=true
echo "Recovering Python SDK release ${RELEASE_TAG} reserved by this source commit"
fi
echo "is_recovery=$RELEASE_RECOVERY" >> "$GITHUB_OUTPUT"
# Update pyproject.toml [project] version (first match only).
awk -v v="$NEW_VERSION" '
!done && /^version = / { print "version = \"" v "\""; done=1; next }
{ print }
END { if (!done) { print "Failed to update version in pyproject.toml" > "/dev/stderr"; exit 1 } }
' "$PYPROJECT" > "$PYPROJECT.tmp" && mv "$PYPROJECT.tmp" "$PYPROJECT"
echo "new_version=$NEW_VERSION" >> "$GITHUB_OUTPUT"
echo "New version: $NEW_VERSION"
- name: Install dependencies
run: |
uv lock
uv sync --all-extras --locked
- name: Run tests
run: uv run python -m pytest
- name: Build distributions
run: uv build
- name: Check distribution metadata
run: uvx twine check dist/*
- name: Check PyPI version state
id: pypi-state
if: github.ref == 'refs/heads/main' && github.event.inputs.dry_run != 'true'
env:
NEW_VERSION: ${{ steps.bump.outputs.new_version }}
RELEASE_RECOVERY: ${{ steps.bump.outputs.is_recovery }}
run: |
set -euo pipefail
for attempt in 1 2 3 4; do
STATUS=$(curl --silent --show-error --connect-timeout 5 --max-time 20 \
--output /dev/null --write-out '%{http_code}' \
"https://pypi.org/pypi/relayfile-sdk/${NEW_VERSION}/json" || true)
case "$STATUS" in
200)
if [ "$RELEASE_RECOVERY" != "true" ]; then
echo "ERROR: relayfile-sdk ${NEW_VERSION} already exists without a same-source tag reservation" >&2
exit 1
fi
echo "published=true" >> "$GITHUB_OUTPUT"
exit 0
;;
404)
echo "published=false" >> "$GITHUB_OUTPUT"
exit 0
;;
429|5??|000)
if [ "$attempt" -eq 4 ]; then
echo "ERROR: PyPI version lookup remained transiently unavailable (HTTP ${STATUS})" >&2
exit 1
fi
sleep $((attempt * 2))
;;
*)
echo "ERROR: PyPI version lookup returned unexpected HTTP ${STATUS}" >&2
exit 1
;;
esac
done
- name: Reserve Python SDK release tag
if: github.ref == 'refs/heads/main' && github.event.inputs.dry_run != 'true'
working-directory: ${{ github.workspace }}
env:
NEW_VERSION: ${{ steps.bump.outputs.new_version }}
SOURCE_SHA: ${{ github.sha }}
RELEASE_RUN_ID: ${{ github.run_id }}
RELEASE_RUN_ATTEMPT: ${{ github.run_attempt }}
run: |
set -euo pipefail
test "$(git rev-parse HEAD)" = "$SOURCE_SHA"
git config user.name "GitHub Actions"
git config user.email "actions@github.com"
TAG="sdk-python-v${NEW_VERSION}"
TAG_TREE=$(git rev-parse "${SOURCE_SHA}^{tree}")
if git show-ref --verify --quiet "refs/tags/${TAG}"; then
node "${GITHUB_WORKSPACE:-.}/scripts/release/resolve-python-release-baseline.mjs" \
--verify-tag "$TAG" \
--source-sha "$SOURCE_SHA" \
--exact-source true \
--cwd "$GITHUB_WORKSPACE"
echo "Python SDK tag ${TAG} is already reserved by this source commit"
exit 0
fi
git tag -a "$TAG" \
-m "relayfile Python SDK v${NEW_VERSION}" \
-m "source-sha=${SOURCE_SHA}" \
-m "tag-tree=${TAG_TREE}" \
-m "workflow-run-id=${RELEASE_RUN_ID}" \
-m "workflow-run-attempt=${RELEASE_RUN_ATTEMPT}"
git push origin "refs/tags/sdk-python-v${NEW_VERSION}:refs/tags/sdk-python-v${NEW_VERSION}"
- name: Publish to PyPI
if: github.ref == 'refs/heads/main' && github.event.inputs.dry_run != 'true' && steps.pypi-state.outputs.published != 'true'
uses: pypa/gh-action-pypi-publish@release/v1
with:
packages-dir: packages/sdk/python/dist
- name: Create GitHub Release
if: github.ref == 'refs/heads/main' && github.event.inputs.dry_run != 'true'
uses: softprops/action-gh-release@3bb12739c298aeb8a4eeaf626c5b8d85266b0e65 # v2
with:
tag_name: sdk-python-v${{ steps.bump.outputs.new_version }}
name: sdk-python-v${{ steps.bump.outputs.new_version }}
body: |
## Python SDK v${{ steps.bump.outputs.new_version }}
### Install
```bash
pip install relayfile-sdk==${{ steps.bump.outputs.new_version }}
```
generate_release_notes: true
env:
GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }}
- name: Summary
if: always()
env:
RELEASE_DRY_RUN: ${{ github.event.inputs.dry_run }}
RELEASE_REF: ${{ github.ref }}
RELEASE_RECOVERY: ${{ steps.bump.outputs.is_recovery }}
NEW_VERSION: ${{ steps.bump.outputs.new_version }}
JOB_STATUS: ${{ job.status }}
run: |
{
echo "## Python SDK Publish Summary"
echo ""
echo "**Version**: \`${NEW_VERSION}\`"
echo "**Dry Run**: \`${RELEASE_DRY_RUN}\`"
echo ""
if [ "$JOB_STATUS" != "success" ]; then
echo "Release failed before completion; inspect the failed workflow step above."
elif [ "$RELEASE_DRY_RUN" = "true" ]; then
echo "Dry run completed. Built and checked dist, but did not publish or tag."
elif [ "$RELEASE_REF" != "refs/heads/main" ]; then
echo "Build and checks completed on a non-main ref; publish, tag, and release were skipped."
elif [ "$RELEASE_RECOVERY" = "true" ]; then
echo "Recovered an existing same-source release tag and PyPI publication."
else
echo "Published to PyPI and created tag \`sdk-python-v${NEW_VERSION}\`."
fi
} >> "$GITHUB_STEP_SUMMARY"