Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
6 changes: 6 additions & 0 deletions .github/actions/checkout/action.yml
Original file line number Diff line number Diff line change
Expand Up @@ -7,9 +7,15 @@ inputs:
Optional deploy key (e.g. `secrets.PUBLISH_PRIVATE_KEY`) for a checkout whose pushes should trigger downstream workflows. A composite action cannot read `secrets.*`, so the caller must plumb the secret through here. Empty (the default) falls back to the standard GITHUB_TOKEN checkout.
required: false
default: ''
fetch-depth:
description: >-
Passed through to actions/checkout. The default shallow checkout suits most jobs; pass '0' for full history plus all tags — required wherever reachability is computed (e.g. rainix-autopublish's soldeer gate reads `git tag --merged HEAD` for next-v intent tags, and refuses to run on a shallow checkout).
required: false
default: '1'
runs:
using: composite
steps:
- uses: actions/checkout@df4cb1c069e1874edd31b4311f1884172cec0e10 # v6
with:
ssh-key: ${{ inputs.ssh-key }}
fetch-depth: ${{ inputs.fetch-depth }}
48 changes: 25 additions & 23 deletions .github/workflows/rainix-autopublish.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -25,7 +25,7 @@ on:
default: ''
soldeer-package:
description: >-
optional Soldeer registry package name (e.g. rain-erc). When set, the workflow publishes on a content change vs the newest published revision. The registry is the version ledger: the publish version is `max(patch_bump(newest published), [package].version)` under semver ordering, so the repo's version line is only an optional FLOOR — edit it in an ordinary PR for a deliberate minor/major jump. First publish (no revisions on the registry yet) uses the local version as-is. The workflow NEVER commits or pushes to the consumer branch: the version line is rewritten to the publish version in the CI checkout only (so the uploaded zip is self-consistent), and the `sol-v<version>` tag + GitHub release are pushed as a tag ref, independent of any branch push — publishing works unchanged on branch-protected mains. A version's deploy-pin snapshot is built and committed by the PR that defines that version's content (main snapshots are frozen constants consumers pin against).
optional Soldeer registry package name (e.g. rain-erc). When set, the workflow publishes on a content change vs the newest published revision. The registry is the version ledger and git tags carry version intent: the publish version is `max(patch_bump(newest published), newest next-v<x.y.z> tag merged into the pushed head)` under semver ordering — push a `next-v<x.y.z>` tag for a deliberate minor/major jump; consumed or stale intent tags are inert under the max. First publish (no revisions on the registry yet) REQUIRES a next-v tag as the explicit version seed. foundry.toml carries NO release metadata: it is never read for a version and never rewritten, and an `[external.package]` / legacy `[package]` section still present in a consumer is simply ignored (excluded from the content hash), so deleting it is content-neutral. The workflow NEVER commits or pushes to the consumer branch: the `sol-v<version>` tag + GitHub release are pushed as a tag ref, independent of any branch push — publishing works unchanged on branch-protected mains. A version's deploy-pin snapshot is built and committed by the PR that defines that version's content (main snapshots are frozen constants consumers pin against).
required: false
type: string
default: ''
Expand All @@ -49,7 +49,7 @@ on:
SOLDEER_API_TOKEN:
required: false
env:
RAINIX_SHA: 558d5d82856d91a479d9d748017b0ab6b9f27a2d
RAINIX_SHA: 5c00627bfaa83920c87596310be4c3f7b345b23d
jobs:
release:
if: ${{ !startsWith(github.event.head_commit.message, 'Package Release') }}
Expand Down Expand Up @@ -85,6 +85,12 @@ jobs:
# falls back to GITHUB_TOKEN over HTTPS — pushes still succeed,
# they just won't trigger tag-listening workflows.
ssh-key: ${{ secrets.PUBLISH_PRIVATE_KEY }}
# Full history + tags: the soldeer gate derives version intent from
# next-v tags merged into the pushed head (`git tag --merged HEAD`),
# which needs the tags AND the ancestry to judge reachability. The
# gate refuses to run on a shallow checkout rather than silently
# missing an intent tag.
fetch-depth: '0'
- uses: rainlanguage/rainix/.github/actions/nix-cachix-setup@main
with:
cachix-auth-token: ${{ secrets.CACHIX_AUTH_TOKEN }}
Expand Down Expand Up @@ -190,16 +196,16 @@ jobs:
# aliasing libs) is excluded, since it is derived from source and a fresh
# `<tag>/` dir appears every release, which would otherwise flag "changed"
# on every merge and republish identical bytecode forever; foundry.toml's
# version line is blanked so a version edit alone is never a content
# change. It derives the publish version from the registry —
# max(patch_bump(newest published), local [package].version) under semver
# ordering, the local line being only a floor, and a first publish (no
# revisions yet) using the local version as-is — and emits
# changed / version. local == published is the normal steady state, not
# an error: nothing ever writes the version line back to the branch. The
# gate logic is Rust, not inline bash or Python
# `[external.package]` / legacy `[package]` release-metadata section (and
# the comment block attached above it) is excluded from the hash, so
# carrying, editing, or deleting that section is never a content change.
# It derives the publish version as max(patch_bump(newest published),
# newest next-v intent tag merged into HEAD) under semver ordering — a
# first publish (no revisions yet) requires a next-v tag as the explicit
# seed, and a malformed next-v tag is a loud error — and emits
# changed / version. The gate logic is Rust, not inline bash or Python
# (rainix-static/src/main.rs); the workflow just runs it inside
# sol-shell, where forge and curl are on PATH.
# sol-shell, where forge, curl and git are on PATH.
- name: Soldeer content gate
if: ${{ inputs.soldeer-package != '' }}
id: soldeer
Expand Down Expand Up @@ -248,12 +254,10 @@ jobs:
echo "NPM_VERSION=$NEW" >> $GITHUB_ENV
git add package.json package-lock.json
git commit -m "Package Release npm-${NEW}"
# Publish the registry-derived version (steps.soldeer.outputs.version).
# foundry.toml's version line is rewritten to it in the CI checkout ONLY,
# so the uploaded zip is self-consistent; nothing commits or pushes the
# rewrite to the consumer branch (a following cargo/npm Tag-and-push
# discards it with `git checkout -- .` before rebasing). The rewrite is
# Rust (rainix-static soldeer-set-version), not sed.
# Publish the gate-derived version (steps.soldeer.outputs.version). The
# version lives in the push spec only: foundry.toml is not read for
# release metadata and not rewritten — the uploaded zip carries whatever
# foundry.toml the repo has.
- name: Publish to Soldeer
if: ${{ inputs.soldeer-package != '' && steps.soldeer.outputs.changed == 'true' }}
env:
Expand All @@ -262,7 +266,6 @@ jobs:
SOLDEER_VERSION: ${{ steps.soldeer.outputs.version }}
run: |
set -euo pipefail
nix develop github:rainlanguage/rainix/${{ env.RAINIX_SHA }}#sol-shell -c rainix-static soldeer-set-version --version "$SOLDEER_VERSION"
nix develop github:rainlanguage/rainix/${{ env.RAINIX_SHA }}#sol-shell -c forge soldeer push "$SOLDEER_PACKAGE~$SOLDEER_VERSION"
# Tag the published content — the commit that triggered this run — and
# push ONLY the tag ref. Deliberately decoupled from any branch push:
Expand Down Expand Up @@ -297,11 +300,10 @@ jobs:
set -euo pipefail
git fetch origin
# Entering the devShell can rewrite generated tracked files (e.g. a
# nix-store pre-commit-config symlink), and a soldeer publish leaves
# its checkout-only foundry.toml version rewrite behind — both dirty
# the tree. The release commit is already made, so restore all such
# leftovers before the rebase, or it aborts with "cannot rebase: You
# have unstaged changes".
# nix-store pre-commit-config symlink), which dirties the tree. The
# release commit is already made, so restore all such leftovers
# before the rebase, or it aborts with "cannot rebase: You have
# unstaged changes".
git checkout -- .
if ! git rebase "origin/${{ github.ref_name }}"; then
if [ -n "${{ inputs.crates }}" ] || [ -n "${{ inputs.crate }}" ]; then
Expand Down
2 changes: 1 addition & 1 deletion .github/workflows/rainix-copy-artifacts.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -2,7 +2,7 @@ name: rainix-copy-artifacts
on:
workflow_call:
env:
RAINIX_SHA: 558d5d82856d91a479d9d748017b0ab6b9f27a2d
RAINIX_SHA: 5c00627bfaa83920c87596310be4c3f7b345b23d
jobs:
copy-artifacts:
runs-on: ubuntu-latest
Expand Down
2 changes: 1 addition & 1 deletion .github/workflows/rainix-manual-sol-artifacts.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -83,7 +83,7 @@ on:
CI_DEPLOY_FLARE_ETHERSCAN_API_KEY:
required: false
env:
RAINIX_SHA: 558d5d82856d91a479d9d748017b0ab6b9f27a2d
RAINIX_SHA: 5c00627bfaa83920c87596310be4c3f7b345b23d
jobs:
deploy:
runs-on: ubuntu-latest
Expand Down
2 changes: 1 addition & 1 deletion .github/workflows/rainix-manual-sol-verify.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -65,7 +65,7 @@ on:
CI_DEPLOY_FLARE_ETHERSCAN_API_KEY:
required: false
env:
RAINIX_SHA: 558d5d82856d91a479d9d748017b0ab6b9f27a2d
RAINIX_SHA: 5c00627bfaa83920c87596310be4c3f7b345b23d
jobs:
verify:
runs-on: ubuntu-latest
Expand Down
2 changes: 1 addition & 1 deletion .github/workflows/rainix-rs-static.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -2,7 +2,7 @@ name: rainix-rs-static
on:
workflow_call:
env:
RAINIX_SHA: 558d5d82856d91a479d9d748017b0ab6b9f27a2d
RAINIX_SHA: 5c00627bfaa83920c87596310be4c3f7b345b23d
jobs:
rs-static:
runs-on: ubuntu-latest
Expand Down
2 changes: 1 addition & 1 deletion .github/workflows/rainix-rs-test.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -2,7 +2,7 @@ name: rainix-rs-test
on:
workflow_call:
env:
RAINIX_SHA: 558d5d82856d91a479d9d748017b0ab6b9f27a2d
RAINIX_SHA: 5c00627bfaa83920c87596310be4c3f7b345b23d
jobs:
rs-test:
strategy:
Expand Down
2 changes: 1 addition & 1 deletion .github/workflows/rainix-rs-wasm-test.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -2,7 +2,7 @@ name: rainix-rs-wasm-test
on:
workflow_call:
env:
RAINIX_SHA: 558d5d82856d91a479d9d748017b0ab6b9f27a2d
RAINIX_SHA: 5c00627bfaa83920c87596310be4c3f7b345b23d
jobs:
rs-wasm-test:
runs-on: ubuntu-latest
Expand Down
2 changes: 1 addition & 1 deletion .github/workflows/rainix-rs-wasm.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -2,7 +2,7 @@ name: rainix-rs-wasm
on:
workflow_call:
env:
RAINIX_SHA: 558d5d82856d91a479d9d748017b0ab6b9f27a2d
RAINIX_SHA: 5c00627bfaa83920c87596310be4c3f7b345b23d
jobs:
rs-wasm:
runs-on: ubuntu-latest
Expand Down
2 changes: 1 addition & 1 deletion .github/workflows/rainix-sol-legal.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -2,7 +2,7 @@ name: rainix-sol-legal
on:
workflow_call:
env:
RAINIX_SHA: 558d5d82856d91a479d9d748017b0ab6b9f27a2d
RAINIX_SHA: 5c00627bfaa83920c87596310be4c3f7b345b23d
jobs:
legal:
runs-on: ubuntu-latest
Expand Down
2 changes: 1 addition & 1 deletion .github/workflows/rainix-sol-static.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -2,7 +2,7 @@ name: rainix-sol-static
on:
workflow_call:
env:
RAINIX_SHA: 558d5d82856d91a479d9d748017b0ab6b9f27a2d
RAINIX_SHA: 5c00627bfaa83920c87596310be4c3f7b345b23d
jobs:
static:
runs-on: ubuntu-latest
Expand Down
2 changes: 1 addition & 1 deletion .github/workflows/rainix-sol-test.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -23,7 +23,7 @@ on:
RPC_URL_POLYGON_FORK:
required: false
env:
RAINIX_SHA: 558d5d82856d91a479d9d748017b0ab6b9f27a2d
RAINIX_SHA: 5c00627bfaa83920c87596310be4c3f7b345b23d
jobs:
test:
runs-on: ubuntu-latest
Expand Down
2 changes: 1 addition & 1 deletion .github/workflows/rainix-subgraph-test.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -2,7 +2,7 @@ name: rainix-subgraph-test
on:
workflow_call:
env:
RAINIX_SHA: 558d5d82856d91a479d9d748017b0ab6b9f27a2d
RAINIX_SHA: 5c00627bfaa83920c87596310be4c3f7b345b23d
jobs:
subgraph-test:
runs-on: ubuntu-latest
Expand Down
7 changes: 4 additions & 3 deletions .github/workflows/rainix-tag-release.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -8,8 +8,9 @@ name: rainix-tag-release
#
# * A LIBRARY repo (rainix-autopublish) publishes on content change at
# merge: the publish version is derived from the registry (newest
# published revision, patch-bumped, with [package].version as an optional
# floor) and nothing is ever committed or pushed back to the branch.
# published revision, patch-bumped) with `next-v<x.y.z>` git tags carrying
# any larger version intent, foundry.toml holds no release metadata, and
# nothing is ever committed or pushed back to the branch.
Comment thread
coderabbitai[bot] marked this conversation as resolved.
# Consumers import its abstract surface (interfaces/libs); it never pins a
# deployed address, so it carries no per-tag deploy-pin snapshot.
#
Expand Down Expand Up @@ -103,7 +104,7 @@ on:
RPC_URL_POLYGON_FORK:
required: false
env:
RAINIX_SHA: 558d5d82856d91a479d9d748017b0ab6b9f27a2d
RAINIX_SHA: 5c00627bfaa83920c87596310be4c3f7b345b23d
jobs:
# The release tag must point at a commit already merged to the release branch.
# `on: push: tags` fires for ANY tag, including one cut from an unmerged branch;
Expand Down
28 changes: 8 additions & 20 deletions rainix-static/src/main.rs
Original file line number Diff line number Diff line change
Expand Up @@ -43,17 +43,13 @@
// soldeer-gate --package <name> [--github-output <file>]
// Soldeer content gate: compare the normalized content of what
// `forge soldeer push --dry-run` would upload against the newest published
// revision, derive the publish version from the registry
// (max(patch_bump(newest published), local [package].version) under
// semver ordering; the local version line is only a floor), and emit
// changed / version. Runs inside sol-shell, so `forge` and `curl` are
// on PATH.
// soldeer-set-version --version <x.y.z>
// rewrite the cwd's foundry.toml first `version = "…"` line (the
// [package] version) to the given version, in place. rainix-autopublish
// runs it in the CI checkout just before `forge soldeer push`, so the
// uploaded zip carries the version it is published under; the rewrite is
// never committed or pushed.
// revision (foundry.toml's `[external.package]` / legacy `[package]`
// release-metadata section is excluded from the hash), derive the publish
// version as max(patch_bump(newest published), newest `next-v<x.y.z>`
// intent tag merged into HEAD) under semver ordering — a first publish
// requires an intent tag — and emit changed / version. Needs a full-depth
// checkout with tags; runs inside sol-shell, so `forge`, `curl` and `git`
// are on PATH.
// rpc-preflight [--root <dir>] [--github-env <file>] [--samples N]
// [--timeout N] [--no-archive]
// Pick a working fork RPC endpoint per network and export it as
Expand Down Expand Up @@ -165,13 +161,6 @@ fn main() {
.unwrap_or_else(|| fail("soldeer-gate: --package <name> required"));
soldeer_gate::run(&pkg, flag(&args, "--github-output").as_deref());
}
"soldeer-set-version" => {
let version = flag(&args, "--version")
.unwrap_or_else(|| fail("soldeer-set-version: --version <x.y.z> required"));
if let Err(e) = soldeer_gate::set_version(Path::new("."), &version) {
fail(&e);
}
}
"snapshots-append-only" => {
let base = flag(&args, "--base").unwrap_or_else(|| "origin/main".to_string());
let root = flag(&args, "--root").unwrap_or_else(|| "src/generated".to_string());
Expand Down Expand Up @@ -213,8 +202,7 @@ fn main() {
eprintln!(
"rainix-static: unknown subcommand {other:?} \
(available: no-submodules, agent-context-cap, prompt-cap, \
snapshots-append-only, soldeer-gate, soldeer-set-version, \
rpc-preflight)"
snapshots-append-only, soldeer-gate, rpc-preflight)"
);
std::process::exit(2);
}
Expand Down
Loading
Loading