Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
3 changes: 3 additions & 0 deletions .config/wasm-pkg/config.toml
Original file line number Diff line number Diff line change
@@ -0,0 +1,3 @@
[namespace_registries]
wasi = "wasi.dev"
componentized = "componentized.dev"
4 changes: 4 additions & 0 deletions .github/dependabot.yml
Original file line number Diff line number Diff line change
Expand Up @@ -8,6 +8,10 @@ updates:
directory: "/"
schedule:
interval: daily
- package-ecosystem: cargo
directory: "/tools"
schedule:
interval: daily
- package-ecosystem: rust-toolchain
directory: "/"
schedule:
Expand Down
159 changes: 159 additions & 0 deletions .github/workflows/bump-version.yaml
Original file line number Diff line number Diff line change
@@ -0,0 +1,159 @@
name: Bump version

on:
workflow_dispatch:
inputs:
version:
description: The new version of the interface package and crates, e.g. 0.1.0 or 0.2.0-dev
required: true
type: string
default: "0.1.0-dev" # the current version, kept current by scripts/bump-version.sh

jobs:
# bumps the version with read only access, the changes are handed to the pull-request job as a
# patch so the third party actions used to build never run with write access
bump:
runs-on: ubuntu-latest
permissions:
contents: read
steps:
- uses: actions/checkout@v7
with:
persist-credentials: false
- uses: actions-rust-lang/setup-rust-toolchain@v2
- name: Install cargo binstall
uses: cargo-bins/cargo-binstall@main
- name: Install tools
run: |
make tools
echo "${PWD}/target/tools/bin" >> "${GITHUB_PATH}"
- name: Bump version
# also fetches the wit dependencies for the new version, and builds and tests the components
run: scripts/bump-version.sh "${VERSION}"
env:
VERSION: ${{ inputs.version }}
- name: Collect changes
run: |
git add --all
git diff --cached --binary > bump-version.patch
- name: Upload changes
uses: actions/upload-artifact@v7
with:
name: bump-version.patch
path: bump-version.patch
if-no-files-found: error
retention-days: 1

# opens the pull request using only first party actions and the gh cli
pull-request:
needs:
- bump
runs-on: ubuntu-latest
# the branch and pull request are created with a token for the custodian GitHub App rather than
# the GITHUB_TOKEN, which can't change workflow files and doesn't trigger the CI workflow
permissions:
contents: read
env:
VERSION: ${{ inputs.version }}
steps:
- name: Check custodian app credentials
run: |
if [ -z "${CLIENT_ID}" ] || [ -z "${PRIVATE_KEY}" ] ; then
echo "::error::the CUSTODIAN_CLIENT_ID and CUSTODIAN_PRIVATE_KEY secrets must be available to this repository, the private key of the custodian GitHub App is needed to create a token"
exit 1
fi
env:
CLIENT_ID: ${{ secrets.CUSTODIAN_CLIENT_ID }}
PRIVATE_KEY: ${{ secrets.CUSTODIAN_PRIVATE_KEY }}
- name: Create custodian app token
id: app-token
uses: actions/create-github-app-token@v3
with:
client-id: ${{ secrets.CUSTODIAN_CLIENT_ID }}
private-key: ${{ secrets.CUSTODIAN_PRIVATE_KEY }}
# only this repository, with only the permissions the bump needs
repositories: ${{ github.event.repository.name }}
permission-contents: write
permission-pull-requests: write
# the bump changes the default version in this workflow
permission-workflows: write
- uses: actions/checkout@v7
with:
persist-credentials: false
- name: Download changes
uses: actions/download-artifact@v8
with:
name: bump-version.patch
path: ${{ runner.temp }}
- name: Read current version
# the checkout is before the bump, the crates' workspace version is the current version
run: |
current=$( sed -n '/^\[workspace.package\]/,/^\[/s/^version = "\(.*\)"$/\1/p' Cargo.toml )
echo "CURRENT_VERSION=${current}" >> "${GITHUB_ENV}"
- name: Commit changes
# the commit is created with the REST API, as the app's token can't push. The patch is applied
# locally only to find the changed files and their modes.
env:
GH_TOKEN: ${{ steps.app-token.outputs.token }}
APP_SLUG: ${{ steps.app-token.outputs.app-slug }}
run: |
branch="bump-version/${VERSION}"
api="repos/${GITHUB_REPOSITORY}"
base=$( git rev-parse HEAD )
git apply --index "${RUNNER_TEMP}/bump-version.patch"

# a blob for each changed file, or a null sha for a deleted file
entries="${RUNNER_TEMP}/tree-entries.json"
echo '[]' > "${entries}"
git diff --cached --no-renames --name-status "${base}" | while IFS=$'\t' read -r status path ; do
if [ "${status}" = "D" ] ; then
entry=$( jq -n --arg path "${path}" '{path: $path, mode: "100644", type: "blob", sha: null}' )
else
mode=$( git ls-files --stage -- "${path}" | cut -d' ' -f1 )
sha=$( base64 < "${path}" | tr -d '\n' | jq -Rs '{encoding: "base64", content: .}' | gh api --method POST "${api}/git/blobs" --input - --jq .sha )
entry=$( jq -n --arg path "${path}" --arg mode "${mode}" --arg sha "${sha}" '{path: $path, mode: $mode, type: "blob", sha: $sha}' )
fi
jq --argjson entry "${entry}" '. + [$entry]' "${entries}" > "${entries}.tmp" && mv "${entries}.tmp" "${entries}"
echo "${status} ${path}"
done
tree=$( jq --arg base "$( git rev-parse "${base}^{tree}" )" '{base_tree: $base, tree: .}' "${entries}" | gh api --method POST "${api}/git/trees" --input - --jq .sha )

# authored and signed off (DCO) by the user who triggered the workflow, with their GitHub
# noreply email so the commit is attributed to them without exposing their email address.
# Committed by the custodian app's bot, which made the commit on their behalf. The commit is
# unsigned, GitHub only signs commits it attributes entirely to the app.
name=$( gh api "users/${GITHUB_ACTOR}" --jq '.name // .login' )
name="${name:-${GITHUB_ACTOR}}"
email="${GITHUB_ACTOR_ID}+${GITHUB_ACTOR}@users.noreply.github.com"
bot="${APP_SLUG}[bot]"
bot_email="$( gh api "users/${bot}" --jq .id )+${bot}@users.noreply.github.com"
commit=$( jq -n \
--arg message "$( printf 'Bump version from %s to %s\n\nSigned-off-by: %s <%s>' "${CURRENT_VERSION}" "${VERSION}" "${name}" "${email}" )" \
--arg tree "${tree}" --arg parent "${base}" --arg name "${name}" --arg email "${email}" \
--arg bot "${bot}" --arg bot_email "${bot_email}" \
'{message: $message, tree: $tree, parents: [$parent], author: {name: $name, email: $email}, committer: {name: $bot, email: $bot_email}}' \
| gh api --method POST "${api}/git/commits" --input - --jq .sha )
echo "created commit ${commit}"

# points the branch at the commit, replacing the branch left by an earlier run for the same version
if gh api "${api}/git/ref/heads/${branch}" --silent 2> /dev/null ; then
gh api --method PATCH "${api}/git/refs/heads/${branch}" -f sha="${commit}" -F force=true --silent
else
gh api --method POST "${api}/git/refs" -f ref="refs/heads/${branch}" -f sha="${commit}" --silent
fi
- name: Open pull request
env:
GH_TOKEN: ${{ steps.app-token.outputs.token }}
run: |
branch="bump-version/${VERSION}"
if [ -n "$( gh pr list --head "${branch}" --state open --json number --jq '.[].number' )" ] ; then
echo "A pull request for ${branch} is already open, updated by the new commit"
exit 0
fi
gh pr create \
--base "${GITHUB_REF_NAME}" \
--head "${branch}" \
--title "Bump version from \`${CURRENT_VERSION}\` to \`${VERSION}\`" \
--body "Bumps the wit package and crates from \`${CURRENT_VERSION}\` to \`${VERSION}\`.

Triggered by @${GITHUB_ACTOR} from the [Bump version](${GITHUB_SERVER_URL}/${GITHUB_REPOSITORY}/actions/runs/${GITHUB_RUN_ID}) workflow."
48 changes: 28 additions & 20 deletions .github/workflows/ci.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -17,21 +17,20 @@ jobs:
- uses: actions-rust-lang/setup-rust-toolchain@v2
- name: Install cargo binstall
uses: cargo-bins/cargo-binstall@main
- name: Install wasmtime
run: cargo binstall --force wasmtime-cli
- name: Install wkg
run: cargo binstall --force wkg
- name: Install wasm-tools
run: cargo binstall --force wasm-tools
- name: Install tools
# the versions pinned in tools/Cargo.toml, on the path for later steps
run: |
make tools
echo "${PWD}/target/tools/bin" >> "${GITHUB_PATH}"
- name: Sync wit
run: make wit
- name: Check for drift in generated wit
run: git diff --exit-code .
- name: Build components
run: make components
- name: Collect components.tar
run: tar -cvf ../components.tar *.wasm*
working-directory: ./lib
run: tar -cvf ../../components.tar .
working-directory: ./target/components
- name: Upload components.tar
uses: actions/upload-artifact@v7
with:
Expand All @@ -41,12 +40,20 @@ jobs:
- name: Test
run: make test
- name: Capture WIT
working-directory: ./lib
working-directory: ./target/components
run: |
for component in *.wasm ; do
echo "::group::${component} ($(du -h ${component} | cut -f1 ))"
wasm-tools component wit "${component}"
echo "::endgroup::"
dump_wit() {
echo "::group::$(basename "$1") ($(du -h "$1" | awk '{print $1}' ))"
wasm-tools component wit "$1"
echo "::endgroup::"
}

# print interface.wasm first
if [ -f interface.wasm ] ; then
dump_wit interface.wasm
fi
for component in $(find . -name '*.wasm' -not -name '*.debug.wasm' -not -name 'interface.wasm' | sort) ; do
dump_wit "${component}"
done

publish:
Expand All @@ -63,21 +70,21 @@ jobs:
- uses: actions-rust-lang/setup-rust-toolchain@v2
- name: Install cargo binstall
uses: cargo-bins/cargo-binstall@main
- name: Install wkg
run: cargo binstall --force wkg
- name: Install wasm-tools
run: cargo binstall --force wasm-tools
- name: Install tools
run: |
make tools
echo "${PWD}/target/tools/bin" >> "${GITHUB_PATH}"
- name: Install cosign
uses: sigstore/cosign-installer@v4.1.2
- name: Download components.tar
uses: actions/download-artifact@v8
with:
name: components.tar
- name: Extract components
run: tar -xvf components.tar -C lib
run: mkdir -p target/components && tar -xvf components.tar -C target/components
- name: Get interface version
id: interface_version
run: echo "VERSION=$( wasm-tools component wit lib/interface.wasm --json | jq -r "[.packages[] | select(.name | contains(\"${GITHUB_REPOSITORY/\//:}@\"))][0].name" | cut -d'@' -f2 )" >> $GITHUB_OUTPUT
run: echo "VERSION=$( wasm-tools component wit target/components/interface.wasm --json | jq -r "[.packages[] | select(.name | contains(\"${GITHUB_REPOSITORY/\//:}@\"))][0].name" | cut -d'@' -f2 )" >> $GITHUB_OUTPUT
- name: Get tag version
if: startsWith(github.ref, 'refs/tags/')
id: tag_version
Expand All @@ -101,7 +108,8 @@ jobs:
with:
draft: true
files: |
lib/*.wasm
target/components/*.wasm
target/components/*/*.wasm
components.tar
fail_on_unmatched_files: true
token: ${{ secrets.GITHUB_TOKEN }}
3 changes: 3 additions & 0 deletions .gitignore
Original file line number Diff line number Diff line change
@@ -1,3 +1,6 @@
/components.tar
/target
.DS_Store
/tools/Cargo.lock
# wit dependencies, fetched by `make wit` from the wkg.toml and wkg.lock files
**/wit/deps/
5 changes: 1 addition & 4 deletions Cargo.toml
Original file line number Diff line number Diff line change
@@ -1,10 +1,7 @@
[workspace]
resolver = "2"
members = [
"components/*",
]
exclude = [
"components/wit",
"components/client",
]

[workspace.dependencies]
Expand Down
Loading
Loading