113 lines
5.5 KiB
Bash
113 lines
5.5 KiB
Bash
#!/bin/bash
|
|
# The newest published release, for the e2e workflow's readme and upgrade jobs, and what
|
|
# their installer logs must show about how that release reached the host:
|
|
#
|
|
# bash deploy/e2e_release.sh find # tag, binary, sums into $GITHUB_OUTPUT
|
|
# bash deploy/e2e_release.sh check-own LOG # the release's own installer (upgrade)
|
|
# bash deploy/e2e_release.sh check-readme LOG # this commit's installer on its default
|
|
# # channel, the README's command (readme)
|
|
#
|
|
# The checks read TAG, BINARY and SUMS from the environment, as find wrote them. The
|
|
# runners are x86_64, so the binary asset is felis-linux-amd64. deploy/e2e_release_test.sh
|
|
# holds this script's own checks, against bootstrap.sh's own messages.
|
|
set -euo pipefail
|
|
|
|
ASSET=felis-linux-amd64
|
|
HOST_BIN=/usr/local/bin/felis
|
|
fails=0
|
|
|
|
pass() { printf 'PASS %s\n' "$*"; }
|
|
fail() { printf 'FAIL %s\n' "$*"; fails=$((fails + 1)); }
|
|
has() { # label fixed-string log
|
|
if grep -qF -- "$2" "$3"; then pass "$1"; else fail "$1: no line with <$2> in $3"; fi
|
|
}
|
|
has_re() { # label regex log
|
|
if grep -qE -- "$2" "$3"; then pass "$1"; else fail "$1: no line matching <$2> in $3"; fi
|
|
}
|
|
lacks_re() { # label regex log
|
|
local hit
|
|
if hit="$(grep -E -m 1 -- "$2" "$3")"; then fail "$1: ${hit}"; else pass "$1"; fi
|
|
}
|
|
|
|
# find_release: `gh release view` with no tag answers with the newest release that is not a
|
|
# prerelease, the one the installer's release channel resolves.
|
|
#
|
|
# An empty tag skips the readme and upgrade jobs, green. Only gh's own `release not found`
|
|
# means there is no release; any other failure (a token it refused, a rate limit, a network
|
|
# error) fails the step, or every release's upgrade would go untested without a word.
|
|
find_release() {
|
|
local lines err rc=0 tag names binary="" sums=""
|
|
err="$(mktemp)"
|
|
lines="$(gh release view --repo "$GITHUB_REPOSITORY" --json tagName,assets --jq '.tagName, .assets[].name' 2>"$err")" || rc=$?
|
|
if [ "$rc" -ne 0 ] && grep -qx 'release not found' "$err"; then
|
|
rm -f "$err"
|
|
echo "::notice::no published release yet; the readme and upgrade jobs have nothing to install"
|
|
printf 'tag=\nbinary=\nsums=\n' >> "${GITHUB_OUTPUT:-/dev/stdout}"
|
|
return 0
|
|
fi
|
|
if [ "$rc" -ne 0 ]; then
|
|
echo "::error::gh release view failed (exit ${rc}), so the newest release is unknown: $(tr '\n' ' ' < "$err")"
|
|
rm -f "$err"
|
|
fails=$((fails + 1))
|
|
return
|
|
fi
|
|
rm -f "$err"
|
|
tag="$(printf '%s\n' "$lines" | head -n 1)"
|
|
names="$(printf '%s\n' "$lines" | tail -n +2)"
|
|
if [ -z "$tag" ]; then
|
|
echo "::error::gh release view answered without a tag"
|
|
fails=$((fails + 1))
|
|
return
|
|
fi
|
|
if printf '%s\n' "$names" | grep -qxF "$ASSET"; then binary=yes; fi
|
|
if printf '%s\n' "$names" | grep -qxF SHA256SUMS; then sums=yes; fi
|
|
printf 'tag=%s\nbinary=%s\nsums=%s\n' "$tag" "$binary" "$sums" >> "${GITHUB_OUTPUT:-/dev/stdout}"
|
|
}
|
|
|
|
# check_own: a release's installer, however old, downloads the release's binary when the
|
|
# release publishes one, and says so in the same words.
|
|
check_own() {
|
|
local log="$1"
|
|
if [ "${BINARY:-}" != yes ]; then
|
|
echo "::notice::release ${TAG} publishes no ${ASSET}; its installer builds it from source"
|
|
return 0
|
|
fi
|
|
has "the release's installer installed the release's binary" "installed ${ASSET} ${TAG} at ${HOST_BIN}" "$log"
|
|
}
|
|
|
|
# check_readme: this commit's installer takes everything from a release that publishes its
|
|
# SHA256SUMS and builds nothing on the host; from one without, it builds the tag from source
|
|
# and says why.
|
|
check_readme() {
|
|
local log="$1" role
|
|
if [ "${BINARY:-}" = yes ] && [ "${SUMS:-}" = yes ]; then
|
|
has "the binary is the release's" "installed ${ASSET} ${TAG} at ${HOST_BIN}" "$log"
|
|
has "the images and plugin come from the release" "release ${TAG}'s prebuilt images and Velocity plugin are installed as published" "$log"
|
|
for role in felis limbo lobby paper; do
|
|
has_re "felis/${role} is the release's" "felis/${role}:[^ ]* is the release's" "$log"
|
|
done
|
|
has_re "the registry image is the release's" "docker.io/library/registry@sha256:[0-9a-f]* is the release's" "$log"
|
|
has_re "the postgres image is the release's" "docker.io/library/postgres@sha256:[0-9a-f]* is the release's" "$log"
|
|
has "felis-velocity.jar is the release's" "felis-velocity.jar is the release's" "$log"
|
|
lacks_re "nothing fell back to a build or a pull" "on this host instead|from Docker Hub instead|building felis from source" "$log"
|
|
lacks_re "Docker was left alone" "docker already installed|installing docker|docker running" "$log"
|
|
elif [ "${BINARY:-}" = yes ]; then
|
|
has "the source build says why" "release ${TAG} publishes no SHA256SUMS, so ${ASSET} cannot be verified; building ${TAG} from source on this host instead" "$log"
|
|
echo "::warning::release ${TAG} publishes no SHA256SUMS, so the README's install builds ${TAG} from source on the host, Docker included; a release cut by release.yml puts it on the assets"
|
|
else
|
|
has "the source build says why" "release ${TAG} publishes no usable ${ASSET}; building ${TAG} from source on this host instead" "$log"
|
|
echo "::warning::release ${TAG} publishes no ${ASSET}, so the README's install builds ${TAG} from source on the host, Docker included; a release cut by release.yml puts it on the assets"
|
|
fi
|
|
}
|
|
|
|
case "${1:-}" in
|
|
find) find_release ;;
|
|
check-own) check_own "${2:?usage: e2e_release.sh check-own LOG}" ;;
|
|
check-readme) check_readme "${2:?usage: e2e_release.sh check-readme LOG}" ;;
|
|
*)
|
|
echo "usage: e2e_release.sh find | check-own LOG | check-readme LOG" >&2
|
|
exit 2
|
|
;;
|
|
esac
|
|
exit "$fails"
|