Invoke POSTLINK
script in mkmf to support codesign on macos (#423)
#395
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
--- | |
name: Build and push docker images | |
on: | |
workflow_dispatch: | |
push: | |
branches: | |
- main | |
tags: | |
- v* | |
concurrency: | |
group: ${{ github.workflow }}-${{ github.ref }} | |
cancel-in-progress: true | |
permissions: | |
contents: read | |
packages: write | |
jobs: | |
docker_images: | |
runs-on: ubuntu-latest | |
strategy: | |
fail-fast: false | |
matrix: | |
platform: | |
- ruby_target: x86_64-linux | |
- ruby_target: x86_64-linux-musl | |
- ruby_target: aarch64-linux | |
- ruby_target: aarch64-linux-musl | |
- ruby_target: arm-linux | |
- ruby_target: x86_64-darwin | |
- ruby_target: arm64-darwin | |
- ruby_target: x64-mingw32 | |
- ruby_target: x64-mingw-ucrt | |
# - ruby_target: x86-linux | |
steps: | |
- uses: actions/checkout@v4 | |
- name: Set rb-sys version variable | |
id: vars | |
run: | | |
version="$(ruby -r $PWD/gem/lib/rb_sys/version.rb -e 'puts RbSys::VERSION')" | |
echo "rb-sys-version=$version" >> $GITHUB_OUTPUT | |
# Test the container | |
- uses: actions/checkout@v4 | |
with: | |
repository: "oxidize-rb/oxi-test" | |
path: "tmp/oxi-test" | |
- uses: ruby/setup-ruby@v1 | |
with: | |
ruby-version: "3.1" | |
- name: Login to Docker Hub | |
if: github.event_name != 'pull_request' | |
uses: docker/login-action@v3 | |
with: | |
username: ${{ secrets.DOCKER_HUB_USERNAME }} | |
password: ${{ secrets.DOCKER_HUB_ACCESS_TOKEN }} | |
- name: Set up QEMU | |
uses: docker/setup-qemu-action@v3 | |
- name: Set up Docker Buildx | |
id: buildx | |
uses: docker/setup-buildx-action@v3 | |
- name: Docker meta | |
id: meta | |
uses: docker/metadata-action@v5 | |
with: | |
images: | | |
${{ secrets.DOCKER_HUB_USERNAME }}/${{ matrix.platform.ruby_target }} | |
flavor: | | |
latest=auto | |
tags: | | |
type=ref,event=branch | |
type=ref,event=pr | |
type=semver,pattern={{version}} | |
type=sha,format=long | |
labels: | |
org.opencontainers.image.description=Image for building native Rust extensions for Ruby on ${{ matrix.platform.ruby_target }} | |
org.opencontainers.image.vendor=oxidize-rb | |
org.oxidize-rb.ruby.platform=${{ matrix.platform.ruby_target }} | |
- name: Docker build | |
uses: docker/build-push-action@v6 | |
with: | |
builder: ${{ steps.buildx.outputs.name }} | |
context: ./docker | |
file: ./docker/Dockerfile.${{ matrix.platform.ruby_target }} | |
platforms: linux/amd64 | |
load: true | |
tags: ${{ steps.meta.outputs.tags }} | |
labels: ${{ steps.meta.outputs.labels }} | |
cache-from: ${{ secrets.DOCKER_HUB_USERNAME }}/${{ matrix.platform.ruby_target }}:cache-${{ steps.vars.outputs.rb-sys-version }} | |
cache-to: ${{ secrets.DOCKER_HUB_USERNAME }}/${{ matrix.platform.ruby_target }}:cache-${{ steps.vars.outputs.rb-sys-version }} | |
- name: Run tests | |
shell: bash | |
run: | | |
echo "::group::Install deps" | |
rb_sys_dock_cache_dir="$HOME/.cache/rb-sys-dock" | |
sudo chmod 777 tmp/oxi-test | |
cd tmp/oxi-test | |
ruby -e "File.write('Gemfile', File.read('Gemfile').gsub(/gem .rb_sys.*$/, 'gem \"rb_sys\", git: \"https://github.com/oxidize-rb/rb-sys\", ref: \"$GITHUB_SHA\"'))" | |
mkdir .cargo | |
echo "[patch.crates-io]" >> .cargo/config.toml | |
for package in rb-sys rb-sys-build rb-sys-env; do | |
echo "$package = { git = 'https://github.com/oxidize-rb/rb-sys', rev = '$GITHUB_SHA' }" >> .cargo/config.toml | |
cargo update -p "$package" | |
done | |
mkdir -p "$rb_sys_dock_cache_dir" | |
export RB_SYS_DOCK_UID="$(id -u)" | |
export RB_SYS_DOCK_GID="$(id -g)" | |
export RB_SYS_DOCK_CACHE_DIR="$rb_sys_dock_cache_dir" | |
bundle install --jobs 4 --retry 3 | |
echo "::endgroup::" | |
echo "::group::Cross build oxi-test gem (sha-$GITHUB_SHA)" | |
bundle exec rb-sys-dock --platform ${{ matrix.platform.ruby_target }} --build --tag "sha-$GITHUB_SHA" --verbose | |
echo "::endgroup::" | |
if [ -f pkg/oxi-test-0.1.0-${{ matrix.platform.ruby_target }}.gem ]; then | |
echo "::group::Unpack oxi-test gem for testing" | |
gem unpack pkg/oxi-test-0.1.0-${{ matrix.platform.ruby_target }}.gem --target=tmp | |
tree tmp/oxi-test-0.1.0-${{ matrix.platform.ruby_target }} | |
echo "::endgroup::" | |
echo "✅ oxi-test gem built successfully" | |
else | |
echo "::group::Debug directory" | |
tree . | |
echo "::endgroup::" | |
echo "❌ oxi-test gem build failed" | |
exit 1 | |
fi | |
- name: Analyze image bloat | |
run: | | |
image="${{ secrets.DOCKER_HUB_USERNAME }}/${{ matrix.platform.ruby_target }}:sha-$GITHUB_SHA" | |
lowest_efficiency="0.95" | |
highest_user_wasted_percent="0.05" | |
case "${{ matrix.platform.ruby_target }}" in | |
x86_64-linux) | |
lowest_efficiency="0.82" | |
highest_user_wasted_percent="0.27" | |
;; | |
esac | |
echo "Running dive on $image with max wasted percent of $lowest_efficiency" | |
docker run --rm -v /var/run/docker.sock:/var/run/docker.sock wagoodman/dive "$image" \ | |
--ci \ | |
--lowestEfficiency "$lowest_efficiency" \ | |
--highestUserWastedPercent "$highest_user_wasted_percent" | |
- name: Docker push | |
uses: docker/build-push-action@v6 | |
with: | |
builder: ${{ steps.buildx.outputs.name }} | |
context: ./docker | |
file: ./docker/Dockerfile.${{ matrix.platform.ruby_target }} | |
platforms: linux/amd64 | |
push: true | |
tags: ${{ steps.meta.outputs.tags }} | |
labels: ${{ steps.meta.outputs.labels }} | |
cache-from: ${{ secrets.DOCKER_HUB_USERNAME }}/${{ matrix.platform.ruby_target }}:cache-${{ steps.vars.outputs.rb-sys-version }} | |
cache-to: ${{ secrets.DOCKER_HUB_USERNAME }}/${{ matrix.platform.ruby_target }}:cache-${{ steps.vars.outputs.rb-sys-version }} | |
- name: Docker Hub Description | |
uses: peter-evans/dockerhub-description@v4 | |
with: | |
username: ${{ secrets.DOCKER_HUB_USERNAME }} | |
password: ${{ secrets.DOCKER_HUB_ACCESS_TOKEN }} | |
repository: rbsys/${{ matrix.platform.ruby_target }} | |
readme-filepath: ./readme.md | |
- name: Slack Noti on Failure | |
uses: 8398a7/action-slack@v3 | |
with: | |
status: ${{ job.status }} | |
fields: repo,message,commit,author,action,eventName,ref,workflow,job,took,pullRequest | |
env: | |
SLACK_WEBHOOK_URL: ${{ secrets.SLACK_WEBHOOK_URL }} | |
if: failure() |