Repository navigation
Externalise cache keys to prevent unneeded invalidation #3922
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
base: main
Are you sure you want to change the base?
Changes from all commits
File filter
Filter by extension
Conversations
Jump to
Diff view
Diff view
There are no files selected for viewing
| Original file line number | Diff line number | Diff line change |
|---|---|---|
| @@ -0,0 +1,8 @@ | ||
| #!/bin/bash | ||
| # The following version pinnings are semi-automatically checked for updates. | ||
| # Verify .github/workflows/bump-dependencies.yml when changing those manually: | ||
|
|
||
| # Values are consumed by ios.sh and the dependency cache key. | ||
| # shellcheck disable=SC2034 | ||
| AQTINSTALL_VERSION=3.3.0 | ||
| QT_VERSION=5.15.2 | ||
| Original file line number | Diff line number | Diff line change |
|---|---|---|
| @@ -0,0 +1,9 @@ | ||
| #!/bin/bash | ||
| # The following version pinnings are semi-automatically checked for updates. | ||
| # Verify .github/workflows/bump-dependencies.yml when changing those manually: | ||
|
|
||
| # Values are consumed by .github/autobuild/mac.sh, mac/deploy_mac.sh and the dependency cache key. | ||
| # shellcheck disable=SC2034 | ||
| AQTINSTALL_VERSION=3.3.0 | ||
| QT_VERSION=5.15.2 | ||
| CREATEDMG_VERSION=1.3.0 |
| Original file line number | Diff line number | Diff line change |
|---|---|---|
| @@ -0,0 +1,9 @@ | ||
| #!/bin/bash | ||
| # The following version pinnings are semi-automatically checked for updates. | ||
| # Verify .github/workflows/bump-dependencies.yml when changing those manually: | ||
|
|
||
| # Values are consumed by .github/autobuild/mac.sh, mac/deploy_mac.sh and the dependency cache key. | ||
| # shellcheck disable=SC2034 | ||
| AQTINSTALL_VERSION=3.3.0 | ||
| QT_VERSION=6.10.2 | ||
| CREATEDMG_VERSION=1.3.0 |
| Original file line number | Diff line number | Diff line change |
|---|---|---|
|
|
@@ -48,10 +48,13 @@ | |
|
|
||
| set -eu | ||
|
|
||
| QT=${QT:-6} | ||
| PROJECT_DIR="$(cd "$(dirname "${BASH_SOURCE[0]}")/../.." && pwd)" | ||
| readonly PROJECT_DIR | ||
| # shellcheck disable=SC1090 | ||
| source "${PROJECT_DIR}/.github/autobuild/mac-dependencies_qt${QT}.sh" | ||
|
Member
There was a problem hiding this comment. Choose a reason for hiding this commentThe reason will be displayed to describe this comment to others. Learn more. Do we have a guarantee that ${QT} is safe and correct? I'd add an error check if the file exists before.
Collaborator
Author
There was a problem hiding this comment. Choose a reason for hiding this commentThe reason will be displayed to describe this comment to others. Learn more. It's set from the autobuild workflow file and, if not, defaults to 6 at the top of the file. If someone sets the wrong value, this command will safely crash the workflow.
Member
There was a problem hiding this comment. Choose a reason for hiding this commentThe reason will be displayed to describe this comment to others. Learn more. I'd still like a guard to reject invalid values.
Member
There was a problem hiding this comment. Choose a reason for hiding this commentThe reason will be displayed to describe this comment to others. Learn more. There was a problem hiding this comment. Choose a reason for hiding this commentThe reason will be displayed to describe this comment to others. Learn more. 🧩 Analysis chain🏁 Script executed: #!/bin/bash
set -euo pipefail
printf '%s\n' '== mac dependency scripts =='
fd -a -t f '^mac-dependencies_qt.*\.sh$' .github/autobuild -x sh -c 'printf "%s\n" "$1"' sh {}
printf '%s\n' '== QT assignments and mac.sh invocations in GitHub workflows =='
rg -n -C 3 --glob '*.yml' --glob '*.yaml' \
'(^|[[:space:]])QT[=:]|mac\.sh|mac-dependencies_qt' .github
printf '%s\n' '== source sites for mac-dependencies scripts =='
rg -n -C 3 'source .*mac-dependencies_qt|mac-dependencies_qt' .githubLength of output: 5420
The workflow currently uses only Add an allowlist before the QT=${QT:-6}
case "${QT}" in
5|6) ;;
*)
echo "Environment variable QT must be 5 or 6"
exit 1
;;
esacThis makes the supported interface explicit and prevents unexpected dependency-script paths. You are interacting with an AI system.
Collaborator
Author
There was a problem hiding this comment. Choose a reason for hiding this commentThe reason will be displayed to describe this comment to others. Learn more. No, it makes a claim that's unjustified. If there were a There was a problem hiding this comment. Choose a reason for hiding this commentThe reason will be displayed to describe this comment to others. Learn more.
Collaborator
Author
There was a problem hiding this comment. Choose a reason for hiding this commentThe reason will be displayed to describe this comment to others. Learn more. The point being, someone could rename |
||
|
|
||
| QT_DIR=~/qt | ||
| # The following version pinnings are semi-automatically checked for | ||
| # updates. Verify .github/workflows/bump-dependencies.yaml when changing those manually: | ||
| AQTINSTALL_VERSION=3.3.0 | ||
|
|
||
| TARGET_ARCHS="${TARGET_ARCHS:-}" | ||
|
|
||
|
|
@@ -65,7 +68,8 @@ if [[ ! ${JAMULUS_BUILD_VERSION:-} =~ [0-9]+\.[0-9]+\.[0-9]+ ]]; then | |
| fi | ||
|
|
||
| setup() { | ||
| if [[ -d "${QT_DIR}" ]]; then | ||
| if [[ -x "${QT_DIR}/${QT_VERSION}/macos/bin/qmake" && | ||
| -x "${QT_DIR}/${QT_VERSION}/macos/bin/macdeployqt" ]]; then | ||
| echo "Using Qt installation from previous run (actions/cache)" | ||
| else | ||
| echo "Installing Qt..." | ||
|
|
@@ -194,7 +198,7 @@ build_app_as_dmg_installer() { | |
| if prepare_signing; then | ||
| BUILD_ARGS=("-s" "${MACOS_CERTIFICATE_DEV_ID_APPLICATION_ID}" "-a" "${MAC_STORE_APP_CERT_ID}" "-i" "${MACOS_CERTIFICATE_INST_DISTRIBUTION_ID}" "-k" "${KEYCHAIN_PASSWORD}") | ||
| fi | ||
| TARGET_ARCHS="${TARGET_ARCHS}" ./mac/deploy_mac.sh "${BUILD_ARGS[@]}" | ||
| QT=${QT} TARGET_ARCHS="${TARGET_ARCHS}" ./mac/deploy_mac.sh "${BUILD_ARGS[@]}" | ||
| } | ||
|
|
||
| pass_artifact_to_job() { | ||
|
|
||
| Original file line number | Diff line number | Diff line change |
|---|---|---|
| @@ -0,0 +1,19 @@ | ||
| # The following version pinnings are semi-automatically checked for updates. | ||
| # Verify .github/workflows/bump-dependencies.yml when changing those manually: | ||
|
|
||
| # Values are consumed by .github/autobuild/windows.ps1, windows/deploy_windows.ps1 and the dependency cache key. | ||
| $Qt32Version = "5.15.2" | ||
| $Qt64Version = "6.10.2" | ||
| $QtCompile32 = "msvc2019" | ||
| $QtCompile64 = "msvc2022" | ||
| $AqtinstallVersion = "3.3.0" | ||
| $JackVersion = "1.9.22" | ||
| $JomVersion = "1.1.2" | ||
|
|
||
| # Important: | ||
| # - Do not update ASIO SDK without checking for license-related changes. | ||
| # - Do not copy (parts of) the ASIO SDK into the Jamulus source tree without | ||
| # further consideration as it would make the license situation more complicated. | ||
|
ann0see marked this conversation as resolved.
|
||
| $AsioSDKVersion = "ASIO-SDK_2.3.4_2025-10-15" | ||
|
|
||
| $NsisVersion = "3.12" | ||
| Original file line number | Diff line number | Diff line change |
|---|---|---|
|
|
@@ -36,51 +36,50 @@ jobs: | |
| fail-fast: false | ||
| matrix: | ||
| components: | ||
|
|
||
| - name: aqt | ||
| # not Changelog-worthy | ||
| get_upstream_version: GH_REPO=miurahr/aqtinstall gh release view --json tagName --jq .tagName | sed -re 's/^v//' | ||
| # The following regexps capture both the *nix and the Windows variable syntax (different case, underscore): | ||
| local_version_regex: (.*AQTINSTALL_?VERSION\s*=\s*"?)([0-9.]*)("?.*) | ||
| # Capture the POSIX-style and PowerShell assignments used by the dependency files. | ||
| local_version_regex: ^(AQTINSTALL_VERSION=|\$AqtinstallVersion = \")([0-9.]+)(|\")$ | ||
|
|
||
| - name: create-dmg | ||
| changelog_name: create-dmg (macOS) | ||
| get_upstream_version: GH_REPO=create-dmg/create-dmg gh release view --json tagName --jq .tagName | sed -re 's/^v//' | ||
| local_version_regex: (.*CREATEDMG_VERSION\s*=\s*"?)([0-9.]*)("?.*) | ||
| local_version_regex: ^(CREATEDMG_VERSION=)([0-9.]+)()$ | ||
|
|
||
| - name: Qt6 | ||
| changelog_name: bundled Qt6 | ||
| get_upstream_version: | | ||
| latest_minor="$(curl -s https://download.qt.io/official_releases/qt/ | grep -oP 'href="\K[0-9.]+(?=/")' | sort --reverse --version-sort | head -n1)"; | ||
| curl -s https://download.qt.io/official_releases/qt/"${latest_minor}"/ | grep -oP 'href="\K[0-9.]+(?=/")' | sort --reverse --version-sort | head -n1 | ||
| # The following regex captures both the *nix and the Windows variable syntax (different case, underscore): | ||
| local_version_regex: (.*QT[0-9_]+VERSION\s*=\s*"?)(6\.[0-9.]+)("?.*) | ||
| local_version_regex: ^(QT_VERSION=|\$Qt64Version = \")(6\.[0-9.]+)(|\")$ | ||
|
|
||
| - name: jack | ||
| changelog_name: bundled JACK (Windows-only) | ||
| get_upstream_version: GH_REPO=jackaudio/jack2-releases gh release view --json tagName --jq .tagName | sed -re 's/^v//' | ||
| local_version_regex: (.*JackVersion\s*=\s*"?)([0-9.]+)("?.*) | ||
| local_version_regex: ^(\$JackVersion = \")([^"]+)(\")$ | ||
|
|
||
| - name: choco-jom | ||
| # not Changelog-worthy | ||
| get_upstream_version: | | ||
| curl -sL "https://community.chocolatey.org/api/v2/FindPackagesById()?id='jom'" | | ||
| grep -oP '(?<=<d:Version>)[^<]+' | sort --version-sort | tail -n1 | ||
| local_version_regex: (.*JomVersion\s*=\s*"?)([0-9.]+)("?.*) | ||
| local_version_regex: ^(\$JomVersion = \")([^"]+)(\")$ | ||
|
|
||
| - name: NSIS | ||
| changelog_name: Windows Installer base (NSIS) | ||
| get_upstream_version: | | ||
| curl -s -o /dev/null --location --range 0-5 --write-out '%{url_effective}' https://sourceforge.net/projects/nsis/files/latest/download | | ||
| grep -oP '.*/nsis-\K[0-9.]+(?=-setup\.)' | ||
| # This pattern is a bit special as it has to match twice in a single line. | ||
| # Therefore, we have to be very careful to avoid consuming too much pattern space. | ||
| # This is why a positive lookahead is used instead of direct matching: | ||
| local_version_regex: (.*"nsis-|.*\/NSIS.20.\/|\/nsis-)([0-9.]+)(".*|(?=\/nsis-)|\.zip.*) | ||
| local_version_regex: ^(\$NsisVersion = \")([^"]+)(\")$ | ||
|
|
||
| - name: ASIO-SDK | ||
| changelog_name: ASIO SDK (Windows-only) | ||
| get_upstream_version: | | ||
| curl -s -o /dev/null --location --range 0-5 --write-out '%{url_effective}' https://www.steinberg.net/asiosdk | | ||
| grep -oP '.*\K(?:ASIO-SDK|asiosdk)_.*(?=\.zip)' | ||
| local_version_regex: (.*["\/])((?:ASIO-SDK|asiosdk)_[^"]+?)(".*|\.zip.*) | ||
| local_version_regex: ^(\$AsioSDKVersion = \")([^"]+)(\")$ | ||
|
|
||
| steps: | ||
| - uses: actions/checkout@v7 | ||
|
|
@@ -91,9 +90,12 @@ jobs: | |
| GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }} | ||
| run: | | ||
| set -eu | ||
| files=( .github/{autobuild,workflows}/* windows/*.ps1 mac/*.sh ) | ||
| files=( .github/autobuild/*-dependencies{,_qt[56]}.* ) | ||
| echo "files: (${files[@]})" | ||
| upstream_version="$(${{ matrix.components.get_upstream_version }})" | ||
| local_version="$(perl -nle 'print "$2" if /${{ matrix.components.local_version_regex }}/i' "${files[@]}" | sort --reverse --version-sort | head -n1)" | ||
| echo "upstream version: {${upstream_version}}" | ||
| local_version="$(perl -nle 'print "$2" if /${{ matrix.components.local_version_regex }}/' "${files[@]}" | sort --reverse --version-sort | head -n1)" | ||
|
coderabbitai[bot] marked this conversation as resolved.
|
||
| echo "local version: {${local_version}}" | ||
| if [[ -z "$upstream_version" ]]; then | ||
| echo "failed to extract upstream version" | ||
| exit 1 | ||
|
|
@@ -106,13 +108,12 @@ jobs: | |
| echo "upstream ${{ matrix.components.name }} (${upstream_version}) matches local ${{ matrix.components.name }} (${local_version})" | ||
| exit 0 | ||
| fi | ||
| echo "upstream ${{ matrix.components.name }} (${upstream_version}) is different than local ${{ matrix.components.name }} (${local_version}), creating PR" | ||
| echo "upstream ${{ matrix.components.name }} (${upstream_version}) does not match local ${{ matrix.components.name }} (${local_version}), creating PR" | ||
| git config --global user.email "[email protected]" | ||
| git config --global user.name "github-actions[bot]" | ||
| pr_branch=ci/bump-dependencies/${{ matrix.components.name }} | ||
| git checkout -b "${pr_branch}" | ||
| # sed does not support replacements with overlapping or lookahead patterns as is the case with NSIS. | ||
| # Therefore, use perl instead: | ||
| # Use Perl so the replacement can preserve the prefix and suffix captured by each component regex. | ||
| perl -pe 's/${{ matrix.components.local_version_regex }}/${1}'"${upstream_version}"'${3}/gi' -i "${files[@]}" | ||
| git add . | ||
| title="Build: Bump ${{ matrix.components.name }} from ${local_version} to ${upstream_version}" | ||
|
|
||
Uh oh!
There was an error while loading. Please reload this page.