From 182bd326b863c405cb49473c51fe6182a907fc24 Mon Sep 17 00:00:00 2001 From: Ben Vincent Date: Sat, 25 Jul 2026 14:58:24 +1000 Subject: [PATCH] Fix release changelog range and attach RPM + checksums (#18) MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit ## Why The `v0.5.4` release step failed with `Error: open node-lookup-linux-amd64: no such file or directory`, so the Gitea releases page carries **none** of the binaries. Root cause: at v0.5.4 the build loop's shell variables (`${name}`, `${pkg}`, `${osarch%/*}`) were unescaped, so Woodpecker substituted them to empty at YAML-parse time and no cross-compiled binaries were produced. The same blanking left the release `--note` empty (`git log "..v0.5.4"`). The build-loop escaping was already fixed in #16. This PR fixes the two remaining release-step defects and enriches the release assets. ## Changes - Replace the `git describe --tags --abbrev=0 HEAD^` changelog anchor with a previous-tag scan that skips tags on the current commit and picks the newest semver **ancestor** tag. Several tags point at the same commit (v0.5.3 and v0.5.4 both on `f296056`), so `describe HEAD^` jumps the range back to v0.5.1; the scan correctly selects v0.5.2. - Attach the packaged RPM (from `dist/`) and a generated `sha256sums.txt` alongside the 12 cross-compiled binaries. - Build the asset list once and checksum exactly what is uploaded. Keeps `serviceAccountName: default` and the k8s resource requests/limits on the release step unchanged. ## Validation - `check-yaml` / `trailing-whitespace` pre-commit hooks pass. - Local dry-run of the exact release-step shell logic (with `$$`→`$`) from the worktree: `PREV_TAG=v0.5.2`, non-empty notes, and all 13 assets (12 binaries + RPM) plus `sha256sums.txt` resolve on disk. --------- Co-authored-by: Ben Vincent Reviewed-on: https://git.unkin.net/unkin/node-lookup/pulls/18 Co-authored-by: Ben Vincent Co-committed-by: Ben Vincent --- .woodpecker/release.yaml | 35 +++++++++++++++++++++-------------- 1 file changed, 21 insertions(+), 14 deletions(-) diff --git a/.woodpecker/release.yaml b/.woodpecker/release.yaml index 47b7826..528b18c 100644 --- a/.woodpecker/release.yaml +++ b/.woodpecker/release.yaml @@ -113,26 +113,33 @@ steps: tea logins add --name gitea --url https://git.unkin.net --token "$${RELEASER_TOKEN}" --no-version-check # $$ escapes shell vars/substitutions so Woodpecker doesn't blank them # at parse time; ${CI_COMMIT_TAG}/${CI_REPO} are real Woodpecker vars. - PREV_TAG=$$(git describe --tags --abbrev=0 HEAD^ 2>/dev/null || echo "") + # Find the previous release tag for the changelog range. Several tags can + # point at the same commit (e.g. v0.5.3 and v0.5.4), so we skip tags on + # the current commit and pick the newest semver tag that is a real + # ancestor of this one -- describe HEAD^ would jump too far back. + CUR_SHA=$$(git rev-list -n1 "${CI_COMMIT_TAG}") + PREV_TAG="" + for t in $$(git tag --sort=-v:refname); do + [ "$$t" = "${CI_COMMIT_TAG}" ] && continue + [ "$$(git rev-list -n1 "$$t")" = "$$CUR_SHA" ] && continue + if git merge-base --is-ancestor "$$t" "${CI_COMMIT_TAG}" 2>/dev/null; then + PREV_TAG="$$t"; break + fi + done if [ -n "$$PREV_TAG" ]; then NOTES=$$(git log "$${PREV_TAG}..${CI_COMMIT_TAG}" --pretty=format:"- %s") else NOTES=$$(git log --pretty=format:"- %s") fi tea releases create --tag "${CI_COMMIT_TAG}" --title "${CI_COMMIT_TAG}" --note "$${NOTES}" --login gitea --repo "${CI_REPO}" - tea releases assets create "${CI_COMMIT_TAG}" \ - node-lookup-linux-amd64 \ - node-lookup-linux-arm64 \ - node-lookup-darwin-amd64 \ - node-lookup-darwin-arm64 \ - pburl-linux-amd64 \ - pburl-linux-arm64 \ - pburl-darwin-amd64 \ - pburl-darwin-arm64 \ - pblastreport-linux-amd64 \ - pblastreport-linux-arm64 \ - pblastreport-darwin-amd64 \ - pblastreport-darwin-arm64 \ + # The build step writes the 12 cross-compiled binaries into the workspace + # root; the package step writes the RPM to dist/. Generate a checksums + # manifest over everything we attach so downloads can be verified. + RPM=$$(ls dist/*.rpm 2>/dev/null | head -1) + ASSETS="node-lookup-linux-amd64 node-lookup-linux-arm64 node-lookup-darwin-amd64 node-lookup-darwin-arm64 pburl-linux-amd64 pburl-linux-arm64 pburl-darwin-amd64 pburl-darwin-arm64 pblastreport-linux-amd64 pblastreport-linux-arm64 pblastreport-darwin-amd64 pblastreport-darwin-arm64" + [ -n "$$RPM" ] && ASSETS="$$ASSETS $$RPM" + sha256sum $$ASSETS > sha256sums.txt + tea releases assets create "${CI_COMMIT_TAG}" $$ASSETS sha256sums.txt \ --login gitea --repo "${CI_REPO}" depends_on: [upload-rpm] backend_options: