srdusr
aboutsummaryrefslogtreecommitdiffstats
diff options
context:
space:
mode:
-rw-r--r--.github/workflows/ci.yml35
-rw-r--r--.github/workflows/release.yml53
-rw-r--r--PLAN.md28
-rw-r--r--README.md7
4 files changed, 122 insertions, 1 deletions
diff --git a/.github/workflows/ci.yml b/.github/workflows/ci.yml
new file mode 100644
index 0000000..c65adb1
--- /dev/null
+++ b/.github/workflows/ci.yml
@@ -0,0 +1,35 @@
+name: CI
+
+on:
+ push:
+ branches: [main]
+ pull_request:
+ branches: [main]
+
+jobs:
+ test:
+ # Linux is the only platform this project has actually run on and
+ # verified live (see README's Platforms section) - testing here
+ # matches that honestly rather than pretending untested platforms
+ # are covered. Cross-platform coverage is a build-only check below,
+ # not a behavioral one.
+ runs-on: ubuntu-latest
+ steps:
+ - uses: actions/checkout@v4
+ - uses: actions/setup-go@v5
+ with:
+ go-version-file: go.mod
+ - run: make test
+
+ cross-build:
+ # CGO_ENABLED=0 + pure-Go SQLite means every platform in the
+ # Makefile's release matrix cross-compiles cleanly from Linux alone
+ # - no need for actual macOS/Windows runners just to confirm the
+ # build still succeeds on every target.
+ runs-on: ubuntu-latest
+ steps:
+ - uses: actions/checkout@v4
+ - uses: actions/setup-go@v5
+ with:
+ go-version-file: go.mod
+ - run: make release
diff --git a/.github/workflows/release.yml b/.github/workflows/release.yml
new file mode 100644
index 0000000..35def39
--- /dev/null
+++ b/.github/workflows/release.yml
@@ -0,0 +1,53 @@
+name: Release
+
+# Fires on a version tag push (v1.2.3, v1.2.3-rc1, etc.) - cross-compiles
+# every platform in the Makefile's release matrix, packages each into a
+# single archive (.tar.gz on Unix, .zip on Windows, since that's what
+# each platform's own tools handle natively without asking a user to
+# install anything extra), and attaches them to a GitHub Release created
+# from the tag. Uses the gh CLI (preinstalled on GitHub-hosted runners,
+# authenticated via the automatic GITHUB_TOKEN) rather than a
+# third-party Marketplace action, matching this project's own general
+# preference for minimizing external dependencies - see e.g. pure-Go
+# SQLite over CGO in go.mod.
+on:
+ push:
+ tags:
+ - "v*"
+
+permissions:
+ contents: write
+
+jobs:
+ release:
+ runs-on: ubuntu-latest
+ steps:
+ - uses: actions/checkout@v4
+ - uses: actions/setup-go@v5
+ with:
+ go-version-file: go.mod
+
+ - run: make release
+
+ - name: Package archives
+ run: |
+ set -eu
+ mkdir -p out
+ for dir in dist/*/; do
+ name=$(basename "$dir")
+ if [[ "$name" == *windows* ]]; then
+ (cd dist && zip -r "../out/$name.zip" "$name")
+ else
+ tar -czf "out/$name.tar.gz" -C dist "$name"
+ fi
+ done
+ cd out && sha256sum * > SHA256SUMS
+
+ - name: Create release
+ env:
+ GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }}
+ run: |
+ gh release create "${{ github.ref_name }}" \
+ --title "${{ github.ref_name }}" \
+ --generate-notes \
+ out/*
diff --git a/PLAN.md b/PLAN.md
index e95622c..bf30b0c 100644
--- a/PLAN.md
+++ b/PLAN.md
@@ -747,3 +747,31 @@ numbers orange, booleans/null magenta, punctuation gray, confirmed
against the raw captured ANSI codes, not just eyeballed - and the
request tab (never JSON, never pretty-printed) rendered as plain
unstyled text, unaffected.
+
+## CI and release automation
+
+`.github/workflows/ci.yml`: `make test` (build/vet/gofmt/test) on
+every push/PR, Linux only - matches the README's own honest claim that
+Linux is the only platform actually run and verified, rather than
+pretending untested platforms are behaviorally covered by CI. A
+separate `make release` job cross-compiles every platform in the
+Makefile's matrix on the same Linux runner (`CGO_ENABLED=0` + pure-Go
+SQLite means this needs no macOS/Windows runner at all) as a build-only
+check - catches a platform-specific compile break without paying for
+real hardware to do it.
+
+`.github/workflows/release.yml`: fires on a `v*` tag push, runs `make
+release`, packages each platform's directory into a single archive
+(`.tar.gz` Unix, `.zip` Windows - whatever each platform's own tools
+already handle, no extra install required to unpack one) alongside a
+`SHA256SUMS` file, and attaches them to a GitHub Release created from
+the tag. Uses the `gh` CLI (preinstalled and pre-authenticated via the
+runner's own `GITHUB_TOKEN` on every GitHub-hosted runner) rather than
+a third-party Marketplace action for the actual release creation -
+matches this project's own general preference for minimizing external
+dependencies (see e.g. pure-Go SQLite over CGO). Verified locally: ran
+the exact packaging shell logic (not the YAML itself, which needs a
+real Actions run to execute) against a real `make release` output -
+confirmed all 6 platform archives (2 macOS, 2 Linux, 1 Windows, 1
+FreeBSD) build with correct internal structure, `zip` selected only
+for the Windows target, and `SHA256SUMS` covers all of them.
diff --git a/README.md b/README.md
index 7acd262..edb62e4 100644
--- a/README.md
+++ b/README.md
@@ -97,7 +97,12 @@ itself for the rest - `make install` (via `go install`, respecting
`GOBIN`/`GOPATH` as usual), `make release` (cross-compiles both
binaries for every platform in `PLATFORMS` into `dist/`), `make test`
(the same build/vet/gofmt/test checks expected before every commit -
-see `PLAN.md`). Building without `make` works identically:
+see `PLAN.md`). Pushing a `v*` tag runs the same `make release` in CI
+and attaches the resulting archives (one per platform, `.tar.gz` on
+Unix/`.zip` on Windows, `SHA256SUMS` alongside them) to a GitHub
+Release, once this repo actually lives on GitHub - see
+`.github/workflows/release.yml`. Building without `make` works
+identically:
```sh
go build -o bin/mitmuxd ./cmd/mitmuxd