1use gh_workflow::{Event, Expression, Push, Run, Step, Use, Workflow, ctx::Context};
2use indoc::formatdoc;
3
4use crate::tasks::workflows::{
5 run_bundling::{bundle_linux, bundle_mac, bundle_windows, upload_artifact},
6 run_tests,
7 runners::{self, Arch, Platform},
8 steps::{self, FluentBuilder, NamedJob, dependant_job, named, release_job},
9 vars::{self, StepOutput, assets},
10};
11
12const CURRENT_ACTION_RUN_URL: &str =
13 "${{ github.server_url }}/${{ github.repository }}/actions/runs/${{ github.run_id }}";
14
15pub(crate) fn release() -> Workflow {
16 let macos_tests = run_tests::run_platform_tests_no_filter(Platform::Mac);
17 let linux_tests = run_tests::run_platform_tests_no_filter(Platform::Linux);
18 let windows_tests = run_tests::run_platform_tests_no_filter(Platform::Windows);
19 let macos_clippy = run_tests::clippy(Platform::Mac, None);
20 let linux_clippy = run_tests::clippy(Platform::Linux, None);
21 let windows_clippy = run_tests::clippy(Platform::Windows, None);
22 let check_scripts = run_tests::check_scripts();
23
24 let create_draft_release = create_draft_release();
25 let compliance = compliance_check();
26
27 let bundle = ReleaseBundleJobs {
28 linux_aarch64: bundle_linux(
29 Arch::AARCH64,
30 None,
31 &[&linux_tests, &linux_clippy, &check_scripts],
32 ),
33 linux_x86_64: bundle_linux(
34 Arch::X86_64,
35 None,
36 &[&linux_tests, &linux_clippy, &check_scripts],
37 ),
38 mac_aarch64: bundle_mac(
39 Arch::AARCH64,
40 None,
41 &[&macos_tests, &macos_clippy, &check_scripts],
42 ),
43 mac_x86_64: bundle_mac(
44 Arch::X86_64,
45 None,
46 &[&macos_tests, &macos_clippy, &check_scripts],
47 ),
48 windows_aarch64: bundle_windows(
49 Arch::AARCH64,
50 None,
51 &[&windows_tests, &windows_clippy, &check_scripts],
52 ),
53 windows_x86_64: bundle_windows(
54 Arch::X86_64,
55 None,
56 &[&windows_tests, &windows_clippy, &check_scripts],
57 ),
58 };
59
60 let upload_release_assets = upload_release_assets(&[&create_draft_release], &bundle);
61 let validate_release_assets = validate_release_assets(&[&upload_release_assets]);
62
63 let auto_release_preview = auto_release_preview(&[&validate_release_assets]);
64
65 let test_jobs = [
66 &macos_tests,
67 &linux_tests,
68 &windows_tests,
69 &macos_clippy,
70 &linux_clippy,
71 &windows_clippy,
72 &check_scripts,
73 ];
74 let push_slack_notification = push_release_update_notification(
75 &create_draft_release,
76 &upload_release_assets,
77 &validate_release_assets,
78 &auto_release_preview,
79 &test_jobs,
80 &bundle,
81 );
82
83 named::workflow()
84 .on(Event::default().push(Push::default().tags(vec!["v*".to_string()])))
85 .concurrency(vars::one_workflow_per_non_main_branch())
86 .add_env(("CARGO_TERM_COLOR", "always"))
87 .add_env(("RUST_BACKTRACE", "1"))
88 .add_job(macos_tests.name, macos_tests.job)
89 .add_job(linux_tests.name, linux_tests.job)
90 .add_job(windows_tests.name, windows_tests.job)
91 .add_job(macos_clippy.name, macos_clippy.job)
92 .add_job(linux_clippy.name, linux_clippy.job)
93 .add_job(windows_clippy.name, windows_clippy.job)
94 .add_job(check_scripts.name, check_scripts.job)
95 .add_job(create_draft_release.name, create_draft_release.job)
96 .add_job(compliance.name, compliance.job)
97 .map(|mut workflow| {
98 for job in bundle.into_jobs() {
99 workflow = workflow.add_job(job.name, job.job);
100 }
101 workflow
102 })
103 .add_job(upload_release_assets.name, upload_release_assets.job)
104 .add_job(validate_release_assets.name, validate_release_assets.job)
105 .add_job(auto_release_preview.name, auto_release_preview.job)
106 .add_job(push_slack_notification.name, push_slack_notification.job)
107}
108
109pub(crate) struct ReleaseBundleJobs {
110 pub linux_aarch64: NamedJob,
111 pub linux_x86_64: NamedJob,
112 pub mac_aarch64: NamedJob,
113 pub mac_x86_64: NamedJob,
114 pub windows_aarch64: NamedJob,
115 pub windows_x86_64: NamedJob,
116}
117
118impl ReleaseBundleJobs {
119 pub fn jobs(&self) -> Vec<&NamedJob> {
120 vec![
121 &self.linux_aarch64,
122 &self.linux_x86_64,
123 &self.mac_aarch64,
124 &self.mac_x86_64,
125 &self.windows_aarch64,
126 &self.windows_x86_64,
127 ]
128 }
129
130 pub fn into_jobs(self) -> Vec<NamedJob> {
131 vec![
132 self.linux_aarch64,
133 self.linux_x86_64,
134 self.mac_aarch64,
135 self.mac_x86_64,
136 self.windows_aarch64,
137 self.windows_x86_64,
138 ]
139 }
140}
141
142pub(crate) fn create_sentry_release() -> Step<Use> {
143 named::uses(
144 "getsentry",
145 "action-release",
146 "526942b68292201ac6bbb99b9a0747d4abee354c", // v3
147 )
148 .add_env(("SENTRY_ORG", "zed-dev"))
149 .add_env(("SENTRY_PROJECT", "zed"))
150 .add_env(("SENTRY_AUTH_TOKEN", vars::SENTRY_AUTH_TOKEN))
151 .add_with(("environment", "production"))
152}
153
154pub(crate) const COMPLIANCE_REPORT_PATH: &str = "compliance-report.md";
155const NEEDS_REVIEW_PULLS_URL: &str = "https://github.com/zed-industries/zed/pulls?q=is%3Apr+is%3Aclosed+label%3A%22PR+state%3Aneeds+review%22";
156
157pub(crate) enum ComplianceContext {
158 Release,
159 Scheduled { tag_source: StepOutput },
160}
161
162pub(crate) fn add_compliance_notification_steps(
163 job: gh_workflow::Job,
164 context: ComplianceContext,
165 compliance_step_id: &str,
166) -> gh_workflow::Job {
167 let upload_step =
168 upload_artifact(COMPLIANCE_REPORT_PATH).if_condition(Expression::new("always()"));
169
170 let (success_prefix, failure_prefix) = match context {
171 ComplianceContext::Release => ("✅ Compliance check passed", "❌ Compliance check failed"),
172 ComplianceContext::Scheduled { .. } => (
173 "✅ Scheduled compliance check passed",
174 "⚠️ Scheduled compliance check failed",
175 ),
176 };
177
178 let script = formatdoc! {r#"
179 REPORT_CONTENT=""
180 if [ -f "{COMPLIANCE_REPORT_PATH}" ]; then
181 REPORT_CONTENT=$(cat "{COMPLIANCE_REPORT_PATH}")
182 fi
183
184 if [ "$COMPLIANCE_OUTCOME" == "success" ]; then
185 STATUS="{success_prefix} for $COMPLIANCE_TAG"
186 else
187 STATUS="{failure_prefix} for $COMPLIANCE_TAG"
188 fi
189
190 MESSAGE=$(printf "%s\n\nReport: %s\nPRs needing review: %s\n\n%s" "$STATUS" "$ARTIFACT_URL" "{NEEDS_REVIEW_PULLS_URL}" "$REPORT_CONTENT")
191
192 curl -X POST -H 'Content-type: application/json' \
193 --data "$(jq -n --arg text "$MESSAGE" '{{"text": $text}}')" \
194 "$SLACK_WEBHOOK"
195 "#,
196 };
197
198 let notification_step = Step::new("send_compliance_slack_notification")
199 .run(&script)
200 .if_condition(Expression::new("always()"))
201 .add_env(("SLACK_WEBHOOK", vars::SLACK_WEBHOOK_WORKFLOW_FAILURES))
202 .add_env((
203 "COMPLIANCE_OUTCOME",
204 format!("${{{{ steps.{compliance_step_id}.outcome }}}}"),
205 ))
206 .add_env((
207 "COMPLIANCE_TAG",
208 match context {
209 ComplianceContext::Release => Context::github().ref_name().to_string(),
210 ComplianceContext::Scheduled { tag_source } => tag_source.to_string(),
211 },
212 ))
213 .add_env((
214 "ARTIFACT_URL",
215 format!("{CURRENT_ACTION_RUN_URL}#artifacts"),
216 ));
217
218 job.add_step(upload_step).add_step(notification_step)
219}
220
221fn compliance_check() -> NamedJob {
222 fn run_compliance_check() -> Step<Run> {
223 named::bash(formatdoc! {r#"
224 cargo xtask compliance "$GITHUB_REF_NAME" --report-path {COMPLIANCE_REPORT_PATH}
225 "#,
226 })
227 .id("run-compliance-check")
228 .add_env(("GITHUB_APP_ID", vars::ZED_ZIPPY_APP_ID))
229 .add_env(("GITHUB_APP_KEY", vars::ZED_ZIPPY_APP_PRIVATE_KEY))
230 }
231
232 let job = release_job(&[])
233 .runs_on(runners::LINUX_SMALL)
234 .add_step(
235 steps::checkout_repo()
236 .with_full_history()
237 .with_ref(Context::github().ref_()),
238 )
239 .add_step(steps::cache_rust_dependencies_namespace())
240 .add_step(run_compliance_check());
241
242 named::job(add_compliance_notification_steps(
243 job,
244 ComplianceContext::Release,
245 "run-compliance-check",
246 ))
247}
248
249fn validate_release_assets(deps: &[&NamedJob]) -> NamedJob {
250 let expected_assets: Vec<String> = assets::all().iter().map(|a| format!("\"{a}\"")).collect();
251 let expected_assets_json = format!("[{}]", expected_assets.join(", "));
252
253 let validation_script = formatdoc! {r#"
254 EXPECTED_ASSETS='{expected_assets_json}'
255 TAG="$GITHUB_REF_NAME"
256
257 ACTUAL_ASSETS=$(gh release view "$TAG" --repo=zed-industries/zed --json assets -q '[.assets[].name]')
258
259 MISSING_ASSETS=$(echo "$EXPECTED_ASSETS" | jq -r --argjson actual "$ACTUAL_ASSETS" '. - $actual | .[]')
260
261 if [ -n "$MISSING_ASSETS" ]; then
262 echo "Error: The following assets are missing from the release:"
263 echo "$MISSING_ASSETS"
264 exit 1
265 fi
266
267 echo "All expected assets are present in the release."
268 "#,
269 };
270
271 fn run_post_upload_compliance_check() -> Step<Run> {
272 named::bash(formatdoc! {r#"
273 cargo xtask compliance "$GITHUB_REF_NAME" --report-path {COMPLIANCE_REPORT_PATH}
274 "#,
275 })
276 .id("run-post-upload-compliance-check")
277 .add_env(("GITHUB_APP_ID", vars::ZED_ZIPPY_APP_ID))
278 .add_env(("GITHUB_APP_KEY", vars::ZED_ZIPPY_APP_PRIVATE_KEY))
279 }
280
281 let job = dependant_job(deps)
282 .runs_on(runners::LINUX_SMALL)
283 .add_step(named::bash(&validation_script).add_env(("GITHUB_TOKEN", vars::GITHUB_TOKEN)))
284 .add_step(
285 steps::checkout_repo()
286 .with_full_history()
287 .with_ref("${{ github.ref }}"),
288 )
289 .add_step(steps::cache_rust_dependencies_namespace())
290 .add_step(run_post_upload_compliance_check());
291
292 named::job(add_compliance_notification_steps(
293 job,
294 ComplianceContext::Release,
295 "run-post-upload-compliance-check",
296 ))
297}
298
299fn auto_release_preview(deps: &[&NamedJob]) -> NamedJob {
300 let (authenticate, token) = steps::authenticate_as_zippy().into();
301
302 named::job(
303 dependant_job(deps)
304 .runs_on(runners::LINUX_SMALL)
305 .cond(Expression::new(indoc::indoc!(
306 r#"startsWith(github.ref, 'refs/tags/v') && endsWith(github.ref, '-pre') && !endsWith(github.ref, '.0-pre')"#
307 )))
308 .add_step(authenticate)
309 .add_step(
310 steps::script(
311 r#"gh release edit "$GITHUB_REF_NAME" --repo=zed-industries/zed --draft=false"#,
312 )
313 .add_env(("GITHUB_TOKEN", &token)),
314 )
315 )
316}
317
318pub(crate) fn download_workflow_artifacts() -> Step<Use> {
319 named::uses(
320 "actions",
321 "download-artifact",
322 "018cc2cf5baa6db3ef3c5f8a56943fffe632ef53", // v6.0.0
323 )
324 .add_with(("path", "./artifacts/"))
325}
326
327pub(crate) fn prep_release_artifacts() -> Step<Run> {
328 let mut script_lines = vec!["mkdir -p release-artifacts/\n".to_string()];
329 for asset in assets::all() {
330 let mv_command = format!("mv ./artifacts/{asset}/{asset} release-artifacts/{asset}");
331 script_lines.push(mv_command)
332 }
333
334 named::bash(&script_lines.join("\n"))
335}
336
337fn upload_release_assets(deps: &[&NamedJob], bundle: &ReleaseBundleJobs) -> NamedJob {
338 let mut deps = deps.to_vec();
339 deps.extend(bundle.jobs());
340
341 named::job(
342 dependant_job(&deps)
343 .runs_on(runners::LINUX_MEDIUM)
344 .add_step(download_workflow_artifacts())
345 .add_step(steps::script("ls -lR ./artifacts"))
346 .add_step(prep_release_artifacts())
347 .add_step(
348 steps::script("gh release upload \"$GITHUB_REF_NAME\" --repo=zed-industries/zed release-artifacts/*")
349 .add_env(("GITHUB_TOKEN", vars::GITHUB_TOKEN)),
350 ),
351 )
352}
353
354fn create_draft_release() -> NamedJob {
355 fn generate_release_notes() -> Step<Run> {
356 named::bash(
357 r#"node --redirect-warnings=/dev/null ./script/draft-release-notes "$RELEASE_VERSION" "$RELEASE_CHANNEL" > target/release-notes.md"#,
358 )
359 }
360
361 fn create_release() -> Step<Run> {
362 named::bash("script/create-draft-release target/release-notes.md")
363 .add_env(("GITHUB_TOKEN", vars::GITHUB_TOKEN))
364 }
365
366 named::job(
367 release_job(&[])
368 .runs_on(runners::LINUX_SMALL)
369 // We need to fetch more than one commit so that `script/draft-release-notes`
370 // is able to diff between the current and previous tag.
371 //
372 // 25 was chosen arbitrarily.
373 .add_step(
374 steps::checkout_repo()
375 .with_custom_fetch_depth(25)
376 .with_ref(Context::github().ref_()),
377 )
378 .add_step(steps::script("script/determine-release-channel"))
379 .add_step(steps::script("mkdir -p target/"))
380 .add_step(generate_release_notes())
381 .add_step(create_release()),
382 )
383}
384
385pub(crate) fn push_release_update_notification(
386 create_draft_release_job: &NamedJob,
387 upload_assets_job: &NamedJob,
388 validate_assets_job: &NamedJob,
389 auto_release_preview: &NamedJob,
390 test_jobs: &[&NamedJob],
391 bundle_jobs: &ReleaseBundleJobs,
392) -> NamedJob {
393 fn env_name(name: &str) -> String {
394 format!("RESULT_{}", name.to_uppercase())
395 }
396
397 let all_job_names: Vec<&str> = test_jobs
398 .iter()
399 .map(|j| j.name.as_ref())
400 .chain(bundle_jobs.jobs().into_iter().map(|j| j.name.as_ref()))
401 .collect();
402
403 let env_entries = [
404 (
405 "DRAFT_RESULT".into(),
406 format!("${{{{ needs.{}.result }}}}", create_draft_release_job.name),
407 ),
408 (
409 "UPLOAD_RESULT".into(),
410 format!("${{{{ needs.{}.result }}}}", upload_assets_job.name),
411 ),
412 (
413 "VALIDATE_RESULT".into(),
414 format!("${{{{ needs.{}.result }}}}", validate_assets_job.name),
415 ),
416 (
417 "AUTO_RELEASE_RESULT".into(),
418 format!("${{{{ needs.{}.result }}}}", auto_release_preview.name),
419 ),
420 ("RUN_URL".into(), CURRENT_ACTION_RUN_URL.to_string()),
421 ]
422 .into_iter()
423 .chain(
424 all_job_names
425 .iter()
426 .map(|name| (env_name(name), format!("${{{{ needs.{name}.result }}}}"))),
427 );
428
429 let failure_checks = all_job_names
430 .iter()
431 .map(|name| {
432 format!(
433 "if [ \"${env_name}\" == \"failure\" ];then FAILED_JOBS=\"$FAILED_JOBS {name}\"; fi",
434 env_name = env_name(name)
435 )
436 })
437 .collect::<Vec<_>>()
438 .join("\n ");
439
440 let notification_script = formatdoc! {r#"
441 TAG="$GITHUB_REF_NAME"
442
443 if [ "$DRAFT_RESULT" == "failure" ]; then
444 echo "❌ Draft release creation failed for $TAG: $RUN_URL"
445 else
446 RELEASE_URL=$(gh release view "$TAG" --repo=zed-industries/zed --json url -q '.url')
447 if [ "$UPLOAD_RESULT" == "failure" ]; then
448 echo "❌ Release asset upload failed for $TAG: $RELEASE_URL"
449 elif [ "$UPLOAD_RESULT" == "cancelled" ] || [ "$UPLOAD_RESULT" == "skipped" ]; then
450 FAILED_JOBS=""
451 {failure_checks}
452 FAILED_JOBS=$(echo "$FAILED_JOBS" | xargs)
453 if [ "$UPLOAD_RESULT" == "cancelled" ]; then
454 if [ -n "$FAILED_JOBS" ]; then
455 echo "❌ Release job for $TAG was cancelled, most likely because tests \`$FAILED_JOBS\` failed: $RUN_URL"
456 else
457 echo "❌ Release job for $TAG was cancelled: $RUN_URL"
458 fi
459 else
460 if [ -n "$FAILED_JOBS" ]; then
461 echo "❌ Tests \`$FAILED_JOBS\` for $TAG failed: $RUN_URL"
462 else
463 echo "❌ Tests for $TAG failed: $RUN_URL"
464 fi
465 fi
466 elif [ "$VALIDATE_RESULT" == "failure" ]; then
467 echo "❌ Release asset validation failed for $TAG (missing assets): $RUN_URL"
468 elif [ "$AUTO_RELEASE_RESULT" == "success" ]; then
469 echo "✅ Release $TAG was auto-released successfully: $RELEASE_URL"
470 elif [ "$AUTO_RELEASE_RESULT" == "failure" ]; then
471 echo "❌ Auto release failed for $TAG: $RUN_URL"
472 else
473 echo "👀 Release $TAG sitting freshly baked in the oven and waiting to be published: $RELEASE_URL"
474 fi
475 fi
476 "#,
477 };
478
479 let mut all_deps: Vec<&NamedJob> = vec![
480 create_draft_release_job,
481 upload_assets_job,
482 validate_assets_job,
483 auto_release_preview,
484 ];
485 all_deps.extend(test_jobs.iter().copied());
486 all_deps.extend(bundle_jobs.jobs());
487
488 let mut job = dependant_job(&all_deps)
489 .runs_on(runners::LINUX_SMALL)
490 .cond(Expression::new("always()"));
491
492 for step in notify_slack(MessageType::Evaluated {
493 script: notification_script,
494 env: env_entries.collect(),
495 }) {
496 job = job.add_step(step);
497 }
498 named::job(job)
499}
500
501pub(crate) fn notify_on_failure(deps: &[&NamedJob]) -> NamedJob {
502 let failure_message = format!("❌ ${{{{ github.workflow }}}} failed: {CURRENT_ACTION_RUN_URL}");
503
504 let mut job = dependant_job(deps)
505 .runs_on(runners::LINUX_SMALL)
506 .cond(Expression::new("failure()"));
507
508 for step in notify_slack(MessageType::Static(failure_message)) {
509 job = job.add_step(step);
510 }
511 named::job(job)
512}
513
514pub(crate) enum MessageType {
515 Static(String),
516 Evaluated {
517 script: String,
518 env: Vec<(String, String)>,
519 },
520}
521
522fn notify_slack(message: MessageType) -> Vec<Step<Run>> {
523 match message {
524 MessageType::Static(message) => vec![send_slack_message(message)],
525 MessageType::Evaluated { script, env } => {
526 let (generate_step, generated_message) = generate_slack_message(script, env);
527
528 vec![
529 generate_step,
530 send_slack_message(generated_message.to_string()),
531 ]
532 }
533 }
534}
535
536fn generate_slack_message(
537 expression: String,
538 env: Vec<(String, String)>,
539) -> (Step<Run>, StepOutput) {
540 let script = formatdoc! {r#"
541 MESSAGE=$({expression})
542 echo "message=$MESSAGE" >> "$GITHUB_OUTPUT"
543 "#
544 };
545 let mut generate_step = named::bash(&script)
546 .id("generate-webhook-message")
547 .add_env(("GH_TOKEN", Context::github().token()));
548
549 for (name, value) in env {
550 generate_step = generate_step.add_env((name, value));
551 }
552
553 let output = StepOutput::new(&generate_step, "message");
554
555 (generate_step, output)
556}
557
558fn send_slack_message(message: String) -> Step<Run> {
559 named::bash(
560 r#"curl -X POST -H 'Content-type: application/json' --data "$(jq -n --arg text "$SLACK_MESSAGE" '{"text": $text}')" "$SLACK_WEBHOOK""#
561 )
562 .add_env(("SLACK_WEBHOOK", vars::SLACK_WEBHOOK_WORKFLOW_FAILURES))
563 .add_env(("SLACK_MESSAGE", message))
564}