Windows #51
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
| name: Windows | |
| on: | |
| workflow_dispatch: | |
| push: | |
| branches: [main] | |
| tags: ['[0-9]+.[0-9]+.[0-9]+'] | |
| jobs: | |
| build: | |
| runs-on: windows-latest | |
| # git-bash on the Windows runner. The Windows default (pwsh) does not | |
| # propagate non-zero exit codes from native exes like nimble, so a failed | |
| # build/test is swallowed and the job runs on into packaging, which then | |
| # fails for a misleading reason (missing artifact). Same workaround as | |
| # release.yml. | |
| defaults: | |
| run: | |
| shell: bash | |
| steps: | |
| - uses: actions/checkout@v4 | |
| - uses: jiro4989/setup-nim-action@v2 | |
| with: | |
| nim-version: stable | |
| repo-token: ${{ secrets.GITHUB_TOKEN }} | |
| - name: Install dependencies | |
| run: nimble install -y --depsOnly | |
| - name: Compute build flags | |
| run: | | |
| if [[ "${GITHUB_REF}" == refs/tags/* ]]; then | |
| # autoupdate on releases only | |
| echo "BUILD_FLAGS=-d:autoUpdate" >> "$GITHUB_ENV" | |
| fi | |
| - name: Build | |
| run: nimble build -y -d:release ${{ env.BUILD_FLAGS }} | |
| - name: Run tests | |
| # The `when defined(windows):` suite in tests/test_streamexec.nim | |
| # asserts the no-bundled-bash contract (resolveBash() == "" and | |
| # runStreamingBash returns 127 on a clean runner, since no installer | |
| # has staged MSYS2 into the bundle path). The POSIX suites guard the | |
| # shared launcher logic both platforms use. | |
| # nimble's exec() can't launch .sh directly on Windows (uses | |
| # CreateProcess, not the bash shell), so we invoke bash explicitly. | |
| run: bash tools/test.sh | |
| timeout-minutes: 20 | |
| - name: Package (Windows) - bundle OpenSSL DLLs alongside .exe | |
| shell: pwsh | |
| run: | | |
| New-Item -ItemType Directory -Path 3code-windows-amd64 | Out-Null | |
| Copy-Item 3code.exe 3code-windows-amd64/ | |
| Copy-Item README.md, LICENSE 3code-windows-amd64/ | |
| # Stock Windows ships no OpenSSL. Nim's std/net dlopens libssl / | |
| # libcrypto by hardcoded names; without these DLLs alongside | |
| # 3code.exe, any TLS code path dies with | |
| # could not load: (libcrypto-1_1-x64|libeay64).dll | |
| # Use the canonical Nim Windows DLL bundle from nim-lang.org; | |
| # it also ships a cacert.pem that we point SSL_CERT_FILE at. | |
| Invoke-WebRequest -Uri https://nim-lang.org/download/dlls.zip -OutFile dlls.zip | |
| Expand-Archive -Path dlls.zip -DestinationPath dlls | |
| Copy-Item dlls/libssl-1_1-x64.dll, dlls/libcrypto-1_1-x64.dll, dlls/cacert.pem 3code-windows-amd64/ | |
| Compress-Archive -Path 3code-windows-amd64 -DestinationPath 3code-windows-amd64.zip | |
| - name: Upload artifact (GitHub Actions) | |
| uses: actions/upload-artifact@v4 | |
| with: | |
| name: 3code-windows-amd64 | |
| path: 3code-windows-amd64.zip | |
| - name: Upload artifact to 3code.capocasa.dev | |
| if: github.ref == 'refs/heads/main' | |
| run: | | |
| curl -f -H "Authorization: Bearer ${{ secrets.RELEASE_SECRET }}" -F "file=@3code-windows-amd64.zip" \ | |
| https://3code.capocasa.dev/main/upload.nim | |