Skip to content

ci: save nim cache inline instead of post-job #84

ci: save nim cache inline instead of post-job

ci: save nim cache inline instead of post-job #84

Workflow file for this run

name: Windows
on:
workflow_dispatch:
push:
branches: [main]
tags: ['[0-9]+.[0-9]+.[0-9]+']
jobs:
build:
runs-on: windows-latest
# git-bash on the Windows runner. The Windows default (pwsh) does not
# propagate non-zero exit codes from native exes like nimble, so a failed
# build/test is swallowed and the job runs on into packaging, which then
# fails for a misleading reason (missing artifact). Same workaround as
# release.yml.
defaults:
run:
shell: bash
steps:
- uses: actions/checkout@v4
- uses: jiro4989/setup-nim-action@v2
with:
nim-version: stable
repo-token: ${{ secrets.GITHUB_TOKEN }}
parent-nim-install-directory: $HOME
nim-install-directory: nim-toolchain
- name: Install dependencies
run: nimble install -y --depsOnly
- name: Compute build flags
run: |
if [[ "${GITHUB_REF}" == refs/tags/* ]]; then
# autoupdate on releases only
echo "BUILD_FLAGS=-d:autoUpdate" >> "$GITHUB_ENV"
fi
- name: Build
run: nimble build -y -d:release ${{ env.BUILD_FLAGS }}
- name: Run tests
# nimble test runs Nim's bundled testament. Tests that can't run on
# Windows yet (the PTY harness) self-disable via disabled:"win"
# specs; see docs/windows-testing.md for the gap and fix path. The
# timeout is generous because the Windows runner compiles each test
# separately (~15-20s each) with no shared cache; actual test runtime
# is only ~4-5 min.
#
# git-bash does not reliably propagate nimble's non-zero exit code,
# so run testament directly and propagate $? explicitly. Without this
# a failing testament reports green (only the OSError shows in the
# log), which silently masks regressions.
run: |
if command -v testament >/dev/null 2>&1; then
testament --print --megatest:off all
else
for d in tests/*/; do
for f in "$d"*.nim; do
nim c -r --path:src --path:tests "$f" || exit 1
done
done
fi
timeout-minutes: 30
- name: Package (Windows) - bundle OpenSSL DLLs alongside .exe
shell: pwsh
run: |
New-Item -ItemType Directory -Path 3code-windows-amd64 | Out-Null
Copy-Item 3code.exe 3code-windows-amd64/
Copy-Item README.md, LICENSE 3code-windows-amd64/
# Stock Windows ships no OpenSSL. Nim's std/net dlopens libssl /
# libcrypto by hardcoded names; without these DLLs alongside
# 3code.exe, any TLS code path dies with
# could not load: (libcrypto-1_1-x64|libeay64).dll
# Use the canonical Nim Windows DLL bundle from nim-lang.org;
# it also ships a cacert.pem that we point SSL_CERT_FILE at.
Invoke-WebRequest -Uri https://nim-lang.org/download/dlls.zip -OutFile dlls.zip
Expand-Archive -Path dlls.zip -DestinationPath dlls
Copy-Item dlls/libssl-1_1-x64.dll, dlls/libcrypto-1_1-x64.dll, dlls/cacert.pem 3code-windows-amd64/
# Capture the version from the staged binary (needs the DLLs
# alongside it to launch) so it can be checked without running
# the binary on its target OS.
& 3code-windows-amd64/3code.exe -v | Set-Content -Encoding ascii 3code-windows-amd64/VERSION
Compress-Archive -Path 3code-windows-amd64 -DestinationPath 3code-windows-amd64.zip
- name: Upload artifact (GitHub Actions)
uses: actions/upload-artifact@v4
with:
name: 3code-windows-amd64
path: 3code-windows-amd64.zip
- name: Upload artifact to 3code.capocasa.dev
if: github.ref == 'refs/heads/main'
run: |
curl -f -H "Authorization: Bearer ${{ secrets.RELEASE_SECRET }}" -F "file=@3code-windows-amd64.zip" \
https://3code.capocasa.dev/main/upload.nim