Repository navigation
198 lines (182 loc) · 6.75 KB
/
Copy pathbuild.yml
File metadata and controls
198 lines (182 loc) · 6.75 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
130
131
132
133
134
135
136
137
138
139
140
141
142
143
144
145
146
147
148
149
150
151
152
153
154
155
156
157
158
159
160
161
162
163
164
165
166
167
168
169
170
171
172
173
174
175
176
177
178
179
180
181
182
183
184
185
186
187
188
189
190
191
192
193
194
195
196
197
198
name: Build
# Builds every distributed target. Called by release.yml for v* tags; can also
# be run by hand to try the builds without releasing. Each target is uploaded
# as a workflow artifact named rt-<target> (files in dist/). The offline
# GitHub Pages site is uploaded separately, as the run's Pages artifact.
#
# Two web builds:
# web - talks to the default lobby (rt-lobby.nexusdynamic.org), served
# from the root of that host. Attached to the release as a zip.
# pages - LOBBY_URL=none: offline unless the player sets a server. Served
# from https://<owner>.github.io/<repo>/.
on:
workflow_call:
inputs:
version:
description: "Version string used in the artifact file names"
required: true
type: string
secrets:
ANDROID_KEYSTORE_BASE64:
required: false
ANDROID_KEYSTORE_PASSWORD:
required: false
ANDROID_KEY_ALIAS:
required: false
ANDROID_KEY_PASSWORD:
required: false
workflow_dispatch:
inputs:
version:
description: "Version string used in the artifact file names"
required: false
type: string
default: "dev"
permissions:
contents: read
defaults:
run:
shell: bash
jobs:
build:
name: ${{ matrix.target }}
strategy:
fail-fast: false
matrix:
include:
- target: linux
os: ubuntu-latest
- target: windows
os: windows-latest
- target: macos
os: macos-latest
- target: android
os: ubuntu-latest
- target: web
os: ubuntu-latest
- target: pages
os: ubuntu-latest
runs-on: ${{ matrix.os }}
env:
NAME: RiseTogether-${{ inputs.version }}
DEFINES: --dart-define=GIT_SHA=${{ github.sha }}
steps:
- uses: actions/checkout@v7
- name: Install Linux build dependencies
# gstreamer and pulse: audioplayers_linux.
if: matrix.target == 'linux'
run: |
sudo apt-get update
sudo apt-get install -y clang cmake ninja-build pkg-config \
libgtk-3-dev liblzma-dev libstdc++-12-dev libpulse-dev \
libgstreamer1.0-dev libgstreamer-plugins-base1.0-dev
- uses: actions/setup-java@v6
if: matrix.target == 'android'
with:
distribution: temurin
java-version: 21
cache: gradle
- uses: subosito/flutter-action@v2
with:
channel: stable
cache: true
- run: flutter pub get
- name: Write Android signing config
if: matrix.target == 'android'
env:
KEYSTORE_BASE64: ${{ secrets.ANDROID_KEYSTORE_BASE64 }}
KEYSTORE_PASSWORD: ${{ secrets.ANDROID_KEYSTORE_PASSWORD }}
KEY_ALIAS: ${{ secrets.ANDROID_KEY_ALIAS }}
KEY_PASSWORD: ${{ secrets.ANDROID_KEY_PASSWORD }}
working-directory: android
run: |
if [ -z "$KEYSTORE_BASE64" ]; then
echo "::warning::No ANDROID_KEYSTORE_BASE64 secret: the APKs are signed with the debug key."
exit 0
fi
echo "$KEYSTORE_BASE64" | base64 --decode > app/release.keystore
{
echo "storeFile=release.keystore"
echo "storePassword=$KEYSTORE_PASSWORD"
echo "keyAlias=$KEY_ALIAS"
echo "keyPassword=$KEY_PASSWORD"
} > key.properties
- name: Ad-hoc signing for macOS
# The project signs with the maintainer's Apple team, whose
# certificate is not on the runner. Project build settings beat
# xcconfig files, so switch the project itself to ad-hoc ("-"),
# which keeps the sandbox entitlements. CI only; nothing is committed.
if: matrix.target == 'macos'
run: |
sed -i '' -E \
-e 's/DEVELOPMENT_TEAM = [A-Z0-9]+;/DEVELOPMENT_TEAM = "";/' \
-e 's/"CODE_SIGN_IDENTITY\[sdk=macosx\*\]" = "Apple Development";/"CODE_SIGN_IDENTITY[sdk=macosx*]" = "-";/' \
-e 's/CODE_SIGN_IDENTITY = "Apple Development";/CODE_SIGN_IDENTITY = "-";/' \
-e 's/CODE_SIGN_STYLE = Automatic;/CODE_SIGN_STYLE = Manual;/' \
macos/Runner.xcodeproj/project.pbxproj
grep -n 'CODE_SIGN_IDENTITY\|DEVELOPMENT_TEAM\|CODE_SIGN_STYLE' macos/Runner.xcodeproj/project.pbxproj
- name: Build
# Web builds are self-contained (no CDN), so the COOP/COEP headers on
# rt-lobby cannot block the renderer.
run: |
case "${{ matrix.target }}" in
android)
flutter build apk --release $DEFINES
cp build/app/outputs/flutter-apk/app-release.apk build/universal.apk
flutter build apk --release --split-per-abi $DEFINES
;;
web)
flutter build web --release --wasm --no-web-resources-cdn \
--base-href / $DEFINES
;;
pages)
flutter build web --release --wasm --no-web-resources-cdn \
--base-href "/${{ github.event.repository.name }}/" \
--dart-define=LOBBY_URL=none $DEFINES
;;
*)
flutter build "${{ matrix.target }}" --release $DEFINES
;;
esac
- name: Package
if: matrix.target != 'pages'
working-directory: build
run: |
DIST="$GITHUB_WORKSPACE/dist"
mkdir -p "$DIST"
case "${{ matrix.target }}" in
linux)
tar -C linux/x64/release/bundle -czf "$DIST/$NAME-linux-x64.tar.gz" .
;;
windows)
(cd windows/x64/runner/Release && 7z a -tzip "$DIST/$NAME-windows-x64.zip" .)
;;
macos)
# Unsigned: users need to right-click → Open the first time.
APP="$(find macos/Build/Products/Release -maxdepth 1 -name '*.app' | head -n1)"
ditto -c -k --keepParent "$APP" "$DIST/$NAME-macos.zip"
;;
android)
cp universal.apk "$DIST/$NAME-android-universal.apk"
for apk in app/outputs/flutter-apk/app-*-release.apk; do
abi="$(basename "$apk" | sed -E 's/^app-(.*)-release\.apk$/\1/')"
cp "$apk" "$DIST/$NAME-android-$abi.apk"
done
;;
web)
(cd web && zip -qr "$DIST/$NAME-web.zip" .)
;;
esac
ls -la "$DIST"
- name: Upload
if: matrix.target != 'pages'
uses: actions/upload-artifact@v7
with:
name: rt-${{ matrix.target }}
path: dist/*
if-no-files-found: error
- name: Upload Pages site
if: matrix.target == 'pages'
uses: actions/upload-pages-artifact@v5
with:
path: build/web