Skip to content
Closed
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
9 changes: 9 additions & 0 deletions .devcontainer/devcontainer-lock.json
Original file line number Diff line number Diff line change
@@ -0,0 +1,9 @@
{
"features": {
"ghcr.io/devcontainers/features/github-cli:1": {
"version": "1.1.3",
"resolved": "ghcr.io/devcontainers/features/github-cli@sha256:bd7ab48a832228f633239277552c30b353867fef2e5b037e064b4e64f0b843f2",
"integrity": "sha256:bd7ab48a832228f633239277552c30b353867fef2e5b037e064b4e64f0b843f2"
}
}
}
46 changes: 46 additions & 0 deletions .devcontainer/devcontainer.json
Original file line number Diff line number Diff line change
@@ -0,0 +1,46 @@
// For format details, see https://aka.ms/devcontainer.json. For config options, see the
// README at: https://github.com/devcontainers/templates/tree/main/src/rust
{
"name": "componentized-sockets",
"image": "mcr.microsoft.com/devcontainers/rust",
// Use 'mounts' to make the cargo cache persistent in a Docker Volume.
"mounts": [
{
"source": "devcontainer-cargo-cache-${devcontainerId}",
"target": "/usr/local/cargo",
"type": "volume"
},
{
"source": "devcontainer-rustup-cache-${devcontainerId}",
"target": "/usr/local/rustup",
"type": "volume"
}
],
// Features to add to the dev container. More info: https://containers.dev/features.
"features": {
"ghcr.io/devcontainers/features/github-cli:1": {}
},
// Use 'postCreateCommand' to run commands after the container is created.
"postCreateCommand": "echo \"export \\\"PATH=$(make -s tools-path):\\${PATH}\\\"\" >> ~/.bashrc && curl -L --proto '=https' --tlsv1.2 -sSf https://raw.githubusercontent.com/cargo-bins/cargo-binstall/main/install-from-binstall-release.sh | bash && cargo check && make tools",
// Configure tool-specific properties.
"customizations": {
// Configure properties specific to VS Code.
"vscode": {
// Set *default* container specific settings.json values on container create.
"settings": {
"dev.containers.githubCLILoginWithToken": true
},
"extensions": [
"bytecodealliance.wit-idl",
"github.vscode-github-actions",
"ms-azuretools.vscode-containers",
"rust-lang.rust-analyzer",
"streetsidesoftware.code-spell-checker",
"tamasfe.even-better-toml",
"vadimcn.vscode-lldb"
]
}
}
// Uncomment to connect as root instead. More info: https://aka.ms/dev-containers-non-root.
// "remoteUser": "root"
}
36 changes: 20 additions & 16 deletions .github/dependabot.yml
Original file line number Diff line number Diff line change
@@ -1,18 +1,22 @@
version: 2
updates:
- package-ecosystem: github-actions
directory: "/"
schedule:
interval: daily
- package-ecosystem: cargo
directory: "/"
schedule:
interval: daily
- package-ecosystem: cargo
directory: "/tools"
schedule:
interval: daily
- package-ecosystem: rust-toolchain
directory: "/"
schedule:
interval: daily
- package-ecosystem: github-actions
directory: "/"
schedule:
interval: daily
- package-ecosystem: cargo
directory: "/"
schedule:
interval: daily
- package-ecosystem: cargo
directory: "/tools"
schedule:
interval: daily
- package-ecosystem: rust-toolchain
directory: "/"
schedule:
interval: daily
- package-ecosystem: devcontainers
directory: "/"
schedule:
interval: weekly
159 changes: 159 additions & 0 deletions .github/workflows/bump-version.yaml
Original file line number Diff line number Diff line change
@@ -0,0 +1,159 @@
name: Bump version

on:
workflow_dispatch:
inputs:
version:
description: The new version of the interface package and crates, e.g. 0.1.0 or 0.2.0-dev
required: true
type: string
default: "0.1.0-dev" # the current version, kept current by scripts/bump-version.sh

jobs:
# bumps the version with read only access, the changes are handed to the pull-request job as a
# patch so the third party actions used to build never run with write access
bump:
runs-on: ubuntu-latest
permissions:
contents: read
steps:
- uses: actions/checkout@v7
with:
persist-credentials: false
- uses: actions-rust-lang/setup-rust-toolchain@v2
- name: Install cargo binstall
uses: cargo-bins/cargo-binstall@main
- name: Install tools
run: |
make tools
make -s tools-path >> "${GITHUB_PATH}"
- name: Bump version
# also fetches the wit dependencies for the new version, and builds and tests the components
run: scripts/bump-version.sh "${VERSION}"
env:
VERSION: ${{ inputs.version }}
- name: Collect changes
run: |
git add --all
git diff --cached --binary > bump-version.patch
- name: Upload changes
uses: actions/upload-artifact@v7
with:
name: bump-version.patch
path: bump-version.patch
if-no-files-found: error
retention-days: 1

# opens the pull request using only first party actions and the gh cli
pull-request:
needs:
- bump
runs-on: ubuntu-latest
# the branch and pull request are created with a token for the custodian GitHub App rather than
# the GITHUB_TOKEN, which can't change workflow files and doesn't trigger the CI workflow
permissions:
contents: read
env:
VERSION: ${{ inputs.version }}
steps:
- name: Check custodian app credentials
run: |
if [ -z "${CLIENT_ID}" ] || [ -z "${PRIVATE_KEY}" ] ; then
echo "::error::the CUSTODIAN_CLIENT_ID and CUSTODIAN_PRIVATE_KEY secrets must be available to this repository, the private key of the custodian GitHub App is needed to create a token"
exit 1
fi
env:
CLIENT_ID: ${{ secrets.CUSTODIAN_CLIENT_ID }}
PRIVATE_KEY: ${{ secrets.CUSTODIAN_PRIVATE_KEY }}
- name: Create custodian app token
id: app-token
uses: actions/create-github-app-token@v3
with:
client-id: ${{ secrets.CUSTODIAN_CLIENT_ID }}
private-key: ${{ secrets.CUSTODIAN_PRIVATE_KEY }}
# only this repository, with only the permissions the bump needs
repositories: ${{ github.event.repository.name }}
permission-contents: write
permission-pull-requests: write
# the bump changes the default version in this workflow
permission-workflows: write
- uses: actions/checkout@v7
with:
persist-credentials: false
- name: Download changes
uses: actions/download-artifact@v8
with:
name: bump-version.patch
path: ${{ runner.temp }}
- name: Read current version
# the checkout is before the bump, the crates' workspace version is the current version
run: |
current=$( sed -n '/^\[workspace.package\]/,/^\[/s/^version = "\(.*\)"$/\1/p' Cargo.toml )
echo "CURRENT_VERSION=${current}" >> "${GITHUB_ENV}"
- name: Commit changes
# the commit is created with the REST API, as the app's token can't push. The patch is applied
# locally only to find the changed files and their modes.
env:
GH_TOKEN: ${{ steps.app-token.outputs.token }}
APP_SLUG: ${{ steps.app-token.outputs.app-slug }}
run: |
branch="bump-version/${VERSION}"
api="repos/${GITHUB_REPOSITORY}"
base=$( git rev-parse HEAD )
git apply --index "${RUNNER_TEMP}/bump-version.patch"

# a blob for each changed file, or a null sha for a deleted file
entries="${RUNNER_TEMP}/tree-entries.json"
echo '[]' > "${entries}"
git diff --cached --no-renames --name-status "${base}" | while IFS=$'\t' read -r status path ; do
if [ "${status}" = "D" ] ; then
entry=$( jq -n --arg path "${path}" '{path: $path, mode: "100644", type: "blob", sha: null}' )
else
mode=$( git ls-files --stage -- "${path}" | cut -d' ' -f1 )
sha=$( base64 < "${path}" | tr -d '\n' | jq -Rs '{encoding: "base64", content: .}' | gh api --method POST "${api}/git/blobs" --input - --jq .sha )
entry=$( jq -n --arg path "${path}" --arg mode "${mode}" --arg sha "${sha}" '{path: $path, mode: $mode, type: "blob", sha: $sha}' )
fi
jq --argjson entry "${entry}" '. + [$entry]' "${entries}" > "${entries}.tmp" && mv "${entries}.tmp" "${entries}"
echo "${status} ${path}"
done
tree=$( jq --arg base "$( git rev-parse "${base}^{tree}" )" '{base_tree: $base, tree: .}' "${entries}" | gh api --method POST "${api}/git/trees" --input - --jq .sha )

# authored and signed off (DCO) by the user who triggered the workflow, with their GitHub
# noreply email so the commit is attributed to them without exposing their email address.
# Committed by the custodian app's bot, which made the commit on their behalf. The commit is
# unsigned, GitHub only signs commits it attributes entirely to the app.
name=$( gh api "users/${GITHUB_ACTOR}" --jq '.name // .login' )
name="${name:-${GITHUB_ACTOR}}"
email="${GITHUB_ACTOR_ID}+${GITHUB_ACTOR}@users.noreply.github.com"
bot="${APP_SLUG}[bot]"
bot_email="$( gh api "users/${bot}" --jq .id )+${bot}@users.noreply.github.com"
commit=$( jq -n \
--arg message "$( printf 'Bump version from %s to %s\n\nSigned-off-by: %s <%s>' "${CURRENT_VERSION}" "${VERSION}" "${name}" "${email}" )" \
--arg tree "${tree}" --arg parent "${base}" --arg name "${name}" --arg email "${email}" \
--arg bot "${bot}" --arg bot_email "${bot_email}" \
'{message: $message, tree: $tree, parents: [$parent], author: {name: $name, email: $email}, committer: {name: $bot, email: $bot_email}}' \
| gh api --method POST "${api}/git/commits" --input - --jq .sha )
echo "created commit ${commit}"

# points the branch at the commit, replacing the branch left by an earlier run for the same version
if gh api "${api}/git/ref/heads/${branch}" --silent 2> /dev/null ; then
gh api --method PATCH "${api}/git/refs/heads/${branch}" -f sha="${commit}" -F force=true --silent
else
gh api --method POST "${api}/git/refs" -f ref="refs/heads/${branch}" -f sha="${commit}" --silent
fi
- name: Open pull request
env:
GH_TOKEN: ${{ steps.app-token.outputs.token }}
run: |
branch="bump-version/${VERSION}"
if [ -n "$( gh pr list --head "${branch}" --state open --json number --jq '.[].number' )" ] ; then
echo "A pull request for ${branch} is already open, updated by the new commit"
exit 0
fi
gh pr create \
--base "${GITHUB_REF_NAME}" \
--head "${branch}" \
--title "Bump version from \`${CURRENT_VERSION}\` to \`${VERSION}\`" \
--body "Bumps the wit package and crates from \`${CURRENT_VERSION}\` to \`${VERSION}\`.

Triggered by @${GITHUB_ACTOR} from the [Bump version](${GITHUB_SERVER_URL}/${GITHUB_REPOSITORY}/actions/runs/${GITHUB_RUN_ID}) workflow."
4 changes: 2 additions & 2 deletions .github/workflows/ci.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -21,7 +21,7 @@ jobs:
# the versions pinned in tools/Cargo.toml, on the path for later steps
run: |
make tools
echo "${PWD}/target/tools/bin" >> "${GITHUB_PATH}"
make -s tools-path >> "${GITHUB_PATH}"
- name: Sync wit
run: make wit
- name: Check for drift in generated wit
Expand Down Expand Up @@ -73,7 +73,7 @@ jobs:
- name: Install tools
run: |
make tools
echo "${PWD}/target/tools/bin" >> "${GITHUB_PATH}"
make -s tools-path >> "${GITHUB_PATH}"
- name: Install cosign
uses: sigstore/cosign-installer@v4.1.2
- name: Download components.tar
Expand Down
2 changes: 2 additions & 0 deletions .gitignore
Original file line number Diff line number Diff line change
Expand Up @@ -2,3 +2,5 @@
/target
.DS_Store
/tools/Cargo.lock
# wit dependencies, fetched by `make wit` from the wkg.toml and wkg.lock files
**/wit/deps/
Loading
Loading