Cutting a release#
For maintainers. Installing and verifying a release is in install.md.
Steps#
- Set
versioninCargo.toml(for an alpha,0.1.0-alpha.2and so on), runcargo checkto updateCargo.lock, and merge that through a reviewed pull request. EveryCargo.tomlchange makesrelease/release-configstale, so each release needs a fresh review of it. - On the merged commit, run
scripts/gate.sh.snob checkmust pass: every obligation is either reviewed orexemptunder the[ratchet]baseline. - Tag that commit
vplus the version (v0.1.0-alpha.2,v1.2.3) and push the tag. - The release workflow builds a draft release; a version with a
prerelease part (
-alpha.1) is marked as a GitHub prerelease. Check it has four archives andSHA256SUMS, and thatgh attestation verifypasses for each archive. Then publish.
What the workflow enforces#
.github/workflows/release.yml runs on
vX.Y.Z and vX.Y.Z-* tags.
- The tag equals
vplus theCargo.tomlversion, andCargo.lockagrees (scripts/release-check.sh). - The tagged commit is on the default branch, so the configuration and ratchet baseline in effect are ones that branch accepted.
scripts/gate.sh allpasses on the tagged commit, with full git history for the ratchet baseline. That includessnob checkon this repository: inherited debt from before the baseline is exempt, but any review outstanding on a later change blocks the release.--lockedand the pinned toolchain are used throughout.- Permissions are denied by default. Build jobs can read and attest; only the last job can write, and only to create the draft.
- Every job uses a runner from the approved list in
tests/dogfood.rs.
Targets and runners#
| Target | Built and smoke-tested on | Notes |
|---|---|---|
x86_64-unknown-linux-gnu |
blacksmith-2vcpu-ubuntu-2204 |
glibc 2.35 or newer |
aarch64-unknown-linux-gnu |
blacksmith-2vcpu-ubuntu-2204-arm |
glibc 2.35 or newer |
x86_64-apple-darwin |
blacksmith-6vcpu-macos-15 |
cross-compiled on Apple Silicon, smoke-tested under Rosetta 2 |
aarch64-apple-darwin |
blacksmith-6vcpu-macos-15 |
All jobs run on Blacksmith runners. Linux binaries are built on Ubuntu 22.04 so they run on glibc 2.35 and newer. Blacksmith has no Intel Macs, so the x86_64 macOS binary is never run on Intel hardware before release. On the first release run, check that the arm64 and macOS runners start and that Rosetta 2 installs.
Attestations need a public repository or GitHub Enterprise Cloud; without them only the checksums are available. There are no Windows binaries: snob may build there, but process cleanup is Unix-only and Windows has not been tested.