Files
Ian MacLeod 6824dabe03 Guard prerelease channel and canary updates against older versions (#47597)
## Why

Publishing a hotfix for an older release line or alpha can replace a newer prerelease pointer. Release pointers should advance according to version order.

## What changed

- Share release version validation and numeric comparison across publishing scripts, including alpha hotfix suffixes and alpha, beta, and stable ordering.
- Read the prerelease pointer directly from R2 and update it only for a newer version or missing or invalid version metadata.
- Restrict `latest-alpha-cli` updates to alpha releases with successful R2 and npm publishing, and compare against the branch's Cargo version before advancing it. Allow replacement when the manifest version cannot be parsed or validated.

## Testing

Add 15 passing unit tests covering version validation, older release lines and alphas, numeric hotfix ordering, prerelease precedence, equal versions, and missing or invalid versions.

GitOrigin-RevId: 6bee3906a47f613b662ef2b2224cfcbd1b56650c
2026-09-23 17:35:40 +00:00

60 lines
1.9 KiB
YAML

name: publish-r2-release
on:
workflow_call:
inputs:
tag:
required: true
type: string
make_latest:
required: true
type: boolean
prerelease:
required: true
type: boolean
stage:
required: true
type: string
permissions: {}
jobs:
publish:
runs-on: ubuntu-latest
timeout-minutes: 60
environment: codex-r2-publisher
permissions:
contents: read
steps:
- name: Checkout
uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2
with:
persist-credentials: false
- name: Publish release assets and metadata to R2
# R2 exposes an S3-compatible API, so the AWS CLI reads AWS-named variables.
env:
AWS_ACCESS_KEY_ID: ${{ secrets.CODEX_R2_ACCESS_KEY_ID }}
AWS_SECRET_ACCESS_KEY: ${{ secrets.CODEX_R2_SECRET_ACCESS_KEY }}
AWS_ENDPOINT_URL: ${{ vars.CODEX_R2_ENDPOINT_URL }}
AWS_REGION: ${{ vars.CODEX_R2_REGION }}
AWS_RETRY_MODE: standard
AWS_MAX_ATTEMPTS: "6"
GH_TOKEN: ${{ github.token }}
RELEASE_TAG: ${{ inputs.tag }}
RELEASE_MAKE_LATEST: ${{ inputs.make_latest }}
RELEASE_PRERELEASE: ${{ inputs.prerelease }}
RELEASE_STAGE: ${{ inputs.stage }}
PYTHONPATH: .github/scripts
run: |
set -euo pipefail
# The publisher parallelizes objects; serialize parts within each object to avoid R2 throttling.
aws configure set default.s3.preferred_transfer_client classic
aws configure set default.s3.max_concurrent_requests 1
python3 .github/scripts/publish_r2_release.py \
--tag "${RELEASE_TAG}" \
--make-latest "${RELEASE_MAKE_LATEST}" \
--prerelease "${RELEASE_PRERELEASE}" \
--stage "${RELEASE_STAGE}"