-
Notifications
You must be signed in to change notification settings - Fork 0
302 lines (268 loc) · 15.1 KB
/
Copy pathrelease.yml
File metadata and controls
302 lines (268 loc) · 15.1 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
130
131
132
133
134
135
136
137
138
139
140
141
142
143
144
145
146
147
148
149
150
151
152
153
154
155
156
157
158
159
160
161
162
163
164
165
166
167
168
169
170
171
172
173
174
175
176
177
178
179
180
181
182
183
184
185
186
187
188
189
190
191
192
193
194
195
196
197
198
199
200
201
202
203
204
205
206
207
208
209
210
211
212
213
214
215
216
217
218
219
220
221
222
223
224
225
226
227
228
229
230
231
232
233
234
235
236
237
238
239
240
241
242
243
244
245
246
247
248
249
250
251
252
253
254
255
256
257
258
259
260
261
262
263
264
265
266
267
268
269
270
271
272
273
274
275
276
277
278
279
280
281
282
283
284
285
286
287
288
289
290
291
292
293
294
295
296
297
298
299
300
301
302
name: Build and Release Python CWMS
on:
push:
tags:
- 'v*'
workflow_dispatch:
inputs:
version:
description: 'Version number (the first installer release must be 2.0)'
required: true
default: '2.0'
permissions:
contents: write
env:
WINPYTHON_VERSION: "WinPython 3.13.15.0dot"
WINPYTHON_FILENAME: "WinPython64-3.13.15.0dot.zip"
WINPYTHON_DOWNLOAD_URL: "https://github.com/winpython/winpython/releases/download/17.12.20260522/WinPython/WinPython64-3.13.15.0dot.zip"
WINPYTHON_SHA256: "28e36408f0140c50b207ea059a599c664564e68a3cbb835f03a71f4601efd8f1"
UV_VERSION: "0.12.22"
jobs:
build:
runs-on: windows-latest
steps:
- name: Checkout repository
uses: actions/checkout@34e114876b0b11c390a56381ad16ebd13914f8d5 # v4
- name: Set release version
shell: pwsh
run: |
$version = if ($env:GITHUB_EVENT_NAME -eq 'workflow_dispatch') {
'${{ github.event.inputs.version }}' -replace '^v', ''
} else {
'${{ github.ref_name }}' -replace '^v', ''
}
if ($version -notmatch '^\d+\.\d+(\.\d+)?$') {
throw "Invalid release version: $version"
}
if ([version]$version -lt [version]'2.0') {
throw 'The installer migration is a breaking change; the next release is v2.0, not a v1.x release.'
}
"VERSION=$version" >> $env:GITHUB_ENV
"RELEASE_TAG=v$version" >> $env:GITHUB_ENV
"ARCHIVE_NAME=pythonCWMS$version.zip" >> $env:GITHUB_ENV
- name: Verify locked requirements are current
shell: pwsh
run: |
python -m pip install --disable-pip-version-check "uv==${{ env.UV_VERSION }}"
if ($LASTEXITCODE -ne 0) { throw 'Could not install the pinned lock generator.' }
$generated = Join-Path $env:RUNNER_TEMP 'locked.txt'
python -m uv pip compile `
--python-platform windows `
--python-version 3.13 `
--upgrade `
--generate-hashes `
--only-binary :all: `
--output-file $generated `
requirements/base_requirements.txt `
requirements/supplemental_requirements.txt
if ($LASTEXITCODE -ne 0) { throw 'Could not regenerate the Windows CPython 3.13 lock.' }
# Ignore uv's command comment because its output path is intentionally temporary.
$committedBody = (Get-Content requirements/locked.txt | Select-Object -Skip 2) -join "`n"
$generatedBody = (Get-Content $generated | Select-Object -Skip 2) -join "`n"
if ($committedBody -cne $generatedBody) {
throw 'requirements/locked.txt is stale. Regenerate it from both input requirement files.'
}
- name: Run Windows installer checks
shell: powershell
run: |
& .\installer\tests\Install-PythonCWMS.Tests.ps1
if ($LASTEXITCODE -ne 0) { exit $LASTEXITCODE }
- name: Download and verify WinPython
shell: pwsh
run: |
Invoke-WebRequest -Uri '${{ env.WINPYTHON_DOWNLOAD_URL }}' -OutFile '${{ env.WINPYTHON_FILENAME }}'
$actual = (Get-FileHash '${{ env.WINPYTHON_FILENAME }}' -Algorithm SHA256).Hash
if ($actual -ne '${{ env.WINPYTHON_SHA256 }}') {
throw "WinPython SHA-256 mismatch. Expected ${{ env.WINPYTHON_SHA256 }}, got $actual."
}
- name: Extract WinPython and install locked packages
shell: pwsh
run: |
$extractRoot = Join-Path $env:RUNNER_TEMP 'wp'
Expand-Archive '${{ env.WINPYTHON_FILENAME }}' -DestinationPath $extractRoot
$winpythonDir = Get-ChildItem $extractRoot -Directory | Select-Object -First 1
if ($null -eq $winpythonDir) { throw 'WinPython archive did not contain a directory.' }
$python = Join-Path $winpythonDir.FullName 'python\python.exe'
if (-not (Test-Path $python -PathType Leaf)) { throw "Python executable not found at $python" }
& $python -m pip install --no-compile --require-hashes --only-binary=:all: -r requirements/locked.txt
if ($LASTEXITCODE -ne 0) { throw 'Locked package installation failed.' }
& $python -m pip check
if ($LASTEXITCODE -ne 0) { throw 'Installed packages have incompatible dependencies.' }
foreach ($requirementsFile in @('requirements/base_requirements.txt', 'requirements/supplemental_requirements.txt')) {
foreach ($line in Get-Content $requirementsFile) {
if ($line -match '^\s*([A-Za-z0-9_.-]+)==([^\s#]+)') {
$name = $Matches[1]
$wanted = $Matches[2]
$shown = & $python -m pip show $name
$installedLine = $shown | Where-Object { $_ -match '^Version:\s*(.+)$' } | Select-Object -First 1
if ($null -eq $installedLine -or $installedLine -notmatch '^Version:\s*(.+)$' -or $Matches[1] -ne $wanted) {
throw "$name requested $wanted but the portable environment does not contain that version."
}
}
}
}
"WINPYTHON_DIR=$($winpythonDir.FullName)" >> $env:GITHUB_ENV
- name: Assemble portable environment
shell: pwsh
run: |
$finalDir = Join-Path $env:RUNNER_TEMP 'pythonCWMS-build'
New-Item -ItemType Directory -Path $finalDir | Out-Null
Copy-Item "${{ env.WINPYTHON_DIR }}\*" $finalDir -Recurse
Copy-Item README.md, LICENSE $finalDir
Copy-Item requirements, jython_scripts $finalDir -Recurse
# Bytecode records the build-time source path and is regenerated on demand.
Get-ChildItem $finalDir -Directory -Filter __pycache__ -Recurse |
Remove-Item -Recurse -Force
Get-ChildItem $finalDir -File -Include *.pyc,*.pyo -Recurse |
Remove-Item -Force
# Normalize pip-generated text launchers that contain the build-time interpreter path.
$scriptsDir = Join-Path $finalDir 'python\Scripts'
Get-ChildItem $scriptsDir -File |
Where-Object { $_.Extension -eq '.py' -or $_.Extension -eq '' } |
ForEach-Object {
$content = [IO.File]::ReadAllText($_.FullName)
if ($content.StartsWith('#!') -and
($content.IndexOf($env:GITHUB_WORKSPACE, [StringComparison]::OrdinalIgnoreCase) -ge 0 -or
$content.IndexOf($env:RUNNER_TEMP, [StringComparison]::OrdinalIgnoreCase) -ge 0)) {
$content = [regex]::Replace($content, '\A#![^\r\n]*', '#!/usr/bin/env python')
[IO.File]::WriteAllText($_.FullName, $content, [Text.UTF8Encoding]::new($false))
}
}
$launcher = Join-Path $finalDir 'python\pythonCWMS.bat'
'@"%~dp0python.exe" %*' | Out-File $launcher -Encoding ascii
"FINAL_DIR=$finalDir" >> $env:GITHUB_ENV
- name: Relocate and smoke test portable environment
shell: pwsh
run: |
$relocated = 'C:\hec\python\pythonCWMS'
if (Test-Path $relocated) { throw "Relocation test target already exists: $relocated" }
New-Item -ItemType Directory -Path ([IO.Path]::GetDirectoryName($relocated)) -Force | Out-Null
Move-Item '${{ env.FINAL_DIR }}' $relocated
$pythonDir = Join-Path $relocated 'python'
$python = Join-Path $pythonDir 'python.exe'
$env:PYTHONDONTWRITEBYTECODE = '1'
$env:PYTHON_CWMS_HOME = $pythonDir
$env:PATH = "$pythonDir;$(Join-Path $pythonDir 'Scripts');$env:PATH"
& $python -c "import sys; import cwms, hecdss, pandas, requests; print(sys.executable)"
if ($LASTEXITCODE -ne 0) { throw 'Relocated Python import smoke test failed.' }
& cmd.exe /d /c "`"$(Join-Path $pythonDir 'pythonCWMS.bat')`" --version"
if ($LASTEXITCODE -ne 0) { throw 'pythonCWMS --version failed after relocation.' }
& (Join-Path $pythonDir 'Scripts\pip.exe') --version
if ($LASTEXITCODE -ne 0) { throw 'pip launcher failed after relocation.' }
& (Join-Path $pythonDir 'Scripts\jupyter.exe') --version
if ($LASTEXITCODE -ne 0) { throw 'Jupyter launcher failed after relocation.' }
$env:PYTHONCWMS_BUILD_PATHS = @(
$env:GITHUB_WORKSPACE, $env:RUNNER_TEMP, $env:WINPYTHON_DIR, $env:FINAL_DIR
) -join [IO.Path]::PathSeparator
& $python -c "import os,sys; p=[x.lower() for x in os.environ['PYTHONCWMS_BUILD_PATHS'].split(os.pathsep) if x]; assert all(all(x not in entry.lower() for entry in sys.path) for x in p), sys.path"
if ($LASTEXITCODE -ne 0) { throw 'Relocated Python retained a build path in sys.path.' }
$pathScan = @'
import os, pathlib, sys
paths = [p for p in os.environ["PYTHONCWMS_BUILD_PATHS"].split(os.pathsep) if p]
needles = {
variant.lower().encode()
for path in paths
for variant in (path, path.replace("\\", "/"))
}
bad = []
for file in pathlib.Path(sys.argv[1]).rglob("*"):
if file.is_file() and any(needle in file.read_bytes().lower() for needle in needles):
bad.append(str(file))
if bad:
raise SystemExit("Build paths remain in: " + ", ".join(bad))
'@
& $python -c $pathScan $relocated
if ($LASTEXITCODE -ne 0) { throw 'Portable files contain an embedded build path.' }
"PORTABLE_DIR=$relocated" >> $env:GITHUB_ENV
- name: Create ZIP archive
shell: pwsh
run: |
Add-Type -AssemblyName System.IO.Compression.FileSystem
$archive = Join-Path $env:GITHUB_WORKSPACE '${{ env.ARCHIVE_NAME }}'
[System.IO.Compression.ZipFile]::CreateFromDirectory(
'${{ env.PORTABLE_DIR }}', $archive,
[System.IO.Compression.CompressionLevel]::Optimal, $false)
$hash = (Get-FileHash $archive -Algorithm SHA256).Hash
"ARCHIVE_HASH=$hash" >> $env:GITHUB_ENV
"ARCHIVE_SIZE_MB=$([math]::Round((Get-Item $archive).Length / 1MB, 2))" >> $env:GITHUB_ENV
- name: Sign archive and validate release key
shell: pwsh
env:
RELEASE_SIGNING_PRIVATE_KEY: ${{ secrets.RELEASE_SIGNING_PRIVATE_KEY }}
run: |
if ([string]::IsNullOrWhiteSpace($env:RELEASE_SIGNING_PRIVATE_KEY)) {
throw 'RELEASE_SIGNING_PRIVATE_KEY is required; refusing to publish an unsigned release.'
}
$archive = '${{ env.ARCHIVE_NAME }}'
$signature = "$archive.sig"
$rsa = [System.Security.Cryptography.RSA]::Create()
try {
$rsa.ImportFromPem($env:RELEASE_SIGNING_PRIVATE_KEY)
$bytes = [System.IO.File]::ReadAllBytes($archive)
$sig = $rsa.SignData($bytes, [Security.Cryptography.HashAlgorithmName]::SHA256, [Security.Cryptography.RSASignaturePadding]::Pkcs1)
} finally { $rsa.Dispose() }
[System.IO.File]::WriteAllBytes($signature, $sig)
$installerSource = Get-Content installer/Install-PythonCWMS.ps1 -Raw
$keyPattern = '(?s)' + [regex]::Escape('$ReleasePublicKeyPem') + "\s*=\s*@'\s*(?<pem>.*?)\s*'@"
$keyMatch = [regex]::Match($installerSource, $keyPattern)
if (-not $keyMatch.Success) { throw 'Could not find the embedded release public key in the PowerShell installer.' }
$publicRsa = [System.Security.Cryptography.RSA]::Create()
try {
$publicRsa.ImportFromPem($keyMatch.Groups['pem'].Value)
$valid = $publicRsa.VerifyData($bytes, $sig, [Security.Cryptography.HashAlgorithmName]::SHA256, [Security.Cryptography.RSASignaturePadding]::Pkcs1)
} finally { $publicRsa.Dispose() }
if (-not $valid) { throw 'The signing private key does not match the public key embedded in the installer.' }
"SIGNATURE_NAME=$signature" >> $env:GITHUB_ENV
- name: Generate release configuration and installer bundle
shell: pwsh
run: |
$assetRoot = Join-Path $env:RUNNER_TEMP 'release-assets'
New-Item -ItemType Directory -Path $assetRoot | Out-Null
$archiveUrl = "https://github.com/${{ github.repository }}/releases/download/${{ env.RELEASE_TAG }}/${{ env.ARCHIVE_NAME }}"
$signatureUrl = "$archiveUrl.sig"
$config = [ordered]@{
config_version = 2
version = '${{ env.VERSION }}'
archive_filename = '${{ env.ARCHIVE_NAME }}'
python_download_url = $archiveUrl
python_expected_hash_sha256 = '${{ env.ARCHIVE_HASH }}'
python_signature_url = $signatureUrl
archive_size_mb = [double]'${{ env.ARCHIVE_SIZE_MB }}'
source_winpython_version = '${{ env.WINPYTHON_VERSION }}'
source_winpython_filename = '${{ env.WINPYTHON_FILENAME }}'
}
$config | ConvertTo-Json | Out-File (Join-Path $assetRoot 'pythonCWMS_config.json') -Encoding utf8
$installerDirectory = Join-Path $assetRoot 'PythonCWMS-Installer'
New-Item -ItemType Directory -Path $installerDirectory | Out-Null
Copy-Item installer/Install-PythonCWMS.cmd, installer/Install-PythonCWMS.ps1 -Destination $installerDirectory
Compress-Archive -Path $installerDirectory -DestinationPath (Join-Path $assetRoot 'PythonCWMS-Installer.zip')
$releaseConfig = (Join-Path $assetRoot 'pythonCWMS_config.json').Replace('\', '/')
$installerBundle = (Join-Path $assetRoot 'PythonCWMS-Installer.zip').Replace('\', '/')
"RELEASE_CONFIG=$releaseConfig" >> $env:GITHUB_ENV
"INSTALLER_BUNDLE=$installerBundle" >> $env:GITHUB_ENV
- name: Publish release
uses: softprops/action-gh-release@de2c0eb89ae2a093876385947365aca7b0e5f844 # v1
with:
tag_name: ${{ env.RELEASE_TAG }}
name: Python CWMS ${{ env.VERSION }}
draft: false
prerelease: false
fail_on_unmatched_files: true
files: |
${{ env.ARCHIVE_NAME }}
${{ env.SIGNATURE_NAME }}
${{ env.RELEASE_CONFIG }}
${{ env.INSTALLER_BUNDLE }}
body: |
## Python CWMS ${{ env.VERSION }}
This is the v2.0 installer migration. The Jython installer has been retired.
### Install or migrate
1. Download `PythonCWMS-Installer.zip`.
2. Extract it; the archive creates a `PythonCWMS-Installer` folder.
3. Open that folder and double-click `Install-PythonCWMS.cmd`.
After a successful installation, the installer removes `PythonCWMS-Installer.zip` and its extracted folder when possible. The default location is `C:\hec\python\pythonCWMS`. If it already exists, the installer asks before replacing it, defaults to Yes, and retains the previous installation as a timestamped backup. Use `-Force` to approve replacement non-interactively.
Release v1.11 cannot be used by the new installer because it has no detached signature asset. Do not modify the historical v1.11 release.
Archive: `${{ env.ARCHIVE_NAME }}` (${{ env.ARCHIVE_SIZE_MB }} MB)
SHA-256: `${{ env.ARCHIVE_HASH }}`
env:
GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }}