You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
{{ message }}
Repository navigation
Commit 78625a6
Browse filesBrowse the repository at this point in the historyBrowse files
description: 'Desktop version, for example 0.1.0 or v0.1.0.'
10
12
required: true
11
13
type: 'string'
12
14
qwen_code_ref:
13
-
description: 'Qwen Code branch, tag, or commit to bundle.'
15
+
description: 'Qwen Code branch or commit to bundle, reachable from main. A release tag whose own commit is off main is refused here: dispatch checks the ref itself, while only the release event peels to its parent.'
if ! jq -e '.isDraft == false and .isPrerelease == false' <<< "$release" >/dev/null 2>&1; then
171
+
exit 0
172
+
fi
173
+
174
+
directory="$(mktemp -d)"
175
+
trap 'rm -rf "$directory"' EXIT
176
+
if ! gh release download "$FEED_TAG" --dir "$directory" --pattern 'desktop-latest.json' >/dev/null 2>&1; then
177
+
exit 0
178
+
fi
179
+
if ! jq -e --arg version "$RELEASE_VERSION" '.version == $version' "$directory/desktop-latest.json" >/dev/null 2>&1; then
180
+
exit 0
181
+
fi
182
+
183
+
if ! curl -fsSL --connect-timeout 15 --max-time 300 "$ALIYUN_OSS_PUBLIC_BASE_URL/desktop/latest/desktop-latest.json" -o "$directory/oss-desktop-latest.json" >/dev/null 2>&1; then
184
+
exit 0
185
+
fi
186
+
if ! jq -e --arg version "$RELEASE_VERSION" '.version == $version' "$directory/oss-desktop-latest.json" >/dev/null 2>&1; then
187
+
exit 0
188
+
fi
189
+
190
+
echo "::notice::Desktop $RELEASE_VERSION is already published; skipping build, publish and sync-oss. Dispatch this workflow with clobber=true to force a rebuild."
echo '::error::Published desktop releases must run from main.'
203
+
if [ "$IS_DRY_RUN" != 'true' ]; then
204
+
if [ "$GITHUB_REF_NAME" != 'main' ] && [ "$GITHUB_EVENT_NAME" != 'release' ]; then
205
+
echo '::error::Published desktop releases must run from main or follow a published release.'
143
206
exit 1
144
207
fi
208
+
# CLI release tags usually point at an off-main version-bump commit
209
+
# whose parent is on main. Verify that parent, while still building
210
+
# the tag itself; tag-publishing permission remains the trust anchor
211
+
# for the version-bump commit.
212
+
ancestor="$sha"
213
+
if [ "$GITHUB_EVENT_NAME" = 'release' ]; then
214
+
ancestor="$(git rev-parse "${sha}^")"
215
+
fi
145
216
git fetch origin main:refs/remotes/origin/main
146
-
if ! git merge-base --is-ancestor "$sha" refs/remotes/origin/main; then
147
-
echo '::error::Published desktop releases may only bundle commits reachable from main.'
217
+
if ! git merge-base --is-ancestor "$ancestor" refs/remotes/origin/main; then
218
+
if [ "$GITHUB_EVENT_NAME" = 'release' ]; then
219
+
echo "::error::Release $INPUT_REF: the tag commit's first parent $ancestor is not reachable from main, so this step cannot confirm the release was cut from main. That shape is a non-main source ref, or commits added to the release branch after the version bump; the dispatch arm refuses it too."
220
+
else
221
+
echo '::error::Published desktop releases may only bundle commits reachable from main.'
0 commit comments