Skip to content
Open
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
49 changes: 41 additions & 8 deletions .github/workflows/build-deps-linux.yml
Original file line number Diff line number Diff line change
Expand Up @@ -23,11 +23,20 @@ on:

permissions:
contents: write
actions: read

jobs:
# x64 ships in two CPU tiers (issue #92): v3 for x86-64-v3 CPUs, v2 for
# anything older. Same script, one --tier switch.
build-x64:
if: ${{ inputs.arch == 'x64' || inputs.arch == 'both' }}
runs-on: ubuntu-24.04
strategy:
fail-fast: false
matrix:
tier: [v3, v2]
env:
ASSET: VapourBox-deps-${{ inputs.version }}-linux-x64${{ matrix.tier == 'v2' && '-v2' || '' }}
steps:
- uses: actions/checkout@v5

Expand All @@ -47,27 +56,51 @@ jobs:
gcc --version | head -1
pip3 install meson

- name: Build dependencies
run: ./Scripts/download-deps-linux.sh --force
- name: Build dependencies (${{ matrix.tier }})
run: ./Scripts/download-deps-linux.sh --force --tier ${{ matrix.tier }}

- name: Package dependencies
run: ./Scripts/package-deps-linux.sh --version "${{ inputs.version }}" --arch x64

- uses: actions/upload-artifact@v5
with:
name: VapourBox-deps-${{ inputs.version }}-linux-x64
name: ${{ env.ASSET }}
path: |
dist/VapourBox-deps-${{ inputs.version }}-linux-x64.zip
dist/VapourBox-deps-${{ inputs.version }}-linux-x64.zip.sha256.json
dist/${{ env.ASSET }}.zip
dist/${{ env.ASSET }}.zip.sha256.json

# The v2 bundle's promise is that it runs on CPUs without AVX. Every hosted
# runner has AVX2, so prove it by running every plugin under Intel SDE
# emulating Westmere (the Mac Pro 5,1 from issue #92).
gate-x64-v2:
needs: build-x64
uses: ./.github/workflows/probe-cpu-compat.yml
with:
artifact_prefix: VapourBox-deps-${{ inputs.version }}-
tier: v2
gate: true
matrix_json: '[{"platform":"linux-x64","runner":"ubuntu-24.04","sde":"sde64","python":"python/bin/python3","chip":"wsm"}]'

# Published only once the v2 gate has passed, so a bundle that would crash on
# an older CPU never reaches a release.
upload-x64:
needs: [build-x64, gate-x64-v2]
if: inputs.release_tag != ''
runs-on: ubuntu-24.04
steps:
- uses: actions/download-artifact@v5
with:
pattern: VapourBox-deps-${{ inputs.version }}-linux-x64*
path: dist
merge-multiple: true
- name: Upload to release
if: inputs.release_tag != ''
env:
GH_TOKEN: ${{ github.token }}
run: |
gh release upload "${{ inputs.release_tag }}" \
"dist/VapourBox-deps-${{ inputs.version }}-linux-x64.zip" \
"dist/VapourBox-deps-${{ inputs.version }}-linux-x64.zip.sha256.json" --clobber
--repo "${{ github.repository }}" \
dist/VapourBox-deps-${{ inputs.version }}-linux-x64*.zip \
dist/VapourBox-deps-${{ inputs.version }}-linux-x64*.zip.sha256.json --clobber

build-arm64:
if: ${{ inputs.arch == 'arm64' || inputs.arch == 'both' }}
Expand Down
25 changes: 18 additions & 7 deletions .github/workflows/build-deps-macos.yml
Original file line number Diff line number Diff line change
Expand Up @@ -60,34 +60,45 @@ jobs:
"dist/VapourBox-deps-${{ inputs.version }}-macos-arm64.zip" \
"dist/VapourBox-deps-${{ inputs.version }}-macos-arm64.zip.sha256.json" --clobber

# x64 ships in two CPU tiers (issue #92): v3 for x86-64-v3 CPUs, v2 for
# anything older. Same script, one --tier switch. The v2 bundle is gated by
# package-deps-macos.sh itself (Scripts/check-load-time-simd.py): macOS has
# no Intel SDE, so it proves statically that no plugin runs AVX while it
# loads — and fails before anything below can upload it.
build-x64:
if: ${{ inputs.arch == 'x64' || inputs.arch == 'both' }}
runs-on: macos-15-intel # only hosted Intel image (macos-13 retired; last one until ~Aug 2027)
strategy:
fail-fast: false
matrix:
tier: [v3, v2]
env:
ASSET: VapourBox-deps-${{ inputs.version }}-macos-x64${{ matrix.tier == 'v2' && '-v2' || '' }}
steps:
- uses: actions/checkout@v5

- name: Build dependencies (x64, native)
- name: Build dependencies (x64 ${{ matrix.tier }}, native)
# STRICT_MIN_OS=1: fail the build if any bundled Mach-O targets newer than
# the macOS 12 floor (issue #39) instead of silently shipping it.
env:
STRICT_MIN_OS: "1"
run: ./Scripts/download-deps-macos.sh --force
run: ./Scripts/download-deps-macos.sh --force --tier ${{ matrix.tier }}

- name: Package dependencies
run: ./Scripts/package-deps-macos.sh --version "${{ inputs.version }}" --arch x64

- uses: actions/upload-artifact@v5
with:
name: VapourBox-deps-${{ inputs.version }}-macos-x64
name: ${{ env.ASSET }}
path: |
dist/VapourBox-deps-${{ inputs.version }}-macos-x64.zip
dist/VapourBox-deps-${{ inputs.version }}-macos-x64.zip.sha256.json
dist/${{ env.ASSET }}.zip
dist/${{ env.ASSET }}.zip.sha256.json

- name: Upload to release
if: inputs.release_tag != ''
env:
GH_TOKEN: ${{ github.token }}
run: |
gh release upload "${{ inputs.release_tag }}" \
"dist/VapourBox-deps-${{ inputs.version }}-macos-x64.zip" \
"dist/VapourBox-deps-${{ inputs.version }}-macos-x64.zip.sha256.json" --clobber
"dist/${{ env.ASSET }}.zip" \
"dist/${{ env.ASSET }}.zip.sha256.json" --clobber
52 changes: 42 additions & 10 deletions .github/workflows/build-deps-windows.yml
Original file line number Diff line number Diff line change
Expand Up @@ -20,34 +20,66 @@ on:

permissions:
contents: write
actions: read

jobs:
# x64 ships in two CPU tiers (issue #92): v3 for x86-64-v3 CPUs, v2 for
# anything older. Same script, one -Tier switch.
build-x64:
runs-on: windows-latest
strategy:
fail-fast: false
matrix:
tier: [v3, v2]
env:
ASSET: VapourBox-deps-${{ inputs.version }}-windows-x64${{ matrix.tier == 'v2' && '-v2' || '' }}
steps:
- uses: actions/checkout@v5

- name: Build dependencies
- name: Build dependencies (${{ matrix.tier }})
shell: pwsh
run: ./Scripts/download-deps-windows.ps1
run: ./Scripts/download-deps-windows.ps1 -Tier ${{ matrix.tier }}

- name: Package dependencies
shell: pwsh
run: ./Scripts/package-deps-windows.ps1 -Version "${{ inputs.version }}"

- uses: actions/upload-artifact@v5
with:
name: VapourBox-deps-${{ inputs.version }}-windows-x64
name: ${{ env.ASSET }}
path: |
dist/VapourBox-deps-${{ inputs.version }}-windows-x64.zip
dist/VapourBox-deps-${{ inputs.version }}-windows-x64.zip.sha256.json
dist/${{ env.ASSET }}.zip
dist/${{ env.ASSET }}.zip.sha256.json

# The v2 bundle must run below x86-64-v3, and every hosted runner has AVX2.
# Windows is probed at Sandy Bridge (AVX without AVX2): at pre-AVX chips SDE
# cannot emulate what Microsoft's runtime reads from the kernel, so the core
# control fails and nothing could be proven (see probe-cpu-compat.yml).
gate-x64-v2:
needs: build-x64
uses: ./.github/workflows/probe-cpu-compat.yml
with:
artifact_prefix: VapourBox-deps-${{ inputs.version }}-
tier: v2
gate: true
matrix_json: '[{"platform":"windows-x64","runner":"windows-latest","sde":"sde.exe","python":"vapoursynth/python.exe","chip":"snb"}]'

# Published only once the v2 gate has passed.
upload-x64:
needs: [build-x64, gate-x64-v2]
if: inputs.release_tag != ''
runs-on: ubuntu-24.04
steps:
- uses: actions/download-artifact@v5
with:
pattern: VapourBox-deps-${{ inputs.version }}-windows-x64*
path: dist
merge-multiple: true
- name: Upload to release
if: inputs.release_tag != ''
shell: pwsh
env:
GH_TOKEN: ${{ github.token }}
run: |
gh release upload "${{ inputs.release_tag }}" `
"dist/VapourBox-deps-${{ inputs.version }}-windows-x64.zip" `
"dist/VapourBox-deps-${{ inputs.version }}-windows-x64.zip.sha256.json" --clobber
gh release upload "${{ inputs.release_tag }}" \
--repo "${{ github.repository }}" \
dist/VapourBox-deps-${{ inputs.version }}-windows-x64*.zip \
dist/VapourBox-deps-${{ inputs.version }}-windows-x64*.zip.sha256.json --clobber
32 changes: 27 additions & 5 deletions .github/workflows/nightly.yml
Original file line number Diff line number Diff line change
Expand Up @@ -44,11 +44,20 @@ jobs:
strategy:
fail-fast: false
matrix:
# x64 runs both CPU-tier bundles (issue #92). The runner is a v3 CPU, so
# the v2 run proves the v2 bundle is functionally equivalent — not that
# it runs on an older CPU; that is build-deps-macos.yml's static gate.
include:
- arch: arm64
runner: macos-15
asset: macos-arm64
- arch: x64
runner: macos-15-intel # last native Intel image, available until ~Aug 2027
asset: macos-x64
- arch: x64
runner: macos-15-intel
asset: macos-x64-v2
name: macos (${{ matrix.asset }})
runs-on: ${{ matrix.runner }}
env:
VAPOURBOX_DEPS_DIR: ${{ github.workspace }}/deps/macos-${{ matrix.arch }}
Expand All @@ -71,14 +80,15 @@ jobs:
- name: Setup Rust
uses: dtolnay/rust-toolchain@stable

- name: Download dependencies (${{ matrix.arch }})
- name: Download dependencies (${{ matrix.asset }})
env:
GH_TOKEN: ${{ github.token }}
DEPS_RUN_ID: ${{ inputs.deps_run_id }}
run: |
# The tier is in the asset name only; either installs to deps/<platform>.
PLATFORM="macos-${{ matrix.arch }}"
mkdir -p "deps/$PLATFORM"
ZIP=$(bash .github/scripts/fetch-deps-bundle.sh "$PLATFORM" \
ZIP=$(bash .github/scripts/fetch-deps-bundle.sh "${{ matrix.asset }}" \
"${{ steps.deps.outputs.tag }}" "${{ steps.deps.outputs.ver }}")
unzip -q -o "$ZIP" -d "deps/$PLATFORM"
rm -rf "$ZIP" .deps-artifact
Expand Down Expand Up @@ -123,6 +133,12 @@ jobs:

windows:
if: ${{ github.event_name == 'schedule' || inputs.platform == 'all' || inputs.platform == 'windows' }}
# Both CPU-tier bundles (issue #92); see the macOS job for what the v2 run proves.
strategy:
fail-fast: false
matrix:
asset: [windows-x64, windows-x64-v2]
name: windows (${{ matrix.asset }})
runs-on: windows-latest
env:
VAPOURBOX_DEPS_DIR: ${{ github.workspace }}/deps/windows-x64
Expand Down Expand Up @@ -153,7 +169,7 @@ jobs:
DEPS_RUN_ID: ${{ inputs.deps_run_id }}
run: |
mkdir -p deps/windows-x64
ZIP=$(bash .github/scripts/fetch-deps-bundle.sh windows-x64 \
ZIP=$(bash .github/scripts/fetch-deps-bundle.sh "${{ matrix.asset }}" \
"${{ steps.deps.outputs.tag }}" "${{ steps.deps.outputs.ver }}")
7z x "$ZIP" -o"deps/windows-x64" -y >/dev/null
rm -rf "$ZIP" .deps-artifact
Expand Down Expand Up @@ -197,6 +213,12 @@ jobs:

linux:
if: ${{ github.event_name == 'schedule' || inputs.platform == 'all' || inputs.platform == 'linux' }}
# Both CPU-tier bundles (issue #92); see the macOS job for what the v2 run proves.
strategy:
fail-fast: false
matrix:
asset: [linux-x64, linux-x64-v2]
name: linux (${{ matrix.asset }})
runs-on: ubuntu-24.04 # must match the deps-build runner (glibc)
env:
VAPOURBOX_DEPS_DIR: ${{ github.workspace }}/deps/linux-x64
Expand Down Expand Up @@ -225,13 +247,13 @@ jobs:
- name: Setup Rust
uses: dtolnay/rust-toolchain@stable

- name: Download dependencies (linux-x64)
- name: Download dependencies (${{ matrix.asset }})
env:
GH_TOKEN: ${{ github.token }}
DEPS_RUN_ID: ${{ inputs.deps_run_id }}
run: |
mkdir -p deps/linux-x64
ZIP=$(bash .github/scripts/fetch-deps-bundle.sh linux-x64 \
ZIP=$(bash .github/scripts/fetch-deps-bundle.sh "${{ matrix.asset }}" \
"${{ steps.deps.outputs.tag }}" "${{ steps.deps.outputs.ver }}")
unzip -q -o "$ZIP" -d deps/linux-x64
rm -rf "$ZIP" .deps-artifact
Expand Down
Loading
Loading