-
Notifications
You must be signed in to change notification settings - Fork 8
ci: arm publishing for @cipherstash/auth and the stack-* crates #1009
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Merged
Merged
Changes from all commits
Commits
Show all changes
5 commits
Select commit
Hold shift + click to select a range
6643785
feat(release): stop freezing the @cipherstash/auth packages
auxesis 0efb59e
ci: require an @cipherstash/auth changeset for changes it ships
auxesis e766c9a
chore(changeset): carry the six pending @cipherstash/auth changesets
auxesis 931f359
build: take @cipherstash/auth from the workspace, not the registry
auxesis ed14d04
chore(changeset): tell Alpine users that @cipherstash/auth loads on m…
auxesis File filter
Filter by extension
Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
There are no files selected for viewing
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
| Original file line number | Diff line number | Diff line change |
|---|---|---|
| @@ -0,0 +1,8 @@ | ||
| --- | ||
| "@cipherstash/auth": patch | ||
| --- | ||
|
|
||
| Internal addition to the underlying Rust crate: `AuthError` gains an | ||
| `is_credential_rejection()` classifier used by FFI front-ends to decide | ||
| whether refreshing the credential and retrying is sensible. No API or | ||
| behaviour change for `@cipherstash/auth` consumers. |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
| Original file line number | Diff line number | Diff line change |
|---|---|---|
| @@ -0,0 +1,5 @@ | ||
| --- | ||
| "@cipherstash/auth": patch | ||
| --- | ||
|
|
||
| Device-session refresh now reports failed profile saves so callers do not silently reuse a consumed refresh token. |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
| Original file line number | Diff line number | Diff line change |
|---|---|---|
| @@ -0,0 +1,11 @@ | ||
| --- | ||
| "@cipherstash/auth": patch | ||
| --- | ||
|
|
||
| Internal restructuring of the underlying Rust crate: HTTP transport (reqwest | ||
| and the bundled access-key, device-session, OIDC-federation and auto | ||
| strategies) now sits behind an `http` cargo feature, on by default and always | ||
| enabled in the npm builds — no API change for `@cipherstash/auth` consumers. | ||
| The only observable difference is the wording of transport-failure error | ||
| messages, which now read "Request to the auth server failed: …" instead of | ||
| "HTTP request failed: …". |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
| Original file line number | Diff line number | Diff line change |
|---|---|---|
| @@ -0,0 +1,9 @@ | ||
| --- | ||
| "@cipherstash/auth": patch | ||
| --- | ||
|
|
||
| Internal restructuring of the underlying Rust crate: every strategy now sends | ||
| its requests through an `HttpTransport` trait, with the bundled reqwest client | ||
| as the default implementation, so the same strategies can run over a host's own | ||
| HTTP client (the Go binding's WASI guest). The npm builds always use the bundled | ||
| client — no API or behaviour change for `@cipherstash/auth` consumers. |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
| Original file line number | Diff line number | Diff line change |
|---|---|---|
| @@ -0,0 +1,6 @@ | ||
| --- | ||
| "@cipherstash/auth": patch | ||
| --- | ||
|
|
||
| The `linux-x64-musl` binary now links musl. In 0.44.0 it linked glibc, so | ||
| `@cipherstash/auth` did not load on musl systems such as Alpine Linux. |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
| Original file line number | Diff line number | Diff line change |
|---|---|---|
| @@ -0,0 +1,5 @@ | ||
| --- | ||
| "@cipherstash/auth": patch | ||
| --- | ||
|
|
||
| Internal test-only change to the underlying Rust crate: adds regression coverage for token expiry, credential rejection, device metadata, and browser-launch results. No API or behaviour change for `@cipherstash/auth` consumers; this entry exists because CI requires a changeset for changes under the crate. |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
| Original file line number | Diff line number | Diff line change |
|---|---|---|
| @@ -0,0 +1,8 @@ | ||
| --- | ||
| "@cipherstash/auth": patch | ||
| --- | ||
|
|
||
| Internal addition to the underlying Rust crate: `stack_auth` now re-exports | ||
| `Crn` (the workspace CRN every strategy is bound to) so a caller that builds | ||
| a strategy by hand needs nothing else from `cts-common`. No API or behaviour | ||
| change for `@cipherstash/auth` consumers. |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
| Original file line number | Diff line number | Diff line change |
|---|---|---|
| @@ -0,0 +1,73 @@ | ||
| name: Build the @cipherstash/auth binding | ||
| description: >- | ||
| Compile `languages/typescript/packages/auth` into what its JS consumers load | ||
| at runtime — the napi module (cargo, debug) and optionally `wasm/` | ||
| (wasm-pack) — then prove they load. | ||
|
|
||
| WHY THIS EXISTS: `@cipherstash/stack`, `stash`, `@cipherstash/wizard` and the | ||
| protect-ffi integration suite take `@cipherstash/auth` from the workspace. | ||
| It ships source only there, and its `index.js` loads the napi module on | ||
| import, so every job that imports the SDK or runs the CLI builds it first. | ||
| From npm, the platform package brought a prebuilt `.node`. Without this, those | ||
| jobs fail with `Failed to load native binding for linux-x64`. It is the auth | ||
| half of `.github/actions/build-ffi-binding`, and runs after it; | ||
| scripts/__tests__/auth-binding-step-order.test.mjs holds the jobs to that. | ||
|
|
||
| DO NOT USE FROM A PUBLISHING WORKFLOW: release builds go through | ||
| `_build-auth-artifacts.yml`, which compiles every platform from scratch. | ||
|
|
||
| inputs: | ||
| wasm: | ||
| description: >- | ||
| Also build `wasm/`, which `@cipherstash/auth/wasm-inline` imports and | ||
| `@cipherstash/stack/wasm-inline` re-exports. Pass it where the job passes | ||
| `wasm: true` to build-ffi-binding. | ||
| required: false | ||
| default: 'false' | ||
|
|
||
| runs: | ||
| using: composite | ||
| steps: | ||
| # The runner's cargo, as build-ffi-binding uses for `index.node`. Writes | ||
| # the typings to the committed `native.d.ts`, so the tree stays clean. | ||
| - name: Build the napi module (cargo) | ||
| shell: bash | ||
| run: pnpm --filter @cipherstash/auth run build:debug | ||
|
|
||
| # The root mise.toml pins wasm-pack for this build. `install_args` narrows | ||
| # the install to it: the root also pins Rust, Go and golangci-lint, which | ||
| # this needs none of. Same action and pin as build-ffi-binding. | ||
| - name: Install wasm-pack | ||
| if: inputs.wasm == 'true' | ||
| uses: jdx/mise-action@5228313ee0372e111a38da051671ca30fc5a96db # v3.6.3 | ||
| with: | ||
| install: true | ||
| install_args: aqua:wasm-bindgen/wasm-pack | ||
| working_directory: . | ||
|
|
||
| - name: Add the wasm32 target | ||
| if: inputs.wasm == 'true' | ||
| shell: bash | ||
| run: rustup target add wasm32-unknown-unknown | ||
|
|
||
| - name: Build wasm/ (wasm-pack) | ||
| if: inputs.wasm == 'true' | ||
| shell: bash | ||
| run: pnpm --filter @cipherstash/auth run build:wasm | ||
|
|
||
| - name: Verify the binding loads | ||
| shell: bash | ||
| working-directory: languages/typescript/packages/auth | ||
| env: | ||
| WANT_WASM: ${{ inputs.wasm }} | ||
| run: | | ||
| set -euo pipefail | ||
|
|
||
| # index.js loads the napi module when it is required. | ||
| node -e "require('./index.js')" | ||
| echo "the napi module loads" | ||
|
|
||
| if [ "$WANT_WASM" = "true" ]; then | ||
| node --input-type=module -e "await import('./wasm-inline.mjs')" | ||
| echo "wasm/ loads" | ||
| fi | ||
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Oops, something went wrong.
Oops, something went wrong.
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Non-blocking: unlike
build-ffi-binding, this action has no cache.build-ffi-bindingcachesindex.nodeon a hash of its Rust inputs, so a PR that changes no Rust only restores the file. Here, each of the ~11 jobs that use this action does a coldcargo build(debug) ofstack-auth-nodeon every run. That build includesaws-lc-systhroughjsonwebtoken, and also the wasm-pack build where the job passeswasm: true.The result is correct, so this does not block the freeze. For a follow-up, the same
actions/cachepattern asbuild-ffi-bindingwould apply here, keyed on the rootCargo.lock, thestack-auth/stack-profilesources and this binding crate. The "DO NOT USE FROM A PUBLISHING WORKFLOW" note above already covers the release-cache rule.