nandi/frqpublic Fork 0
b4172e953d70d5164f0837f6a88b0b92448c32f6
Commits
Clone
git clone https://git.rickub.com/nandi/frq.git
git clone ssh://git@rickub.com/nandi/frq.git

Host key fingerprint (ed25519): SHA256:iycHnxEyq0Q7uyVpB7JlznP0G7JrTPXLYRcAU5CSLhc — verify it before your first connect.

A Mesa nobody needed, and the AppImage that carried it 9db383c · on b4172e953d70d5164f0837f6a88b0b92448c32f6 · nandi · 22h ago
build.yml · 99 lines · 4.3 KBYAML Blame HistoryRaw
 1
 2
 3
 4
 5
 6
 7
 8
 9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
# The build, on rickub. GitLab CI next door reads source and no more —
# check-common on every push, the flake.lock nightly — and deliberately builds
# nothing. This is the other half: the desktop bundle, actually assembled.
#
# It is not assembled *here*, though it nearly could be now. The job hands the
# work to Modal exactly as a person at a terminal would, and the Sandbox does
# it against the `devshell` volume. What a runner contributes is a checkout, a
# python, and somewhere to put the result afterwards.
#
# It used to be `nix build .#appimage`, which a rickub runner could not have
# done at all — a container against libjoltcosmic's dependency tree is the
# laptop-shaped death CLAUDE.md warns about. That is no longer what the
# container runs: jolt, the backends and libmoq_ffi all arrive pinned and
# prebuilt, so the Modal side fetches and copies rather than compiling. The
# reason it still goes to Modal is the volume the toolchain is cached on, not
# the size of the build.
#
# Lives in .rickub/workflows/ rather than .github/workflows/ because rickub
# reads one or the other and never both: with this directory present, a
# .github/workflows/ added later would be silently ignored. There is none
# today, so nothing is being shadowed — see
# https://rickub.com/docs/actions and https://rickub.com/docs/migrating-from-github
name: build

on:
  push:
  workflow_dispatch:

jobs:
  # The same read-only check GitLab runs, for the same reason: common/ compiles
  # twice and only the jolt half is on the way to anything anyone runs, so a
  # JVM call in shared code breaks the phone at a namespace nobody touched.
  # Seconds, no toolchain. Worth having on both hosts rather than depending on
  # which one a given push reaches.
  check-common:
    runs-on: ubuntu-latest
    steps:
      - uses: actions/checkout@v4
      - run: python3 tools/check-common.py common

  desktop:
    runs-on: ubuntu-latest
    needs: check-common
    # Minutes now, not an hour. The Modal side compiles one .c file; what it
    # spends its time on is fetching the pinned pieces on a cold toolchain and
    # the upload of the tree from here.
    timeout-minutes: 30
    steps:
      # The container copies `.` — the whole working tree, uncommitted edits
      # included. On a runner that is whatever the checkout left, so it wants
      # to be the commit and not a shallow surprise.
      - uses: actions/checkout@v4

      - uses: actions/setup-python@v5
        with:
          python-version: "3.12"

      - run: pip install --disable-pip-version-check modal

      # Two secrets, set under Settings -> Secrets and variables. A Modal
      # token is the whole of this job's configuration: no nix, no builder,
      # no cache of its own.
      - name: Assemble the desktop bundle, on Modal
        env:
          MODAL_TOKEN_ID: ${{ secrets.MODAL_TOKEN_ID }}
          MODAL_TOKEN_SECRET: ${{ secrets.MODAL_TOKEN_SECRET }}
        # Unpiped on purpose. The image build streams to this client and
        # nowhere else, and `modal app logs` cannot reach an ephemeral run —
        # so this terminal is the only place the build is visible. tee, not
        # tail: a run killed mid-pipe through tail takes its output with it.
        run: modal run .modal/frq/container.py 2>&1 | tee /tmp/frq-build.log

      # The Sandbox leaves the tarball on the devshell volume rather than
      # anywhere a runner can see, so fetch it back out. One file, already a
      # squashed tree — nothing to import on the other end, and nothing to
      # unpack before it can be uploaded.
      - name: Fetch the bundle out of the volume
        env:
          MODAL_TOKEN_ID: ${{ secrets.MODAL_TOKEN_ID }}
          MODAL_TOKEN_SECRET: ${{ secrets.MODAL_TOKEN_SECRET }}
        run: |
          modal volume get --force devshell \
            artifacts/frq-desktop-x86_64-linux.tar.gz \
            frq-desktop-x86_64-linux.tar.gz

      - uses: actions/upload-artifact@v4
        with:
          name: frq-desktop-${{ github.sha }}
          path: frq-desktop-x86_64-linux.tar.gz
          if-no-files-found: error

      # Kept whether or not the build succeeded: a failed run's log is the
      # one most worth reading, and it is gone with the runner otherwise.
      - uses: actions/upload-artifact@v4
        if: always()
        with:
          name: build-log
          path: /tmp/frq-build.log
          if-no-files-found: ignore