[
https://issues.apache.org/jira/browse/THRIFT-6395?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel
]
Jens Geyer resolved THRIFT-6395.
--------------------------------
Fix Version/s: 0.26.0
Assignee: Jens Geyer
Resolution: Fixed
> Fix the Ruby gem release workflow and limit it to release tags
> --------------------------------------------------------------
>
> Key: THRIFT-6395
> URL: https://issues.apache.org/jira/browse/THRIFT-6395
> Project: Thrift
> Issue Type: Bug
> Components: Build Process, Ruby - Library
> Reporter: Jens Geyer
> Assignee: Jens Geyer
> Priority: Major
> Fix For: 0.26.0
>
> Time Spent: 20m
> Remaining Estimate: 0h
>
> The {{Release Ruby Gem}} workflow ({{.github/workflows/release_ruby.yml}})
> has not published a gem yet. For 0.24.0 and 0.25.0 it stopped at the trusted
> publishing step, because RubyGems.org has no trusted publisher for it, and
> both gems were pushed by hand.
> With a trusted publisher in place it would still fail one step later.
> {{rubygems/release-gem}} runs {{bundle exec rake release}}, but the job never
> installs the bundle: THRIFT-5965 turned {{bundler-cache}} off, and nothing
> replaced it. Replaying the job in {{ruby:4.0}} with Bundler 2.2.34, the
> version setup-ruby installs from {{Gemfile.lock}}:
> {noformat}
> Could not find rack-2.2.23, rack-test-0.8.3, rspec-3.13.2, ... in locally
> installed gems (Bundler::GemNotFound)
> {noformat}
> Installing the bundle brings up a second problem. The workflow can also be
> started by hand, from any branch, and Bundler's release task creates and
> pushes the version tag before it publishes, if that tag does not exist yet.
> Started from master, it would push a v0.26.0 tag and publish 0.26.0.
> h2. Change
> * Install the bundle, frozen to {{Gemfile.lock}}, in a step of its own. Not
> through {{bundler-cache}}: a job that publishes should not restore a cache.
> * Check that the run is for a release tag {{vX.Y.Z}} and that
> {{thrift.gemspec}} has the same version, as {{release_rust.yml}} does for the
> crate. The tag then always exists, and the release task never creates one.
> * Give the job {{contents: read}} only, so that it cannot push a tag.
> * Skip pre-releases, like the other publishing workflows.
> * Describe the workflow in {{doc/ReleaseManagement.md}}.
> _Drafted with AI assistance (Claude Opus 5.5)._
--
This message was sent by Atlassian Jira
(v8.20.10#820010)