From b7420fe5f213b5af0eeae2db1caf76651e2d425e Mon Sep 17 00:00:00 2001 From: Chris Date: Sun, 27 Sep 2026 08:00:48 +0800 Subject: [PATCH] fix(ci): bootstrap release upload CLIs (#8144) fix(ci): bootstrap release upload CLIs on self-hosted runners --- .github/workflows/build.yml | 27 ++++++++++++++-- .github/workflows/functional-chain-health.yml | 32 +++++++++++++++++++ 2 files changed, 56 insertions(+), 3 deletions(-) diff --git a/.github/workflows/build.yml b/.github/workflows/build.yml index 2f6f6c251..9768d4f65 100644 --- a/.github/workflows/build.yml +++ b/.github/workflows/build.yml @@ -726,12 +726,33 @@ jobs: fi # The self-hosted Linux runners do not ship the aws CLI (GitHub-hosted - # images did). Install it on demand so R2 uploads survive a fresh runner - # instead of hard-failing here. + # images did). Install the official CLI bundle on demand so R2 uploads + # survive a fresh runner without relying on a distro package. if ! command -v aws >/dev/null 2>&1; then echo "aws CLI not found on runner; installing..." if command -v apt-get >/dev/null 2>&1; then - sudo apt-get update && sudo apt-get install -y awscli + aws_arch="$(uname -m)" + case "$aws_arch" in + x86_64) aws_arch="x86_64" ;; + aarch64|arm64) aws_arch="aarch64" ;; + *) + echo "❌ Unsupported Linux architecture for AWS CLI: $aws_arch" + exit 1 + ;; + esac + + aws_install_root="${RUNNER_TEMP:-$PWD}/aws-cli" + rm -rf "$aws_install_root" + mkdir -p "$aws_install_root" + curl --fail --location --retry 3 \ + "https://awscli.amazonaws.com/awscli-exe-linux-${aws_arch}.zip" \ + --output "$aws_install_root/awscliv2.zip" + unzip -q "$aws_install_root/awscliv2.zip" -d "$aws_install_root" + "$aws_install_root/aws/install" \ + --install-dir "$aws_install_root/aws-cli" \ + --bin-dir "$aws_install_root/bin" + export PATH="$aws_install_root/bin:$PATH" + aws --version elif command -v brew >/dev/null 2>&1; then brew install awscli else diff --git a/.github/workflows/functional-chain-health.yml b/.github/workflows/functional-chain-health.yml index f6f4f3bda..da311e3f1 100644 --- a/.github/workflows/functional-chain-health.yml +++ b/.github/workflows/functional-chain-health.yml @@ -17,6 +17,38 @@ jobs: - uses: actions/checkout@f548e57e544e1ff5a4c46bf1e1b8685f8e4a348a # v7 with: persist-credentials: false + - name: Ensure GitHub CLI + shell: bash + run: | + if command -v gh >/dev/null 2>&1; then + gh --version + exit 0 + fi + + gh_version="2.101.0" + case "$(uname -m)" in + x86_64) gh_arch="amd64" ;; + aarch64|arm64) gh_arch="arm64" ;; + *) + echo "Unsupported Linux architecture for GitHub CLI: $(uname -m)" >&2 + exit 1 + ;; + esac + + gh_install_root="${RUNNER_TEMP:-$PWD}/gh-cli" + rm -rf "$gh_install_root" + mkdir -p "$gh_install_root/bin" + archive="$gh_install_root/gh.tar.gz" + curl --fail --location --retry 3 \ + "https://github.com/cli/cli/releases/download/v${gh_version}/gh_${gh_version}_linux_${gh_arch}.tar.gz" \ + --output "$archive" + tar -xzf "$archive" -C "$gh_install_root" + install -m 0755 \ + "$gh_install_root/gh_${gh_version}_linux_${gh_arch}/bin/gh" \ + "$gh_install_root/bin/gh" + echo "$gh_install_root/bin" >> "$GITHUB_PATH" + export PATH="$gh_install_root/bin:$PATH" + gh --version - name: Collect and publish verified chain health env: GH_TOKEN: ${{ secrets.PF_TESTING_GH_TOKEN }}