build 13 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327328329330331332333334335336337338339340341342343344345346347348349350351352353354355356357358359360361362363364365366367368369370371372373374375376377378379380381382383384385386387388389390391392393394395396397398399400401402403404405406407408409410411412413414415416417418419420421422
  1. #!/usr/bin/env bash
  2. # This script helps to build release artifacts.
  3. # arg1: profile, e.g. emqx | emqx-enterprise
  4. # arg2: artifact, e.g. rel | relup | tgz | pkg
  5. set -euo pipefail
  6. [ "${DEBUG:-0}" -eq 1 ] && set -x
  7. PROFILE_ARG="$1"
  8. ARTIFACT="$2"
  9. is_enterprise() {
  10. case "$1" in
  11. *enterprise*)
  12. echo 'yes'
  13. ;;
  14. *)
  15. echo 'no'
  16. ;;
  17. esac
  18. }
  19. PROFILE_ENV="${PROFILE:-${PROFILE_ARG}}"
  20. case "$(is_enterprise "$PROFILE_ARG"),$(is_enterprise "$PROFILE_ENV")" in
  21. 'yes,yes')
  22. true
  23. ;;
  24. 'no,no')
  25. true
  26. ;;
  27. *)
  28. echo "PROFILE env var is set to '$PROFILE_ENV', but '$0' arg1 is '$PROFILE_ARG'"
  29. exit 1
  30. ;;
  31. esac
  32. # make sure PROFILE is exported, it is needed by rebar.config.erl
  33. PROFILE=$PROFILE_ARG
  34. export PROFILE
  35. # ensure dir
  36. cd -P -- "$(dirname -- "${BASH_SOURCE[0]}")"
  37. PKG_VSN="${PKG_VSN:-$(./pkg-vsn.sh "$PROFILE")}"
  38. export PKG_VSN
  39. SYSTEM="$(./scripts/get-distro.sh)"
  40. ARCH="$(uname -m)"
  41. case "$ARCH" in
  42. x86_64)
  43. ARCH='amd64'
  44. ;;
  45. aarch64)
  46. ARCH='arm64'
  47. ;;
  48. arm*)
  49. ARCH='arm64'
  50. ;;
  51. esac
  52. export ARCH
  53. ##
  54. ## Support RPM and Debian based linux systems
  55. ##
  56. if [ "$(uname -s)" = 'Linux' ]; then
  57. case "${SYSTEM:-}" in
  58. ubuntu*|debian*|raspbian*)
  59. PKGERDIR='deb'
  60. ;;
  61. *)
  62. PKGERDIR='rpm'
  63. ;;
  64. esac
  65. fi
  66. if [ "${SYSTEM}" = 'windows' ]; then
  67. # windows does not like the find
  68. FIND="/usr/bin/find"
  69. TAR="/usr/bin/tar"
  70. export BUILD_WITHOUT_ROCKSDB="on"
  71. else
  72. FIND='find'
  73. TAR='tar'
  74. fi
  75. log() {
  76. local msg="$1"
  77. # rebar3 prints ===>, so we print ===<
  78. echo "===< $msg"
  79. }
  80. make_docs() {
  81. local libs_dir1 libs_dir2 libs_dir3 docdir dashboard_www_static
  82. libs_dir1="$("$FIND" "_build/$PROFILE/lib/" -maxdepth 2 -name ebin -type d)"
  83. if [ -d "_build/default/lib/" ]; then
  84. libs_dir2="$("$FIND" "_build/default/lib/" -maxdepth 2 -name ebin -type d)"
  85. else
  86. libs_dir2=''
  87. fi
  88. if [ -d "_build/$PROFILE/checkouts" ]; then
  89. libs_dir3="$("$FIND" "_build/$PROFILE/checkouts/" -maxdepth 2 -name ebin -type d 2>/dev/null || true)"
  90. else
  91. libs_dir3=''
  92. fi
  93. case "$(is_enterprise "$PROFILE")" in
  94. 'yes')
  95. SCHEMA_MODULE='emqx_ee_conf_schema'
  96. ;;
  97. 'no')
  98. SCHEMA_MODULE='emqx_conf_schema'
  99. ;;
  100. esac
  101. docdir="_build/docgen/$PROFILE"
  102. dashboard_www_static='apps/emqx_dashboard/priv/www/static/'
  103. mkdir -p "$docdir" "$dashboard_www_static"
  104. # shellcheck disable=SC2086
  105. erl -noshell -pa $libs_dir1 $libs_dir2 $libs_dir3 -eval \
  106. "ok = emqx_conf:dump_schema('$docdir', $SCHEMA_MODULE), \
  107. halt(0)."
  108. cp "$docdir"/bridge-api-*.json "$dashboard_www_static"
  109. cp "$docdir"/hot-config-schema-*.json "$dashboard_www_static"
  110. }
  111. assert_no_compile_time_only_deps() {
  112. :
  113. }
  114. make_rel() {
  115. ./scripts/pre-compile.sh "$PROFILE"
  116. # make_elixir_rel always create rebar.lock
  117. # delete it to make git clone + checkout work because we use shallow close for rebar deps
  118. rm -f rebar.lock
  119. # compile all beams
  120. ./rebar3 as "$PROFILE" compile
  121. # generate docs (require beam compiled), generated to etc and priv dirs
  122. make_docs
  123. # now assemble the release tar
  124. ./rebar3 as "$PROFILE" tar
  125. assert_no_compile_time_only_deps
  126. }
  127. make_elixir_rel() {
  128. ./scripts/pre-compile.sh "$PROFILE"
  129. export_elixir_release_vars "$PROFILE"
  130. # for some reason, this has to be run outside "do"...
  131. mix local.rebar --if-missing --force
  132. # shellcheck disable=SC1010
  133. mix do local.hex --if-missing --force, \
  134. local.rebar rebar3 "${PWD}/rebar3" --if-missing --force, \
  135. deps.get
  136. mix release --overwrite
  137. assert_no_compile_time_only_deps
  138. }
  139. ## extract previous version .tar.gz files to _build/$PROFILE/rel/emqx before making relup
  140. make_relup() {
  141. local rel_dir="_build/$PROFILE/rel/emqx"
  142. local name_pattern
  143. name_pattern="${PROFILE}-$(./pkg-vsn.sh "$PROFILE" --vsn_matcher --long)"
  144. local releases=()
  145. mkdir -p _upgrade_base
  146. while read -r tgzfile ; do
  147. local base_vsn
  148. base_vsn="$(echo "$tgzfile" | grep -oE "[0-9]+\.[0-9]+\.[0-9]+(-(alpha|beta|rc)\.[0-9])?(-[0-9a-f]{8})?" | head -1)"
  149. ## we have to create tmp dir to untar old tgz, as `tar --skip-old-files` is not supported on all plantforms
  150. local tmp_dir
  151. tmp_dir="$(mktemp -d -t emqx.XXXXXXX)"
  152. $TAR -C "$tmp_dir" -zxf "$tgzfile"
  153. mkdir -p "${rel_dir}/releases/"
  154. cp -npr "$tmp_dir/releases"/* "${rel_dir}/releases/"
  155. ## There is for some reason a copy of the '$PROFILE.rel' file to releases dir,
  156. ## the content is duplicated to releases/5.0.0/$PROFILE.rel.
  157. ## This file seems to be useless, but yet confusing as it does not change after upgrade/downgrade
  158. ## Hence we force delete this file.
  159. rm -f "${rel_dir}/releases/${PROFILE}.rel"
  160. mkdir -p "${rel_dir}/lib/"
  161. cp -npr "$tmp_dir/lib"/* "${rel_dir}/lib/"
  162. rm -rf "$tmp_dir"
  163. releases+=( "$base_vsn" )
  164. done < <("$FIND" _upgrade_base -maxdepth 1 -name "${name_pattern}.tar.gz" -type f)
  165. if [ ${#releases[@]} -eq 0 ]; then
  166. log "No upgrade base found, relup ignored"
  167. return 0
  168. fi
  169. RELX_BASE_VERSIONS="$(IFS=, ; echo "${releases[*]}")"
  170. export RELX_BASE_VERSIONS
  171. ./rebar3 as "$PROFILE" relup --relname emqx --relvsn "${PKG_VSN}"
  172. }
  173. cp_dyn_libs() {
  174. local rel_dir="$1"
  175. local target_dir="${rel_dir}/dynlibs"
  176. if ! [ "$(uname -s)" = 'Linux' ]; then
  177. return 0;
  178. fi
  179. mkdir -p "$target_dir"
  180. while read -r so_file; do
  181. cp -L "$so_file" "$target_dir/"
  182. done < <("$FIND" "$rel_dir" -type f \( -name "*.so*" -o -name "beam.smp" \) -print0 \
  183. | xargs -0 ldd \
  184. | grep -E '(libcrypto)|(libtinfo)|(libatomic)' \
  185. | awk '{print $3}' \
  186. | sort -u)
  187. }
  188. ## Re-pack the relx assembled .tar.gz to EMQX's package naming scheme
  189. ## It assumes the .tar.gz has been built -- relies on Makefile dependency
  190. make_tgz() {
  191. local pkgpath="_packages/${PROFILE}"
  192. local src_tarball
  193. local target_name
  194. local target
  195. if [ "${IS_ELIXIR:-no}" = "yes" ]
  196. then
  197. # ensure src_tarball exists
  198. ELIXIR_MAKE_TAR=yes make_elixir_rel
  199. local relpath="_build/${PROFILE}"
  200. full_vsn="$(./pkg-vsn.sh "$PROFILE" --long --elixir)"
  201. else
  202. # build the src_tarball again to ensure relup is included
  203. # elixir does not have relup yet.
  204. make_rel
  205. local relpath="_build/${PROFILE}/rel/emqx"
  206. full_vsn="$(./pkg-vsn.sh "$PROFILE" --long)"
  207. fi
  208. case "$SYSTEM" in
  209. macos*)
  210. target_name="${PROFILE}-${full_vsn}.zip"
  211. ;;
  212. windows*)
  213. target_name="${PROFILE}-${full_vsn}.zip"
  214. ;;
  215. *)
  216. target_name="${PROFILE}-${full_vsn}.tar.gz"
  217. ;;
  218. esac
  219. target="${pkgpath}/${target_name}"
  220. src_tarball="${relpath}/emqx-${PKG_VSN}.tar.gz"
  221. tard="$(mktemp -d -t emqx.XXXXXXX)"
  222. mkdir -p "${tard}/emqx"
  223. mkdir -p "${pkgpath}"
  224. if [ ! -f "$src_tarball" ]; then
  225. log "ERROR: $src_tarball is not found"
  226. fi
  227. $TAR zxf "${src_tarball}" -C "${tard}/emqx"
  228. if [ -f "${tard}/emqx/releases/${PKG_VSN}/relup" ]; then
  229. ./scripts/relup-build/inject-relup.escript "${tard}/emqx/releases/${PKG_VSN}/relup"
  230. fi
  231. ## try to be portable for tar.gz packages.
  232. ## for DEB and RPM packages the dependencies are resoved by yum and apt
  233. cp_dyn_libs "${tard}/emqx"
  234. case "$SYSTEM" in
  235. macos*)
  236. # if the flag to sign macos binaries is set, but developer certificate
  237. # or certificate password is not configured, reset the flag
  238. # could happen, for example, when people submit PR from a fork, in this
  239. # case they cannot access secrets
  240. if [[ "${APPLE_SIGN_BINARIES:-0}" == 1 && \
  241. ( "${APPLE_DEVELOPER_ID_BUNDLE:-0}" == 0 || \
  242. "${APPLE_DEVELOPER_ID_BUNDLE_PASSWORD:-0}" == 0 ) ]]; then
  243. echo "Apple developer certificate is not configured, skip signing"
  244. APPLE_SIGN_BINARIES=0
  245. fi
  246. if [ "${APPLE_SIGN_BINARIES:-0}" = 1 ]; then
  247. ./scripts/macos-sign-binaries.sh "${tard}/emqx"
  248. fi
  249. ## create zip after change dir
  250. ## to avoid creating an extra level of 'emqx' dir in the .zip file
  251. pushd "${tard}/emqx" >/dev/null
  252. zip -r "../${target_name}" -- * >/dev/null
  253. popd >/dev/null
  254. mv "${tard}/${target_name}" "${target}"
  255. if [ "${APPLE_SIGN_BINARIES:-0}" = 1 ]; then
  256. # notarize the package
  257. # if fails, check what went wrong with this command:
  258. # xcrun notarytool log --apple-id <apple id> \
  259. # --apple-id <apple id> \
  260. # --password <apple id password>
  261. # --team-id <apple team id> <submission-id>
  262. echo 'Submitting the package for notarization to Apple (normally takes about a minute)'
  263. notarytool_output="$(xcrun notarytool submit \
  264. --apple-id "${APPLE_ID}" \
  265. --password "${APPLE_ID_PASSWORD}" \
  266. --team-id "${APPLE_TEAM_ID}" "${target}" \
  267. --no-progress \
  268. --wait)"
  269. echo "$notarytool_output"
  270. echo "$notarytool_output" | grep -q 'status: Accepted' || {
  271. echo 'Notarization failed';
  272. exit 1;
  273. }
  274. fi
  275. # sha256sum may not be available on macos
  276. openssl dgst -sha256 "${target}" | cut -d ' ' -f 2 > "${target}.sha256"
  277. ;;
  278. windows*)
  279. pushd "${tard}" >/dev/null
  280. 7z a "${target_name}" ./emqx/* >/dev/null
  281. popd >/dev/null
  282. mv "${tard}/${target_name}" "${target}"
  283. sha256sum "${target}" | head -c 64 > "${target}.sha256"
  284. ;;
  285. *)
  286. ## create tar after change dir
  287. ## to avoid creating an extra level of 'emqx' dir in the .tar.gz file
  288. pushd "${tard}/emqx" >/dev/null
  289. $TAR -zcf "../${target_name}" -- *
  290. popd >/dev/null
  291. mv "${tard}/${target_name}" "${target}"
  292. sha256sum "${target}" | head -c 64 > "${target}.sha256"
  293. ;;
  294. esac
  295. log "Archive successfully repacked: ${target}"
  296. log "Archive sha256sum: $(cat "${target}.sha256")"
  297. }
  298. trap docker_cleanup EXIT
  299. docker_cleanup() {
  300. rm -f ./.dockerignore >/dev/null
  301. }
  302. ## This function builds the default docker image based on debian 11
  303. make_docker() {
  304. EMQX_BUILDER="${EMQX_BUILDER:-${EMQX_DEFAULT_BUILDER}}"
  305. EMQX_RUNNER="${EMQX_RUNNER:-${EMQX_DEFAULT_RUNNER}}"
  306. EMQX_DOCKERFILE="${EMQX_DOCKERFILE:-deploy/docker/Dockerfile}"
  307. if [[ "$PROFILE" = *-elixir ]]; then
  308. PKG_VSN="$PKG_VSN-elixir"
  309. fi
  310. local default_tag="emqx/${PROFILE%%-elixir}:${PKG_VSN}"
  311. EMQX_IMAGE_TAG="${EMQX_IMAGE_TAG:-$default_tag}"
  312. echo '_build' >> ./.dockerignore
  313. set -x
  314. docker build --no-cache --pull \
  315. --build-arg BUILD_FROM="${EMQX_BUILDER}" \
  316. --build-arg RUN_FROM="${EMQX_RUNNER}" \
  317. --build-arg EMQX_NAME="$PROFILE" \
  318. --tag "${EMQX_IMAGE_TAG}" \
  319. -f "${EMQX_DOCKERFILE}" .
  320. [[ "${DEBUG:-}" -eq 1 ]] || set +x
  321. }
  322. function join {
  323. local IFS="$1"
  324. shift
  325. echo "$*"
  326. }
  327. # used to control the Elixir Mix Release output
  328. # see docstring in `mix.exs`
  329. export_elixir_release_vars() {
  330. local profile="$1"
  331. case "$profile" in
  332. emqx|emqx-enterprise)
  333. export ELIXIR_MAKE_TAR=${ELIXIR_MAKE_TAR:-no}
  334. ;;
  335. emqx-pkg|emqx-enterprise-pkg)
  336. export ELIXIR_MAKE_TAR=${ELIXIR_MAKE_TAR:-yes}
  337. ;;
  338. *)
  339. echo Invalid profile "$profile"
  340. exit 1
  341. esac
  342. export MIX_ENV="$profile"
  343. }
  344. log "building artifact=$ARTIFACT for profile=$PROFILE"
  345. case "$ARTIFACT" in
  346. doc|docs)
  347. make_docs
  348. ;;
  349. rel)
  350. make_rel
  351. ;;
  352. relup)
  353. make_relup
  354. ;;
  355. tgz)
  356. make_tgz
  357. ;;
  358. pkg)
  359. # this only affect build artifacts, such as schema doc
  360. export EMQX_ETC_DIR='/etc/emqx/'
  361. if [ -z "${PKGERDIR:-}" ]; then
  362. log "Skipped making deb/rpm package for $SYSTEM"
  363. exit 0
  364. fi
  365. export EMQX_REL_FORM="$PKGERDIR"
  366. if [ "${IS_ELIXIR:-}" = 'yes' ]; then
  367. make_elixir_rel
  368. else
  369. make_rel
  370. fi
  371. env EMQX_REL="$(pwd)" \
  372. EMQX_BUILD="${PROFILE}" \
  373. make -C "deploy/packages/${PKGERDIR}" clean
  374. env EMQX_REL="$(pwd)" \
  375. EMQX_BUILD="${PROFILE}" \
  376. make -C "deploy/packages/${PKGERDIR}"
  377. ;;
  378. docker)
  379. make_docker
  380. ;;
  381. elixir)
  382. make_elixir_rel
  383. ;;
  384. *)
  385. log "Unknown artifact $ARTIFACT"
  386. exit 1
  387. ;;
  388. esac