社区

发布指南

qianmoQqianmoQ· 更新于 2026-10-05· 阅读 31 分钟· 0 次阅读

登录后可跨设备保存划线和私人笔记登录

发布指南

如何发布 bRPC 版本

brpc Apache 发布指南(分步说明)

概述:分为以下步骤

  1. 准备工作:包括生成签名所需的密钥、创建 GitHub 发布分支和标签、修改版本文件等
  2. 发布软件包:包括制作源码压缩包、签名、上传到指定位置并验证
  3. 投票:包括在邮件组 dev@brpc.apache.org 和 general@incubator.apache.org 中发起投票
  4. 发布公告:包括更新 brpc 网站、发送公告邮件、发布微信公众号公告、将发布分支合并到 master 分支

准备密钥

1. 安装 GPG

从 GnuPG 官方网站 下载安装包。GnuPG 1.x 版本和 2.x 版本的命令略有不同。以下说明以 GnuPG-2.3.1 版本(OSX)为例。

安装完成后,执行以下命令查看版本号。

gpg --version

2. 创建密钥

安装完成后,执行以下命令来创建密钥。

gpg --full-gen-key

按照提示完成密钥创建。注意,邮箱应使用 Apache 邮箱地址,而 Real Name 可使用 Apache ID 或 GitHub ID:

gpg (GnuPG) 2.3.1; Copyright (C) 2021 Free Software Foundation, Inc.
This is free software: you are free to change and redistribute it.
There is NO WARRANTY, to the extent permitted by law.

Please select what kind of key you want:
   (1) RSA and RSA
   (2) DSA and Elgamal
   (3) DSA (sign only)
   (4) RSA (sign only)
   (9) ECC (sign and encrypt) *default*
  (10) ECC (sign only)
  (14) Existing key from card
Your selection? 1
RSA keys may be between 1024 and 4096 bits long.
What keysize do you want? (3072) 4096
Requested keysize is 4096 bits
Please specify how long the key should be valid.
         0 = key does not expire
      <n>  = key expires in n days
      <n>w = key expires in n weeks
      <n>m = key expires in n months
      <n>y = key expires in n years
Key is valid for? (0) 0
Key does not expire at all
Is this correct? (y/N) y

GnuPG needs to construct a user ID to identify your key.

Real name: LorinLee
Email address: lorinlee@apache.org
Comment: lorinlee's key
You selected this USER-ID:
    "LorinLee (lorinlee's key) <lorinlee@apache.org>"

Change (N)ame, (C)omment, (E)mail or (O)kay/(Q)uit? O
You need a Passphrase to protect your secret key. # Input password

We need to generate a lot of random bytes. It is a good idea to perform
some other action (type on the keyboard, move the mouse, utilize the
disks) during the prime generation; this gives the random number
generator a better chance to gain enough entropy.
gpg: key 92E18A11B6585834 marked as ultimately trusted
gpg: revocation certificate stored as '/Users/lilei/.gnupg/openpgp-revocs.d/C30F211F071894258497F46392E18A11B6585834.rev'
public and secret key created and signed.

pub   rsa4096 2021-10-17 [SC]
      C30F211F071894258497F46392E18A11B6585834
uid                      LorinLee (lorinlee's key) <lorinlee@apache.org>
sub   rsa4096 2021-10-17 [E]

3. 检查生成的密钥

gpg --list-keys

请提供需要翻译的 Markdown 原文(当前「Release Guide」章节内容为空),我会按要求仅输出简体中文译文。

gpg: checking the trustdb
gpg: marginals needed: 3  completes needed: 1  trust model: pgp
gpg: depth: 0  valid:   2  signed:   0  trust: 0-, 0q, 0n, 0m, 0f, 2u
/Users/lilei/.gnupg/pubring.kbx
----------------------------------
pub   rsa4096 2021-10-17 [SC]
      C30F211F071894258497F46392E18A11B6585834
uid           [ultimate] LorinLee (lorinlee's key) <lorinlee@apache.org>
sub   rsa4096 2021-10-17 [E]

注意 C30F211F071894258497F46392E18A11B6585834 是公钥。

4. 将公钥发布到服务器

执行以下命令:

gpg --keyserver hkp://pgp.mit.edu --send-key C30F211F071894258497F46392E18A11B6585834

5. 生成指纹并上传至 Apache 用户资料

由于公钥服务器没有验证机制,任何人都可以冒用你的名义上传公钥,因此无法保证服务器上公钥的可靠性。通常,你可以在自己的网站上发布公钥指纹,以便他人核对所下载的公钥。

执行以下命令查看指纹。

gpg --fingerprint lorinlee # user id

发布指南

/Users/lilei/.gnupg/pubring.kbx
----------------------------------
pub   rsa4096 2021-10-17 [SC]
      C30F 211F 0718 9425 8497  F463 92E1 8A11 B658 5834
uid           [ultimate] LorinLee (lorinlee's key) <lorinlee@apache.org>
sub   rsa4096 2021-10-17 [E]

将上述指纹 C30F 211F 0718 9425 8497 F463 92E1 8A11 B658 5834 粘贴到你在 https://id.apache.org] 上的 Apache 用户信息的 OpenPGP Public Key Primary Fingerprint: 字段中。

准备发布包

1. 创建发布分支

如果你要发布一个新的 MINOR 版本,例如 1.0.0,你需要从 master 创建一个新分支 release-1.0。

如果你要在现有 MINOR 版本基础上发布一个新的 PATCH 版本,例如 1.0.1,你只需要修改现有的 release-1.0 分支,并添加需要发布的内容。

发布过程中的代码修改都在发布分支(例如 release-1.0)上进行。发布完成后,请将发布分支合并回 master 分支。

2. 更新源代码中的版本

更新 RELEASE_VERSION 文件

编辑项目根目录下的 RELEASE_VERSION 文件,更新版本号,并提交到代码仓库。例如,该文件的 1.0.0 版本内容为:

1.0.0

更新 CMakeLists.txt 文件

编辑项目根目录下的 CMakeLists.txt 文件,更新版本号并提交到代码仓库。例如:

set(BRPC_VERSION 1.0.0)

更新 /package/rpm/brpc.spec 文件

编辑项目根目录下的 /package/rpm/brpc.spec 文件,更新版本号,并将其提交到代码仓库。例如:

Version:	1.0.0

3. 创建发布标签

将发布分支推送并打上标签,例如:

git clone -b release-1.0 git@github.com:apache/brpc.git ~/brpc

cd ~/brpc

git tag -a 1.0.0 -m "release 1.0.0"

git push origin --tags

4. 创建发布包

git archive --format=tar 1.0.0 --prefix=apache-brpc-1.0.0-incubating-src/ | gzip > apache-brpc-1.0.0-incubating-src.tar.gz

5. 生成 GPG 签名

gpg -u lorinlee@apache.org --armor --output apache-brpc-1.0.0-incubating-src.tar.gz.asc --detach-sign apache-brpc-1.0.0-incubating-src.tar.gz

gpg --verify apache-brpc-1.0.0-incubating-src.tar.gz.asc apache-brpc-1.0.0-incubating-src.tar.gz

6. 生成 SHA512 校验和

sha512sum apache-brpc-1.0.0-incubating-src.tar.gz > apache-brpc-1.0.0-incubating-src.tar.gz.sha512

sha512sum --check apache-brpc-1.0.0-incubating-src.tar.gz.sha512

发布到 Apache SVN 仓库

1. checkout dist/dev/brpc 目录

如果本地没有工作目录,先创建一个本地工作目录。克隆 Apache SVN 仓库,用户名需使用你自己的 Apache LDAP 用户名:

mkdir -p ~/brpc_svn/dev/

cd ~/brpc_svn/dev/

svn --username=lorinlee co https://dist.apache.org/repos/dist/dev/brpc/

cd ~/brpc_svn/dev/brpc

2. 添加 GPG 公钥

新任发布经理首次发布时,必须将密钥添加到 KEYS 文件中。

(gpg --list-sigs lorinlee && gpg -a --export lorinlee) >> KEYS

3. 将待发布的包添加到 SVN 目录

mkdir -p ~/brpc_svn/dev/brpc/1.0.0

cd ~/brpc_svn/dev/brpc/1.0.0

cp ~/brpc/apache-brpc-1.0.0-incubating-src.tar.gz ~/brpc_svn/dev/brpc/1.0.0

cp ~/brpc/apache-brpc-1.0.0-incubating-src.tar.gz.asc ~/brpc_svn/dev/brpc/1.0.0

cp ~/brpc/apache-brpc-1.0.0-incubating-src.tar.gz.sha512 ~/brpc_svn/dev/brpc/1.0.0

4. 提交 SVN

返回父目录,使用 Apache LDAP 账号提交 SVN

cd ~/brpc_svn/dev/brpc

svn add *

svn --username=lorinlee commit -m "release 1.0.0"

验证发行版本

1. 校验 SHA512 校验和

sha512sum --check apache-brpc-1.0.0-incubating-src.tar.gz.sha512

2. 验证 GPG 签名

首先导入发布者的公钥。将 svn 仓库中的 KEYS 文件导入本地。(发布版本的人员无需重复导入,负责验证的人员才需要导入。)

curl https://dist.apache.org/repos/dist/dev/brpc/KEYS >> KEYS

gpg --import KEYS

信任发布者的签名,使用发布者的用户名执行以下命令

gpg --edit-key lorinlee

请提供需要翻译的 Markdown 原文,当前输入中没有包含待翻译的文本。

gpg (GnuPG) 2.3.1; Copyright (C) 2021 Free Software Foundation, Inc.
This is free software: you are free to change and redistribute it.
There is NO WARRANTY, to the extent permitted by law.

Secret key is available.

gpg> trust

Please decide how far you trust this user to correctly verify other users' keys
(by looking at passports, checking fingerprints from different sources, etc.)

  1 = I don't know or won't say
  2 = I do NOT trust
  3 = I trust marginally
  4 = I trust fully
  5 = I trust ultimately
  m = back to the main menu

Your decision? 5
Do you really want to set this key to ultimate trust? (y/N) y

gpg> save

然后验证 GPG 签名:

gpg --verify apache-brpc-1.0.0-incubating-src.tar.gz.asc apache-brpc-1.0.0-incubating-src.tar.gz

3. 检查发布内容

1. 比较源码包与 GitHub 标签之间的差异

curl -Lo tag-1.0.0.tar.gz https://github.com/apache/brpc/archive/refs/tags/1.0.0.tar.gz

tar xvzf tag-1.0.0.tar.gz

tar xvzf apache-brpc-1.0.0-incubating-src.tar.gz

diff -r brpc-1.0.0 apache-brpc-1.0.0-incubating-src

2. 检查文件内容

  • 检查源码包中是否包含不必要的文件,导致 tar 包过大

  • LICENSE 和 NOTICE 文件是否存在

  • NOTICE 文件中的年份是否正确

  • 是否只包含文本文件,没有二进制文件

  • 所有文件开头是否带有 ASF 许可证声明

  • 源代码能否正确编译,单元测试能否通过

  • 检查是否存在冗余的文件或目录,例如空目录

  • 检查第三方依赖的许可证:

    • 第三方依赖许可证的兼容性
    • 所有第三方依赖的许可证是否已在 LICENSE 文件中声明
    • 依赖许可证的完整版本是否位于 license 目录中
    • 如果第三方依赖使用 Apache 许可证并带有 NOTICE 文件,则需要将这些 NOTICE 文件也添加到发布的 NOTICE 文件中

在 Apache brpc 社区进行投票

1. 投票阶段

  1. 向 dev@brpc.apache.org 发送投票邮件。PPMC 成员在投票前需要根据文档检查版本的正确性。在至少 72 小时内获得 3 位以上 PPMC 成员的 +1 投票后,即可进入下一阶段。
  2. 公布投票结果,并将投票结果发送至 dev@brpc.apache.org 。

2. 投票邮件模板

  1. Apache brpc 社区投票邮件模板

标题:

[VOTE] Release Apache brpc 1.0.0

注意:Release Commit ID 填入当前发布分支最后一次提交的 commit ID。

Hi Apache brpc Community,

This is a call for vote to release Apache brpc version
1.0.0

[Release Note]
- xxx

The release candidates:
https://dist.apache.org/repos/dist/dev/incubator/brpc/1.0.0/

Git tag for the release:
https://github.com/apache/brpc/releases/tag/1.0.0

Release Commit ID:
https://github.com/apache/brpc/commit/xxx

Keys to verify the Release Candidate:
https://dist.apache.org/repos/dist/dev/incubator/brpc/KEYS

The vote will be open for at least 72 hours or until the necessary number of
votes are reached.

Please vote accordingly:
[ ] +1 approve
[ ] +0 no opinion
[ ] -1 disapprove with the reason

PMC vote is +1 binding, all others are +1 non-binding.

Checklist for reference:
[ ] Download links are valid.
[ ] Checksums and PGP signatures are valid.
[ ] Source code distributions have correct names matching the current
release.
[ ] LICENSE and NOTICE files are correct for each brpc repo.
[ ] All files have license headers if necessary.
[ ] No compiled archives bundled in source archive.

Regards,
LorinLee

2. Apache brpc 社区公布投票结果模板

标题:

[Result] [VOTE] Release Apache brpc 1.0.0

目录:

Hi all,

The vote to release Apache brpc 1.0.0 has passed.

The vote PASSED with 3 binding +1, 3 non binding +1 and no -1 votes:

Binding votes:
- xxx
- yyy
- zzz

Non-binding votes:
- aaa
- bbb
- ccc

Vote thread: xxx (vote email link in https://lists.apache.org/)

Thank you to all the above members to help us to verify and vote for the 1.0.0 release. We will move to IPMC voting shortly.

Regards,
LorinLee

3. 投票未通过

如果社区投票未通过,请修改发布分支的代码,重新打包并再次发起投票。

在 Apache 孵化器社区进行投票

1. 更新 GPG 签名

svn delete https://dist.apache.org/repos/dist/release/brpc/KEYS -m "delete KEYS"

svn cp https://dist.apache.org/repos/dist/dev/brpc/KEYS https://dist.apache.org/repos/dist/release/brpc/KEYS -m "update brpc KEYS"

提交 SVN 后,访问 https://downloads.apache.org/brpc/KEYS,检查内容是否已更新。可能需要等待几分钟,待内容更新后再继续。

2. 投票阶段

  1. 向 general@incubator.apache.org 发送投票邮件,由 IPMC 进行投票。在至少 72 小时后、并收集到 3 张 IPMC 成员的 +1 票,即可进入下一阶段。
  2. 将投票结果发送到 general@incubator.apache.org,以公告投票结果。

3. 投票邮件模板

  1. Apache Incubator 社区投票邮件模板

标题:

[VOTE] Release Apache brpc 1.0.0

发布指南

Hi Incubator Community,

This is a call for a vote to release Apache brpcversion
1.0.0.

The Apache brpc community has voted and approved the release of Apache
brpc 1.0.0.

We now kindly request the Incubator PMC members review and vote on this
incubator release.

brpc is an industrial-grade RPC framework with extremely high performance,
and it supports multiple protocols, full rpc features, and has many
convenient tools.

brpc community vote thread: xxx

Vote result thread: xxx

The release candidate:
https://dist.apache.org/repos/dist/dev/incubator/brpc/1.0.0/

This release has been signed with a PGP available here:
https://downloads.apache.org/incubator/brpc/KEYS

Git tag for the release:
https://github.com/apache/brpc/releases/tag/1.0.0

Build guide and get started instructions can be found at:
https://brpc.apache.org/docs/getting_started

The vote will be open for at least 72 hours or until the necessary number
of votes is reached.

Please vote accordingly:
[ ] +1 approve
[ ] +0 no opinion
[ ] -1 disapprove with the reason

Regards,
Lorin Lee
Apache brpc community

2. Apache Incubator 社区投票结果公告模板

标题:

[投票已通过] [项目名称] 已毕业(或发布版本号)

[Result] [VOTE] Release Apache brpc 1.0.0

目录:

Hi Incubator Community,

Thanks to everyone that participated. The vote to release Apache
brpc version 1.0.0 in general@incubator.apache.org
is now closed.

Vote thread: xxx

The vote PASSED with 3 binding +1, 3 non binding +1 and no -1 votes:

Binding votes:
- xxx
- yyy
- zzz

Non-binding votes:
- aaa
- bbb
- ccc

Many thanks for all our mentors helping us with the release procedure,
and all IPMC helped us to review and vote for Apache brpc release.
We will proceed with publishing the approved artifacts and
sending out the announcement soon.

Regards,
Lorin Lee
Apache brpc community

完成发布

1. 将发布包从 Apache SVN 目录 dist/dev 移动到 dist/release

svn mv https://dist.apache.org/repos/dist/dev/brpc/1.0.0 https://dist.apache.org/repos/dist/release/brpc/1.0.0 -m "release brpc 1.0.0"

2. 创建 GitHub Release

  1. 在 GitHub Releases 页面] 点击对应版本以创建新的 Release
  2. 编辑版本号与版本说明,然后点击 Publish release

3. 更新下载页面

等待并确认新版本已同步到 Apache 镜像后,更新以下页面:https://brpc.apache.org/docs/downloadbrpc/](/book/reader/apache-brpc/downloadbrpc),方法是修改 https://github.com/apache/brpc-website/](https://github.com/apache/brpc-website/) 中的代码。中英文版本都需要更新。

GPG 签名文件和哈希校验文件的下载链接应使用以下前缀:https://downloads.apache.org/brpc/

代码包的下载链接应使用以下前缀:https://dlcdn.apache.org/brpc/

4. 发送邮件宣布发布完成

向 dev@brpc.apache.org、general@incubator.apache.org 和 announce@apache.org 发送邮件,宣布发布完成。

注意:邮件账号必须使用个人 Apache 邮箱,邮件内容必须为纯文本格式(在 gmail 中可选择“纯文本模式”)。向 announce@apache.org 邮件组发送的邮件需经过人工审核后才会投递。发送邮件后请耐心等待,通常一天内会通过审核。

公告邮件模板:

标题:

[ANNOUNCE] Apache brpc 1.0.0 released

注意:Brief notes of this release 只需列出本次发布的主要变更,无需列出对应的贡献者和 PR 编号。建议参考之前的公告邮件。

Hi all,

The Apache brpc community is glad to announce the new release
of Apache brpc 1.0.0.

brpc is an Industrial-grade RPC framework using C++ Language, which is
often used in high performance systems such as Search, Storage,
Machine learning, Advertisement, Recommendation etc.

Brief notes of this release:
- xxx
- yyy
- zzz

More details regarding Apache brpc can be found at:
http://brpc.apache.org/

The release is available for download at:
https://brpc.apache.org/docs/downloadbrpc/

The release notes can be found here:
https://github.com/apache/brpc/releases/tag/1.0.0

Website: http://brpc.apache.org/

brpcResources:
- Issue: https://github.com/apache/brpc/issues/
- Mailing list: dev@brpc.apache.org
- Documents: https://brpc.apache.org/docs/

We would like to thank all contributors of the Apache brpc community and
Incubating community who made this release possible!

Best Regards,
Apache brpc community

5. 发布微信公众号公告

参考 https://mp.weixin.qq.com/s/DeFhpAV_AYsn_Xd1ylPTSg。

6. 更新 master 分支

发布完成后,将 release 分支合并到 master 分支。

最后修改于 2023 年 7 月 24 日:Update index.md (5980c83bf)

评论

登录后参与评论

正在加载评论…