diff --git a/.gitea/workflows/bump.yaml b/.gitea/workflows/bump.yaml
index 6288c08..89d8683 100644
--- a/.gitea/workflows/bump.yaml
+++ b/.gitea/workflows/bump.yaml
@@ -2,7 +2,14 @@ name: Bump
on:
schedule:
- cron: '0 5 * * *'
- workflow_dispatch: {}
+ workflow_dispatch:
+ inputs:
+ version:
+ description: >-
+ Upstream gitea/runner version to bump to (e.g. 3.4.0, no leading
+ "v"). Leave empty to use the latest upstream release.
+ required: false
+ type: string
jobs:
bump:
@@ -19,7 +26,14 @@ jobs:
id: check
env:
BUMP_TOKEN: ${{ secrets.BUMP_TOKEN }}
+ BUMP_VERSION: ${{ inputs.version }}
run: |
+ # An explicitly requested version always runs the full bump.
+ if [ -n "${BUMP_VERSION}" ]; then
+ echo "needed=true" >> "$GITHUB_OUTPUT"
+ echo "explicit version requested: ${BUMP_VERSION}"
+ exit 0
+ fi
latest=$(wget -qO- https://gitea.com/gitea/runner/releases.rss \
| grep -oE '
v[0-9]+\.[0-9]+\.[0-9]+' \
| head -1 | sed -E 's#?title>##g; s/^v//')
@@ -51,6 +65,12 @@ jobs:
> /etc/portage/repos.conf/gentoo.conf
sed -i '/^verify-signature/d' /etc/portage/binrepos.conf/gentoo.conf
printf '\nverify-signature = false\n' >> /etc/portage/binrepos.conf/gentoo.conf
+ # Upstream's go.mod can require a Go that Gentoo only has under
+ # ~amd64 (GOTOOLCHAIN=local forbids auto-download), so accept the
+ # testing-keyworded dev-lang/go. It is built from source when no
+ # stable binpkg satisfies the requirement.
+ mkdir -p /etc/portage/package.accept_keywords
+ echo 'dev-lang/go ~amd64' > /etc/portage/package.accept_keywords/go
emerge -q --getbinpkg \
dev-vcs/git net-misc/curl app-arch/xz-utils app-misc/jq \
dev-lang/go dev-util/pkgdev
@@ -59,6 +79,7 @@ jobs:
if: steps.check.outputs.needed == 'true'
env:
BUMP_TOKEN: ${{ secrets.BUMP_TOKEN }}
+ BUMP_VERSION: ${{ inputs.version }}
run: |
host=${GITHUB_SERVER_URL#http://}; host=${host#https://}
curl -fsSL "http://x-access-token:${BUMP_TOKEN}@${host}/${GITHUB_REPOSITORY}/raw/branch/master/scripts/bump-version.sh" \
diff --git a/.gitea/workflows/ci.yaml b/.gitea/workflows/ci.yaml
index a8f7d8b..c2c3f19 100644
--- a/.gitea/workflows/ci.yaml
+++ b/.gitea/workflows/ci.yaml
@@ -81,6 +81,11 @@ jobs:
> /etc/portage/repos.conf/azy5030.conf
mkdir -p /etc/portage/package.accept_keywords
echo 'dev-util/gitea-runner ~amd64' > /etc/portage/package.accept_keywords/gitea-runner
+ # Upstream tracks new Go releases faster than Gentoo stabilises them
+ # (the ebuild's BDEPEND follows upstream go.mod), so accept the
+ # testing-keyworded dev-lang/go. No stable binpkg exists for it, so
+ # this compiles Go from source when a newer one is required.
+ echo 'dev-lang/go ~amd64' > /etc/portage/package.accept_keywords/go
- name: QA scan
run: pkgcheck scan --repo /var/db/repos/azy5030 dev-util/gitea-runner
diff --git a/scripts/bump-version.sh b/scripts/bump-version.sh
index b794975..5f9ace6 100755
--- a/scripts/bump-version.sh
+++ b/scripts/bump-version.sh
@@ -6,12 +6,17 @@
# Expects a Gentoo environment with: go, pkgdev, git, curl, xz, jq.
# Required env: BUMP_TOKEN, GITHUB_SERVER_URL, GITHUB_REPOSITORY.
# Optional env: GITHUB_API_URL (defaults to ${GITHUB_SERVER_URL}/api/v1).
+# BUMP_VERSION target a specific upstream version (X.Y.Z, no
+# leading "v") instead of the latest release. An
+# explicit target may be older than the current
+# ebuild (useful to back out of a broken release).
set -euo pipefail
PN="gitea-runner"
UPSTREAM_RSS="https://gitea.com/gitea/runner/releases.rss"
UPSTREAM_ARCHIVE="https://gitea.com/api/v1/repos/gitea/runner/archive"
UPSTREAM_GOMOD="https://gitea.com/api/v1/repos/gitea/runner/raw/go.mod"
+UPSTREAM_TAGS="https://gitea.com/api/v1/repos/gitea/runner/tags"
: "${BUMP_TOKEN:?BUMP_TOKEN is required}"
: "${GITHUB_SERVER_URL:?GITHUB_SERVER_URL is required}"
@@ -25,10 +30,22 @@ host="${GITHUB_SERVER_URL#*://}"
api() { curl -fsSL -H "Authorization: token ${BUMP_TOKEN}" "$@"; }
# --- determine versions ------------------------------------------------------
-latest=$(curl -fsSL "$UPSTREAM_RSS" \
- | grep -oE 'v[0-9]+\.[0-9]+\.[0-9]+' \
- | head -1 | sed -E 's#?title>##g; s/^v//')
-[ -n "$latest" ] || { echo "could not parse upstream version"; exit 1; }
+if [ -n "${BUMP_VERSION:-}" ]; then
+ latest="${BUMP_VERSION#v}"
+ echo "$latest" | grep -qE '^[0-9]+\.[0-9]+\.[0-9]+$' \
+ || { echo "BUMP_VERSION must look like X.Y.Z (got '${BUMP_VERSION}')"; exit 1; }
+ # Fail fast if the tag doesn't exist upstream, before cloning anything.
+ # (The raw endpoint silently falls back to the default branch for an
+ # unknown ref, so ask the tags API, which 404s.)
+ curl -fsSL "${UPSTREAM_TAGS}/v${latest}" -o /dev/null \
+ || { echo "upstream tag v${latest} not found"; exit 1; }
+ echo "targeting explicit version ${latest}"
+else
+ latest=$(curl -fsSL "$UPSTREAM_RSS" \
+ | grep -oE 'v[0-9]+\.[0-9]+\.[0-9]+' \
+ | head -1 | sed -E 's#?title>##g; s/^v//')
+ [ -n "$latest" ] || { echo "could not parse upstream version"; exit 1; }
+fi
WORK=$(mktemp -d)
git clone "${scheme}://x-access-token:${BUMP_TOKEN}@${host}/${GITHUB_REPOSITORY}.git" "$WORK"
@@ -39,11 +56,15 @@ current=$(find "$pkgdir" -name "${PN}-*.ebuild" \
| sed -E "s#.*/${PN}-(.*)\.ebuild#\1#" | sort -V | tail -1)
echo "upstream=${latest} current=${current}"
+[ "$latest" != "$current" ] || { echo "already at ${latest}"; exit 0; }
newest=$(printf '%s\n%s\n' "$current" "$latest" | sort -V | tail -1)
-if [ "$newest" = "$current" ] && [ "$latest" != "$current" ]; then
- echo "current ($current) is newer than upstream ($latest); nothing to do"; exit 0
+if [ "$newest" = "$current" ]; then
+ if [ -n "${BUMP_VERSION:-}" ]; then
+ echo "warning: explicit target ${latest} is older than current ${current}; downgrading"
+ else
+ echo "current ($current) is newer than upstream ($latest); nothing to do"; exit 0
+ fi
fi
-[ "$latest" != "$current" ] || { echo "already at latest ($current)"; exit 0; }
branch="bump/${PN}-${latest}"
if api "${API}/repos/${GITHUB_REPOSITORY}/branches/${branch}" >/dev/null 2>&1; then