ci: only run on branch pushes; drop bump-script emerge; repoint vendor tags
- ci.yaml: filter the push trigger to branches. An unfiltered `push` also fired for every tag ref, including the vendor-release tags the bump script creates via the API. - bump-version.sh: remove the pkgcheck/emerge/--version validation before push. The branch push triggers CI, which runs the same checks and, unlike the script's local copy, fetches the real release asset. The PR body now asks for green CI instead of claiming the build passed in the bump job. - vendor-tags.yaml: new workflow on pushes to master touching dev-util/**. The vendor release is created before the bump commit exists (and PRs are squash-merged), so its tag pointed at an arbitrary master commit. This force-updates each vendor tag whose ebuild is in the tree to the master commit that added that ebuild. Tags are only ever updated, never deleted, since deleting a release's tag deletes the release and its assets. - CLAUDE.md: document both changes. Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
This commit was merged in pull request #20.
This commit is contained in:
@@ -1,5 +1,10 @@
|
||||
name: CI
|
||||
on: [push]
|
||||
# Restrict to branch pushes: an unfiltered `push` also fires for tag refs,
|
||||
# including the vendor-release tags the bump script creates via the API.
|
||||
on:
|
||||
push:
|
||||
branches:
|
||||
- '**'
|
||||
|
||||
jobs:
|
||||
# Lint gate: runs on the plain Docker-backend runner (not the Gentoo
|
||||
|
||||
@@ -0,0 +1,43 @@
|
||||
name: Vendor tags
|
||||
# The bump script creates the `${PN}-${ver}-vendor` release (which hosts the
|
||||
# vendor tarball) *before* the bump commit exists, so its tag can only point at
|
||||
# whatever master was at the time. The PR is then squash/rebase-merged, so the
|
||||
# branch commit never lands on master either. This job re-points each vendor
|
||||
# tag at the master commit that introduced that version's ebuild. It is
|
||||
# idempotent: a tag already on the right commit is left alone.
|
||||
#
|
||||
# Only ever force-*update* a tag here. Deleting a release's tag makes Gitea
|
||||
# delete the release and its assets, which would break the ebuild's SRC_URI.
|
||||
on:
|
||||
push:
|
||||
branches:
|
||||
- master
|
||||
paths:
|
||||
- 'dev-util/**'
|
||||
|
||||
jobs:
|
||||
repoint:
|
||||
runs-on: ubuntu-latest
|
||||
steps:
|
||||
- uses: actions/checkout@v4
|
||||
with:
|
||||
fetch-depth: 0
|
||||
|
||||
- name: Point vendor tags at their bump commits
|
||||
run: |
|
||||
set -euo pipefail
|
||||
git fetch --tags --force origin
|
||||
for ebuild in dev-util/gitea-runner/gitea-runner-*.ebuild; do
|
||||
ver=${ebuild##*/gitea-runner-}; ver=${ver%.ebuild}
|
||||
tag="gitea-runner-${ver}-vendor"
|
||||
if ! cur=$(git rev-parse --verify -q "refs/tags/${tag}^{commit}"); then
|
||||
echo "${tag}: no such tag, skipping"; continue
|
||||
fi
|
||||
# git mv shows up as an addition of the new path (no --follow).
|
||||
target=$(git log --diff-filter=A --format=%H -1 -- "$ebuild")
|
||||
if [ "$cur" = "$target" ]; then
|
||||
echo "${tag}: already at ${target}"; continue
|
||||
fi
|
||||
echo "${tag}: ${cur} -> ${target}"
|
||||
git push --force origin "${target}:refs/tags/${tag}"
|
||||
done
|
||||
@@ -52,8 +52,9 @@ re-uploaded as a release asset, or the build will fail Manifest verification. Th
|
||||
4. `git mv`s the ebuild to the new version, rewrites `BDEPEND`'s Go version from
|
||||
upstream `go.mod`, and regenerates the Manifest with `pkgdev manifest` (after copying
|
||||
both distfiles into `/var/cache/distfiles` and wiring a temporary `repos.conf`).
|
||||
5. Validates: `pkgcheck scan`, then `emerge` + `gitea-runner --version | grep v${ver}`.
|
||||
6. Commits, pushes the branch, opens a PR against `master`.
|
||||
5. Commits, pushes the branch, opens a PR against `master`. The script does **not**
|
||||
emerge or pkgcheck the result itself: the branch push triggers CI, which does both
|
||||
(and fetches the real release asset, which the script's local copy never would).
|
||||
|
||||
Requires a `BUMP_TOKEN` repo secret (scopes: repository read/write, write release) plus
|
||||
a Gentoo env with `go pkgdev git curl xz jq`.
|
||||
@@ -74,6 +75,17 @@ runner executes JS actions by `docker exec node …` *inside* the job container,
|
||||
`gentoo/stage3` ships no node, so any JS action fails with exit 127. The lint job has no
|
||||
`container:`, so it runs in the runner's default node-capable image and checkout works.
|
||||
|
||||
## Vendor-tag repointing (`.gitea/workflows/vendor-tags.yaml`)
|
||||
|
||||
The bump script creates the `${PN}-${ver}-vendor` release before the bump commit
|
||||
exists, so its tag points at whatever `master` was at the time (and squash/rebase
|
||||
merges mean the branch commit never lands on `master` anyway). On every push to
|
||||
`master` touching `dev-util/**`, this workflow force-updates each vendor tag whose
|
||||
ebuild is still in the tree to the `master` commit that added that ebuild. It only
|
||||
ever *updates* tags: deleting a release's tag makes Gitea delete the release and its
|
||||
assets, breaking the ebuild's `SRC_URI`. Tag pushes don't re-trigger CI because
|
||||
`ci.yaml` is filtered to branch pushes.
|
||||
|
||||
## Conventions / gotchas
|
||||
|
||||
- **YAML** is linted by `.yamllint.yaml` (relaxed: line-length and document-start
|
||||
|
||||
@@ -120,13 +120,10 @@ printf '[azy5030]\nlocation = %s\nmasters = gentoo\nauto-sync = false\n' "$WORK"
|
||||
> /etc/portage/repos.conf/azy5030.conf
|
||||
( cd "${pkgdir}" && pkgdev manifest )
|
||||
|
||||
# --- validate, commit, push, open PR ----------------------------------------
|
||||
pkgcheck scan --repo "$WORK" "${pkgdir}" || true
|
||||
mkdir -p /etc/portage/package.accept_keywords
|
||||
echo 'dev-util/gitea-runner ~amd64' > /etc/portage/package.accept_keywords/gitea-runner
|
||||
emerge -v --getbinpkg "=dev-util/${PN}-${latest}"
|
||||
gitea-runner --version | grep -q "v${latest}"
|
||||
|
||||
# --- commit, push, open PR ---------------------------------------------------
|
||||
# No emerge/pkgcheck here: pushing the branch triggers CI, which runs pkgcheck,
|
||||
# builds the package from the Manifest (fetching the real release asset) and
|
||||
# asserts `gitea-runner --version`. A broken release shows up as a red PR.
|
||||
git add -A
|
||||
git commit -m "dev-util/${PN}: bump to ${latest}"
|
||||
git push origin "$branch"
|
||||
@@ -141,8 +138,7 @@ Review checklist:
|
||||
- [ ] LICENSE still covers all vendored module licenses (\`go-licenses report ./...\`)
|
||||
- [ ] BDEPEND Go version matches upstream go.mod (set to >=${goreq:-unchanged})
|
||||
- [ ] version ldflags path \`internal/pkg/ver.version\` unchanged upstream
|
||||
|
||||
CI build + \`gitea-runner --version\` passed in this workflow.
|
||||
- [ ] CI (pkgcheck + emerge + \`gitea-runner --version\`) is green on this PR
|
||||
EOF
|
||||
)
|
||||
api -X POST -H 'Content-Type: application/json' \
|
||||
|
||||
Reference in New Issue
Block a user