Compare commits

..

12 Commits

Author SHA1 Message Date
gitea-actions 9247f13991 dev-util/gitea-runner: bump to 3.4.0
Vendor tags / repoint (push) Successful in 9s
CI / lint (push) Successful in 1m55s
CI / build (push) Successful in 12m50s
2026-09-21 01:15:44 +00:00
gitea-actions 02fb5f1012 dev-util/gitea-runner: bump to 3.3.2
Vendor tags / repoint (push) Successful in 9s
CI / lint (push) Successful in 55s
CI / build (push) Successful in 11m59s
2026-09-21 00:50:25 +00:00
azy5030 c9a31ba468 ci: only run on branch pushes; drop bump-script emerge; repoint vendor tags
CI / lint (push) Successful in 58s
CI / build (push) Successful in 11m54s
- ci.yaml: filter the push trigger to branches. An unfiltered `push` also
  fired for every tag ref, including the vendor-release tags the bump script
  creates via the API.
- bump-version.sh: remove the pkgcheck/emerge/--version validation before
  push. The branch push triggers CI, which runs the same checks and, unlike
  the script's local copy, fetches the real release asset. The PR body now
  asks for green CI instead of claiming the build passed in the bump job.
- vendor-tags.yaml: new workflow on pushes to master touching dev-util/**.
  The vendor release is created before the bump commit exists (and PRs are
  squash-merged), so its tag pointed at an arbitrary master commit. This
  force-updates each vendor tag whose ebuild is in the tree to the master
  commit that added that ebuild. Tags are only ever updated, never deleted,
  since deleting a release's tag deletes the release and its assets.
- CLAUDE.md: document both changes.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-09-20 19:25:33 -05:00
gitea-actions 4a3dc17dc9 dev-util/gitea-runner: bump to 3.3.1
CI / lint (push) Has been cancelled
CI / build (push) Has been cancelled
2026-09-21 00:05:06 +00:00
azy5030 17e1bfae50 fix bump/ci actions to support new gitea runner
CI / lint (push) Successful in 1m26s
CI / build (push) Successful in 12m13s
2026-09-20 17:08:11 -05:00
gitea-actions aa4707da6a dev-util/gitea-runner: bump to 3.3.0
CI / lint (push) Has been cancelled
CI / build (push) Has been cancelled
2026-09-20 16:32:40 -05:00
gitea-actions d8714c8917 dev-util/gitea-runner: bump to 3.2.0
CI / lint (push) Has been cancelled
CI / build (push) Has been cancelled
2026-09-20 16:32:19 -05:00
gitea-actions 8344a203c2 dev-util/gitea-runner: bump to 3.1.0
CI / lint (push) Has been cancelled
CI / build (push) Has been cancelled
2026-09-20 16:30:41 -05:00
azy5030 4f092a980f dev-util/gitea-runner: bump to 3.0.2 (#13)
CI / lint (push) Has been cancelled
CI / build (push) Has been cancelled
Automated bump of `dev-util/gitea-runner` from 3.0.1 to 3.0.2.

- Upstream release: https://gitea.com/gitea/runner/releases/tag/v3.0.2
- Vendor tarball: https://git.azy.dev/azy5030/azy5030-overlay/releases/tag/gitea-runner-3.0.2-vendor

Review checklist:
- [ ] LICENSE still covers all vendored module licenses (`go-licenses report ./...`)
- [ ] BDEPEND Go version matches upstream go.mod (set to >=1.26.0)
- [ ] version ldflags path `internal/pkg/ver.version` unchanged upstream

CI build + `gitea-runner --version` passed in this workflow.

---------

Co-authored-by: gitea-actions <actions@azy.dev>
Reviewed-on: #13
2026-09-20 16:28:57 -05:00
azy5030 6c6d626890 dev-util/gitea-runner: bump to 3.0.1 (#12)
CI / lint (push) Has been cancelled
CI / build (push) Has been cancelled
Automated bump of `dev-util/gitea-runner` from 3.0.0 to 3.0.1.

- Upstream release: https://gitea.com/gitea/runner/releases/tag/v3.0.1
- Vendor tarball: https://git.azy.dev/azy5030/azy5030-overlay/releases/tag/gitea-runner-3.0.1-vendor

Review checklist:
- [ ] LICENSE still covers all vendored module licenses (`go-licenses report ./...`)
- [ ] BDEPEND Go version matches upstream go.mod (set to >=1.26.0)
- [ ] version ldflags path `internal/pkg/ver.version` unchanged upstream

CI build + `gitea-runner --version` passed in this workflow.

---------

Co-authored-by: gitea-actions <actions@azy.dev>
Reviewed-on: #12
2026-09-20 15:49:21 -05:00
azy5030 97e47f3ffe dev-util/gitea-runner: bump to 3.0.0 (#11)
CI / lint (push) Has been cancelled
CI / build (push) Has been cancelled
Automated bump of `dev-util/gitea-runner` from 2.0.1 to 3.0.0.

- Upstream release: https://gitea.com/gitea/runner/releases/tag/v3.0.0
- Vendor tarball: https://git.azy.dev/azy5030/azy5030-overlay/releases/tag/gitea-runner-3.0.0-vendor

Review checklist:
- [ ] LICENSE still covers all vendored module licenses (`go-licenses report ./...`)
- [ ] BDEPEND Go version matches upstream go.mod (set to >=1.26.0)
- [ ] version ldflags path `internal/pkg/ver.version` unchanged upstream

CI build + `gitea-runner --version` passed in this workflow.

---------

Co-authored-by: gitea-actions <actions@azy.dev>
Reviewed-on: #11
2026-09-20 15:40:42 -05:00
azy5030 0bc4250f39 dev-util/gitea-runner: bump to 2.3.0 (#10)
CI / lint (push) Has been cancelled
CI / build (push) Has been cancelled
Automated bump of `dev-util/gitea-runner` from 2.0.1 to 2.3.0.

- Upstream release: https://gitea.com/gitea/runner/releases/tag/v2.3.0
- Vendor tarball: https://git.azy.dev/azy5030/azy5030-overlay/releases/tag/gitea-runner-2.3.0-vendor

Review checklist:
- [ ] LICENSE still covers all vendored module licenses (`go-licenses report ./...`)
- [ ] BDEPEND Go version matches upstream go.mod (set to >=1.26.0)
- [ ] version ldflags path `internal/pkg/ver.version` unchanged upstream

CI build + `gitea-runner --version` passed in this workflow.

---------

Co-authored-by: gitea-actions <actions@azy.dev>
Reviewed-on: #10
2026-09-20 15:31:42 -05:00
7 changed files with 126 additions and 23 deletions
+22 -1
View File
@@ -2,7 +2,14 @@ name: Bump
on:
schedule:
- cron: '0 5 * * *'
workflow_dispatch: {}
workflow_dispatch:
inputs:
version:
description: >-
Upstream gitea/runner version to bump to (e.g. 3.4.0, no leading
"v"). Leave empty to use the latest upstream release.
required: false
type: string
jobs:
bump:
@@ -19,7 +26,14 @@ jobs:
id: check
env:
BUMP_TOKEN: ${{ secrets.BUMP_TOKEN }}
BUMP_VERSION: ${{ inputs.version }}
run: |
# An explicitly requested version always runs the full bump.
if [ -n "${BUMP_VERSION}" ]; then
echo "needed=true" >> "$GITHUB_OUTPUT"
echo "explicit version requested: ${BUMP_VERSION}"
exit 0
fi
latest=$(wget -qO- https://gitea.com/gitea/runner/releases.rss \
| grep -oE '<title>v[0-9]+\.[0-9]+\.[0-9]+</title>' \
| head -1 | sed -E 's#</?title>##g; s/^v//')
@@ -51,6 +65,12 @@ jobs:
> /etc/portage/repos.conf/gentoo.conf
sed -i '/^verify-signature/d' /etc/portage/binrepos.conf/gentoo.conf
printf '\nverify-signature = false\n' >> /etc/portage/binrepos.conf/gentoo.conf
# Upstream's go.mod can require a Go that Gentoo only has under
# ~amd64 (GOTOOLCHAIN=local forbids auto-download), so accept the
# testing-keyworded dev-lang/go. It is built from source when no
# stable binpkg satisfies the requirement.
mkdir -p /etc/portage/package.accept_keywords
echo 'dev-lang/go ~amd64' > /etc/portage/package.accept_keywords/go
emerge -q --getbinpkg \
dev-vcs/git net-misc/curl app-arch/xz-utils app-misc/jq \
dev-lang/go dev-util/pkgdev
@@ -59,6 +79,7 @@ jobs:
if: steps.check.outputs.needed == 'true'
env:
BUMP_TOKEN: ${{ secrets.BUMP_TOKEN }}
BUMP_VERSION: ${{ inputs.version }}
run: |
host=${GITHUB_SERVER_URL#http://}; host=${host#https://}
curl -fsSL "http://x-access-token:${BUMP_TOKEN}@${host}/${GITHUB_REPOSITORY}/raw/branch/master/scripts/bump-version.sh" \
+11 -1
View File
@@ -1,5 +1,10 @@
name: CI
on: [push]
# Restrict to branch pushes: an unfiltered `push` also fires for tag refs,
# including the vendor-release tags the bump script creates via the API.
on:
push:
branches:
- '**'
jobs:
# Lint gate: runs on the plain Docker-backend runner (not the Gentoo
@@ -81,6 +86,11 @@ jobs:
> /etc/portage/repos.conf/azy5030.conf
mkdir -p /etc/portage/package.accept_keywords
echo 'dev-util/gitea-runner ~amd64' > /etc/portage/package.accept_keywords/gitea-runner
# Upstream tracks new Go releases faster than Gentoo stabilises them
# (the ebuild's BDEPEND follows upstream go.mod), so accept the
# testing-keyworded dev-lang/go. No stable binpkg exists for it, so
# this compiles Go from source when a newer one is required.
echo 'dev-lang/go ~amd64' > /etc/portage/package.accept_keywords/go
- name: QA scan
run: pkgcheck scan --repo /var/db/repos/azy5030 dev-util/gitea-runner
+43
View File
@@ -0,0 +1,43 @@
name: Vendor tags
# The bump script creates the `${PN}-${ver}-vendor` release (which hosts the
# vendor tarball) *before* the bump commit exists, so its tag can only point at
# whatever master was at the time. The PR is then squash/rebase-merged, so the
# branch commit never lands on master either. This job re-points each vendor
# tag at the master commit that introduced that version's ebuild. It is
# idempotent: a tag already on the right commit is left alone.
#
# Only ever force-*update* a tag here. Deleting a release's tag makes Gitea
# delete the release and its assets, which would break the ebuild's SRC_URI.
on:
push:
branches:
- master
paths:
- 'dev-util/**'
jobs:
repoint:
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@v4
with:
fetch-depth: 0
- name: Point vendor tags at their bump commits
run: |
set -euo pipefail
git fetch --tags --force origin
for ebuild in dev-util/gitea-runner/gitea-runner-*.ebuild; do
ver=${ebuild##*/gitea-runner-}; ver=${ver%.ebuild}
tag="gitea-runner-${ver}-vendor"
if ! cur=$(git rev-parse --verify -q "refs/tags/${tag}^{commit}"); then
echo "${tag}: no such tag, skipping"; continue
fi
# git mv shows up as an addition of the new path (no --follow).
target=$(git log --diff-filter=A --format=%H -1 -- "$ebuild")
if [ "$cur" = "$target" ]; then
echo "${tag}: already at ${target}"; continue
fi
echo "${tag}: ${cur} -> ${target}"
git push --force origin "${target}:refs/tags/${tag}"
done
+14 -2
View File
@@ -52,8 +52,9 @@ re-uploaded as a release asset, or the build will fail Manifest verification. Th
4. `git mv`s the ebuild to the new version, rewrites `BDEPEND`'s Go version from
upstream `go.mod`, and regenerates the Manifest with `pkgdev manifest` (after copying
both distfiles into `/var/cache/distfiles` and wiring a temporary `repos.conf`).
5. Validates: `pkgcheck scan`, then `emerge` + `gitea-runner --version | grep v${ver}`.
6. Commits, pushes the branch, opens a PR against `master`.
5. Commits, pushes the branch, opens a PR against `master`. The script does **not**
emerge or pkgcheck the result itself: the branch push triggers CI, which does both
(and fetches the real release asset, which the script's local copy never would).
Requires a `BUMP_TOKEN` repo secret (scopes: repository read/write, write release) plus
a Gentoo env with `go pkgdev git curl xz jq`.
@@ -74,6 +75,17 @@ runner executes JS actions by `docker exec node …` *inside* the job container,
`gentoo/stage3` ships no node, so any JS action fails with exit 127. The lint job has no
`container:`, so it runs in the runner's default node-capable image and checkout works.
## Vendor-tag repointing (`.gitea/workflows/vendor-tags.yaml`)
The bump script creates the `${PN}-${ver}-vendor` release before the bump commit
exists, so its tag points at whatever `master` was at the time (and squash/rebase
merges mean the branch commit never lands on `master` anyway). On every push to
`master` touching `dev-util/**`, this workflow force-updates each vendor tag whose
ebuild is still in the tree to the `master` commit that added that ebuild. It only
ever *updates* tags: deleting a release's tag makes Gitea delete the release and its
assets, breaking the ebuild's `SRC_URI`. Tag pushes don't re-trigger CI because
`ci.yaml` is filtered to branch pushes.
## Conventions / gotchas
- **YAML** is linted by `.yamllint.yaml` (relaxed: line-length and document-start
+2 -2
View File
@@ -1,2 +1,2 @@
DIST gitea-runner-2.3.0-vendor.tar.xz 3074844 BLAKE2B fc0084749e1bef15bd935da31262ba357a1bdeb21232561280d6dbbb7f0b8ad0a29b111d1168f8562e879da9dd1c75a6cf43a45a98e113627ea374384be89aaf SHA512 9276727f2988a49e6f006aa5baf6244aa84a4aaea2a62cd91e6be7a7131952b60141584c325eca333e15f1f7815ec40378d745b86f3c4627158564af47c23f11
DIST gitea-runner-2.3.0.tar.gz 428155 BLAKE2B 82466ad63de998054d756d506efbfd558b474d6fb05ff7a4ee2ec9e94684274d7b6057bf6332f42284dfa24613f3e16737d447dd82dc94145e130e347de02004 SHA512 68ac5129b90f01720fd04a02c4bfa4dc52724d55382904325d8b4a159cc13fcf8b30a78a0f50048968a4ea59f63e4d8f679737bdd1788087df2c036edf2011fc
DIST gitea-runner-3.4.0-vendor.tar.xz 3274276 BLAKE2B 22d86437a167bb7799d503bc707361f9f9a441ab3623f474ebe848dfd7b6dc98afc024c0d6cc74113326bcea83e8bb50ff4c993692646f5086d35fdbfa555a3e SHA512 cf4095ae2da6a5a3068e76a2057505616f725519397b9541f67f5b377217a7af4bbd9b6022628dca4a67b621673a2997c3af1c0054398874ff0f3d1a9a3affbe
DIST gitea-runner-3.4.0.tar.gz 494665 BLAKE2B 6ce05560e622e3bdcaf5d35a9f1353cf452a4a277427730ee61dc123d77bcee1bb4ca6ba4bae40c41e35d05e25f68e1539f63d17310b76b694b13e0e1f8fbfbf SHA512 7f1ac2010f84b0b7976f4da7fe19dd2eeb67b4b280b4698e3f7dd29e45bb9f9847f6023333950fbfb385649e5d3f0d32503f19616bbbdc48114728a799f61454
@@ -19,7 +19,7 @@ LICENSE="MIT Apache-2.0 BSD BSD-2 ISC MPL-2.0"
SLOT="0"
KEYWORDS="~amd64"
BDEPEND=">=dev-lang/go-1.26.0"
BDEPEND=">=dev-lang/go-1.27"
# The runner shells out to the docker client for the Docker backend.
RDEPEND="app-containers/docker-cli"
+33 -16
View File
@@ -6,12 +6,17 @@
# Expects a Gentoo environment with: go, pkgdev, git, curl, xz, jq.
# Required env: BUMP_TOKEN, GITHUB_SERVER_URL, GITHUB_REPOSITORY.
# Optional env: GITHUB_API_URL (defaults to ${GITHUB_SERVER_URL}/api/v1).
# BUMP_VERSION target a specific upstream version (X.Y.Z, no
# leading "v") instead of the latest release. An
# explicit target may be older than the current
# ebuild (useful to back out of a broken release).
set -euo pipefail
PN="gitea-runner"
UPSTREAM_RSS="https://gitea.com/gitea/runner/releases.rss"
UPSTREAM_ARCHIVE="https://gitea.com/api/v1/repos/gitea/runner/archive"
UPSTREAM_GOMOD="https://gitea.com/api/v1/repos/gitea/runner/raw/go.mod"
UPSTREAM_TAGS="https://gitea.com/api/v1/repos/gitea/runner/tags"
: "${BUMP_TOKEN:?BUMP_TOKEN is required}"
: "${GITHUB_SERVER_URL:?GITHUB_SERVER_URL is required}"
@@ -25,10 +30,22 @@ host="${GITHUB_SERVER_URL#*://}"
api() { curl -fsSL -H "Authorization: token ${BUMP_TOKEN}" "$@"; }
# --- determine versions ------------------------------------------------------
latest=$(curl -fsSL "$UPSTREAM_RSS" \
| grep -oE '<title>v[0-9]+\.[0-9]+\.[0-9]+</title>' \
| head -1 | sed -E 's#</?title>##g; s/^v//')
[ -n "$latest" ] || { echo "could not parse upstream version"; exit 1; }
if [ -n "${BUMP_VERSION:-}" ]; then
latest="${BUMP_VERSION#v}"
echo "$latest" | grep -qE '^[0-9]+\.[0-9]+\.[0-9]+$' \
|| { echo "BUMP_VERSION must look like X.Y.Z (got '${BUMP_VERSION}')"; exit 1; }
# Fail fast if the tag doesn't exist upstream, before cloning anything.
# (The raw endpoint silently falls back to the default branch for an
# unknown ref, so ask the tags API, which 404s.)
curl -fsSL "${UPSTREAM_TAGS}/v${latest}" -o /dev/null \
|| { echo "upstream tag v${latest} not found"; exit 1; }
echo "targeting explicit version ${latest}"
else
latest=$(curl -fsSL "$UPSTREAM_RSS" \
| grep -oE '<title>v[0-9]+\.[0-9]+\.[0-9]+</title>' \
| head -1 | sed -E 's#</?title>##g; s/^v//')
[ -n "$latest" ] || { echo "could not parse upstream version"; exit 1; }
fi
WORK=$(mktemp -d)
git clone "${scheme}://x-access-token:${BUMP_TOKEN}@${host}/${GITHUB_REPOSITORY}.git" "$WORK"
@@ -39,11 +56,15 @@ current=$(find "$pkgdir" -name "${PN}-*.ebuild" \
| sed -E "s#.*/${PN}-(.*)\.ebuild#\1#" | sort -V | tail -1)
echo "upstream=${latest} current=${current}"
[ "$latest" != "$current" ] || { echo "already at ${latest}"; exit 0; }
newest=$(printf '%s\n%s\n' "$current" "$latest" | sort -V | tail -1)
if [ "$newest" = "$current" ] && [ "$latest" != "$current" ]; then
echo "current ($current) is newer than upstream ($latest); nothing to do"; exit 0
if [ "$newest" = "$current" ]; then
if [ -n "${BUMP_VERSION:-}" ]; then
echo "warning: explicit target ${latest} is older than current ${current}; downgrading"
else
echo "current ($current) is newer than upstream ($latest); nothing to do"; exit 0
fi
fi
[ "$latest" != "$current" ] || { echo "already at latest ($current)"; exit 0; }
branch="bump/${PN}-${latest}"
if api "${API}/repos/${GITHUB_REPOSITORY}/branches/${branch}" >/dev/null 2>&1; then
@@ -99,13 +120,10 @@ printf '[azy5030]\nlocation = %s\nmasters = gentoo\nauto-sync = false\n' "$WORK"
> /etc/portage/repos.conf/azy5030.conf
( cd "${pkgdir}" && pkgdev manifest )
# --- validate, commit, push, open PR ----------------------------------------
pkgcheck scan --repo "$WORK" "${pkgdir}" || true
mkdir -p /etc/portage/package.accept_keywords
echo 'dev-util/gitea-runner ~amd64' > /etc/portage/package.accept_keywords/gitea-runner
emerge -v --getbinpkg "=dev-util/${PN}-${latest}"
gitea-runner --version | grep -q "v${latest}"
# --- commit, push, open PR ---------------------------------------------------
# No emerge/pkgcheck here: pushing the branch triggers CI, which runs pkgcheck,
# builds the package from the Manifest (fetching the real release asset) and
# asserts `gitea-runner --version`. A broken release shows up as a red PR.
git add -A
git commit -m "dev-util/${PN}: bump to ${latest}"
git push origin "$branch"
@@ -120,8 +138,7 @@ Review checklist:
- [ ] LICENSE still covers all vendored module licenses (\`go-licenses report ./...\`)
- [ ] BDEPEND Go version matches upstream go.mod (set to >=${goreq:-unchanged})
- [ ] version ldflags path \`internal/pkg/ver.version\` unchanged upstream
CI build + \`gitea-runner --version\` passed in this workflow.
- [ ] CI (pkgcheck + emerge + \`gitea-runner --version\`) is green on this PR
EOF
)
api -X POST -H 'Content-Type: application/json' \