Compare commits

...

4 Commits

Author SHA1 Message Date
gitea-actions 02fb5f1012 dev-util/gitea-runner: bump to 3.3.2
Vendor tags / repoint (push) Successful in 9s
CI / lint (push) Successful in 55s
CI / build (push) Successful in 11m59s
2026-09-21 00:50:25 +00:00
azy5030 c9a31ba468 ci: only run on branch pushes; drop bump-script emerge; repoint vendor tags
CI / lint (push) Successful in 58s
CI / build (push) Successful in 11m54s
- ci.yaml: filter the push trigger to branches. An unfiltered `push` also
  fired for every tag ref, including the vendor-release tags the bump script
  creates via the API.
- bump-version.sh: remove the pkgcheck/emerge/--version validation before
  push. The branch push triggers CI, which runs the same checks and, unlike
  the script's local copy, fetches the real release asset. The PR body now
  asks for green CI instead of claiming the build passed in the bump job.
- vendor-tags.yaml: new workflow on pushes to master touching dev-util/**.
  The vendor release is created before the bump commit exists (and PRs are
  squash-merged), so its tag pointed at an arbitrary master commit. This
  force-updates each vendor tag whose ebuild is in the tree to the master
  commit that added that ebuild. Tags are only ever updated, never deleted,
  since deleting a release's tag deletes the release and its assets.
- CLAUDE.md: document both changes.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-09-20 19:25:33 -05:00
gitea-actions 4a3dc17dc9 dev-util/gitea-runner: bump to 3.3.1
CI / lint (push) Has been cancelled
CI / build (push) Has been cancelled
2026-09-21 00:05:06 +00:00
azy5030 17e1bfae50 fix bump/ci actions to support new gitea runner
CI / lint (push) Successful in 1m26s
CI / build (push) Successful in 12m13s
2026-09-20 17:08:11 -05:00
7 changed files with 126 additions and 23 deletions
+22 -1
View File
@@ -2,7 +2,14 @@ name: Bump
on: on:
schedule: schedule:
- cron: '0 5 * * *' - cron: '0 5 * * *'
workflow_dispatch: {} workflow_dispatch:
inputs:
version:
description: >-
Upstream gitea/runner version to bump to (e.g. 3.4.0, no leading
"v"). Leave empty to use the latest upstream release.
required: false
type: string
jobs: jobs:
bump: bump:
@@ -19,7 +26,14 @@ jobs:
id: check id: check
env: env:
BUMP_TOKEN: ${{ secrets.BUMP_TOKEN }} BUMP_TOKEN: ${{ secrets.BUMP_TOKEN }}
BUMP_VERSION: ${{ inputs.version }}
run: | run: |
# An explicitly requested version always runs the full bump.
if [ -n "${BUMP_VERSION}" ]; then
echo "needed=true" >> "$GITHUB_OUTPUT"
echo "explicit version requested: ${BUMP_VERSION}"
exit 0
fi
latest=$(wget -qO- https://gitea.com/gitea/runner/releases.rss \ latest=$(wget -qO- https://gitea.com/gitea/runner/releases.rss \
| grep -oE '<title>v[0-9]+\.[0-9]+\.[0-9]+</title>' \ | grep -oE '<title>v[0-9]+\.[0-9]+\.[0-9]+</title>' \
| head -1 | sed -E 's#</?title>##g; s/^v//') | head -1 | sed -E 's#</?title>##g; s/^v//')
@@ -51,6 +65,12 @@ jobs:
> /etc/portage/repos.conf/gentoo.conf > /etc/portage/repos.conf/gentoo.conf
sed -i '/^verify-signature/d' /etc/portage/binrepos.conf/gentoo.conf sed -i '/^verify-signature/d' /etc/portage/binrepos.conf/gentoo.conf
printf '\nverify-signature = false\n' >> /etc/portage/binrepos.conf/gentoo.conf printf '\nverify-signature = false\n' >> /etc/portage/binrepos.conf/gentoo.conf
# Upstream's go.mod can require a Go that Gentoo only has under
# ~amd64 (GOTOOLCHAIN=local forbids auto-download), so accept the
# testing-keyworded dev-lang/go. It is built from source when no
# stable binpkg satisfies the requirement.
mkdir -p /etc/portage/package.accept_keywords
echo 'dev-lang/go ~amd64' > /etc/portage/package.accept_keywords/go
emerge -q --getbinpkg \ emerge -q --getbinpkg \
dev-vcs/git net-misc/curl app-arch/xz-utils app-misc/jq \ dev-vcs/git net-misc/curl app-arch/xz-utils app-misc/jq \
dev-lang/go dev-util/pkgdev dev-lang/go dev-util/pkgdev
@@ -59,6 +79,7 @@ jobs:
if: steps.check.outputs.needed == 'true' if: steps.check.outputs.needed == 'true'
env: env:
BUMP_TOKEN: ${{ secrets.BUMP_TOKEN }} BUMP_TOKEN: ${{ secrets.BUMP_TOKEN }}
BUMP_VERSION: ${{ inputs.version }}
run: | run: |
host=${GITHUB_SERVER_URL#http://}; host=${host#https://} host=${GITHUB_SERVER_URL#http://}; host=${host#https://}
curl -fsSL "http://x-access-token:${BUMP_TOKEN}@${host}/${GITHUB_REPOSITORY}/raw/branch/master/scripts/bump-version.sh" \ curl -fsSL "http://x-access-token:${BUMP_TOKEN}@${host}/${GITHUB_REPOSITORY}/raw/branch/master/scripts/bump-version.sh" \
+11 -1
View File
@@ -1,5 +1,10 @@
name: CI name: CI
on: [push] # Restrict to branch pushes: an unfiltered `push` also fires for tag refs,
# including the vendor-release tags the bump script creates via the API.
on:
push:
branches:
- '**'
jobs: jobs:
# Lint gate: runs on the plain Docker-backend runner (not the Gentoo # Lint gate: runs on the plain Docker-backend runner (not the Gentoo
@@ -81,6 +86,11 @@ jobs:
> /etc/portage/repos.conf/azy5030.conf > /etc/portage/repos.conf/azy5030.conf
mkdir -p /etc/portage/package.accept_keywords mkdir -p /etc/portage/package.accept_keywords
echo 'dev-util/gitea-runner ~amd64' > /etc/portage/package.accept_keywords/gitea-runner echo 'dev-util/gitea-runner ~amd64' > /etc/portage/package.accept_keywords/gitea-runner
# Upstream tracks new Go releases faster than Gentoo stabilises them
# (the ebuild's BDEPEND follows upstream go.mod), so accept the
# testing-keyworded dev-lang/go. No stable binpkg exists for it, so
# this compiles Go from source when a newer one is required.
echo 'dev-lang/go ~amd64' > /etc/portage/package.accept_keywords/go
- name: QA scan - name: QA scan
run: pkgcheck scan --repo /var/db/repos/azy5030 dev-util/gitea-runner run: pkgcheck scan --repo /var/db/repos/azy5030 dev-util/gitea-runner
+43
View File
@@ -0,0 +1,43 @@
name: Vendor tags
# The bump script creates the `${PN}-${ver}-vendor` release (which hosts the
# vendor tarball) *before* the bump commit exists, so its tag can only point at
# whatever master was at the time. The PR is then squash/rebase-merged, so the
# branch commit never lands on master either. This job re-points each vendor
# tag at the master commit that introduced that version's ebuild. It is
# idempotent: a tag already on the right commit is left alone.
#
# Only ever force-*update* a tag here. Deleting a release's tag makes Gitea
# delete the release and its assets, which would break the ebuild's SRC_URI.
on:
push:
branches:
- master
paths:
- 'dev-util/**'
jobs:
repoint:
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@v4
with:
fetch-depth: 0
- name: Point vendor tags at their bump commits
run: |
set -euo pipefail
git fetch --tags --force origin
for ebuild in dev-util/gitea-runner/gitea-runner-*.ebuild; do
ver=${ebuild##*/gitea-runner-}; ver=${ver%.ebuild}
tag="gitea-runner-${ver}-vendor"
if ! cur=$(git rev-parse --verify -q "refs/tags/${tag}^{commit}"); then
echo "${tag}: no such tag, skipping"; continue
fi
# git mv shows up as an addition of the new path (no --follow).
target=$(git log --diff-filter=A --format=%H -1 -- "$ebuild")
if [ "$cur" = "$target" ]; then
echo "${tag}: already at ${target}"; continue
fi
echo "${tag}: ${cur} -> ${target}"
git push --force origin "${target}:refs/tags/${tag}"
done
+14 -2
View File
@@ -52,8 +52,9 @@ re-uploaded as a release asset, or the build will fail Manifest verification. Th
4. `git mv`s the ebuild to the new version, rewrites `BDEPEND`'s Go version from 4. `git mv`s the ebuild to the new version, rewrites `BDEPEND`'s Go version from
upstream `go.mod`, and regenerates the Manifest with `pkgdev manifest` (after copying upstream `go.mod`, and regenerates the Manifest with `pkgdev manifest` (after copying
both distfiles into `/var/cache/distfiles` and wiring a temporary `repos.conf`). both distfiles into `/var/cache/distfiles` and wiring a temporary `repos.conf`).
5. Validates: `pkgcheck scan`, then `emerge` + `gitea-runner --version | grep v${ver}`. 5. Commits, pushes the branch, opens a PR against `master`. The script does **not**
6. Commits, pushes the branch, opens a PR against `master`. emerge or pkgcheck the result itself: the branch push triggers CI, which does both
(and fetches the real release asset, which the script's local copy never would).
Requires a `BUMP_TOKEN` repo secret (scopes: repository read/write, write release) plus Requires a `BUMP_TOKEN` repo secret (scopes: repository read/write, write release) plus
a Gentoo env with `go pkgdev git curl xz jq`. a Gentoo env with `go pkgdev git curl xz jq`.
@@ -74,6 +75,17 @@ runner executes JS actions by `docker exec node …` *inside* the job container,
`gentoo/stage3` ships no node, so any JS action fails with exit 127. The lint job has no `gentoo/stage3` ships no node, so any JS action fails with exit 127. The lint job has no
`container:`, so it runs in the runner's default node-capable image and checkout works. `container:`, so it runs in the runner's default node-capable image and checkout works.
## Vendor-tag repointing (`.gitea/workflows/vendor-tags.yaml`)
The bump script creates the `${PN}-${ver}-vendor` release before the bump commit
exists, so its tag points at whatever `master` was at the time (and squash/rebase
merges mean the branch commit never lands on `master` anyway). On every push to
`master` touching `dev-util/**`, this workflow force-updates each vendor tag whose
ebuild is still in the tree to the `master` commit that added that ebuild. It only
ever *updates* tags: deleting a release's tag makes Gitea delete the release and its
assets, breaking the ebuild's `SRC_URI`. Tag pushes don't re-trigger CI because
`ci.yaml` is filtered to branch pushes.
## Conventions / gotchas ## Conventions / gotchas
- **YAML** is linted by `.yamllint.yaml` (relaxed: line-length and document-start - **YAML** is linted by `.yamllint.yaml` (relaxed: line-length and document-start
+2 -2
View File
@@ -1,2 +1,2 @@
DIST gitea-runner-3.3.0-vendor.tar.xz 3236784 BLAKE2B f3c2f9c96a042682d3a8afc36e33191edd4322814757d32617d056751e6e50495be0e9d9a92bb139e7476f02bb9f812b0bfe379d32e2c2db2291883501b16afe SHA512 6feec2e3f34a6b3fefe98b87a3fb3447ebf2ac6d9464cfa64527fe333a82280c148765660ee795ea40b31d774100876396114fe1eae97bb20b5139e140b6ec5b DIST gitea-runner-3.3.2-vendor.tar.xz 3273532 BLAKE2B 376e88938aef1a945ca2da00f23d3320e5ab7efdaa539f3825aed104b3eab4c965359b1bef602613fb0e236d089146f14449fba4d0ba54a60062edb6aeae66a3 SHA512 92e202990a6e501205d7068a305e123442887263d1967b3ec3a38480b2e5f65592887a14ac861bfebf5c71060daab914bb38edd25f373e1414ebfda745bc367b
DIST gitea-runner-3.3.0.tar.gz 478383 BLAKE2B 5f2fec136b7e603c24eb711fa17986be26ea1aa0f4a7f26d273cdc3465f5cc9a0455b03c57f60128c4a551789889fcf6aab08c2ada064cce69e41f0ac1737152 SHA512 640a0e742ee30fbf94887c00f5a3de9423db0601054ac169c0498203afc255386279c9b21600ab0eb5489219094344fb9e92da52d4064fbac591b8afad597713 DIST gitea-runner-3.3.2.tar.gz 485524 BLAKE2B 691b9f1d051a4879bc32b5d858123c7b13a92ce87ee27127e47ee0a7608a2208799a13d6bfb529889d6f083116d396a8d6abf5da5ae8d169fe216ff0ac9efcc9 SHA512 a0d86250da07262e654c7b9fafbbeeb2691e21ea76992bf555b2a57155ee8f60ea5fe436dc067af992ae9892a23fec208ca60802bc7fdf7fd81bb45d2d73c091
@@ -19,7 +19,7 @@ LICENSE="MIT Apache-2.0 BSD BSD-2 ISC MPL-2.0"
SLOT="0" SLOT="0"
KEYWORDS="~amd64" KEYWORDS="~amd64"
BDEPEND=">=dev-lang/go-1.26.0" BDEPEND=">=dev-lang/go-1.27"
# The runner shells out to the docker client for the Docker backend. # The runner shells out to the docker client for the Docker backend.
RDEPEND="app-containers/docker-cli" RDEPEND="app-containers/docker-cli"
+33 -16
View File
@@ -6,12 +6,17 @@
# Expects a Gentoo environment with: go, pkgdev, git, curl, xz, jq. # Expects a Gentoo environment with: go, pkgdev, git, curl, xz, jq.
# Required env: BUMP_TOKEN, GITHUB_SERVER_URL, GITHUB_REPOSITORY. # Required env: BUMP_TOKEN, GITHUB_SERVER_URL, GITHUB_REPOSITORY.
# Optional env: GITHUB_API_URL (defaults to ${GITHUB_SERVER_URL}/api/v1). # Optional env: GITHUB_API_URL (defaults to ${GITHUB_SERVER_URL}/api/v1).
# BUMP_VERSION target a specific upstream version (X.Y.Z, no
# leading "v") instead of the latest release. An
# explicit target may be older than the current
# ebuild (useful to back out of a broken release).
set -euo pipefail set -euo pipefail
PN="gitea-runner" PN="gitea-runner"
UPSTREAM_RSS="https://gitea.com/gitea/runner/releases.rss" UPSTREAM_RSS="https://gitea.com/gitea/runner/releases.rss"
UPSTREAM_ARCHIVE="https://gitea.com/api/v1/repos/gitea/runner/archive" UPSTREAM_ARCHIVE="https://gitea.com/api/v1/repos/gitea/runner/archive"
UPSTREAM_GOMOD="https://gitea.com/api/v1/repos/gitea/runner/raw/go.mod" UPSTREAM_GOMOD="https://gitea.com/api/v1/repos/gitea/runner/raw/go.mod"
UPSTREAM_TAGS="https://gitea.com/api/v1/repos/gitea/runner/tags"
: "${BUMP_TOKEN:?BUMP_TOKEN is required}" : "${BUMP_TOKEN:?BUMP_TOKEN is required}"
: "${GITHUB_SERVER_URL:?GITHUB_SERVER_URL is required}" : "${GITHUB_SERVER_URL:?GITHUB_SERVER_URL is required}"
@@ -25,10 +30,22 @@ host="${GITHUB_SERVER_URL#*://}"
api() { curl -fsSL -H "Authorization: token ${BUMP_TOKEN}" "$@"; } api() { curl -fsSL -H "Authorization: token ${BUMP_TOKEN}" "$@"; }
# --- determine versions ------------------------------------------------------ # --- determine versions ------------------------------------------------------
latest=$(curl -fsSL "$UPSTREAM_RSS" \ if [ -n "${BUMP_VERSION:-}" ]; then
| grep -oE '<title>v[0-9]+\.[0-9]+\.[0-9]+</title>' \ latest="${BUMP_VERSION#v}"
| head -1 | sed -E 's#</?title>##g; s/^v//') echo "$latest" | grep -qE '^[0-9]+\.[0-9]+\.[0-9]+$' \
[ -n "$latest" ] || { echo "could not parse upstream version"; exit 1; } || { echo "BUMP_VERSION must look like X.Y.Z (got '${BUMP_VERSION}')"; exit 1; }
# Fail fast if the tag doesn't exist upstream, before cloning anything.
# (The raw endpoint silently falls back to the default branch for an
# unknown ref, so ask the tags API, which 404s.)
curl -fsSL "${UPSTREAM_TAGS}/v${latest}" -o /dev/null \
|| { echo "upstream tag v${latest} not found"; exit 1; }
echo "targeting explicit version ${latest}"
else
latest=$(curl -fsSL "$UPSTREAM_RSS" \
| grep -oE '<title>v[0-9]+\.[0-9]+\.[0-9]+</title>' \
| head -1 | sed -E 's#</?title>##g; s/^v//')
[ -n "$latest" ] || { echo "could not parse upstream version"; exit 1; }
fi
WORK=$(mktemp -d) WORK=$(mktemp -d)
git clone "${scheme}://x-access-token:${BUMP_TOKEN}@${host}/${GITHUB_REPOSITORY}.git" "$WORK" git clone "${scheme}://x-access-token:${BUMP_TOKEN}@${host}/${GITHUB_REPOSITORY}.git" "$WORK"
@@ -39,11 +56,15 @@ current=$(find "$pkgdir" -name "${PN}-*.ebuild" \
| sed -E "s#.*/${PN}-(.*)\.ebuild#\1#" | sort -V | tail -1) | sed -E "s#.*/${PN}-(.*)\.ebuild#\1#" | sort -V | tail -1)
echo "upstream=${latest} current=${current}" echo "upstream=${latest} current=${current}"
[ "$latest" != "$current" ] || { echo "already at ${latest}"; exit 0; }
newest=$(printf '%s\n%s\n' "$current" "$latest" | sort -V | tail -1) newest=$(printf '%s\n%s\n' "$current" "$latest" | sort -V | tail -1)
if [ "$newest" = "$current" ] && [ "$latest" != "$current" ]; then if [ "$newest" = "$current" ]; then
echo "current ($current) is newer than upstream ($latest); nothing to do"; exit 0 if [ -n "${BUMP_VERSION:-}" ]; then
echo "warning: explicit target ${latest} is older than current ${current}; downgrading"
else
echo "current ($current) is newer than upstream ($latest); nothing to do"; exit 0
fi
fi fi
[ "$latest" != "$current" ] || { echo "already at latest ($current)"; exit 0; }
branch="bump/${PN}-${latest}" branch="bump/${PN}-${latest}"
if api "${API}/repos/${GITHUB_REPOSITORY}/branches/${branch}" >/dev/null 2>&1; then if api "${API}/repos/${GITHUB_REPOSITORY}/branches/${branch}" >/dev/null 2>&1; then
@@ -99,13 +120,10 @@ printf '[azy5030]\nlocation = %s\nmasters = gentoo\nauto-sync = false\n' "$WORK"
> /etc/portage/repos.conf/azy5030.conf > /etc/portage/repos.conf/azy5030.conf
( cd "${pkgdir}" && pkgdev manifest ) ( cd "${pkgdir}" && pkgdev manifest )
# --- validate, commit, push, open PR ---------------------------------------- # --- commit, push, open PR ---------------------------------------------------
pkgcheck scan --repo "$WORK" "${pkgdir}" || true # No emerge/pkgcheck here: pushing the branch triggers CI, which runs pkgcheck,
mkdir -p /etc/portage/package.accept_keywords # builds the package from the Manifest (fetching the real release asset) and
echo 'dev-util/gitea-runner ~amd64' > /etc/portage/package.accept_keywords/gitea-runner # asserts `gitea-runner --version`. A broken release shows up as a red PR.
emerge -v --getbinpkg "=dev-util/${PN}-${latest}"
gitea-runner --version | grep -q "v${latest}"
git add -A git add -A
git commit -m "dev-util/${PN}: bump to ${latest}" git commit -m "dev-util/${PN}: bump to ${latest}"
git push origin "$branch" git push origin "$branch"
@@ -120,8 +138,7 @@ Review checklist:
- [ ] LICENSE still covers all vendored module licenses (\`go-licenses report ./...\`) - [ ] LICENSE still covers all vendored module licenses (\`go-licenses report ./...\`)
- [ ] BDEPEND Go version matches upstream go.mod (set to >=${goreq:-unchanged}) - [ ] BDEPEND Go version matches upstream go.mod (set to >=${goreq:-unchanged})
- [ ] version ldflags path \`internal/pkg/ver.version\` unchanged upstream - [ ] version ldflags path \`internal/pkg/ver.version\` unchanged upstream
- [ ] CI (pkgcheck + emerge + \`gitea-runner --version\`) is green on this PR
CI build + \`gitea-runner --version\` passed in this workflow.
EOF EOF
) )
api -X POST -H 'Content-Type: application/json' \ api -X POST -H 'Content-Type: application/json' \