Compare commits

..

1 Commits

Author SHA1 Message Date
gitea-actions 4d3aa0d48d dev-util/gitea-runner: bump to 2.3.0
CI / lint (push) Successful in 50s
CI / build (push) Successful in 6m18s
2026-09-20 15:24:05 -05:00
7 changed files with 23 additions and 126 deletions
+1 -22
View File
@@ -2,14 +2,7 @@ name: Bump
on: on:
schedule: schedule:
- cron: '0 5 * * *' - cron: '0 5 * * *'
workflow_dispatch: workflow_dispatch: {}
inputs:
version:
description: >-
Upstream gitea/runner version to bump to (e.g. 3.4.0, no leading
"v"). Leave empty to use the latest upstream release.
required: false
type: string
jobs: jobs:
bump: bump:
@@ -26,14 +19,7 @@ jobs:
id: check id: check
env: env:
BUMP_TOKEN: ${{ secrets.BUMP_TOKEN }} BUMP_TOKEN: ${{ secrets.BUMP_TOKEN }}
BUMP_VERSION: ${{ inputs.version }}
run: | run: |
# An explicitly requested version always runs the full bump.
if [ -n "${BUMP_VERSION}" ]; then
echo "needed=true" >> "$GITHUB_OUTPUT"
echo "explicit version requested: ${BUMP_VERSION}"
exit 0
fi
latest=$(wget -qO- https://gitea.com/gitea/runner/releases.rss \ latest=$(wget -qO- https://gitea.com/gitea/runner/releases.rss \
| grep -oE '<title>v[0-9]+\.[0-9]+\.[0-9]+</title>' \ | grep -oE '<title>v[0-9]+\.[0-9]+\.[0-9]+</title>' \
| head -1 | sed -E 's#</?title>##g; s/^v//') | head -1 | sed -E 's#</?title>##g; s/^v//')
@@ -65,12 +51,6 @@ jobs:
> /etc/portage/repos.conf/gentoo.conf > /etc/portage/repos.conf/gentoo.conf
sed -i '/^verify-signature/d' /etc/portage/binrepos.conf/gentoo.conf sed -i '/^verify-signature/d' /etc/portage/binrepos.conf/gentoo.conf
printf '\nverify-signature = false\n' >> /etc/portage/binrepos.conf/gentoo.conf printf '\nverify-signature = false\n' >> /etc/portage/binrepos.conf/gentoo.conf
# Upstream's go.mod can require a Go that Gentoo only has under
# ~amd64 (GOTOOLCHAIN=local forbids auto-download), so accept the
# testing-keyworded dev-lang/go. It is built from source when no
# stable binpkg satisfies the requirement.
mkdir -p /etc/portage/package.accept_keywords
echo 'dev-lang/go ~amd64' > /etc/portage/package.accept_keywords/go
emerge -q --getbinpkg \ emerge -q --getbinpkg \
dev-vcs/git net-misc/curl app-arch/xz-utils app-misc/jq \ dev-vcs/git net-misc/curl app-arch/xz-utils app-misc/jq \
dev-lang/go dev-util/pkgdev dev-lang/go dev-util/pkgdev
@@ -79,7 +59,6 @@ jobs:
if: steps.check.outputs.needed == 'true' if: steps.check.outputs.needed == 'true'
env: env:
BUMP_TOKEN: ${{ secrets.BUMP_TOKEN }} BUMP_TOKEN: ${{ secrets.BUMP_TOKEN }}
BUMP_VERSION: ${{ inputs.version }}
run: | run: |
host=${GITHUB_SERVER_URL#http://}; host=${host#https://} host=${GITHUB_SERVER_URL#http://}; host=${host#https://}
curl -fsSL "http://x-access-token:${BUMP_TOKEN}@${host}/${GITHUB_REPOSITORY}/raw/branch/master/scripts/bump-version.sh" \ curl -fsSL "http://x-access-token:${BUMP_TOKEN}@${host}/${GITHUB_REPOSITORY}/raw/branch/master/scripts/bump-version.sh" \
+1 -11
View File
@@ -1,10 +1,5 @@
name: CI name: CI
# Restrict to branch pushes: an unfiltered `push` also fires for tag refs, on: [push]
# including the vendor-release tags the bump script creates via the API.
on:
push:
branches:
- '**'
jobs: jobs:
# Lint gate: runs on the plain Docker-backend runner (not the Gentoo # Lint gate: runs on the plain Docker-backend runner (not the Gentoo
@@ -86,11 +81,6 @@ jobs:
> /etc/portage/repos.conf/azy5030.conf > /etc/portage/repos.conf/azy5030.conf
mkdir -p /etc/portage/package.accept_keywords mkdir -p /etc/portage/package.accept_keywords
echo 'dev-util/gitea-runner ~amd64' > /etc/portage/package.accept_keywords/gitea-runner echo 'dev-util/gitea-runner ~amd64' > /etc/portage/package.accept_keywords/gitea-runner
# Upstream tracks new Go releases faster than Gentoo stabilises them
# (the ebuild's BDEPEND follows upstream go.mod), so accept the
# testing-keyworded dev-lang/go. No stable binpkg exists for it, so
# this compiles Go from source when a newer one is required.
echo 'dev-lang/go ~amd64' > /etc/portage/package.accept_keywords/go
- name: QA scan - name: QA scan
run: pkgcheck scan --repo /var/db/repos/azy5030 dev-util/gitea-runner run: pkgcheck scan --repo /var/db/repos/azy5030 dev-util/gitea-runner
-43
View File
@@ -1,43 +0,0 @@
name: Vendor tags
# The bump script creates the `${PN}-${ver}-vendor` release (which hosts the
# vendor tarball) *before* the bump commit exists, so its tag can only point at
# whatever master was at the time. The PR is then squash/rebase-merged, so the
# branch commit never lands on master either. This job re-points each vendor
# tag at the master commit that introduced that version's ebuild. It is
# idempotent: a tag already on the right commit is left alone.
#
# Only ever force-*update* a tag here. Deleting a release's tag makes Gitea
# delete the release and its assets, which would break the ebuild's SRC_URI.
on:
push:
branches:
- master
paths:
- 'dev-util/**'
jobs:
repoint:
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@v4
with:
fetch-depth: 0
- name: Point vendor tags at their bump commits
run: |
set -euo pipefail
git fetch --tags --force origin
for ebuild in dev-util/gitea-runner/gitea-runner-*.ebuild; do
ver=${ebuild##*/gitea-runner-}; ver=${ver%.ebuild}
tag="gitea-runner-${ver}-vendor"
if ! cur=$(git rev-parse --verify -q "refs/tags/${tag}^{commit}"); then
echo "${tag}: no such tag, skipping"; continue
fi
# git mv shows up as an addition of the new path (no --follow).
target=$(git log --diff-filter=A --format=%H -1 -- "$ebuild")
if [ "$cur" = "$target" ]; then
echo "${tag}: already at ${target}"; continue
fi
echo "${tag}: ${cur} -> ${target}"
git push --force origin "${target}:refs/tags/${tag}"
done
+2 -14
View File
@@ -52,9 +52,8 @@ re-uploaded as a release asset, or the build will fail Manifest verification. Th
4. `git mv`s the ebuild to the new version, rewrites `BDEPEND`'s Go version from 4. `git mv`s the ebuild to the new version, rewrites `BDEPEND`'s Go version from
upstream `go.mod`, and regenerates the Manifest with `pkgdev manifest` (after copying upstream `go.mod`, and regenerates the Manifest with `pkgdev manifest` (after copying
both distfiles into `/var/cache/distfiles` and wiring a temporary `repos.conf`). both distfiles into `/var/cache/distfiles` and wiring a temporary `repos.conf`).
5. Commits, pushes the branch, opens a PR against `master`. The script does **not** 5. Validates: `pkgcheck scan`, then `emerge` + `gitea-runner --version | grep v${ver}`.
emerge or pkgcheck the result itself: the branch push triggers CI, which does both 6. Commits, pushes the branch, opens a PR against `master`.
(and fetches the real release asset, which the script's local copy never would).
Requires a `BUMP_TOKEN` repo secret (scopes: repository read/write, write release) plus Requires a `BUMP_TOKEN` repo secret (scopes: repository read/write, write release) plus
a Gentoo env with `go pkgdev git curl xz jq`. a Gentoo env with `go pkgdev git curl xz jq`.
@@ -75,17 +74,6 @@ runner executes JS actions by `docker exec node …` *inside* the job container,
`gentoo/stage3` ships no node, so any JS action fails with exit 127. The lint job has no `gentoo/stage3` ships no node, so any JS action fails with exit 127. The lint job has no
`container:`, so it runs in the runner's default node-capable image and checkout works. `container:`, so it runs in the runner's default node-capable image and checkout works.
## Vendor-tag repointing (`.gitea/workflows/vendor-tags.yaml`)
The bump script creates the `${PN}-${ver}-vendor` release before the bump commit
exists, so its tag points at whatever `master` was at the time (and squash/rebase
merges mean the branch commit never lands on `master` anyway). On every push to
`master` touching `dev-util/**`, this workflow force-updates each vendor tag whose
ebuild is still in the tree to the `master` commit that added that ebuild. It only
ever *updates* tags: deleting a release's tag makes Gitea delete the release and its
assets, breaking the ebuild's `SRC_URI`. Tag pushes don't re-trigger CI because
`ci.yaml` is filtered to branch pushes.
## Conventions / gotchas ## Conventions / gotchas
- **YAML** is linted by `.yamllint.yaml` (relaxed: line-length and document-start - **YAML** is linted by `.yamllint.yaml` (relaxed: line-length and document-start
+2 -2
View File
@@ -1,2 +1,2 @@
DIST gitea-runner-3.4.2-vendor.tar.xz 3278360 BLAKE2B f6bc131ffd37d4d2021d8eaba1d74f2926aece0a7cf4cd0326058282c39a28e3bfc08c4bbd26696b0c1764c12ddd68160260b0366bbcf280d1e82ba4190c6c16 SHA512 823bb450f2ee714e9514f8d0c5f70744dc5322d06d9dab09abcefa25fcc15826a02eb0b7608f382ff5922a96277f0182d3db22dd265deb1c7ccf57d0103665b1 DIST gitea-runner-2.3.0-vendor.tar.xz 3074844 BLAKE2B fc0084749e1bef15bd935da31262ba357a1bdeb21232561280d6dbbb7f0b8ad0a29b111d1168f8562e879da9dd1c75a6cf43a45a98e113627ea374384be89aaf SHA512 9276727f2988a49e6f006aa5baf6244aa84a4aaea2a62cd91e6be7a7131952b60141584c325eca333e15f1f7815ec40378d745b86f3c4627158564af47c23f11
DIST gitea-runner-3.4.2.tar.gz 505523 BLAKE2B 07dcbaaf7969a54f002b5047edd07d2c8e6d2df09383c5dda011cf48291f04ee01fe35b6ce8c6b32c4d7695da5b93ea419048da73977f6133b40f282ad60c431 SHA512 ec1564d179c2319c3923f9c6e27e2c1a4fc00cff996ccaf545e3e6adb9946b8c836d4735377ffceb26a26d9cc77779e4a28e8dd4f4e29c3a6da46efe95907d0e DIST gitea-runner-2.3.0.tar.gz 428155 BLAKE2B 82466ad63de998054d756d506efbfd558b474d6fb05ff7a4ee2ec9e94684274d7b6057bf6332f42284dfa24613f3e16737d447dd82dc94145e130e347de02004 SHA512 68ac5129b90f01720fd04a02c4bfa4dc52724d55382904325d8b4a159cc13fcf8b30a78a0f50048968a4ea59f63e4d8f679737bdd1788087df2c036edf2011fc
@@ -19,7 +19,7 @@ LICENSE="MIT Apache-2.0 BSD BSD-2 ISC MPL-2.0"
SLOT="0" SLOT="0"
KEYWORDS="~amd64" KEYWORDS="~amd64"
BDEPEND=">=dev-lang/go-1.27" BDEPEND=">=dev-lang/go-1.26.0"
# The runner shells out to the docker client for the Docker backend. # The runner shells out to the docker client for the Docker backend.
RDEPEND="app-containers/docker-cli" RDEPEND="app-containers/docker-cli"
+16 -33
View File
@@ -6,17 +6,12 @@
# Expects a Gentoo environment with: go, pkgdev, git, curl, xz, jq. # Expects a Gentoo environment with: go, pkgdev, git, curl, xz, jq.
# Required env: BUMP_TOKEN, GITHUB_SERVER_URL, GITHUB_REPOSITORY. # Required env: BUMP_TOKEN, GITHUB_SERVER_URL, GITHUB_REPOSITORY.
# Optional env: GITHUB_API_URL (defaults to ${GITHUB_SERVER_URL}/api/v1). # Optional env: GITHUB_API_URL (defaults to ${GITHUB_SERVER_URL}/api/v1).
# BUMP_VERSION target a specific upstream version (X.Y.Z, no
# leading "v") instead of the latest release. An
# explicit target may be older than the current
# ebuild (useful to back out of a broken release).
set -euo pipefail set -euo pipefail
PN="gitea-runner" PN="gitea-runner"
UPSTREAM_RSS="https://gitea.com/gitea/runner/releases.rss" UPSTREAM_RSS="https://gitea.com/gitea/runner/releases.rss"
UPSTREAM_ARCHIVE="https://gitea.com/api/v1/repos/gitea/runner/archive" UPSTREAM_ARCHIVE="https://gitea.com/api/v1/repos/gitea/runner/archive"
UPSTREAM_GOMOD="https://gitea.com/api/v1/repos/gitea/runner/raw/go.mod" UPSTREAM_GOMOD="https://gitea.com/api/v1/repos/gitea/runner/raw/go.mod"
UPSTREAM_TAGS="https://gitea.com/api/v1/repos/gitea/runner/tags"
: "${BUMP_TOKEN:?BUMP_TOKEN is required}" : "${BUMP_TOKEN:?BUMP_TOKEN is required}"
: "${GITHUB_SERVER_URL:?GITHUB_SERVER_URL is required}" : "${GITHUB_SERVER_URL:?GITHUB_SERVER_URL is required}"
@@ -30,22 +25,10 @@ host="${GITHUB_SERVER_URL#*://}"
api() { curl -fsSL -H "Authorization: token ${BUMP_TOKEN}" "$@"; } api() { curl -fsSL -H "Authorization: token ${BUMP_TOKEN}" "$@"; }
# --- determine versions ------------------------------------------------------ # --- determine versions ------------------------------------------------------
if [ -n "${BUMP_VERSION:-}" ]; then latest=$(curl -fsSL "$UPSTREAM_RSS" \
latest="${BUMP_VERSION#v}" | grep -oE '<title>v[0-9]+\.[0-9]+\.[0-9]+</title>' \
echo "$latest" | grep -qE '^[0-9]+\.[0-9]+\.[0-9]+$' \ | head -1 | sed -E 's#</?title>##g; s/^v//')
|| { echo "BUMP_VERSION must look like X.Y.Z (got '${BUMP_VERSION}')"; exit 1; } [ -n "$latest" ] || { echo "could not parse upstream version"; exit 1; }
# Fail fast if the tag doesn't exist upstream, before cloning anything.
# (The raw endpoint silently falls back to the default branch for an
# unknown ref, so ask the tags API, which 404s.)
curl -fsSL "${UPSTREAM_TAGS}/v${latest}" -o /dev/null \
|| { echo "upstream tag v${latest} not found"; exit 1; }
echo "targeting explicit version ${latest}"
else
latest=$(curl -fsSL "$UPSTREAM_RSS" \
| grep -oE '<title>v[0-9]+\.[0-9]+\.[0-9]+</title>' \
| head -1 | sed -E 's#</?title>##g; s/^v//')
[ -n "$latest" ] || { echo "could not parse upstream version"; exit 1; }
fi
WORK=$(mktemp -d) WORK=$(mktemp -d)
git clone "${scheme}://x-access-token:${BUMP_TOKEN}@${host}/${GITHUB_REPOSITORY}.git" "$WORK" git clone "${scheme}://x-access-token:${BUMP_TOKEN}@${host}/${GITHUB_REPOSITORY}.git" "$WORK"
@@ -56,15 +39,11 @@ current=$(find "$pkgdir" -name "${PN}-*.ebuild" \
| sed -E "s#.*/${PN}-(.*)\.ebuild#\1#" | sort -V | tail -1) | sed -E "s#.*/${PN}-(.*)\.ebuild#\1#" | sort -V | tail -1)
echo "upstream=${latest} current=${current}" echo "upstream=${latest} current=${current}"
[ "$latest" != "$current" ] || { echo "already at ${latest}"; exit 0; }
newest=$(printf '%s\n%s\n' "$current" "$latest" | sort -V | tail -1) newest=$(printf '%s\n%s\n' "$current" "$latest" | sort -V | tail -1)
if [ "$newest" = "$current" ]; then if [ "$newest" = "$current" ] && [ "$latest" != "$current" ]; then
if [ -n "${BUMP_VERSION:-}" ]; then echo "current ($current) is newer than upstream ($latest); nothing to do"; exit 0
echo "warning: explicit target ${latest} is older than current ${current}; downgrading"
else
echo "current ($current) is newer than upstream ($latest); nothing to do"; exit 0
fi
fi fi
[ "$latest" != "$current" ] || { echo "already at latest ($current)"; exit 0; }
branch="bump/${PN}-${latest}" branch="bump/${PN}-${latest}"
if api "${API}/repos/${GITHUB_REPOSITORY}/branches/${branch}" >/dev/null 2>&1; then if api "${API}/repos/${GITHUB_REPOSITORY}/branches/${branch}" >/dev/null 2>&1; then
@@ -120,10 +99,13 @@ printf '[azy5030]\nlocation = %s\nmasters = gentoo\nauto-sync = false\n' "$WORK"
> /etc/portage/repos.conf/azy5030.conf > /etc/portage/repos.conf/azy5030.conf
( cd "${pkgdir}" && pkgdev manifest ) ( cd "${pkgdir}" && pkgdev manifest )
# --- commit, push, open PR --------------------------------------------------- # --- validate, commit, push, open PR ----------------------------------------
# No emerge/pkgcheck here: pushing the branch triggers CI, which runs pkgcheck, pkgcheck scan --repo "$WORK" "${pkgdir}" || true
# builds the package from the Manifest (fetching the real release asset) and mkdir -p /etc/portage/package.accept_keywords
# asserts `gitea-runner --version`. A broken release shows up as a red PR. echo 'dev-util/gitea-runner ~amd64' > /etc/portage/package.accept_keywords/gitea-runner
emerge -v --getbinpkg "=dev-util/${PN}-${latest}"
gitea-runner --version | grep -q "v${latest}"
git add -A git add -A
git commit -m "dev-util/${PN}: bump to ${latest}" git commit -m "dev-util/${PN}: bump to ${latest}"
git push origin "$branch" git push origin "$branch"
@@ -138,7 +120,8 @@ Review checklist:
- [ ] LICENSE still covers all vendored module licenses (\`go-licenses report ./...\`) - [ ] LICENSE still covers all vendored module licenses (\`go-licenses report ./...\`)
- [ ] BDEPEND Go version matches upstream go.mod (set to >=${goreq:-unchanged}) - [ ] BDEPEND Go version matches upstream go.mod (set to >=${goreq:-unchanged})
- [ ] version ldflags path \`internal/pkg/ver.version\` unchanged upstream - [ ] version ldflags path \`internal/pkg/ver.version\` unchanged upstream
- [ ] CI (pkgcheck + emerge + \`gitea-runner --version\`) is green on this PR
CI build + \`gitea-runner --version\` passed in this workflow.
EOF EOF
) )
api -X POST -H 'Content-Type: application/json' \ api -X POST -H 'Content-Type: application/json' \