Compare commits
1 Commits
| Author | SHA1 | Date | |
|---|---|---|---|
| 18c6a6a075 |
@@ -2,14 +2,7 @@ name: Bump
|
|||||||
on:
|
on:
|
||||||
schedule:
|
schedule:
|
||||||
- cron: '0 5 * * *'
|
- cron: '0 5 * * *'
|
||||||
workflow_dispatch:
|
workflow_dispatch: {}
|
||||||
inputs:
|
|
||||||
version:
|
|
||||||
description: >-
|
|
||||||
Upstream gitea/runner version to bump to (e.g. 3.4.0, no leading
|
|
||||||
"v"). Leave empty to use the latest upstream release.
|
|
||||||
required: false
|
|
||||||
type: string
|
|
||||||
|
|
||||||
jobs:
|
jobs:
|
||||||
bump:
|
bump:
|
||||||
@@ -26,14 +19,7 @@ jobs:
|
|||||||
id: check
|
id: check
|
||||||
env:
|
env:
|
||||||
BUMP_TOKEN: ${{ secrets.BUMP_TOKEN }}
|
BUMP_TOKEN: ${{ secrets.BUMP_TOKEN }}
|
||||||
BUMP_VERSION: ${{ inputs.version }}
|
|
||||||
run: |
|
run: |
|
||||||
# An explicitly requested version always runs the full bump.
|
|
||||||
if [ -n "${BUMP_VERSION}" ]; then
|
|
||||||
echo "needed=true" >> "$GITHUB_OUTPUT"
|
|
||||||
echo "explicit version requested: ${BUMP_VERSION}"
|
|
||||||
exit 0
|
|
||||||
fi
|
|
||||||
latest=$(wget -qO- https://gitea.com/gitea/runner/releases.rss \
|
latest=$(wget -qO- https://gitea.com/gitea/runner/releases.rss \
|
||||||
| grep -oE '<title>v[0-9]+\.[0-9]+\.[0-9]+</title>' \
|
| grep -oE '<title>v[0-9]+\.[0-9]+\.[0-9]+</title>' \
|
||||||
| head -1 | sed -E 's#</?title>##g; s/^v//')
|
| head -1 | sed -E 's#</?title>##g; s/^v//')
|
||||||
@@ -65,12 +51,6 @@ jobs:
|
|||||||
> /etc/portage/repos.conf/gentoo.conf
|
> /etc/portage/repos.conf/gentoo.conf
|
||||||
sed -i '/^verify-signature/d' /etc/portage/binrepos.conf/gentoo.conf
|
sed -i '/^verify-signature/d' /etc/portage/binrepos.conf/gentoo.conf
|
||||||
printf '\nverify-signature = false\n' >> /etc/portage/binrepos.conf/gentoo.conf
|
printf '\nverify-signature = false\n' >> /etc/portage/binrepos.conf/gentoo.conf
|
||||||
# Upstream's go.mod can require a Go that Gentoo only has under
|
|
||||||
# ~amd64 (GOTOOLCHAIN=local forbids auto-download), so accept the
|
|
||||||
# testing-keyworded dev-lang/go. It is built from source when no
|
|
||||||
# stable binpkg satisfies the requirement.
|
|
||||||
mkdir -p /etc/portage/package.accept_keywords
|
|
||||||
echo 'dev-lang/go ~amd64' > /etc/portage/package.accept_keywords/go
|
|
||||||
emerge -q --getbinpkg \
|
emerge -q --getbinpkg \
|
||||||
dev-vcs/git net-misc/curl app-arch/xz-utils app-misc/jq \
|
dev-vcs/git net-misc/curl app-arch/xz-utils app-misc/jq \
|
||||||
dev-lang/go dev-util/pkgdev
|
dev-lang/go dev-util/pkgdev
|
||||||
@@ -79,7 +59,6 @@ jobs:
|
|||||||
if: steps.check.outputs.needed == 'true'
|
if: steps.check.outputs.needed == 'true'
|
||||||
env:
|
env:
|
||||||
BUMP_TOKEN: ${{ secrets.BUMP_TOKEN }}
|
BUMP_TOKEN: ${{ secrets.BUMP_TOKEN }}
|
||||||
BUMP_VERSION: ${{ inputs.version }}
|
|
||||||
run: |
|
run: |
|
||||||
host=${GITHUB_SERVER_URL#http://}; host=${host#https://}
|
host=${GITHUB_SERVER_URL#http://}; host=${host#https://}
|
||||||
curl -fsSL "http://x-access-token:${BUMP_TOKEN}@${host}/${GITHUB_REPOSITORY}/raw/branch/master/scripts/bump-version.sh" \
|
curl -fsSL "http://x-access-token:${BUMP_TOKEN}@${host}/${GITHUB_REPOSITORY}/raw/branch/master/scripts/bump-version.sh" \
|
||||||
|
|||||||
@@ -1,10 +1,5 @@
|
|||||||
name: CI
|
name: CI
|
||||||
# Restrict to branch pushes: an unfiltered `push` also fires for tag refs,
|
on: [push]
|
||||||
# including the vendor-release tags the bump script creates via the API.
|
|
||||||
on:
|
|
||||||
push:
|
|
||||||
branches:
|
|
||||||
- '**'
|
|
||||||
|
|
||||||
jobs:
|
jobs:
|
||||||
# Lint gate: runs on the plain Docker-backend runner (not the Gentoo
|
# Lint gate: runs on the plain Docker-backend runner (not the Gentoo
|
||||||
@@ -86,11 +81,6 @@ jobs:
|
|||||||
> /etc/portage/repos.conf/azy5030.conf
|
> /etc/portage/repos.conf/azy5030.conf
|
||||||
mkdir -p /etc/portage/package.accept_keywords
|
mkdir -p /etc/portage/package.accept_keywords
|
||||||
echo 'dev-util/gitea-runner ~amd64' > /etc/portage/package.accept_keywords/gitea-runner
|
echo 'dev-util/gitea-runner ~amd64' > /etc/portage/package.accept_keywords/gitea-runner
|
||||||
# Upstream tracks new Go releases faster than Gentoo stabilises them
|
|
||||||
# (the ebuild's BDEPEND follows upstream go.mod), so accept the
|
|
||||||
# testing-keyworded dev-lang/go. No stable binpkg exists for it, so
|
|
||||||
# this compiles Go from source when a newer one is required.
|
|
||||||
echo 'dev-lang/go ~amd64' > /etc/portage/package.accept_keywords/go
|
|
||||||
|
|
||||||
- name: QA scan
|
- name: QA scan
|
||||||
run: pkgcheck scan --repo /var/db/repos/azy5030 dev-util/gitea-runner
|
run: pkgcheck scan --repo /var/db/repos/azy5030 dev-util/gitea-runner
|
||||||
|
|||||||
@@ -1,43 +0,0 @@
|
|||||||
name: Vendor tags
|
|
||||||
# The bump script creates the `${PN}-${ver}-vendor` release (which hosts the
|
|
||||||
# vendor tarball) *before* the bump commit exists, so its tag can only point at
|
|
||||||
# whatever master was at the time. The PR is then squash/rebase-merged, so the
|
|
||||||
# branch commit never lands on master either. This job re-points each vendor
|
|
||||||
# tag at the master commit that introduced that version's ebuild. It is
|
|
||||||
# idempotent: a tag already on the right commit is left alone.
|
|
||||||
#
|
|
||||||
# Only ever force-*update* a tag here. Deleting a release's tag makes Gitea
|
|
||||||
# delete the release and its assets, which would break the ebuild's SRC_URI.
|
|
||||||
on:
|
|
||||||
push:
|
|
||||||
branches:
|
|
||||||
- master
|
|
||||||
paths:
|
|
||||||
- 'dev-util/**'
|
|
||||||
|
|
||||||
jobs:
|
|
||||||
repoint:
|
|
||||||
runs-on: ubuntu-latest
|
|
||||||
steps:
|
|
||||||
- uses: actions/checkout@v4
|
|
||||||
with:
|
|
||||||
fetch-depth: 0
|
|
||||||
|
|
||||||
- name: Point vendor tags at their bump commits
|
|
||||||
run: |
|
|
||||||
set -euo pipefail
|
|
||||||
git fetch --tags --force origin
|
|
||||||
for ebuild in dev-util/gitea-runner/gitea-runner-*.ebuild; do
|
|
||||||
ver=${ebuild##*/gitea-runner-}; ver=${ver%.ebuild}
|
|
||||||
tag="gitea-runner-${ver}-vendor"
|
|
||||||
if ! cur=$(git rev-parse --verify -q "refs/tags/${tag}^{commit}"); then
|
|
||||||
echo "${tag}: no such tag, skipping"; continue
|
|
||||||
fi
|
|
||||||
# git mv shows up as an addition of the new path (no --follow).
|
|
||||||
target=$(git log --diff-filter=A --format=%H -1 -- "$ebuild")
|
|
||||||
if [ "$cur" = "$target" ]; then
|
|
||||||
echo "${tag}: already at ${target}"; continue
|
|
||||||
fi
|
|
||||||
echo "${tag}: ${cur} -> ${target}"
|
|
||||||
git push --force origin "${target}:refs/tags/${tag}"
|
|
||||||
done
|
|
||||||
@@ -52,9 +52,8 @@ re-uploaded as a release asset, or the build will fail Manifest verification. Th
|
|||||||
4. `git mv`s the ebuild to the new version, rewrites `BDEPEND`'s Go version from
|
4. `git mv`s the ebuild to the new version, rewrites `BDEPEND`'s Go version from
|
||||||
upstream `go.mod`, and regenerates the Manifest with `pkgdev manifest` (after copying
|
upstream `go.mod`, and regenerates the Manifest with `pkgdev manifest` (after copying
|
||||||
both distfiles into `/var/cache/distfiles` and wiring a temporary `repos.conf`).
|
both distfiles into `/var/cache/distfiles` and wiring a temporary `repos.conf`).
|
||||||
5. Commits, pushes the branch, opens a PR against `master`. The script does **not**
|
5. Validates: `pkgcheck scan`, then `emerge` + `gitea-runner --version | grep v${ver}`.
|
||||||
emerge or pkgcheck the result itself: the branch push triggers CI, which does both
|
6. Commits, pushes the branch, opens a PR against `master`.
|
||||||
(and fetches the real release asset, which the script's local copy never would).
|
|
||||||
|
|
||||||
Requires a `BUMP_TOKEN` repo secret (scopes: repository read/write, write release) plus
|
Requires a `BUMP_TOKEN` repo secret (scopes: repository read/write, write release) plus
|
||||||
a Gentoo env with `go pkgdev git curl xz jq`.
|
a Gentoo env with `go pkgdev git curl xz jq`.
|
||||||
@@ -75,17 +74,6 @@ runner executes JS actions by `docker exec node …` *inside* the job container,
|
|||||||
`gentoo/stage3` ships no node, so any JS action fails with exit 127. The lint job has no
|
`gentoo/stage3` ships no node, so any JS action fails with exit 127. The lint job has no
|
||||||
`container:`, so it runs in the runner's default node-capable image and checkout works.
|
`container:`, so it runs in the runner's default node-capable image and checkout works.
|
||||||
|
|
||||||
## Vendor-tag repointing (`.gitea/workflows/vendor-tags.yaml`)
|
|
||||||
|
|
||||||
The bump script creates the `${PN}-${ver}-vendor` release before the bump commit
|
|
||||||
exists, so its tag points at whatever `master` was at the time (and squash/rebase
|
|
||||||
merges mean the branch commit never lands on `master` anyway). On every push to
|
|
||||||
`master` touching `dev-util/**`, this workflow force-updates each vendor tag whose
|
|
||||||
ebuild is still in the tree to the `master` commit that added that ebuild. It only
|
|
||||||
ever *updates* tags: deleting a release's tag makes Gitea delete the release and its
|
|
||||||
assets, breaking the ebuild's `SRC_URI`. Tag pushes don't re-trigger CI because
|
|
||||||
`ci.yaml` is filtered to branch pushes.
|
|
||||||
|
|
||||||
## Conventions / gotchas
|
## Conventions / gotchas
|
||||||
|
|
||||||
- **YAML** is linted by `.yamllint.yaml` (relaxed: line-length and document-start
|
- **YAML** is linted by `.yamllint.yaml` (relaxed: line-length and document-start
|
||||||
|
|||||||
@@ -1,2 +1,2 @@
|
|||||||
DIST gitea-runner-3.5.0-vendor.tar.xz 3263236 BLAKE2B 747cf45afebd2b1c3c5b44d2f9335e2b787db0fd5fbc14195346ba84250dfec69dd34e64221a015db3973cd7cbc796c58d704e00efd7cd8aba3628e896794244 SHA512 d881dafa3dd09d9d20e138e19a38c8bc82fe2eef90885db7a9a8fe1eac531470a55ac61be870e37b9b1b9807b71f1ce765d0c6b4b373d0c94032ff322fd6ac20
|
DIST gitea-runner-3.0.2-vendor.tar.xz 3214304 BLAKE2B d60382f0675bc1d234fc5e880a717d12d0be73abf0012e6a08b301afc8f3333e6ef04d04d60aebbb8ea3280e81c9c5edbde8453fd83299ee57ae86ad587f3a28 SHA512 8327c5befc2dc8681cf9bc6d50ed3395e5c08de7a3d19e284a55667e92e2acd4c802fe4c028f14528f00ed1704321f224370e6cdbc04a4252dccfada9b66ec40
|
||||||
DIST gitea-runner-3.5.0.tar.gz 516558 BLAKE2B 262e7e6383f99c61f6e3bdf6b72e8916ae1ea916f789b2b8a3db36e332bc4a2ed3f3c662d052fe9eb9ab802ae634938c360c7d5d82afd63f38580d344c786ef7 SHA512 0b2697ad8b481125cce52fbdd2cb38c4cb6a13df016646d332a6676573e38bc2e4beee711ed629f392ce6d1b8a19e6006d1009024bfa2866aabfe8dc2258b5c2
|
DIST gitea-runner-3.0.2.tar.gz 477392 BLAKE2B fc88a350e205b4cff65458763016048a0c40731d6160877820ef8626d6f107058d24a5c153b8d0a26a1e0f7d2164ee198b2743343052b154b2f9f1b4418ade1d SHA512 d7b1832086961e6737f0e6366b78218b5928609d6c0ac03ebe7709a2ac6cdfc7efe27d12eef57122d1d785a98ea4b9b1d981bddbd8a4b72e2626f3a9d1e9e522
|
||||||
|
|||||||
+1
-1
@@ -19,7 +19,7 @@ LICENSE="MIT Apache-2.0 BSD BSD-2 ISC MPL-2.0"
|
|||||||
SLOT="0"
|
SLOT="0"
|
||||||
KEYWORDS="~amd64"
|
KEYWORDS="~amd64"
|
||||||
|
|
||||||
BDEPEND=">=dev-lang/go-1.27"
|
BDEPEND=">=dev-lang/go-1.26.0"
|
||||||
# The runner shells out to the docker client for the Docker backend.
|
# The runner shells out to the docker client for the Docker backend.
|
||||||
RDEPEND="app-containers/docker-cli"
|
RDEPEND="app-containers/docker-cli"
|
||||||
|
|
||||||
+16
-33
@@ -6,17 +6,12 @@
|
|||||||
# Expects a Gentoo environment with: go, pkgdev, git, curl, xz, jq.
|
# Expects a Gentoo environment with: go, pkgdev, git, curl, xz, jq.
|
||||||
# Required env: BUMP_TOKEN, GITHUB_SERVER_URL, GITHUB_REPOSITORY.
|
# Required env: BUMP_TOKEN, GITHUB_SERVER_URL, GITHUB_REPOSITORY.
|
||||||
# Optional env: GITHUB_API_URL (defaults to ${GITHUB_SERVER_URL}/api/v1).
|
# Optional env: GITHUB_API_URL (defaults to ${GITHUB_SERVER_URL}/api/v1).
|
||||||
# BUMP_VERSION target a specific upstream version (X.Y.Z, no
|
|
||||||
# leading "v") instead of the latest release. An
|
|
||||||
# explicit target may be older than the current
|
|
||||||
# ebuild (useful to back out of a broken release).
|
|
||||||
set -euo pipefail
|
set -euo pipefail
|
||||||
|
|
||||||
PN="gitea-runner"
|
PN="gitea-runner"
|
||||||
UPSTREAM_RSS="https://gitea.com/gitea/runner/releases.rss"
|
UPSTREAM_RSS="https://gitea.com/gitea/runner/releases.rss"
|
||||||
UPSTREAM_ARCHIVE="https://gitea.com/api/v1/repos/gitea/runner/archive"
|
UPSTREAM_ARCHIVE="https://gitea.com/api/v1/repos/gitea/runner/archive"
|
||||||
UPSTREAM_GOMOD="https://gitea.com/api/v1/repos/gitea/runner/raw/go.mod"
|
UPSTREAM_GOMOD="https://gitea.com/api/v1/repos/gitea/runner/raw/go.mod"
|
||||||
UPSTREAM_TAGS="https://gitea.com/api/v1/repos/gitea/runner/tags"
|
|
||||||
|
|
||||||
: "${BUMP_TOKEN:?BUMP_TOKEN is required}"
|
: "${BUMP_TOKEN:?BUMP_TOKEN is required}"
|
||||||
: "${GITHUB_SERVER_URL:?GITHUB_SERVER_URL is required}"
|
: "${GITHUB_SERVER_URL:?GITHUB_SERVER_URL is required}"
|
||||||
@@ -30,22 +25,10 @@ host="${GITHUB_SERVER_URL#*://}"
|
|||||||
api() { curl -fsSL -H "Authorization: token ${BUMP_TOKEN}" "$@"; }
|
api() { curl -fsSL -H "Authorization: token ${BUMP_TOKEN}" "$@"; }
|
||||||
|
|
||||||
# --- determine versions ------------------------------------------------------
|
# --- determine versions ------------------------------------------------------
|
||||||
if [ -n "${BUMP_VERSION:-}" ]; then
|
latest=$(curl -fsSL "$UPSTREAM_RSS" \
|
||||||
latest="${BUMP_VERSION#v}"
|
| grep -oE '<title>v[0-9]+\.[0-9]+\.[0-9]+</title>' \
|
||||||
echo "$latest" | grep -qE '^[0-9]+\.[0-9]+\.[0-9]+$' \
|
| head -1 | sed -E 's#</?title>##g; s/^v//')
|
||||||
|| { echo "BUMP_VERSION must look like X.Y.Z (got '${BUMP_VERSION}')"; exit 1; }
|
[ -n "$latest" ] || { echo "could not parse upstream version"; exit 1; }
|
||||||
# Fail fast if the tag doesn't exist upstream, before cloning anything.
|
|
||||||
# (The raw endpoint silently falls back to the default branch for an
|
|
||||||
# unknown ref, so ask the tags API, which 404s.)
|
|
||||||
curl -fsSL "${UPSTREAM_TAGS}/v${latest}" -o /dev/null \
|
|
||||||
|| { echo "upstream tag v${latest} not found"; exit 1; }
|
|
||||||
echo "targeting explicit version ${latest}"
|
|
||||||
else
|
|
||||||
latest=$(curl -fsSL "$UPSTREAM_RSS" \
|
|
||||||
| grep -oE '<title>v[0-9]+\.[0-9]+\.[0-9]+</title>' \
|
|
||||||
| head -1 | sed -E 's#</?title>##g; s/^v//')
|
|
||||||
[ -n "$latest" ] || { echo "could not parse upstream version"; exit 1; }
|
|
||||||
fi
|
|
||||||
|
|
||||||
WORK=$(mktemp -d)
|
WORK=$(mktemp -d)
|
||||||
git clone "${scheme}://x-access-token:${BUMP_TOKEN}@${host}/${GITHUB_REPOSITORY}.git" "$WORK"
|
git clone "${scheme}://x-access-token:${BUMP_TOKEN}@${host}/${GITHUB_REPOSITORY}.git" "$WORK"
|
||||||
@@ -56,15 +39,11 @@ current=$(find "$pkgdir" -name "${PN}-*.ebuild" \
|
|||||||
| sed -E "s#.*/${PN}-(.*)\.ebuild#\1#" | sort -V | tail -1)
|
| sed -E "s#.*/${PN}-(.*)\.ebuild#\1#" | sort -V | tail -1)
|
||||||
echo "upstream=${latest} current=${current}"
|
echo "upstream=${latest} current=${current}"
|
||||||
|
|
||||||
[ "$latest" != "$current" ] || { echo "already at ${latest}"; exit 0; }
|
|
||||||
newest=$(printf '%s\n%s\n' "$current" "$latest" | sort -V | tail -1)
|
newest=$(printf '%s\n%s\n' "$current" "$latest" | sort -V | tail -1)
|
||||||
if [ "$newest" = "$current" ]; then
|
if [ "$newest" = "$current" ] && [ "$latest" != "$current" ]; then
|
||||||
if [ -n "${BUMP_VERSION:-}" ]; then
|
echo "current ($current) is newer than upstream ($latest); nothing to do"; exit 0
|
||||||
echo "warning: explicit target ${latest} is older than current ${current}; downgrading"
|
|
||||||
else
|
|
||||||
echo "current ($current) is newer than upstream ($latest); nothing to do"; exit 0
|
|
||||||
fi
|
|
||||||
fi
|
fi
|
||||||
|
[ "$latest" != "$current" ] || { echo "already at latest ($current)"; exit 0; }
|
||||||
|
|
||||||
branch="bump/${PN}-${latest}"
|
branch="bump/${PN}-${latest}"
|
||||||
if api "${API}/repos/${GITHUB_REPOSITORY}/branches/${branch}" >/dev/null 2>&1; then
|
if api "${API}/repos/${GITHUB_REPOSITORY}/branches/${branch}" >/dev/null 2>&1; then
|
||||||
@@ -120,10 +99,13 @@ printf '[azy5030]\nlocation = %s\nmasters = gentoo\nauto-sync = false\n' "$WORK"
|
|||||||
> /etc/portage/repos.conf/azy5030.conf
|
> /etc/portage/repos.conf/azy5030.conf
|
||||||
( cd "${pkgdir}" && pkgdev manifest )
|
( cd "${pkgdir}" && pkgdev manifest )
|
||||||
|
|
||||||
# --- commit, push, open PR ---------------------------------------------------
|
# --- validate, commit, push, open PR ----------------------------------------
|
||||||
# No emerge/pkgcheck here: pushing the branch triggers CI, which runs pkgcheck,
|
pkgcheck scan --repo "$WORK" "${pkgdir}" || true
|
||||||
# builds the package from the Manifest (fetching the real release asset) and
|
mkdir -p /etc/portage/package.accept_keywords
|
||||||
# asserts `gitea-runner --version`. A broken release shows up as a red PR.
|
echo 'dev-util/gitea-runner ~amd64' > /etc/portage/package.accept_keywords/gitea-runner
|
||||||
|
emerge -v --getbinpkg "=dev-util/${PN}-${latest}"
|
||||||
|
gitea-runner --version | grep -q "v${latest}"
|
||||||
|
|
||||||
git add -A
|
git add -A
|
||||||
git commit -m "dev-util/${PN}: bump to ${latest}"
|
git commit -m "dev-util/${PN}: bump to ${latest}"
|
||||||
git push origin "$branch"
|
git push origin "$branch"
|
||||||
@@ -138,7 +120,8 @@ Review checklist:
|
|||||||
- [ ] LICENSE still covers all vendored module licenses (\`go-licenses report ./...\`)
|
- [ ] LICENSE still covers all vendored module licenses (\`go-licenses report ./...\`)
|
||||||
- [ ] BDEPEND Go version matches upstream go.mod (set to >=${goreq:-unchanged})
|
- [ ] BDEPEND Go version matches upstream go.mod (set to >=${goreq:-unchanged})
|
||||||
- [ ] version ldflags path \`internal/pkg/ver.version\` unchanged upstream
|
- [ ] version ldflags path \`internal/pkg/ver.version\` unchanged upstream
|
||||||
- [ ] CI (pkgcheck + emerge + \`gitea-runner --version\`) is green on this PR
|
|
||||||
|
CI build + \`gitea-runner --version\` passed in this workflow.
|
||||||
EOF
|
EOF
|
||||||
)
|
)
|
||||||
api -X POST -H 'Content-Type: application/json' \
|
api -X POST -H 'Content-Type: application/json' \
|
||||||
|
|||||||
Reference in New Issue
Block a user