diff --git a/.gitea/workflows/ci.yaml b/.gitea/workflows/ci.yaml index c2c3f19..b2d7710 100644 --- a/.gitea/workflows/ci.yaml +++ b/.gitea/workflows/ci.yaml @@ -1,5 +1,10 @@ name: CI -on: [push] +# Restrict to branch pushes: an unfiltered `push` also fires for tag refs, +# including the vendor-release tags the bump script creates via the API. +on: + push: + branches: + - '**' jobs: # Lint gate: runs on the plain Docker-backend runner (not the Gentoo diff --git a/.gitea/workflows/vendor-tags.yaml b/.gitea/workflows/vendor-tags.yaml new file mode 100644 index 0000000..af382df --- /dev/null +++ b/.gitea/workflows/vendor-tags.yaml @@ -0,0 +1,43 @@ +name: Vendor tags +# The bump script creates the `${PN}-${ver}-vendor` release (which hosts the +# vendor tarball) *before* the bump commit exists, so its tag can only point at +# whatever master was at the time. The PR is then squash/rebase-merged, so the +# branch commit never lands on master either. This job re-points each vendor +# tag at the master commit that introduced that version's ebuild. It is +# idempotent: a tag already on the right commit is left alone. +# +# Only ever force-*update* a tag here. Deleting a release's tag makes Gitea +# delete the release and its assets, which would break the ebuild's SRC_URI. +on: + push: + branches: + - master + paths: + - 'dev-util/**' + +jobs: + repoint: + runs-on: ubuntu-latest + steps: + - uses: actions/checkout@v4 + with: + fetch-depth: 0 + + - name: Point vendor tags at their bump commits + run: | + set -euo pipefail + git fetch --tags --force origin + for ebuild in dev-util/gitea-runner/gitea-runner-*.ebuild; do + ver=${ebuild##*/gitea-runner-}; ver=${ver%.ebuild} + tag="gitea-runner-${ver}-vendor" + if ! cur=$(git rev-parse --verify -q "refs/tags/${tag}^{commit}"); then + echo "${tag}: no such tag, skipping"; continue + fi + # git mv shows up as an addition of the new path (no --follow). + target=$(git log --diff-filter=A --format=%H -1 -- "$ebuild") + if [ "$cur" = "$target" ]; then + echo "${tag}: already at ${target}"; continue + fi + echo "${tag}: ${cur} -> ${target}" + git push --force origin "${target}:refs/tags/${tag}" + done diff --git a/CLAUDE.md b/CLAUDE.md index 2fc6cdb..2381772 100644 --- a/CLAUDE.md +++ b/CLAUDE.md @@ -52,8 +52,9 @@ re-uploaded as a release asset, or the build will fail Manifest verification. Th 4. `git mv`s the ebuild to the new version, rewrites `BDEPEND`'s Go version from upstream `go.mod`, and regenerates the Manifest with `pkgdev manifest` (after copying both distfiles into `/var/cache/distfiles` and wiring a temporary `repos.conf`). -5. Validates: `pkgcheck scan`, then `emerge` + `gitea-runner --version | grep v${ver}`. -6. Commits, pushes the branch, opens a PR against `master`. +5. Commits, pushes the branch, opens a PR against `master`. The script does **not** + emerge or pkgcheck the result itself: the branch push triggers CI, which does both + (and fetches the real release asset, which the script's local copy never would). Requires a `BUMP_TOKEN` repo secret (scopes: repository read/write, write release) plus a Gentoo env with `go pkgdev git curl xz jq`. @@ -74,6 +75,17 @@ runner executes JS actions by `docker exec node …` *inside* the job container, `gentoo/stage3` ships no node, so any JS action fails with exit 127. The lint job has no `container:`, so it runs in the runner's default node-capable image and checkout works. +## Vendor-tag repointing (`.gitea/workflows/vendor-tags.yaml`) + +The bump script creates the `${PN}-${ver}-vendor` release before the bump commit +exists, so its tag points at whatever `master` was at the time (and squash/rebase +merges mean the branch commit never lands on `master` anyway). On every push to +`master` touching `dev-util/**`, this workflow force-updates each vendor tag whose +ebuild is still in the tree to the `master` commit that added that ebuild. It only +ever *updates* tags: deleting a release's tag makes Gitea delete the release and its +assets, breaking the ebuild's `SRC_URI`. Tag pushes don't re-trigger CI because +`ci.yaml` is filtered to branch pushes. + ## Conventions / gotchas - **YAML** is linted by `.yamllint.yaml` (relaxed: line-length and document-start diff --git a/scripts/bump-version.sh b/scripts/bump-version.sh index 5f9ace6..3c21f70 100755 --- a/scripts/bump-version.sh +++ b/scripts/bump-version.sh @@ -120,13 +120,10 @@ printf '[azy5030]\nlocation = %s\nmasters = gentoo\nauto-sync = false\n' "$WORK" > /etc/portage/repos.conf/azy5030.conf ( cd "${pkgdir}" && pkgdev manifest ) -# --- validate, commit, push, open PR ---------------------------------------- -pkgcheck scan --repo "$WORK" "${pkgdir}" || true -mkdir -p /etc/portage/package.accept_keywords -echo 'dev-util/gitea-runner ~amd64' > /etc/portage/package.accept_keywords/gitea-runner -emerge -v --getbinpkg "=dev-util/${PN}-${latest}" -gitea-runner --version | grep -q "v${latest}" - +# --- commit, push, open PR --------------------------------------------------- +# No emerge/pkgcheck here: pushing the branch triggers CI, which runs pkgcheck, +# builds the package from the Manifest (fetching the real release asset) and +# asserts `gitea-runner --version`. A broken release shows up as a red PR. git add -A git commit -m "dev-util/${PN}: bump to ${latest}" git push origin "$branch" @@ -141,8 +138,7 @@ Review checklist: - [ ] LICENSE still covers all vendored module licenses (\`go-licenses report ./...\`) - [ ] BDEPEND Go version matches upstream go.mod (set to >=${goreq:-unchanged}) - [ ] version ldflags path \`internal/pkg/ver.version\` unchanged upstream - -CI build + \`gitea-runner --version\` passed in this workflow. +- [ ] CI (pkgcheck + emerge + \`gitea-runner --version\`) is green on this PR EOF ) api -X POST -H 'Content-Type: application/json' \