azy5030 7dc4ace3d5
CI / lint (push) Successful in 1m58s
CI / build (push) Successful in 6m11s
ci(bump): gate toolchain install behind a cheap version check; fix binpkg verify (#4)
## Why

The daily **Bump** job (`runs/107` and every other scheduled run) does ~5–26 min
of work on every run before it ever checks whether a bump is needed — and on the
common no-op day it isn't. Timeline of a no-op run:

`docker pull stage3` → `emerge-webrsync` → **`emerge … dev-lang/go dev-util/pkgdev` (29 pkgs)** → `bump-version.sh` finds `already at latest` and exits in **1 second**.

`go`/`pkgdev`/`xz`/`jq` are only needed when a bump actually happens. Recent
no-op scheduled runs took 5m, 26m, 9m, 5m, 10m — all to do nothing.

Separately, the log on every emerge was flooded with binpkg GPG failures
(`unknown key`, `pubring.kbx: No such file`, `Try running getuto`). The
`sed 's/^verify-signature = true/.../'` matched nothing in the stage3 binhost
config, so the intended "disable binpkg signature verification" never took
effect (it worked anyway only because the failures are non-fatal).

## What

- **`bump.yaml`**: add a cheap `Check whether a bump is needed` step that compares
  the newest upstream release (`releases.rss`) against the newest committed ebuild
  (Gitea contents API) using only base-image `wget`, and gate `Sync ::gentoo`,
  the toolchain install, and the bump step on its `needed` output. The gate only
  short-circuits when **confident** (both versions parsed and current ≥ upstream);
  on any doubt — failed fetch, unparseable version — it falls through to the full
  run, where `bump-version.sh` remains the source of truth and re-checks.
- **`bump.yaml` + `ci.yaml`**: replace the no-op `sed` with `sed -i '/^verify-signature/d'`
  + append `verify-signature = false`, so the knob is actually set regardless of
  the stage3 default contents.

## Notes / limits

- The job `container:` still pulls `gentoo/stage3` before the gate runs, so the
  ~3.5 min image pull on no-op days is unchanged; this saves the larger
  webrsync + 29-package emerge. A follow-up could split the gate into a separate
  container-less job to skip the pull too, but that depends on what the runner
  maps `runs-on: ubuntu-latest` to, so it's left out here.
- Validated: `yamllint -c .yamllint.yaml` clean on both files; version-comparison
  logic and the contents-API JSON parsing unit-tested locally (equal / upstream-newer /
  current-ahead / parse-failure cases).

🤖 Generated with [Claude Code](https://claude.com/claude-code)

Reviewed-on: #4
Co-authored-by: Ali Zein Yousuf <azy5030@gmail.com>
Co-committed-by: Ali Zein Yousuf <azy5030@gmail.com>
2026-06-19 21:03:06 -05:00
2026-05-20 20:51:48 -05:00

azy5030 overlay

CI

A personal Gentoo ebuild repository (overlay) for packages not in the main ::gentoo tree.

Packages

Package Description
dev-util/gitea-runner Gitea Actions runner (formerly act_runner), built from upstream source with a vendored Go module tree.

Using the overlay

eselect repository add azy5030 git https://git.azy.dev/azy5030/azy5030-overlay.git
emaint sync -r azy5030
echo 'dev-util/gitea-runner ~amd64' >> /etc/portage/package.accept_keywords/gitea-runner
emerge dev-util/gitea-runner

Maintenance

  • .gitea/workflows/ci.yaml builds each package in a gentoo/stage3 container on every push and asserts the resulting binary runs.
  • .gitea/workflows/bump.yaml runs scripts/bump-version.sh daily: it checks the upstream releases feed and, when a newer version exists, regenerates + uploads the vendor tarball, bumps the ebuild, and opens a pull request. Requires a BUMP_TOKEN repository secret (scopes: repository read/write, write release).
S
Description
Collection of packages that I couldn't find anywhere else
Readme 180 KiB
2026-09-25 00:10:42 -05:00
Languages
Shell 74.9%
Just 25.1%