From 6466b9b4131c8a27c4885c471e0930b708425b83 Mon Sep 17 00:00:00 2001 From: alex Date: Fri, 17 Jul 2026 08:27:02 +0200 Subject: [PATCH] ci: add Gitea Actions cron to bump+rebuild on upstream .deb change Daily cron detects a new Cato client .deb, bumps pkgver (resets pkgrel=1), pins the .deb sha256 for integrity, regenerates .SRCINFO, runs makepkg, and pushes the version bump back. Mirrors PKGBUILD's pkgver() for detection. --- .gitea/workflows/bump.yml | 100 ++++++++++++++++++++++++++++++++++++++ 1 file changed, 100 insertions(+) create mode 100644 .gitea/workflows/bump.yml diff --git a/.gitea/workflows/bump.yml b/.gitea/workflows/bump.yml new file mode 100644 index 0000000..934014f --- /dev/null +++ b/.gitea/workflows/bump.yml @@ -0,0 +1,100 @@ +name: bump-and-build + +# Triggers: +# - schedule: a daily cron (Gitea cron is UTC). Tune to taste. +# - workflow_dispatch: run it manually from the Actions tab. +on: + schedule: + - cron: '17 4 * * *' # 04:17 UTC daily + workflow_dispatch: {} + +# The auto-provided GITEA_TOKEN needs write access to push the bump back. +permissions: + contents: write + +jobs: + update: + # Label must match a runner that can run containers. `ubuntu-latest` is the + # default act_runner label; swap for `docker` (or your runner's label) if needed. + runs-on: ubuntu-latest + container: + image: archlinux:base-devel + + steps: + - name: Install build tooling + run: | + set -euo pipefail + pacman -Sy --noconfirm --needed curl libarchive git sudo + + - name: Checkout + uses: https://gitea.com/actions/checkout@v4 + with: + fetch-depth: 0 + + # Mirror PKGBUILD's pkgver() exactly: pull the .deb, read control's Version, + # strip the trailing "-release". Compare against the hardcoded pkgver line. + - name: Detect upstream version + id: ver + run: | + set -euo pipefail + deb_url=$(grep -m1 '^_deb_url=' PKGBUILD | cut -d"'" -f2) + upstream=$(curl -fsSL "$deb_url" \ + | bsdtar -xOf - control.tar.xz \ + | bsdtar -xOf - control \ + | awk -F': ' '/^Version:/ { print $2 }' \ + | sed 's/-release$//' \ + | tr -d '[:space:]') + current=$(grep -m1 '^pkgver=' PKGBUILD | cut -d= -f2) + echo "upstream=${upstream}" >> "$GITHUB_OUTPUT" + echo "current=${current}" >> "$GITHUB_OUTPUT" + echo "Upstream: ${upstream} Current: ${current}" + + - name: Bump PKGBUILD and regenerate .SRCINFO + if: ${{ steps.ver.outputs.upstream != steps.ver.outputs.current }} + env: + UPSTREAM: ${{ steps.ver.outputs.upstream }} + run: | + set -euo pipefail + sed -i "s/^pkgver=.*/pkgver=${UPSTREAM}/" PKGBUILD + sed -i "s/^pkgrel=.*/pkgrel=1/" PKGBUILD + # Pin the upstream .deb's sha256 so the build is integrity-checked. + deb_url=$(grep -m1 '^_deb_url=' PKGBUILD | cut -d"'" -f2) + curl -fsSL "$deb_url" -o /tmp/cato-client-install.deb + deb_sha=$(sha256sum /tmp/cato-client-install.deb | cut -d' ' -f1) + sed -i "s/^ 'SKIP'$/ '${deb_sha}'/" PKGBUILD + makepkg --printsrcinfo > .SRCINFO + + # makepkg refuses to run as root, so build as an unprivileged user. + - name: Build package (makepkg) + if: ${{ steps.ver.outputs.upstream != steps.ver.outputs.current }} + run: | + set -euo pipefail + useradd -m builder + echo 'builder ALL=(ALL) NOPASSWD: ALL' >> /etc/sudoers + chown -R builder . + sudo -u builder makepkg -s --noconfirm + - name: Upload built package as artifact + if: ${{ steps.ver.outputs.upstream != steps.ver.outputs.current }} + continue-on-error: true + uses: https://gitea.com/actions/upload-artifact@v4 + with: + name: cato-client-bin-${{ steps.ver.outputs.upstream }} + path: '*.pkg.tar.zst' + if-no-files-found: warn + + - name: Commit and push the version bump + if: ${{ steps.ver.outputs.upstream != steps.ver.outputs.current }} + env: + UPSTREAM: ${{ steps.ver.outputs.upstream }} + TOKEN: ${{ env.GITEA_TOKEN }} + SERVER: ${{ env.GITEA_SERVER_URL }} + run: | + set -euo pipefail + git config user.email "actions@tesserakt.pro" + git config user.name "Gitea Actions" + git add PKGBUILD .SRCINFO + git commit -m "cato-client-bin: bump to ${UPSTREAM}" + # Push over HTTPS using the workflow token. If your instance rejects the + # 'oauth2' username, switch to '${{ gitea.actor }}:${TOKEN}'. + remote="https://oauth2:${TOKEN}@${SERVER#https://}/${{ gitea.repository }}.git" + git push "${remote}" HEAD:${{ gitea.ref_name }}