ci: add Gitea Actions cron to bump+rebuild on upstream .deb change
Some checks failed
bump-and-build / update (push) Failing after 8s

Daily cron detects a new Cato client .deb, bumps pkgver (resets pkgrel=1),
pins the .deb sha256 for integrity, regenerates .SRCINFO, runs makepkg, and
pushes the version bump back. Mirrors PKGBUILD's pkgver() for detection.
This commit is contained in:
2026-07-17 08:27:02 +02:00
parent 97fc99aacf
commit 6466b9b413

100
.gitea/workflows/bump.yml Normal file
View File

@@ -0,0 +1,100 @@
name: bump-and-build
# Triggers:
# - schedule: a daily cron (Gitea cron is UTC). Tune to taste.
# - workflow_dispatch: run it manually from the Actions tab.
on:
schedule:
- cron: '17 4 * * *' # 04:17 UTC daily
workflow_dispatch: {}
# The auto-provided GITEA_TOKEN needs write access to push the bump back.
permissions:
contents: write
jobs:
update:
# Label must match a runner that can run containers. `ubuntu-latest` is the
# default act_runner label; swap for `docker` (or your runner's label) if needed.
runs-on: ubuntu-latest
container:
image: archlinux:base-devel
steps:
- name: Install build tooling
run: |
set -euo pipefail
pacman -Sy --noconfirm --needed curl libarchive git sudo
- name: Checkout
uses: https://gitea.com/actions/checkout@v4
with:
fetch-depth: 0
# Mirror PKGBUILD's pkgver() exactly: pull the .deb, read control's Version,
# strip the trailing "-release". Compare against the hardcoded pkgver line.
- name: Detect upstream version
id: ver
run: |
set -euo pipefail
deb_url=$(grep -m1 '^_deb_url=' PKGBUILD | cut -d"'" -f2)
upstream=$(curl -fsSL "$deb_url" \
| bsdtar -xOf - control.tar.xz \
| bsdtar -xOf - control \
| awk -F': ' '/^Version:/ { print $2 }' \
| sed 's/-release$//' \
| tr -d '[:space:]')
current=$(grep -m1 '^pkgver=' PKGBUILD | cut -d= -f2)
echo "upstream=${upstream}" >> "$GITHUB_OUTPUT"
echo "current=${current}" >> "$GITHUB_OUTPUT"
echo "Upstream: ${upstream} Current: ${current}"
- name: Bump PKGBUILD and regenerate .SRCINFO
if: ${{ steps.ver.outputs.upstream != steps.ver.outputs.current }}
env:
UPSTREAM: ${{ steps.ver.outputs.upstream }}
run: |
set -euo pipefail
sed -i "s/^pkgver=.*/pkgver=${UPSTREAM}/" PKGBUILD
sed -i "s/^pkgrel=.*/pkgrel=1/" PKGBUILD
# Pin the upstream .deb's sha256 so the build is integrity-checked.
deb_url=$(grep -m1 '^_deb_url=' PKGBUILD | cut -d"'" -f2)
curl -fsSL "$deb_url" -o /tmp/cato-client-install.deb
deb_sha=$(sha256sum /tmp/cato-client-install.deb | cut -d' ' -f1)
sed -i "s/^ 'SKIP'$/ '${deb_sha}'/" PKGBUILD
makepkg --printsrcinfo > .SRCINFO
# makepkg refuses to run as root, so build as an unprivileged user.
- name: Build package (makepkg)
if: ${{ steps.ver.outputs.upstream != steps.ver.outputs.current }}
run: |
set -euo pipefail
useradd -m builder
echo 'builder ALL=(ALL) NOPASSWD: ALL' >> /etc/sudoers
chown -R builder .
sudo -u builder makepkg -s --noconfirm
- name: Upload built package as artifact
if: ${{ steps.ver.outputs.upstream != steps.ver.outputs.current }}
continue-on-error: true
uses: https://gitea.com/actions/upload-artifact@v4
with:
name: cato-client-bin-${{ steps.ver.outputs.upstream }}
path: '*.pkg.tar.zst'
if-no-files-found: warn
- name: Commit and push the version bump
if: ${{ steps.ver.outputs.upstream != steps.ver.outputs.current }}
env:
UPSTREAM: ${{ steps.ver.outputs.upstream }}
TOKEN: ${{ env.GITEA_TOKEN }}
SERVER: ${{ env.GITEA_SERVER_URL }}
run: |
set -euo pipefail
git config user.email "actions@tesserakt.pro"
git config user.name "Gitea Actions"
git add PKGBUILD .SRCINFO
git commit -m "cato-client-bin: bump to ${UPSTREAM}"
# Push over HTTPS using the workflow token. If your instance rejects the
# 'oauth2' username, switch to '${{ gitea.actor }}:${TOKEN}'.
remote="https://oauth2:${TOKEN}@${SERVER#https://}/${{ gitea.repository }}.git"
git push "${remote}" HEAD:${{ gitea.ref_name }}