name: Sync Rebuild Triggers on: schedule: # Every 6 hours, off the hour to dodge the scheduling backlog at :00 - cron: '40 */6 * * *' workflow_dispatch: inputs: packages: description: 'Specific packages to update (space-separated, leave empty for all)' required: false default: '' jobs: sync: runs-on: ubuntu-latest permissions: contents: write pull-requests: write outputs: branch: ${{ steps.branch.outputs.branch }} pushed_at: ${{ steps.pushed.outputs.at }} number: ${{ steps.cpr.outputs.pull-request-number }} operation: ${{ steps.cpr.outputs.pull-request-operation }} head_sha: ${{ steps.cpr.outputs.pull-request-head-sha }} steps: - name: Checkout repository uses: actions/checkout@v4 with: persist-credentials: false # A scoped dispatch regenerates only the named packages. Pushed to the # shared branch, that would replace every other pending update in its # PR, so it gets a branch and PR of its own. - name: Choose the PR branch id: branch env: PACKAGES: ${{ github.event.inputs.packages }} run: | read -r -a package_args <<< "${PACKAGES:-}" .github/scripts/sync-pr-branch.sh auto/sync-rebuilds "${package_args[@]}" | tee -a "$GITHUB_OUTPUT" # Runs in an Arch container against the mirror the x86_64 builder itself # uses, because the question being asked is what that builder will link # against and a different mirror can be hours ahead of it. Recording a # version the build never saw is the one failure this command must not # have: nothing re-fires once the record matches. - name: Bump pkgrel for packages whose dependencies moved run: | docker run --rm \ -e PACKAGES="$PACKAGES" \ -e HOST_UID="$(id -u)" \ -e HOST_GID="$(id -g)" \ -v "$PWD/bin:/workspace/bin:ro" \ -v "$PWD/helpers:/workspace/helpers:ro" \ -v "$PWD/pkgbuilds:/workspace/pkgbuilds" \ -w /workspace \ archlinux:base-devel bash -lc ' set -euo pipefail printf "Server = https://mirror.omarchy.org/\$repo/os/\$arch\n" > /etc/pacman.d/mirrorlist pacman -Syu --noconfirm jq groupadd -g "$HOST_GID" runner useradd -m -u "$HOST_UID" -g "$HOST_GID" runner chown -R runner:runner /workspace/pkgbuilds if [[ -n "${PACKAGES:-}" ]]; then read -r -a package_args <<< "$PACKAGES" runuser -u runner -- ./bin/sync-rebuilds "${package_args[@]}" else runuser -u runner -- ./bin/sync-rebuilds fi ' env: PACKAGES: ${{ github.event.inputs.packages }} - name: Check for changes id: changes run: | if [ -z "$(git status --porcelain)" ]; then echo "has_changes=false" >> "$GITHUB_OUTPUT" else echo "has_changes=true" >> "$GITHUB_OUTPUT" fi # Runs created by this push are newer than this; the approve job # waits for them. A minute's slack absorbs runner clock skew. - name: Record push time if: steps.changes.outputs.has_changes == 'true' id: pushed run: echo "at=$(date -u -d '-1 minute' +%Y-%m-%dT%H:%M:%SZ)" >> "$GITHUB_OUTPUT" - name: Create Pull Request if: steps.changes.outputs.has_changes == 'true' id: cpr uses: peter-evans/create-pull-request@v7 with: token: ${{ secrets.GITHUB_TOKEN }} commit-message: 'chore: rebuild against updated dependencies' title: "chore: rebuild against updated dependencies${{ steps.branch.outputs.scope && format(' ({0})', steps.branch.outputs.scope) || '' }}" body: | Automated pkgrel bump for packages that link against a dependency which has moved in the official repositories. Each package names those dependencies in `rebuild_on` and carries the versions its current pkgrel was bumped for in `rebuilt_against`. The bump is what makes the rebuilt package an upgrade pacman will offer; without it the build produces the version already published and no one receives it. branch: ${{ steps.branch.outputs.branch }} delete-branch: true labels: automated reviewers: ryanrhughes - name: Notify Basecamp on failure if: failure() && env.BASECAMP_CHATBOT_URL != '' env: BASECAMP_CHATBOT_URL: ${{ secrets.BASECAMP_CHATBOT_URL }} run: | curl -s -o /dev/null \ -H "Content-Type: application/json" \ -d "$(jq -n --arg content \ "🔴 Rebuild trigger sync failed
View run" \ '{content: $content}')" \ "$BASECAMP_CHATBOT_URL" # GitHub holds pull_request runs from a GITHUB_TOKEN push for approval and # creates no pull_request_target run for it, so approve-pr.yml never sees # the sync's own pushes. Once a maintainer has labelled the PR # build-approved, release the held runs for the commit just pushed. A # separate job, so the sync container's token never holds actions: write. approve: needs: sync if: ${{ !cancelled() && needs.sync.outputs.operation == 'updated' }} runs-on: ubuntu-latest timeout-minutes: 5 permissions: contents: read pull-requests: read actions: write steps: - uses: actions/checkout@v4 with: persist-credentials: false - name: Release held build and test runs if build-approved uses: actions/github-script@v7 env: NUMBER: ${{ needs.sync.outputs.number }} BRANCH: ${{ needs.sync.outputs.branch }} HEAD_SHA: ${{ needs.sync.outputs.head_sha }} SINCE: ${{ needs.sync.outputs.pushed_at }} with: script: | const approve = require('./.github/scripts/approve-sync-push.cjs'); const { NUMBER, BRANCH, HEAD_SHA, SINCE } = process.env; await approve({ github, context, core, number: Number(NUMBER), branch: BRANCH, headSha: HEAD_SHA, since: SINCE });