From 0c7e7f3a7bee415f7f45ae4fd778dd795d99c7a8 Mon Sep 17 00:00:00 2001 From: Rick Peters Date: Wed, 30 Sep 2026 12:49:36 +0200 Subject: [PATCH] feat(ci): a build badge in the GitHub release: running, then succeeded / failed / cancelled from the mirror's build --- .github/workflows/iso-1-github-tag.yml | 4 ++- .github/workflows/iso-2-gitea-build.yml | 39 +++++++++++++++++++++++++ AGENTS.md | 5 ++++ 3 files changed, 47 insertions(+), 1 deletion(-) diff --git a/.github/workflows/iso-1-github-tag.yml b/.github/workflows/iso-1-github-tag.yml index 76e9937..32b08cc 100644 --- a/.github/workflows/iso-1-github-tag.yml +++ b/.github/workflows/iso-1-github-tag.yml @@ -57,7 +57,9 @@ jobs: file="steamify-cachyos-${tag#v}-x86_64.iso" dl="$GITEA_URL/$GITEA_REPO/releases/download/$tag" # The Steamify section of CHANGELOG.md ("## CachyOS with Steamify Live ISO"), without its heading. section="$(awk '/^## CachyOS with Steamify Live ISO/ {found = 1; next} found && /^#/ {exit} found' CHANGELOG.md)" - notes="The ISO is built from \`$(git rev-parse --short HEAD)\` (${{ github.ref_name }}) with Steamify $steamify and published on the mirror (GitHub releases take at most 2 GB per file), about half an hour after this release (the mirror's sync, then the build): + notes="![ISO build](https://img.shields.io/badge/ISO_build-running-yellow) + + The ISO is built from \`$(git rev-parse --short HEAD)\` (${{ github.ref_name }}) with Steamify $steamify and published on the mirror (GitHub releases take at most 2 GB per file), about half an hour after this release (the mirror's sync, then the build): **Download: [$file]($dl/$file)** ([SHA-256]($dl/$file.sha256), [release page]($GITEA_URL/$GITEA_REPO/releases/tag/$tag)) diff --git a/.github/workflows/iso-2-gitea-build.yml b/.github/workflows/iso-2-gitea-build.yml index dbe1c2c..dba587b 100644 --- a/.github/workflows/iso-2-gitea-build.yml +++ b/.github/workflows/iso-2-gitea-build.yml @@ -184,3 +184,42 @@ jobs: out/desktop/*.iso.sha256 out/desktop/*.iso.sha1 out/desktop/*.pkgs.txt + + # The result goes back to GitHub: the badge at the top of the GitHub release (started as "running" by iso-1) becomes + # succeeded / failed / cancelled and links to this run. Needs a GitHub token as the secret GH_RELEASE_TOKEN here on the + # mirror (fine-grained, this repository only, Contents: read and write); without it the badge stays "running". + report: + name: Report the result to GitHub + needs: [build, release] + if: ${{ always() && github.server_url != 'https://github.com' }} + runs-on: ubuntu-latest + container: + image: docker.io/cachyos/cachyos:latest + steps: + - name: Badge in the GitHub release + env: + GH_TOKEN: ${{ secrets.GH_RELEASE_TOKEN }} + BUILD: ${{ needs.build.result }} + RELEASE: ${{ needs.release.result }} + run: | + [ -n "$GH_TOKEN" ] || { echo "No GH_RELEASE_TOKEN: GitHub's release keeps its 'running' badge."; exit 0; } + pacman -Sy --noconfirm --needed curl python > /dev/null + tag="${{ github.ref_name }}" + if [ "$BUILD" = success ] && [ "$RELEASE" = success ]; then st=succeeded col=brightgreen + elif [ "$BUILD" = cancelled ] || [ "$RELEASE" = cancelled ]; then st=cancelled col=lightgrey + else st=failed col=red; fi + run="${{ github.server_url }}/${{ github.repository }}/actions/runs/${{ github.run_id }}" + api="https://api.github.com/repos/theupriser/steamify-cachyos-live-iso/releases" + curl -fsS -H "Authorization: Bearer $GH_TOKEN" "$api/tags/$tag" -o /tmp/rel.json || { echo "::warning::no GitHub release for $tag"; exit 0; } + ST="$st" COL="$col" RUN="$run" python3 - << 'PY' + import json, os, re + d = json.load(open("/tmp/rel.json")) + badge = f"[![ISO build](https://img.shields.io/badge/ISO_build-{os.environ['ST']}-{os.environ['COL']})]({os.environ['RUN']})" + body = d.get("body") or "" + pat = re.compile(r"\[?!\[ISO build\]\([^)]*\)(\]\([^)]*\))?") + body = pat.sub(lambda m: badge, body, count=1) if pat.search(body) else badge + "\n\n" + body + json.dump({"body": body}, open("/tmp/patch.json", "w")) + open("/tmp/rel.id", "w").write(str(d["id"])) + PY + curl -fsS -X PATCH -H "Authorization: Bearer $GH_TOKEN" -H "Content-Type: application/json" -d @/tmp/patch.json "$api/$(cat /tmp/rel.id)" > /dev/null + echo "GitHub release $tag: ISO build $st" diff --git a/AGENTS.md b/AGENTS.md index a79d379..0600ad6 100644 --- a/AGENTS.md +++ b/AGENTS.md @@ -134,3 +134,8 @@ Full write-up, with every trap: `steamify-iso-release` in steamify-cachyos-dev. `container: privileged: true` (archiso mounts `/proc`); the workflow's `--privileged` option is ignored. - Caches (`actions/cache`, the runner's cache server): pacman's package cache per job kind (build, test) and the VMs' packages (`VM_CACHE`, `~/vms/pkg-cache`), keys per ISO week. Each job first installs only node and git, restores the caches, then installs the rest. - CachyOS's own `Desktop ISO` workflow (`build.yml`) is removed here; the VM tests live in steamify-cachyos (GitHub). + +- **Build badge in the GitHub release:** iso-1 puts `![ISO build](...running-yellow)` at the top of the release notes; + iso-2's last job `report` (`if: always()`) replaces it with succeeded / failed / cancelled, linked to the Gitea run, + through the GitHub API with the Gitea secret `GH_RELEASE_TOKEN` (fine-grained, this repo, Contents read and write). + Without the secret the badge stays "running". Gitea's own badge can't show these runs (they run on a tag ref).