diff --git a/.github/workflows/build.yml b/.github/workflows/build.yml deleted file mode 100644 index 059be29..0000000 --- a/.github/workflows/build.yml +++ /dev/null @@ -1,141 +0,0 @@ -name: Desktop ISO -on: - push: - branches: - - master - pull_request: - -concurrency: - group: ${{ github.ref }} - cancel-in-progress: true - -jobs: - build: - # CachyOS's plain ISO and its quicktest matrix: only in CachyOS's own repo, not in this fork - # (the Steamify ISO is iso-2-gitea-build.yml). - if: github.repository == 'CachyOS/CachyOS-Live-ISO' - runs-on: ubuntu-latest - container: - image: archlinux:base-devel - options: --privileged - name: Build - outputs: - builddate: ${{ steps.date.outputs.builddate }} - steps: - - name: Get build date - id: date - run: | - echo "builddate=$(date +'%y%m%d')" >> $GITHUB_OUTPUT - - - name: Clone CachyOS-Live-ISO - id: clone - uses: actions/checkout@v4 - with: - fetch-depth: 0 - - - name: Add CachyOS keyring - id: keyring - run: | - pacman-key --init - pacman-key --recv-keys F3B607488DB35A47 --keyserver keyserver.ubuntu.com - pacman-key --lsign-key F3B607488DB35A47 - - sed -i '/^\[core\]$/i[cachyos]\nServer = https://mirror.cachyos.org/repo/$arch/$repo\n' /etc/pacman.conf - - - name: Install dependencies - id: dependencies - run: | - sudo pacman -Syu --noconfirm archiso cachyos-keyring mkinitcpio-archiso squashfs-tools grub - - - name: Create build user - id: user-archiso - run: | - useradd builder -m - echo "builder ALL=(ALL) NOPASSWD: ALL" >> /etc/sudoers - chmod -R a+rw . - - - name: Build ISO (${{ steps.date.outputs.builddate }}) - id: build - run: | - sudo -H -E -u builder ./buildiso.sh - - - name: Upload ISO to artifacts - id: upload - uses: actions/upload-artifact@v4 - with: - name: cachyos-desktop-linux-${{ steps.date.outputs.builddate }} - path: out/desktop/* - quicktest: - name: Testing (${{ matrix.bootloader }} / ${{ matrix.filesystem }}) - runs-on: ubuntu-latest - needs: build - container: - image: archlinux:base-devel - options: --privileged - strategy: - fail-fast: false - max-parallel: 4 - matrix: - bootloader: [grub, systemd-boot, refind, limine] - filesystem: [btrfs, xfs, ext4, f2fs, zfs] - steps: - - name: Clone CachyOS-Live-ISO - id: clone - uses: actions/checkout@v6 - - - name: Install dependencies - id: dependencies - run: | - pacman -Syu --noconfirm git ffmpeg imagemagick tesseract-data-eng qemu-desktop - - - name: Create build user - id: user - run: | - useradd builder -m - echo "builder ALL=(ALL) NOPASSWD: ALL" >> /etc/sudoers - chmod -R a+rw . - - - name: Build quickemu - id: quickemu - run: | - sudo -u builder git clone https://aur.archlinux.org/quickemu.git - cd quickemu - sudo -H -E -u builder makepkg --syncdeps --noconfirm - pacman -U --noconfirm quickemu*.pkg.tar.zst - cd .. - - - name: Clone quicktest - id: clone-quicktest - uses: actions/checkout@v6 - with: - repository: 'quickemu-project/quicktest' - path: 'quicktest' - - - name: Download ISO - id: download - uses: actions/download-artifact@v4 - with: - path: machines/cachyos-dailylive - merge-multiple: true - - - name: Run quicktest - id: quicktest - run: | - ./quicktest/quicktest test_install_calamares cachyos dailylive - env: - QT_NOTIFY: "false" - QT_OPEN_RESULTS: "false" - QT_QUICKGET_SKIP: "true" - QT_TESTCASES_DIR: "./testcases" - QUICKEMU_DISPLAY: "none" - QUICKEMU_VM_DIR: "./machines" - TEST_BOOTLOADER: "${{ matrix.bootloader }}" - TEST_FILESYSTEM: "${{ matrix.filesystem }}" - - - name: Upload results to artifacts - id: upload-results - if: always() - uses: actions/upload-artifact@v4 - with: - name: cachyos-desktop-linux-results-${{needs.build.outputs.builddate}}-${{ matrix.bootloader }}-${{ matrix.filesystem }} - path: results/* diff --git a/.github/workflows/git-upriser-sync.yml b/.github/workflows/git-upriser-sync.yml new file mode 100644 index 0000000..50ad01f --- /dev/null +++ b/.github/workflows/git-upriser-sync.yml @@ -0,0 +1,26 @@ +name: Sync git.upriser.nl mirror + +# Trigger the Gitea pull-mirror immediately instead of waiting for its interval, +# so Gitea builds/tests right after any branch or tag lands on GitHub (the mirror has no sync interval of its own). +on: + push: + branches: ['**'] + tags: ['*'] + workflow_dispatch: + +jobs: + sync: + # Gitea also reads .github/workflows on the mirror; only run on GitHub + if: github.server_url == 'https://github.com' + runs-on: ubuntu-latest + steps: + - name: Trigger mirror-sync + env: + GITEA_URL: ${{ secrets.GIT_UPRISER_URL }} + GIT_UPRISER_TOKEN: ${{ secrets.GIT_UPRISER_TOKEN }} + # Gitea "owner/repo"; defaults to the same path as on GitHub + GITEA_REPO: ${{ vars.GITEA_REPO || github.repository }} + run: | + curl --fail-with-body -sS --retry 5 --retry-delay 10 --retry-all-errors -X POST \ + -H "Authorization: token ${GIT_UPRISER_TOKEN}" \ + "${GITEA_URL%/}/api/v1/repos/${GITEA_REPO}/mirror-sync" diff --git a/.github/workflows/iso-2-gitea-build.yml b/.github/workflows/iso-2-gitea-build.yml index edae835..f91e15a 100644 --- a/.github/workflows/iso-2-gitea-build.yml +++ b/.github/workflows/iso-2-gitea-build.yml @@ -4,6 +4,8 @@ # checksums and package list to the mirror's release for that tag. The tag names the Steamify version and # the time: v-- (master) or v-dev.<...> (feat/steamify, a pre-release); # the ISO gets exactly that Steamify release, and its label the same moment. GitHub skips it. +# Two jobs: build the ISO -> release it. The VM tests run on GitHub (steamify-cachyos vmtest.yml, the newest ISO release of +# this mirror), where the runners are bigger. # The runner needs privileged containers (archiso mounts loop devices) and ~20 GB of disk; Gitea's # [repository.release] FILE_MAX_SIZE must allow the ISO (default 2 GB). name: ISO 2/2 ยท Build and publish (Gitea) @@ -13,12 +15,14 @@ on: tags: ['v*'] workflow_dispatch: +# One run at a time for the whole workflow (not per tag): a new run stops the running one and takes over. concurrency: - group: steamify-iso-${{ github.ref }} + group: steamify-iso cancel-in-progress: true jobs: - iso: + build: + name: Build the ISO if: github.server_url != 'https://github.com' runs-on: ubuntu-latest container: @@ -27,12 +31,86 @@ jobs: defaults: run: shell: bash + outputs: + steamify: ${{ steps.tag.outputs.steamify }} + steps: + # First only what the cache action needs (node, git), then the caches, then the rest from the restored cache. + - name: Node and git + id: node + run: | + pacman-key --init && pacman-key --populate + pacman -Syu --noconfirm --needed nodejs git + # The caches' keys: one entry per ISO week (an exact hit saves nothing, a new week restores the old one and saves once). + echo "week=$(date -u +%G-%V)" >> "$GITHUB_OUTPUT" + - name: Cache - pacman packages + uses: actions/cache@v4 + with: + path: /var/cache/pacman/pkg + key: pacman-build-${{ steps.node.outputs.week }} + restore-keys: pacman-build- + - name: Tools + run: pacman -S --noconfirm --needed archiso mkinitcpio-archiso squashfs-tools grub sudo curl jq + + + - uses: actions/checkout@v4 + with: + fetch-depth: 0 + + - name: Version and time from the tag + id: tag + run: | + tag="${{ github.ref_name }}" + [[ "$tag" =~ ^v([0-9]+\.[0-9]+\.[0-9]+)-(dev\.)?([0-9]{4})\.([0-9]{2})\.([0-9]{2})-([0-9]{4})$ ]] || + { echo "::error::$tag is not a Steamify ISO release tag (v-[dev.]-)"; exit 1; } + m=("${BASH_REMATCH[@]}") + { + echo "STEAMIFY_VERSION=${m[1]}" + # One moment for the ISO's label (profiledef.sh) and the release's name: the tag's (UTC). + echo "STEAMIFY_BUILD_STAMP=${m[3]}${m[4]}${m[5]}_${m[6]}" + echo "ISO_PRERELEASE=$([ -n "${m[2]}" ] && echo true || echo false)" + # The ISO's file name: the tag without its v (profiledef.sh). + echo "STEAMIFY_ISO_VERSION=${tag#v}" + } >> "$GITHUB_ENV" + + echo "steamify=${m[1]}" >> "$GITHUB_OUTPUT" + + - name: Steamify on the ISO (the version the tag names) + run: ./steamify-prepare.sh + + - name: Build + run: | + ./build-live-modules.sh + ./build-calamares-modules.sh + ./buildiso.sh -p desktop -w || ./buildiso.sh -p desktop -c -w + + + - name: Keep the ISO for the tests and the release + uses: christopherhx/gitea-upload-artifact@v4 + with: + name: iso + path: | + out/desktop/*.iso + out/desktop/*.iso.sha256 + out/desktop/*.iso.sha1 + out/desktop/*.pkgs.txt + retention-days: 3 + + release: + name: Release + needs: build + runs-on: ubuntu-latest + container: + image: docker.io/cachyos/cachyos:latest + defaults: + run: + shell: bash steps: - name: Tools run: | pacman-key --init && pacman-key --populate # nodejs: the actions below run in this container - pacman -Syu --noconfirm --needed archiso mkinitcpio-archiso git squashfs-tools grub sudo nodejs curl jq + pacman -Syu --noconfirm --needed git nodejs curl jq + - uses: actions/checkout@v4 with: @@ -53,14 +131,11 @@ jobs: echo "STEAMIFY_ISO_VERSION=${tag#v}" } >> "$GITHUB_ENV" - - name: Steamify on the ISO (the version the tag names) - run: ./steamify-prepare.sh - - name: Build - run: | - ./build-live-modules.sh - ./build-calamares-modules.sh - ./buildiso.sh -p desktop -w || ./buildiso.sh -p desktop -c -w + - uses: christopherhx/gitea-download-artifact@v4 + with: + name: iso + path: out/desktop - name: Release name and notes id: rel diff --git a/AGENTS.md b/AGENTS.md index 3724971..3f11d4c 100644 --- a/AGENTS.md +++ b/AGENTS.md @@ -118,8 +118,9 @@ Full write-up, with every trap: `steamify-iso-release` in steamify-cachyos-dev. release, whose `bundle.yml` needs the secret `ISO_DISPATCH_TOKEN`) names the release: the Steamify version plus GitHub's UTC time, `vX.Y.Z-[dev.]YYYY.MM.DD-HHMM`, an **annotated** tag and a release with notes and the direct download link. `feat/steamify` makes a `dev.` pre-release, `master` a real one. -- `.github/workflows/iso-2-gitea-build.yml` (Gitea, `on: push: tags: v*`, skipped on GitHub) builds the ISO for that - tag and attaches it to the mirror's release. The tag decides everything: Steamify version (`steamify-prepare.sh` +- `.github/workflows/iso-2-gitea-build.yml` (Gitea, `on: push: tags: v*`, skipped on GitHub) runs two jobs for that + tag: build the ISO, then attach it to the mirror's release. It is not tested there (the runner is small): the VM tests + run on GitHub, in steamify-cachyos `vmtest.yml`, on the newest ISO release of the mirror. The tag decides everything: Steamify version (`steamify-prepare.sh` takes `STEAMIFY_VERSION`), file name (`STEAMIFY_ISO_VERSION` -> `iso_version` in `profiledef.sh`), label (`STEAMIFY_BUILD_STAMP`), boot menu and `/etc/steammachine-iso-build`. The build reads no clock; without a tag everything says `local`. @@ -129,4 +130,5 @@ Full write-up, with every trap: `steamify-iso-release` in steamify-cachyos-dev. GitHub doesn't have, and the release with them. GitHub releases can't hold the ISO (2 GB per file). - Gitea needs `[repository.release] FILE_MAX_SIZE` above the ISO (413 otherwise) and the runner `container: privileged: true` (archiso mounts `/proc`); the workflow's `--privileged` option is ignored. -- CachyOS's own `Desktop ISO` workflow (`build.yml`) only runs in `CachyOS/CachyOS-Live-ISO`. +- Caches (`actions/cache`, the runner's cache server): pacman's package cache per job kind (build, test) and the VMs' packages (`VM_CACHE`, `~/vms/pkg-cache`), keys per ISO week. Each job first installs only node and git, restores the caches, then installs the rest. +- CachyOS's own `Desktop ISO` workflow (`build.yml`) is removed here; the VM tests live in steamify-cachyos (GitHub).