mirror of
https://github.com/theupriser/steamify-cachyos-live-iso.git
synced 2026-10-02 15:10:26 +02:00
Compare commits
3
Commits
0c7e7f3a7b
...
2686b20fd6
| Author | SHA1 | Date | |
|---|---|---|---|
|
|
2686b20fd6 | ||
|
|
f1689f5c6c | ||
|
|
2494c1ad2e |
No files matched your search
@@ -20,6 +20,10 @@ on:
|
|||||||
type: choice
|
type: choice
|
||||||
options: [auto, release, dev]
|
options: [auto, release, dev]
|
||||||
default: auto
|
default: auto
|
||||||
|
steamify_ref:
|
||||||
|
description: "Steamify branch or tag to build the ISO with (empty: the newest published release). A release branch tests its own version."
|
||||||
|
type: string
|
||||||
|
default: ""
|
||||||
|
|
||||||
permissions:
|
permissions:
|
||||||
contents: write
|
contents: write
|
||||||
@@ -42,6 +46,12 @@ jobs:
|
|||||||
run: |
|
run: |
|
||||||
steamify="$(gh release view -R theupriser/steamify-cachyos --json tagName -q .tagName)"
|
steamify="$(gh release view -R theupriser/steamify-cachyos --json tagName -q .tagName)"
|
||||||
steamify="${steamify#v}"
|
steamify="${steamify#v}"
|
||||||
|
# A branch or tag of Steamify to build with (a release branch before its release), else the newest release.
|
||||||
|
sref="${{ inputs.steamify_ref }}"
|
||||||
|
if [ -n "$sref" ]; then
|
||||||
|
steamify="$(gh api "repos/theupriser/steamify-cachyos/contents/steamify.sh?ref=$sref" -q .content | base64 -d | sed -n 's/^VERSION=//p' | head -n 1)"
|
||||||
|
[ -n "$steamify" ] || { echo "::error::no VERSION in steamify.sh at $sref"; exit 1; }
|
||||||
|
fi
|
||||||
stamp="$(date -u +%y%m%d)" day="$(date -u +%Y.%m.%d)"
|
stamp="$(date -u +%y%m%d)" day="$(date -u +%Y.%m.%d)"
|
||||||
kind="${{ inputs.kind }}"
|
kind="${{ inputs.kind }}"
|
||||||
if [ -z "$kind" ] || [ "$kind" = auto ]; then
|
if [ -z "$kind" ] || [ "$kind" = auto ]; then
|
||||||
@@ -57,11 +67,13 @@ jobs:
|
|||||||
file="steamify-cachyos-${tag#v}-x86_64.iso" dl="$GITEA_URL/$GITEA_REPO/releases/download/$tag"
|
file="steamify-cachyos-${tag#v}-x86_64.iso" dl="$GITEA_URL/$GITEA_REPO/releases/download/$tag"
|
||||||
# The Steamify section of CHANGELOG.md ("## CachyOS with Steamify Live ISO"), without its heading.
|
# The Steamify section of CHANGELOG.md ("## CachyOS with Steamify Live ISO"), without its heading.
|
||||||
section="$(awk '/^## CachyOS with Steamify Live ISO/ {found = 1; next} found && /^#/ {exit} found' CHANGELOG.md)"
|
section="$(awk '/^## CachyOS with Steamify Live ISO/ {found = 1; next} found && /^#/ {exit} found' CHANGELOG.md)"
|
||||||
notes="The ISO is built from \`$(git rev-parse --short HEAD)\` (${{ github.ref_name }}) with Steamify $steamify and published on the mirror (GitHub releases take at most 2 GB per file), about half an hour after this release (the mirror's sync, then the build):
|
notes="
|
||||||
|
|
||||||
|
The ISO is built from \`$(git rev-parse --short HEAD)\` (${{ github.ref_name }}) with Steamify $steamify${sref:+ (branch $sref)} and published on the mirror (GitHub releases take at most 2 GB per file), about half an hour after this release (the mirror's sync, then the build):
|
||||||
|
|
||||||
**Download: [$file]($dl/$file)** ([SHA-256]($dl/$file.sha256), [release page]($GITEA_URL/$GITEA_REPO/releases/tag/$tag))
|
**Download: [$file]($dl/$file)** ([SHA-256]($dl/$file.sha256), [release page]($GITEA_URL/$GITEA_REPO/releases/tag/$tag))
|
||||||
|
|
||||||
Sources: [Steamify](https://github.com/theupriser/steamify-cachyos/tree/v$steamify), this repository at this tag, and the packages' sources at [CachyOS](https://github.com/CachyOS) and [Arch Linux](https://archlinux.org/packages/).
|
Sources: [Steamify](https://github.com/theupriser/steamify-cachyos/tree/${sref:-v$steamify}), this repository at this tag, and the packages' sources at [CachyOS](https://github.com/CachyOS) and [Arch Linux](https://archlinux.org/packages/).
|
||||||
|
|
||||||
$section"
|
$section"
|
||||||
# One ISO per day and kind: the newest build of a day replaces the earlier one (space), here and on the mirror.
|
# One ISO per day and kind: the newest build of a day replaces the earlier one (space), here and on the mirror.
|
||||||
@@ -78,6 +90,7 @@ jobs:
|
|||||||
gh release create "$tag" --verify-tag $pre --title "$name" --notes "$notes"
|
gh release create "$tag" --verify-tag $pre --title "$name" --notes "$notes"
|
||||||
echo "Released $tag"
|
echo "Released $tag"
|
||||||
echo "ISO_TAG=$tag" >> "$GITHUB_ENV"
|
echo "ISO_TAG=$tag" >> "$GITHUB_ENV"
|
||||||
|
echo "STEAMIFY_REF=$sref" >> "$GITHUB_ENV"
|
||||||
|
|
||||||
# Retention (space): at most 10 dev and 10 real releases; the oldest go, release and tag. The mirror drops the
|
# Retention (space): at most 10 dev and 10 real releases; the oldest go, release and tag. The mirror drops the
|
||||||
# tag with its release and ISO at its next sync (the step below).
|
# tag with its release and ISO at its next sync (the step below).
|
||||||
@@ -108,5 +121,5 @@ jobs:
|
|||||||
[ "$got" = "$want" ] || { echo "::error::the mirror does not have $ISO_TAG ($want) after 5 minutes"; exit 1; }
|
[ "$got" = "$want" ] || { echo "::error::the mirror does not have $ISO_TAG ($want) after 5 minutes"; exit 1; }
|
||||||
# ref: the full name (refs/tags/...), as in Gitea's API documentation; --fail-with-body shows the server's reason.
|
# ref: the full name (refs/tags/...), as in Gitea's API documentation; --fail-with-body shows the server's reason.
|
||||||
curl -sS --fail-with-body --retry 3 -X POST -H "Authorization: token $GIT_UPRISER_TOKEN" -H "Content-Type: application/json" \
|
curl -sS --fail-with-body --retry 3 -X POST -H "Authorization: token $GIT_UPRISER_TOKEN" -H "Content-Type: application/json" \
|
||||||
-d "{\"ref\":\"refs/tags/$ISO_TAG\"}" "$api/actions/workflows/iso-2-gitea-build.yml/dispatches"
|
-d "{\"ref\":\"refs/tags/$ISO_TAG\",\"inputs\":{\"steamify_ref\":\"$STEAMIFY_REF\"}}" "$api/actions/workflows/iso-2-gitea-build.yml/dispatches"
|
||||||
echo "Started the mirror's build for $ISO_TAG"
|
echo "Started the mirror's build for $ISO_TAG"
|
||||||
@@ -14,6 +14,11 @@ name: ISO 2/2 · Build and publish (Gitea)
|
|||||||
# run by itself, so nothing is triggered by tag pushes).
|
# run by itself, so nothing is triggered by tag pushes).
|
||||||
on:
|
on:
|
||||||
workflow_dispatch:
|
workflow_dispatch:
|
||||||
|
inputs:
|
||||||
|
steamify_ref:
|
||||||
|
description: "Steamify branch or tag to build with (set by iso-1; empty: the release the tag names)"
|
||||||
|
type: string
|
||||||
|
default: ""
|
||||||
|
|
||||||
# One run at a time for the whole workflow (not per tag): a new run stops the running one and takes over.
|
# One run at a time for the whole workflow (not per tag): a new run stops the running one and takes over.
|
||||||
concurrency:
|
concurrency:
|
||||||
@@ -75,7 +80,15 @@ jobs:
|
|||||||
echo "steamify=${m[1]}" >> "$GITHUB_OUTPUT"
|
echo "steamify=${m[1]}" >> "$GITHUB_OUTPUT"
|
||||||
|
|
||||||
- name: Steamify on the ISO (the version the tag names)
|
- name: Steamify on the ISO (the version the tag names)
|
||||||
run: ./steamify-prepare.sh
|
run: |
|
||||||
|
ref="${{ inputs.steamify_ref }}"
|
||||||
|
if [ -n "$ref" ]; then
|
||||||
|
# A branch (a release branch before its release): its checkout goes on the ISO.
|
||||||
|
git clone -q --depth 1 --branch "$ref" https://github.com/theupriser/steamify-cachyos.git /tmp/steamify-src
|
||||||
|
./steamify-prepare.sh /tmp/steamify-src
|
||||||
|
else
|
||||||
|
./steamify-prepare.sh
|
||||||
|
fi
|
||||||
|
|
||||||
- name: Build
|
- name: Build
|
||||||
run: |
|
run: |
|
||||||
@@ -159,12 +172,13 @@ jobs:
|
|||||||
fi
|
fi
|
||||||
{ echo "publish=true"; echo "name=$name"; } >> "$GITHUB_OUTPUT"
|
{ echo "publish=true"; echo "name=$name"; } >> "$GITHUB_OUTPUT"
|
||||||
section="$(awk '/^## CachyOS with Steamify Live ISO/ {found = 1; next} found && /^#/ {exit} found' CHANGELOG.md)"
|
section="$(awk '/^## CachyOS with Steamify Live ISO/ {found = 1; next} found && /^#/ {exit} found' CHANGELOG.md)"
|
||||||
|
src="${{ inputs.steamify_ref }}"; src="${src:-v$STEAMIFY_VERSION}"
|
||||||
{
|
{
|
||||||
echo "Built from \`$(git rev-parse --short HEAD)\` ($tag) with Steamify $STEAMIFY_VERSION."
|
echo "Built from \`$(git rev-parse --short HEAD)\` ($tag) with Steamify $STEAMIFY_VERSION."
|
||||||
echo
|
echo
|
||||||
echo "SHA-256: \`$(cut -d' ' -f1 "$iso.sha256")\`, label \`STEAMIFY_${STEAMIFY_VERSION//./_}_$b\`"
|
echo "SHA-256: \`$(cut -d' ' -f1 "$iso.sha256")\`, label \`STEAMIFY_${STEAMIFY_VERSION//./_}_$b\`"
|
||||||
echo
|
echo
|
||||||
echo "Sources: [Steamify](https://github.com/theupriser/steamify-cachyos/tree/v$STEAMIFY_VERSION), this repository at this tag, and the packages' sources at [CachyOS](https://github.com/CachyOS) and [Arch Linux](https://archlinux.org/packages/)."
|
echo "Sources: [Steamify](https://github.com/theupriser/steamify-cachyos/tree/$src), this repository at this tag, and the packages' sources at [CachyOS](https://github.com/CachyOS) and [Arch Linux](https://archlinux.org/packages/)."
|
||||||
echo
|
echo
|
||||||
echo "$section"
|
echo "$section"
|
||||||
} > release-notes.md
|
} > release-notes.md
|
||||||
@@ -184,3 +198,42 @@ jobs:
|
|||||||
out/desktop/*.iso.sha256
|
out/desktop/*.iso.sha256
|
||||||
out/desktop/*.iso.sha1
|
out/desktop/*.iso.sha1
|
||||||
out/desktop/*.pkgs.txt
|
out/desktop/*.pkgs.txt
|
||||||
|
|
||||||
|
# The result goes back to GitHub: the badge at the top of the GitHub release (started as "running" by iso-1) becomes
|
||||||
|
# succeeded / failed / cancelled and links to this run. Needs a GitHub token as the secret GH_RELEASE_TOKEN here on the
|
||||||
|
# mirror (fine-grained, this repository only, Contents: read and write); without it the badge stays "running".
|
||||||
|
report:
|
||||||
|
name: Report the result to GitHub
|
||||||
|
needs: [build, release]
|
||||||
|
if: ${{ always() && github.server_url != 'https://github.com' }}
|
||||||
|
runs-on: ubuntu-latest
|
||||||
|
container:
|
||||||
|
image: docker.io/cachyos/cachyos:latest
|
||||||
|
steps:
|
||||||
|
- name: Badge in the GitHub release
|
||||||
|
env:
|
||||||
|
GH_TOKEN: ${{ secrets.GH_RELEASE_TOKEN }}
|
||||||
|
BUILD: ${{ needs.build.result }}
|
||||||
|
RELEASE: ${{ needs.release.result }}
|
||||||
|
run: |
|
||||||
|
[ -n "$GH_TOKEN" ] || { echo "No GH_RELEASE_TOKEN: GitHub's release keeps its 'running' badge."; exit 0; }
|
||||||
|
pacman -Sy --noconfirm --needed curl python > /dev/null
|
||||||
|
tag="${{ github.ref_name }}"
|
||||||
|
if [ "$BUILD" = success ] && [ "$RELEASE" = success ]; then st=succeeded col=brightgreen
|
||||||
|
elif [ "$BUILD" = cancelled ] || [ "$RELEASE" = cancelled ]; then st=cancelled col=lightgrey
|
||||||
|
else st=failed col=red; fi
|
||||||
|
run="${{ github.server_url }}/${{ github.repository }}/actions/runs/${{ github.run_id }}"
|
||||||
|
api="https://api.github.com/repos/theupriser/steamify-cachyos-live-iso/releases"
|
||||||
|
curl -fsS -H "Authorization: Bearer $GH_TOKEN" "$api/tags/$tag" -o /tmp/rel.json || { echo "::warning::no GitHub release for $tag"; exit 0; }
|
||||||
|
ST="$st" COL="$col" RUN="$run" python3 - << 'PY'
|
||||||
|
import json, os, re
|
||||||
|
d = json.load(open("/tmp/rel.json"))
|
||||||
|
badge = f"[]({os.environ['RUN']})"
|
||||||
|
body = d.get("body") or ""
|
||||||
|
pat = re.compile(r"\[?!\[ISO build\]\([^)]*\)(\]\([^)]*\))?")
|
||||||
|
body = pat.sub(lambda m: badge, body, count=1) if pat.search(body) else badge + "\n\n" + body
|
||||||
|
json.dump({"body": body}, open("/tmp/patch.json", "w"))
|
||||||
|
open("/tmp/rel.id", "w").write(str(d["id"]))
|
||||||
|
PY
|
||||||
|
curl -fsS -X PATCH -H "Authorization: Bearer $GH_TOKEN" -H "Content-Type: application/json" -d @/tmp/patch.json "$api/$(cat /tmp/rel.id)" > /dev/null
|
||||||
|
echo "GitHub release $tag: ISO build $st"
|
||||||
@@ -119,7 +119,7 @@ Full write-up, with every trap: `steamify-iso-release` in steamify-cachyos-dev.
|
|||||||
date, no time): `vX.Y.Z-YYMMDD` (real) or `vX.Y.Z-dev-YYMMDD` (dev), file `steamify-cachyos-X.Y.Z-[dev-]YYMMDD-x86_64.iso`, an **annotated** tag and a
|
date, no time): `vX.Y.Z-YYMMDD` (real) or `vX.Y.Z-dev-YYMMDD` (dev), file `steamify-cachyos-X.Y.Z-[dev-]YYMMDD-x86_64.iso`, an **annotated** tag and a
|
||||||
release with notes and the direct download link. One ISO per day and kind: a second build the same day deletes
|
release with notes and the direct download link. One ISO per day and kind: a second build the same day deletes
|
||||||
the earlier release and tag (GitHub) and tags again; the mirror takes the new tag object, iso-2 replaces the old mirror release. Retention: at most 10 dev and 10 real
|
the earlier release and tag (GitHub) and tags again; the mirror takes the new tag object, iso-2 replaces the old mirror release. Retention: at most 10 dev and 10 real
|
||||||
releases are kept (space); the oldest are deleted with `gh release delete --cleanup-tag`, and the mirror drops their tags, releases and ISOs at its next sync. The workflow always runs from `master`; its input `kind` (`release`, `dev`, or `auto`: release on master, dev on other branches) decides: `release` is a real release, `dev` a `dev-` pre-release. steamify-cachyos' bundle.yml passes it: a version published from main -> `release`, a version on a release branch -> `dev`.
|
releases are kept (space); the oldest are deleted with `gh release delete --cleanup-tag`, and the mirror drops their tags, releases and ISOs at its next sync. The workflow always runs from `master`; its input `steamify_ref` (a Steamify branch or tag, empty = the newest published release) builds the ISO with that checkout and names it after that branch's `VERSION` (a release branch tests its own version before it is released); its input `kind` (`release`, `dev`, or `auto`: release on master, dev on other branches) decides: `release` is a real release, `dev` a `dev-` pre-release. steamify-cachyos' bundle.yml passes it: a version published from main -> `release`, a version on a release branch -> `dev`.
|
||||||
- `.github/workflows/iso-2-gitea-build.yml` (Gitea, `workflow_dispatch` with the tag as the ref, started by iso-1's last step through the mirror's dispatch API after the mirror has the new tag object; a tag push starts nothing, because a replaced tag of the same name starts no run; skipped on GitHub) runs two jobs for that
|
- `.github/workflows/iso-2-gitea-build.yml` (Gitea, `workflow_dispatch` with the tag as the ref, started by iso-1's last step through the mirror's dispatch API after the mirror has the new tag object; a tag push starts nothing, because a replaced tag of the same name starts no run; skipped on GitHub) runs two jobs for that
|
||||||
tag: build the ISO, then attach it to the mirror's release. It is not tested there (the runner is small): the VM tests
|
tag: build the ISO, then attach it to the mirror's release. It is not tested there (the runner is small): the VM tests
|
||||||
run on GitHub, in steamify-cachyos `vmtest.yml`, on the newest ISO release of the mirror. The tag decides everything: Steamify version (`steamify-prepare.sh`
|
run on GitHub, in steamify-cachyos `vmtest.yml`, on the newest ISO release of the mirror. The tag decides everything: Steamify version (`steamify-prepare.sh`
|
||||||
@@ -134,3 +134,8 @@ Full write-up, with every trap: `steamify-iso-release` in steamify-cachyos-dev.
|
|||||||
`container: privileged: true` (archiso mounts `/proc`); the workflow's `--privileged` option is ignored.
|
`container: privileged: true` (archiso mounts `/proc`); the workflow's `--privileged` option is ignored.
|
||||||
- Caches (`actions/cache`, the runner's cache server): pacman's package cache per job kind (build, test) and the VMs' packages (`VM_CACHE`, `~/vms/pkg-cache`), keys per ISO week. Each job first installs only node and git, restores the caches, then installs the rest.
|
- Caches (`actions/cache`, the runner's cache server): pacman's package cache per job kind (build, test) and the VMs' packages (`VM_CACHE`, `~/vms/pkg-cache`), keys per ISO week. Each job first installs only node and git, restores the caches, then installs the rest.
|
||||||
- CachyOS's own `Desktop ISO` workflow (`build.yml`) is removed here; the VM tests live in steamify-cachyos (GitHub).
|
- CachyOS's own `Desktop ISO` workflow (`build.yml`) is removed here; the VM tests live in steamify-cachyos (GitHub).
|
||||||
|
|
||||||
|
- **Build badge in the GitHub release:** iso-1 puts `` at the top of the release notes;
|
||||||
|
iso-2's last job `report` (`if: always()`) replaces it with succeeded / failed / cancelled, linked to the Gitea run,
|
||||||
|
through the GitHub API with the Gitea secret `GH_RELEASE_TOKEN` (fine-grained, this repo, Contents read and write).
|
||||||
|
Without the secret the badge stays "running". Gitea's own badge can't show these runs (they run on a tag ref).
|
||||||
Reference in new issue
Block a user