Fetch the source before an on-server F-Droid build, and let the Release workflow rerun steps by hand

This commit is contained in:
Jon Staab 2026-09-25 09:40:11 -07:00
parent c66f9cb3ed
commit 801b981bdf
4 changed files with 34 additions and 9 deletions

View file

@ -68,7 +68,7 @@ CI uses the job's own token for the release, and the `PACKAGE_TOKEN` and `GH_MIR
- [ ] Start `pnpm release:local` once the tag is pushed. `fdroid-sign` waits for CI's F-Droid build, up to two hours.
- [ ] Watch the Release workflow run for the tag in gitea's Actions tab. Its `image` and `release` jobs must both pass.
- [ ] When a step fails, fix the cause and rerun the command the run prints, which resumes from that step.
- [ ] When a step fails, fix the cause and rerun the command the run prints, which resumes from that step. For a CI step, push the fix to dev and run the Release workflow by hand from dev with the steps to rerun, e.g. `fdroid`; it builds the tag's commit with dev's scripts, so the tag never has to move.
### After both runs

View file

@ -3,6 +3,13 @@ name: Release
on:
push:
tags: ["*.*.*"]
# Reruns steps of the release for package.json's version, from the branch it's run on
workflow_dispatch:
inputs:
steps:
description: Steps to run, such as "fdroid" (all when empty)
required: false
default: ""
concurrency:
group: ${{ github.workflow }}-${{ github.ref }}
@ -15,6 +22,7 @@ env:
jobs:
image:
runs-on: ubuntu-latest
if: github.event_name == 'push'
permissions:
contents: read
packages: write
@ -61,6 +69,8 @@ jobs:
steps:
- name: Checkout repository
uses: actions/checkout@v4
with:
fetch-depth: 0
- name: Set up Node
uses: actions/setup-node@v4
@ -77,4 +87,5 @@ jobs:
env:
GITEA_TOKEN: ${{ secrets.GITHUB_TOKEN }}
GITEA_PACKAGE_TOKEN: ${{ secrets.PACKAGE_TOKEN }}
run: pnpm release:ci --yes
STEPS: ${{ github.event.inputs.steps }}
run: pnpm release:ci --yes $STEPS

View file

@ -206,7 +206,9 @@ pnpm release:local
`pnpm release:local --check` runs those checks and reports the plan without building anything.
Naming steps runs a subset, such as `pnpm release:local ios` or `pnpm release:local apk gitea`. A
step that fails stops the run and prints the command to pick up from there.
step that fails stops the run and prints the command to pick up from there. To rerun CI steps, run
the Release workflow by hand from a branch with the fix, naming the steps; it releases
`package.json`'s version without moving its tag, and skips the container image.
| step | run by | what it does |
| --- | --- | --- |

View file

@ -46,13 +46,25 @@ with open(os.path.join(os.environ["home_vagrant"], "metadata/social.flotilla.fdr
EOF
chown -R vagrant "$home_vagrant"
fdroid() {
sudo --preserve-env --user vagrant \
env PATH="$fdroidserver:$PATH" \
env PYTHONPATH="$fdroidserver:$fdroidserver/examples" \
env PYTHONUNBUFFERED=true \
env HOME="$home_vagrant" \
fdroid "$@"
}
cd "$home_vagrant"
sudo --preserve-env --user vagrant \
env PATH="$fdroidserver:$PATH" \
env PYTHONPATH="$fdroidserver:$fdroidserver/examples" \
env PYTHONUNBUFFERED=true \
env HOME="$home_vagrant" \
fdroid build --verbose --test --refresh-scanner --on-server --no-tarball \
# --on-server builds whatever is already checked out in build/, which the host fetches in production
curl --silent https://gitlab.com/fdroid/fdroid-bootstrap-buildserver/-/raw/master/roles/production_hardening/files/gitconfig \
>"$home_vagrant/.gitconfig"
chown vagrant "$home_vagrant/.gitconfig"
fdroid fetchsrclibs "social.flotilla.fdroid:$VERSION_CODE" --verbose
rm "$home_vagrant/.gitconfig"
fdroid build --verbose --test --refresh-scanner --on-server --no-tarball \
"social.flotilla.fdroid:$VERSION_CODE"
cp "$home_vagrant/tmp/social.flotilla.fdroid_$VERSION_CODE.apk" /work/unsigned.apk