From 801b981bdf85ad1865afcd951875e62c93e03910 Mon Sep 17 00:00:00 2001 From: Jon Staab Date: Fri, 25 Sep 2026 09:40:11 -0700 Subject: [PATCH] Fetch the source before an on-server F-Droid build, and let the Release workflow rerun steps by hand --- .agents/skills/flotilla-release/SKILL.md | 2 +- .gitea/workflows/release.yml | 13 ++++++++++++- README.md | 4 +++- scripts/fdroid/reproduce.sh | 24 ++++++++++++++++++------ 4 files changed, 34 insertions(+), 9 deletions(-) diff --git a/.agents/skills/flotilla-release/SKILL.md b/.agents/skills/flotilla-release/SKILL.md index f9439aae..5749ad44 100644 --- a/.agents/skills/flotilla-release/SKILL.md +++ b/.agents/skills/flotilla-release/SKILL.md @@ -68,7 +68,7 @@ CI uses the job's own token for the release, and the `PACKAGE_TOKEN` and `GH_MIR - [ ] Start `pnpm release:local` once the tag is pushed. `fdroid-sign` waits for CI's F-Droid build, up to two hours. - [ ] Watch the Release workflow run for the tag in gitea's Actions tab. Its `image` and `release` jobs must both pass. -- [ ] When a step fails, fix the cause and rerun the command the run prints, which resumes from that step. +- [ ] When a step fails, fix the cause and rerun the command the run prints, which resumes from that step. For a CI step, push the fix to dev and run the Release workflow by hand from dev with the steps to rerun, e.g. `fdroid`; it builds the tag's commit with dev's scripts, so the tag never has to move. ### After both runs diff --git a/.gitea/workflows/release.yml b/.gitea/workflows/release.yml index 20d5032e..66569ff9 100644 --- a/.gitea/workflows/release.yml +++ b/.gitea/workflows/release.yml @@ -3,6 +3,13 @@ name: Release on: push: tags: ["*.*.*"] + # Reruns steps of the release for package.json's version, from the branch it's run on + workflow_dispatch: + inputs: + steps: + description: Steps to run, such as "fdroid" (all when empty) + required: false + default: "" concurrency: group: ${{ github.workflow }}-${{ github.ref }} @@ -15,6 +22,7 @@ env: jobs: image: runs-on: ubuntu-latest + if: github.event_name == 'push' permissions: contents: read packages: write @@ -61,6 +69,8 @@ jobs: steps: - name: Checkout repository uses: actions/checkout@v4 + with: + fetch-depth: 0 - name: Set up Node uses: actions/setup-node@v4 @@ -77,4 +87,5 @@ jobs: env: GITEA_TOKEN: ${{ secrets.GITHUB_TOKEN }} GITEA_PACKAGE_TOKEN: ${{ secrets.PACKAGE_TOKEN }} - run: pnpm release:ci --yes + STEPS: ${{ github.event.inputs.steps }} + run: pnpm release:ci --yes $STEPS diff --git a/README.md b/README.md index 0b906588..b6a0cf44 100644 --- a/README.md +++ b/README.md @@ -206,7 +206,9 @@ pnpm release:local `pnpm release:local --check` runs those checks and reports the plan without building anything. Naming steps runs a subset, such as `pnpm release:local ios` or `pnpm release:local apk gitea`. A -step that fails stops the run and prints the command to pick up from there. +step that fails stops the run and prints the command to pick up from there. To rerun CI steps, run +the Release workflow by hand from a branch with the fix, naming the steps; it releases +`package.json`'s version without moving its tag, and skips the container image. | step | run by | what it does | | --- | --- | --- | diff --git a/scripts/fdroid/reproduce.sh b/scripts/fdroid/reproduce.sh index f0db3013..c61ce23e 100755 --- a/scripts/fdroid/reproduce.sh +++ b/scripts/fdroid/reproduce.sh @@ -46,13 +46,25 @@ with open(os.path.join(os.environ["home_vagrant"], "metadata/social.flotilla.fdr EOF chown -R vagrant "$home_vagrant" +fdroid() { + sudo --preserve-env --user vagrant \ + env PATH="$fdroidserver:$PATH" \ + env PYTHONPATH="$fdroidserver:$fdroidserver/examples" \ + env PYTHONUNBUFFERED=true \ + env HOME="$home_vagrant" \ + fdroid "$@" +} + cd "$home_vagrant" -sudo --preserve-env --user vagrant \ - env PATH="$fdroidserver:$PATH" \ - env PYTHONPATH="$fdroidserver:$fdroidserver/examples" \ - env PYTHONUNBUFFERED=true \ - env HOME="$home_vagrant" \ - fdroid build --verbose --test --refresh-scanner --on-server --no-tarball \ + +# --on-server builds whatever is already checked out in build/, which the host fetches in production +curl --silent https://gitlab.com/fdroid/fdroid-bootstrap-buildserver/-/raw/master/roles/production_hardening/files/gitconfig \ + >"$home_vagrant/.gitconfig" +chown vagrant "$home_vagrant/.gitconfig" +fdroid fetchsrclibs "social.flotilla.fdroid:$VERSION_CODE" --verbose +rm "$home_vagrant/.gitconfig" + +fdroid build --verbose --test --refresh-scanner --on-server --no-tarball \ "social.flotilla.fdroid:$VERSION_CODE" cp "$home_vagrant/tmp/social.flotilla.fdroid_$VERSION_CODE.apk" /work/unsigned.apk