name: AUR Publish on: workflow_dispatch: inputs: tag: description: 'Release tag to publish (e.g. v0.3.0). Defaults to the tag the workflow was dispatched from.' required: false default: '' pkgrel: description: 'AUR pkgrel to publish. Use 2+ for packaging-only republishes of an existing tag.' required: false default: '1' push: tags: - 'v*' jobs: aur-publish-fips: name: Publish fips to AUR runs-on: ubuntu-latest if: github.event_name == 'workflow_dispatch' || !contains(github.ref_name, '-') steps: - name: Resolve release tag id: tag env: INPUT_TAG: ${{ inputs.tag }} INPUT_PKGREL: ${{ inputs.pkgrel }} run: | set -euo pipefail TAG="${INPUT_TAG:-$GITHUB_REF_NAME}" PKGREL="${INPUT_PKGREL:-1}" case "$TAG" in v*) ;; *) echo "Tag '$TAG' does not look like a release tag (vX.Y.Z)"; exit 1 ;; esac case "$PKGREL" in ''|*[!0-9]*|0) echo "pkgrel '$PKGREL' must be a positive integer"; exit 1 ;; esac case "$TAG" in *-*) if [ "$GITHUB_EVENT_NAME" != "workflow_dispatch" ]; then echo "Pre-release tag '$TAG' — skipping AUR publish" exit 1 fi ;; esac echo "tag=${TAG}" >> "$GITHUB_OUTPUT" echo "version=${TAG#v}" >> "$GITHUB_OUTPUT" echo "pkgrel=${PKGREL}" >> "$GITHUB_OUTPUT" - uses: actions/checkout@v4 with: ref: ${{ steps.tag.outputs.tag }} - name: Patch PKGBUILD with pkgver, pkgrel, conflicts, and b2sums env: TAG: ${{ steps.tag.outputs.tag }} VERSION: ${{ steps.tag.outputs.version }} PKGREL: ${{ steps.tag.outputs.pkgrel }} run: | set -euo pipefail URL="https://github.com/${GITHUB_REPOSITORY}/archive/${TAG}.tar.gz" echo "Fetching $URL" SOURCE_SUM=$(curl -fsSL --retry 3 "$URL" | b2sum | awk '{print $1}') SYSUSERS_SUM=$(b2sum packaging/aur/fips.sysusers | awk '{print $1}') TMPFILES_SUM=$(b2sum packaging/aur/fips.tmpfiles | awk '{print $1}') for v in SOURCE_SUM SYSUSERS_SUM TMPFILES_SUM; do eval val=\$$v if [ -z "$val" ]; then echo "$v is empty"; exit 1; fi done sed -i "s/^pkgver=.*/pkgver=${VERSION}/" packaging/aur/PKGBUILD sed -i "s/^pkgrel=.*/pkgrel=${PKGREL}/" packaging/aur/PKGBUILD sed -i "s/^conflicts=.*/conflicts=('fips-git' 'fips-git-debug')/" packaging/aur/PKGBUILD sed -i "s/^options=.*/options=('!lto' '!debug')/" packaging/aur/PKGBUILD sed -i "s|^b2sums=('SKIP'.*|b2sums=('${SOURCE_SUM}'|" packaging/aur/PKGBUILD awk -v s1="$SYSUSERS_SUM" -v s2="$TMPFILES_SUM" ' /^b2sums=\(/ { in_block=1; count=0 } in_block { count++ if (count == 2) sub(/[a-f0-9]{128}/, s1) if (count == 3) sub(/[a-f0-9]{128}/, s2) if ($0 ~ /\)/) in_block=0 } { print } ' packaging/aur/PKGBUILD > packaging/aur/PKGBUILD.new mv packaging/aur/PKGBUILD.new packaging/aur/PKGBUILD echo "Patched PKGBUILD:" grep -E "^(pkgver|pkgrel|conflicts|options)=" packaging/aur/PKGBUILD awk '/^b2sums=\(/,/\)$/' packaging/aur/PKGBUILD - name: Publish to AUR uses: KSXGitHub/github-actions-deploy-aur@v4.1.2 with: pkgname: fips pkgbuild: packaging/aur/PKGBUILD updpkgsums: false assets: | packaging/aur/fips.sysusers packaging/aur/fips.tmpfiles packaging/aur/fips.install commit_username: ${{ github.repository_owner }} commit_email: ${{ secrets.AUR_EMAIL }} ssh_private_key: ${{ secrets.AUR_SSH_PRIVATE_KEY }} commit_message: "Update to ${{ steps.tag.outputs.tag }}"