mirror of
https://github.com/jmcorgan/fips.git
synced 2026-07-30 19:46:15 +00:00
The v0.3.0 stable AUR push silently failed: with updpkgsums: true, makepkg downloaded fips-<ver>.tar.gz into the AUR working tree, where it was then staged by the deploy action and rejected by AUR's 488 KiB max-blob hook. Fetch the upstream source tarball and compute its b2sum in CI, patch pkgver and the b2sums SKIP placeholder in PKGBUILD in-place, then publish with updpkgsums: false so the AUR clone stays metadata-only. Recompute and patch the fips.sysusers / fips.tmpfiles asset b2sums in the same step so they stay in sync with the local files; this safety net was previously provided by updpkgsums. Add aur-publish-git.yml for the VCS fips-git PKGBUILD, triggered on master pushes that touch PKGBUILD-git or its companion files plus workflow_dispatch. pkgver is computed at build time by the PKGBUILD's pkgver() function, so this workflow is not tied to release tags. Add a workflow_dispatch tag input on the stable workflow so historical release tags can be re-published manually, and drop continue-on-error: true so future regressions surface in CI.
58 lines
1.9 KiB
YAML
58 lines
1.9 KiB
YAML
name: AUR Publish (fips-git)
|
|
|
|
on:
|
|
workflow_dispatch:
|
|
push:
|
|
branches:
|
|
- master
|
|
paths:
|
|
- 'packaging/aur/PKGBUILD-git'
|
|
- 'packaging/aur/fips.sysusers'
|
|
- 'packaging/aur/fips.tmpfiles'
|
|
- 'packaging/aur/fips.install'
|
|
|
|
jobs:
|
|
aur-publish-fips-git:
|
|
name: Publish fips-git to AUR
|
|
runs-on: ubuntu-latest
|
|
|
|
steps:
|
|
- uses: actions/checkout@v4
|
|
|
|
- name: Patch PKGBUILD-git b2sums for local assets
|
|
run: |
|
|
set -euo pipefail
|
|
SYSUSERS_SUM=$(b2sum packaging/aur/fips.sysusers | awk '{print $1}')
|
|
TMPFILES_SUM=$(b2sum packaging/aur/fips.tmpfiles | awk '{print $1}')
|
|
if [ -z "$SYSUSERS_SUM" ] || [ -z "$TMPFILES_SUM" ]; then
|
|
echo "Failed to compute asset b2sums"; exit 1
|
|
fi
|
|
awk -v s1="$SYSUSERS_SUM" -v s2="$TMPFILES_SUM" '
|
|
/^b2sums=\(/ { in_block=1; count=0 }
|
|
in_block {
|
|
count++
|
|
if (count == 2) sub(/[a-f0-9]{128}/, s1)
|
|
if (count == 3) sub(/[a-f0-9]{128}/, s2)
|
|
if ($0 ~ /\)/) in_block=0
|
|
}
|
|
{ print }
|
|
' packaging/aur/PKGBUILD-git > packaging/aur/PKGBUILD-git.new
|
|
mv packaging/aur/PKGBUILD-git.new packaging/aur/PKGBUILD-git
|
|
echo "Patched PKGBUILD-git b2sums:"
|
|
awk '/^b2sums=\(/,/\)$/' packaging/aur/PKGBUILD-git
|
|
|
|
- name: Publish to AUR
|
|
uses: KSXGitHub/github-actions-deploy-aur@v4.1.2
|
|
with:
|
|
pkgname: fips-git
|
|
pkgbuild: packaging/aur/PKGBUILD-git
|
|
updpkgsums: false
|
|
assets: |
|
|
packaging/aur/fips.sysusers
|
|
packaging/aur/fips.tmpfiles
|
|
packaging/aur/fips.install
|
|
commit_username: ${{ github.repository_owner }}
|
|
commit_email: ${{ secrets.AUR_EMAIL }}
|
|
ssh_private_key: ${{ secrets.AUR_SSH_PRIVATE_KEY }}
|
|
commit_message: "Update PKGBUILD-git (${{ github.sha }})"
|