Files
fips/.github
Johnathan Corgan c468eae4ca Hold the AUR publish until the tag's package workflows have succeeded
The AUR publish job depended only on the AUR build job, so on a release
tag it pushed the new pkgver while the Linux, macOS, Windows, OpenWrt and
FreeBSD package workflows were still building and uploading. At v0.5.1 the
AUR was updated while the release had 15 of its 17 assets. Once the AUR
points at a tag, deleting that tag to withdraw a bad release leaves the AUR
package unbuildable, because its b2sum pins the tag's source archive.

The publish job now waits, before it touches the AUR, for every
package-*.yml workflow in the tag's tree to have a successful run of the
tag push. Runs are matched on the tag name as well as the commit, because
the branch push of the same commit starts runs that are not the release's.
A failed or cancelled run stops the publish at once; a missing, unfinished
or unreadable run is polled for up to an hour and then fails the job. The
gate script is taken from the workflow's own revision, so a dispatched
republish of a tag cut before this change still runs it.

The gate lives in packaging/aur/await-package-runs.sh so it can be
exercised against a stubbed gh; its fixture tests run in the AUR build job
on every trigger.
2026-09-19 05:04:07 +00:00
..