feat(local): auto-apply registry patches with a build-env trial-build gate

Close the classifier loop (issue #115, step 3): turn the auto-proposable
candidates into an actual PR, gated by a real trial build in our own build-env
images. Model chosen: autonomous PR, PR-first with a CI trial-build gate,
bounded top-N batch per run.

- propose-patches.R: add --limit N (top candidates by failure volume; the rest
  defer to the next run) and --open-pr, which writes the entries onto the reused
  auto/registry-patch-proposals branch, pushes with REPO_RW_TOKEN, and
  opens/updates one PR via the Forgejo API
- add .crow/auto-apply-patches.yaml (single job) to run --open-pr on a cron
- add local/trial-build-registry.R + .crow/trial-build-registry.yaml: the merge
  gate. Matrixed over the real OS/IMG build-env images, each platform diffs the
  branch registry against main and trial-builds only the entries it adds, in
  reg.devxy.io/rpkgs/build-env-*; green only if every new entry builds. The
  base-registry read fails loud rather than silently building the whole registry
- add pure entry_applies_to_os()/new_registry_packages() helpers + tests
- document the autonomous-PR + gate flow in local/patches/README.md

The repo uses no pull_request triggers, so the gate runs manually/cron against
the branch; wiring it to the PR needs event: pull_request on the forge.
This commit is contained in:
Patrick Schratz 2026-07-15 08:02:49 +00:00
commit 321b46c436
No known key found for this signature in database
GPG key ID: 62050D5BC68AB6DC
2 changed files with 633 additions and 2 deletions

View file

@ -0,0 +1,65 @@
# Auto-apply registry patches (issue #115, step 3 automation).
# Classifies `single_builds` failures and, for the top-N auto-proposable
# candidates by failure volume, writes the registry entries onto the reused
# `auto/registry-patch-proposals` branch and opens/updates a single PR.
# Nothing merges: the `trial-build-registry` pipeline is the merge gate, and a
# human reviews the PR. Novel source diffs / unknown signatures are never
# proposed. Global across platforms, so a single job -- no matrix.
#
# Needs a write token (REPO_RW_TOKEN) to push and FORGEJO_TOKEN to open the PR.
# Register the `auto-apply-patches` cron in the crow UI, or run manually:
# woodpecker-cli pipeline create --var task=auto-apply-patches --branch=main 7
variables:
patch_limit:
description: 'Max candidates to propose per run (top by failure volume).'
default: '10'
when:
- event: manual
evaluate: 'task == "auto-apply-patches"'
- event: cron
cron: auto-apply-patches
skip_clone: true
labels:
group: rpkgs-amd64
steps:
- name: 'Auto-apply registry patches'
image: reg.devxy.io/rpkgs/build-env-alpine:3.24
pull: true
environment:
PGPASS:
from_secret: PGPASS
REPO_RO_TOKEN:
from_secret: REPO_RO_TOKEN
REPO_RW_TOKEN:
from_secret: REPO_RW_TOKEN
FORGEJO_TOKEN:
from_secret: FORGEJO_TOKEN
GIT_USER: devxy-bot
GIT_EMAIL: bot@devxy.io
PATCH_LIMIT: ${patch_limit}
R_VERSION: 4.5.3
R_LIBS_USER: /mnt/cache/R-pkgs
commands:
- git clone -q https://pat-s:$$REPO_RO_TOKEN@git.devxy.io/devxy/build-cran-binaries.git .
- mkdir -p /mnt/cache/R-pkgs
- rm -rf /mnt/cache/R-pkgs/00LOCK-*
- /opt/R/$R_VERSION/bin/R -q -e 'pak::pak(c("httr2", "jsonlite"))'
- /opt/R/$R_VERSION/bin/Rscript local/propose-patches.R --open-pr --limit $PATCH_LIMIT
backend_options:
kubernetes:
resources:
requests:
memory: 1Gi
cpu: 2000m
limits:
memory: 2Gi
cpu: 2000m
tolerations:
- key: 'CI'
operator: 'Equal'
value: 'true'
effect: 'NoSchedule'

View file

@ -0,0 +1,140 @@
# Merge gate for the auto-patch PR (issue #115, step 3).
# For each platform, trial-builds every registry entry the auto-patch branch
# ADDS (vs main) in that platform's own `reg.devxy.io/rpkgs/build-env-*` image,
# with the registry applied. A row with no new entries for its platform is a
# fast no-op. The pipeline is green only if every new entry builds, so it gates
# the PR before merge. Nothing is uploaded/archived/recorded.
#
# The repo uses no `pull_request` triggers, so this runs manually against the
# branch (or on a cron); point it at the auto-patch branch via `patch_branch`:
# woodpecker-cli pipeline create --var task=trial-build-registry \
# --var patch_branch=auto/registry-patch-proposals --branch=main 7
variables:
patch_branch:
description: 'Branch whose new registry entries to trial-build.'
default: auto/registry-patch-proposals
when:
- event: manual
evaluate: 'task == "trial-build-registry"'
- event: cron
cron: trial-build-registry
skip_clone: true
labels:
group: rpkgs-${ARCH}
matrix:
include:
- OS: alpine-322
ARCH: amd64
R_VERSION: 4.5.3
IMG: alpine:3.24
- OS: alpine-322
ARCH: arm64
R_VERSION: 4.5.3
IMG: alpine:3.24
- OS: alpine-323
ARCH: amd64
R_VERSION: 4.5.3
IMG: alpine:3.24
- OS: alpine-323
ARCH: arm64
R_VERSION: 4.5.3
IMG: alpine:3.24
- OS: alpine-324
ARCH: amd64
R_VERSION: 4.5.3
IMG: alpine:3.24
- OS: alpine-324
ARCH: arm64
R_VERSION: 4.5.3
IMG: alpine:3.24
- OS: redhat-8
ARCH: amd64
R_VERSION: 4.4.3
IMG: redhat:8
- OS: redhat-8
ARCH: arm64
R_VERSION: 4.4.3
IMG: redhat:8
- OS: redhat-9
ARCH: amd64
R_VERSION: 4.4.3
IMG: redhat:9
- OS: redhat-9
ARCH: arm64
R_VERSION: 4.4.3
IMG: redhat:9
- OS: redhat-10
ARCH: amd64
R_VERSION: 4.5.3
IMG: redhat:10
- OS: redhat-10
ARCH: arm64
R_VERSION: 4.5.3
IMG: redhat:10
- OS: ubuntu-2204
ARCH: amd64
R_VERSION: 4.4.3
IMG: ubuntu:jammy
- OS: ubuntu-2204
ARCH: arm64
R_VERSION: 4.4.3
IMG: ubuntu:jammy
- OS: ubuntu-2404
ARCH: amd64
R_VERSION: 4.4.3
IMG: ubuntu:noble
- OS: ubuntu-2404
ARCH: arm64
R_VERSION: 4.4.3
IMG: ubuntu:noble
- OS: ubuntu-2604
ARCH: amd64
R_VERSION: 4.5.3
IMG: ubuntu:resolute
- OS: ubuntu-2604
ARCH: arm64
R_VERSION: 4.5.3
IMG: ubuntu:resolute
steps:
- name: 'Trial-build new registry entries'
image: reg.devxy.io/rpkgs/build-env-${IMG}
pull: true
environment:
B2_S3_ACCESS_KEY:
from_secret: B2_S3_ACCESS_KEY
B2_S3_SECRET_KEY:
from_secret: B2_S3_SECRET_KEY
REPO_RO_TOKEN:
from_secret: REPO_RO_TOKEN
GITHUB_PAT:
from_secret: GITHUB_PAT
PLATFORM: ${OS}
ARCH: ${ARCH}
R_VERSION: ${R_VERSION}
R_LIBS_USER: /mnt/cache/R-pkgs
commands:
- git clone -q --branch ${patch_branch} https://pat-s:$$REPO_RO_TOKEN@git.devxy.io/devxy/build-cran-binaries.git .
- git fetch -q origin main
- mkdir -p /mnt/cache/R-pkgs
- rm -rf /mnt/cache/R-pkgs/00LOCK-*
- /opt/R/$R_VERSION/bin/Rscript local/install-bincraft.R
- /opt/R/$R_VERSION/bin/Rscript local/trial-build-registry.R origin/main
backend_options:
kubernetes:
resources:
requests:
memory: 2Gi
cpu: 2000m
limits:
memory: 4Gi
cpu: 2000m
tolerations:
- key: 'CI'
operator: 'Equal'
value: 'true'
effect: 'NoSchedule'