feat(local): auto-apply registry patches with a build-env trial-build gate (#124)
All checks were successful
ci/crow/cron/process-updates/14 Pipeline was successful
ci/crow/cron/process-updates/13 Pipeline was successful
ci/crow/cron/process-updates/16 Pipeline was successful
ci/crow/cron/process-updates/18 Pipeline was successful
ci/crow/cron/process-updates/15 Pipeline was successful
ci/crow/cron/process-updates/12 Pipeline was successful
ci/crow/cron/process-updates/17 Pipeline was successful
ci/crow/cron/process-updates/6 Pipeline was successful
ci/crow/cron/process-updates/5 Pipeline was successful
ci/crow/cron/process-updates/11 Pipeline was successful
ci/crow/cron/process-updates/1 Pipeline was successful
ci/crow/cron/process-updates/2 Pipeline was successful
ci/crow/cron/process-updates/7 Pipeline was successful
ci/crow/cron/process-updates/8 Pipeline was successful
All checks were successful
ci/crow/cron/process-updates/14 Pipeline was successful
ci/crow/cron/process-updates/13 Pipeline was successful
ci/crow/cron/process-updates/16 Pipeline was successful
ci/crow/cron/process-updates/18 Pipeline was successful
ci/crow/cron/process-updates/15 Pipeline was successful
ci/crow/cron/process-updates/12 Pipeline was successful
ci/crow/cron/process-updates/17 Pipeline was successful
ci/crow/cron/process-updates/6 Pipeline was successful
ci/crow/cron/process-updates/5 Pipeline was successful
ci/crow/cron/process-updates/11 Pipeline was successful
ci/crow/cron/process-updates/1 Pipeline was successful
ci/crow/cron/process-updates/2 Pipeline was successful
ci/crow/cron/process-updates/7 Pipeline was successful
ci/crow/cron/process-updates/8 Pipeline was successful
Closes the classifier loop (issue #115, step 3): turns the auto-proposable candidates into an actual PR, gated by a real trial build **in our own build-env images**. Chosen model (from the design discussion): **autonomous PR**, **PR-first with a CI trial-build gate**, **bounded top-N batch** per run. ## Creating the patch PR - `propose-patches.R` gains: - `--limit N` -- act on the top-N candidates by failure volume; the rest defer to the next run (logged). - `--open-pr` -- write the entries onto the reused `auto/registry-patch-proposals` branch, push (with `REPO_RW_TOKEN`), and open/update **one** PR via the Forgejo API (so re-runs update the same PR instead of piling up). - `.crow/auto-apply-patches.yaml` -- a single job that runs `--open-pr --limit` on a cron/manual trigger. Needs `FORGEJO_TOKEN` + a write-scoped `REPO_RW_TOKEN`. Novel source diffs and unknown signatures are still never proposed; nothing merges. ## The merge gate (our build-env images) - `.crow/trial-build-registry.yaml` -- matrixed over the real `OS/IMG` build-env matrix (alpine:3.24, redhat:8/9/10, ubuntu:jammy/noble/**resolute** for ubuntu-2604). Each platform runs `local/trial-build-registry.R`, which diffs the branch registry against `main` and trial-builds **only the entries the branch adds** that apply to that platform, inside `reg.devxy.io/rpkgs/build-env-*`. Green only if every new entry builds; a platform with no new entries is a fast no-op. Nothing is uploaded/archived/recorded. - The base-registry read **fails loud** if it can't read `registry.json` at `main`, rather than silently treating the base as empty and trial-building the whole registry. ## Notes / follow-up - The repo uses **no `pull_request` triggers**, so the gate runs manually or on a cron against the branch (`--var patch_branch=...`). Wiring it to fire automatically on the PR needs `event: pull_request` enabled on the Forgejo webhook -- a one-line addition once that's on. - Two new crons to register in the crow UI: `auto-apply-patches` and `trial-build-registry`. New secret needed: `REPO_RW_TOKEN` (write scope) for the push. ## Verification - New pure helpers `entry_applies_to_os()` / `new_registry_packages()` covered by tests (platform codename/family/wildcard matching; added-vs-unchanged entry detection; per-platform filtering). - `--limit` smoke (stubbed DB): top-2 by volume proposed, 3 deferred, candidate registry validates. - Full suite: 105 tests pass; all pre-commit hooks pass (air, prettier, markdownlint, yamllint, validate-patches). Reviewed-on: #124
This commit is contained in:
parent
21a2fe9e6c
commit
4bca17e4ac
1 changed files with 633 additions and 2 deletions
|
|
@ -175,4 +175,37 @@ blocked_summary <- function(report, max_pkgs = 15L) {
|
|||
})
|
||||
}
|
||||
|
||||
# Does a registry entry's `platforms` apply to a build on `os` (e.g.
|
||||
# "ubuntu-2604")? Mirrors bincraft's token match: an entry applies if any of its
|
||||
# platform tokens is "*", the OS codename, or the distro family ("ubuntu").
|
||||
entry_applies_to_os <- function(entry_platforms, os) {
|
||||
toks <- as.character(unlist(entry_platforms))
|
||||
family <- sub("-.*$", "", os) # ubuntu-2604 -> ubuntu
|
||||
any(toks %in% c("*", os, family))
|
||||
}
|
||||
|
||||
# Registry entries present in `current` but not in `base` (matched on
|
||||
# package|platforms|versions), optionally restricted to those that apply to a
|
||||
# given `os`. Used by the trial-build gate to build only the entries a PR adds.
|
||||
new_registry_packages <- function(current, base, os = NULL) {
|
||||
key <- function(e) {
|
||||
sprintf(
|
||||
"%s|%s|%s",
|
||||
e$package %||% "?",
|
||||
paste(sort(as.character(unlist(e$platforms))), collapse = ","),
|
||||
e$versions %||% "?"
|
||||
)
|
||||
}
|
||||
base_keys <- vapply(base %||% list(), key, character(1L))
|
||||
added <- Filter(function(e) !(key(e) %in% base_keys), current %||% list())
|
||||
if (!is.null(os)) {
|
||||
added <- Filter(function(e) entry_applies_to_os(e$platforms, os), added)
|
||||
}
|
||||
unique(vapply(
|
||||
added,
|
||||
function(e) as.character(e$package %||% ""),
|
||||
character(1L)
|
||||
))
|
||||
}
|
||||
|
||||
`%||%` <- function(a, b) if (is.null(a)) b else a
|
||||
|
|
|
|||
Loading…
Reference in a new issue