diff --git a/.crow/auto-apply-patches.yaml b/.crow/auto-apply-patches.yaml index 15cc1ee..2ac6886 100644 --- a/.crow/auto-apply-patches.yaml +++ b/.crow/auto-apply-patches.yaml @@ -6,8 +6,9 @@ # human reviews the PR. Novel source diffs / unknown signatures are never # proposed. Global across platforms, so a single job -- no matrix. # -# Needs a write token (REPO_RW_TOKEN) to push and FORGEJO_TOKEN to open the PR. -# Register the `auto-apply-patches` cron in the crow UI, or run manually: +# FORGEJO_TOKEN is used for both the branch push and opening the PR (no separate +# write-scoped secret needed). Register the `auto-apply-patches` cron in the crow +# UI, or run manually: # woodpecker-cli pipeline create --var task=auto-apply-patches --branch=main 7 variables: patch_limit: @@ -34,8 +35,6 @@ steps: from_secret: PGPASS REPO_RO_TOKEN: from_secret: REPO_RO_TOKEN - REPO_RW_TOKEN: - from_secret: REPO_RW_TOKEN FORGEJO_TOKEN: from_secret: FORGEJO_TOKEN GIT_USER: devxy-bot diff --git a/local/patches/README.md b/local/patches/README.md index 455a96c..ce60c9a 100644 --- a/local/patches/README.md +++ b/local/patches/README.md @@ -84,11 +84,12 @@ Rscript local/trial-build-patch.R #### Autonomous PR + trial-build gate `--open-pr` closes the loop: it writes the top-N candidates (by failure volume) onto the reused `auto/registry-patch-proposals` branch and opens/updates a single PR. -`.crow/auto-apply-patches.yaml` runs this on a cron (needs `FORGEJO_TOKEN` and a write-scoped `REPO_RW_TOKEN`). +`.crow/auto-apply-patches.yaml` runs this on a cron. +`FORGEJO_TOKEN` is used for both the branch push and the PR (no separate write-scoped secret). ```bash # Bounded batch; opens/updates one PR. -PGPASS=... FORGEJO_TOKEN=... REPO_RW_TOKEN=... Rscript local/propose-patches.R --open-pr --limit 10 +PGPASS=... FORGEJO_TOKEN=... Rscript local/propose-patches.R --open-pr --limit 10 ``` The merge gate is `.crow/trial-build-registry.yaml`: matrixed over the build-env images, each platform trial-builds only the entries the branch **adds** (`local/trial-build-registry.R`, which diffs the registry against `main`) and is green only if every new entry builds. diff --git a/local/propose-patches.R b/local/propose-patches.R index fb45ea9..11085f0 100644 --- a/local/propose-patches.R +++ b/local/propose-patches.R @@ -21,8 +21,8 @@ # the proposals ledger (commit + open a PR yourself) # --open-issue post/update a Forgejo tracking issue (needs FORGEJO_TOKEN) # --open-pr write the entries, push the `auto/registry-patch-proposals` -# branch, and open/update a PR autonomously (needs -# FORGEJO_TOKEN, and REPO_RW_TOKEN to push in CI). The +# branch, and open/update a PR autonomously. Uses +# FORGEJO_TOKEN for both the push and the PR API. The # `trial-build-registry` pipeline is the merge gate. # --limit N only act on the top-N candidates by failure volume # (bounded batch; the rest are picked up on the next run) @@ -466,18 +466,15 @@ if (do_write) { if (length(candidate_entries) == 1L) "entry" else "entries" ) ) - # Push with a write token when provided (CI); otherwise rely on origin creds. - rw_token <- Sys.getenv("REPO_RW_TOKEN") - push_target <- if (nchar(rw_token) > 0L) { - sprintf( - "https://%s:%s@git.devxy.io/%s.git", - Sys.getenv("GIT_USER", "devxy-bot"), - rw_token, - repo - ) - } else { - "origin" - } + # Push over HTTPS with FORGEJO_TOKEN (same token used for the PR API), so no + # separate write-scoped secret is needed. The read-only `origin` clone URL + # can't push, so build an authenticated URL explicitly. + push_target <- sprintf( + "https://%s:%s@git.devxy.io/%s.git", + Sys.getenv("GIT_REMOTE_USER", "pat-s"), + forgejo_token, + repo + ) git("push", "-f", push_target, sprintf("HEAD:refs/heads/%s", pr_branch)) pr_title <- sprintf(