feat(local): auto-apply registry patches with a build-env trial-build gate #124

Merged
pat-s merged 1 commit from t3code/auto-apply-patches into main 2026-07-15 08:28:15 +00:00
Owner

Closes the classifier loop (issue #115, step 3): turns the auto-proposable candidates into an actual PR, gated by a real trial build in our own build-env images.

Chosen model (from the design discussion): autonomous PR, PR-first with a CI trial-build gate, bounded top-N batch per run.

Creating the patch PR

  • propose-patches.R gains:
    • --limit N -- act on the top-N candidates by failure volume; the rest defer to the next run (logged).
    • --open-pr -- write the entries onto the reused auto/registry-patch-proposals branch, push (with REPO_RW_TOKEN), and open/update one PR via the Forgejo API (so re-runs update the same PR instead of piling up).
  • .crow/auto-apply-patches.yaml -- a single job that runs --open-pr --limit on a cron/manual trigger. Needs FORGEJO_TOKEN + a write-scoped REPO_RW_TOKEN.

Novel source diffs and unknown signatures are still never proposed; nothing merges.

The merge gate (our build-env images)

  • .crow/trial-build-registry.yaml -- matrixed over the real OS/IMG build-env matrix (alpine:3.24, redhat:8/9/10, ubuntu:jammy/noble/resolute for ubuntu-2604). Each platform runs local/trial-build-registry.R, which diffs the branch registry against main and trial-builds only the entries the branch adds that apply to that platform, inside reg.devxy.io/rpkgs/build-env-*. Green only if every new entry builds; a platform with no new entries is a fast no-op. Nothing is uploaded/archived/recorded.
  • The base-registry read fails loud if it can't read registry.json at main, rather than silently treating the base as empty and trial-building the whole registry.

Notes / follow-up

  • The repo uses no pull_request triggers, so the gate runs manually or on a cron against the branch (--var patch_branch=...). Wiring it to fire automatically on the PR needs event: pull_request enabled on the Forgejo webhook -- a one-line addition once that's on.
  • Two new crons to register in the crow UI: auto-apply-patches and trial-build-registry. New secret needed: REPO_RW_TOKEN (write scope) for the push.

Verification

  • New pure helpers entry_applies_to_os() / new_registry_packages() covered by tests (platform codename/family/wildcard matching; added-vs-unchanged entry detection; per-platform filtering).
  • --limit smoke (stubbed DB): top-2 by volume proposed, 3 deferred, candidate registry validates.
  • Full suite: 105 tests pass; all pre-commit hooks pass (air, prettier, markdownlint, yamllint, validate-patches).
Closes the classifier loop (issue #115, step 3): turns the auto-proposable candidates into an actual PR, gated by a real trial build **in our own build-env images**. Chosen model (from the design discussion): **autonomous PR**, **PR-first with a CI trial-build gate**, **bounded top-N batch** per run. ## Creating the patch PR - `propose-patches.R` gains: - `--limit N` -- act on the top-N candidates by failure volume; the rest defer to the next run (logged). - `--open-pr` -- write the entries onto the reused `auto/registry-patch-proposals` branch, push (with `REPO_RW_TOKEN`), and open/update **one** PR via the Forgejo API (so re-runs update the same PR instead of piling up). - `.crow/auto-apply-patches.yaml` -- a single job that runs `--open-pr --limit` on a cron/manual trigger. Needs `FORGEJO_TOKEN` + a write-scoped `REPO_RW_TOKEN`. Novel source diffs and unknown signatures are still never proposed; nothing merges. ## The merge gate (our build-env images) - `.crow/trial-build-registry.yaml` -- matrixed over the real `OS/IMG` build-env matrix (alpine:3.24, redhat:8/9/10, ubuntu:jammy/noble/**resolute** for ubuntu-2604). Each platform runs `local/trial-build-registry.R`, which diffs the branch registry against `main` and trial-builds **only the entries the branch adds** that apply to that platform, inside `reg.devxy.io/rpkgs/build-env-*`. Green only if every new entry builds; a platform with no new entries is a fast no-op. Nothing is uploaded/archived/recorded. - The base-registry read **fails loud** if it can't read `registry.json` at `main`, rather than silently treating the base as empty and trial-building the whole registry. ## Notes / follow-up - The repo uses **no `pull_request` triggers**, so the gate runs manually or on a cron against the branch (`--var patch_branch=...`). Wiring it to fire automatically on the PR needs `event: pull_request` enabled on the Forgejo webhook -- a one-line addition once that's on. - Two new crons to register in the crow UI: `auto-apply-patches` and `trial-build-registry`. New secret needed: `REPO_RW_TOKEN` (write scope) for the push. ## Verification - New pure helpers `entry_applies_to_os()` / `new_registry_packages()` covered by tests (platform codename/family/wildcard matching; added-vs-unchanged entry detection; per-platform filtering). - `--limit` smoke (stubbed DB): top-2 by volume proposed, 3 deferred, candidate registry validates. - Full suite: 105 tests pass; all pre-commit hooks pass (air, prettier, markdownlint, yamllint, validate-patches).
Close the classifier loop (issue #115, step 3): turn the auto-proposable
candidates into an actual PR, gated by a real trial build in our own build-env
images. Model chosen: autonomous PR, PR-first with a CI trial-build gate,
bounded top-N batch per run.

- propose-patches.R: add --limit N (top candidates by failure volume; the rest
  defer to the next run) and --open-pr, which writes the entries onto the reused
  auto/registry-patch-proposals branch, pushes with REPO_RW_TOKEN, and
  opens/updates one PR via the Forgejo API
- add .crow/auto-apply-patches.yaml (single job) to run --open-pr on a cron
- add local/trial-build-registry.R + .crow/trial-build-registry.yaml: the merge
  gate. Matrixed over the real OS/IMG build-env images, each platform diffs the
  branch registry against main and trial-builds only the entries it adds, in
  reg.devxy.io/rpkgs/build-env-*; green only if every new entry builds. The
  base-registry read fails loud rather than silently building the whole registry
- add pure entry_applies_to_os()/new_registry_packages() helpers + tests
- document the autonomous-PR + gate flow in local/patches/README.md

The repo uses no pull_request triggers, so the gate runs manually/cron against
the branch; wiring it to the PR needs event: pull_request on the forge.
pat-s merged commit 4bca17e4ac into main 2026-07-15 08:28:15 +00:00
pat-s deleted branch t3code/auto-apply-patches 2026-07-15 08:28:16 +00:00
Sign in to join this conversation.
No reviewers
No labels
No milestone
No assignees
1 participant
Notifications
Due date
The due date is invalid or out of range. Please use the format "yyyy-mm-dd".

No due date set.

Dependencies

No dependencies set

Reference
devxy/build-cran-binaries!124
No description provided.