# Auto-apply registry patches (issue #115, step 3 automation). # Classifies `single_builds` failures and, for the top-N auto-proposable # candidates by failure volume, writes the registry entries onto the reused # `auto/registry-patch-proposals` branch and opens/updates a single PR. # Nothing merges: the `trial-build-registry` pipeline is the merge gate, and a # human reviews the PR. Novel source diffs / unknown signatures are never # proposed. Global across platforms, so a single job -- no matrix. # # FORGEJO_TOKEN is used for both the branch push and opening the PR (no separate # write-scoped secret needed). Register the `auto-apply-patches` cron in the crow # UI, or run manually: # crow pipeline create --branch main \ # --var auto_apply_patches=true devxy/build-cran-binaries # # The gate variable is `auto_apply_patches`, named after the pipeline: a manual # run instantiates every pipeline in `.crow/`, so one without its own gate runs # on *any* manual trigger in this repo. This one pushes a branch and opens a PR, # so it must stay off unless it is what was asked for. variables: auto_apply_patches: description: 'Run the auto-patch proposer. Also gates this pipeline.' options: - 'true' - 'false' default: 'false' patch_limit: description: 'Max candidates to propose per run (top by failure volume).' default: '10' when: - event: manual evaluate: 'auto_apply_patches == "true"' - event: cron cron: auto-apply-patches skip_clone: true labels: group: rpkgs-amd64 steps: - name: 'Auto-apply registry patches' image: reg.devxy.io/rpkgs/build-env-alpine:3.24 pull: true environment: PGPASS: from_secret: PGPASS REPO_RO_TOKEN: from_secret: REPO_RO_TOKEN FORGEJO_TOKEN: from_secret: FORGEJO_TOKEN GIT_USER: devxy-bot GIT_EMAIL: bot@devxy.io PATCH_LIMIT: ${patch_limit} R_VERSION: 4.5.3 R_LIBS_USER: /mnt/cache/R-pkgs commands: - git clone -q https://pat-s:$$REPO_RO_TOKEN@git.devxy.io/devxy/build-cran-binaries.git . - mkdir -p /mnt/cache/R-pkgs - rm -rf /mnt/cache/R-pkgs/00LOCK-* - UVR_R_BIN=/opt/R/$R_VERSION/bin/R local/uvr-install.sh httr2 jsonlite - /opt/R/$R_VERSION/bin/Rscript local/propose-patches.R --open-pr --limit $PATCH_LIMIT backend_options: kubernetes: resources: requests: memory: 1Gi cpu: 2000m limits: memory: 2Gi cpu: 2000m tolerations: - key: 'CI' operator: 'Equal' value: 'true' effect: 'NoSchedule'