build-cran-binaries/.crow/trial-build-registry.yaml
pat-s 1e843523a0 fix(ci): gate the three ungated pipelines on their own variable (#155)
## Problem

A manual `crow pipeline create` instantiates **every** pipeline in `.crow/`, and each one decides for itself whether to run. Three had nothing to decide with — their only manual condition was a bare `event: manual`:

- `auto-apply-patches` — pushes to `auto/registry-patch-proposals` and opens/updates a PR
- `weekly-patch-proposals` — posts and edits two Forgejo issues
- `trial-build-registry` — starts a build per matrix row, on both arches

So they fired on *any* manual trigger in this repo, whatever it was for. That is how they came to run alongside a manual `process-updates` run for `alpine-324-arm64` (#10723), which is also why that pipeline is marked failure.

`repair-built-stamp.yaml` already documents the rule this breaks:

> The gate variable is `repair_built_stamp`, not `target_arch` … Every pipeline here gates on a variable named after itself for exactly that reason.

## What this changes

Each of the three gets a gate variable named after the pipeline, `evaluate`d on the manual event, defaulting to off:

```yaml
variables:
  auto_apply_patches:
    description: 'Run the auto-patch proposer. Also gates this pipeline.'
    options: ['true', 'false']
    default: 'false'

when:
  - event: manual
    evaluate: 'auto_apply_patches == "true"'
  - event: cron
    cron: auto-apply-patches
```

Cron triggers are untouched, so the scheduled runs behave exactly as before.

The run-manually comments in all three headers were also stale: they documented `--var task=<name>` with `woodpecker-cli`, and no pipeline evaluates a `task` variable. They now show the real invocation.

## Note on the sibling pipelines

The already-gated pipelines use `default: all` (e.g. `weekly_rebuild_missing`). If Crow applies a declared default to a variable that an API-created pipeline never passed, those would match on an unrelated manual run too — `weekly-rebuild-missing` would be an expensive way to find out. I could not settle that from #10723 because its step logs have since expired, so I left them alone rather than guess. The three fixed here default to `'false'`, which is safe under either semantics.

## Verification

`crow lint .crow/` passes. Auditing every pipeline that accepts a manual event now reports a gate on all ten:

```
build-all-versions-install-deps.yaml: gated
auto-apply-patches.yaml: gated
weekly-patch-proposals.yaml: gated
weekly-audit-missing.yaml: gated
repair-built-stamp.yaml: gated
archive-missed-packages.yaml: gated
weekly-rebuild-missing.yaml: gated
trial-build-registry.yaml: gated
build-all-versions.yaml: gated
process-updates.yaml: gated
```

Reviewed-on: #155
2026-08-09 10:02:05 +00:00

160 lines
4.9 KiB
YAML

# Merge gate for the auto-patch PR (issue #115, step 3).
# For each platform, trial-builds every registry entry the auto-patch branch
# ADDS (vs main) in that platform's own `reg.devxy.io/rpkgs/build-env-*` image,
# with the registry applied. A row with no new entries for its platform is a
# fast no-op. The pipeline is green only if every new entry builds, so it gates
# the PR before merge. Nothing is uploaded/archived/recorded.
#
# The repo uses no `pull_request` triggers, so this runs manually against the
# branch (or on a cron); point it at the auto-patch branch via `patch_branch`:
# crow pipeline create --branch main --var trial_build_registry=true \
# --var patch_branch=auto/registry-patch-proposals devxy/build-cran-binaries
#
# The gate variable is `trial_build_registry`, named after the pipeline: a
# manual run instantiates every pipeline in `.crow/`, so one without its own
# gate runs on *any* manual trigger in this repo. This one starts a build per
# matrix row on both arches, which is far too expensive to fire by accident.
variables:
trial_build_registry:
description: 'Trial-build the branch new registry entries. Also gates this pipeline.'
options:
- 'true'
- 'false'
default: 'false'
patch_branch:
description: 'Branch whose new registry entries to trial-build.'
default: auto/registry-patch-proposals
when:
- event: manual
evaluate: 'trial_build_registry == "true"'
- event: cron
cron: trial-build-registry
skip_clone: true
labels:
group: rpkgs-${ARCH}
matrix:
include:
- OS: alpine-322
ARCH: amd64
R_VERSION: 4.5.3
IMG: alpine:3.22
- OS: alpine-322
ARCH: arm64
R_VERSION: 4.5.3
IMG: alpine:3.22
- OS: alpine-323
ARCH: amd64
R_VERSION: 4.5.3
IMG: alpine:3.23
- OS: alpine-323
ARCH: arm64
R_VERSION: 4.5.3
IMG: alpine:3.23
- OS: alpine-324
ARCH: amd64
R_VERSION: 4.5.3
IMG: alpine:3.24
- OS: alpine-324
ARCH: arm64
R_VERSION: 4.5.3
IMG: alpine:3.24
- OS: redhat-8
ARCH: amd64
R_VERSION: 4.4.3
IMG: redhat:8
- OS: redhat-8
ARCH: arm64
R_VERSION: 4.4.3
IMG: redhat:8
- OS: redhat-9
ARCH: amd64
R_VERSION: 4.4.3
IMG: redhat:9
- OS: redhat-9
ARCH: arm64
R_VERSION: 4.4.3
IMG: redhat:9
- OS: redhat-10
ARCH: amd64
R_VERSION: 4.5.3
IMG: redhat:10
- OS: redhat-10
ARCH: arm64
R_VERSION: 4.5.3
IMG: redhat:10
- OS: ubuntu-2204
ARCH: amd64
R_VERSION: 4.4.3
IMG: ubuntu:jammy
- OS: ubuntu-2204
ARCH: arm64
R_VERSION: 4.4.3
IMG: ubuntu:jammy
- OS: ubuntu-2404
ARCH: amd64
R_VERSION: 4.4.3
IMG: ubuntu:noble
- OS: ubuntu-2404
ARCH: arm64
R_VERSION: 4.4.3
IMG: ubuntu:noble
- OS: ubuntu-2604
ARCH: amd64
R_VERSION: 4.5.3
IMG: ubuntu:resolute
- OS: ubuntu-2604
ARCH: arm64
R_VERSION: 4.5.3
IMG: ubuntu:resolute
steps:
- name: 'Trial-build new registry entries'
image: reg.devxy.io/rpkgs/build-env-${IMG}
pull: true
environment:
B2_S3_ACCESS_KEY:
from_secret: B2_S3_ACCESS_KEY
B2_S3_SECRET_KEY:
from_secret: B2_S3_SECRET_KEY
REPO_RO_TOKEN:
from_secret: REPO_RO_TOKEN
GITHUB_PAT:
from_secret: GITHUB_PAT
PLATFORM: ${OS}
ARCH: ${ARCH}
R_VERSION: ${R_VERSION}
R_LIBS_USER: /mnt/cache/R-pkgs
# Surface the real compiler error when an isolated patched build fails,
# instead of bincraft's opaque "System command 'R' failed" (needs bincraft
# with BINCRAFT_VERBOSE_PATCH_BUILD support; harmless on older versions).
BINCRAFT_VERBOSE_PATCH_BUILD: 'TRUE'
commands:
# Clone main, then check out the auto-patch branch if it exists. When the
# proposer had no candidates it never (re)creates that branch, so a missing
# branch means "nothing to verify" -- no-op cleanly instead of failing the
# clone.
- git clone -q https://pat-s:$$REPO_RO_TOKEN@git.devxy.io/devxy/build-cran-binaries.git .
- git fetch -q origin main
- 'if git ls-remote --exit-code --heads origin ${patch_branch} >/dev/null 2>&1; then git fetch -q origin ${patch_branch} && git checkout -q FETCH_HEAD; else echo "No ${patch_branch} branch; no pending auto-patch proposals to verify."; exit 0; fi'
- mkdir -p /mnt/cache/R-pkgs
- rm -rf /mnt/cache/R-pkgs/00LOCK-*
- /opt/R/$R_VERSION/bin/Rscript local/install-bincraft.R
- /opt/R/$R_VERSION/bin/Rscript local/trial-build-registry.R origin/main
backend_options:
kubernetes:
resources:
requests:
memory: 2Gi
cpu: 2000m
limits:
memory: 4Gi
cpu: 2000m
tolerations:
- key: 'CI'
operator: 'Equal'
value: 'true'
effect: 'NoSchedule'