The no-op path worked (the else branch runs and exits 0), but using `git fetch` as the existence check printed `fatal: couldn't find remote ref ...` to stderr when the branch is absent -- which reads as a failure even though the step succeeds. Probe with `git ls-remote --exit-code --heads` instead, which is silent and sets a clean exit code; only fetch/checkout when the branch exists.
148 lines
4.4 KiB
YAML
148 lines
4.4 KiB
YAML
# Merge gate for the auto-patch PR (issue #115, step 3).
|
|
# For each platform, trial-builds every registry entry the auto-patch branch
|
|
# ADDS (vs main) in that platform's own `reg.devxy.io/rpkgs/build-env-*` image,
|
|
# with the registry applied. A row with no new entries for its platform is a
|
|
# fast no-op. The pipeline is green only if every new entry builds, so it gates
|
|
# the PR before merge. Nothing is uploaded/archived/recorded.
|
|
#
|
|
# The repo uses no `pull_request` triggers, so this runs manually against the
|
|
# branch (or on a cron); point it at the auto-patch branch via `patch_branch`:
|
|
# woodpecker-cli pipeline create --var task=trial-build-registry \
|
|
# --var patch_branch=auto/registry-patch-proposals --branch=main 7
|
|
variables:
|
|
patch_branch:
|
|
description: 'Branch whose new registry entries to trial-build.'
|
|
default: auto/registry-patch-proposals
|
|
|
|
when:
|
|
- event: manual
|
|
- event: cron
|
|
cron: trial-build-registry
|
|
|
|
skip_clone: true
|
|
|
|
labels:
|
|
group: rpkgs-${ARCH}
|
|
|
|
matrix:
|
|
include:
|
|
- OS: alpine-322
|
|
ARCH: amd64
|
|
R_VERSION: 4.5.3
|
|
IMG: alpine:3.24
|
|
- OS: alpine-322
|
|
ARCH: arm64
|
|
R_VERSION: 4.5.3
|
|
IMG: alpine:3.24
|
|
- OS: alpine-323
|
|
ARCH: amd64
|
|
R_VERSION: 4.5.3
|
|
IMG: alpine:3.24
|
|
- OS: alpine-323
|
|
ARCH: arm64
|
|
R_VERSION: 4.5.3
|
|
IMG: alpine:3.24
|
|
- OS: alpine-324
|
|
ARCH: amd64
|
|
R_VERSION: 4.5.3
|
|
IMG: alpine:3.24
|
|
- OS: alpine-324
|
|
ARCH: arm64
|
|
R_VERSION: 4.5.3
|
|
IMG: alpine:3.24
|
|
- OS: redhat-8
|
|
ARCH: amd64
|
|
R_VERSION: 4.4.3
|
|
IMG: redhat:8
|
|
- OS: redhat-8
|
|
ARCH: arm64
|
|
R_VERSION: 4.4.3
|
|
IMG: redhat:8
|
|
- OS: redhat-9
|
|
ARCH: amd64
|
|
R_VERSION: 4.4.3
|
|
IMG: redhat:9
|
|
- OS: redhat-9
|
|
ARCH: arm64
|
|
R_VERSION: 4.4.3
|
|
IMG: redhat:9
|
|
- OS: redhat-10
|
|
ARCH: amd64
|
|
R_VERSION: 4.5.3
|
|
IMG: redhat:10
|
|
- OS: redhat-10
|
|
ARCH: arm64
|
|
R_VERSION: 4.5.3
|
|
IMG: redhat:10
|
|
- OS: ubuntu-2204
|
|
ARCH: amd64
|
|
R_VERSION: 4.4.3
|
|
IMG: ubuntu:jammy
|
|
- OS: ubuntu-2204
|
|
ARCH: arm64
|
|
R_VERSION: 4.4.3
|
|
IMG: ubuntu:jammy
|
|
- OS: ubuntu-2404
|
|
ARCH: amd64
|
|
R_VERSION: 4.4.3
|
|
IMG: ubuntu:noble
|
|
- OS: ubuntu-2404
|
|
ARCH: arm64
|
|
R_VERSION: 4.4.3
|
|
IMG: ubuntu:noble
|
|
- OS: ubuntu-2604
|
|
ARCH: amd64
|
|
R_VERSION: 4.5.3
|
|
IMG: ubuntu:resolute
|
|
- OS: ubuntu-2604
|
|
ARCH: arm64
|
|
R_VERSION: 4.5.3
|
|
IMG: ubuntu:resolute
|
|
|
|
steps:
|
|
- name: 'Trial-build new registry entries'
|
|
image: reg.devxy.io/rpkgs/build-env-${IMG}
|
|
pull: true
|
|
environment:
|
|
B2_S3_ACCESS_KEY:
|
|
from_secret: B2_S3_ACCESS_KEY
|
|
B2_S3_SECRET_KEY:
|
|
from_secret: B2_S3_SECRET_KEY
|
|
REPO_RO_TOKEN:
|
|
from_secret: REPO_RO_TOKEN
|
|
GITHUB_PAT:
|
|
from_secret: GITHUB_PAT
|
|
PLATFORM: ${OS}
|
|
ARCH: ${ARCH}
|
|
R_VERSION: ${R_VERSION}
|
|
R_LIBS_USER: /mnt/cache/R-pkgs
|
|
# Surface the real compiler error when an isolated patched build fails,
|
|
# instead of bincraft's opaque "System command 'R' failed" (needs bincraft
|
|
# with BINCRAFT_VERBOSE_PATCH_BUILD support; harmless on older versions).
|
|
BINCRAFT_VERBOSE_PATCH_BUILD: 'TRUE'
|
|
commands:
|
|
# Clone main, then check out the auto-patch branch if it exists. When the
|
|
# proposer had no candidates it never (re)creates that branch, so a missing
|
|
# branch means "nothing to verify" -- no-op cleanly instead of failing the
|
|
# clone.
|
|
- git clone -q https://pat-s:$$REPO_RO_TOKEN@git.devxy.io/devxy/build-cran-binaries.git .
|
|
- git fetch -q origin main
|
|
- 'if git ls-remote --exit-code --heads origin ${patch_branch} >/dev/null 2>&1; then git fetch -q origin ${patch_branch} && git checkout -q FETCH_HEAD; else echo "No ${patch_branch} branch; no pending auto-patch proposals to verify."; exit 0; fi'
|
|
- mkdir -p /mnt/cache/R-pkgs
|
|
- rm -rf /mnt/cache/R-pkgs/00LOCK-*
|
|
- /opt/R/$R_VERSION/bin/Rscript local/install-bincraft.R
|
|
- /opt/R/$R_VERSION/bin/Rscript local/trial-build-registry.R origin/main
|
|
backend_options:
|
|
kubernetes:
|
|
resources:
|
|
requests:
|
|
memory: 2Gi
|
|
cpu: 2000m
|
|
limits:
|
|
memory: 4Gi
|
|
cpu: 2000m
|
|
tolerations:
|
|
- key: 'CI'
|
|
operator: 'Equal'
|
|
value: 'true'
|
|
effect: 'NoSchedule'
|