Files
pygienium/.gitea/workflows/port-to-omp.yml
2026-08-10 16:44:54 -04:00

73 lines
2.6 KiB
YAML

name: port-to-omp
# Regenerate the omp port of pygenium from this repo and push it to
# Mike/omp-pygienium.
#
# Prerequisites on git.freno.me:
# - an access token with write:repository scope, stored as the repo/org
# secret PORTING_TOKEN (the workflow authenticates as `oauth2:<token>` over
# https)
# - a registered Actions runner (act_runner) for this repo
#
# Safe by construction: the port commit lands in the omp repo, never here, so
# this workflow cannot re-trigger itself.
on:
push:
branches: [master]
jobs:
port:
runs-on: ubuntu-latest
steps:
- name: Checkout
uses: actions/checkout@v4
- name: Install bun
uses: oven-sh/setup-bun@v2
- name: Port to omp
env:
PORTING_TOKEN: ${{ secrets.PORTING_TOKEN }}
OMP_REPO: omp-pygienium
run: |
set -euo pipefail
# Trim the secret: a stray newline from pasting silently breaks
# oauth2 basic-auth. Fail loudly when it is missing entirely.
PORTING_TOKEN="$(printf '%s' "${PORTING_TOKEN}" | tr -d '[:space:]')"
: "${PORTING_TOKEN:?PORTING_TOKEN secret is not set}"
URL="https://oauth2:${PORTING_TOKEN}@git.freno.me/Mike/${OMP_REPO}.git"
# The omp checkout lives in $RUNNER_TEMP, outside the pi checkout:
# the port script refuses to write into a subdirectory of its own
# source (cpSync would recurse into itself).
PORT_DIR="${RUNNER_TEMP:-/tmp}/omp-port"
if git ls-remote "$URL" HEAD >/dev/null 2>&1; then
git clone --depth 1 "$URL" "$PORT_DIR"
git -C "$PORT_DIR" config user.name "omp-port"
git -C "$PORT_DIR" config user.email "omp-port@freno.me"
else
git init -b main "$PORT_DIR"
git -C "$PORT_DIR" remote add origin "$URL"
git -C "$PORT_DIR" config user.name "omp-port"
git -C "$PORT_DIR" config user.email "omp-port@freno.me"
fi
# Regenerate the port directly into the omp checkout. The script
# preserves .git, asserts every patch rule, and runs `bun install`
# (refreshing bun.lock + node_modules).
bun "$GITHUB_WORKSPACE/port-to-omp.mjs" --out "$PORT_DIR"
cd "$PORT_DIR"
# The port must compile against the pinned @oh-my-pi SDK before it
# ships to users.
bun run typecheck
if git diff --quiet HEAD; then
echo "port unchanged; nothing to push"
exit 0
fi
git add -A
git commit -m "port: sync from ${GITHUB_REPOSITORY}@${GITHUB_SHA::8}"
git push origin HEAD:main