workflow: Gitea-canonical auth (Mike:<token>), PORTING_KEY everywhere, workflow_dispatch, preflight auth check
Some checks failed
port-to-omp / port (push) Failing after 4s

This commit is contained in:
2026-08-11 09:09:25 -04:00
parent 3f118202c1
commit 595ce48f3c

View File

@@ -4,17 +4,19 @@ name: port-to-omp
# Mike/omp-pygienium. # Mike/omp-pygienium.
# #
# Prerequisites on git.freno.me: # Prerequisites on git.freno.me:
# - an access token with write:repository scope, stored as the repo/org # - an access token with write:repository scope, stored as the repo secret
# secret PORTING_KEY (the workflow authenticates as `oauth2:<token>` over # PORTING_KEY (the workflow authenticates as https://Mike:<token>@…)
# https)
# - a registered Actions runner (act_runner) for this repo # - a registered Actions runner (act_runner) for this repo
# - the omp repo must exist (Mike/omp-pygienium)
# #
# Manual run: Actions tab → Run workflow (workflow_dispatch), or push.
# Safe by construction: the port commit lands in the omp repo, never here, so # Safe by construction: the port commit lands in the omp repo, never here, so
# this workflow cannot re-trigger itself. # this workflow cannot re-trigger itself.
on: on:
push: push:
branches: [master] branches: [master]
workflow_dispatch:
jobs: jobs:
port: port:
@@ -33,24 +35,25 @@ jobs:
run: | run: |
set -euo pipefail set -euo pipefail
# Trim the secret: a stray newline from pasting silently breaks # Trim the secret: a stray newline from pasting silently breaks
# oauth2 basic-auth. Fail loudly when it is missing entirely. # basic auth. Fail loudly when it is missing entirely.
PORTING_KEY="$(printf '%s' "${PORTING_KEY}" | tr -d '[:space:]')"
: "${PORTING_KEY:?PORTING_KEY secret is not set}" || exit 1 : "${PORTING_KEY:?PORTING_KEY secret is not set}" || exit 1
URL="https://oauth2:${PORTING_KEY}@git.freno.me/Mike/${OMP_REPO}.git" URL="https://Mike:${PORTING_KEY}@git.freno.me/Mike/${OMP_REPO}.git"
# The omp checkout lives in $RUNNER_TEMP, outside the pi checkout: # The omp checkout lives in $RUNNER_TEMP, outside the pi checkout:
# the port script refuses to write into a subdirectory of its own # the port script refuses to write into a subdirectory of its own
# source (cpSync would recurse into itself). # source (cpSync would recurse into itself).
PORT_DIR="${RUNNER_TEMP:-/tmp}/omp-port" PORT_DIR="${RUNNER_TEMP:-/tmp}/omp-port"
if git ls-remote "$URL" HEAD >/dev/null 2>&1; then # Preflight: reach the omp repo with the token. Fail with a clear
# message instead of a confusing error later at push time.
if ! git ls-remote "$URL" HEAD >/dev/null 2>&1; then
echo "::error::cannot read Mike/omp-pygienium with PORTING_KEY — is the secret set on this repo, valid, and write:repository-scoped?"
exit 1
fi
git clone --depth 1 "$URL" "$PORT_DIR" git clone --depth 1 "$URL" "$PORT_DIR"
git -C "$PORT_DIR" config user.name "omp-port" git -C "$PORT_DIR" config user.name "omp-port"
git -C "$PORT_DIR" config user.email "omp-port@freno.me" git -C "$PORT_DIR" config user.email "omp-port@freno.me"
else
git init -b main "$PORT_DIR"
git -C "$PORT_DIR" remote add origin "$URL"
git -C "$PORT_DIR" config user.name "omp-port"
git -C "$PORT_DIR" config user.email "omp-port@freno.me"
fi
# Regenerate the port directly into the omp checkout. The script # Regenerate the port directly into the omp checkout. The script
# preserves .git, asserts every patch rule, and runs `bun install` # preserves .git, asserts every patch rule, and runs `bun install`