Add the autopatch-pungi pipeline and Forgejo workflows #1
Loading…
Add table
Add a link
Reference in a new issue
No description provided.
Delete branch "pipeline"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
Summary
This PR adds
autopatch-pungi, a CLI that keepsrpms/pungiin sync with the Fedora pungi package. It implements plan B of the design in almalinux/pungi:docs/superpowers/specs/2026-09-29-pungi-autopatch-design.mdanddocs/superpowers/plans/2026-09-30-pungi-autopatch-pipeline.md.The CLI has five subcommands:
watch-upstream,prepare,verify,publish, andrun(all of them in sequence). A run:alma/<Version>patch branches, and inconfig.yaml/files/. State is kept in the commit trailersFedora-Commit,Alma-Patches, andAutopatch-Config.alma/<cur>onto a new upstream tagpungi-<new>into a new branchalma/<new>. Old branches are never rewritten.config.yamlthrough the autopatch-tool library, with the.alma.Nrelease iteration taken from existing tags..alma.entries.scripts/build-in-el.sh).local-build.shwraps it in podman and mounts the inputs with the shared:ro,zlabel.autopatch/syncintorpms/pungimain.Every failure opens a deduplicated issue in this repository, labelled
autopatch-failureorupstream-not-packaged. Forge API errors are treated as fetch failures and escalate to an issue after repeated failed runs. Nothing is pushed in--dry-run. Without a token and without--dry-run, the CLI exits with code 2.Token handling: the token is never put into URLs or
.git/config. Git authenticates with ahttp.<forge>/.extraHeaderheader passed through the environment. The workflow givesAUTOPATCH_TOKENonly to the two CLI steps, and CI runs only for PRs from this repository.This reuses the autopatch-tool config format and engine, not the existing autopatch webhook service. That service handles CentOS
cN→aNimports; pungi follows Fedora dist-git and needs rebase, build verification and a PR flow.Workflows
sync.yml: runs daily, on dispatch, and on push tomain. It is one job on a runner with the labelhost:watch-upstream, thenrun.ci.yml:pytestandautopatch_validate_config config.yamlon PRs.Verification
autopatch-pungi --dry-run runagainst the real repositories:pungi-4.14.0-2.alma.1;1185 passed, 2 skippedeach;publish:no-rpms-repoissue, becauserpms/pungidoes not exist yet.alma/4.14.0). It reports the conflicting kojimock patch andpungi/phases/gather/__init__.py.Go-live steps (not in this PR)
rpms/pungiwith an initial commit onmain(auto_init).hostrunner for this repository on the AWS machine requested from infra, and add theBOT_TOKENsecret.rpms/pungiPRs with a merge commit or a rebase, not a squash, so the state trailers stay in the history ofmain.failure.rpms/pungibranchesmainandautopatch/sync.🤖 Generated with Claude Code