Add the autopatch-pungi pipeline and Forgejo workflows #1

Merged
soksanichenko merged 19 commits from pipeline into main 2026-09-30 11:46:06 +00:00

Summary

This PR adds autopatch-pungi, a CLI that keeps rpms/pungi in sync with the Fedora pungi package. It implements plan B of the design in almalinux/pungi: docs/superpowers/specs/2026-09-29-pungi-autopatch-design.md and docs/superpowers/plans/2026-09-30-pungi-autopatch-pipeline.md.

The CLI has five subcommands: watch-upstream, prepare, verify, publish, and run (all of them in sequence). A run:

  1. Detects changes in Fedora dist-git, in the alma/<Version> patch branches, and in config.yaml/files/. State is kept in the commit trailers Fedora-Commit, Alma-Patches, and Autopatch-Config.
  2. Rebases alma/<cur> onto a new upstream tag pungi-<new> into a new branch alma/<new>. Old branches are never rewritten.
  3. Generates the 1000+ patches.
  4. Applies config.yaml through the autopatch-tool library, with the .alma.N release iteration taken from existing tags.
  5. Merges the AlmaLinux changelog history by date, including released .alma. entries.
  6. Builds EL9 and EL10 in parallel with the ALBS repositories (scripts/build-in-el.sh). local-build.sh wraps it in podman and mounts the inputs with the shared :ro,z label.
  7. Opens or updates one PR from autopatch/sync into rpms/pungi main.

Every failure opens a deduplicated issue in this repository, labelled autopatch-failure or upstream-not-packaged. Forge API errors are treated as fetch failures and escalate to an issue after repeated failed runs. Nothing is pushed in --dry-run. Without a token and without --dry-run, the CLI exits with code 2.

Token handling: the token is never put into URLs or .git/config. Git authenticates with a http.<forge>/.extraHeader header passed through the environment. The workflow gives AUTOPATCH_TOKEN only to the two CLI steps, and CI runs only for PRs from this repository.

This reuses the autopatch-tool config format and engine, not the existing autopatch webhook service. That service handles CentOS cN → aN imports; pungi follows Fedora dist-git and needs rebase, build verification and a PR flow.

Workflows

  • sync.yml: runs daily, on dispatch, and on push to main. It is one job on a runner with the label host: watch-upstream, then run.
  • ci.yml: pytest and autopatch_validate_config config.yaml on PRs.

Verification

  • 82 unit tests pass.
  • I ran autopatch-pungi --dry-run run against the real repositories:
    • it produced tag pungi-4.14.0-2.alma.1;
    • the EL9 and EL10 builds passed, with 1185 passed, 2 skipped each;
    • it recorded the expected publish:no-rpms-repo issue, because rpms/pungi does not exist yet.
  • I ran a rebase-conflict scenario (a clone without alma/4.14.0). It reports the conflicting kojimock patch and pungi/phases/gather/__init__.py.
  • Every task was reviewed on its own, and the whole branch was reviewed at the end. The findings are fixed in this branch.

Go-live steps (not in this PR)

  • Create rpms/pungi with an initial commit on main (auto_init).
  • Register a host runner for this repository on the AWS machine requested from infra, and add the BOT_TOKEN secret.
  • Merge rpms/pungi PRs with a merge commit or a rebase, not a squash, so the state trailers stay in the history of main.
  • Check that Forgejo reports failed runs with the status failure.
  • Confirm with the autopatch service maintainers that its webhook ignores rpms/pungi branches main and autopatch/sync.

🤖 Generated with Claude Code

## Summary This PR adds `autopatch-pungi`, a CLI that keeps `rpms/pungi` in sync with the Fedora pungi package. It implements plan B of the design in almalinux/pungi: `docs/superpowers/specs/2026-09-29-pungi-autopatch-design.md` and `docs/superpowers/plans/2026-09-30-pungi-autopatch-pipeline.md`. The CLI has five subcommands: `watch-upstream`, `prepare`, `verify`, `publish`, and `run` (all of them in sequence). A run: 1. Detects changes in Fedora dist-git, in the `alma/<Version>` patch branches, and in `config.yaml`/`files/`. State is kept in the commit trailers `Fedora-Commit`, `Alma-Patches`, and `Autopatch-Config`. 2. Rebases `alma/<cur>` onto a new upstream tag `pungi-<new>` into a new branch `alma/<new>`. Old branches are never rewritten. 3. Generates the 1000+ patches. 4. Applies `config.yaml` through the autopatch-tool library, with the `.alma.N` release iteration taken from existing tags. 5. Merges the AlmaLinux changelog history by date, including released `.alma.` entries. 6. Builds EL9 and EL10 in parallel with the ALBS repositories (`scripts/build-in-el.sh`). `local-build.sh` wraps it in podman and mounts the inputs with the shared `:ro,z` label. 7. Opens or updates one PR from `autopatch/sync` into `rpms/pungi` `main`. Every failure opens a deduplicated issue in this repository, labelled `autopatch-failure` or `upstream-not-packaged`. Forge API errors are treated as fetch failures and escalate to an issue after repeated failed runs. Nothing is pushed in `--dry-run`. Without a token and without `--dry-run`, the CLI exits with code 2. Token handling: the token is never put into URLs or `.git/config`. Git authenticates with a `http.<forge>/.extraHeader` header passed through the environment. The workflow gives `AUTOPATCH_TOKEN` only to the two CLI steps, and CI runs only for PRs from this repository. This reuses the autopatch-tool config format and engine, not the existing autopatch webhook service. That service handles CentOS `cN` → `aN` imports; pungi follows Fedora dist-git and needs rebase, build verification and a PR flow. ## Workflows - `sync.yml`: runs daily, on dispatch, and on push to `main`. It is one job on a runner with the label `host`: `watch-upstream`, then `run`. - `ci.yml`: `pytest` and `autopatch_validate_config config.yaml` on PRs. ## Verification - 82 unit tests pass. - I ran `autopatch-pungi --dry-run run` against the real repositories: - it produced tag `pungi-4.14.0-2.alma.1`; - the EL9 and EL10 builds passed, with `1185 passed, 2 skipped` each; - it recorded the expected `publish:no-rpms-repo` issue, because `rpms/pungi` does not exist yet. - I ran a rebase-conflict scenario (a clone without `alma/4.14.0`). It reports the conflicting kojimock patch and `pungi/phases/gather/__init__.py`. - Every task was reviewed on its own, and the whole branch was reviewed at the end. The findings are fixed in this branch. ## Go-live steps (not in this PR) - Create `rpms/pungi` with an initial commit on `main` (`auto_init`). - Register a `host` runner for this repository on the AWS machine requested from infra, and add the `BOT_TOKEN` secret. - Merge `rpms/pungi` PRs with a merge commit or a rebase, not a squash, so the state trailers stay in the history of `main`. - Check that Forgejo reports failed runs with the status `failure`. - Confirm with the autopatch service maintainers that its webhook ignores `rpms/pungi` branches `main` and `autopatch/sync`. 🤖 Generated with [Claude Code](https://claude.com/claude-code)
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Carry released AlmaLinux changelog entries from rpms/pungi into the merge
Some checks failed
ci / test (pull_request) Has been cancelled
ab903dfebb
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Report forge errors from the open-PR lookup as fetch failures
Some checks failed
ci / test (pull_request) Has been cancelled
a417175732
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
soksanichenko deleted branch pipeline 2026-09-30 11:46:06 +00:00
Sign in to join this conversation.
No reviewers
No labels
No milestone
No project
No assignees
1 participant
Notifications
Due date
The due date is invalid or out of range. Please use the format "yyyy-mm-dd".

No due date set.

Dependencies

No dependencies set.

Reference
autopatch/pungi!1
No description provided.