Compare commits
7 Commits
c3771d22f2
...
1996a32153
| Author | SHA1 | Date | |
|---|---|---|---|
| 1996a32153 | |||
| 65998692ae | |||
| 094da1776b | |||
| 188e6eb882 | |||
| 9cc109910c | |||
| 6da385425e | |||
| 5d4c68eaf5 |
@@ -165,6 +165,39 @@ jobs:
|
||||
fi
|
||||
fi
|
||||
|
||||
# ── Orphan sweep ────────────────────────────────────────────────
|
||||
#
|
||||
# The check above is VERSION-SCOPED: it only ever asks about the one
|
||||
# version this run computed. That is enough to recover an orphan on
|
||||
# the very next run, and useless afterwards — once any releasable
|
||||
# commit lands, the next run computes a NEW version, never looks at
|
||||
# the old tag again, and the orphan becomes permanent and silent.
|
||||
#
|
||||
# servuo-plugins v0.1.0 is the proof, and the proof is pointed: the
|
||||
# commit that ADDED the recovery above was itself typed
|
||||
# `fix(release): ... recover the orphaned v0.1.0 tag`, so it bumped to
|
||||
# v0.1.1 — and the run that introduced the recovery stepped straight
|
||||
# past the tag it was written to rescue. That tag is still orphaned.
|
||||
#
|
||||
# So every v* tag is checked, and anything missing a release is
|
||||
# WARNED about. Deliberately not recovered: publishing an old version
|
||||
# would mean building today's tree and shipping it under a tag whose
|
||||
# tree it is not, which is worse than the inconsistency it fixes.
|
||||
# A human decides whether to recover or drop it.
|
||||
#
|
||||
# Never fails the run. A sweep that can break a good release is a
|
||||
# sweep someone will delete.
|
||||
ORPHANS=""
|
||||
for T in $(git tag -l 'v*' --sort=-v:refname); do
|
||||
T_HTTP="$(curl -s -o /dev/null -w '%{http_code}' \
|
||||
-H "Authorization: token $(printf '%s' "${REGISTRY_TOKEN:-}" | tr -d '\r\n')" \
|
||||
"https://${GITEA_HOST}/api/v1/repos/${REPO}/releases/tags/${T}" || echo 000)"
|
||||
[ "$T_HTTP" = "404" ] && ORPHANS="${ORPHANS} ${T}"
|
||||
done
|
||||
if [ -n "${ORPHANS}" ]; then
|
||||
echo "::warning::Tags with no release:${ORPHANS} — a run failed after tagging. Publish or delete them; this job will not do either."
|
||||
fi
|
||||
|
||||
# Changelog range. A recovery run has nothing after the tag, so
|
||||
# summarize what the tag itself contains rather than emitting an empty
|
||||
# list: the range that produced it, i.e. previous-tag..this-tag.
|
||||
@@ -395,17 +428,74 @@ jobs:
|
||||
# corrupt the Authorization header.
|
||||
CI_TOKEN="$(printf '%s' "${REGISTRY_TOKEN}" | tr -d '\r\n')"
|
||||
|
||||
REL_ID="$(curl -sSf -X POST "${API}/releases" \
|
||||
-H "Authorization: token ${CI_TOKEN}" \
|
||||
-H "Content-Type: application/json" \
|
||||
-d "$(jq -n --arg tag "$TAG" --arg body "$BODY" \
|
||||
'{tag_name:$tag, name:$tag, body:$body, draft:false, prerelease:false}')" \
|
||||
| jq -r '.id')"
|
||||
PAYLOAD="$(jq -n --arg tag "$TAG" --arg body "$BODY" \
|
||||
'{tag_name:$tag, name:$tag, body:$body, draft:false, prerelease:false}')"
|
||||
|
||||
# This POST is the step that orphaned tag v0.1.1 (run 75): it landed one
|
||||
# second after the tag push and Gitea answered 500, having not finished
|
||||
# processing the pushed tag. Re-running the workflow published the same
|
||||
# four assets untouched, so the failure was a race, not a bad request.
|
||||
#
|
||||
# Two things went wrong there, and both are fixed here.
|
||||
#
|
||||
# 1. `curl -sSf` prints NO response body on an error status, so all the
|
||||
# log carried was "curl: (22) ... error: 500" and the cause had to be
|
||||
# inferred from timestamps. Capture the body and print it.
|
||||
# 2. Nothing retried, so a transient 5xx became a permanent orphan tag.
|
||||
# The plan step CAN recover one, but only on a run that reaches it --
|
||||
# and a later push with no releasable commits stands down before it
|
||||
# gets there, so in practice the tag sits until a human notices.
|
||||
#
|
||||
# 4xx is deliberately NOT retried: a bad token or a malformed body does
|
||||
# not improve by being sent again, and retrying only turns a clear
|
||||
# failure into a slow one.
|
||||
REL_ID=""
|
||||
for attempt in 1 2 3 4 5; do
|
||||
HTTP="$(curl -s -o /tmp/rel.json -w '%{http_code}' -X POST "${API}/releases" \
|
||||
-H "Authorization: token ${CI_TOKEN}" \
|
||||
-H "Content-Type: application/json" \
|
||||
-d "${PAYLOAD}" || echo 000)"
|
||||
|
||||
if [ "$HTTP" = "201" ] || [ "$HTTP" = "200" ]; then
|
||||
REL_ID="$(jq -r '.id' /tmp/rel.json)"
|
||||
break
|
||||
fi
|
||||
|
||||
echo "::warning::POST /releases attempt ${attempt} returned HTTP ${HTTP}"
|
||||
echo "--- response body ---"
|
||||
cat /tmp/rel.json || true
|
||||
echo
|
||||
echo "---------------------"
|
||||
|
||||
case "$HTTP" in
|
||||
4*) echo "::error::HTTP ${HTTP} is a client error - not retrying."; exit 1 ;;
|
||||
esac
|
||||
|
||||
if [ "$attempt" = 5 ]; then
|
||||
echo "::error::POST /releases still failing after 5 attempts. Tag ${TAG} is pushed but has no release."
|
||||
echo "::error::Re-run this workflow - the plan step detects the orphan tag and republishes it."
|
||||
exit 1
|
||||
fi
|
||||
sleep $(( attempt * 5 ))
|
||||
done
|
||||
|
||||
if [ -z "$REL_ID" ] || [ "$REL_ID" = "null" ]; then
|
||||
echo "::error::Release created but no id came back; refusing to upload assets blind."
|
||||
exit 1
|
||||
fi
|
||||
echo "Created release ${TAG} (id=${REL_ID})"
|
||||
|
||||
for f in "${BIN}-linux-x86_64" "${BIN}-linux-aarch64" "${BIN}-windows-x86_64.exe" SHA256SUMS; do
|
||||
curl -sSf -X POST "${API}/releases/${REL_ID}/assets?name=${f}" \
|
||||
# Same treatment. An upload that fails quietly leaves a release whose
|
||||
# SHA256SUMS does not cover every binary it advertises, which is worse
|
||||
# than no release at all -- that file IS the trust anchor.
|
||||
HTTP="$(curl -s -o /tmp/asset.json -w '%{http_code}' -X POST "${API}/releases/${REL_ID}/assets?name=${f}" \
|
||||
-H "Authorization: token ${CI_TOKEN}" \
|
||||
-F "attachment=@dist/${f}" >/dev/null
|
||||
-F "attachment=@dist/${f}" || echo 000)"
|
||||
if [ "$HTTP" != "201" ] && [ "$HTTP" != "200" ]; then
|
||||
echo "::error::uploading ${f} returned HTTP ${HTTP}"
|
||||
cat /tmp/asset.json || true
|
||||
exit 1
|
||||
fi
|
||||
echo " uploaded ${f}"
|
||||
done
|
||||
|
||||
@@ -77,7 +77,7 @@ pub struct Cli {
|
||||
pub patches_unsupported_servuo: bool,
|
||||
/// `--host <name>`: the hostname to print in the website URLs.
|
||||
pub host: Option<String>,
|
||||
/// `--site-url <url>`: the site's base URL, for the Admin → Shard link.
|
||||
/// `--site-url <url>`: the site's base URL, for the Admin → Shard (uo-link) link.
|
||||
pub site_url: Option<String>,
|
||||
/// `--yes`: assume the default answer to every prompt.
|
||||
pub assume_yes: bool,
|
||||
@@ -137,7 +137,7 @@ Options:
|
||||
--host <NAME> install. The hostname to print in the
|
||||
website URLs.
|
||||
--site-url <URL> install. Your site's base URL, for the
|
||||
Admin → Shard link.
|
||||
Admin → Shard (uo-link) link.
|
||||
--yes Assume the default answer to every prompt.
|
||||
On uninstall it means yes: that prompt
|
||||
defaults to no, and typing `uninstall
|
||||
|
||||
@@ -294,6 +294,18 @@ fn port_of(bind: &str) -> &str {
|
||||
}
|
||||
}
|
||||
|
||||
/// Where the shard settings live in the website's admin panel.
|
||||
///
|
||||
/// NOT `/admin/shard`, which is what this printed until 2026-08-24 and what an operator who ran
|
||||
/// an older build still has in their scrollback. Those screens belong to the `uo` MODULE now, and
|
||||
/// a module owns one path segment wherever it appears (website `MODULE_SYSTEM.md` §2.8), so the
|
||||
/// page moved. The old path does not 404 — the SPA sends it to the dashboard, which is the worst
|
||||
/// way for a link in a handoff to be wrong, because it looks like it worked.
|
||||
///
|
||||
/// API routes are NOT affected by that rule and keep `/api/v1/admin/shard/*`. This is the SPA URL
|
||||
/// a person types.
|
||||
const ADMIN_SHARD_PATH: &str = "/admin/uo/link";
|
||||
|
||||
/// The end-of-run block from PLAN.md §6 — the one manual step the installer cannot do.
|
||||
///
|
||||
/// Returned as a string rather than printed so it can be tested, and so the caller decides where it
|
||||
@@ -312,12 +324,13 @@ pub fn handoff(doc: &ConfigDoc, host: &str, site_url: Option<&str>) -> String {
|
||||
Protocol version {protocol}\n \
|
||||
Auth token {token}\n \
|
||||
(also in {config})\n\n\
|
||||
Paste these into Admin → Shard on your Runic Gateway site:\n \
|
||||
{site}/admin/shard\n\n\
|
||||
Paste these into Admin → Shard (uo-link) on your Runic Gateway site:\n \
|
||||
{site}{admin_path}\n\n\
|
||||
The token is write-only once saved — the site will never show it back to you.\n",
|
||||
protocol = doc.protocol,
|
||||
token = doc.web.auth_token,
|
||||
config = doc.config_path,
|
||||
admin_path = ADMIN_SHARD_PATH,
|
||||
)
|
||||
}
|
||||
|
||||
@@ -401,7 +414,7 @@ mod tests {
|
||||
assert!(block.contains(&doc.web.auth_token), "{block}");
|
||||
// The trailing slash on the site URL must not produce a double slash in the link.
|
||||
assert!(
|
||||
block.contains("https://my-site.example/admin/shard"),
|
||||
block.contains("https://my-site.example/admin/uo/link"),
|
||||
"{block}"
|
||||
);
|
||||
assert!(block.contains("/etc/runicgateway/sidecar.toml"), "{block}");
|
||||
@@ -412,7 +425,10 @@ mod tests {
|
||||
// An unattended run has nobody to ask, and the token is far too useful to withhold over a
|
||||
// link the operator does not need.
|
||||
let block = handoff(&doc(), "shard", None);
|
||||
assert!(block.contains("https://<your-site>/admin/shard"), "{block}");
|
||||
assert!(
|
||||
block.contains("https://<your-site>/admin/uo/link"),
|
||||
"{block}"
|
||||
);
|
||||
assert!(block.contains("4f9c"), "{block}");
|
||||
}
|
||||
|
||||
|
||||
@@ -81,7 +81,7 @@ pub fn closing(prior: Option<&InstallRecord>, bundle: &Bundle, now: &InstallReco
|
||||
println!();
|
||||
ui::warn(&format!(
|
||||
"The protocol version changed: {} → {}.\n \
|
||||
Update the Protocol version field in Admin → Shard on your website. Nothing else \
|
||||
Update the Protocol version field in Admin → Shard (uo-link) on your website. Nothing else \
|
||||
changed —\n the URLs and the auth token are the same, and the sidecar answers a \
|
||||
website still set to\n {} with 409 rather than mis-parsing it.",
|
||||
previous_protocol.unwrap_or(bundle.protocol),
|
||||
|
||||
Reference in New Issue
Block a user