🔧 chore(thirdparty): generalize skills sync pipeline
replace the superpowers-only workflow with a manifest-driven pipeline sync ui-ux-pro-max into codex/skills and document source lists fix the prettier path test so the Python suite passes on Windows
This commit is contained in:
@@ -1,77 +0,0 @@
|
||||
#!/usr/bin/env bash
|
||||
set -euo pipefail
|
||||
|
||||
REPO_DIR="${REPO_DIR:-$(pwd)}"
|
||||
SUPERPOWERS_BRANCH="${SUPERPOWERS_BRANCH:-thirdparty/skill}"
|
||||
SUPERPOWERS_DIR="${SUPERPOWERS_DIR:-superpowers}"
|
||||
SUPERPOWERS_LIST="${SUPERPOWERS_LIST:-codex/skills/.sources/superpowers.list}"
|
||||
TARGET_BRANCH="${TARGET_BRANCH:-main}"
|
||||
COMMIT_AUTHOR_NAME="${COMMIT_AUTHOR_NAME:-ci[bot]}"
|
||||
COMMIT_AUTHOR_EMAIL="${COMMIT_AUTHOR_EMAIL:-ci-bot@local}"
|
||||
|
||||
cd "$REPO_DIR"
|
||||
|
||||
git config user.name "$COMMIT_AUTHOR_NAME"
|
||||
git config user.email "$COMMIT_AUTHOR_EMAIL"
|
||||
|
||||
git fetch origin "$SUPERPOWERS_BRANCH"
|
||||
git fetch origin "$TARGET_BRANCH"
|
||||
|
||||
tmp_dir="$(mktemp -d)"
|
||||
cleanup() {
|
||||
rm -rf "$tmp_dir"
|
||||
}
|
||||
trap cleanup EXIT
|
||||
|
||||
git archive --format=tar "origin/${SUPERPOWERS_BRANCH}" "${SUPERPOWERS_DIR}/skills" | tar -xf - -C "$tmp_dir"
|
||||
|
||||
tmp_skills_dir="$tmp_dir/${SUPERPOWERS_DIR}/skills"
|
||||
if [ ! -d "$tmp_skills_dir" ]; then
|
||||
echo "ERROR: ${SUPERPOWERS_DIR}/skills not found in ${SUPERPOWERS_BRANCH}" >&2
|
||||
exit 1
|
||||
fi
|
||||
|
||||
git checkout -B "$TARGET_BRANCH" "origin/$TARGET_BRANCH"
|
||||
|
||||
mkdir -p "$(dirname "$SUPERPOWERS_LIST")"
|
||||
|
||||
old_list="$SUPERPOWERS_LIST"
|
||||
if [ -f "$old_list" ]; then
|
||||
while IFS= read -r name; do
|
||||
[ -n "$name" ] || continue
|
||||
rm -rf "codex/skills/$name"
|
||||
done < "$old_list"
|
||||
fi
|
||||
|
||||
names=()
|
||||
for dir in "$tmp_skills_dir"/*; do
|
||||
[ -d "$dir" ] || continue
|
||||
name="$(basename "$dir")"
|
||||
|
||||
if [ -d "codex/skills/$name" ] && ! grep -qx "$name" "$old_list" 2>/dev/null; then
|
||||
echo "ERROR: skill name conflict: $name" >&2
|
||||
exit 1
|
||||
fi
|
||||
|
||||
rm -rf "codex/skills/$name"
|
||||
cp -R "$dir" "codex/skills/$name"
|
||||
names+=("$name")
|
||||
done
|
||||
|
||||
printf "%s\n" "${names[@]}" | sort > "$SUPERPOWERS_LIST"
|
||||
|
||||
git add codex/skills "$SUPERPOWERS_LIST"
|
||||
|
||||
if git diff --cached --quiet; then
|
||||
echo "No changes to sync."
|
||||
exit 0
|
||||
fi
|
||||
|
||||
git commit -m ":package: deps(skills): sync superpowers"
|
||||
|
||||
TOKEN="${WORKFLOW:-}"
|
||||
if [ -n "$TOKEN" ] && [ -n "${GITHUB_SERVER_URL:-}" ] && [ -n "${GITHUB_REPOSITORY:-}" ]; then
|
||||
git remote set-url origin "https://oauth2:${TOKEN}@${GITHUB_SERVER_URL#https://}/${GITHUB_REPOSITORY}.git"
|
||||
fi
|
||||
|
||||
git push origin "$TARGET_BRANCH"
|
||||
@@ -0,0 +1,211 @@
|
||||
#!/usr/bin/env bash
|
||||
set -euo pipefail
|
||||
|
||||
REPO_DIR="${REPO_DIR:-$(pwd)}"
|
||||
THIRDPARTY_BRANCH="${THIRDPARTY_BRANCH:-thirdparty/skill}"
|
||||
TARGET_BRANCH="${TARGET_BRANCH:-main}"
|
||||
MANIFEST_PATH="${MANIFEST_PATH:-.gitea/ci/thirdparty_skills.json}"
|
||||
COMMIT_AUTHOR_NAME="${COMMIT_AUTHOR_NAME:-ci[bot]}"
|
||||
COMMIT_AUTHOR_EMAIL="${COMMIT_AUTHOR_EMAIL:-ci-bot@local}"
|
||||
|
||||
emit_sources_tsv() {
|
||||
python3 - "$MANIFEST_PATH" <<'PY'
|
||||
import json
|
||||
import sys
|
||||
|
||||
with open(sys.argv[1], encoding="utf-8") as fh:
|
||||
data = json.load(fh)
|
||||
|
||||
for entry in data["sources"]:
|
||||
print(
|
||||
"\t".join(
|
||||
[
|
||||
entry["id"],
|
||||
entry["snapshot_dir"],
|
||||
entry["sync_mode"],
|
||||
entry["source_list"],
|
||||
entry.get("skills_subdir", ""),
|
||||
entry.get("output_name", entry["id"]),
|
||||
entry.get("platform_config", ""),
|
||||
entry.get("template_root", ""),
|
||||
entry.get("data_dir", ""),
|
||||
entry.get("scripts_dir", ""),
|
||||
]
|
||||
)
|
||||
)
|
||||
PY
|
||||
}
|
||||
|
||||
render_codex_skill() {
|
||||
local snapshot_root="$1"
|
||||
local output_dir="$2"
|
||||
local platform_config_rel="$3"
|
||||
local template_root_rel="$4"
|
||||
local data_dir_rel="$5"
|
||||
local scripts_dir_rel="$6"
|
||||
|
||||
python3 - "$snapshot_root" "$output_dir" "$platform_config_rel" "$template_root_rel" "$data_dir_rel" "$scripts_dir_rel" <<'PY'
|
||||
import json
|
||||
import pathlib
|
||||
import shutil
|
||||
import sys
|
||||
|
||||
snapshot_root = pathlib.Path(sys.argv[1])
|
||||
output_dir = pathlib.Path(sys.argv[2])
|
||||
platform_config_path = snapshot_root / sys.argv[3]
|
||||
template_root = snapshot_root / sys.argv[4]
|
||||
data_dir = snapshot_root / sys.argv[5]
|
||||
scripts_dir = snapshot_root / sys.argv[6]
|
||||
|
||||
config = json.loads(platform_config_path.read_text(encoding="utf-8"))
|
||||
skill_template = (template_root / "base" / "skill-content.md").read_text(encoding="utf-8")
|
||||
quick_reference = ""
|
||||
if config.get("sections", {}).get("quickReference"):
|
||||
quick_reference = "\n" + (template_root / "base" / "quick-reference.md").read_text(encoding="utf-8")
|
||||
|
||||
def render_frontmatter(frontmatter):
|
||||
if not frontmatter:
|
||||
return ""
|
||||
|
||||
lines = ["---"]
|
||||
for key, value in frontmatter.items():
|
||||
if any(ch in value for ch in ':"\n'):
|
||||
value = value.replace('"', '\\"')
|
||||
lines.append(f'{key}: "{value}"')
|
||||
else:
|
||||
lines.append(f"{key}: {value}")
|
||||
lines.extend(["---", ""])
|
||||
return "\n".join(lines)
|
||||
|
||||
content = skill_template
|
||||
content = content.replace("{{TITLE}}", config["title"])
|
||||
content = content.replace("{{DESCRIPTION}}", config["description"])
|
||||
content = content.replace("{{SCRIPT_PATH}}", config["scriptPath"])
|
||||
content = content.replace("{{SKILL_OR_WORKFLOW}}", config["skillOrWorkflow"])
|
||||
content = content.replace("{{QUICK_REFERENCE}}", quick_reference)
|
||||
|
||||
if output_dir.exists():
|
||||
shutil.rmtree(output_dir)
|
||||
output_dir.mkdir(parents=True, exist_ok=True)
|
||||
|
||||
(output_dir / "SKILL.md").write_text(
|
||||
render_frontmatter(config.get("frontmatter")) + content,
|
||||
encoding="utf-8",
|
||||
)
|
||||
if data_dir.exists():
|
||||
shutil.copytree(data_dir, output_dir / "data")
|
||||
if scripts_dir.exists():
|
||||
shutil.copytree(scripts_dir, output_dir / "scripts")
|
||||
PY
|
||||
}
|
||||
|
||||
tracked_skill_exists() {
|
||||
local name="$1"
|
||||
if git ls-files --error-unmatch -- "codex/skills/$name" >/dev/null 2>&1; then
|
||||
return 0
|
||||
fi
|
||||
return 1
|
||||
}
|
||||
|
||||
cd "$REPO_DIR"
|
||||
|
||||
git config user.name "$COMMIT_AUTHOR_NAME"
|
||||
git config user.email "$COMMIT_AUTHOR_EMAIL"
|
||||
|
||||
git fetch origin "$THIRDPARTY_BRANCH"
|
||||
git fetch origin "$TARGET_BRANCH"
|
||||
|
||||
tmp_dir="$(mktemp -d)"
|
||||
cleanup() {
|
||||
rm -rf "$tmp_dir"
|
||||
}
|
||||
trap cleanup EXIT
|
||||
|
||||
git checkout -B "$TARGET_BRANCH" "origin/$TARGET_BRANCH"
|
||||
|
||||
mkdir -p "codex/skills/.sources"
|
||||
|
||||
while IFS=$'\t' read -r source_id snapshot_dir sync_mode source_list skills_subdir output_name platform_config template_root data_dir scripts_dir; do
|
||||
[ -n "$source_id" ] || continue
|
||||
|
||||
if [ -f "$source_list" ]; then
|
||||
while IFS= read -r name; do
|
||||
[ -n "$name" ] || continue
|
||||
rm -rf "codex/skills/$name"
|
||||
done < "$source_list"
|
||||
fi
|
||||
done < <(emit_sources_tsv)
|
||||
|
||||
declare -A owners=()
|
||||
while IFS=$'\t' read -r source_id snapshot_dir sync_mode source_list skills_subdir output_name platform_config template_root data_dir scripts_dir; do
|
||||
[ -n "$source_id" ] || continue
|
||||
|
||||
git archive --format=tar "origin/${THIRDPARTY_BRANCH}" "$snapshot_dir" | tar -xf - -C "$tmp_dir"
|
||||
snapshot_root="$tmp_dir/$snapshot_dir"
|
||||
|
||||
names=()
|
||||
case "$sync_mode" in
|
||||
copy_skill_dirs)
|
||||
source_skills_dir="$snapshot_root/$skills_subdir"
|
||||
if [ ! -d "$source_skills_dir" ]; then
|
||||
echo "ERROR: $skills_subdir not found in snapshot $snapshot_dir" >&2
|
||||
exit 1
|
||||
fi
|
||||
|
||||
for dir in "$source_skills_dir"/*; do
|
||||
[ -d "$dir" ] || continue
|
||||
name="$(basename "$dir")"
|
||||
if [ -n "${owners[$name]:-}" ] && [ "${owners[$name]}" != "$source_id" ]; then
|
||||
echo "ERROR: duplicate third-party skill name: $name" >&2
|
||||
exit 1
|
||||
fi
|
||||
if [ -d "codex/skills/$name" ] && tracked_skill_exists "$name"; then
|
||||
echo "ERROR: skill name conflict with tracked skill: $name" >&2
|
||||
exit 1
|
||||
fi
|
||||
|
||||
rm -rf "codex/skills/$name"
|
||||
cp -R "$dir" "codex/skills/$name"
|
||||
names+=("$name")
|
||||
owners["$name"]="$source_id"
|
||||
done
|
||||
;;
|
||||
render_codex_skill)
|
||||
name="$output_name"
|
||||
if [ -n "${owners[$name]:-}" ] && [ "${owners[$name]}" != "$source_id" ]; then
|
||||
echo "ERROR: duplicate third-party skill name: $name" >&2
|
||||
exit 1
|
||||
fi
|
||||
if [ -d "codex/skills/$name" ] && tracked_skill_exists "$name"; then
|
||||
echo "ERROR: skill name conflict with tracked skill: $name" >&2
|
||||
exit 1
|
||||
fi
|
||||
|
||||
render_codex_skill "$snapshot_root" "codex/skills/$name" "$platform_config" "$template_root" "$data_dir" "$scripts_dir"
|
||||
names+=("$name")
|
||||
owners["$name"]="$source_id"
|
||||
;;
|
||||
*)
|
||||
echo "ERROR: unsupported sync mode: $sync_mode" >&2
|
||||
exit 1
|
||||
;;
|
||||
esac
|
||||
|
||||
printf "%s\n" "${names[@]}" | sort > "$source_list"
|
||||
done < <(emit_sources_tsv)
|
||||
|
||||
git add codex/skills
|
||||
|
||||
if git diff --cached --quiet; then
|
||||
echo "No third-party skills to sync."
|
||||
exit 0
|
||||
fi
|
||||
|
||||
git commit -m ":package: deps(skills): sync thirdparty skills"
|
||||
|
||||
TOKEN="${WORKFLOW:-}"
|
||||
if [ -n "$TOKEN" ] && [ -n "${GITHUB_SERVER_URL:-}" ] && [ -n "${GITHUB_REPOSITORY:-}" ]; then
|
||||
git remote set-url origin "https://oauth2:${TOKEN}@${GITHUB_SERVER_URL#https://}/${GITHUB_REPOSITORY}.git"
|
||||
fi
|
||||
|
||||
git push origin "$TARGET_BRANCH"
|
||||
@@ -0,0 +1,26 @@
|
||||
{
|
||||
"sources": [
|
||||
{
|
||||
"id": "superpowers",
|
||||
"upstream_repo": "https://github.com/obra/superpowers.git",
|
||||
"upstream_ref": "main",
|
||||
"snapshot_dir": "superpowers",
|
||||
"sync_mode": "copy_skill_dirs",
|
||||
"source_list": "codex/skills/.sources/superpowers.list",
|
||||
"skills_subdir": "skills"
|
||||
},
|
||||
{
|
||||
"id": "ui-ux-pro-max",
|
||||
"upstream_repo": "https://github.com/nextlevelbuilder/ui-ux-pro-max-skill.git",
|
||||
"upstream_ref": "main",
|
||||
"snapshot_dir": "ui-ux-pro-max",
|
||||
"sync_mode": "render_codex_skill",
|
||||
"source_list": "codex/skills/.sources/ui-ux-pro-max.list",
|
||||
"output_name": "ui-ux-pro-max",
|
||||
"platform_config": "src/ui-ux-pro-max/templates/platforms/codex.json",
|
||||
"template_root": "src/ui-ux-pro-max/templates",
|
||||
"data_dir": "src/ui-ux-pro-max/data",
|
||||
"scripts_dir": "src/ui-ux-pro-max/scripts"
|
||||
}
|
||||
]
|
||||
}
|
||||
@@ -0,0 +1,184 @@
|
||||
#!/usr/bin/env bash
|
||||
set -euo pipefail
|
||||
|
||||
REPO_DIR="${REPO_DIR:-$(pwd)}"
|
||||
TARGET_BRANCH="${TARGET_BRANCH:-thirdparty/skill}"
|
||||
MANIFEST_PATH="${MANIFEST_PATH:-.gitea/ci/thirdparty_skills.json}"
|
||||
COMMIT_AUTHOR_NAME="${COMMIT_AUTHOR_NAME:-ci[bot]}"
|
||||
COMMIT_AUTHOR_EMAIL="${COMMIT_AUTHOR_EMAIL:-ci-bot@local}"
|
||||
|
||||
retry_cmd() {
|
||||
local retries="$1"
|
||||
shift
|
||||
local delay="$1"
|
||||
shift
|
||||
|
||||
local attempt=1
|
||||
while true; do
|
||||
if "$@"; then
|
||||
return 0
|
||||
fi
|
||||
if [ "$attempt" -ge "$retries" ]; then
|
||||
return 1
|
||||
fi
|
||||
echo "Retry ($attempt/$retries): $*" >&2
|
||||
sleep "$delay"
|
||||
attempt=$((attempt + 1))
|
||||
done
|
||||
}
|
||||
|
||||
github_owner_repo() {
|
||||
case "$1" in
|
||||
https://github.com/*)
|
||||
echo "$1" | sed -E 's#^https://github.com/([^/]+/[^/.]+)(\.git)?$#\1#'
|
||||
;;
|
||||
http://github.com/*)
|
||||
echo "$1" | sed -E 's#^http://github.com/([^/]+/[^/.]+)(\.git)?$#\1#'
|
||||
;;
|
||||
git@github.com:*)
|
||||
echo "$1" | sed -E 's#^git@github.com:([^/]+/[^/.]+)(\.git)?$#\1#'
|
||||
;;
|
||||
*)
|
||||
return 1
|
||||
;;
|
||||
esac
|
||||
}
|
||||
|
||||
resolve_latest_sha() {
|
||||
local repo="$1"
|
||||
local ref="$2"
|
||||
local tmp_json="$3"
|
||||
local gh_repo="$4"
|
||||
local sha=""
|
||||
|
||||
if [ -n "$gh_repo" ]; then
|
||||
local api_url="https://api.github.com/repos/${gh_repo}/commits/${ref}"
|
||||
if retry_cmd 3 2 curl -fsSL --retry 3 --retry-delay 2 "$api_url" -o "$tmp_json"; then
|
||||
sha="$(sed -n 's/^[[:space:]]*"sha":[[:space:]]*"\([0-9a-f]\{40\}\)".*/\1/p' "$tmp_json" | head -n 1)"
|
||||
if [ -n "$sha" ]; then
|
||||
echo "$sha"
|
||||
return 0
|
||||
fi
|
||||
fi
|
||||
fi
|
||||
|
||||
sha="$(retry_cmd 3 2 git -c http.version=HTTP/1.1 ls-remote "$repo" "refs/heads/$ref" | awk 'NR==1 {print $1}')"
|
||||
if [ -n "$sha" ]; then
|
||||
echo "$sha"
|
||||
return 0
|
||||
fi
|
||||
|
||||
return 1
|
||||
}
|
||||
|
||||
emit_sources_tsv() {
|
||||
python3 - "$MANIFEST_PATH" <<'PY'
|
||||
import json
|
||||
import sys
|
||||
|
||||
with open(sys.argv[1], encoding="utf-8") as fh:
|
||||
data = json.load(fh)
|
||||
|
||||
for entry in data["sources"]:
|
||||
print(
|
||||
"\t".join(
|
||||
[
|
||||
entry["id"],
|
||||
entry["upstream_repo"],
|
||||
entry.get("upstream_ref", "main"),
|
||||
entry["snapshot_dir"],
|
||||
entry["sync_mode"],
|
||||
]
|
||||
)
|
||||
)
|
||||
PY
|
||||
}
|
||||
|
||||
cd "$REPO_DIR"
|
||||
|
||||
git config user.name "$COMMIT_AUTHOR_NAME"
|
||||
git config user.email "$COMMIT_AUTHOR_EMAIL"
|
||||
|
||||
git fetch origin "$TARGET_BRANCH"
|
||||
git checkout -B "$TARGET_BRANCH" "origin/$TARGET_BRANCH"
|
||||
|
||||
tmp_dir="$(mktemp -d)"
|
||||
cleanup() {
|
||||
rm -rf "$tmp_dir"
|
||||
}
|
||||
trap cleanup EXIT
|
||||
|
||||
changed=0
|
||||
while IFS=$'\t' read -r source_id upstream_repo upstream_ref snapshot_dir sync_mode; do
|
||||
[ -n "$source_id" ] || continue
|
||||
|
||||
gh_repo=""
|
||||
if gh_repo="$(github_owner_repo "$upstream_repo" 2>/dev/null)"; then
|
||||
:
|
||||
fi
|
||||
|
||||
latest_sha="$(resolve_latest_sha "$upstream_repo" "$upstream_ref" "$tmp_dir/${source_id}-latest.json" "$gh_repo" || true)"
|
||||
if [ -z "$latest_sha" ]; then
|
||||
echo "ERROR: failed to resolve upstream ref for ${source_id}: $upstream_repo $upstream_ref" >&2
|
||||
exit 1
|
||||
fi
|
||||
|
||||
current_sha=""
|
||||
if [ -f "$snapshot_dir/SOURCE.md" ]; then
|
||||
current_sha="$(sed -n 's/^- Ref:[[:space:]]*//p' "$snapshot_dir/SOURCE.md" | head -n 1)"
|
||||
fi
|
||||
|
||||
if [ "$latest_sha" = "$current_sha" ]; then
|
||||
echo "Third-party snapshot is up to date for ${source_id}: $latest_sha"
|
||||
continue
|
||||
fi
|
||||
|
||||
rm -rf "$snapshot_dir"
|
||||
mkdir -p "$snapshot_dir"
|
||||
|
||||
snapshot_loaded=0
|
||||
if [ -n "$gh_repo" ]; then
|
||||
tar_url="https://codeload.github.com/${gh_repo}/tar.gz/${latest_sha}"
|
||||
if retry_cmd 3 2 curl -fsSL --retry 3 --retry-delay 2 "$tar_url" -o "$tmp_dir/${source_id}.tar.gz"; then
|
||||
tar -xzf "$tmp_dir/${source_id}.tar.gz" -C "$snapshot_dir" --strip-components=1
|
||||
snapshot_loaded=1
|
||||
fi
|
||||
fi
|
||||
|
||||
if [ "$snapshot_loaded" -eq 0 ]; then
|
||||
upstream_dir="$tmp_dir/${source_id}-upstream"
|
||||
git init "$upstream_dir" >/dev/null
|
||||
git -C "$upstream_dir" remote add origin "$upstream_repo"
|
||||
retry_cmd 3 2 git -C "$upstream_dir" fetch --depth 1 origin "$latest_sha"
|
||||
git -C "$upstream_dir" checkout --detach FETCH_HEAD
|
||||
git -C "$upstream_dir" archive --format=tar HEAD | tar -xf - -C "$snapshot_dir"
|
||||
fi
|
||||
|
||||
snapshot_date="$(date -u +%Y-%m-%d)"
|
||||
cat > "$snapshot_dir/SOURCE.md" <<EOF
|
||||
# Source
|
||||
|
||||
- Repo: ${upstream_repo%".git"}
|
||||
- Ref: $latest_sha
|
||||
- Snapshot: $snapshot_date
|
||||
- Sync-Mode: $sync_mode
|
||||
- Notes: vendored into playbook branch $TARGET_BRANCH
|
||||
EOF
|
||||
|
||||
git add -A "$snapshot_dir"
|
||||
changed=1
|
||||
done < <(emit_sources_tsv)
|
||||
|
||||
if [ "$changed" -eq 0 ] || git diff --cached --quiet; then
|
||||
echo "All third-party snapshots are up to date."
|
||||
exit 0
|
||||
fi
|
||||
|
||||
git commit -m ":package: deps(thirdparty): update snapshots"
|
||||
|
||||
TOKEN="${WORKFLOW:-}"
|
||||
if [ -n "$TOKEN" ] && [ -n "${GITHUB_SERVER_URL:-}" ] && [ -n "${GITHUB_REPOSITORY:-}" ]; then
|
||||
git remote set-url origin "https://oauth2:${TOKEN}@${GITHUB_SERVER_URL#https://}/${GITHUB_REPOSITORY}.git"
|
||||
fi
|
||||
|
||||
git push origin "$TARGET_BRANCH"
|
||||
@@ -1,159 +0,0 @@
|
||||
#!/usr/bin/env bash
|
||||
set -euo pipefail
|
||||
|
||||
REPO_DIR="${REPO_DIR:-$(pwd)}"
|
||||
TARGET_BRANCH="${TARGET_BRANCH:-thirdparty/skill}"
|
||||
SNAPSHOT_DIR="${SNAPSHOT_DIR:-superpowers}"
|
||||
SOURCE_FILE="${SOURCE_FILE:-${SNAPSHOT_DIR}/SOURCE.md}"
|
||||
UPSTREAM_REPO="${UPSTREAM_REPO:-https://github.com/obra/superpowers.git}"
|
||||
UPSTREAM_REF="${UPSTREAM_REF:-main}"
|
||||
COMMIT_AUTHOR_NAME="${COMMIT_AUTHOR_NAME:-ci[bot]}"
|
||||
COMMIT_AUTHOR_EMAIL="${COMMIT_AUTHOR_EMAIL:-ci-bot@local}"
|
||||
|
||||
retry_cmd() {
|
||||
local retries="$1"
|
||||
shift
|
||||
local delay="$1"
|
||||
shift
|
||||
|
||||
local attempt=1
|
||||
while true; do
|
||||
if "$@"; then
|
||||
return 0
|
||||
fi
|
||||
if [ "$attempt" -ge "$retries" ]; then
|
||||
return 1
|
||||
fi
|
||||
echo "Retry ($attempt/$retries): $*" >&2
|
||||
sleep "$delay"
|
||||
attempt=$((attempt + 1))
|
||||
done
|
||||
}
|
||||
|
||||
github_owner_repo() {
|
||||
case "$1" in
|
||||
https://github.com/*)
|
||||
echo "$1" | sed -E 's#^https://github.com/([^/]+/[^/.]+)(\.git)?$#\1#'
|
||||
;;
|
||||
http://github.com/*)
|
||||
echo "$1" | sed -E 's#^http://github.com/([^/]+/[^/.]+)(\.git)?$#\1#'
|
||||
;;
|
||||
git@github.com:*)
|
||||
echo "$1" | sed -E 's#^git@github.com:([^/]+/[^/.]+)(\.git)?$#\1#'
|
||||
;;
|
||||
*)
|
||||
return 1
|
||||
;;
|
||||
esac
|
||||
}
|
||||
|
||||
resolve_latest_sha() {
|
||||
local repo="$1"
|
||||
local ref="$2"
|
||||
local tmp_json="$3"
|
||||
local gh_repo="$4"
|
||||
local sha=""
|
||||
|
||||
# Prefer GitHub API when possible to avoid git+gnutls handshake failures.
|
||||
if [ -n "$gh_repo" ]; then
|
||||
local api_url="https://api.github.com/repos/${gh_repo}/commits/${ref}"
|
||||
if retry_cmd 3 2 curl -fsSL --retry 3 --retry-delay 2 "$api_url" -o "$tmp_json"; then
|
||||
sha="$(sed -n 's/^[[:space:]]*"sha":[[:space:]]*"\([0-9a-f]\{40\}\)".*/\1/p' "$tmp_json" | head -n 1)"
|
||||
if [ -n "$sha" ]; then
|
||||
echo "$sha"
|
||||
return 0
|
||||
fi
|
||||
fi
|
||||
fi
|
||||
|
||||
# Fallback to git transport.
|
||||
sha="$(retry_cmd 3 2 git -c http.version=HTTP/1.1 ls-remote "$repo" "refs/heads/$ref" | awk 'NR==1 {print $1}')"
|
||||
if [ -n "$sha" ]; then
|
||||
echo "$sha"
|
||||
return 0
|
||||
fi
|
||||
return 1
|
||||
}
|
||||
|
||||
cd "$REPO_DIR"
|
||||
|
||||
git config user.name "$COMMIT_AUTHOR_NAME"
|
||||
git config user.email "$COMMIT_AUTHOR_EMAIL"
|
||||
|
||||
git fetch origin "$TARGET_BRANCH"
|
||||
git checkout -B "$TARGET_BRANCH" "origin/$TARGET_BRANCH"
|
||||
|
||||
tmp_dir="$(mktemp -d)"
|
||||
cleanup() {
|
||||
rm -rf "$tmp_dir"
|
||||
}
|
||||
trap cleanup EXIT
|
||||
|
||||
gh_repo=""
|
||||
if gh_repo="$(github_owner_repo "$UPSTREAM_REPO" 2>/dev/null)"; then
|
||||
:
|
||||
fi
|
||||
|
||||
latest_sha="$(resolve_latest_sha "$UPSTREAM_REPO" "$UPSTREAM_REF" "$tmp_dir/latest.json" "$gh_repo" || true)"
|
||||
if [ -z "$latest_sha" ]; then
|
||||
echo "ERROR: failed to resolve upstream ref: $UPSTREAM_REPO $UPSTREAM_REF" >&2
|
||||
exit 1
|
||||
fi
|
||||
|
||||
current_sha=""
|
||||
if [ -f "$SOURCE_FILE" ]; then
|
||||
current_sha="$(sed -n 's/^- Ref:[[:space:]]*//p' "$SOURCE_FILE" | head -n 1)"
|
||||
fi
|
||||
|
||||
if [ "$latest_sha" = "$current_sha" ]; then
|
||||
echo "Third-party snapshot is up to date: $latest_sha"
|
||||
exit 0
|
||||
fi
|
||||
|
||||
rm -rf "$SNAPSHOT_DIR"
|
||||
mkdir -p "$SNAPSHOT_DIR"
|
||||
|
||||
snapshot_loaded=0
|
||||
|
||||
if [ -n "$gh_repo" ]; then
|
||||
tar_url="https://codeload.github.com/${gh_repo}/tar.gz/${latest_sha}"
|
||||
if retry_cmd 3 2 curl -fsSL --retry 3 --retry-delay 2 "$tar_url" -o "$tmp_dir/upstream.tar.gz"; then
|
||||
tar -xzf "$tmp_dir/upstream.tar.gz" -C "$SNAPSHOT_DIR" --strip-components=1
|
||||
snapshot_loaded=1
|
||||
fi
|
||||
fi
|
||||
|
||||
if [ "$snapshot_loaded" -eq 0 ]; then
|
||||
upstream_dir="$tmp_dir/upstream"
|
||||
git init "$upstream_dir" >/dev/null
|
||||
git -C "$upstream_dir" remote add origin "$UPSTREAM_REPO"
|
||||
retry_cmd 3 2 git -C "$upstream_dir" fetch --depth 1 origin "$latest_sha"
|
||||
git -C "$upstream_dir" checkout --detach FETCH_HEAD
|
||||
git -C "$upstream_dir" archive --format=tar HEAD | tar -xf - -C "$SNAPSHOT_DIR"
|
||||
fi
|
||||
|
||||
snapshot_date="$(date -u +%Y-%m-%d)"
|
||||
cat > "$SOURCE_FILE" <<EOF
|
||||
# Source
|
||||
|
||||
- Repo: ${UPSTREAM_REPO%".git"}
|
||||
- Ref: $latest_sha
|
||||
- Snapshot: $snapshot_date
|
||||
- Notes: vendored into playbook branch $TARGET_BRANCH
|
||||
EOF
|
||||
|
||||
git add "$SNAPSHOT_DIR"
|
||||
|
||||
if git diff --cached --quiet; then
|
||||
echo "No changes detected after snapshot refresh."
|
||||
exit 0
|
||||
fi
|
||||
|
||||
git commit -m ":package: deps(superpowers): vendor snapshot"
|
||||
|
||||
TOKEN="${WORKFLOW:-}"
|
||||
if [ -n "$TOKEN" ] && [ -n "${GITHUB_SERVER_URL:-}" ] && [ -n "${GITHUB_REPOSITORY:-}" ]; then
|
||||
git remote set-url origin "https://oauth2:${TOKEN}@${GITHUB_SERVER_URL#https://}/${GITHUB_REPOSITORY}.git"
|
||||
fi
|
||||
|
||||
git push origin "$TARGET_BRANCH"
|
||||
Reference in New Issue
Block a user