diff --git a/.github/workflows/open-gitea-pr.yml b/.github/workflows/open-gitea-pr.yml index bc4c4d7..e2d579d 100644 --- a/.github/workflows/open-gitea-pr.yml +++ b/.github/workflows/open-gitea-pr.yml @@ -1,9 +1,5 @@ name: Open Gitea PR on merge to main -# When main changes on GitHub (i.e. after a PR is merged here), push those -# commits to a branch on Gitea and open a pull request there, so the same -# change can be reviewed and landed on the Gitea side. One-way: GitHub -> Gitea. - on: push: branches: [main] @@ -14,15 +10,12 @@ permissions: jobs: open-gitea-pr: - # GitHub-hosted runners are billing-blocked for this org, so the hosted job - # never started. Run on the self-hosted runner, which also has LAN access to - # the Gitea host. This workflow only fires on push to main (never on PRs from - # forks), so it is safe on the private runner. - runs-on: [self-hosted, Linux, X64] + runs-on: [self-hosted, Linux, X64, co-server-sync] steps: - - uses: actions/checkout@11d5960a326750d5838078e36cf38b85af677262 # v4 + - uses: actions/checkout@11d5960a326750d5838078e36cf38b85af677262 with: fetch-depth: 0 + persist-credentials: false - name: Push main to Gitea and open a pull request env: @@ -33,38 +26,59 @@ jobs: SYNC_BRANCH: sync/from-github run: | set -euo pipefail + umask 077 + if [ -z "${GITEA_TOKEN:-}" ]; then - echo "::error::Missing GITEA_TOKEN secret. Add a Gitea access token as a" - echo "::error::repository secret named GITEA_TOKEN (Settings -> Secrets and" - echo "::error::variables -> Actions -> New repository secret)." + echo "::error::Missing GITEA_TOKEN repository secret." exit 1 fi - git config user.name "github-sync" - git config user.email "github-sync@users.noreply.github.com" + askpass="${RUNNER_TEMP}/gitea-askpass-${GITHUB_RUN_ID}-${GITHUB_RUN_ATTEMPT}.sh" + header_file="${RUNNER_TEMP}/gitea-header-${GITHUB_RUN_ID}-${GITHUB_RUN_ATTEMPT}" + response_file="${RUNNER_TEMP}/gitea-pr-${GITHUB_RUN_ID}-${GITHUB_RUN_ATTEMPT}.json" - # Mirror the current main onto a dedicated Gitea branch. Force is safe: - # this branch is owned by the automation and only ever tracks GitHub main. - git remote add gitea "https://${GITEA_USER}:${GITEA_TOKEN}@${GITEA_HOST}/${GITEA_REPO}.git" + cleanup() { + git remote remove gitea >/dev/null 2>&1 || true + rm -f -- "$askpass" "$header_file" "$response_file" + } + trap cleanup EXIT + + cat > "$askpass" <<'EOF' + #!/usr/bin/env bash + case "$1" in + *Username*) printf '%s\n' "${GITEA_USER:?}" ;; + *Password*) printf '%s\n' "${GITEA_TOKEN:?}" ;; + *) exit 1 ;; + esac + EOF + chmod 700 "$askpass" + printf 'Authorization: token %s\n' "$GITEA_TOKEN" > "$header_file" + chmod 600 "$header_file" + + export GIT_ASKPASS="$askpass" + export GIT_TERMINAL_PROMPT=0 + + git config user.name "github-sync" + git config user.email "github-sync@users.noreply.github.com" + git remote remove gitea >/dev/null 2>&1 || true + git remote add gitea "https://${GITEA_HOST}/${GITEA_REPO}.git" git push -f gitea "HEAD:refs/heads/${SYNC_BRANCH}" - # Open a PR on Gitea: sync/from-github -> main. If one is already open, - # the push above has already updated it, so a 409 is success too. - http_code=$(curl -sS -o /tmp/gitea_pr.json -w "%{http_code}" -X POST \ + http_code=$(curl -sS -o "$response_file" -w "%{http_code}" -X POST \ "https://${GITEA_HOST}/api/v1/repos/${GITEA_REPO}/pulls" \ - -H "Authorization: token ${GITEA_TOKEN}" \ + -H "@${header_file}" \ -H "Content-Type: application/json" \ - -d "{\"title\":\"Sync from GitHub main\",\"head\":\"${SYNC_BRANCH}\",\"base\":\"main\",\"body\":\"Automated: GitHub main was updated. Review and merge to land it on Gitea.\"}") + -d "{\"title\":\"Sync from GitHub main\",\"head\":\"${SYNC_BRANCH}\",\"base\":\"main\",\"body\":\"GitHub main was updated. Review and merge to land it on Gitea.\"}") echo "Gitea pulls API returned HTTP ${http_code}" - cat /tmp/gitea_pr.json || true + cat "$response_file" || true echo - if [ "${http_code}" = "201" ]; then + if [ "$http_code" = "201" ]; then echo "Opened a new Gitea pull request." - elif [ "${http_code}" = "409" ] || grep -qiE "already exist|issue_exist" /tmp/gitea_pr.json; then + elif [ "$http_code" = "409" ] || grep -qiE "already exist|issue_exist" "$response_file"; then echo "A Gitea PR from ${SYNC_BRANCH} is already open; it now has the latest commits." else - echo "::warning::Unexpected Gitea response (${http_code}). The branch was pushed;" - echo "::warning::open the PR manually on Gitea if it did not appear." + echo "::error::Unexpected Gitea response (${http_code})." + exit 1 fi