CI: ensure patch on runner (vendored shim), fallback to artifacts branch, master target

This commit is contained in:
Hermes (for frank)
2026-09-12 17:11:37 +00:00
parent bbd1034c69
commit 99c66bd52c
2 changed files with 237 additions and 7 deletions
+48 -7
View File
@@ -1,8 +1,10 @@
# Builds the signed release APK and F-Droid v2 artifacts as soon as a new
# release is created, and attaches everything to that release.
#
# Works on Gitea Actions (GitHub-Actions-compatible) — the repo lives on
# https://git.obahan.xyz/frank/wirevpn.
# Written for Gitea Actions (GitHub-Actions-compatible) — the repo lives on
# https://git.obahan.xyz/frank/wirevpn. If release-attachment storage is
# unavailable on the server, outputs are also published to the `artifacts`
# branch (tag-name addressed via commit message).
#
# Required repository secrets:
# KEYSTORE_FILE base64-encoded release signing keystore (.jks)
@@ -61,7 +63,20 @@ jobs:
"$ANDROID_HOME/cmdline-tools/latest/bin/sdkmanager" --sdk_root="$ANDROID_HOME" \
"platform-tools" "platforms;android-${ANDROID_API_LEVEL}" "build-tools;36.0.0" "ndk;${ANDROID_NDK_VERSION}"
echo "sdk.dir=$ANDROID_HOME" > local.properties
echo "ndk.dir=$ANDROID_HOME/ndk/${ANDROID_NDK_VERSION}" >> local.properties
- name: Ensure build prerequisites (patch)
run: |
set -e
if ! command -v patch >/dev/null 2>&1; then
echo "patch not found; using vendored shim"
mkdir -p "$HOME/bin"
cp scripts/patch-shim.py "$HOME/bin/patch"
chmod +x "$HOME/bin/patch"
echo "$HOME/bin" >> "$GITHUB_PATH"
echo "patch shim ready (vendored)"
else
echo "patch present on runner"
fi
- name: Decode signing keystore
run: |
@@ -114,15 +129,41 @@ jobs:
rid=$(curl -fsSL -H "Authorization: token $GITEA_TOKEN" "$GITEA_API/repos/$REPO/releases/tags/$tag" | python3 -c 'import json,sys; print(json.load(sys.stdin)["id"])' 2>/dev/null || true)
if [ -z "$rid" ]; then
rid=$(curl -fsSL -H "Authorization: token $GITEA_TOKEN" -H "Content-Type: application/json" \
-d "{\"name\":\"$tag\",\"tag_name\":\"$tag\",\"target\":\"main\"}" \
-d "{\"name\":\"$tag\",\"tag_name\":\"$tag\",\"target\":\"master\"}" \
"$GITEA_API/repos/$REPO/releases" | python3 -c 'import json,sys; print(json.load(sys.stdin)["id"])')
fi
ok=0
for f in dist/page.onram.wirevpn.apk dist/page.onram.wirevpn.metadata dist/page.onram.wirevpn.signature; do
curl -fsSL -H "Authorization: token $GITEA_TOKEN" \
if curl -fsSL -H "Authorization: token $GITEA_TOKEN" \
-F "file=@$f" \
"$GITEA_API/repos/$REPO/releases/$rid/assets"
echo "uploaded $f"
"$GITEA_API/repos/$REPO/releases/$rid/assets" >/dev/null; then
echo "uploaded $f"
ok=1
else
echo "attachment upload failed for $f (Gitea attachment storage broken?)"
fi
done
if [ "$ok" != "1" ]; then
echo "::warning::Could not attach release assets; falling back to artifacts branch"
fi
- name: Publish build outputs to artifacts branch (fallback + archive)
if: always()
env:
GITEA_TOKEN: ${{ secrets.GITEA_TOKEN || github.token }}
run: |
set -e
tag="${GITHUB_REF#refs/tags/}"
[ -n "$tag" ] || tag="latest"
mkdir -p dist-artifacts && cd dist-artifacts
cp ../dist/page.onram.wirevpn.apk ../dist/page.onram.wirevpn.metadata ../dist/page.onram.wirevpn.signature . 2>/dev/null || exit 0
git config user.name "wirevpn-ci"
git config user.email "ci@localhost"
git init -q .
git add -A
git commit -qm "build outputs for $tag"
git push -q --force "https://frank:${GITEA_TOKEN}@git.obahan.xyz/frank/wirevpn.git" HEAD:artifacts
echo "artifacts published to branch 'artifacts'"
- name: Upload build artifacts
uses: actions/upload-artifact@v4