scripts: do not fail a job when the AUR is unreachable and nothing is owed

The AUR clone runs unconditionally, so every maintenance window turns the
whole matrix red - including the packages that had nothing to publish.
Tolerate connectivity failures when the run produced no commit; a pending
push and non-transient errors stay fatal.
This commit is contained in:
Felitendo committed 2026-08-03 10:13:05 +02:00
1 parent f993b8ae0b
commit f7c4395f5c
1 file changed
+23 -1
+23 -1
View File
@@ -93,6 +93,8 @@ rm -f "$pkg"/*.pkg.tar.* "$pkg"/*.tar.zst "$pkg"/*.tar.gz "$pkg"/*.deb "$pkg"/*.
### 4: commit back to this repository ######################################## ### 4: commit back to this repository ########################################
committed=false
if [[ "${CI:-}" == "true" ]]; then if [[ "${CI:-}" == "true" ]]; then
git config user.name "github-actions[bot]" git config user.name "github-actions[bot]"
git config user.email "41898282+github-actions[bot]@users.noreply.github.com" git config user.email "41898282+github-actions[bot]@users.noreply.github.com"
@@ -104,6 +106,7 @@ if [[ "${CI:-}" == "true" ]]; then
git commit -m "$pkg: update to $ver-$rel [skip ci]" git commit -m "$pkg: update to $ver-$rel [skip ci]"
git pull --rebase origin "${GITHUB_REF_NAME:-main}" git pull --rebase origin "${GITHUB_REF_NAME:-main}"
git push origin "HEAD:${GITHUB_REF_NAME:-main}" git push origin "HEAD:${GITHUB_REF_NAME:-main}"
committed=true
fi fi
fi fi
@@ -127,7 +130,26 @@ echo 'aur.archlinux.org ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIEuBKrPzbawxA/k2g6Nc
export GIT_SSH_COMMAND="ssh -i $sshdir/key -o UserKnownHostsFile=$sshdir/known_hosts -o IdentitiesOnly=yes" export GIT_SSH_COMMAND="ssh -i $sshdir/key -o UserKnownHostsFile=$sshdir/known_hosts -o IdentitiesOnly=yes"
aurdir="$(mktemp -d)" aurdir="$(mktemp -d)"
git clone "ssh://aur@aur.archlinux.org/$pkg.git" "$aurdir"
# The AUR goes down for maintenance every now and then, and the clone is the
# first thing that notices. When this run produced no commit there is nothing
# to publish, so an unreachable AUR is noise - warn and stop instead of
# failing the job. A run that did commit stays red: its push is still owed.
# Anything that is not a connectivity problem (missing repository, rejected
# key) is fatal either way.
if ! clone_log="$(git clone "ssh://aur@aur.archlinux.org/$pkg.git" "$aurdir" 2>&1)"; then
printf '%s\n' "$clone_log" >&2
if [[ "$committed" == false ]] &&
grep -qEi 'down due to maintenance|Connection (timed out|refused|closed)|Could not resolve hostname|kex_exchange|Broken pipe|Operation timed out' \
<<< "$clone_log"; then
echo "::warning::$pkg: the AUR is unreachable and this run has nothing to push -" \
"skipping the AUR sync, the next run picks it up."
exit 0
fi
echo "::error::$pkg: could not clone the AUR repository."
exit 1
fi
printf '%s\n' "$clone_log"
# every tracked file of the package except our automation glue belongs on # every tracked file of the package except our automation glue belongs on
# the AUR (PKGBUILD, .SRCINFO, .desktop files, .install files, ...) # the AUR (PKGBUILD, .SRCINFO, .desktop files, .install files, ...)