From 6b0b60eb4a04b2995cf4e3c0e5be0e0206e24905 Mon Sep 17 00:00:00 2001 From: Kit OC5 Date: Wed, 23 Sep 2026 14:17:10 -0400 Subject: [PATCH] =?UTF-8?q?scripts:=20rerun=5Fci.sh=20=E2=80=94=20re-fire?= =?UTF-8?q?=20a=20PR's=20CI=20without=20the=20web=20button?= MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit Gitea 1.24 has no rerun API and the web button needs Grant's SSO identity. Guarded branch rewind that the next sync undoes; restores the branch itself on timeout. Used today for eternitas #166 and windy-mind #131 after the Veron IO stall. Co-Authored-By: Claude Opus 5.5 --- docs/RUNBOOK-VERON.md | 13 +++++++++++++ scripts/rerun_ci.sh | 45 +++++++++++++++++++++++++++++++++++++++++++ 2 files changed, 58 insertions(+) create mode 100755 scripts/rerun_ci.sh diff --git a/docs/RUNBOOK-VERON.md b/docs/RUNBOOK-VERON.md index 4cc97a2..825cc16 100644 --- a/docs/RUNBOOK-VERON.md +++ b/docs/RUNBOOK-VERON.md @@ -152,3 +152,16 @@ disqualifying the moment a stranger depends on it. **The trigger is not a date it is the first external push.** Move the control plane to a dedicated VPS (not Kit 0), keep Veron 1 as the runner. It is an rsync, a Postgres dump and three DNS record edits. + +## Re-run a PR's CI (Gitea 1.24 has no rerun API) + +```bash +ssh wg-veron +cd /srv/windygit/src && bash scripts/rerun_ci.sh +``` +Moves the Windy Git branch back one commit; the next sync force-pushes the +GitHub head again and Gitea re-fires every workflow for that event on the same +commit. Guarded: refuses unless the branch is at the given sha, waits for a +sync that starts AFTER the rewind, restores the branch itself on timeout. +Don't use the web "Re-run" button: it needs a hub-SSO session as windyadmin, +which is Grant's identity. diff --git a/scripts/rerun_ci.sh b/scripts/rerun_ci.sh new file mode 100755 index 0000000..fc95a47 --- /dev/null +++ b/scripts/rerun_ci.sh @@ -0,0 +1,45 @@ +#!/usr/bin/env bash +# Re-run a PR's (or branch's) CI on Windy Git. Runs ON Veron 1. +# +# bash scripts/rerun_ci.sh +# +# Gitea 1.24 has NO rerun API; the web button needs a hub-SSO session as +# windyadmin, which is Grant's identity, so we don't use it. Instead: move the +# Windy Git branch back one commit, let the next sync force-push the GitHub head +# again, and Gitea fires an ordinary push / pull_request_sync event on the SAME +# commit. Every workflow on that event re-runs, not only the failed one. +# +# Safety: refuses unless the branch is exactly at (GitHub's head), +# never rewinds while a sync is running (a run already past this repo would +# not push it back), waits for a sync that STARTS after the rewind, and if the +# branch is not verifiably back at by the deadline, restores it +# itself, so Windy Git is never left behind GitHub. +set -euo pipefail +repo="${1:?repo}"; branch="${2:?branch}"; want="${3:?sha prefix}" +G="sudo docker exec -u git windy-git-gitea-1 git -C /data/git/repositories/windyadmin/${repo}.git" + +head=$($G rev-parse "refs/heads/${branch}") +[[ "$head" == "$want"* ]] || { echo "refusing: ${branch} is at ${head:0:7}, not ${want}"; exit 1; } +parent=$($G rev-parse "${head}^") + +while systemctl is-active -q windygit-sync; do sleep 5; done +$G update-ref "refs/heads/${branch}" "$parent" "$head" +mark=$(awk '{print int($1*1000000)}' /proc/uptime) +echo "rewound ${repo}:${branch} ${head:0:7} -> ${parent:0:7}" + +deadline=$(( $(date +%s) + 900 )) +until [ "$(systemctl show windygit-sync -p ExecMainStartTimestampMonotonic --value)" -gt "$mark" ] \ + && [ "$($G rev-parse "refs/heads/${branch}")" = "$head" ]; do + if [ "$(date +%s)" -ge "$deadline" ]; then + $G update-ref "refs/heads/${branch}" "$head" "$($G rev-parse "refs/heads/${branch}")" || true + echo "TIMEOUT: restored ${branch} to ${head:0:7} by hand; NO new run fired"; exit 1 + fi + sleep 10 +done +echo "restored by sync: ${branch} = ${head:0:7}" +sleep 5 +~/bin/wg-q <