Sync workflow: every failure is now reported as `ERROR: [category] message` with the categories configuration, credentials (HTTP 401), permissions (HTTP 403) and api (other HTTP errors, unreachable service); HTTP 404 is a configuration error. Before changing anything the workflow checks that the GitHub token can administer the mirror repository and stops with a permissions error otherwise. No secret value is printed. Guides: onboarding (with runner labels, prerequisites and offline runner symptoms), credentials (minimum permissions, preflight, rotation) and troubleshooting (every message mapped to a category and a fix). README capability table updated. MIL-002 records the verification of scoped workflow support: Gitea 1.27.3 runs the workflow in this repository; delivery to other repositories is not yet verified. Task: MIL-002#2 Task: MIL-002#3 Task: MIL-002#4 Task: MIL-002#5 Task: MIL-002#6 Task: MIL-002#7 Refs #9 Refs #10 Refs #11 Refs #12 Refs #13 Refs #14 Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>
260 lines
10 KiB
YAML
260 lines
10 KiB
YAML
name: Sync GitHub mirror metadata
|
|
|
|
on:
|
|
push:
|
|
branches: [ main ]
|
|
workflow_dispatch:
|
|
schedule:
|
|
- cron: "17 3 * * *"
|
|
|
|
jobs:
|
|
sync-metadata:
|
|
permissions:
|
|
contents: read
|
|
runs-on: ubuntu-latest
|
|
steps:
|
|
- name: Sync description and topics
|
|
env:
|
|
GITEA_API_URL: ${{ gitea.api_url }}
|
|
GITEA_CREDENTIALS: ${{ secrets.TOKEN_FOR_GITEA }}
|
|
SOURCE_REPOSITORY: ${{ gitea.repository }}
|
|
GITHUB_CREDENTIALS: ${{ secrets.CREDENTIALS_FOR_GITHUB }}
|
|
run: |
|
|
python3 - <<'PY'
|
|
import json
|
|
import os
|
|
import sys
|
|
import urllib.error
|
|
import urllib.parse
|
|
import urllib.request
|
|
|
|
|
|
class WorkflowError(RuntimeError):
|
|
"""A failure with a category.
|
|
|
|
configuration: a secret or repository setting is missing or malformed.
|
|
credentials: a service rejected the token (HTTP 401).
|
|
permissions: the token is valid but not allowed (HTTP 403).
|
|
api: any other API or network failure.
|
|
"""
|
|
|
|
def __init__(self, category, message):
|
|
super().__init__(f"[{category}] {message}")
|
|
self.category = category
|
|
|
|
|
|
def service_name(url):
|
|
hostname = urllib.parse.urlsplit(url).hostname
|
|
return "GitHub" if hostname == "api.github.com" else "Gitea"
|
|
|
|
|
|
def request_json(url, method="GET", headers=None, body=None):
|
|
request = urllib.request.Request(
|
|
url,
|
|
data=json.dumps(body).encode("utf-8") if body is not None else None,
|
|
headers=headers or {},
|
|
method=method,
|
|
)
|
|
service = service_name(url)
|
|
try:
|
|
with urllib.request.urlopen(request, timeout=30) as response:
|
|
content = response.read()
|
|
return json.loads(content) if content else None
|
|
except urllib.error.HTTPError as error:
|
|
detail = (
|
|
f"{service} API request failed with HTTP "
|
|
f"{error.code} ({error.reason})"
|
|
)
|
|
if error.code == 401:
|
|
raise WorkflowError(
|
|
"credentials", f"{detail}. The token was rejected."
|
|
) from None
|
|
if error.code == 403:
|
|
raise WorkflowError(
|
|
"permissions",
|
|
f"{detail}. The token lacks a required permission.",
|
|
) from None
|
|
if error.code == 404:
|
|
raise WorkflowError(
|
|
"configuration",
|
|
f"{detail}. The repository was not found or the "
|
|
"token cannot see it.",
|
|
) from None
|
|
raise WorkflowError("api", detail) from None
|
|
except (urllib.error.URLError, TimeoutError) as error:
|
|
raise WorkflowError(
|
|
"api", f"{service} API is unreachable ({error})."
|
|
) from None
|
|
|
|
|
|
def parse_github_token(raw_credentials):
|
|
raw_credentials = (raw_credentials or "").strip()
|
|
if not raw_credentials:
|
|
raise WorkflowError(
|
|
"configuration", "CREDENTIALS_FOR_GITHUB is missing or empty."
|
|
)
|
|
|
|
try:
|
|
credentials = json.loads(raw_credentials)
|
|
except json.JSONDecodeError:
|
|
raise WorkflowError(
|
|
"configuration",
|
|
"CREDENTIALS_FOR_GITHUB must contain valid JSON.",
|
|
) from None
|
|
|
|
if not isinstance(credentials, dict):
|
|
raise WorkflowError(
|
|
"configuration",
|
|
"CREDENTIALS_FOR_GITHUB must be a JSON object.",
|
|
)
|
|
|
|
token = credentials.get("GITHUB_PAT")
|
|
if not isinstance(token, str) or not token.strip():
|
|
raise WorkflowError(
|
|
"configuration",
|
|
"CREDENTIALS_FOR_GITHUB must contain a non-empty GITHUB_PAT.",
|
|
)
|
|
return token.strip()
|
|
|
|
|
|
def parse_gitea_token(raw_credentials):
|
|
raw_credentials = (raw_credentials or "").strip()
|
|
if not raw_credentials:
|
|
raise WorkflowError(
|
|
"configuration", "TOKEN_FOR_GITEA is missing or empty."
|
|
)
|
|
|
|
try:
|
|
credentials = json.loads(raw_credentials)
|
|
except json.JSONDecodeError:
|
|
token = raw_credentials
|
|
else:
|
|
if isinstance(credentials, dict):
|
|
token = credentials.get("GITEA_TOKEN")
|
|
elif isinstance(credentials, str):
|
|
token = credentials
|
|
else:
|
|
token = None
|
|
|
|
if not isinstance(token, str) or not token.strip():
|
|
raise WorkflowError(
|
|
"configuration",
|
|
"TOKEN_FOR_GITEA must contain a non-empty GITEA_TOKEN.",
|
|
)
|
|
return token.strip()
|
|
|
|
|
|
def split_repository(full_name):
|
|
owner, separator, repo = (full_name or "").partition("/")
|
|
if not separator or not owner or not repo:
|
|
raise WorkflowError(
|
|
"configuration",
|
|
"Could not determine the Gitea source repository.",
|
|
)
|
|
return owner, repo
|
|
|
|
|
|
def find_github_targets(mirrors):
|
|
targets = []
|
|
for mirror in mirrors:
|
|
remote_address = mirror.get("remote_address", "")
|
|
if remote_address.startswith("git@github.com:"):
|
|
mirror_path = remote_address.split(":", 1)[1]
|
|
else:
|
|
parsed_remote = urllib.parse.urlsplit(remote_address)
|
|
if parsed_remote.hostname != "github.com":
|
|
continue
|
|
mirror_path = parsed_remote.path.lstrip("/")
|
|
|
|
mirror_path = mirror_path.removesuffix(".git").strip("/")
|
|
path_parts = mirror_path.split("/")
|
|
if len(path_parts) != 2 or not all(path_parts):
|
|
raise WorkflowError(
|
|
"configuration",
|
|
"Could not determine the GitHub owner and repository "
|
|
"from a configured push mirror.",
|
|
)
|
|
targets.append(tuple(path_parts))
|
|
|
|
if len(targets) != 1:
|
|
raise WorkflowError(
|
|
"configuration",
|
|
"Expected exactly one GitHub push mirror for this repository; "
|
|
f"found {len(targets)}.",
|
|
)
|
|
return targets[0]
|
|
|
|
|
|
def main():
|
|
github_token = parse_github_token(os.environ.get("GITHUB_CREDENTIALS"))
|
|
gitea_token = parse_gitea_token(os.environ.get("GITEA_CREDENTIALS"))
|
|
source_owner, source_repo = split_repository(
|
|
os.environ.get("SOURCE_REPOSITORY")
|
|
)
|
|
|
|
gitea_api_url = os.environ["GITEA_API_URL"].rstrip("/")
|
|
source_url = f"{gitea_api_url}/repos/{source_owner}/{source_repo}"
|
|
gitea_headers = {
|
|
"Authorization": f"token {gitea_token}",
|
|
"Accept": "application/json",
|
|
}
|
|
source = request_json(source_url, headers=gitea_headers)
|
|
mirrors = request_json(
|
|
f"{source_url}/push_mirrors",
|
|
headers=gitea_headers,
|
|
)
|
|
if not isinstance(mirrors, list):
|
|
print(
|
|
"WARNING: Gitea returned an invalid push mirror list; "
|
|
"GitHub metadata was not synced."
|
|
)
|
|
return 0
|
|
|
|
github_owner, github_repo = find_github_targets(mirrors)
|
|
github_api_url = (
|
|
"https://api.github.com/repos/"
|
|
f"{urllib.parse.quote(github_owner, safe='')}/"
|
|
f"{urllib.parse.quote(github_repo, safe='')}"
|
|
)
|
|
github_headers = {
|
|
"Authorization": f"Bearer {github_token}",
|
|
"Accept": "application/vnd.github+json",
|
|
"X-GitHub-Api-Version": "2022-11-28",
|
|
"Content-Type": "application/json",
|
|
}
|
|
|
|
github_repository = request_json(github_api_url, headers=github_headers)
|
|
permissions = (github_repository or {}).get("permissions")
|
|
if isinstance(permissions, dict) and not permissions.get("admin"):
|
|
raise WorkflowError(
|
|
"permissions",
|
|
f"The GitHub token cannot administer {github_owner}/{github_repo}; "
|
|
"editing the description and topics needs administration access.",
|
|
)
|
|
print("Preflight passed: Gitea and GitHub accepted the credentials.")
|
|
|
|
request_json(
|
|
github_api_url,
|
|
method="PATCH",
|
|
headers=github_headers,
|
|
body={"description": source.get("description") or ""},
|
|
)
|
|
request_json(
|
|
f"{github_api_url}/topics",
|
|
method="PUT",
|
|
headers=github_headers,
|
|
body={"names": source.get("topics") or []},
|
|
)
|
|
|
|
print(f"Synced description and topics to {github_owner}/{github_repo}.")
|
|
return 0
|
|
|
|
|
|
if __name__ == "__main__":
|
|
try:
|
|
sys.exit(main())
|
|
except RuntimeError as error:
|
|
print(f"ERROR: {error}", file=sys.stderr)
|
|
sys.exit(1)
|
|
PY
|