From 20c1efb8a3b1ea8252daa1146f0b5434e89c443a Mon Sep 17 00:00:00 2001 From: Butler Agent Date: Fri, 11 Sep 2026 08:10:38 +0000 Subject: [PATCH] Scope documentation CI and isolate delivery job resources --- .gitea/workflows/build-and-push.yml | 15 +++++++++++ scripts/ci-select.sh | 39 +++++++++++++++++++++++++++++ 2 files changed, 54 insertions(+) create mode 100644 scripts/ci-select.sh diff --git a/.gitea/workflows/build-and-push.yml b/.gitea/workflows/build-and-push.yml index 46c9939..dd3e25a 100644 --- a/.gitea/workflows/build-and-push.yml +++ b/.gitea/workflows/build-and-push.yml @@ -20,13 +20,26 @@ jobs: - name: Checkout uses: actions/checkout@v4 + - name: Select relevant delivery work + id: delivery + env: + DELIVERY_EVENT: ${{ github.event_name }} + DELIVERY_REF: ${{ github.ref }} + DELIVERY_SHA: ${{ github.sha }} + DELIVERY_BASE: ${{ github.event.pull_request.base.sha || github.event.before }} + run: | + cd . + bash scripts/ci-select.sh - name: Set up QEMU + if: ${{ steps.delivery.outputs.run == 'true' }} uses: docker/setup-qemu-action@v3 - name: Set up Docker Buildx + if: ${{ steps.delivery.outputs.run == 'true' }} uses: docker/setup-buildx-action@v3 - name: Log in to Gitea registry + if: ${{ steps.delivery.outputs.run == 'true' }} uses: docker/login-action@v3 with: registry: ${{ env.REGISTRY }} @@ -34,6 +47,7 @@ jobs: password: ${{ secrets.REGISTRY_PASSWORD }} - name: Prepare image tags + if: ${{ steps.delivery.outputs.run == 'true' }} id: prep shell: bash run: | @@ -56,6 +70,7 @@ jobs: } >> "$GITHUB_OUTPUT" - name: Build and push image + if: ${{ steps.delivery.outputs.run == 'true' }} uses: docker/build-push-action@v6 with: context: . diff --git a/scripts/ci-select.sh b/scripts/ci-select.sh new file mode 100644 index 0000000..7260b1b --- /dev/null +++ b/scripts/ci-select.sh @@ -0,0 +1,39 @@ +#!/usr/bin/env bash +# Keep required jobs alive; only skip reviewed non-runtime documentation paths. +set -euo pipefail +base="${DELIVERY_BASE:-}" +head="$(git rev-parse HEAD)" +run=true +if [[ "${DELIVERY_REF:-}" != refs/tags/* && "$head" == "${DELIVERY_SHA:-}" && "${DELIVERY_EVENT:-}" =~ ^(push|pull_request)$ && "$base" =~ ^[0-9a-f]{40}$ && "$base" != 0000000000000000000000000000000000000000 ]]; then + if ! git cat-file -e "$base^{commit}" 2>/dev/null; then + if [[ -n "${DELIVERY_FETCH_TOKEN:-}" ]]; then + git -c "http.extraHeader=Authorization: token ${DELIVERY_FETCH_TOKEN}" fetch --quiet --depth=1 origin "$base" >/dev/null 2>&1 || true + else + git fetch --quiet --depth=1 origin "$base" >/dev/null 2>&1 || true + fi + fi + if git cat-file -e "$base^{commit}" 2>/dev/null; then + paths="$(mktemp)" + trap 'rm -f -- "$paths"' EXIT + # Snapshot comparison is conservative when main advanced during a PR. + # Both rename sides remain visible, including names containing newlines. + if git diff --no-renames --name-only -z "$base" "$head" > "$paths"; then + run=false + while IFS= read -r -d '' path; do + case "$path" in + README.md|CHANGELOG.md|LICENSE|LICENSE.md) ;; + *) run=true; break ;; + esac + done < "$paths" + fi + fi +fi +if [[ "$run" == false ]]; then + echo 'Only reviewed non-runtime documentation changed; build and validation are not applicable.' +else + echo 'Runtime, unknown inputs, or unavailable event history: run required validation.' +fi +if [[ -n "${GITHUB_OUTPUT:-}" ]]; then + echo "run=$run" >> "$GITHUB_OUTPUT" +fi +printf '%s\n' "$run"