From 5d4d58f3e15e7726bb3f256ba1325db381e9299e Mon Sep 17 00:00:00 2001 From: sneak Date: Tue, 6 Oct 2026 03:55:06 +0000 Subject: [PATCH] Fetch history and tags in the canonical workflow (closes #110) The checkout step of the canonical `.gitea/workflows/check.yml` now sets `fetch-depth: 0`, with a one-line comment saying why. The checkout action otherwise clones shallow with no tags, so `git describe --tags --always` gave a bare short commit id in CI where a local build of a tagged repository gives the tag. `REPO_POLICIES.md` and the existing repo checklist told each tagged repository to add it itself, which a byte-identical re-vendor would remove; they now say the canonical file sets it. Unverified: the live check, which waits on the shared runner. Model: opus-5-5 --- .gitea/workflows/check.yml | 2 ++ TODO.md | 7 +++++++ prompts/EXISTING_REPO_CHECKLIST.md | 6 +++--- prompts/REPO_POLICIES.md | 4 ++-- 4 files changed, 14 insertions(+), 5 deletions(-) diff --git a/.gitea/workflows/check.yml b/.gitea/workflows/check.yml index 6246a7e..7c8c682 100644 --- a/.gitea/workflows/check.yml +++ b/.gitea/workflows/check.yml @@ -13,4 +13,6 @@ jobs: # script/cibuild needs no token, so none is left in .git/config. with: persist-credentials: false + # All history and tags, so git describe finds the version tag. + fetch-depth: 0 - run: script/cibuild diff --git a/TODO.md b/TODO.md index 0057a3b..13c5b77 100644 --- a/TODO.md +++ b/TODO.md @@ -21,6 +21,13 @@ fmt-check, and commit. # Completed Steps +- 2026-10-06: The canonical `.gitea/workflows/check.yml` now sets + `fetch-depth: 0` on its checkout step (issue 110), so CI fetches the history + and tags that `git describe --tags --always` needs, and a tagged repository + stamps the same version in CI as in a local build. `REPO_POLICIES.md` and the + existing repo checklist now say the canonical file sets it, instead of asking + each repository to add it. Not yet tried on the shared runner, which is out of + disk space. Repositories pick this up on their next re-vendor. - 2026-10-06: The canonical `.gitea/workflows/check.yml` now has a `concurrency` block, so a new push cancels the older run on the same branch and no other, and its checkout step sets `persist-credentials: false`, so the job's token is diff --git a/prompts/EXISTING_REPO_CHECKLIST.md b/prompts/EXISTING_REPO_CHECKLIST.md index b12ee3b..84ebac0 100644 --- a/prompts/EXISTING_REPO_CHECKLIST.md +++ b/prompts/EXISTING_REPO_CHECKLIST.md @@ -92,9 +92,9 @@ with your task. `docker build .` with no build arguments must succeed; a Dockerfile that refuses an empty build argument drops that refusal and keeps the argument. `script/docker` and `script/cibuild` pass the version they compute on the - host; it takes precedence. A tag-derived version additionally needs - `fetch-depth: 0` on the CI checkout step, which clones shallow and fetches - no tags by default. + host; it takes precedence. The canonical `.gitea/workflows/check.yml` sets + `fetch-depth: 0` on its checkout step, which otherwise clones shallow and + fetches no tags, so a CI build finds the tag too. - [ ] Gitea Actions workflow in `.gitea/workflows/` runs `script/cibuild` on push, checks out with `persist-credentials: false`, and carries the `concurrency` block that lets a new push cancel only the same branch's diff --git a/prompts/REPO_POLICIES.md b/prompts/REPO_POLICIES.md index 73a0b8c..663f074 100644 --- a/prompts/REPO_POLICIES.md +++ b/prompts/REPO_POLICIES.md @@ -466,8 +466,8 @@ style conventions are in separate documents: there because `ARG` is stage-scoped; passing `VERSION` to a repo whose Dockerfile declares no such `ARG` is ignored and costs nothing, which is why the scripts stay byte-identical. One consequence for CI: the standard - checkout action clones shallow and fetches no tags, so a repo that embeds a - tag-derived version must set `fetch-depth: 0` on its checkout step. + checkout action clones shallow and fetches no tags, so the canonical + `.gitea/workflows/check.yml` sets `fetch-depth: 0` on its checkout step. - **Verify `.dockerignore` by enumerating the image, not by reading the patterns.** Plant files at the root _and_ at least two directories deep, build