Fetch history and tags in the canonical workflow (closes #110)
check / check (push) Canceled after 0s

The checkout step of the canonical `.gitea/workflows/check.yml` now sets `fetch-depth: 0`, with a one-line comment saying why. The checkout action otherwise clones shallow with no tags, so `git describe --tags --always` gave a bare short commit id in CI where a local build of a tagged repository gives the tag. `REPO_POLICIES.md` and the existing repo checklist told each tagged repository to add it itself, which a byte-identical re-vendor would remove; they now say the canonical file sets it.

Unverified: the live check, which waits on the shared runner.

Model: opus-5-5
This commit is contained in:
2026-10-06 03:55:06 +00:00
parent 6aac45857a
commit 5d4d58f3e1
4 changed files with 14 additions and 5 deletions
+2
View File
@@ -13,4 +13,6 @@ jobs:
# script/cibuild needs no token, so none is left in .git/config. # script/cibuild needs no token, so none is left in .git/config.
with: with:
persist-credentials: false persist-credentials: false
# All history and tags, so git describe finds the version tag.
fetch-depth: 0
- run: script/cibuild - run: script/cibuild
+7
View File
@@ -21,6 +21,13 @@ fmt-check, and commit.
# Completed Steps # Completed Steps
- 2026-10-06: The canonical `.gitea/workflows/check.yml` now sets
`fetch-depth: 0` on its checkout step (issue 110), so CI fetches the history
and tags that `git describe --tags --always` needs, and a tagged repository
stamps the same version in CI as in a local build. `REPO_POLICIES.md` and the
existing repo checklist now say the canonical file sets it, instead of asking
each repository to add it. Not yet tried on the shared runner, which is out of
disk space. Repositories pick this up on their next re-vendor.
- 2026-10-06: The canonical `.gitea/workflows/check.yml` now has a `concurrency` - 2026-10-06: The canonical `.gitea/workflows/check.yml` now has a `concurrency`
block, so a new push cancels the older run on the same branch and no other, block, so a new push cancels the older run on the same branch and no other,
and its checkout step sets `persist-credentials: false`, so the job's token is and its checkout step sets `persist-credentials: false`, so the job's token is
+3 -3
View File
@@ -92,9 +92,9 @@ with your task.
`docker build .` with no build arguments must succeed; a Dockerfile that `docker build .` with no build arguments must succeed; a Dockerfile that
refuses an empty build argument drops that refusal and keeps the argument. refuses an empty build argument drops that refusal and keeps the argument.
`script/docker` and `script/cibuild` pass the version they compute on the `script/docker` and `script/cibuild` pass the version they compute on the
host; it takes precedence. A tag-derived version additionally needs host; it takes precedence. The canonical `.gitea/workflows/check.yml` sets
`fetch-depth: 0` on the CI checkout step, which clones shallow and fetches `fetch-depth: 0` on its checkout step, which otherwise clones shallow and
no tags by default. fetches no tags, so a CI build finds the tag too.
- [ ] Gitea Actions workflow in `.gitea/workflows/` runs `script/cibuild` on - [ ] Gitea Actions workflow in `.gitea/workflows/` runs `script/cibuild` on
push, checks out with `persist-credentials: false`, and carries the push, checks out with `persist-credentials: false`, and carries the
`concurrency` block that lets a new push cancel only the same branch's `concurrency` block that lets a new push cancel only the same branch's
+2 -2
View File
@@ -466,8 +466,8 @@ style conventions are in separate documents:
there because `ARG` is stage-scoped; passing `VERSION` to a repo whose there because `ARG` is stage-scoped; passing `VERSION` to a repo whose
Dockerfile declares no such `ARG` is ignored and costs nothing, which is why Dockerfile declares no such `ARG` is ignored and costs nothing, which is why
the scripts stay byte-identical. One consequence for CI: the standard the scripts stay byte-identical. One consequence for CI: the standard
checkout action clones shallow and fetches no tags, so a repo that embeds a checkout action clones shallow and fetches no tags, so the canonical
tag-derived version must set `fetch-depth: 0` on its checkout step. `.gitea/workflows/check.yml` sets `fetch-depth: 0` on its checkout step.
- **Verify `.dockerignore` by enumerating the image, not by reading the - **Verify `.dockerignore` by enumerating the image, not by reading the
patterns.** Plant files at the root _and_ at least two directories deep, build patterns.** Plant files at the root _and_ at least two directories deep, build