From 786702586eed88d5f51c4624769051fa08ca49d0 Mon Sep 17 00:00:00 2001 From: sneak Date: Tue, 6 Oct 2026 05:31:29 +0000 Subject: [PATCH] Fetch history and tags in the canonical workflow (closes #110) The checkout step of the canonical `.gitea/workflows/check.yml` now sets `fetch-depth: 0`, with a one-line comment saying why. The checkout action otherwise clones shallow with no tags, so `git describe --tags --always` gave a bare short commit id in CI where a local build of a tagged repository gives the tag. `REPO_POLICIES.md` and both checklists now name `fetch-depth: 0` among what the workflow does, next to `persist-credentials: false` and the `concurrency` block, where they used to ask each tagged repository to add it. Unverified: the live check, which waits on the shared runner. Model: opus-5-5 --- .gitea/workflows/check.yml | 2 ++ TODO.md | 8 ++++++++ prompts/EXISTING_REPO_CHECKLIST.md | 14 ++++++++------ prompts/NEW_REPO_CHECKLIST.md | 7 ++++--- prompts/REPO_POLICIES.md | 9 ++++++--- 5 files changed, 28 insertions(+), 12 deletions(-) diff --git a/.gitea/workflows/check.yml b/.gitea/workflows/check.yml index 6246a7e..7c8c682 100644 --- a/.gitea/workflows/check.yml +++ b/.gitea/workflows/check.yml @@ -13,4 +13,6 @@ jobs: # script/cibuild needs no token, so none is left in .git/config. with: persist-credentials: false + # All history and tags, so git describe finds the version tag. + fetch-depth: 0 - run: script/cibuild diff --git a/TODO.md b/TODO.md index feeff5d..ea3ef0e 100644 --- a/TODO.md +++ b/TODO.md @@ -21,6 +21,14 @@ fmt-check, and commit. # Completed Steps +- 2026-10-06: The canonical `.gitea/workflows/check.yml` now sets + `fetch-depth: 0` on its checkout step (issue 110), so CI fetches the history + and tags that `git describe --tags --always` needs, and a tagged repository + stamps the same version in CI as in a local build. `REPO_POLICIES.md` and both + checklists name `fetch-depth: 0` among what the workflow does, next to + `persist-credentials: false` and the `concurrency` block, instead of asking + each tagged repository to add it. Not yet tried on the shared runner, which is + out of disk space. Repositories pick this up on their next re-vendor. - 2026-10-06: The canonical `script/bootstrap` now runs `apt-get update` once, before the first `apt-get install` of a run (issue 115). The Gitea runner image starts with empty package lists, so installing anything it lacks, such diff --git a/prompts/EXISTING_REPO_CHECKLIST.md b/prompts/EXISTING_REPO_CHECKLIST.md index cb7efd1..c501263 100644 --- a/prompts/EXISTING_REPO_CHECKLIST.md +++ b/prompts/EXISTING_REPO_CHECKLIST.md @@ -96,13 +96,15 @@ with your task. directory outside the build context, so the build cannot read the version and a plain `docker build .` fails; pass the version with `--build-arg VERSION=...`. `script/docker` and `script/cibuild` already - pass the version they compute on the host; it takes precedence. A - tag-derived version additionally needs `fetch-depth: 0` on the CI checkout - step, which clones shallow and fetches no tags by default. + pass the version they compute on the host; it takes precedence. The + canonical `.gitea/workflows/check.yml` sets `fetch-depth: 0` on its + checkout step, which otherwise clones shallow and fetches no tags, so a CI + build finds the tag too. - [ ] Gitea Actions workflow in `.gitea/workflows/` runs `script/cibuild` on - push, checks out with `persist-credentials: false`, and carries the - `concurrency` block that lets a new push cancel only the same branch's - older run — reference + push, checks out with `persist-credentials: false` and with + `fetch-depth: 0` (which fetches the tags `git describe` needs), and + carries the `concurrency` block that lets a new push cancel only the same + branch's older run — reference `https://git.eeqj.de/sneak/prompts/raw/branch/main/.gitea/workflows/check.yml` - [ ] Language-specific config: - [ ] Go: `go.mod`, `go.sum`, `.golangci.yml` (fetch from diff --git a/prompts/NEW_REPO_CHECKLIST.md b/prompts/NEW_REPO_CHECKLIST.md index 3f64ae3..8152040 100644 --- a/prompts/NEW_REPO_CHECKLIST.md +++ b/prompts/NEW_REPO_CHECKLIST.md @@ -112,9 +112,10 @@ Template files can be fetched from: - Non-server: the final stage brings up the dev environment - Image pinned by sha256 hash with version/date comment - [ ] Gitea Actions workflow at `.gitea/workflows/check.yml` that runs - `script/cibuild` on push, checks out with `persist-credentials: false`, - and carries the `concurrency` block that lets a new push cancel only the - same branch's older run — reference + `script/cibuild` on push, checks out with `persist-credentials: false` and + with `fetch-depth: 0` (which fetches the tags `git describe` needs), and + carries the `concurrency` block that lets a new push cancel only the same + branch's older run — reference `https://git.eeqj.de/sneak/prompts/raw/branch/main/.gitea/workflows/check.yml` - [ ] Language-specific: - [ ] Go: `go mod init sneak.berlin/go/`, `.golangci.yml` (fetch from diff --git a/prompts/REPO_POLICIES.md b/prompts/REPO_POLICIES.md index 5dc9ddd..ca2c195 100644 --- a/prompts/REPO_POLICIES.md +++ b/prompts/REPO_POLICIES.md @@ -292,7 +292,10 @@ style conventions are in separate documents: runs `script/cibuild` on push, and checks out the repo as its only other step, with `persist-credentials: false`: `script/cibuild` needs no token, and without it the checkout leaves the job's token in `.git/config` for every - later step. Its `concurrency` block groups runs by workflow and branch + later step. The checkout step also sets `fetch-depth: 0`, which fetches the + tags `git describe` needs: by default it clones shallow with no tags, and a + tagged repository's CI build would stamp a bare short commit id. The + workflow's `concurrency` block groups runs by workflow and branch (`${{ github.workflow }}-${{ github.ref }}`) with `cancel-in-progress: true`, so a new push cancels the older run on the same branch, queued or running, and no other: runs for replaced commits do not hold up the shared runner. @@ -472,8 +475,8 @@ style conventions are in separate documents: there because `ARG` is stage-scoped; passing `VERSION` to a repo whose Dockerfile declares no such `ARG` is ignored and costs nothing, which is why the scripts stay byte-identical. One consequence for CI: the standard - checkout action clones shallow and fetches no tags, so a repo that embeds a - tag-derived version must set `fetch-depth: 0` on its checkout step. + checkout action clones shallow and fetches no tags, so the canonical + `.gitea/workflows/check.yml` sets `fetch-depth: 0` on its checkout step. - **Verify `.dockerignore` by enumerating the image, not by reading the patterns.** Plant files at the root _and_ at least two directories deep, build