claude f9777ccbd2 Stop the reporter naming a path that no longer exists
The comment it posts said "posted by `tools/report_job_log.py`". Since
weblib-archive#44 there is no such file in any consuming repo -- the script
lives here. So it pointed a reader at a path they cannot find, on the one
occasion they are already looking for the cause of a failure.

Links here instead.

Found by deliberately breaking a build on weblib-fs#31 to prove the failure
path worked. A green run never renders this message, so nothing else would
have surfaced it.

Co-authored-by: bit <bit@das-labor.org>
2026-09-07 12:15:05 +00:00
2026-09-07 11:30:00 +00:00
2026-09-07 11:25:33 +00:00
2026-09-07 11:25:33 +00:00

weblib-ci

The CI scripts shared by cfbypass, weblib-archive, weblib-fs and weblib-viewer. Split out per weblib-archive#44, where they had been hand-copied into each repo and had already drifted once.

Public deliberately. Nothing here is a secret or specific to the archive's contents: a nixpkgs-pinning wrapper, a log poster and a label reconciler. Public means a consumer needs no deploy key, no ssh setup and no secret to fetch it — which was measured to be the difference between one step and three.

What is here

file what it does
with-nixpkgs.sh Runs a command with one nixpkgs package on PATH, pinned to the consuming repo's flake.lock. Avoids nix shell nixpkgs#x, which re-resolves the registry and refetches a channel tarball whenever the branch moves.
report_job_log.py Posts the tail of a build log as a PR comment. Exists because actions/jobs/{id}/logs returns 500 for every id on Gitea 1.25.2, so a red job otherwise says only that it failed.
sync_blocked_label.py Keeps Status/Blocked in step with Gitea's dependency graph.

All three are standard library / plain bash only. They are run, not built, so this repo has no flake.

Using it

- uses: actions/checkout@v4
- id: ci
  uses: https://git.chaosbit.de/weblib/weblib-ci@main
- run: bash ${{ steps.ci.outputs.path }}/with-nixpkgs.sh python3 \
         python3 ${{ steps.ci.outputs.path }}/report_job_log.py /tmp/build.log

No credentials anywhere: the repo is public, which is the point of it being so.

with-nixpkgs.sh reads the consuming repo's flake.lock relative to the working directory, so it keeps working when invoked by absolute path from outside the checkout.

Use the full URL, not weblib/weblib-ci@main

Measured on weblib-archive#44 (2026-09-07), one job per form because Gitea posts one commit status per job and job logs return 500:

form result
uses: https://git.chaosbit.de/weblib/weblib-ci@main works
uses: weblib/weblib-ci@main fails
git clone https://…/weblib-ci.git with no credentials works
steps.<id>.outputs.path, then running a tool through it works

The bare owner/repo form resolves against the instance's default actions URL rather than this host, so it has to be the full URL. Both forms failed while this repo was private, which is the other half of why it is public — the alternative was a deploy key and an ssh setup step in four repos.

The outputs.path row is listed separately on purpose: the action running and its output reaching the caller are different claims, and a composite action returning an empty string is exactly the sort of thing that looks green.

Why not a flake input

These are scripts a workflow runs, not derivations. A flake input would cost a flake.lock bump in four repos every time one changes, and buys nothing.

Description
No description provided
Readme 99 KiB
Languages
Python 87.6%
Shell 12.4%