name: image # Builds a flashable postmarketOS image for the Fairphone 6 (kernel from # milos-linux combined-stable + imsd) and publishes it as the rolling # 'latest' release. # # Runs on the dedicated privileged runner label "pmos" (loop devices for # pmbootstrap install, qemu-user binfmt on the host for the aarch64 chroots). # Until that runner is registered, dispatched runs will sit queued. on: workflow_dispatch: # push trigger is temporary, for pipeline bring-up; narrow to # workflow_dispatch + a nightly schedule once the pipeline is green: push: branches: [main] # schedule: # - cron: '30 3 * * *' jobs: image: runs-on: pmos timeout-minutes: 420 steps: # actions/checkout & friends are Node actions; bare alpine has no node. # bash: required by the forgejo-release composite action. - name: Provision job container run: apk add -q nodejs git bash - name: Checkout uses: actions/checkout@v4 with: persist-credentials: true - name: Build image run: ./build.sh - name: Upload artifacts uses: actions/upload-artifact@v3 with: name: fp6-image-${{ github.sha }} path: dist/* if-no-files-found: error # Ship every locally built apk (kernel, modemmanager, libqmi, imsd, # callaudioshim, audio files, ...) to the Forgejo Alpine registry, so # installed systems get updates via 'apk upgrade' instead of losing # the FP6 patches to the next upstream version bump. Requires the # PACKAGE_TOKEN repo secret (catbot account, package:write scope); # skips quietly until it exists. 409 = same version already published. - name: Publish packages to the apk registry env: PACKAGE_TOKEN: ${{ secrets.PACKAGE_TOKEN }} run: | if [ -z "$PACKAGE_TOKEN" ]; then echo "no PACKAGE_TOKEN secret configured; skipping package publish" exit 0 fi apk add -q curl found=0 for f in /home/build/.local/var/pmbootstrap/packages/*/aarch64/*.apk; do [ -e "$f" ] || continue found=1 code=$(curl -s -o /dev/null -w '%{http_code}' \ --user "catbot:$PACKAGE_TOKEN" --upload-file "$f" \ "https://forgejo.catcrafts.net/api/packages/Catcrafts/alpine/edge/fp6") case "$code" in 201) echo "published: $(basename "$f")" ;; 409) echo "already published: $(basename "$f")" ;; *) echo "FAILED ($code): $(basename "$f")"; exit 1 ;; esac done [ "$found" = 1 ] || { echo "no packages found to publish"; exit 1; } - name: Update rolling 'latest' tag run: | git config --global --add safe.directory "$PWD" git config user.email "ci@catcrafts.net" git config user.name "fp6-img CI" git tag -f latest git push origin latest --force - name: Publish rolling 'latest' release uses: https://code.forgejo.org/actions/forgejo-release@v2 with: direction: upload url: ${{ github.server_url }} repo: ${{ github.repository }} tag: latest title: Latest FP6 postmarketOS image (EMERGENCY CALLING UNVERIFIED) prerelease: true override: true release-dir: dist token: ${{ secrets.GITHUB_TOKEN }}