v0.4.0 failed to mirror, and it would have failed at every future release. On a tag-triggered run, checkout materializes refs/tags/<tag> as a LIGHTWEIGHT tag at the commit SHA; the annotated tag object Gitea holds is never fetched. Run 2070 therefore pushed a lightweight v0.4.0 to GitHub and reported success. Run 2076, on main with fetch-depth 0, did fetch the real annotated object and was rejected with "already exists" trying to correct it -- git will not clobber an existing tag. Gitea hade138eeb(annotated), GitHub hadd2caa6d(the commit). Re-fetch canonical tag objects from Gitea before pushing. --force rewrites LOCAL tag refs only; it is not a force push and does not weaken the non-force guarantee on main. It is required: without it the fetch is rejected with "would clobber existing tag" and the lightweight ref survives to be mirrored again. Verified against a scratch clone -- lightweightd2caa6dbecomes annotatede138eeb, peeling back to the same commit; without --force the tag is unchanged. The GitHub tag was repaired by hand out of band, so the two remotes already agree; this stops it recurring.
56 lines
2.4 KiB
YAML
56 lines
2.4 KiB
YAML
# Mirror the canonical Gitea repo to the public GitHub mirror.
|
|
#
|
|
# Deliberately a plain `git push`, NOT Gitea's built-in push mirror. A push
|
|
# mirror force-updates the refs it owns: if anyone ever clicks Merge on a
|
|
# GitHub PR, the next sync silently overwrites main, the PR still displays
|
|
# "Merged", the commit becomes unreachable, and nothing anywhere says so.
|
|
# A non-force push is REJECTED as non-fast-forward the moment that happens,
|
|
# turning a silent data-loss trap into a red CI run in a place we already look.
|
|
#
|
|
# Do NOT add --force here, and do NOT add GitHub branch protection to the
|
|
# mirror: protection rules block the mirror's legitimate pushes too, breaking
|
|
# normal syncing to catch an abnormal case.
|
|
#
|
|
# PAT_GH is a GitHub personal access token (repo + workflow scope; workflow is
|
|
# required because this pushes .github/workflows/). It is stored as a Gitea
|
|
# Actions secret. The name cannot begin with GITHUB_ or GITEA_ -- Gitea
|
|
# reserves both prefixes for its own injected variables and rejects the secret.
|
|
name: Mirror to GitHub
|
|
|
|
on:
|
|
push:
|
|
branches: [main]
|
|
tags: ['v*']
|
|
|
|
jobs:
|
|
mirror:
|
|
runs-on: ubuntu-latest
|
|
steps:
|
|
- uses: actions/checkout@v4
|
|
with:
|
|
fetch-depth: 0
|
|
|
|
- name: Push main and tags to the GitHub mirror
|
|
env:
|
|
PAT_GH: ${{ secrets.PAT_GH }}
|
|
run: |
|
|
set -eu
|
|
if [ -z "${PAT_GH:-}" ]; then
|
|
echo "PAT_GH is unset -- add it under Settings > Actions > Secrets." >&2
|
|
exit 1
|
|
fi
|
|
# On a tag-triggered run, checkout materializes refs/tags/<tag> as a
|
|
# LIGHTWEIGHT tag at the commit SHA -- the annotated tag object Gitea
|
|
# holds is never fetched. Mirroring that strips the annotation, and the
|
|
# NEXT run on main (which does fetch the real object) is then rejected
|
|
# with "already exists" trying to correct it, because git will not
|
|
# clobber an existing tag. That is why v0.4.0 failed to mirror.
|
|
#
|
|
# Re-fetch canonical tag objects from Gitea first. --force here rewrites
|
|
# LOCAL tag refs only; it is not a force push and does not weaken the
|
|
# non-force guarantee on main documented above.
|
|
git fetch --tags --force origin
|
|
|
|
git push "https://x-access-token:${PAT_GH}@github.com/civilytics/uscogdata.git" \
|
|
HEAD:refs/heads/main --tags
|