lib/facts.sh + release.yml — the release doors speak the shim, and an unread fact refuses (#191) #193

Merged
andres merged 5 commits from build/191-release-door-facts into main 2026-08-04 14:58:30 +00:00
2 changed files with 19 additions and 8 deletions
Showing only changes of commit 87cc7d5aa5 - Show all commits

View file

@ -2,19 +2,23 @@
- The release doors run on a Forgejo consumer. `lib/facts.sh` and
`release.yml` gathered and published through `gh`, which the runner image
does not ship, so the merge door read `labeled=no` for a correctly labeled
ceremony PR and the tag door died at the publish (#191).
does not ship, so the merge door read `labeled=no` for a correctly
labeled ceremony PR and the tag door died at the publish (#191).
- A release fact that could not be read is no longer reported as a definite
`no`. A completed read finding no label is still `no` and still
fail-closed; a read that did not complete refuses and emits no fact — the
distinction that demoted a ceremony PR to "a bare push" (#191).
fail-closed; a read that did not complete refuses and emits no fact
(#191).
### Added
- `forge_release_exists`, `forge_commit_pulls`, `forge_tag_create`,
`forge_release_create` and `forge_pr_create` on both backends, so the
release path names no client. Forgejo serves one PR object at
`/commits/{sha}/pull` where GitHub serves an array at `/pulls`, and
creates tags at `/tags` where GitHub POSTs to `/git/refs`; both verbs emit
the GitHub shape so the call sites carry one expression (#191).
release path names no client (#191).
- The forgejo backend serves one PR object at `/commits/{sha}/pull` where
GitHub serves an array at `/pulls`; both verbs emit the array shape, so
the call site carries one expression (#191).
- Forgejo creates tags at `POST /tags` — it serves `/git/refs` GET-only,
so GitHub's ref-POST would have 404'd there forever (#191).

View file

@ -101,6 +101,13 @@ if ! version_is_dev "$ver"; then
# The forge is selected only in the states that consult the API — a -dev
# tree, every ordinary merge, still decides on the two versions alone and
# touches no forge at all (#8's tolerance for empty facts).
# The forgejo backend addresses the repo through REPO; the github backend
# reads GITHUB_REPOSITORY directly. Set it here from the one this script
# already documents, so the two backends address the same repository —
# missing it made every forgejo read refuse with "REPO: unbound variable"
# (caught by release-exercise on !193).
REPO="${REPO:-${GITHUB_REPOSITORY:?facts: GITHUB_REPOSITORY is required for the API facts}}"
export REPO
# "" means decide from the environment; forge_select takes an explicit
# forge only in tests.
forge_select "" || exit 1