diff --git a/.github/workflows/update-meta-gbp.yml b/.github/workflows/update-meta-gbp.yml index 1754ff1..8ce9130 100644 --- a/.github/workflows/update-meta-gbp.yml +++ b/.github/workflows/update-meta-gbp.yml @@ -72,17 +72,17 @@ jobs: - name: meta-gbp update run: python-pipeline/meta-gbp update --no-interactive - - name: Export revision - id: rev - run: | - echo "rev=$(git rev-parse HEAD)" >> "$GITHUB_OUTPUT" - echo "py=$(echo '${{ github.repository }}' | cut -d/ -f2 | sed 's/^py//')" >> "$GITHUB_OUTPUT" - echo "py_repo_dir=$GITHUB_WORKSPACE" >> "$GITHUB_OUTPUT" - + # Fetch/rebase before exporting rev so build/smoke/publish use the SHA that lands on main. + # Stale origin/main (e.g. commits pushed after checkout) used to cause non-fast-forward push failures. - name: Push update commits run: | git remote set-url origin "https://x-access-token:${{ secrets.GITHUB_TOKEN }}@github.com/${{ github.repository }}.git" + git fetch origin main if git rev-parse origin/main >/dev/null 2>&1; then + behind="$(git rev-list --count HEAD..origin/main || true)" + if [[ "${behind}" != "0" ]]; then + git rebase origin/main + fi ahead="$(git rev-list --count origin/main..HEAD || true)" else ahead="$(git rev-list --count HEAD || true)" @@ -91,6 +91,13 @@ jobs: git push origin HEAD:main fi + - name: Export revision + id: rev + run: | + echo "rev=$(git rev-parse HEAD)" >> "$GITHUB_OUTPUT" + echo "py=$(echo '${{ github.repository }}' | cut -d/ -f2 | sed 's/^py//')" >> "$GITHUB_OUTPUT" + echo "py_repo_dir=$GITHUB_WORKSPACE" >> "$GITHUB_OUTPUT" + build: needs: update runs-on: ${{ matrix.arch == 'arm64' && 'ubuntu-24.04-arm' || 'ubuntu-latest' }} diff --git a/docs/ci.md b/docs/ci.md index 650785c..7e027cd 100644 --- a/docs/ci.md +++ b/docs/ci.md @@ -113,6 +113,7 @@ Scheduled runs publish when `DEPLOY_SSH_KEY` is configured. Use `workflow_dispat | Failure | Action | |---------|--------| | `meta-gbp update` rebase conflict | Resolve locally, push fix, re-run workflow | +| Push update commits non-fast-forward | Workflow fetches `main` and rebases before push; if rebase conflicts, resolve locally and re-run | | Builder image pull fails | CI falls back to `make build-tools-image build-builder-images` (slow) | | Smoke test `apt-get -f install` fails | Check missing runtime deps in generated `.deb` set | | Publish SSH/rsync fails | Verify `DEPLOY_*` variables and `DEPLOY_SSH_KEY` |