From 990868b2e72aed583d7d3c19b72d29e8cbc12601 Mon Sep 17 00:00:00 2001 From: atlas Date: Sun, 28 Jun 2026 23:53:07 +0200 Subject: [PATCH] address argus review on the mirror seed - drop the three cross-ref tracker tags from comments/description (prose only) - build the orgs + migrate JSON bodies with jq -n --arg (an upstream URL containing a quote no longer corrupts the request) - don't auto-append the actions/checkout mirror when the operator already declared that dest (avoids a duplicate effectiveMirrors entry when CI is on) --- nix/modules/hive-forge.nix | 23 +++++++++++++++++------ 1 file changed, 17 insertions(+), 6 deletions(-) diff --git a/nix/modules/hive-forge.nix b/nix/modules/hive-forge.nix index dd1399fd..bad108e8 100644 --- a/nix/modules/hive-forge.nix +++ b/nix/modules/hive-forge.nix @@ -38,14 +38,21 @@ let # When CI is enabled, the runner needs `actions/checkout` resolvable # without external DNS (hive-ci shares the host netns, so a host-resolver # blip otherwise reds every `actions/checkout@vN` fetch from - # data.forgejo.org — see #2072). Auto-append a pull-mirror of it and point + # data.forgejo.org). Auto-append a pull-mirror of it and point # forgejo's DEFAULT_ACTIONS_URL at this instance so `uses:` resolves local. ciEnabled = config.services.hyperhive.forge.ci.enable; actionCheckoutMirror = { upstream = "https://github.com/actions/checkout"; dest = "actions/checkout"; }; - effectiveMirrors = cfg.mirrors ++ lib.optional ciEnabled actionCheckoutMirror; + # Auto-append the actions/checkout mirror only when CI is on AND the + # operator hasn't already declared that dest themselves (else CI-on + + # an explicit `actions/checkout` entry would duplicate it). + effectiveMirrors = + cfg.mirrors + ++ lib.optional ( + ciEnabled && !(lib.any (m: m.dest == actionCheckoutMirror.dest) cfg.mirrors) + ) actionCheckoutMirror; # Host-side core admin token hive-c0re mints after provisioning the forge # admin (same file hive-ci-prefetch reads). Root-only; never enters a @@ -78,9 +85,10 @@ let seed_one() { upstream="$1"; owner="$2"; repo="$3" # Ensure the dest org (idempotent: 201 created / 422 already exists). + org_body=$(${pkgs.jq}/bin/jq -nc --arg u "$owner" '{ username: $u }') ohttp=$(${pkgs.curl}/bin/curl -s -o /dev/null -w '%{http_code}' -X POST \ -H "$AUTH" -H 'Content-Type: application/json' \ - "$FORGE_URL/api/v1/orgs" -d "{\"username\":\"$owner\"}" || echo 000) + "$FORGE_URL/api/v1/orgs" -d "$org_body" || echo 000) case "$ohttp" in 201 | 422) ;; *) echo "forgejo-seed-mirrors: ensure org '$owner' returned HTTP $ohttp" >&2 ;; @@ -97,10 +105,13 @@ let # Create the pull-mirror. service=git → generic git clone of # clone_addr (no upstream API token needed); mirror=true → forgejo # keeps it re-syncing on its mirror interval. + mig_body=$(${pkgs.jq}/bin/jq -nc \ + --arg c "$upstream" --arg o "$owner" --arg r "$repo" \ + '{ clone_addr: $c, repo_owner: $o, repo_name: $r, mirror: true, service: "git", private: false }') resp=$(${pkgs.curl}/bin/curl -s -w $'\n%{http_code}' -X POST \ -H "$AUTH" -H 'Content-Type: application/json' \ "$FORGE_URL/api/v1/repos/migrate" \ - -d "{\"clone_addr\":\"$upstream\",\"repo_owner\":\"$owner\",\"repo_name\":\"$repo\",\"mirror\":true,\"service\":\"git\",\"private\":false}" \ + -d "$mig_body" \ || printf '\n000') mhttp=$(printf '%s' "$resp" | tail -n1) case "$mhttp" in @@ -305,7 +316,7 @@ in forgejo's `DEFAULT_ACTIONS_URL` is pointed at this instance, so CI `uses: actions/checkout@vN` steps resolve entirely on loopback with no external DNS on the critical path (the seed/re-sync needs - external DNS, but that's off the CI path). See `#2072`. + external DNS, but that's off the CI path). ''; }; }; @@ -468,7 +479,7 @@ in # THIS instance (the seeded `actions/checkout` pull-mirror) # instead of the upstream default `data.forgejo.org` — keeps # the checkout step on loopback, immune to a host-resolver - # blip (#2072). `self` = forgejo expands actions against its + # blip. `self` = forgejo expands actions against its # own ROOT_URL. actions.DEFAULT_ACTIONS_URL = lib.mkIf ciEnabled "self"; # F3 (federation) computes its data dir relative to the