From 20106fb433167897595b2fede45cb71ec5f4192d Mon Sep 17 00:00:00 2001 From: Saubhik Datta <50126327+saubhikdattagithub@users.noreply.github.com> Date: Mon, 28 Sep 2026 10:10:15 +0200 Subject: [PATCH 1/2] chore: move UPSTREAM_TAG out of build.yml into plain file MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit GITHUB_TOKEN cannot push changes to workflow files without the `workflows` permission, causing the daily update-upstream-tag job to fail. Moving UPSTREAM_TAG into a plain UPSTREAM_TAG file (same pattern as package-linux/prepare_source) means the auto-update workflow only touches a plain file — no special permission needed. build.yml reads the tag via `cat UPSTREAM_TAG` after checkout. update_upstream.yml writes to UPSTREAM_TAG instead of build.yml. Signed-off-by: Saubhik Datta <50126327+saubhikdattagithub@users.noreply.github.com> --- .github/workflows/build.yml | 13 ++++++++++--- .github/workflows/update_upstream.yml | 12 ++++++------ UPSTREAM_TAG | 1 + 3 files changed, 17 insertions(+), 9 deletions(-) create mode 100644 UPSTREAM_TAG diff --git a/.github/workflows/build.yml b/.github/workflows/build.yml index 21b2820..155af44 100644 --- a/.github/workflows/build.yml +++ b/.github/workflows/build.yml @@ -8,7 +8,6 @@ on: env: UPSTREAM_REPO: astral-sh/python-build-standalone - UPSTREAM_TAG: "20260901" PYTHON_VERSION: "3.14" BUILD_OPTIONS: "pgo+lto" @@ -22,11 +21,15 @@ jobs: with: path: patch-repo + - name: Read UPSTREAM_TAG + id: upstream_tag + run: echo "tag=$(cat patch-repo/UPSTREAM_TAG)" >> "$GITHUB_OUTPUT" + - name: Checkout upstream python-build-standalone uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 with: repository: ${{ env.UPSTREAM_REPO }} - ref: ${{ env.UPSTREAM_TAG }} + ref: ${{ steps.upstream_tag.outputs.tag }} path: python-build-standalone - name: Apply no-libdb patch @@ -106,11 +109,15 @@ jobs: with: path: patch-repo + - name: Read UPSTREAM_TAG + id: upstream_tag + run: echo "tag=$(cat patch-repo/UPSTREAM_TAG)" >> "$GITHUB_OUTPUT" + - name: Checkout upstream python-build-standalone uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 with: repository: ${{ env.UPSTREAM_REPO }} - ref: ${{ env.UPSTREAM_TAG }} + ref: ${{ steps.upstream_tag.outputs.tag }} path: python-build-standalone - name: Apply no-libdb patch diff --git a/.github/workflows/update_upstream.yml b/.github/workflows/update_upstream.yml index 3b4f0c7..107e774 100644 --- a/.github/workflows/update_upstream.yml +++ b/.github/workflows/update_upstream.yml @@ -24,13 +24,13 @@ jobs: latest=$(gh release view --repo astral-sh/python-build-standalone --json tagName --jq '.tagName') echo "tag=$latest" >> "$GITHUB_OUTPUT" - - name: Get current tag from build.yml + - name: Get current tag from UPSTREAM_TAG file id: current run: | - current=$(grep 'UPSTREAM_TAG:' .github/workflows/build.yml | sed 's/.*UPSTREAM_TAG: *"\(.*\)".*/\1/') + current=$(cat UPSTREAM_TAG) echo "tag=$current" >> "$GITHUB_OUTPUT" - - name: Update build.yml if outdated + - name: Update UPSTREAM_TAG file if outdated id: changes run: | latest="${{ steps.upstream.outputs.tag }}" @@ -43,7 +43,7 @@ jobs: fi echo "Updating UPSTREAM_TAG from $current to $latest" - sed -i "s/UPSTREAM_TAG: \"${current}\"/UPSTREAM_TAG: \"${latest}\"/" .github/workflows/build.yml + echo "$latest" > UPSTREAM_TAG echo "has_changes=true" >> "$GITHUB_OUTPUT" echo "latest=$latest" >> "$GITHUB_OUTPUT" echo "current=$current" >> "$GITHUB_OUTPUT" @@ -70,7 +70,7 @@ jobs: fi git checkout -b "${branch}" - git add .github/workflows/build.yml + git add UPSTREAM_TAG git commit -s -m "chore: update UPSTREAM_TAG from ${current} to ${latest}" git push origin "${branch}" -f @@ -78,4 +78,4 @@ jobs: --base main \ --head "${branch}" \ --title "chore: update UPSTREAM_TAG from ${current} to ${latest}" \ - --body "Automated update of \`UPSTREAM_TAG\` in \`build.yml\` from \`${current}\` to \`${latest}\` from [astral-sh/python-build-standalone](https://github.com/astral-sh/python-build-standalone/releases/tag/${latest})." + --body "Automated update of \`UPSTREAM_TAG\` from \`${current}\` to \`${latest}\` from [astral-sh/python-build-standalone](https://github.com/astral-sh/python-build-standalone/releases/tag/${latest})." diff --git a/UPSTREAM_TAG b/UPSTREAM_TAG new file mode 100644 index 0000000..0d3a0d1 --- /dev/null +++ b/UPSTREAM_TAG @@ -0,0 +1 @@ +20260924 From 63de91d9ff6623b5078375a477e6c835af56990b Mon Sep 17 00:00:00 2001 From: Saubhik Datta <50126327+saubhikdattagithub@users.noreply.github.com> Date: Mon, 28 Sep 2026 11:20:32 +0200 Subject: [PATCH 2/2] rename the wf Signed-off-by: Saubhik Datta <50126327+saubhikdattagithub@users.noreply.github.com> --- .github/workflows/update_upstream.yml | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/.github/workflows/update_upstream.yml b/.github/workflows/update_upstream.yml index 107e774..ab035a5 100644 --- a/.github/workflows/update_upstream.yml +++ b/.github/workflows/update_upstream.yml @@ -1,4 +1,4 @@ -name: Update upstream tag +name: update tag on: workflow_dispatch: