mirror of
https://github.com/4gray/iptvnator.git
synced 2026-10-11 02:46:16 -08:00
gh run cancel needs the actions scope; with only contents: write the cancellation 403s silently and the settle-poll burns its full window. Also skip the cleanup job for fork PRs entirely: they never get a draft and their token is read-only regardless of the permissions block. Addresses Greptile P1 / Codex P2 follow-up on #1202. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
68 lines
3.0 KiB
YAML
68 lines
3.0 KiB
YAML
name: Cleanup PR Draft Release
|
|
|
|
on:
|
|
pull_request:
|
|
types: [closed]
|
|
|
|
# contents: write — delete the draft release; actions: write — cancel the
|
|
# closed PR's still-running build workflow before deleting.
|
|
permissions:
|
|
actions: write
|
|
contents: write
|
|
|
|
jobs:
|
|
delete-draft:
|
|
name: Delete PR draft release
|
|
# Fork PRs never get a draft (the release job skips them) and their
|
|
# GITHUB_TOKEN is read-only regardless of the permissions block, so
|
|
# there is nothing to cancel or delete.
|
|
if: github.event.pull_request.head.repo.full_name == github.repository
|
|
runs-on: ubuntu-latest
|
|
steps:
|
|
# A build for this PR may still be running and would recreate the
|
|
# rolling draft after we delete it. Cancel those runs (dead work
|
|
# for a closed PR anyway) and wait for them to wind down. The
|
|
# release job additionally re-checks the live PR state, so this
|
|
# wait is defense in depth, not the only guard.
|
|
- name: Cancel in-progress builds for the closed PR
|
|
env:
|
|
GH_TOKEN: ${{ secrets.GITHUB_TOKEN }}
|
|
HEAD_BRANCH: ${{ github.event.pull_request.head.ref }}
|
|
run: |
|
|
set -euo pipefail
|
|
|
|
list_active_runs() {
|
|
gh run list --repo "${GITHUB_REPOSITORY}" \
|
|
--workflow 'Build and Make Electron App' \
|
|
--branch "${HEAD_BRANCH}" \
|
|
--json databaseId,status \
|
|
--jq '.[] | select(.status == "queued" or .status == "in_progress" or .status == "waiting" or .status == "requested" or .status == "pending") | .databaseId'
|
|
}
|
|
|
|
for run_id in $(list_active_runs); do
|
|
echo "Cancelling run ${run_id}"
|
|
gh run cancel "${run_id}" --repo "${GITHUB_REPOSITORY}" || true
|
|
done
|
|
|
|
# Cancellation is asynchronous; poll until the runs settle.
|
|
for _ in $(seq 1 18); do
|
|
if [ -z "$(list_active_runs)" ]; then
|
|
break
|
|
fi
|
|
sleep 10
|
|
done
|
|
|
|
# Draft releases have no real git tag, so a lookup via
|
|
# releases/tags/<tag> returns 404. List releases and match the
|
|
# draft by its stored tag_name (test-pr-<n>) instead.
|
|
- name: Delete draft release for closed PR
|
|
env:
|
|
GH_TOKEN: ${{ secrets.GITHUB_TOKEN }}
|
|
PR_NUMBER: ${{ github.event.pull_request.number }}
|
|
run: |
|
|
set -euo pipefail
|
|
|
|
gh api "repos/${GITHUB_REPOSITORY}/releases?per_page=100" --paginate \
|
|
--jq ".[] | select(.draft and .tag_name == \"test-pr-${PR_NUMBER}\") | .id" |
|
|
xargs -r -n1 -I{} gh api -X DELETE "repos/${GITHUB_REPOSITORY}/releases/{}"
|