#!/usr/bin/env bash set -euo pipefail cd "$(dirname "$0")/.." for tool in git curl jq; do command -v "$tool" >/dev/null; done [[ -z $(git status --porcelain) ]] || { echo 'Release requires a clean working tree' >&2 exit 1 } sha=$(git rev-parse HEAD) owner=did:plc:mkqt76xvfgxuemlwlx6ruc3w pds=$(curl -fsS --max-time 30 "https://plc.directory/$owner" | jq -er '.service[] | select(.type == "AtprotoPersonalDataServer") | .serviceEndpoint') record=$(curl -fsSG --max-time 30 "$pds/xrpc/com.atproto.repo.getRecord" \ --data-urlencode "repo=$owner" --data-urlencode collection=sh.tangled.repo --data-urlencode rkey=jetstream) repo=$(jq -er '.value.repoDid | strings | select(length > 0)' <<<"$record") spindle=$(jq -er '.value.spindle | strings | select(length > 0)' <<<"$record") || { echo 'Jetstream has no selected spindle' >&2 exit 1 } results='[]' cursor='' while :; do page=$(curl -fsSG --max-time 30 "https://$spindle/xrpc/sh.tangled.ci.queryPipelines" \ --data-urlencode "repo=$repo" --data-urlencode limit=250 --data-urlencode "cursor=$cursor") jq -e '.pipelines | type == "array"' <<<"$page" >/dev/null results=$(jq -cn --argjson previous "$results" --argjson page "$page" --arg sha "$sha" \ '$previous + [$page.pipelines[] | select(.commit == $sha)]') if jq -e 'all(["checks.yml", "release.yml"][]; . as $name | any($pipelines[]; any(.workflows[]; .name == $name)))' \ --argjson pipelines "$results" <</dev/null; then break fi next=$(jq -r '.cursor // empty' <<<"$page") [[ -n $next && $next != "$cursor" ]] || break cursor=$next done jq -r --arg sha "$sha" ' . as $pipelines | ["checks.yml", "release.yml"][] as $name | ([$pipelines[] | . as $pipeline | .workflows[] | select(.name == $name) | {pipeline: $pipeline.id, status: .status}][0] // {pipeline: "missing", status: "missing"}) as $run | "\($sha) \($name) \($run.status) (\($run.pipeline))" ' <<<"$results" jq -e ' . as $pipelines | all(["checks.yml", "release.yml"][]; . as $name | ([$pipelines[] | .workflows[] | select(.name == $name)][0].status // "missing") == "success") ' <<<"$results" >/dev/null || { echo 'Release blocked: latest exact-commit checks and release workflows must both succeed' >&2 exit 1 } echo "Release checks passed for $sha; no tag created or pushed"