From e7f87c8f8d10cf5e8b05754a21e56311ddd5e7ff Mon Sep 17 00:00:00 2001 From: sagudev <16504129+sagudev@users.noreply.github.com> Date: Tue, 15 Sep 2026 17:00:34 +0200 Subject: [PATCH] Add security bump automation for ANGLE Signed-off-by: sagudev <16504129+sagudev@users.noreply.github.com> --- .github/workflows/security-bump.yml | 40 +++++++++++++ security-bump.py | 90 +++++++++++++++++++++++++++++ 2 files changed, 130 insertions(+) create mode 100644 .github/workflows/security-bump.yml create mode 100755 security-bump.py diff --git a/.github/workflows/security-bump.yml b/.github/workflows/security-bump.yml new file mode 100644 index 000000000..c12d3e160 --- /dev/null +++ b/.github/workflows/security-bump.yml @@ -0,0 +1,40 @@ +name: Security bump + +on: + workflow_dispatch: + schedule: + # Runs at 03:30, every Saturday + - cron: "30 3 * * 6" + +jobs: + bump: + runs-on: ubuntu-latest + # We don't want to run the security bump in forks. + if: github.repository == 'servo/mozangle' + permissions: + contents: write + pull-requests: write + steps: + - uses: actions/checkout@v6 + - name: Configure Git + run: | + git config user.name "github-actions[bot]" + git config user.email "41898282+github-actions[bot]@users.noreply.github.com" + - run: python3 ./security-bump.py + id: bump + - run: python3 ./update.py + - name: Commit changes + if: ${{ steps.bump.outputs.tag != '' }} + # if there are no changes to the gfx/angle directory we remove all other changes + # so there will be no PR created + run: | + git add gfx/angle + git --cached diff --exit-code && git reset --hard HEAD || git commit -sam "Bump ANGLE to ${{ steps.bump.outputs.tag }}" + - name: Create Pull Request + uses: peter-evans/create-pull-request@c0f553fe549906ede9cf27b5156039d195d2ece0 + with: + title: Security bump ANGLE to ${{ steps.bump.outputs.tag }} + body: | + Bump ANGLE to ${{ steps.bump.outputs.tag }} + + Close and reopen this PR to trigger CI. diff --git a/security-bump.py b/security-bump.py new file mode 100755 index 000000000..14a7e7795 --- /dev/null +++ b/security-bump.py @@ -0,0 +1,90 @@ +#!/usr/bin/env python3 + +import os +import re +import subprocess +import tempfile +from pathlib import Path + +upstream_txt = Path("UPSTREAM").read_text() + +tag, commit = upstream_txt.removeprefix("gfx/angle is taken from ").split(": ", 1) + +print(f"Existing Firefox tag: {tag} and commit: {commit}") + +esr = tag.removeprefix("FIREFOX_").split("_", 1)[0] + +print(f"ESR: {esr}") + +with tempfile.TemporaryDirectory() as tmpdir: + subprocess.run( + [ + "git", + "clone", + "--filter=blob:none", + "--no-checkout", + "https://github.com/mozilla-firefox/firefox.git", + str(tmpdir), + ], + check=True, + ) + + subprocess.run( + ["git", "fetch", "--tags"], + cwd=tmpdir, + check=True, + ) + + latest_tag = ( + subprocess.check_output( + [ + "git", + "for-each-ref", + "--sort=-creatordate", + "--format=%(refname:short)", + f"refs/tags/FIREFOX_{esr}_*_RELEASE", + ], + cwd=tmpdir, + ) + .decode() + .splitlines()[0] + ) + + latest_commit = ( + subprocess.check_output(["git", "rev-list", "-n", "1", latest_tag], cwd=tmpdir) + .decode() + .strip() + ) + +print(f"Latest Firefox tag: {latest_tag} and commit: {latest_commit}") + +Path("UPSTREAM").write_text(f"gfx/angle is taken from {latest_tag}: {latest_commit}\n") + +if GITHUB_OUTPUT := os.getenv("GITHUB_OUTPUT"): + with open(GITHUB_OUTPUT, "a") as github_output_file: + print(f"tag={latest_tag}", file=github_output_file) + print(f"commit={latest_commit}", file=github_output_file) + +# bump cargo.toml + +toml_path = Path("Cargo.toml") + +toml_text = toml_path.read_text() +# extract create version +version_match = re.search( + r'^\s*version\s*=\s*"(\d+)\.(\d+)\.(\d+)"', + toml_text, + re.MULTILINE, +) +version_major, version_minor, version_patch = map(int, version_match.groups()) +print(f"Current mozangle version: {version_major}.{version_minor}.{version_patch}") +toml_text = re.sub( + r'version = "\d+\.\d+\.\d+"\n', + f'version = "{version_major}.{version_minor}.{version_patch + 1}"\n', + toml_text, +) +print( + f"Bumped mozangle version to: {version_major}.{version_minor}.{version_patch + 1}" +) + +toml_path.write_text(toml_text)