Make release publication fail closed
This commit is contained in:
@@ -56,8 +56,8 @@ bin/omarchy-release # shepherd: status + guided next step
|
|||||||
bin/omarchy-release start 4.0.2 # open the train: branch v4-0-2 + staging PR
|
bin/omarchy-release start 4.0.2 # open the train: branch v4-0-2 + staging PR
|
||||||
bin/omarchy-release pick # choose merged PRs to cherry-pick (multi-select)
|
bin/omarchy-release pick # choose merged PRs to cherry-pick (multi-select)
|
||||||
bin/omarchy-release rc # publish the next 4.0.2rcN to the rc channel
|
bin/omarchy-release rc # publish the next 4.0.2rcN to the rc channel
|
||||||
bin/omarchy-release ship # final pins, promote rc → stable, tag,
|
bin/omarchy-release ship # tag, final pins, promote rc → stable,
|
||||||
# GitHub release, ISO, website — one swoop
|
# draft GitHub release, ISO, website — one swoop
|
||||||
bin/omarchy-release doctor # verify credentials/connections up front
|
bin/omarchy-release doctor # verify credentials/connections up front
|
||||||
```
|
```
|
||||||
|
|
||||||
|
|||||||
+52
-27
@@ -52,7 +52,7 @@ Commands:
|
|||||||
pick [pr#|sha ...] Cherry-pick merged PRs onto the release branch; with no
|
pick [pr#|sha ...] Cherry-pick merged PRs onto the release branch; with no
|
||||||
args, choose from a list of merged $DEV_BRANCH PRs
|
args, choose from a list of merged $DEV_BRANCH PRs
|
||||||
rc Cut the next X.Y.ZrcN into the rc channel
|
rc Cut the next X.Y.ZrcN into the rc channel
|
||||||
ship Final pins, promote rc -> stable, tag, GitHub release,
|
ship Tag, final pins, promote rc -> stable, draft GitHub release,
|
||||||
ISO (prompted), website bump
|
ISO (prompted), website bump
|
||||||
status Show where the train stands (read-only)
|
status Show where the train stands (read-only)
|
||||||
doctor Verify every credential and connection the flow needs
|
doctor Verify every credential and connection the flow needs
|
||||||
@@ -158,6 +158,13 @@ ensure_mirror_clone() {
|
|||||||
git -C "$MIRROR_CLONE" remote set-url --push origin "$UPSTREAM_PUSH_URL"
|
git -C "$MIRROR_CLONE" remote set-url --push origin "$UPSTREAM_PUSH_URL"
|
||||||
}
|
}
|
||||||
|
|
||||||
|
# A clone made with `git clone --mirror` sets remote.origin.mirror=true. Git
|
||||||
|
# otherwise rejects an explicit SHA:ref push as an invalid combination with
|
||||||
|
# mirror mode, so disable that remote setting for narrowly targeted pushes.
|
||||||
|
push_upstream_ref() { # push_upstream_ref <source-sha> <destination-ref>
|
||||||
|
git -c remote.origin.mirror=false -C "$MIRROR_CLONE" push --quiet origin "$1:$2"
|
||||||
|
}
|
||||||
|
|
||||||
ensure_work_clone() {
|
ensure_work_clone() {
|
||||||
if [[ -d "$WORK_CLONE" ]]; then
|
if [[ -d "$WORK_CLONE" ]]; then
|
||||||
git -C "$WORK_CLONE" fetch --quiet origin
|
git -C "$WORK_CLONE" fetch --quiet origin
|
||||||
@@ -449,7 +456,7 @@ cmd_start() {
|
|||||||
print_info "Release type: $kind — branching $branch from $base_ref (${base_sha:0:12})"
|
print_info "Release type: $kind — branching $branch from $base_ref (${base_sha:0:12})"
|
||||||
confirm "Create branch $branch on $UPSTREAM_REPO?" || exit 1
|
confirm "Create branch $branch on $UPSTREAM_REPO?" || exit 1
|
||||||
ensure_mirror_clone
|
ensure_mirror_clone
|
||||||
git -C "$MIRROR_CLONE" push --quiet origin "$base_sha:refs/heads/$branch"
|
push_upstream_ref "$base_sha" "refs/heads/$branch"
|
||||||
print_success "Created $branch"
|
print_success "Created $branch"
|
||||||
fi
|
fi
|
||||||
|
|
||||||
@@ -756,36 +763,61 @@ cmd_ship() {
|
|||||||
|
|
||||||
echo ""
|
echo ""
|
||||||
print_info "This will, in order (steps already done are skipped):"
|
print_info "This will, in order (steps already done are skipped):"
|
||||||
echo " 1. Pin the final $version from $branch@${pin_commit:0:12} and publish it to rc"
|
echo " 1. Tag v$version at the tested $branch@${pin_commit:0:12} on $UPSTREAM_REPO"
|
||||||
echo " 2. Promote the rc channel to stable (packages + signatures + db)"
|
echo " 2. Pin the final $version from that tag and publish it to rc"
|
||||||
echo " 3. Tag v$version on $UPSTREAM_REPO"
|
echo " 3. Promote the rc channel to stable (packages + signatures + db)"
|
||||||
echo " 4. Merge the final pins to master (edge overlap + record)"
|
echo " 4. Merge the final pins to master (edge overlap + record)"
|
||||||
echo " 5. Create the GitHub release from the staging PR body"
|
echo " 5. Create a draft GitHub release from the staging PR body"
|
||||||
echo " 6. Build + upload the final ISO (${iso_mode})"
|
echo " 6. Build + upload the final ISO (${iso_mode})"
|
||||||
echo " 7. Point the website at the new ISO"
|
echo " 7. Point the website at the new ISO"
|
||||||
echo ""
|
echo ""
|
||||||
confirm "Ship $version?" || exit 1
|
confirm "Ship $version?" || exit 1
|
||||||
|
|
||||||
# 1. Final pins into rc
|
# 1. Tag the exact commit the tested RC was built from before any final
|
||||||
|
# package metadata is written or published. A pre-existing tag is only safe
|
||||||
|
# to reuse when it resolves to that same commit.
|
||||||
|
local tag_commit
|
||||||
|
if tag_exists "v$version"; then
|
||||||
|
tag_commit=$(resolve_tag_commit "v$version")
|
||||||
|
if [[ "$tag_commit" != "$pin_commit" ]]; then
|
||||||
|
print_error "Tag v$version points to ${tag_commit:0:12}, not the tested ${pin_commit:0:12}"
|
||||||
|
echo "Refusing to publish final package metadata for the wrong source commit."
|
||||||
|
exit 1
|
||||||
|
fi
|
||||||
|
print_success "1/7 Tag v$version already exists at ${pin_commit:0:12}"
|
||||||
|
else
|
||||||
|
ensure_mirror_clone
|
||||||
|
push_upstream_ref "$pin_commit" "refs/tags/v$version"
|
||||||
|
tag_commit=$(resolve_tag_commit "v$version")
|
||||||
|
if [[ "$tag_commit" != "$pin_commit" ]]; then
|
||||||
|
print_error "Tag push completed but v$version resolves to '${tag_commit:-nothing}'"
|
||||||
|
echo "Expected the tested commit $pin_commit; refusing to continue."
|
||||||
|
exit 1
|
||||||
|
fi
|
||||||
|
print_success "1/7 Tagged v$version at ${pin_commit:0:12}"
|
||||||
|
fi
|
||||||
|
|
||||||
|
# 2. Final pins into rc. Resolve the tag we just established so the final
|
||||||
|
# PKGBUILDs record both its provenance and its exact commit.
|
||||||
local rc_pub stable_pub
|
local rc_pub stable_pub
|
||||||
rc_pub=$(published_version rc 2>/dev/null) || rc_pub=""
|
rc_pub=$(published_version rc 2>/dev/null) || rc_pub=""
|
||||||
if [[ "${rc_pub%-*}" == "$version" ]]; then
|
if [[ "${rc_pub%-*}" == "$version" ]]; then
|
||||||
print_success "1/7 Final $version already published to rc"
|
print_success "2/7 Final $version already published to rc"
|
||||||
else
|
else
|
||||||
if [[ "$pin_ver" != "$version" ]]; then
|
if [[ "$pin_ver" != "$version" ]]; then
|
||||||
print_info "1/7 Pinning final $version..."
|
print_info "2/7 Pinning final $version from tag v$version..."
|
||||||
cut_pins "v$version" --commit "$pin_commit"
|
cut_pins "v$version"
|
||||||
else
|
else
|
||||||
print_info "1/7 Final $version pinned — re-triggering build"
|
print_info "2/7 Final $version pinned — re-triggering build"
|
||||||
fi
|
fi
|
||||||
trigger_rc_build || true
|
trigger_rc_build || true
|
||||||
wait_for_published rc "$version" || exit 1
|
wait_for_published rc "$version" || exit 1
|
||||||
fi
|
fi
|
||||||
|
|
||||||
# 2. Promote rc -> stable
|
# 3. Promote rc -> stable
|
||||||
stable_pub=$(published_version stable 2>/dev/null) || stable_pub=""
|
stable_pub=$(published_version stable 2>/dev/null) || stable_pub=""
|
||||||
if [[ "${stable_pub%-*}" == "$version" ]]; then
|
if [[ "${stable_pub%-*}" == "$version" ]]; then
|
||||||
print_success "2/7 Stable already serves $version"
|
print_success "3/7 Stable already serves $version"
|
||||||
else
|
else
|
||||||
host_advance rc stable || exit 1
|
host_advance rc stable || exit 1
|
||||||
stable_pub=$(published_version stable 2>/dev/null) || stable_pub=""
|
stable_pub=$(published_version stable 2>/dev/null) || stable_pub=""
|
||||||
@@ -793,17 +825,7 @@ cmd_ship() {
|
|||||||
print_error "Promotion ran but stable serves '${stable_pub:-nothing}' — investigate before continuing"
|
print_error "Promotion ran but stable serves '${stable_pub:-nothing}' — investigate before continuing"
|
||||||
exit 1
|
exit 1
|
||||||
fi
|
fi
|
||||||
print_success "2/7 Promoted to stable: omarchy $stable_pub"
|
print_success "3/7 Promoted to stable: omarchy $stable_pub"
|
||||||
fi
|
|
||||||
|
|
||||||
# 3. Tag — at the pinned commit the artifacts were built from, never the
|
|
||||||
# branch head (they can differ on a resumed ship).
|
|
||||||
if tag_exists "v$version"; then
|
|
||||||
print_success "3/7 Tag v$version already exists"
|
|
||||||
else
|
|
||||||
ensure_mirror_clone
|
|
||||||
git -C "$MIRROR_CLONE" push --quiet origin "$pin_commit:refs/tags/v$version"
|
|
||||||
print_success "3/7 Tagged v$version at ${pin_commit:0:12}"
|
|
||||||
fi
|
fi
|
||||||
|
|
||||||
# 4. Final pins onto master (keeps edge overlap publishing and the repo record)
|
# 4. Final pins onto master (keeps edge overlap publishing and the repo record)
|
||||||
@@ -830,7 +852,9 @@ cmd_ship() {
|
|||||||
fi
|
fi
|
||||||
fi
|
fi
|
||||||
|
|
||||||
# 5. GitHub release from the staging PR body
|
# 5. Draft GitHub release from the staging PR body. Requiring the tag makes
|
||||||
|
# this fail closed if step 1 did not finish instead of letting gh create the
|
||||||
|
# tag from the default branch.
|
||||||
if gh release view "v$version" --repo "$UPSTREAM_REPO" >/dev/null 2>&1; then
|
if gh release view "v$version" --repo "$UPSTREAM_REPO" >/dev/null 2>&1; then
|
||||||
print_success "5/7 GitHub release v$version already exists"
|
print_success "5/7 GitHub release v$version already exists"
|
||||||
else
|
else
|
||||||
@@ -840,8 +864,9 @@ cmd_ship() {
|
|||||||
notes="Omarchy $version"
|
notes="Omarchy $version"
|
||||||
print_warning "No staging PR body found — using a bare title; edit the release afterwards"
|
print_warning "No staging PR body found — using a bare title; edit the release afterwards"
|
||||||
fi
|
fi
|
||||||
gh release create "v$version" --repo "$UPSTREAM_REPO" --title "v$version" --notes "$notes"
|
gh release create "v$version" --repo "$UPSTREAM_REPO" --title "v$version" \
|
||||||
print_success "5/7 GitHub release v$version created"
|
--notes "$notes" --draft --verify-tag
|
||||||
|
print_success "5/7 Draft GitHub release v$version created"
|
||||||
fi
|
fi
|
||||||
|
|
||||||
# 6. ISO
|
# 6. ISO
|
||||||
|
|||||||
Reference in New Issue
Block a user