diff --git a/bin/promote-build b/bin/promote-build index 57c9a46..fd46049 100755 --- a/bin/promote-build +++ b/bin/promote-build @@ -72,30 +72,88 @@ if [[ "$DRY_RUN" == true ]]; then print_warning "DRY RUN MODE - No files will be copied" echo "" print_info "Packages that would be promoted:" - ls -1 *.pkg.tar.* 2>/dev/null | grep -v 'omarchy-build\.db' | while read -r pkg; do + ls -1 *.pkg.tar.* 2>/dev/null | grep -v 'omarchy-build\.db' | grep -v 'omarchy-build\.files' | while read -r pkg; do echo " - $pkg" done else echo "" mkdir -p "$REPO_DIR" - - # Move all package files (excluding build database) - # Using mv instead of cp avoids filesystem sync issues and is atomic + + echo "==> Verifying all packages have signatures..." + MISSING_SIGS=() + for pkg_file in *.pkg.tar.*; do + # Skip build database files + [[ "$pkg_file" == omarchy-build.db* ]] && continue + [[ "$pkg_file" == omarchy-build.files* ]] && continue + # Skip signature files themselves + [[ "$pkg_file" == *.sig ]] && continue + [[ ! -f "$pkg_file" ]] && continue + + # Check if signature exists + if [[ ! -f "$pkg_file.sig" ]]; then + MISSING_SIGS+=("$pkg_file") + fi + done + + if [[ ${#MISSING_SIGS[@]} -gt 0 ]]; then + echo "" + print_error "ERROR: The following packages are missing signatures:" + for pkg in "${MISSING_SIGS[@]}"; do + echo " - $pkg (missing $pkg.sig)" + done + echo "" + print_error "All packages must be signed before promotion!" + echo "" + echo "To fix this, run:" + echo " bin/repo sign --mirror $MIRROR --arch $ARCH" + exit 1 + fi + + echo "==> Checking for existing files in production..." + CONFLICTS=() + for pkg_file in *.pkg.tar.*; do + # Skip build database files + [[ "$pkg_file" == omarchy-build.db* ]] && continue + [[ "$pkg_file" == omarchy-build.files* ]] && continue + [[ ! -f "$pkg_file" ]] && continue + + if [[ -f "$REPO_DIR/$pkg_file" ]]; then + CONFLICTS+=("$pkg_file") + fi + done + + if [[ ${#CONFLICTS[@]} -gt 0 ]]; then + echo "" + print_error "ERROR: The following packages already exist in production:" + for conflict in "${CONFLICTS[@]}"; do + echo " - $conflict" + done + echo "" + print_error "Packages already exist in pkgs.omarchy.org!" + exit 1 + fi + + print_info "Moving packages to production..." + MOVED=0 for pkg_file in *.pkg.tar.*; do # Skip build database files [[ "$pkg_file" == omarchy-build.db* ]] && continue - - if [[ -f "$pkg_file" ]]; then - mv -v "$pkg_file" "$REPO_DIR/" + [[ "$pkg_file" == omarchy-build.files* ]] && continue + [[ ! -f "$pkg_file" ]] && continue + + # Use mv to prevent race condition caused by cp + if mv -v "$pkg_file" "$REPO_DIR/"; then MOVED=$((MOVED + 1)) + else + print_error "Failed to move $pkg_file" + exit 1 fi done - + echo "" print_success "Promoted $MOVED file(s) to pkgs.omarchy.org" - - # Cleanup build directory after successful promotion + print_info "Cleaning up build directory..." cd "$BUILD_OUTPUT_DIR" rm -f *.pkg.tar.* omarchy-build.db* omarchy-build.files*