Stop an unscoped deploy from rebuilding the whole repository

bin/build asks the local repository database which packages are already built.
A build machine has no such database, so every package looks out of date: an
unscoped 'bin/repo deploy' on this laptop would have built all 108 packages and
published them. Verified with a dry run.

deploy now refuses to run unscoped when that database is absent, and push
refuses the same combination under --yes, where nobody would see the list it
prints before publishing. Both are allowed on the repository host, which has
the database that makes the comparison meaningful.

Also states the split in the README: build, push and deploy are the three
commands that may run off the repository host; everything else works on the
published tree directly.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
This commit is contained in:
David Heinemeier Hansson
2026-08-12 04:03:31 -07:00
co-authored by Claude Opus 5
parent 736579a6eb
commit 51004999e7
4 changed files with 59 additions and 0 deletions
+12
View File
@@ -97,6 +97,18 @@ bin/repo push --package nvidia-580xx-utils # Upload + publish on the host
`bin/upload-prebuilt` there. Do not publish from a local checkout instead: only `bin/upload-prebuilt` there. Do not publish from a local checkout instead: only
the repository host holds the complete repository and the signing key. the repository host holds the complete repository and the signing key.
**Name the package.** `build` asks the local repository database which packages
are already built, and a build machine has no such database, so an unscoped run
treats every package as out of date and rebuilds the whole repository. `deploy`
refuses to run unscoped when that database is missing. Unscoped builds belong on
the repository host, where `bin/repo release` does the same job against a real
database.
Every other command in `bin/` — `sign`, `promote`, `update`, `clean`, `migrate`,
`remove`, `sync`, `release` — works on the published tree directly and is meant
to run on the repository host. `build`, `push` and `deploy` are the three that
may run elsewhere.
## Commands ## Commands
### Global Flags ### Global Flags
+20
View File
@@ -94,6 +94,26 @@ if [[ "$PACKAGE_FLAG_GIVEN" == true && ${#PACKAGES[@]} -eq 0 ]]; then
exit 1 exit 1
fi fi
# bin/build asks the local repository database what is already built. On a build
# machine that database does not exist, so every package looks unbuilt and an
# unscoped run rebuilds the entire repository and publishes it. Deploying from
# here is for the occasional heavy package, so name it.
if [[ ${#PACKAGES[@]} -eq 0 ]] && ! on_repo_host; then
print_error "--package is required when deploying from a build machine"
echo ""
echo "There is no repository database in:"
echo " $REPO_DIR"
echo ""
echo "bin/build uses it to tell which packages are already built, so without it"
echo "every package looks out of date and this would build and publish all of"
echo "them. Name the package you came here to build:"
echo " bin/repo deploy --package <name>"
echo ""
echo "Unscoped builds belong on the repository host, where 'bin/repo release'"
echo "does the same job against a real database."
exit 1
fi
echo "" echo ""
print_info "This will:" print_info "This will:"
echo " 1. Build packages locally" echo " 1. Build packages locally"
+17
View File
@@ -126,6 +126,23 @@ if [[ "$PACKAGE_FLAG_GIVEN" == true && -z "$PACKAGES" ]]; then
exit 1 exit 1
fi fi
# On a build machine an unscoped build leaves the whole repository in
# build-output, because there is no local database to tell it what already
# exists. Interactively that is survivable — the confirmation below lists every
# package first — but with --yes nobody sees the list, so require an explicit
# selection instead.
if [[ -z "$PACKAGES" && "$ASSUME_YES" == true ]] && ! on_repo_host; then
print_error "--package is required to publish unattended from a build machine"
echo ""
echo "There is no repository database in $REPO_DIR, so a preceding unscoped"
echo "build would have rebuilt everything rather than only what changed, and"
echo "--yes would publish all ${#ALL_FILES[@]} of them without showing the list."
echo ""
echo "Name the packages to publish:"
echo " bin/repo push --package <name>"
exit 1
fi
FILES=() FILES=()
if [[ -z "$PACKAGES" ]]; then if [[ -z "$PACKAGES" ]]; then
FILES=("${ALL_FILES[@]}") FILES=("${ALL_FILES[@]}")
+10
View File
@@ -33,6 +33,16 @@ resolve_repo_host() {
return 1 return 1
} }
# True when this checkout holds the published repository, which in practice means
# this machine is the repository host. Every other command in bin/ works on that
# tree directly; build, push and deploy are the ones that may run elsewhere.
#
# The database is the marker rather than the directory: bin/build creates empty
# mirror directories as a side effect, so their presence proves nothing.
on_repo_host() {
[[ -f "$REPO_DIR/omarchy.db" || -f "$REPO_DIR/omarchy.db.tar.zst" ]]
}
# Shared wording so every command explains configuration the same way. # Shared wording so every command explains configuration the same way.
print_no_repo_host() { print_no_repo_host() {
print_error "No repository host configured" print_error "No repository host configured"