Address Momus branch-review findings: harden ship, advance, and locking

- ship: no interactive override of the untested-commit guard; the tag targets
  the pinned commit the artifacts were built from (never the branch head); a
  tagged-but-incomplete train is found and resumed instead of vanishing from
  open-train detection; a fully shipped train reports as such
- start: a failed edge→rc advance fails the command loudly (both start and
  the advance are idempotent) instead of opening a train against stale rc
- rc trigger: bootstraps the server's rc worktree on first use, so a host set
  up before the rc branch existed can run its first RC build
- advance-channel: fast-ring packages are excluded from edge→rc (the stable
  build replicated by parity is authoritative for rc — same filename, other
  bytes); differing destination bytes abort instead of warn; a package whose
  signature copy was interrupted gets its .sig restored on resume
- the release lock now also covers direct promote/update/clean/remove/sync
  invocations, not just release/advance/upload-prebuilt
This commit is contained in:
Ryan Hughes
2026-08-27 01:10:33 -04:00
parent da92095f75
commit 5fae475743
7 changed files with 132 additions and 27 deletions
+3
View File
@@ -9,6 +9,7 @@ BUILD_ROOT=$(realpath "${BASH_SOURCE[0]%/*}/..")
source "$BUILD_ROOT/helpers/message-helpers.sh"
source "$BUILD_ROOT/helpers/docker-helpers.sh"
source "$BUILD_ROOT/helpers/paths.sh"
source "$BUILD_ROOT/helpers/lock-helpers.sh"
# Function to update repository database using Docker
update_database() {
@@ -77,6 +78,8 @@ main() {
print_info "Mirror: $MIRROR"
print_info "Output directory: $REPO_DIR"
acquire_release_lock || exit 1
update_database
echo ""