From 83bdfb5fa13c7250fde4f0fa10ca4bb0279dbe5a Mon Sep 17 00:00:00 2001 From: Ryan Hughes Date: Mon, 24 Aug 2026 20:14:45 -0400 Subject: [PATCH] Prove the migrated mise path end to end and harden discovery per Momus The self-test now runs sync_package over the checked-in mise-bin package -- its real metadata and PKGBUILD, the full selection/validation/backstop/ rewrite/read-back path -- with only the two network fetches replaced by mise-shaped fixtures, asserting the final PKGBUILD holds the quarantine- cleared version, pkgrel 1, and both architecture checksums. Review fixes: the release-row builder uses "" fallbacks instead of empty so a malformed row cannot shift columns past the per-field checks, and provider discovery now keys on the presence of an upstream declaration rather than a well-formed one, with sync_package failing loudly on a declaration it cannot use -- a malformed manifest can no longer silently drop a package out of scheduled synchronization. --- bin/sync-upstream | 58 ++++++++++++++++++++++++++++++++++++- helpers/package-metadata.sh | 9 ++++-- helpers/upstream-github.sh | 5 +++- 3 files changed, 67 insertions(+), 5 deletions(-) diff --git a/bin/sync-upstream b/bin/sync-upstream index c06f1a3..99bd2e1 100755 --- a/bin/sync-upstream +++ b/bin/sync-upstream @@ -328,8 +328,19 @@ sync_package() { return 0 fi - local github_repo + local github_repo has_upstream=false github_repo=$(package_upstream_github_repo "$package_dir") + if package_has_upstream_provider "$package_dir"; then + has_upstream=true + fi + + # A present-but-unusable declaration fails loudly; treating it like "no + # upstream source" would silently drop the package from scheduled runs. + if [[ "$has_upstream" == true && -z "$github_repo" ]]; then + print_error "Package $package has an unusable upstream declaration (needs a github owner/repo)" + ((++FAILED)) + return 0 + fi if [[ -n "$github_repo" && -f "$hook" ]]; then print_error "Package $package declares both upstream.github and an upstream.sh hook; keep exactly one" @@ -596,6 +607,51 @@ EOF vst=0; validate_package_metadata "$agepkg" >/dev/null || vst=$? check "the real declaration shape is accepted" "0" "$vst" + # End to end over the real mise-bin package: its checked-in metadata and + # PKGBUILD, the full sync_package path (selection, validation, backstop, + # rewrite, read-back verification), with only the two network fetches + # replaced by mise-shaped fixtures. + echo "End-to-end sync_package with the checked-in mise-bin metadata:" + local e2e_root="$TEMP_DIR/e2e-pkgbuilds" + mkdir -p "$e2e_root" + cp -a "$BUILD_ROOT/pkgbuilds/mise-bin" "$e2e_root/mise-bin" + + local mise_x64 mise_a64 + mise_x64=$(printf 'e%.0s' {1..64}) + mise_a64=$(printf 'f%.0s' {1..64}) + FIXTURE_RELEASES=$(jq -n --arg young "$young" --arg old2 "$old2d" '[ + {tag_name: "v2026.9.1", published_at: $young, draft: false, prerelease: false}, + {tag_name: "v2026.9.0", published_at: $old2, draft: false, prerelease: false} + ]') + FIXTURE_CHECKSUMS=$(printf '%s\n' \ + "$mise_x64 ./mise-v2026.9.0-linux-x64.tar.xz" \ + "$mise_a64 ./mise-v2026.9.0-linux-arm64.tar.xz") + + local prev_updated=$UPDATED prev_failed=$FAILED + PKGBUILDS_DIR="$e2e_root" sync_package mise-bin >/dev/null 2>&1 || true + check "sync_package updates without failures" "updated=1 failed=0" \ + "updated=$((UPDATED - prev_updated)) failed=$((FAILED - prev_failed))" + check "the 24h manifest policy holds v2026.9.1 and ships v2026.9.0" "2026.9.0" \ + "$(grep -m1 '^pkgver=' "$e2e_root/mise-bin/PKGBUILD" | cut -d= -f2-)" + check "pkgrel resets to 1" "1" \ + "$(grep -m1 '^pkgrel=' "$e2e_root/mise-bin/PKGBUILD" | cut -d= -f2-)" + check "x86_64 checksum lands in the PKGBUILD" "sha256sums_x86_64=('$mise_x64')" \ + "$(grep -m1 '^sha256sums_x86_64=' "$e2e_root/mise-bin/PKGBUILD")" + check "aarch64 checksum lands in the PKGBUILD" "sha256sums_aarch64=('$mise_a64')" \ + "$(grep -m1 '^sha256sums_aarch64=' "$e2e_root/mise-bin/PKGBUILD")" + + # A malformed declaration must fail the run loudly, and still be discovered. + local badpkg="$e2e_root/selftest-broken" + mkdir -p "$badpkg/.omarchy" + printf 'pkgver=1.0.0\npkgrel=1\n' > "$badpkg/PKGBUILD" + echo '{"source": "local", "upstream": false}' > "$badpkg/.omarchy/package.json" + check "malformed upstream stays discoverable for scheduled runs" "yes" \ + "$(PKGBUILDS_DIR="$e2e_root" packages_for_upstream_sync | grep -qx selftest-broken && echo yes || echo no)" + prev_failed=$FAILED + PKGBUILDS_DIR="$e2e_root" sync_package selftest-broken >/dev/null 2>&1 || true + check "malformed upstream fails the sync instead of skipping" "1" "$((FAILED - prev_failed))" + FAILED=0 + echo "" if [[ "$failures" -eq 0 ]]; then print_success "Self-test passed" diff --git a/helpers/package-metadata.sh b/helpers/package-metadata.sh index 01f828e..1a13745 100644 --- a/helpers/package-metadata.sh +++ b/helpers/package-metadata.sh @@ -178,9 +178,12 @@ package_has_upstream_hook() { } package_has_upstream_provider() { - local pkgdir="$1" - # `objects` drops a non-object upstream value instead of erroring jq. - [[ -n "$(package_metadata_value "$pkgdir" '(.upstream? | objects | .github)' "")" ]] + local pkgdir="$1" metadata + metadata=$(metadata_file_for_dir "$pkgdir") + [[ -f "$metadata" ]] || return 1 + # Any upstream key counts, valid or not: a malformed declaration must reach + # bin/sync-upstream and fail loudly there, not vanish from discovery. + jq -e 'has("upstream")' "$metadata" >/dev/null } packages_for_upstream_sync() { diff --git a/helpers/upstream-github.sh b/helpers/upstream-github.sh index 297056c..a0e3ebc 100644 --- a/helpers/upstream-github.sh +++ b/helpers/upstream-github.sh @@ -104,7 +104,10 @@ github_upstream_release() { best_pkgver=$pkgver best_published_at=$published_at fi - done < <(jq -r '.[] | select((.draft or .prerelease) | not) | [.tag_name // empty, .published_at // empty] | @tsv' <<<"$releases") + # `// ""` rather than `// empty`: empty would drop the field and shift the + # columns, so a malformed row could masquerade as a different one instead + # of tripping the per-field checks above. + done < <(jq -r '.[] | select((.draft or .prerelease) | not) | [.tag_name // "", .published_at // ""] | @tsv' <<<"$releases") if (( candidates == 0 )); then echo "no stable releases found in the feed for $repo" >&2