Overhaul the whole build process

This commit is contained in:
Ryan Hughes
2025-10-26 23:33:22 -04:00
parent 2d673b4ccf
commit 95d1a77659
13 changed files with 715 additions and 137 deletions
+18 -47
View File
@@ -9,12 +9,13 @@ source "$BUILD_ROOT/lib/message-helpers.sh"
ARCH=${ARCH:-x86_64}
ARCH_DIR="$BUILD_ROOT/output/$ARCH"
BUILD_OUTPUT_DIR="$BUILD_ROOT/build-output/$ARCH"
FINAL_OUTPUT_DIR="$BUILD_ROOT/pkgs.omarchy.org/$ARCH"
SRC_DIR="$BUILD_ROOT/src"
BUILD_DIR="$BUILD_ROOT/build"
# Create directories if they don't exist
mkdir -p "$ARCH_DIR" "$SRC_DIR"
mkdir -p "$BUILD_OUTPUT_DIR" "$FINAL_OUTPUT_DIR" "$SRC_DIR"
# Check for Docker
if ! command -v docker &>/dev/null; then
@@ -80,7 +81,13 @@ done
# Show target architecture after parsing args
print_info "Target architecture: $ARCH"
print_info "Output directory: $ARCH_DIR"
print_info "Build workspace: $BUILD_OUTPUT_DIR"
print_info "Final output: $FINAL_OUTPUT_DIR"
# Clean build-output directory to start fresh
print_info "Cleaning build workspace..."
rm -rf "$BUILD_OUTPUT_DIR"/*
mkdir -p "$BUILD_OUTPUT_DIR"
# Check if AUR package list exists (only required if not building single package)
if [[ -z "$SINGLE_PACKAGE" ]]; then
@@ -92,36 +99,9 @@ else
print_info "Building single package: $SINGLE_PACKAGE"
fi
# Handle GPG signing setup
if [[ "$SKIP_SIGNING" == true ]]; then
print_warning "Skipping GPG signing (--skip-signing flag set)"
export SKIP_SIGNING=true
else
# Get GPG key from 1Password or environment for signing
if [[ -z "$GPG_PRIVATE_KEY" ]]; then
print_info "Fetching GPG signing key from 1Password..."
GPG_PRIVATE_KEY=$(op document get "Omarchy GPG Private Key" --account=omarchy.1password.com) || {
print_error "Failed to fetch GPG key from 1Password or environment"
exit 1
}
else
print_info "Using existing GPG signing key from environment"
fi
export GPG_PRIVATE_KEY="$GPG_PRIVATE_KEY"
# Get passphrase from 1Password or environment
if [[ -z "$GPG_PASSPHRASE" ]]; then
print_info "Fetching GPG key passphrase from 1Password..."
GPG_PASSPHRASE=$(op item get "Omarchy GPG Private Key" --account=omarchy.1password.com --fields password --reveal) || {
print_error "Failed to fetch GPG passphrase from 1Password or environment"
exit 1
}
else
print_info "Using existing GPG passphrase from environment"
fi
export GPG_PASSPHRASE
print_success "GPG signing key and passphrase loaded"
fi
# GPG is no longer used during build - signing happens in separate step
# But we still need to import verification keys for package validation
export SKIP_SIGNING=true
# Build/update the Docker image
print_info "Building Docker image..."
@@ -129,12 +109,12 @@ docker build -t omarchy-aur-builder:latest -f "$BUILD_DIR/Dockerfile" "$BUILD_DI
print_info "Running AUR package build..."
# Ensure output directory is writable by container user
# Ensure output directories are writable by container user
# The container runs as 'builder' user, so we need to make output writable
if [ "$(id -u)" -eq 0 ]; then
chmod -R 777 "$ARCH_DIR"
chmod -R 777 "$BUILD_OUTPUT_DIR" "$FINAL_OUTPUT_DIR"
else
sudo chown -R $(id -u):$(id -g) "$ARCH_DIR" 2>/dev/null || chmod -R 777 "$ARCH_DIR"
sudo chown -R $(id -u):$(id -g) "$BUILD_OUTPUT_DIR" "$FINAL_OUTPUT_DIR" 2>/dev/null || chmod -R 777 "$BUILD_OUTPUT_DIR" "$FINAL_OUTPUT_DIR"
fi
# Build Docker arguments
@@ -142,10 +122,9 @@ DOCKER_ARGS=(
--rm
-e ARCH="$ARCH"
-e SKIP_SIGNING
-e GPG_PRIVATE_KEY
-e GPG_PASSPHRASE
-e SINGLE_PACKAGE="$SINGLE_PACKAGE"
-v "$BUILD_ROOT/output:/output"
-v "$BUILD_ROOT/build-output:/build-output"
-v "$BUILD_ROOT/pkgs.omarchy.org:/pkgs.omarchy.org"
-v "$BUILD_DIR:/build:ro"
-v "$BUILD_ROOT/pkgbuilds:/pkgbuilds:ro"
)
@@ -158,20 +137,12 @@ fi
# Run the builder with assembled args
docker run "${DOCKER_ARGS[@]}" omarchy-aur-builder:latest /build/build.sh
# Clear the GPG key and passphrase from environment
unset GPG_PRIVATE_KEY
unset GPG_PASSPHRASE
BUILD_RESULT=$?
# Summary
echo ""
if [[ $BUILD_RESULT -eq 0 ]]; then
print_success "AUR build completed successfully!"
echo ""
print_info "Next steps:"
echo " 1. Run ./bin/update-repo to update the repository"
echo " 2. Commit and push changes"
else
print_warning "Some AUR packages failed (see details above)"
exit $BUILD_RESULT