Track upstream branches as pinned releases on an unattended lane

Since publishing moved to CI on merge, a package whose PKGBUILD never
changes while its source moves was never rebuilt: omarchy-dev and
omarchy-settings-dev followed quattro through "#branch=" and a pkgver()
function, and nothing in this repository changed when quattro did. The
host timers that used to notice are off, so edge fell days behind.

The rule now: no git source without a commit or tag pin
(tests/pinned-sources.sh, run in CI). A package that has to follow a
branch declares a git_branch upstream watch, and the pin moves through
the same PR/build/publish path as every other version bump.

Watch (helpers/upstream-watch.py)
  git_branch gains tag_pattern: the newest release tag in the pinned
  commit's own history, exposed as {tag}/{version}/{distance}, so a
  branch build is versioned <tag>.r<n>.g<sha>, above the release it
  follows and below the next one. One blobless clone per branch per
  run, shared by every package on it. min_release_age selects the
  newest commit older than the window, so a push burst builds once.

Lane (helpers/package-metadata.sh, bin/sync-upstream --lane)
  "auto_merge": true moves a package from the reviewed 6-hourly sync
  PR to the unattended lane. Packages pinned from the same branch move
  together: a failure on one restores the others and fails the group,
  so the dev pair can never ship from two quattro commits.

Tracker (.github/workflows/track-branches.yml)
  Every two hours: pin, open one PR with a GitHub App token, enable
  auto-merge. Branch protection still gates the merge on result,
  self-tests and build-isolation. A tip that fails to build stays an
  open red PR until the next tick supersedes it. The App is required:
  a PR opened with GITHUB_TOKEN has its checks held for approval and
  its auto-merge would not fire publish.yml.

The reviewed workflows (sync-upstream, sync-rebuilds) open their PRs
with the same App so their builds start without a maintainer clicking
"Approve workflows to run"; without the App they fall back to
GITHUB_TOKEN and behave as before.

Recipes
  The dev pair pins _commit and a real sha256sum, keeps the OMARCHY_SRC
  override, and drops pkgver(). Its r-number stays the branch's total
  commit count because the published history used it and pacman must
  never see the version go down. omasnap-git is new: omacom/omasnap
  main, versioned <tag>.r<distance>.g<sha>, provides/conflicts omasnap.
This commit is contained in:
Ryan Hughes committed 2026-09-27 12:39:53 -04:00
1 parent e7da505280
commit d87686ca4f
17 files changed
+746 -68

No files matched your search

+25 -4
View File
@@ -47,11 +47,13 @@ jobs:
useradd -m -u "$HOST_UID" -g "$HOST_GID" runner
chown -R runner:runner /workspace/pkgbuilds
# The reviewed lane only: packages marked auto_merge ride
# track-branches.yml, which merges without a human.
if [[ -n "${PACKAGES:-}" ]]; then
read -r -a package_args <<< "$PACKAGES"
runuser -u runner -- ./bin/sync-upstream "${package_args[@]}"
runuser -u runner -- ./bin/sync-upstream --lane reviewed "${package_args[@]}"
else
runuser -u runner -- ./bin/sync-upstream
runuser -u runner -- ./bin/sync-upstream --lane reviewed
fi
'
env:
@@ -70,11 +72,30 @@ jobs:
echo "has_changes=true" >> "$GITHUB_OUTPUT"
fi
# A PR opened with GITHUB_TOKEN gets its build and test runs held
# until a maintainer clicks "Approve workflows to run"; one opened by
# the App builds on its own, so the reviewer sees a green (or red) PR
# instead of a pending one. The App only opens the PR: merging stays
# a human decision in this lane.
- name: Mint the bot token
if: ${{ !cancelled() && steps.changes.outputs.has_changes == 'true' }}
id: app
env:
PKGS_BOT_APP_ID: ${{ secrets.PKGS_BOT_APP_ID }}
# Without the App configured this falls back to GITHUB_TOKEN below,
# which still opens the PR; a maintainer then has to approve its
# workflow runs by hand, as before.
uses: actions/create-github-app-token@bcd2ba49218906704ab6c1aa796996da409d3eb1 # v3.2.0
with:
app-id: ${{ secrets.PKGS_BOT_APP_ID }}
private-key: ${{ secrets.PKGS_BOT_PRIVATE_KEY }}
continue-on-error: true
- name: Create Pull Request
if: ${{ !cancelled() && steps.changes.outputs.has_changes == 'true' }}
uses: peter-evans/create-pull-request@v7
uses: peter-evans/create-pull-request@5f6978faf089d4d20b00c7766989d076bb2fc7f1 # v8.1.1
with:
token: ${{ secrets.GITHUB_TOKEN }}
token: ${{ steps.app.outputs.token || secrets.GITHUB_TOKEN }}
commit-message: 'chore: sync upstream releases'
title: 'chore: sync upstream releases'
body: |