Track upstream branches as pinned releases on an unattended lane
Since publishing moved to CI on merge, a package whose PKGBUILD never
changes while its source moves was never rebuilt: omarchy-dev and
omarchy-settings-dev followed quattro through "#branch=" and a pkgver()
function, and nothing in this repository changed when quattro did. The
host timers that used to notice are off, so edge fell days behind.
The rule now: no git source without a commit or tag pin
(tests/pinned-sources.sh, run in CI). A package that has to follow a
branch declares a git_branch upstream watch, and the pin moves through
the same PR/build/publish path as every other version bump.
Watch (helpers/upstream-watch.py)
git_branch gains tag_pattern: the newest release tag in the pinned
commit's own history, exposed as {tag}/{version}/{distance}, so a
branch build is versioned <tag>.r<n>.g<sha>, above the release it
follows and below the next one. One blobless clone per branch per
run, shared by every package on it. min_release_age selects the
newest commit older than the window, so a push burst builds once.
Lane (helpers/package-metadata.sh, bin/sync-upstream --lane)
"auto_merge": true moves a package from the reviewed 6-hourly sync
PR to the unattended lane. Packages pinned from the same branch move
together: a failure on one restores the others and fails the group,
so the dev pair can never ship from two quattro commits.
Tracker (.github/workflows/track-branches.yml)
Every two hours: pin, open one PR with a GitHub App token, enable
auto-merge. Branch protection still gates the merge on result,
self-tests and build-isolation. A tip that fails to build stays an
open red PR until the next tick supersedes it. The App is required:
a PR opened with GITHUB_TOKEN has its checks held for approval and
its auto-merge would not fire publish.yml.
The reviewed workflows (sync-upstream, sync-rebuilds) open their PRs
with the same App so their builds start without a maintainer clicking
"Approve workflows to run"; without the App they fall back to
GITHUB_TOKEN and behave as before.
Recipes
The dev pair pins _commit and a real sha256sum, keeps the OMARCHY_SRC
override, and drops pkgver(). Its r-number stays the branch's total
commit count because the published history used it and pacman must
never see the version go down. omasnap-git is new: omacom/omasnap
main, versioned <tag>.r<distance>.g<sha>, provides/conflicts omasnap.
This commit is contained in:
1 parent
e7da505280
commit
d87686ca4f
17 files changed
+746
-68
No files matched your search
@@ -47,11 +47,13 @@ jobs:
|
||||
useradd -m -u "$HOST_UID" -g "$HOST_GID" runner
|
||||
chown -R runner:runner /workspace/pkgbuilds
|
||||
|
||||
# The reviewed lane only: packages marked auto_merge ride
|
||||
# track-branches.yml, which merges without a human.
|
||||
if [[ -n "${PACKAGES:-}" ]]; then
|
||||
read -r -a package_args <<< "$PACKAGES"
|
||||
runuser -u runner -- ./bin/sync-upstream "${package_args[@]}"
|
||||
runuser -u runner -- ./bin/sync-upstream --lane reviewed "${package_args[@]}"
|
||||
else
|
||||
runuser -u runner -- ./bin/sync-upstream
|
||||
runuser -u runner -- ./bin/sync-upstream --lane reviewed
|
||||
fi
|
||||
'
|
||||
env:
|
||||
@@ -70,11 +72,30 @@ jobs:
|
||||
echo "has_changes=true" >> "$GITHUB_OUTPUT"
|
||||
fi
|
||||
|
||||
# A PR opened with GITHUB_TOKEN gets its build and test runs held
|
||||
# until a maintainer clicks "Approve workflows to run"; one opened by
|
||||
# the App builds on its own, so the reviewer sees a green (or red) PR
|
||||
# instead of a pending one. The App only opens the PR: merging stays
|
||||
# a human decision in this lane.
|
||||
- name: Mint the bot token
|
||||
if: ${{ !cancelled() && steps.changes.outputs.has_changes == 'true' }}
|
||||
id: app
|
||||
env:
|
||||
PKGS_BOT_APP_ID: ${{ secrets.PKGS_BOT_APP_ID }}
|
||||
# Without the App configured this falls back to GITHUB_TOKEN below,
|
||||
# which still opens the PR; a maintainer then has to approve its
|
||||
# workflow runs by hand, as before.
|
||||
uses: actions/create-github-app-token@bcd2ba49218906704ab6c1aa796996da409d3eb1 # v3.2.0
|
||||
with:
|
||||
app-id: ${{ secrets.PKGS_BOT_APP_ID }}
|
||||
private-key: ${{ secrets.PKGS_BOT_PRIVATE_KEY }}
|
||||
continue-on-error: true
|
||||
|
||||
- name: Create Pull Request
|
||||
if: ${{ !cancelled() && steps.changes.outputs.has_changes == 'true' }}
|
||||
uses: peter-evans/create-pull-request@v7
|
||||
uses: peter-evans/create-pull-request@5f6978faf089d4d20b00c7766989d076bb2fc7f1 # v8.1.1
|
||||
with:
|
||||
token: ${{ secrets.GITHUB_TOKEN }}
|
||||
token: ${{ steps.app.outputs.token || secrets.GITHUB_TOKEN }}
|
||||
commit-message: 'chore: sync upstream releases'
|
||||
title: 'chore: sync upstream releases'
|
||||
body: |
|
||||
|
||||
Reference in new issue
Block a user