Build fast-ring for rc as rc, instead of copying stable's artifacts

The rc channel's Arch base can sit anywhere between stable's snapshot and
edge's, so a package built against stable's libraries is not necessarily
correct for rc. Copying stable's fast-ring artifacts into rc therefore shipped
possibly-mislinked packages to RC testers. Fast-ring packages now build
natively for all three channels, each in its own image against its own base
mirror, and the stable release's replication step is gone.

That required separating 'may be built here' from 'whose version wins'. The
release pair is now marked "pinned": its version is set per release on the rc
branch, so it builds for rc only from that branch's worktree
(OMARCHY_RC_PINS=1, set by omarchy-release rc) — master's shipped pins can
never overwrite an in-flight RC, even though check-versions now discovers rc
work like it does for edge and stable.
This commit is contained in:
Ryan Hughes
2026-08-27 12:39:29 -04:00
parent 9fd75fc3ba
commit dbb5e72051
10 changed files with 74 additions and 111 deletions
-5
View File
@@ -202,11 +202,6 @@ package_eligible() {
if [[ "$FAST_RING_ONLY" == true ]]; then
package_is_fast_ring "$pkgdir" || return 1
elif [[ "$FROM" == "edge" && "$TO" == "rc" ]]; then
# Fast-ring packages reach rc by replication of the STABLE build (same
# bytes stable users get). Carrying the independently built edge artifact
# forward would race it under the same filename.
package_is_fast_ring "$pkgdir" && return 1
fi
# The bootstrap seeds an empty rc from stable, so parity is the whole point:
-43
View File
@@ -1,43 +0,0 @@
#!/bin/bash
# Scheduled entry point for the rc channel.
#
# The rc channel builds from the standing `rc` branch in its own worktree, but
# that branch does not exist until the first RC is cut — and a host set up
# before then has no worktree either. This runs from the MAIN checkout, which
# always exists, and makes both conditions non-events: no branch means nothing
# to build, and a missing worktree is created on demand rather than failing
# the unit every five minutes.
set -e
BUILD_ROOT=$(realpath "${BASH_SOURCE[0]%/*}/..")
source "$BUILD_ROOT/helpers/message-helpers.sh"
RC_WORKTREE="${OMARCHY_RC_WORKTREE:-/root/omarchy-pkgs-rc}"
STATE_DIR="${OMARCHY_STATE_DIR:-/root/.state}"
# Nothing queued: the common case. Exit before touching the network.
[[ -f "$STATE_DIR/.sync-needed-rc" ]] || exit 0
git -C "$BUILD_ROOT" fetch --quiet origin rc 2>/dev/null || true
if ! git -C "$BUILD_ROOT" show-ref --verify --quiet refs/remotes/origin/rc; then
print_info "No rc branch yet — nothing to build (the first RC cut creates it)"
exit 0
fi
if [[ ! -d "$RC_WORKTREE" ]]; then
print_info "Creating rc worktree at $RC_WORKTREE..."
if git -C "$BUILD_ROOT" show-ref --verify --quiet refs/heads/rc; then
git -C "$BUILD_ROOT" worktree add "$RC_WORKTREE" rc
else
git -C "$BUILD_ROOT" worktree add --track -b rc "$RC_WORKTREE" origin/rc
fi
fi
# The rc branch is rebuilt as master + pins for each cut and force-pushed, so
# this follows with a hard reset rather than a fast-forward pull.
git -C "$RC_WORKTREE" fetch origin rc
git -C "$RC_WORKTREE" reset --hard origin/rc
exec "$RC_WORKTREE/bin/auto-release" rc
+1
View File
@@ -179,6 +179,7 @@ check_mirror() {
}
check_mirror edge
check_mirror rc
check_mirror stable
print_success "Version check complete!"
+13 -12
View File
@@ -225,8 +225,12 @@ print_no_host_help() { # print_no_host_help <what> <script>
echo "$2" >&2
}
# Creates the rc worktree on first use (a host set up before the rc branch
# existed has none), then syncs it and kicks the service.
# Builds the pinned release pair for the rc channel from the rc branch's own
# worktree, creating it on first use. OMARCHY_RC_PINS marks this as the one
# build allowed to set those packages' rc versions; OMARCHY_REPO_ROOT points
# the worktree at the primary checkout's channel tree so all three channels
# stay in one place. Fast-ring packages are not built here — the scheduled rc
# release covers those from master.
RC_TRIGGER_SCRIPT='
set -e
git -C /root/omarchy-pkgs fetch origin rc
@@ -236,24 +240,21 @@ if [ ! -d /root/omarchy-pkgs-rc ]; then
fi
git -C /root/omarchy-pkgs-rc fetch origin rc
git -C /root/omarchy-pkgs-rc reset --hard origin/rc
mkdir -p /root/.state
touch /root/.state/.sync-needed-rc
systemctl start --no-block omarchy-auto-release-rc.service
cd /root/omarchy-pkgs-rc
OMARCHY_RC_PINS=1 OMARCHY_REPO_ROOT=/root/omarchy-pkgs/pkgs.omarchy.org \
bin/repo release --mirror rc --package omarchy omarchy-settings --skip-prod-check
'
# An explicitly configured destination outranks the local-host inference: a
# workstation that once ran a full local release carries the published-db
# marker too, and its .repo-host must still win.
trigger_rc_build() {
local host
if host=$(repo_host); then
print_info "Triggering rc build on $host..."
ssh "$host" "$RC_TRIGGER_SCRIPT"
print_info "Building the RC on $host (this takes a while)..."
ssh "$host" "source /root/.omarchy/build-credentials 2>/dev/null; $RC_TRIGGER_SCRIPT"
elif on_repo_host; then
print_info "Triggering rc build locally (this is the build host)..."
print_info "Building the RC locally (this is the build host)..."
bash -c "$RC_TRIGGER_SCRIPT"
else
print_no_host_help "build the rc channel" "$RC_TRIGGER_SCRIPT"
print_no_host_help "build the release candidate" "$RC_TRIGGER_SCRIPT"
return 1
fi
}
-20
View File
@@ -218,25 +218,5 @@ else
notify_info "Release ran with nothing to publish: $MIRROR" "$summary"
fi
# Step 7 (stable only): fast-ring packages publish to rc and stable together,
# so rc never falls behind what stable users actually run. Skipped until the
# rc channel has been bootstrapped.
if [[ "$MIRROR" == "stable" ]]; then
echo ""
if [[ -f "$REPO_ROOT/rc/$ARCH/omarchy.db.tar.zst" ]]; then
print_info "Step 7: Replicating fast-ring packages to rc (parity)..."
REPLICATE_ARGS=(--from stable --to rc --fast-ring --arch "$ARCH")
[[ -n "$SYNC_REMOTE" ]] && REPLICATE_ARGS+=(--sync-remote "$SYNC_REMOTE")
[[ "$SKIP_PROD_CHECK" == true ]] && REPLICATE_ARGS+=(--skip-prod-check)
"$BUILD_ROOT/bin/advance-channel" "${REPLICATE_ARGS[@]}" || {
print_error "Fast-ring replication to rc failed"
notify_error "Release failed: rc parity replication failed" "$RELEASE_CONTEXT"
exit 1
}
else
print_info "rc channel not bootstrapped; skipping fast-ring replication"
fi
fi
echo ""
print_success "Release workflow completed successfully!"